Privacy policy
Last updated 3 September 2026 · Wedgetail System is operated by Outback Safety (Australia). Contact: systems@outbacksafety.com.au.
This policy explains how Outback Safety (“we”, “us”) handles personal information in the Wedgetail System — the web application at wedgetailsystem.com.au, the Wedgetail pilot screen (kiosk) and the Wedgetail Pilot Android app (together, “the Service”). We handle personal information in accordance with the Australian Privacy Principles in the Privacy Act 1988 (Cth).
1. Who the Service is for, and whose information it holds
The Service is a compliance and safety management system used by operators (our “clients”). Each client runs its own separate workspace. A client decides what it records in its workspace and is the party responsible under work health and safety and aviation law for those records. We act as the provider of the system on the client’s behalf.
Information in a workspace may relate to:
- the client’s staff and pilots who hold user accounts (name, work email, role, login and authentication data);
- workers, crews and contractors who sign on to safe work method statements or complete inductions on a shared tablet (name, role, company, licence reference, a hand-drawn signature image, the time and device of the signature);
- passengers named on a flight manifest (name, affiliation and the weight declared for the load sheet);
- people involved in incidents, hazards, inspections and audits as recorded by the client.
2. What we collect about account holders
- Account details: name, work email address, the client workspace(s) you belong to and your role in each.
- Authentication data: a one-way hash of your password (we never store or can read the password itself), an encrypted authenticator (TOTP) secret if you enable multi-factor authentication, and hashed recovery codes.
- Session and device data: sign-in times, IP address and browser identifier for each session; for the pilot app and kiosk tablets, a device name, the app version and the time the device last synchronised.
- Activity records: the system keeps an append-only audit trail of who created, changed, approved or verified each record and when. This trail is a compliance feature — it cannot be edited or deleted by anyone, including us.
3. Why we collect it
- to operate the Service for the client — authenticating users, enforcing each client’s roles and approval rules, and producing the client’s compliance records (SWMS packs, Form 12 flight preparation records, load sheets, reports);
- to keep the Service secure — detecting misuse, revoking compromised sessions, and maintaining the audit trail;
- to support clients — when a client asks us for help, an Outback Safety platform administrator may open that client’s workspace. Every such access is recorded with the administrator’s name, the reason and the time, and the client’s owners are notified. We do not browse client workspaces silently;
- to send service messages — sign-in and invitation emails, notifications the client has configured (overdue actions, review reminders) and app-update notices. We do not send marketing email from the Service.
4. Where the information is stored
The Service is hosted in Australia on infrastructure in Adelaide, South Australia. Database contents, uploaded documents, signature images and generated PDFs are stored on that infrastructure and in encrypted nightly backups also held in Australia. Transactional email is relayed through an Australian-region connection of our email provider. We do not transfer client records overseas in the ordinary course of operating the Service.
5. Who can see what
- Users of a client workspace see only that workspace, and within it only what their role permits. Workspaces are isolated from each other at the database level.
- Contractors given portal access see only their own company’s prequalification records.
- Outback Safety platform administrators can see account metadata (names, emails, roles, whether MFA is enabled, last sign-in) and workspace activity statistics, and can open a workspace for support as described above. Nobody — including us — can read a user’s password. Administrators can reset a password, require multi-factor re-enrolment, or disable a login instead.
- We do not sell or share client records with third parties. We use a small number of service providers (hosting, backups, email relay) who process data on our instructions; each is bound by contract to keep it confidential.
- We may disclose information where required by law, for example to a work health and safety regulator or to CASA under the Civil Aviation Safety Regulations, or where a client directs us to.
6. How long we keep it — including after a client leaves
Many records in the Service exist to satisfy legal retention duties. In particular, flight preparation records are retention-locked in the database for the period the client configures (default six months, reflecting CASR 119.245) and cannot be deleted before that date; signed SWMS packs, sign-on registers and the audit trail are kept as immutable evidence for as long as the workspace exists. Session logs are kept for security review for up to twelve months.
When a client ends its subscription:
- the workspace is first suspended — sign-ins stop, but every record, timer and document is retained unchanged;
- the client is given a complete export of its workspace (records, documents, signature images, audit trail) so it can continue to meet its own retention obligations;
- after a holding period agreed in the client’s terms (and never before any statutory retention date attached to a record has passed), the workspace is deleted from live systems, and it leaves the backup rotation over the following fourteen days.
Individual records within a live workspace are corrected by superseding them, not by deletion — a corrected safe work method statement, for example, becomes a new revision while the signed original remains on file. This is deliberate: the Service is designed so that safety evidence cannot quietly disappear.
7. Security
Passwords are stored as Argon2id hashes; multi-factor authentication is available to every account and required for platform administrators; every connection uses TLS; tenant isolation is enforced by database row-level security; approval and verification rules (for example, that a person cannot verify their own weight-and-balance figures unless their organisation has formally granted that authority) are enforced inside the database, not just in the screens. Devices enrolled as shared tablets hold a scoped token that the client can revoke at any time.
8. Your rights
You may ask to access or correct personal information we hold about you. If the information sits inside a client’s workspace, we will usually refer the request to that client, which controls the record, and assist them. Where a record is a compliance record that the law requires to be kept, we may be unable to delete it, but we will explain why. To make a request or a complaint, email systems@outbacksafety.com.au. If you are not satisfied with our response you may complain to the Office of the Australian Information Commissioner (oaic.gov.au).
9. The Wedgetail Pilot app
The Android app is the same pilot screen packaged for phones and tablets. It stores your sign-in token and any records captured while offline on the device, in the app’s private storage (excluded from cloud backup), until they synchronise. The app requests no permissions beyond network access and, when you choose to update it, the ability to install the new version. It contains no advertising and no third-party analytics.
10. Changes to this policy
We will post any change here with a new “last updated” date, and notify client owners of material changes through the Service.
