Skip to content

Legal

The Terms that govern a SYNQE subscription, and the Privacy Policy, which covers both the product and this website.

Terms and Conditions

v1.3, effective 14 September 2026

These Terms apply to every SYNQE subscription and are read together with your Order Form and our Privacy Policy. Questions about them go to legal@synqe.com.au.

1. Definitions

These Terms and Conditions ("Terms") govern access to and use of the SYNQE computer-aided dispatch and incident logging platform (the "Services"), provided by EC Event Technology Pty Ltd (ACN 700 404 977), trading as SYNQE, an Australian company ("SYNQE", "we", "us", "our").

The Services are offered on a business-to-business basis. By signing an Order Form, clicking "I agree," or accessing or using the Services, the entity on whose behalf you act (the "Customer," "you," "your") agrees to be bound by these Terms. If you are accessing the Services on behalf of an organisation, you represent that you have authority to bind that organisation.

If you do not agree to these Terms, do not access or use the Services.

"Authorised User" means an individual (employee, contractor, volunteer, or agent of Customer or an approved third-party agency) whom Customer permits to access the Services under Customer's account.

"Customer Data" means all data, records, and content submitted, uploaded, or generated by Customer or its Authorised Users through the Services, including dispatch logs, incident reports, communications, attachments, and any Incident Data (defined below).

"Incident Data" means Customer Data relating to a specific incident at an event, which may include auxiliary details about injuries, first-aid or medical treatment provided, welfare checks, or other health-related information collected in the ordinary course of security, medical, or venue operations logging. Incident Data is not intended to constitute a clinical or diagnostic health record.

"Account Closure" means the date on which Customer's account is closed, being the later of (a) the expiry or termination of the last Order Form in effect, and (b) the date Customer notifies SYNQE in writing that it wishes its account closed. SYNQE records this date and it is the date from which the deletion period in Section 5.5 runs.

"Order Form" means an ordering document, subscription agreement, or online signup referencing these Terms that specifies the subscription plan, term, fees, and permitted Authorised Users.

"Privacy Policy" means the SYNQE Privacy Policy, published within the Services and available at any time from the sign-in page, as updated from time to time. A copy will be provided on request.

"Retention Hold" means a marker SYNQE places on Customer's account or a specific event, at Customer's request or where SYNQE is legally required to do so, which suspends deletion of the affected Customer Data.

"Services" means the SYNQE web and mobile CAD/dispatch and logging platform, including associated APIs, integrations, and support.

"Subscription Term" means the period during which Customer has a paid or trial right to access the Services, as set out in an Order Form.

2. Eligibility and Accounts

2.1 The Services are intended for use by organisations operating in the live event industry (security providers, medical/first-aid providers, production companies, venue operators, and related third-party agencies) and their personnel. The Services are not directed at children, and no one under the age of 18 may be registered as an Authorised User.

2.2 Customer is responsible for: (a) ensuring all information provided during registration is accurate and kept up to date; (b) maintaining the confidentiality of login credentials issued to its Authorised Users; (c) all activity that occurs under its account, whether or not authorised by Customer, except to the extent caused by SYNQE's breach of these Terms; and (d) promptly notifying SYNQE of any suspected unauthorised access.

3. The Services and Licence Grant

3.1 Subject to these Terms and payment of applicable fees, SYNQE grants Customer a non-exclusive, non-transferable, non-sublicensable right to access and use the Services during the Subscription Term, solely for Customer's internal business operations and event-management purposes, for the number of Authorised Users specified in the applicable Order Form.

3.2 SYNQE may make updates, patches, and improvements to the Services from time to time. SYNQE will use reasonable efforts to avoid materially reducing core functionality during a paid Subscription Term without notice.

3.3 No emergency service. The Services are a logging, dispatch-coordination, and information-sharing tool. The Services are not a substitute for calling emergency services (triple zero / 000, 911, 999, or the applicable local emergency number). Customer is responsible for ensuring its personnel understand this and maintain appropriate emergency escalation procedures independent of the Services.

4. Acceptable Use

Customer must not, and must ensure Authorised Users do not: (a) use the Services to break any applicable law, including privacy, health-records, or workplace-safety laws; (b) upload content that is unlawful, defamatory, or that infringes a third party's intellectual property or privacy rights; (c) attempt to gain unauthorised access to the Services, other customers' data, or SYNQE's systems; (d) reverse engineer, decompile, or attempt to derive source code from the Services, except to the extent this restriction is not permitted by law; (e) resell, sublicense, or provide the Services to any third party as a service bureau, except an approved third-party agency acting as an Authorised User under Customer's account; (f) use the Services to store or transmit malicious code; or (g) use the Services in a manner that could reasonably endanger patron, staff, or public safety (e.g., as a sole or primary safety-critical system without appropriate redundancy).

5. Customer Data and Incident Data

5.1 Ownership. As between the parties, Customer owns all Customer Data. SYNQE does not acquire any ownership rights in Customer Data.

