Privacy Policy
Version 2.0.0 - effective 5 September 2026
1. Introduction
This Privacy Policy explains how CommandPost Pty Ltd ACN 641 527 148 (CommandPost, we, us, our) collects, holds, uses and discloses personal information in connection with the CommandPost platform, a crisis-management and incident-coordination service used by government and public-safety agencies (the Platform).
CommandPost is an APP entity for the purposes of the Privacy Act 1988 (Cth) (Privacy Act) and is bound by the 13 Australian Privacy Principles (APPs) in Schedule 1 to that Act. This Policy is our APP 1 privacy policy. It is written to be clear and specific about what the Platform actually does. Where a practice is described in this Policy, it is one the Platform implements today, not one we intend to implement in the future.
Where the Platform is used to hold health information, the handling of that information may also be regulated by state or territory health-records legislation, such as the Health Records and Information Privacy Act 2002 (NSW), the Health Records Act 2001 (Vic) and the Health Records (Privacy and Access) Act 1997 (ACT). Where such legislation imposes a higher standard than the APPs, the higher standard applies.
This Policy applies to the version of the Platform hosted in Australia. It is published only on a deployment whose hosting region resolves to Australia. If you are using a deployment hosted in another country, a different version of this Policy governs, and the Platform displays that version to you instead.
2. Who we are and the role of your Agency
Access to the Platform is provisioned through an organisation, typically a government department, emergency service, health service, local council, event operator or other public-safety body (your Agency). Your Agency decides who may use the Platform, what roles and permissions each user holds, which operations each user may enter, and what information is entered into the Platform during an operation.
This creates two distinct relationships, and this Policy is careful to distinguish them:
- Information about you as a user of the Platform, such as your name, email address, phone numbers, authentication details, session records and audit records. CommandPost collects and holds this information in its own right in order to provide you with an account and keep the Platform secure. This Policy governs that information directly.
- Information your Agency enters into the Platform during operations, such as incident logs, tasks, chat messages, contact lists, form submissions, uploaded files, location tracks and reports. This information may concern you, other users, and third parties such as members of the public, patients, casualties and witnesses. Your Agency determines why this information is collected and how it is used, and it remains your Agency's information. CommandPost holds and processes it on your Agency's behalf and on your Agency's instructions, subject to the security, retention and access controls described in this Policy. Your Agency's own privacy policy, and any privacy legislation that binds your Agency (which for state and territory agencies may be state or territory legislation rather than the Privacy Act), governs that information. If you have a question or request about that information, your first point of contact is your Agency.
The Platform enforces tenant isolation: every operational record is scoped to the Agency and operation that created it, and access to a record requires membership of that Agency and, for operation-scoped records, an active session in that operation with a role that carries the relevant permission.
3. The personal information we collect (APP 3)
We collect only the personal information that is reasonably necessary to provide and secure the Platform. The categories below reflect what the Platform actually stores.
Account information. Your first name, last name and email address; an avatar colour; your language preference; display preferences (dark mode, reduced motion); the date your account was created; your account status; and an internal identifier that links your account to the identity service described in Section 7. One or more phone numbers, with country code, together with whether each number has been verified and whether it is your primary number.
Authentication and security information. The multi-factor authentication (MFA) methods you have enabled (authenticator app, SMS, WhatsApp, email, voice call or recovery codes) and the phone number each is tied to; one-time access codes and recovery codes, which are stored only as hashes; session records containing a hashed session token, the IP address and browser or device identifier (user agent) from which you signed in, and the times the session was created and expires; and a record of any forced password reset. Your password is verified by the identity service described in Section 7. CommandPost does not store your password in a readable form.
Registration information. If your Agency registers with the Platform through the self-service registration form, we collect from the person registering: first name, last name, email address and phone number; the Agency's name, type, country, Australian Business Number or New Zealand Business Number or company registration number, and postal address; a description of the intended use of the Platform, the anticipated number of users, and whether the Agency is responding to an active emergency; the time at which the Terms of Service and this Policy were accepted; and, for fraud prevention, the IP address, user agent and bot-detection score associated with the registration.
Operation session information. Each time you enter an operation, the Platform records the operation, control-room instance, role and team you entered with, the IP address and user agent of the device you used, the time you entered, your last activity time, when the session ended and why (for example log-out, timeout, or termination by a concurrent session or an administrator).
Legal acceptance records. When you accept a legal document such as the Terms of Service or this Policy, the Platform records the document version accepted, its content hash, the language in which you read it, the time of acceptance, and the IP address and user agent from which you accepted it.
