Hydian
Contact Sign in Get started

Documentation

Terms and policies.

Privacy Policy

Last updated 18 July 2026

Purpose

This Privacy Policy explains how Hydian handles account data, connected-account content, AI-derived information, usage data, support records, cookies, and security logs.

Plain-English position

Hydian runs an AI-assisted business administration product. Customers connect business systems so Hydian can help process work such as messages, files, calendars, tasks, summaries, approvals, documents, and operational workflows.

Baseline position

  • Hydian acts as controller for the customer's own account data, such as name, email, login, sessions, company membership, and support interactions.On request
  • Hydian acts as processor for customer content pulled from connected accounts, including emails, calendar events, files, SMS, contacts, and derived AI work product.On request
  • Customer content may include information about people who have not signed up for Hydian.On request
  • Customers are responsible for having rights, consents, notices, lawful bases, and internal authority for the data and workflows they connect.On request
  • Billing runs every 28 days and is invoiced in AUD.On request
  • No third-party analytics or advertising trackers are used. Cookies are limited to strictly necessary session cookies plus first-party local preferences.On request
  • Retention includes a 30-day soft suspension period followed by hard purge, per-file reference deletion, member-removal token revocation, seven-day rolling sessions, permanent SMS opt-out, log redaction, and AES-GCM vault encryption for secrets.On request
  • Business content is stored in managed infrastructure with storage-level encryption. Tenant separation is logical application-level isolation.On request

Information Hydian collects

  • Account and identity data: name, email, email verification status, password hash, profile image, two-factor authentication data, backup codes, social login tokens, sessions, IP address, user agent, verification tokens, and reset tokens.
  • Company data: company name, code, description, industry, brand colour, logo, timezone, memberships, roles, invited emails, join requests, budget settings, and spend figures.
  • Customer content: email bodies, subjects, senders, threads, SMS bodies, phone numbers, calendar events, attendees, uploaded files, extracted text, images, scans, AI-generated documents, contacts, and sender-classification lists.
  • Credentials and connected-account secrets: OAuth tokens, Twilio credentials, customer-pasted API keys, SSO and SCIM tokens, plugin tokens, and MCP OAuth tokens.
  • AI-derived data: embeddings, learned voice or preference signals, priority preferences, briefing preferences, task history, approval history, comments, and activity records.
  • Usage and technical data: AI token usage, cost per action, selected model, budget incidents, audit logs, compliance logs, session metadata, and redacted server logs.

How Hydian uses information

Hydian uses information to provide the product, authenticate users, secure accounts, run connected workflows, generate AI-assisted outputs, maintain audit history, manage usage and budgets, provide support, enforce acceptable use rules, and meet legal obligations.

Controller and processor roles

For account and company administration data, Hydian generally acts as a controller. For customer content from connected accounts and customer-directed workflows, Hydian generally acts as a processor or service provider acting on customer instructions. The Data Processing Agreement explains this split in more detail.

Customer responsibilities

Customers must only connect accounts, content, and workflows they are authorised to use. Customers are responsible for privacy notices, consents, lawful bases, employment notices, client notices, sector rules, and internal approvals needed for their use of Hydian.

AI processing

Hydian may send customer content and instructions to AI model providers or infrastructure providers to perform the requested workflow. AI outputs may be inaccurate, incomplete, or unsuitable for legal, financial, employment, medical, safety, or regulated decisions without human review.

Training and sale of data

Hydian does not sell customer data.

Cookies and local storage

Hydian uses a strictly necessary session cookie, configured as httpOnly and Secure with a seven-day life, plus first-party localStorage preferences. Hydian does not use third-party advertising trackers or analytics trackers.

Retention and deletion

Hydian applies a 30-day soft suspension period before hard purge. Hard purge removes database records through cascade deletion and sweeps stored blobs. File references may be deleted individually. Removing a member cancels related tasks and revokes tokens. Password resets revoke rolling sessions. SMS opt-outs are permanent. Logs are redacted where possible.

Security

Hydian protects secrets in an AES-GCM encrypted vault. Business content is stored in managed infrastructure with storage-level encryption. Hydian applies logical tenant isolation and audit logging.

International transfers

Hydian may process data through infrastructure, AI, support, and security vendors located outside the customer's country.

Data rights

Customers and individuals may request access, correction, deletion, export, objection, restriction, or other rights available under applicable law. Requests involving customer content are routed to the relevant customer where Hydian acts as processor.