5.2 Licence to SYNQE. Customer grants SYNQE a worldwide, non-exclusive licence to host, store, process, transmit, and display Customer Data solely to (a) provide, maintain, and support the Services, (b) as instructed by Customer, and (c) as otherwise permitted under the SYNQE Privacy Policy.

5.3 Sensitive and health-related information. Where Customer or its Authorised Users submit Incident Data containing health, medical, or other sensitive information about staff, patrons, or third parties, Customer represents and warrants that it has all necessary rights, consents, and legal bases required under applicable privacy and health-information laws (including, in Australia, the Privacy Act 1988 (Cth) and Australian Privacy Principles) to collect that information and to disclose it to SYNQE for processing via the Services. Customer is responsible for determining what Incident Data is appropriate to record and for its own downstream obligations (e.g., mandatory incident reporting, workplace health and safety, or medical-privacy obligations).

Customer further acknowledges and agrees that: (a) Notifying individuals is Customer's responsibility. Australian Privacy Principle 5 requires an organisation collecting personal information about an individual to take reasonable steps to notify that individual, including where the information is collected from someone else. Where Customer or its Authorised Users record information about patrons, members of the public, or other third parties through the Services, Customer is responsible for making those individuals aware that the recording occurs — through event signage, ticket or entry terms, staff briefings, or other appropriate means. SYNQE has no relationship with those individuals and cannot discharge this obligation on Customer's behalf. (b) Location and surveillance notices. Where Customer uses the Services to record the location of its personnel, Customer is responsible for any notice or consent obligations arising under workplace surveillance legislation, including the Workplace Surveillance Act 2005 (NSW) and equivalent State and Territory laws. (c) Requests from individuals. Where an individual contacts SYNQE seeking access to, or correction of, information Customer submitted through the Services, SYNQE will refer or coordinate that request with Customer, except where SYNQE is required by law to respond directly. Customer will provide reasonable and timely cooperation, recognising that statutory response periods may apply.

5.4 Retention. SYNQE retains Customer Data for as long as Customer's account remains open. SYNQE does not delete Customer Data at the end of an event or at the end of a Subscription Term. This reflects the evidentiary purpose of the Services: incident records are commonly required months or years after the event they concern, for insurance, coronial, regulatory, or litigation purposes.

5.5 Export and deletion on Account Closure. (a) During the Subscription Term, Customer may export Customer Data at any time using the in-Services export tools. (b) For 30 days following Account Closure, SYNQE will keep Customer's export tools available and will provide reasonable assistance with a bulk export on request. (c) SYNQE will delete Customer Data 90 days after Account Closure, except where a Retention Hold applies or a longer retention period is required by law. (d) The 30-day period in (b) and the 90-day period in (c) run concurrently from Account Closure. Customer's data is not deleted at day 30; only assisted export ends. (e) Deletion is subject to Section 5.7 (audit records) and to the retention provisions of the Privacy Policy.

5.6 Retention Holds — Customer's obligation to notify. Customer must notify SYNQE in writing before Account Closure if Customer is subject to a legal obligation requiring retention of Customer Data beyond the period in Section 5.5(c). This includes, without limitation: (a) obligations of a health service provider under the Health Records and Information Privacy Act 2002 (NSW) or equivalent State or Territory legislation, which may require health information to be retained for at least seven years, or in the case of a minor until that individual turns 25; and (b) obligations of a public sector agency under the State Records Act 1998 (NSW) or equivalent legislation, where Customer Data may constitute State records that must not be destroyed without authority.

On receiving such a notice, SYNQE will apply a Retention Hold and will not delete the affected Customer Data while it remains in place. SYNQE cannot know what obligations apply to Customer, and is not responsible for deletion carried out in accordance with these Terms in the absence of a notice under this Section. SYNQE may charge reasonable storage fees for data retained under a Retention Hold more than 12 months after Account Closure.

5.7 Audit records survive deletion. The Services maintain a tamper-evident audit trail. Deletion under Section 5.5 removes Customer's operational data but does not delete the audit trail, which is retained together with a record of the deletion. SYNQE retains it so that it can demonstrate — to Customer, to a regulator, or in a dispute — that Customer Data was handled properly and that deletion occurred. This is described in Section 13 of the Privacy Policy.

5.8 Aggregated/de-identified data. SYNQE may create and use aggregated or de-identified data derived from Customer Data (that does not identify Customer, any individual, or any specific event) for product improvement, benchmarking, and analytics purposes.

6. Third-Party Services and Integrations

The Services may allow integration with third-party tools (e.g., radios, access-control, ticketing, or weather systems). SYNQE is not responsible for third-party services, and Customer's use of them is governed by the applicable third party's terms.

7. Fees and Payment

7.1 Customer will pay the fees set out in the applicable Order Form. Unless stated otherwise, fees are quoted in Australian Dollars (AUD) exclusive of GST and other applicable taxes, which Customer is responsible for in addition to the stated fees.

7.2 Except as required by law or expressly stated in an Order Form, fees are non-refundable.

7.3 Unless otherwise agreed, Subscription Terms renew automatically for successive terms of the same length as the initial term, unless either party gives written notice of non-renewal at least 30 days before the end of the then-current term.