Audit records. The Platform keeps an append-only audit trail of security-relevant and administrative actions, such as sign-in, token refresh, permission changes, user status changes, configuration changes and every failed request. Audit entries carry your user identifier, the Agency and operation involved, a request identifier, the action taken and, for administrative changes, the before and after values. Personal information such as email addresses, phone numbers, addresses and names appearing in before and after values is masked before the entry is written. Passwords, tokens and request bodies are never written to the audit trail.
Support information. If you raise a support ticket through the Platform, we collect the title, description and category of the ticket, your preferred contact method and, if you provide one, a callback number.
Operational content entered by your Agency. As described in Section 2, this includes incident logs, tasks, chat messages, reactions and read receipts, contacts, form submissions, uploaded files and media, reports, standard operating procedures and other content. It may identify you as the author, editor or assignee of a record. It may contain personal information and sensitive information about third parties, which your Agency is responsible for collecting lawfully.
Location information. If your Agency enables resource tracking and you grant the mobile application permission to access your device's location, the mobile application sends location breadcrumbs to the Platform while tracking is active. Each breadcrumb records latitude, longitude, accuracy, speed, heading, whether the device is moving, battery level and charging state, together with the operation, instance, team and user it belongs to and the time it was recorded. Location is collected only while you are tracked within an operation, and only if your device permits it.
Information from members of the public. Some Agency features collect information from people who are not users of the Platform, for example public forms, public booking links, incident-log location requests sent to a person by link, shared incident-log and file links, and the public hotline. Information collected through these features is your Agency's information. Public form submissions record the submitter's IP address for abuse prevention; that address is masked after 48 hours.
Telemetry. The web application sends performance beacons to the Platform's own servers containing the route viewed, the view mode and a numeric timing value. Beacons carry no personal information and no Agency identifiers, are not written to the audit trail, and are not sent to any third party. The Platform uses no third-party analytics or advertising services.
4. How we collect personal information (APP 3 and APP 5)
We collect personal information:
- directly from you, when you register, accept an invitation, complete your profile, enable an MFA method, sign in, enter an operation, raise a support ticket, accept a legal document, or enter content into the Platform;
- from your Agency, when an administrator invites you, assigns you a role, adds you to a team or operation, or bulk-imports users;
- automatically from your device, in the form of IP address, user agent, session timing, performance beacons and, where enabled and permitted, device location; and
- from other users, where they record information about you in operational content, for example by assigning you a task or naming you in an incident log.
Where it is reasonable and practicable, we notify you of the matters required by APP 5 at or before the time of collection. For information collected directly through the Platform, this Policy is that notice. For information your Agency collects about third parties, your Agency is responsible for giving any required notice.
Unsolicited personal information (APP 4). If we receive personal information we did not solicit, for example in a support ticket or an email, and we could not lawfully have collected it, we will destroy or de-identify it as soon as practicable, unless it is contained in a Commonwealth record or we are required by law to retain it.
5. Why we collect, use and disclose personal information (APP 6)
We collect, hold, use and disclose personal information for the primary purpose of providing, securing and supporting the Platform for you and your Agency, and for related secondary purposes that you would reasonably expect. Specifically:
- to create and administer your account and to identify you to your Agency and to other users in the same operation, by name, avatar and role;
- to authenticate you and to deliver MFA codes and verification codes to your email address or phone number;
- to manage sessions and enforce security controls, including idle and absolute session timeouts, concurrent-session rules, rate limiting, lockout and revocation;
- to prevent fraud and abuse, including bot detection on registration and public forms, and review of self-service registrations before an Agency is approved;
- to keep an audit trail of security and administrative events, as required by our own obligations and by the assurance frameworks our government customers rely on;
- to record acceptance of legal documents, so that both you and we can establish which version of a document was accepted, when and from where;
- to deliver the operational features your Agency uses, including incident logging, task management, chat, notifications, forms, reports, exports and resource tracking;
- to send you service messages, such as invitations, verification emails, MFA codes, notifications you or your Agency have configured, and notices of changes to legal documents;
- to respond to your support requests; and
- to comply with our legal obligations, including under the Privacy Act, the Archives Act 1983 (Cth) where applicable, and lawful requests from courts, regulators and law-enforcement agencies.
We do not use personal information for any purpose unrelated to the Platform without your consent, unless the use is required or authorised by law.
6. Sensitive information
The Platform is used during emergencies. Operational content entered by your Agency may include sensitive information as defined in the Privacy Act, including health information (for example triage notes, injuries, medical conditions and medications recorded about a casualty or patient), and information about a person's racial or ethnic origin, religious beliefs or criminal record where that is relevant to an incident.
