AI use, discernment and consent
The short version
CEDA helps you prepare and track information. You decide what is true and what gets submitted. CEDA never files anything with an agency, never signs anything, and never commits you to a bid.
1. What the AI features actually do
CEDA uses automated systems, including a third-party AI service, for a limited set of tasks:
- Reading uploaded documents. When you upload a licence, permit, bond or certificate, CEDA reads it and proposes values (dates, reference numbers, category, issuing office).
- Sorting uploads. Bulk import proposes which credential each file belongs to.
- Drafting scope. Estimating features can draft a bill of quantities' line items.
That is the whole list. In particular, AI does not price your work, does not decide whether you are eligible for a bid, and does not decide whether a credential is valid.
2. Nothing is saved until you accept it
This is a property of the software, not a promise about how carefully we work:
- Uploading a document opens a review screen with the document on one side and the proposed values on the other, each next to whatever your record currently says.
- Only the values you tick are written. You can keep the file and change nothing.
- Every proposed value carries a confidence indicator.
- In bulk import, only high-confidence values are applied without you looking. Everything less certain is listed under "Not applied, please check" with a link to each record.
- Dates that fail a sanity check (an expiry before its issue date, a renewal span that does not match the credential's cycle) are never applied unattended.
- An unpriced line in a bill of quantities still prints, carries no money, and raises a warning before the document leaves your hands.
3. Where a figure is unknown, CEDA leaves it blank
CEDA does not fill gaps with assumptions. If a retention percentage has not been set, the Statement of Work Accomplished prints it blank with a note rather than assuming a customary figure. If a government portal publishes no peso value, CEDA shows no peso value.
A blank is not a zero, and "not found" is not "does not exist". A search that fails to find a licence means the search failed to find it. It is not a finding that the licence is invalid.
4. You are the one who decides
You are responsible for checking every value against the source document and, where it matters, against the issuing agency, before you:
- rely on it,
- submit it to a client or an agency,
- sign anything based on it, or
- price or submit a bid.
Automated extraction can be wrong. It can misread a handwritten date, transpose digits in a reference number, or sort a document to the wrong credential. You have the document; you can check.
By using the AI-assisted features you acknowledge that you understand this and accept responsibility for verification. Where you have not verified a value, CEDA is not liable for loss arising from your reliance on it.
5. What CEDA is not
CEDA is not a law firm, an accounting firm, an engineering practice, or a licensed professional adviser of any kind. Nothing in the software is legal, tax, accounting or engineering advice.
Guidance about how to apply for or renew a permit describes general processes and typical requirements. The issuing agency's own current requirements always govern. Fees, forms and procedures change, and CEDA does not warrant that its guidance reflects the latest change.
6. Records of your decisions
CEDA writes an audit record each time a value is applied to a record, showing who applied it and when. That record exists so that you, and anyone reviewing your compliance later, can see that a person made the decision.
7. Availability
AI features depend on a third-party service. They may be slow, unavailable, rate-limited or withdrawn. CEDA remains usable without them: every value they propose can be typed in by hand, and no part of your records depends on the AI service continuing to exist.
8. Where your documents go
Documents you upload for reading are sent to Google's Gemini API. What that means for your privacy, including an important condition that applies during closed beta, is set out in the Privacy Notice §4. Read it before uploading anything.
Questions about this policy: [email protected]
Privacy notice
CEDA is operated by [FULL LEGAL NAME], an Australian sole trader trading as CEDA Systems (ABN [ABN]), of [BUSINESS ADDRESS]. This notice explains what we collect, why, who else sees it, and what you can ask us to do about it.
Two privacy laws apply to CEDA at the same time, and this notice is written to meet both. We are established in Australia, so the Privacy Act 1988 (Cth) and the thirteen Australian Privacy Principles apply to how we handle your information. CEDA is built for Philippine contractors, and the information we hold is largely the personal information of people in the Philippines, so the Data Privacy Act of 2012 (RA 10173) applies to us as well. Where the two set different standards we follow the stricter one rather than the more convenient one. Section 10 sets out how they fit together.
Data Protection Officer and privacy contact. We have designated a Data Protection Officer, as the Data Privacy Act requires. The same person is our contact point for privacy enquiries under Australian law. Reach them at [email protected], marking your message for the Data Protection Officer. If you need the DPO's name for a complaint, a filing, or your own records, ask and we will give it to you.
