Security, Privacy and Technical Specifications
Version 1.0 · 30 August 2026
Di Marco is an Australian HR and industrial relations assistant used by employers, HR teams and advisers. This document sets out the technical, security and data-handling information an IT, security or procurement team needs in order to assess and approve Di Marco for use by staff.
In short. Di Marco runs in the browser. Nothing is installed on your devices, nothing connects into your network, and no integration work is required. It is an advisory tool: it answers questions, drafts documents and runs calculations. It cannot reach your systems and cannot take action in them.
- In Summary
- What It Is
- How It Works
- Deployment and Integration
- Access and Authentication
- Data Flow
- Data Collected and Retained
- Encryption and Protection
- Hosting and Data Residency
- Sources and Citations
- What Di Marco Cannot Do
- Privacy and the APPs
- Sub-Processors
- Breaches, Complaints and Contact
- Questions to Ask Any HR AI Vendor
In Summary
| Audience | Employers, HR and IR practitioners, people leaders and advisers in Australia. |
| Where it runs | In a standard web browser at dimarco.consulting. Also available inside Claude, ChatGPT and Microsoft Copilot through a personal connector. |
| Authentication | Email and password, with sessions issued on sign-in. Access follows an active subscription. |
| Scope of answers | Australian workplace relations and employment law: the Fair Work Act 2009 (Cth), the National Employment Standards, modern awards, enterprise agreements and Fair Work Commission practice. |
| Installed on your devices | Nothing. |
| Connects to your systems | No. |
| Data leaving your organisation | Whatever a user types or attaches, plus standard web interaction data. |
| Can it take actions? | No. It answers, drafts and calculates. It cannot act in any system. |
| Owner and contracting party | Di Marco Consulting Pty Ltd (ABN 55 693 264 087), an Australian company. Your agreement is with an Australian entity. |
| Governing law | Western Australia, Australia. Disputes are resolved in Australian courts. |
| Conversation retention | 24 months, then automatically deleted. Deleted sooner on request. |
| Cost | From A$49 per month. Cancel at any time through the Stripe billing portal. |
What It Is
Di Marco is a generative AI assistant for Australian HR and industrial relations work, operated by Di Marco Consulting Pty Ltd. It answers substantive questions, drafts correspondence and documents, identifies the applicable modern award, calculates entitlements, and tracks legislative change.
It is built and operated by an Australian company. There is no overseas licensor between you and the operator, and no third-party association controls the content or configuration.
How It Works
Di Marco combines a specialist instruction set with live retrieval from authoritative Australian sources. It is not a custom-trained model, and your content is not used to train any model.
- Your question, the relevant conversation history, and any files you attach are assembled into a request.
- Where the question turns on something current, such as a rate, a threshold or a recent decision, Di Marco retrieves from the authoritative source rather than relying on model memory.
- A large language model composes the answer against a strict instruction set that requires it to work from the Fair Work Act, the NES, modern awards and Fair Work Commission practice, and forbids it from fabricating case names, citation numbers, penalty figures or section numbers.
- The answer is returned with citations to specific pages on authoritative sources.
Deployment and Integration
| Software installed | None. No agent, browser extension, plugin, certificate or configuration is deployed to any device in your environment. |
| Integration with your systems | None required. Di Marco does not connect to your network, identity provider, directory, file storage, email, HRIS or any line-of-business system. |
| Inbound connections | None. All traffic is outbound from the user's browser over HTTPS. |
| Your enterprise agreement, policies or documents | Not held and not accessible unless a user chooses to attach them to a conversation. |
| Change to your environment | None, beyond ordinary web access to dimarco.consulting. |
| Optional: AI assistant connector | Users on eligible plans can add Di Marco to Claude, ChatGPT or Microsoft Copilot using a personal connector link. This is opt-in, per user, and revocable. It exposes Di Marco's tools to that assistant; it does not expose your systems to Di Marco. |
Access and Authentication
| Access control | Each user holds an individual account. Content and history are scoped to that account. |
| Credential storage | Passwords are stored as one-way bcrypt hashes. Plain-text passwords are never stored and cannot be recovered, only reset. |
| Session handling | Session cookies are set Secure, HttpOnly and SameSite, and expire after 8 hours. They are not readable by page scripts and are not sent cross-site.Verified |
| Cross-site request forgery | State-changing forms and API calls carry per-session CSRF tokens which are validated server-side. |
| Abuse and rate limiting | Request rate limiting is applied to sign-in, password reset and message endpoints. |
| Account provisioning and removal | Accounts are created on subscription and removed on request. For multi-user plans, an administrator can request provisioning and removal in bulk. |
| Single sign-on and SAML | Not currently supported. Access is by individual account. If SAML is a requirement for your organisation, tell us before you subscribe and we will confirm whether and when we can meet it. |
| Multi-factor authentication | Not currently offered on user accounts. Sessions expire after 8 hours and every sign-in attempt is rate limited. |
Data Flow, and What Leaves Your Organisation
What Leaves
The text a user types, any files a user chooses to attach, and standard web interaction data. Nothing is read from the user's device, network or systems: Di Marco has no access to files, mail, directories or applications.