CommandPost does not solicit sensitive information about you as a user, other than health-related accessibility preferences you choose to set.
Sensitive information about third parties is collected by your Agency, not by CommandPost. Your Agency is responsible for ensuring it has the individual's consent, or that the collection is otherwise permitted under APP 3.4, for example because it is necessary to lessen or prevent a serious threat to life, health or safety, or is required or authorised by law. CommandPost holds and processes that information on your Agency's behalf, applies the security and access controls described in Section 9 to it, and uses it only to provide the Platform to your Agency.
Operation-session records, which combine identity, role, IP address and device information, are classified by the Platform as OFFICIAL: Sensitive and are handled accordingly.
7. Disclosure to third parties and service providers (APP 6)
Your Agency. Your Agency's administrators can see your account information, your roles and permissions, your operation-session history, and any content you enter. Your Agency can export operational content, including content that identifies you.
Other users. Users in the same Agency, team or operation can see your name, avatar, role, availability status and the content you author, and, if resource tracking is enabled, your current location and location history within that operation.
Service providers. We use the following categories of service provider to operate the Platform. Each receives only the personal information necessary to perform its function.
- Cloud infrastructure and identity. The Platform runs on Amazon Web Services (AWS). AWS hosts the application servers, primary database, cache and file storage, and provides the identity service (Amazon Cognito) that verifies your password, issues your sign-in tokens and holds your MFA configuration. The identity service is configured separately from the application's own hosting region, as described in Section 8.
- Transactional email. Invitations, verification emails, MFA codes sent by email, notifications and legal-document notices are sent through Postmark. Postmark receives your email address and the content of each message, and returns delivery status information which we record against the message.
- SMS, WhatsApp and voice. Phone verification, MFA codes sent by SMS, WhatsApp or voice call, and notifications your Agency configures for those channels are delivered through Twilio. Twilio receives the destination phone number and the message content.
- Bot protection. Self-service registration and public forms are protected by Google reCAPTCHA, which receives your IP address and browser signals directly from your browser and returns a score to us.
- Address lookup. When an address is typed into an address field, the text you type is sent through our servers to the Google Places service to return suggestions.
- Map tiles. Maps are rendered in your browser from tile providers, which may include Mapbox, OpenStreetMap, Esri ArcGIS Online and OpenTopoMap. Your browser requests tiles from the provider directly, so the provider receives your IP address and the map area you are viewing.
- AI-assisted features. Where your Agency enables them, certain features send content to Anthropic's API to generate a draft: a description you type or a document you upload when generating a form, a description you type when generating a standard operating procedure, and the free-text note you type when asking the Platform to format an incident log entry. Only the content you submit to the feature, together with the structural instructions needed to produce a draft, is sent. Your name, email address and other account information are not. The draft is returned to you for review before anything is saved.
Legal and regulatory disclosure. We may disclose personal information where required or authorised by law, including in response to a subpoena, warrant, court order or a lawful request from a regulator or law-enforcement agency, and to establish, exercise or defend a legal claim. Where the request concerns your Agency's operational content, we will refer the requesting party to your Agency where the law permits.
Business transfer. If CommandPost is acquired or merges with another entity, personal information may be transferred to the successor, which will be bound by this Policy in respect of that information.
We do not sell personal information.
8. Cross-border disclosure and data residency (APP 8)
Where your Agency's deployment is hosted. The Platform is deployed per region, and the region a deployment runs in determines which version of this Policy is displayed. This version is displayed only where the deployment's hosting region resolves to Australia. Accordingly, the application servers, primary database, cache and file storage for your Agency's deployment are located in Australia. A deployment whose region has not been configured makes no residency claim and does not display this Policy.
Components configured separately. The identity service (Amazon Cognito) is configured with its own region setting, separate from the application's hosting region. It holds your email address, name, phone number for MFA, MFA configuration and credential data. For the Australian deployment it is configured within an AWS region; if your Agency requires confirmation of the specific region, contact us using the details in Section 16.
Service providers outside Australia. The service providers described in Section 7 for email delivery (Postmark), SMS, WhatsApp and voice (Twilio), bot protection and address lookup (Google), map tiles (Mapbox and other tile providers) and AI-assisted features (Anthropic) are operated by companies headquartered in the United States of America and may process the limited information they receive outside Australia, including in the United States. Before disclosing personal information to an overseas recipient, we take steps that are reasonable in the circumstances to ensure the recipient handles the information in a way that does not breach the APPs, including contractual terms governing the recipient's use, security and onward disclosure of the information. Under APP 8.1 we remain accountable for those recipients' handling of the information unless an exception in APP 8.2 applies.
