YourCA
Terms of UsePrivacy PolicyDPAData & AI

Privacy Policy

Privacy Policy

On this page

  1. 1. Our role: controller and processor
  2. 1.1 Our privacy commitments
  3. 1.2 Scope
  4. 2. Information we collect
  5. 2.1 Information you give us
  6. 2.2 Information we collect automatically
  7. 2.3 Information from third parties
  8. 2.4 Site workers, attendance and location
  9. 2.5 Sensitive information
  10. 3. How we collect personal information
  11. 4. Why we collect personal information and our legal bases
  12. 5. AI and machine learning
  13. 5.1 We do not train on your data
  14. 5.2 Retrieval at inference, not training
  15. 5.3 Source-platform compliance
  16. 5.4 What a connected source lets us do
  17. 5.5 Accuracy and control
  18. 6. Who we disclose personal information to
  19. 6.1 Our sub-processors
  20. 7. Cookies and similar technologies
  21. 8. Direct marketing
  22. 9. International data transfers and data residency
  23. 9.1 What stays in Australia
  24. 9.2 What leaves Australia
  25. 9.3 Cross-border disclosure under APP 8
  26. 9.4 GDPR transfers
  27. 10. Security
  28. 11. Data retention
  29. 11.1 Contract documents and review history
  30. 12. Your rights
  31. 12.1 All individuals (including Australia)
  32. 12.2 GDPR / UK GDPR
  33. 12.3 How to exercise rights
  34. 12.4 Identity verification
  35. 12.5 Response timeframes
  36. 13. Children's privacy
  37. 14. Data breach notification
  38. 15. Anonymised, de-identified, and aggregated data
  39. 16. Complaints
  40. 17. Changes to this Privacy Policy
  41. 18. Contact us

Effective date: 8 September 2026 Last updated: 8 August 2026 Version: 2.0

In plain English. This is a plain-language summary to help you navigate the policy. It is a reading aid only; the numbered clauses below govern.

  • YourCA is one product. Everything described here applies to the single YourCA service and every module inside it. There are no separate products to buy.
  • We read your data; we never train on it. We undertake not to use Customer Data, or anything we generate from it (outputs, embeddings, indexes), to train, retrain, fine-tune, or benchmark any AI model. This is a contractual undertaking by us and by our model provider, not a control you can see enforced in the software. (Clause 5.1.)
  • Retrieval, not training. Our AI looks things up in your sources at the moment you ask and cites them back to you. Your data is context at inference time, never a training set. (Clause 5.2.)
  • We honour every source platform's rules, where and when we offer that connection. Where the Service offers a connection to Procore, Microsoft 365, Google (Gmail and Drive), Xero, or Dropbox and you connect it, the data it shares is handled under that platform's developer and API terms for as long as the connection is offered, including Procore's restriction on using its data to train AI or machine-learning models. These are undertakings that attach to a connection when it is offered, not statements that any particular connection is available to you today. (Clause 5.3.)
  • Storage is in Australia; AI text processing is not. Your files, the database and the search index sit in Sydney (ap-southeast-2), and so does document text extraction and the embedding step. All AI text processing (chat, extraction and contract review) is sent to Anthropic in the United States. Product analytics and error reports go to PostHog in the European Union, whether they come from our servers or from your browser: both paths refuse PostHog's United States host, so this telemetry is European or it is not sent at all. Events sent from your browser are not put through our scrub and carry your network address to that European host. (Clause 9.)
  • Connections are yours, and reversible. Where the Service offers a connection to a source and you connect it, you authorise that source and can disconnect it at any time. A connection is not read-only: some connected-source actions write back into that system, for example sending an email or creating a record. While a source is connected, those actions run when you run them. The Service also has an automatic chasing capability, and a scheduled reading of a connected mailbox, that would act without you starting anything, and neither is enabled in the Service today. This describes what a connection does when you have one, not that any particular connection or capability is available to you today. (Clauses 5.4 and 5.5.)
  • You hold the rights. Access, correction, deletion, and more: see Clause 12. Questions: admin@yourca.ai.

A fuller plain-English explainer lives in our Data & AI statement.

This Privacy Policy explains how Michael Dewick trading as YourCA (ABN 84 390 063 197), a sole trader (YourCA, we, us, our), collects, uses, discloses, stores, secures, and otherwise handles personal information. We are bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). Where we process personal information of individuals in the European Economic Area, United Kingdom, or other jurisdictions with applicable data protection laws, we additionally comply with those laws (including the GDPR and UK GDPR).

This policy applies to:

(a) visitors to our websites and marketing properties; (b) users of the YourCA service (the Service); (c) prospective customers, partners, and job applicants; and (d) any other individual whose personal information we collect.

If you do not agree with this policy, you should not use the Service.


