HR data is sensitive. We've built Workforce Ledger from the ground up to minimise risk, maximise your control, and comply with Australian privacy obligations.
All data processed and stored by Workforce Ledger is hosted in AWS Sydney. Your data never crosses international borders, satisfying Australian Privacy Act cross-border disclosure obligations and keeping you on solid ground with local compliance requirements.
Every organisation's data is completely isolated using row-level security enforced at the database layer. This means even if there were a bug in our application code, one customer cannot access another's records. Isolation is structural, not just policy.
Each customer's data is cryptographically scoped to their organisation ID and cannot be queried without the correct authenticated session.
All data is encrypted at rest within the database. All connections to Workforce Ledger use HTTPS — no unencrypted data transfer is permitted at any point in the system.
Credentials and API keys are stored in a managed secrets service and are never exposed in logs, error messages, or application code.
Data uploaded to Workforce Ledger is used solely to produce your organisation's dashboard, metrics, and cleansed output. Processing is limited to the specific functions you initiate.
Access to Workforce Ledger requires authenticated login. Sessions are time-limited and all access is scoped to the authenticated user's organisation only.
User management allows you to control who in your organisation can view and edit data.
Workforce Ledger works from CSV exports — we never request or require direct access to your HRIS, payroll system, or internal network. You control what data you provide and when.
You remain the data controller. We act as a data processor under the Privacy Act 1988 (Cth).
Customer data is retained for the duration of the active subscription. On account closure, data is deleted within 30 days unless a shorter period is requested.
You can request deletion of your data at any time by contacting us directly.
Workforce Ledger operates as a data processor under the Privacy Act 1988 (Cth). You remain the data controller and retain full ownership and regulatory responsibility for your data.
All data is hosted in Australia, ensuring cross-border disclosure obligations are not triggered.
If your organisation has specific security, privacy, or data handling requirements — including documented internal policies or supplier assessment processes — we are willing to discuss and accommodate where practical. Get in touch.