DDDI One
Privacy Policy
Effective 28 August 2026 · Last updated 1 September 2026
This Privacy Policy explains how DDDI Group Pty Ltd ("DDDI", "we", "us" or "our") collects, uses, stores and discloses personal information through DDDI One.
This page covers the DDDI One mobile app only. The public DDDI Group website is covered by our separate website privacy policy.
1. Introduction
App name: DDDI One.
Operating entity: DDDI Group Pty Ltd.
DDDI One is the unified mobile app built on DDDI OS and is the main mobile entry point to DDDI Group's digital ecosystem. It is currently intended primarily for employees' day-to-day work.
Current user roles: employees, managers and site personnel.
DDDI OS uses unified identity, single sign-on at the platform level, and access control based on company, department, position, project and specific permissions. After sign-in, DDDI One shows workspaces according to the user's identity and permissions. Different companies, projects and roles have permission boundaries; users may only view data they are authorised to access.
We handle personal information in accordance with applicable Australian privacy law, including the Privacy Act 1988 (Cth) and the Australian Privacy Principles where they apply.
2. Information we collect
2.1 Account and identity information
Sign-in method (current app): account name and password. The app supports remembering a password and changing a password. Authentication tokens are generally valid for about seven days. We have not identified biometric login, OAuth or an in-app SSO implementation in the current app client.
- account name, work email and related account details;
- company, department, position, projects, role and permissions;
- sign-in / sign-out and session information; and
- authentication and access-control records.
Whether the app collects a profile avatar or employee number has not been confirmed at the time of publication.
If you choose to remember credentials, the password is stored in iOS Keychain or Android Keystore; the email address may be stored in local app preferences (for example SharedPreferences on Android).
2.2 Business and user-provided information
Depending on role and features used, DDDI One may process personal information in:
- projects, people, customers, suppliers and subcontractors;
- orders, contracts, files, expenses and tasks;
- training records, site records and site photos; and
- content submitted to AI-assisted features.
2.3 Device permissions, photos and EXIF / GPS
Declared device permissions may include camera, photo-library read/write, microphone and location-related declarations. The microphone is not actively used in the current app. Location-related declarations are mainly associated with reading photo EXIF metadata; the app does not perform active real-time location tracking.
Original images are uploaded as whole files to object storage. The current code has not been found to strip EXIF, so original images may retain EXIF / GPS metadata. The current upload flow does not actively write separate latitude / longitude fields (they default to zero).
2.4 Technical and log information
We may collect device and app information, permission status, session data, timestamps, errors and activity logs. Business operation logging includes finance system logs / approval records and CPM activity logs.
2.5 Information we do not collect (current app assessment)
- no third-party crash SDK identified (for example Firebase Crashlytics or Sentry);
- no third-party analytics SDK identified (for example Firebase Analytics or Mixpanel);
- no biometric login, OAuth or in-app SSO implementation identified;
- no active use of the microphone;
- no active real-time GPS tracking (beyond possible EXIF in original photos).
3. How we use information
We use personal information to:
- verify identity and control access / permissions;
- manage projects, tasks, approvals and workflows;
- manage files, knowledge, expenses, payments and training;
- support site records and operational messaging / system notifications;
- provide AI-assisted document, quotation, email and finance features;
- secure systems, investigate incidents and troubleshoot faults; and
- meet legal and record-keeping obligations.
4. Data sharing and third-party services
We may share information within DDDI Group with authorised personnel, with service providers that support hosting, storage, communications, security, document processing and AI features, where required by law, or with your consent. We do not sell personal information.
4.1 Confirmed providers and processing
- Object storage: Alibaba Cloud OSS. The app obtains a signed upload via
POST /v1/files/oss-signand uploads directly. The configured OSS region is not confirmed at publication. - AI processing: the app does not connect directly to OpenAI, Gemini or similar model APIs. It calls DDDI's own backend. Data that may be sent for AI features includes invoice image / document URLs, quotation files / images, and email subject and body. Results may be saved in business systems (for example quotation
result_json, emailai_result_json, extracted finance fields). Whether AI providers use data for model training is not confirmed. The AI service provider identity is not confirmed. - Crash / analytics SDKs: none identified in the current app assessment.
4.2 Not confirmed at publication
The following items from our technical inventory remain blank until confirmed, and are therefore not named on this page: cloud hosting provider and region; push notification provider / region / data; OCR provider / region / data; email delivery provider / region / data; map provider / region / data.
5. Data storage and security
- Transport: HTTPS. App Store configuration declares use of standard system HTTPS (
ITSAppUsesNonExemptEncryption = false). - Device credentials: passwords in iOS Keychain / Android Keystore; email may be in local preferences.
- Access control: company, department, position, project and permission boundaries.
- Business logs: finance system logs / approval records and CPM activity logs.
- Server-side at-rest encryption method, unified security audit platform, backup frequency and backup retention period are not confirmed at publication.
6. Data retention and deletion
We keep personal information for as long as needed for the purposes in this policy, for legitimate business and operational needs, and to meet legal, accounting, construction, WHS and record-keeping obligations.
Fixed retention periods for account data, project / site data, finance data, training / WHS data and logs are not confirmed at publication. In general, account and access data is kept while an account is active and for a reasonable period afterwards; project, site, finance, training, safety and audit records may need to be retained after a user stops using the app because they are company business records.
When information is no longer required, we take reasonable steps to delete or de-identify it, subject to technical, legal and business-record requirements.
6.1 Account deletion path
The current app has no in-app self-service account deletion option. Users can sign out, which clears local credentials. Accounts are administered by DDDI backend administrators.
To request account closure or deletion of personal information, contact your DDDI account administrator or email info@dddi.com.au. We may verify identity and authority before acting. A fixed response time limit for privacy / deletion requests is not confirmed at publication; we will respond within a reasonable period under applicable law.
7. Your rights
Subject to applicable law, you may ask us to:
- access personal information we hold about you;
- correct inaccurate, incomplete or out-of-date information;
- delete personal information or close your account; and
- withdraw device permissions in your device settings.
These rights align with the access, correction and deletion rights described in the DDDI Group website privacy policy. Send requests to the contacts in section 12. If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner.
8. Children's privacy
DDDI One is a workplace application and is not directed to children. If we learn that information about a child has been collected through the app without an appropriate lawful basis, we will take reasonable steps to delete or otherwise address it.
9. Cross-border data transfers
Some technology providers may store or process information outside Australia, depending on configured service regions. Specific hosting and processing regions for several providers are not confirmed at publication. Where personal information is disclosed overseas, we take reasonable steps required by applicable Australian privacy law. Contact us for current location details once confirmed.
10. Cookies and analytics
DDDI One is a mobile app. The current app assessment found no third-party analytics SDK. If you open a DDDI website from the app or elsewhere, that website may use cookies for traffic analysis and to improve user experience, as described in the DDDI Group website privacy policy.
11. Changes to this policy
We may update this policy when DDDI One, our providers or legal requirements change. Updated versions will be published at this URL with a revised "Last updated" date. A dedicated in-app privacy-policy change notification mechanism is not currently implemented; depending on the change, we may also use email or another appropriate workplace channel.
12. Contact us
- Company: DDDI Group Pty Ltd
- Privacy email: info@dddi.com.au
- Website: https://dddi.com.au/
- Address: L2/135 Fullarton Rd, Rose Park, SA 5067, Australia
- Phone: +61 8 7110 0999
