We hold nothing we don't have to.
Most firms keep client files indefinitely. We deliver your report through a private portal, wait for your confirmation that every file has been received, and then destroy everything except the tax invoice. The destruction is unrecoverable. This page explains exactly what we collect, where it sits while we hold it, and what happens to it afterwards.
The short version
- Your report is delivered through a private portal. Not as an email attachment. You receive a time-limited link, view the report and evidence pack, and download them as PDFs to your own system.
- Nothing is destroyed until you confirm receipt. After downloading, the portal asks you one question: did you receive your report? On your confirmation, the report, the evidence pack, the engagement file, your contact details and all working notes are overwritten and permanently destroyed.
- We keep only three things. Your tax invoice, retained for five years. Privacy correspondence, retained in identifiable form for 24 months then de-identified. And portal access records, retained for five years as the factual record of delivery. Nothing else is kept.
- Live chat conversations are not a retained record. They are stored while open, then deleted 15 days after the conversation closes. They are not linked to any client file or investigation.
- All retained records are stored in Australia only, on encrypted hard drives. The drives are held in a physically caged environment with no network connection of any kind. They cannot be read without being physically attached to a dedicated reader in that same environment. Access to the cage is logged.
- We share nothing with any third party for commercial purposes. Privacy enquiries are handled with our legal advisers, who receive them first on our behalf.
- Your copy is the only copy. Once destroyed, we cannot reissue, resend or reconstruct the report. If it is lost, a new investigation would be required.
- We cannot deliver without verified identity. Invalid contact details mean no report can be issued, to protect you and any party named in it.
- During an investigation, your material sits in pieces on offline systems in Australia with no internet access, internal or external. Nothing on it can be reached over a network.
Who we are
Sentinel Due Diligence Pty Ltd is an Australian company providing forensic due diligence and investigative research services. This policy covers information we collect through this website and information we handle in the course of an engagement.
Privacy enquiries — including access requests, correction requests and complaints — are handled in conjunction with our legal advisers, who receive them first and respond on our behalf where appropriate. A compliance copy of all privacy correspondence is retained separately.
For any question about this policy or about information we may hold, contact [email protected]. This address reaches our legal advisers directly.
What we collect, and when
If you send an enquiry through our contact form, we receive only what you type into it:
- Your name
- Your email address
- Your phone number — optional
- The purpose of your enquiry — selected from a list
- Any details you choose to include in the free-text field
If you use the live chat, we receive the messages you send and — if you choose to provide them — your name and email address. Chat is a first-contact enquiry channel, not a client record. Nothing you type in chat is linked to any client file or investigation.
Our applications do not collect or retain IP addresses, browser fingerprints, device identifiers, advertising IDs, location data, or behavioural analytics. We do not use third-party tracking scripts, pixels or profiling tools.
Standard web server access logs record request information — including IP address, timestamp, requested path and user agent — for the sole purpose of security and abuse prevention. This is the same practice used by every website and by Cloudflare in front of it, and it is what allows us to detect and defend against attacks. Those logs are rotated on a short cycle and destroyed. We do not use them for analytics, profiling, marketing or any other purpose.
When you access the delivery portal, standard technical information is recorded — see section 06 for what is logged and how long it is retained.
A single session cookie is used to protect the enquiry form against cross-site request forgery. The live chat stores a random session identifier in your browser so your conversation is preserved if you navigate between pages. Neither contains personal information, and neither is used for tracking.
Where your information is held
Our infrastructure runs on segregated systems, each dedicated to a single function. No system holds more than it needs to, and no system has access to the others. The result is that a compromise of any one environment does not expose the others, and nothing sensitive sits on a system reachable from the public internet unless it has to.
Colocation — dedicated system
Serves this website, the enquiry form and the live chat. Holds no reports, no investigation material and no client engagement files at any point.
Colocation — dedicated system
Handles email and nothing else. Held under EU data protection law. Cleared when the matter is destroyed.
Offline — no network access
Segregated local systems with no internet access. All client data, evidence and draft reports are held here, in pieces, and nowhere else.
Delivery only
The portal used to deliver completed reports to clients. Reports are transferred to it from the offline systems by physical media, held for the seven-day access window, and destroyed on client confirmation.
Encrypted drives — caged
All retained records are held on encrypted hard drives in a physically caged environment in Australia. The drives have no network connection of any kind and cannot be read without being physically attached to a dedicated reader inside that environment.
During an investigation
Once an engagement begins, all client data, working files and draft reports are held on segregated systems located in Australia with no internal or external internet access. Those systems are not reachable over any network. They have no connection to our website, our mail server, or any other online system.
The material is held in pieces across those systems rather than as a single assembled document. This means that while an investigation is underway, no report, evidence pack or client record can be exfiltrated over a network — because there is no network to exfiltrate it over. The material exists only on physical media inside that environment, and leaves it only when the report is assembled and prepared for delivery.
