top of page
Privacy Policy
PRIVACY POLICY
Effective Date: 25 February 2026
Last Updated: 15 September 2026
WorkSiteDiary respects your privacy.
This Privacy Policy explains how WorkSiteDiary collects, holds, uses, discloses and protects personal information when individuals use our website, web application, mobile applications, site induction and sign-in functionality and related services (collectively, the Services).
This policy describes our current information-handling practices. Where the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) apply to WorkSiteDiary, we will handle personal information in accordance with those requirements.
1. WHO WE ARE
WorkSiteDiary is operated by Nicholas Corrie trading as WorkSiteDiary (ABN 25 792 937 644).
Location: Adelaide, South Australia, Australia
Privacy contact: Privacy Officer, WorkSiteDiary
Email: contact@worksitediary.com.au
References to WorkSiteDiary, we, us or our in this policy mean the operator of WorkSiteDiary identified above.
2. WHO THIS POLICY APPLIES TO
This policy may apply to personal information relating to:
WorkSiteDiary account holders;
customer organisation administrators;
employees and workers;
contractors and subcontractors;
apprentices and other young workers;
visitors to construction sites or workplaces;
individuals completing site inductions;
individuals signing into or out of sites;
individuals identified in site diaries, safety records, incidents or permits;
website visitors;
people contacting WorkSiteDiary for support or enquiries; and
other individuals whose information is entered into the Services by a customer.
WorkSiteDiary is designed for workplace and construction-industry use. Workers under 18 may use or be recorded within the Services where this occurs legitimately in connection with their employment, apprenticeship, site access or other workplace activities.
3. WORKSITEDIARY AND CUSTOMER ORGANISATIONS
WorkSiteDiary is a business-to-business construction management platform.
Customer organisations may use WorkSiteDiary to collect and maintain information concerning their employees, workers, contractors, subcontractors, visitors and other individuals.
A customer organisation may determine why information is entered into WorkSiteDiary and how that information is used within its workplace.
WorkSiteDiary provides the systems used to store, manage and process that information and also handles personal information for its own purposes where necessary to provide, secure, maintain and improve the Services.
Customer organisations are responsible for ensuring that their own collection and use of personal information through WorkSiteDiary is lawful, including providing appropriate notices and obtaining consent where required.
This does not remove WorkSiteDiary’s own responsibilities in relation to personal information that WorkSiteDiary collects or holds.
Individuals may contact WorkSiteDiary directly in relation to access, correction or deletion requests.
Where a request concerns a record created or maintained by a customer organisation, WorkSiteDiary may consult that organisation where reasonably necessary, including where workplace, safety, legal or record-integrity considerations apply.
4. PERSONAL INFORMATION WE COLLECT
The information we collect depends on how WorkSiteDiary is used and the functionality enabled by a customer.
4.1 Identity and contact information
We may collect:
name;
email address;
telephone number;
company or business name;
job title or role;
residential or postal address;
city;
state;
postcode;
country;
date of birth; and
emergency-contact information.
4.2 Worker and contractor information
We may collect:
employer or subcontractor details;
White Card numbers;
licence numbers;
qualifications and other workplace credentials;
worker or contractor status;
induction information;
approvals;
declarations;
acknowledgements;
signatures; and
information entered into custom workplace forms.
4.3 Account and authentication information
We may collect:
account identifiers;
login information;
authentication identifiers;
telephone-verification information;
authentication method;
multi-factor authentication information;
user roles;
account permissions;
account status; and
subscription status.
WorkSiteDiary uses third-party authentication and verification services where required.
4.4 Attendance and visitor information
WorkSiteDiary may record:
site sign-in and sign-out;
attendance dates;
arrival and departure times;
time spent on site;
worker attendance;
contractor attendance;
visitor attendance;
site identifiers; and
associated worker or contractor details.
4.5 Site and project information
We may collect or hold:
project names;
construction site names;
site addresses;
job or project numbers;
geographic coordinates associated with sites;
contractors associated with a site;
site activities; and
related project metadata.
4.6 Site diary information
Site diaries may contain:
daily work records;
activities undertaken;
labour information;
contractor information;
site attendance;
weather information;
notes;
comments;
custom fields;
approvals;
signatures;
photographs;
PDF documents; and
other information entered by authorised users.
Information entered into free-text fields may contain personal information that WorkSiteDiary cannot predict in advance.
4.7 Safety, health and emergency information
WorkSiteDiary may store information relating to workplace safety or a worker’s health where it is relevant to the records maintained by a site operator.
This may include:
allergies;
allergic reactions;
allergy severity;
emergency information;
emergency contacts;
incidents;
injuries;
near misses;
first-aid information;
safety observations;
corrective actions; and
health-related information contained in notes or uploaded records.
Some of this information may constitute sensitive information, including health information, under Australian privacy law.