Where It Goes
To Di Marco's own hosting, and from there to the language model provider for the generation step. Where the question requires current source material, Di Marco also makes outbound requests to Australian government sources.
Who Can See It
Conversations are visible to the account holder. Di Marco Consulting personnel can access conversation data where necessary to operate, support or secure the service. Your staff's questions are not visible to other customers, and other customers' questions are not visible to you.
The Compliance Audit never leaves the browser. Di Marco's Workplace Compliance Audit, a structured self-assessment that produces a risk-scored report with prioritised findings, is scored entirely in the browser. The answers are not transmitted to the server and are not stored. You can assess your own compliance position without disclosing it to anyone.
Data Collected and Retained
| Item | Position |
|---|---|
| Account data | Name, email address, organisation and subscription tier. Held for the life of the account. |
| Payment data | Handled by Stripe. Di Marco Consulting never receives or stores card numbers. |
| Conversation content | Stored against the account so history is available across sessions. The account holder can export any conversation to a file at any time. |
| Retention period | 24 months. A scheduled job runs daily and permanently deletes conversation content older than 24 months. Account records are retained for the life of the account, and for 7 years afterwards where required for tax and corporate record-keeping. |
| Remembered context | Di Marco can retain short context about a user's role and organisation to improve answers. The user can erase it at any time from the chat sidebar, and erasure is immediate. |
| Compliance Audit answers | Not collected. Scored in the browser and never transmitted. |
| Deletion on request | An account holder may request deletion of their conversation data or their account. Requests are actioned within 30 days. |
| Deletion on cancellation | The account is deactivated immediately. Conversation content remains available for 30 days so it can be exported, then is deleted. Deletion can be requested sooner. |
| Use of your content for model training | Never. Your conversations are not used to train any model, and are not used to improve answers for other customers. |
| Ownership of your content | You retain ownership of what you enter and what Di Marco drafts for you. Di Marco Consulting claims no licence to commercialise, sublicense or transfer your content or any behavioural data derived from it. |
Encryption and Protection
| In transit | All traffic is served over HTTPS. HTTP requests are permanently redirected to HTTPS, and HTTP Strict Transport Security is enabled with a one-year max-age and includeSubDomains. HTTP/2 and HTTP/3 are supported.Verified |
| At rest | Application-level encryption is not applied to the database or to stored files. Data at rest is protected by hosting-account isolation and access controls. Passwords are the exception: they are stored only as one-way bcrypt hashes and are never recoverable. |
| Credentials and secrets | API keys and configuration secrets are held server-side outside the web root and are never exposed to the browser. |
| Perimeter | A web application firewall and CDN sit in front of the site. Filtering and denial-of-service absorption happen before a request reaches the application.Verified |
| Backups and recovery | The hosting account provides cPanel backup facilities, and the application source is retained separately from the host so the service can be rebuilt. |
| Access by personnel | Administrative access is limited to the director of Di Marco Consulting Pty Ltd, and is used only to operate, support and secure the service. |
Controls You Can Verify Yourself
These are response headers and cookie attributes served by dimarco.consulting. You do not have to take our word for any of them. Open the developer tools in your browser, or run an external scan such as SSL Labs or Mozilla Observatory, and check.
