1. Overview & Legal Entity
Cloudcon Pty Ltd (ABN 87 623 058 695) (trading as “Cloudcon”, “we”, “us”, or “our”) respects your right to privacy and is committed to protecting personal information disclosed to us in accordance with the Privacy Act 1988 (Cth) (the “Privacy Act”) and the Australian Privacy Principles (APPs)
This Privacy Policy informs you how we collect, store, use, disclose, and safeguard your personal information across our website (cloudcon.com, with cloudcon.com.au redirecting to it), web application, native iOS and Android mobile applications (including Prestartr), sales/support channels, and related platform services (collectively, the “Services”)
For the purpose of this Privacy Policy, “personal information” has the meaning given under the Privacy Act, being information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether true or not and whether recorded in a material form or not. “Sensitive information” has the meaning given under APP 3.3, and includes health information – see Section 4 below
2. Scope & Applicability
This policy applies to:
Account Holders & Enterprise Users: Directors, project managers, finance officers, site supervisors, and administrative personnel accessing Cloudcon platform services.
Field Operators & Mobile App Users: Employees, sub-contractors, and site personnel using the Prestartr mobile application or web-based field forms.
Demo, Sales & Support Participants: Individuals who participate in sales demonstrations, customer support calls, training webinars, or phone/video meetings with Cloudcon personnel.
Website Visitors & Inquirers: Individuals visiting our website or submitting online inquiries.
Where you access Cloudcon on behalf of an employer, principal contractor, or client who holds a subscription with us (a “Customer Tenant”), your information is processed by Cloudcon as a service provider acting on that Customer Tenant’s instructions, under the configuration set by that Customer Tenant’s administrators. In this relationship, the Customer Tenant is generally responsible for having its own lawful basis for collecting your information (for example, as your employer or principal contractor) and for telling you how it will be used. Cloudcon’s role is to process that information to deliver the Services, and to comply with our own separate legal obligations described in this policy
3. Information We Collect
We collect and store personal information in a variety of ways, including when you disclose it to us, interact with us electronically or in person, access our software, participate in meetings, or when provided to us by third parties or your employer
Depending on your interaction with us, we may collect:
Identity & Contact Data: Full name, business email address, office address, telephone number, job title, and company name collected when you submit contact forms, book a demo, download resources, or engage in direct commercial transactions.
Call & Video Meeting Recordings: Audio recordings, video recordings, AI-generated transcripts, screen-shares, and meeting notes captured during sales demonstrations, customer support calls, onboarding sessions, and operational meetings, using our video conferencing and meeting-recording provider(s) (see Section 4).
Workforce & Qualification Records: Licences, tickets, ticket expiry dates, safety inductions, training qualifications, and pay classification details logged in the Training Matrix or People module.
Field & Safety Records: Information submitted via digital Form Templates, including Site Prestarts, TAKE 5s, Job Hazard Analyses (JHAs), SWMS sign-offs, Incident Forms, Defects, and Site Diaries. These records may occasionally contain health information – see Section 4.
Signatures & Media: Digital signatures captured in form Signature Fields and photographs captured via Photo Fields (e.g., equipment defects, hazard logs, site dockets).
Location & Geotag Data: GPS coordinates recorded at the time of form completion, prestart submission, or clock-in, where location permissions are enabled on your mobile device.
Technical & Usage Data: IP address, device type, browser type, operating system version, app version, access times, crash analytics, and offline synchronisation logs.
Where lawful and practicable, you have the right to interact with us anonymously or by using a pseudonym. However, given the nature of our B2B services, if you wish to book a demo, request support, or access the Cloudcon platform, we will generally require your true identity and accurate contact details
4. Sensitive Information
Some of the field and safety data described in Section 3 – particularly Incident Forms, JHAs, and TAKE 5s – may include health information (for example, details of a workplace injury) or other information that qualifies as “sensitive information” under APP 3.3
We (and the Customer Tenant on whose behalf a form is submitted) only collect sensitive information where:
it is volunteered by the individual or their employer as part of a workplace safety record required by law or workplace policy;
it is reasonably necessary for work health and safety compliance, incident investigation, or workers’ compensation purposes; or
the individual has otherwise consented to its collection.
Sensitive information is subject to the same security safeguards described in Section 8 (Storage, Hosting & Data Security), and is not used by Cloudcon for any secondary purpose – including marketing or AI model training – without separate consent. If you are a field worker and believe sensitive information about you has been recorded incorrectly, please refer to Section 14 (Access to and Correction of Personal Information)
5. Call & Meeting Recording Notice
To maintain service quality, train our personnel, and assist with technical support, Cloudcon may record and transcribe digital interactions:
Technologies Used: We use third-party video conferencing, meeting recording, and AI transcription software to support sales, onboarding, and customer support interactions.
