Last updated: 25/08/2026, Version 1.0
Austral Facility Services (“AFS”, “we”, “us”, “our”) is committed to handling personal information in accordance with the Privacy Act 1988 (Cth) (Privacy Act) and the Australian Privacy Principles (APPs).
This policy explains what personal information we collect through the AFS Connect mobile app and the systems it connects to, why we collect it, how we hold it, who we disclose it to, and how you can access it, correct it, export it, or complain about how we have handled it.
Entity details:
Name: EMG Facility Services Pty Ltd, trading as Austral Facility Services
ABN: 66 623 184 529
Head Office: 25/23 Ashtan Place, Brisbane 4014
1. Who this policy applies to
AFS Connect is used by contractor personnel engaged by contractor companies that supply services to AFS client sites, and in some cases by sole traders contracted directly. Users of the app are generally not direct employees of AFS.
Because of this, AFS does not rely on the “employee records” exemption in section 7B(3) of the Privacy Act in relation to information handled through AFS Connect. We treat all personal information collected through the app as fully within the scope of the Privacy Act and the APPs.
This policy applies to:
- individuals who use AFS Connect to take up shifts and to clock in and out (“users”, “you”);
- managers at contractor companies, who hold their own AFS Connect accounts; and
- parents or guardians who provide details in connection with a user under 18 (see section 16).
2. The systems this policy covers
SYSTEM ROLE
AFS Connect The contractor mobile app (iOS and Android) – shift information and geofence-verified clock-in and clock-out.
AFS middleware AFS-operated integration layer between AFS Connect and Deputy. It holds the record linking each AFS Connect user to a
placeholder position in Deputy.
Deputy Third-party workforce management platform used for rostering, timesheets and location mapping. Deputy holds placeholder
positions, not named individuals. See section 8.
AFS internal systems AFS-operated hosting and administration, in Microsoft Azure (Australia East).
This policy does not cover the separate privacy practices of your own employer, of AFS’ clients, or of any third-party service you reach from a link in the app. Those organisations have their own privacy policies.
3. What personal information we collect
CATEGORY EXAMPLES SOURCE
Identity and contact First and last name, email address, Your account activation; details
phone number supplied by your employer
Engagement Contractor company, role AFS Connect
(contractor or manager), site
assignment
Shift and attendance Shifts taken up, rostered start and AFS Connect, synchronised with
end times, clock-in and clock-out Deputy against a placeholder
timestamps position (see Section 8)
Location GPS coordinates and distance from AFS Connect (device location
the assigned site, captured at the services), only while you are
moment of clock-in and clock-out actively clocking in or out
Guardian details Name and contact details of a parent Contractor onboarding (see
or guardian, where a user is under 18 Section 16)
What we do not collect
- No background location tracking. See section 4.
- No camera, photo library, contacts, microphone or biometric access. The app does not request these permissions and does not use facial or fingerprint verification.
- No free-text notes. AFS Connect does not provide a notes field.
- No push notification tokens. The app does not use push notifications.
- No sensitive information as defined in section 6 of the Privacy Act – no health information, racial or ethnic origin, religious beliefs, or union membership.
- No payment or bank account details. You are paid by your employer, not by AFS. AFS Connect does not handle payment information and is not a payroll system.
4. Location – how the geofence works
Location is the most sensitive information the app handles, so we set out our practices in full.
When location is read
Location is read only at the moment you take an explicit clock-in or clock-out action. It is not read at any other time.
We do not track your location in the background or when the app is closed. On iOS the app requests “when in use” permission only and does not request “always” or background location. On Android the app requests ACCESS_FINE_LOCATION and ACCESS_COARSE_LOCATION only and does not request ACCESS_BACKGROUND_LOCATION.
We do not use location to build a movement history, to monitor you between clock-in and clock-out, or for any purpose unrelated to confirming site attendance.
What we use it for
We compare your location against the boundary of your assigned site – a “geofence” check. The purpose is to establish the hours actually spent on site, so that these can be compared against the hours invoiced by your contractor company. The purpose is the hours, not your whereabouts.
The app never blocks you
AFS Connect will not stop you clocking in or out. This matters, so we are explicit about each case:
- If location is unavailable – no signal, no GPS fix, or permission declined – the app records your clock-in or clock-out immediately, without a location, rather than making you wait. If the location permission is granted, the app then keeps trying quietly in the background for up to around 10 minutes, for as long as the app stays open, and fills in the location on your existing record if it succeeds. Either way, your attendance is recorded straight away and never help up waiting on a location fix. The record is marked as not location-verified unless and until that happens.