#1. Our role: controller and processor

We act in two distinct capacities:

  • Controller: for personal information about visitors, account administrators, billing contacts, prospects, and any contractor we engage. We determine the purposes and means of processing.
  • Processor: for personal information uploaded to or generated within the Service by our Customers ("Customer Data") on behalf of the Customer (the controller). For that data, the Customer is responsible for the lawful basis and for responding to data subject requests; we process it under our agreement with the Customer.

References to "personal information" in this policy align with the meaning under the Privacy Act 1988 (Cth) and include "personal data" under the GDPR/UK GDPR.

#1.1 Our privacy commitments

We apply privacy-by-design principles. This means we:

  • collect only the personal information we need for a specified purpose;
  • limit access to personal information to the people who need it, which for a business operated by one person means the sole trader and any contractor engaged under written confidentiality obligations;
  • minimise the use of identifiers and pseudonymise or de-identify where practicable; and
  • review this policy when our handling of personal information changes, and in any event at least annually.

#1.2 Scope

This policy applies globally to YourCA's handling of personal information. Where local law mandates additional rights or stricter protections, those apply in addition to (and prevail over) this policy.


#2. Information we collect

#2.1 Information you give us

  • Account information: name, work email, phone, job title, employer, password (hashed), profile photo.
  • Billing information: billing contact, ABN/VAT/tax ID, business address, payment method details (stored by our payment processor, not by us).
  • Content you upload: files, documents, messages, project data, photos, drawings, and other Customer Data you submit to the Service.
  • Communications: emails, support tickets, survey responses, feedback, and call recordings (where notified).
  • Identity verification: where required for higher-trust features, identity documents and verification metadata.

#2.2 Information we collect automatically

  • Usage data: pages viewed, features used, clicks, search queries, time stamps, performance metrics, errors, and crash reports.
  • Device and connection: IP address, device identifiers, browser type and version, operating system, screen size, referring URL, language preference.
  • Approximate location: derived from IP address (city/country level), used for security, fraud prevention, and regional routing.
  • Cookies and similar technologies: see clause 7.

#2.3 Information from third parties

  • Identity providers and SSO: where you sign in via Google, Microsoft, or another SSO provider, we receive profile information they share.
  • Connected sources: where the Service offers a connection to a third-party service (for example, Gmail, Microsoft 365 / Outlook / OneDrive / Teams, Dropbox, Google Drive, Xero, Procore) and you connect it, we receive, for as long as it stays connected, the information you authorise that service to share with us, scoped to the OAuth permissions you grant.
  • Lead and enrichment providers: limited business contact information for sales and marketing.
  • Public sources: corporate websites, professional networks, and public registers.
  • Payment processors: transaction status, last four digits of card numbers, expiry, and fraud signals.

#2.4 Site workers, attendance and location

Where a Customer uses the workforce features of the Service, we hold personal information about individuals who are not our Account holders and who did not sign up to the Service: the Customer's own employees, apprentices and subcontracted trades. That information is described here because it is the category most likely to be overlooked, and because those individuals are entitled to know from this policy what is held about them.

  • Crew directory: full name, work email, phone, trade or role, employer, and the tickets, licences and competency cards a person holds, including their expiry dates.
  • Site login: where the Customer issues one, an account with a distinct login used only to record attendance.
  • Attendance records: the person's name, the job they were scheduled to, the date, the start and finish times, breaks, and any correction. A correction is stored as a new record beside the original rather than replacing it, so a time record cannot be silently edited.
  • Clock-event location: only where the Customer has switched location on and has given its workers the written surveillance notice its state law requires, a single latitude, longitude and accuracy reading taken at the moment a person clocks on and clocks off, and a flag saying whether that reading fell within tolerance of the site. There is no background tracking, no trail between those two moments, and no reading is taken at any other time. Location readings are never sent to an AI model, never included in anything the Customer sends to a head contractor, and never leave the Customer's Account.
  • Site diary: a daily record which, at close, freezes the named workers on site that day and the hours each worked. This is the largest volume of worker personal information in the Service.
  • Site photographs: photographs taken on site may show workers. Where the Customer includes a photograph in a claim pack or export, any person visible in it is included with it.

Who decides what is collected. The Customer is the employer and the controller of this information. They decide whether location is switched on, and the obligation to give a workplace surveillance notice is theirs, not ours. We provide the notice workflow and we enforce the notice period; we do not and cannot give the notice on their behalf. We do not rely on the employee-records exemption in s 7B(3) of the Privacy Act 1988 (Cth) for any of this: that exemption covers acts of an employer, and we are a service provider, not the employer. Much of a typical crew are contractors, for whom it would not apply to anyone.

Access, correction and complaints. An individual whose information is held under this clause has the same rights as anyone else under clause 12, and may bring a complaint under clause 16, whether or not they are our Account holder. Where the information is the Customer's record rather than ours, we will tell the individual so and direct them to the Customer, because the Customer is the party who can change it.

