Privacy Policy

Plain Language Summary

This Privacy Policy explains how Gathid collects, uses, discloses, and protects personal information. It is intended to meet global privacy expectations, including the GDPR, CCPA/CPRA, LGPD, PIPEDA, and Australia’s Privacy Act and Australian Privacy Principles. We aim to be transparent, collect only what we need, protect it appropriately, and give individuals meaningful choices and rights over their information.

Privacy Policy Overview

  • Gathid collects information directly from you, automatically when you use our websites and services, and from selected third-party sources.

  • We use information to provide, secure, support, personalise, and improve our services, and to communicate with you.

  • We disclose information to service providers under contractual controls, to comply with law, to protect rights and security, in connection with business transfers, and with your consent. We do not sell personal information or share personal information for cross-context behavioural advertising.

  • You may have rights to access, correct, delete, object to, restrict, or port your personal information, and to opt out of some communications or uses.

  • Region-specific rights and disclosures are included in the Regional Disclosures section.

Introduction

At Gathid, we value privacy and are committed to protecting personal information in accordance with applicable data protection laws worldwide, including the General Data Protection Regulation (GDPR), California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), Brazil’s LGPD, Australia’s Privacy Act and Australian Privacy Principles (APPs), Canada’s PIPEDA and applicable provincial privacy legislation (including Quebec’s Law 25), and other applicable regional regulations.

Scope of This Policy

This policy describes how Gathid collects, uses, discloses, and protects personal information from individuals across the globe, including website visitors, users, prospective customers, customers, business partners, suppliers, event contacts, and other people who interact with Gathid. It applies to Gathid websites, products, and services that reference this policy.

Controller and Processor Roles

This Privacy Policy describes Gathid’s data practices as a controller of personal information. It does not apply to the extent that we process personal information in the role of a processor or service provider on behalf of our customers, as further specified in the Data Processing Addendum or other agreement entered into with those customers.

When Gathid processes personal information on behalf of a customer, such as your employer or another organisation that provides you access to Gathid services, that customer is the controller or business and manages the relevant account. We handle that information according to the customer’s instructions. For more information about how a Gathid customer uses your personal information, please contact that organisation directly.

Information We Collect

We collect personal information in four main ways: information you provide to us, information collected automatically when you use our services, file ingestion and metadata and information we receive from other sources.

Information You Provide

  • Account and profile information: name, email address, phone number, role, organisation, login credentials, and account preferences.

  • Content and communications: information you submit through Gathid products, forms, surveys, events, support requests, sales conversations, or other interactions with us.

  • Business relationship information: contact, contractual, procurement, billing, and relationship information, including information provided by handing over a business card, scanning an event badge, completing a web form, or connecting with us on LinkedIn or other professional networks.

  • Payment and transaction information: billing details, purchase history, and related commercial information. Payment card information may be processed by third-party payment providers.

  • Physical visit information: visitor logs and access records used for safety, security, and compliance.

Information We Collect Automatically

  • Usage information: pages visited, features used, interactions, timestamps, referral URLs, and product activity.

  • Device and connection information: IP address, device identifiers, browser type, operating system, approximate location, language settings, and network information.

  • Authentication and security information: login events, identity management signals, audit logs, and security telemetry.

  • Cookies and similar technologies: identifiers and usage data collected through cookies, pixels, local storage, SDKs, and similar technologies.

File Ingestion and Metadata

When customers use Gathid services to upload, connect, scan, or ingest files or documents, Gathid may collect and process metadata associated with those files. This metadata may include information such as file name, file type, file size, creation and modification dates, document properties, author or owner fields, access permissions, location or folder path, system identifiers, and other technical or structural attributes associated with the file.

File metadata may include personal information where, for example, a file name, author field, document property, access permission, or embedded identifier relates to an identifiable person. Gathid does not collect file metadata for purposes unrelated to providing, securing, supporting, or improving the services.

We use file metadata to:

  • provide and operate Gathid services;

  • support identity governance, access visibility, and security analysis;

  • help customers understand where files are stored, who may have access to them, and how they are used;

  • detect, investigate, and respond to security, compliance, or operational risks;

  • improve the accuracy, reliability, and performance of our services; and

  • provide customer support, troubleshooting, reporting, and audit capabilities.

