Privacy & Security Statement

– as of January 2025
Alex Solutions Pty Ltd (the “Company”, “We”, “Alex Solutions”, “Alex”) is committed to protecting the privacy of individuals who visit the our Websites (“Visitors”), individuals who register to use the Services as defined below (“Customers”), and individuals who register to attend the Alex’s corporate events (“Attendees”).

This Privacy Statement combined with Security Policy describes how we collect, use, store, and protect personal and customer data across our Services, websites, and infrastructure. It also outlines your rights regarding data access, export, deletion, and communications, and defines the technical, procedural, and organizational controls we implement to protect our Customer’s Data.

1. Websites covered

 

This Statement covers the information practices of websites that link to it, including alexsolutions.com and websites deployed to deliver Services to our Customers (“Alex Instances”); collectively referred to as ”Alex’s Websites” or “Alex Solutions’ Websites”.

 

Alex’s Websites may contain links to other websites. The information practices or the content of such other websites is governed by the privacy statements of those other websites. Alex Solutions encourages the review of the privacy statements of other websites to understand their information practices.

2. Information collected

 

When expressing an interest in obtaining additional information about the Services, or registering to use Alex’s Websites or other Services, or registering for an event, we may require Visitors, Customers, and Attendees to provide Alex Solutions with personal contact information, such as name, company name, address, phone number, and email address (“Required Contact Information”).


When purchasing the Services or registering for an event, we may also require Customers to provide Alex Solutions with financial qualification and billing information, such as billing name and address, and the number of employees within the organisation that will be using the Services (“Billing Information”).
We may also ask Visitors, Customers, and Attendees to provide additional information, such as company annual revenues, number of employees, or industry (“Optional Information”).


When Visitors apply for a job with Alex Solutions, we may also require applicants to submit additional personal information as well as a resume or curriculum vitae (“Applicant Information”). Required Contact Information, Billing Information, Applicant Information, Optional Information and any other information submitted to Alex Solutions to or through the Services is referred to collectively as “Data.”


During navigation of the Alex’s Websites, we may also collect information through the use of commonly-used information-gathering tools, such as cookies and web beacons (“Website Navigational Information”). Website Navigational Information includes standard information from your web browser (such as browser type and browser language), your Internet Protocol (“IP”) address, and the actions you take on the Alex’s Websites (such as the web pages viewed and the links clicked). For additional information about the collection of Website Navigational Information by Alex Solutions and others, please see the table in the related section below.

3. Use of information collected

 

Alex Solutions uses Data about Customers to perform the services requested. For example, if you fill out a “Contact Me” Web form, Alex Solutions will use the information provided to contact you about your interest in the Services.


Alex Solutions also uses Data about Attendees to plan and host corporate events, host online forums and social networks in which event Attendees may participate, and to populate online profiles for Attendees on Alex’s Websites. Additional information on Alex Solutions’ privacy practices with respect to Data about Attendees may be found in additional privacy statements on the event Websites, as the case may be. Please see item number 5 for more information on bulletin boards, blogs, or chat rooms provided by Alex Solutions in connection with its corporate events.


Alex Solutions may also use Data about Customers and Data about Attendees for marketing purposes. For example, we may use information you provide to contact you to further discuss your interest in the Services and to send you information regarding Alex Solutions, its affiliates, and its partners, such as information about promotions or events.


Alex Solutions uses Website Navigational Information to operate and improve Alex’s Websites. We may also use Website Navigational Information alone or in combination with Data about Customers and Data about Attendees to provide personalised information about Alex Solutions.

4. Website navigational information

 

Cookies, web Beacons and IP Addresses
Alex Solutions uses commonly-used information-gathering tools, such as cookies and web beacons, to collect information during navigation of Alex’s Websites (“Website Navigational Information”). This section describes the types of Website Navigational Information used on Alex’s Websites and how this information may be used.
Cookies
Alex Solutions uses cookies to make interactions with Alex’s Websites easy and meaningful. When visiting one of Alex’s Websites, Alex’s servers send a cookie to the client computer. Standing alone, cookies do not personally identify a user; they merely recognize the user’s web browser. Unless the user chooses to identify themselves to alexsolutions.com, either by responding to a promotional offer, opening an account, or filling out a web form (such as a “Contact Me” or a “Request a demo” web form), the user remains anonymous to us.
Alex Solutions uses cookies that are session-based and persistent-based. Session cookies exist only during one session. They disappear from the user’s computer when the user closes their browser software or turns off their computer. Persistent cookies remain on the user’s computer after the user closes their browser or turns off their computer.
The following sets out how Alex’s Websites uses different categories of cookies and your options for managing cookies’ settings:

 

Type of Cookies

Description

Managing Settings

Required Cookies

Required cookies enable users to navigate the Company’s Websites and use its features, such as accessing secure areas of the Websites and using Services.

