Legal & Privacy

Privacy Policy

J&L International PTY Ltd  ·  ABN 37 672 976 395  ·  Last updated: 1 January 2025
Effective date: 1 January 2025  ·  Applies to: siramapp.com and all SIRAM platform services
Contents
  1. Who we are
  2. What personal data we collect
  3. How we use your data
  4. Legal bases for processing (GDPR / Australian Privacy Act)
  5. Who we share data with
  6. Data residency, storage and transfers
  7. Retention and deletion
  8. Your rights
  9. Cookies and tracking technologies
  10. Safety records and regulatory obligations
  11. Children and minors
  12. Changes to this policy
  13. Contact us and complaints

Plain-language summary: SIRAM is a B2B safety governance platform. We collect and process data to deliver our service to your organisation. We do not sell personal data. We do not use your data for advertising. Safety records stored in SIRAM may be subject to regulatory retention obligations that limit our ability to delete them on request — we explain this fully in Section 10.

1. Who we are

J&L International PTY Ltd (ABN 37 672 976 395, ACN 672 976 395), trading as SIRAM, is the data controller for personal data collected through the SIRAM platform and siramapp.com. Our registered office is at 1/7-9 Churchill Street, Heidelberg Heights VIC 3081, Australia.

SIRAM is a software-as-a-service platform providing safety governance infrastructure to regulated industries, including aviation, construction, mining, maritime, and manufacturing. We operate primarily in Australia and Vietnam and serve organisations subject to ICAO, CASA, and equivalent civil aviation and workplace safety regulatory frameworks.

For the purposes of the Australian Privacy Act 1988 (Cth) and the General Data Protection Regulation (EU) 2016/679 (GDPR), J&L International PTY Ltd is the data controller. For any personal data processed on behalf of our business customers (operators), SIRAM acts as a data processor, and the customer organisation acts as the data controller.

2. What personal data we collect

2.1 Account and identity data

2.2 Safety governance records (operator data)

As part of the SIRAM platform, we process safety-related records on behalf of your organisation. These may include:

Note: Safety governance records may contain sensitive personal data including health information, workplace injury details, and personnel performance records. Processing of this data is governed by your organisation's data processing agreement with SIRAM and the applicable regulatory framework.

2.3 Usage and technical data

2.4 Billing and commercial data

3. How we use your data

PurposeData usedLegal basis
Deliver the SIRAM platform serviceAccount data, safety records, usage dataContract performance
User authentication and access controlIdentity data, MFA, SSO tokensContract performance / Legitimate interests
Governance engine validation (4-check audit)Role, competency, scope, conflict recordsContract performance / Regulatory obligation
Utility billing calculationUser counts, bandwidth, storage metricsContract performance
Security and fraud preventionIP logs, session data, API logsLegitimate interests
Platform improvement and analyticsAggregated, anonymised usage data onlyLegitimate interests
Customer support and communicationsAccount data, support ticket contentContract performance
Legal and regulatory complianceAs required by applicable lawLegal obligation

We do not use your personal data for advertising, do not sell data to third parties, and do not use safety governance records for any purpose other than delivering the SIRAM service to your organisation.

4. Legal bases for processing

4.1 Australian Privacy Act 1988 (Cth)

SIRAM complies with the 13 Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth). We collect personal information only by lawful and fair means, for purposes directly related to our functions, and only to the extent necessary for those purposes. You have the right to access and correct your personal information under APP 12 and APP 13.

4.2 GDPR (for users in the European Economic Area)

Where GDPR applies, our legal bases for processing are:

4.3 Vietnam Personal Data Protection Decree (PDPD 13/2023/ND-CP)

For users in Vietnam, we comply with the Personal Data Protection Decree effective from 1 July 2023. We collect personal data for lawful, explicit purposes, obtain consent where required, and implement appropriate technical and organisational measures to protect personal data. You may exercise your rights under the PDPD by contacting us using the details in Section 13.

5. Who we share data with

We do not sell, rent, or trade personal data. We share data only in the following circumstances:

RecipientPurposeSafeguards
Stripe Inc.Payment processing and billingPCI DSS Level 1; Stripe Privacy Policy
Amazon Web Services (AWS)Cloud infrastructure; data hosted in ap-southeast-1 (Singapore)AWS DPA
SendGrid (Twilio)Transactional email (notifications, invitations)GDPR DPA
Your organisation's IT systemsSSO integration (Azure AD, Okta, Google) if configuredControlled by your organisation
Regulatory authoritiesWhere required by law (e.g. CASA mandatory occurrence reports)Legal obligation; minimum necessary data
SIRAM professional services staffImplementation support, with your consentConfidentiality obligations; minimum access

All third-party sub-processors are bound by data processing agreements requiring them to implement equivalent privacy and security standards.

