Privacy Policy
1. Who we are
AuditM8 is operated by Hassan Rasheid Foreman (sole trader, trading as AuditM8), ABN 60 485 410 398, Queensland, Australia. We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles.
2. Two kinds of information
It matters which of these we're talking about, because our role differs.
| Type | Examples | Our role |
|---|---|---|
| Your account information | Your name, work email, organisation name, plan, billing status | We decide how this is handled. |
| Content you upload | Worker certificates, screening checks, policies, rosters, incident records — which may include personal information about your workers and participants | We process it on your instructions. You control it and remain responsible for it. |
3. What we collect and why
Account and billing
Name, email, organisation details, and subscription status — to create your account, provide the service, send service emails, and take payment. Card details are handled by Stripe and never reach our servers.
Content you upload
Documents and records you choose to upload, so the service can read, organise, track and present them back to you. Document content is sent to our AI sub-processor solely to extract proposed details (document type, person, dates). Nothing extracted counts as verified until a human in your organisation confirms it.
Expiry reminder emails
If enabled, we email your nominated address a digest of credentials and policies approaching their due date. That email includes worker names and dates. You can change the frequency or turn it off in the app.
4. Analytics — what we measure and what we don't
We measure usage so we can understand what's working. We want to be specific about it.
Our own first-party analytics
- Cookieless. We do not set tracking cookies for analytics. Identifiers are randomly generated and held only for the browsing session.
- No fingerprinting and no cross-site tracking. We cannot follow you to other websites, and we don't try.
- We record: pages visited (with any identifiers stripped from the address), approximate time on page, referring site, and a fixed list of product actions such as "generated an audit pack".
- Website analytics are not linked to any individual person. In-app analytics are linked to your account so we can tell whether the product is actually being used.
- Analytics records are deleted after 400 days.
- Analytics data is never used to make decisions about your compliance. It never affects your readiness score, your evidence, or your billing.
- On our marketing website we honour the Do Not Track browser setting and collect nothing if it is on.
Google Analytics
Our marketing website also uses Google Analytics 4 to measure visits. You can opt out with Google's browser add-on. Google Analytics is not used inside the application.
5. Who else touches your data (sub-processors)
| Provider | Purpose | Where |
|---|---|---|
| Supabase | Database, authentication, file storage | Australia (Sydney) |
| Cloudflare | Website and application hosting, bot protection | Global edge network |
| Anthropic | AI reading of uploaded documents | United States |
| Stripe | Payment processing | Australia / United States |
| Resend | Sending expiry reminder emails | United States |
| Google Analytics | Marketing website measurement only | United States |
Document content is sent to Anthropic in the United States for AI extraction. It is not used to train their models. Your stored records remain in Australia.
We do not sell personal information, and we do not disclose it for advertising.
6. Security
- Encryption in transit and at rest.
- Database-level access rules that separate each organisation's data.
- Optional multi-factor authentication for owners and administrators.
- Bot protection on sign-in and sign-up.
- An internal audit log of significant actions.
No system is perfectly secure. If a data breach occurs that is likely to cause serious harm, we will notify affected customers and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme.
7. How long we keep things
- Your content: for as long as your organisation has an account, and after cancellation until you ask us to delete it.
- Analytics: 400 days, then deleted automatically.
- Billing records: as long as Australian tax law requires.
8. Your rights
You may ask us to access, correct, export or delete personal information we hold about you. Email hello@auditm8.au and we will respond within 30 days. There is no charge for a reasonable request.
If your worker or participant asks about information you have uploaded, that request should generally come to you as the organisation that controls it — but tell us and we will help you action it.
9. Complaints
If you think we have mishandled your personal information, contact us first at hello@auditm8.au. We will investigate and respond within 30 days. If you are not satisfied, you may complain to the Office of the Australian Information Commissioner at oaic.gov.au or 1300 363 992.
10. Changes
We may update this policy. Material changes will be notified by email or in the app at least 30 days before taking effect. The version number and effective date at the top of this page always show the current version.
11. Contact
AuditM8 — Privacy
Email: hello@auditm8.au