Data Security Policy
Effective Date: December 16, 2024 | Last Updated: January 21, 2025
1. About This Policy
This Data Security Policy describes the security measures implemented by Krrisp Pty Ltd (ACN: 609 221 570), operator of Klaris ("we", "us", "our"), to protect information processed through our wealth-structure record software platform ("Klaris" or the "Platform").
This policy applies to all users of the Platform, including individual clients and financial advisors who access the Platform.
Our commitment is to protect your financial structure data with industry-standard security practices while maintaining transparency about how we safeguard your information.
2. Data Storage and Infrastructure
Australian Data Residency
Klaris is operated for Australian families and advisers. Our data-handling approach is designed around the privacy and confidentiality expectations that apply to sensitive family wealth records.
Controlled Records
Klaris is designed to keep sensitive family wealth information organised, private, and available only to appropriate people. This means:
- Families and advisers work from one clearer structure record.
- Access is intended to be granted only where there is a legitimate family, adviser, or support purpose.
- Operational access is limited to what is needed to provide, support, and protect the service.
- Data handling is guided by confidentiality, privacy, and Australian professional-services expectations.
3. Information Protection
Klaris avoids publishing detailed security architecture on the public website. At a practical level, our approach focuses on:
- Secure connections - Protecting information as it moves between users and the Platform.
- Access control - Limiting sensitive records to authorised users and legitimate service purposes.
- Operational safeguards - Using internal controls, support procedures, and review practices to reduce unauthorised access risk.
- Data minimisation - Avoiding unnecessary collection of highly sensitive information where it is not needed for the service.
4. Account Access
Klaris accounts are intended for authorised users only. Access may be reviewed or configured during onboarding so that the right family members, advisers, or support contacts are involved.
- Users should use strong, unique credentials.
- Access should not be shared with unauthorised people.
- Adviser access should be reviewed when professional relationships change.
- Suspected unauthorised access should be reported promptly.
5. Access Controls and Permissions
Klaris is built around controlled collaboration. A high-net-worth family may need accountants, financial advisers, lawyers, and family office contacts to work from the same picture, but not every person should automatically see everything.
- Families should decide which advisers need access to the structure record.
- Advisers should only use client information for legitimate professional purposes.
- Access should be reviewed as advisers, family roles, or structures change.
- Support access is intended to be limited to what is necessary to resolve a service issue.
6. Third-Party Security
Klaris uses trusted service providers where needed for payments, communications, analytics, hosting, support, or security. We do not publish the full operational stack on the public website.
Where providers are used, our focus is to limit unnecessary data sharing and to keep sensitive family wealth records separate from routine payment, analytics, and communications activity unless disclosure is required for support, legal, or service reasons.
7. Security Monitoring and Incident Response
Monitoring
- We monitor for unusual access patterns and potential security threats.
- Failed login attempts are tracked and accounts may be temporarily locked after repeated failures.
- System logs are maintained for security audit purposes.
Incident Response
In the event of a security incident:
- We will investigate and contain the incident as quickly as possible.
- Affected users will be notified in accordance with the Notifiable Data Breaches (NDB) scheme under the Privacy Act 1988.
- We will notify the Office of the Australian Information Commissioner (OAIC) if the breach is likely to result in serious harm.
- We will provide affected users with information about the breach and recommended steps to protect their accounts.
8. User Responsibilities
While we implement robust security measures, account security is a shared responsibility. We recommend that all users:
- Use strong, unique account credentials for your Klaris account.
- Use any additional account-security controls offered during onboarding.
- Do not share your login credentials with anyone.
- Sign out of your account when using shared or public devices.
- Keep your email address up to date for security notifications.
- Review advisor access permissions regularly and revoke access that is no longer needed.
- Report any suspected unauthorised access immediately to info@klaris.com.au.
9. Privacy Act Alignment
Our security practices are designed to align with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth), including:
- APP 11 (Security of Personal Information) - We take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access, modification, or disclosure.
- APP 8 (Cross-border Disclosure) - Where account-level, payment, email, analytics, support, or operational metadata is processed by trusted providers, we use appropriate safeguards and contractual controls.
- Notifiable Data Breaches Scheme - We comply with the NDB scheme and will notify affected individuals and the OAIC of eligible data breaches.
10. Limitations
While we implement security measures, no system can guarantee absolute security. We cannot be held liable for:
- Unauthorised access resulting from user actions (e.g., sharing shared credentials, weak account practices, compromised devices).
- Security breaches at third-party providers despite their own security certifications.
- Force majeure events or circumstances beyond our reasonable control.
11. Changes to This Policy
We may update this Data Security Policy from time to time to reflect changes in our security practices, technology, or legal requirements. When we make material changes:
- We will update the "Last Updated" date at the top of this policy.
- For significant changes, we will notify users via email or an in-app notification.
- Continued use of the Platform after changes constitutes acceptance of the updated policy.
12. Contact Information
If you have questions about our security practices or wish to report a security concern, please contact us:
Email: info@klaris.com.au
Entity: Krrisp Pty Ltd (ABN: 38 609 221 570 | ACN: 609 221 570)
Website: klaris.com.au
Have Security Questions?
If you have any concerns about data security or want to learn more about how we protect your information, get in touch with our team.
Contact Us