Legal
Privacy Policy
Draft β pending legal review
This document is a working draft prepared as a starting point, not a lawyer-reviewed or binding agreement. It does not yet govern any account or subscription. Bracketed items (like our registered entity name and ABN) are placeholders pending company registration. Draft dated draft, not yet published.
This Privacy Policy explains how [Eidon Pty Ltd, ACN/ABN pending]("we", "us") handles personal information in connection with the Eidon website and product ("Service"). It is written to align with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth), and to give equivalent protection to individuals in the European Economic Area under the GDPR where it applies to our processing of their data.
1. Two kinds of personal information
We handle personal information in two distinct roles. As the operator of the Service, we collect account and billing information about the people who sign up for and administer a workspace (account data), for which we are the data controller. Separately, our Customers use workspaces to store their own architecture, service, engagement and diagramming records, which may incidentally include personal information about a Customer's own staff, stakeholders or contacts (Customer Data), for which the Customer is the controller and we act only as a processor on their instructions β see our Data Processing Addendum for that relationship. This policy is primarily about the first category.
2. What we collect
- Account details you provide: name, work email, password (stored hashed, never in plaintext), and workspace name.
- Billing details, handled directly by Stripe: we receive subscription status and billing metadata, not full card numbers.
- Usage and diagnostic data: log-in activity, audit-log entries for actions taken in your workspace, and basic technical logs (IP address, browser) kept for security and troubleshooting.
- Support correspondence, if you contact us via the contact form or in-app support.
- Content of Customer Data only to the extent needed to operate features you use (for example, AI-assisted drafting sends the relevant content to the AI provider you configure β see section 4).
3. How we use it
- To create and operate your account and workspace, including authentication and role-based access control.
- To process payments, taxes (including GST) and manage subscriptions, via Stripe.
- To send service communications: trial and billing notices, security alerts, and (only if you opt in) product updates.
- To provide support when you ask for it.
- To maintain the security, integrity and audit trail of the Service, including detecting abuse.
We do not sell personal information, and we do not use Customer Data to train any AI model.
4. Who we share it with
We keep the list of parties who can access data intentionally short, and each one exists for a specific reason rather than as a bundled default β see our security page for the current subprocessor list. Notably: payment processing is handled by Stripe; outbound email is sent through SMTP credentials you configure yourself in Settings, not a bundled email vendor; and any third-party AI provider used for AI-assisted drafting or search is also one you configure yourself per workspace β if you choose to enable that feature, content you send through it is subject to that provider's own terms, which we do not control. Optional integrations (Jira, Azure DevOps, Confluence, an SSO/OIDC identity provider) only exchange data with the destination you configure. We may also disclose information where required by law, or to protect the rights, safety or property of Eidon, our customers, or others.
5. Overseas disclosure
Some of the providers above (including Stripe, and cloud hosting infrastructure once finalised) may process or store data outside Australia. Where this happens, we take reasonable steps to ensure recipients handle personal information consistently with the APPs, or rely on an applicable exception, consistent with APP 8. We will publish our finalised list of hosting regions and any related safeguards (such as GDPR standard contractual clauses for EEA customers) once our cloud infrastructure is finalised.
6. Data security
Connector credentials, single sign-on/LDAP configuration and other secrets are encrypted at rest. Every record in the product is scoped to its workspace at the data layer, and every change to a governed artifact is recorded in an audit trail. See our security page for the fuller picture of how the Service is built.
7. Data retention
We retain account data for as long as your workspace is active. If you schedule your workspace for cancellation, it enters a 30-day grace period during which it can be restored; once that period elapses (or you request immediate deletion), workspace data is deleted, other than what we must retain for legal, accounting or dispute-resolution purposes. Workspace admins can configure their own retention policy for audit history and backups within the product.
8. Your rights
You can access and export your own account and workspace data at any time from within the product (a self-service action, not a support ticket). Subject to identity verification, you may ask us to correct inaccurate account data, and β where the GDPR applies to you β to erase it, restrict its processing, or receive it in a portable format. To make a request, contact us using the details in section 10. If you are not satisfied with our response, Australian individuals may complain to the Office of the Australian Information Commissioner (OAIC), and EEA individuals to their local supervisory authority.
9. Cookies
See our separate Cookie Policy for what this website and the product application do and don't set.
10. Contact and changes
Privacy questions or requests can be sent to [privacy@eidon.example.com] or via our contact page. We may update this policy from time to time; material changes will be reflected here with an updated date once this document is finalised.