Legal

Privacy Policy

How Heimdall collects, uses and stores information when you use BriefDuty, and what you can ask us to do about it.

Effective 23 August 2026Version 1.0

Draft for review. Placeholders marked [ ] need your registered company details. Have a lawyer review before publishing.

01

Who we are

BriefDuty is operated by Heimdall [registered company name and ACN to be inserted] (“we”, “us”). We are based in Western Australia.

For questions about this policy, or to make a privacy request, email [email protected]. For anything else, email [email protected].

02

Our role, and your operator's

BriefDuty is used by tour operators, contractors and other businesses (“operators”) to publish safety briefs. Two different relationships sit inside the product, and they are governed differently.

For an operator's own account data — their sign-in details, tenant, team and billing — we decide how that information is handled. We are the controller.

For the content of a safety brief and the records of the people who read it, the operator decides what is collected and why. They are the controller; we process that information on their instructions. If you are a guest and want your record removed, contact the operator who gave you the link. We will help them action it.

03

What we collect

We collect only what the product needs to work.

  • Account information — your name, email address and password credentials, handled through Firebase Authentication.
  • Tenant and team information — company name, contact details you choose to publish on a brief, team member invitations and roles.
  • Brief content — everything you write or upload into a safety brief, including documents, images and video.
  • Reader records — the name a guest enters when they finish a brief, their email address if they provide one, the language they read it in, the time they finished, and whether a guide has scanned their ticket.
  • Billing information — a Stripe customer reference and subscription status. Card numbers go directly to Stripe and never reach our systems.
  • Technical information — standard server logs, including IP address and browser type, kept for security and troubleshooting.
04

Cookies and the visitor identifier

When someone opens a public safety brief we set a visitor identifier on their device. Its only purpose is to tell repeat views apart from new readers, so the operator's read count is accurate. It is not used for advertising, profiling or cross-site tracking, and it is not shared with third parties.

We do not run third-party advertising or analytics cookies on public briefs.

05

How we use information

We use the information above to:

  • Provide the product — create, translate, publish and serve safety briefs.
  • Give operators a record of who has read a brief and who has been verified.
  • Take payment and manage subscriptions.
  • Send transactional email such as invitations and password resets.
  • Keep the service secure, and diagnose faults.
06

AI drafting and translation

BriefDuty uses Google's Gemini models, through Google's paid API, to draft safety brief content and translate it into the supported languages.

Content you send to the assistant is used to generate your result. It is not used to train Google's models or ours.

Our staff may review samples of brief content — the text and media an operator writes or uploads — to improve the quality of the assistant's output. Reader records are excluded from this: we do not review, analyse or otherwise use the names, email addresses or timestamps left by the people who read a brief.

Translated content is cached against your brief so it does not need regenerating on every visit. AI-generated text is a draft: you remain responsible for reviewing it before you publish.

07

Who we share it with

We do not sell personal information. We use a small number of service providers, each of which handles information only to deliver its part of the product:

  • Google Cloud and Firebase — hosting, sign-in, database and file storage.
  • Stripe — subscription billing and payment processing.
  • Resend — transactional email delivery.
  • Google Gemini — AI drafting and translation, as described above.
08

Where information is held

Customer data is stored in Australia.

Some of the providers listed above operate globally, so limited information — for example an email address passed to our email provider, or text sent for translation — may be processed outside Australia. We take reasonable steps to ensure providers handle it consistently with this policy.

09

How long we keep it

Brief content and reader records are kept until the operator deletes them or closes their tenant. Operators control this directly in the product.

Deletion is immediate and permanent. We do not keep backup copies, so once content is deleted we cannot restore it — for you, or for anyone who asks us to.

Account and billing records are kept for as long as the account is open, and afterwards only where we are required to keep them — for example, tax and accounting records.

10

Your rights

Under the Australian Privacy Principles you may ask for access to the personal information we hold about you, and ask us to correct it if it is wrong. Email [email protected] and we will respond within a reasonable period.

If you are in the EU or UK, you may also have rights to erasure, restriction, objection and data portability, and a right to complain to your local supervisory authority. Where an operator is the controller of your information, we will pass your request to them and support them in answering it.

[We have not yet appointed an EU representative under Article 27, a data protection officer, or put Standard Contractual Clauses in place. This paragraph should be reviewed with your lawyer before publication.]

11

Security

Access to the product requires authentication. Every brief, document and reader record is scoped to the tenant that owns it, and a person's role in that tenant determines what they can see and change.

Public safety briefs are reachable by anyone holding the link. They are served with noindex, nofollow so they do not appear in search results, but they are not secret — do not put confidential information into a published brief.

No system is perfectly secure. If we become aware of a data breach, we will notify affected parties and the OAIC where the law requires it.

12

Children

BriefDuty is designed for adult readers and we do not knowingly collect information from children. Operators are responsible for how they use the product with minors, and should not ask a child to enter their details into a brief.

13

Changes and contact

We may update this policy as the product changes. The effective date at the top of this page will change, and material changes will be notified to account holders by email.

Privacy questions: [email protected]. Everything else: [email protected].