OnDuty365 Privacy Policy
Last updated: 12 June 2026
1. Purpose and scope
This Privacy Policy explains how ONDUTY 365 PTY LTD (ABN 37 697 633 168, ACN 697 633 168) ("OnDuty365", "we", "us", "our") collects, uses, stores, discloses and protects personal information when you use the OnDuty365 platform: including our mobile app, web admin dashboard, and website at onduty365.com (collectively, the "Platform").
This policy applies to:
- Guard companies (our customers) and their administrators and supervisors who use the Platform to manage their workforce
- Security guards and other personnel whose data is processed through the Platform by their employer
- Individual security workers who sign up directly to the OnDuty365 marketplace (see section 4B)
- Visitors to our website at onduty365.com
We are committed to handling personal information in accordance with the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs), the Notifiable Data Breaches scheme, applicable state-based workplace surveillance laws, and the Spam Act 2003 (Cth).
2. Who we are
ONDUTY 365 PTY LTD is an Australian proprietary limited company registered on 30 April 2026 (ANZSIC 7000: Computer System Design and Related Services), trading as OnDuty365. We provide a workforce management platform purpose-built for the Australian security industry.
If you have any questions about this policy or how we handle your personal information, contact us using the details in section 21.
3. Data controller and data processor: who is responsible for what
OnDuty365 is primarily a business-to-business platform, and also operates a marketplace where individual security workers can sign up directly (see section 4B). Most personal information processed through the Platform belongs to employees of guard companies who use OnDuty365 to manage their workforce.
Under Australian law and consistent with internationally recognised data protection concepts:
- The guard company is the data controller for its employees' personal information. It decides what data is collected, why, and how long it is kept (subject to applicable law).
- OnDuty365 is the data processor. We process personal information on the guard company's instructions through the Platform's features and functionality. We do not use guard company employee data for our own purposes, except as strictly required to operate, secure, support, and improve the Platform.
When you are a guard or other employee of a guard company, you should also read your employer's privacy policy and any workplace monitoring notice provided to you. Your employer is your primary point of contact for access, correction, and deletion requests relating to data they have collected through the Platform. We will, however, assist where required by law.
For data we collect directly from guard company administrators (for account creation, billing, and support), and from website visitors, OnDuty365 is the data controller.
Where an individual security worker signs up to our marketplace directly (rather than being added by an employer), OnDuty365 is the entity that collects and is responsible for that worker's personal information under the Australian Privacy Principles. Section 4B sets out what we collect, the separate consents we ask for, how we display worker reputation to hiring businesses, and how long we keep the data.
4. What personal information we collect
We collect only the personal information necessary to provide the Platform. The categories below are exhaustive.
4.1 From guard company administrators, managers, and supervisors
- Full name, email address, phone number
- Employer (guard company) and role
- Login credentials (managed by our authentication system: we never store passwords in plain text)
- IP address, device type, browser, operating system, session data
- Records of your interactions with the Platform (audit logs)
4.2 From security guards and other personnel
- Full legal name (required for licensing and payroll compliance)
- Date of birth (collected only where your employer enables payroll or identity-verification features; where these are not enabled, date of birth is not collected or stored as a profile field, though it may appear as text extracted from an identity document you upload, see the note on document OCR below)
- Contact details: email, phone, residential address
- Security industry licence number, issuing state, and expiry date
- Employment status (active, inactive, terminated)
- Tax File Number (TFN): collected only when payroll integration is enabled and handled in accordance with the Privacy (Tax File Number) Rule 2015. We collect and use TFNs solely for payroll tax purposes and do not use TFNs to identify individuals for any other purpose.
- Bank account details: collected only when payroll integration is enabled
- Profile photo (avatar)
- Geo-location data: collected (i) at discrete events: shift sign-in, shift sign-out, each welfare check submission, and timestamp photo events; and (ii) at regular intervals (approximately every 60 seconds) while you are signed in to an active shift and the app is open, so your employer's administrators and supervisors can confirm on a live map that you remain at your assigned site. Location is collected only while you are signed in to a shift with the app in the foreground. It is not collected when you are off shift, and the app does not track your location in the background or when the app is closed. Live-location points are retained for a short period (currently 7 days) and the discrete-event points are retained with the related shift record.
- Sign-in and sign-out photos: captured at the start and end of each shift
- Welfare check photos: captured when an employee submits a welfare check
- Timestamp photos: captured at discrete events during a shift
- Welfare check responses (text and status)
- Incident report data: text descriptions, photographs, witness statements, time, and location
- Shift history: date, time, location, hours worked
- Document uploads: licences, certifications, training records, with associated expiry dates
- Push notification tokens (for the iOS and Android push-notification services)
- Device identifiers, app version, operating system version
When you or your employer upload an identity or licensing document (for example, a security licence), the document image may be processed by a specialist optical character recognition (OCR) subprocessor (see section 9) to extract text such as the licence number, name, and expiry date, to assist verification and speed up data entry. OCR is applied only to uploaded documents; it is never applied to your sign-in or sign-out selfie, and no facial recognition is performed (see section 4.5).
