1. Overview

FirstAidLog Pty Ltd ("we", "us", "our") operates FirstAidLog ("the Service"). We are committed to protecting your personal information in accordance with the Australian Privacy Principles (APPs) contained in the Privacy Act 1988 (Cth) and applicable workplace health and safety legislation.

This policy explains what information we collect, why we collect it, how we use, store, and protect it, and your rights regarding your data. It applies to all users of the FirstAidLog web and mobile applications.

2. Information We Collect

2.1 Account Information

DataPurposeLegal Basis
Full nameDisplay name, audit trailAccount registration (APP 3)
Email addressAuthentication, notifications, reportsAccount registration (APP 3)
Password (hashed)AuthenticationAccount registration (APP 3)
Organisation name & ABNMulti-tenancy, access control, complianceOrganisation setup (APP 3)
Role assignmentPermission enforcementOrganisation admin action (APP 6)

2.2 Operational Data (including Health Information)

Under the Privacy Act 1988, health information is classified as sensitive information (s6(1)), requiring explicit consent for collection (APP 3.3), higher protection standards (APP 11), and restrictions on disclosure (APP 6.2(a)).

DataPurposeProtection
Kit inventories (items, quantities, expiry dates)Core service functionalityRLS + TLS
Incident reports (patient info, injury details)WHS record-keepingAES-256-GCM field-level encryption
Witness statements & first aider detailsWHS compliance, legal recordsAES-256-GCM field-level encryption
Psychological harm detailsNotifiable incident reportingAES-256-GCM field-level encryption
Inspection records (checklist results)Compliance trackingRLS + TLS
Training records (certificate numbers, qualifications)Training managementRLS + TLS
Location data (GPS coordinates, when permitted)Kit location, auto-fillUser-controlled permission

2.3 Lead Capture Data

Certain public tools collect limited information from non-registered visitors:

SourceData CollectedPurpose
Compliance calculatorEmail, state, worker countDeliver detailed results
Compliance audit toolEmail, state, audit scoreDeliver audit report
Inspector directoryName, email, messageFacilitate inspector contact
Blog & guide CTAsEmailDeliver requested resource

Lead data is stored in our database and used only to deliver the requested service and occasional product updates. You may opt out of follow-up communications at any time.

2.4 Inspector Directory Data

Inspectors who opt in to the public directory voluntarily publish:

2.5 Technical Data

3. How We Use Your Information (APP 6)

We only use or disclose personal information for the primary purpose for which it was collected, or a directly related secondary purpose you would reasonably expect:

We will never sell, rent, or trade your personal information to any third party.

4. Third-Party Services (APP 8)

We use the following third-party processors. All are bound by data processing agreements:

ServicePurposeData Centre RegionData Sent
SupabaseDatabase, authentication, storageAustralia (Sydney)All application data
VercelWeb hosting, API, CDNAustralia (Sydney), global edgeRequest/response data
SentryError monitoringUSError context (no PII)
Zoho MailTransactional emails (SMTP)AustraliaRecipient email, report content
StripePayment processingUS/AUPayment method, billing email
XeroAccounting integration (optional)AU/NZOrganisation name, contact, invoice items
QuickBooks Online (coming soon)Planned accounting integrationUS/AUOrganisation name, contact, estimate items if enabled in future
Google Analytics (GA4)Website analytics (public site only)USPage views, anonymised usage (no PII)

OAuth token security: Xero OAuth tokens, and QuickBooks OAuth tokens if that integration is enabled in future, are encrypted at rest using AES-256-GCM before storage. They are never stored in plaintext.

We do not sell, rent, or trade your personal information to any third party.

5. Data Storage & Security (APP 11)

We take reasonable steps to protect personal information from misuse, interference, loss, unauthorised access, modification, and disclosure:

6. Data Retention (APP 11.2)

We retain personal information only for as long as necessary to fulfil the purposes for which it was collected, or as required by law:

Data TypeRetention PeriodLegal Requirement
Active account dataDuration of account + 30 days after deletionOperational necessity
Incident reports (serious injury)30 yearsWHS Act 2011 s274(d)
Incident reports (general)Minimum 5 yearsWHS Regulations
Inspection records5 yearsWHS Regulations
Training recordsEmployment + 7 yearsFair Work Act / Tax obligations
Audit logs7 yearsBest practice / tax obligations
Financial records7 yearsTax obligations
Lead capture data2 years from collectionOperational
Error logs (Sentry)90 daysOperational
Backups7 days rollingDisaster recovery

An automated retention policy enforces these periods. When retention periods expire, data is anonymised (aggregate statistics preserved) rather than deleted, except where full deletion is required.

7. Your Rights (APPs 12 & 13)

Under the Australian Privacy Principles, you have the right to:

To exercise any of these rights, email us at privacy@firstaidlog.com. We will respond within 30 days.

8. Collection Notice (APP 5)

When you create an incident report, you will be shown a Collection Notice explaining:

You must accept the Collection Notice before submitting personal health information. Consent can be withdrawn at any time by contacting us.

9. Cookies & Tracking

Application (firstaidlog.com)

Public website (landing pages, blog, tools)

10. Children's Privacy

FirstAidLog is designed for workplace use and is not intended for children under 16. We do not knowingly collect information from children. If you believe a child has provided us personal information, please contact us and we will delete it promptly.

11. International Data Transfers (APP 8)

Your primary data is stored in Supabase's Australian (Sydney, ap-southeast-2) region. Some processing occurs internationally:

ServiceRegionSafeguards
StripeUS/AUPCI-DSS Level 1, SCCs
SentryUSSOC 2 Type II, no PII transmitted
Vercel (edge CDN)GlobalSOC 2 Type II, edge caching only
QuickBooks Online (coming soon)US/AUSOC 1 & 2, user-initiated only if enabled in future
Google AnalyticsUSAnonymised data only, no PII

All international transfers are governed by appropriate safeguards, data processing agreements, and the transferee's privacy obligations under APP 8.1.

12. Notifiable Data Breaches (NDB Scheme)

In the event of an eligible data breach, we will:

Our internal Notifiable Data Breach Response Plan details our assessment, containment, notification, and review procedures.

13. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email or in-app notice at least 14 days before taking effect. The "Last updated" date at the top will always reflect the current version.

14. Contact

For privacy-related enquiries:

Privacy Officer
FirstAidLog Pty Ltd
Email: privacy@firstaidlog.com
Queensland, Australia

If you are not satisfied with our response, you may lodge a complaint with the OAIC.