← CDX website

Confidentiality, agreed before sharing.

Review the mutual NDA, confirm the parties and define the permitted purpose.

Questions or negotiated terms? info@cdx.net.au · cdx.net.au

Standard draft for review. This form cannot cover every project or jurisdiction. Obtain appropriate legal review before enabling it. Restricted information should not be shared until the agreement and access arrangements are accepted by both parties.

CDX party details

CDX contact: info@cdx.net.au

CDX’s contracting details are awaiting completion. Submission remains unavailable.

Read all 35 NDA clauses · CDX-MUTUAL-NDA-2026.3

1. Parties, purpose and formation

The parties identified in the agreement schedule intend to discuss, evaluate or deliver the project described in the permitted purpose. Each may disclose information to the other. This agreement becomes effective only when an authorised representative of each party has accepted the same version. Client submission records the client’s proposed acceptance; it does not automatically apply CDX’s signature. No party is required to disclose information, place an order or proceed with a project merely because this agreement is signed.

2. Confidential information

Confidential information means non-public information disclosed for the permitted purpose that is marked confidential or would reasonably be understood as confidential from its nature or circumstances. It may include drawings, CAD models, software, source data, product configurations, specifications, methods, pricing, supplier and customer details, business plans, personal information and derived notes or copies. The information may be written, visual, electronic or oral. Where an oral disclosure’s status is uncertain, the disclosing party should identify and confirm the confidential subject matter in writing.

3. Permitted use

The recipient may use confidential information only for the permitted purpose and to the extent reasonably necessary to perform that purpose. It must not exploit the information for an unrelated product, compete through misuse of protected material, disclose it for publicity or use it to train an AI model. This clause does not create a general restraint on lawful competition using independently developed or public information. Any additional permitted use must be agreed in writing by the disclosing party.

4. Care and safeguards

The recipient must protect the information with reasonable care and with at least the care it uses for comparable confidential information of its own. Access must be limited to authorised people with a need to know. Appropriate safeguards include controlled accounts, agreed transfer methods, restricted storage and prevention of accidental public publication. Each party should identify material subject to special legal, security or contractual controls before disclosure so suitable arrangements can be agreed.

5. Representatives and responsibility

Disclosure to employees, professional advisers and approved contractors is permitted only where necessary for the purpose and subject to confidentiality obligations appropriate to the information. The recipient must explain relevant restrictions and remains responsible for its representatives’ handling of information to the extent permitted by applicable law. A representative is not entitled to redistribute the information merely because it has access. The parties must agree any exceptions or onward-disclosure arrangements before the information is shared.

6. Offshore delivery and subprocessors

CDX uses Australian coordination and offshore production partners. That delivery model does not constitute blanket permission to transfer all confidential information overseas. Before restricted information is made available to an offshore team, the parties must confirm authorised recipient organisations or roles, countries, purpose, applicable restrictions and required safeguards in the project schedule or another written approval. If these matters are not agreed, disclosure requiring that approval must wait. Changes to agreed restricted locations or recipients require prior written consent.

7. AI, public platforms and demonstration work

Confidential project information must not be uploaded to public generative AI services, entered into the public CDX chatbot or published through website media tools. CDX’s client documentation is prepared by people using agreed production tools. Neither party may use the other party’s name, marks, project material or confidential results in marketing, a portfolio, training examples or demonstrations without separate written permission identifying the material and use. Public demonstration samples must not expose protected client information.

8. Excluded information

The confidentiality restrictions do not apply to information the recipient can demonstrate was lawfully public without breach, was lawfully known to it before disclosure, was independently developed without use of the protected information, or was lawfully received from another source without an applicable duty of confidence. The recipient should retain evidence supporting an exclusion. A compilation may remain confidential even where some individual elements are public, if the compilation itself is not public.

9. Required legal disclosure

If disclosure is required by law, a regulator or a court with lawful authority, the recipient may disclose only what is required. Where legally permitted and reasonably practicable, it must notify the disclosing party in advance and cooperate with reasonable protective steps at the disclosing party’s cost. Nothing in this agreement prevents lawful reporting of wrongdoing, protected disclosures, cooperation with regulators or the exercise of non-excludable rights.

10. Intellectual property and licences

Ownership of confidential information remains with its owner. Disclosure grants only the limited right to use it for the permitted purpose. It does not transfer patents, copyright, trade secrets, trademarks or other intellectual property. Ownership and licensing of paid project deliverables, background templates, software and third-party materials must be addressed in the separate engagement. The recipient must not remove proprietary notices or claim authorship of the other party’s protected material.