4.3 From client (guard company) accounts
- Business name, ABN, registered office address
- Operational site addresses and details
- Authorised contact persons
- Subscription, billing, and payment data (when payment integration is enabled)
4.4 From website visitors
- IP address, browser, device, referring URL
- Pages viewed and time spent
- Information you provide if you contact us via a web form or email
Where AI-assisted features are enabled on our website (for example, a website chat that helps with enquiries), the text of your messages is processed by our AI subprocessor (see section 9) to generate replies. Visitor messages are retained for the period set out in section 11. We do not use these messages to train any general-purpose AI model.
4.5 Sensitive biometric information: sign-in and sign-out selfies
Where your employer (the guard company) enables the optional sign-in selfie feature for its workforce, OnDuty365 captures a photograph of your face at the start, and where enabled at the end, of each shift. Because this photograph can be used to identify you and may include biometric information, it is treated as sensitive information under section 6 of the Privacy Act 1988 (Cth).
We collect this information only with your explicit consent (APP 3.3). Before the first selfie is captured, the app presents an in-app consent screen describing what is captured, why, who will see it, and how long it is kept. You may decline at the consent screen; if you decline, your shift sign-in still proceeds and an audit entry recording the decline is written. Your employer is notified through standard supervisor visibility but cannot retrospectively force capture of a declined selfie. Your employer may have its own workforce policies about attendance verification; those are a matter between you and your employer, and OnDuty365 is not a party to them. You may withdraw your consent at any time (APP 12.10) by contacting your employer's administrator or emailing support@onduty365.com; from the point of withdrawal, no further selfies will be captured for you and existing selfies will be deleted within 90 days of capture (except where preserved as evidence in an active incident investigation) in accordance with our standard retention schedule.
What is captured. A single still photograph from the device's front-facing camera, the timestamp of capture (device clock, recorded server-side on upload), and the GPS coordinates already collected at sign-in (see section 4.2). No video, no continuous monitoring, no facial-recognition matching against any external database. We do not generate or store a biometric template, vector, or hash of your face, and we do not use the photograph to train any machine-learning model.
Why we collect it. Proof of attendance for each shift, including verifying that the person physically present at the post is the licensed individual rostered to perform the shift. This supports your employer's duty-of-care obligations to its end clients and its obligations under state and territory security industry licensing regimes.
Who can see it. The employee who took the selfie (you), the supervisors assigned to the relevant site, and administrators of the guard company you work for. The photograph is not visible to other guards, other guard companies, end clients of the guard company, or any party outside the OnDuty365 service except the subprocessors disclosed in section 9 and only to the extent necessary to provide hosting and operational support.
Retention. Selfie photographs are automatically deleted 90 days after capture, except where preserved as evidence in an active incident investigation, in which case retention follows the rules in section 11 for incident reports. The 90-day window is enforced by an automated process; selfies are not stored beyond this period as a matter of routine.
Legal basis. Collection: APP 3.3 (consent to sensitive information collection) and APP 6.1(a) (use for the primary purpose for which it was collected). Notification: APP 5.1, satisfied by this policy and the in-app consent screen. Storage and security: APP 11. Access and correction: APP 12 and APP 13. Cross-border disclosure: APP 8, see section 10 of this policy.
4.6 AI-assisted features within the Platform
The Platform includes AI-assisted features that allow authorised users to query operational information using natural language and, where enabled by your employer, to receive responses informed by their recent usage patterns. These features are referred to collectively in this policy as "AI-assisted features".
What is processed when you use an AI-assisted feature.
- The text of your query
- A minimal context block describing your role and the categories of Platform data you are permitted to view, derived from your existing Platform records
- Where the relevant AI-assisted feature is configured to personalise responses, a short usage-pattern summary computed automatically from your prior queries
Who processes it. Queries and the minimal context block are sent to a third-party AI text-processing provider for response generation. That provider acts as our data processor under commercial terms that prohibit using customer content to train its general-purpose AI models. Where the optional in-app voice assistant is used, the text of the assistant's response is additionally sent to a specialist text-to-speech provider to generate the spoken audio (see section 9).
What is NOT done. AI-assisted features are not used to:
- Generate biometric templates, vectors, or any other identifying signature
- Make automated decisions that have legal or similarly significant effects on you without human review
- Train any machine-learning model on your personal information or your employer's data
- Knowingly process sensitive information (as defined in section 4.5) as part of a query
Retention. Conversation history is retained for the period set out in section 11. Where AI-assisted features generate a usage-pattern summary, that summary is stored as a per-user record that is replaced by each subsequent processing cycle and deleted on opt-out or account closure.
