Privacy Statement
Last updated 20 July 2026
SensorZero is a product of Eviant, ABN 42 693 128 764 ("we", "us", "our"). This statement explains how we handle personal information, and reflects our commitment to handling personal information in accordance with the Australian Privacy Principles in the Privacy Act 1988 (Cth).
Our platform
SensorZero is a security platform. Our collectors gather data related to the security of our customers' environments in order to detect threat actor activity. We collect the minimum data required for that purpose.
Customers control what is sent to the platform. What each collector gathers is agreed and configured with the customer through our data onboarding process, so sources and data types are scoped deliberately rather than collected by default.
Security collectors
Data reaches the platform through collectors deployed in the customer's environment: endpoint sensors, network sensors, and direct collection from cloud and SaaS services. Each is enabled and configured by the customer during onboarding. Security telemetry from onboarded sources may include personal information, such as usernames, device identifiers and records of activity on monitored systems.
Google Workspace
Where a customer connects Google Workspace, the SensorZero Google Workspace Ingestor accesses audit logs, the user directory and licence status. We use this only to detect advanced attacks against that customer's environment and to help them respond to and recover from incidents. Access is read-only: we cannot modify or delete anything in the Workspace, and we do not read the contents of email, files or calendars. The data is stored encrypted in the customer's SensorZero workspace, retained for the retention period agreed with that customer and then deleted, and is never sold, shared for advertising, or used to train advertising or generalised AI models.
Microsoft 365
Where a customer connects Microsoft 365, the SensorZero M365 Ingestor App accesses audit logs, the user directory and licence status on the same terms: read-only access, used only for security detection and incident response, stored encrypted, retained for the agreed period and then deleted, and never sold or used for advertising.
Both integrations are opt-in. No Google Workspace or Microsoft 365 data is collected unless the customer explicitly completes the setup process and grants access, and that access can be revoked at any time from their own administrator console, which stops collection immediately.
Where we hold data as part of delivering the platform to a business customer, that customer determines what is collected and why, and our handling of it is governed by our agreement with them rather than by this statement.
What we collect
We collect the following through this website:
- Information you give us. When you submit our contact form, we collect your first and last name, work email address, company name and anything you write in the message field. If you email us directly, we collect whatever your message contains.
- Technical and usage information. When you visit, we automatically collect your IP address, browser and device type, pages viewed, referring page, and interactions such as clicks, scrolling and mouse movement.
We do not ask for sensitive information through this website, and we ask that you not include it in the message field.
How we collect it
We collect information directly from you when you complete our contact form or email us, and automatically through our website and its analytics when you browse the site. We do not buy personal information from third parties.
Why we collect it
We use personal information to respond to your enquiry and provide the information you asked for; to follow up about our products where you have contacted us about them; to operate, secure and improve our website; and to meet our legal obligations. We do not sell personal information.
Cookies
Our website uses cookies to operate the site and understand how visitors use it. You can block cookies through your browser settings; the site will still work, though some parts may behave differently.
How we store and protect it
We hold personal information in systems operated by us and by our service providers, and we take reasonable steps to protect it from misuse, interference, loss and unauthorised access, modification or disclosure. This includes access controls, encryption in transit and limiting access to staff who need it. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
We keep personal information only as long as we need it for the purposes described here, or as required by law, and then take reasonable steps to destroy or de-identify it.
Accessing and correcting your information
You can ask us for a copy of the personal information we hold about you, and ask us to correct it if it is inaccurate, out of date or incomplete. Email support@sensorzero.com. We will need to verify your identity and will respond within a reasonable period, normally 30 days. If we refuse a request, we will explain why in writing.
You can also ask us to stop sending you marketing communications at any time, either by using the unsubscribe link in any email or by contacting us.
Complaints
If you think we have mishandled your personal information or breached the Australian Privacy Principles, please contact us at support@sensorzero.com. We will acknowledge your complaint, investigate, and respond in writing, normally within 30 days.
If you are not satisfied with our response, you can refer your complaint to the Office of the Australian Information Commissioner at oaic.gov.au.
Changes to this statement
We may update this statement from time to time. The current version is always the one published on this page, with the date shown above.
Contact
Privacy and general enquiries: support@sensorzero.com.