Our internet-connected systems hold no client investigation material at any time during an engagement. Live chat operates on a separate system entirely and is never linked to an investigation.
How delivery works — and when we destroy
Your completed report is never sent as an email attachment. Attachments sit in mail servers, get forwarded, get backed up, and stay reachable long after anyone intended. We do not do it.
Instead, the report is assembled on the offline system, transferred to the delivery portal by physical media, and placed in a portal accessible only to you. What happens next follows a defined sequence. Nothing is destroyed until step four is complete.
Report transferred to your private portal
The finished report and complete evidence pack are moved from the offline system by physical media and placed in a portal accessible only to you. Access is time-limited to seven days from the moment your link is issued.
You receive your access link
A link is sent to the email address confirmed at intake. It opens the portal, where you can view the report and the evidence pack. The link is tied to your login — it cannot be forwarded to someone else, and it cannot be reused once the access window closes.
You view and download
A download produces a PDF of the report and the supporting files. You can print it, save it, or store it wherever you choose. This is the point at which the material passes into your control. The download must be completed within the seven-day window.
You confirm receipt in the portal
Once the download completes, the portal asks you one question: did you receive your report? You select yes or no. Your answer determines what happens next.
Immediate, unrecoverable destruction
On your confirmation, the report and every associated file are destroyed immediately. The data is overwritten — not merely deleted or moved to a recycle bin. Every drive holding that data is purged at the same time, including the mirrored copy. There is no versioned backup that retains deleted data, no residual record on the portal, and nothing left on any connected system.
From that moment, the material is unrecoverable — by you, by us, by anyone. We cannot reissue it, resend it, or reconstruct it.
The portal locks. Nothing is destroyed.
If the download did not complete, or a file did not arrive, the portal locks immediately. Nothing is destroyed — the material is held pending resolution.
Contact us, and we will resolve the delivery and issue fresh access so the download can be completed and confirmed. The same process then applies.
If the seven-day window closes without a download and confirmation, the portal locks automatically. Nothing is destroyed at that point. The material is held until you contact us, and we will issue fresh access on request. Material is only ever destroyed after a confirmed download.
If you lose the report or evidence pack after download and confirmation, we cannot reissue, resend or reconstruct it. A lost report means a new investigation, scoped and charged as a fresh matter.
What we keep
Three categories of record survive an engagement. None contains investigation material.
Tax invoices
Australian tax law requires us to retain invoice records for five years from the date they are issued. We comply with that requirement and no more.
Invoices carry no investigation information. They do not name the entity you asked us to look at, describe the findings, or record what the matter concerned. They record that a professional service was rendered and a fee was paid. That is all.
Because no engagement record exists, invoices cannot be linked to any investigation by us or by anyone else.
Privacy correspondence
Emails and other correspondence you send us regarding privacy — access requests, correction requests, complaints, or general privacy enquiries — are retained in identifiable form for 24 months from the date of last correspondence.
This period exists so that we can demonstrate compliance with the Australian Privacy Principles if our handling of a request is ever reviewed or challenged. It is a compliance record, not a client file.
At the end of that period, the correspondence is de-identified and retained indefinitely as an anonymised record. Names, email addresses, matter references, dates and any other identifying detail are removed. What survives is the substance of the issue, the response given and the outcome — held so that we can examine patterns over time and improve how we handle privacy enquiries.
De-identification is performed manually, not by automated redaction. Re-identification risk is assessed before any record is retained in de-identified form. Where that risk cannot be adequately addressed — for example, because the substance of a complaint describes a specific matter in sufficient detail — the record is destroyed rather than retained.
Privacy correspondence is received and handled by our legal advisers, with a duplicate retained in a separate compliance archive. The archive sits on the same encrypted-drive environment described below. It is not accessed during investigations, is not linked to any engagement file, and contains no investigation material.
Portal access records
When you access the delivery portal — whether you view the report, download it, or confirm receipt — a record is created of that access. This is standard practice for any system that delivers sensitive material, and it exists to protect both parties.
The record includes:
- Date and time of each portal interaction
- Login information — which account accessed the portal
- Connecting IP address
- Browser and device information — the technical signature sent by your browser
- Actions taken — pages viewed, files downloaded, and the confirmation response
These records are retained for five years from the date of access. They serve a specific purpose: if a dispute ever arises about whether a report was delivered or downloaded, the log is the factual record. Without it, neither party could demonstrate what occurred.
Portal access records contain no investigation material. They record that access occurred — not what was in the report or what you did with it afterwards.
Where all retained records are stored
All three categories of retained record — invoices, privacy correspondence, and portal access records — are stored in Australia only. They are held on encrypted hard drives inside a physically caged and restricted environment.
The drives are not connected to any network. They have no internet connection and no connection to any local network or system. They are not held in a server, a NAS, or any device with a network interface. They are physical drives, stored offline, and nothing on them can be reached remotely.
