Privacy Policy
Version 2.3 · Last updated 27 September 2026 · All legal documents
This policy explains how Techarda (“Techarda”, “we”, “us”) collects, uses, shares and protects personal information when you visit techarda.com, create an account, take part in the community, receive our emails, or use our APIs and feeds. It is written to meet the Australian Privacy Principles (APPs) in the Privacy Act 1988 (Cth), the EU and UK General Data Protection Regulations (GDPR / UK GDPR), the California Consumer Privacy Act as amended by the CPRA and other US state privacy laws, Canada’s PIPEDA, Brazil’s LGPD, Singapore’s PDPA and India’s Digital Personal Data Protection Act 2023. The short version: we collect little, we never sell personal information, companies only ever see aggregated statistics, and you can see, download or delete your data yourself at any time from Account → Privacy & data.
1. Who we are
Techarda, Sydney, New South Wales, Australia, is the controller (APP entity / “business”) responsible for your personal information. Contact our privacy team at engage@techarda.com.
2. What we collect
| Category | Examples | Source |
|---|---|---|
| Identifiers & account | Email address; display name; handle; optional headline, job title and avatar. We sign you in with one-time email links and never store a password. | You |
| Sign in with LinkedIn (optional) | If you choose “Continue with LinkedIn”, LinkedIn shares your name, profile photo, email address and language setting with us (OpenID Connect scopes openid, profile, email). We use them only to create and pre-fill your account. We never post to LinkedIn, read your connections or share LinkedIn data with vendors, and it is deleted with your account. You can disconnect Techarda in your LinkedIn settings at any time. | LinkedIn, at your request |
| Work-email check | New accounts need an organisation email address. We check only the part after the @ against a list of personal and disposable email providers; the address itself is not sent anywhere. | You |
| Professional attributes (optional) | Job function, seniority, company size, industry, country and employer, all self-declared and optional. Your employer is only used in company-level counts if you switch on “share employer”. | You |
| Contributions | Community threads, replies, polls, votes, “helpful” marks, reviews, questions, answers, reports you make; the public profile they appear under. | You |
| Preferences & relationships | Categories, companies and spaces you follow; saved stories; your Monday brief choice and your two optional email choices (see “Optional marketing choices” below), each with the date you made it. | You |
| Usage & device | Pages viewed, searches, filters, outbound clicks, whether you returned from a source article and how long you were away, ratings, referring site, UTM tags, browser type and approximate country (from your IP address at our edge; we do not store IP addresses with your activity). | Automatically, subject to your cookie choices |
| Consent records | What you chose, when, under which policy version, and whether a Global Privacy Control signal was present. | Automatically |
| Communications | Emails you send us; brief opens/clicks (clicks are measured by redirect links). | You / automatically |
| Vendor representatives | Business contact details of people who manage a company profile. | You or your employer |
| Privacy requests | The details you give when exercising your rights. | You |
Sensitive information. We do not ask for, and do not want, sensitive information (health, racial or ethnic origin, religious or political views, sexual orientation, biometrics, government identifiers, precise location). Please don’t post it; moderators remove it. We do not use sensitive personal information to infer characteristics about you.
3. How we use it and our legal bases
| Purpose | Data | Legal basis (GDPR/UK) |
|---|---|---|
| Provide the site and your account; sign-in; show and moderate contributions; remember what you follow | Identifiers, contributions, preferences | Contract (Art. 6(1)(b)) |
| Keep the community safe: spam, abuse, fake reviews, rate limits, vendor-affiliation labels | Account, contributions, usage | Legitimate interests (6(1)(f)); legal obligation where applicable |
| Analytics: understand what is popular and improve the site | Usage linked to a pseudonymous ID or your account | Consent (6(1)(a)) in opt-in regions; legitimate interests elsewhere with an easy opt-out. Without consent we only count visits without any identifier. |
| Personalisation: “For you”, rankings, the Monday brief | Preferences, usage | Consent / contract (for features you request) |
| Aggregated market insights for Techarda and its customers (see §4) | De-identified, aggregated usage, contributions and self-declared attributes (groups ≥ 5) | Legitimate interests; consent for employer-level counts |
| Service emails (sign-in links, moderation outcomes) and the Monday brief you ask for | Email, preferences | Contract; consent for the brief |
| Optional marketing emails: Techarda briefings, research and event invitations, and sponsored briefings and webinars (only if you opt in) | Email, name, job title, company, categories you follow and optional professional attributes, used to decide which messages are relevant to you | Consent (6(1)(a)), given separately for each choice |
| Handle privacy requests, legal claims, and comply with law | As needed | Legal obligation; legitimate interests |
We do not use your personal information for targeted advertising, and we do not sell it. Where we rely on legitimate interests you can object at any time (see §10).
Optional marketing choices
When you set up your account, and at any time in Account → Privacy & data, you can choose two kinds of email. Both boxes start unticked and each one is separate, so you can have one without the other:
- Briefings, research and events: “Email me Techarda briefings, research and event invitations on the topics I follow.”
