Plain-language summary: SIRAM is a B2B safety governance platform. We collect and process data to deliver our service to your organisation. We do not sell personal data. We do not use your data for advertising. Safety records stored in SIRAM may be subject to regulatory retention obligations that limit our ability to delete them on request — we explain this fully in Section 10.
J&L International PTY Ltd (ABN 37 672 976 395, ACN 672 976 395), trading as SIRAM, is the data controller for personal data collected through the SIRAM platform and siramapp.com. Our registered office is at 1/7-9 Churchill Street, Heidelberg Heights VIC 3081, Australia.
SIRAM is a software-as-a-service platform providing safety governance infrastructure to regulated industries, including aviation, construction, mining, maritime, and manufacturing. We operate primarily in Australia and Vietnam and serve organisations subject to ICAO, CASA, and equivalent civil aviation and workplace safety regulatory frameworks.
For the purposes of the Australian Privacy Act 1988 (Cth) and the General Data Protection Regulation (EU) 2016/679 (GDPR), J&L International PTY Ltd is the data controller. For any personal data processed on behalf of our business customers (operators), SIRAM acts as a data processor, and the customer organisation acts as the data controller.
As part of the SIRAM platform, we process safety-related records on behalf of your organisation. These may include:
Note: Safety governance records may contain sensitive personal data including health information, workplace injury details, and personnel performance records. Processing of this data is governed by your organisation's data processing agreement with SIRAM and the applicable regulatory framework.
| Purpose | Data used | Legal basis |
|---|---|---|
| Deliver the SIRAM platform service | Account data, safety records, usage data | Contract performance |
| User authentication and access control | Identity data, MFA, SSO tokens | Contract performance / Legitimate interests |
| Governance engine validation (4-check audit) | Role, competency, scope, conflict records | Contract performance / Regulatory obligation |
| Utility billing calculation | User counts, bandwidth, storage metrics | Contract performance |
| Security and fraud prevention | IP logs, session data, API logs | Legitimate interests |
| Platform improvement and analytics | Aggregated, anonymised usage data only | Legitimate interests |
| Customer support and communications | Account data, support ticket content | Contract performance |
| Legal and regulatory compliance | As required by applicable law | Legal obligation |
We do not use your personal data for advertising, do not sell data to third parties, and do not use safety governance records for any purpose other than delivering the SIRAM service to your organisation.
SIRAM complies with the 13 Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth). We collect personal information only by lawful and fair means, for purposes directly related to our functions, and only to the extent necessary for those purposes. You have the right to access and correct your personal information under APP 12 and APP 13.
Where GDPR applies, our legal bases for processing are:
For users in Vietnam, we comply with the Personal Data Protection Decree effective from 1 July 2023. We collect personal data for lawful, explicit purposes, obtain consent where required, and implement appropriate technical and organisational measures to protect personal data. You may exercise your rights under the PDPD by contacting us using the details in Section 13.
We do not sell, rent, or trade personal data. We share data only in the following circumstances:
| Recipient | Purpose | Safeguards |
|---|---|---|
| Stripe Inc. | Payment processing and billing | PCI DSS Level 1; Stripe Privacy Policy |
| Amazon Web Services (AWS) | Cloud infrastructure; data hosted in ap-southeast-1 (Singapore) | AWS DPA |
| SendGrid (Twilio) | Transactional email (notifications, invitations) | GDPR DPA |
| Your organisation's IT systems | SSO integration (Azure AD, Okta, Google) if configured | Controlled by your organisation |
| Regulatory authorities | Where required by law (e.g. CASA mandatory occurrence reports) | Legal obligation; minimum necessary data |
| SIRAM professional services staff | Implementation support, with your consent | Confidentiality obligations; minimum access |
All third-party sub-processors are bound by data processing agreements requiring them to implement equivalent privacy and security standards.
SIRAM stores all customer data in AWS ap-southeast-1 (Singapore). Singapore is recognised as having adequate data protection standards. We do not transfer data to jurisdictions with inadequate protections without appropriate safeguards.