If users have chosen to identify themselves to the Company, the Company uses cookies containing encrypted information to allow the Company to uniquely the user. Each time a user logs into the Services, a cookie containing an encrypted, unique identifier that is tied to a user’s account is placed on the user’s browser. These cookies allow the Company to uniquely identify the user when the user is logged into the Services and to process online requests.

Because required cookies are essential to operate the Company’s Websites and the Services, there is no option to opt out of these cookies.
Performance cookies

These cookies collect information about how Visitors use the Company’s Website, including which pages visitors go to most often and if they receive error messages from certain pages. These cookies do not collect information that individually identifies a Visitor. All information these cookies collect is aggregated and anonymous. It is only used to improve how the Company’s Website functions and performs.

From time-to-time, the Company may engage third parties to track and analyze usage and volume statistical information from individuals who visit the Company’s Websites. The Company may also utilise Flash cookies for these purposes.

To learn how to opt out of performance cookies using your browser settings click here.

To learn how to manage privacy and storage settings for Flash cookies click here.

Functionality cookies

Functionality cookies allow the Company’s Websites to remember information users have entered or choices users make (such as username, language, or region) and provide enhanced, more personal features.  These cookies also enable users to optimise their use of Services after logging in. These cookies can also be used to remember changes users have made to text size, fonts and other parts of web pages that users can customize.

The Company uses local shared objects, also known as Flash cookies, to store user preferences or display content based upon what users view on Websites to personalise user visits.

To learn how to opt out of functionality cookies using your browser settings click here. Note that opting out may impact the functionality you receive when using the Company’s Websites.

To learn how to manage privacy and storage settings for Flash cookies click here.

   

5. IP Addresses

 

 

When users visit the Alex’s Websites, Alex Solutions collects user Internet Protocol (“IP”) addresses to track and aggregate non-personal information. For example, we use IP addresses to monitor the regions from which Customers and Visitors navigate the Alex’s Web sites.
Alex Solutions also collects IP addresses from Customers when they log into the Services as part of the Alex Solutions’ “Identity Confirmation” and “IP Range Restrictions” security features.


Data from the Services (Usage logs and Analytics Data). Alex Solutions also collects and processes usage data when Customers use the Services (e.g., ingest volume, search concurrency, number of unique user logins, operating system, internet protocol address, source type (count), session duration and other use data) (“Usage Data”) in order to provide, maintain, and improve Services.


In addition, Alex Solutions collects and processes anonymised, aggregated data about a group or category of Services, features or users in order to improve the Services (“Analytics Data”). For example, Analytics Data may include anonymized Usage Data, information about the server environment (e.g., OS type/version, CPU type/version, database type/version, disk utilisation), information about the devices operating the Services (e.g., browser type/version, OS type/version, device type/version), or such other similar information about user configuration or operation of the Service features or functionality.

6. Customer testimonials

 

We may post a list of Customers and testimonials on Alex’s Web sites that contain information such as Customer names and titles. Alex Solutions always obtains the consent of each Customer prior to posting any information on such a list or posting testimonials.

7. Sharing of information collected

 

Service Providers, Affiliates, Business Partners


Alex Solutions will not share Data about Visitors, Customers and Attendees unless formal consent has been obtained beforehand. We do not share, sell, rent, or trade any information with third parties.


Compelled Disclosure


Alex Solutions reserves the right to use or disclose information provided if required by law or if Alex Solutions reasonably believes that use or disclosure is necessary to protect our rights and/or to comply with a judicial proceeding, court order, or legal process.

8. Communications preferences

 

Alex Solutions offers Visitors, Customers, and Attendees who provide contact information a means to choose how Alex Solutions uses the information provided. Visitors, Customers, and Attendees may manage receipt of marketing and non-transactional communications by clicking on the “unsubscribe” link located on the bottom of our marketing emails. Additionally, Visitors, Customers, and Attendees may end a request to [email protected].

