Trust & procurement
What you need for a vendor-risk check.
A plain summary of who we are, how data is handled on this website and in client work, which providers we use and where, and how to request a security questionnaire or NDA. The legal detail is in our Privacy Policy and AI Use Notice.
Last updated 11 October 2026.
At a glance
- Business
- S Farsoodeh Saligheh & A Montazami, trading as Melora Digital
- ABN
- 68 158 833 095
- Location
- Melbourne, Victoria, Australia — delivery in Australia and internationally
- Established
- 2025
- Security and privacy contact
- Support@meloradigital.com
Assurance status — stated plainly
We don’t currently hold formal certifications such as ISO/IEC 27001 or SOC 2, and we don’t claim panel membership or government approval. We will answer your security questionnaire honestly, tell you exactly which controls apply to your engagement, and agree data-handling terms in writing before any work with your information begins.
Client engagements: how your data is handled
- Your data stays yours. We use client information only to deliver the engagement, and return or delete it at the end on request.
- No client data in AI tools by default. We don’t put your confidential or personal information into AI tools unless you’ve agreed to it in the engagement terms and the tool’s terms prevent it being used for training.
- Residency assessed per engagement. Where data must stay in Australia or inside your environment, we design for that — for example Australian-region cloud services or private/local models. See Security & deployment.
- Least privilege. We ask only for the access the work needs, use your accounts and approval processes where possible, and remove access when the work ends.
- People stay accountable. Every solution we design has named human approval points for decisions that matter.
This website and the AI consultation: providers and locations
| Provider | What they do | Data involved | Location |
|---|---|---|---|
| Hostinger | Website hosting, application, MySQL database, email, daily backups | Website enquiries, assessment reports, consultation transcripts and summaries | Hostinger data centres (may be outside Australia) |
| Cloudflare (Turnstile) | Bot protection on forms | Technical browser signals only; no tracking cookies | Global network |
| Surplus Intelligence | Routes AI requests to model and voice providers; per its policy it does not store request content or use it for training | Consultation text (contact details removed first), short voice clips in some browsers, reply text for speech | USA |
| Amazon Bedrock (via Surplus) | Runs the primary language model (DeepSeek) | Consultation text | USA and other regions |
| OpenAI (via Surplus) | Fallback language model if the primary is unavailable | Consultation text | USA |
| xAI and ElevenLabs voices (via Surplus) | Turn the consultant’s replies into speech | Reply text only | USA and other regions |
| Your browser maker (Google, Apple or Microsoft) | Speech recognition in Chrome, Safari and Edge, under their own terms | Your voice, in the browser; we receive only the text | Varies |
Before any text reaches an AI model we automatically remove names, email addresses and phone numbers we can detect. Providers outside Australia handle data under their own terms — see “Overseas disclosure” in our Privacy Policy.
Data lifecycle
| Information | Where it’s held | How long |
|---|---|---|
| Contact enquiries and report requests | Database and Support@ mailbox | 24 months after last contact, then deleted |
| AI consultation transcript and summary | Database (encrypted at rest); summary PDF emailed to Support@ | 180 days, then the transcript is deleted |
| Consultation audio | Not recorded or stored by Melora | Not retained |
| Assessment answers | Your browser; an anonymous score summary is stored | Anonymous scores kept for comparison (no personal data) |
| Fair-use checks | One-way keyed hashes of email and phone | 12 months |
| Backups | Hostinger daily backups | Rolled over on Hostinger’s backup cycle |
You can ask us to access, correct or delete your information at any time by emailing Support@meloradigital.com. Deletion covers our database and mailbox; copies in Hostinger’s rolling backups expire on their normal cycle.
Security practices
- HTTPS everywhere with HSTS, a strict Content Security Policy, and protection against framing, sniffing and cross-site requests.
- Consultation transcripts and summaries encrypted at rest; secrets kept out of source code.
- Admin access limited to named Melora staff through single-use sign-in links, with an audit trail of admin actions.
- Bot protection, rate limits and spend caps on all public forms and AI features.
- Daily backups by our hosting provider.
Security contact and incidents
If you think you’ve found a security issue, email Support@meloradigital.com (see also security.txt). Please act in good faith: don’t access data that isn’t yours or disrupt the service, and give us a reasonable chance to fix the issue before disclosing it. If a data breach is likely to cause serious harm, we will notify affected people and the OAIC under the Notifiable Data Breaches scheme.
Request a security questionnaire, NDA or data terms
Tell us what your process needs — a security or AI questionnaire, an NDA before sharing details, or data-processing terms — and we’ll respond with what applies to your engagement. Please don’t include confidential information in the first message.
Request procurement information →
Related: Privacy Policy · AI Use Notice · Terms of Use · Cookie Notice · Security & deployment