DRAFT — NOT LEGAL ADVICE. This document was prepared as a starting draft and has not been reviewed by a lawyer. It must be reviewed and adapted by a qualified Australian legal practitioner before it is published or relied on. Items in
[TO CONFIRM: …]need your input. Seedocs/legal/README.mdfor the full list.
Privacy Policy — Grace
Provider: [TO CONFIRM: full legal entity name, e.g. "Egan Services Pty Ltd"] (ABN [TO CONFIRM]) ("we", "us", "our", "Egan Services") Product: Grace, the ISO 9001 / ISO 27001 compliance platform at grace.eganservices.com ("Grace", the "Service") Effective date: [TO CONFIRM] Last updated: [TO CONFIRM]
We are committed to protecting your privacy and handling personal information in accordance with the Privacy Act 1988 (Cth) (as amended, including by the Privacy and Other Legislation Amendment Act 2024) and the Australian Privacy Principles (APPs). This policy explains how we collect, hold, use and disclose personal information, and how you can access, correct or complain about it.
1. Two roles: your data vs. our account data
Grace is business-to-business software. It helps two kinds of personal information meet:
- Account and usage information — information about the individuals who sign up for and use Grace (names, work emails, workspace membership, activity logs). For this information we are the entity responsible under the Privacy Act, and this policy governs it.
- Customer content — the records your organisation creates in Grace (documents, registers,
assessments, and any personal information about your staff, contractors or contacts that you choose
to put in). Here we act on your organisation's instructions to host and process that content so
we can provide the Service. Your organisation (our customer) is responsible for that content and for
its own privacy notices to the individuals concerned. Our handling of customer content is governed by
our customer agreement and Data Processing Addendum (
data-processing-addendum.md); we do not use it for our own purposes.
If you are an employee, contractor or contact of one of our customers and have a question about your personal information in that customer's workspace, please contact that organisation directly; we will support them in responding.
2. Kinds of personal information we collect and hold
- Identity and contact information: name, work email address, and the organisation (workspace) you belong to.
- Authentication information: credentials and sign-in data, handled by our authentication provider (Clerk). We do not store your password.
- Usage, device and log information: IP address, browser/device type, pages and actions within the Service, and timestamps — collected automatically to run, secure and improve the Service.
- Support and communications: information you provide when you contact us for support or by email.
- Customer content may contain personal information your organisation chooses to include (see section 1). We do not control what that is.
We do not intentionally collect sensitive information (as defined in the Privacy Act) about you for our own purposes. Please do not enter sensitive information into free-text fields except where your organisation has determined it is appropriate for its compliance records.
3. How we collect personal information
- Directly from you when you sign up, use the Service, or contact us.
- From your organisation when an administrator invites you to a workspace or assigns your role.
- Automatically through the Service and standard web logs when you use Grace.
- From our sub-processors (for example, authentication metadata from Clerk).
Where reasonable and practicable, we collect personal information directly from the individual concerned.
4. Purposes for which we collect, hold, use and disclose personal information
- To create and administer accounts and workspaces, and to authenticate users;
- To provide, maintain, secure and support the Service;
- To communicate with you about the Service, including service and security notices;
- To detect, prevent and respond to security incidents, fraud, and misuse;
- To meet our legal, regulatory and contractual obligations;
- To provide optional AI-assisted features (the "Ask Grace" assistant) where your workspace chooses to enable them (see sections 6 and 7);
- To bill for the Service where it is a paid plan (billing is not active during a free pilot); and
- To improve the Service, using aggregated or de-identified information where practicable.
We will only use or disclose personal information for a purpose set out above, a directly related purpose you would reasonably expect, or as otherwise permitted or required by law.
5. Cookies and similar technologies
Grace uses essential cookies only — principally the session cookie set by our authentication provider to keep you signed in and to keep your session secure across the Service and its workspace subdomains. We do not use advertising or third-party tracking cookies. Blocking essential cookies will prevent you from signing in.
