Privacy Policy

Last updated: [DATE] · Operated by [LEGAL ENTITY NAME], [ABN/ACN]

This is a template. Complete every [BRACKETED] item and have it reviewed by a lawyer in your jurisdiction before relying on it.

This policy explains what personal information [LEGAL ENTITY NAME] ("we") collects when you use this preventative-maintenance compliance service ("the Service"), why we collect it, who it is shared with, and what you can do about it.

1. Who the information belongs to

The Service is used by trade contracting businesses to record maintenance and compliance work. Two distinct groups appear in it:

For the second group we act as a processor: the contracting business decides what is entered and why, and is the controller of that information. Requests about site or client records should be directed to the business that entered them.

2. What we collect

CategoryDetailsWhy
AccountName, email address, password (stored only as a hash), roleTo create and secure your account
SessionA first-party cookie holding a session identifierTo keep you signed in
Business detailsTrading and legal name, licence number, address, phone, contact email, logoTo place on the certificates you issue
Site recordsSite names and addresses, client names, service schedules, notes, identifiers from your job systemTo schedule and evidence the work
Visit recordsDate, technician name and email, checklist results, measurements, defectsTo produce the compliance record
Photographs and signaturesImages captured on site, including a customer's signature where takenEvidence attached to the visit
Integration credentialsAPI keys and OAuth tokens for your job system and cloud storageTo create jobs and file report copies
InvitationsEmail address and a single-use tokenTo let you add colleagues

We do not use tracking or advertising cookies, and we do not run third-party analytics in the application.

3. How it is protected

4. Who else receives it

The Service passes information to the providers you connect, and to the infrastructure it runs on:

RecipientWhat is sent
DigitalOcean, Sydney, AustraliaAll application data, at rest and in transit
[EMAIL PROVIDER]Recipient address and message content for invitations and reminder digests
Your job-management system (e.g. Fergus), if connectedJob details and a completion note containing the date, technician, pass/fail counts and a link
Your cloud storage (Google Drive, Dropbox, OneDrive), if connectedA copy of each report filed into your own folders
DigitalOcean, Sydney, Australia (stored on the same server as the application)Photographs, signatures and generated certificates

We do not sell personal information, and we do not disclose it to anyone else except where required by law.

5. Where it is stored

Data is hosted in Australia, in DigitalOcean’s Sydney data centre. If you connect a cloud-storage or job-management provider, copies also reside wherever that provider stores them, under their terms.

6. How long we keep it

Compliance records are kept for as long as your organisation keeps its account, because they are the evidence your clients and insurers may need years later. [STATE YOUR RETENTION PERIOD AND WHAT HAPPENS AFTER CLOSURE — e.g. deleted within 90 days of account closure, subject to any legal obligation to retain.] Invitations expire automatically and unused tokens become invalid.

7. Your rights

You may ask us to access, correct or delete the personal information we hold about you, and to provide it in a portable form. Where we hold that information on behalf of a contracting business, we will refer your request to them. Contact us at [PRIVACY CONTACT EMAIL]. If you are not satisfied with our response you may complain to [RELEVANT PRIVACY REGULATOR].

8. Changes

If we change this policy we will update the date at the top and, for material changes, notify account holders by email.