Opt out. Where your employer enables AI-assisted features for your role, you may opt out of AI-assisted processing on request through your employer's administrator or by contacting us at support@onduty365.com. We will record the opt-out preference and exclude your account from subsequent AI-assisted processing.
Legal basis. Collection: APP 3 (necessary to provide the AI-assisted features as instructed by the data controller). Notification: APP 5, satisfied by this policy and any in-app notice presented to you. Cross-border disclosure: APP 8, see section 10 of this policy. Subprocessor disclosure: see section 9.
4.7 Automated decision-making
OnDuty365 does not make decisions about you that have legal or similarly significant effects through fully automated means. AI-assisted features may summarise operational data and generate suggestions, but any decision that could significantly affect your rights or interests (for example, conduct, disciplinary, rostering-eligibility, or payroll decisions) is made by a person at your employer with appropriate authority.
The categories of personal information that may be used to generate AI-assisted summaries are: your role, the operational records you are permitted to view, and your prior queries to the assistant. You may opt out of AI-assisted processing as set out in section 4.6.
Where you use the marketplace, the automated matching and ranking of worker profiles is described in section 4B.7. As the Privacy Act's automated-decision-making transparency provisions commence (10 December 2026), we will expand this section to disclose the kinds of personal information used in, and the kinds of decisions substantially assisted by, any automated processing.
4.8A Assistive nature of AI-assisted outputs (cross-reference)
Outputs produced by the AI assistant, including any payroll, award-rate, or pay calculations it generates, are assistive tools designed to support human decision-making. Every action the assistant proposes requires explicit confirmation by the user, showing the exact details of what will be done. Users are responsible for reviewing those details before confirming. This policy does not extend any warranty or guarantee of accuracy in respect of AI-assisted outputs. See section 9.1 of our Terms of Service and our Disclaimer for the full liability position.
4.8 Health information (patient-watch and healthcare-site engagements)
Where your employer's engagement involves healthcare or patient-watch duties, an incident report or welfare note submitted through the Platform may incidentally contain health information about a third party (for example, a patient). Health information is sensitive information under the Privacy Act, and in some states is also regulated by dedicated health-records legislation, including the Health Records and Information Privacy Act 2002 (NSW), the Health Records Act 2001 (Vic), and the Health Records (Privacy and Access) Act 1997 (ACT).
The guard company (and, where applicable, the healthcare provider it serves) is the data controller for any such health information: it is responsible for the lawful basis to collect it and for meeting the applicable state health-privacy obligations. OnDuty365 processes this information only as a processor, on the guard company's instructions, and applies the security and retention controls in sections 11 and 12. Personnel should record only the health information strictly necessary for the incident or welfare purpose.
4.9 Social sign-in (Google and Apple)
You may create or sign in to your account using your existing Google or Apple account instead of a password. If you choose to do so:
- We receive from your chosen provider only your name, email address, and a provider-specific account identifier. We do not receive access to your contacts, calendar, files, or any other data held by that provider.
- We use that information only to create or authenticate your OnDuty365 account, and handle it in accordance with this policy in the same way as information collected directly from you.
- Password-based sign-in remains available at all times; you are not required to use a social sign-in method.
- Signing in with Google or Apple is also governed by Google's or Apple's own privacy policy and terms of service, which are separate from this policy. We encourage you to review them.
This feature is available only where enabled by your guard company administrator (for B2B accounts) or during direct marketplace sign-up (see section 4B). The identity provider's servers are located outside Australia; section 10 of this policy covers that cross-border disclosure.
Legal basis. Collection: APP 3.1 (the information is reasonably necessary to provide the Platform). Notification: APP 5, satisfied by this section. Cross-border disclosure: APP 8, see section 10.
4.10 Automated licence register verification
For security personnel required to hold a valid security industry licence, we verify the currency of that licence on a recurring basis, calibrated to risk, to confirm it has not expired, been suspended, or been cancelled since it was last checked. This is in addition to the initial check performed when a record is created.
What is checked. Your licence number, the name under which it was issued, and the relevant Australian state or territory. These are the details already held in your Platform record (section 4.2 and section 14).
How it is checked. We check the details you have supplied against official government licensing registers for the relevant state or territory (listed in section 14). Where a register is accessible by authorised automated query, we send only the minimum information needed (licence number and, where required, name and state) to confirm the record. Where a register cannot be checked automatically, a trained OnDuty365 administrator performs the same check manually using the same official public channels.
What we record. The outcome of each check: one of "current", "expired", "cancelled or not found", or "unable to verify". Each outcome is recorded with a timestamp. We do not record the full content of the register response beyond what is needed to record the outcome.
