Privacy Policy - Duetiful
Last Updated: February 2026
Effective Date: February 2026
1. Introduction
Duetiful (operated by 주식회사, Korean Business Registration Number ) is committed to protecting your privacy.
This Privacy Policy explains how we collect, use, store, and protect your personal information when you use our deadline management platform at https://duetiful.com (the "Service").
1.1 Beta Service Notice
⚠️ Duetiful is currently in Beta. While we implement industry-standard security practices, the Service is still under active development. We're working toward future security certifications (SOC 2 Type II, ISO 27001) but are not currently certified. By using the Beta Service, you acknowledge this status.
1.2 Who This Applies To
This policy applies to:
- Australian users (our primary market)
- Users in other jurisdictions who choose to use our Service
1.3 Laws We Comply With
We comply with:
- Australian Privacy Act 1988 (including the 13 Australian Privacy Principles) - our primary governing law
- GDPR (General Data Protection Regulation - for European users)
- CCPA (California Consumer Privacy Act - for California users)
- Other applicable privacy laws where our users are located
2. Who We Are
Company: 주식회사
Business Registration:
Registered Address:
Australian Contact:
Data Storage Location: Australia (Supabase Sydney region)
Contact Information:
- General Privacy Inquiries: privacy@duetiful.com
- Data Protection Officer: dpo@duetiful.com
- General Support: support@duetiful.com
- Legal Matters: legal@duetiful.com
Australian Privacy Principle 1: We are an APP entity under Australian privacy law because we operate in Australia and target Australian customers.
3. Information We Collect
3.1 Information You Provide Directly
Account Information:
- Full name
- Email address
- Password (encrypted — we never see your actual password)
- Phone number (optional)
- Organization/company name
- Job title
- Time zone and language preferences
Reminder & Deadline Information:
- Reminder titles and descriptions
- Due dates and deadlines
- Matter/client references (if you provide them)
- Assignee and Backstop Adviser assignments
- Notes and comments (visible to assigned team members)
- Custom reminder intervals and preferences
- Tags and categories
Support Communications:
- Messages you send to support@duetiful.com
- Feedback, feature requests, and bug reports
- Chat transcripts (if we add live chat)
3.2 Information We Collect Automatically
Usage Data:
- Pages and features you access
- Reminders created, completed, or missed
- Time spent on platform
- Actions you take (creating, editing, deleting reminders)
- Search queries within the Service
- Login/logout times and frequency
Technical Data:
- IP address and approximate geolocation (city/region level)
- Browser type, version, and language
- Device type (desktop, mobile, tablet)
- Operating system and version
- Screen resolution
- Referral source (how you found Duetiful)
- User agent string
Performance Data:
- Page load times
- Error messages and crashes
- Feature usage patterns (aggregated)
3.3 Information from Third Parties
Calendar Integration (When You Connect):
- Calendar access tokens
- Event metadata (to sync reminders)
- Calendar names and IDs
We do NOT access your entire calendar — only the events we sync with your permission.
Payment Information (via Lemon Squeezy):
- We do NOT collect or store payment information
- Lemon Squeezy (our Merchant of Record) handles all payment processing
- You'll see "LEMSQZY*Duetiful" on your credit card statement
- See Section 5.2 for details
Email Staging (Inbound Email Processing):
- Sender email address and IP address
- Email subject line and body content (encrypted at rest)
- Message metadata (timestamps, headers)
- Attachment count (attachments are NOT stored)
Email content is encrypted immediately upon receipt and automatically purged 24 hours after conversion to a reminder. Unconverted emails are deleted after 30 days.