This information is intended to assist the relevant site owner, operator or customer organisation in maintaining workplace, emergency and safety records.
WorkSiteDiary does not use health information for advertising or unrelated commercial profiling.
4.8 Permits and compliance information
The Services may contain information relating to:
confined-space work;
excavation;
hot work;
work at heights;
crane or lifting activities;
other work permits;
SWMS and safety documentation;
approvals;
signatures;
associated workers; and
associated contractors.
4.9 Uploaded content
Customers may upload:
photographs; and
PDF documents.
Those files may contain personal information or sensitive information depending on what the customer chooses to upload.
Customers should avoid uploading personal or sensitive information that is not reasonably necessary for a legitimate workplace purpose.
4.10 Technical, security and audit information
WorkSiteDiary may collect technical and security information including:
IP address;
user identifier;
site identifier;
device type;
operating system;
browser;
user agent;
application version;
dates and timestamps;
application activity;
request paths;
security events;
authentication activity;
event outcomes;
failure information;
risk or security indicators; and
other technical information reasonably required to secure and operate the platform.
This information is used primarily for:
security;
authentication;
fraud and abuse prevention;
troubleshooting;
incident investigation;
system reliability; and
auditability.
4.11 Error and performance monitoring
WorkSiteDiary uses Sentry for application monitoring, diagnostics and error investigation across frontend and backend systems.
Information sent to Sentry may include:
first name;
last name;
email address;
IP address;
user identifiers;
browser information;
device information;
application activity;
error information; and
technical diagnostic information.
This information is used to identify, diagnose and resolve errors, reliability problems and security issues affecting the Services.
4.12 Analytics information
WorkSiteDiary uses Google Analytics to understand how the Services are used and to improve the product.
Analytics information may include:
application events;
pages or screens viewed;
functionality used;
device and browser information;
session information;
approximate location derived from technical information; and
an account-linked user identifier for authenticated users.
Logged-in users may therefore have their application activity associated with a persistent analytics user identifier.
WorkSiteDiary does not currently use Google Analytics for:
remarketing;
personalised advertising;
advertising audiences; or
Google Signals.
WorkSiteDiary currently uses analytics for product and service measurement rather than advertising.
4.13 Billing and subscription information
Where a customer purchases a paid WorkSiteDiary subscription, we may collect or hold:
subscription plan;
subscription status;
billing status;
transaction information;
invoices; and
payment-related records.
Payment-card processing is performed by Stripe.
WorkSiteDiary does not store complete payment-card numbers or card verification values such as CVVs.
5. SENSITIVE INFORMATION
Some WorkSiteDiary functionality may involve sensitive information, particularly health information.
Sensitive information may appear in:
allergy records;
injury records;
incident reports;
first-aid records;
emergency information;
worker records;
site diary notes;
photographs;
PDF documents; or
free-text content.
Where WorkSiteDiary collects sensitive information directly from an individual and consent is required by applicable law, appropriate consent or another lawful basis for collection must apply.
Customer organisations are responsible for ensuring they are authorised to enter or collect sensitive information about their workers, contractors and visitors.
WorkSiteDiary encourages customers to collect only information reasonably required for workplace, safety, emergency, compliance or other legitimate purposes.
6. HOW WE COLLECT PERSONAL INFORMATION
We may collect personal information:
directly from you when you create an account, complete an induction, sign into a site, submit information or contact us;
from a customer organisation, site administrator, employer, principal contractor or another authorised user;
when another authorised user enters information concerning you;
automatically through security logs, application logs, analytics and monitoring technologies;
through authentication and verification providers;
through payment providers;
through integrations and services used to operate WorkSiteDiary; and
from devices used to access the Services.
7. WHY WE USE PERSONAL INFORMATION
We may collect, hold, use and disclose personal information to:
provide WorkSiteDiary;
establish and administer user accounts;
authenticate users;
verify telephone numbers;
manage permissions;
administer site inductions;
identify workers and visitors;
record site attendance;
maintain construction site diaries;
maintain workplace and safety records;
record incidents and corrective actions;
manage permits;
maintain customer records;
generate site diary reports and exports;
process subscriptions and payments;
provide customer support;
secure the Services;
identify fraud or unauthorised access;
investigate security events;
maintain audit records;
diagnose errors;
monitor application performance;
analyse how WorkSiteDiary is used;
improve existing functionality;
develop the Services;
protect our legal rights;
respond to disputes;
meet legal and regulatory obligations; and
meet contractual obligations.
8. PUBLIC SITE INDUCTION
WorkSiteDiary allows customer organisations to provide public site-induction functionality, including through QR codes or public links.
A site induction may collect information including:
name;
email address;
telephone number;
date of birth;
residential address;
state;
postcode;
White Card number; and
subcontractor or employer information.
