Privacy Policy
Last updated: March 2026
Summary
Protocol Labs (ABN 49 634 013 629), trading as AxionSite (referred to as "AxionSite", "we", "us", "our") is committed to protecting your personal information. We comply with the Australian Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs), and applicable 2026 amendments including automated decision-making transparency requirements. We do not sell your personal information. Primary data is stored in Australia. By accessing or using our website, platform, or services you acknowledge you have read this policy and consent to the collection, use, and disclosure of information as described herein.
1. Who We Are and Scope
This Privacy Policy ("Policy") applies to Protocol Labs (ABN 49 634 013 629), a sole trader business trading as AxionSite. It describes how we collect, hold, use, disclose, and safeguard personal information when you visit our website at axionsite.com, use our platform, mobile applications, APIs, or any related services (collectively, the "Service"). This Policy applies to all visitors, prospective customers, registered users, administrators, and any individual whose personal information we process in connection with the Service. If you provide us with personal information of third parties (e.g. worker details for SWMS sign-on rosters), you warrant that you have obtained their consent or are otherwise authorised to provide that information and that you have made this Policy available to them.
To the extent that additional privacy laws apply to our processing of your information (for example, the General Data Protection Regulation for individuals in the EEA/UK, or the New Zealand Privacy Act 2020), we will comply with those laws where applicable.
2. Information We Collect
2.1 Information you provide directly
(a) Account and identity information — full name, email address, phone number, company or trading name, ABN/ACN, job title, and similar details provided during registration or profile updates.
(b) Content and operational data — any data, text, descriptions, images, or materials you input into the Service, including task descriptions, site addresses, hazard information, worker names, and photo uploads ("Customer Data").
(c) Payment and billing information — billing address, company details, and payment method details processed by our PCI-compliant payment provider (Stripe). We do not store full card numbers on our systems.
(d) Communications — records of correspondence when you contact us via email, our contact form, or any support channel.
(e) Feedback and survey data — responses to optional surveys, product feedback, feature requests, or reviews you choose to provide.
2.2 Information collected automatically
(a) Usage and log data — pages visited, features used, actions taken, timestamps, session duration, referral URLs, and interaction patterns.
(b) Device and technical data — IP address, browser type and version, operating system, device type, screen resolution, language preference, and unique device identifiers.
(c) Cookies and tracking technologies — we use cookies, pixels, local storage, and similar technologies. See Section 11 and our Cookie Policy for full details.
(d) Analytics data — aggregated and pseudonymised data collected via Google Tag Manager, analytics services, and our own internal instrumentation to understand how the Service is used and to improve performance.
2.3 Information from third parties
We may receive information from third-party sources such as identity verification services, publicly available business registries (e.g. ASIC, ABR), marketing partners, and social login providers (e.g. Google), which we combine with information we already hold to maintain accurate records and improve the Service.
2.4 Sensitive information
We generally do not request sensitive information (as defined in the Privacy Act) such as health information, racial or ethnic origin, political opinions, or biometric data. If you voluntarily include sensitive information in Content you submit (e.g. worker medical clearances in uploaded documents), you consent to our collection and handling of that information for the purpose of providing the Service.
3. How We Use Your Information
We use personal information for the following purposes:
(a) Providing the Service — to operate, maintain, and deliver the features of the Service, including generating permits, SWMS, JHA, toolbox talks, and related WHS compliance materials; processing sign-on/off rosters; and providing customer support.
(b) Account management — to create and manage your account, process payments, send invoices, and manage subscriptions.
(c) Service communications — to send transactional emails (e.g. account verification, password resets, export confirmations, billing receipts) and service announcements.
(d) Marketing — with your consent or where permitted by law, to send promotional communications about new features, product updates, industry content, and offers. You may opt out of marketing communications at any time using the unsubscribe link in any email or by contacting us.
(e) Product improvement and analytics — to analyse usage patterns, diagnose technical issues, conduct A/B testing, measure feature adoption, and improve the functionality, usability, reliability, and performance of the Service.
(f) AI and machine learning — to train, improve, fine-tune, and develop our AI models and algorithms using aggregated, anonymised, or de-identified data derived from usage of the Service. This may include analysis of prompt patterns, output quality, and interaction flows to improve the accuracy, relevance, and safety of AI-generated content. We do not use individually identifiable Customer Data to train AI models for purposes unrelated to providing or improving the Service, unless you have given us explicit consent.