A dedicated address is coming. Until it exists we would rather point you at one that is monitored today than one that looks more official and bounces.
1. What we collect
About the people who use CEDA
- Name, work email address, and the role you hold in your organisation
- Sign-in records, and a record of what you did in the software and when
About your business, entered or uploaded by you
- Licence, permit, bond and insurance records, including reference numbers, issuing offices, and issue and expiry dates
- Government-issued identifiers, including TIN, SSS, PhilHealth and Pag-IBIG numbers, where a credential requires them
- Copies of the documents themselves
- Project, contract, billing, purchasing and workforce records you enter
How government identifiers are protected, under both laws. These numbers carry a specific status in each regime, and we hold ourselves to both:
- Under RA 10173 they are sensitive personal information, which carries the Act's higher standard of protection and narrower grounds for processing.
- Under the Australian Privacy Act they are government related identifiers, governed by APP 9. That means we do not adopt any of them as our own identifier for you, and we do not use or disclose them except where the credential you are recording actually requires it, or where the law otherwise permits.
We collect them only where a credential in the compliance catalog genuinely calls for one. We do not ask for a government identifier to build a profile of you, and we never use one as your account identifier.
What we deliberately do not collect
- We never store passwords to government portals. There is no field for one anywhere in CEDA, and there will not be. Those belong in your own browser or password manager.
- We do not use tracking pixels in our email, and our emails load no images other than our own logo.
2. Why we hold it
To provide the service you signed up for: tracking what is due, warning you before it bites, producing the documents you submit, and keeping the history that proves your compliance over time. We also use it to keep the service secure and to meet our own legal obligations.
We use your information for those purposes and for purposes directly related to them that you would reasonably expect. If we ever want to use it for something else, we will ask you first.
We do not sell your data. We do not share it for advertising.
3. Who else can see it
Access inside your organisation is controlled by the role your owner or admin gives you. Access is scoped to organisations you are an active member of. A pending invitation or a removed member has no access to anything.
We use the following service providers, who process data on our behalf:
| Provider | What it handles | Where it is processed |
|---|---|---|
| Supabase | Database, sign-in, and document storage | Singapore. The project is pinned to the AWS ap-southeast-1 region, which Supabase names "Southeast Asia (Singapore)" |
| Cloudflare | Website hosting and the code that runs our features | Cloudflare's global network, which Cloudflare describes as thousands of machines across hundreds of locations. Our code runs there; your records do not live there |
| Google (Gemini API) | Reading documents you upload, see §4 | [REGIONS TO CONFIRM] |
| Resend | Sending invitations, password resets and security notices | [REGIONS TO CONFIRM] |
| ImprovMX | Forwarding email sent to our published address | [REGIONS TO CONFIRM] |
This list is kept current. If it changes materially we will tell you.
Your information is held outside the Philippines, in Singapore. This matters under both laws and we would rather state it plainly than bury it. Everything you enter or upload, including the documents and the identifiers in them, is stored in the database above, and that database sits in one region rather than moving around.
The distinction between the first two rows is worth drawing, because it is the one people get wrong. Cloudflare runs our code, it does not store your records. Its network is global by design, so the code that serves a page executes near whoever asked for it; what that code reads and writes still lives in the Supabase database, in Singapore. We do not use Cloudflare's regional restriction add-ons, so we do not claim any geographic limit on where our code executes.
CEDA itself is operated from Australia. Being an Australian business is not the same as storing data in Australia, and we would rather say which is which than let the first imply the second.
Two commitments follow from that, and they are obligations rather than courtesies:
- Under APP 8, before we disclose your personal information to an overseas recipient we take reasonable steps to ensure that recipient handles it consistently with the Australian Privacy Principles, and we remain accountable to you for what they do with it. Choosing a provider does not transfer our responsibility to you.
- Under RA 10173, we remain responsible for personal information transferred to a third party for processing, and we contract with these providers on that basis.
CEDA was built using AI development tools, including Claude and ChatGPT. Those are tools we used to write the software. They are not part of the running service and they never receive your data. They are named here only so this notice is complete about how CEDA was made.
4. Documents you upload, and an important beta condition
When you upload a document for CEDA to read, the document itself is sent to Google's Gemini API, not just text taken from it.
