Privacy Policy

LEGAL

Last updated 31 March 2026

01

About This Policy

Nooriam Group (comprising Nooriam Pty Ltd ACN 654 246 509, Nooriam Sarjana Pty Ltd ACN 666 673 623, and Nooriam Alfareria Pty Ltd ACN 666 513 515, collectively “Nooriam”, “we”, “us”, “our”) is a techno-legal infrastructure company. We build legal infrastructure for the digital economy, including tools and systems for authenticating Nooriam Data Objects, registering and governing AI systems, executing programmable legal instruments, and establishing legally operative records across organisational boundaries. This Privacy Policy should be read in conjunction with Nooriam’s Terms of Use. Terms used in this Privacy Policy have the same meaning as defined in Nooriam’s Terms of Use. This Privacy Policy explains how we collect, use, disclose, and protect personal information across the Nooriam ecosystem. The Services operate across two access tiers. Certain non-confidential information held in The Registry is publicly accessible without an account. All other Services, including the full Nooriam platform and all transactional and registry management functions, are accessible only to users who hold a verified Nooriam account and are logged in. These account-required Services are collectively referred to as “Nooriam Core”. In this Policy, “Nooriam Data Object” means any data object created, registered, or authenticated through the Nooriam platform, including a Legally Authenticated System (LAS), a Legally Authenticated Dataset (LAD), a Smart Legal Contract (SLC), and any other data object product within the Nooriam ecosystem. This Policy applies to all individuals whose information we hold, whether as public users of The Registry, Nooriam Core users, counterparties, job applicants, or website visitors. Because our products process authenticated personal and legal data as a core function, we treat privacy not as a compliance checkbox but as a foundational design principle. Our Techno-Legal Infrastructure Framework (TLIF) embeds privacy-by-design at the system level, and this Policy reflects those commitments. We review this Policy regularly and revise it as our platform, products, and the applicable law evolve. The current version is published at nooriam.com. Continued use of our services constitutes acceptance of the then-current Policy. We will notify users of material changes by email or prominent website notice at least 30 days before they take effect. Questions about this Policy may be directed to our Privacy Officer at info@nooriam.com. Applicable law: This Policy is primarily governed by the Privacy Act 1988 (Cth), as amended by the Privacy and Other Legislation Amendment Act 2024 (Cth). It also addresses obligations under the EU General Data Protection Regulation 2016/679 (GDPR), the UK General Data Protection Regulation and Data Protection Act 2018, the Singapore Personal Data Protection Act 2012 (PDPA), and applicable US state privacy laws including the California Consumer Privacy Act (CCPA) as amended by the CPRA. Where these frameworks impose different standards, we apply the higher standard.

02

Information We Collect

The Registry: Special Considerations

03

The Registry is Nooriam’s independent legal registry for Data Objects. It is real-time, machine-readable, and legally operative across organisational boundaries. Because The Registry functions as an authoritative legal record, it carries privacy implications that are distinct from those arising in relation to other Nooriam products, and this section addresses those implications directly.

How We Use Your Information

04

We use personal information only for purposes that are lawful, proportionate, and disclosed to you. Our primary purposes are:

Disclosure of Personal Information

05

Security

06

We implement technical, organisational, and physical measures designed to protect personal information against unauthorised access, modification, disclosure, loss, and misuse. These measures include access controls, encryption, audit logging, and regular security reviews. We require all personnel and third-party service providers with access to personal information to be subject to appropriate confidentiality obligations and to maintain security standards commensurate with the sensitivity of the information they handle. Transmission of information over the internet carries inherent risks that we cannot eliminate. By using our services, you acknowledge and accept this. We cannot guarantee or accept liability for data theft or unauthorised access beyond our reasonable control. In the event of a data breach that is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) in accordance with the Notifiable Data Breaches scheme under Part IIIC of the Privacy Act 1988 (Cth), as amended. Where the GDPR or UK GDPR applies, we will also notify the relevant supervisory authority within 72 hours of becoming aware of the breach.

Cookies and Tracking Technologies

07

Cookies are small text files placed on your device by websites you visit. We use cookies and similar technologies to operate our website, protect it against security threats, and (with your consent) understand how it is used.

Your Privacy Rights

08

Depending on your jurisdiction and the circumstances of our processing, you may have the following rights in relation to your personal information. All rights relating to erasure, deletion, or removal of data are subject to the limitations described in Section 2.4. In particular: where personal information forms part of a multi-party record, erasure cannot be effected unilaterally without the consent of all parties or other lawful authority; and where personal information appears in a registry entry, the historical record of that entry will be preserved, with any change in status noted by annotation rather than deletion. We will always communicate clearly when these limitations apply to a specific request.

Children

09

Our platform and services are not directed at individuals under 16 years of age and we do not knowingly collect personal information from children. If we become aware that we have inadvertently collected personal information from a child without appropriate consent, we will take steps to delete that information promptly.

Contact and Complaints

10

If you have questions about this Policy, wish to exercise your rights, or wish to submit a complaint, please contact:

Privacy Officer, Nooriam Group Email: info@nooriam.com Phone: +61 401 825 175 Website: nooriam.com Please allow up to 30 days for requests to be processed (45 days for US requests). If you are not satisfied with our response, you may escalate your complaint to the relevant authority for your jurisdiction:

(a) Australia: Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.

(b) EU: your local data protection authority.

(c) UK: the Information Commissioner’s Office (ICO) at ico.org.uk.

(d) Singapore: the Personal Data Protection Commission (PDPC) at pdpc.gov.sg.

(e) United States: the Federal Trade Commission (FTC) or your state Attorney General’s office.

Appendix: Legislative Framework

This Policy is informed by the following legislation and frameworks:

(a) Privacy Act 1988 (Cth), including the Australian Privacy Principles (APPs).

(b) Privacy and Other Legislation Amendment Act 2024 (Cth), including amendments to the Notifiable Data Breaches scheme, the new statutory tort for serious invasions of privacy, and enhanced enforcement provisions.

(c) General Data Protection Regulation (EU) 2016/679 (GDPR), applicable to personal data of individuals in the EEA.

(d) UK General Data Protection Regulation (UK GDPR) and Data Protection Act 2018, applicable to personal data of individuals in the United Kingdom.

(e) Personal Data Protection Act 2012 (Singapore) (PDPA), as amended, applicable to personal data of individuals in Singapore.

(f) California Consumer Privacy Act 2018 as amended by the California Privacy Rights Act 2020 (CCPA/CPRA), and substantially equivalent state privacy legislation in other US states.

(g) Nooriam Techno-Legal Infrastructure Framework (TLIF), which embeds privacy-by-design across our product suite.

This Policy was reviewed and updated in March 2026. It supersedes all prior versions. Nooriam is not a law firm and this Policy does not constitute legal advice. If you require legal advice about your privacy rights, please consult a qualified legal practitioner.(b)