Collecting and processing file metadata helps customers gain better visibility into their information environment, identify access or identity risks, improve governance, and make more informed security and compliance decisions.

Customers may configure, limit, or disable certain file ingestion features where product settings, integrations, or contractual arrangements allow. Customers may also contact Gathid at privacy@gathid.com to ask questions, provide feedback, or request assistance with limiting or opting out of metadata processing where available. Some metadata processing may be necessary for Gathid to provide core service functionality, security controls, auditability, or compliance obligations.

Where Gathid processes file metadata on behalf of a customer, we do so in accordance with the customer’s instructions, applicable agreements, and our Data Processing Addendum. Customers are responsible for ensuring they have appropriate authority, notices, and legal bases for making files and associated metadata available to Gathid through their selected integrations and product configurations.

Information From Other Sources

  • Other users and administrators: information provided by your organisation, administrator, or other users when they invite you, manage your account, or interact with you through our services.

  • Service providers and business partners: enrichment, analytics, marketing, security, and integration information from providers we work with.

  • Publicly available sources: professional information available from company websites, public registers, social networks, or similar sources.

How We Use Information

We use personal information for the following purposes:

  • Provide and personalise the services: create and manage accounts, authenticate users, deliver product functionality, and personalise user experience.

  • Develop and improve services: understand usage, troubleshoot, test, enhance performance, and develop new features.

  • Communicate with you: send service messages, product updates, security notices, administrative information, and responses to inquiries.

  • Marketing and events: provide information about Gathid products, events, content, and offers where permitted by law and your preferences.

  • Customer support: investigate, respond to, and resolve support requests. We may use artificial intelligence to assist with support-related responses and service improvement, subject to appropriate safeguards.

  • Safety, security, and integrity: detect, prevent, and respond to security incidents, fraud, abuse, unauthorised access, and service misuse.

  • Legal and business purposes: comply with legal obligations, enforce agreements, protect rights and interests, and maintain business records.

  • With consent: use information for other purposes where you have given consent.

  • Aggregate or de-identify data: create aggregated, anonymised, or de-identified information that does not identify you and use it for analytics, reporting, benchmarking, and service improvement.

Cookies and Tracking Technologies

Gathid uses cookies and similar technologies to operate our websites and services, remember preferences, improve user experience, analyse traffic, support security, and, where applicable, deliver or measure marketing. We use the following categories of cookies:

  • Essential cookies: required for basic site functionality, authentication, security, and service delivery.

  • Performance and analytics cookies: help us understand how visitors use our websites and services so we can improve them.

  • Functional cookies: remember preferences and choices, such as language, region, or interface settings.

  • Marketing cookies: used to deliver, measure, or personalise marketing, where permitted by law.

Where required, we provide cookie notices, consent banners, or preference controls that allow you to accept, reject, or manage non-essential cookies. You can also control cookies through your browser settings. Disabling some cookies may affect site functionality.

Legal Basis for Processing

Where applicable law requires a legal basis for processing, we rely on the basis that best matches the purpose of processing. The table below summarises common purposes and bases.

 
 
 

Purpose

 

GDPR / UK GDPR Basis

 

CCPA / CPRA

 

Australia APPs

 

Provide the services

Contractual necessity

Business purpose

Consent / primary purpose

Improve the services

Legitimate interests

Business purpose

Related secondary purpose

Marketing

Consent or legitimate interests, depending on context

Opt-out rights may apply

Consent where required

Security and fraud prevention

Legitimate interests / legal obligation

Business purpose

Legal obligation / related secondary purpose

Legal compliance

Legal obligation

Required or permitted by law

Required or authorised by law

Consent-based activities

Consent

Consent or opt-in where required

Consent

File ingestion and metadata processing

Contractual necessity; legitimate interests for security, governance, service improvement, and support

Business purpose

Primary purpose / related secondary purpose; consent where required

 
 
 

Your Privacy Rights

Depending on where you live, you may have rights regarding your personal information. These may include the right to access, correct, delete, object to, restrict, or port your information, withdraw consent, opt out of certain communications, and appeal or complain about our handling of your request.