During closed beta, CEDA uses Google's free service tier. Under Google's terms for that tier, content submitted to the API and the responses generated from it may be used by Google to improve and develop its products, and Google's human reviewers may read, annotate and process it.
That means a document you upload during beta, including any government identifiers it contains, may be seen by a person at Google and may contribute to training Google's models.
We are telling you this plainly because it should change what you choose to upload. If a document is too sensitive for that, do not upload it during beta. You can create and maintain a record by hand without uploading anything.
This is a beta condition with an end. Before CEDA is generally available, and before any firm that has not personally agreed to this uses it, we will move to Google's paid tier, where submitted content is not used for training and is covered by a data processing agreement. We will confirm when that has happened.
Everything else about your documents stays with us: they are stored in a private bucket, are never publicly accessible, and are served to you only through short-lived links.
4a. The updates list
If you enter your address in the "Get updates" box on our website, we add it to a mailing list and send occasional news about CEDA. This is separate from everything above, and it is worth being precise about:
- We use it only to send you CEDA news. Not for advertising, and not shared with anyone.
- The only thing we store is your email address, held with Resend, who send the messages. We do not add you to it from any other source, and signing up for the product does not sign you up for this.
- Every message carries a one-click unsubscribe link, and the link is signed so it can only remove the address it was issued for. Nobody can unsubscribe you, and you cannot be unsubscribed by someone editing a web address.
- Unsubscribing is instant and needs no reason, no login and no reply. You can also email [email protected] and we will remove you by hand.
- It does not affect account email. Password resets, invitations and security notices are not marketing and are still sent, because they are how you keep control of your account.
- We keep an unsubscribed address on a suppression list rather than deleting it outright, so that a later import cannot accidentally add you back. Ask us and we will erase it entirely.
Your consent here is separate and specific: subscribing is not consent to anything else, and withdrawing it does not affect your use of CEDA.
As an Australian sender we also meet the Spam Act 2003 (Cth): we send commercial messages only to people who asked for them, every message identifies us and how to reach us, and the unsubscribe works and is honoured promptly. APP 7 says the same thing about direct marketing, and you can tell us at any time to stop.
5. How long we keep it
See the Data Retention Policy.
Both regimes point the same way here: APP 11.2 requires us to destroy or de-identify personal information once we no longer need it for any permitted purpose, and RA 10173 requires that it not be kept longer than the purpose needs. The retention policy is where we say what that means in practice, per record type.
6. Your rights
You have these rights under both the Australian Privacy Principles and RA 10173. We do not operate two standards, and you do not need to tell us which law you are relying on. You may ask us to:
- tell you what we hold about you and where it came from (APP 12; RA 10173 right to access)
- correct anything inaccurate, incomplete or out of date (APP 13; RA 10173 right to rectify)
- give you a copy in a portable form (RA 10173 right to data portability)
- erase or block data, subject to what we must keep by law (RA 10173 rights to erasure and blocking; and see APP 11.2 above, which obliges us to dispose of it once it is no longer needed whether or not you ask)
- object to processing, and withdraw a consent you have given
- stop receiving direct marketing, at any time (APP 7)
- complain, both to us and to a regulator (see below)
To exercise any of these, email [email protected]. We will acknowledge your request within 15 days and complete it within 30 days. Thirty days is the maximum the Australian Privacy Principles allow an organisation for an access request (APP 12.4), and it is the period we work to for every kind of request under both laws, so there is one clock rather than two. If a request is complex enough that we cannot finish inside 30 days, we will write and tell you why and when it will be done, rather than let the date pass in silence.
We do not charge you for making a request. If a request is unusually large and we need to charge for the work of giving access, we will tell you the amount before we start and it will not be excessive. If we refuse a request, we will tell you in writing why, and how to complain about it.
How to complain. Tell us first, at [email protected], and we will investigate and respond. If you are not satisfied with our response, or we have not responded within 30 days, you can take it to either regulator:
- the Office of the Australian Information Commissioner (OAIC), at oaic.gov.au
- the National Privacy Commission (NPC) of the Philippines, at privacy.gov.ph
You do not need our permission to complain to either, and complaining costs you nothing with us.