#2.5 Sensitive information

We do not seek to collect sensitive information (such as health, racial or ethnic origin, religious beliefs, sexual orientation, or biometric data). If you upload such information to the Service, you do so as the controller and warrant that you have a lawful basis. We will treat any sensitive information we hold with the additional protections required by law.


#3. How we collect personal information

We collect personal information:

(a) directly from you when you sign up, configure your Account, use the Service, contact us, or apply for a role; (b) automatically as you use the Service or our marketing properties; (c) from your authorised users, administrators, or colleagues acting on your behalf; (d) from third parties listed in clause 2.3; and (e) where required or authorised by law.

Where reasonable and practicable, we collect personal information directly from you. Where this is not the case (for example, lead enrichment), we take reasonable steps to ensure you are informed of the matters required by APP 5.


#4. Why we collect personal information and our legal bases

We collect, hold, use, and disclose personal information for the following purposes:

PurposeExamplesGDPR/UK GDPR legal basis
Providing the ServiceAuthenticating, hosting Customer Data, delivering featuresContract performance
Account management and supportAccount setup, billing, support ticketsContract performance
Security and abuse preventionDetecting fraud, abuse, intrusion; protecting users and the ServiceLegitimate interests; legal obligation
Improving the ServiceDiagnostics, analytics, feature usage researchLegitimate interests
Communications about the ServiceService notices, security alerts, billing emails, policy updatesContract performance; legal obligation
MarketingNewsletters, product announcements, eventsConsent (where required); legitimate interests
Legal and complianceTax records, regulatory reporting, responding to lawful requests, defending claimsLegal obligation; legitimate interests
Corporate transactionsDue diligence and integration in mergers, acquisitions, or financingsLegitimate interests
RecruitmentAssessing applicantsPre-contract steps at the data subject's request

We do not engage in profiling that produces legal or similarly significant effects on individuals without their consent.


#5. AI and machine learning

The Service uses machine learning and generative AI to provide features such as search, summarisation, classification, and content generation. Our approach rests on one principle: we read and cite your data; we never train on it.

#5.1 We do not train on your data

  • We undertake not to use Customer Data, or any output, embedding, index, or other derivative we generate from it, to train, retrain, fine-tune, or benchmark any machine learning or AI model. This applies equally to foundation models and to models scoped to your tenant. We build and operate no model training, fine-tuning or model-customisation capability of any kind.
  • AI text generation and analysis are performed by our model provider (Anthropic) under commercial terms that prohibit using Customer Data to train or improve any model and provide only limited, short-term retention for safety and abuse monitoring. This is a contractual commitment given by us and by that provider. It is not a technical control we can demonstrate inside the Service, and we do not claim it as one.
  • That AI text processing is served from the United States. Text embeddings, document text extraction, storage and indexing remain in Australia. See clause 9 for the full residency position.
  • Outputs are returned only to the Customer's tenant and are subject to the same access controls as other Customer Data.
  • Features such as personalised search rely on deterministic, rule-based ranking and prompt-time retrieval, not on models trained on your data.

#5.2 Retrieval at inference, not training

The Service indexes your sources and retrieves the relevant passages at the moment you ask, then cites them back to you (a pattern commonly called retrieval-augmented generation). Your data is context supplied to the model at inference time to answer your request. It is never added to a training corpus, and the index exists solely to serve your own tenant.

#5.3 Source-platform compliance

Where the Service offers a connection to a third-party source and you connect it, we handle the data it shares under that platform's developer, API, and marketplace terms, in addition to this policy, for as long as that connection is offered. The undertakings below attach to a connection when it is offered to you. They describe how we will handle data obtained through a connection, and they are not assertions that we hold a particular platform certification, verification, or approval today. Where a platform requires a certification or verification of us before a connection may be offered, we will obtain it before offering that connection.

  • Procore. Customer Data sourced from a Procore connection is categorically excluded from any model training, improvement, or fine-tuning, consistent with the Procore developer and marketplace terms, which restrict using Procore data to train AI or machine-learning models. We use Procore data only to deliver the feature you request, back to your tenant, at inference time.
  • Google (Gmail and Google Drive restricted scopes). Where we offer a Google connection, our use of Google user data will comply with the Google API Services User Data Policy, including its Limited Use requirements, and we will hold the independent security assessment that policy requires for restricted scopes before that connection is offered. We do not use Google restricted-scope data to train, develop, or improve any generalised or standalone AI or machine-learning model, and we use it only to provide the user-facing features you request.
  • Microsoft 365, Xero, and Dropbox. Data obtained through a connection to any of these sources is handled under their respective developer and API terms and is likewise excluded from any model training, retraining, or fine-tuning.

