Legal /
Privacy Policy
Last updated 29 July 2026
In short /
We process contract documents, account details and — where you use web conferencing — call recordings and transcripts, in order to provide the service. We do not sell personal data, we do not use your contract content to train models for anyone else, and we host in the EU by default. You can access, correct, export or delete your data.
1. Who we are
ChangeSteward Pty Ltd(“ChangeSteward”, “we”, “us”) provides a platform for managing variations to already-signed contracts. Our registered address is Level 14, 120 Collins Street, Melbourne VIC 3000, Australia.
For personal data that our customers upload into the platform, our customer is the data controller and we act as a data processor on their instructions. For data we collect directly — account registration, billing, website analytics, support correspondence — we are the controller. This policy covers both, and says which is which throughout.
2. What we collect
2.1 Information you give us
- Account details. Name, work email address, organisation, job title, and authentication identifiers from your identity provider where SSO is used.
- Billing details. Billing contact, address and tax identifiers. Card details are handled by our payment processor and are never stored on our systems.
- Contract content.The agreements you import, the variations you author, clause text, comments, approval decisions and signatures. This frequently contains personal data about your staff and your counter-party’s staff.
- Correspondence. Support requests and anything you choose to include in them.
2.2 Information generated by using the service
- Call recordings and transcripts. Where you use ChangeSteward Web Conference, we record audio and video, produce a transcript, and derive the proposed changes discussed. Every participant is shown a recording indicator before the session begins.
- Calendar availability. Where you connect a calendar for smart scheduling, we read free/busy information only. We do not read event titles, attendees or descriptions.
- Audit records.Who did what and when — proposals, approvals, counter-signatures, access changes. These are part of the product’s evidential value and cannot be selectively edited.
- Technical logs. IP address, browser and device type, timestamps and error diagnostics.
2.3 What we do not collect
We do not use third-party advertising or cross-site tracking technologies. We do not build advertising profiles. We do not buy personal data from data brokers. The marketing site you are reading sets no analytics or advertising cookies.
3. Why we process it, and on what legal basis
- To provide the service — importing and verifying agreements, computing working contracts, running risk analysis, hosting conferences, sealing variations. Basis: performance of a contract, or our customer’s instructions where we act as processor.
- To keep the service secure — authentication, abuse and fraud prevention, audit logging. Basis: legitimate interests.
- To meet legal obligations — tax, accounting, and responding to lawful requests. Basis: legal obligation.
- To communicate with you — service notices, and product updates you can unsubscribe from at any time. Basis: legitimate interests or consent.
4. Artificial intelligence
ChangeSteward uses machine learning to transcribe conversations, detect proposed changes, draft deeds of variation, suggest clause redlines, and score clause risk.
We do not use your contract content, recordings or transcripts to train models that are made available to other customers or to third parties. Inference runs on infrastructure we control within your data region. Where a model improvement would benefit from customer data, we will ask for opt-in consent first, and the service works identically if you decline.
AI output is a suggestion, never an action. A person accepts or discards every redline, and no variation takes effect without human approval and counter-signature.
5. Where your data is stored
By default, application data, documents, recordings and transcripts are stored in the European Union (Google Cloud europe-west1), with our database region-pinned to the same location. Enterprise customers may select a different region.
Where any processing or routing occurs outside your selected region, we rely on Standard Contractual Clauses and apply supplementary technical measures including encryption in transit and at rest. We will tell you in our Data Processing Agreement exactly which sub-processors are involved and where they operate.
6. Who we share it with
We share personal data only with:
- Your counter-party and colleagues — to the extent you grant them access to an agreement. Access is per-agreement and per-person, and revocable by the initiator.
- Sub-processors — cloud hosting, database, e-signature, payment and email delivery providers, each under a written processing agreement. A current list is available on request and forms part of our DPA.
- Authorities — where legally compelled. Where we are permitted to tell you, we will.
We do not sell personal data, and we do not share it for cross-context behavioural advertising.
7. How long we keep it
Contract records are evidence of what was agreed, so we retain them for as long as your account is active and for a defined period afterwards.
- Agreements, variations and audit records — for the life of the account, then seven years, unless you instruct earlier deletion.
- Call recordings — 12 months by default. Enterprise customers set their own period. Recordings can be deleted on request; the audit record that a call occurred, and the variation it produced, necessarily remain.
- Technical logs — 90 days.
- Billing records — seven years, as tax law requires.
8. Your rights
Depending on where you live, you may have the right to access, correct, delete, restrict or object to our processing of your personal data, to receive it in a portable format, and to withdraw consent. Under the GDPR you may also lodge a complaint with your supervisory authority; under Australian Privacy Principles, with the OAIC.
If your data sits inside a customer’s agreement, that customer is the controller and we will refer your request to them and assist them in answering it.
To exercise a right, write to privacy@changesteward.com. We respond within 30 days. We do not charge for this and we will not treat you differently for asking.
One honest limitation: deleting an approved variation would break the audit chain that makes the contract evidentially useful, and other parties have legal rights in that record. Where an erasure request conflicts with a legal-hold or another party’s rights, we will explain precisely what we can and cannot remove rather than quietly doing neither.
9. Security
- Encryption in transit (TLS 1.2+) and at rest (AES-256).
- Single sign-on, SCIM provisioning and per-agreement access control.
- Least-privilege internal access, logged and reviewed.
- Append-only audit records for every contractual action.
- Independent penetration testing and a SOC 2 Type II programme.
If a breach affects your personal data we will notify affected customers without undue delay, and supervisory authorities within 72 hours where required.
10. Cookies
This marketing site uses no cookies beyond those strictly necessary to serve the page. The application uses a single session cookie to keep you signed in and a preference cookie to remember your light or dark theme. Neither is used for tracking or advertising.
11. Children
ChangeSteward is a business tool and is not directed at anyone under 16. We do not knowingly collect their personal data. If you believe we have, contact us and we will delete it.
12. Changes to this policy
We will post any change here and update the date above. For material changes we will notify account administrators by email at least 30 days before they take effect, so you have time to object or to leave.
13. Contact
Privacy enquiries: privacy@changesteward.com. General enquiries: hello@changesteward.com. By post: ChangeSteward Pty Ltd, Level 14, 120 Collins Street, Melbourne VIC 3000, Australia.