Records are written to a mirrored pair — two drives holding identical copies at all times. When a record is deleted, the deletion is propagated to both drives on an automated schedule, so the data does not persist on either drive beyond the deletion cycle. There is no versioned archive, no cold-storage copy, and no retained history of deleted records. Once purged, the record exists on no drive in our possession.
The drives are encrypted, with the decryption key held on a single dedicated computer located inside the same caged environment. That computer has no network connection. It is maintained and tested on a scheduled basis to ensure that the retained records remain retrievable for the full period we are required to keep them.
To read any data, a drive must be physically removed from the cage and attached to that dedicated reader by hard-wired connection. This is the only method by which retained records can be accessed. There is no remote access path of any kind.
Access to the caged environment is restricted and logged. Any person entering the cage is recorded, with the reason for access and the time. Records do not leave that environment except where we are legally compelled to produce them.
We share nothing with third parties
We do not share, sell, license, disclose, publish or otherwise make available any investigation information to any third party. Ever. Not to other clients, not to commercial partners, not to data brokers, not to advertisers, not to research firms, not to anyone.
This is not a marketing position — it is a structural one. Once a report is delivered, confirmed and destroyed, there is nothing left in our possession to share, even if someone asked us to.
Privacy enquiries are handled by our legal advisers as described in section 01. That is a professional handling arrangement, not a disclosure of client matter information, and it exists specifically to protect the exercise of your privacy rights.
The one narrow exception is where we are compelled by a court order, subpoena or regulatory notice with the force of law. If that ever occurred, we would tell you unless we were legally prohibited from doing so. It has not occurred to date.
Identity confirmation before delivery
We cannot deliver a completed report or any associated information unless your identity and contact details have been confirmed. If the contact information provided at enquiry is invalid, incomplete or unverifiable, delivery cannot proceed.
This protects you and it protects any party named in the report. A due diligence report contains sensitive material about named individuals and entities. It should reach the person who commissioned it, and no one else.
If we cannot verify contact, we will attempt to reach you through the details you supplied. If those details fail, the matter cannot be concluded.
No tracking, no analytics, no profiling
This website does not use Google Analytics, Facebook Pixel, Hotjar, or any other behavioural tracking or advertising platform. We do not build profiles of visitors. We do not sell or share visitor data. We do not run retargeting.
Our DNS and edge security are provided by Cloudflare, which may set its own technical cookies for security and DDoS protection. Those cookies are Cloudflare's and are governed by Cloudflare's own privacy policy. We do not use Cloudflare's analytics products.
The only cookie set by this site itself is the session cookie described in section 02.
The live chat stores a random session identifier in your browser's local storage. That identifier is not a cookie, contains no personal information, and is used only to keep your conversation intact while you navigate between pages. It is not shared with any third party and is not used to track you across sites.
The delivery portal is separate from this website. It uses authentication cookies to maintain your session while logged in, and it records access events as described in section 06. Those records are for security and dispute resolution — not for analytics, profiling or marketing.
Your rights
Under the Australian Privacy Principles, you may request access to personal information we hold about you, and ask us to correct it if it is inaccurate.
In practice, because we destroy client material after confirmed delivery, what we hold about you is almost always limited to a tax invoice if you have engaged us, correspondence you have sent us if you have made a privacy enquiry, portal access records if a report has been delivered to you, or a brief contact history if none of the above apply. Chat conversations are held only for 15 days after they close, and are deleted automatically.
Access and correction requests should be sent to [email protected]. They are handled by our legal advisers, and we aim to respond within 30 days as required under the Australian Privacy Principles.
Where privacy correspondence has been de-identified after the 24-month retention period, the resulting record no longer constitutes personal information and falls outside the scope of an access request. This is explained in section 06.
If you are not satisfied with our response, you may refer the matter to the Office of the Australian Information Commissioner.
Changes to this policy
If we change this policy, we will update it on this page and adjust the effective date below. We will not email you to tell you about the change — we do not retain your contact details after an engagement, so we have no way to reach you. That is a direct consequence of the retention policy, and we consider it a reasonable trade.
Material changes will be flagged at the top of the page for a period after they take effect.
Effective date and contact
This policy is effective from 9 October 2026 and supersedes any earlier version.
Questions about this policy, or about information we may hold, should be sent to:
Live chat is a first-contact enquiry channel, not a client record. Nothing you type in chat is linked to any client file or investigation, and no investigation material ever passes through it.
Conversations are stored on our website infrastructure while open, and deleted automatically 15 days after they close. We keep that short window so we can review how enquiries were handled and improve our responses — not to retain a record of you.
Chat is available Monday to Friday, 8:00am to 5:00pm. Outside those hours, the chat is closed and you are directed to the contact form or email instead.
Ask us anything about how we handle your information.
If something in this policy needs clarifying before you engage us, ask. We would rather answer a question now than have you find out something later.
Send a Confidential Enquiry[email protected]