#5.4 What a connected source lets us do

The Service offers, as a capability, connections to systems you already run. The sources for which a connection may be offered are Gmail, Microsoft 365 (including Outlook mail and calendar, OneDrive, Teams, To Do and SharePoint), Dropbox, Google Drive, Xero, and Procore. Which of them is offered to your account at any time depends on your plan, your entitlements, and what the Service currently makes available, and this clause is not a statement that any particular connection is available to you today. Everything below applies where you connect a source, and for as long as it stays connected.

  • You authorise each connection, and the connection is limited to the OAuth permissions you grant. You can disconnect a source at any time, in the Service or from your account with that platform.
  • Reading. With your authorisation we read messages, files, records and metadata from the connected source so the Service can index them, cite them, and answer your questions from them.
  • Writing back. Some features write back into a connected source. Depending on the source and the permissions you grant, that can include sending, drafting, forwarding, labelling, moving, archiving or deleting email; creating, updating or cancelling calendar events; uploading, moving, renaming, sharing or deleting files; posting messages; and creating or updating records in Xero and Procore, including financial records such as invoices, invoice requests, purchase orders and variations, and certifying a progress claim. Any such action runs when you run it. The Service also has an automatic chasing capability: where we offer it and you switch it on for a supplier in the procurement module, the Service may send a chase email from your connected mailbox without further action from you, that setting is off unless you switch it on for that supplier, the Service will not chase a supplier you have not already emailed yourself, and it sends at most one chase to a supplier in a day. That capability is not enabled in the Service today. Apart from it, we do not perform write actions on a connected source on our own initiative.
  • We do not describe our connections as read-only. Some are not, and you should assume a connection you authorise for a write-capable feature can change data in that system.
  • A connected source is your own account with that platform, held under your agreement with it. It is not a YourCA sub-processor, and what we exchange with it is governed by the authorisation you give.

#5.5 Accuracy and control

Where AI-generated output is provided, we mark it as such where reasonably practicable. AI outputs may be inaccurate; Customers must review them before relying on them. AI outputs are not legal, financial, or other professional advice, and using the Service does not create a lawyer-client or other professional relationship: see the clause headed "No legal, financial, or other professional advice" in the Terms of Use. AI processing mostly happens when you run a feature that uses it, so for the most part you control it by choosing what to run. The Service also has a capability, where we offer it and you connect a mailbox, for a scheduled job to read that mail to prepare your brief and to draft a chase without you starting anything. That capability is not enabled in the Service today, so no scheduled reading of a connected mailbox takes place. There is no account-wide switch to turn AI off while continuing to use the Service; if you need AI processing disabled or restricted for your account, email admin@yourca.ai and we will tell you what we can do.

Where the Service prepares a statutory or contractual document (for example a payment claim, a statutory declaration, or a compliance certificate), it produces the complete filled document with every field editable and the signature and witness blocks left blank, and exports it to you. The Service cannot serve or transmit that document to another party, so any personal information in it is disclosed by you, when you serve it, and not by us.


#6. Who we disclose personal information to

We disclose personal information to:

(a) Authorised Users within your organisation: collaboration is core to the Service. Account administrators may have access to other users' activity and content; (b) Our service providers and sub-processors: the full list is in clause 6.1. We keep the same list in the DPA, notify Customers at least 30 days before engaging a new sub-processor that materially affects the processing of Customer Data, and Customers may object on reasonable data-protection grounds (see the Terms); (c) Third parties you connect: where the Service offers a connection and you authorise it, we exchange information with that service per your authorisation for as long as it stays connected, as described in clause 5.4; (d) Professional advisors: lawyers, auditors, accountants, and any insurer or insurance broker, under confidentiality obligations. Naming insurers here describes a category of recipient we may need to disclose to; it is not a statement that YourCA holds any particular insurance, and YourCA does not hold professional indemnity insurance; (e) Acquirers: in connection with a merger, acquisition, restructure, financing, or sale of assets, subject to confidentiality; (f) Regulators, law enforcement, and courts: where required by law, including in response to a lawful request such as a subpoena, search warrant, or court order. We assess each request and challenge those that are overbroad or unlawful where appropriate; (g) To protect rights and safety: to enforce our terms, prevent fraud, address security issues, or protect the rights, property, or safety of YourCA, our customers, or others; and (h) With your consent: for any other purpose disclosed to you at the point of collection.

We do not sell personal information.

