Privacy Policy
How Lede collects, uses, and protects personal information.
Lede Technologies Pty Ltd (ACN 698 337 718)
Last updated: 30 August 2026
Who we are
Lede Technologies Pty Ltd (ACN 698 337 718) (Lede, we, us) is an Australian registered company. We build operational intelligence tools for workforce-facing industries, beginning with Handover — a shift handover platform for teams in aged care, healthcare, cleaning, security, facilities, hospitality, manufacturing, logistics and warehousing, retail, and field services.
We are committed to handling personal information responsibly, transparently, and in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
Contact us at: privacy@workwithlede.com
Who this policy covers
This policy covers three types of people who interact with Lede:
Operators — businesses and organisations that create a Lede account and deploy Handover for their workforce. Operators are our direct customers and agree to our Terms of Service on sign-up.
Workers — the employees and contractors who use the Handover app to record shift notes and receive briefings. Workers use Handover because their employer has deployed it. Workers do not need a direct account with Lede.
Website enquirers — people who submit an enquiry through a form on our marketing website. Enquirers are not Lede account holders and do not need to be; we hold their details only to respond to the enquiry and to follow up about Lede.
Managers and site owners are Workers with elevated access permissions within the Lede platform. This policy applies to them in their capacity as Workers, unless otherwise specified.
What we collect
From operators
- Business name, ABN, and contact details of the account holder
- Name and email address of the account administrator
- Site names and configuration details provided to set up Handover
- Billing information (processed securely by Stripe — we do not store card details)
- Usage data including login activity, feature use, and account settings
- Your role, industry, and interests — the job role, industry, and operational topics you share during Intelligence onboarding, used to tailor the insights and Cover Stories you see
- Technical request data, including IP address — used only for security and abuse prevention (for example, rate-limiting sign-in attempts). This is retained only briefly and is not used to profile you.
- Questions you ask the Intelligence "Ask" assistant, and the resulting conversation history — stored against your account and processed by AI to generate answers
- Push notification subscription details — if you enable push notifications, the device or browser push subscription (endpoint and associated keys) needed to deliver them
- Profile photo (optional) — if the account administrator chooses to upload one
- Imported handover history — where you import your organisation's historical handover records from a previous system, we collect the records you upload: for each entry, the date, site, shift type, the author's name or email address as written in your source file, and the handover text itself.
From workers
- Shift notes — text and voice-transcribed content entered during a shift
- Clock-in and clock-out times
- Clock-in location check — where your operator has enabled geofencing, whether your device was inside the site boundary at clock-in, and the accuracy of that reading. We do not store your coordinates. Where your operator enforces the boundary and you choose to clock in anyway, we also record the reason you give and the time you did so, which is visible to your managers.
- AI-generated end-of-shift summaries and briefing content derived from shift notes
- The site and shift type the note relates to
- General usage data including session timestamps and device type
- Technical request data, including IP address — used only for security and abuse prevention (for example, rate-limiting sign-in attempts). This is retained only briefly and is not used to profile you.
- Push notification subscription details — if you enable push notifications, the device or browser push subscription (endpoint and associated keys) needed to deliver them
- Name and role, as configured by the operator
- Profile photo (optional) — if the worker chooses to upload one
- Historical handover records attributed to you — where your operator imports handover history from a previous system, entries attributed to you (matched by the name or email in that source file) are stored alongside the notes you enter directly.
Workers may, in the course of writing shift notes, include personal information about themselves, colleagues, or clients that was not specifically requested by Lede. We have designed the platform to minimise the collection of sensitive information, but we cannot prevent it from entering freeform note fields. This policy addresses how we handle such information.
We do not collect sensitive information as defined under the Privacy Act (including health information, racial or ethnic origin, or biometric data) intentionally. Where sensitive information is incidentally disclosed in shift notes, it is handled under APP 11 security obligations and is not used for any purpose beyond operational delivery.
From website enquirers
If you submit an enquiry through a form on our marketing website, we collect:
- Your name and email address (both required)
- Your company, role, and industry, if you choose to provide them
- Any message you write in the enquiry
- Which form you used, so we know what you were asking about
We use this only to respond to you and to follow up about Lede. We do not use it for any other purpose. We disclose it to Salesforce, our customer relationship management provider, which stores it in Australia. Our marketing forms (including the waitlist) are also protected by Google reCAPTCHA, which receives some technical information about your device to tell genuine visitors from bots — see the provider list below. We keep enquiry records until you ask us to delete them — email privacy@workwithlede.com at any time and we will remove your details.
