Legal

Privacy policy

Version 1.0 Effective 13 August 2026 Last updated 13 August 2026

This policy explains what personal information Epplit Pty Ltd collects, why we collect it, who we share it with, and what you can ask us to do about it. It is written to be read, not filed.

01 Who we are

Epplit Pty Ltd (ABN 14 691 288 329) — Epplit, we, us or our — is an Australian company based in Sydney, New South Wales. We build software for procurement and contract management.

We handle personal information in line with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). Where privacy laws in other places apply to you and give you additional rights, we will honour those rights to the extent they apply to us.

This policy covers the Epplit website at epplit.com and the Epplit platform and related services (together, the Services). It forms part of our Terms of Use.

02 Who this policy covers

This policy applies to:

  • visitors to our website;
  • people who book a call with us, email us, or take part in research, workshops, pilots or design partner programs;
  • users of the Epplit platform, including early access, beta and pilot users; and
  • people whose details reach us through their employer or another user.

03 What we collect

What we collect depends on how you deal with us. Most of it you give us directly.

If you book a call or contact us

Your name, business email address, employer, job title, phone number if you give it, your availability, and whatever you choose to tell us in the booking form, the meeting or the email thread. We also keep notes of what we discussed.

If you use the platform

Account details (name, business contact details, role, username or account ID, preferences and settings). We do not store passwords in readable form.

Content you or your organisation put into the Services — Customer Data — which for a procurement product typically means contracts, supplier records, correspondence, spend and payment data, policy and template documents, and the names and contact details of your staff and your suppliers' staff that appear inside those documents. You are responsible for making sure you are allowed to give us that material.

Automatically, when you use the Services

Log data (timestamps, pages and features used, actions taken), device and browser information, IP address and the general region it indicates, and diagnostic information such as error and crash reports.

From third parties

Your organisation, where an employer sets up your account or names you as an authorised user; other users who invite you; and publicly available business sources such as company websites and professional networking profiles, which we may use to research and contact prospective customers.

What we do not collect

We do not collect sensitive information as defined in the Privacy Act — such as health information, racial or ethnic origin, political opinions, religious beliefs, union membership or criminal record — and we ask you not to put it into the Services. We do not collect government identifiers. We do not currently collect payment card details; if we introduce paid plans, payments will be handled by a specialist payment provider and card numbers will not be stored by us.

If you choose not to give us certain information, we may not be able to set up your account, provide parts of the Services, or answer your enquiry.

04 How we collect it

  • Directly from you — when you book a call, email us, register, use the Services, or take part in a workshop, interview or pilot.
  • From your organisation — where your employer or its administrator sets up or manages your access.
  • Automatically — through log files and similar technologies when you use the Services.
  • From third parties — as described above.

Where it is reasonable and practicable, we collect personal information from you rather than from someone else. Where we receive it from someone else, we take reasonable steps to let you know.

05 Why we use it

  • To run the Services — create and administer accounts, authenticate users, deliver the features you use, and provide support.
  • To build the product with you — understand your role, organisation and requirements, gather and analyse feedback, and design, test and validate what we build. This is the core of our design partner program.
  • To keep the Services secure — monitor for and investigate misuse, fraud and security incidents, enforce our Terms, and meet legal obligations and lawful requests.
  • To understand usage — measure adoption and performance, and debug and improve reliability.
  • To communicate with you — service notices, invitations to research or pilots, and marketing where you have opted in (see section 14).
  • To run our business — manage customer, partner and supplier relationships, keep records, and support any merger, acquisition or restructure.

Where laws such as the EU or UK GDPR apply, we rely on: performance of a contract; our legitimate interests in operating, improving and securing the Services; your consent where it is required; and compliance with legal obligations. Where we rely on consent, you can withdraw it at any time without affecting what we did before.

06 How we use AI

Epplit uses artificial intelligence to read documents, extract dates and obligations, summarise contract terms and draft text. That means Customer Data — which can include personal information inside your contracts and correspondence — is processed by AI models.