#6.1 Our sub-processors

Sub-processorWhat it doesWhere it processes
AnthropicAll AI text processing: chat, extraction of information from your documents, and contract reviewUnited States
Amazon Web Services (S3)Object storage for uploaded documentsAustralia (Sydney, ap-southeast-2), pinned in application code
Amazon Web Services (Textract)Optical character recognition of scanned PDFs and imagesAustralia (Sydney, ap-southeast-2), pinned in application code
Amazon Web Services (Bedrock, Titan embeddings)Text embeddings for the search indexAustralia (Sydney, ap-southeast-2), pinned in application code
Neon, Inc.Managed PostgreSQL database and vector search index; the primary store of Customer DataAustralia (Sydney, ap-southeast-2), fixed by the provider endpoint rather than by a check in our code
Upstash, Inc.Managed Redis for background job and queue processingRegion is a matter of deployment configuration and is not pinned in application code; see the note below
Replit, Inc.Application hosting and computeRegion is a matter of deployment configuration and is not pinned in application code; see the note below
Stripe (Stripe Payments Australia Pty Ltd and its group)Payment processing. Card details are entered directly with Stripe and raw card data never reaches YourCA systemsStripe group locations, including outside Australia
ResendDelivery of email we send you, being transactional and notification email such as sign-in verification codes and review-status notices, and also the daily brief, risk digest and urgent alert emails, which quote Customer Data including email subject lines and counterparty namesNot pinned to an Australian region; email is delivered to the recipient's own mail provider wherever that provider operates
PostHogProduct usage analytics and the only application error capture we operate. Events sent from our servers are scrubbed of email addresses, credentials, tokens and authorisation headers before they leave our systems. Events sent from your browser are not scrubbed by us and carry the network address they come fromEuropean Union (PostHog EU). Both the server path and the browser path refuse a PostHog United States host, and refuse a host they cannot read; where the host is refused that telemetry is disabled rather than sent offshore, and where no host is configured for the browser no browser telemetry is sent at all. The refusal prevents PostHog's United States cloud specifically and is not proof that a configured host sits in Australia or the European Union

A note on the two unpinned regions. We deploy our queue provider (Upstash) and our hosting provider (Replit) to Sydney, but we do not have a control in the Service that would stop either if it were configured for another region, unlike the AWS services above. You should treat the region for those two as a configuration commitment rather than an enforced control. Upstash holds queue and job metadata rather than the document corpus; Replit runs the application, so Customer Data passes through it in transit.

The sources listed in clause 5.4 (Gmail, Microsoft 365, Dropbox, Google Drive, Xero and Procore) are not sub-processors, whether or not a connection to any of them is offered to you or taken up by you. They are your own accounts, under your own agreements, which you would authorise us to reach.


#7. Cookies and similar technologies

We use cookies, local storage, web beacons, and similar technologies, classified as follows:

CategoryPurposeConsentExamples
Strictly necessarySign-in, session security, CSRF protection, load balancingRequired to use the Service; cannot be disabledSession cookie, auth cookie, CSRF token
FunctionalRemember preferences (language, layout, recently viewed)Implied consent through usePreferences cookie, recently-viewed cache
AnalyticsMeasure use, diagnose errors, improve features (aggregated)No consent gate today: analytics runs from the moment the Service loads, and we do not offer an in-product opt-out or an EU and UK opt-in. Your browser settings are the control that worksFirst-party product analytics, error monitoring

We do not currently use advertising or third-party tracking cookies, and we do not run advertising pixels on our websites or in the Service. If that changes, we will update this policy and obtain consent where required.

You can control cookies through:

  • your browser settings (note that disabling strictly necessary cookies may prevent the Service from working); and
  • platform-level controls in your operating system.

We do not currently operate an in-product cookie preferences tool or an analytics consent banner, and analytics is not gated on consent anywhere. We describe that here rather than claim a control we have not built. We do not respond to "Do Not Track" or Global Privacy Control browser signals, as we do not use advertising or cross-site tracking cookies for those signals to act on. If we introduce advertising or tracking cookies, we will provide a consent tool and honour those signals where required by law.


#8. Direct marketing

We may send you marketing communications about YourCA products, features, events, and offers. You can opt out at any time:

  • by clicking "unsubscribe" in any marketing email;
  • by adjusting in-product notification preferences; or
  • by emailing admin@yourca.ai.

We do not currently send SMS marketing.

We comply with the Spam Act 2003 (Cth) for electronic marketing to Australian recipients. We send commercial electronic messages only where we have express or inferred consent, every message identifies us as the sender with valid contact details, and every message includes a functional unsubscribe mechanism that takes effect within 5 business days. For recipients outside Australia, we comply with applicable laws (including GDPR/UK GDPR consent requirements, CAN-SPAM, and CASL).

Opting out of marketing does not affect transactional, security, or service messages we need to send to operate the Service.


#9. International data transfers and data residency

#9.1 What stays in Australia

The following are hosted in Australia (Sydney, ap-southeast-2):

  • uploaded documents and other files in object storage;
  • the primary database, which holds Customer Data and the vector search index;
  • optical character recognition of scanned documents; and
  • the computation of text embeddings for the search index.