6. Data residency, storage, and international transfers

SIRAM stores all customer data in AWS ap-southeast-1 (Singapore). Singapore is recognised as having adequate data protection standards. We do not transfer data to jurisdictions with inadequate protections without appropriate safeguards.

Where international transfers occur (for example, to Stripe in the United States), we rely on:

Customers with specific data residency requirements should contact us at privacy@siramapp.com to discuss options.

7. Retention and deletion

7.1 General retention

Data typeRetention period
Account and identity dataDuration of subscription + 90 days after termination
Billing records and invoices7 years (Australian tax law requirement)
Usage logs and security logs12 months rolling
Support tickets3 years from resolution
Aggregated analytics (anonymised)Indefinite (no personal data)

7.2 Safety records — regulatory retention obligations

Important: Safety governance records (incidents, audits, investigations, risk records) may be subject to mandatory regulatory retention requirements under ICAO Annex 13, CASA regulations, the Work Health and Safety Act, or equivalent legislation. These obligations may prevent us from deleting records even upon your request. Where deletion is not possible due to regulatory requirements, we will inform you of the applicable obligation and the records will be retained only for the minimum period required by law.

Upon termination of your SIRAM subscription, all non-regulatory data will be deleted within 90 days. You may request an export of your data in machine-readable format before termination.

8. Your rights

Depending on your jurisdiction, you have the following rights regarding your personal data:

RightDescriptionApplies under
AccessRequest a copy of the personal data we hold about youPrivacy Act (APP 12), GDPR Art. 15, PDPD
CorrectionRequest correction of inaccurate personal dataPrivacy Act (APP 13), GDPR Art. 16, PDPD
DeletionRequest deletion of personal data (subject to regulatory retention obligations)GDPR Art. 17, PDPD
PortabilityReceive your data in a structured, machine-readable formatGDPR Art. 20
RestrictionRequest restriction of processing in certain circumstancesGDPR Art. 18
ObjectObject to processing based on legitimate interestsGDPR Art. 21
Withdraw consentWithdraw consent at any time (where processing is consent-based)GDPR Art. 7, PDPD

To exercise any of these rights, contact us at privacy@siramapp.com. We will respond within 30 days. In complex cases, we may extend this by a further 60 days and will notify you accordingly. We do not charge for exercising your rights except in cases of manifestly unfounded or excessive requests.

9. Cookies and tracking technologies

SIRAM uses cookies and similar technologies to operate the platform and improve your experience. We do not use advertising cookies or third-party tracking for commercial purposes.

Cookie typePurposeDuration
Essential / SessionAuthentication, session management, CSRF protectionSession / 24 hours
FunctionalUser preferences (language, timezone, UI state)12 months
AnalyticsAggregated platform usage (no cross-site tracking; data anonymised)12 months rolling

You can control cookies through your browser settings. Disabling essential cookies will prevent you from accessing the SIRAM platform. We do not use cookies for advertising or cross-site tracking.

10. Safety records and regulatory obligations

SIRAM serves regulated industries where safety record integrity is a legal requirement. The following principles apply to all safety governance records processed through the SIRAM platform:

11. Children and minors

SIRAM is a business-to-business (B2B) platform intended exclusively for use by adults in a professional capacity. We do not knowingly collect personal data from persons under the age of 18. If you become aware that a minor has accessed the platform, please contact us immediately at privacy@siramapp.com.

12. Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or platform features. We will notify you of material changes by:

Continued use of the platform after the effective date of any change constitutes acceptance of the updated policy. Previous versions of this policy are available on request.

13. Contact us and complaints

Privacy Officer

For all privacy-related enquiries, access requests, correction requests, and complaints:

Complaints — Australia

If you are not satisfied with our response to a privacy complaint, you have the right to lodge a complaint with the Office of the Australian Information Commissioner (OAIC):

Complaints — EEA / UK

If you are located in the European Economic Area or United Kingdom, you have the right to lodge a complaint with your local data protection authority. A full list of EU supervisory authorities is available at edpb.europa.eu.

Complaints — Vietnam

If you are located in Vietnam, you may lodge a complaint with the Ministry of Information and Communications (MIC) or the Ministry of Public Security (MPS), which are the competent authorities under the Personal Data Protection Decree (PDPD 13/2023/ND-CP).

Questions about your privacy?

Our Privacy Officer is here to help. We aim to respond to all enquiries within 5 business days and to all formal requests within 30 days.

privacy@siramapp.com →