Government and Law-Enforcement Data Request Policy
Version: 1.0
Effective date: 19 August 2026
Last reviewed: 19 August 2026
This Government and Law-Enforcement Data Request Policy explains how Aperim Pty Ltd, which operates the aicial brand, evaluates and responds to a request from a government authority or law-enforcement agency for personal information we hold. It should be read together with our Privacy Policy, which describes our handling of personal information more generally.
1. About this policy
Aperim Pty Ltd (ABN 46150699737; ACN 150699737) is incorporated in New South Wales, Australia and operates the aicial brand. In this policy, “aicial” refers to that brand; “we”, “us” and “our” refer to Aperim Pty Ltd; and “you” refers to a customer or other individual whose personal information may be the subject of a request described in this policy.
Our Privacy Policy’s sharing and disclosure section explains that we may disclose personal information where required or authorised by law, or where reasonably necessary to protect rights, safety, security and the integrity of our services. This policy sets out, in more detail, how we handle a request from a government authority or law-enforcement agency, including grounds not itemised in that section: the standard we apply to a request, how we handle a genuine emergency, how we notify an affected customer, and how we report on requests in aggregate.
This policy applies to a request for personal information or other customer data we hold, whether we hold it as controller in our own right or as a customer’s processor or service provider. It applies wherever the requesting authority is located, including within Australia and overseas.
2. Our general position
We scrutinise every government or law-enforcement request for personal information before responding to it. We disclose only what a request legally requires us to disclose, and only to the extent it legally requires. We do not treat a request as an invitation to provide more than the request itself compels.
Australian privacy law supports this approach. Australian Privacy Principle 6.2(b) permits disclosure that is required or authorised by or under an Australian law or a court or tribunal order, as our Privacy Policy notes; this, together with the distinct basis described in section 4, is the ground we rely on to respond to a government or law-enforcement request. Australian Privacy Principle 6.2(e) would also permit us to disclose personal information where we reasonably believe it is reasonably necessary for an enforcement related activity conducted by, or on behalf of, an Australian enforcement body, without the requester first obtaining a warrant, court order or other compulsory process. We hold ourselves to a higher standard than that: outside a genuine emergency assessed under section 4, we do not disclose personal information on the strength of Australian Privacy Principle 6.2(e) alone.
3. What we require of a valid request
Except where section 4 (Emergency requests) applies, we require a request to be legally valid and binding under applicable law before we disclose personal information in response to it. In Australia, that generally means a warrant, a court order, or another form of legally binding compulsory process. A request expressed only as a general inquiry, or a request that does not carry legal force, does not meet this standard.
We review each request for its legal basis, scope and specificity. Where a request is overly broad, vague or otherwise legally deficient — for example, because it does not identify a legal basis, does not clearly identify the information sought, or seeks more than the law allows for that type of process — we push back on it and ask the requesting authority to narrow or correct it. Where appropriate, we may challenge a request, including by seeking to have it narrowed or set aside through the applicable legal process.
4. Emergency requests
Where a government or law-enforcement authority describes a genuine emergency involving a risk of death or serious physical harm to a person, we may, in our discretion and consistent with applicable law, respond to that request without the requester first obtaining a warrant, court order or other compulsory process, provided we reasonably believe the emergency described is genuine.
This reflects a permitted general situation under the Privacy Act 1988 (Cth), which applies where we reasonably believe disclosure is necessary to lessen or prevent a serious threat to an individual’s life, health or safety, or to public health or safety generally, and it is unreasonable or impracticable to obtain the individual’s consent; we apply a narrower trigger within that ground, limited to a risk of death or serious physical harm. It does not lower the standard described in section 2: even where we respond to an emergency request without a court order, we disclose only the personal information reasonably necessary to address the emergency described.
We are not obliged to treat any request as an emergency. We may decline to do so, or may seek to verify the emergency, where we are not reasonably satisfied that it is genuine.
Where we hold the information as a customer’s processor or service provider, we exercise this discretion only to the extent our Data Processing Agreement permits — that is, only where responding is itself something a law binding on us requires, not merely something the law permits us to choose to do.
5. Notifying you before disclosure
Where legally permitted, we notify the affected party before we disclose personal information in response to a government or law-enforcement request, so that party has an opportunity to challenge the request itself, including by seeking to have it narrowed or set aside. Where we hold the information as controller, we notify you directly. Where we hold the information as a customer’s processor or service provider, we notify that customer instead — consistent with our Data Processing Agreement and with the approach described in our Privacy Policy, under which an individual whose information appears in a customer’s connected account or content directs privacy requests to that customer in the first instance — and the customer is responsible for any further notice to the affected individual.
We do not give that notice where we are legally prohibited from doing so — for example, by a non-disclosure order accompanying the request — or where we reasonably believe that giving notice would create a genuine risk to someone’s safety.
6. No backdoor access and no bulk data
We do not provide a government or law-enforcement agency with ongoing, direct or automated access to our systems, and we do not build or maintain a “backdoor” into aicial for that or any other purpose.
We do not provide bulk data in response to a request. Every disclosure we make responds either to a legally valid request that is sufficiently specific about the information sought, assessed against the standard described in section 3, or to a genuine emergency assessed under section 4.
7. Jurisdiction
We are based in Australia. A request from a government or law-enforcement authority outside Australia is assessed against Australian law and any applicable mutual legal assistance process between Australia and the requesting country.
Where the law of the requesting jurisdiction is directly binding on us — for example, because we or the personal information sought have a sufficient connection to that jurisdiction — we also assess the request against that law. Where Australian law and the law of a requesting jurisdiction conflict, we take legal advice on how to respond, and we do not disclose personal information where Australian law does not permit us to do so.
aicial’s technical infrastructure is provided by Cloudflare, Inc., our only sub-processor — see our Sub-processor List. A government or law-enforcement authority may direct a request to Cloudflare directly rather than to us. This policy governs how we handle a request made to us; it does not, and cannot, bind Cloudflare, which publishes its own approach to a government or law-enforcement request. Where we become aware of a request made to Cloudflare for personal information we process, we apply the notification commitment described in section 5 to the extent we are legally permitted and practically able to do so.
8. How we report on requests
We report on government and law-enforcement requests in aggregate. We do not identify an individual customer, or the personal information sought, in that report. See our Transparency Report for those figures. For a question about that report, contact compliance@aicial.com.
9. Reviewing this policy
We may update this policy to reflect changes to our practices, our services, or applicable law. The version, effective date and last-reviewed date shown at the top of this page identify the current policy. Where a change is material, we publish the updated policy on our website and take reasonable steps to bring it to the attention of affected customers.
10. Contact us
A government or law-enforcement authority submitting a request under this policy should contact legal@aicial.com. Where practical, include the legal basis for the request, the specific information sought, the applicable deadline and a return contact for our response.
If you are an individual with a general privacy question, including about how we handle your personal information, contact us as described in our Privacy Policy instead, at privacy@aicial.com.
Aperim Pty Ltd, which operates the aicial brand
ABN 46150699737
ACN 150699737
New South Wales, Australia
Email: legal@aicial.com