Please note: the ability to make some of these requests yourself, inside the product, is still being built. Until it is, we handle them by hand on request, and we would rather say that than promise a button that does not exist.
7. Security
- Your data is separated by organisation at the database level, not only in the interface.
- Documents live in a private store, keyed so that the separation is enforced by the storage layer itself, and are reachable only through short-lived signed links.
- Sign-in supports two-factor authentication using an authenticator app.
- Administrative keys are held only in server environments and never reach your browser.
No system is perfectly secure. If a data breach happens that is likely to cause you serious harm, we will tell you and we will tell the regulators. Both regimes require this, on different clocks, and we work to the shorter one:
- Philippines (RA 10173): notification to the National Privacy Commission and to affected individuals within 72 hours of becoming aware of a qualifying breach.
- Australia (Notifiable Data Breaches scheme, Privacy Act Part IIIC): we must assess a suspected eligible breach within 30 days and, if it is one, notify the OAIC and affected individuals as soon as practicable.
Seventy-two hours is the tighter requirement, so it is the one we hold ourselves to for any breach touching personal information, whoever it belongs to.
8. Children
CEDA is a business tool and is not directed at children. We do not knowingly collect data from anyone under 18.
9. Changes
If we change this notice materially we will tell you and, where the change affects what you agreed to, ask you to agree again. Each version is dated.
10. Which law applies, and why both
This is the part most privacy notices leave out, and it is the part a contractor is most likely to need if something goes wrong.
Both laws apply, for different reasons. The Australian Privacy Act applies because we are established in Australia and carry on business there. RA 10173 applies because it reaches organisations that process the personal information of people in the Philippines where there is a sufficient link to the country, and CEDA is built for, sold to, and used by Philippine firms handling Philippine records. Registering the business in Australia did not move CEDA out of the Philippine Act, and being built for the Philippines does not put us outside the Australian one.
Where they differ, we follow the stricter. In practice that means the 72-hour breach clock from the Philippine side and the Australian Privacy Principles' handling standards throughout, applied to everyone's information rather than sorted by where each person happens to live. Sorting our users into two tiers of protection would be worse for them and harder for us to get right.
You keep every right either law gives you. Nothing in this notice, and nothing in any agreement you sign with us, takes away a right you have under RA 10173 or the Privacy Act, or your ability to complain to the National Privacy Commission or the Office of the Australian Information Commissioner.
Privacy questions and requests: [email protected]
Data retention and archiving
1. The principle
CEDA is a compliance record. Its value is its history. A licence that has been renewed six times tells a story that a single current record cannot, and a client, an agency or an auditor may ask you to show that story years later. So CEDA is built to keep, not to discard.
That is a deliberate choice, and this policy exists so it is a stated one rather than an accident.
2. What we keep, and how
Records are archived, never overwritten.
- A renewal is a new record, not an edit. Renewing a licence creates a fresh record carrying the same credential code, so every year of that licence remains readable in sequence.
- Superseded documents are archived, not replaced. When you upload a renewed certificate, the previous one is kept and labelled with the period it covered. Only one document is ever "current" for a credential; the rest sit below it, newest first.
- Deleting a record inside CEDA removes it from your workspace, and it stops appearing in lists, dashboards and reports. It is retained in the underlying database rather than erased. See the Data Deletion Policy, which explains the difference and how to have something actually erased.
We keep an activity record of who did what and when. It is deliberately narrow: actor, action, record and timestamp. It exists so that you can show a reviewer that a person made a decision, and it is what makes the verification described in AI use §6 provable rather than merely asserted.
3. How long
| What | While your subscription is active | After cancellation |
|---|---|---|
| Compliance records, documents, projects | Kept for as long as your account is open | 90 days, then deleted |
| Activity record | Kept for as long as your account is open | 180 days, then deleted |
| Your account and profile | Kept while open | Deleted with the organisation's data |
| Encrypted backups | See below | See below |
Why the activity record outlives the records themselves. It is the log of who did what and when, and it is the only thing that can answer "was this account misused?" after the fact. A security problem is often noticed months after it happened, and a log deleted on day 90 cannot help you establish what occurred. It holds no documents and no compliance data, only actions.
We are also required to dispose of it, not merely permitted to. Under APP 11.2 of the Australian Privacy Act we must destroy or de-identify personal information once it is no longer needed for any purpose the law permits, and RA 10173 requires that it not be kept longer than its purpose needs. The periods below are how we meet that in practice, which is why they are ceilings rather than targets.
