Last updated 6 Aug 2026
Hospitality Shield Group Pty Ltd · ABN 70 700 608 386 · Level 28, 140 St Georges Terrace, Perth WA 6000, Australia · Version 1.0
Hospitality Shield is committed to handling personal information responsibly, transparently and securely. This policy explains what information we collect, why we collect it, how we use and disclose it, and the choices and rights available to individuals.
This Privacy Policy describes how Hospitality Shield Group Pty Ltd, trading as Hospitality Shield (Hospitality Shield, we, us or our), manages personal information in connection with our website, software platform, mobile applications, compliance services, client onboarding, customer-support and business operations.
We intend to manage personal information consistently with the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs), the Notifiable Data Breaches scheme where applicable, contractual privacy obligations and other applicable Australian laws. Where the Privacy Act does not legally apply to a particular activity, we will nevertheless seek to follow the privacy practices described in this policy as a matter of good governance, subject to lawful exceptions.
This policy applies to individuals whose information we handle, including venue owners and operators, directors, managers, employees, contractors, Hospitality Compliance Support Officers (HCSOs), compliance officers, auditors, inspectors, training participants, website visitors, prospective customers, suppliers, job applicants and authorised platform users.
Important distinction. This policy explains Hospitality Shield’s own handling of personal information. Where a venue, council, regulator or other client uses our platform and determines why personal information is collected, that organisation may have its own privacy policy and legal responsibilities. Hospitality Shield may act as a service provider processing information on that client’s instructions.
Personal information is information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether the information is true or recorded in a material form. Sensitive information is a more protected category and may include health information, biometric information, racial or ethnic origin, religious beliefs, sexual orientation, political opinions, professional or trade association memberships and criminal records.
Many compliance records concern a venue or business rather than an individual. However, a record may still contain personal information where it identifies a staff member, manager, contractor, complainant, visitor, customer, HCSO, inspector or other person.
Depending on how you interact with Hospitality Shield, we may collect and hold the following categories of information:
We may collect personal information:
We generally collect personal information directly from the individual where reasonable and practicable. Where information is collected from another person or organisation, we may rely on that party to have authority to provide it and to give any necessary privacy notices.
We may handle personal information for purposes including:
The platform may allow authorised users to upload photographs, videos, documents and notes as evidence of venue conditions, corrective actions, incidents, food-safety practices or audit findings. Users should avoid capturing unnecessary personal information and should not upload images of individuals unless relevant, proportionate, authorised and lawful.
Photographs can carry more than the picture.A photo taken on a phone may contain the location where it was taken and details of the device, recorded inside the image file. We remove that data from every photo we store. Where we cannot remove it we do not store the photo: HEIC and AVIF files, which are the default camera format on many current phones, keep that data in a part of the file we are not able to edit without risking the picture itself, so we refuse them and ask you to upload the photo in another format. On an iPhone, Settings › Camera › Formats › Most Compatible makes the camera save photos as JPEG. Switching your camera’s location tagging off is worth doing regardless.
Clients are responsible for configuring access permissions, informing their personnel about workplace record-keeping, and ensuring that records entered into Hospitality Shield are accurate, relevant and lawfully collected. Hospitality Shield may remove, restrict or quarantine content that appears unlawful, unsafe, malicious or outside the agreed service scope.
Hospitality Shield may use artificial intelligence, machine learning, rules-based automation or analytical tools to assist with functions such as document classification, risk identification, anomaly detection, summaries, reminders, recommendations, compliance workflow support and customer service.
Where these features process personal information, we seek to apply appropriate access controls, data minimisation, testing and human oversight. Automated outputs may be incomplete or incorrect and should not replace professional judgment, legal obligations, regulatory decisions or a venue’s responsibility for food-safety and compliance.
We will not knowingly use customer confidential information to train a publicly available general-purpose AI model unless authorised by the customer and permitted by applicable law and contract. Third-party AI providers may process information where necessary to provide an authorised feature and subject to appropriate contractual and security controls.
Who receives it, and where. When the in-app assistant is switched on for your account, the questions you type and the records the assistant reads to answer them are sent to Anthropic, PBC in the United States, which operates the language model. Those records can include the free text your team has written into incident reports, corrective actions and record notes, and the names of the people who wrote them. If a question needs current information from the web, the model’s provider may also run a search on our behalf. Nothing is sent to it unless the assistant is switched on for your venue. Other parts of the platform do send some information overseas for their own purposes: our email provider receives the full text of every message we send you, and our payment provider receives billing details. Section 10 lists each one and what it receives.