3.4 Email Staging Security & Processing
Duetiful offers an optional Email Staging feature that allows you to create reminders by sending emails to a designated inbox. Here's how we handle this data:
What We Collect:
- Sender email address (to match to your account)
- Sender IP address (for security monitoring)
- Email subject (encrypted, used for reminder title)
- Email body (encrypted, parsed for dates and details)
- Attachment count only (attachments are never stored)
How We Process Emails:
- Emails are received via secure webhook (HMAC-verified)
- Content is immediately encrypted using XSalsa20-Poly1305
- Malicious content scanning occurs before storage
- Emails containing threats may be quarantined for review
- Rate limiting prevents abuse (max 10 emails/hour per user)
Retention & Deletion:
- Unconverted emails: Automatically deleted after 30 days
- Converted emails: Content purged 24 hours after conversion (metadata retained)
- Quarantined emails: Deleted after 7 days if not reviewed
- Security logs: Retained for 90 days for audit purposes
Security Measures:
- HMAC signature verification on all incoming webhooks
- IP whitelist/blocklist for sender verification
- Unknown sender tracking (max 3 attempts before blocking)
- Malicious content detection (XSS, SQL injection, command injection)
- Duplicate detection via message ID hashing
Your Rights:
- View all staged emails in your account
- Delete staged emails before conversion
- Opt-out of Email Staging entirely (don't use the feature)
- Request deletion of all staging data via privacy@duetiful.com
⚠️ Attachment Policy:
We do NOT store email attachments. Only the attachment count is logged for reference. If you need to include documents with your reminders, please upload them directly through the Duetiful interface after creating the reminder.
3.5 Information We DON'T Collect
We do NOT collect or request:
- ❌ Health information or medical records
- ❌ Criminal records or background check data
- ❌ Financial account details (credit cards, bank accounts)
- ❌ Biometric data (fingerprints, facial recognition)
- ❌ Precise geolocation (GPS coordinates)
- ❌ Passwords or credentials for other services
- ❌ Sensitive personal information under the Privacy Act 1988
If you upload sensitive information to Duetiful, you do so at your own risk. Our Service is not designed to handle sensitive personal information as defined by Australian privacy law.
4. How We Use Your Information
4.1 Primary Purposes (Why You Gave Us Information)
We use your information to:
Provide the Service:
- Create and maintain your account
- Store and manage your reminders and deadlines
- Send reminder notifications via email and calendar
- Display deadline information to you and authorized team members
- Enable Backstop Adviser functionality
- Sync with your calendar (Outlook/Google)
- Process your subscription payments (via Lemon Squeezy)
- Provide customer support
- Monitor approaching deadlines through automated daily processing
- Send Backstop Adviser notifications at T-7 days and escalations at T-1 day before deadlines
- Display system health status transparently so you always know monitoring is operational
Communicate with You:
- Send deadline reminder notifications
- Respond to support requests and inquiries
- Send important Service updates and security alerts
- Notify you of changes to Terms of Service or Privacy Policy
- Send account-related emails (password resets, confirmations)
Ensure Security:
- Verify your identity when you log in
- Prevent fraud, abuse, and unauthorized access
- Detect and investigate suspicious activity
- Monitor for security threats
- Enforce our Terms of Service
- Comply with legal obligations
4.2 Secondary Purposes (Other Ways We Use Information)
With your consent or where legally permitted:
Improve the Service:
- Analyze usage patterns (aggregated and anonymized)
- Identify bugs, errors, and performance issues
- Test and develop new features
- Optimize user experience and interface
- Conduct internal research and analytics
Marketing Communications (Optional — You Can Opt Out):
- Send product updates and feature announcements
- Share tips and best practices for using Duetiful
- Conduct user satisfaction surveys
- Send occasional newsletters (no more than monthly)
Analytics:
- Understand how users interact with the Service
- Measure effectiveness of features
- Track conversion and retention metrics
- Google Analytics for usage analytics
Legal Compliance:
- Comply with Australian and international laws
- Respond to legal requests (subpoenas, court orders, warrants)
- Protect our rights under the Terms of Service
- Investigate suspected violations or illegal activity
- Cooperate with law enforcement when legally required
Australian Privacy Principle 6: We will only use or disclose your personal information for secondary purposes if you would reasonably expect us to, if you consent, or if permitted/required by law.
5. Who We Share Your Information With
5.1 Within Your Organization (Team Data Sharing)
IMPORTANT: Please read this section carefully to understand how data is shared within your team.