- If you are outside the site boundary, the app tells you so, and still records the clock-in or clock-out. It notifies your contractor company’s manager and the AFS Client Service Manager so the difference can be discussed. It does not block you and does not automatically affect anything.
- If you decline the location permission entirely, you can continue to use the app and to clock in and out. Your records will not be location-verified.
You control the location permission through your device settings and can withdraw it at any time, with no consequence to your ability to use the app.
Data held briefly on your device
If your device has no network connection when you clock in or out, the event – including the location captured at that moment – is held on your device, encrypted, and sent to AFS automatically once connectivity returns. It carries the time recorded on your device at the moment of the action.
Events held on the device for more than 12 hours are marked as unverified.
Workplace surveillance
Recording your location at clock-in and clock-outs is “tracking surveillance” under the Workplace Surveillance Act 2005 (NSW) and the Workplace Privacy Act 2011 (ACT), and is regulated as use of a tracking device under surveillance devices legislation in Victoria, Western Australia, South Australia and the Northern Territory. Under the NSW and ACT Acts, AFS is treated as an employer in relation to labour-hire personnel working at AFS sites, even though AFS is not your direct employer.
AFS therefore issues a separate Workplace Surveillance Notice, applying nationally, which sets out the kind of surveillance, how and when it is carried out, and how the information may be used. This privacy policy does not replace it.
The clock-in and clock-out screen also display a visible notice telling you that taking that action will record your location.
5. How we collect personal information
We collect personal information:
- directly from you, when you activate your account, take up a shift, or clock-in or out; and
- from your employer, which supplies your name, contact details, role and site assignment so your account can be created, and which identifies users under 18.
Where we collect information about you from your employer rather than from you directly, we take reasonable steps to ensure you are made aware.
6. Why we collect, hold, use and disclose it
We collect and use personal information to:
- give you the shift information you need to do your work;
- record when you start and finish at an AFS client site;
- establish the hours actually worked onsite, and compare them against the hours invoiced by your contractor company under a purchase order;
- identify differences between recorded attendance and invoiced hours, so they can be discussed;
- communicate with you, and with your contractor company, about shifts, attendance and your account;
- administer, secure and support AFS Connect, including investigating misuse;
- meet our obligations under work health and safety law and our contracts with clients and contractor companies; and
- comply with any other legal obligation, or respond to a lawful request from a court, regulator or law enforcement agency.
AFS does not use this information for payroll. You are paid by your employer. AFS uses attendance records to verify invoices from your employer against purchase orders, which is a different purpose.
We will only use or disclose your personal information for a secondary purpose where you have consented, or where the secondary purpose is permitted under APP 6.
7. Who we disclose it to
- Your contractor company – your employer can see your shift and attendance records through the manager view in AFS Connect. Where a clock-in or clock-out is recorded outside the site boundary, your employer’s manager is notified.
- AFS personnel – the AFS Client Service Manager responsible for the site is also notified of out-of-boundary events, and AFS staff administering the app can access records for that purpose.
- Deputy – see section 8.
- AFS clients – in one specific arrangement, a client receives a daily report of total hours. The contractor component appears as a single aggregated line with no names and no personal information. Your individual records are not provided to clients.
- Service providers – Microsoft Azure hosting, and IT support and security providers engaged by AFS, bound by confidentiality and data-handling obligations.
- Where required or authorised by law – including to courts, regulators, insurers, or in connection with a legal claim.
We do not sell personal information, and we do not disclose it to third parties for their own marketing purposes.
8. Deputy and how we minimise what is shared
AFS Connect and Deputy do not exchange your name.
Rostering in Deputy is done against placeholder positions rather than named individuals. A shift is published through the AFS middleware to AFS Connect, where you take it up. Attendance data is written back against the placeholder.
The record connecting you to a placeholder is held only in the AFS middleware, under AFS’ control. It is never sent to Deputy.
Placeholder do not identify you individually. Deputy allocates each shift to a placeholder position to satisfy its own scheduling rules – for example, so that shifts on the same day don’t conflict with each other in its system. This allocation happens independently of, and separately from, the decision about which of AFS’ contractors will actually perform the shift; whoever allocates the placeholder in Deputy has no way of knowing, and has no need to know, who that will be. In practice the same placeholder is often used across several different people’s shifts, including more than one person on the same day. Deputy holds no record connecting a placeholder to your name, email address, or contact details.
What Deputy does receive: shift and roster data, clock-in and clock-out times, and the location coordinates captured at those moments. AFS uses Deputy’s built-in mapping and geofencing to display where a clock-in or clock-out occurred relative to the site, rather than building a duplicate capability.
