· Privacy
Privacy Policy.
aedile exists to hold and organise fire safety records. Those records can contain information about building owners, occupiers, contractors, technicians and other people, so how that information is handled matters. This policy explains, in plain English, what aedile collects, why, how it is used, where it is stored, who it may be shared with, and the choices available to you. It applies to this website (aedile.com.au) and the aedile application.
Last Updated 13 September 2026
The Short Version
- The core aedile platform is hosted on Amazon Web Services in the Sydney, Australia region.
- aedile uses the information you provide to operate the service, organise your records, process uploaded documents and support your account.
- Uploaded documents may be read by an AI service to extract information. Under the commercial terms aedile operates on, uploaded content is not used to train AI models.
- aedile does not sell personal information, build advertising profiles from it, or send marketing email to purchased lists.
- Card details are handled by Stripe and are not stored on aedile's systems.
- No online service can promise perfect security, but aedile uses technical and organisational controls designed to protect the information it holds.
Who We Are
aedile is a fire safety record-keeping platform for building owners and occupiers, built and operated in Queensland, Australia. The platform is operated by Aedile FC Pty Ltd (ACN 698 740 206). In this policy, "aedile", "we" and "us" refer to Aedile FC Pty Ltd.
Questions, privacy requests and complaints can be sent to support@aedile.com.au.
This policy has been designed around the privacy standards set by the Australian Privacy Principles in the Privacy Act 1988 (Cth). Where the Privacy Act applies to aedile or to particular information we handle, we comply with the obligations that apply. Where it does not apply, this policy describes the practices we follow.
What We Collect
The information aedile holds depends on how you use the service.
Account Information
When an account is created or a person is invited to an organisation, aedile may collect:
- name;
- email address;
- organisation name;
- account and role information; and
- information associated with invitations to other users.
Passwords are not stored in plain text. They are stored only in hashed form.
Building and Fire Safety Records
When you use aedile, you may provide:
- building names and street addresses;
- maintenance records;
- inspection and service documents;
- certificates;
- occupier statements;
- evacuation and training records;
- other fire safety documentation; and
- information entered directly into the platform.
aedile also holds information extracted from uploaded documents so that it can organise and present the records contained in your account.
Information About Other People
Fire safety records often contain personal information about people who are not aedile users. For example, an uploaded service record may contain a technician's name, licence number, QBCC details, employer, signature or other identifying information.
aedile receives this information because a customer has included the document in its building record. That information is held as part of that customer's record and is used for the purposes of storing, reading, organising and presenting that record. Customers are responsible for ensuring that they are entitled to provide documents and personal information to aedile.
aedile does not use personal information contained in one customer's records to create profiles about people for another customer.
Payment Information
Payments are processed by Stripe. Card details are entered directly into Stripe's payment systems and are not stored on aedile's systems. aedile retains information required to administer subscriptions and payments, such as subscription status, invoices and transaction records.
Technical and Security Information
When you use aedile, systems may automatically create technical records such as:
- sign-in events;
- audit records;
- security events;
- error and diagnostic logs; and
- information needed to maintain a user session.
This information is used to operate, secure, troubleshoot and support the platform.
How We Collect Information
Most information is provided directly by aedile customers and users when they create an account, register a building, invite a team member, enter information or upload documents.
Some personal information is collected indirectly because it appears in documents uploaded by a customer. This can include information about contractors, technicians and other third parties. Technical information is created automatically when the service is used. Payment-related information is received from Stripe to the extent needed to administer the customer's subscription.
If you contact aedile - by email or the contact form on this website - we receive the information you include in your message. A form submission is delivered to us as an email; the website itself does not store it.
How We Use Information
aedile uses information to:
- create and administer accounts;
- store and organise building records;
- read uploaded documents and extract information from them;
- present extracted information for customer review;
- track dates and obligations described in the records held;
- generate reports and summaries from information supplied to aedile;
- manage user roles and invitations;
- administer subscriptions and payments;
- send transactional emails;
- operate, maintain, troubleshoot and secure the service;
- respond to support and privacy requests;
- maintain audit and security records; and
- comply with legal obligations.
Transactional emails can include account and sign-in messages, notifications relating to dates or records configured in the platform, and delivery of reports generated by a customer.
aedile does not:
- sell personal information;
- sell customer records;
- use customer information to build advertising profiles;
- send marketing email to purchased lists; or
- combine different customers' fire safety records into a shared customer record.
AI Processing of Documents
aedile uses a commercial AI service to read uploaded documents and extract information from them. Content required for document processing is provided to the AI service for that purpose. Under the commercial terms on which aedile uses the service, uploaded content is not used to train AI models.