Your Agency's own transfers. Your Agency may export operational content or share links to it with parties of its choosing, including overseas parties. Those disclosures are made by your Agency, not by CommandPost.
9. Security of personal information (APP 11)
We take steps that are reasonable in the circumstances to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure. The measures the Platform implements include:
- Encryption in transit. All connections to the Platform, including database and cache connections in production, use TLS 1.2 or later.
- Credential protection. Passwords are verified by the identity service and are never stored in readable form by CommandPost. Session tokens are stored only as SHA-256 hashes. One-time codes and recovery codes are stored only as hashes. Secrets that the Platform must hold in recoverable form, such as integration credentials and the short-lived password cache used during MFA, are encrypted with AES-256-GCM using a unique initialisation vector per record, with keys held outside the database and rotated.
- Multi-factor authentication. MFA by authenticator app, SMS, WhatsApp, email, voice call or recovery code is supported, and your Agency may require it for an operation.
- Session controls. Sessions expire after 4 hours of inactivity and 5 days in absolute terms, at which point you must sign in again. All sessions are invalidated when your password, roles or MFA configuration change or when your account is deactivated.
- Access control. Permissions are role-based and checked on every request. Every operational query is scoped to the Agency and operation it belongs to.
- Rate limiting and lockout. Sign-in, MFA and public endpoints are rate-limited and lock out after repeated failures. Lockouts are capped at 5 minutes so that emergency responders are never locked out for longer than that.
- Bot protection on registration and public forms.
- Audit trail. Security and administrative actions are written to an append-only audit log that cannot be updated or deleted by the application. Personal information in audit values is masked, and log lines carry user identifiers rather than names or contact details. Capability tokens in URLs are redacted before logging.
- Local storage on devices. The mobile application stores its local database in encrypted form (SQLCipher). The web application never stores information classified OFFICIAL: Sensitive in persistent browser storage.
- Input validation on every request, with strict schemas that reject unexpected fields.
- Access to production systems is restricted to authorised personnel and is itself logged.
No system is completely secure. If we become aware of an eligible data breach involving personal information we hold, we will assess it and, where the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act requires, notify the affected individuals and the Office of the Australian Information Commissioner. Where the breach concerns your Agency's operational content, we will notify your Agency so that it can meet its own obligations.
10. Retention and deletion (APP 11.2)
We retain personal information for as long as it is needed for the purposes in Section 5, or as long as the law or a Commonwealth record-keeping obligation requires. The Platform applies the following retention rules automatically:
| Information | Retention |
|---|---|
| Audit trail | 7 years, after which whole monthly partitions are removed. Individual audit rows are never edited or deleted. |
| Expired sign-in sessions and administrator sessions | Purged 90 days after expiry |
| Expired invitations | Purged 90 days after expiry |
| Used recovery codes | Purged 30 days after use |
| Expired or used one-time access codes | Purged 30 days after expiry or use |
| Submitter IP addresses on public form submissions | Masked after 48 hours |
| Public hotline conversations | Purged after the period your Agency configures, which defaults to 365 days |
| Orphaned chat attachments never linked to a sent message | Purged after 24 hours |
| Location breadcrumbs | Retained for the life of the operation record. The Platform does not automatically delete location history; removal is by your Agency's request. |
| Operational content (incident logs, tasks, chat, files, forms, contacts, reports) | Retained by your Agency for as long as your Agency requires. Records are deactivated rather than destroyed, so that the incident record remains complete and auditable. |
Deleting your account. You may delete your own account from your account settings after re-entering your password. When you do, the Platform anonymises your account: your name is replaced with "Deleted User", your email address is replaced with a placeholder, your phone numbers, MFA methods, access codes and recovery codes are deleted, your roles, licences and sessions are deactivated, and your identity-service account is disabled. Operational content you authored remains in your Agency's records, attributed to a deleted user, because it forms part of the incident record. Audit entries that reference your user identifier are retained for their full retention period. Your Agency's administrators can also deactivate your account, which suspends access without anonymising your profile.
11. Access and correction (APP 12 and APP 13)
Self-service. You can view and update your name, avatar colour, language and display preferences, phone numbers and MFA methods from your account settings at any time. You can download a copy of the personal information held in your account from the data export function in your account settings.
