SRP Deck

Privacy Policy

Last updated: 16 July 2026

This policy reflects our current practices and is accurate as at the date shown. We have not yet set specific retention periods; see section 8.

1. Who we are

SRP Deck is the work-order, contractor and asset-management platform operated by SRP Global Consultancy, based in Docklands, Melbourne, Victoria, Australia. For any privacy question you can reach us at sales@srpglobalconsultancy.com.au.

2. What we collect

  • Identity & contact: name, email address, phone number and your role within an organisation.
  • Business & financial: for contractors, business details and bank/ABN information used to process payments, and the quotes and invoices raised through the platform.
  • Job & operational data: sites, units, assets, service requests, scopes of work, schedules, work-order notes and timestamps.
  • Photos & video: before, daily and completion photos, and completion videos, uploaded against jobs.
  • Compliance documents: police checks, driver/trade licences and similar certifications uploaded for team members.
  • Location: for contractors, GPS coordinates and their accuracy captured once, at the moment of clock-in, to confirm on-site attendance. Location is not tracked in the background, between jobs, after hours, or when the app is closed. Declining the location permission still allows clock-in; we simply record that location was unavailable.
  • Technical logs: standard access logs, including IP address and browser/user-agent, kept for security and audit.

3. How we use it

We use this information to deliver the service — authenticating users and applying role-based access; managing service requests, work orders, scheduling, quotes, purchase orders, invoices and contractor payments; storing compliance records; and keeping an operational audit history. Location is used for one purpose only: confirming a contractor was on site at the moment they clocked in.

4. Use of Artificial Intelligence

Our public website includes an AI assistant called “Ask SRP”. It is not active yet — while we finalise it, it simply directs you to our team. When we enable it, it will be powered by Anthropic's Claude API to answer general enquiries about SRP Deck; its responses will be AI-generated and may be inaccurate, and it will never be a substitute for our team. We publish how it will work here so this policy is accurate before it goes live.

  • What it processes: when enabled, it will process only the messages a user chooses to type into it. We do not feed your account, job or contractor records into the assistant.
  • Using it is optional: you are not required to use the assistant — you can always contact us directly at sales@srpglobalconsultancy.com.au instead.
  • How it works: once enabled, the message you type will be sent to Anthropic to generate a reply. We use Anthropic's commercial API; under Anthropic's Commercial Terms, API inputs and outputs are not used to train Anthropic's models and are retained only briefly for abuse-monitoring before deletion. Anthropic operates outside Australia (primarily in the United States), so this will be a cross-border disclosure.
  • Please don't enter sensitive information: do not type sensitive personal information, passwords, or another person's private details into the assistant.
  • No automated decision-making: we do not use AI to make automated decisions that have legal or similarly significant effects about you.
  • Development tools: we also use AI-assisted coding tools when building SRP Deck; these operate on our source code, not on your personal data.

5. Who we share it with (processors)

We do not sell personal information. We rely on a small set of trusted service providers to run SRP Deck:

  • Neon - managed PostgreSQL database (hosted in Sydney, Australia).
  • Cloudinary - storage of uploaded files, images and video.
  • Resend - transactional email delivery.
  • Render - application/back-end hosting.
  • Anthropic PBC (via the Claude API) — which will power the “Ask SRP” AI assistant on our website once it is enabled (it is not active yet). When the assistant is switched on and a user sends it a message, that message will be transmitted to Anthropic's API to generate a response. We use Anthropic's commercial API; under Anthropic's Commercial Terms, API inputs and outputs are not used to train Anthropic's models and are retained only briefly for abuse-monitoring before deletion. Anthropic operates primarily in the United States, so this will be a cross-border disclosure.

Where these providers process data: Neon hosts the database in AWS Sydney (ap-southeast-2), Australia. Cloudinary (file, image and video storage) is United States-based and processes data there. Resend (transactional email) processes data in Tokyo, Japan (ap-northeast-1). Our application hosting, Render, may operate outside Australia. Using SRP Deck therefore involves cross-border disclosure to these providers.

6. Where your data is stored

The primary database is hosted in AWS Sydney (ap-southeast-2), Australia, via Neon. Some processors (file storage, email and the AI assistant) may operate outside Australia; see section 5.

7. Security

  • Encryption in transit (HTTPS/TLS) for all traffic to and from the platform.
  • Application-level encryption at rest for the most sensitive fields: bank details (account name, BSB and account number) are encrypted with AES-256-GCM wherever we store them — for a contractor business, a contractor's own invoicing profile, a team member, and your organisation's own remittance settings — as are operator two-factor secrets. The encryption key is held outside the database, so those values cannot be read from the database on its own.
  • All other information is held in plain text within the database and file storage, protected by our hosting providers' disk-level encryption at rest (Neon/AWS for the database, Cloudinary for uploaded files) and by PostgreSQL Row-Level Security, which isolates each organisation's data so one tenant cannot see another's.
  • Passwords are stored only as bcrypt hashes, in separate sealed login pools.
  • Role-based access controls, input validation and API rate limiting.

8. Data retention

We keep information only for as long as needed to deliver the service and to meet legal, financial, tax and audit obligations. In practice:

  • Financial and operational records — jobs, quotes, invoices and clock-in history — are archived rather than hard-deleted, to preserve financial and audit history.
  • Uploaded documents and media, including compliance documents and job photos, are soft-deleted — marked as deleted and hidden from view, but recoverable — rather than erased immediately.
  • A team member or login is permanently deleted only when it has no associated history. Once someone has worked a job, uploaded a document or clocked on, their record is deactivated and retained instead of removed, so the evidence attached to it stays intact.

We do not yet run an automated purge on a fixed schedule, and we have not yet set specific retention periods for each type of data. Our intention is to define and publish those periods, and to erase information that is no longer needed, as the product matures. Until then we retain data under the principles above, and we will act on a specific deletion request where we are not legally required to keep the information.

9. Your rights

You may request access to, or correction of, the personal information we hold about you, and you may raise a privacy complaint. Contact us at sales@srpglobalconsultancy.com.au. If you are a contractor or crew member, questions about your clock-in or location records should go to your employer first; SRP Global Consultancy holds the same records for the sites you work on.

10. Contractors and their team members

A contractor business using SRP Deck can store information about its own team members — name and contact details, compliance documents, and, where entered, bank details, ABN and address. For that information the contractor is the controller: they decide what to record and are responsible for having a lawful basis and any consent their people require. SRP acts as the processor — we store and secure that information, make it available to the contractor within their own account, and do not use it for our own purposes, sell it, or disclose it to other contractors.

Bank details recorded for a team member are encrypted at rest (see section 7). A team member with a question about the information their employer holds about them should raise it with that employer, who controls it; on request we will help the contractor locate, correct or remove it.

11. Changes to this policy

We may update this policy as the product and our practices evolve. The “last updated” date above reflects the current version.