Some of it happens without anyone asking.While the assistant is switched on, the platform also writes the short summaries shown at the top of your pages: overnight for every venue, and again during the day when records change. Nobody presses anything for that to happen, and building each one sends information from the venue’s records to Anthropic in the same way: how many records are due, missed or waiting to be signed off, the titles of open incidents and outstanding corrective actions, the KIND of any document that has expired or is expiring soon (a registration, a certificate, an insurance policy), the kind of any fridge or freezer currently reading out of range, and the name and telephone number of the HCSO assigned to the venue.
What the summaries do not send is the wording you typed: not the name you gave a document, and not the name you gave a fridge. Only the kind of thing it is, and the date.
If you would rather your venue’s records were not processed this way, tell us and we will turn the assistant off for your account. Do not type information about a named person’s health into the assistant. Describe the situation without identifying them.
Assistant conversations are saved. Both sides of every conversation are kept against the account that had it, and Hospitality Shield staff can read them: we use them to see what the assistant was asked, whether it answered correctly, and to look into an answer somebody has reported. Treat it as a work tool rather than a private one. Section 13 covers how long they are kept.
Decisions the platform makes automatically. Three things are worked out by the software rather than by a person:
None of the three is a decision about a person’s legal rights, and none of them results in a penalty from us. If you think one of them is wrong, write to the Privacy Officer or your account administrator and a person will look at it: statuses and scores are recalculated from the underlying records, and an administrator can unlock an account immediately.
We may disclose personal information to:
We do not sell personal information as a standalone commercial product. We do not disclose customer records for unrelated advertising without appropriate authority.
Hospitality Shield may use cloud infrastructure and service providers that store, support or process information outside Australia. Countries may vary depending on the providers selected, their backup arrangements and the location of authorised support personnel. Possible locations may include Australia, the United States, European Union member states, the United Kingdom, Singapore and other jurisdictions disclosed by relevant service providers.
Who they actually are. The providers we use today, and what each one receives:
If we add or change a provider that receives personal information, we will update this list. Before using a material overseas provider, we seek to consider the nature of the information, contractual protections, security practices, access controls and applicable legal requirements. Overseas recipients may be subject to laws that differ from Australian privacy law.
Client configuration. Enterprise and government customers may request agreed data-location, access, retention or subcontractor arrangements. Any specific commitment must be recorded in the applicable customer agreement or data-processing schedule.
We take reasonable steps appropriate to our size, systems and risk profile to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure. Measures may include:
No internet-based service can guarantee absolute security. Users must protect their login credentials, use appropriate access permissions, keep devices secure and promptly report suspected compromise.
We maintain processes for identifying, containing, assessing and responding to suspected data breaches. Where the Notifiable Data Breaches scheme applies and an eligible data breach is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner as required by law.
Customers and users should immediately report suspected unauthorised access, lost devices, exposed credentials, unintended disclosures or other security incidents to compliance@hospitalityshield.com.au.
We retain personal information only for as long as reasonably required for the purposes for which it was collected, our contractual obligations, legal and regulatory requirements, dispute management, security, backup cycles and legitimate business needs.
Retention periods vary according to the record type. Compliance and audit records may need to be retained for periods determined by the customer, applicable food-safety laws, council requirements, contractual obligations or limitation periods. Account, billing and corporate records may be retained for taxation and legal record-keeping periods.
Some information is destroyed on a schedule. Revoked sessions, spent two-factor confirmations and expired trusted devices are removed automatically each night, once they can no longer be used. Used or lapsed invitation, password-reset and email-change links are removed thirty days afterwards, long enough that a question about how an account was set up can still be answered, and no longer.
The text of an email we sent you is removed after ninety days. We keep the record that it was sent, and to which address, because that is how we can tell whether something we owed you actually reached you.
Food-safety records are the exception, and deliberately so. Temperature readings, checklists, inspection results, corrective actions, incident reports, training records and the documents and photographs attached to them are the evidence a council environmental health officer may ask a venue to produce, so we keep them for as long as the account exists and do not delete them on request. A record that is withdrawn or corrected is marked as such and kept, rather than removed, that is what makes the rest of the record trustworthy. If you close your account, tell us what you need done with them.
For anything else, account details, billing records, our log of emails sent to you, assistant conversations and the audit trail, we keep it while it is needed for the purposes above and destroy or de-identify it when it is not. If you want to know what is held about you, the Data & privacy page in your account will produce a copy, and you can ask us to correct or remove anything that is not part of the food-safety record. Residual copies may remain in secure backups until they are overwritten through normal backup cycles.
You may request access to personal information we hold about you and ask us to correct information that is inaccurate, out of date, incomplete, irrelevant or misleading. To make a request, contact the Privacy Officer using the details in section 22.