7.4 Overdue amounts may accrue interest at the lesser of 1.5% per month or the maximum rate permitted by law, and SYNQE may suspend access for accounts more than 14 days overdue, following written notice.

8. Term, Suspension, and Termination

8.1 These Terms remain in effect for as long as any Order Form is in effect.

8.2 SYNQE may suspend access to the Services immediately, with notice where practicable, if: (a) Customer materially breaches these Terms and does not cure within 10 days of notice; (b) SYNQE reasonably believes suspension is necessary to prevent harm to the Services, other customers, or third parties; or (c) required by law.

8.3 Either party may terminate an Order Form for the other party's uncured material breach on 30 days' written notice, or immediately if the other party becomes insolvent.

8.4 On termination or expiry, Customer's right to access the Services ends, subject to Section 5.5 (export and deletion on Account Closure).

9. Intellectual Property

SYNQE and its licensors retain all right, title, and interest in and to the Services, including all software, designs, trademarks (including the SYNQE brand and EC Event Technology branding), and documentation. No rights are granted to Customer except as expressly set out in these Terms.

10. Confidentiality

Each party will protect the other's non-public business, technical, and pricing information disclosed in connection with these Terms ("Confidential Information") using at least reasonable care, and will use it only to perform its obligations or exercise its rights under these Terms. This section does not apply to information that is or becomes public through no fault of the receiving party, was already known to the receiving party, or is required to be disclosed by law (subject to reasonable notice where legally permitted).

11. Data Protection

11.1 Privacy Policy and Data Processing Addendum. SYNQE's collection and handling of personal information, including Customer Data containing personal information, is described in the Privacy Policy, which forms part of these Terms. SYNQE maintains a standard Data Processing Addendum, available on request, which governs SYNQE's handling of personal information on Customer's behalf and which the parties will execute where required by applicable law or reasonably requested by Customer. Where executed, the Data Processing Addendum prevails over these Terms in relation to the handling of personal information.

11.2 Commitment to the Australian Privacy Principles. SYNQE will handle personal information (including Customer Data containing personal information) in accordance with the Australian Privacy Principles set out in Schedule 1 to the Privacy Act 1988 (Cth), as if SYNQE were an APP entity bound by that Act, and in accordance with the Health Records and Information Privacy Act 2002 (NSW) and equivalent State and Territory health privacy legislation to the extent applicable to the Customer Data. This is a contractual obligation owed to Customer and enforceable under these Terms. SYNQE will notify Customer if its status under the Privacy Act 1988 (Cth) changes.

11.3 Roles. As between the parties, Customer is responsible for determining what personal information is collected through the Services and why. SYNQE processes Customer Data on Customer's instructions in providing the Services. SYNQE acts on its own account only in respect of account, billing, support, and marketing information it collects directly.

11.4 Where data is held. SYNQE hosts the Services and the database in Australia. Media files are held in the Asia-Pacific and Oceania region. A current list of SYNQE's service providers, and the countries in which they operate, is set out in the Privacy Policy and is available on request. SYNQE will give Customer reasonable prior notice before adding a service provider that will receive Customer Data.

11.5 Security. SYNQE will maintain administrative, technical, and physical safeguards proportionate to the sensitivity of Customer Data, including encryption in transit, per-organisation data isolation enforced at the database level, role-based access controls, and time-limited signed access to media files.

11.6 Data breach notification. If SYNQE becomes aware of unauthorised access to, or unauthorised disclosure or loss of, Customer Data, SYNQE will notify Customer without undue delay and in any event within 72 hours of becoming aware, and will provide the information reasonably available to it and reasonable assistance with Customer's own assessment and notification obligations. As between the parties, Customer is responsible for deciding whether to notify affected individuals and any regulator, except where SYNQE is independently required by law to notify.

11.7 SYNQE support access. SYNQE personnel do not routinely access Customer Data. Where necessary to resolve a support request or a platform fault, an authorised SYNQE administrator may obtain time-limited access to Customer's organisation. Any such access expires automatically and is recorded on both SYNQE's records and Customer's own audit trail, where Customer can see it.

11.8 Immutable records. Customer acknowledges that the Services are designed so that running log entries and audit records cannot be edited or deleted. Corrections are recorded by appending a correcting entry; retractions are marked but retained. Requests to correct such records will be met by annotation rather than erasure.

12. Warranties and Disclaimers

12.1 SYNQE warrants that it will provide the Services in a manner consistent with generally recognised industry standards.

12.2 To the maximum extent permitted by law, except as expressly stated in these Terms, the Services are provided "as is" and "as available," without warranties of any kind, whether express, implied, or statutory, including any implied warranties of merchantability, fitness for a particular purpose, or non-infringement.

12.3 Nothing in these Terms excludes, restricts, or modifies any consumer guarantee, right, or remedy conferred on Customer under the Australian Consumer Law (Schedule 2 to the Competition and Consumer Act 2010 (Cth)) or any other law that cannot lawfully be excluded, restricted, or modified. To the extent SYNQE's liability for breach of such a guarantee may be limited, and it is fair and reasonable to do so, SYNQE's liability is limited, at SYNQE's option, to re-supply of the Services or the cost of having the Services re-supplied.