From website chat visitors
If you use the "Ask Lede" chat on our marketing website, we collect the questions you ask and the resulting conversation, together with any name, email address, or company you choose to share (for example, if you ask us to follow you up). We use this to answer you and to follow up about Lede. This is a different assistant from the in-product "Ask" assistant — the website chat is public and governed by this Privacy Policy.
Your messages are answered by an AI assistant, and its replies are AI-generated and may be imperfect. When you send a message, the text you type is transmitted to and processed by Amazon Bedrock (AWS), our AI provider, to generate a reply; Bedrock inference for the website chat normally runs in Australia (AWS ap-southeast-2), subject to the global inference routing option described below. By continuing to chat, you agree to this processing as described in this Privacy Policy, and your conversation may be recorded. For every message we log technical request data — including your IP address and basic message metadata such as message length — for security, abuse prevention, and rate-limiting; we do not record the content of your messages in those operational logs. If you share your email address so the team can follow you up, your message and the conversation are also sent to us by email and retained as an enquiry, which we keep until you ask us to delete it — email privacy@workwithlede.com at any time and we will remove your details. The technical request data is retained only briefly and is not used to profile you.
How we classify worker data
Lede applies a three-tier data classification to information in the Lede platform:
| Tier | Description | Examples |
|---|---|---|
| Tier 1 — Operational | Standard operational information about tasks, equipment, and shift status. | Cleaning completed in room 12. Faulty lock on door 3 reported. |
| Tier 2 — Behavioural | Information that, individually or in aggregate, describes patterns of worker behaviour or performance. | Shift note frequency, urgency flag patterns, recurring topics raised. |
| Tier 3 — Sensitive | Health information, personal circumstances, or observations about third-party vulnerability incidentally disclosed in freeform notes. | Worker health disclosures, resident condition observations, personal distress noted during a shift. |
Tier 3 information is handled with the highest level of care. It is secured under APP 11, is not used for AI training or product improvement, is not surfaced in management dashboards at an individual level, and access is restricted to authorised personnel only.
How we use your data
To provide the Lede platform
We use operator and worker data to operate the Lede platform — processing shift notes, generating AI summaries and briefings, enabling manager dashboards, and delivering operational insights. This is the primary purpose for which data is collected.
To deliver AI features
The AI features of Handover — including shift summaries, incoming briefings, pattern detection, and the Manager Dashboard — are powered by large language model processing of shift note content. This processing occurs on a per-session basis and is used to generate outputs for workers and managers.
Lede also provides an interactive "Ask" assistant (part of Intelligence) that lets authorised users type free-text questions about their organisation's data. The questions you ask and the resulting conversation history are stored against your account and processed by our AI provider (Anthropic) to generate answers.
Where AI pattern analysis is available (Free, Starter, Growth and Enterprise tiers), the AI identifies patterns across multiple shifts. This analysis is designed to surface operational signals at a site or team level. AI outputs are framed as patterns for human review — not findings or conclusions. Lede prohibits the use of AI outputs as the sole basis for any employment decision.
To support privacy, fairness, and responsible use of AI, individual worker attribution in AI-generated outputs is restricted. Outputs that identify or name individual workers are subject to human review and appropriate approval controls.
To improve Lede for everyone
AI-generated outputs, system performance metrics, and aggregated usage patterns may be analysed to monitor service quality, evaluate system performance, and improve product functionality. This analysis is conducted at an aggregated level and is not used to identify individual workers or operators, nor is it linked back to specific accounts. Tier 3 (Sensitive) data is excluded from this process.
To communicate with operators
We send product updates, onboarding information, and service notifications to operators via email. Where you have enabled them, we also send operational notifications to operators and workers via push notifications — these are opt-in, and you can turn them off at any time in the app or through your device's notification settings. Operators can opt out of marketing communications at any time by emailing privacy@workwithlede.com.
We do not sell personal data to third parties — ever.