This information may be used to:
identify the person entering the site;
confirm induction information;
maintain site-access records;
maintain workplace and safety records;
associate the person with an employer or subcontractor; and
make relevant records available to the organisation operating the site.
Failure to provide information required by the relevant site operator may prevent an individual from completing an induction or being permitted to access the site.
WorkSiteDiary may provide additional privacy information at or near the point at which induction information is collected.
9. PUBLIC SITE SIGN-IN AND SIGN-OUT
WorkSiteDiary provides functionality allowing workers and other authorised individuals to sign into or out of a site.
The public sign-in process may use:
telephone number;
site identifier;
worker identity; and
attendance information.
This information is used to identify the individual and create or update site attendance records.
10. ANALYTICS AND COOKIES
WorkSiteDiary uses technologies such as application identifiers, cookies and analytics events to operate and understand the Services.
Google Analytics is currently used for product analytics.
For authenticated users, an analytics user identifier may be associated with activity undertaken while using WorkSiteDiary.
We use this information to:
understand product usage;
understand which functionality is used;
identify usability issues;
assess application performance; and
improve WorkSiteDiary.
We do not currently use this information for behavioural advertising or remarketing.
Users may be able to restrict cookies or similar technologies using their browser or device settings. Doing so may affect some functionality.
11. SERVICE PROVIDERS
We use third-party providers to operate WorkSiteDiary.
These may include:
Google Cloud Platform
Used for application hosting, processing, databases, storage and other cloud infrastructure.
Our primary Google Cloud production infrastructure is configured to use Australian regions.
This includes services such as:
Firebase;
Firestore;
cloud storage;
application and API infrastructure; and
related Google Cloud services.
Google Analytics
Used for product and application analytics.
Sentry
Used for application monitoring, error reporting, performance monitoring and diagnostics.
Twilio / Authy
Used for telephone-number verification and verification codes.
Stripe
Used for payment and subscription processing where paid subscriptions are used.
WeatherAPI
Used to obtain weather information associated with sites and site diary functionality.
Other infrastructure or service providers may be introduced where reasonably necessary to operate the Services.
12. DISCLOSURE OF PERSONAL INFORMATION
We may disclose personal information to:
the customer organisation responsible for the relevant account or site;
authorised administrators and users within that organisation;
third-party providers that operate WorkSiteDiary infrastructure;
authentication providers;
payment providers;
analytics providers;
monitoring and security providers;
professional advisers including lawyers, accountants and insurers;
regulators;
courts;
law-enforcement authorities; and
government agencies where required or authorised by law.
Personal information may also be disclosed in connection with a merger, acquisition, restructure, financing event or sale of all or part of WorkSiteDiary, subject to appropriate protections.
WorkSiteDiary does not sell personal information.
13. OVERSEAS PROCESSING
Our primary Google Cloud production infrastructure is configured to store and process application data within Australia.
However, some third-party providers used by WorkSiteDiary operate global infrastructure.
Services such as:
Google Analytics;
Sentry;
Twilio / Authy;
Stripe; and
WeatherAPI
may process or make personal information accessible outside Australia depending on their infrastructure, configuration and support arrangements.
Where Australian privacy law applies to an overseas disclosure, WorkSiteDiary will take reasonable steps appropriate to the circumstances to manage the privacy risks associated with that disclosure.
We may update this policy as provider processing locations or infrastructure arrangements change.
14. DATA SECURITY
WorkSiteDiary takes reasonable technical and organisational measures designed to protect personal information against:
misuse;
interference;
loss;
unauthorised access;
unauthorised modification; and
unauthorised disclosure.
Measures may include:
authentication;
multi-factor authentication where applicable;
role-based access controls;
encryption in transit;
cloud-provider security controls;
audit logging;
monitoring;
application security controls; and
restricted administrative access.
No online service, transmission method or storage system can be guaranteed to be completely secure.
Users are responsible for maintaining the security of their own passwords, authentication methods and endpoint devices.
15. SUBSCRIPTION CANCELLATION AND DATA RETENTION
Cancellation of a WorkSiteDiary subscription does not automatically delete customer data.
Customers generally retain access until the end of their applicable subscription period.
Following the end of a subscription:
access to paid WorkSiteDiary functionality may be restricted; and
customer information and site records may continue to be retained for account restoration, customer recordkeeping, workplace safety, legal, security and other legitimate business purposes.
If a subscription is subsequently restored, access to retained information may also be restored.
WorkSiteDiary does not treat subscription cancellation as a request to erase customer information.
A customer or individual may make a separate privacy or deletion request as described below.
Retention periods may vary depending on:
the type of information;
why it was collected;
customer requirements;
workplace-health-and-safety requirements;
security requirements;
dispute or legal requirements; and
technical backup processes.
Security and audit information may be retained for a period reasonably necessary for security, investigation, fraud prevention, auditability and related operational purposes.