13. Limitation of Liability

13.1 To the maximum extent permitted by law and subject to Section 12.3, neither party will be liable to the other for any indirect, special, incidental, or consequential loss, or loss of profits, revenue, data, or goodwill, arising out of or related to these Terms, even if advised of the possibility of such loss.

13.2 Subject to Section 12.3, each party's total aggregate liability arising out of or related to these Terms will not exceed the total fees paid or payable by Customer to SYNQE in the 12 months preceding the event giving rise to the claim.

13.3 The limitations in this Section 13 do not apply to: (a) a party's indemnification obligations under Section 14; (b) breach of Section 10 (Confidentiality); (c) a party's fraud or wilful misconduct; or (d) liability that cannot lawfully be limited.

13.4 Safety disclaimer. SYNQE is a logging and coordination tool. To the maximum extent permitted by law, SYNQE is not liable for injury, loss of life, or property damage arising from an event, incident, or emergency, except to the extent directly caused by SYNQE's breach of these Terms or negligence in providing the Services.

14. Indemnification

14.1 Customer will indemnify and hold harmless SYNQE from third-party claims arising from: (a) Customer Data (including any Incident Data) or Customer's or its Authorised Users' use of the Services in violation of applicable law or these Terms; or (b) Customer's failure to obtain necessary consents or legal bases for information submitted to the Services.

14.2 SYNQE will indemnify and hold harmless Customer from third-party claims that the Services, as provided by SYNQE and used in accordance with these Terms, infringe that third party's intellectual property rights, except to the extent the claim arises from Customer Data, Customer's modifications, or use in combination with non-SYNQE products.

14.3 The indemnified party must promptly notify the indemnifying party of the claim, give the indemnifying party control of the defence and settlement (subject to the indemnified party's consent to any settlement that imposes liability on it), and provide reasonable cooperation.

15. Governing Law and Disputes

15.1 These Terms are governed by the laws of New South Wales, Australia, without regard to conflict-of-law principles, and the parties submit to the non-exclusive jurisdiction of the courts of that state, unless a specific Order Form for a Customer outside Australia specifies otherwise.

15.2 Before commencing formal proceedings (other than for urgent injunctive relief or IP protection), the parties will attempt to resolve any dispute in good faith through senior-executive discussions for at least 15 business days.

16. General

16.1 Force majeure. Neither party is liable for delay or failure to perform caused by circumstances beyond its reasonable control.

16.2 Changes to these Terms. SYNQE may update these Terms from time to time. For material changes, SYNQE will provide at least 30 days' notice via the Services or email before the changes take effect for existing Customers. Continued use after the effective date constitutes acceptance.

16.3 Assignment. Neither party may assign these Terms without the other's consent, except to a successor in connection with a merger, acquisition, or sale of substantially all assets.

16.4 Notices. Notices must be given in writing to the contact details specified in the Order Form or, for SYNQE, to legal@synqe.com.au. Notices relating to privacy, personal information, or a data breach may also be sent to privacy@synqe.com.au.

16.5 Entire agreement. These Terms, together with all Order Forms and any Data Processing Addendum, constitute the entire agreement between the parties regarding the Services and supersede prior agreements on that subject.

16.6 Severability. If any provision is held unenforceable, the remaining provisions continue in full force, and the unenforceable provision will be modified to the minimum extent necessary to make it enforceable.

16.7 Export and sanctions. Customer will not use the Services in violation of applicable trade control or sanctions laws.

Contact

EC Event Technology Pty Ltd (trading as SYNQE) ACN 700 404 977

General and legal: legal@synqe.com.au Privacy: privacy@synqe.com.au

↑ Back to top

Privacy Policy

v3.2, effective 30 September 2026

1. Who this policy is about

EC Event Technology Pty Ltd (ACN 700 404 977), trading as SYNQE ("SYNQE", "we", "us"), operates a computer-aided dispatch and incident-logging platform for live event operations (the "Services").

This policy explains what personal information we collect, why we hold it, who we share it with, where it goes, and what you can do about it. It covers the Services, our website, and our dealings with customers and prospects.

We are based in Australia, and we handle personal information in accordance with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth). We commit to this in our Terms and Conditions, so our customers can hold us to it.

Because the Services record injuries, first aid and welfare concerns at events, we also handle health information, and we apply the Health Records and Information Privacy Act 2002 (NSW) and its equivalents in other states and territories.

We do not currently offer the Services in the European Economic Area or the United Kingdom. If that changes, we will publish a jurisdiction-specific addendum before launch. See section 15.

We hold information about five groups of people. What we owe each of them differs.

Customers — organisations that subscribe, such as security, medical, production, venue operations, councils and agencies. We control account, billing and support data for this group.

Authorised users — staff, contractors and volunteers who log in under a Customer's account. The Customer controls this data; we process it.

Field contributors — people sent a one-time link to upload a photo from the ground, with no account. The Customer controls this data; we process it.