Team Members & Backstop Advisers:
- When you assign a Backstop Adviser to a reminder, that person can see the full reminder details, including:
- Reminder title and description
- Due date and deadlines
- Matter/client information (if included)
- All notes and comments
- Assignment history
- Backstop Advisers receive email notifications about assigned reminders
- This is necessary for the backstop feature to work
Support Requests:
- When you activate "Request Support" on a matter, your assigned Backstop Adviser is notified via email
- The matter transitions to an assistance-requested status visible to you and your Backstop Adviser
- This action is logged in our audit trail for quality assurance
- No other team members or administrators are notified beyond the assigned Backstop Adviser
Organization Administrators & Team Leaders:
- Can view all reminders and data within the organization account, including:
- All users' reminders and deadlines
- Individual user activity and completion rates
- Team performance metrics
- Private notes added to reminders
- Full audit logs of all actions
- This is necessary for team management and oversight
By using Duetiful and assigning Backstop Advisers or joining an organization account, you authorize this internal data sharing.
If you need to keep certain reminders private from Backstop Advisers or administrators, do not include sensitive details in the reminder fields.
5.2 Third-Party Service Providers
We share your information with trusted service providers who help us operate Duetiful:
Supabase (Database & Hosting)
- What they do: Host our database and application infrastructure
- What we share: All data you provide to Duetiful (account info, reminders, usage data)
- Data location: Australia (Supabase Sydney region)
- Privacy Policy: https://supabase.com/privacy
- Safeguards: Data Processing Agreement (DPA) in place, daily backups (7-day retention), industry-standard encryption
Lemon Squeezy (Payment Processing — Merchant of Record)
- What they do: Process all subscription payments, handle billing, collect payment information
- What we share: Your name, email, subscription plan details
- What they collect directly: Payment card details, billing address, tax information
- Important: We NEVER see or store your payment information — Lemon Squeezy handles this entirely
- Your statement shows: "LEMSQZY*Duetiful"
- Privacy Policy: https://www.lemonsqueezy.com/privacy
- Note: When you subscribe, you also agree to Lemon Squeezy's Terms of Service
Resend (Email Delivery)
- What they do: Send reminder notifications and account emails on our behalf
- What we share: Your email address, name, reminder details (only for emails you're supposed to receive)
- Privacy Policy: https://resend.com/legal/privacy-policy
- Safeguards: Industry-standard email security (TLS encryption)
Google Analytics (Usage Analytics)
- What they do: Help us understand how users interact with Duetiful
- What we share: Anonymized usage data, page views, feature interactions
- Cookies: Yes (see Section 7 for cookie controls)
- Privacy Policy: https://policies.google.com/privacy
- Opt-out: You can opt out via browser settings or our cookie preferences
Calendar Providers (Microsoft, Google)
- When you connect your calendar: We sync reminder information to your calendar
- What we share: Reminder titles, due dates, descriptions (what you authorize us to sync)
- Your control: You can disconnect calendar integration at any time in Settings
- Privacy Policies:
- Microsoft: https://privacy.microsoft.com/
- Google: https://policies.google.com/privacy
Google Gemini (AI Processing)
- What they do: Process optional AI features (quick-add parsing, email drafts, column detection, risk prediction)
- What we share: Anonymized text only. Names, emails, phone numbers, and client IDs are replaced with placeholders (e.g., "[NAME_1]", "[EMAIL_1]") before any data leaves your browser
- What we DON'T share: Raw personal data (except Quick Add text, which is sent as-is for parsing accuracy)
- Data in transit: All communication uses HTTPS (TLS encryption) — data is encrypted during transmission
- Data at rest: Client PII stored in our database is encrypted using XSalsa20-Poly1305 (libsodium) with 256-bit keys
- AI provider policy: Google Gemini processes data transiently — it is NOT stored, retained, or used for model training
- Your control: You can disable all AI features via the "Enable AI Assistance" toggle in your profile settings
- Privacy Policy: https://policies.google.com/privacy
Data Processing Agreements: We have (or will establish) Data Processing Agreements with all service providers that process your personal information, ensuring they comply with Australian privacy standards.
5.3 We Do NOT Sell Your Data
We will NEVER:
- ❌ Sell your personal information to third parties
- ❌ Share your reminder data with competitors
- ❌ Rent or lease your contact information
- ❌ Use your client information for our own marketing purposes
- ❌ Share your data with advertisers (beyond standard analytics)
5.4 Legal Disclosures & Law Enforcement
We may disclose your information when:
Legally Required:
- Court order, subpoena, or warrant
- Australian or foreign law requires disclosure
- Regulatory authority requests information
To Protect Rights:
- Investigating suspected fraud or Terms violations
- Protecting our legal rights or property
- Defending against legal claims
Public Safety:
- Preventing imminent harm to individuals
- Cooperating with law enforcement in urgent situations
We will only disclose the minimum information necessary and will notify you when legally permitted.