The region is enforced differently for different items, and we state the difference rather than blur it. For object storage, optical character recognition, and the computation of embeddings, the Service is built to raise an error and stop that component rather than run it in any region other than Sydney. The embedding component raises that error as the application loads. Object storage raises it the first time it is used, and only where a storage bucket is configured. Optical character recognition raises it the first time it is used, and only where that feature is switched on. For the database, the region is fixed by the provider endpoint we connect to, not by a check inside our own code. Application hosting and the background queue are deployed to Sydney as a matter of configuration and are not region-checked at all: see the note in clause 6.1.

We will not move primary storage of Customer Data outside Australia without notifying the Customer.

#9.2 What leaves Australia

This clause is important and you should read it in full. Not everything stays onshore.

What leavesWho receives itCountryWhy
The text we send a model to answer your request, including the passages retrieved from your own documents and sourcesAnthropicUnited StatesAll AI text processing: chat, extraction, contract review
Product usage events and error reports raised by our servers, scrubbed of email addresses, credentials and tokens before they leave our serversPostHogEuropean UnionAnalytics and error reporting
Product usage events raised by your browser, which are not put through that scrub and carry the network address they come fromPostHogEuropean Union; a PostHog United States host is refused, and where no host is configured your browser sends nothingAnalytics
Payment and billing informationStripeStripe's global locations, including the United StatesTaking payment
The contents of transactional and notification email we send youResendNot region-pinned by usEmail delivery
Application and queue processingReplit, UpstashNot region-pinned by us; see the note in clause 6.1Hosting and background jobs

There is no setting that keeps AI text processing in Australia. If you use an AI feature of the Service, the material that feature works on is disclosed to the United States. If that is unacceptable for a particular document, do not put that document through an AI feature.

Moving AI text processing in-region is something we have considered and have not committed to. That work has not started and no date is set for it, so you should plan on AI text processing remaining in the United States.

Your connected sources (clause 5.4) are processed wherever your own tenancy with that platform sits, which is a matter between you and that platform.

#9.3 Cross-border disclosure under APP 8

The disclosures in clause 9.2 are cross-border disclosures of personal information for the purposes of Australian Privacy Principle 8. Before disclosing personal information overseas, we take reasonable steps to ensure the recipient does not breach the APPs, including by:

(a) entering into contractual safeguards (such as Standard Contractual Clauses or the UK International Data Transfer Addendum) where applicable; (b) assessing the recipient's privacy and security practices; and (c) limiting disclosure to what is necessary.

The countries in which our sub-processors process personal information are Australia, the United States, and the European Union, as set out in clause 6.1 and the table above. Our payment processor and our transactional email provider are global services that we do not pin to a region, so they may also process in other countries in which they operate.

#9.4 GDPR transfers

For transfers of personal data out of the EEA or UK, we rely on:

(a) adequacy decisions issued by the European Commission or the UK Information Commissioner (Australia does not currently have full adequacy; transfers to Australia are made under appropriate safeguards); (b) the European Commission's 2021 Standard Contractual Clauses (Module 1, 2, or 4 as applicable); (c) the UK International Data Transfer Addendum to the EU SCCs (or the UK IDTA, at our discretion); and (d) other lawful transfer mechanisms where applicable.

We have not commissioned a formal transfer impact assessment and we do not represent that one exists. YourCA is operated by a sole trader with no legal department. The supplementary measures we actually apply are encryption in transit and at rest, minimising the personal information disclosed for each request, contractual no-training and limited-retention terms with our model provider, and a stated commitment to assess and where appropriate challenge any government access request. We do not offer customer-managed encryption keys. Clause 10.6 of the DPA states the same position, and you must reach your own conclusion on whether those measures are sufficient for the personal information you choose to send.


#10. Security

We take reasonable steps to protect personal information against loss, misuse, interference, unauthorised access, modification, and disclosure. The measures we currently apply are:

  • encryption in transit over public networks (TLS 1.2 or higher), and encryption at rest as provided by our hosting and infrastructure providers;
  • encryption of third-party integration credentials and access tokens (AES-256-GCM) before they are stored;
  • role-based access control within the Service, with each Customer's data isolated at the application and data layers;
  • optional multi-factor authentication on user accounts;
  • request rate limiting, security response headers, and server-side validation of request input;
  • audit logging of administrative activity within the Service, and application error monitoring;
  • automated typecheck, test, and build checks on every change proposed for, or merged into, the main branch of our codebase before it is released;
  • least-privilege access, with production access held only by the sole trader who operates YourCA and by any contractor engaged under written confidentiality obligations; and
  • written confidentiality obligations on any contractor given access to personal information.