  • Access and update: you may be able to access and update account information through your account settings or by contacting us.

  • Delete information: you may request deletion of personal information, subject to legal, security, contractual, and operational limitations.

  • Opt out of communications: you can unsubscribe from marketing emails using the unsubscribe link or by contacting us. We may still send transactional or service-related messages.

  • Cookie and advertising choices: where applicable, use our cookie preference controls or browser settings to manage non-essential cookies and similar technologies.

  • Data portability: where required, we will provide portable information in a structured, commonly used, machine-readable format.

  • Authorised agents: you may authorise another person to submit a request on your behalf where permitted by law. We may require verification of authority and identity.

To exercise your rights, contact us at privacy@gathid.com. We will verify and respond to requests within the timeframe required by applicable law.

How We Disclose Information

We do not sell personal information or share personal information for cross-context behavioural advertising. We disclose personal information only as described in this policy, as needed to provide our services, or with your consent.

  • Service providers and subprocessors: vendors that help us provide hosting, analytics, communications, support, security, payment, and operational services under contractual confidentiality and data protection obligations.

  • Business partners: partners involved in events, integrations, or joint activities, where permitted by law or with your consent.

  • Third-party services and integrations: services you or your administrator choose to connect to Gathid services.

  • Legal compliance and protection: regulators, courts, law enforcement, or other parties where required by law or reasonably necessary to protect rights, safety, security, or the integrity of our services.

  • Business transfers: parties involved in an actual or proposed merger, acquisition, financing, reorganisation, sale of assets, or similar transaction.

  • Other service users and administrators: information visible to users, account owners, or administrators based on product functionality, organisational controls, and customer settings.

Sub Processors

We use third-party service providers and sub processors to help deliver our services. We maintain an up-to-date list of relevant providers in our Trust Centre: Trust

Data Security and Retention

We implement administrative, technical, and organisational safeguards designed to protect personal information, including encryption, access control, monitoring, logging, vulnerability management, and security review processes.

In the event of a personal data breach that meets notification thresholds under applicable law, Gathid will notify affected individuals, customers, and relevant supervisory authorities within the required timeframes.

We retain personal information only for as long as reasonably necessary for the purposes described in this policy, unless a longer retention period is required or permitted by law. Typical retention considerations include:

  • Account information: retained while the account is active and for a reasonable period afterward for reactivation, audit, legal, or legitimate business purposes.

  • Customer content in products: retained according to customer agreements, product settings, and applicable data processing terms.

  • Marketing information: retained for a reasonable period after your last interaction or expressed interest, unless you opt out earlier.

  • Support information: retained as needed to resolve issues, improve services, maintain records, and meet legal requirements.

  • Security logs and audit records: retained for security, fraud prevention, compliance, and incident investigation purposes.

When retention is no longer necessary, we delete, de-identify, or anonymise personal information. If information remains in backups, it is isolated from active use until deletion is technically feasible through normal backup lifecycle processes.

International Data Transfers

Gathid may process personal information in Australia and other countries where we, our affiliates, service providers, or subprocessors operate. These countries may have data protection laws that differ from those in your location.

Where required, we use appropriate safeguards for international transfers, such as Standard Contractual Clauses, UK transfer mechanisms, adequacy decisions, approved certification frameworks, the Data Privacy Framework where applicable, contractual commitments, and supplementary safeguards.

Regional Disclosures

European Economic Area (EEA) and United Kingdom

EEA (EU GDPR)

Gathid processes personal information of individuals in the EEA in accordance with the General Data Protection Regulation (EU) 2016/679 (GDPR).

Legal basis. We process personal information only where we have a valid legal basis, as set out in the Legal Basis for Processing table above. Where we rely on legitimate interests, we conduct balancing assessments to ensure our interests do not override your fundamental rights and freedoms.

