This Privacy Policy explains how Hydian handles account data, connected-account content, AI-derived information, usage data, support records, cookies, and security logs.
Plain-English position
Hydian runs an AI-assisted business administration product. Customers connect business systems so Hydian can help process work such as messages, files, calendars, tasks, summaries, approvals, documents, and operational workflows.
Baseline position
Hydian acts as controller for the customer's own account data, such as name, email, login, sessions, company membership, and support interactions.On request
Hydian acts as processor for customer content pulled from connected accounts, including emails, calendar events, files, SMS, contacts, and derived AI work product.On request
Customer content may include information about people who have not signed up for Hydian.On request
Customers are responsible for having rights, consents, notices, lawful bases, and internal authority for the data and workflows they connect.On request
Billing runs every 28 days and is invoiced in AUD.On request
No third-party analytics or advertising trackers are used. Cookies are limited to strictly necessary session cookies plus first-party local preferences.On request
Retention includes a 30-day soft suspension period followed by hard purge, per-file reference deletion, member-removal token revocation, seven-day rolling sessions, permanent SMS opt-out, log redaction, and AES-GCM vault encryption for secrets.On request
Business content is stored in managed infrastructure with storage-level encryption. Tenant separation is logical application-level isolation.On request
Information Hydian collects
Account and identity data: name, email, email verification status, password hash, profile image, two-factor authentication data, backup codes, social login tokens, sessions, IP address, user agent, verification tokens, and reset tokens.
Company data: company name, code, description, industry, brand colour, logo, timezone, memberships, roles, invited emails, join requests, budget settings, and spend figures.
Credentials and connected-account secrets: OAuth tokens, Twilio credentials, customer-pasted API keys, SSO and SCIM tokens, plugin tokens, and MCP OAuth tokens.
AI-derived data: embeddings, learned voice or preference signals, priority preferences, briefing preferences, task history, approval history, comments, and activity records.
Usage and technical data: AI token usage, cost per action, selected model, budget incidents, audit logs, compliance logs, session metadata, and redacted server logs.
How Hydian uses information
Hydian uses information to provide the product, authenticate users, secure accounts, run connected workflows, generate AI-assisted outputs, maintain audit history, manage usage and budgets, provide support, enforce acceptable use rules, and meet legal obligations.
Controller and processor roles
For account and company administration data, Hydian generally acts as a controller. For customer content from connected accounts and customer-directed workflows, Hydian generally acts as a processor or service provider acting on customer instructions. The Data Processing Agreement explains this split in more detail.
Customer responsibilities
Customers must only connect accounts, content, and workflows they are authorised to use. Customers are responsible for privacy notices, consents, lawful bases, employment notices, client notices, sector rules, and internal approvals needed for their use of Hydian.
AI processing
Hydian may send customer content and instructions to AI model providers or infrastructure providers to perform the requested workflow. AI outputs may be inaccurate, incomplete, or unsuitable for legal, financial, employment, medical, safety, or regulated decisions without human review.
Training and sale of data
Hydian does not sell customer data.
Cookies and local storage
Hydian uses a strictly necessary session cookie, configured as httpOnly and Secure with a seven-day life, plus first-party localStorage preferences. Hydian does not use third-party advertising trackers or analytics trackers.
Retention and deletion
Hydian applies a 30-day soft suspension period before hard purge. Hard purge removes database records through cascade deletion and sweeps stored blobs. File references may be deleted individually. Removing a member cancels related tasks and revokes tokens. Password resets revoke rolling sessions. SMS opt-outs are permanent. Logs are redacted where possible.
Security
Hydian protects secrets in an AES-GCM encrypted vault. Business content is stored in managed infrastructure with storage-level encryption. Hydian applies logical tenant isolation and audit logging.
International transfers
Hydian may process data through infrastructure, AI, support, and security vendors located outside the customer's country.
Data rights
Customers and individuals may request access, correction, deletion, export, objection, restriction, or other rights available under applicable law. Requests involving customer content are routed to the relevant customer where Hydian acts as processor.
These Terms govern access to Hydian's website, application, APIs, workflows, AI features, connected-account integrations, and related services.
Service
Hydian provides AI-assisted business administration software. Customers can connect accounts and systems, configure workflows, create tasks, generate drafts, review outputs, and automate operational activity.
Customer account
Customers are responsible for account security, invited users, roles, permissions, connected accounts, credentials, API keys, and any actions taken through their workspace.
