About this policy
Iron Watch is a security workforce operations, compliance, rostering and reporting platform. This policy explains how personal information may be collected, held, used, disclosed, secured and otherwise managed in connection with Iron Watch.
We seek to manage personal information consistently with applicable Australian privacy laws, including the Privacy Act 1988 (Cth) and the Australian Privacy Principles where they apply. Nothing in this policy limits a right that cannot lawfully be limited.
Our role
Iron Watch may process information in its own right for account creation, billing, support, security, administration and product operation. It may also process information on behalf of a customer about guards, employees, contractors, clients, sites, credentials, shifts and incidents.
Customers are responsible for determining that they are permitted to collect, use and provide that information. Iron Watch processes customer information only for legitimate platform, support, security and service-delivery purposes and applicable contractual requirements.
Information we may collect
Depending on use, information may include:
- Account details, role, authentication and contact information
- Workforce identifiers, employment status, availability, leave, rosters, hours and site assignments
- Security licence and credential details, issue and expiry dates and supporting documents
- Client, site, operational contact, instruction and staffing information
- Shifts, attendance, incidents, reports, compliance exceptions and coverage communications
- IP address, browser or device details, audit records, security events and diagnostics
- Limited information required for an authorised AI function
Sensitive information
Some incident or workforce information may be sensitive information. Customers should only enter sensitive information where reasonably necessary for a legitimate operational, employment, safety, compliance or legal purpose. Sensitive incident access should be restricted to appropriately authorised personnel. Iron Watch is not intended to hold unnecessary medical, biometric, political, religious or similar information.
Collection and use
Information may be collected directly, from an Iron Watch customer, through an authorised import or upload, through platform activity, secure response links, integrations, system-generated records or support communications.
Information may be used to operate and secure Iron Watch; authenticate users; manage workforces, credentials, shifts, attendance and incidents; identify expiry and roster risks; support Rapid Cover; preserve audit trails; create authorised reports; provide AI-assisted functions; detect misuse; provide support; improve reliability; and satisfy legal obligations. We do not sell guard personal information.
Artificial intelligence and automated support
AI may interpret roster requests, explain recommendations, summarise operational risk and extract proposed document fields. AI is not authoritative for licence validity, credential validity, employment status, legal compliance, availability, conflicts or final assignments.
AI-extracted document fields are proposals only. They require authorised human confirmation and do not mark a credential verified. Material staffing decisions remain subject to authorised human review. Iron Watch is a decision-support platform, not an autonomous employment decision-maker.
Service providers and overseas processing
Trusted cloud hosting, database, authentication, infrastructure, AI, messaging, security and monitoring providers may process information where reasonably required to operate the service. Providers may operate infrastructure outside Australia. Where applicable, reasonable steps will be taken regarding cross-border information handling consistent with applicable law.
Security
Controls may include authentication, MFA for privileged access, role-based permissions, tenant isolation, row-level security, private document storage, access controls, audit logging, protected credentials, encrypted transport, backups, security testing, monitoring and least privilege.
No internet-connected system can be guaranteed completely secure. Users must protect credentials and promptly report suspected unauthorised access.
Access, correction, deletion and complaints
Subject to applicable law and legitimate security needs, an individual may request access to or correction of personal information. Where information is held only for a customer, Iron Watch may refer the request to that customer. Identity may need to be verified.
Where information is no longer reasonably required and no legal, contractual, audit, investigation or preservation requirement applies, it may be securely deleted or de-identified. Active-system deletion may not immediately remove secure backup copies, which ordinarily expire under the applicable backup lifecycle.
Privacy requests and complaints may be sent to shakeeb@cornerman.agency. Where applicable, a person may also have a right to complain to the Office of the Australian Information Commissioner.
Retention, breaches and changes
Information is retained only as reasonably required for service delivery, legitimate operations, contracts, security, disputes, audit, regulation and law. A legal hold, investigation or litigation may require longer retention.
Suspected breaches will be investigated. Where applicable law requires notification of an eligible data breach, affected parties and the relevant regulator will be notified in accordance with those requirements.
This policy may change when services, technology or legal obligations change. The current version displays its effective date. Material changes will be communicated where reasonably appropriate.