Privacy Policy
Applies to the CheckPass Inspector mobile app for iOS and Android.
Effective 25 September 2026. Last updated 25 September 2026.
CheckPass Inspector is a workplace tool, not a consumer app. It is issued by Check Pass Technologies PTY LTD to field technicians so they can carry out equipment inspections on behalf of their employer, including while offline.
Your account details — your name, your role and the sites you can access — are set up by your administrator rather than collected from you. What the app itself records is the evidence of an inspection: the answers entered, and the photographs and timestamps that support them. It contains no advertising, no third-party analytics or tracking, and no data is ever sold.
1. Who we are
Check Pass Technologies PTY LTD (we, us) develops and operates CheckPass Inspector and the CheckPass inspection platform it connects to. We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
Inspection records created in the app are made available to the organisation that engaged us — normally your employer or the site operator. That organisation decides which sites, assets and inspection templates you are assigned, and which of its administrators can view your records. If your question concerns how your employer uses your inspection records, raise it with your employer as well as with us.
2. What information the app collects
2.1 Your account details are set by your administrator, not collected from you
The app never asks you for personal details, and you cannot create an account in it. Your administrator creates your account on the platform and sets:
- your name and work email address;
- your role and permissions; and
- the sites you are allowed to access.
These values come from your organisation's own records. The app cannot change them and never asks you to supply them.
2.2 Signing in
If your organisation uses Microsoft single sign-on, you sign in on Microsoft's own page. Your password is never entered into, seen by, or handled by our app. Microsoft returns a signed token that proves you control that work or school account, and we use it only to confirm you hold an account your administrator has already created:
- We read the tenant and account identifiers from the token and match them to your existing account record.
- On your first sign-in only, we match the email address in the token against the account your administrator created, so that the Microsoft identity and the account can be linked. From then on, matching is by identifier alone.
- We do not store the display name or any other profile detail carried in the token. The name shown against your inspections is the one your administrator entered.
- We never query the Microsoft directory, your mailbox, your calendar, your files or your contacts. Your role and site access are read only from your account record on our platform, never from Microsoft.
- The app accepts work or school accounts only. It cannot sign in with a personal Microsoft account.
Signing in with Microsoft does not create an account. If your administrator has not already set one up for you, sign-in is refused.
Where your organisation issues an email and password instead of single sign-on, your administrator creates that account as well. In that case the password is entered in the app and sent to us once to be checked; we store only a one-way cryptographic hash of it, never the password itself, which we cannot recover or read.
We record sign-in activity, including successful and failed attempts, so an account can be locked after repeated failures and suspicious access can be investigated.
2.3 Inspection content you enter
- Your answers to inspection checklist items, free-text notes and measurements.
- The asset, site and inspection template involved, and the times you started and submitted the inspection.
- Defects you raise and any accompanying description.
- Your signature or confirmation of completion where the template requires it.
2.4 Where you were when you answered
While you have an inspection open, the app records where you were for each answer you give. This is what allows an inspection to show that the work was carried out at the equipment, which is the point of an inspection record. For every answer it stores:
- The coordinates of the device, to about one metre of precision.
- The time you recorded the answer.
- The time the underlying position reading was taken. The app keeps one recent reading and refreshes it periodically rather than asking the satellites on every keypress, so the reading is usually a little older than the answer. Both times are stored so the difference is visible rather than hidden.
Be aware of what this means in practice: because each answer carries a position and a time, the answers to one inspection together show your movement around the site while you carried it out. They are retained as part of the inspection record and are visible to administrators who can see that record.
Position readings are taken only while an inspection is open on screen. The app does not track you between inspections, does not run location services when it is not in use, and does not record your location anywhere else in the app.
If the device cannot get a position — you declined the permission, you are indoors or underground, or the reading is too old to be trustworthy — the app records that the answer has no location and you can still answer it, finish the inspection and submit it. It never withholds or discards your work over a missing position, and it never substitutes a stale reading for a real one.
2.5 Photographs and their metadata
When an inspection item asks for a photograph, the app stores the image together with audit metadata so the photograph can be shown to be genuine:
- The capture time recorded by the camera in the image's EXIF data.
- GPS coordinates, taken from the image's EXIF data where the camera recorded them. If the image carries no coordinates, the app asks the device for its current position instead.