We use Amazon Bedrock, run in Amazon Web Services' Sydney region (ap-southeast-2). Document content sent to the model is processed in that region and is not stored by the model provider after the request is served.

What we commit to:

  • We do not use your Customer Data to train, fine-tune or improve any AI model, whether ours or a third party's. Amazon Bedrock does not use the inputs or outputs of our requests to train its models or share them with model providers.
  • We do not use one customer's data to produce output for another customer, and we do not commingle customer data sets.
  • We do not send Customer Data to any consumer AI product or public chatbot.
  • AI output is a draft. Nothing is sent, filed, signed or actioned outside your organisation without a person on your side approving it.

If we add or change an AI provider in a way that materially changes how your data is processed, or in a way that moves processing outside Australia, we will update this policy and notify account holders before the change takes effect.

AI systems make mistakes. You remain responsible for your own commercial and legal decisions, and you should verify anything material against the source document.

07 Automated decisions

We do not use personal information in automated decision-making that produces legal effects for you or similarly significantly affects your rights or interests. Our software prepares information and recommendations; decisions are made by people.

If that changes, we will set out here what decisions are automated, what kinds of personal information are used, and how you can ask for human review.

08 De-identified information

We may create aggregated or de-identified information by combining and transforming data so that no individual and no customer can reasonably be identified from it — for example, benchmarks about how long contract cycles take across the market.

We use that information for analytics, research, benchmarking, reporting and product development. We will not attempt to re-identify individuals from it, and we take reasonable steps to reduce the risk of anyone else doing so. Aggregated information is never published or shared in a form that identifies you, your organisation, your suppliers or your commercial terms.

09 Who we disclose it to

We do not sell personal information. We disclose it in these circumstances:

Our people

Directors, employees and individual contractors who need it to build, run and support the Services, under confidentiality obligations.

Service providers

We use a small number of providers to run the Services:

  • Amazon Web Services — cloud hosting, storage, logging and monitoring for the Epplit platform, in the Sydney region (ap-southeast-2).
  • Amazon Bedrock — AI model processing for document reading, extraction and drafting, in the Sydney region.
  • Microsoft — email, calendar, meetings and the booking form used for discovery calls.
  • Vercel and Framer — hosting and built-in usage analytics for our public website.
  • Professional advisers — legal, accounting and audit, as needed.

These providers may only handle personal information for the purposes we specify and must protect it appropriately.

Your organisation

If you use the Services for your employer, we may disclose your usage, participation and feedback to that organisation and its administrators. In group workshops or interviews, other participants will see your name, role and contributions.

Business transfers

In connection with a merger, acquisition, financing, restructure or sale of assets, subject to confidentiality protections.

Legal

Where required or authorised by law, or where we reasonably believe disclosure is necessary to protect our rights or the safety of our users or the public.

With your consent

Anywhere else you ask us to.

10 Where your data is held

Customer Data is stored and processed in Australia, in Amazon Web Services' Sydney region (ap-southeast-2). That includes the AI processing described in section 6.

Some personal information is disclosed to recipients outside Australia. Specifically:

  • Microsoft may store or access email, calendar, meeting and booking content in the United States and other countries where it operates infrastructure and support, so the details you give us when you book a call are handled outside Australia;
  • Vercel and Framer host our public website on global edge infrastructure and provide its usage analytics, so visitor IP addresses, page views and referrer data are processed outside Australia, including in the United States; and
  • our providers' support and engineering teams may access their systems from outside Australia for troubleshooting, under contractual access controls.

Before disclosing personal information overseas we take reasonable steps to ensure the recipient handles it consistently with the Australian Privacy Principles, usually through contractual commitments. Overseas recipients may be subject to laws that differ from Australian law.

If you need all processing of your Customer Data to stay onshore, tell us before you sign — we will confirm in writing what we can and cannot meet.

11 Security

We take reasonable technical and organisational steps to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure. These include encryption in transit and at rest, multi-factor authentication, role-based access control, least-privilege access for our own staff, logging and monitoring, and separation of customer data.

