Legal

Privacy Policy

Version 2.3 · Last updated 27 September 2026 · All legal documents

This policy explains how Techarda (“Techarda”, “we”, “us”) collects, uses, shares and protects personal information when you visit techarda.com, create an account, take part in the community, receive our emails, or use our APIs and feeds. It is written to meet the Australian Privacy Principles (APPs) in the Privacy Act 1988 (Cth), the EU and UK General Data Protection Regulations (GDPR / UK GDPR), the California Consumer Privacy Act as amended by the CPRA and other US state privacy laws, Canada’s PIPEDA, Brazil’s LGPD, Singapore’s PDPA and India’s Digital Personal Data Protection Act 2023. The short version: we collect little, we never sell personal information, companies only ever see aggregated statistics, and you can see, download or delete your data yourself at any time from Account → Privacy & data.

1. Who we are

Techarda, Sydney, New South Wales, Australia, is the controller (APP entity / “business”) responsible for your personal information. Contact our privacy team at engage@techarda.com.

2. What we collect

CategoryExamplesSource
Identifiers & accountEmail address; display name; handle; optional headline, job title and avatar. We sign you in with one-time email links and never store a password.You
Sign in with LinkedIn (optional)If you choose “Continue with LinkedIn”, LinkedIn shares your name, profile photo, email address and language setting with us (OpenID Connect scopes openid, profile, email). We use them only to create and pre-fill your account. We never post to LinkedIn, read your connections or share LinkedIn data with vendors, and it is deleted with your account. You can disconnect Techarda in your LinkedIn settings at any time.LinkedIn, at your request
Work-email checkNew accounts need an organisation email address. We check only the part after the @ against a list of personal and disposable email providers; the address itself is not sent anywhere.You
Professional attributes (optional)Job function, seniority, company size, industry, country and employer, all self-declared and optional. Your employer is only used in company-level counts if you switch on “share employer”.You
ContributionsCommunity threads, replies, polls, votes, “helpful” marks, reviews, questions, answers, reports you make; the public profile they appear under.You
Preferences & relationshipsCategories, companies and spaces you follow; saved stories; your Monday brief choice and your two optional email choices (see “Optional marketing choices” below), each with the date you made it.You
Usage & devicePages viewed, searches, filters, outbound clicks, whether you returned from a source article and how long you were away, ratings, referring site, UTM tags, browser type and approximate country (from your IP address at our edge; we do not store IP addresses with your activity).Automatically, subject to your cookie choices
Consent recordsWhat you chose, when, under which policy version, and whether a Global Privacy Control signal was present.Automatically
CommunicationsEmails you send us; brief opens/clicks (clicks are measured by redirect links).You / automatically
Vendor representativesBusiness contact details of people who manage a company profile.You or your employer
Privacy requestsThe details you give when exercising your rights.You

Sensitive information. We do not ask for, and do not want, sensitive information (health, racial or ethnic origin, religious or political views, sexual orientation, biometrics, government identifiers, precise location). Please don’t post it; moderators remove it. We do not use sensitive personal information to infer characteristics about you.

3. How we use it and our legal bases

PurposeDataLegal basis (GDPR/UK)
Provide the site and your account; sign-in; show and moderate contributions; remember what you followIdentifiers, contributions, preferencesContract (Art. 6(1)(b))
Keep the community safe: spam, abuse, fake reviews, rate limits, vendor-affiliation labelsAccount, contributions, usageLegitimate interests (6(1)(f)); legal obligation where applicable
Analytics: understand what is popular and improve the siteUsage linked to a pseudonymous ID or your accountConsent (6(1)(a)) in opt-in regions; legitimate interests elsewhere with an easy opt-out. Without consent we only count visits without any identifier.
Personalisation: “For you”, rankings, the Monday briefPreferences, usageConsent / contract (for features you request)
Aggregated market insights for Techarda and its customers (see §4)De-identified, aggregated usage, contributions and self-declared attributes (groups ≥ 5)Legitimate interests; consent for employer-level counts
Service emails (sign-in links, moderation outcomes) and the Monday brief you ask forEmail, preferencesContract; consent for the brief
Optional marketing emails: Techarda briefings, research and event invitations, and sponsored briefings and webinars (only if you opt in)Email, name, job title, company, categories you follow and optional professional attributes, used to decide which messages are relevant to youConsent (6(1)(a)), given separately for each choice
Handle privacy requests, legal claims, and comply with lawAs neededLegal obligation; legitimate interests

We do not use your personal information for targeted advertising, and we do not sell it. Where we rely on legitimate interests you can object at any time (see §10).