Patrons and members of the public — people recorded in an incident log or photograph, who never touch the platform. The Customer controls this data; we process it. See section 4.

Website visitors and prospects — people who visit synqe.com.au or send us a demo request. We control this data. See section 2.8.

Where a Customer submits information through the Services, that Customer decides what is collected and why. We hold it on their instructions. If you want to know why something about you was recorded at an event, ask the organisation that ran the event — they hold the answer and the authority. You can still contact us using section 17, and we will help you reach the right party.

Where we collect information directly — you sign up, you email support, you subscribe to updates, you visit our website or send us a demo request — we are accountable for it.

2. What we collect

2.1 Account and contact information. Name, work email, phone number, employer, and role. Password credentials are stored as a one-way hash — we never hold your password. We also retain a short history of your previous password hashes so the platform can stop you reusing a recent password.

2.2 Operational records. The core of the Services. Authorised users create: running log entries — free-text incident notes with timestamp, author, department, priority and location; jobs — dispatched tasks with title, details, category, status, assignments and resolution history; locations and coordinates — precise WGS84 latitude and longitude for jobs, event anchors and location presets, and where enabled, what3words three-word addresses; site plans — venue floor plans uploaded and georeferenced by the Customer; rosters — operatives including contractors who hold no login, with name, role, phone number and availability; announcements, run sheets, notes and notifications; and sign-offs — where a category requires review, the reviewer's typed attestation name, note and timestamp.

2.3 Media. Photographs, video, PDFs and documents attached to jobs and log entries, with captions, thumbnails and file metadata. Media may show identifiable people, including injuries. Where it does, it is both personal information and health information, and section 3 applies.

2.4 Incident data and health information. Incident records may describe injuries, first aid or medical treatment given, ejections, or welfare concerns about staff or patrons. This is operational logging, not a clinical record. It is nevertheless sensitive information under APP 3 and health information under the Health Records and Information Privacy Act 2002 (NSW) and equivalent state legislation. We treat it accordingly. See section 3.

2.5 Field media contributions. A Customer can send a one-time link to someone on the ground — a contractor, a steward, a bystander — so they can upload a photo directly to a job without an account. Where the link is delivered by WhatsApp, we hold the recipient's phone number to route it and match the reply. Links are single-use and expire. If you received such a link, we hold the media you uploaded and, if WhatsApp was used, your phone number. We hold it for the organisation that sent the link.

2.6 Technical information. Session records — a hashed session token, expiry and last-seen time; sessions expire after 12 hours absolute, or 60 minutes idle. Push notification subscriptions — where you enable alerts, a per-device endpoint and encryption keys. Audit records — every significant action, with actor, action, affected record, and a before/after snapshot; see section 13. Server logs — our servers record each request, including the IP address it came from. We use this to operate and secure the platform: investigating abuse, blocking brute-force attempts, and diagnosing faults. We do not log your browser's user-agent string. Request logs are retained for 30 days, after which they are deleted automatically. Aggregate usage — per-organisation counts of users, active users, events, storage and record volume, used for billing and capacity; not linked to individual behaviour.

What our public website collects is set out in section 2.8. Cookies are covered in section 16.

2.7 What we do not do. We do not use tracking pixels, advertising networks, behavioural profiling, or third-party marketing analytics in the Services. We do not sell personal information. We do not use incident data to train models that identify a person, Customer or event.

2.8 Our website

Our public website, synqe.com.au, is separate from the Services. Nothing you do on it is linked to a SYNQE account or to any Customer's data.

No cookies, no browser storage. The website sets no cookies and stores nothing in your browser. See section 16.

Server logs — like the Services, the website's servers record each request, including the IP address it came from, to operate and secure the site. These logs are deleted automatically after 30 days.

Visit measurement — we use Cloudflare Web Analytics to count visits and see which pages are useful. It sets no cookies, uses no local storage, and does not build a profile of you or follow you across other sites. It records the page viewed, the referring site, your browser and device type, and your country. Cloudflare receives your IP address to deliver the measurement and states that it does not use it to identify or fingerprint visitors.

Demo requests — if you use the demo request form, we receive what you enter: your name and work email, and optionally your organisation, role, what you are running, how many teams coordinate, and any notes. It is delivered to our inbox by our email provider, Resend. We use it to reply and arrange a demo. We do not add you to a mailing list unless you ask us to (see section 5.4).

Abuse protection — to stop the form being used to send spam, the website counts recent requests from each IP address in memory for ten minutes. This count is not stored or logged.

3. Health and sensitive information

We hold health information only because a Customer records it in the course of running an event, and only on that Customer's instructions. We do not diagnose, treat, or build health profiles, and we make no automated decision about any individual using it.

Consent and lawful basis sit with the Customer. The organisation running the event — the venue, council, security or medical provider — is responsible for having the authority to record health information and disclose it to us through the Services. Their obligations are set out in our Terms and Conditions.