Why we do this. Rostering an unlicensed person to perform licensed security work is a breach of each state's security industry legislation. Ongoing verification is a condition of being rostered to licensed work through the Platform.
You are informed. This policy is the standing notification required under APP 5. Where the outcome of a check indicates a potential licensing issue, we notify the guard company administrator and you may also be notified through the Platform. If you believe a result is incorrect, contact us at support@onduty365.com; we will prompt a re-check and work with you and your employer to resolve it.
Retention. Verification check records are retained for the same period as the related licence record (section 11). Check records do not replace or override the official register; the authoritative record remains with the issuing regulator.
Legal basis. Collection and use: APP 3.1 (reasonably necessary to provide the compliance and licensing features of the Platform and to assist guard companies in meeting their legal obligations) and APP 6.1(a) (use for the primary purpose for which the licence information was collected). APP 9 (government related identifiers): use and disclosure are limited to the purposes in section 14. Notification: APP 5, satisfied by this policy.
4.11 Assistant behaviour profile
When you use the Platform's built-in AI assistant, we maintain one short personalisation record about you so the assistant can tailor its responses to how you work.
What it is. A single brief text summary (a few sentences) describing your general usage patterns, such as the kinds of questions you ask, the features you use most, the sites you most often work at, and your typical duty times.
What it is not.
- We do not store your assistant conversations. Each conversation starts fresh; the summary is the only thing that carries over.
- The summary never contains other people's personal information, your message contents, exact addresses, or pay amounts.
How it works.
- The summary is rebuilt periodically from limited usage metadata (for example, the names of actions you performed and your own duty sign-in times). Each rebuild replaces the previous summary in full; summaries are not accumulated over time.
- The rebuild is performed using a third-party artificial intelligence service, acting as our data processor under commercial terms that prohibit using customer content to train its general-purpose models. Only the limited metadata described above is processed for this purpose.
- The summary is stored with your account in our cloud database (section 9) and is readable only by you and by the assistant acting for you. It is never shared with other users, other employers, or used for marketing.
Your control.
- You can view the current summary at any time through your account settings.
- You can clear it at any time from the same screen. Clearing deletes the summary immediately. If you keep using the assistant, a new summary may be built from your later activity.
- The summary is deleted when your account is deleted.
Retention. The summary is overwritten by each subsequent processing cycle. It is deleted on account closure or on your request (section 16). See also section 11.
Legal basis. Collection: APP 3.1 (reasonably necessary to provide the personalised AI-assisted features as configured by the data controller). Notification: APP 5, satisfied by this section. Cross-border disclosure: APP 8, see sections 9 and 10.
5. How we collect personal information
We collect personal information:
- Directly from you: when you create an account (including when you sign up directly to the marketplace, see section 4B), log in, complete your profile, sign in to a duty, complete a welfare check, submit an incident report, or contact us
- From an identity provider you choose: when you use Google or Apple to sign in, we receive limited account information from that provider as described in section 4.9
- From your employer: when a guard company adds you as a guard, supervisor, or administrator, or uploads documents on your behalf
- From your device: geo-location, camera images, push notification tokens, device identifiers (only with the relevant operating system permissions you have granted)
- From official government licensing registers: when we carry out automated or manual licence verification as described in section 4.10
- Automatically: server logs, audit logs, cookies and similar technologies (see section 8)
Where lawful and practicable, we collect personal information directly from the individual it relates to. Where we receive personal information from a guard company about its employees, we rely on the guard company's representation that it has lawful authority to provide it to us.
Unsolicited personal information (APP 4)
If we receive personal information we did not solicit, we will determine within a reasonable period whether we could have collected it under APP 3. If not, we will destroy or de-identify it as soon as practicable, unless it would be unlawful or unreasonable to do so.
6. Why we collect personal information
We collect and use personal information for the following purposes:
- Workforce management: scheduling shifts, allocating guards to sites, real-time supervision
- Compliance: verifying that personnel hold valid security industry licences in the relevant Australian state or territory
- Duty of care: confirming a guard has arrived at their post (sign-in photo and GPS), is safe during their shift (welfare checks), and has completed their shift (sign-out)
- Incident management: recording incidents for client reporting, regulatory obligations, and evidentiary purposes
- Client SLAs: providing guard companies with proof of attendance and welfare for their end clients
- Payroll: calculating hours worked, processing pay (when payroll integration is enabled)
- Account administration: billing, subscription management, support
- Platform security and integrity: authentication, fraud detection, abuse prevention
- Legal obligations: responding to lawful requests from regulators, courts, and law enforcement
- Service improvement: diagnosing issues, improving features, in aggregated and de-identified form wherever possible
- AI-assisted features: providing AI-assisted natural-language queries over your permitted operational data, and personalising responses where your employer has enabled that (including maintaining a behaviour profile as described in section 4.11)
- Licence register verification: carrying out recurring automated and manual checks against official government licensing registers to confirm that security personnel remain licenced for the work to which they are rostered (section 4.10)
- Social sign-in: authenticating your account when you choose to sign in using a third-party identity provider (section 4.9)
- Communications: operational notices, security alerts, and (with your consent or where lawfully permitted) product updates
We do not sell personal information to anyone, ever.