Australian Privacy Principle 6.2: We are permitted to disclose information when required or authorized by law.
6. Cross-Border Data Transfers
6.1 Korean Company, Australian Data Storage
IMPORTANT NOTICE:
Your personal information is:
- Collected and controlled by: 주식회사 (a Korean company)
- Stored in: Australia (Supabase Sydney region)
- Processed by: Our Korean company and Australian service providers (Supabase, Resend)
Your data does NOT leave Australia — it remains stored in Supabase's Sydney data center.
However, because our legal entity is a Korean company, Australian privacy law considers this a "cross-border disclosure" of personal information.
6.2 How We Comply with Australian Privacy Principle 8
APP 8: Cross-border Disclosure of Personal Information
Before disclosing your information to our Korean entity, we take reasonable steps to ensure compliance with Australian Privacy Principles:
Contractual Safeguards:
- Our Korean company commits to handling your information according to Australian Privacy Principles
- Internal data protection policies aligned with APP requirements
- Technical and organizational measures to protect your information
Data Storage Protections:
- Data remains in Australia (Supabase Sydney)
- Industry-standard encryption in transit (HTTPS/TLS) and at rest
- Access controls limiting who can access your information
- Audit logging of all data access
Your Rights:
- You retain all rights under the Australian Privacy Act
- You can complain to the Office of the Australian Information Commissioner (OAIC)
- We remain accountable for how your information is handled
6.3 For European Users (GDPR)
If you're in the EU/EEA:
Good news: Australia has an "adequacy decision" from the European Commission, meaning:
- Transfers from EU → Australia are permitted without additional safeguards
- Australian privacy law is considered equivalent to GDPR
- Your data in Australia receives similar protections to data in the EU
Standard Contractual Clauses: We also use EU-approved Standard Contractual Clauses (SCCs) with our service providers where applicable.
Your GDPR Rights: See Section 9.2 for details.
6.4 For California Users (CCPA)
If you're a California resident:
- We comply with CCPA requirements for transparency and data rights
- See Section 9.3 for your specific rights under CCPA
7. Cookies and Tracking Technologies
7.1 What Are Cookies?
Cookies are small text files stored on your device when you visit Duetiful. They help us:
- Remember you're logged in
- Save your preferences
- Understand how you use the Service
- Improve your experience
7.2 Types of Cookies We Use
Necessary Cookies (Essential — Always Active)
These cookies are required for Duetiful to function. You cannot disable these without losing core functionality.
What they do:
- Keep you logged in (session cookies)
- Remember authentication state
- Store security tokens
- Enable core Service features
- Prevent CSRF attacks
Duration: Session cookies (deleted when you close browser) or up to 30 days
Functional Cookies (Optional — On by Default)
These cookies enhance your experience but aren't strictly necessary.
What they do:
- Remember your language and time zone
- Save your dashboard preferences
- Recall your reminder view settings (list/calendar/board)
- Store UI customizations
You can disable these, but you'll need to reset preferences each visit.
Duration: Up to 1 year
Analytics Cookies (Optional — On by Default)
These help us understand how Duetiful is used so we can improve it.
What they do:
- Track which features are used most
- Identify pages with high error rates
- Measure time spent on different screens
- Analyze user journey through the app
We use: Google Analytics (anonymized data only), Supabase Analytics (first-party analytics)
Data collected is aggregated and anonymized — we can't identify individual users from analytics data.
You can disable these if you prefer not to contribute to usage statistics.
Duration: Up to 2 years
Marketing/Advertising Cookies (Opt-In Only — Off by Default)
We currently do NOT use advertising cookies. If we add them in the future:
- They would be opt-in only (off by default)
- Used only with your explicit consent
- You could withdraw consent at any time
7.3 Managing Your Cookie Preferences
Within Duetiful:
- Go to Account Settings → Privacy
- Click Cookie Preferences
- Toggle categories on/off (except Necessary cookies)
- Save your preferences
You'll see a cookie consent banner on your first visit where you can customize settings immediately.
