Cliff & Co
PlatformHow it worksSolutionsGovernanceAbout
Resources
InsightsPractical thinking on AI and operationsFAQDirect answers about Cliff
Talk to us

Legal

Privacy Policy

How Cliff & Co handles personal information across our website, enquiries, engagements and managed AI services.

1. About this policy

Cliff & Co is operated by Cliff and Family Pty Ltd (ABN 75 699 047 151) (“Cliff & Co”, “we”, “us” or “our”). This policy explains how we collect, hold, use and disclose personal information when people visit our website, contact us, participate in an operating review or interact with services we provide.

We handle personal information in accordance with applicable Australian privacy law, including the Privacy Act 1988 (Cth) and the Australian Privacy Principles where they apply to us.

Last updated: 27 August 2026.

2. The information we may collect

The information we collect depends on how you interact with us and may include:

  • identity and contact information, including your name, role, organisation, email address and telephone number;
  • enquiry, meeting and relationship information, including correspondence and information you provide about an operating problem;
  • account and access information used to authenticate or administer authorised users;
  • organisational content provided through an engagement, which may include documents, communications, workflow information, approvals and operating records containing personal information;
  • technical, usage and security information, including device, browser, IP address, event, diagnostic and page-view data; and
  • other information you or an organisation you represent chooses to provide.

We seek to collect only information reasonably necessary for the relevant purpose. Please do not provide sensitive or unnecessary personal information through a general website enquiry.

3. How we collect information

We may collect information directly from you, from the organisation you represent, through our website and services, from systems an organisation authorises us to connect with, and from service providers or public sources where lawful and relevant.

If you provide personal information about another person, you should be authorised to do so and make them aware of the relevant collection and handling arrangements.

4. How we use information

We may use personal information to:

  • respond to enquiries and arrange conversations or operating reviews;
  • assess, configure, provide, operate, support and improve agreed services;
  • prepare work, coordinate authorised actions, surface exceptions and maintain relevant operating evidence;
  • administer accounts, permissions, communications and client relationships;
  • protect systems, investigate incidents, prevent misuse and meet legal obligations;
  • understand website performance and improve our public information; and
  • communicate about services or insights where permitted by law and subject to available opt-out rights.

5. Information handled for client organisations

When a client organisation provides information for an engagement, that organisation generally determines why the information is used and who may access it. Cliff & Co handles the information to deliver the agreed service and in accordance with the applicable client agreement, authorised instructions and law.

Client information remains subject to the rights of the client and other relevant rights holders. Engagement-specific arrangements—including access, approved purposes, return, retention and deletion—should be recorded in the applicable agreement or service schedule.

6. AI systems and model training

Cliff & Co may use AI models and related technology to provide agreed capabilities. We do not use a client organisation’s content to train general-purpose AI models for ourselves or third parties without that organisation’s express written agreement.

Where third-party AI or cloud providers process information, we assess the service, available controls and intended use having regard to the information and engagement involved. Specific providers, locations or safeguards may also be addressed in client documentation.

7. Disclosure and service providers

We may disclose information where reasonably required to technology, hosting, AI, communications, security, analytics and professional-advisory providers; personnel and contractors who need it to perform their roles; a party involved in a proposed or completed business transaction; regulators, courts or authorities; and other recipients you authorise or the law permits.

We do not sell personal information. Providers are expected to handle information for the relevant service and subject to applicable contractual and legal obligations.

8. Overseas processing

Some service providers may store or process information outside Australia, including in jurisdictions where their infrastructure or support teams operate. The countries involved can vary by service and engagement.

Where overseas processing is material, we take reasonable steps appropriate to the circumstances and identify relevant arrangements in client documentation where required.

9. Website data, cookies and analytics

Our website and its security or hosting providers may use essential technologies and collect limited technical information needed to deliver, protect and understand the website. If we introduce non-essential advertising or behavioural tracking, we will update our notices and consent controls as appropriate.

You can control many browser technologies through your device or browser settings, although restricting essential functions may affect website operation.

10. Security and data incidents

We use technical and organisational safeguards appropriate to the information and service involved. These may include access controls, authentication, encryption, logging, environment separation and controlled permissions. No system is completely secure.

We assess suspected data incidents and will notify affected organisations, individuals or regulators where required by applicable law or contract.

11. Retention and deletion

We retain personal information only for as long as reasonably required for the purpose for which it was collected, an agreed service, security, dispute management, backup or legal and record-keeping obligations. We then delete, de-identify or securely dispose of it where reasonably practicable.

Client offboarding arrangements may be defined more specifically in the applicable agreement.

12. Access, correction and complaints

You may ask to access or correct personal information we hold about you, withdraw a consent where relevant, or raise a privacy concern by emailing hello@cliffandco.ai with the subject “Attention: Privacy Officer”. We may need to verify your identity and may be unable to provide access in circumstances permitted by law.

We will review privacy complaints and respond within a reasonable period. If you are not satisfied, you may be entitled to contact the Office of the Australian Information Commissioner.

13. Changes to this policy

We may update this policy as our services, practices and legal obligations change. The current version and its last-updated date will remain available on this page.

Cliff & Co

The managed AI operating system
for organisations.

Explore

PlatformHow it worksSolutionsGovernanceAbout

Resources

InsightsFAQ

Contact

hello@cliffandco.aiGold Coast, Australia

Legal

Privacy PolicyTerms of Use
© 2026 Cliff & Co · Operated by Cliff and Family Pty Ltd · ABN 75 699 047 151Work keeps moving. Your people stay in control.