9. Customer Data Security Policy

 

Governance & Framework

 

Alex Solutions operates under a certified and actively managed information security management system (ISMS):

  • ISO/IEC 27001:2022 certified, with annual third-party audits
  • Alignment with GDPR, HIPAA, PCI DSS, DORA, and Australian Privacy Principles (APPs)
  • Risk management, incident response, and security oversight are governed by our Chief Security Officer (CSO), Engineering Leadership, and a dedicated Security Committee
  • All exceptions, risk decisions, and remediations are tracked through a formal governance process

Data Protection

 

Customer Data means all electronic data, records, files or information submitted by or on behalf of a Customer into the Services for hosting, processing, analysis or safe‑keeping. All Customer Data remains the property of the Customer and is logically segregated so no Customer can access another’s data. We only access this data to deliver services (including hosting), resolve technical issues, or where required by law. Our platform ensures protection through:

  • Encryption in transit using TLS 1.2+ and AES-256 encryption at rest across all databases, backups, and file stores
  • API credentials and secrets are encrypted at all times during storage and transmission
  • Customers may export their data at any time during their subscription period
  • Within 30 days post contract termination, Customers may request return of their respective Customer Data, to the extent such Customer Data can be copied and exported
  • Data will be retained for 60 days post-subscription termination. Requests for earlier deletion will be honoured subject to applicable laws or based on the agreement terms

Identity, Access & Authentication

We apply strong, flexible access controls to ensure that only the right individuals can access customer data:

  • SSO integration via SAML 2.0 / OIDC
  • Role-Based Access Control (RBAC) down to the attribute level, with optional support for Attribute-Based Access Control (ABAC)
  • Passwords are securely hashed using a salted SHA-256 or stronger algorithm, never stored in plain text, and never logged
  • User authentication events and policy changes are fully auditable

Monitoring, Auditing & Incident Response

 

Security monitoring is embedded in our operational model:

  • Logs are stored centrally, are tamper-protected, and access is restricted to authorized security personnel
  • We maintain a documented incident response process, including triage, containment, remediation, and customer notification
  • Customers are encouraged to report any suspected misuse or anomalies by contacting [email protected]

Infrastructure & Architecture

 

In cloud deployments, Alex Platform is hosted in Amazon Web Services (AWS) SOC2-certified data centers in customers’ preferred region. Our infrastructure is designed for both physical and logical resilience:

  • Data centers feature 24/7 security monitoring, biometric access control, escorted entry, and redundant power and climate systems
  • Our services run in segmented VPCs, with hardened configurations, firewalls, and continuous vulnerability scanning
  • Twice a day backups are encrypted and retained locally for 60 days and retained 5 days offsite to ensure recoverability

Continuous Improvement & Vulnerability Management


Alex Solutions implements a rigorous Secure Development Lifecycle (SDLC) and Vulnerability Management Program:

  • Secure development practices include peer-reviewed code, Static Application Security Testing (SAST), and Software Composition Analysis (SCA) for third-party dependencies
  • Annual third-party penetration tests are conducted to identify unknown threats
  • Vulnerabilities are triaged using CVSS v3 and addressed under strict timelines
  • Patch management follows structured SLAs
  • All security changes undergo integrity checks, backups, and auditing
  • The Chief Security Officer and Engineering Management enforce remediation SLAs and approve any exceptions through formal governance

Customer Responsibilities

Security is a shared responsibility. To protect your own environment and data, we ask our customers to:

  • Use strong, unique passwords for platform access
  • Configure user roles and data access responsibly
  • Promptly report any unusual activity to [email protected]

10. Compliance & Certifications

 

We uphold the following standards:

 

  • ISO/IEC 27001:2022 certified Information Security Management System
  • Adherence to GDPR, HIPAA, PCI DSS, DORA and Australian Privacy Principles (APPs)
  • Documentation to support audits, compliance reviews, and customer obligations under data residency or industry-specific laws
  • Secure export tools, logging, and metadata-level tracking that support audit readiness

 

Audit reports and security documentation are available under NDA at [email protected].

11. Changes to this Statement

 

Alex Solutions reserves the right to change this Statement. Alex Solutions will provide notification of the material changes to this Statement through Alex’s Web sites at least thirty (30) business days prior to the change taking effect.