Privacy Policy
We build underwriting infrastructure. Personal information on the platform belongs to our clients and the parties they deal with — this policy explains the small amount we handle ourselves, and how the rest is protected.
Last updated 25 July 2026 · Version 1.0
01 · Who we are
This policy is issued by Cuttleflow Pty Ltd, trading as Cuttleflow Systems, ABN 86 699 564 871 (“Cuttleflow”, “we”, “us”), an Australian company based in Sydney. We provide underwriting, rating and policy-administration software, and we are developing a proposed marketplace on which insurers, underwriting agencies and brokers would transact if it launches.
We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. This policy explains what we collect, why, and the choices you have.
02 · Two kinds of information
Cuttleflow collects very little personal information itself, while our clients may process substantial personal information on our platform. This policy deals with both, separately.
- Information we collect and hold ourselves — details about the people we deal with directly: visitors to this website, prospective clients, and the staff of client organisations who hold platform accounts. Sections 3 to 7 cover this.
- Information our clients process on the platform (“Client Data”) — underwriting, policy and claims information, including any future marketplace submissions, entered or uploaded by our clients. We hold this on our clients’ behalf. Section 8 covers this.
03 · Personal information we collect ourselves
We collect only what we need to run our business and operate the platform.
| Category | What it includes | How we get it |
|---|---|---|
| Business contacts | Name, role, organisation, work email and phone of prospective and current clients and partners | Directly from you — enquiries through this site, meetings, demonstrations, contracts |
| Platform accounts | Name, work email, role and login credentials of client staff who use the platform | From you or your employer when accounts are set up |
| Support and correspondence | Emails, support requests and their contents | Directly from you |
| Technical and security data | Platform access logs, security event logs, and the IP address and user agent recorded when an enquiry form is submitted | Automatically, when you use the platform or submit a form |
| Recruitment | Applications, CVs and referee details | Directly from applicants |
We do not collect sensitive information — such as health information — about the people in those categories, and we do not buy, sell or trade personal information.
04 · Why we collect it
We collect, hold and use this information to provide and operate the platform (and the proposed Marketplace, if it launches); set up and administer client accounts; respond to enquiries and provide support; invoice and administer client agreements; secure the platform, detect misuse and meet audit obligations; improve our website and products; send service notices and, where you would reasonably expect it, relevant updates about our products, which you can opt out of at any time; and assess job applications.
Field Notes. If you subscribe to Field Notes, we use your email address to send occasional writing about governed insurance infrastructure and nothing else. Subscription is opt-in, every email carries an unsubscribe link, and unsubscribing takes effect immediately.
We do not use personal information for any purpose a reasonable person would not expect from the relationship we have with them.
05 · Who we disclose it to
We disclose personal information only where it is needed to run the business.
- Service providers — Microsoft Azure hosts this website, our enquiry records and the platform. We use Microsoft 365 for email and business records. We also use a third-party AI provider to read submitted documents and draft correspondence on the platform. Each operates under contractual confidentiality and security obligations, and none is permitted to use the information for its own purposes or to train its own models.
- Professional advisers — lawyers, accountants and insurers, where required.
- Regulators and law enforcement — where the law requires or permits it.
We do not sell personal information, and we do not disclose it to third parties for their own marketing.
06 · Overseas disclosure
This website, the enquiry records it generates and the platform are hosted in Australia, in the Microsoft Azure Australia East and Australia Southeast regions.
Some providers we use to run our own business may process limited personal information — typically business contact details — outside Australia. Microsoft 365 may replicate business records outside Australia depending on the service. Where a document is processed by our third-party AI provider, that processing may occur outside Australia; the provider is contractually prevented from using the content for its own purposes or for training. Where information is handled overseas we take reasonable steps to ensure it is handled consistently with the Australian Privacy Principles.
07 · Cookies and analytics
This website sets no cookies at all. There is no third-party analytics on it, and no advertising or retargeting pixels. This is why you are not asked to accept cookies when you arrive.
Our web host records standard server logs, including IP addresses, which we use only to keep the site available and secure.
The platform itself uses a session cookie that is strictly necessary to keep you signed in.
08 · Client Data on the platform, including future marketplace submissions
Client Data is encrypted in transit and at rest, and every record is bound to the client that owns it, so the platform will only ever return a client’s data to that client. Access is limited to the client that holds the data and, on the marketplace, the parties to a transaction.
Our clients — insurers, underwriting agencies and brokers — use the platform to quote, bind and administer insurance, and — if the proposed Marketplace launches — would exchange submissions on it. In doing so they may enter or upload personal information about their own customers: for example the name, contact details and risk information of an insured contained in a broker’s submission.
For that information:
- Our clients are responsible for it. The client that collects the information is the entity responsible under the Privacy Act for having the right to collect it, for notifying the individuals concerned, and for dealing with access, correction and complaint requests. Their privacy policies, not this one, govern that information.
- We hold it on their behalf and do not use it for our own purposes. Client Data is encrypted in transit and at rest, and tenancy is enforced on every record so one client’s data cannot be returned to another. Access by Cuttleflow personnel is restricted to named administrators, permitted only where it is necessary to operate or support the service, logged in the platform’s audit ledger, and never used to compete with a participant.
- Marketplace submissions would move only between the parties. If the proposed venue launches: when a broker submits a risk, the personal information in that submission would be visible to the broker and to the markets the submission is routed to.
- We act on our clients’ instructions. If a client requires assistance involving Client Data, we act on their documented instructions.
If you are an insured, a claimant or another individual whose information has been entered on the platform, please direct any privacy request to your broker, agency or insurer, who holds it. If you contact us instead, we will refer your request to the relevant client.
09 · Automated decisions
We do not use the personal information we collect ourselves, described in section 3, in computer programs that make decisions significantly affecting an individual’s rights or interests.
The platform provides rating and decisioning tools that our clients configure and operate. Any automated decision made with those tools is made by the relevant client, using their own data and criteria, and is addressed in that client’s privacy policy. Language models are used on the platform only to read submissions and draft documents, always subject to human confirmation, and never to make a decision on the bind path.
10 · Security and data breaches
We protect personal information with encryption in transit and at rest, role-based access controls, tenancy enforced on every record, an immutable audit ledger, logging and monitoring, and vendor due diligence. No system is impenetrable, so we also maintain a data breach response plan.
If a data breach occurs that is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner in accordance with the Notifiable Data Breaches scheme. Where a breach involves Client Data we will notify the affected clients without undue delay so they can meet their own obligations.
11 · Retention
We keep personal information only as long as we need it for the purposes above or as the law requires, and then take reasonable steps to destroy or de-identify it. Client Data is retained and deleted in accordance with the relevant client agreement, and any participant may export all of their own data, in open formats, at any time and at no charge.
12 · Access, correction and complaints
You may ask us for access to the personal information we hold about you, or ask us to correct it, using the contact details below. We will respond within a reasonable period and will not charge you for making the request.
If you believe we have mishandled your personal information, please contact us first and we will investigate and respond, ordinarily within 30 days. If you are not satisfied with our response you may complain to the Office of the Australian Information Commissioner at oaic.gov.au or on 1300 363 992.
13 · Changes to this policy
We review this policy regularly and will update it when our practices or the law change, including the amendments to the Privacy Act commencing during 2026. The current version is always available on this page, with the date above.
14 · Contact
Privacy Officer
Cuttleflow Pty Ltd trading as Cuttleflow Systems
ABN 86 699 564 871
Sydney NSW, Australia
Email: max@cuttleflow.com
For anything else, get in touch.