Privacy Policy
This Privacy Policy explains how coRise, operated independently by its founder ("coRise", "we", "us"), based in Melbourne, Victoria, Australia, handles personal information when you visit our websites (corise.me and corisehq.com), apply for or hold a coRise membership, or contact us.
We aim to handle personal information consistently with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles. Where we offer services to people in other regions, we also take into account widely recognised data-protection principles such as those in the EU/UK GDPR. This document is a plain-language summary and is not legal advice.
1. Who is responsible for your data
The data controller is coRise, operated independently by its founder, based in Melbourne, Victoria, Australia. We do not publish a street address; for privacy enquiries, contact [email protected].
2. Information we collect
- Identity and contact details — your name or preferred title and your email address, provided when you register.
- Referral / source parameters — values such as a
refquery parameter or campaign source captured with your registration, so we understand how members find us. - Optional membership profile — details you choose to add for voluntary community matching, such as your transition stage, birth year (year only — we do not collect a full date of birth), star sign, and MBTI type. These fields are optional and you can decline them.
- Communications — the content of emails or messages you send us, and our replies.
- Technical and security logs — information generated automatically when you use our sites, such as IP address, approximate location derived from IP, browser and device type, timestamps, requested pages, and records used for rate limiting, abuse prevention, and verifying that an email address belongs to you.
- Marketing preferences — whether you have opted in to non-essential updates, and the date and policy version recorded with that choice.
We do not intentionally collect special-category / sensitive information, and we ask that you do not send it to us through registration fields.
3. Why we use your information (purposes)
- To create and administer your membership and issue your founding member number.
- To verify that an email address is valid and controlled by you.
- To deliver membership services, including onboarding, group access, and support.
- To match members into peer circles, where you have provided optional profile details for that purpose.
- To respond to your enquiries.
- To protect our services and members — security monitoring, rate limiting, fraud and abuse prevention, and enforcing our Terms and Community Guidelines.
- To send non-essential updates only where you have opted in (see section 8).
- To comply with legal obligations.
Depending on the applicable law, our legal bases include performance of our membership agreement with you, your consent (for optional profile data and marketing), our legitimate interests in running and securing a trusted community, and compliance with law.
4. Service providers we use
We share personal information with a small number of vendors that process it on our behalf, under contract and only for the purposes above. By category, these currently include:
- Cloud hosting, edge delivery and security — Cloudflare (site hosting, serverless functions, bot / abuse protection).
- Membership records database — Cloudflare D1, where member records are stored.
- Transactional email delivery — an email sending provider used to send verification codes and membership emails.
- Fonts and content delivery — Google Fonts and similar CDN providers used to load page assets.
This list may change as our stack evolves; we will keep this section current. We do not sell personal information.
5. International transfers
Our providers may store or process data outside Australia, including in the United States and other countries. Where we transfer personal information overseas, we take reasonable steps to ensure it is handled consistently with this policy and applicable law, for example through the provider's contractual commitments and recognised transfer mechanisms. Contact us if you would like more detail on a specific provider.
6. How long we keep it
We keep membership records for as long as you hold a membership and for a reasonable period afterwards to meet legal, accounting, and dispute-resolution needs, then delete or de-identify them. Verification and security logs are kept only for a short period appropriate to their purpose. Marketing preference records are kept while relevant to show the basis of your consent or opt-out.
7. How we protect your information
We use technical and organisational measures appropriate to the risk, including encryption in transit, access controls, limiting who can see member data, and abuse / rate-limiting protections on our endpoints. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we become aware of a data breach that is likely to cause serious harm, we will notify affected individuals and the relevant regulator as required by law.
8. Marketing communications
Membership does not depend on receiving marketing. We send non-essential updates (such as newsletters or event invitations) only if you have opted in with the separate, unticked checkbox at registration or elsewhere. You can withdraw consent at any time using the unsubscribe link in those emails or by contacting [email protected]. We will still send you essential service messages related to your membership.
9. Your rights and choices
You can ask us to:
- access the personal information we hold about you;
- correct information that is inaccurate or out of date;
- delete your information, subject to legal retention needs;
- stop or limit certain processing, or withdraw consent;
- provide a copy of certain information in a portable format, where applicable law requires it.
To make a request, email [email protected]. We may need to verify your identity. We aim to respond within the timeframe required by applicable law.
10. Complaints
If you are concerned about how we have handled your personal information, contact us first at [email protected] so we can try to resolve it. You may also complain to the Office of the Australian Information Commissioner (oaic.gov.au) or, if you are in another jurisdiction, to your local data-protection authority.
11. Children
coRise is intended for adults. It is not directed at children, and we do not knowingly collect their personal information. If you believe a child has provided us data, contact us and we will delete it.
12. Changes to this policy
We may update this policy from time to time. We will change the "last updated" date above and, for material changes, take reasonable steps to notify members.