1. About this policy
Chaird respects privacy and is committed to handling personal information openly, transparently and responsibly.
This Privacy Policy explains how Chaird Pty Ltd and its authorised personnel (Chaird, we, us or our) collect, hold, use and disclose personal information. It also explains how individuals may access or correct their information, make a privacy complaint, or contact us with a question.
This policy is designed to align with the Australian Privacy Principles in the Privacy Act 1988 (Cth) where they apply. Chaird intends to follow comparable privacy-by-design standards even during any period in which a small-business exemption may apply.
2. Who we are
Chaird is developing a Governance Intelligence platform intended to help organisations manage governance information, meetings, Board and committee papers, decisions, actions, accountability, organisational memory and related insights.
- Legal entity: Chaird Pty Ltd ACN 700 916 570
- Website: chaird.com
- Privacy contact: Privacy Officer
- Email: hello@chaird.com
3. Scope
This policy applies to personal information Chaird handles through:
- our website and online forms;
- customer discovery, research and Design Partner activities;
- product demonstrations, trials, pilots and subscriptions;
- sales, marketing and events;
- customer implementation, support and account management;
- supplier, contractor and advisor relationships;
- recruitment and workforce administration, subject to any applicable employee-records rules;
- corporate, legal, finance, security and governance activities.
Customer organisations may use Chaird to handle personal information under their own authority and instructions. In those circumstances, Chaird may act as a service provider or processor, while the customer remains responsible for deciding why and how the information is handled. Customer contracts and data-processing terms may provide additional detail.
4. Meaning of personal information
Personal information is information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether the information is true or recorded in material form.
Some personal information may be sensitive information and receive additional protection. Examples can include health information, racial or ethnic origin, political opinions, religious beliefs, sexual orientation, trade-union membership, criminal record or biometric information.
Chaird does not intend to collect sensitive information unless it is reasonably necessary for a legitimate activity and the collection is permitted by law, including obtaining consent where required.
5. Personal information we collect
The categories of personal information we may collect include identity and contact information; account information; customer and governance information; research and discovery information; commercial information; website and technical information; communications; supplier and advisor information; recruitment information; and security and compliance information.
Examples include your name, title, role, organisation, email address and professional profile; account identifiers and permissions; research responses and workflow descriptions; enquiries and proposals; browser, device and referral information; and communications with Chaird.
6. How we collect personal information
We may collect personal information directly from you when you contact us, complete a form, create an account, attend an event or participate in research; from your organisation; through use of our website, products and services; from approved service providers, partners, advisors or referral sources; from public sources such as professional websites, company websites and public registers; through recruitment agencies, referees and background-check providers where appropriate; and when required or authorised by law.
Where reasonable and practicable, Chaird will collect personal information directly from the individual. We will seek to collect only information reasonably necessary for our functions and activities.
7. If you do not provide information
You may choose not to provide personal information. However, Chaird may be unable to respond to an enquiry, provide an account, complete a transaction, conduct a research activity, assess an application or deliver a requested service.
Where lawful and practicable, individuals may interact anonymously or using a pseudonym. This may not be possible where identity is required for security, customer access, contracting, payment, legal compliance or effective service delivery.
8. Purposes for which we use information
Chaird may use personal information to provide, administer, secure and improve our website, products and services; create and manage accounts and permissions; support governance workflows as instructed by customers; conduct customer discovery, Design Partner, product research and usability activities; respond to enquiries and complaints; manage business relationships and transactions; send service, security, legal and account communications; develop and test product functionality subject to appropriate controls; protect Chaird, customers and users; maintain corporate and compliance records; recruit and manage workers; conduct marketing and thought-leadership activities where permitted; and comply with law and enforce agreements.
9. Product data and customer instructions
Customers control the information they choose to place in the Chaird service and are responsible for ensuring they have authority to provide that information and instruct Chaird to process it.
Chaird will use customer-provided personal information to provide and support the service, meet security and legal obligations, and perform other activities authorised by the customer agreement.
Chaird will not use customer content to train a general-purpose AI model unless this has been expressly agreed in writing and supported by an appropriate legal, privacy, security and Responsible AI assessment.
10. Artificial intelligence
Chaird may use artificial intelligence and automated tools to assist with functions such as summarisation, classification, retrieval, drafting, analysis, workflow support or product improvement.
Where AI is used, Chaird seeks to apply purpose limitation and data minimisation; appropriate security and provider assessment; clear customer instructions and contractual controls; human review for material governance outputs; transparency appropriate to the context; monitoring for material error, bias or misuse; and preservation of accountability for decisions.
