Privacy Policy
Last updated: 29 September 2026
Looking for an easier read? A plain English summary of this policy is available at Privacy Policy (plain English summary). The legal text below is the binding version.
Maelstrom AI Pty Ltd ATF Maelstrom AI Holding Trust (ABN 61 633 823 792) (“we”, “us”, “our”) operates the Maelstrom AI website (maelstrom.au), and the product downpipes. Our address is PO Box 169, St Arnaud VIC 3478, Australia. We are committed to protecting your personal information in accordance with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
This Privacy Policy covers the Maelstrom AI website and our limited processing for downpipes (the “Services”) in Sections 1 to 11 below. This Privacy Policy also covers, in Section 13 (Support Data) below, the support data our support platform holds about anyone who contacts Maelstrom support.
In this policy, “personal information” has the meaning given in the Privacy Act 1988. Where we refer to the EU General Data Protection Regulation (GDPR), the equivalent term is “personal data.”
Scope of this policy. Maelstrom AI runs one ISMS over its downpipes platform and its support platform.
- downpipes, no-custody backup and disaster recovery for the Cloudflare data layer. Available now.
- Our support platform, used internally to handle support enquiries.
downpipes runs in the customer’s own Cloudflare account, under the customer’s own keys. It backs up the customer’s own infrastructure. It does not send Maelstrom the customer’s data. downpipes sends Maelstrom no customer data, so Maelstrom engages no sub-processor for that customer data. Maelstrom does operate two surfaces for downpipes directly. The downpipes control-plane issues licence tokens and receives a content-free advisory beacon that fails open. The static, pull-only update channel serves updates for the downpipes engine. Neither surface receives customer backup or infrastructure data. The control-plane holds the licensee contact details that Section 2.2 describes.
Support data a customer sends us is separate. If a customer chooses to send Maelstrom support data, for example a diagnostic bundle, Maelstrom holds that data directly. Section 13 (Support Data) says what it holds, and the Sub-Processors page lists who processes it. Otherwise, downpipes is out of scope for the rest of this policy.
1. Overview of Our Privacy Architecture
Our product is designed so that a customer’s own data stays in the customer’s own Cloudflare account, under the customer’s own keys. downpipes runs there. We do not receive, store, or process that data ourselves.
We do not maintain user accounts for downpipes. We do not require a customer’s name, email address, or other identifying information to use this product, beyond what a licence token requires (see Section 2.2).
Our Services implement data protection by design and by default. We build data minimisation and purpose limitation into our technical architecture, rather than adding them as afterthoughts.
2. Information We Collect
We collect personal information only where it is reasonably necessary for the provision of our Services (APP 3). The sections below set out what we collect, whether we retain it, and the purpose.
2.1 Website
Our website is a static informational site. It collects minimal data:
- No application cookies: Our website code does not set any cookies. Cloudflare’s CDN infrastructure may set strictly necessary cookies for security purposes (such as bot protection). See our Cookie Policy for full details.
- No forms or accounts: We do not collect email addresses, names, or any personal information through the website.
- No tracking: We do not use Google Analytics, advertising pixels, or any third-party tracking scripts.
- Request data: Cloudflare processes technical data, such as IP addresses and request headers, to deliver and protect the website. Our Cloudflare account shows traffic analytics. For a request that Cloudflare’s security features challenge or block, it also shows the request details, including the IP address. Workers Logs are turned on for the website, and keep any record they hold for seven days. We use this data only to run and protect the website.
2.2 downpipes
downpipes does not send Maelstrom the customer’s own infrastructure data. This product runs in the customer’s own Cloudflare account, under the customer’s own keys, and backs up the customer’s own infrastructure.
The downpipes control-plane issues licence tokens and receives a content-free advisory beacon that fails open; it never gates a backup or a restore. It holds no customer keys, backup data, or Cloudflare tokens. To issue and administer a licence, the control-plane holds:
- The organisation name, and the names, work email addresses and role titles of the contacts a customer names
- For a prospective customer, the organisation name and the contact details that the prospective customer gave us
- For a Business self-serve subscription, the name and email address given at Stripe checkout. We also hold the band and the subscription status.
- The Cloudflare account ID of each engine that claims the licence, and the zone that a console activates the licence from
- A log of the licence emails we send, with the recipient address, the subject and the outcome
- An audit log of our administrative actions on the licence, which includes the address that a licence email went to
We use this information for licence administration and billing, and to contact the licensee about their licence. Cloudflare Workers Logs for the control-plane also hold request records, including the caller IP address.
Maelstrom does not know, and has no way to determine, what personal information a customer’s own infrastructure holds. That data, and any decision about how to handle it, stays with the customer.