11. Authority to disclose and third-party restrictions

Each disclosing party must have authority to provide the information for the purpose and should identify relevant third-party restrictions before transfer. Neither party is required to receive material it cannot lawfully handle. If authority, licensing, export controls or permitted access are uncertain, the parties must pause the affected disclosure and resolve the issue. This agreement does not itself authorise export of controlled technical data or override another person’s intellectual property rights.

12. Personal information

Where personal information is involved, each party must comply with the privacy obligations applicable to it and the agreed purpose. Share only the minimum necessary information and agree any cross-border, security, retention and incident requirements before transfer. This NDA is not a complete data-processing agreement and does not by itself establish a lawful basis for every collection or international disclosure. Additional terms may be required for the particular project or jurisdiction.

13. Accuracy and technical reliance

Information disclosed during evaluation may be incomplete or preliminary. Unless separately agreed or required by law, disclosure under this NDA is not a warranty of technical accuracy, fitness for purpose or regulatory compliance. The recipient must confirm the appropriate approved source before relying on technical information for manufacture or operation. CDX’s standard preparation services do not provide engineering sign-off, certification or independent compliance determination. Nothing excludes a right or obligation that cannot lawfully be excluded.

14. Security incidents

The recipient must notify the disclosing party without undue delay after becoming aware of an actual or reasonably suspected unauthorised disclosure, loss or misuse affecting the information. The notice should describe known facts, affected material and containment steps without waiting for every detail to be established. The parties must cooperate reasonably in investigation, mitigation and any legally required notification. Neither party should make misleading assurances or conceal a known material incident.

15. Return, deletion and retained copies

On written request or when the purpose ends, the recipient must cease further use and return or securely delete confidential information as reasonably directed, subject to lawful retention requirements and agreed project records. It may retain information required by law, a genuine legal hold or necessary professional records, and residual backups not reasonably separable from routine backup systems. Retained copies remain protected, must not be used for an unrelated purpose and should expire under the applicable retention process. The parties may agree a practical written confirmation of completion.

16. Term and survival

Unless the schedule states another agreed period, this agreement covers disclosures made during three years from its effective date. Confidentiality and permitted-use obligations continue for five years after the last covered disclosure. Trade secrets remain protected for as long as they retain that character under applicable law. Personal information and legally retained copies remain subject to applicable legal obligations. The parties should review these periods against the sensitivity of their project before accepting the agreement.

17. Remedies and proportionality

Unauthorised disclosure may cause harm that is difficult to quantify. An affected party may seek remedies available under applicable law, including urgent protective relief where the legal requirements are met. This agreement does not guarantee that a court will grant an injunction or create an automatic penalty. Liability, causation, available defences and any separately agreed lawful limitations remain matters for the applicable law and the relevant agreements.

18. Notices and disputes

Routine notices should be sent to the business email addresses in the schedule or a replacement address notified in writing. A party raising a dispute should identify the issue and proposed resolution, and the parties should first attempt a good-faith discussion between authorised representatives where appropriate. This process does not prevent urgent relief, regulatory reporting or exercise of non-excludable rights. Any agreed mediation process should identify location, language and cost arrangements.

19. Governing law and international requirements

The governing law and forum must be identified in the CDX party schedule before this form is enabled. The parties should obtain advice where cross-border enforcement, mandatory local law, controlled information or consumer protections are relevant. A selected governing law does not necessarily displace mandatory obligations applying elsewhere. Do not accept this standard form if your project requires different jurisdiction, liability, security or confidentiality terms; request a negotiated agreement instead.

20. Changes, assignment and general provisions

Changes to this agreement must be recorded in writing and accepted by authorised representatives of both parties. Neither party may assign its rights or obligations without the other’s written consent except where applicable law permits otherwise. A delay in exercising a right is not a waiver. If a provision is unenforceable, the remaining provisions continue to the extent the law permits. This agreement concerns confidentiality and does not replace a statement of work, supply contract or approved technical specification.

21. Electronic acceptance and record

By submitting, the client representative confirms that the entered details are accurate, that they are authorised to act for the named client and that they intend to accept this agreement electronically, subject to CDX’s countersignature. The website records the signed-in account, typed name, role, acceptance time and exact agreement version. CDX’s authorised representative separately countersigns. Both parties receive access to the resulting copy; email dispatch depends on configured delivery services and does not replace the preserved agreement record.