Customer content and authority
Customers retain ownership of their customer content. Customers grant Hydian the rights needed to host, process, transmit, display, transform, analyse, and generate outputs from that content for the service.
Customers warrant that they have all rights, consents, notices, lawful bases, and authority needed to connect accounts, upload content, run workflows, and process information about staff, clients, suppliers, contacts, and other people.
AI outputs
AI outputs may be inaccurate, incomplete, offensive, duplicated, unsuitable, or non-compliant. Customers remain responsible for reviewing outputs before relying on them or sending them. Hydian is not a substitute for legal, financial, employment, medical, safety, tax, accounting, or other professional advice.
Prohibited use
Customers must not use Hydian to break the law, violate privacy rights, scrape or spam, impersonate others, transmit malware, abuse connected platforms, bypass security controls, make prohibited automated decisions, process special category data without authority, or create safety-critical outcomes without suitable human review.
Suspension
Hydian may suspend or limit access when needed to protect the service, comply with law, prevent abuse, respond to security risk, avoid excessive usage, or enforce these Terms.
Billing
Subscriptions bill every 28 days and are invoiced in AUD. Commercial terms may be set out in an order form, subscription agreement, MSA, or enterprise agreement.
Availability
Hydian may depend on third-party model providers, hosting providers, email providers, calendar providers, messaging providers, and customer-connected services. Temporary outages, rate limits, model changes, or degraded third-party service may affect performance.
Intellectual property
Hydian owns the service, software, workflows, prompts not specific to a customer, design, systems, documentation, and brand assets. Customers own their customer content and, subject to these Terms, their AI outputs.
Confidentiality
Each party must protect confidential information using reasonable care and use it only for the agreement and service.
Liability and general terms
Limitation of liability, exclusion of indirect and consequential damages, warranty disclaimers, customer indemnity for unlawful use, force majeure, export and sanctions compliance, governing law, assignment, survival, severability, entire agreement, and the amendment process are set out in the signed contractual version of these Terms.
This policy sets the line between permitted and prohibited use across the website, application, APIs, workspaces, connected-account integrations and AI-assisted workflows.
Hydian must not be used for unlawful processing, spam, harassment, malware, credential theft, impersonation, unlawful surveillance, prohibited automated decisions, rights violations, regulated professional advice without human review, or attempts to bypass security controls.
Hydian may suspend accounts, block workflows, revoke connected-account access or limit usage to protect customers, third parties, Hydian and connected platforms. The policy is owned jointly by legal, security and product, and is reviewed at least annually or when the product, vendors, jurisdictions or data handling change.
AI Usage Policy
Last updated 18 July 2026
Customers review material AI outputs before sending, filing, acting on or relying on them. Output can be inaccurate, incomplete, biased, duplicated, stale or unsuited to a regulated decision.
Hydian should not be the sole basis for legal, financial, medical, employment, safety, insurance, credit or housing decisions. Models may change over time, output quality varies, third-party model providers may be used, and provider outages may affect the service.
Cookie Policy
Last updated 18 July 2026
Hydian currently uses one strictly necessary session cookie and first-party localStorage preferences. There are no third-party analytics cookies, advertising cookies or cross-site tracking pixels. If that changes, this policy is updated before the change is deployed.
Data Processing Agreement
Last updated 18 July 2026
The DPA governs Hydian's processing of personal information in customer content where Hydian acts as processor. The customer is controller for customer content, connected-account content, workflow instructions and third-party personal information brought into Hydian. Hydian is controller for account administration, security, billing administration, legal compliance and support records.
Customer content may include emails, files, calendar events, SMS, contacts, images, scans, extracted text, embeddings, workflow history, AI outputs and metadata, and may relate to staff, clients, prospects, suppliers, attendees, senders and recipients. Customers must not submit sensitive data without authority and appropriate safeguards.
Sub-processors may be used for hosting, storage, AI models, email, communications, security, monitoring, support and infrastructure, with a public list and change notice. Security measures include access controls, secret encryption, logging, vulnerability management, incident response, backup and recovery controls, and logical tenant isolation. Cross-border processing uses applicable transfer mechanisms, including EU standard contractual clauses where required.
Hydian assists with data subject requests, impact assessments, regulator requests, incidents, deletion, access, correction and portability where it acts as processor. At termination or on instruction, content is deleted or returned in line with the retention and deletion policy, subject to legal, security, backup and audit retention. Audit information and trust documentation are available on request, with on-site audit rights limited to enterprise terms.
