Effective Date: 19 December 2024
Last Updated: 19 December 2024
CivDocs Pty Ltd (ABN 16 691 993 049) ("CivDocs," "we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and disclose personal information when you use the CivDocs platform (the "Service").
This Privacy Policy is governed by the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
CivDocs is designed for Australian businesses, users located outside Australia may access the Service. By using CivDocs, you consent to the handling of your personal information in accordance with this Privacy Policy and Australian law.
We collect personal information that is reasonably necessary to operate the CivDocs platform.
Depending on your role within an organisation, this may include:
Where uploaded by users or organisations:
When using Crank.ai:
For organizations using the invoice creation feature, we may store:
This information is stored securely and used solely to display payment instructions on invoices generated by your organization. These details are not used for payment processing by CivDocs. Only organization administrators can add or modify this information.
CivDocs is not designed to collect sensitive information such as:
However, due to free-text fields and file uploads, users may choose to upload such information.
By uploading sensitive information, you:
CivDocs does not review, validate, or classify uploaded content for sensitive information.
We use personal information to:
CivDocs does not use your data to train AI models.
AI processing is performed using OpenAI's API. When you use Crank.ai, the following data is sent to OpenAI:
OpenAI processes this data according to their API privacy policy. According to OpenAI's current policy, data sent via their API is not used to train their models unless explicitly opted in. However, OpenAI's policies are subject to change, and CivDocs cannot control third-party provider practices.
We do not sell, rent, or trade personal information.
We may disclose personal information to the following third-party service providers for the purpose of operating CivDocs:
Purpose: Database, authentication, file storage
Data disclosed: All personal information collected by CivDocs is stored in Supabase's database and file storage systems.
Purpose: Subscription billing and payments
Data disclosed: Organization name and email, billing name, billing email, billing address (street, city, state, postal code, country), payment card information (processed securely by Stripe, not stored by CivDocs), and subscription plan and billing interval metadata.
Purpose: AI analysis and response generation
Data disclosed: User questions and prompts, relevant organization data (project names, scope descriptions, cost data, timesheet summaries, machine information) necessary to answer queries, and conversation history for context. See Section 6.2 for more details.
Purpose: Email delivery
Data disclosed: Recipient email addresses, organization names, inviter names, invite roles, and password reset tokens (for password reset emails only).
Purpose: Hosting and infrastructure
Data disclosed: Vercel hosts the CivDocs application and may log IP addresses and request metadata for operational and security purposes.
These providers may process data outside Australia. We take reasonable steps to ensure they handle personal information in accordance with applicable privacy laws.
CivDocs uses cookies strictly necessary for:
We do not use advertising cookies or third-party tracking cookies.
Local storage may be used for:
Local storage is not used for tracking or advertising.
CivDocs logs limited application activity for operational and security purposes, including:
We do not:
(Note: Third-party infrastructure providers may log IP addresses for security and operational purposes.)
We take reasonable technical and organisational measures to protect personal information, including:
However, no system is completely secure. CivDocs does not guarantee absolute security and is not liable for unauthorised access beyond what is required by law.
You may:
Some information (such as roles, rates, or employment data) may only be managed by an organisation administrator.
Account Deletion:
At this time, CivDocs does not provide self-service account deletion. Requests may be made via support.
CivDocs may use aggregated and anonymised data (with all personal and organisational identifiers removed) for:
Such data cannot be used to identify individuals or organisations.
In the event of a data breach involving personal information, CivDocs will comply with its obligations under the Notifiable Data Breaches scheme and notify affected individuals where required by law.
We may update this Privacy Policy from time to time. Material changes will be notified via the Service or email.
Continued use of CivDocs after changes take effect constitutes acceptance of the updated Policy.
For privacy-related questions or requests, contact:
CivDocs Pty Ltd
ABN 16 691 993 049