Legal
Privacy Policy
Last updated: 1 August 2026
Cassandra AML is provided by Cassandra Research Pty Ltd, an Australian company based in Melbourne, Victoria ("we", "us"). It is an AML/CTF compliance workspace for Australian tax and BAS agents, accountants, lawyers, conveyancers, real estate professionals, trust and company service providers, and precious-metals and stones dealers. This policy explains how we handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
1. Two kinds of information we handle
Account information is information about you and your practice that you give us to operate your account: names, work email addresses, practice name, ABN, professional registration numbers (such as a Tax Practitioners Board registration or a state licence number), roles and security settings.
Practice compliance records are records your practice enters while performing its own AML/CTF obligations: client identities, beneficial ownership, screening outcomes, risk assessments, reports and supporting evidence. Your practice is the custodian of these records and decides what is collected. We process them solely to provide the service and never use them for any other purpose.
2. What we collect and why
- Account and practice details — to create and administer your workspace.
- Authentication data (hashed passwords, session and device records) — to secure access.
- Audit records of actions taken in the workspace — to provide the tamper-evident history the service exists to provide.
- Identity-verification consent and redacted provider outcomes — to start a practice-initiated electronic check and retain evidence of its status without storing full identity numbers or identity images.
- Technical logs (IP address, browser type, timestamps) — to operate, secure and troubleshoot the service.
- Email delivery events for the messages we send you — to make sign-in, invitations and security notices reliable.
- Public scope-check email details - when you ask us to email an assessment, we use the address for delivery, delivery-status handling and abuse prevention, never marketing. Abuse limits use a salted one-way address key rather than the address itself. The delivery record receives a deletion date one year after the request; expired records and stale abuse-limit keys are purged before the public scope-check service next processes an assessment or email request.
We do not sell personal information, disclose it for third-party advertising, or use tracking pixels in our emails.
3. Cookies and website data
We use only essential cookies required to sign you in and keep your session secure (for example, an encrypted, HTTP-only session cookie). We do not use advertising, analytics or cross-site tracking cookies, and we do not embed third-party trackers on the site. Because only strictly necessary cookies are used, no consent banner is required; you can still block cookies in your browser, but sign-in will not work without the session cookie.
4. How information is stored
Practice compliance records and uploaded evidence files are stored in our production Neon database in Sydney, Australia. Vercel application functions are configured to execute in Sydney, although Vercel's global network, build and control-plane services may process technical request, deployment and operational metadata outside Australia. Postmark processes transactional-email recipient, message and delivery metadata in the United States.
Where your practice enables them, Didit, NameScan and Stripe process the minimum data required for identity verification, screening or billing transactions. No practice compliance data flows to an optional provider unless an authorised user initiates the relevant transaction. Where information is disclosed overseas we take reasonable steps, consistent with APP 8, to ensure it is handled in accordance with the APPs.
The service providers (subprocessors) we rely on, the function each performs and where it processes data are:
- Neon — production database and uploaded evidence storage (Sydney, Australia).
- Vercel — application hosting; functions execute in Sydney, while global network, build and control-plane services may process technical, deployment and operational metadata outside Australia (United States and other regions).
- Postmark — transactional email delivery and delivery-status metadata (United States).
- Didit — identity verification, only when your practice enables a live check; processed by the provider under its own terms and may occur overseas.
- NameScan — PEP, sanctions and adverse-media screening, only when your practice enables a live check; processed by the provider under its own terms.
- Stripe — payment and subscription processing, only if and when billing is enabled for your practice; processed by the provider under its own terms and may occur overseas.
We will update this list before adding a new subprocessor that handles personal information, and material additions are notified to account owners under section 9.
5. Security
- Encryption in transit for all connections, and encryption at rest provided by our infrastructure providers.
- Password-protected sign-in with progressive lockout and individually revocable sessions.
- Enforced row-level separation between practices at the database layer.
- A hash-chained, tamper-evident audit trail.
- Access to restricted reporting records limited to authorised roles within your practice.
6. Retention and deletion
AML/CTF record-keeping obligations generally require records to be kept for seven years, and the service applies retention periods designed around that requirement. Account information is retained while your account is active. If you close your account we will, at your written direction, export your practice's records to you and delete them from the live service, except where law requires retention.
7. Access, correction and complaints
You may request access to, or correction of, personal information we hold about you by emailing support@cassandraresearch.com. We will respond within 30 days. If you are unsatisfied with our response, you may complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
8. Data breaches
We assess suspected data breaches under the Notifiable Data Breaches scheme and will notify affected individuals and the OAIC where an eligible data breach occurs.
9. Changes to this policy
We will post updates to this page and, for material changes, notify account owners by email before the change takes effect.
10. Governing law
This Privacy Policy and any dispute concerning our handling of personal information are governed by the laws of Victoria, Australia, subject to the Privacy Act 1988 (Cth) and other applicable Commonwealth law. The parties submit to the non-exclusive jurisdiction of the courts of Victoria and the Commonwealth courts entitled to hear appeals from those courts.
11. Contact
Privacy questions: support@cassandraresearch.com