Privacy Policy
Last updated: 16 May 2026
1. Who we are
This Privacy Policy applies to DDES ("DDES", "we", "us", "our"), a Queensland-based business operating the website ddes.biz and the client platform at advisory.ddes.biz. We provide WHS, civil construction, and tender advisory services. We are committed to handling personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
2. What information we collect
We collect personal and business information through:
- Public enquiry form — your name, business name, email, phone, project details, and how you found us
- Referral submissions — your name, contact details, and the relationship to the referring party
- Documents you provide — scope documents, existing WHS material, tender documentation, and other content you share with us in the course of an engagement
- Client portal interactions — files you upload, messages you send, and proposal acceptance records
- Payment information — handled by Stripe; we do not store full card details on our systems
- Site analytics — anonymous traffic data, UTM parameters, and the page that referred you
3. How we use your information
- To respond to your enquiry and quote our services
- To deliver advisory services you have engaged us for
- To process payments and issue invoices
- To send service updates, proposal follow-ups, and engagement communications
- To improve our service, including processing documents you provide through AI tools to draft, review and audit compliance documentation
- To meet our legal, tax and regulatory obligations
We do not sell your personal information. We do not use your information for advertising other than directly responding to your enquiry.
4. AI processing of your documents
Where you upload or share documents with us (for example, existing SWMSes, SOPs, tender material, or scope documents), DDES uses AI tools — currently Anthropic's Claude — to assist us in reviewing, drafting and producing advisory output. Your documents are transmitted to Anthropic's API for processing under Anthropic's commercial terms, which prohibit the use of your content for training. We do not authorise any AI subprocessor to retain your data beyond what is required to deliver the response. If you have specific concerns or a contractual prohibition on AI processing, tell us before sharing the document and we will arrange a manual workflow.
4a. How we evidence your consent
When you accept a proposal online, we ask you to tick a privacy-consent box and store the exact wording you were shown, the version of that wording, and the date, time and IP address of acceptance against your proposal. This gives you an audit trail of exactly what you agreed to, and gives us evidence to satisfy the Australian Privacy Principles. The current consent wording is shown to you at the time of acceptance — if it changes, you'll see the new version before you can accept.
5. Subprocessors
Your information passes through the following service providers in the course of delivering our service:
- Railway (United States) — application hosting and database
- Anthropic (United States) — AI processing of documents and queries
- Resend (United States) — transactional email delivery
- Stripe (United States / Australia) — payment processing
- Google Cloud (United States) — OAuth login (only where you choose to log in via Google)
Each subprocessor is bound by their own privacy and security obligations. By engaging us, you consent to your information being processed by these providers.
6. Storage and security
We hold information on infrastructure provided by Railway, with daily backups. Access to your information within DDES is limited to DDES principals and any specific staff or contractors engaged on your matter, on a need-to-know basis. We use industry-standard encryption for data in transit (TLS) and rely on our infrastructure provider's encryption for data at rest. Despite these measures, no online service is fully secure; we will notify you in accordance with the Notifiable Data Breaches scheme if we become aware of a breach likely to cause you serious harm.
7. How long we retain information
- Enquiry data we don't progress — retained for up to 24 months, then deleted
- Active client engagement records — retained for the duration of the engagement plus 7 years (to meet professional indemnity, tax and audit obligations)
- Financial records — retained for 7 years as required by Australian tax law
- WHS documents we produce for you — your copies are yours; our working copies are retained for the engagement plus 7 years
8. Your rights
You may at any time:
- Ask us to confirm what personal information we hold about you
- Ask us to correct inaccurate information
- Ask us to delete your information (subject to our legal retention obligations)
- Ask us to stop sending non-essential communications
- Lodge a complaint with us, and if not resolved, with the Office of the Australian Information Commissioner (oaic.gov.au)
9. Cookies
Our site uses essential cookies for login session state. We do not currently use third-party tracking or advertising cookies.
10. Changes to this policy
We may update this policy from time to time. The "Last updated" date at the top reflects the current version. Material changes will be notified to active clients by email.
11. Contact us
For privacy enquiries, requests for access or correction, or to lodge a complaint:
Email: scott@ddes.biz
Postal: available on request.