Privacy Policy
Last updated: June 2025
This document is pending final legal review and does not yet constitute the company's binding legal terms. It will be updated before public launch.
This policy describes how Becide handles personal information in line with the Privacy Act 1988 (Cth) and the Australian Privacy Principles.
Who we are
Becide is a CFO intelligence platform operated by Klair Technology. We provide software and related services to Australian organisations.
For privacy enquiries, access requests, corrections, or complaints, contact us at hello@foresight.app. We will respond within a reasonable time.
Scope of this policy
This policy applies to personal information we collect about users of the Becide website, platform, and related services. It does not apply to personal information contained in client data that you upload or connect through the platform; that data is governed by your agreement with us and our Data Processing Agreement.
We are subject to the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
Kinds of personal information we collect
The personal information we collect depends on how you interact with Becide. We collect only what is reasonably necessary for the purposes described in this policy.
- Identity and contact details: name, work email, organisation, role, and phone number where provided
- Account and authentication data: user identifiers, session tokens, and sign-in metadata from our authentication service
- Usage and technical data: IP address, browser type, device information, pages visited, and feature usage logs
- Communications: messages you send us, support requests, and access-request form submissions
- AI interaction metadata: encrypted question records, run identifiers, and tool invocation logs (not full message bodies in analytics)
- Connector configuration metadata: data source names and connection status (not database passwords or API keys)
How we collect personal information
We collect personal information directly from you when you request access, sign in, use the platform, configure connectors, contact support, or subscribe to communications.
We also collect information automatically through cookies, server logs, and platform telemetry required to operate and secure the service.
We do not purchase marketing lists or collect personal information from third-party data brokers for the core platform.
Why we collect, use, and disclose personal information
We use personal information for the primary purpose of providing and improving Becide, and for related purposes you would reasonably expect.
- Creating and managing accounts and authenticating users
- Delivering CFO intelligence features, including AI-assisted Q&A and reporting
- Operating connectors you authorise and maintaining data pipelines
- Monitoring security, detecting abuse, and maintaining audit trails
- Responding to enquiries, support requests, and access or correction requests
- Meeting legal, regulatory, and contractual obligations
- Improving reliability and product quality using aggregated, de-identified usage patterns
Marketing and direct communications
We may contact you about your account, service updates, or security notices. We do not use client financial data for marketing.
Where we send promotional communications, you may opt out at any time. Service-critical notices may still be sent.
Disclosure to third parties
We disclose personal information only where necessary to operate the platform, with your consent, or where required or authorised by law.
- our Australian hosting provider for hosting, storage, encryption, and compute
- our authentication service
- our approved AI services for inference, configured within approved regions
- Professional advisers (legal, accounting) bound by confidentiality obligations
- Regulators, courts, or law enforcement when required by law
Overseas disclosure
Our primary data stores and processing occur in Australia. Some subprocessors may process limited metadata or provide support from other countries under contractual safeguards designed to meet APP 8 requirements.
Before disclosing personal information overseas, we take reasonable steps to ensure recipients handle information consistently with the APPs. A subprocessor register is available on request.
Likely overseas locations may include the United States where our hosting or support providers operates global infrastructure. Encryption and access controls apply regardless of processing location.
Storage, encryption, and security
Personal information and client data are encrypted at rest using AES-256 with dedicated encryption keys. Each client receives a dedicated encryption key. Becide does not store encryption key material.
Data in transit is protected with TLS. Login passwords are hashed by our authentication service and cannot be read by Becide. Connector credentials are stored in secure credential storage and are never shown in the UI, logged, or sent to AI models.
We implement least-privilege access, tenant isolation, and audit logging. See our Security page for further detail.
Client data layers
Your organisation's data is organised in three layers in Sydney: original uploads (raw), a cleaned analytics layer, and a curated command-centre layer. The AI can read only approved layers for your tenant. Raw uploads are not exposed to AI tools.
Retention
We retain personal information for as long as needed to provide the service and meet legal obligations. Account data is retained while your organisation has an active relationship with us.
When you leave, you may request export and deletion. We confirm deletion in writing and destroy your encryption key so data becomes unreadable, including in backups. Inactive enterprise accounts are handled per your agreement.
AI, automated processing, and accuracy
Becide uses automated tools, including large language models, to assist with financial analysis and document retrieval. Outputs may be incomplete or inaccurate and are not financial, legal, or tax advice.
We do not use client data to train third-party AI models. AI interaction records are retained only as necessary for audit, support, and product reliability.
Where automated processing could significantly affect an individual's rights or interests, human review is available on request. See the Automated decision-making section below.
Automated decision-making
Becide uses computer programs to assist with financial research, data classification, and connector validation. These programs do not make binding decisions about individuals without human oversight in normal operation.
Kinds of personal information used may include account identifiers, usage metadata, and content submitted to AI features. Decisions assisted by automation include research summaries and data-quality checks. You may request human review of significant outputs.
Access, correction, and complaints
You may request access to or correction of personal information we hold about you by contacting hello@foresight.app. We will verify your identity before responding and aim to respond within 30 days.
If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
Changes to this policy
We may update this policy when our practices change. Material updates will be published on this page. Continued use after notice constitutes acceptance where permitted by law.