Privacy Policy
Last updated 3 October 2026
1. Who we are
Annan CMMS (annancmms.com) is operated by Northpoint Integrity Services. It is a maintenance management service for organisations. This policy explains how we handle personal information in line with the Privacy Act 1988 (Cth) and the Australian Privacy Principles.
2. Information we collect
- Account details: name, email address, role and organisation membership.
- Records your organisation enters: sites, assets, work orders, schedules, audits and notes.
- Contractor and site-access records: orientation and SWMS signatures, permits, sign-in and sign-out times, and device location at the moment of sign-in or signing.
- Passkey public keys (we never receive your device passcode or biometrics).
- Technical data needed to run the service, such as security and error logs.
3. How we use it
To provide the service to your organisation, verify identity, keep safety and compliance records, send notifications your organisation requests, and keep the service secure. We do not sell personal information and we do not use it for advertising.
4. Your files stay in your own storage
Photos, documents, approved safety records and exports are saved in your organisation's own Google Drive, OneDrive or SharePoint. We store only references to those files, not the files themselves.
5. Google user data
- Google sign-in (openid, email, profile): used only to confirm your identity and match you to your organisation account.
- Google Drive (drive.file): used only to create and manage the files Annan CMMS saves in an "Annan CMMS" folder in your organisation's Drive. We cannot see other files.
- Gmail (gmail.send): used only to send messages your organisation triggers, such as work requests, invitations and approved safety documents. We do not read your inbox.
Annan CMMS's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is not used to train AI or machine learning models, is not sold, and is not used for advertising.
6. Microsoft user data
Microsoft 365 sign-in, mail sending and OneDrive/SharePoint storage are used on the same limited basis as Google: identity confirmation, sending messages your organisation triggers, and managing files Annan CMMS creates.
7. AI features
Optional AI assistance uses Anthropic's Claude models through Amazon Bedrock, processed in Australia (Sydney and Melbourne) only. Looking up a manufacturer's details sends only the make and model to Perplexity, which may be processed outside Australia. Providers do not train on your data. Data from Google or Microsoft accounts is never sent to AI models.
8. Service providers and overseas disclosure
We use hosting, database and email infrastructure providers to run the service. Some, including AI providers, may process data outside Australia (for example the United States). We take reasonable steps to ensure they protect it consistently with the Australian Privacy Principles.
9. Security and retention
Each organisation's data is isolated in the database. Connection tokens are encrypted. Deleted records are kept for 30 days for recovery and then removed. Safety and induction records are kept for as long as your organisation needs them for compliance.
10. Access, correction and deletion
You can ask to access or correct your information, or close your account, through your organisation administrator or by emailing us. You can revoke Google access at any time at myaccount.google.com/permissions.
11. Contact and complaints
Email mark@annan.dev. If you are not satisfied with our response, you can contact the Office of the Australian Information Commissioner (oaic.gov.au).