What Deputy does not receive: your name, email address or phone number; any free-text content, since AFS Connect has no notes field; and the record linking you to a placeholder.
AFS has confirmed that no identifying information about any user has been provided to Deputy’s support personnel.
Two things this does not mean, which we state plainly rather than overclaim:
- The information is pseudonymous, not anonymous. AFS holds the link, so in AFS’ hands the combined record is personal information and is protected under this policy.
- It does not remove all possibility of identification. A location recorded away from a work site, or at a site where very few people work, may in some circumstances point to an individual even without a name attached.
9. Disclosure of personal information overseas (APP 8)
Under APP 8 (Australian Privacy Principles, Section 8), before we disclose personal information to an overseas recipient we must take reasonable steps to ensure that the recipient does not breach the APPs, unless an exception applies. Under section 16C of the Privacy Act, we generally remain accountable for acts of an overseas recipient that would breach the APPs.
AFS systems. All AFS-operated systems – the app back end, the middleware, and the record linking you to a Deputy placeholder – are hosted in Microsoft Azure, Australia East. This information is stored in Australia.
Backups are held in Australia East, and all administrative and support access to these systems is handled in-house by AFS, based in Australia – no offshore support access.
Deputy. The AFS tenant is hosted on AWS (Amazon Web Services) infrastructure, in an Australian region, and Deputy’s support for AFS is also Australia-based.
10. How we store and secure your information
Personal information is held in AFS’s systems in Microsoft Azure (Australia East), and – in the limited form described in section 8 – in Deputy.
We take reasonable steps to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure, including:
- restricting access to authorised AFS personnel and to your own contractor company’s management users, on a role-based basis;
- keeping the record that links you to a Deputy placeholder separate from operational data, and restricting access to it;
- encrypting the clock events held temporarily on your device before they are sent, in a dedicated on-device queue;
- caching your current shifts, site location and attendance status on your device in your device’s standard app storage, so the app remains usable briefly offline – this is the same information already described elsewhere in this policy, held locally rather than transmitted, and is not separately encrypted;
- multi-factor authentication, mandatory on all AFS employee accounts including administrators;
- logging and monitoring of administrative access; and
- contractual security obligations on our third-party providers.
Application usage monitoring. AFS’s backend systems use Microsoft Application Insights to monitor performance and diagnose faults. This records technical details of each request (the web address called, response time, and status) but not the content of what you submit – for example, a clock-in request is recorded as “a clock-in request was made,” not with the location or other details you sent. Your device’s IP address is recorded but truncated for privacy. This data is kept for 30 days.
11. How long we keep it
We keep personal information only for as long as it is needed, or for as long as we are required to keep it by law.
Because AFS is not your employer, the employee record-keeping obligations in the Fair Work Act 2009 (Cth) apply to your employer rather than to AFS. AFS’s retention is driven by our contract with your employer and the period during which an invoice may be queried or audited, by Commonwealth tax law, by work health and safety obligations, and by the limitation periods for bringing a claim.
INFORMATION RETAINED FOR
Attendance records – date, site, times, verification status 6 years
Raw location coordinates 60 days, then reduced to a geofence result plus distance from site
Identity and contact details For the time using the app, and then 90 days after
Guardian details (section 16) While using the app, or age reaches 18 (whichever is first)
Acknowledgement of the surveillance notice 1 Year (renewal required each year)
The six-year period for attendance records aligns with the limitation period for contractual claims in Queensland and with the period for recovering underpaid wages, so the record remains available to you as well as to us if a question arises about hours worked.
Reducing raw coordinates after 60 days means that, beyond that point, we retain whether you were at the site rather than exactly where you were.
When information is no longer needed and we are not required to retain it, we take reasonable steps to destroy it or de-identify it.
12. Data breaches
AFS is subject to the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act. If we suspect a data breach, we will assess it promptly. If we conclude there has been an eligible data breach – one likely to result in serious harm – we will notify the affected individuals and the Office of the Australian Information Commissioner as required by law.
13. Automated decision-making
From 10 December 2026, subclauses 1.7 to 1.9 of APP 1, inserted by the Privacy and Other Legislation Amendment Act 2024 (Cth), require an APP entity to include information in its privacy policy where a computer program uses personal information to make, or substantially assist in making, a decision that could reasonably be expected to significantly affect an individual’s rights or interests. The obligation covers rule-based automation, not only artificial intelligence.
AFS’s assessment is that this obligation does not apply to AFS Connect. The reasoning is set out here so that the assessment is on the record:
- The geofence comparison is automated, but it produces no automated consequence. The app does not block a clock-in or clock-out in any circumstance.
