Cadie Pty Ltd (“Cadie”, “we”, “our”, “us”) builds AI-assisted software that helps organisations manage governance, risk and compliance. This policy explains how we collect, use, share and protect personal information when you visit cadie.com.au, sign up for an account, use the Cadie platform, or otherwise deal with us.
Cadie complies with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
If your organisation is a Cadie customer, this policy sits alongside and doesn’t replace the privacy and data handling terms in your customer agreement. Where those terms go into more detail (for example, on data residency or retention timeframes), the agreement governs.
Depending on how you interact with us, we may collect:
We don’t ask you to upload sensitive information (like health or criminal history) to Cadie, but recognise it can sometimes appear within Customer Content your organisation manages, for example inside an incident register. Your organisation is responsible for having a lawful basis to include that information, and we protect it to the same standard as everything else.
We use personal information to: provide and support the platform; authenticate users and manage accounts; keep the platform secure and running well; respond to enquiries; send service-related communications; comply with our legal obligations; and, where you’ve agreed to hear from us, send marketing communications (see below).
We don’t sell personal information.
Marketing. You can opt out of marketing emails at any time using the unsubscribe link, or by contacting us (see Contact us, below). Opting out won’t affect service-related messages about your account.
Cadie uses artificial intelligence to help generate insights, summaries and recommendations from the information your organisation uploads. Unless a customer has expressly agreed otherwise in writing:
We use Amazon Bedrock to run AI inference; Bedrock doesn’t use our customers’ inputs or outputs to train its own models.
Cadie’s AI is built to support human decision-makers, not replace them and outputs should be reviewed by an authorised person before being relied on for compliance, legal or operational decisions.
We may share information with the service providers who help us run Cadie, for example cloud hosting, authentication, payment, email and support tools, and with professional advisers or regulators where the law requires it. Anyone we share information with is only permitted to use it to provide the relevant service to us, or as required by law.
We don’t sell or rent personal information to third parties.
We host and process data primarily in Australia and apply security measures including encryption in transit and at rest, multi-factor authentication, role-based access controls, audit logging and regular security reviews. No system is perfectly secure, but we continually review and improve our controls.
If we ever need to send personal information overseas, we take reasonable steps to make sure it’s protected to a standard consistent with the Australian Privacy Principles, including through contractual safeguards.
We keep personal information only for as long as we reasonably need it and to provide the platform, meet our legal and contractual obligations, resolve disputes, and maintain proper business records. When we no longer need it, we securely delete or de-identify it, subject to backup processes that may retain copies for a limited period.
If you’re a Cadie customer, the specific data export and deletion timeframes that apply after your service ends are set out in your customer agreement.
Our website uses essential cookies to make the site work, and analytics cookies to help us understand how visitors use it. You can control or disable cookies in your browser settings, though some site functionality may be affected.
We use Google Analytics to help us understand how visitors use our site. Google Analytics may set cookies on your device for this purpose. You can find out more about how Google handles this data at policies.google.com/technologies/partner-sites.
Subject to some exceptions under the Privacy Act, you can ask us to:
Contact us using the details below and we’ll acknowledge your request within 5 business days and respond within 30 days.
If your organisation is a Cadie customer and your request relates to information your employer has uploaded to Cadie, we may need to direct you to your organisation, since we handle that information on their instructions.
If you’re unhappy with how we’ve handled your personal information, contact us first (details below), we’ll acknowledge your complaint within 5 business days and aim to resolve it within 30 days. If you’re not satisfied with our response, you can complain to the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au.
We may update this policy from time to time to reflect changes in our practices, technology or the law. The current version will always be available on our website.
For privacy questions, requests or complaints:
Privacy Officer
Email: support@cadie.com.au
Website: www.cadie.com.au