Legal

Privacy Policy

Last updated 25 September 2026

This policy explains what personal information Sidecar collects, why, where it is kept and what you can do about it. It covers this website and the Sidecar Agents platform, including Corporate Brain and Agent Archie.

Who we are

“Sidecar”, “we” and “us” mean Sidecar Unlimited Pty Ltd (ABN 40 653 158 484). We handle personal information in line with the Privacy Act 1988 (Cth) and the Australian Privacy Principles.

Information we collect

When you use this website

  • Enquiries. If you send us a message, we collect what you enter: your name, email address, phone number, company, role, your message and how you heard about us.
  • Spam protection. The enquiry form uses Cloudflare Turnstile to tell people from bots. Turnstile processes technical signals from your browser and your IP address for that purpose only.
  • Technical logs. Our hosting provider records standard request information such as IP address, browser type and the pages requested. We use it to keep the site secure and working.

We do not use advertising or analytics cookies on this website. The site loads typefaces from Google Fonts, which receives your IP address when your browser requests them.

When your organisation uses the Sidecar Agents platform

Our platform works on a business’s own documents and systems, and only once an administrator of that business connects them. Depending on which sources are connected, we process:

  • Account information for the people who sign in: name, email address and organisation.
  • Content and metadata from connected sources, such as file names, folder structure, sharing permissions, document text and CRM records. This may include personal information that happens to be in those files and records.
  • Access credentials issued by the connected provider (for example an OAuth refresh token). These are kept in an encrypted secrets store, never in our code or logs.
  • Usage records: questions asked of the platform, the actions agents take, and audit logs of what was read or changed.

Data from connected Google and Microsoft accounts

Connecting a source is always an administrator’s decision, made through the provider’s own consent screen. We ask for the narrowest permissions that let the agents do their job.

ProviderPermissionWhat we use it for
Google Drivedrive.readonlyReading file content so a document can be understood, classified and named from what it says.
Google Drivedrive.metadata.readonlyListing drives, folders and sharing, so the file estate can be mapped without opening every file.
Microsoft 365Files.Read.All (delegated)Reading file content in SharePoint and OneDrive that the consenting administrator can already open.
Microsoft 365Sites.Read.All (delegated)Listing sites, libraries and sharing so the estate can be mapped.
Microsoft 365Sites.Selected (application, optional)Filing documents, but only in SharePoint sites an administrator has separately and explicitly granted. It gives no access to any other site.
Microsoft 365offline_access, openidKeeping the connection working when nobody is signed in, and identifying which Microsoft directory the connection belongs to.

We use this data only to provide the features your organisation has turned on: building your organisation’s private knowledge base, answering questions from people your organisation has authorised, and organising and filing documents.

Google API Services. Sidecar’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

In particular, for data we receive from Google Workspace and Microsoft 365:

  • We do not sell it, and we do not use or transfer it for advertising, retargeting or personalised advertising.
  • We do not use it to develop, improve or train generalised or foundation artificial-intelligence or machine-learning models, and we do not let anyone else do so.
  • We do not use it to work out anyone’s creditworthiness or for lending purposes.
  • We transfer it to others only as needed to provide the service (see “Who we share it with”), to comply with the law, or as part of a merger or acquisition with notice to you.
  • Our people do not read it unless you have given us permission for a specific item (for example, to investigate a support request), it is needed for security purposes such as investigating abuse, or it is required by law.

How we use personal information

  • To respond to enquiries and provide the services your organisation has engaged us for.
  • To secure and operate the platform, including keeping audit logs and preventing misuse.
  • To communicate with you about your account or service.
  • To meet our legal obligations.

How AI is used

The platform uses large language models to read, summarise, classify and answer questions about your organisation’s content. Those models run on Amazon Bedrock within AWS’s Australian regions. The model provider does not receive your content for its own purposes, and your content is not used to train any model. Each organisation’s data is kept separate from every other organisation’s.

Where information is stored

Platform data, including content from connected sources, is stored in Amazon Web Services in Sydney, Australia (ap-southeast-2). Model processing may also take place in AWS’s Melbourne region. Website spam checks (Cloudflare) and typeface delivery (Google) may be processed outside Australia. Where information leaves Australia, we take reasonable steps to make sure it is handled consistently with the Australian Privacy Principles.

Who we share it with

We do not sell personal information. We share it only with service providers who help us run the website and platform, under contracts that restrict their use of it:

  • Amazon Web Services: hosting, storage, email delivery and model processing.
  • Cloudflare: spam protection on the enquiry form.
  • Google: typeface delivery for this website.

We may also disclose information where the law requires it.

Security

Data is encrypted in transit and at rest. Access credentials are held in an encrypted secrets store. Access to production systems is restricted and logged. If a data breach is likely to cause serious harm, we will notify affected people and the Office of the Australian Information Commissioner as the Notifiable Data Breaches scheme requires.

How long we keep it

  • Enquiries are kept for as long as needed to respond and manage our relationship with you.
  • When a source is disconnected, its stored credential is deleted straight away.
  • Content indexed from connected sources is deleted within 30 days of your organisation’s agreement ending, or sooner on written request. The only exception is where the law requires us to keep something longer.

Revoking access

An administrator can disconnect any source from the platform’s Connections screen at any time. Access can also be revoked directly with the provider:

Your rights

You can ask for access to the personal information we hold about you, and ask us to correct it. If your information reached us through your employer’s use of the platform, we may refer your request to them, because they control that data. We respond within 30 days.

Complaints

If you are concerned about how we have handled your personal information, contact us first and we will respond within 30 days. If you are not satisfied, you can complain to the Office of the Australian Information Commissioner.

Changes

We will post any changes here and update the date above. If a change materially affects how we use data from connected accounts, we will tell affected customers before it takes effect.

Contact

Sidecar Unlimited Pty Ltd (ABN 40 653 158 484), Level 11, 348 Edward Street, Brisbane QLD 4000, Australia · hello@sidecar.com.au