(g) Benchmarking and research — to produce aggregated, anonymised industry benchmarks, compliance trend reports, safety statistics, and research insights. Such aggregated data will not identify any individual or organisation.
(h) Security and fraud prevention — to detect, investigate, and prevent fraudulent, unauthorised, or illegal activity, and to protect the rights, safety, and property of AxionSite and its users.
(i) Legal compliance — to comply with applicable laws, regulations, legal processes, or enforceable governmental requests, and to enforce our Terms of Service and other agreements.
(j) Other purposes — for other purposes described at the time of collection, with your consent, or as otherwise permitted or required by law.
4. Legal Basis for Processing
Under the Australian Privacy Principles, we collect and process personal information where it is reasonably necessary for, or directly related to, one or more of our functions or activities (APP 3). In addition, where the GDPR or similar overseas legislation applies, our legal bases include: (a) performance of a contract (providing the Service); (b) legitimate interests (product improvement, security, analytics, and direct marketing to existing customers); (c) your consent (marketing communications, optional data sharing); and (d) legal obligation (compliance with laws and regulations).
5. Automated Decision-Making
In accordance with the Privacy and Other Legislation Amendment Act 2024 (Cth) amendments to APP 1, which take effect from 10 December 2026, we disclose the following:
The Service uses computer programs — including artificial intelligence, machine learning models, and rule-based logic — to generate WHS compliance documents (permits, SWMS, JHA, toolbox talks, risk matrices) based on information you provide. These automated processes analyse your inputs (task description, site details, industry, state/territory) to produce tailored outputs.
Kinds of personal information used: task and site descriptions, state/territory, industry, worker names (for sign-on rosters), and uploaded site photographs.
Types of decisions: content generation (selection of applicable hazards, controls, legislation references, PPE requirements, emergency procedures); risk-level assessments; and document formatting. These automated outputs are designed as drafts that must be reviewed and verified by a competent person before workplace use. They do not make decisions that directly and solely determine legal rights, employment, or financial outcomes for individuals.
6. Disclosure and Sharing
We do not sell your personal information. We may disclose personal information in the following circumstances:
(a) Service providers and sub-processors — trusted vendors who assist us in operating the Service, including cloud hosting (Google Cloud / Firebase — Australian regions), payment processing (Stripe), email delivery (Resend), AI processing (OpenAI — subject to a data processing agreement that prohibits use of your data for model training), analytics, and customer support tools. These providers are contractually bound to protect your information and use it only for the purposes we specify.
(b) Legal and regulatory — where required or authorised by law, court order, subpoena, or government authority; where we reasonably believe disclosure is necessary to protect the rights, property, or safety of AxionSite, our users, or the public; or in connection with the investigation or prevention of fraud or illegal activity.
(c) Corporate transactions — in connection with a merger, acquisition, sale of assets, corporate restructuring, or similar transaction, subject to the successor entity being bound by privacy obligations at least as protective as this Policy.
(d) Professional advisors — to our lawyers, accountants, auditors, and insurers where necessary for them to provide professional services to us.
(e) With your consent — for any other purpose you have agreed to.
(f) Aggregated and anonymised data — we may share aggregated, anonymised, or de-identified data that does not identify any individual or organisation with any third party, including for industry research, benchmarking, and marketing purposes. Such data is not personal information.
7. Overseas Disclosure
Primary application data and Customer Data are stored in Australia. Some of our sub-processors may store or process personal information outside Australia, including in the United States (e.g. OpenAI for AI processing, Stripe for payment processing, Resend for email delivery, Vercel for edge hosting). Where we disclose personal information overseas, we take reasonable steps to ensure recipients comply with privacy standards comparable to the APPs (APP 8), including by entering into data processing agreements, standard contractual clauses, or relying on comparable privacy frameworks. You consent to such overseas disclosure where it is necessary for the operation and delivery of the Service. You may contact us for a current list of countries in which recipients are likely to be located.