7. Anonymity and pseudonymity (APP 2)
The nature of the Platform, security workforce management and licensing compliance, generally requires individuals to be identified. Anonymity is not practical for guards on shift, and pseudonymity would prevent us from meeting state security licensing obligations.
For website visitors and general enquiries, you may interact with us pseudonymously where practicable.
8. Cookies and similar technologies
Our website uses cookies and similar technologies for:
- Strictly necessary functions: keeping you logged in, remembering preferences
- Performance and analytics (when enabled): understanding how the website is used
- Security: protecting against fraud and abuse
Specific cookies / similar technologies we use:
- Authentication cookies (from our authentication system): strictly necessary, keeping you logged in
- A bot-management cookie (from our security and content-delivery provider): strictly necessary, security
- Anonymised session storage (when error-monitoring or analytics is enabled): performance, analytics
- No third-party advertising cookies
- No social-media cookies
You can disable cookies in your browser settings. Some Platform functions may not work correctly if you do.
9. Who we share personal information with
We share personal information only with the following categories of recipients, and only as necessary.
9.1 Subprocessors currently in use
| Subprocessor | Purpose | Data shared | Hosting location |
|---|---|---|---|
| Cloud hosting, database, and authentication provider | Database, authentication, file storage | All Platform data (encrypted at rest) | Singapore (primary). Migration to an Australian region is planned; we will update this policy when it completes. |
| Mobile push-notification services | Push notifications to iOS and Android devices | Push tokens, notification payloads | Global (primary United States, regional points of presence) |
| Mapping and geocoding provider | Address geocoding, mapping | Site addresses, GPS coordinates | United States |
| AI text-processing provider | AI-assisted response generation for natural-language queries within the Platform and on our website chat | Query text, role context, usage-pattern summary (where personalisation is enabled), visitor message text (for website chat) | Singapore (primary processing); global routing under the provider's commercial terms |
| Text-to-speech provider | Converting AI-assisted feature text responses into spoken audio for the optional in-app voice assistant | The text of the response to be spoken aloud | United States / global |
| Document OCR provider | Extracting text from identity and licensing documents you upload (for example, security licences) to assist verification and data entry | Images of uploaded identity / licensing documents only (never the sign-in or sign-out selfie) | United States / global |
9.2 Planned subprocessors (not yet enabled)
We disclose these in advance so you can make an informed decision about using the Platform. They are not currently active. We will update this policy and notify guard company administrators before enabling any of them.
| Subprocessor | Planned purpose | Anticipated data shared | Hosting location |
|---|---|---|---|
| SMS provider | SMS notifications | Phone number, SMS content | Australia and United States |
| Payments provider | Subscription payments | Billing contact, payment metadata | Australia and United States |
| Transactional email provider | Transactional email (account, security, operational) | Email address, message content | United States |
| Product analytics provider | Product analytics | Anonymised usage events, device metadata | United States or European Union (configurable) |
| Error-monitoring provider | Error monitoring | Error stack traces, anonymised user identifiers | Germany or United States (configurable) |
9.3 Other recipients
- Your employer: guard company administrators and supervisors can see data about their personnel within the Platform
- End clients of guard companies: where the guard company configures client reporting, limited duty, attendance, and incident data may be shared with that company's end client
- Subcontracted guard companies: where your employer subcontracts a duty to another guard company through the Platform, the receiving guard company will be shown the personal information necessary to manage the duty: your name, contact details, security licence number and expiry, and duty-related photos and welfare data. Receiving guard companies are required to handle this data in accordance with their own privacy obligations and only for the purpose of the specific subcontracted engagement.
- Official government licensing registers: when carrying out automated licence verification (section 4.10), we disclose your licence number and, where required by the register, your name and state, to the relevant government register channel. This is a disclosure to a government-regulated channel, not to a commercial third party.
- Professional advisers: lawyers, accountants, and auditors under confidentiality obligations
- Regulators and law enforcement: where lawfully required (e.g. state security licensing regulators, the OAIC, courts)
- Hiring businesses on the marketplace: where you have a marketplace worker account, your verified profile, work history, and ratings are shown to hiring businesses (including businesses you have not worked for) as described in section 4B, subject to your consent and your ability to hide your profile at any time
- A successor entity: in the event of a sale, merger, or restructure of OnDuty365, subject to equivalent privacy protections
10. Cross-border disclosure (APP 8)
The primary database and file storage that holds Platform data is currently hosted in our cloud infrastructure provider's Singapore region. Migration to an Australian region is planned, after which the primary processing region will be Australia. We will update this policy when the migration completes.