- The time you attached the photograph, and whether the coordinates came from the image, the device, or were unavailable.
If no location is available, the app records that fact and the inspection can still be completed.
2.6 Device and technical information
- Application request logs. For each request your device makes we record a request identifier, the method and path, the response status and how long it took. These entries contain no IP address and no inspection content. They exist to diagnose faults.
- Web server access logs. Our web server keeps standard access logs, which include your IP address and the identifier your device sends with each request, for security monitoring.
- Security audit records. We record the IP address you acted from against security-significant events — signing in and out, failed sign-in attempts, permission and role changes, data exports, and the submission or acceptance of an inspection. These records are append-only: the application cannot alter or delete them, which is what makes the audit trail reliable.
- Abuse controls. Where we rate-limit a publicly reachable endpoint we use a one-way cryptographic hash of the IP address rather than the address itself.
- Authentication tokens issued to your device so you stay signed in between sessions.
- Connectivity state — whether the device is online, so the app knows when it can synchronise.
2.7 What the app does not collect
- No advertising identifier, and no advertising or marketing profiles.
- No third-party analytics, crash-reporting or tracking software. The app contains no such components.
- No profile information from your Microsoft account beyond the identifiers needed to match you to your existing account record.
- No contacts, calendar, mailbox, files, microphone, call, SMS or health data.
- No background location tracking. Position readings are taken only while an inspection is open on screen, never when the app is in the background or closed, and never between inspections.
- No browsing activity outside the app.
3. Device permissions the app asks for
| Permission | Why the app asks | If you decline |
|---|---|---|
| Camera | To photograph equipment and defects as inspection evidence. | You cannot take new photographs in the app. You can still attach an existing image and complete items that do not require a photograph. |
| Camera and location, asked together when you start an inspection | An inspection needs your location for its answers, and the camera when its template asks for photographs. Both are requested as the inspection opens so a permission prompt does not interrupt you partway through a checksheet. A template that asks for no photographs does not request the camera. | The app tells you what the inspection will be missing and lets you decide whether to start anyway. |
| Photo library | To attach an existing photograph to an inspection item. | You cannot attach existing images. Taking a new photograph still works. |
| Location (while using the app) | To record where each inspection answer was given, and to stamp photographs with coordinates when the image itself carries none, so a record shows where the work was done. | Answers and photographs are saved without coordinates and marked as having no location. Inspections can still be completed and submitted. |
| Network access | To sign in and to synchronise inspections with our server. | Not optional. Inspections can be completed offline, but nothing can be synchronised. |
4. Why we collect this information
- To let you perform inspections — including offline, by holding your assigned templates, assets and in-progress work on the device.
- To produce a defensible inspection record — timestamps, location and photograph metadata are what allow an inspection to be relied on for safety and compliance purposes.
- To identify who performed an inspection, which is a requirement of the inspection regimes the platform supports.
- To generate reports, certificates and defect notifications for your organisation.
- To secure the service — authenticating you, enforcing which sites you may access, and investigating suspected misuse.
- To operate and support the app — diagnosing sync failures and other faults.
- To meet legal obligations, including record-keeping and responding to lawful requests.
We do not use your information for advertising or marketing, and we do not make automated decisions about you that have legal or similarly significant effects.
5. Information held on your device
Because inspections must work without a signal, the app keeps inspection data on the device itself:
- Inspection drafts, responses, photographs, your assigned templates and a cached list of assets are held in a local database encrypted with AES-256. The encryption key is generated on the device, stored in the iOS Keychain or Android Keystore, and never leaves the device or reaches our servers.
- Your sign-in tokens and account details are held in the platform's secure credential store, not in ordinary app storage, and are marked so they are not copied to other devices.
- On Android, the app disables system backup, so app data is not included in device backups.
Signing out clears your credentials from the device. Uninstalling the app removes its local database and everything in it. Inspections already submitted to our server are unaffected by either action.
6. How information is transmitted and where it is stored
- All communication between the app and our servers uses HTTPS with TLS 1.2 or higher. The app refuses unencrypted connections.
- Submitted inspections, photographs and reports are stored on Amazon Web Services infrastructure in the Asia Pacific (Sydney) region, in Australia. Databases are not reachable from the public internet.