Contact

Privacy: privacy@hydian.ai. Security: security@hydian.ai.


Terms of Service

Last updated 18 July 2026

Purpose

These Terms govern access to Hydian's website, application, APIs, workflows, AI features, connected-account integrations, and related services.

Service

Hydian provides AI-assisted business administration software. Customers can connect accounts and systems, configure workflows, create tasks, generate drafts, review outputs, and automate operational activity.

Customer account

Customers are responsible for account security, invited users, roles, permissions, connected accounts, credentials, API keys, and any actions taken through their workspace.

Customer content and authority

Customers retain ownership of their customer content. Customers grant Hydian the rights needed to host, process, transmit, display, transform, analyse, and generate outputs from that content for the service.

Customers warrant that they have all rights, consents, notices, lawful bases, and authority needed to connect accounts, upload content, run workflows, and process information about staff, clients, suppliers, contacts, and other people.

AI outputs

AI outputs may be inaccurate, incomplete, offensive, duplicated, unsuitable, or non-compliant. Customers remain responsible for reviewing outputs before relying on them or sending them. Hydian is not a substitute for legal, financial, employment, medical, safety, tax, accounting, or other professional advice.

Prohibited use

Customers must not use Hydian to break the law, violate privacy rights, scrape or spam, impersonate others, transmit malware, abuse connected platforms, bypass security controls, make prohibited automated decisions, process special category data without authority, or create safety-critical outcomes without suitable human review.

Suspension

Hydian may suspend or limit access when needed to protect the service, comply with law, prevent abuse, respond to security risk, avoid excessive usage, or enforce these Terms.

Billing

Subscriptions bill every 28 days and are invoiced in AUD. Commercial terms may be set out in an order form, subscription agreement, MSA, or enterprise agreement.

Availability

Hydian may depend on third-party model providers, hosting providers, email providers, calendar providers, messaging providers, and customer-connected services. Temporary outages, rate limits, model changes, or degraded third-party service may affect performance.

Intellectual property

Hydian owns the service, software, workflows, prompts not specific to a customer, design, systems, documentation, and brand assets. Customers own their customer content and, subject to these Terms, their AI outputs.

Confidentiality

Each party must protect confidential information using reasonable care and use it only for the agreement and service.

Liability and general terms

Limitation of liability, exclusion of indirect and consequential damages, warranty disclaimers, customer indemnity for unlawful use, force majeure, export and sanctions compliance, governing law, assignment, survival, severability, entire agreement, and the amendment process are set out in the signed contractual version of these Terms.

Contact

legal@hydian.ai


Acceptable Use Policy

Last updated 18 July 2026

This policy sets the line between permitted and prohibited use across the website, application, APIs, workspaces, connected-account integrations and AI-assisted workflows.

Hydian must not be used for unlawful processing, spam, harassment, malware, credential theft, impersonation, unlawful surveillance, prohibited automated decisions, rights violations, regulated professional advice without human review, or attempts to bypass security controls.

Hydian may suspend accounts, block workflows, revoke connected-account access or limit usage to protect customers, third parties, Hydian and connected platforms. The policy is owned jointly by legal, security and product, and is reviewed at least annually or when the product, vendors, jurisdictions or data handling change.


AI Usage Policy

Last updated 18 July 2026

Customers review material AI outputs before sending, filing, acting on or relying on them. Output can be inaccurate, incomplete, biased, duplicated, stale or unsuited to a regulated decision.

Hydian should not be the sole basis for legal, financial, medical, employment, safety, insurance, credit or housing decisions. Models may change over time, output quality varies, third-party model providers may be used, and provider outages may affect the service.


Cookie Policy

Last updated 18 July 2026

Hydian currently uses one strictly necessary session cookie and first-party localStorage preferences. There are no third-party analytics cookies, advertising cookies or cross-site tracking pixels. If that changes, this policy is updated before the change is deployed.


Data Processing Agreement

Last updated 18 July 2026

The DPA governs Hydian's processing of personal information in customer content where Hydian acts as processor. The customer is controller for customer content, connected-account content, workflow instructions and third-party personal information brought into Hydian. Hydian is controller for account administration, security, billing administration, legal compliance and support records.

Customer content may include emails, files, calendar events, SMS, contacts, images, scans, extracted text, embeddings, workflow history, AI outputs and metadata, and may relate to staff, clients, prospects, suppliers, attendees, senders and recipients. Customers must not submit sensitive data without authority and appropriate safeguards.