Optional marketing choices

When you set up your account, and at any time in Account → Privacy & data, you can choose two kinds of email. Both boxes start unticked and each one is separate, so you can have one without the other:

  • Briefings, research and events: “Email me Techarda briefings, research and event invitations on the topics I follow.”
  • Sponsored briefings and webinars: “Tell me about sponsored briefings and webinars from companies in my categories.” Techarda sends these, not the sponsoring company. The sponsor doesn’t receive your name, email or any other detail from this choice.

We record each choice with the date and the version of the wording you saw. To withdraw, switch the choice off in Privacy & data, use the unsubscribe link in any of these emails, or email engage@techarda.com. Withdrawing is free, doesn’t affect your account or the Monday brief, and takes effect as soon as we process it (and always within the time the law allows, for example five business days under Australia’s Spam Act 2003).

Your details go to a company only with your say-so, one action at a time. If you register for a sponsored webinar or ask a company to contact you, the form tells you exactly what will be shared and with whom, and nothing is shared unless you tick “share” on that form. Ticking it once doesn’t cover anything else.

4. Community data and aggregated insights

Techarda is funded partly by helping technology companies understand market demand. To do that responsibly:

  • When you post in the community, our software tags your post with topics, the companies it mentions, a buying stage (e.g. researching, comparing, evaluating) and a sentiment score. These tags are generated by transparent rules, stored with the post, and visible to our administrators.
  • We combine these tags, reading activity and optional self-declared attributes into aggregated statistics, for example “questions about zero trust rose 40% this quarter” or “security directors at large financial-services firms read comparisons most”.
  • Anything describing people (role, seniority, company size, industry, region) is only shown for groups of five or more; smaller groups are merged or hidden.
  • Company-level (employer) interest only includes members who switched on “share employer” in their profile. That list is visible only to Techarda’s own team and is never given to vendors.
  • Companies listed on Techarda never receive your name, email or identity, unless you choose to contact them (for example a contact request or a webinar registration, where we tell you exactly what will be shared at that moment).
  • Public posts are, by nature, public: they can be read by anyone, including search engines and AI assistants, under your display name.

5. Cookies and consent

We use a handful of first-party cookies and no advertising or third-party tracking cookies. Details are in our Cookie Policy. In the EU/EEA, UK, Switzerland, Brazil, India, South Korea and China nothing beyond strictly necessary cookies runs until you choose; elsewhere analytics is on by default with a one-click opt-out. We honour Global Privacy Control and Do Not Track signals automatically. Change your choice any time: .

6. Who we share it with

  • Service providers (processors) who host and run Techarda for us under contracts that restrict their use of data (see Subprocessors).
  • Conversera (conversera.ai), a demand-generation agency, may act as our service provider to plan and run programmes that Techarda runs, such as sponsored briefings and webinars. It works on our instructions, may use member details only for those programmes and only for members who opted in, and may not use them for its own purposes, sell them or pass them on.
  • The public: your published contributions and public profile.
  • Companies you choose to contact: only what you submit to them, when you submit it, and only when you tick “share” for that registration or request.
  • Customers of our insights: aggregated, de-identified statistics only (see §4).
  • Authorities and advisers: where required by law, to protect rights and safety, or to our professional advisers under confidentiality.
  • A successor: if Techarda is merged or sold, subject to this policy and with notice to you.

We do not sell personal information and do not “share” it for cross-context behavioural advertising (as those terms are used in California law).

7. International transfers

Our database and file storage are hosted in Sydney, Australia (Supabase on AWS ap-southeast-2). Our web application is served by Vercel from Sydney with a global edge network, and email is sent through Microsoft 365. Some providers may process data in other countries, including the United States. Where GDPR/UK GDPR applies we rely on adequacy decisions or the European Commission’s Standard Contractual Clauses (and the UK Addendum) with supplementary measures; for other regimes we take reasonable steps (APP 8, PIPEDA accountability, LGPD Art. 33, PDPA transfer obligations) to ensure recipients protect your information to a comparable standard.

8. How long we keep it

DataRetention
Account, profile, preferences, attributesWhile your account is active; deleted when you delete your account
Community posts, reviews, Q&AWhile published; on account deletion you choose to delete them or keep them as “Former member”
Usage eventsIdentifiers removed after 13 months; events deleted after 25 months (aggregated daily totals are kept without identifiers)
AI crawler logs25 months
In-app notifications180 days, or until you delete them or your account
Unconfirmed sign-ups30 days
Consent records6 years (proof of consent), without a link to a deleted account
Record of administrator access to member profiles and exports2 years
Privacy requests3 years after closure
Moderation reports2 years after resolution

Retention runs automatically every day.