Analytics and monitoring information is retained according to the relevant WorkSiteDiary and service-provider configuration.
Where personal information is no longer reasonably required for a permitted purpose, and there is no legal or other valid requirement to retain it, WorkSiteDiary will take reasonable steps required by applicable law to destroy or de-identify it.
16. BACKUPS
WorkSiteDiary and its infrastructure providers may maintain backups for:
disaster recovery;
system resilience;
operational recovery; and
security purposes.
Deletion from active systems may not immediately remove information from every backup.
Information remaining in backups may remain protected and unavailable for ordinary use until the backup is overwritten, expires or is otherwise removed through normal backup-management processes.
17. ACCESS AND CORRECTION
You may request access to personal information WorkSiteDiary holds about you.
You may also request correction where information is:
inaccurate;
out of date;
incomplete;
irrelevant; or
misleading.
Requests can be made to:
Privacy Officer, WorkSiteDiary
contact@worksitediary.com.au
We may require reasonable verification of your identity before providing access to or changing personal information.
If the information forms part of workplace, safety or customer records, we may need to consult the relevant customer organisation or consider legal and record-integrity requirements before changing the record.
In some circumstances permitted by law we may refuse an access or correction request.
Where required, we will explain the reason for doing so.
18. DELETION REQUESTS
Subscription cancellation does not automatically constitute a request to delete personal information.
Individuals and customer organisations may separately request deletion or de-identification of personal information by contacting:
contact@worksitediary.com.au
Deletion requests are currently assessed and processed by WorkSiteDiary.
Whether information can be deleted will depend on matters including:
why the information is held;
whether the relevant customer still reasonably requires the record;
workplace-health-and-safety requirements;
incident and safety record requirements;
taxation or financial-record obligations;
legal obligations;
contractual obligations;
current or anticipated disputes;
insurance requirements;
security and fraud-prevention requirements; and
technical backup processes.
Where deletion is appropriate, WorkSiteDiary will take reasonable steps to delete or de-identify the relevant information.
Processing a deletion request may involve multiple WorkSiteDiary systems or service providers and may therefore require manual processing.
Information retained solely within protected backups may remain until those backups expire or are replaced through ordinary backup processes.
19. SITE DIARY EXPORTS
Authorised WorkSiteDiary customers may export site diary information from the Services.
Exports may contain personal information entered into the relevant site diary.
The customer receiving the export is responsible for appropriately protecting and handling exported information once it leaves WorkSiteDiary.
20. COMMUNICATIONS AND VERIFICATION CODES
WorkSiteDiary currently uses electronic communications primarily for operational purposes.
Twilio / Authy may be used to send verification codes required for authentication or account security.
These are service or security communications rather than promotional marketing messages.
WorkSiteDiary does not currently use personal information to send general promotional email, SMS or push-notification marketing.
If we introduce direct marketing in the future, this policy and relevant consent and unsubscribe mechanisms will be updated as appropriate.
21. ANONYMITY AND PSEUDONYMS
Where reasonably practicable, individuals may contact WorkSiteDiary without identifying themselves.
However, many features of WorkSiteDiary relate to:
site access;
worker identification;
induction;
attendance;
construction safety;
authentication;
permits;
workplace records; and
compliance.
Those functions generally require accurate identification and cannot practically be provided anonymously.
22. PRIVACY COMPLAINTS
If you believe WorkSiteDiary has mishandled personal information or failed to comply with applicable privacy requirements, you may contact:
Privacy Officer, WorkSiteDiary
Email: contact@worksitediary.com.au
Please provide enough information for us to understand and investigate your concern.
We may contact you for additional information where necessary.
We will investigate privacy complaints and respond within a reasonable period.
Where applicable, if you are not satisfied with our response, you may be able to lodge a complaint with the Office of the Australian Information Commissioner (OAIC).
Information about the OAIC is available at www.oaic.gov.au.
23. THIRD-PARTY LINKS AND SERVICES
WorkSiteDiary may contain links to or integrations with third-party websites and services.
Independent third parties may have their own privacy policies and information-handling practices.
WorkSiteDiary is not responsible for the independent privacy practices of a third party except to the extent that responsibility arises under applicable law or our contractual arrangements.
24. CHANGES TO THIS PRIVACY POLICY
We may update this Privacy Policy from time to time to reflect:
changes to WorkSiteDiary;
new functionality;
changes in information-handling practices;
changes to service providers;
changes to infrastructure; or
changes in applicable laws or regulatory guidance.
The updated version will be published on our website with a revised Last Updated date.
Where a change materially affects how personal information is handled, we may also provide notice through the Services or another appropriate method.
25. CONTACT US
Privacy Officer
WorkSiteDiary
Nicholas Corrie trading as WorkSiteDiary
ABN 25 792 937 644
Email: contact@worksitediary.com.au
Location: Adelaide, South Australia, Australia
bottom of page
