Privacy Policy

Current version · Last updated: 24 September 2026

1. Who we are

RopeLogix, supplied by Nice Technology Group Pty Ltd. RopeLogix is supplied by Nice Technology Group Pty Ltd (ABN 29 674 686 269) (“we”, “us”). We provide a digital platform for rope access compliance management. Privacy contact: privacy@ropelogix.com.

2. What we collect

We collect information you provide directly, and some information generated when you use the Platform:

  • Account data: name, email address, phone number, organisation name and role. If you sign in with Apple, the identifier Apple provides.
  • Professional credentials: IRATA certificate number and level, expiry dates, First Aid / White Card / site induction details, and the certificate files you upload
  • Work records: logbook entries (dates, hours, work descriptions, location), job records, SWMS content, rescue plans, pre-start records, toolbox talk notes, incident reports, equipment records and inspection photos
  • Photos and voice notes: photos and short audio memos you attach to records
  • Signatures: signature images, with the time, device details (browser/user agent) and IP address at the moment of signing
  • Location data: GPS coordinates captured at specific moments only — when you submit a pre-start, when you sign a document, and when a Mayday is raised. Job and site addresses are also stored. We do not track your location continuously.
  • Emergency data: when a Mayday is raised, the time, location, who raised it, who responded, and — for an automatic man-down alert — a snapshot of the phone’s motion-sensor readings. The phone watches its motion sensors locally when you turn man-down detection on; sensor data is only sent to us when an alert fires.
  • Device data: push-notification tokens for the RopeLogix mobile apps, and security data such as trusted-device records if you use multi-factor authentication
  • Marketplace data: if you publish an availability card or apply for work, your level, banded hours, region and availability. Your name and contact details are only released to a company after you apply and are shortlisted.
  • Health-adjacent data: medical fitness certificate type and expiry only — we do not collect medical diagnoses or records
  • Payment data: card payments are handled by Stripe. We do not see or store your card number. We keep records of what you bought and paid, and the tax invoices we issued.
  • Website analytics: ropelogix.com and the app use Cloudflare Web Analytics, which counts page views without cookies

3. How we use your data

  • To provide the RopeLogix platform services
  • To send credential expiry reminders, sign-off requests and system notifications by email and push notification
  • To deliver Mayday alerts to the crew on the job and the organisation’s nominated responders
  • To send SMS verification codes for multi-factor authentication, and SMS or phone-call Mayday escalation, once those features are switched on (see §5)
  • To run the AI features described in §5
  • To record weather conditions for a job site
  • To process payments, issue tax invoices, handle refunds and chargebacks, and meet our tax obligations
  • To keep the Platform secure, including audit logs of who changed what
  • To comply with our legal obligations

4. Where your data is stored

  • Application and database: the RopeLogix application and its PostgreSQL database run on servers located in Australia. Traffic reaches them through Cloudflare’s network.
  • Files: documents, signatures, photos, voice notes and other uploads are stored in Amazon Web Services S3 in the Sydney region (ap-southeast-2).
  • Service providers: the providers in §5 process some data on their own systems, which may be outside Australia (see §6).

Data is encrypted in transit (HTTPS). We keep your data for as long as your account is active, and after that as described in our Terms and §8 below.

5. Service providers

We use these providers to run RopeLogix. Each receives only what it needs for its task.

  • Stripe: payment processing. Your card details go directly to Stripe. Stripe Privacy Policy
  • Cloudflare: DNS, network and secure tunnel in front of the application, hosting of ropelogix.com, email routing for our @ropelogix.com addresses, and cookieless Web Analytics
  • Amazon Web Services: file storage (S3, Sydney region)
  • Resend: transactional email (sign-off links, credential reminders, notifications)
  • Anthropic: AI processing. What is sent depends on the feature:
    • AI SWMS drafting — the job details you enter
    • SWMS document import — the SWMS file (PDF or image) you upload
    • SWMS suggestions — the SWMS title and content
    • Equipment serial reading — the photo of the equipment label
    • Nightly operational insights (currently run for Operator, Enterprise and free Personal organisations) — the organisation name, job counts, the top technicians’ rope hours for the week (by internal ID, not name), the names of people whose credentials expire within 60 days with the credential type and date, equipment overdue for inspection, and short extracts of recent incident descriptions
    • Product feedback you choose to upload on the Contribute page — the file and your note
    Anthropic Privacy Policy
  • Google Firebase Cloud Messaging: push notifications to the mobile apps (device token and notification content)
  • Apple: push notifications to iPhones through the Apple Push Notification service, and Sign in with Apple if you choose to use it
  • Twilio: SMS verification codes for multi-factor authentication, and SMS and phone-call escalation of Mayday alerts (your phone number and the message). At the date of this policy these Twilio features are not yet switched on; we will not send your number to Twilio until they are.
  • OpenWeather: the job site’s coordinates, to fetch weather conditions
  • OpenStreetMap (Nominatim) and OpenFreeMap: address searches you type and map tiles are requested directly from your browser, so these services see your IP address and the search text

We do not sell your data to any third party.

6. Overseas disclosure

Some of the providers above process data outside Australia, including in the United States, the United Kingdom and the European Union. Cloudflare operates a global network. Where we disclose personal information overseas, we take reasonable steps under Australian Privacy Principle 8 to ensure the recipient handles it consistently with the APPs.

7. Australian Privacy Principles

We handle personal information in line with the Australian Privacy Act 1988 (Cth) and the 13 Australian Privacy Principles (APPs), whether or not the Act’s small business exemption applies to us. Complaints may be lodged with the Office of the Australian Information Commissioner at oaic.gov.au.

8. Your rights

You may at any time, free of charge: access the personal data we hold; request corrections; request deletion of your account and data; and obtain a copy of your logbook data in a machine-readable format. Separately, Logbook Port-Out is a paid product (one-off AU$99) that migrates your complete sealed logbook, with its attestation chain intact, out of RopeLogix. Port-Out is optional and is never a condition of exercising the rights above. Contact privacy@ropelogix.com. We respond within 30 days. If you are not satisfied with our response, you may escalate to the Office of the Australian Information Commissioner at oaic.gov.au.

You can delete your account from the Profile page in the app, or by emailing us. We complete a confirmed deletion request within 30 days, except for records we must keep by law (for example, tax records). Deleted data may remain in encrypted backups for up to 90 days until they are overwritten.

How long we keep records: While your organisation uses RopeLogix, its records are kept until you delete them. If you close your organisation you have 30 days to download a final export; after that we keep its records locked and read-only only for the periods in our records retention schedule, which follow the record-keeping periods in Australian work health and safety, workplace and tax law (for example, 3 years after a job ends, 5 years after notice where a notifiable incident occurred, and 7 years for hours-of-work and billing records), and then permanently delete them. If you delete your personal account, we delete your personal information within 30 days, except that records your employer must keep are retained with your name replaced by a pseudonym and deleted at the end of the same periods. You can cancel a deletion request within 7 days of making it. Deleted information may remain in encrypted backups for up to 90 days until those backups expire.

9. Changes to this policy

We will notify registered users by email of material changes at least 14 days before they take effect. The version on this page, with the date shown at the top, is the current version.

10. Contact

Nice Technology Group Pty Ltd (ABN 29 674 686 269). Privacy enquiries: privacy@ropelogix.com