Privacy Policy
Cassandra Research Pty Ltd
Effective date: 30 June 2026
Last updated: 30 June 2026
Version: 2.0
1. About this Policy and who we are
This Privacy Policy explains how Cassandra Research Pty Ltd ("Cassandra", "we", "us" or "our") collects, holds, uses, discloses and protects personal information. It applies to our websites (including cassandraresearch.com and cassandratax.com), our software platform and related products and services, and any other dealings you have with us, whether online or offline (collectively, the "Services").
We are an Australian company that provides an artificial-intelligence research and workflow platform for tax and legal practitioners. Our Services are intended for use by professionals and businesses, not by consumers or children.
We are committed to handling personal information in accordance with the Privacy Act 1988 (Cth) ("Privacy Act") and the thirteen Australian Privacy Principles ("APPs") contained in Schedule 1 to that Act, together with any other privacy laws that apply to us, including the Privacy (Tax File Number) Rule 2015 and the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act.
If you have any questions about this Policy, contact our Privacy Officer using the details in Section 20.
2. What is personal information and sensitive information
Personal information means information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether the information is true or not and whether or not it is recorded in a material form. Examples include a person's name, contact details, and, in some circumstances, online identifiers.
Sensitive information is a special category of personal information defined in the Privacy Act. It includes information about an individual's health, racial or ethnic origin, political opinions, religious beliefs, sexual orientation, criminal record, and biometric or genetic information. We do not seek to collect sensitive information through the Services and ask that you do not submit it.
Financial, tax and business information about an individual is personal information, and we treat it as confidential and high-risk, but it is generally not "sensitive information" as that term is defined in the Privacy Act. Tax File Number information is dealt with separately in Section 11.
3. The personal information we collect
We collect personal information that is reasonably necessary for, or directly related to, our functions and activities. The kinds of personal information we collect include:
(a) Account and identity information. Your name, business name, position, email address, telephone number, login credentials and account preferences.
(b) Content you submit to the Services ("User Content"). Queries, prompts, documents, files and other material you upload to or generate using the platform. User Content may contain personal information about third parties, including your clients. Where you submit personal information about another individual, you are responsible for ensuring you are authorised to do so and that the individual has been made aware of how their information may be handled, as described in this Policy. We ask that you do not submit more personal information about third parties than is necessary, and that you avoid submitting Tax File Numbers and other government related identifiers (see Section 11).
(c) Payment and billing information. Subscription, billing and transaction records. Your card and payment details are collected and processed directly by our third-party payment processor (Stripe) and are not stored by us in full (see Sections 9 and 10).
(d) Technical and usage information. IP address, device and browser information, log data, pages and features accessed, and usage patterns, collected automatically when you use the Services (see Section 16).
(e) Communications. Information you provide when you contact us for support, sales, feedback or other enquiries, including the content of those communications.
(f) Information from third parties. Where lawful, we may collect personal information from third-party sources such as your authorised colleagues, our service providers, identity or verification providers, and publicly available sources, where it is impracticable to collect it from you directly.
If we receive personal information we did not solicit, we will deal with it in accordance with APP 4, including by destroying or de-identifying it where it would not have been lawful for us to collect it and it is not contained in a Commonwealth record.
4. How we collect personal information
We collect personal information by lawful and fair means, and (where reasonable and practicable) directly from you — for example, when you register, configure your account, submit User Content, make a payment, complete a form, or communicate with us. We also collect technical information automatically through cookies and similar technologies, and we may collect information from the third-party sources described in Section 3(f).
Where we collect personal information about you, we will take reasonable steps to notify you, or ensure you are aware, of the matters set out in APP 5, including the purposes of collection, the consequences if it is not provided, the types of entities to which we usually disclose it, and that this Policy contains information about how to access and correct your information and how to complain.
5. Why we collect, hold, use and disclose personal information
We use and disclose personal information for the primary purposes for which it was collected, for related secondary purposes you would reasonably expect, and otherwise as permitted under APP 6 or with your consent. These purposes include:
- providing, operating, maintaining and securing the Services, including processing your User Content to generate research outputs;
- creating and administering your account and verifying your identity;
- processing payments and managing billing and subscriptions;
- providing customer and technical support and responding to your enquiries;
- improving, developing and testing the Services, and conducting research and analytics, using de-identified or aggregated information wherever practicable (see Section 6);
- maintaining the security and integrity of the Services, and detecting, investigating and preventing fraud, misuse, and security incidents;
- complying with our legal and regulatory obligations, and establishing, exercising or defending legal claims;
- sending you service, transactional and administrative communications; and
- where permitted, sending you marketing communications (see Section 10).
If we propose to use or disclose your personal information for a purpose that is not permitted under the Privacy Act, we will seek your consent.