22. Party identity, trusts and signing capacity

The agreement schedule must identify each actual contracting person or company. A trading name, website domain or email address alone is not the contracting entity. Where a party acts as trustee, the schedule must identify the trustee by its full legal name and identify the trust and the capacity in which the trustee acts. A corporate trustee should also identify its company registration and the relevant business registration. Each signatory confirms authority to bind the named party in the stated capacity. This clause does not create a personal guarantee by an employee or director merely because they sign for a company. Any proposed limitation of a trustee’s liability or recourse to trust assets must be expressly negotiated; it is not assumed from the use of a trust name. Changes of trustee or contracting party must be notified and documented before further restricted disclosures.

23. Disclosure schedule and information classification

Before transfer, the parties should record the project reference, permitted activities, source owner, information categories, intended users, approved systems and any heightened security requirements. Classification may distinguish public, internal, confidential and specially restricted material, without making a label essential to protection under clause 2. For CAD and technical work, the schedule should identify native models, drawings, bills of materials, calculation inputs, supplier information and any customer-owned material. Disclose only the portion reasonably needed for the purpose. If a recipient becomes aware that material appears more sensitive than the agreed arrangements permit, it must restrict access and ask for instructions. Prior disclosures are covered only where the parties expressly identify them in the accepted purpose or another mutually accepted written record; this template does not imply retrospective coverage of every earlier conversation.

24. CAD, drawings and technical file handling

Native CAD files, configurations, design tables, embedded properties, external references, suppressed features, hidden layers and model history can contain protected information even when a plotted drawing appears innocuous. The recipient must apply the confidentiality restrictions to these elements and to exports, renders, screenshots, mark-ups and derivative files. Before sending an authorised extract to another approved recipient, check that linked files and metadata do not disclose unrelated client information. The recipient must preserve agreed document numbers, revision references and proprietary notices where practicable. Conversion, redaction or removal of metadata must not silently alter engineering meaning or the controlled source record. A deliverable produced for review remains subject to the separate technical approval process; receipt of a confidential drawing is not authority to manufacture, operate or modify equipment.

25. Minimum access and account controls

Each recipient must use access controls proportionate to the information and the agreed purpose. People should use individually attributable accounts, strong authentication and multi-factor authentication where supported and appropriate. Shared access must be justified and controlled; passwords or access tokens must not be embedded in publicly accessible files or sent through the public chatbot. Grant the minimum necessary permissions, review them when team membership changes and remove access promptly when the need ends. Approved devices should receive supported security updates, use appropriate device protection and prevent unauthorised local access. These are contractual handling requirements, not a representation that either party holds a particular security certification or that the website supplies enterprise identity controls for every external tool.

26. Transfers, links and working copies

Use the agreed portal or another approved transfer channel for confidential material. Check recipients and permissions before sharing, avoid publicly accessible links, and apply expiry or revocation where the agreed system supports it. Encryption in transit and at rest should be appropriate to the sensitivity and available approved systems; any required cryptographic standard must be specified in the project arrangements. Do not copy information to personal email, personal cloud storage, removable media or unapproved collaboration platforms without written authorisation. Keep working copies to the reasonable minimum. Physical printouts must be secured and disposed of appropriately. If a misdirected message or exposed link is discovered, take prompt containment action and follow the incident obligations even if there is no confirmed download.

27. Offshore partner approval and changes

Approval of an offshore partner must identify the organisation or defined team, country of access, required information, work scope and confidentiality arrangements. Remote viewing from another country counts as access for the purposes of this agreement even if the main file remains hosted in Australia. The recipient must ensure approved subcontractors are bound by written obligations no less protective in substance for the material they receive and must not allow further subcontracting of restricted work without the required approval. Proposed changes to countries, partners or storage systems affecting agreed restrictions must be notified before access changes. If approval is refused or withdrawn, the parties must agree a lawful alternative, scope change or orderly suspension. Commercial convenience or the quoted hourly rate does not override confidentiality or export restrictions.

28. AI systems, analytics and automated tools

Neither party may submit the other’s confidential information, including excerpts, embeddings, prompts, screenshots or derived summaries, to a generative AI service or use it for model training, fine-tuning, evaluation or retrieval indexing without a separate written authorisation specifying the permitted system, purpose, retention, access and safeguards. CDX’s standard client documentation service is human-prepared; this NDA does not itself authorise an exception. Ordinary agreed CAD automation, document formatting and local scripts may be used for the purpose where they do not disclose information to an unapproved provider. Software telemetry, crash reports, plug-ins and cloud collaboration settings should be assessed for unintended disclosure. Public chatbot consent is not consent to process confidential project information and must not be treated as a substitute for project approval.