2.3 Unsolicited Personal Information
If we receive personal information that we did not request and that is not reasonably necessary for our Services, we will destroy or de-identify it as soon as practicable in accordance with APP 4.
3. How We Use Your Information
The limited information we process is used solely to:
- Operate the website
- Issue licence tokens for downpipes
- Maintain security and prevent abuse of our infrastructure
- Respond to support enquiries (see Section 13, Support Data)
We do not use your information for advertising, profiling, direct marketing, or any purpose beyond operating our Services. APP 7 (direct marketing) is not engaged.
4. How We Protect Your Information
We implement security measures at every level:
- No-custody design: downpipes runs in the customer’s own Cloudflare account. Because Maelstrom does not hold the customer’s data, a compromise of Maelstrom’s own systems does not expose it.
- Transport security: All communications use TLS encryption. Our servers enforce HSTS.
- Server security: Our infrastructure runs on Cloudflare Workers with rate limiting, content security policies, and strict access controls. We apply data minimisation principles: we do not store what we do not need.
5. Sharing and Disclosure
We do not sell, trade, or rent your personal information.
Categories of recipients who may receive personal information:
- Cloudflare, Inc. (infrastructure provider and data processor): processes requests on our behalf under a Data Processing Agreement
- Amazon Web Services, Inc. (backup storage): holds encrypted backup copies of our own systems in Sydney, Australia, under the AWS Data Processing Addendum. We encrypt each copy before upload, so AWS cannot read it.
- Proton AG (company email, Switzerland): hosts our company mailboxes on the maelstrom.au domain, including support@maelstrom.au, and receives mail sent to sales@downpipes.io
- Stripe (subscription checkout and billing): processes the purchaser’s name, email address and card details for a downpipes Business self-serve subscription. Card details do not reach us.
- Xero (invoicing and accounting): holds billing contact details and invoice records
- Airwallex (international payments): processes payment and remittance details
- Law enforcement or regulatory authorities: only when required by Australian law, a court order, or a lawful government request. We will notify you of such requests where legally permitted.
Our Sub-Processors page lists each provider above, with the data it processes and where it processes it. It gives the DPA reference and transfer mechanism for Cloudflare and Amazon Web Services. It lists Proton, Stripe, Xero and Airwallex separately, as providers for our own records. That page also lists the sub-processors engaged for support data, described in Section 13 (Support Data) below.
6. Cross-Border Data Processing
Our infrastructure runs on Cloudflare’s global network, which operates data centres in over 300 locations worldwide. Cloudflare processes requests at the data centre closest to the user, which means the specific country of processing depends on the user’s location. We cannot reasonably specify all countries in advance, but processing is likely to occur in Australia, the United States, European Union member states, the United Kingdom, Singapore, Japan, and other countries where Cloudflare maintains data centres.
Other providers in Section 5 process limited contact and billing information outside Australia. Proton processes it in Switzerland. Xero processes it in New Zealand and the United States. Stripe processes it in the United States and globally. Airwallex processes payments in Australia and globally.
Cloudflare processes personal information on our behalf as a data processor, under a Data Processing Agreement. That agreement complies with Article 28 of the GDPR and includes the European Commission’s Standard Contractual Clauses (adopted under Decision 2021/914). We take reasonable steps, as required by APP 8, to ensure that overseas processing of personal information meets protections comparable to the Australian Privacy Principles.
For downpipes, this cross-border processing concerns the two surfaces in the scope note above and the licensee contact details that the control-plane holds. No customer backup or infrastructure data crosses a border through Maelstrom, because Maelstrom never receives it. Support data, described in Section 13 (Support Data) below, is also processed in this way.
7. Your Rights
Under Australian Privacy Law
You have the right to:
- Request access to any personal information we hold about you (APP 12)
- Request correction of any inaccurate personal information (APP 13)
- Make a complaint about how we handle your personal information
In practice, for the Services, because we do not maintain user accounts and downpipes itself sends us no infrastructure data, there is generally no personal information for us to provide access to or correct, other than the licensee contact details described in Section 2.2. If you have contacted our support team, see Section 13 (Support Data) below. That section sets out the personal information we hold about that contact, and how to exercise your rights over it.
Under the EU General Data Protection Regulation (GDPR)
Our Services may be used by businesses established in the European Economic Area. Because downpipes is no-custody, Maelstrom does not act as controller or processor of the data those businesses run through the product; the business itself is the controller of its own infrastructure data.
Where Maelstrom does process personal data of a person in the EEA, we act as described in Section 13 (Support Data) below. The most common case is when we hold support data on their behalf.