Notice & Choice: At the commencement of a video call or demo meeting, participants are notified that the session is being recorded. If you do not wish to be recorded, you may notify the host, mute your microphone, turn off your camera, or opt to leave the meeting and communicate via written email instead.
Storage & Access: Call recordings and transcripts are securely stored in restricted cloud environments and accessed only by authorized Cloudcon staff for quality control and administrative record-keeping.
Retention: Recordings and transcripts are hard deleted within 100 days of the date of the call, unless a longer period is required to resolve an active support ticket, dispute, or legal obligation.
6. Purpose of Collection and Use
We collect, hold, and use your personal information for the following purposes, on the legal bases described below:
Where you are a Customer Tenant employee or field worker: we process your information as a service provider to your employer or principal contractor, to the extent reasonably necessary to deliver the Services they have configured (for example, capturing a prestart form your employer requires). We rely on this service-provider relationship, and on our own obligations under this policy, rather than on your individual consent, for these purposes.
Where you deal with us directly (for example, as an Account Holder, or when booking a demo, contacting sales/support, or visiting our website): we collect, hold, and use your information where you have consented, where it is reasonably necessary for our functions as a business, or where we are otherwise permitted or required to do so by law.
Depending on the context, this includes:
Service Delivery: Provisioning access to Cloudcon and Prestartr, managing Tenants, processing Work Orders, and synchronising mobile data.
Demonstrations, Sales & Support: Conducting product walkthroughs, responding to support tickets, recording customer instructions, and verifying technical requirements.
Site Safety & Compliance: Maintaining verifiable audit trails for SWMS, JHAs, Site Prestarts, Attendance Registers, and ticket validity via the Training Matrix.
Commercial & Operational: Generating accurate Timesheets, Cost Code allocations, Site Diaries, Purchase Orders, Cost Estimates, and customer Invoices.
Administration & Reporting: Administering our business, managing customer accounts, and fulfilling any State or Commonwealth bodies’ legal requests for information or reporting.
Product Development: Researching, analysing, and improving our software services, and enhancing user experience – see Section 7 (AI & Automated Processing).
7. AI & Automated Processing
We use artificial intelligence tools in the following limited way:
Meeting transcription & summarisation: call and video meeting audio may be processed by our third-party video conferencing provider’s AI transcription models to generate transcripts and summaries, as described in Section 5.
Cloudcon does not use customer data or field data to train or fine-tune any AI models. Where an AI tool is used to generate a transcript or summary, a human remains responsible for reviewing and relying on that output
8. Storage, Hosting & Data Security
We are committed to ensuring that your personal information is secure. To prevent unauthorised access, modification, or disclosure, we maintain administrative, technical, and physical safeguards informed by SOC 2 principles. Cloudcon is not currently SOC 2 certified
Australian Data Residency: Primary customer application data, commercial records, and field form submissions are hosted within Australia via Amazon Web Services (AWS Sydney Region: ap-southeast-2).
Encryption Standards: Data in transit is secured using TLS 1.3 encryption. Data at rest is encrypted using AES-256.
Access Control: System access within Cloudcon is restricted using strict role-based access controls (RBAC) and User Zone configurations.
9. Data Retention
We retain personal information only for as long as it is reasonably necessary for the purposes described in this policy, or as required by law. Across all data types – including field and safety records, commercial and financial records, call recordings and transcripts, and website/CRM contact data – Cloudcon hard deletes personal information within 100 days of the point it is no longer needed for the purpose for which it was collected, unless a longer period is required by law
Please note: Given this 100-day deletion practice, Customer Tenants (including employers and principal contractors using Cloudcon and Prestartr) are responsible for exporting and independently retaining their own copies of any records they are required to keep for longer periods under work health and safety, taxation, or other applicable laws or contractual obligations. Cloudcon is not responsible for a Customer Tenant’s failure to export or retain records before they are deleted from our systems
10. Disclosure of Personal Information & Sub-Processors
Cloudcon may disclose your personal information to any of our employees, officers, insurers, professional advisers, agents, suppliers, or sub-contractors, or related bodies corporate (as defined in the Corporations Act 2001 (Cth)), insofar as reasonably necessary for the purposes set out in this policy
Specific disclosures include:
Customer Tenant Administrators: If your user account is linked to an employer or principal contractor’s Tenant, all submitted dockets, timesheets, safety forms, photos, signatures, and geotags are accessible to authorized administrators of that Tenant.
Third-Party Systems & ERPs: Where configured by a Customer Tenant administrator, Cloudcon transfers relevant financial, timesheet, or commercial dockets to third-party accounting or ERP platforms (such as Xero, MYOB, Jobpac, or Viewpoint).