International transfers. Where personal information is transferred outside the EEA, Gathid relies on appropriate safeguards including:

  • European Commission adequacy decisions (including the EU-US Data Privacy Framework where applicable);

  • Standard Contractual Clauses (SCCs) adopted by the European Commission; or

  • other approved transfer mechanisms under Chapter V of the GDPR.

Details of our transfer mechanisms and subprocessors are available in our Trust Centre.

AI and automated processing. Where Gathid deploys AI systems or automated processing in the delivery of its services, we comply with applicable transparency obligations under the GDPR and the EU Artificial Intelligence Act (Regulation (EU) 2024/1689). Where an AI system interacts directly with individuals or generates outputs that affect them, we provide clear disclosure of the AI system’s involvement, its purpose, and its limitations. Individuals have the right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects, and may request human review of such decisions.

Your rights. Individuals in the EEA may exercise the following rights under the GDPR:

  • access their personal information;

  • rectify inaccurate or incomplete data;

  • request erasure (“right to be forgotten”);

  • restrict processing;

  • data portability;

  • object to processing based on legitimate interests or direct marketing;

  • withdraw consent at any time (without affecting the lawfulness of prior processing); and

  • lodge a complaint with a supervisory authority.

To exercise your rights, contact us at privacy@gathid.com.


United Kingdom (UK GDPR and Data Protection Act 2018)

Gathid processes personal information of individuals in the United Kingdom in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, as amended by the Data Protection and Digital Information Act 2024 (DPDI Act).

Recognised legitimate interests. The DPDI Act introduces a limited set of recognised legitimate interests for which no balancing test is required, including processing necessary for national security, crime prevention, and safeguarding. Where Gathid relies on legitimate interests outside these recognised categories, we continue to conduct balancing assessments.

International transfers. Where personal information is transferred outside the United Kingdom, Gathid relies on:

  • UK adequacy regulations;

  • the International Data Transfer Agreement (IDTA) or UK Addendum to the EU SCCs; or

  • other approved transfer mechanisms under UK data protection law.

Automated decision-making. The DPDI Act modifies the framework for automated decision-making. Where Gathid makes decisions based solely on automated processing that produce significant effects on individuals, we provide meaningful information about the logic involved and offer a pathway to request human intervention or challenge the decision.

AI transparency. Where AI systems are used in the delivery of Gathid services to UK-based individuals, we provide clear information about the AI system’s role, consistent with the UK government’s pro-innovation approach to AI regulation and applicable sector-specific guidance.

Your rights. Individuals in the UK have equivalent rights to those listed above for the EEA, including the right to lodge a complaint with the Information Commissioner’s Office (ICO) at ico.org.uk.


United States

Gathid respects the privacy rights of individuals across the United States. In addition to the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), Gathid acknowledges and complies with applicable state privacy laws including, but not limited to:

  • California — CCPA/CPRA (Cal. Civ. Code § 1798.100 et seq.)

  • Virginia — Consumer Data Protection Act (VCDPA)

  • Colorado — Colorado Privacy Act (CPA)

  • Connecticut — Connecticut Data Privacy Act (CTDPA)

  • Texas — Texas Data Privacy and Security Act (TDPSA)

  • Oregon — Oregon Consumer Privacy Act (OCPA)

  • Montana — Montana Consumer Data Privacy Act (MCDPA)

  • Delaware — Delaware Personal Data Privacy Act (DPDPA)

  • Iowa — Iowa Consumer Data Protection Act (ICDPA)

  • Nebraska — Nebraska Data Privacy Act (NDPA)

  • New Hampshire — New Hampshire Privacy Act (NHPA)

  • New Jersey — New Jersey Data Privacy Act (NJDPA)

  • Maryland — Maryland Online Data Privacy Act (MODPA)

  • Minnesota — Minnesota Consumer Data Privacy Act (MCDPA)

Where a state law provides rights or protections beyond those described in this section, Gathid will honour those additional requirements for residents of that state.

Categories of personal information

Gathid may collect the following categories of personal information (using CCPA terminology):

  • Identifiers (name, email address, account ID, IP address)

  • Professional or employment-related information

  • Internet or electronic network activity information

  • Geolocation data (coarse, derived from IP address)

  • Inferences drawn from the above categories

How we use personal information

We use personal information for the business purposes described in the “How We Use Your Information” section of this policy. We do not sell personal information. We do not share personal information for cross-context behavioural advertising.