Sub-processors may be used for hosting, storage, AI models, email, communications, security, monitoring, support and infrastructure, with a public list and change notice. Security measures include access controls, secret encryption, logging, vulnerability management, incident response, backup and recovery controls, and logical tenant isolation. Cross-border processing uses applicable transfer mechanisms, including EU standard contractual clauses where required.

Hydian assists with data subject requests, impact assessments, regulator requests, incidents, deletion, access, correction and portability where it acts as processor. At termination or on instruction, content is deleted or returned in line with the retention and deletion policy, subject to legal, security, backup and audit retention. Audit information and trust documentation are available on request, with on-site audit rights limited to enterprise terms.


Trust Centre

Last updated 18 July 2026

The trust material covers security, privacy, AI governance, subprocessors, data residency, incident notification, architecture and contact details. Procurement teams can request the longer versions, including the security whitepaper, architecture overview, privacy impact assessment, incident notification process and vulnerability management process.


Security

Last updated 18 July 2026

Connected-account secrets are held in an AES-GCM encrypted vault. Business content sits in managed infrastructure with storage-level encryption. Hydian does not describe the service as end-to-end encrypted, because that is not what the architecture does today.

Tenants are separated by logical application-level isolation. Access is controlled and logged, with audit and compliance records kept per workspace. The wider programme covers identity and access management, encryption, logging and monitoring, vulnerability management, penetration testing, secure development, incident response, backup, recovery and business continuity. Security reports go to contact@hydian.ai.


Subprocessors

Last updated 18 July 2026

Hydian maintains a public subprocessor list covering hosting, storage, AI models, email, communications, security, monitoring, support and infrastructure. Material changes to the list trigger customer notice through the published process. The current named list is available on request: contact@hydian.ai.


Data residency

Last updated 18 July 2026

Hydian is built in Australia and runs on managed infrastructure. Data may be processed by infrastructure, AI, support and security vendors located outside a customer's country. The approved version of this statement lists the regions in use and the transfer mechanisms relied on for Australian Privacy Act and GDPR purposes. Enterprise customers can request a custom data residency review.


EU AI Act compliance

Last updated 18 August 2026

Regulation (EU) 2024/1689, the EU AI Act, applies to AI systems placed on the market or used inside the European Union, including by providers established outside it. Where a customer operates Hydian in the EU, this statement sets out how the platform is positioned against that regime and which obligations sit with whom.

How Hydian classifies its systems

Hydian's agents draft, extract, summarise and prepare business administration for a person to approve. They are built as assistive systems, not as autonomous decision-makers, and Hydian does not offer them for the prohibited practices listed in Article 5. Hydian does not build foundation models; general-purpose models are obtained from model providers, and their obligations sit with those providers.

Classification depends on use. A workflow a customer builds for recruitment, credit, education, essential services, employment decisions or another Annex III purpose can be high risk even where the platform is not. Customers who configure that kind of workflow take on the deployer obligations that come with it, and are asked to tell Hydian before doing so.

Transparency and human oversight

Article 50 transparency is built into the product rather than bolted on: AI-generated drafts are shown as drafts with the source behind them, material actions wait for human approval, and workflow history records what an agent did and who released it. Where an agent handles a message on a customer's behalf, the customer remains responsible for disclosing that to the people they are communicating with.

Documentation available to customers

On request, Hydian provides the AI transparency statement, human oversight policy, AI risk assessment, model governance and incident response material that EU deployers need for their own records, together with the subprocessor list and data residency statement. AI literacy obligations under Article 4 apply to the customer's own staff; Hydian supplies the product documentation that supports them.

Obligations under the Act phase in through 2025, 2026 and 2027. This statement is reviewed as each phase takes effect, and questions about a specific deployment reach Hydian at contact@hydian.ai.


Commercial and billing

10 documents

How money and commitments work. Subscriptions bill every 28 days, and this area covers billing, cancellation, refunds, renewals, subscription and enterprise agreements, order form template, master services agreement, service levels and the support policy.

  • Billing policyOn request
  • Cancellation policyOn request
  • Enterprise agreementOn request
  • Master services agreement MSAOn request
  • Order form templateOn request
  • Refund policyOn request
  • Renewal policyOn request
  • Service level agreement SLAOn request
  • Subscription agreementOn request
  • Support policyOn request
Read the full area →

AI governance

10 documents

How the agents are governed: human oversight, output review, transparency, model governance, hallucination disclosure, safety, ethics, risk management and AI incident response.