Overseas Data Transfers (CRM, Marketing & Meeting Tools): While our core application data is hosted strictly in Australia, some administrative, CRM, marketing, hosting, and meeting-recording sub-processors store or process personal information overseas. Currently these include HubSpot (United States), Google/Google Analytics (United States), Meta (United States), Framer B.V. (Netherlands) — our website hosting provider — and our video conferencing and meeting-recording provider(s) (United States). Before we disclose personal information to these overseas recipients, we take reasonable steps to ensure they handle it consistently with the APPs. You may ask us not to share your information with these specific sub-processors by contacting us at info@cloudcon.com.au, though this may limit our ability to respond to marketing enquiries or provide certain website features.
Legal Obligations: We may disclose personal information to comply with any legal requirement, law, regulation, court order, subpoena, warrant, legal proceeding, or response to a law enforcement or government safety agency request.
11. Mobile Application Permissions (Prestartr)
To provide reliable offline field capabilities, the Prestartr application requests specific device permissions:
Camera & Media: To capture and attach photos to site prestarts, defect reports, and dockets.
Location Services: To verify the geographical location of site prestarts, timesheets, and safety submissions where configured by your employer. Where background (“always allow”) location access is requested, we explain the specific feature this enables at the point the permission is requested, in addition to this policy.
Device Storage: To store local encrypted databases allowing offline form creation and automatic Sync when network connectivity is restored.
12. Website Cookies, Tracking & Analytics
When you visit our website, we automatically collect certain technical and usage information:
Cookies & Pixels: We use cookies, web beacons, and tracking pixels (including the Meta Pixel and Meta Conversions API) to analyse site traffic, personalise content, and measure the effectiveness of our advertising campaigns (including Google Ads).
Analytics & CRM: We utilise third-party platforms such as Google Analytics 4 (GA4) and HubSpot to understand how users navigate our site and to manage our sales inquiries.
Your Choices: You can control or block cookies through your browser settings, opt out of Google Analytics using the Google Analytics Opt-out Browser Add-on, and manage your targeted advertising preferences via your Facebook/Meta account settings. Disabling cookies may affect certain functionality of our website and SaaS portal
13. Direct Marketing & Communications
If you book a demo, download resources, or submit a contact form, we may use your contact details to send you information about Cloudcon products, industry news, and promotional offers. We comply with the Spam Act 2003 (Cth)
You can opt out of these marketing communications at any time by clicking the “unsubscribe” link at the bottom of our emails or by contacting us directly. Opting out of marketing does not prevent us from sending you critical system, security, or billing notices related to an active software subscription
14. Access to and Correction of Personal Information
You may request details of the personal information we hold about you in accordance with the provisions of the Privacy Act
Correction Requests: It is important that your personal information is accurate, complete, and up to date. If you find that personal information we hold about you is inaccurate, out of date, incomplete, or misleading, please contact us to request an amendment
Tenant Data: If you are a field worker or employee accessing Cloudcon via an employer’s Tenant, your employer is generally responsible for your personal information under its own obligations (including, where applicable, the employee records exemption under the Privacy Act). Requests to edit or delete submitted safety forms or dockets should be directed to your employer’s Cloudcon administrator in the first instance. Cloudcon does not itself claim the employee records exemption, as you are not Cloudcon’s employee – we will still assist your employer, as our customer, in responding to your request
We reserve the right to refuse access to or correction of personal information in certain specific circumstances permitted by the Privacy Act or other applicable laws
15. Notifiable Data Breaches (NDB) Scheme
In accordance with Part IIIC of the Privacy Act, Cloudcon maintains an active data breach response protocol
If we have reasonable grounds to believe an eligible data breach has occurred – where personal information is accessed, disclosed, or lost in circumstances likely to result in serious harm – we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) as soon as practicable, providing recommendations on protective steps
Where a breach affects data held on behalf of a Customer Tenant, we will also notify the affected Tenant’s designated administrator without undue delay
If you suspect or become aware of a potential security incident or data breach involving Cloudcon, please report it immediately to info@cloudcon.com.au
16. Changes to this Privacy Policy
Cloudcon reserves the right to modify this Privacy Policy at any time in our sole discretion. Material changes will be indicated by an updated “Last updated” date at the top of this policy, and, where the change significantly affects how we handle field or safety data, we will take reasonable steps to notify Customer Tenant administrators directly. We encourage users to check back periodically to review our current policy
17. Complaints & Privacy Officer Contact Details
If you have any questions, concerns, or complaints regarding our privacy practices or our handling of your personal information, please submit your written query to our Privacy Officer:
Privacy Officer
Cloudcon Pty Ltd
Address: Level 4 / 344 Johnston St, Abbotsford VIC 3067, Australia
Email: info@cloudcon.com.au
We take all privacy complaints seriously and will respond promptly upon receiving written notice of your complaint. If you remain dissatisfied with our response, you may refer your matter to the Office of the Australian Information Commissioner (OAIC):
Website: www.oaic.gov.au
Phone: 1300 363 992