How we collect, use, store and disclose your personal information.
Last updated: 18 August 2026PRATHAM TECHNOLOGIES PTY LTD trading as CorpArray (ABN 89 691 841 059, "CorpArray", "we", "us", "our") respects your privacy. This policy explains what personal information we collect, why, how we protect it, and your rights — in line with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth).
As a Trust and Company Service Provider regulated under the AML/CTF Tranche 2 reforms, we also collect and handle certain information as part of our legal customer due diligence obligations — this policy explains that too.
| Category | Examples | When |
|---|---|---|
| Contact details | Name, email, phone, company name | Contact form, "Get Started" service request, lead magnet downloads, newsletter signup |
| Enquiry / request details | The service you're asking about, your message, free-text details you provide | Any form submission |
| Identity & verification documents | Certified copies of passport/driver's licence, proof of address, director/beneficial-owner details | Only if you engage us for a service requiring AML/CTF customer due diligence (e.g. company incorporation) — never collected from a casual enquiry |
| Payment information | Processed by Stripe — we do not store full card details ourselves | When you're invoiced for a service |
| Communications | Emails, live-chat messages, call notes | Any time you contact us |
| Website usage | Pages visited, general device/browser info, live-chat session data | Automatically, via the tools listed in Section 3 |
We do not sell your personal information, ever.
We use the following third-party services to run our business. Each only receives the information needed for its purpose:
| Service | Purpose | What it receives |
|---|---|---|
| HubSpot | Our CRM — the system of record for contacts and enquiries | Contact details, enquiry details, service requested |
| Stripe | Payment processing | Billing details and payment information (PCI-DSS compliant; we don't see or store full card numbers) |
| DocuSeal | Electronic signatures on documents (consents, resolutions, agreements) | The document being signed and signer contact details |
| Tawk.to | Live chat widget on our website | Chat messages and general visitor/session information |
| Google Drive | Encrypted internal backup of business records | Business records as part of our backup process — access-restricted to us only |
| AI drafting tools (Anthropic Claude, Google Gemini, and/or DeepSeek) | Preparing first drafts of documents (structuring advice, compliance checklists, correspondence) from the details you provide | The information needed to draft that specific document. These tools assist with drafting only — every document is reviewed by us, and nothing is filed, lodged, or sent to you without human review. We do not use these tools to make decisions about your matter. |
We may also disclose information where required by law — including to AUSTRAC under our AML/CTF reporting obligations, to ASIC as part of a lodgement you've asked us to make, or to a regulator, court, or law enforcement body with a lawful basis to request it.
Where a service involves cross-border work (for example, FEMA/RBI/ODI advisory), we may share relevant information with a corridor partner (such as an Indian CA/CS firm or Authorised Dealer bank) strictly to progress that engagement, and only with your knowledge as part of that service.
Some of the services above (including the AI drafting tools listed in Section 3) may process information on servers located outside Australia, including in the United States. Where this happens, we take reasonable steps to ensure the recipient handles your information consistently with the Australian Privacy Principles. If you have concerns about overseas handling of your information, contact us using the details in Section 9 before providing it.
No online system is 100% secure, and we can't guarantee absolute security — but we take reasonable, proportionate steps appropriate to a firm of our size handling this kind of information.
Records connected to an AML/CTF customer due diligence obligation are retained for at least 7 years after the engagement ends, as required by AUSTRAC. General enquiry and marketing contact information is kept only as long as it remains relevant, or until you ask us to delete it (subject to Section 7).
Under the Australian Privacy Principles, you can:
Some requests may be limited where we have a legal obligation to retain information (for example, AML/CTF records within the 7-year retention period).
Our live chat widget (Tawk.to) uses cookies to maintain your chat session. We don't currently run third-party advertising trackers. If that changes, this policy will be updated first.
If you have a concern about how we've handled your personal information, contact us first — we'll aim to resolve it directly:
PRATHAM TECHNOLOGIES PTY LTD trading as CorpArray
5 Bando Road, Girraween, Sydney NSW 2145, Australia
contact@corparray.com.au · +61 434 945 317
If you're not satisfied with our response, you can lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
We may update this policy as our services or obligations change. The "Last updated" date at the top will always reflect the current version. Material changes affecting how we handle an active engagement will be communicated to you directly.
This policy describes our current practices as at the date above. It is provided for transparency and does not itself create a contract. If you have questions before providing personal information, contact us first.