| Control | Position |
|---|---|
| strict-transport-security | max-age=31536000; includeSubDomains. Browsers are instructed to use HTTPS only, for a year, across all subdomains. |
| HTTP to HTTPS | Permanent redirect. Plain HTTP is never served. |
| x-frame-options | SAMEORIGIN. The site cannot be framed by a third party, which blocks clickjacking. |
| x-content-type-options | nosniff. Browsers may not second-guess declared content types. |
| referrer-policy | strict-origin-when-cross-origin. Full URLs are not leaked to third-party sites. |
| permissions-policy | geolocation=(), microphone=(), camera=(). The page cannot request location, microphone or camera. |
| content-security-policy | upgrade-insecure-requests. Any subresource requested over HTTP is upgraded to HTTPS. |
| Session cookie | Secure; HttpOnly; SameSite=Lax, with an 8-hour lifetime. |
| Web application firewall | Sucuri Cloudproxy fronts all traffic. |
| Protocols | HTTP/2 and HTTP/3 supported. |
Hosting and Data Residency
| Application hosting | GoDaddy, a United States company, on its Linux and cPanel platform, with MySQL co-located with the application. |
| Edge protection | A GoDaddy Website Security subscription, delivered by Sucuri Cloudproxy, a web application firewall and CDN operated by Sucuri, a GoDaddy company. All public traffic passes through it before reaching the origin. The origin address is not publicly exposed.Verified |
| DNS | GoDaddy authoritative nameservers.Verified |
| TLS certificate | A GoDaddy-issued SSL certificate on an annual, auto-renewing subscription. |
| Inbound mail to Microsoft 365 (Exchange Online). Outbound transactional mail over authenticated SMTP with TLS, published in SPF with a hard fail so no other host can send as the domain.Verified | |
| Language model processing | OpenAI, in the United States, on a standard commercial API account. Under OpenAI's published API policy, data sent to the API is not used to train or improve OpenAI models, and abuse-monitoring logs containing customer content are retained for up to 30 days unless a longer period is required by law. |
| Data residency | Di Marco does not offer Australian data residency. The hosting provider, the edge network and the language model provider are all United States companies, and language model processing is performed in the United States. Anything entered into Di Marco should be assumed to be processed outside Australia. |
Note for reviewers. Every generative AI product in this market sends prompts to a United States model provider. Any vendor telling you otherwise is either running its own models or not telling you the whole story, so ask which. What genuinely differs between products is who you contract with, whose law governs the agreement, whether the vendor claims ownership of your data, and whether any of this is written down. Under section 16C of the Privacy Act, accountability for an overseas recipient's handling stays with the organisation that disclosed the information. It does not transfer with the data. That is why the prohibition on entering personal information matters more than any technical control, and why we ask customers to reinforce it in their own acceptable use guidance.
Sources and Citations
Di Marco is instructed to work from authoritative Australian sources and to cite specific pages rather than homepages. The source set includes:
- fairwork.gov.au, Fair Work Ombudsman guidance, pay tools and award summaries
- fwc.gov.au, Fair Work Commission decisions, awards and agreements
- legislation.gov.au, Commonwealth legislation as made and in force
- austlii.edu.au, case law
- safeworkaustralia.gov.au, work health and safety
- aph.gov.au, bills before Parliament
- State and territory industrial relations commissions
| Fabricated citations | Expressly prohibited. Di Marco is instructed never to invent case names, citation numbers, penalty figures or section numbers it cannot verify, and to say so plainly where something is genuinely uncertain. |
| Wiki and crowd-sourced sources | Expressly excluded. |
| Currency of information | Di Marco tracks Fair Work, Commission, Safe Work Australia and parliamentary developments, and subscribers can receive plain-language alerts when new material is published. A regulatory calendar of key compliance dates is maintained on the site. |
| Human verification | Answers are not reviewed by a person before the user sees them. Users are directed to open the cited source, and to obtain independent legal advice on consequential matters. |
What Di Marco Cannot Do
- It cannot take action. It cannot create, change or delete anything in any system, send email on your behalf, submit forms or trigger workflows.
- It cannot reach your environment. No access to your network, devices, accounts, files or applications.
- It is not legal advice and is not a substitute for it. Answers are general HR and IR guidance, are not reviewed by a person before you see them, and are not subject to legal professional privilege.
- It is not an automated decision-making system. It provides information. It does not make decisions about individuals, and it should not be used as the decision-maker in a disciplinary, performance or termination process.
- It does not know your enterprise agreement, policies or site arrangements unless a user attaches them to a conversation.
- It cannot represent anyone at the Fair Work Commission or in any tribunal or court. Di Marco Consulting's advisers do that.
Privacy and the Australian Privacy Principles
Di Marco does not need personal information to answer a question, and users are asked not to provide it. Describe the situation generally and the answer is the same. Where a user does enter personal information, it is collected as part of the conversation.