What we do not claim. YourCA is operated by one person. We hold no independent security certification or attestation (for example, SOC 2 or ISO 27001). We have not commissioned third-party penetration testing. We do not run intrusion detection, a security operations centre, continuous human monitoring, or automated vulnerability or dependency scanning, and we do not maintain a security team. We do not scan uploaded files for malware or viruses. We check that an uploaded file is the type it says it is and refuse it otherwise, and we return stored files as downloads under the type their extension promises, but nothing here inspects a genuine document for harmful content. Scan anything you download from the Service before you open it. The fuller description is in Data and AI and in the DPA, Annex 2. We also hold no professional indemnity insurance and no cyber liability insurance, and what you can recover from us is capped by clause 15.2 of the Terms of Use at the greater of A$1,000 and the fees you have actually paid us in the preceding 12 months. That cap is never nil, but A$1,000 is a small amount and is not a meaningful remedy for a large loss. Please do not assume any of those controls, or any insurance, are in place.

No system is perfectly secure. You are responsible for keeping your credentials safe and using available security features (such as multi-factor authentication).


#11. Data retention

We retain personal information only for as long as necessary for the purposes for which it was collected or as required by law.

CategoryRetention
Active Account informationFor the life of the Account, plus 90 days after closure
Customer Data (in-Service)While the Account is active; 30 days for export after termination; then deleted (subject to clause 11.1 below and legal hold)
Billing and tax records7 years from the end of the financial year (per Australian tax law)
Marketing contactsUntil you unsubscribe or after 24 months of inactivity
Support communications3 years from the date of the interaction
Security logsUp to 24 months
Backups and point-in-time recoveryAs provided by our hosting providers' standard retention windows
Recruitment data (unsuccessful applicants)12 months unless you consent to longer
Worker attendance records (hours, breaks, corrections)7 years, because the Fair Work Act 2009 (Cth) requires employee time and pay records to be kept for that period
Clock-event location readings (coordinates and accuracy)A short window set by the Customer, 30 days by default and never more than 365. Coordinates are deleted automatically by a nightly process; the hours, the person, the job and the within-tolerance flag survive that deletion. The two cannot share one number: one is minimised, the other is required for seven years
Site diary entries, including the named workers and hours frozen at closeFor the life of the job in the Account, and then as for Customer Data above. A closed diary is append-only and is not edited afterwards
Crew directory, including ticket and licence expiry datesWhile the person is active in the Customer's directory, and then as for Customer Data above

We may retain information for longer where required by law, for the establishment, exercise or defence of legal claims, or in anonymised form for analytics and research.

#11.1 Contract documents and review history

Where you use the contract review capability of the Service, we retain more than the review we generated for you. For each contract you upload we also store, for the life of that contract in your Account:

  • the extracted text of each document, held both as uploaded and in a normalised form, together with a content hash of each clause;
  • structural information about the document, being the clause labels, heading trails and the character positions of each clause; and
  • where generated, mathematical representations (embeddings) of that clause text.

Why. These let us compare a later version of the same contract against the one we reviewed, so we can tell you which clauses changed and what that does to your position, and they let us keep tracking the deadlines in the contract when the wording behind them moves. Without them a re-issued contract can only be reviewed from scratch, and a changed deadline passes unnoticed.

Deletion. When you delete a contract, or when your Account is closed and the retention windows in the table above expire, all of the above is hard-deleted, along with the risk positions, the evidence linking them to clauses, and the history of how each position was negotiated. We do not keep a de-identified copy of that history for benchmarking or research after deletion. This is a deliberate exception to clause 15 below: contract negotiation history is deleted, not de-identified and kept.


#12. Your rights

Subject to applicable law and verifying your identity, you may exercise the following rights:

#12.1 All individuals (including Australia)

  • Access: request access to personal information we hold about you (APP 12).
  • Correction: request correction of inaccurate or out-of-date information (APP 13).
  • Complaint: complain about our handling of your personal information (see clause 16).

We will respond within 30 days. We may decline access in limited circumstances permitted by law (for example, where giving access would breach another person's privacy or reveal commercially sensitive information) and will give written reasons.

#12.2 GDPR / UK GDPR

If GDPR or UK GDPR applies to you, you additionally have rights to:

  • erasure ("right to be forgotten") in certain circumstances;
  • restriction of processing;
  • data portability in a structured, machine-readable format;
  • object to processing based on legitimate interests, including profiling, and to processing for direct marketing;
  • withdraw consent at any time where processing is based on consent (without affecting the lawfulness of prior processing); and
  • lodge a complaint with a supervisory authority (in the UK, the ICO; in Ireland, the DPC; in your country of residence within the EEA).

#12.3 How to exercise rights

Email admin@yourca.ai with details of your request. If you are an Authorised User of a Customer's Account, we may direct your request to that Customer (as controller) and assist them in responding.

We do not charge for routine requests. We may charge a reasonable cost-based fee for manifestly unfounded or excessive requests, or refuse to act, as permitted by law.