Worker consent and awareness
Workers use Handover because their employer has deployed it as an operational platform. Operators are responsible for ensuring their workers are informed that:
- their shift notes and clock-in data are recorded and stored in the Lede platform;
- managers and site owners can access shift note history for the sites they manage;
- AI features process shift note content to generate summaries, briefings, and operational insights; and
- where paid-tier (Starter, Growth, or Enterprise) AI pattern features are active, note content may be analysed across multiple shifts.
Lede provides suggested worker disclosure language on request. Operators are contractually required to provide this disclosure before workers first use the platform.
Where AI features are upgraded or extended — for example, when an operator moves from Free to a paid tier (Starter, Growth, or Enterprise) — operators must ensure workers receive updated disclosure before those AI features are activated on their account.
Who has access to your data
Your data is accessible to the Lede team. We use the following third-party services to operate the platform, each governed by their own privacy policies:
| Provider | Purpose |
|---|---|
| AWS (Amazon Web Services) | Infrastructure, data storage, and AI processing services. All Lede operational data is hosted in Australian AWS regions (ap-southeast-2) to comply with APP 8. AWS also provides Amazon Transcribe, which converts workers' spoken shift notes into text, and Amazon Bedrock, which may be used to run the AI models that process shift-note Content and imported handover records and the questions asked through the 'Ask Lede' chat on our marketing website. Bedrock inference normally runs in Australia (ap-southeast-2); a global inference routing option, where enabled by Lede, may process that Content outside Australia — a cross-border disclosure under APP 8 (see below). |
| WorkOS | Authentication and identity management — user sign-in, SSO, and multi-factor authentication. |
| Anthropic | AI processing of shift note content to generate summaries, briefings, and pattern insights. |
| Stripe | Payment processing. Stripe stores billing details on our behalf. We do not hold card data. |
| Atlassian (Jira Cloud) | Issue and feedback tracking. Receives in-app feedback and support requests, including the feedback text, the submitter's name and email address, their organisation's name, the page they were on when they submitted it, and their browser and device information. Where the request concerns billing or account access, it also includes the account's current billing status. Hosted outside Australia; this is a cross-border disclosure under APP 8. |
| Salesforce | Customer relationship management — receives waitlist and contact-form submissions from our marketing website, including your name, email address, and any company, role, industry or message you provide. Hosted in Australia; this is not a cross-border disclosure. |
| Google reCAPTCHA | Bot and abuse protection on our marketing forms (including the waitlist). When a form page loads, reCAPTCHA receives your IP address, browser and device characteristics, and interaction signals to tell genuine visitors from bots. Provided by Google, hosted outside Australia; this is a cross-border disclosure under APP 8. |
| PostHog | Website and product analytics — captures page views and feature interactions, on both our website and our apps, to understand how people find and use Lede and to monitor and improve the platform. Runs only where you have accepted analytics. Hosted in the European Union; this is a cross-border disclosure under APP 8. |
| Meta (Facebook) | Website advertising. Our Meta pixel records page views on our marketing website, and a conversion event when you join our waitlist, so we can measure and target our advertising. Runs only where you have accepted cookies. Provided by Meta Platforms, hosted in the United States, outside Australia; this is a cross-border disclosure under APP 8. |
| Sentry | Error and performance monitoring for the Lede apps — captures error events, stack traces, and diagnostic breadcrumbs (which can include account and site identifiers and the page URL) together with the reporting device's IP address, so we can detect and fix faults. Runs only in our apps, not the marketing site. Hosted in the European Union; this is a cross-border disclosure under APP 8. |
| SMTP2GO | Transactional email delivery — sends account, verification, and service-notification emails, which include the recipient's name and email address, and delivers 'Ask Lede' website-chat enquiries (including any name, email, and conversation you share) to our team. Hosted in Australia. |
| Google Workspace | Email hosting for our own team's mailboxes — where email addressed to us is received and stored. This includes the 'Ask Lede' website-chat enquiries SMTP2GO delivers to our team, and any access, correction, deletion, opt-out or complaint request you email us, together with your name, email address and the content of your message. Provided by Google, hosted outside Australia; this is a cross-border disclosure under APP 8. |
| Slack (Salesforce) | Internal operational and billing alerting — our own team's alerts about platform and payment issues. Receives your organisation's name, account identifiers and billing status. Hosted outside Australia. |
| Browser push services (Google, Apple, Mozilla) | Delivery of push notifications you have opted into. Notifications are routed through your browser vendor's own push infrastructure, hosted outside Australia; this is a cross-border disclosure under APP 8. Notification content is encrypted in transit and cannot be read by the vendor. |
We take reasonable steps to ensure these providers handle personal data securely and in accordance with applicable law. All providers are engaged under data processing terms consistent with APP 8 cross-border disclosure obligations.
