Privacy Policy

Last updated: 19 July 2026

1. Who we are and how to contact us

This policy explains how Cassandra Research Pty Ltd (we, us, our) handles personal information in Cassandra ASIC Agent OS. We handle personal information in line with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

You can reach our privacy contact through the contact page on this site. Security and data-handling evidence is summarised in our Trust Center.

2. Scope — firms and their clients

Our customers are firms: ASIC registered agents, tax agents, accounting firms and corporate secretarial teams. When a firm enters or imports information about its client companies and their officeholders and members, we process that information on the firm's instructions and for the purpose of providing the service. The firm remains the controller of its client data and is responsible for having the authority to collect and share it with us.

3. What we collect

We collect:

  • Account information — your name, work email, firm details and billing contact, provided when your firm registers.
  • Client-company register data — information your firm enters or imports to do its compliance work, such as company details, officeholder and member names, addresses, dates of birth and director IDs. Sensitive identifiers such as dates of birth and director IDs are stored with field-level encryption.
  • Signing metadata — when a document is signed through the service, the IP address, user agent, timestamps and signing events recorded in the audit certificate.
  • Billing data — subscription and payment details, processed by Stripe; we do not store full card numbers.
  • Usage and security records — sign-in events, product telemetry and an audit history of changes, kept so firms can prove who changed what, and when.
  • Messages — anything you send us through the contact page, together with the details you include in it.

4. Why we use it

We use personal information to provide and improve the service: preparing documents and forms, tracking lodgements, collecting signatures, sending reminders your firm has asked for, processing payments, providing support, and keeping the service secure. We do not sell personal information, and we do not use your firm's client records for advertising.

5. Consent and legal basis

We collect, use and disclose personal information with the consent of the individuals concerned (obtained by your firm for client data), where it is necessary to provide the service your firm has engaged us for, and where the law otherwise permits or requires it. Your firm is responsible for telling its clients how their information will be handled.

6. Who we share it with

We share personal information only where needed to run the service, with subprocessors including:

  • Hosting and infrastructure — including Vercel (application hosting) and Supabase (Postgres database).
  • Payments — including Stripe, for subscription billing.
  • Communications — including our transactional email provider, for service and signing emails.
  • Government registries — when your firm chooses to lodge a form, the information in that form goes to ASIC and related government registers, as your firm directs.
  • Where the law requires it — such as in response to a lawful request by a regulator or court.

7. Overseas disclosure (APP 8)

The service is primarily hosted in Australia (Sydney region). Some of our vendors may process limited personal information overseas as part of their global operations. Where that happens, we take reasonable steps to make sure those recipients handle the information consistently with the APPs, through contractual and technical safeguards.

8. How we protect it

Each firm's data is isolated from every other firm's. Access is role-based, connections are encrypted in transit, sensitive identifiers are encrypted at field level, signing tokens are stored only as hashes, and every change is recorded in an append-only audit history that cannot be edited or deleted. We host the service with reputable cloud providers and prefer Australian regions where available.

9. How long we keep it

We keep personal information while your firm has an account. Audit logs and signing evidence are retained for the periods needed to meet compliance and record-keeping obligations. If your firm closes its account, we give you a reasonable opportunity to export your data before deletion, and we delete or de-identify personal information on request, subject to legal holds and retention obligations.

10. Cookies

The website uses only the cookies needed to keep you signed in and keep the service secure. We do not use advertising or cross-site tracking cookies.

11. Access and correction

You can ask to access or correct the personal information we hold about you through our contact page. For information about a client company, the firm that manages that company's work is usually the right first contact, because it controls that data.

12. Data breaches

If a data breach is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme, and we will work with the affected firm on its own notification obligations.

13. Complaints

If you believe we have mishandled your information, contact us first through our contact page and we will respond within a reasonable time. If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au.

14. Changes to this policy

If we change this policy we will update the date at the top of this page and, for material changes, let account holders know in the app.