Privacy Policy

Effective date: 31/08/2026|Provider: QAccess Pty Ltd (“we”, “us”, “our”)

Contact: admin@qaccess.au

QAccess is a door-access control app for organisations. This policy explains what personal information the QAccess mobile app collects, how we use it, who we share it with, and your choices — including how to delete your account. It also covers the personal information collected through this website's contact and demo-booking forms, which is handled separately from your in-app account (see section 1 and section 3 below).

1. Information we collect

Account information (provided by you or your organisation's administrator):

  • Name (first and last)
  • Email address
  • Mobile phone number
  • Organisation membership(s) and your role within them

Authentication data:

  • Password (stored only as a salted one-way hash; we never store it in plain text)
  • Multi-factor authentication (MFA) codes, sent to your email at sign-in
  • Per-device session tokens issued after you sign in

Device and technical data:

  • A device name and platform (e.g. “iPhone”, “Android device”) for the signed-in devices list
  • Firebase Cloud Messaging (FCM) registration token and Firebase Installation ID, used to deliver push notifications
  • IP address and browser/app user-agent, recorded with security events
  • Approximate sign-in metadata (date/time) for your security-activity feed

Access and security activity:

  • Records of doors you open and access grants made to you
  • Sign-in successes/failures, password changes, and device enrolments/revocations (shown to you in “Recent security activity” and retained for audit)

Biometric data:

Face ID / fingerprint / device PIN is used only on your device to unlock the app. Biometric data never leaves your device and is never transmitted to or stored by us — it is handled by your device's operating system.

This website's contact and demo-booking forms (separate from your in-app account):

  • Name, work email, company name, and phone number, if you submit our contact form
  • Name, phone number, your selected appointment time, and any notes you add, if you request a demo booking

We do not collect location data, contacts, photos, your camera, advertising identifiers, or any analytics/behavioural tracking. QAccess contains no advertising and we do not sell your personal information.

2. How we use your information

  • To authenticate you and keep your account secure (sign-in, MFA, session and device management)
  • To provide the core service: granting and exercising door access within your organisation
  • To send you operational push notifications and emails (e.g. door activity, access grants, MFA and password-reset messages)
  • To maintain security and audit logs, detect misuse, and meet our legal and contractual obligations to your organisation
  • To respond to enquiries submitted through this website, and to schedule and manage demo bookings

We rely on your consent and on our legitimate interest in operating a secure access-control service, and on performance of our agreement with your organisation.

3. How your information is shared

We share personal information only as needed to run the service:

Your organisation.

QAccess is provided to you through your organisation. Administrators and facility managers in your organisation can see your account details, roles, and door-access activity relevant to their administration.

Service providers (processors):

  • Google Firebase Cloud Messaging (Google LLC) — delivers push notifications; receives your device push token and message payloads.
  • Email delivery — sends MFA codes and notification emails; receives your email address and message content.
  • Hosting/infrastructure — Google Cloud Platform hosts the QAccess backend and database.
  • Resend (Resend, Inc., based in the United States) — when you submit this website's contact or demo-booking form, Resend delivers the notification email to our team and receives the details you submitted to do so. Because Resend is US-based, this involves a cross-border transfer of your information.
  • Netlify — hosts this website and stores contact and booking form submissions as part of operating it, including the appointment-availability record described in section 4.

Legal.

We may disclose information where required by law or to protect our rights, users, or the public.

We do not sell or rent personal information, and we do not use it for advertising.

4. Data retention

We keep your account information for as long as your account is active. Security and door-access audit records may be retained for a longer period where required for security, compliance, or legitimate business/legal reasons, after which they are deleted or anonymised. When you delete your account (below), your account and personal profile data are removed; audit records that we are required to keep are retained in anonymised form where possible.

For this website's demo-booking form: the appointment-availability record (your name, phone number, selected time, and any notes) is automatically removed once the scheduled appointment date has passed. Contact and booking submissions kept as a record of the enquiry itself are retained as standard business correspondence and can be deleted on request at any time — see Contact us, below.

5. Deleting your account and data

You can permanently delete your QAccess account from within the app: Profile → Delete account. You will be asked to confirm your password. This signs you out of every device, removes your access to all doors, and permanently deletes your account.

You can also request deletion at admin@qaccess.au, or on the web at https://app.qaccess.au/account/delete.

Note: if you are the only administrator of an organisation, the app will ask you to appoint another administrator (or delete the organisation) first, so the organisation is not left without an administrator.

6. Security

We protect your information with encryption in transit (HTTPS/TLS), hashed passwords, multi-factor authentication, per-device tokens that can be revoked, and biometric-gated on-device storage of session credentials. No method of transmission or storage is completely secure, but we work to protect your information and continuously improve our safeguards.

7. Children

QAccess is an enterprise access-control product intended for use by adults in a workplace or managed-tenancy context. It is not directed to children and we do not knowingly collect personal information from children.

8. International users

The service is operated from Australia and your information may be processed in Australia and in the regions where our service providers operate. We handle personal information in accordance with the Australian Privacy Principles under the Privacy Act 1988 (Cth).

9. Your rights

Depending on your location, you may have rights to access, correct, or delete your personal information, or to object to or restrict certain processing. To exercise these rights, contact us at admin@qaccess.au. Because QAccess is provided through your organisation, some requests may be directed to your organisation's administrator.

10. Changes to this policy

We may update this policy from time to time. Material changes will be reflected by updating the effective date above and, where appropriate, notifying you in the app or by email.

11. Contact us

QAccess Pty Ltd

U 1 L 250 Canterbury Rd

Surrey Hills VICTORIA 3127

Email: admin@qaccess.au