In Your Browser:
You can also control cookies through your browser settings:
- Chrome: Settings → Privacy and Security → Cookies and other site data
- Firefox: Settings → Privacy & Security → Cookies and Site Data
- Safari: Preferences → Privacy → Manage Website Data
- Edge: Settings → Cookies and site permissions → Manage and delete cookies
Warning: Disabling all cookies will prevent you from logging into Duetiful.
7.4 Third-Party Cookies
Google Analytics: If enabled, Google sets cookies to track usage. You can opt out using:
- Our cookie preferences (disables analytics cookies)
- Google Analytics Opt-out Browser Add-on: https://tools.google.com/dlpage/gaoptout
Lemon Squeezy: May set cookies during checkout process. Subject to their privacy policy.
7.5 Do Not Track (DNT)
Some browsers offer a "Do Not Track" (DNT) signal. We currently:
- Do NOT respond to DNT signals automatically
- Instead provide explicit cookie controls (Section 7.3)
- May implement DNT support in future
You can achieve similar privacy by:
- Disabling analytics cookies in our settings
- Using browser privacy modes (Incognito, Private Browsing)
For full details on our cookie usage, please see our Cookie Policy.
8. How We Protect Your Information
8.1 Security Measures We Implement
Encryption:
- In transit: All data transmitted over HTTPS/TLS 1.2+ encryption
- At rest: Industry-standard encryption via Supabase
- Passwords: Hashed using bcrypt with salt (we can never see your actual password)
Access Controls:
- Role-based access control (RBAC) — you only see what you're authorized to see
- Multi-factor authentication (MFA) available and recommended
- Strong password requirements (minimum 8 characters, complexity rules)
- Automatic session timeout after 30 minutes of inactivity
- API authentication tokens with limited scope
Monitoring & Logging:
- Audit logs of all data access and modifications
- Automated monitoring for suspicious activity
- Security alerts for unusual login patterns
- Error tracking and crash reporting (anonymized)
Infrastructure Security:
- Supabase Pro plan with daily backups (7-day retention)
- Database backups encrypted and stored securely
- Regular security updates and patches
- Network security (firewalls, DDoS protection)
Organizational Measures:
- Limited employee access to production data (need-to-know basis)
- Security awareness training (as team grows)
- Incident response procedures
- Regular security reviews
8.2 Beta Service Security Notice
⚠️ As a Beta service:
- We implement industry-standard security practices
- We are NOT currently SOC 2 Type II or ISO 27001 certified
- We plan to pursue these certifications as we grow
- Our infrastructure providers (Supabase) have robust security programs
By using the Beta service, you acknowledge we're still strengthening security controls.
8.3 What We DON'T Guarantee
No system is 100% secure. Despite our best efforts:
- ⚠️ Data breaches can occur
- ⚠️ Unauthorized access may happen
- ⚠️ Service providers may experience security incidents
- ⚠️ Human error can lead to data exposure
We cannot guarantee absolute security of your information.
8.4 Your Security Responsibilities
You play a critical role in security:
Do:
- ✅ Use a strong, unique password (12+ characters, mix of types)
- ✅ Enable multi-factor authentication (highly recommended)
- ✅ Log out on shared or public devices
- ✅ Keep your email account secure
- ✅ Report suspicious activity immediately
- ✅ Review your account activity regularly
- ✅ Keep your device and browser updated
Don't:
- ❌ Share your password with anyone
- ❌ Use the same password as other accounts
- ❌ Write down your password in insecure places
- ❌ Click suspicious links in emails
- ❌ Ignore security warnings or alerts
8.5 Data Breach Notification
If a data breach occurs that is likely to result in serious harm:
- We will notify you within 72 hours (as required by Australian law)
- We'll explain:
- What information was affected
- When the breach occurred
- What we're doing to address it
- Steps you should take to protect yourself
- We'll notify the Office of the Australian Information Commissioner (OAIC) if required
- We'll post a notice on our website if the breach affects many users
You can also report suspected breaches to support@duetiful.com
Australian Privacy Principle 11: We take reasonable steps to protect your information from misuse, interference, loss, unauthorized access, modification, or disclosure.
9. Your Privacy Rights
9.1 For Australian Users (Privacy Act 1988)
Under the Australian Privacy Act, you have the following rights:
Right to Access (APP 12)
You can request a copy of all personal information we hold about you.