Your own statutory obligation is longer than ours, and it is yours. Philippine tax and corporate rules require a business to preserve its books of accounts and supporting records for a defined period, and some of what you keep in CEDA is exactly that. That obligation sits with you, not with us, and the period is set by the BIR rather than by this policy, so we do not restate it here: a number written into a software company's retention policy is the wrong place for a reader to learn their tax obligations, and it would be out of date the first time the rule changed.
What this means practically: 90 days after cancellation is not long enough to serve as your archive, and it is not meant to be. Export before you cancel, and keep your own copy for as long as your accountant tells you to. If you need us to hold something longer, ask us before you cancel and we will agree it in writing.
Backups, stated plainly. As of this version, the database CEDA runs on is on a service tier that includes no scheduled backups, so there is no backup copy of your data and nothing survives deletion in one. That is the honest position today and it is not the position we want: enabling scheduled backups is planned before general availability, at which point deleted data will persist in an encrypted backup for the length of that window, unreachable in the product but not yet gone. When that changes, this section changes with it, and the version date at the top of this page tells you which is in force. A policy claiming instant and total erasure would be describing a system with no backups at all, which is not a system you would want holding your compliance history for long.
4. What we do not do
- We do not sell or share your records with third parties for their own purposes.
- We do not mine your records to build products for other customers.
- We do not keep your data to hold it hostage. Export is available before and after cancellation; see the Cancellation Policy.
5. Changes
If we shorten a retention period in a way that would delete data we currently hold, we will tell you before it takes effect and give you time to export.
Questions: [email protected]
Data deletion and liability
1. Three different things are called "delete"
Most complaints about deletion come from these being confused. CEDA names them separately.
Removing a record from your workspace
When you delete a compliance record, project or document inside CEDA, it is marked as removed and hidden. It stops appearing in lists, dashboards, reports and searches. It is retained in the underlying database.
This is deliberate. A compliance history that can be silently erased by one person is not evidence of anything, and a mis-click that destroyed a licence lineage would be unrecoverable.
We do not call this erasure, because it is not.
Erasing data on request
If you want data genuinely erased rather than hidden, ask us. Email [email protected] from an address on the account and tell us what you want erased. We will confirm what will go, then do it.
This is currently a manual process handled by a person, not a button in the product. We are saying so rather than describing a self-service feature we have not built yet. We will acknowledge your request within 15 days and complete it within 30 days, and if something makes that impossible we will tell you why and when it will be done rather than let the date pass quietly.
Closing the whole account
Cancelling ends your subscription; it is not the same as erasure. What happens to your data afterwards is in the Cancellation Policy and the Retention Policy.
2. Backups
As of this version, the database CEDA runs on is on a service tier that includes no scheduled backups. There is therefore no backup copy for erased data to survive in, and erasure is complete when we tell you it is done.
We are stating that as a fact about today rather than as a feature. Scheduled backups are planned before general availability, because a system holding your compliance history with no way to recover from a mistake or an outage is not one you should rely on long term. Once they are on, erased data will persist in an encrypted backup for the length of the backup window before being overwritten in the ordinary course, unreachable in the product and used for nothing. This section will be rewritten the day that happens, and the version date at the top of this page tells you which position is in force.
We would rather explain the mechanism than claim an instant and total erasure that no system with backups can honestly offer.
3. What we may have to keep
We may retain limited records after an erasure request where:
- a law requires us to keep them,
- they are needed to establish, exercise or defend a legal claim, or
- they are needed to resolve a dispute or enforce our agreement with you.
Where we keep records on one of these grounds we keep only what is necessary, and we restrict them from ordinary use.
4. Liability
Erasure is irreversible. Once data is erased at your request, we cannot bring it back. There is no undo, and no copy held aside for you.
Export first. Before asking for erasure, export anything you or your business may need later, including anything your own record-keeping obligations require you to hold. If you are unsure whether you are required to keep something, ask your accountant or lawyer before you ask us to erase it, not after.
We are not liable for loss arising from data erased at your request, including loss caused by your later inability to produce a record to a client, an agency or an auditor. This does not limit any liability that cannot be limited by law.
