E
Privacy & data notice

What this app collects, and why

This page explains, in plain language, what the EDL Jobs Board collects about you, who inside EDL can see it, and how long it's kept. It applies to every page linked from the Launch Dashboard.

Location

Only used on the Pre-Start Checklist, when you sign on to a job.

One-time sign-on check

When you tap "Sign on," your browser's GPS location is sent once to confirm you're near the job site. You're asked to allow location access before this happens, and your choice is remembered so you're not asked every time.

Ongoing check while signed on up to 8 hours

After a successful sign-on, the app re-checks your location roughly every 10 minutes for up to 8 hours while the page stays open, and records if you've moved more than 3km from the site. This is a working feature under review - it is not yet fully explained on the Pre-Start page itself, and how it should be disclosed is still being finalised.

Who can see it

You can see your own sign-on result. EDL administrators can see the same location history - yours and everyone else's - in the admin reporting area, rounded to a distance from site rather than an exact address.

Usage & activity

Runs on most pages of the app.

Page visits and selected actions

Most pages record that you visited them, roughly how long you spent, and a small number of specific button clicks - tied to your name and Odoo login, not anonymous. This is used to fix pages that people get stuck on, and to see which parts of the app are actually being used.

Who can see it

You don't see your own usage history anywhere in the app. EDL administrators can look up any one person's activity - pages visited, when, and for how long - in the admin reporting area.

Personal & safety records

Licences, tickets & insurance

You enter your own licence/ticket numbers and expiry dates, and subcontractors enter their own insurance details, so the app can warn about upcoming expiries. You can only see and edit your own records; EDL office staff can see the full register.

Incident & hazard reports

Incident and hazard reports can include health-related details and the names of anyone involved - including people who don't use this app themselves, such as a subcontractor, a client's staff member, or a witness. These reports go to EDL's safety register. If a report looks regulator-notifiable, the system escalates it to an authorised WHS/office reviewer; it does not notify the regulator automatically.

Expenses & timesheets

Expense claims and time worked are recorded against your name for payroll and job-costing purposes, visible to you and to EDL office/accounts staff.

How long it's kept

Safety, licence, employment-adjacent, financial and client approval records are retained according to the EDL retention matrix. Some records must be kept because they are evidence for safety, payroll, tax, contract, insurance or regulator obligations; data that is no longer needed should be archived, destroyed or de-identified where lawful.

Access, correction & deletion requests

Use this when you want to see, correct, annotate, restrict or delete information about you.

Request handling

Requests are logged for office review with your name, contact details, request type, affected record and the outcome. If EDL cannot change or delete a record because it must be retained for safety, employment, tax, contract or regulator reasons, the reviewer should record the reason and, where appropriate, add a correction note instead.

Client approvals & contract evidence

Portal submissions

Client portal requirement changes are stored against the job with the submitted contact details, timestamp, portal terms version and review outcome. A portal submission is not automatically a price, schedule or scope variation until EDL reviews and records the decision.

Quotes, variations and scope

Commercial acceptance should be tied to the current Odoo quote, variation or written approval record. The app keeps audit evidence, but EDL should still use the correct contract, quote and invoice documents for binding terms.

Unauthorised access controls

Portal access and document download logs

Client portal link failures, successful portal views, requirement submissions and COE downloads are logged with timestamp, job, action, browser details and a hashed network address. These logs help detect leaked links, unauthorised access and unusual document access.

Monthly access reviews and leaver checks

EDL office staff can record monthly access reviews and leaver access-removal checklists covering Odoo accounts, client portal links, shared credentials, devices, groups and exports.

Export control

Exports containing personal, client, job, financial or safety information should be logged with purpose, recipient, approval, legal basis and retention plan before sharing.

Privacy incidents & data breaches

Internal breach register

Suspected unauthorised access, accidental disclosure, lost device/document, wrong-recipient email, or exposed portal link should be logged for review. The system records assessment, containment, notification decision and closure evidence; it does not notify regulators or individuals automatically.

Retention matrix

Legal hold beats deletion

If a dispute, regulator enquiry, insurance claim, incident investigation or legal hold exists, relevant records should be preserved even if their normal retention period has expired.

Questions about your own information, or want something corrected or removed? Speak to your EDL office contact, or reach out to whoever manages this system on EDL's behalf.