Where international transfers occur (for example, to Stripe in the United States), we rely on:
Customers with specific data residency requirements should contact us at privacy@siramapp.com to discuss options.
| Data type | Retention period |
|---|---|
| Account and identity data | Duration of subscription + 90 days after termination |
| Billing records and invoices | 7 years (Australian tax law requirement) |
| Usage logs and security logs | 12 months rolling |
| Support tickets | 3 years from resolution |
| Aggregated analytics (anonymised) | Indefinite (no personal data) |
Important: Safety governance records (incidents, audits, investigations, risk records) may be subject to mandatory regulatory retention requirements under ICAO Annex 13, CASA regulations, the Work Health and Safety Act, or equivalent legislation. These obligations may prevent us from deleting records even upon your request. Where deletion is not possible due to regulatory requirements, we will inform you of the applicable obligation and the records will be retained only for the minimum period required by law.
Upon termination of your SIRAM subscription, all non-regulatory data will be deleted within 90 days. You may request an export of your data in machine-readable format before termination.
Depending on your jurisdiction, you have the following rights regarding your personal data:
| Right | Description | Applies under |
|---|---|---|
| Access | Request a copy of the personal data we hold about you | Privacy Act (APP 12), GDPR Art. 15, PDPD |
| Correction | Request correction of inaccurate personal data | Privacy Act (APP 13), GDPR Art. 16, PDPD |
| Deletion | Request deletion of personal data (subject to regulatory retention obligations) | GDPR Art. 17, PDPD |
| Portability | Receive your data in a structured, machine-readable format | GDPR Art. 20 |
| Restriction | Request restriction of processing in certain circumstances | GDPR Art. 18 |
| Object | Object to processing based on legitimate interests | GDPR Art. 21 |
| Withdraw consent | Withdraw consent at any time (where processing is consent-based) | GDPR Art. 7, PDPD |
To exercise any of these rights, contact us at privacy@siramapp.com. We will respond within 30 days. In complex cases, we may extend this by a further 60 days and will notify you accordingly. We do not charge for exercising your rights except in cases of manifestly unfounded or excessive requests.
SIRAM uses cookies and similar technologies to operate the platform and improve your experience. We do not use advertising cookies or third-party tracking for commercial purposes.
| Cookie type | Purpose | Duration |
|---|---|---|
| Essential / Session | Authentication, session management, CSRF protection | Session / 24 hours |
| Functional | User preferences (language, timezone, UI state) | 12 months |
| Analytics | Aggregated platform usage (no cross-site tracking; data anonymised) | 12 months rolling |
You can control cookies through your browser settings. Disabling essential cookies will prevent you from accessing the SIRAM platform. We do not use cookies for advertising or cross-site tracking.
SIRAM serves regulated industries where safety record integrity is a legal requirement. The following principles apply to all safety governance records processed through the SIRAM platform:
SIRAM is a business-to-business (B2B) platform intended exclusively for use by adults in a professional capacity. We do not knowingly collect personal data from persons under the age of 18. If you become aware that a minor has accessed the platform, please contact us immediately at privacy@siramapp.com.
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or platform features. We will notify you of material changes by:
Continued use of the platform after the effective date of any change constitutes acceptance of the updated policy. Previous versions of this policy are available on request.
For all privacy-related enquiries, access requests, correction requests, and complaints:
If you are not satisfied with our response to a privacy complaint, you have the right to lodge a complaint with the Office of the Australian Information Commissioner (OAIC):
If you are located in the European Economic Area or United Kingdom, you have the right to lodge a complaint with your local data protection authority. A full list of EU supervisory authorities is available at edpb.europa.eu.
If you are located in Vietnam, you may lodge a complaint with the Ministry of Information and Communications (MIC) or the Ministry of Public Security (MPS), which are the competent authorities under the Personal Data Protection Decree (PDPD 13/2023/ND-CP).
Our Privacy Officer is here to help. We aim to respond to all enquiries within 5 business days and to all formal requests within 30 days.
privacy@siramapp.com →