Saolyn Privacy Policy
Version 1.1 · Effective 21 August 2026
Saolyn Pty Ltd (ABN 92 688 690 637) respects your privacy. This Policy explains what personal information we collect, why, who we share it with, and what rights you have. It forms part of the Saolyn Platform Terms of Service.
Contact for privacy matters: ross@saolyn.com.au
1. Scope
This Policy covers the Saolyn platform and all Services delivered through it, including the website, Intelligence Reports, Applied Education, and Advisory Services.
It is written to meet the Australian Privacy Principles under the Privacy Act 1988 (Cth) and, where they apply to you, the EU and UK GDPR.
2. What we collect
2.1 Information you give us
| Category | Fields | When |
|---|---|---|
| Lead capture | Name, work email, company, current role / function | You request a free executive summary or subscribe to communications |
| Account | Name, email, authentication identifier | You register an account |
| Consent records | Terms version accepted, timestamp, IP address, browser user agent, marketing opt-in status and timestamp | You accept Terms or opt in to marketing |
| Purchase | Items purchased, amount, currency, transaction reference, billing country | You buy a Service |
| Enquiries | Anything you write to us | You contact us |
| Service inputs | Information you enter into course activities or any interactive Service | You use those Services |
2.2 Information collected automatically
Log data (IP address, timestamp, page or endpoint requested, user agent) for security, rate limiting, abuse prevention, and troubleshooting. Email engagement events (delivery, open, click, bounce, complaint, unsubscribe) from our email provider.
Aggregate page analytics. We count page views and referring sites using Cloudflare Web Analytics. It sets no cookie and creates no identifier for you, so what we receive is counts and trends — not a record of what any individual visitor did, and nothing that can be joined back to your account. See clause 6.
2.3 What we do not collect
We do not receive or store full payment card numbers — payment is handled entirely by our payment provider.
We do not ask for, and you must not submit, patient-identifiable data, personal health information about identifiable individuals, or special-category personal data. See clause 14.2 of the Terms.
2.4 Public regulatory data
Some Services analyse public regulatory databases, including adverse-event and recall databases published by regulators. These records are published by the regulator, not collected by us from you. Where such a record contains narrative text that may incidentally include personal information, we process it only in de-identified or aggregate form for signal analysis, and do not attempt to re-identify any individual.
3. Why we use it, and our lawful basis
| Purpose | Lawful basis (GDPR) |
|---|---|
| Provide the Services you requested, grant access, deliver downloads | Performance of a contract |
| Create and secure your account | Performance of a contract |
| Process payments and issue receipts | Performance of a contract; legal obligation |
| Record your acceptance of Terms and your consent | Legal obligation; legitimate interests (evidencing consent) |
| Send transactional messages about your account, purchases, and access | Performance of a contract |
| Send marketing about reports and Services | Consent (double opt-in) |
| Segment our audience using tags so communications are relevant | Legitimate interests; consent for the marketing itself |
| Security, rate limiting, fraud and abuse prevention | Legitimate interests; legal obligation |
| Improve the Services using aggregated, de-identified data | Legitimate interests |
| Comply with law and enforce our Terms | Legal obligation; legitimate interests |
We do not sell your personal information. We do not share it with third parties for their own marketing.
4. Marketing and double opt-in
4.1 When you request a free executive summary or subscribe, we send a confirmation email. We add you to a marketing list, and deliver the material, only after you click the confirmation link. If you do not confirm, the request expires and the contact record is retained only as an unconfirmed enquiry.
4.2 You may unsubscribe at any time using the link in any marketing email or by emailing ross@saolyn.com.au. Unsubscribing takes effect promptly and does not stop transactional messages about your account or purchases.
4.3 We record when and how you consented, and the version of the Terms in force at that time.
5. Tags and segmentation
We apply internal labels (“tags”) to your contact record so that communications are relevant. Tags are held in our own database and are not shared with advertising networks.