Sensitive personal information

Gathid does not knowingly collect or process sensitive personal information as defined under the CCPA/CPRA or other state privacy laws (e.g., Social Security numbers, financial account credentials, precise geolocation, racial or ethnic origin, health data, biometric data).

Automated decision-making and profiling

Where Gathid uses automated systems or profiling that produce legal or similarly significant effects on individuals, we provide transparency about the logic involved and, where required by applicable state law, offer the right to opt out of such profiling or request human review.

Your rights

Depending on your state of residence, you may have the right to:

  • know what personal information we collect, use, disclose, or sell;

  • access your personal information;

  • correct inaccurate personal information;

  • delete your personal information;

  • opt out of the sale or sharing of personal information;

  • opt out of targeted advertising;

  • opt out of profiling in furtherance of decisions that produce legal or similarly significant effects;

  • data portability (receive your data in a portable format);

  • appeal a denial of a privacy request; and

  • exercise these rights without discrimination.

To exercise your rights, contact us at privacy@gathid.com. We will verify your identity before processing your request. Where permitted by law, you may designate an authorised agent to make a request on your behalf.

Response timing

We will respond to verifiable consumer requests within the timeframes required by applicable state law (generally 45 days, with extensions where permitted).


Australia

Gathid handles personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

Statutory tort for serious invasion of privacy. Australian law now recognises a statutory cause of action for serious invasion of privacy. Gathid is committed to handling personal information in a manner that respects individuals’ reasonable expectations of privacy and does not intrude upon seclusion or misuse personal information in ways that could cause serious harm.

Children’s Online Privacy Code. Where Gathid services are accessible to children or young people under 18, Gathid will comply with the Children’s Online Privacy Code, including requirements relating to age-appropriate privacy information, default privacy-protective settings, and restrictions on the collection, use, and disclosure of children’s personal information. Gathid’s services are not directed to children under 16, and we do not knowingly collect personal information from children without appropriate parental or guardian consent.

Enhanced enforcement and transparency obligations. The Privacy Act reforms introduce strengthened enforcement powers for the Office of the Australian Information Commissioner (OAIC), including increased civil penalty provisions. Gathid maintains transparency about its data practices and cooperates with the OAIC in relation to any inquiry, investigation, or determination.

Automated decision-making. Where Gathid uses automated systems that substantially contribute to decisions affecting individuals’ rights or interests, we will provide meaningful information about the nature and effect of such processing and, where required, offer a pathway to request human review.

Overseas disclosure. Before disclosing personal information to an overseas recipient, Gathid takes reasonable steps to ensure the recipient handles the information consistently with the APPs, or that an exception under APP 8 applies. A list of countries where personal information may be processed is available in our Trust Centre or upon request.

Your rights. Australian individuals may:

  • request access to, or correction of, their personal information;

  • make a privacy complaint if they believe Gathid has breached the APPs or the Privacy Act;

  • request information about how automated decisions affecting them were made; and

  • contact us at privacy@gathid.com with any privacy question or concern.

If a complaint is not resolved to your satisfaction, you may contact the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au.

Children’s Privacy

Our services are not directed to individuals under 16 years old. We do not knowingly collect personal information from children without appropriate consent. If you believe a child has provided personal information to us, please contact us so we can take appropriate action.

How to Contact Us

You may contact our Data Protection Officer (DPO) or privacy team using the details below.

 
 
 

Purpose

 

Contact

 

General privacy inquiries

privacy@gathid.com

Data Protection Officer

Gathid Privacy Team — privacy@gathid.com

Data subject requests

privacy@gathid.com

Mailing address

PO BOX 4839, Robina Town Centre QLD 4230 Australia

 
 
 

Updates to This Policy

We may change this Privacy Policy from time to time. We will post changes on this page and, if changes are significant, provide a more prominent notice, such as an email notification or notice on our website. We encourage you to review this policy periodically.