- Photographs and documents are stored in access-controlled object storage and served only through short-lived, authenticated links.
- Data is encrypted at rest.
7. Who we share information with
We do not sell your personal information, and we do not disclose it for advertising. We share it only as follows:
- Your organisation. Administrators at the sites you are assigned to can see the inspections you performed, including your name, the answers you recorded, your photographs and their timestamps and coordinates, and any defects you raised.
- Microsoft. If your organisation uses single sign-on, you sign in on Microsoft's own page and Microsoft returns a signed token confirming the sign-in succeeded. Microsoft's handling of that sign-in is governed by its own privacy terms and your organisation's Microsoft tenant settings. We send Microsoft no inspection answers, no photographs and no location data.
- Amazon Web Services, which hosts the platform in Australia under contract to us and does not use the data for its own purposes.
- Our email delivery provider, where a certificate, report or notification must be emailed to recipients your organisation has configured.
- Professional advisers, auditors, or law enforcement and regulators, where we are permitted or required by Australian law to disclose information.
- A successor entity, if our business or the relevant part of it is transferred, subject to that entity being bound by terms no less protective than this policy.
8. Overseas disclosure
Your account record and all inspection data are stored in Australia. Two things may be handled outside Australia: the single sign-on step itself, which Microsoft performs on its own infrastructure under your organisation's Microsoft tenant settings, and the delivery of an email where a certificate, report or notification is sent. Where that occurs we take reasonable steps to ensure the recipient handles the information consistently with the Australian Privacy Principles.
9. How long we keep information, and deletion
- Submitted inspections are compliance records. Once you submit an inspection it cannot be edited, including by us — that immutability is what makes the record trustworthy. Your organisation determines how long its inspection records are retained.
- On-device copies of accepted inspections are held for a limited window after synchronisation to guard against data loss, then removed automatically.
- Request and web server access logs are kept only as long as needed for security monitoring and fault diagnosis.
- Security audit records are append-only and are retained as part of the platform's audit trail. The application has no ability to alter or delete them, so they are not removed on request.
- Deactivated accounts lose access immediately. Account details are retained while they remain necessary to attribute historical inspection records.
You can ask us to delete personal information that is not part of a compliance record. Where we cannot delete information — because a law, or the integrity of an inspection record, requires us to keep it — we will tell you why.
10. Accessing and correcting your information
You may ask us to:
- confirm what personal information we hold about you and give you a copy of it;
- correct information that is inaccurate, out of date or incomplete;
- delete information we are not required to keep; or
- explain how a particular piece of information is used.
Email admin@checkpass.com.au. We will verify your identity, respond within 30 days, and will not charge you to make a request. There is no fee for correcting information. If we refuse a request in whole or in part, we will give you written reasons and explain how to complain.
Because your name, work email address, role and site assignments are maintained by your administrator, the fastest way to correct any of them is to ask your administrator, who can change them directly. You can also contact us and we will arrange it.
Where a submitted inspection contains an error, it cannot be altered after the fact. Your organisation can record a correction alongside the original so the audit trail stays intact.
11. Security
We protect personal information with measures including encryption in transit and at rest, AES-256 encryption of the on-device database, storage of credentials in the platform secure keystore, short-lived access tokens that rotate, account lockout after repeated failed sign-ins, role-based and site-scoped access controls enforced on the server, private network placement of databases, and audit logging of security events.
No system can be guaranteed completely secure. If a data breach occurs that is likely to cause you serious harm, we will notify you and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme.
12. Children
CheckPass Inspector is provided to employees and contractors for workplace use and is not directed at children. We do not knowingly collect personal information from anyone under 16. If you believe a child has used the app, contact us and we will investigate and delete the information.
13. Changes to this policy
We may update this policy as the app changes or as our legal obligations change. The effective date at the top of this page shows when the current version took effect, and the current version is always published at inspector.checkpass.com.au/privacy. Where a change materially affects how we handle your personal information, we will take reasonable steps to notify you or your organisation before it takes effect.
14. Contact us and how to complain
If you are concerned about how we have handled your personal information, contact us first and we will investigate and respond. If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner:
- Website: www.oaic.gov.au
- Phone: 1300 363 992
- Post: GPO Box 5288, Sydney NSW 2001