- Sponsored briefings and webinars: “Tell me about sponsored briefings and webinars from companies in my categories.” Techarda sends these, not the sponsoring company. The sponsor doesn’t receive your name, email or any other detail from this choice.
We record each choice with the date and the version of the wording you saw. To withdraw, switch the choice off in Privacy & data, use the unsubscribe link in any of these emails, or email engage@techarda.com. Withdrawing is free, doesn’t affect your account or the Monday brief, and takes effect as soon as we process it (and always within the time the law allows, for example five business days under Australia’s Spam Act 2003).
Your details go to a company only with your say-so, one action at a time. If you register for a sponsored webinar or ask a company to contact you, the form tells you exactly what will be shared and with whom, and nothing is shared unless you tick “share” on that form. Ticking it once doesn’t cover anything else.
4. Community data and aggregated insights
Techarda is funded partly by helping technology companies understand market demand. To do that responsibly:
- When you post in the community, our software tags your post with topics, the companies it mentions, a buying stage (e.g. researching, comparing, evaluating) and a sentiment score. These tags are generated by transparent rules, stored with the post, and visible to our administrators.
- We combine these tags, reading activity and optional self-declared attributes into aggregated statistics, for example “questions about zero trust rose 40% this quarter” or “security directors at large financial-services firms read comparisons most”.
- Anything describing people (role, seniority, company size, industry, region) is only shown for groups of five or more; smaller groups are merged or hidden.
- Company-level (employer) interest only includes members who switched on “share employer” in their profile. That list is visible only to Techarda’s own team and is never given to vendors.
- Companies listed on Techarda never receive your name, email or identity, unless you choose to contact them (for example a contact request or a webinar registration, where we tell you exactly what will be shared at that moment).
- Public posts are, by nature, public: they can be read by anyone, including search engines and AI assistants, under your display name.
5. Cookies and consent
We use a handful of first-party cookies and no advertising or third-party tracking cookies. Details are in our Cookie Policy. In the EU/EEA, UK, Switzerland, Brazil, India, South Korea and China nothing beyond strictly necessary cookies runs until you choose; elsewhere analytics is on by default with a one-click opt-out. We honour Global Privacy Control and Do Not Track signals automatically. Change your choice any time: .
6. Who we share it with
- Service providers (processors) who host and run Techarda for us under contracts that restrict their use of data (see Subprocessors).
- Conversera (conversera.ai), a demand-generation agency, may act as our service provider to plan and run programmes that Techarda runs, such as sponsored briefings and webinars. It works on our instructions, may use member details only for those programmes and only for members who opted in, and may not use them for its own purposes, sell them or pass them on.
- The public: your published contributions and public profile.
- Companies you choose to contact: only what you submit to them, when you submit it, and only when you tick “share” for that registration or request.
- Customers of our insights: aggregated, de-identified statistics only (see §4).
- Authorities and advisers: where required by law, to protect rights and safety, or to our professional advisers under confidentiality.
- A successor: if Techarda is merged or sold, subject to this policy and with notice to you.
We do not sell personal information and do not “share” it for cross-context behavioural advertising (as those terms are used in California law).
7. International transfers
Our database and file storage are hosted in Sydney, Australia (Supabase on AWS ap-southeast-2). Our web application is served by Vercel from Sydney with a global edge network, and email is sent through Microsoft 365. Some providers may process data in other countries, including the United States. Where GDPR/UK GDPR applies we rely on adequacy decisions or the European Commission’s Standard Contractual Clauses (and the UK Addendum) with supplementary measures; for other regimes we take reasonable steps (APP 8, PIPEDA accountability, LGPD Art. 33, PDPA transfer obligations) to ensure recipients protect your information to a comparable standard.
8. How long we keep it
| Data | Retention |
|---|---|
| Account, profile, preferences, attributes | While your account is active; deleted when you delete your account |
| Community posts, reviews, Q&A | While published; on account deletion you choose to delete them or keep them as “Former member” |
| Usage events | Identifiers removed after 13 months; events deleted after 25 months (aggregated daily totals are kept without identifiers) |
| AI crawler logs | 25 months |
| In-app notifications | 180 days, or until you delete them or your account |
| Unconfirmed sign-ups | 30 days |
| Consent records | 6 years (proof of consent), without a link to a deleted account |
| Record of administrator access to member profiles and exports | 2 years |
| Privacy requests | 3 years after closure |
| Moderation reports | 2 years after resolution |
Retention runs automatically every day.
9. Security
We use encryption in transit (TLS) and at rest, row-level security so each account and each company can only reach its own data, least-privilege administrator access, passwordless sign-in, and audit-friendly logs. A small number of Techarda administrators can view member profiles, professional attributes, consent choices and account activity to operate the service (support, moderation, security and sending the emails you opted in to). Every time an administrator opens a member’s record or exports a list of members, we log who did it, when and what was included, and that log can’t be edited. Exports only ever include members who opted in to the purpose of the export. No system is perfectly secure; if a breach is likely to cause you serious harm we will notify you and the relevant regulators as required (for example under Australia’s Notifiable Data Breaches scheme and GDPR Arts. 33–34).