- Where a clock-in or clock-out falls outside the site boundary, the result is a notification to your contractor company’s manager and to the AFS Client Service Manager. What follows is a conversation between people.
- Your access to the app is not determined by geofence results, and your ability to perform contracted work does not depend on the app at all – work is contracted through the purchase order process.
- The commercial effect of a difference between recorded and invoiced hours falls on the contractor company under its purchase order, and does not automatically stop payment.
- You can review your own attendance records in the app before your contractor company invoices, so differences can be identified and raised before they reach a decision point.
14. Accessing, correcting and exporting your information
In the app. You can see your own attendance history in AFS Connect at any time, and export it as a CSV or PDF file. The export covers your own records only.
The export is a record of activity in the app – when clock-in and clock-out actions were recorded, and whether each was location-verified. It is not a record of hours worked or hours payable. Hours payable depend on your engagement terms and are determined by your employer, not by AFS.
Requests to us. You may also request access to the personal information we hold about you, and ask us to correct it if it is inaccurate, out of date, incomplete, irrelevant or misleading. Contact afsconnect@australfs.com.au.
We will respond within a reasonable period. Typically within 7 business days. There is no charge for making a request.
If we refuse access or a correction, we will tell you why in writing and explain how you can complain.
If a record looks wrong. Tell your contractor company, or contact us, as soon as you can so it can be checked and corrected.
15. Deleting your account
You can delete your AFS Connect account:
- from within the app, under Settings; or
- from our website at /App/DeleteAccount on the AFS Connect web host, if you have already uninstalled the app.
Before you confirm deletion, we will offer you the export described in section 14. Once deletion completes, your records are no longer available to you.
What is deleted: your name, email address, phone number, login credentials, your contractor company association and site assignment, and the record linking you to your Deputy placeholder.
What is retained: the underlying attendance records – date, site, times and verification status. AFS retains these because they are the records used to verify invoices against purchase orders, and to meet the retention obligations in section 11.
Why the retained records are no longer about you: deleting your account destroys the link between you and the placeholder, so the retained records cannot be connected back to you.
Your employer holds its own separate records of your engagement and attendance, which AFS cannot delete on your behalf.
16. Users under 18
- AFS requires the contractor company to identify the user as under 18 before an account is created;
- AFS, the contractor company and the user’s parent or guardian enter into an agreement covering the user’s use of the app, including the recording of location at clock-in and clock-out; and
- we collect and hold the parent or guardian’s name and contact details for that purpose.
Guardian details are used only for that purpose and are held under this policy.
Note also that a minor’s contract is voidable at common law, which is the reason for the guardian agreement covering the Terms of Service and End User Licence Agreement as well as this policy.
17. Dealing with us anonymously
APP 2 gives you the option of dealing with us anonymously or under a pseudonym where that is lawful and practicable. It is not practicable for AFS Connect: the app exists to record which identified individual attended which site at which time, and that function cannot be performed without identifying you to AFS.
You can make a general privacy enquiry anonymously, though we may not be able to respond fully or resolve a complaint if we cannot identify you.
18. Marketing
We do not use personal information collected through AFS Connect for direct marketing.
19. Complaints
If you believe we have breached the APPs or otherwise mishandled your personal information, please tell us first so we can try to fix it.
Step 1 – Notify AFS
Email afsconnect@australfs.com.au, or write to 25/23 Ashtan Place, Brisbane 4014, marked to the attention of “Compliance”.
Describe what happened, when, and what outcome you are seeking.
We will acknowledge your communication within 3 days and aim to respond substantively within 30 days. If we need longer, we will tell you why.
Step 2 – Speak to the OAIC
If we do not respond within 30 days, or you are not satisfied with our response, you may speak to the Office of the Australian Information Commissioner (OAIC).
A privacy concern to the OAIC must be made in writing – the OAIC cannot take a complaint over the phone. You can lodge one:
- Online: through the privacy complaint form at oaic.gov.au
- By email: oaicintake@oaic.gov.au
- By post: GPO Box 5288, Sydney NSW 2001
- Enquiries: 1300 363 992 (Monday to Thursday, 10 am to 4 pm AEST/AEDT)
The OAIC’s enquiries line can help with the process, and support is available through the National Relay Service and the Translating and Interpreting Service.
Generally, a complaint to the OAIC must concern something that occurred less than 12 months ago, and you must have complained to us first.
20. Changes to this policy
We may update this policy to reflect changes to the app, to our systems, or to the law.