#12.4 Identity verification

Before acting on a request, we will take reasonable steps to verify your identity. For account holders, this is usually confirming the request from the registered email and, where higher risk, requiring a second factor. For non-account holders, we may request government-issued identification or other proof. Identity documents are destroyed once verification is complete.

#12.5 Response timeframes

We will respond to:

  • access and correction requests under APP 12/13: within 30 days;
  • requests under GDPR/UK GDPR: within 1 month, extendable by up to 2 further months for complex requests on notice;
  • erasure, restriction, portability, and objection requests under GDPR/UK GDPR: within 1 month.

We will tell you if we cannot meet a request and why.


#13. Children's privacy

The Service is intended for use by adults in business settings. We do not knowingly collect personal information from children under 16. If you believe a child has provided us with personal information, contact us and we will take steps to delete it.


#14. Data breach notification

On becoming aware of a suspected breach, we aim to triage it within 24 hours, contain it as soon as practicable, and record a written assessment. We do not maintain a separate security team or a tested incident response programme; incidents are handled by the sole trader who operates YourCA, with assistance from our hosting and infrastructure providers.

If we determine that an eligible data breach has occurred under the Privacy Act 1988 (Cth) Notifiable Data Breaches scheme, or a personal data breach has occurred under GDPR/UK GDPR that is likely to result in risk to the rights and freedoms of natural persons, we will:

(a) notify the Office of the Australian Information Commissioner (OAIC) as soon as practicable after we form the belief that an eligible data breach has occurred, as section 26WK of the Privacy Act 1988 (Cth) requires. Where we only suspect an eligible data breach, we carry out an assessment as quickly as reasonably possible and in any event within 30 days of becoming aware of the grounds for that suspicion, which is the assessment deadline in section 26WH, not a notification deadline; (b) notify the relevant European or UK supervisory authority within 72 hours of becoming aware, where feasible; (c) notify affected individuals without undue delay, with information about the breach, likely consequences, and steps they can take; and (d) maintain a record of the breach and our response.

Where we process Customer Data as a processor, we will notify the Customer without undue delay and, where feasible, within 48 hours of confirming a personal data breach affecting their data, and in any event we will use reasonable efforts to notify them in time to meet their own 72-hour notification obligation under applicable Privacy Laws. Clause 8 of the DPA governs that notification, including what it does and does not commit us to, and clause 13.1 of the DPA caps our liability in connection with it.


#15. Anonymised, de-identified, and aggregated data

We may create anonymised, de-identified, or aggregated data from personal information (including Customer Data) and use it for any lawful purpose, including improving the Service, benchmarking, and producing industry research. One purpose is excluded, and it is the one that matters most here: we do not use de-identified, anonymised or aggregated data, or any embedding, index or other derivative of it, to train, retrain, fine-tune or benchmark any machine learning or AI model. De-identifying data does not put it outside our never-train undertaking in clause 5.1. Benchmarking in this clause means measuring the Service and producing industry statistics, not evaluating or tuning a model.

When we de-identify data, we apply techniques such as removing direct and indirect identifiers, generalising values, and aggregating records, and we consider re-identification risk before use. We do not attempt to re-identify data we have de-identified, and where we disclose de-identified data we prohibit the recipient from doing so.

Once data is genuinely de-identified or aggregated, it does not identify any individual or Customer and is not subject to this Privacy Policy.

Clause 11.1 carves out one category from this section: contract text and contract negotiation history are deleted when you delete the contract, and are not retained in de-identified form afterwards.

We may also pseudonymise personal information (replacing direct identifiers with tokens, with the mapping held separately and protected) where this reduces risk without preventing the intended purpose. Pseudonymised data is still personal information and remains subject to this policy.


#16. Complaints

If you have a concern or complaint, please contact us first at admin@yourca.ai. We aim to acknowledge complaints within 5 business days and resolve them within 30 days.

If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner:

Office of the Australian Information Commissioner (OAIC) GPO Box 5288, Sydney NSW 2001 1300 363 992 oaic.gov.au

EU/UK residents may complain to their local supervisory authority.


#17. Changes to this Privacy Policy

We may update this Privacy Policy from time to time. The "Last updated" date will reflect any change. Where changes are material, we will notify you by email or in-product notification at least 30 days before they take effect. Continued use of the Service after the effective date constitutes acceptance.

Prior versions are available on request.


#18. Contact us

For all privacy questions, requests, and complaints:

Michael Dewick trading as YourCA (ABN 84 390 063 197), Privacy Officer Sydney NSW, Australia

Email: admin@yourca.ai Security: admin@yourca.ai

We do not currently market or offer the Service to individuals in the European Economic Area or the United Kingdom. If that changes and Article 27 of the GDPR or UK GDPR requires us to appoint a representative, we will do so and update this policy.

Michael Dewick trading as YourCA
ABN 84 390 063 197
admin@yourca.ai
Terms of UsePrivacy PolicyDPAData & AI