6. Artificial intelligence, automated processing and model training
The Services use artificial-intelligence and machine-learning technologies, including third-party large language models and embedding services, to process User Content and generate outputs.
Model training. We do not use your User Content, or personal information contained in it, to train, fine-tune or improve generally available AI models, and we contractually require our AI sub-processors not to use your User Content to train their models, except to the extent strictly necessary to provide the Services to you. Where we use information to improve our own Services, we use de-identified or aggregated information that does not identify you or any individual.
Automated decisions. The Services are a research and drafting tool. We do not use a computer program to make decisions about you that produce legal effects concerning you or otherwise significantly affect your rights or interests. The outputs of the Services are intended to assist a qualified professional and are not a substitute for the exercise of independent professional judgement. From 10 December 2026, if we arrange for a computer program to use personal information to make a decision that could reasonably be expected to significantly affect an individual's rights or interests, we will update this Policy to disclose the kinds of personal information used and the kinds of decisions made, as required by APP 1.7 to APP 1.9.
7. Dealing with us anonymously or by pseudonym
Where it is lawful and practicable, you have the option of dealing with us anonymously or by using a pseudonym (APP 2). However, because the Services are a secured, account-based professional platform, we generally cannot provide the Services, process payments, or provide support without collecting information that identifies you.
8. To whom we disclose personal information
We disclose personal information to the following categories of recipients, in each case only as reasonably necessary for the purposes in Section 5:
- Service providers and sub-processors who perform functions on our behalf, including cloud hosting and infrastructure providers, artificial-intelligence model and embedding providers, database and vector-search providers, analytics, identity and security providers, and customer-support tools;
- Payment processors, who process your payment information directly;
- Professional advisers, such as our lawyers, accountants and auditors;
- Government agencies, regulators, courts and law-enforcement bodies, where required or authorised by law, or to protect the rights, property or safety of any person;
- Parties to a business transaction, in connection with any actual or proposed merger, acquisition, financing, or sale of assets, subject to appropriate confidentiality protections; and
- Other parties with your consent or as otherwise permitted by the Privacy Act.
The material sub-processors we currently rely on to deliver the Services are:
- Voyage AI — text-embedding services used to index and retrieve content (United States of America);
- Vercel — application hosting and infrastructure (United States of America); and
- Stripe — payment processing (United States of America).
We require our service providers and sub-processors to handle personal information consistently with the APPs and to use it only for the purposes for which we engage them. We may update our sub-processors from time to time; the current list above is maintained as part of this Policy and the latest version is also available on request from the contact in Section 20.
We do not sell personal information, and we do not disclose personal information to third parties for their own marketing purposes.
9. Disclosure of personal information overseas (APP 8)
Some of the personal information you provide to us, including personal information contained in your User Content, is disclosed to and processed by recipients located outside Australia. This is because we rely on global cloud, artificial-intelligence and payment providers to deliver the Services.
Based on our current providers, personal information may be disclosed to, stored in, or accessed from:
- The People's Republic of China — our artificial-intelligence language model provider (DeepSeek), used to process queries and User Content; and
- The United States of America — our embedding provider (Voyage AI), our hosting and infrastructure provider (Vercel), and our payment processor (Stripe).
Before disclosing personal information to an overseas recipient, we take steps that are reasonable in the circumstances to ensure the recipient does not breach the APPs in relation to that information (APP 8.1). However, you should be aware that overseas recipients are subject to the laws of the countries in which they operate, which may differ from, and provide a lower standard of protection than, Australian privacy law, and it may not be practicable for you, or for us, to seek redress in those jurisdictions.
By submitting User Content or other personal information to the Services with knowledge of this Section, you acknowledge that it may be disclosed to recipients in the countries listed above. To reduce risk, we strongly recommend that you do not submit personal information about third parties — and in particular Tax File Numbers and identifying client details — beyond what is necessary for your query (see Section 11). Where overseas disclosure of an individual's personal information requires consent under the Privacy Act, we will obtain it before disclosure.
10. Direct marketing
We may use your personal information to send you marketing communications about our Services where you would reasonably expect us to do so, or where you have consented, in accordance with APP 7, the Spam Act 2003 (Cth), and the Do Not Call Register Act 2006 (Cth).
Every marketing email we send contains a means to opt out. You can also opt out at any time by contacting us using the details in Section 20. We will action your request within a reasonable period. We do not use sensitive information for direct marketing, and we do not provide your personal information to third parties for those parties' direct marketing.
11. Tax File Numbers and government related identifiers
Tax File Number ("TFN") information is subject to specific protections under the Privacy Act and the Privacy (Tax File Number) Rule 2015, and the use and disclosure of government related identifiers (such as TFNs and ABNs) is restricted under APP 9.