Legal basis for processing
Where we process personal data through the website or our security infrastructure, we rely on:
- Legitimate interests (Article 6(1)(f)) for maintaining the security and integrity of our infrastructure, including rate limiting and abuse prevention.
Legal basis for support data is set out in Section 13 (Support Data) below.
Automated decision-making
We do not engage in profiling and do not make automated decisions that produce legal effects concerning you.
Your GDPR rights
- Right to access: You may request a copy of any personal data we hold about you (Article 15).
- Right to rectification: You may request correction of inaccurate personal data (Article 16).
- Right to erasure: You may request deletion of your personal data (Article 17), subject to the retention periods in Section 9 (Data Retention).
- Right to restriction: You may request that we restrict processing of your personal data (Article 18).
- Right to portability: You may request your personal data in a structured, machine-readable format (Article 20).
- Right to object: You may object to processing based on legitimate interests (Article 21).
- Right to complain: You have the right to lodge a complaint with the data protection supervisory authority in your Member State of habitual residence, place of work, or place of the alleged infringement.
International transfers
Australia does not have an EU adequacy decision. Standard Contractual Clauses (European Commission Decision 2021/914, Module 2: controller to processor), as incorporated in Cloudflare’s Data Processing Agreement, protect transfers of personal data outside the EEA. Section 4 above describes supplementary technical measures.
Data Protection Officer and EU representative
We have not appointed a Data Protection Officer as our processing activities do not meet the thresholds requiring one under Article 37 of the GDPR. For data protection enquiries from EEA residents, please contact support@maelstrom.au.
We have not appointed an EU representative under Article 27 of the GDPR. If you are in the EEA and have a question about our processing of your personal data, contact us using the details in Section 14.
8. Children’s Privacy
Our website, downpipes and our support platform are not directed at children and are not designed for use by children.
downpipes processes only a customer’s own infrastructure data, under the customer’s own responsibility. Maelstrom has no way to know whether any of that data relates to a child.
We do not knowingly collect personal information from children through the website or through our support platform beyond what this policy describes. Parents or guardians with concerns about a child’s personal information held by Maelstrom may contact us at the address in Section 14.
9. Data Retention
- Website data: The website itself collects no personal data. Cloudflare keeps the request data described in Section 2.1 for the period that its service sets. Workers Logs are turned on for the website, and keep any record they hold for seven days.
- downpipes: No customer backup, log or infrastructure data is retained by Maelstrom. This product is no-custody. For the licence information described in Section 2.2:
- We keep the customer record while the customer relationship continues. When the relationship ends, an operator marks the record as ended. The control-plane then deletes it five years after its last change. Until an operator marks it, the record has no time limit.
- We keep a record for a prospective customer, with the contact details they gave us, until an operator marks it as ended. The same five-year rule then applies.
- When you ask, we erase the contact details from an ended record before then. We keep the commercial terms of the licence, which tax law requires us to keep.
- We keep the log of licence emails for two years, then it is deleted automatically. An erasure request does not remove its entries.
- We keep the administrative audit log without a time limit, as the record of each administrative action. An erasure request does not remove its entries.
- Encrypted backup copies of the licence record in Amazon Web Services keep erased or expired details until the copy is deleted. Section 1.2 of the Sub-Processors page states how long we keep each copy.
- Cloudflare Workers Logs keep the control-plane’s request records for seven days.
- Support data: See Section 13 (Support Data) below.
10. Data Breach Notification
We follow the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act 1988 (Cth).
If we suspect a data breach, we assess it within 30 days. The assessment decides whether it is an eligible data breach: unauthorised access to, unauthorised disclosure of, or loss of personal information that is likely to result in serious harm to an individual.
If we have reasonable grounds to believe that an eligible data breach has occurred, we will do these steps as soon as practicable:
- Give a statement about the breach to the Office of the Australian Information Commissioner (OAIC).
- Notify each affected individual whose contact details we hold, by email. For example, this includes the contact details you gave us when you signed up to a paid plan or contacted our support.
- For affected individuals we cannot contact directly, publish the statement on maelstrom.au and downpipes.io, and take reasonable steps to make it known to them.
The statement describes the breach, the kinds of information involved, and the steps we recommend you take. The statement also gives our contact details.
Our no-custody architecture significantly reduces breach risk for downpipes. Maelstrom does not hold customer data processed through this product. Because of this, the practical impact of a breach of Maelstrom’s own systems on that data is limited. Support data held on our support platform is different: we hold it directly, so we assess and notify a breach of the support platform under this section in the normal way. We also notify business customers who have signed a DPA with us, under the terms of that DPA.
11. Source availability
The downpipes engine and console are source-available under the Elastic License 2.0. The offline reader is MIT-licensed. The engine, console and offline reader repositories are public on GitHub. The control-plane repository is private. Our support platform is not published.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will post the updated policy on this page with a revised “Last updated” date. For material changes, we will provide notice on our website.
