Privacy Policy

Last updated: 19 August 2026

Cassandra Research Pty Ltd (“Cassandra”, “we”, “us”) operates the Cassandra Tax practice-management platform and public website. This policy explains how we handle personal information when providing the platform, client portal, support, security, billing, and configured tax-lodgement services.

We handle personal information in accordance with applicable Australian law, including the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs), and the Privacy (Tax File Number) Rule 2015. Registered tax agents and accounting practices using Cassandra Tax remain responsible for their own privacy, professional, client-authority, and record-keeping obligations.

1. Scope and the information we collect

We collect this information directly from account holders, authorised practice users and client-portal users; from configured accounting, identity, signing, billing, and ATO services when an authorised user initiates a workflow; and automatically through essential security, session, and diagnostic technologies. Please do not provide personal information that is not reasonably necessary for the relevant workflow.

2. How we use your information

The platform may produce deterministic, rules-based review flags to assist an authorised professional. Those flags are not final tax advice and do not make decisions that determine a person's rights. A qualified human remains responsible for reviewing the return and authorising any lodgement.

3. Tax File Number handling

We collect a TFN only where it is reasonably necessary for an authorised taxation, superannuation, or personal-assistance purpose permitted by law. The application encrypts TFNs at the application boundary, limits access by tenant and permission, and uses encrypted transport when an authorised workflow transmits them. We do not use or disclose TFNs as general-purpose identifiers. We securely destroy or de-identify TFN information when it is no longer required by law or for a permitted purpose.

4. Storage and security

No internet service is risk-free. If you believe your account or information has been compromised, contact security@cassandratax.com promptly.

5. Disclosure and overseas recipients

We disclose personal information only as reasonably necessary to provide an authorised service, with consent, or where required or permitted by law. Recipient categories may include:

The provider used, data disclosed, and processing location depend on the services and region configured for the practice. Likely overseas recipient locations for supported providers include the United States and New Zealand; globally distributed network, security, and support services may also process limited account or technical information in other countries. Contact us for the current configured subprocessor and country schedule before enabling a service if data location is material to you. We do not sell or rent personal information.

6. Retention and deletion

We retain personal information only while it is needed to provide the service, meet legal, professional, security, dispute, and backup obligations, or maintain an authorised record. The application is designed to retain ATO-relevant lodgement and audit evidence for seven years. Other retention periods depend on the record type, the practice's instructions, and applicable law. Deletion from active systems may not immediately remove encrypted backup copies, which expire under the applicable backup schedule.

7. Data breaches

We investigate suspected breaches promptly. Where there are reasonable grounds to suspect an eligible data breach, we will complete a reasonable and expeditious assessment within 30 calendar days. If we reasonably believe an eligible data breach has occurred, we will notify the Office of the Australian Information Commissioner and affected or at-risk individuals as soon as practicable, as required by Part IIIC of the Privacy Act.

8. Access, correction, deletion, and complaints

To request access to or correction of personal information, ask about retention or deletion, or make a privacy complaint, email privacy@cassandratax.com. Please describe the information or concern and your relationship to the relevant practice. We may verify your identity and authority before disclosing or changing information. Where a practice controls the client record, we may refer the request to that practice.

We will acknowledge a complaint, investigate it fairly, and respond within a reasonable period. If you are dissatisfied with our response, you may complain to the Office of the Australian Information Commissioner.

9. Cookies and similar technologies

Cassandra Tax uses essential cookies and local browser storage for authentication, security, navigation, and user preferences. Optional analytics or monitoring operates only when enabled for the deployment. Blocking essential cookies may prevent secure areas of the platform from working.

10. Contact, accessibility, and changes

Contact privacy@cassandratax.com for privacy questions, the current configured subprocessor schedule, or this policy in an alternative accessible format. We will post updates here and notify account holders of material changes where appropriate.