Where consent is impracticable, we rely on section 16A, Item 1 of the Privacy Act. When someone is injured or unconscious at an event, nobody stops to obtain consent before logging it. Recording and passing that information is necessary to lessen or prevent a serious threat to an individual's life, health or safety. That is the basis on which the record is made, and it is the correct one.

Access is restricted by design. Health information sits behind the same controls as every other incident record: department scoping, a six-tier permission model, and a separate restricted/commander clearance that the Customer sets per person. An entry marked restricted is hidden even from colleagues in the same department unless they hold clearance.

Health information is often subject to minimum retention periods, which override deletion requests. See section 12.

4. If you were recorded at an event

You may be reading this because an incident involving you was logged, or you appear in a photograph taken by event staff.

We did not choose to record you. The event organiser did, and they decide what happens to that record. Contact them first — they can tell you what was recorded, why, and how long they will keep it. If you do not know who they are, contact us using section 17 and we will identify the Customer and pass your request on.

We will not refuse you outright. Where the law gives you a right that runs directly against us — including access to health information about you under state health records legislation — we will consult the Customer and respond as the law requires, within the timeframes in section 17.

Event organisers, not SYNQE, must tell you that recording happens. APP 5 requires an organisation collecting information about you to make you aware of it. Where information reaches us through a Customer, that duty is theirs, discharged through event signage, ticket terms and staff briefings. We require it of them contractually. We cannot do it for them.

5. How we use information

5.1 Operating the Services. Providing, securing and supporting the platform. Processing payments and managing accounts. Sending service, security and incident notifications. Investigating misuse, fraud and security incidents. Meeting legal obligations and defending legal claims.

5.2 Improving the Services. Aggregate and de-identified analysis of how the platform is used — never in a form that identifies an individual, Customer or event.

5.3 What we do not decide for you. We do not make automated decisions about individuals. Category defaults, priority settings and escalation timers order operational work; they do not determine anything about a person. See section 14.

A note on location. Locations in the Services are entered deliberately — a pin dropped on an incident, a preset chosen from a list, an address typed in. We do not track your device. The Services do not read your phone's location in the background, and we hold no location history about you as a person — only the places incidents happened.

If we ever add device location tracking, we will update this policy first. Customers should note that tracking an employee's location may constitute workplace surveillance under the Workplace Surveillance Act 2005 (NSW), which generally requires 14 days' prior written notice, with equivalent rules in other states.

5.4 Marketing. With consent, or where otherwise permitted, we send product news to business contacts. Every message identifies us and carries a working unsubscribe link, as required by the Spam Act 2003 (Cth). Unsubscribing does not stop service and security notices, which we send regardless because you need them.

6. Who we share it with

Within a Customer's account — other authorised users, according to the permissions that Customer configures.

Partner organisations a Customer grants access to — for example, a medical provider seeing a security-logged incident relevant to their response. The Customer controls these grants.

Service providers who help us run the platform — listed in section 9, contractually bound to protect the information and use it only as instructed.

Emergency services, police and regulators — where legally required, or in a genuine emergency to prevent a serious threat to life, health or safety.

Professional advisers — lawyers, auditors and insurers, as reasonably necessary.

A successor entity — in a merger, acquisition, financing or sale of assets, subject to comparable privacy protections.

We do not sell personal information, and we do not disclose it for advertising.

7. Payments

Card and billing details are handled by Stripe, our payment processor. We never see or store full card numbers — they go directly to Stripe. Stripe's own privacy terms govern its handling of that data.

8. When SYNQE staff access customer data

We do not browse customer incident data. In defined circumstances — a support request we cannot resolve any other way, or a platform fault — a SYNQE platform administrator can obtain break-glass access to a Customer's organisation.

Access is time-boxed and expires automatically. Every action is recorded twice: on our platform audit trail and on the Customer's own audit trail. The Customer can see it. We do not hide it.

We disclose this because a vendor access path you find out about later is worse than one you were told about up front.

9. Where your data is stored

Your operational data is stored in Australia.

Our application, website and database run in Google Cloud's Sydney region (australia-southeast1). Incident records, jobs, running logs, rosters and account data — including health information — are held in Australia.

Pages of our public website are delivered to visitors through Firebase Hosting, Google's content delivery network, which serves copies of those pages from locations around the world. It carries website pages only — never Customer Data or anything from the Services.

Media you attach to incidents (photographs, video, documents and site plans) is stored with Cloudflare R2 in the Oceania jurisdiction, which keeps those files within the Asia-Pacific and Oceania region.

Some things still go overseas. Payment processing, email delivery, map imagery, push notifications, website delivery and website analytics are provided by companies that operate outside Australia. What they receive is set out below — none of them receives your incident records.

Where we disclose personal information to an overseas recipient, we take reasonable steps under APP 8 to ensure it is handled consistently with the APPs, including through contractual protections, before disclosure. We remain accountable for those recipients under section 16C of the Privacy Act.

One point of precision. Data stored in Australia is not the same thing as data beyond the reach of any foreign law. Google Cloud is a United States company, and data held in its Australian region may in limited circumstances be subject to lawful access requests under laws applying to it. We say "stored in Australia" because that is accurate, and we do not claim more than that.