9. Security

We use encryption in transit (TLS) and at rest, row-level security so each account and each company can only reach its own data, least-privilege administrator access, passwordless sign-in, and audit-friendly logs. A small number of Techarda administrators can view member profiles, professional attributes, consent choices and account activity to operate the service (support, moderation, security and sending the emails you opted in to). Every time an administrator opens a member’s record or exports a list of members, we log who did it, when and what was included, and that log can’t be edited. Exports only ever include members who opted in to the purpose of the export. No system is perfectly secure; if a breach is likely to cause you serious harm we will notify you and the relevant regulators as required (for example under Australia’s Notifiable Data Breaches scheme and GDPR Arts. 33–34).

10. Your rights (everyone, wherever you live)

  • Access & portability: download everything linked to your account instantly (JSON/CSV) from Privacy & data.
  • Correction: edit your profile or ask us.
  • Deletion: delete your account yourself, with the choice to keep or remove your posts.
  • Objection, restriction and consent withdrawal: switch off analytics and personalisation, unsubscribe from emails in one click, switch off either optional email choice in Privacy & data, or ask us to restrict processing.
  • Opt out of sale/sharing: we don’t sell or share, but see Do not sell or share.
  • Appeal: if we refuse a request, reply to our decision to appeal; we respond within the legal deadline.

Make any request from your account or at Privacy requests (no account needed). We may need to verify your identity, and we accept requests from authorised agents with proof of authority. We respond within 30 days (15 in Brazil; 45 in US states, extendable where the law allows) and never charge for reasonable requests. We will not discriminate against you for exercising your rights.

11. Rights by jurisdiction

European Union, EEA, United Kingdom and Switzerland (GDPR / UK GDPR / FADP)

You have the rights of access, rectification, erasure, restriction, portability and objection (including to processing based on legitimate interests), and to withdraw consent at any time without affecting prior processing. You can complain to your local supervisory authority, the UK Information Commissioner’s Office or the Swiss FDPIC.

California and other US states (CCPA/CPRA; Virginia, Colorado, Connecticut, Utah, Texas, Oregon and others)

In the last 12 months we collected the categories in §2 (identifiers, commercial information such as follows and saves, internet or network activity, professional information, and inferences limited to topic and buying-stage tags) for the purposes in §3, from the sources listed. We disclosed them for business purposes to the service providers in §6. We have not sold or shared personal information, have no actual knowledge of selling or sharing information of consumers under 16, and do not use sensitive personal information. You have the right to know, delete, correct, opt out of sale/sharing and targeted advertising, limit use of sensitive information, and not be discriminated against; residents of other states have equivalent rights including appeal. Contact us or your state Attorney General if an appeal is denied.

Australia (Privacy Act 1988 and the APPs)

You can access and correct your information and complain about a breach of the APPs. If you are not satisfied with our response within 30 days, you can complain to the Office of the Australian Information Commissioner (oaic.gov.au). You can deal with us anonymously or pseudonymously where practicable. Browsing requires no account.

Canada (PIPEDA and provincial laws)

We obtain meaningful consent, limit collection to identified purposes, and you can access and challenge the accuracy of your information and withdraw consent. You can complain to the Office of the Privacy Commissioner of Canada.

Brazil (LGPD)

You may confirm processing, access, correct, anonymise, block or delete unnecessary data, port data, obtain information about sharing, and revoke consent. Complaints may be made to the ANPD.

Singapore (PDPA)

You may access and correct your data and withdraw consent; we notify significant breaches to the PDPC and affected individuals. Complaints may be made to the PDPC.

India (Digital Personal Data Protection Act 2023)

We process your data on the basis of your consent or legitimate uses, give you a clear notice, and you may access a summary of processing, correct and erase data, nominate another person to exercise your rights, and seek grievance redressal from us (contact engage@techarda.com) before approaching the Data Protection Board of India.

Other countries

Wherever you are, we extend the rights in §10 to you.

12. Children

Techarda is for professionals. You must be at least 16 to create an account, and 18 to post in the community. We do not knowingly collect information from children; if you believe a child has given us information, contact us and we will delete it.

13. AI crawlers, AI features and automated decisions

Public pages are intentionally readable by search engines and AI assistants; we log automated visits from known AI crawlers separately from human visits and never expose account details or unpublished content to them. We do not make decisions that produce legal or similarly significant effects about you solely by automated means. Automated tagging of posts (topics, buying stage, sentiment) is used only for aggregated statistics and content organisation. We do not use your personal information to train third-party AI models.

14. Changes to this policy

We will update the version and date above, keep a change history below, and tell signed-in members about material changes before they take effect.

15. Contact and complaints

Privacy team: engage@techarda.com · Privacy request form · Techarda, Sydney, New South Wales, Australia. Please contact us first so we can try to resolve your concern; you can always complain to the regulator where you live.