Trust Centre
Security and Privacy at Lede
Lede handles what your frontline teams record every shift. This page sets out how we protect that data, where it lives, who we share it with, and the documents that govern it.
Our Security Posture
The measures in place today to keep your data safe.
Australian Data Residency
All Lede operational data (shift notes, worker records and account information) is stored on AWS infrastructure in Australia (ap-southeast-2, Sydney). Some AI processing may cross a border; where it does, we disclose it in our Privacy Policy under APP 8.
Encryption in Transit and at Rest
Your data is encrypted in transit and at rest, including in our database backups. It is never sold, and never used to train public AI models.
Tenant Isolation
Each organisation's data is isolated at the database layer with row-level security, so one operator's data is never visible to another.
Authentication and MFA
Sign-in, single sign-on (SSO) and multi-factor authentication are handled by WorkOS, a dedicated identity provider, rather than built in-house.
Least-Privilege Access
Access to systems and data is scoped to what each service and team member needs. Public, unauthenticated endpoints (such as our website chat) run with their own tightly-scoped credentials.
Monitoring and Email Authentication
We monitor the platform for errors and performance issues, and our email is protected with SPF, DKIM and DMARC to guard against spoofing of the Lede domain.
Frameworks and Obligations We Follow
The privacy law, and the sub-processor terms, that govern how we handle your data today.
Australian Privacy Principles (Privacy Act 1988)
We operate under the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles, including APP 8 for cross-border disclosures. Our Privacy Policy sets out exactly what we collect, how we use it, and your rights.
Data Processing Terms with Sub-Processors
Every third-party provider we use is engaged under data processing terms consistent with our APP 8 cross-border disclosure obligations.
How We Handle Your Data
A summary. The full detail lives in our Privacy Policy.
What We Collect
The shift notes and submissions your workers enter, the account and site details operators set up, and standard product and website analytics where you have accepted them.
Retention
Retention follows your subscription tier, from 14 days on Free up to indefinite on Growth while active. Raw shift notes are deleted on the same ceiling as the summaries derived from them.
Your Rights and Control
You can export your data at any time from your account settings, and request access, correction or deletion by emailing us. Deletion is permanent and is recorded.
AI Processing
AI features process shift-note content to generate summaries, briefings and insights. Anthropic's Claude models on Amazon Bedrock are our primary, default choice; content is never used to train public models.
Data Breaches
We have a defined breach-response process and will notify affected operators and the OAIC as required under the Notifiable Data Breaches scheme.
On Cancellation
When a subscription ends, access is removed and the data in the account is permanently deleted on the schedule set out in our Privacy Policy. Financial records are kept for five years as tax law requires.
Sub-Processors
The third-party services we use to run Lede. This list mirrors the "Who has access to your data" table in our Privacy Policy.
| Provider | What They Handle | Hosting Location |
|---|---|---|
| AWS (Amazon Web Services) | Infrastructure, data storage, transcription and AI processing (Amazon Bedrock, Amazon Transcribe) | Australia (ap-southeast-2); some AI models/routing outside Australia |
| WorkOS | Authentication and identity: sign-in, SSO and MFA | See Privacy Policy |
| Anthropic, and AI models from other providers served through Amazon Bedrock | AI processing of shift-note content for summaries, briefings and insights | Via Amazon Bedrock — see AWS row |
| Stripe | Payment processing (we do not hold card data) | See Privacy Policy |
| Internal support, engineering, and operations tooling | Used to manage support requests, monitor and fix errors, and run internal team communications | Both in Australia and overseas |
| Salesforce | CRM and support-case tracking; waitlist and contact-form submissions | Australia |
| Google reCAPTCHA | Bot and abuse protection on our marketing forms | Outside Australia |
| PostHog | Website and product analytics (only where analytics accepted) | European Union |
| Meta (Facebook) | Website advertising pixel (only where cookies accepted) | United States, outside Australia |
| LinkedIn (LinkedIn Corporation) | Website advertising Insight Tag (only where cookies accepted) | United States, outside Australia |
| Google Calendar (Google LLC) | Appointment scheduling on our marketing website | United States, outside Australia |
| SMTP2GO | Transactional email delivery and "Ask Lede" enquiry delivery | Australia |
| Browser push services (Google, Apple, Mozilla) | Delivery of push notifications you opt into (content encrypted in transit) | Outside Australia |
Every provider hosted outside Australia is a cross-border disclosure under APP 8, and each is handled in accordance with the Australian Privacy Principles. For the full description of what each provider receives, see our Privacy Policy.
Matches Privacy Policy last updated 22 September 2026.
Documents
The policies that govern how we handle your data.
Questions About Security or Privacy?
Contact our team at privacy@workwithlede.com. We respond to privacy requests within 20 working days.
Read Your Operation Like a Front Page.
Lede partners with operators to build the tools you need most.