Privacy Policy
How we handle personal information you and your firm entrust to Cassandra Legal.
Last updated 13 July 2026
Cassandra Legal Pty Ltd ("Cassandra Legal", "we", "us") provides legal practice-management software to law firms. This policy explains how we handle personal information and is designed to align with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth). It applies to our website and the Cassandra Legal application.
Roles: controller and processor
When a law firm uses Cassandra Legal to manage its matters, clients, and trust records, the firm is the controller of that data and Cassandra Legal acts as a processor, handling the data on the firm's instructions under our Terms of Service. For our own account, billing, and website data, we act as the controller.
Information we collect
- Account information — firm name, your name, work email, role, and hashed password. Passwords are stored only as salted bcrypt hashes and are never visible to us.
- Firm workspace data — matters, clients, documents, time entries, invoices, and trust-ledger records your firm enters or imports. This may include personal information about your firm's clients.
- Billing information — plan, subscription status, and a Stripe customer identifier. Card details are collected and stored by Stripe, our payment processor; we do not store card numbers.
- Technical information — request logs, IP address, and diagnostic data used to secure and operate the service.
How we use information
- To provide, secure, and support the Cassandra Legal service.
- To process subscriptions and payments through Stripe.
- To send transactional email (invites, invoices, portal notices, password resets) through our email provider.
- To detect, prevent, and respond to security and abuse.
- To meet legal, regulatory, and trust-accounting record-keeping obligations.
We do not sell personal information, and we do not use your firm's workspace data to train machine-learning models.
Sub-processors
We rely on a small number of vetted providers to run the service: cloud hosting and application delivery (Vercel), the managed PostgreSQL database (Neon), payments (Stripe), transactional email (Postmark), and e-signature (Zoho Sign). Each processes data only to provide its function to us.
Data location and security
Firm data is stored in a managed PostgreSQL database. We use encryption in transit (HTTPS), scoped multi-tenant access so each firm can only see its own records, role-based permissions, and audit logging of material actions. No method of transmission or storage is perfectly secure, but we take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access.
Retention
We retain firm workspace data for as long as your firm maintains an account, and afterwards only as needed to meet legal and trust-accounting record-keeping obligations, resolve disputes, and enforce agreements. You can request export or deletion of your firm's data as described below.
Your rights
Subject to the APPs, you may request access to, or correction of, the personal information we hold about you. Where Cassandra Legal is a processor, requests from a firm's clients should be directed to the firm; we will assist the firm in responding. To make a request or raise a privacy concern, contact us at privacy@cassandralegal.com. If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC).
Data breach notification
We maintain an incident-response process and, in the event of an eligible data breach likely to result in serious harm, will notify affected firms and the OAIC as required by the Notifiable Data Breaches scheme.
Changes
We may update this policy from time to time. Material changes will be posted here with a revised "last updated" date. Continued use of the service after an update constitutes acceptance of the revised policy.
Contact
Cassandra Legal Pty Ltd — privacy@cassandralegal.com. For support, see our support page.