LEGAL · PRIVACY POLICY

Privacy Policy

Effective: 1 May 2026 · Operated by Dara Technology Pty Ltd (ACN to be confirmed)

// 01

Who we are

DARA OS ("DARA", "we", "us") is a SaaS platform operated by Dara Technology Pty Ltd (ACN to be confirmed), an Australian-registered company headquartered in Sydney, NSW. We provide a Bloomberg-style operating terminal that unifies a customer's POS, accounting, and treasury data sources into an AI-grounded daily briefing.
// 02

Scope of this policy

This Privacy Policy explains how DARA collects, uses, stores, and discloses information when you (i) visit daraos.ai, (ii) sign up for a DARA workspace, (iii) connect third-party services to your workspace, or (iv) communicate with us by email, support form, or any other channel. It applies to both the public website and the authenticated application.
// 03

Information we collect

We collect the following categories of information:

  • Account data: name, business name, role, email address, hashed password, industry classification, two-factor authentication seed (if enabled), and email-consent timestamp.
  • Workspace data: business data you upload, paste, or sync into your workspace — including (where you choose to connect them) transactions from your POS provider (e.g. Square), invoices from your accounting provider (e.g. Xero or MYOB), and structured CSV files you upload. This data belongs to you.
  • Operational logs: IP addresses, browser user-agents, request paths, and event timestamps, kept for security and abuse-prevention purposes for up to 90 days.
  • Billing data: payment-method metadata (card brand, last four digits, expiry) handled through Stripe — DARA does not store full card numbers.
  • Marketing data: if you tick our email consent box, we record the consent action with timestamp, IP, and source URL.
// 04

How we use your information

We use the data described above to:

  • Provide and operate the DARA platform — including authentication, data ingestion, AI-grounded briefings, and integration with any third-party services you elect to connect.
  • Bill you for subscriptions and process refunds through Stripe.
  • Send transactional emails (account verification, billing receipts, security alerts) that are required to operate the service.
  • Send marketing or product-update emails only where you have given explicit consent, with a one-click unsubscribe in every email.
  • Monitor for fraud, abuse, performance issues, and unauthorised access.
  • Comply with our legal obligations under Australian and other applicable law.
// 05

AI and your data

DARA uses Anthropic's Claude (Sonnet 4.5) large language model to synthesise your workspace data into daily briefings and answer your natural-language queries. We submit your data to the Claude API solely for the purpose of returning the response you have requested.

Anthropic does not train its commercial models on data submitted via their API. We do not authorise or instruct any model provider to train on your data. We retain Claude prompts and responses associated with your workspace for up to 30 days for debugging and quality-assurance purposes, after which they are deleted.

If you operate in a sector with strict data-residency requirements (defence, government, regulated finance) please contact us at privacy@daraos.ai to discuss an air-gapped Enterprise deployment.

// 06

Third-party services we use

We rely on the following third-party services to operate DARA. Each provider operates its own privacy policy, which you should review:

  • Anthropic — AI synthesis layer (Claude 4.5 Sonnet)
  • Stripe — payment processing
  • Resend — transactional and consent-based marketing email delivery
  • MongoDB Atlas — primary data store
  • Square, Xero, MYOB — only where you have explicitly connected one of these services to your workspace

We do not sell, rent, or otherwise share your personal information with third parties for their own marketing purposes. We only share the minimum information necessary for these providers to deliver the services we contract them to perform.

// 07

Data security

We maintain commercially reasonable safeguards to protect your data, including:

  • TLS 1.3 for all data in transit
  • Fernet-encrypted vault for stored API keys and OAuth tokens
  • Per-user TOTP two-factor authentication available on every account
  • Server-side rate-limiting and brute-force protection on authentication endpoints
  • Bcrypt password hashing
  • Email-consent audit trail with IP + timestamp
  • Audit log of administrative actions
  • SOC 2 Type I attestation in progress (target 2026)
// 08

Your rights

If you reside in Australia, under the Privacy Act 1988 (Cth) you have the right to:

  • Access the personal information we hold about you
  • Correct any personal information that is inaccurate or out of date
  • Request that we delete your account and associated data (data deletion is also available self-serve within the app: Settings → Account → Delete account)
  • Lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au

If you reside in the European Union or United Kingdom, the rights granted under the General Data Protection Regulation (GDPR) apply to you in addition to the above — including the right to data portability and the right to object to processing.

// 09

International data transfers

DARA is hosted on infrastructure located primarily in Australia and the United States. Where data is transferred outside Australia, we rely on the privacy frameworks operated by our third-party providers (including EU Standard Contractual Clauses) and only transfer the minimum data necessary to deliver the service you requested.
// 10

Data retention

We retain your data as follows:

  • Account data: for the lifetime of your account, plus 90 days after deletion to handle billing reconciliation and abuse investigations.
  • Workspace data: for the lifetime of your subscription, plus 30 days after subscription cancellation to allow for restoration if you reactivate.
  • Operational logs: up to 90 days.
  • Billing records: 7 years, as required by Australian tax law.
// 11

Children

DARA is a B2B platform intended for use by businesses. We do not knowingly collect personal information from anyone under 18 years of age.
// 12

Updates to this policy

We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. Material changes will be notified to active customers by email with at least 14 days' advance notice. The most current version is always available at this URL.
// 13

Contact us

Privacy enquiries should be directed to privacy@daraos.ai. Postal mail can be addressed to: Dara Technology Pty Ltd (ACN to be confirmed), c/o the Privacy Officer, Sydney NSW, Australia.
Dara Technology Pty Ltd (ACN to be confirmed) · 1 May 2026 · v1.0