We do not require, and ask that you do not submit, TFNs or other government related identifiers as part of your User Content. If TFN information is nonetheless provided to us, we will use and disclose it only for purposes authorised by taxation law, will not use it as a general identifier, will protect it from misuse, loss and unauthorised access, and will take reasonable steps to securely destroy or de-identify it when it is no longer required by law to be retained.
12. Security of personal information (APP 11)
We take steps that are reasonable in the circumstances to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure. These steps include both technical and organisational measures, such as encryption in transit and, where applicable, at rest, access controls and authentication, network and application security controls, logging and monitoring, vendor due diligence, staff confidentiality obligations, and internal policies and training.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for keeping your login credentials confidential and for the security of the devices and networks you use to access the Services.
13. Data breaches (Notifiable Data Breaches scheme)
We maintain a data-breach response plan. If we suspect that an eligible data breach affecting personal information has occurred, we will assess it promptly, and in any event within the timeframe required by Part IIIC of the Privacy Act. Where a breach is likely to result in serious harm to one or more individuals, and we are unable to prevent that harm through remedial action, we will notify the affected individuals and the Office of the Australian Information Commissioner ("OAIC") as required by the Notifiable Data Breaches scheme.
14. How long we keep personal information (data retention)
We hold personal information only for as long as it is reasonably necessary for the purposes for which it was collected, to provide the Services, and to comply with our legal, regulatory, accounting and record-keeping obligations. Our general approach is:
- Account and identity information is retained for the life of your account and for up to twelve (12) months after your account is closed, after which it is destroyed or de-identified.
- User Content is retained for the duration of your account and is deleted or de-identified within ninety (90) days of account closure, unless we are required to retain it by law or a legal hold.
- Billing, payment and transaction records are retained for seven (7) years to meet our obligations under the Corporations Act 2001 (Cth) and taxation law.
- Support and communications records are retained for as long as reasonably necessary to manage our relationship with you and to handle any related disputes.
When personal information is no longer needed for any purpose for which it may lawfully be used, and we are not required by law or a court or tribunal order to retain it, we take reasonable steps to destroy it or to ensure it is de-identified.
15. Accessing and correcting your personal information (APP 12 and APP 13)
You may request access to the personal information we hold about you, and ask us to correct it if it is inaccurate, out of date, incomplete, irrelevant or misleading. To make a request, contact our Privacy Officer using the details in Section 20. We may need to verify your identity before processing your request.
We will respond to your request within a reasonable period and will provide access in the manner you request where it is reasonable and practicable to do so. There is no charge for making a request, although we may charge a reasonable cost for giving access, and we will tell you in advance. In limited circumstances we may decline a request — for example, where access would have an unreasonable impact on the privacy of others, or where a request is frivolous or vexatious, or where the law otherwise permits us to refuse. If we refuse, we will give you written reasons and information about how to complain. If we correct information that we have previously disclosed, you may ask us to notify the recipients of the correction, and we will take reasonable steps to do so.
16. Cookies and similar technologies
We use cookies, pixels, tags and similar technologies to operate and secure the Services, remember your preferences, authenticate your session, and understand and improve how the Services are used. You can manage or disable cookies through your browser settings, although some features of the Services may not function properly if you do. We do not currently respond to browser "Do Not Track" signals; where required, we provide controls and choices through this Policy and through your browser and cookie settings.
17. Children
The Services are intended for professional and business users and are not directed to, or intended for use by, individuals under 18 years of age. We do not knowingly collect personal information from children. If we become aware that we have collected personal information from a child without appropriate authority, we will take reasonable steps to delete it, unless we are required by law to retain it.
18. Third-party websites and services
The Services may contain links to, or integrate with, third-party websites and services that we do not control. This Policy does not apply to those third parties. We encourage you to review the privacy policies of any third-party website or service you use.
19. Complaints
If you believe we have breached the Australian Privacy Principles or otherwise mishandled your personal information, please contact our Privacy Officer using the details in Section 20. Please provide enough detail for us to investigate. We will acknowledge your complaint, investigate it, and respond to you within a reasonable period.
If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner:
- Website: oaic.gov.au
- Telephone: 1300 363 992
- Post: GPO Box 5288, Sydney NSW 2001
20. Contact us
For any question, request or complaint about this Policy or your personal information, contact:
The Privacy Officer — Cassandra Research Pty Ltd
Email: service@cassandraresearch.com
Support: service@cassandraresearch.com
21. Changes to this Policy
We may update this Policy from time to time to reflect changes in our practices, technology, or legal obligations. The current version will always be available on our website, and the "Last updated" date will indicate when it was last revised. Where changes are material, we will take reasonable steps to notify you. Your continued use of the Services after an updated Policy takes effect indicates your acknowledgement of the updated Policy, to the extent permitted by law.
This Policy is intended to comply with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. It should be read together with our Terms of Service and any data processing terms that apply to your use of the Services.