29. No reverse engineering or unrelated exploitation

Except to the extent expressly authorised for the permitted purpose or allowed by a right that cannot lawfully be restricted, the recipient must not reverse engineer, disassemble or analyse confidential samples, software or models to derive protected know-how for an unrelated purpose. It must not use confidential pricing, customer lists or supplier information to divert an identified opportunity through misuse of that information. The recipient must not apply to register intellectual property derived from the other party’s confidential information without authority. These restrictions do not prevent legitimate competition, independently developed work, general professional experience or lawful dealings with independently known contacts. There is no blanket non-compete or non-solicitation obligation under this NDA.

30. Derived work, residual knowledge and segregation

Notes, translated content, calculations, extracts, issue registers and compilations remain protected to the extent they contain or reveal confidential information. The recipient cannot avoid its obligations by paraphrasing material or claiming that a person remembers it without consulting a file. General skills and experience may be retained, but there is no licence to deliberately memorise or reconstruct protected designs, dimensions, processes or customer information for unrelated use. Keep project work identifiable and reasonably separated from other customers’ material to prevent accidental reuse. A generic template may be reused only if the separate engagement permits it and all protected project content has been removed. Ownership of new deliverables must still be settled in the engagement; confidentiality alone does not assign copyright.

31. Incident coordination and evidence preservation

Following an incident under clause 14, the recipient must promptly restrict affected access, preserve relevant logs and records where lawful, and avoid destroying evidence through indiscriminate deletion. Initial notice should identify the contact coordinating the response, the approximate discovery time, known information categories, affected systems and immediate safeguards. Provide material updates as the investigation develops and correct earlier information when necessary. Notify CDX at info@cdx.net.au using a clear security-incident subject; notify the client through the address in the accepted schedule. This mailbox is not represented as a continuously monitored emergency service. Neither party may delay a legally required notification while awaiting the other’s approval. External statements must be accurate and coordinated where practicable, without preventing lawful reporting or independent legal advice.

32. Assurance, records and proportionate review

On a reasonable written request relating to protected information, the recipient must provide a proportionate explanation of relevant safeguards, approved access arrangements and corrective steps. The parties may agree documentary evidence, questionnaires or a targeted independent review if the information risk justifies it. This clause does not grant unrestricted access to premises, source systems, credentials, privileged advice or another client’s confidential records. Any inspection must be separately agreed as to scope, notice, reviewer, confidentiality and costs, with suitable redaction and business-continuity safeguards. A refusal to disclose another client’s data is not itself evidence of breach. If a material concern remains unresolved, the parties should restrict further disclosure and agree an appropriate resolution before continuing the affected work.

33. Exit, retention register and deletion confirmation

When a return or deletion request is received, the recipient must identify relevant active copies, derived materials and approved representatives holding them. Unless a different period is agreed, it must acknowledge the request and propose a practical completion timetable within ten business days. It must then complete the agreed steps without unreasonable delay. Any retained category must have an identified reason, restricted access and an applicable review or expiry process. Backups retained under clause 15 must not be restored for ordinary project use after the purpose ends; if restored for genuine recovery, the relevant restrictions and deletion instructions must be reapplied. On reasonable request, an authorised representative must provide written confirmation describing completed steps and permitted exceptions. No party must falsely certify immediate erasure from systems where that cannot be verified.

34. Suspension, termination and continuing protection

Either party may end further disclosures under this NDA by written notice, without cancelling a separately agreed project engagement. A recipient must pause the affected handling if it cannot meet an agreed confidentiality condition, believes a transfer may be unlawful or discovers unauthorised access that requires containment. The parties must agree any resulting delivery or commercial changes under their engagement. Termination, completion, non-payment or a commercial dispute does not authorise disclosure, publication or unrelated use of confidential information. Return and retention obligations and the survival periods in clause 16 continue to apply. Confidential files must not be published as leverage in a payment dispute. Lawful preservation of evidence and confidential disclosure to authorised advisers remain subject to the applicable exceptions and safeguards.

35. Priority, electronic copies and pre-disclosure checklist

The accepted party and project schedules form part of this agreement. An express variation signed or electronically accepted by both authorised parties takes priority for the specific provision it varies. A purchase order, email footer, later website edit or unilateral policy change does not silently amend this NDA. Where another signed agreement imposes conflicting confidentiality requirements, the parties must resolve the conflict in writing before the affected disclosure; no automatic override is assumed. Counterparts may together form one agreement where permitted by applicable law. Download and retain the exact accepted copy and its reference. Before sharing, confirm legal identities, authorised signatories, permitted purpose, approved countries and recipients, applicable law, transfer method and any special retention or security terms. Website updates apply to new proposals only and do not alter preserved agreement snapshots.

Your client details

The copy will use your verified sign-in email: Sign in to continue.

Sign in to submit

Your agreements