Privacy Policy
Draft for legal review, structured against the Australian Privacy Principles (Privacy Act 1988 (Cth)). Placeholders in [square brackets] must be completed by the operator.
1. Who we are (APP 1)
[Operator legal name] (ABN [ABN]) operates this platform. Contact: [privacy contact email]. This policy explains what personal information we handle, why, and how you can access or correct it.
2. What we collect (APP 3)
- Account information — name, email address, hashed password, second-factor enrolment, session metadata (IP address, browser), and the time you accepted these terms.
- Workspace content you enter — documents, registers, assessments, evidence files, incident and training records. This may include personal information about your workers, contractors and contacts, which you control and we hold on your behalf.
- Connected systems — if you connect Google Workspace or Microsoft 365, file metadata and, where you enable directory sync, workforce names and email addresses.
- Operational records — an append-only audit log of sensitive actions, and logs needed to run and secure the service.
We do not use tracking or advertising cookies. Session cookies are required to sign in.
3. Why we handle it (APP 6)
To provide the platform, authenticate you, keep records you are legally required to keep, secure the service, support you, and bill you. We do not sell personal information, and we do not use your workspace content to train AI models.
4. Overseas disclosure (APP 8)
Data is hosted in Australia ([region]) on Google Cloud. AI features are served from an Australian region. Where a sub-processor operates outside Australia, it is listed in the Data Processing Addendum with the country and purpose. [Confirm and complete the list.]
5. Security (APP 11.1)
- Encryption in transit and at rest; files served only through short-lived signed URLs.
- Separation of every organisation's data at the database level (row-level security), tested per release.
- Mandatory second factor for administrative roles; shared rate limiting on authentication.
- Credentials for connected systems stored in a managed secret store, never in the database.
- An append-only audit log of sensitive actions.
6. Retention and destruction (APP 11.2)
We keep workspace content while your account is active. You can export everything at any time in an integrity-verifiable archive and request destruction from within the product. A different active owner must approve the request; destruction then runs after a 7-day grace period and removes database records, stored files and stored credentials for connected systems. Failed external deletion steps are retried before database records are removed. The append-only audit log is retained as the tamper-evident record of what happened, including of the deletion, for 12 months from the date of each entry, after which entries are destroyed automatically. We may pause a pending deletion only where a documented legal or regulatory preservation obligation applies; the reason and release of that hold are recorded and shown to the workspace.
7. Access and correction (APP 12, 13)
Your own account details are editable in the product. For workspace content held on behalf of your employer, ask your organisation's workspace administrator; if you are that administrator, the export and deletion tools are in Settings. Otherwise contact us at [privacy contact email] and we will respond within 30 days.
8. Data breaches
We maintain an incident response process. Where an eligible data breach is likely to result in serious harm we notify affected individuals and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme, and we notify affected customers without undue delay.
9. Complaints
Contact [privacy contact email] first. If you are not satisfied you may complain to the Office of the Australian Information Commissioner (oaic.gov.au).