AU
Sydney hosted
AWS ap-southeast-2
0
Third-party
data sharing
100%
Organisation-isolated
row-level security

Workforce data stays in Australia

All data processed and stored by Workforce Ledger is hosted in AWS Sydney. Your data never crosses international borders, satisfying Australian Privacy Act cross-border disclosure obligations and keeping you on solid ground with local compliance requirements.

01

Organisation isolation

Every organisation's data is completely isolated using row-level security enforced at the database layer. This means even if there were a bug in our application code, one customer cannot access another's records. Isolation is structural, not just policy.

Each customer's data is cryptographically scoped to their organisation ID and cannot be queried without the correct authenticated session.

02

Encryption at rest and in transit

All data is encrypted at rest within the database. All connections to Workforce Ledger use HTTPS — no unencrypted data transfer is permitted at any point in the system.

Credentials and API keys are stored in a managed secrets service and are never exposed in logs, error messages, or application code.

03

Purpose limitation

Data uploaded to Workforce Ledger is used solely to produce your organisation's dashboard, metrics, and cleansed output. Processing is limited to the specific functions you initiate.

We do not
Use your data for marketing or benchmarking
Share data with any third party
Aggregate or compare data across organisations
Train AI or machine learning models on your data
04

Authentication and access control

Access to Workforce Ledger requires authenticated login. Sessions are time-limited and all access is scoped to the authenticated user's organisation only.

User management allows you to control who in your organisation can view and edit data.

05

No direct system access required

Workforce Ledger works from CSV exports — we never request or require direct access to your HRIS, payroll system, or internal network. You control what data you provide and when.

You remain the data controller. We act as a data processor under the Privacy Act 1988 (Cth).

06

Data retention and deletion

Customer data is retained for the duration of the active subscription. On account closure, data is deleted within 30 days unless a shorter period is requested.

You can request deletion of your data at any time by contacting us directly.

07

Privacy Act compliance

Workforce Ledger operates as a data processor under the Privacy Act 1988 (Cth). You remain the data controller and retain full ownership and regulatory responsibility for your data.

All data is hosted in Australia, ensuring cross-border disclosure obligations are not triggered.

08

Specific security requirements

If your organisation has specific security, privacy, or data handling requirements — including documented internal policies or supplier assessment processes — we are willing to discuss and accommodate where practical. Get in touch.