Privacy policy
What personal information we handle, why, who else can see it, where it goes, and how to get at yours or complain about it.
1. Who we are, and what this covers
Adeel Hamid trading as CalibraWorks (ABN 61661477964) operates a calibration laboratory management system. This policy explains how we handle personal information, as the Privacy Act 1988 (Cth) and the Australian Privacy Principles require.
Most of the personal information in the system was not collected by us. It belongs to the laboratories that subscribe: their staff, and the contacts at their customers. We handle it on their behalf and under their instructions, which the data processing agreement sets out. If you are a contact at a laboratory’s customer, that laboratory is who holds your information, and this policy tells you what we do with it for them.
2. What we collect
About the people who use the system:
- name, email address, and the role they hold in the laboratory
- sign-in records — when, and from what address
- competence and training records, where the laboratory keeps them here, because ISO/IEC 17025 §6.2 requires a laboratory to hold them
- every change a person makes to a record, in an audit log that cannot be edited or deleted
2a. Whether you can use this anonymously (APP 2)
You cannot, and this is one of the few places where that is the right answer rather than a convenience.
A calibration laboratory’s records are a chain of attribution. ISO/IEC 17025 requires the laboratory to show that a named, competent person performed each piece of work, to keep a technical record identifying who did what, and to issue certificates over the name of an authorised signatory. A customer relying on a certificate is entitled to know whose judgement stands behind it. An anonymous or pseudonymous user would make every record that person touched unusable as evidence, which is the opposite of what the laboratory is paying for.
So identifying yourself is impracticable to avoid here, in the sense APP 2 uses. It applies to the people who work in a laboratory. It does not oblige a laboratory’s own customers to hold an account with us at all — anybody can check a certificate at our verification page without signing in or identifying themselves.
3. What laboratories put in about their own customers
A laboratory records who its customers are and how to reach them: business name, contact name, email address, phone number, and delivery and billing addresses. It also records the instruments it holds for them and the work it has done.
We do not decide what goes in, we do not use it for our own purposes, and we do not contact those people except by sending a message the laboratory asked us to send on its behalf — a recall notice, a certificate, a quote, an invoice.
4. Why we handle it
To run the service: to sign people in, to show a laboratory its own records, to produce certificates and invoices, to send the messages a laboratory asks us to send, and to keep the audit trail that a quality system depends on.
To bill for the service, and to contact an account holder about it.
To keep the service secure and to investigate misuse.
We do not sell personal information. We do not use it for advertising. We do not use it to train machine-learning models.
4a. Messages we send you (APP 7)
If you hold an account with us we may email you about the service — changes that affect how you work, security notices, billing, and from time to time new features or training. Every promotional message carries an unsubscribe link and you can opt out at any time. Opting out does not stop the messages we have to send: an invoice, a security notice, or a change to these terms is part of the service rather than marketing.
We never market to a laboratory’s own customers. Their addresses are in the system so the laboratory can write to them — a recall notice, a certificate, a quote — and those messages are the laboratory’s, sent under its name and its sending domain. Using that list for our own purposes would be using our customer’s customer list, and we do not.
5. Who else can see it, and where they are (APP 8)
We use a small number of providers to run the service. Each is listed below with what it can see and where it is, and the list is kept current — it is generated from the same record the data processing agreement uses, so the two cannot disagree.
Personal information is disclosed to recipients outside Australia. Under APP 8 we remain accountable for how an overseas recipient handles it, and we take reasonable steps to ensure they handle it consistently with the Australian Privacy Principles.
- Supabase — Database, file storage and sign-in. Sydney, Australia (ap-southeast-2). Supabase Inc is incorporated in the United States.
- Hostinger — Runs the application itself. Asia. Hostinger has no Australian data centre; its Sydney presence is a cache for static files. (outside Australia)
- The email provider (SMTP) — Delivers recall notices, certificates, quotes and invoices. Depends on the provider configured. Brevo, the first, processes in the European Union. (outside Australia)
- Stripe — Takes the laboratory’s subscription payment, and card payments from its customers. United States and Australia. (outside Australia)
- Amazon Bedrock — Reads a customer’s written list of instruments into intake lines a person then confirms. Sydney, Australia (ap-southeast-2), pinned to the region rather than a cross-region profile. — not yet connected
6. Where the data actually sits
The database and all stored files — every record, every certificate, every reading — are held in Sydney, Australia, and do not leave it.
The application server is a separate machine and is the one that reads those records into memory to render pages and documents. It currently runs outside Australia (Hostinger, The email provider (SMTP), Stripe). This is an interim arrangement recorded as a decision rather than left as an oversight, and the target is Australian hosting. We state it here because a customer is entitled to know that the two are not the same question, and because a residency claim that quietly covers only the database is a misleading one.
7. How we protect it
Encrypted in transit and at rest. Each laboratory’s data is isolated by the database itself, not by application code, so a fault in the application cannot show one laboratory another’s records. Access is by role, checked by the database on every statement rather than read from a token, so removing somebody’s access takes effect immediately.
Documents are held in private storage and served through short-lived links. Certificates are stored where they cannot be altered or deleted by anyone, and every download is checked against a hash recorded when the certificate was issued.
8. How long we keep it
For as long as the laboratory needs it, which for calibration records is a long time: certificates and the readings behind them are kept indefinitely, because a certificate may be relied on for decades and the readings are the only thing that can reproduce it.
Where the law sets a shorter or longer period, the longer applies. A laboratory can set a retention period for its own records, and that period is a floor rather than a ceiling.
Nothing is deleted automatically. Disposal is a deliberate act with a name against it.
9. Getting at your information, and correcting it (APP 12, APP 13)
You can ask us for a copy of the personal information we hold about you, and ask us to correct it, by writing to privacy@calibraworks.com. We will respond within 30 days.
If your information was put into the system by a laboratory — for example, you are a contact at one of its customers — we will usually direct your request to that laboratory, because it is the one that holds it and decides what it says. We will tell you who that is and help them answer you.
10. If something goes wrong
We have a data breach response plan. Where a breach is likely to result in serious harm we will notify the affected individuals and the Office of the Australian Information Commissioner, as the Notifiable Data Breaches scheme requires. The scheme allows 30 days from suspicion to complete an assessment, and our own plan treats the clock as starting when anybody in the business first hears of it rather than when it is escalated.
Where the breach affects a laboratory’s records we will tell that laboratory without undue delay and in any event within 72 hours of becoming aware, so that it can meet its own obligations to its customers.
11. Complaints
Complain to us first, at privacy@calibraworks.com. We will acknowledge within 5 business days and respond within 30 days.
If you are not satisfied with our response you can complain to the Office of the Australian Information Commissioner: 1300 363 992, enquiries@oaic.gov.au, GPO Box 5218, Sydney NSW 2001, https://www.oaic.gov.au.
12. Changes to this policy
We will post any change here with a new version number and effective date. Where a change materially affects how we handle personal information we will tell account holders by email before it takes effect.