10. Your rights (everyone, wherever you live)
- Access & portability: download everything linked to your account instantly (JSON/CSV) from Privacy & data.
- Correction: edit your profile or ask us.
- Deletion: delete your account yourself, with the choice to keep or remove your posts.
- Objection, restriction and consent withdrawal: switch off analytics and personalisation, unsubscribe from emails in one click, switch off either optional email choice in Privacy & data, or ask us to restrict processing.
- Opt out of sale/sharing: we don’t sell or share, but see Do not sell or share.
- Appeal: if we refuse a request, reply to our decision to appeal; we respond within the legal deadline.
Make any request from your account or at Privacy requests (no account needed). We may need to verify your identity, and we accept requests from authorised agents with proof of authority. We respond within 30 days (15 in Brazil; 45 in US states, extendable where the law allows) and never charge for reasonable requests. We will not discriminate against you for exercising your rights.
11. Rights by jurisdiction
European Union, EEA, United Kingdom and Switzerland (GDPR / UK GDPR / FADP)
You have the rights of access, rectification, erasure, restriction, portability and objection (including to processing based on legitimate interests), and to withdraw consent at any time without affecting prior processing. You can complain to your local supervisory authority, the UK Information Commissioner’s Office or the Swiss FDPIC.
California and other US states (CCPA/CPRA; Virginia, Colorado, Connecticut, Utah, Texas, Oregon and others)
In the last 12 months we collected the categories in §2 (identifiers, commercial information such as follows and saves, internet or network activity, professional information, and inferences limited to topic and buying-stage tags) for the purposes in §3, from the sources listed. We disclosed them for business purposes to the service providers in §6. We have not sold or shared personal information, have no actual knowledge of selling or sharing information of consumers under 16, and do not use sensitive personal information. You have the right to know, delete, correct, opt out of sale/sharing and targeted advertising, limit use of sensitive information, and not be discriminated against; residents of other states have equivalent rights including appeal. Contact us or your state Attorney General if an appeal is denied.
Australia (Privacy Act 1988 and the APPs)
You can access and correct your information and complain about a breach of the APPs. If you are not satisfied with our response within 30 days, you can complain to the Office of the Australian Information Commissioner (oaic.gov.au). You can deal with us anonymously or pseudonymously where practicable. Browsing requires no account.
Canada (PIPEDA and provincial laws)
We obtain meaningful consent, limit collection to identified purposes, and you can access and challenge the accuracy of your information and withdraw consent. You can complain to the Office of the Privacy Commissioner of Canada.
Brazil (LGPD)
You may confirm processing, access, correct, anonymise, block or delete unnecessary data, port data, obtain information about sharing, and revoke consent. Complaints may be made to the ANPD.
Singapore (PDPA)
You may access and correct your data and withdraw consent; we notify significant breaches to the PDPC and affected individuals. Complaints may be made to the PDPC.
India (Digital Personal Data Protection Act 2023)
We process your data on the basis of your consent or legitimate uses, give you a clear notice, and you may access a summary of processing, correct and erase data, nominate another person to exercise your rights, and seek grievance redressal from us (contact engage@techarda.com) before approaching the Data Protection Board of India.
Other countries
Wherever you are, we extend the rights in §10 to you.
12. Children
Techarda is for professionals. You must be at least 16 to create an account, and 18 to post in the community. We do not knowingly collect information from children; if you believe a child has given us information, contact us and we will delete it.
13. AI crawlers, AI features and automated decisions
Public pages are intentionally readable by search engines and AI assistants; we log automated visits from known AI crawlers separately from human visits and never expose account details or unpublished content to them. We do not make decisions that produce legal or similarly significant effects about you solely by automated means. Automated tagging of posts (topics, buying stage, sentiment) is used only for aggregated statistics and content organisation. We do not use your personal information to train third-party AI models.
14. Changes to this policy
We will update the version and date above, keep a change history below, and tell signed-in members about material changes before they take effect.
15. Contact and complaints
Privacy team: engage@techarda.com · Privacy request form · Techarda, Sydney, New South Wales, Australia. Please contact us first so we can try to resolve your concern; you can always complain to the regulator where you live.
Version history
- v2.3 · 27 Sept 2026: Two optional, separate email choices (briefings and events; sponsored briefings and webinars) and how to withdraw them; administrator access to member profiles and logging of access and exports; Conversera as a possible service provider for programmes Techarda runs; member details go to a company only with per-action consent.
- v2.2 · 27 Sept 2026: In-app notifications and their 180-day retention.
- v2.1 · 27 Sept 2026: Optional Sign in with LinkedIn and the work-email requirement for new accounts.
- v2.0 · 27 Sept 2026: Rewritten: community, consent regimes, GPC, member attributes, aggregated intelligence, jurisdiction-specific rights (GDPR/UK, CCPA/CPRA and US states, Australia, Canada, Brazil, Singapore, India), retention schedule, transfers.
- v1.1 · 26 Sept 2026: Monday brief and reading activity added.
- v1.0 · 26 Sept 2026: First version.
When we make material changes we update the version and date above and, for changes that affect how we use your personal information, tell signed-in members by email or on the site before they take effect.