Service providers. Google Cloud — application, website and database hosting — Australia (Sydney, australia-southeast1). Google (Firebase Hosting) — delivers public website pages to visitors and receives visitors' IP addresses; website only, no Customer Data — global edge network, origin in Sydney. Cloudflare Web Analytics — cookieless visit measurement on the public website, see section 2.8 — global (United States company). Cloudflare (R2) — media and file storage — Oceania, data stays in the Asia-Pacific/Oceania jurisdiction. Stripe — payment processing — United States and other regions. Resend — service, account and security email, and delivery of website demo requests to our inbox — United States. CARTO — map imagery; loading a map sends your IP address to CARTO, and repeated use reveals which areas you view — European Union. Browser push services (Google, Apple, Mozilla) — push notification delivery — various. Twilio — WhatsApp delivery, inactive unless a Customer enables it — United States. what3words Ltd — three-word geocoding, inactive unless enabled — United Kingdom.

Note on maps. Map imagery is fetched from CARTO as you pan and zoom, which discloses your IP address to CARTO. Map data is credited to OpenStreetMap under CARTO's licence, but no request is sent to OpenStreetMap. We are reviewing whether to proxy or self-host map tiles to remove this disclosure.

Other than the map tiles above, no third party receives any information when you load a page of the Services. Fonts, styles and charting libraries are served from our own infrastructure.

On our public website, fonts and icons are likewise served from our own infrastructure. The only third parties involved are Firebase Hosting, which delivers the pages, and Cloudflare Web Analytics, described in section 2.8.

We will keep this table current. Ask us at any time for the version in force.

10. Security

We use administrative, technical and physical safeguards proportionate to the sensitivity of what we hold: encryption in transit; session tokens stored only as hashes, with absolute and idle expiry; per-organisation data isolation enforced at the database level, not only in application code; a six-tier role model with department scoping and separate clearance for restricted incidents; time-limited signed URLs for all media access; rate-limited authentication and password reuse prevention; an append-only, cryptographically chained audit trail (section 13); and penetration testing at each development milestone, with all critical and high findings remediated.

No system is perfectly secure and we do not claim otherwise.

If something goes wrong. If we become aware of a data breach affecting customer data, we will notify the affected Customer without undue delay and in any event within 72 hours of becoming aware, with what we know and what we are doing.

Notifying affected individuals is normally the Customer's decision and duty, because the Customer holds the relationship and the context. We will support them and provide what they need.

Where we are required by law to report a breach to a regulator, we will do so. Where a Customer has its own reporting obligations, we will give them what they need to meet them, and we will do it in time.

11. Your rights

Access and correction. You can ask what we hold about you and ask us to correct it (APP 12 and 13). For information a Customer entered through the Services, we will coordinate with that Customer. For health information, state legislation may give you a direct right against us — we will respond as that law requires.

Correction of operational records works differently. See section 13.

Marketing. Unsubscribe at any time, from any message, or contact us.

Complaints. Section 17.

12. How long we keep it

We keep incident records for as long as your account is open.

Incident records are evidence. Insurance claims, coronial inquiries, regulatory investigations and civil proceedings routinely arise months or years after the event they concern — and a record that has been deleted cannot be produced.

So we do not delete your operational data at the end of an event, or at the end of a subscription term. It stays available to you for as long as you hold an account with us.

When an account is closed, we delete its data 90 days later. The 90 days exist so you can export anything you still need, and so an account closed in error can be recovered.

Retention periods by data type. Incident and operational records — indefinitely while the account is open; deleted 90 days after account closure, subject to the statutory minimums and holds described below. Health information — retained for as long as the Customer's own legal obligations require. Where a Customer is a health service provider, s 25 of the Health Records and Information Privacy Act 2002 (NSW) generally requires them to keep health information for at least 7 years from the last occasion of service — and where the individual was under 18 when it was collected, until they turn 25. Equivalent rules apply in other states. We will not delete data a Customer tells us is subject to such an obligation. Audit trail — survives deletion of the account; see section 13. Media — retained with the records it belongs to; a file you individually delete is removed from storage 90 days after you delete it, and a record that it was attached and later removed is kept. Account, billing and support records — as long as necessary, including for tax and accounting record-keeping. Server logs (including IP addresses), for the Services and the website — 30 days, then deleted automatically. Demo requests and other enquiries — as long as necessary to respond and to manage any business relationship that follows; ask us to delete yours at any time. Password history — a small number of previous hashes per user, to prevent reuse. Session records — until expiry, then pruned.

Two different 90-day periods appear above. They are unrelated: one runs from account closure, the other from the deletion of an individual file.

Why we keep it this long. We hold operational data for as long as your account is open because that is how long it remains useful to you for the purpose it was collected — proving what happened. If you want data removed sooner, tell us and we will discuss what can be deleted without undermining the evidentiary value of what remains.

Two overrides. Where a Customer tells us they are subject to a legal retention obligation — for example, a NSW council whose incident records are State records under the State Records Act 1998 (NSW) — we will not delete that data, regardless of what the subscription term says. We record this as a retention hold on the account or the specific event, and while a hold is in place our deletion process refuses to run against it. Customers with record-keeping obligations should tell us before termination.