Requests to CommandPost. You may ask us for access to, or correction of, personal information we hold about you as a user by contacting us using the details in Section 16. We will respond within 30 days. We will give access in the manner you request where it is reasonable and practicable to do so. We may decline access in the circumstances permitted by APP 12.3, for example where giving access would have an unreasonable impact on the privacy of others or would prejudice enforcement activities, and if we do we will tell you why in writing and how you can complain. If we decline to correct information, we will tell you why, and you may ask us to attach a statement to the information noting that you consider it inaccurate, out of date, incomplete, irrelevant or misleading.
Requests about operational content. Requests for access to, or correction of, personal information contained in your Agency's operational content, including information about you that another user entered, should be made to your Agency, which controls that content and holds the tools to view, correct and export it. If you contact us instead, we will refer your request to your Agency and assist it in responding.
Data quality (APP 10). We take reasonable steps to ensure the personal information we collect is accurate, up to date and complete. The Platform verifies your email address before your account is activated and verifies phone numbers before they are used for MFA, and account details are collected directly from you.
12. Your other rights under the APPs
Anonymity and pseudonymity (APP 2). The Platform is an authenticated, accountable system for public-safety operations. Because every action must be attributable to an identified responder, it is impracticable for us to deal with you anonymously or under a pseudonym as a user. Members of the public interacting with some Agency features, such as the public hotline, may do so without an account, subject to the design of the feature your Agency has deployed.
Direct marketing (APP 7). We do not use personal information for direct marketing. Messages we send you are service messages relating to your account, your Agency's operations, or changes to legal documents.
Government-related identifiers (APP 9). We do not adopt, use or disclose a government-related identifier of an individual as our own identifier. Your Agency may record an Australian Business Number or company registration number for the Agency itself during registration; these are identifiers of the organisation, not of an individual.
13. Cookies and similar technologies
The Platform uses cookies only to keep you signed in. In production, two cookies are set: an access-token cookie and a refresh-token cookie. Both are httpOnly, Secure and SameSite=Strict, meaning they cannot be read by scripts in your browser and are not sent on cross-site requests. The web application also keeps a minimal snapshot of your identity (identifier, name, email address, avatar colour and whether you are an external user) in session storage, which is cleared when the tab closes or you sign out.
We do not set advertising, analytics or tracking cookies, and no third party sets cookies through the Platform other than Google reCAPTCHA on the registration and public-form pages, where it is used solely for bot protection.
The mobile application holds its sign-in tokens in the device's secure storage rather than cookies.
14. Complaints
If you believe we have breached the APPs or a registered APP code, or handled your personal information in a way that is inconsistent with this Policy, you may complain to us using the details in Section 16. Please describe the conduct you are concerned about and how you would like it resolved. We will acknowledge your complaint within 7 days, investigate it, and give you a written response within 30 days. If we need longer, we will tell you why and when you can expect a response.
If you are not satisfied with our response, or you do not receive one within that time, you may complain to the Office of the Australian Information Commissioner (OAIC):
- Website: www.oaic.gov.au
- Phone: 1300 363 992
- Post: GPO Box 5288, Sydney NSW 2001
If your complaint concerns your Agency's handling of operational content, the appropriate regulator may be the privacy regulator for your Agency's state or territory rather than the OAIC. We will help you identify the right body.
15. Changes to this Policy
We may update this Policy from time to time to reflect changes to the Platform, our service providers or the law. Each version of this Policy carries a version number, an effective date and a summary of what changed, all of which are displayed with the Policy in the Platform.
How you are notified. Where a change is material, we will notify you before it takes effect by email to the address registered on your account or by a notice displayed in the Platform, or both, stating what has changed and the date the new version takes effect. Minor changes that do not affect how your personal information is handled, such as corrections and clarifications, may be made without notice and are identified in the version summary.
No re-acceptance is required. Because the Platform is used during live emergencies, a new version of this Policy does not interrupt your access or require you to accept it again before continuing. Your continued use of the Platform after the effective date of a new version constitutes your acceptance of that version. If you do not agree to a change, you should stop using the Platform and may delete your account as described in Section 10, and your Agency may end its agreement with us in accordance with its terms.
Previous versions of this Policy remain available on request, and the Platform keeps a record of which version you accepted and when.
16. Contact
Privacy enquiries, access and correction requests, and complaints should be sent to:
- Privacy enquiries and complaints: compliance@commandpost.com.au
- Security incidents, including a suspected compromise of your account or of any personal information: security@commandpost.com.au
- General support: support@commandpost.com.au
Please address correspondence to CommandPost Pty Ltd ACN 641 527 148. Your Agency's administrator remains your first point of contact for questions about operational content and for access requests concerning it.