| APP | Position |
|---|---|
| APP 1, open and transparent management | Di Marco Consulting maintains a privacy policy and publishes this document. |
| APP 3, collection | Personal information is not solicited through the assistant. Any collection is incidental to a user's own free-text input. |
| APP 5, notification | A collection notice is displayed with the assistant, covering what is collected, why, and who it is disclosed to. |
| APP 6, use and disclosure | Question content is used to generate the answer and to operate and support the service. It is not disclosed to other customers, and not used for any unrelated purpose. |
| APP 7, direct marketing | Question content is not used to target marketing to an individual. |
| APP 8, cross-border disclosure | Engaged. The hosting provider, the edge network and the language model provider are United States companies, and model processing is performed in the United States. Where a user enters personal information it is disclosed to overseas recipients. This is addressed primarily by prevention: users are instructed not to enter personal information and are shown how to ask the same question generically, and the position is disclosed here and in the privacy policy. |
| APP 11, security | Traffic is encrypted in transit with HSTS enforced. Passwords are bcrypt-hashed. Sessions are Secure, HttpOnly, SameSite and expire after 8 hours, and state-changing requests are CSRF-protected. A web application firewall sits in front of the site. Data at rest is not encrypted at the application layer, as set out under Encryption and Protection. |
| APP 11.2, destruction | Conversation content is automatically deleted after 24 months. Remembered context can be erased by the user at any time, and conversation data is deleted on request within 30 days. |
| APP 12, access | An individual may ask what is held about them, and may export their own conversations directly from the interface at any time. |
| APP 13, correction | An individual may ask for information to be corrected or removed. |
Sub-Processors
Di Marco Consulting will notify subscribers before appointing a new sub-processor that handles customer content.
| Party | Role |
|---|---|
| OpenAI | Language model processing. Composes the answer from the question and the retrieved source material. United States. |
| GoDaddy | Application hosting, database, file storage, DNS and outbound transactional mail. United States. |
| Sucuri, a GoDaddy company | Web application firewall and CDN in front of the site. United States. |
| Stripe | Subscription payments and the billing portal, on an Australian Stripe account held in the name of Di Marco Consulting Pty Ltd and settled to an Australian bank account. Card details are entered directly with Stripe and never reach Di Marco Consulting's systems. Only customer and subscription identifiers are returned. |
| Microsoft | Inbound business email (Microsoft 365 and Exchange Online). Not used to process assistant conversations. |
Breaches, Complaints and Contact
| Notifiable Data Breaches | Di Marco Consulting Pty Ltd is subject to the scheme. A suspected eligible breach is assessed within 30 days as the scheme requires, and affected individuals and the Office of the Australian Information Commissioner are notified as soon as practicable once an eligible breach is confirmed. |
| Privacy contact | admin@dimarco.consulting. Enquiries are acknowledged within 5 business days. |
| Escalation | An individual not satisfied with the response may complain to the Office of the Australian Information Commissioner. |
| Security disclosure | Suspected vulnerabilities can be reported to admin@dimarco.consulting and will be acknowledged and investigated. |
Questions to Ask Any HR AI Vendor
If you are comparing Di Marco against another product, these are the questions that separate them. Ask all of them, of everyone, and ask for the answers in writing.
| Question | Di Marco's answer |
|---|---|
| Who am I actually contracting with, and where are they incorporated? | Di Marco Consulting Pty Ltd, an Australian company (ABN 55 693 264 087). There is no overseas licensor in between. |
| Which country's law governs the agreement, and where are disputes heard? | Australian law, in the courts of Western Australia. |
| Does the vendor claim ownership of my behavioural or interaction data? | No. No ownership claim, and no claim that survives termination. |
| Does the vendor take a perpetual or sublicensable licence over aggregated data? | No. No perpetual licence, no sublicensing, no derivative works, no onward provision to third parties. |
| Is my content used to train models? | No. |
| Is there a published retention period, or is data simply kept for the life of the relationship? | 24 months, enforced by a scheduled deletion job, and sooner on request. |
| Where is the data processed? | The United States, and we say so plainly above rather than leaving you to find out. Ask every vendor this, and ask what their terms permit. |
| Can I get my data out, myself, without asking? | Yes. Any conversation can be exported from the interface. Remembered context can be erased by the user. |
| Can the assistant reach current source material, or only a fixed library someone loaded? | Di Marco retrieves live from authoritative Australian sources and tracks legislative change. It is not limited to a static loaded corpus. |
| Can I use it where I already work? | Yes. Di Marco can be added to Claude, ChatGPT or Microsoft Copilot through a personal connector, as well as used on the site. |
| Can I assess my own compliance position without handing the answers to the vendor? | Yes. The Workplace Compliance Audit is scored in your browser and never transmitted. |
| If the AI is not enough, can the same provider act for me? | Yes. Di Marco Consulting takes on investigations, classification reviews, HR system reviews and hands-on IR support. |
Reviewing Di Marco for your organisation? Email admin@dimarco.consulting and we will answer any question in this document in writing, on letterhead, for your risk or procurement file.