Data storage location
All Lede operational data — including shift notes, worker records, and account information — is stored on infrastructure located in Australia (AWS ap-southeast-2, Sydney region). To deliver our AI features, shift-note Content is disclosed to our AI provider, Anthropic, for processing. This processing may occur outside Australia. This is a cross-border disclosure for the purposes of APP 8, and we take reasonable steps to ensure it is handled in accordance with the Australian Privacy Principles. In addition, our AI processing on Amazon Bedrock normally occurs in Australia (AWS ap-southeast-2); however, Lede operates a global inference routing option which, when enabled, processes shift-note Content and imported handover records and questions asked through our marketing-site 'Ask Lede' chat outside Australia. Where that option is in use, this is a further cross-border disclosure for the purposes of APP 8, and we take reasonable steps to ensure it is handled in accordance with the Australian Privacy Principles. We also use PostHog (hosted in the European Union) for website and product analytics, which receives page-view and feature-interaction data from our website and our apps where you have accepted analytics; this is a further cross-border disclosure for the purposes of APP 8. We also use Meta's advertising pixel (Meta Platforms, hosted in the United States) on our marketing website, which receives page-view and waitlist-conversion data where you have accepted cookies; this is a further cross-border disclosure for the purposes of APP 8. We also use Sentry (hosted in the European Union) for error and performance monitoring of our apps, which receives error events, stack traces and diagnostic breadcrumbs — which can include account and site identifiers and the page URL — together with the reporting device's IP address; this is a further cross-border disclosure for the purposes of APP 8. In-app feedback and support requests (including the submitter's name and email address, their organisation's name, the page URL, browser information, and where relevant the account's billing status) are disclosed to Atlassian (Jira Cloud) for issue tracking; Atlassian hosts this data outside Australia, a further cross-border disclosure for the purposes of APP 8. We also use WorkOS (hosted in the United States) for authentication and identity management, including sign-in, single sign-on, and multi-factor authentication; this is a further cross-border disclosure for the purposes of APP 8. Where you opt into push notifications, delivery is routed through your browser vendor's push service (Google, Apple, or Mozilla), hosted outside Australia; this is a further cross-border disclosure for the purposes of APP 8. The content of those notifications is encrypted in transit and cannot be read by the vendor, although the delivery endpoint, the timing of delivery, and your device's IP address are disclosed. Enquiries and waitlist submissions made through our marketing website are stored in Salesforce on Australian infrastructure, so that disclosure does not cross a border. Our marketing forms use Google reCAPTCHA to prevent spam and abuse; when a form page loads it discloses your IP address and device characteristics to Google, hosted outside Australia — a further cross-border disclosure for the purposes of APP 8. Operational and billing alerts for our own team — which include your organisation's name, account identifiers and billing status — are delivered to Slack (Salesforce), hosted outside Australia; this is a further cross-border disclosure for the purposes of APP 8. Email addressed to our team — including the 'Ask Lede' chat enquiries passed to us for follow-up, and any access, correction, deletion, opt-out or complaint request you email us — is received and stored in our own mailboxes, which are hosted by Google Workspace outside Australia; this is a further cross-border disclosure for the purposes of APP 8. Aside from these disclosures, we do not transfer operational data offshore without explicit operator consent.
Data retention
Operator account data is retained for as long as the subscription is active. What happens to it when a subscription ends is set out below.
Raw worker shift notes (the text and voice-transcribed content workers enter) are retained until the operator’s account is deleted, regardless of subscription tier.
Two tier-based limits apply to AI-generated handover summaries and briefings (the end-of-shift content derived from shift notes):
- Visible history window — how far back the AI features analyse and display handover history.