How to request:
- Email: privacy@duetiful.com
- Subject line: "Access Request"
- Include: Your name, email, and organization name
- Verify identity: We may ask security questions
Response time: Within 30 days
Cost: Free for reasonable requests
Right to Correction (APP 13)
You can request correction of inaccurate, out-of-date, incomplete, or misleading information.
How to correct:
- Minor changes: Update directly in your Account Settings
- Major corrections: Email privacy@duetiful.com with details
Right to Deletion
You can request deletion of your account and all associated data.
How to delete:
- Option 1: Account Settings → Delete Account → Confirm deletion
- Option 2: Email privacy@duetiful.com
What happens:
- Your account is immediately deactivated
- You have 60 days to download any data
- After 60 days, all your data is permanently deleted
- Cannot be recovered after deletion
Right to Data Portability
You can export your data in a common, machine-readable format. The scope depends on your role:
Admin / Organisation Lead:
- Full organisational export including client records, all deadlines, and team data
Adviser (non-admin):
- Personal activity archive only — your actions, assigned deadline metadata, and session history
- Client PII, firm documents, and other team members' data are excluded
How to export:
- Account Settings → Data & Privacy
- Click "Export My Data" (Admin) or "Download My Activity History (GDPR)" (Adviser)
- Download file immediately
This role-based scope ensures your individual privacy rights are honoured while protecting proprietary firm and client data. See our Terms of Service (Section 5.2) for data ownership definitions.
Right to Complain
If you believe we've breached your privacy:
Step 1: Contact us first
- Email: privacy@duetiful.com
- Subject: "Privacy Complaint"
Step 2: We'll investigate (response within 30 days)
Step 3: If unsatisfied, escalate to OAIC
- Website: https://www.oaic.gov.au
- Phone: 1300 363 992 (within Australia)
- Email: enquiries@oaic.gov.au
10. Data Retention
We retain your personal data only as long as necessary to provide our services and comply with legal obligations.
While Your Account is Active
We keep your information as long as your account remains active and your subscription is current. No time limit while you're an active user.
Individual Account Deletion
When you delete your account, your personal profile, clients, reminders, calendar connections, and session data are permanently and immediately deleted from our systems.
Audit log pseudonymisation: Your identity is permanently severed from security audit records — we replace your user identifier with an anonymised reference. We retain anonymised audit trails under our legitimate interest in maintaining regulatory compliance and organisational security integrity (GDPR Art. 6(1)(c) and Art. 17(3)(b)). These records contain no information that could identify you.
Organisation Subscription Cancellation
30-Day Grace Period: When an organisation's subscription is cancelled, all organisation data is retained for 30 days. This allows the data controller to export records before permanent deletion.
After 30 Days: All organisation-scoped data — including client records, reminders, team data, and settings — is permanently deleted from our systems. A data deletion receipt is sent to the organisation owner confirming what was removed.
⚠️ Information We Retain After Deletion:
- Anonymised security audit logs (retained, no personal data): Your identity is fully removed. These records are retained under legitimate interest for regulatory integrity (GDPR Art. 17(3)(b)).
- Professional records — 7 years: Deadline escalation records, backstop intervention records, and agent reassignment logs are retained for 7 years to meet professional liability standards (SRA, ICAEW, and equivalent regulatory requirements).
- Security and fraud prevention — up to 2 years: Logs of suspected abuse or security violations.
- Operational log archive — up to 7 years: System maintenance and CRON job logs are archived for SOC 2 Type II evidence requirements.
- Backup retention — up to 7 days: Deleted data may persist in automated daily backups before being fully purged.
11. Changes to This Policy
We may update this Privacy Policy periodically. We will notify you of significant changes via email or through our platform. Continued use of our services constitutes acceptance of the updated policy.
12. Contact Us
For privacy-related questions or to exercise your rights:
Privacy Inquiries: privacy@duetiful.com
Data Protection Officer: dpo@duetiful.com
General Support: support@duetiful.com
Legal Matters: legal@duetiful.com
Address:
Australian Information Commissioner: www.oaic.gov.au
Related Policies
This Privacy Policy should be read together with:
- Terms of Service — Terms governing your use of Duetiful
- Cookie Policy — How we use cookies