Tags we apply, and what triggers them:
| Tag | Applied when |
|---|---|
| Audience: MedTech Reports | You request or purchase any report |
| Lead: Executive Summary — report | You submit the free-summary form |
| Confirmed: Executive Summary — report | You confirm your email address |
| Customer: report | You complete a purchase |
| Role: your selected role | From the role you select on the form |
| Member | You register an account and accept the Terms |
Tags are applied automatically by our systems based on your actions. We do not use tags to make any decision that produces a legal or similarly significant effect on you, and we do not carry out automated decision-making or profiling within the meaning of Article 22 of the GDPR.
6. Cookies and similar technologies
We use a small number of strictly necessary cookies:
| Cookie | Purpose | Duration |
|---|---|---|
academy_session | Keeps you signed in. HttpOnly, Secure, SameSite=Lax | Session token lifetime (typically 1 hour) |
academy_login_txn | Protects the login exchange against interception (PKCE state) | 10 minutes |
Page analytics, and why it needs no cookie. Our pages load a small script from Cloudflare Web Analytics to count visits. It stores nothing on your device, assigns you no identifier, and cannot follow you to any other website: a page view is measured from the request itself and the page that referred it, and is discarded into aggregate counts.
We do not use advertising cookies, cross-site behavioural advertising, or any tracking pixel that identifies you or follows you between sites. Because our cookies are strictly necessary and our analytics is identifier-free, no consent banner is required — but you can block cookies in your browser, in which case sign-in will not work.
7. Who we share it with
We use the following processors. Each is bound by contract to process personal information only on our instructions.
| Provider | Function | Data | Location |
|---|---|---|---|
| Auth0 (Okta) | Authentication | Email, name, authentication identifiers | US / EU |
| Stripe | Payments | Name, email, billing country, transaction data | US / global |
| Resend | Transactional and marketing email | Name, email, engagement events | US |
| Cloudflare | Hosting, CDN, security, page analytics | IP address, request logs, aggregate page-view counts | Global edge |
| Railway | Application and database hosting | All stored application data | US |
We may also disclose personal information where required by law, to enforce our Terms, to protect rights or safety, or to a successor entity in connection with a merger, acquisition, or sale of assets (in which case this Policy continues to apply until replaced).
8. International transfers
We are based in Australia. Our providers process data in the United States, the European Union, and at global edge locations. Where personal information protected by the EU or UK GDPR is transferred outside those areas, we rely on the transfer mechanisms operated by the relevant provider, including Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework.
9. How long we keep it
| Data | Retention |
|---|---|
| Unconfirmed lead (no double opt-in) | 90 days, then deleted |
| Confirmed marketing contact | Until you unsubscribe, then a suppression record only (email, unsubscribe date) so we do not re-contact you |
| Account and access records | For the life of the account, then 12 months |
| Purchase and entitlement records | 7 years (Australian tax and record-keeping obligations) |
| Consent and Terms-acceptance records | 7 years after the account closes, as evidence of consent |
| Security and request logs | 90 days |
| Enquiries | 24 months |
10. Security
Data is encrypted in transit. Authentication is delegated to Auth0; we never see or store your password. Session cookies are HttpOnly, Secure, and SameSite=Lax. Report downloads are served through short-lived, signed links. Access to production data is limited to those who need it. Public write endpoints are rate limited.
No system is perfectly secure. If a data breach occurs that is likely to result in serious harm, we will notify the Office of the Australian Information Commissioner and affected individuals as required by the Notifiable Data Breaches scheme, and the relevant supervisory authority where the GDPR applies.
11. Your rights
Wherever you are, you may ask us to:
- Access the personal information we hold about you
- Correct anything inaccurate or out of date
- Delete your information, where we are not required to keep it
- Stop marketing to you
- Provide a copy in a portable, machine-readable format
If the EU or UK GDPR applies to you, you additionally have the right to restrict or object to processing, and to withdraw consent at any time (which does not affect processing already carried out).
To exercise any right, email ross@saolyn.com.au. We will respond within 30 days. We may need to verify your identity first.
If you are unsatisfied with our response, you may complain to the Office of the Australian Information Commissioner (oaic.gov.au), or to your local supervisory authority if you are in the EU or UK.
12. Children
The Services are for business use by adults. We do not knowingly collect personal information from anyone under 18. If we learn we have, we will delete it.
13. Changes
We may update this Policy. The current version is always published at /privacy with its version number and effective date. Material changes will be notified to account holders by email at least 30 days before they take effect.