- Storage ceiling — handover summaries older than this are deleted, even while the account is active. How a change of tier affects this ceiling is described below. Raw shift notes are not affected by this ceiling.
| Subscription tier | Visible history window | Handover deletion ceiling |
|---|---|---|
| Free | 7 days | 14 days |
| Starter | 60 days | 90 days |
| Growth | Unlimited | Not deleted while your subscription is active |
| Enterprise | As agreed in your contract (unlimited by default) | As agreed in your contract (not deleted by default) |
An Enterprise agreement may set a shorter negotiated retention window; where it does, that window applies to both the visible history window and the handover deletion ceiling for that account.
Operators on the Free and Starter tiers receive an in-app warning before handover summaries are deleted, with the option to upgrade to retain them.
If your tier changes. The deletion ceiling in the table above is set for each handover summary when it is created, from the tier the account is on at that moment, and after that it is only ever extended. Upgrading lifts the ceiling on the handover summaries you already have. Downgrading does not lower it: summaries created under the higher tier keep the ceiling they were given, and only summaries created after the change are held to the new tier's ceiling. The visible history window is not held this way — it follows your current tier straight away, so after a downgrade you may be able to see less than we are still storing. One exception applies: if you move off the Growth tier, handover summaries that were being kept indefinitely are instead kept for at least a further twelve months from the date of the change, and are then deleted.
The Cover Story front page is held differently, because each edition is a synthesis of recent handovers rather than a record of a single shift. Cover Story editions are deleted against the ceiling for the tier you are on now, not the tier they were created under, and after a downgrade we allow a grace period of one full retention period before the shorter ceiling is applied to them.
If your payment fails. A failed payment does not close your account. Stripe retries the charge, and the account keeps working while it does. If every retry fails, the subscription is marked unpaid and your organisation is suspended: nobody in your organisation can reach the information held in the account, although your billing settings stay available so the outstanding amount can be settled. A suspension deletes nothing and starts no deletion clock. Handover summaries already in the account keep the deletion date they were given and are deleted when it arrives, so content can pass its ceiling while you are unable to reach it. The unpaid invoice is left outstanding rather than cancelled, so the record of what was owed is preserved. Paying it lifts the suspension and restores access. A suspension does not lift on its own: if the amount is not settled we may end the subscription, and if we do, the account is closed and the information in it is deleted.
If you cancel. Cancellation ends your subscription and begins the removal of your account. The clock runs from the end of the period you have paid for: your account becomes inaccessible 30 days after that point — it can no longer be used, and nobody in your organisation can reach the information held in it — and everything in it is permanently deleted once 90 days have passed. Retrieve anything you want to keep before your access ends: you can export your data at any time from your account settings, and a deletion cannot be reversed.
Coming back is a fresh start. We do not restore a deleted account, and we do not hold anything back in case you return. Once your account has been deleted, signing up again gives you a new account with none of your previous data in it.
What we keep. Financial records — invoices and payment history — are retained for five years as Australian tax law requires. We also keep an audit record of the deletion itself, as evidence it was carried out. Everything else is destroyed: shift notes, handover summaries, worker records, reports and account information.
Backups. Deleted data may persist in encrypted database backups until those backups expire on their normal schedule.
Operators can request deletion of their site's shift note history at any time by emailing privacy@workwithlede.com. Workers who wish to request deletion of their own records should contact their employer in the first instance, or contact us directly at the same address.
Your rights
Under the Privacy Act 1988 (Cth) and the Australian Privacy Principles, you have the right to:
- request access to the personal information we hold about you;
- ask us to correct information that is inaccurate or out of date;
- ask us to delete your personal information, subject to our legal obligations; and
- make a complaint about how we have handled your personal information.
To make any of these requests, email privacy@workwithlede.com. We will respond within 20 working days.
If you are not satisfied with our response, you have the right to lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
Data breaches
Lede maintains a written data breach response plan. In the event of an eligible data breach as defined under the Notifiable Data Breaches (NDB) scheme (Privacy Act 1988, Part IIIC), we will:
- assess the breach within 30 days of becoming aware;
- notify the OAIC and all affected individuals as required by law; and
- take immediate steps to contain the breach and prevent recurrence.
To report a suspected security issue or data breach, contact privacy@workwithlede.com immediately.