Where the law requires us to keep something, we keep it, even if you ask us not to.

13. Why some records cannot be edited or deleted

The Services are designed so that operational records can be proven un-altered after the fact. That is the point of the platform, and it constrains what we can do at your request.

Running log entries are never overwritten. A correction is added as a new entry that points at the original. Both remain visible.

Retracted entries are struck through, not removed, with a reason and the identity of the person who retracted them.

The audit trail is append-only and cryptographically chained, per organisation. Removing or altering a record breaks the chain and is detectable — which is precisely what makes it evidence.

Deleted media is soft-deleted. The record of the deletion remains.

What this means for you. If you ask us to correct an operational record and we agree it is wrong, we will not erase the original. We will annotate it with the correction, so anyone reading it later sees both. This is expressly contemplated by APP 13.5 where correction is impracticable, and it is how an evidentiary record is meant to behave.

If you believe a record about you is wrong, tell us — or tell the event organiser — and it will be corrected in this way.

What survives when an account is deleted. When a Customer's account is deleted, we remove their operational data — incident logs, jobs, media, site plans, rosters and user accounts.

The audit trail is not deleted. What survives is the record of administrative actions taken on that account, and a tombstone recording that a deletion occurred, when, and how much was removed.

We keep it deliberately. It is how we can demonstrate — to the Customer, to a regulator, or in a dispute — that their data was handled properly and that the deletion actually happened. Destroying that record at the same time as the data would leave us unable to prove either.

So a deleted Customer is not erased without trace. A record that the organisation existed, and of what was done to its account, remains. If that matters to you, raise it with us before termination.

14. Automated decision-making

We do not currently make automated decisions about individuals that could significantly affect their rights or interests. Category defaults, priority values and escalation timers organise operational work; a person makes every decision that affects a person.

From 10 December 2026, APP 1.7 requires privacy policies to disclose automated decision-making of that kind. We will review our position and update this policy before that date.

15. International

We do not currently offer the Services in the European Economic Area or the United Kingdom, and this policy does not attempt to state GDPR or UK GDPR compliance.

Before offering the Services in any jurisdiction with its own data protection regime, we will publish a jurisdiction-specific addendum and put appropriate transfer mechanisms in place. We would rather say this plainly than imply a compliance posture we have not built.

16. Cookies

The Services. The Services use one cookie, and it is the one that signs you in.

The cad_session cookie keeps you signed in and expires after 12 hours, or 60 minutes idle.

It is strictly necessary — the Services will not work without it. It is set HttpOnly and Secure, so scripts cannot read it and it only travels over an encrypted connection.

We use no other cookies. No analytics cookies, no advertising or tracking pixels, no third-party cookies, no cross-site tracking. Because the only cookie we set is essential to a service you have asked for, we do not show a cookie consent banner — there is nothing to consent to.

We also keep a few preferences on your own device, in your browser's local storage. These stay on your device, are never sent to us as an identifier, and are not used to recognise you: your light or dark theme choice; which event you last had selected; your saved dashboard layout; and map display preferences.

Clearing your browser storage resets these. Blocking the session cookie will prevent sign-in.

Our website. Our public website sets no cookies and stores nothing in your browser. Its analytics are cookieless (section 2.8). There is nothing to consent to, so it shows no cookie banner.

If this changes, we will say so first. Any cookie on the website, or any feature of the Services that identifies your device, would change this section — and we will update this policy before that happens, not after.

17. Contact and complaints

Privacy contact: privacy@synqe.com.au

Please put privacy requests and complaints in writing to that address. It reaches our privacy contact directly.

Tell us what happened and what you would like done. We will acknowledge within 5 business days and respond substantively within 30 days. If we need longer, we will tell you why and when.

If you are not satisfied with our response: where your complaint is about information an organisation recorded through the Services — an incident at an event, for example — that organisation is accountable for it. Raise it with them. If they are a government agency or otherwise covered by privacy law, they can tell you which regulator oversees them, and you can take it there.

For health information in New South Wales, you can complain to the NSW Information and Privacy Commission — ipc.nsw.gov.au, 1800 472 679.

For anything else about how SYNQE itself has handled your information, tell us and we will work with you to resolve it. If we cannot, we will tell you plainly what other options are open to you rather than leave you to find out.

Regulators generally expect you to raise a matter with the organisation first and allow 30 days.

18. Children

The Services are for business use by adult personnel. We do not knowingly collect information directly from children.

Incident records may nevertheless reference a minor — a patron involved in an incident at a public event. Where they do, section 3 applies. Health information collected about someone under 18 commonly carries a longer retention obligation for the Customer, in New South Wales until the individual turns 25. See section 12.

19. Changes

We may update this policy. Material changes will be notified through the Services or by email, and the version and date at the top will change. Continued use after a change takes effect means you accept the updated policy.

This policy is current as at 30 September 2026 and is under periodic legal review.

↑ Back to top