12.1 Version history
| Version | Date | Summary |
|---|---|---|
| 2.2 | 19 June 2026 | downpipes added to scope. Added a scope note clarifying that downpipes is no-custody and processes no end-user personal information. |
| 2.3 | 3 September 2026 | Scope note updated. Added a new Support Data section and updated Section 7 to point to it. Renumbered later sections. |
| 2.4 | 3 September 2026 | Support Data section now states Maelstrom’s role: controller of support-contact and ticket data, processor of bundle and attachment content under the support DPA. Updated the sub-processor description for company mailbox hosting. |
| 2.5 | 4 September 2026 | Corrected the sub-processor description for company mailbox hosting. |
| 2.6 | 4 September 2026 | Support Data section now links the published Support Privacy Notice. |
| 3.0 | 4 September 2026 | Document re-scoped to downpipes and our support platform. Rewrote Sections 1 to 11 for the website and downpipes. Removed recipient categories and sub-processors that do not apply. Renumbered sections. |
| 3.1 | 4 September 2026 | Editorial update. |
| 3.2 | 24 September 2026 | Editorial update. Section 10 now describes breach notification under the Australian Notifiable Data Breaches scheme, including how we notify people we cannot contact directly. |
| 3.3 | 24 September 2026 | Technical log records for support are kept for 90 days. Added Amazon Web Services as the backup storage provider. |
| 3.4 | 25 September 2026 | Factual corrections in the scope note and Sections 2.1, 4, 6 and 11. No change to obligations. |
| 3.5 | 25 September 2026 | Section 5 lists every provider that receives personal information from us. Proton, Stripe, Xero and Airwallex join Cloudflare and Amazon Web Services. Section 6 names where they process it. Section 2.2 lists the licence information we hold, including prospective customer records. Section 9 states how long our systems keep it, and what an erasure request does not remove. Section 2.1 describes the request data that Cloudflare processes for the website, including Workers Logs. Section 14 gives support@downpipes.io for downpipes privacy requests. Section 13 describes the rule-based diagnosis of tickets that carry a support bundle. Section 10 states how we reach affected people we cannot contact directly. |
| 3.6 | 29 September 2026 | Plain English rewrite. No change to any commitment, right or obligation. |
13. Support Data
Maelstrom AI also operates a support platform. It handles support for downpipes. If you contact Maelstrom support, our support platform holds:
- Your support conversation and message content
- Your email address and display name
- Any attachments or support bundles you send us, including bundles uploaded through a one-time upload link
- Notes we add to your ticket
- Your entitlement record at the time of the ticket
- Technical log records, which include the IP address your request came from and the email address of the person who handled your ticket
We hold this data to respond to your enquiry, diagnose your issue, and run our support service. When a ticket carries a support bundle, a rule-based diagnosis adds a note to the ticket and can set its priority, labels and category. An operator reviews the diagnosis and can change it.
We keep closed tickets and attachments for 365 days after the ticket closes. We delete support bundles 30 days after upload, whatever the ticket status, and also as soon as the ticket closes. Technical log records are kept for 90 days for security purposes, and then deleted automatically.
Maelstrom is the controller of your support-contact and ticket data: your name, email address, message content and any notes we add. We decide the purposes and means of that processing, and you contact us directly. Maelstrom is a processor of the content of any bundles or attachments you supply. We handle that content only on your instruction, under the support DPA. Cloudflare, Inc. stores this data, in Maelstrom’s own Cloudflare account, as our processor, for both roles.
Proton AG hosts Maelstrom’s company mailboxes on the maelstrom.au domain, including support@maelstrom.au. Our support platform does not send or store support mail through Proton. See the Sub-Processors page for the sub-processors engaged for support data.
We publish a support-specific Support Privacy Notice, which gives the full disclosure for support data. This section is a summary of it.
You have the same rights over your support data that Section 7 sets out: access, correction, and complaint. Contact us using the details in Section 14.
14. Contact Us and Complaints
Please contact us with questions about this Privacy Policy, to exercise your rights, or to complain about how we handle your personal information:
- Email: support@maelstrom.au
- Post: PO Box 169, St Arnaud VIC 3478, Australia
For a privacy request about downpipes, you can also write to support@downpipes.io, as the downpipes privacy policy says.
Complaint handling
If you make a privacy complaint, we will acknowledge receipt within 5 business days and investigate the matter. We aim to respond with an outcome within 30 days. If we need more time, we will let you know and explain why.
If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner. If you are in the EEA, you may lodge a complaint with the data protection supervisory authority in your Member State.