Privacy Policy

Version 2026-09

Draft template — not yet reviewed by counsel. Written against the Australian Privacy Principles; highlighted items are placeholders. Not legal advice.

1. What we collect, and why

DataPurposeBasis
Work email address, organisation name, role in the workspaceCreate and secure your account and workspace; invite teammates; contact you about the ServicePerformance of the agreement
Sign-in events, IP address, browser detailsSecurity, rate limiting, abuse prevention, the workspace audit trailLegitimate interests (security)
Your workspace model (capabilities, systems, processes, business cases, uploaded workbooks)Providing the Service — this is your Customer Data; it is designed to hold organisational, not personal, informationPerformance of the agreement; you are the controller
Billing details (name, email, plan; card data is held by Stripe only)Subscriptions, invoices, taxPerformance of the agreement; legal obligation
Support correspondenceAnswering you and improving the ServiceLegitimate interests

We do not use analytics trackers or advertising cookies. The only cookie is a signed session cookie required to keep you signed in.

2. Where data is stored and who processes it

The Service runs on Cloudflare (Pages Functions and D1 database). Data is stored in Cloudflare's data-centre network; edge compute is global by design. Our subprocessors are listed in the DPA: Cloudflare (hosting, storage), Stripe (payments), [Clerk (identity), once enabled]. If you need data pinned to a specific region or a single-tenant deployment, ask us — a region-pinned hosted option and the offline zero-egress edition exist for that purpose.

3. Optional AI features

AI assistance is off by default. When you enable it, text is sent to an endpoint you configure (your own provider or an in-network model); we show you the exact text first and redact identifying names by default. We do not train models on your data and we do not operate a shared default AI endpoint.

4. Retention

5. Your rights

You can access and export your workspace data at any time from the workspace page or the app. You can ask us to correct or delete personal information, or complain about our handling of it, at [privacy contact email]. We will respond within 30 days. If you are not satisfied you may complain to the Office of the Australian Information Commissioner (OAIC) or your local supervisory authority.

6. Security

Encryption in transit (TLS) and at rest (platform-managed); tenant isolation enforced server-side; signed HttpOnly session cookies; least-privilege secrets management; an append-only audit trail per workspace; rate limiting and bot protection on sign-up. We hold no security certification yet; controls are being documented toward SOC 2 / ISO 27001. We notify affected customers of an eligible data breach without undue delay in accordance with the Notifiable Data Breaches scheme.

7. Children

The Service is for organisations and is not directed at children under 16.

8. Changes and contact

We will notify workspace administrators of material changes at least 30 days in advance. Contact: [Operator legal name], [postal address], [privacy contact email].