Our security program is aligned to ISO/IEC 27001 and the ACSC Essential Eight. We are not certified against either standard, and we will tell you in writing exactly where we are if you ask.

No system is completely secure. To the extent the law allows, we do not guarantee absolute security, and you are responsible for keeping your credentials safe and for keeping your own copies of anything you cannot afford to lose.

12 Data breaches

If we suspect a data breach involving personal information, we will investigate promptly and complete our assessment within 30 days. Where a breach is likely to result in serious harm, we will notify the affected individuals and the Office of the Australian Information Commissioner as soon as practicable, as required by the Notifiable Data Breaches scheme.

Where the breach affects Customer Data belonging to an organisation, we will also notify that organisation's nominated contact so it can meet its own obligations.

To report a suspected vulnerability or breach, email security@epplit.com.

13 How long we keep it

  • Customer Data — for as long as your organisation uses the Services, then deleted or de-identified within 90 days of the end of your agreement, unless you ask for it sooner or the law requires us to keep it.
  • Account and contact records — while your account is active and for up to 7 years afterwards, to meet record-keeping, tax and dispute obligations.
  • Prospect and enquiry records — up to 2 years after our last contact, unless you ask us to delete them earlier.
  • Logs and diagnostics — up to 12 months.

Backups are overwritten on a rolling cycle, so deleted data may persist in backup for a short period before it is fully removed.

14 Marketing

We send marketing emails only to people who have asked to hear from us, or whose business contact details we have obtained in circumstances where the Spam Act 2003 (Cth) allows us to contact them about a directly relevant business offering. Every marketing message identifies us and includes a working unsubscribe link that we action within 5 business days.

Using our website does not sign you up to anything. You can opt out at any time by using the unsubscribe link or emailing us. We will still send you notices about your account and the Services.

15 Cookies and analytics

Our public website is hosted on Vercel and Framer and uses the usage analytics built into those platforms. They count page views, referrers and approximate location so we can see which parts of the site are read. They do not set advertising or cross-site tracking cookies, and we do not run advertising pixels or retargeting on the site.

The Epplit platform uses cookies and similar storage to keep you signed in, remember your preferences and measure how features are used. You can control cookies through your browser, but blocking them may stop parts of the platform working.

If we add analytics or marketing tools beyond those described above, we will update this section and, where consent is required, ask for it first.

16 Your rights

You can ask us to:

  • give you access to the personal information we hold about you;
  • correct anything inaccurate, out of date, incomplete or misleading;
  • delete personal information we hold about you, where we are not required to keep it;
  • stop or limit particular uses; or
  • provide your information in a portable format, where that right applies to you.

Email us using the details in section 19. We may need to verify who you are. We will respond within 30 days. If we refuse a request, we will tell you why in writing and how to complain, unless the law prevents us.

If your organisation controls your account, some requests may need to go through them, and we will tell you if that is the case.

17 Age

The Services are for use by adults in a business context. They are not directed at anyone under 18, and we do not knowingly collect personal information about children. If you believe we have, contact us and we will delete it.

18 Changes

We update this policy when our practices or the law change. The version number and effective date at the top always tell you which version applies.

For minor changes, we update this page. For changes that materially affect how we handle personal information, we will give account holders at least 30 days' notice by email or in the platform before the change takes effect.

19 Contact and complaints

Questions, access and correction requests, and privacy complaints all go to the same place.

Privacy Officer, Epplit Pty Ltd
Email: privacy@epplit.com
Post: Level 1, 63–73 Ann Street, Surry Hills NSW 2010, Australia
ABN 14 691 288 329

We will acknowledge a complaint within 5 business days and give you a written response within 30 days. We may ask you for more detail so we understand the problem. If we agree something has gone wrong, we will tell you what we are doing to fix it.

If you are not satisfied with our response, you can take the matter to the Office of the Australian Information Commissioner at oaic.gov.au or 1300 363 992.