1. Overview

TenThirtyFour Pty Ltd ("we", "us") operates FirstAidLog. We are committed to protecting your personal information in accordance with the Australian Privacy Principles (APPs) contained in the Privacy Act 1988 (Cth).

This policy explains what information we collect, why we collect it, how we use and store it, and your rights regarding your data.

2. Information We Collect

2.1 Account Information

DataPurposeBasis
Full nameDisplay name, audit trailAccount registration
Email addressAuthentication, notifications, reportsAccount registration
Password (hashed)AuthenticationAccount registration
Organisation nameMulti-tenancy, access controlOrganisation setup
Role assignmentPermission enforcementOrganisation admin action

2.2 Operational Data

DataPurpose
Kit inventories (items, quantities, expiry dates)Core service functionality
Incident reports (patient info, injury details, witness statements)WHS record-keeping
Inspection records (checklist results, environment checks)Compliance tracking
Training records (certificate numbers, qualifications, expiry dates)Training management
Photos (uploaded by users)Evidence for incidents/inspections
Location data (GPS coordinates, when permitted by user)Kit location, auto-fill

2.3 Technical Data

3. How We Use Your Information

4. Third-Party Services

We use the following third-party processors. All are bound by data processing agreements:

ServicePurposeData Centre Region
SupabaseDatabase, authentication, storage, real-timeAustralia (Sydney)
VercelWeb hosting, CDNGlobal edge, primary US
SentryError monitoring, performanceEU (Frankfurt)
Zoho MailTransactional emails (SMTP)Australia
StripePayment processing (subscription billing)US/AU

We do not sell, rent, or trade your personal information to any third party.

5. Data Storage & Security

6. Data Retention

Data TypeRetention Period
Active account dataDuration of account + 30 days after deletion
Incident reportsMinimum 5 years (WHS record-keeping requirement)
Inspection recordsMinimum 5 years
Audit logs2 years
Error logs (Sentry)90 days
Backups30 days rolling

7. Your Rights

Under the Australian Privacy Principles, you have the right to:

To exercise any of these rights, email us at privacy@firstaidlog.com. We will respond within 30 days.

8. Cookies & Tracking

The web version of FirstAidLog uses:

9. Children's Privacy

FirstAidLog is designed for workplace use and is not intended for children under 16. We do not knowingly collect information from children. If you believe a child has provided us personal information, please contact us and we will delete it promptly.

10. International Data Transfers

Your primary data is stored in Supabase's Australian (Sydney) region. Some processing occurs internationally via Vercel (CDN) and Sentry (EU). All international transfers are governed by appropriate safeguards and data processing agreements.

11. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email or in-app notice at least 14 days before taking effect. The "Last updated" date at the top will always reflect the current version.

12. Contact

For privacy-related enquiries:

Privacy Officer
TenThirtyFour Pty Ltd
Email: privacy@firstaidlog.com
Queensland, Australia