  • AI ethics policyOn request
  • AI hallucination disclosureOn request
  • AI incident response policyOn request
  • AI output review policyOn request
  • AI risk management policyOn request
  • AI safety policyOn request
  • AI transparency statementOn request
  • Human oversight policyOn request
  • Model governance policyOn request
  • Responsible AI policyOn request
Read the full area →

Privacy and data

11 documents

What happens to information once it is in the workspace: ownership, access, classification, retention, deletion, portability, backup, recovery, records management, GDPR processing terms and international transfers.

  • Customer data ownership policyOn request
  • Data access policyOn request
  • Data backup policyOn request
  • Data classification policyOn request
  • Data deletion policyOn request
  • Data portability policyOn request
  • Data processing agreement GDPR
  • Data recovery policyOn request
  • Data retention policyOn request
  • International data transfer addendumOn request
  • Records management policyOn request
Read the full area →

Security

14 documents

The security programme in full: information security policy, encryption, identity and access management, logging and monitoring, passwords, penetration testing, secure coding, secure development lifecycle, incident response, disclosure, continuity and disaster recovery.

  • Business continuity plan BCPOn request
  • Disaster recovery plan DRPOn request
  • Encryption policyOn request
  • Identity access management policyOn request
  • Incident response planOn request
  • Information security policy
  • Logging monitoring policyOn request
  • Password policyOn request
  • Penetration testing policyOn request
  • Responsible disclosure policyOn request
  • Secure coding standardOn request
  • Secure development lifecycle SDLCOn request
  • Security whitepaper
  • Vulnerability disclosure policyOn request
Read the full area →

Customer trust

22 documents

The material procurement and security reviewers ask for: trust centre, architecture and infrastructure overviews, encryption overview, data flow diagram, data residency statement, subprocessor list, incident notification, penetration test and audit summaries, security FAQ, uptime and status.

  • AI governance overviewOn request
  • AI risk assessmentOn request
  • Architecture overviewOn request
  • Audit reports SOC 2 ISO 27001 (once obtained)On request
  • Business continuity summaryOn request
  • Data flow diagramOn request
  • Data residency statement
  • Disaster recovery summaryOn request
  • Encryption overviewOn request
  • Incident notification processOn request
  • Infrastructure diagramOn request
  • Infrastructure overviewOn request
  • Penetration test summaryOn request
  • Privacy impact assessmentOn request
  • Secure SDLC overviewOn request
  • Security contactOn request
  • Security FAQ
  • Status pageOn request
  • Subprocessor list
  • Trust centre
  • Uptime historyOn request
  • Vulnerability management processOn request
Read the full area →

Operations

8 documents

How change reaches production and who is accountable for it: asset management, change and release management, maintenance, backup schedule, vendor and third-party risk, and version support.

  • Asset management policyOn request
  • Backup scheduleOn request
  • Change management policyOn request
  • Maintenance policyOn request
  • Release management policyOn request
  • Third party risk management policyOn request
  • Vendor management policyOn request
  • Version support policyOn request
Read the full area →

Compliance

7 documents

Statements and guides written for regulators and buyers: Australian Privacy Act, privacy and regulatory compliance, a GDPR guide, EU AI Act compliance, accessibility and export control.

  • Accessibility statementOn request
  • Australian privacy act compliance statementOn request
  • EU AI Act compliance
  • Export control complianceOn request
  • GDPR compliance guideOn request
  • Privacy compliance statementOn request
  • Regulatory compliance statementOn request
Read the full area →

Developer

6 documents

For teams building against Hydian: API terms of use, developer agreement, SDK licence, integration policy, webhook policy and rate limits.

  • API terms of useOn request
  • Developer agreementOn request
  • Integration policyOn request
  • Rate limit policyOn request
  • SDK licenceOn request
  • Webhook policyOn request
Read the full area →

Intellectual property

5 documents

Who owns what, and how the brand may be used: copyright notice, IP policy, licence notices, patent statement and trademark guidelines.

  • Copyright noticeOn request
  • IP policyOn request
  • Licence noticesOn request
  • Patent statementOn request
  • Trademark guidelinesOn request
Read the full area →