Operator responsibility
Operators who use Handover are responsible for:
- informing their workers that the Lede platform is in use and that shift notes are recorded, stored, and processed by AI features;
- providing worker disclosure in the form required by this policy and our Terms of Service before workers first use the platform, and again before any AI feature upgrade is activated;
- where they import historical handover records from a previous system, confirming they have the right to provide those records to Lede, including any personal information of the workers named in them;
- ensuring workers use pseudonyms or codes (not resident, client, or patient names) when entering notes that reference third parties, particularly in aged care, disability support, and health settings;
- not using Handover data, including AI outputs, as the sole basis for any employment decision; and
- maintaining an internal response protocol for any safety or compliance signals surfaced by the platform.
Lede provides template disclosure language and recommended usage guidelines to all operators on request.
Cookies and tracking
We use cookies on our marketing website and our apps for two purposes. For analytics we use PostHog (hosted in the European Union) to understand how people find and use Lede. For advertising we use the Meta (Facebook) pixel on our marketing website (hosted in the United States) to measure page views and waitlist sign-ups so we can run and target ads. Both run only where you have accepted cookies; choose "Essential only" to decline. This is a cross-border disclosure under APP 8.
Analytics are off until you accept them. On both our marketing website and in the Lede apps, the analytics code is not loaded at all until you choose to accept. Declining leaves no analytics identifier in your browser and sends nothing to PostHog — no page views, no clicks, no other usage, and nothing connected to your account. If you accept and later change your mind, the identifier and any analytics data held in your browser are removed. Our alpha testing environment is the one exception, described at the end of this section.
If you accept, browsing on our website can later be linked to your account. When you accept on our website, PostHog stores an identifier in a cookie scoped to .workwithlede.com, so that the same identifier can be read by our apps at app.workwithlede.com. If you then sign in to Lede, having also accepted analytics in the app, that identifier is attached to your Lede user account. The practical effect is that pages you viewed on our website before you had an account — including pages you viewed before you decided to sign up — become linked to you as an identified person from that point onward.
This happens only if you accept analytics in both places. If you decline in the app, we do not make that link, and your earlier website browsing is not connected to you. The app still stores the randomly generated identifier described above, but it stays in your browser: it is never sent to us and it is never attached to your account.
Changing your mind. You can change your choice at any time. On our website, use "Cookie settings" in the footer of any page. In our apps, use the analytics setting in your profile. Your choice applies everywhere you use Lede. When you withdraw consent we stop collecting straight away and delete the analytics identifier stored by the Lede page you are on. Your browser may still hold an unused identifier, which is never sent to us while analytics is off. If you have another Lede page open in the same browser, it may keep collecting until you reload it, and then it stops and clears its own copy. One exception to everything in this section: on our alpha testing environment, at addresses ending staging.workwithlede.com, usage analytics and session replay are a condition of access, they cannot be switched off, and the in-app setting is shown but cannot be changed. You can also email privacy@workwithlede.com and we will action it for you.
Session replay. Session replay records what happens on screen while you use the Lede apps — the pages you open, what is displayed on them, and the actions you take — so that we can see where the product is confusing or broken. Where you have accepted analytics, your sessions in the Lede apps at app.workwithlede.com and handover.workwithlede.com may be recorded in this way. If you decline analytics, no replay is recorded at all; there is no reduced or partial recording. On our alpha testing environment, at addresses ending staging.workwithlede.com, sessions are recorded as a condition of access, as described above. Where replay is running we record whole sessions rather than a sample of them, and a recording is deleted 30 days after it is made. Fields we know to be sensitive are masked and are never recorded. We do not record your session while a member of the Lede team is signed in to your account to assist you.
What we do not do. We do not record or replay your screen on our marketing website at workwithlede.com. We do not build a profile of anonymous visitors — no person record is created in PostHog unless and until an account is linked as described above.
Changes to this policy
We may update this policy from time to time as our product and obligations evolve. We will notify operators of any significant changes via email before they take effect. The current version is always available at workwithlede.com/privacy.
This policy is governed by the Privacy Act 1988 (Cth) and the Australian Privacy Principles.
Last updated: 30 August 2026
Lede Technologies Pty Ltd (ACN 698 337 718) — privacy@workwithlede.com — workwithlede.com/privacy