We may need to verify your identity and authority before responding. Where information is controlled by a venue, employer, council or other client, we may refer the request to that organisation or respond in consultation with it. Access may be refused or limited where permitted by law, including where disclosure would unreasonably affect another person’s privacy, reveal commercially sensitive information, prejudice an investigation or be unlawful.
We will respond within a reasonable period, and aim to do so within 30 days of receiving your request and verifying your identity, explaining any lawful refusal. We generally do not charge for making a request, but may charge reasonable costs where permitted and notified in advance.
Asking us to delete something. Our collection notices say you may ask us to delete information, so here is what that means in practice. Australian privacy law gives no general right to erasure, and food-safety records are the part we will not delete: temperature readings, checklists, inspection results, corrective actions, incident reports, training records and their attachments are the evidence a venue may have to produce to a council, and section 13 explains why they are kept and marked rather than removed. Anything outside that record, your contact details, an enquiry you sent us, an account we no longer need, assistant conversations, we will delete or de-identify on request unless we are required to keep it. Write to the Privacy Officer and we will tell you which category each item falls into and what we have done.
Where practicable, you may interact with us anonymously or using a pseudonym, such as when making a general enquiry. Identification will usually be required where necessary to provide an account, verify authority, maintain compliance records, provide contracted services, process payments, address security or meet legal obligations.
We may use contact details to communicate about Hospitality Shield products, services, events and updates where permitted by law. We send promotional email only where you have asked for it, for example by taking our 60 second compliance visibility check and agreeing to receive your result. Every such message carries an unsubscribe link at its foot, which opens a page where one press stops them; you can also ask us and we will stop. Messages about an account you hold, such as an invitation, a password reset, a sign-in confirmation, an invoice, a notice that your price is changing, or a reply to something you sent us, are service messages rather than marketing and continue for as long as you have the account.
We do not use sensitive information for direct marketing without consent or another lawful basis.
Our website and platform may use cookies, local storage, pixels, software development kits and analytics tools to:
You can control some cookies through browser or device settings. Blocking essential cookies may prevent parts of the website or platform from functioning. Where required, we will provide additional cookie choices or notices.
Hospitality Shield is designed primarily for businesses, authorised workplace users and professionals. It is not directed to children. We do not knowingly create platform accounts for children without appropriate authority. If information about a child is entered into an incident or compliance record, the client and authorised user must ensure the collection is necessary, proportionate and lawful. Contact us if you believe a child’s information has been provided improperly.
The platform may contain links to third-party websites or integrate with external services. Those services operate under their own privacy policies and security practices. Hospitality Shield is not responsible for a third-party’s independent handling of personal information, except to the extent required by law or contract.
You may make a privacy complaint by contacting our Privacy Officer. Please provide enough detail for us to understand the issue, including relevant dates, account or venue details and the outcome you seek.
We will acknowledge the complaint within a reasonable period, investigate it fairly and aim to provide a response within 30 days. Complex matters may require more time, in which case we will provide an update where practicable.
If you are not satisfied and the Privacy Act applies, you may be able to complain to the Office of the Australian Information Commissioner. Information about privacy complaints is available through the OAIC website.
We may update this Privacy Policy to reflect changes to law, technology, our products, service providers or business practices. The current version will be published on our website with the effective date. Where a change materially affects how existing customer information is handled, we may provide additional notice through the platform, email or contractual channels.
Privacy Officer, Hospitality Shield
Hospitality Shield Group Pty Ltd
Level 28, 140 St Georges Terrace, Perth WA 6000, Australia
Email: compliance@hospitalityshield.com.au
Telephone: +61 8 6189 4947
Website: www.hospitalityshield.com.au
A client organisation using Hospitality Shield should:
This policy is intended to be read consistently with applicable law and the relevant customer agreement. It does not create rights or obligations beyond those imposed by law or expressly accepted in contract. If a customer agreement contains stronger privacy or data-protection commitments, those commitments apply to that customer to the extent of any inconsistency.
The Privacy Act generally covers organisations with annual turnover above the statutory threshold and certain other organisations and activities. Hospitality Shield’s legal coverage may evolve as the business grows, enters contracts or undertakes regulated activities. This policy reflects our intended privacy standard and should be reviewed when the platform, business model, providers or applicable laws materially change.
This policy was prepared with reference to the following official Australian privacy materials current as at the effective date:
Document control: Hospitality Shield Privacy Policy · Version 1.0 · Effective 6 Aug 2026 · Owner: Privacy Officer · Approved by: Founder & Director