Some other subprocessors are also located outside Australia, as set out in section 9. By using the Platform, you acknowledge that personal information may be disclosed to overseas recipients in those jurisdictions.
For each overseas recipient, we take reasonable steps to ensure the recipient does not breach the APPs in relation to the personal information disclosed. These steps include:
- Selecting providers that contractually commit to data protection standards substantially similar to Australian law
- Contractual data processing terms restricting use to the purposes we have engaged them for
- Encryption in transit (TLS 1.2 or higher) for all data sent to overseas recipients
- Minimising the personal information disclosed to what is strictly necessary for the service
You should be aware that overseas recipients may be subject to laws in their own jurisdiction that could compel disclosure to foreign authorities, for example, the United States CLOUD Act. This is a residual legal risk that cannot be fully eliminated when using global cloud infrastructure.
11. How long we keep personal information
| Data category | Retention |
|---|---|
| Welfare check photos | 90 days, then automatically deleted, unless the photo is preserved as evidence for an incident or investigation (in which case it follows the incident-report retention rule below) |
| Sign-in and sign-out photos | 90 days, then automatically deleted, unless preserved as evidence for an incident or investigation |
| Timestamp photos | 90 days, then automatically deleted, unless preserved as evidence for an incident or investigation |
| Late-start justification photos and task-checklist photos | 90 days, then automatically deleted, unless preserved as evidence for an incident or investigation |
| Document uploads (licences, certifications, training records) | Retained until the guard company administrator deletes or replaces the record. When an administrator re-uploads a record, the previous version is permanently replaced. |
| Incident reports and attached evidence (including photos) | Retained while needed for the applicable limitation period or a legal claim (typically up to 7 years), then de-identified or destroyed |
| Shift records | Retained for the employer's record-keeping period (archived after 24 months), then de-identified or destroyed when no longer required by law |
| Audit logs | Retained for the period required for security and compliance, then de-identified or destroyed |
| AI-assisted feature conversation history (within the Platform) | 90 days, then automatically deleted unless preserved for an active investigation |
| AI-assisted feature usage-pattern summary (behaviour profile, section 4.11) | Overwritten by each subsequent processing cycle; deleted on opt-out, manual clear, or account closure |
| Website AI-assisted chat sessions (marketing site) | 12 months for support analysis, then automatically deleted |
| Licence register verification check records (section 4.10) | Retained for the same period as the related licence record; in any case no longer than 7 years, then destroyed or de-identified |
| Social sign-in provider identifier (section 4.9) | Retained for the life of the account; deleted when the account is deleted |
| Account data after a guard company terminates its subscription | 30 days, then permanent deletion, except where law requires longer retention |
| Marketplace worker profile after a subscription lapses or is cancelled | Hidden from hiring businesses immediately; full profile retained for a 90-day re-activation window; then the discovery profile (photo, bio, contact, identity-linked ratings) is deleted or de-identified (section 4B.6) |
| Marketplace engagement records and legally-required records | Held in a restricted store, kept no longer than the relevant limitation or record-keeping period and in any case no longer than 7 years, then destroyed or de-identified |
| Marketing contact data | Until you unsubscribe, then suppressed for compliance with the Spam Act |
We will keep personal information longer than the periods above only where retention is required by Australian law, necessary to defend a legal claim, or expressly directed by the data controller (the guard company) within the limits of the law.
12. How we secure personal information (APP 11)
We take reasonable steps to protect personal information from loss, misuse, interference, unauthorised access, modification, or disclosure. These steps include:
- Encryption at rest: for all data stored in our database and file storage
- Encryption in transit: TLS 1.2 or higher for all connections between client devices, our APIs, and our subprocessors
- Authentication: managed by our authentication system with secure password handling
- Access controls: row-level access controls so each guard company can only access its own data; principle of least privilege for OnDuty365 staff
- Audit logging: administrative and security-relevant actions are logged
- Secure development practices: code review, dependency monitoring, periodic security review
- Data minimisation: we collect only what is needed for the purposes in section 6
We do not provide end-to-end encryption (data is encrypted at rest and in transit, but is decryptable by us as needed to operate the Platform). No system is completely secure. If you believe your account has been compromised, contact us immediately.