Trust Centre
Last updated 18 July 2026
The trust material covers security, privacy, AI governance, subprocessors, data residency, incident notification, architecture and contact details. Procurement teams can request the longer versions, including the security whitepaper, architecture overview, privacy impact assessment, incident notification process and vulnerability management process.
Connected-account secrets are held in an AES-GCM encrypted vault. Business content sits in managed infrastructure with storage-level encryption. Hydian does not describe the service as end-to-end encrypted, because that is not what the architecture does today.
Tenants are separated by logical application-level isolation. Access is controlled and logged, with audit and compliance records kept per workspace. The wider programme covers identity and access management, encryption, logging and monitoring, vulnerability management, penetration testing, secure development, incident response, backup, recovery and business continuity. Security reports go to contact@hydian.ai.
Subprocessors
Last updated 18 July 2026
Hydian maintains a public subprocessor list covering hosting, storage, AI models, email, communications, security, monitoring, support and infrastructure. Material changes to the list trigger customer notice through the published process. The current named list is available on request: contact@hydian.ai.
Data residency
Last updated 18 July 2026
Hydian is built in Australia and runs on managed infrastructure. Data may be processed by infrastructure, AI, support and security vendors located outside a customer's country. The approved version of this statement lists the regions in use and the transfer mechanisms relied on for Australian Privacy Act and GDPR purposes. Enterprise customers can request a custom data residency review.
EU AI Act compliance
Last updated 18 August 2026
Regulation (EU) 2024/1689, the EU AI Act, applies to AI systems placed on the market or used inside the European Union, including by providers established outside it. Where a customer operates Hydian in the EU, this statement sets out how the platform is positioned against that regime and which obligations sit with whom.
How Hydian classifies its systems
Hydian's agents draft, extract, summarise and prepare business administration for a person to approve. They are built as assistive systems, not as autonomous decision-makers, and Hydian does not offer them for the prohibited practices listed in Article 5. Hydian does not build foundation models; general-purpose models are obtained from model providers, and their obligations sit with those providers.
Classification depends on use. A workflow a customer builds for recruitment, credit, education, essential services, employment decisions or another Annex III purpose can be high risk even where the platform is not. Customers who configure that kind of workflow take on the deployer obligations that come with it, and are asked to tell Hydian before doing so.
Transparency and human oversight
Article 50 transparency is built into the product rather than bolted on: AI-generated drafts are shown as drafts with the source behind them, material actions wait for human approval, and workflow history records what an agent did and who released it. Where an agent handles a message on a customer's behalf, the customer remains responsible for disclosing that to the people they are communicating with.
Documentation available to customers
On request, Hydian provides the AI transparency statement, human oversight policy, AI risk assessment, model governance and incident response material that EU deployers need for their own records, together with the subprocessor list and data residency statement. AI literacy obligations under Article 4 apply to the customer's own staff; Hydian supplies the product documentation that supports them.
Obligations under the Act phase in through 2025, 2026 and 2027. This statement is reviewed as each phase takes effect, and questions about a specific deployment reach Hydian at contact@hydian.ai.
Commercial and billing
10 documents
How money and commitments work. Subscriptions bill every 28 days, and this area covers billing, cancellation, refunds, renewals, subscription and enterprise agreements, order form template, master services agreement, service levels and the support policy.
How the agents are governed: human oversight, output review, transparency, model governance, hallucination disclosure, safety, ethics, risk management and AI incident response.
What happens to information once it is in the workspace: ownership, access, classification, retention, deletion, portability, backup, recovery, records management, GDPR processing terms and international transfers.
The security programme in full: information security policy, encryption, identity and access management, logging and monitoring, passwords, penetration testing, secure coding, secure development lifecycle, incident response, disclosure, continuity and disaster recovery.
The material procurement and security reviewers ask for: trust centre, architecture and infrastructure overviews, encryption overview, data flow diagram, data residency statement, subprocessor list, incident notification, penetration test and audit summaries, security FAQ, uptime and status.
AI governance overviewOn request
AI risk assessmentOn request
Architecture overviewOn request
Audit reports SOC 2 ISO 27001 (once obtained)On request
How change reaches production and who is accountable for it: asset management, change and release management, maintenance, backup schedule, vendor and third-party risk, and version support.
Statements and guides written for regulators and buyers: Australian Privacy Act, privacy and regulatory compliance, a GDPR guide, EU AI Act compliance, accessibility and export control.
Accessibility statementOn request
Australian privacy act compliance statementOn request