Privacy Policy
This policy explains how All Passive Services Pty Ltd ("APS", "we", "us") collects, uses, stores, discloses and protects personal information through the All Passive Services mobile app (iOS and Android) and the APS staff portal at admin.allpassiveservices.com.au (together, "the Service"). We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles.
The Service is a business tool for recording passive fire protection inspections and installations. It is used by APS staff and technicians, and by the businesses that engage them. It is not intended for the general public or for children.
1. Information we collect
Account information. Accounts are created by an administrator, not by public sign-up. For each user we hold: name, email address, user name, role and permissions, the Australian state you work in, optional phone number and employee ID, an optional profile photo, and a securely hashed password (we never store your password in readable form).
Work records you create. Projects, client and site details (business names, addresses and contact people), inspection and installation records, notes, product and test-report selections, floor-plan markers, and the photographs you take or choose to attach. Each record notes who created or changed it and when.
Photographs. The app uses your device camera, or your photo library, only when you choose to take or attach a photo. It does not access your camera or photos at any other time, and it does not record video or audio.
Security and technical information. Sign-in times, failed sign-in attempts, the app version and device type (iPhone or Android), your IP address as seen by our server, and an audit log of changes made in the Service. We use these to keep accounts secure and to diagnose problems.
What we do not collect. We do not collect your location, contacts, calendar, microphone recordings or browsing activity. We do not use advertising or analytics trackers, and we do not build advertising profiles.
2. Face ID, Touch ID and fingerprint sign-in
If you turn on biometric sign-in, your face or fingerprint is checked entirely by your phone's operating system. The app never receives, stores or sends your biometric data - it only learns whether the check succeeded. You can turn biometric sign-in off at any time in the app's Settings.
3. Information stored on your device
To let you keep working without a signal, the app stores on your device: your sign-in session (in the device's secure keychain / keystore), your profile, the projects you download, and work you record offline until it is sent. Downloaded projects and your session are removed when you sign out, and the previous user's projects are removed when a different person signs in on the same device.
4. How we use information
- to provide the Service: sign you in, show you the work assigned to you, and record and sync your inspection work;
- to produce inspection and compliance reports for APS and its clients;
- to schedule and dispatch work;
- to send service emails such as account invitations and password resets;
- to keep the Service secure, prevent misuse, and investigate problems;
- to meet our legal and record-keeping obligations.
We do not sell personal information, and we do not use it for marketing.
5. Who we share information with
- APS's clients, who receive inspection reports. Reports name the technician who carried out the work.
- Service providers who run the Service for us, under confidentiality obligations: our technology provider, Central Coast Telephone Systems Pty Ltd (CCTS), which builds and operates the Service; Amazon Web Services, which hosts it in Australia; and Resend, which delivers service emails and may process your email address outside Australia.
- Apple and Google, which distribute the app through their stores under their own privacy policies.
- Authorities, where the law requires it.
6. Where information is stored, and for how long
The Service's database, files and backups are hosted in Australia (Sydney). Backups are kept for up to 56 days. We keep work records for as long as APS needs them for its business and to meet legal and compliance obligations, because inspection records support fire-safety certification. User accounts are deactivated rather than deleted, so that the history of who did what remains accurate; on request we will delete or anonymise personal information we are not required to keep.
7. How we protect information
All traffic is encrypted in transit (HTTPS). Passwords are hashed; sessions expire and can be ended from the Service; accounts are locked after repeated failed sign-ins; staff portal users can use two-factor authentication; and access is limited by role. On your device, session details are held in the operating system's secure storage.
8. Your choices and rights
You can ask to access or correct the personal information we hold about you, ask us to delete your account and associated personal information (subject to the record-keeping described above), or make a privacy complaint. Contact us using the details below. We will respond within 30 days. If you are not satisfied with our response you may contact the Office of the Australian Information Commissioner at www.oaic.gov.au.
To stop using the app, sign out and uninstall it; this removes the information stored on your device.
9. Changes to this policy
We may update this policy as the Service changes. The effective date at the top shows when it last changed.
10. Contact us
All Passive Services Pty Ltd1-3/9 Blackett St, West Gosford NSW 2250, Australia
Email: james@allpassiveservices.com.au