13. Workplace monitoring transparency
The Platform includes features that constitute workplace surveillance under Australian law. Specifically:
- Location tracking: GPS coordinates at sign-in, sign-out, and welfare check submissions, and at regular intervals (approximately every 60 seconds) while an employee is signed in to an active shift with the app open (live location), shown to administrators and supervisors on a live map; not collected off shift, in the background, or when the app is closed
- Camera surveillance: sign-in, sign-out, welfare-check, and timestamp photos
- Device monitoring: device identifiers and app interaction logs
What's monitored, why, and who sees it
- GPS coordinates are captured at discrete events (sign-in, sign-out, welfare check submission, timestamp photo) and, while you are signed in to an active shift with the app open, at regular intervals of approximately 60 seconds so your position can be shown to your administrators and supervisors on a live map. Location is collected only during an active shift while the app is in the foreground; it is not collected off shift, in the background, or when the app is closed. Live-location points are retained for a short period (currently 7 days).
- Photos are taken at the same discrete events and visible to the same people.
- Device data (push tokens, app version, OS) is used for delivering notifications and diagnosing technical issues.
Notice obligations under workplace surveillance laws
Several Australian states and territories, most notably under the NSW Workplace Surveillance Act 2005 and the ACT Workplace Privacy Act 2011, require employers to give employees written notice before conducting workplace surveillance.
Because the guard company is the employer, the guard company is responsible for issuing this notice to its personnel and obtaining any required acknowledgements. To support our customers, we provide guidance and recommended language that guard companies can adapt for their own Workplace Monitoring Notice. Guard companies should obtain their own legal advice on the specific notice requirements applicable in each state or territory in which they operate.
Beyond NSW and the ACT, several states regulate the use of tracking devices through general surveillance-devices legislation, which can apply to GPS location tracking and may require consent: the Surveillance Devices Act 1999 (Vic), the Surveillance Devices Act 2016 (SA), the Surveillance Devices Act 1998 (WA), and the Surveillance Devices Act 2007 (NT). Queensland and Tasmania have no dedicated workplace-surveillance or surveillance-devices tracking statute, so monitoring there is governed by the Privacy Act and the common law. In every jurisdiction we recommend that guard companies provide a clear written monitoring notice and obtain appropriate consent before location tracking begins, and obtain their own legal advice on the specific requirements applicable in each state or territory in which they operate.
14. Government related identifiers (APP 9)
We collect and store security industry licence numbers issued by Australian state and territory regulators. These are government related identifiers under the Privacy Act.
We collect, store, use, and disclose these identifiers only for the purposes of:
- Verifying licensing status as required by state regulators
- Demonstrating compliance to guard companies' end clients where contractually required
- Producing records to regulators on lawful request
We acknowledge the regulators whose identifiers we may handle:
- South Australia: Consumer and Business Services
- Victoria: Licensing & Regulation Division (LRD)
- New South Wales: Security Licensing & Enforcement Directorate (SLED)
- Queensland: Office of Fair Trading
- Western Australia: WA Police Licensing Services
- Tasmania: Department of Justice
- Northern Territory: NT Police Licensing
- Australian Capital Territory: Access Canberra
These licences are issued under each jurisdiction's security industry legislation, including the Security and Investigation Industry Act 1995 (SA), the Security Industry Act 1997 (NSW), the Security Providers Act 1993 (Qld), and the Private Security Act 2004 (Vic), and the equivalent legislation in the other states and territories.
We do not adopt these identifiers as our own identifier of an individual.
15. Direct marketing and the Spam Act (APP 7)
We will only send you marketing communications where:
- You have opted in, or
- You are an existing customer or contact and the communication is directly related to the Platform, and you have a clear and easy way to opt out
Every marketing email we send includes an unsubscribe link. You can also email us at hello@onduty365.com to unsubscribe at any time. We maintain a suppression list to honour unsubscribe requests in compliance with the Spam Act 2003.
We do not use guard or employee data (collected via the Platform on behalf of a guard company) for our own marketing purposes.
16. Your rights
You have the right to:
- Access the personal information we hold about you (APP 12)
- Correct personal information that is inaccurate, out of date, incomplete, irrelevant, or misleading (APP 13)
- Request deletion of your personal information, subject to legal retention obligations
- Withdraw consent for any processing that relies on your consent
- Opt out of marketing at any time (see section 15)
- Make a complaint about how we handle your personal information (see section 19)
How to exercise your rights
To exercise any of these rights, email support@onduty365.com. Where you are an employee of a guard company, we may direct you to your employer first, since your employer is the data controller for most of your data.
We aim to respond to access and correction requests within 30 days. We do not charge a fee for reasonable requests. If a request is unusually complex or involves significant cost, we will let you know in advance.
We may need to verify your identity before acting on a request, for example, by confirming details through your registered Platform email.
Account deletion: important note for guard employees
If you are a guard or other employee using the Platform on behalf of your employer (the guard company), please note:
- You can request personal data removal (your name, photos, location history, contact details).
