1. Who we are
Decision Keep is operated by Growpay Technologies Pty Ltd (ACN 656 964 180), trading as Decision Keep. Decision Keep is the independent, tamper-evident witness for automated decisions. We provide a self-hosted ledger that records, signs and lets your auditors verify the automated decisions your organisation makes. This policy explains what personal information we handle, how, and your rights.
2. Automated decision-making. what we disclose (APP 1.7–1.9)
From 10 December 2026, the Australian Privacy Act 1988 (Cth) requires APP entities to disclose, in their privacy policy, how they use automated decision-making (ADM). Decision Keep is a system that records and evidences ADM on your behalf. The disclosures below satisfy APP 1.7, 1.8 and 1.9.
2.1 Kinds of personal information used (APP 1.8)
When an organisation pipes a decision through Decision Keep, each record stores the inputs needed to evidence it: the system that made the decision (e.g. Salesforce, Oracle, SAP), the agent or model, the version, the decision type, the payload (the inputs to the decision), and governance metadata such as confidence, risk, routing outcome and the human verifier identifier where a person was involved. Raw payloads always remain under the organisation's own control; only a cryptographic fingerprint of the content is retained in the public record so the content is never exposed.
2.2 Decisions made solely by automated processes (APP 1.8)
For a decision with a AUTONOMOUS routing outcome, no human reviewed or overrode it before it took effect. it was made solely by automated means. The record captures this explicitly so the organisation can disclose exactly which of its decisions fall into this category. Where an Australian law or a code binding on the organisation requires a human to be involved, the organisation must not rely on a purely automated decision in that context.
2.3 Decisions where automation plays a substantial role (APP 1.8)
For a decision with an ASSISTED or ESCALATED routing outcome, a human was in the loop, but automation still played a substantial role in supporting that human's decision. for example by scoring risk, recommending an action, or surfacing the inputs. The record stores the routing outcome and rationale, and the human verifier's identifier, so the organisation can clearly explain to the public the substantial part automation played.
2.4 Meaningful information about the logic used (APP 1.9)
Each receipt proves exactly when (the signed timestamp) and by what version a decision was made, who or what triggered it, and the routing outcome. The content hash lets your auditors confirm the recorded inputs were exactly as submitted, without revealing the raw payload. This is the meaningful information about the logic used, available on request and via the public verifier.
3. How we handle your information
- Account & waitlist data: the email you provide to join the waitlist or create an account, plus your consent choices recorded at sign-up (see Section 5).
- Decision records: stored and signed with your organisation's own key. Content remains on infrastructure you control in the self-hosted deployment.
- Security (APP 11): each organisation has its own key; erasure is cryptographic and preserves the record anchor.
4. Your rights
You may request access to, correction of, or erasure of your personal information (Privacy Act APP 12–13; GDPR Art. 15–17 where applicable). Erased decision content is cryptographically removed while the chain anchor is preserved for integrity. To make a request, contact the organisation operating your Decision Keep instance, or contact us.
5. Consent and marketing
When you join the waitlist you are asked to accept this Privacy Policy and our Terms of Service. That consent is recorded with a timestamp and the policy version you accepted. Separately, and only if you opt in, we may send you product updates. You can withdraw marketing consent at any time using the unsubscribe link in any message, and withdrawing it does not affect the lawfulness of processing carried out beforehand.
5A. Website analytics & marketing (public site only)
On our public marketing pages only (the home page, waitlist, sign-up and login, and the public verifier), we use a third-party analytics and lead-identification service, Octolane AI (cdn.octolane.com / ingest.octolane.com), to understand anonymous site traffic and to route interested visitors to our team. This script is never loaded on the authenticated, data-sensitive routes (the ledger, settings, API and audit surfaces), and our Content Security Policy blocks those hosts there as well. As a result, no decision, receipt or evidence content is ever transmitted to Octolane or any other third party. the evidence stays sovereign to your infrastructure.
If you prefer not to be measured on the public site, you can block third-party scripts with a browser extension or privacy setting; doing so does not affect the product. Octolane processes this analytics data in the United States; it receives only anonymous, non-evidence web-traffic signals (no decision, receipt or ledger content), so no regulated personal information about individuals recorded in your ledger is transferred.
6. Data breach notification
Because the ledger never exposes raw decision content and the evidence stays on infrastructure you control, the record itself is not a notifiable-breach vector for the decisions you record. Where a personal-data breach affecting you does occur, Growpay Technologies Pty Ltd (trading as Decision Keep) will notify affected individuals and the Office of the Australian Information Commissioner without undue delay where required by the Notifiable Data Breaches scheme (APP 11) and, where the GDPR applies, within 72 hours under Article 33. Notification arrangements for managed plans are set out in the Data Processing Addendum (security page).
7. Contact
Questions about this policy or our handling of personal information can be sent to us. Enterprise customers can request a Data Processing Addendum and our SOC 2 control mapping from the security page. If you are unsatisfied with our response, you may complain to the Office of the Australian Information Commissioner (OAIC).