These terms form part of the Terms of Use and apply whenever CoreDocket handles personal information on your business’s behalf. They set out our obligations to you in writing, as commonly required by a principal contractor, insurer or client security assessment.
In these terms, we and us mean Peak Productive Consulting Pty Ltd trading as CoreDocket. You means the business with a CoreDocket account. Your Data means the personal information you or your people enter into, or generate through, the platform — including information about your staff, your customers and the sites you work on.
Your Data is yours. You determine what is entered into CoreDocket, for what purpose, and who within your business may access it. Under the Privacy Act you are the entity responsible for that information, including for responding to requests from the individuals it concerns.
We process it on your instructions. Your instructions comprise the actions you take within the platform and anything you ask us to do in writing. We do not use Your Data for our own purposes, to market to your customers, or to train artificial intelligence models, and we do not sell it.
Separately, we are responsible in our own right for the account relationship with you, including your billing details, your sign-in credentials and our own website analytics. That information is governed by our Privacy Policy.
Subject matter: providing the CoreDocket platform to you.
Nature of the processing: storing, organising, displaying, transmitting, backing up and deleting Your Data; producing documents such as dockets, quotes, invoices and safety records; and sending the messages you ask us to send.
Types of information: names and contact details of your staff and customers; site addresses; job records, photographs and signatures; safety documents and the signatures on them; timesheets; invoicing and pricing records; and, where you use messaging, the content of those messages.
People it is about: your workers, your customers, and the people present on the sites you attend.
Duration: for as long as your account is open, and then as described in clause 7.
We keep Your Data confidential. Our people may access it only where it is needed to operate the platform, to provide support you have asked for, or where the law requires it, and they are bound to confidentiality obligations that survive their engagement with us. We do not disclose Your Data to anyone else except the sub-processors in clause 9, or where we are legally compelled — in which case we will tell you unless we are prohibited from doing so.
We maintain technical and organisational measures appropriate to the harm that would result from a breach and to the nature of the information. What those measures are today is set out at coredocket.com.au/security. We may change them as the platform develops, but not in a way that materially reduces the protection given to Your Data.
Certain aspects of account security rest with you: ensuring each person holds their own login rather than sharing one, setting permissions to what each role requires, and withdrawing access when a person leaves.
Where an individual requests access to, correction of, or deletion of information you hold about them, the platform provides the means to act on most such requests directly. Where it does not, we will provide reasonable assistance at no charge for ordinary requests.
Where such a request is made to us directly, we will not respond on your behalf. We will refer it to you, as the record is yours and the obligation to respond rests with you.
If we become aware of unauthorised access to, or disclosure or loss of, Your Data, we will notify you without undue delay and in any case within 72 hours of becoming aware of it. We will tell you what happened, what information was involved so far as we know it, what we are doing about it, and what we suggest you do.
We will notify you on the basis of what is known at the time rather than on completion of our assessment, as the assessment period under the Notifiable Data Breaches scheme applies to you as well as to us. We will provide reasonable assistance with your own assessment and with any notification you elect to make.
Export remains available at all times, including while an account is overdue or suspended. CoreDocket does not withhold Customer Data in order to secure payment of an invoice.
If your account closes, we keep Your Data for 90 days so that it can still be retrieved, and then delete or de-identify it. You can ask us to delete it sooner and we will, unless we are required to keep something — for example records needed for tax or for a legal claim, which we keep only for as long as that requirement lasts.
Deletion propagates through our backups as those backups expire on their rolling window rather than immediately, as is inherent in any system maintaining disaster recovery capability.
CoreDocket does not delete Your Data on a schedule of its own. Certain records held in the platform, including employee and safety records, are subject to statutory retention periods for which you are responsible.
Your database, files, sign-in and our backups are held in Australia. A small number of specific jobs are performed overseas by the providers in clause 9 — sending email or text messages, taking card payments, looking up addresses. Where we disclose personal information overseas we take reasonable steps to ensure the recipient handles it consistently with the Australian Privacy Principles, as APP 8 requires.
You authorise us to use the sub-processors listed at coredocket.com.au/sub-processors, which names each one, what it receives and where it processes. That list was last checked against our systems on 27 August 2026.
We impose data protection obligations on each sub-processor no less protective than these terms, and we remain responsible to you for what they do with Your Data.
Before engaging a new sub-processor that will receive Your Data, we will give you at least 30 days’ notice by email or within the application. If you reasonably object on data protection grounds within that period, we will work with you to identify an alternative. If no alternative is available, you may terminate your subscription without penalty and we will refund any fees paid in respect of the period following termination.
We will provide the information you reasonably need to satisfy yourself that we are meeting these terms, including answering a security questionnaire from a principal contractor or an insurer. Most of what such a questionnaire asks is already published at coredocket.com.au/security so that it is available to you without delay.
CoreDocket does not offer on-site audit of infrastructure, which is operated by our hosting providers rather than by us.
We may update these terms as the platform changes, but not in a way that materially reduces the protections in them. The effective date above shows when they were last revised, and material changes are notified to account holders by email or in the app.
Peak Productive Consulting Pty Ltd trading as CoreDocket
Privacy and data protection enquiries: enquiries@coredocket.com.au