8. Data Storage and Security
We implement technical and organisational measures appropriate to the risk to protect personal information against unauthorised access, alteration, disclosure, destruction, and loss. These measures include, but are not limited to:
(a) encryption of data in transit (TLS 1.2+) and at rest (AES-256); (b) role-based access controls and least-privilege principles; (c) multi-factor authentication for administrative access; (d) regular security assessments and penetration testing; (e) secure software development lifecycle practices; (f) incident response and disaster recovery procedures; and (g) employee security awareness training.
No method of electronic transmission or storage is 100% secure. While we strive to use commercially acceptable means to protect your personal information, we cannot guarantee absolute security. In the event of a data breach that is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) as required under the Notifiable Data Breaches (NDB) scheme in Part IIIC of the Privacy Act, as soon as practicable and in any event within the timeframes required by law.
9. Data Retention
We retain personal information for as long as reasonably necessary to: (a) provide the Service and fulfil the purposes described in this Policy; (b) comply with legal, tax, audit, accounting, and regulatory obligations; (c) resolve disputes and enforce agreements; and (d) maintain immutable audit trails where required for WHS compliance (e.g. sign-on/off records).
When you close your account or request deletion, we will delete or de-identify your personal information within 90 days, except where we are required or permitted to retain it by law or for legitimate business purposes (e.g. backup archives that are overwritten on a rolling schedule, legal holds, or records required under WHS legislation). Aggregated and anonymised data that does not identify you may be retained indefinitely for analytics, benchmarking, and product improvement.
10. Your Rights
10.1 Access and correction (APP 12 & 13)
You have the right to request access to the personal information we hold about you and to request correction of any information that is inaccurate, incomplete, out of date, or misleading. You can update much of your account information directly in the Service. For access or correction requests, contact us using the details in Section 15. We will respond within a reasonable time (generally within 30 days) and may need to verify your identity. We may refuse access in limited circumstances permitted by law and will provide reasons if we do.
10.2 Deletion and de-identification
You may request that we delete or de-identify your personal information. We will comply where we are not required to retain the information by law or for legitimate business purposes. Some information may persist in encrypted backups for a limited period before being overwritten.
10.3 Marketing opt-out
You may opt out of direct marketing at any time by clicking the unsubscribe link in any marketing email, updating your preferences in the Service, or contacting us. We will process your opt-out request promptly, and in any event within 5 business days.
10.4 Data portability
On request, we will provide you with a copy of your Customer Data in a commonly used, machine-readable format (e.g. CSV or JSON) within a reasonable time.
10.5 Additional rights
If the GDPR or other privacy legislation applies to you, you may have additional rights such as the right to restriction of processing, the right to object, and the right to lodge a complaint with a supervisory authority. Contact us to exercise any of these rights.
12. Direct Marketing
We may use your personal information to send you direct marketing communications about our products, services, features, and events where: (a) you have consented; or (b) you are an existing customer and the communication relates to similar products or services, and we provide a simple opt-out mechanism in each communication (in accordance with the Spam Act 2003 (Cth) and APP 7). We will not provide your personal information to unrelated third parties for their direct marketing purposes without your express consent.
13. Children's Privacy
The Service is not directed at individuals under 18 years of age. We do not knowingly collect personal information from children. If we become aware that we have collected personal information from a child without appropriate consent, we will take steps to delete that information promptly.
14. Third-Party Links and Services
The Service may contain links to third-party websites, services, or resources that are not operated by us. We are not responsible for the privacy practices, content, or security of any third-party sites. We encourage you to review the privacy policies of any third-party services you access through or in connection with the Service.
15. Complaints and Contact
If you believe we have breached the Australian Privacy Principles or this Policy, please contact us first so we can investigate and try to resolve your concern. We will acknowledge your complaint within 5 business days and provide a substantive response within 30 days.
If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC):
Website: oaic.gov.au
Phone: 1300 363 992
For all privacy-related enquiries, access or correction requests, deletion requests, or complaints, contact us via our Contact page or at the contact details published on our website. Protocol Labs (ABN 49 634 013 629), trading as AxionSite, Sydney, New South Wales, Australia.
16. Changes to This Policy
We may update this Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will post the updated Policy on this page and update the "Last updated" date. For material changes that reduce your rights or expand our use of your information, we will provide at least 30 days' notice via email or prominent in-product notification before the changes take effect. Your continued use of the Service after the effective date of the updated Policy constitutes your acceptance of the changes. If you do not agree with the updated Policy, you must stop using the Service and may request deletion of your information.