Automated document reading can make mistakes. Handwriting, poor scans, unusual document formats and unclear source material can increase that risk. For that reason, extracted information is presented for customer review and aedile may identify information it has read with low confidence. Customers are responsible for reviewing extracted information before relying on it.
AI processing does not determine whether a building is compliant, safe or properly maintained. It reads and organises information contained in the records supplied to aedile. The original uploaded document is retained as part of the customer's account while that record is held, so the source document remains available alongside the information extracted from it.
Where Your Information Is Stored
The core aedile platform is hosted on Amazon Web Services in the Sydney region, Australia. Uploaded documents are stored in Amazon S3 and structured platform data is held in a managed PostgreSQL database hosted on AWS.
Some providers used to operate the service process information outside Australia. Stripe, which processes payments, and the AI service used for document reading currently process information in the United States.
aedile does not represent that every piece of information associated with the service will remain in Australia in every circumstance.
Who We Share Information With
aedile does not sell personal information. Information may be made available to the following categories of recipients where necessary to operate the service.
People in Your Organisation
Users invited into an organisation can access information according to the roles and permissions assigned within that organisation. The organisation controls who it invites and what roles those users are given.
Amazon Web Services
AWS provides infrastructure used to host the platform and store customer information.
Stripe
Stripe processes subscription payments. Payment information is provided to Stripe in connection with that service.
AI Document Processing
Uploaded document content may be provided to the AI service used by aedile to extract information from those documents.
Email Delivery
Information such as an email address and the content required for a transactional message may be provided to an email delivery service so that aedile can send account messages, configured notifications and generated reports.
Legal and Security Requirements
Information may also be disclosed where required or authorised by law, or where reasonably necessary to protect the security, integrity or lawful operation of the service.
Each service provider receives information only to the extent reasonably required for the function it performs for aedile.
Security
aedile uses technical and organisational measures designed to protect the information it holds. These include:
- encryption in transit using TLS;
- encryption of stored data;
- hashed password storage;
- role-based access within customer organisations;
- platform-level isolation between customer organisations;
- audit and security logging; and
- routine backups.
Each customer organisation's records are isolated from the records of other customer organisations at the platform level.
No internet-connected service can promise absolute security. Security risks change over time, and aedile may update its controls as the platform, technology and threat environment change. If you believe an aedile account or information held in aedile has been accessed without authorisation, contact support@aedile.com.au promptly.
Data Breaches
aedile investigates suspected security incidents involving information held by the service and takes reasonable steps to contain and respond to confirmed incidents. Where the Privacy Act 1988 (Cth) and the Notifiable Data Breaches scheme apply, aedile will assess suspected eligible data breaches and notify affected individuals and the Office of the Australian Information Commissioner where required by law.
Retention
Fire safety records can remain relevant for long periods. Maintaining a durable record is a core purpose of aedile. Information associated with an active account is therefore generally retained while the account remains active and while it is required to provide the service.
Customers can use available export functions to obtain records from their account, including audit information where supported by the platform. If an account is closed, customers should export information they wish to retain before closure.
Following closure, aedile will delete or de-identify account information within a reasonable period where it is no longer required, subject to:
- ordinary backup and deletion cycles;
- information reasonably required to resolve disputes or security matters; and
- records that must be retained for legal, accounting, taxation or other legitimate requirements.
Deletion from active systems may therefore occur before information disappears from every routine backup copy.
Cookies
The aedile marketing website does not use advertising cookies or third-party analytics cookies. The aedile application uses cookies and similar session technologies required for functions such as sign-in and session security. aedile does not use those technologies to create advertising profiles of application users.
Access, Correction and Privacy Requests
You can access and correct much of the information associated with your account directly through the aedile application. For other requests relating to your personal information, including access, correction or deletion requests, email support@aedile.com.au.
Please provide enough information for us to understand your request. We may need to confirm your identity before giving access to personal information or making certain changes.
There may be circumstances where information cannot be deleted or access cannot be provided, including where retention is required by law, the information relates to another person, or another lawful exception applies. Where appropriate, we will explain the reason. We will deal with privacy requests within a reasonable period.
Privacy Complaints
If you believe aedile has not handled personal information appropriately, email support@aedile.com.au with enough information for us to understand and investigate the issue. We will review the complaint and respond within a reasonable period.
If the Privacy Act applies to the matter and you are not satisfied with the response, you may be entitled to make a complaint to the Office of the Australian Information Commissioner at oaic.gov.au.
Changes to This Policy
Privacy practices may change as aedile develops or as legal and operational requirements change. When this policy changes, the updated version will be published on this page and the "Last Updated" date will be changed. If a change materially affects how existing account holders' personal information is handled, aedile will take reasonable steps to notify affected account holders, including by email where appropriate.
Contact
Questions about this Privacy Policy, the information aedile holds, or a privacy request can be sent to support@aedile.com.au.