Privacy Policy

Home

Last Updated: July 1, 2026

StaffLoop (operated by Siva Tech Services Pty Ltd, ABN 61 680 000 640) ("we," "our," or "us") provides a multi-tenant software-as-a-service (SaaS) platform for workforce and care management. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our application. This policy is intended to reflect the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth).

We maintain internal practices, procedures, and systems — including designated privacy responsibilities and regular compliance reviews — to ensure ongoing compliance with the APPs as required under APP 1.

1. Roles and Responsibilities

It is important to understand the distinction between StaffLoop and your employing organisation (the "Subscriber"):

2. Information We Collect

We collect information under the direction of our Subscribers. The information we process includes:

3. Data Storage and Location

Your data is stored primarily in secure AWS data centers located in the Asia Pacific (Sydney) region. Depending on the service and provider used, some limited data may also be processed in other countries where our service providers or their subprocessors operate.

4. Data Isolation and Security

We are committed to the security of your data:

5. Data Retention

We retain your personal information for as long as necessary to provide the Service to you and your Subscriber. Specific retention policies:

6. Disclosure of Your Information

We may share information we have collected about you in certain situations:

7. Security and Bot Protection

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply. We use reCAPTCHA v3 to protect our login and signup forms from automated abuse and bots.

8. Your Rights

As the Data Controller, your employing organisation is responsible for handling your requests regarding access, correction, or deletion of your personal data. Please contact your administrator directly for such requests.

You may also exercise the following rights:

9. International Data Transfers

While we primarily store data in Australia (AWS Asia Pacific — Sydney region), some service providers may process limited operational data in other countries. In accordance with APP 8, we take reasonable steps to ensure overseas recipients do not breach the APPs, including:

Sub-processor List: Our current sub-processors and their data locations include: AWS (Sydney, AU — primary hosting, database, storage, email/SMS delivery via SES/SNS), Mapbox (USA — map matching and distance calculation), Google (USA — reCAPTCHA bot protection, Maps geocoding), Sentry (USA — error tracking and performance monitoring), Apple/Google Push Services (USA — push notification delivery), and Square (USA — point-of-sale data integration, where enabled by Subscriber). We will notify Subscribers of material changes to this list via email or in-app notification.

10. Data Breaches and Security Incidents

If we believe an eligible data breach has occurred, we will assess the incident promptly and, where required by law, notify affected individuals and the Office of the Australian Information Commissioner (OAIC) as required under the Notifiable Data Breaches scheme.

11. Children's Privacy

Our Service is not directed to children. We do not knowingly collect personal information from individuals who lack the capacity to understand privacy matters, consistent with the Privacy Act's capacity-based approach. Where a platform user is a minor or otherwise lacks such capacity — for example, NDIS participants who are under 18 — the Subscriber must ensure that a parent or legal guardian has provided appropriate consent before the individual's information is entered into the platform. If you believe we have inadvertently collected information from such an individual without proper consent, please contact us immediately.

12. Changes to This Privacy Policy

We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last Updated" date. Your continued use of the Service after changes constitutes acceptance of the updated policy.

13. Contact Us

If you have questions about this Privacy Policy, please contact:

If you have a complaint about our compliance with the Privacy Act and we have not resolved your complaint within 30 days, you can refer your complaint to the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au.

← Back to StaffLoop