We are also not liable for data you delete inside the product where you have not asked us to erase it and the retention period has since expired. If you remove a record and then let your account lapse, the ordinary retention window applies to it like anything else.
5. Your rights are not affected
Nothing in this policy limits your rights under the Data Privacy Act of 2012 or the Australian Privacy Act 1988, including your right to have inaccurate data corrected (RA 10173; APP 13) and your right to erasure or blocking in the circumstances the Philippine Act provides. Both laws apply to CEDA at once, and where they differ we follow the stricter. See the Privacy Notice §6 for the full list of rights and §10 for how the two fit together.
Separately from anything you ask for, APP 11.2 obliges us to destroy or de-identify personal information once we no longer need it for any purpose the law permits. That duty runs on its own whether or not you ever make a request, and the schedule for it is the Data Retention Policy.
Erasure requests: [email protected]
Cancellation
1. During closed beta
CEDA is free for pilot firms, so there is nothing to cancel in a billing sense. What matters is what happens to your records, and you are entitled to a straight answer before you upload a single licence:
- You can leave whenever you like. Tell us and we will close the account.
- You can take your data with you. Ask and we will export your records and documents in a usable form.
- If CEDA does not launch, we will tell you, give you 60 days to export, and then delete your data. We will not quietly keep it.
- When your pilot ends, the same applies: notice, an export window, then deletion.
Nothing about the pilot obliges you to become a paying customer.
2. After launch, for paying subscriptions
Cancelling
You can cancel at any time from your account settings, or by emailing [email protected].
Cancellation takes effect at the end of the period you have already paid for. You keep full access until then, and we do not refund the remainder of that period.
We are saying it plainly because the alternative is worse than it sounds: an immediate cut-off with a pro-rata refund means the day you cancel is the day you lose access to your own compliance records, which is exactly the wrong moment to be locked out. Paying to the end of the period you already bought buys you the time to export properly.
After it takes effect
- Export window. Your account becomes read-only for 30 days. You can view and export everything; you cannot add or edit.
- Then deletion. At the end of that window your organisation's data is deleted in line with the Retention Policy.
- Backups age out separately, as described in the Deletion Policy §2.
Why a read-only window rather than an immediate cut-off: the realistic worst case is a contractor whose card fails in the middle of a PCAB renewal. Locking them out of their own licence history at that moment turns a billing problem into a compliance problem, and that is not a reasonable thing to do to somebody over an invoice.
Non-payment is not cancellation
If a payment fails we will contact you and retry. If it stays unpaid we may suspend access after 14 days. Suspension is not deletion: your data is intact and access is restored when payment succeeds. We will always tell you before a suspension becomes a deletion, and you will have an export window first.
Price changes
We will give 30 days notice before a price change affects you. If you do not want to continue at the new price, cancel before it takes effect and you will not be charged it.
3. If we cancel
We may suspend or close an account that is being used to break the law, to attack the service, or in breach of our terms. Except where the law or the seriousness of the breach makes it impossible, we will give notice and an opportunity to export first.
If we discontinue CEDA altogether, we will give 90 days notice and an export window before deleting anything.
4. What you keep
Your records are yours. Cancelling does not transfer ownership of anything to us, and we do not retain your business records for our own use after the retention period ends.
Cancellation and export requests: [email protected]
How CEDA is built
CEDA is a small, deliberate piece of software. No framework, no build step, no bundler: plain HTML, CSS and JavaScript served as files, with server-side work running at the edge. That keeps it fast on a site office connection and keeps the number of things that can break small.
The AI features inside CEDA use Google Gemini. It reads the documents you upload and proposes values for you to check. It never decides anything on its own, and nothing it proposes is saved until you accept it. How that works, and what it means for your documents, is set out in our AI use policy and Privacy Notice.
CEDA was built with the help of AI development tools, including Anthropic's Claude and OpenAI's ChatGPT. They were used the way a good contractor uses good equipment: to work faster and to catch mistakes. Every line was reviewed, every regulatory claim checked against the agency that issues it, and the decisions about how CEDA should behave were made by people who have watched Philippine contractors lose work to paperwork.
We mention it because we would rather say it than have you wonder.
Where it runs
Supabase holds the database and your documents. Cloudflare serves the site and runs the code behind our features. Both are named, with everything else, in our Privacy Notice.