- You cannot unilaterally delete shift records: these are employer records that the guard company is required to retain under the Fair Work Act and other applicable laws (typically 7 years).
- The "Delete account" function in the mobile app sends a request to your employer's administrators, who will action it in accordance with their legal obligations.
- If your employer fails to action a lawful deletion request within a reasonable time, you may contact us directly at support@onduty365.com and we will assist where required by law.
For guard company administrators and direct OnDuty365 customers, account deletion is available from the in-app Settings menu.
If you are an individual marketplace worker, you can request deletion of your personal information directly, and we will action it as described in section 4B.6, subject to any records we are required to keep by law.
17. Children
The Platform is not directed at children under 13. Security industry licensing in Australia generally requires applicants to be 18 or older.
If we become aware that an individual under 18 has been added to the Platform without our customer's lawful basis, we will:
- Restrict access to that data
- Notify the guard company administrator
- Take reasonable steps to obtain appropriate consent or remove the data
If you believe a child has provided personal information to the Platform, contact us at support@onduty365.com and we will take immediate action.
18. Notifiable Data Breaches
We comply with the Notifiable Data Breaches (NDB) scheme under Part IIIC of the Privacy Act.
Where we have reasonable grounds to suspect that an eligible data breach may have occurred, we will carry out a reasonable and expeditious assessment and take all reasonable steps to complete that assessment within 30 days of becoming aware of the grounds for suspicion (Privacy Act s 26WH).
If we become aware of an eligible data breach, a breach that is likely to result in serious harm to one or more individuals, we will:
- Promptly investigate and contain the breach
- Notify affected individuals
- Notify the Office of the Australian Information Commissioner (OAIC)
- Provide recommendations on steps individuals can take to protect themselves
Serious harm in this context includes financial loss, identity theft, reputational damage, emotional or psychological harm, and physical safety risks. The physical safety dimension is particularly relevant for security personnel whose location and shift data could be misused if disclosed without authorisation.
Where a data breach affects guard company employees and the guard company is the data controller, we will notify the guard company without undue delay so it can meet its own NDB obligations, and we will support the guard company's response.
19. Complaints
If you believe we have breached this policy or the Australian Privacy Principles, please contact us first at support@onduty365.com with the details of your complaint. We will acknowledge your complaint within 5 business days and aim to resolve it within 30 days.
If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (OAIC):
- Website: oaic.gov.au
- Phone: 1300 363 992
- Mail: GPO Box 5288, Sydney NSW 2001
20. Changes to this policy
We may update this policy from time to time. The "Last updated" date at the top of the policy indicates when it was most recently changed.
For material changes, for example, adding a new subprocessor, expanding the categories of personal information collected, or changing retention periods, we will notify guard company administrators by email and within the Platform, and update this policy at least 14 days before the change takes effect, unless a shorter notice period is required by law or necessary for security.
Continued use of the Platform after a change takes effect constitutes acceptance of the updated policy.
21. Contact us
ONDUTY 365 PTY LTD (ABN 37 697 633 168) Trading as OnDuty365
- Privacy, access, deletion, complaints: support@onduty365.com
- General enquiries: hello@onduty365.com
- Phone: +61 439 074 245
22. Data linked to your identity
The following categories of personal information are linked to your identity:
- Identifiers: User ID, email address
- Contact info: name, email, phone, residential address
- Location: precise location at sign-in, sign-out, welfare check submissions, and timestamp photo events, and at regular intervals (approximately every 60 seconds) while signed in to an active shift with the app open (live location); not collected off shift, in the background, or when the app is closed
- User content: photos (sign-in, sign-out, welfare check, timestamp, incident report), incident report text, welfare check responses, chat messages
- Sensitive info: security industry licence numbers (government related identifier under APP 9); biometric photographs (sign-in / sign-out selfies, where enabled by your employer - see section 4.5)
- Financial info: Tax File Number and bank account details (when payroll integration is enabled; handled under the Privacy (Tax File Number) Rule 2015)
- Diagnostics: crash logs, performance data (when error monitoring is enabled)
- Usage data: anonymised product analytics events (when analytics is enabled)
- AI-assisted feature data: text of natural-language queries to AI-assisted features, role-context blocks sent with those queries, and (where personalisation is enabled) usage-pattern summaries computed automatically from your prior queries (section 4.11)
- Licence verification records: outcomes and timestamps of automated and manual licence register checks (section 4.10)
- Social sign-in identifiers: provider-specific account identifier received when you sign in with Google or Apple (section 4.9)
We do not use any data for tracking across other apps or websites. We do not sell personal information. We do not share personal information for advertising or marketing by third parties.
This section corresponds to the privacy disclosures required by the Apple App Store ("App Privacy") and Google Play Store ("Data Safety") listings for the OnDuty365 mobile app.