6. To whom we disclose personal information
- Our sub-processors — service providers who host and support the Service under contract and on our
instructions. The current list, with each provider's purpose and location, is in
sub-processors.md. - Our AI provider (optional feature) — if your workspace enables the optional AI assistant, the prompts you submit and the specific records you ask it about are disclosed to Anthropic, PBC (United States), under contract and on our instructions, solely to generate the assistant's response (see sections 4 and 7).
- Your organisation — administrators of your workspace can see workspace membership and activity.
- Legal and safety — where required or authorised by law, to comply with a lawful request, or to protect our rights, users or the public.
- Business transfers — if we are involved in a merger, acquisition or sale of assets, personal information may be disclosed subject to this policy and applicable law.
We do not sell personal information, and we do not disclose it to third parties for their own marketing.
7. Overseas disclosure (APP 8)
Some of our sub-processors store or process information outside Australia. In particular, our authentication provider (Clerk) is located in the United States. Our application database and file storage are hosted in Australia (Sydney region).
Optional AI assistant. If your workspace chooses to enable the optional AI assistant, the prompts you submit and the specific records the assistant is asked to work with are disclosed to our AI provider, Anthropic, PBC, in the United States, for the sole purpose of generating a response. This feature is off by default and is enabled only at your workspace's choice; you can disable it at any time. Anthropic processes this information as our sub-processor under its Commercial Terms and Data Processing Addendum; it does not use the information to train its models and (under its API terms) deletes it within approximately 30 days of processing [TO CONFIRM: or does not store it, if a Zero-Data-Retention agreement is in place]. In-Australia processing is not available for this feature.
The full list of providers and their locations — including [TO CONFIRM: confirm each provider's
data-processing region] — is in sub-processors.md. Before disclosing personal information to an
overseas recipient we take reasonable steps to ensure the recipient handles it consistently with the
APPs.
8. Security (APP 11)
We take reasonable steps to protect personal information from misuse, interference, loss, and
unauthorised access, modification or disclosure. Measures include tenant isolation (row-level security),
least-privilege database access, encryption in transit, managed authentication, role-based access
control, security headers, rate limiting, audit logging, and Australian data hosting. A customer-facing
summary is in security-statement.md.
If we experience a data breach that is likely to result in serious harm, we will assess it and, where it is an eligible data breach, notify the Office of the Australian Information Commissioner (OAIC) and affected individuals in accordance with the Notifiable Data Breaches scheme — carrying out our assessment expeditiously (within 30 days of becoming aware of grounds to suspect a breach) and notifying as soon as practicable. Where the breach concerns customer content, we will notify the affected customer so they can meet their own obligations.
9. How long we keep personal information
We keep personal information only as long as needed for the purposes above or as required by law. Account information is retained for the life of the account and for a reasonable period afterwards. Customer content is retained per the customer agreement and deleted or returned on termination as set out there. [TO CONFIRM: confirm specific retention periods with your solicitor.]
10. Accessing and correcting your personal information (APP 12 & 13)
You may request access to, or correction of, the personal information we hold about you by contacting us (section 13). We will respond within a reasonable period and, if we refuse, give reasons and explain how to complain. For personal information held as customer content, please contact the relevant customer organisation; we will assist them.
11. Complaints
If you think we have breached the APPs, contact our Privacy Officer (section 13) with details. We will acknowledge your complaint, investigate, and respond within a reasonable period (ordinarily 30 days). If you are not satisfied with our response, you may complain to the OAIC (oaic.gov.au; 1300 363 992).
12. Direct marketing
Any marketing communications we send will be limited and relevant to the Service, and every message will offer a simple way to opt out. We do not use sensitive information for marketing.
13. Contact us / Privacy Officer
Privacy Officer, [TO CONFIRM: entity name] Email: [TO CONFIRM: e.g. privacy@eganservices.com] Postal: [TO CONFIRM: registered/postal address]
14. Changes to this policy
We may update this policy from time to time. The current version is always available at grace.eganservices.com/privacy, and we will indicate the "last updated" date above. Material changes will be notified through the Service or by email.