Chaird does not intend AI-generated output to replace legal, regulatory, audit, governance or other professional judgement. Customers and users remain responsible for reviewing outputs and exercising decision authority.
11. Cookies, analytics and tracking technologies
Chaird may use cookies, local storage, logs and similar technologies to operate and secure its website, remember preferences and understand usage. Where optional analytics or marketing technologies are introduced, Chaird will provide appropriate transparency and any required preference or consent controls.
12. Direct marketing
Chaird may use business contact information to send relevant information about its products, research, events, insights or opportunities where permitted by law.
Marketing communications will provide a practical way to unsubscribe. You may also ask Chaird at any time not to use your personal information for direct marketing. Service, legal, security and account communications are not marketing and may continue where necessary.
13. Disclosure of personal information
Chaird may disclose personal information to the organisation that provides or manages your Chaird account; Chaird personnel, contractors and advisors who require access for an authorised purpose; cloud, hosting, communications, authentication, analytics, customer-support, payment and other technology providers; professional advisers, auditors, insurers and financiers; implementation, integration and support partners authorised for the engagement; potential investors, purchasers or transaction advisers under appropriate confidentiality safeguards; regulators, courts, law-enforcement bodies or other parties where required or authorised by law; and another party with your consent or at your direction.
Chaird does not sell personal information. Chaird will not disclose identifiable customer research quotations, names, logos or case-study information without the required approval.
14. Overseas storage and disclosure
Chaird may use service providers or personnel located outside Australia. This can involve storing, accessing or disclosing personal information overseas.
Chaird will take reasonable steps appropriate to the circumstances to assess and manage overseas privacy and security risk, which may include contractual protections, supplier due diligence, access controls, encryption, data minimisation and customer-specific commitments.
15. Security
Chaird takes reasonable steps to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure.
Depending on the context, controls may include identity and access management, least privilege and multi-factor authentication; encryption where supported; secure development and change-management practices; environment separation and access logging; supplier and subprocessor assessment; vulnerability, backup and recovery controls; security awareness and confidentiality obligations; incident detection, escalation and response; and retention, deletion and de-identification controls.
No system can be guaranteed completely secure. Individuals should protect their credentials, use strong authentication and notify Chaird promptly of suspected unauthorised access.
16. Data breaches
Chaird maintains processes to assess and respond to suspected data breaches. Where the Notifiable Data Breaches scheme applies and a breach is likely to result in serious harm, Chaird will take the required steps, which may include notifying affected individuals and the Office of the Australian Information Commissioner.
17. Retention and deletion
Chaird retains personal information only for as long as reasonably required for the purpose for which it was collected, related business and legal purposes, contractual commitments, security, dispute management and applicable recordkeeping obligations.
When information is no longer required, Chaird will take reasonable steps to delete it, destroy it or de-identify it, subject to backup cycles, legal holds and technical constraints.
Website enquiries and research or discovery records may generally be retained for up to 24 months after the last meaningful interaction, unless a shorter activity-specific period applies or a longer period is required for legal or legitimate business reasons.
18. Access and correction
You may request access to personal information Chaird holds about you or ask us to correct information that is inaccurate, out of date, incomplete, irrelevant or misleading.
Chaird may need to verify your identity and may ask for information required to locate the relevant records. We will respond within a reasonable period. Where personal information is controlled by a Chaird customer, we may direct the request to that customer or assist the customer in responding.
19. Complaints
You may complain if you believe Chaird has mishandled your personal information or breached an applicable privacy requirement. Please email hello@chaird.com with your contact details, a description of the concern, relevant dates or records and the outcome you are seeking.
Chaird will acknowledge the complaint, investigate it fairly and seek to respond within a reasonable period. If you are not satisfied with Chaird’s response and the Privacy Act applies, you may be entitled to complain to the Office of the Australian Information Commissioner.
20. Children
Chaird’s services are intended for organisations and professional users, not children. Chaird does not knowingly seek personal information directly from children.
21. Third-party websites and services
Chaird’s website or communications may link to third-party websites or services. Chaird is not responsible for their privacy practices. Individuals should review the privacy information provided by those third parties.
22. Business transactions and corporate change
If Chaird considers or completes an investment, financing, restructure, merger, acquisition, sale or transfer of assets, personal information may be disclosed to advisers and counterparties under appropriate confidentiality safeguards and may be transferred as part of the transaction, subject to law.
23. Changes to this policy
Chaird may update this policy as its products, systems, suppliers, legal obligations and privacy practices change. The current version will state its effective date. Where a change is material, Chaird may provide additional notice through the website, product or direct communication.
24. Contact us
For privacy questions, access or correction requests, complaints or other privacy enquiries, contact the Chaird Privacy Officer at hello@chaird.com.