Lomandra
Security and privacy

How Lomandra protects the people in your project.

Our products hold residents' details, complaints, job applications, business contacts and workers' details. Each one is built differently, so here is where the data sits for each, who can see it, how long we keep it, and what's still on the way.

In short

The plain-English version.

For project directors and clients. The detail for IT and security teams is further down.

Engage data stays in Australia

Held in the AWS Sydney region, and encrypted when stored and when it moves.

People only see their own project

Access rules sit in the database itself and follow each person's role, so a mistake on a screen can't expose records.

Every change is recorded

Who changed a stakeholder, complaint or commitment, and when, is kept on the record.

We keep less, for less time

Forms ask for what the job needs, and personal details nobody needs are cleared on a schedule.

Tested on every release

360 automated checks of who can see and change what run before anything reaches a live project.

Connect is clear about where data goes

It runs on established website services, some of which store data outside Australia. Each project's privacy statement names them.

Every producthow we work

Some things are the same whichever product you use.

Rules we design for

Our products are built to help project teams meet their obligations, not to replace their advice.

  • Privacy Act 1988 and the Australian Privacy Principles.
  • Information Privacy Act 2009 (Qld) and the Queensland Privacy Principles, for work with Queensland agencies.
  • Notifiable data breach obligations, supported by access records.
  • The ASD Essential Eight and the Information Security Manual, as the benchmark for our own controls.

Less data, kept less long

We ask for what the job needs and clear what nobody needs any more.

  • Each privacy statement names the services a product uses and where they store data.
  • Retention follows the privacy statement and your records schedule.
  • Optional questions are clearly marked optional.
Engagecommunity and stakeholder engagement

Engage runs on its own database, with the access rules built into the database itself.

Where data lives

The database, sign-in, file storage and server functions run on Supabase in the AWS Sydney region. Data is encrypted at rest and in transit. Supabase holds SOC 2 Type 2 and ISO 27001 certification.

  • Each project has its own records. Staff on one project cannot see another project.
  • The public pages and app hold only the public key; the service key never leaves the server.
  • Uploaded photos and submission files sit in private storage with file type and size limits.

Who can see what

Access rules are enforced by the database on every request, so a mistake in a screen can't expose data the rules don't allow.

  • Four roles: admin, engagement lead, editor and read-only viewer.
  • Several organisations on one project, each with its own people.
  • Viewers can read but never send, publish, reply as the project or change records.
  • Every project always keeps at least one admin.

What we record

Changes to stakeholders, interactions, commitments, complaints, tasks, social accounts, consultations, team roles and project settings are logged with who made them and when.

  • Enquiry and reply times are set by the database, so reply-time reports can be trusted.
  • Complaint timelines record every stage change and action.

What we keep, and for how long

Personal details nobody needs are cleared automatically.

  • Unconfirmed email and text sign-ups are deleted after 7 days, and people who unsubscribe after 30.
  • Text message logs are cleared after 13 months.
  • Complaints, enquiries and the audit log follow your records retention schedule.
  • Members of the public can delete what they added from the app or consultation pages.
  • Social listening never stores author names or handles.

How it's tested

Every release runs the full test suite before it goes anywhere near a live project.

  • 360 automated checks of who can see and change what, run under strict and permissive database settings.
  • End-to-end tests of every server function, including sign-in, alerts, mail and listening.
  • Automated accessibility checks against WCAG 2.2 AA on the console and public pages.
  • A strict content security policy and other security headers on every page.

What's next

We'd rather tell you what's coming than overstate what's there.

  • Single sign-on with Microsoft Entra ID, with multi-factor sign-in required for admins.
  • Session time limits and automatic sign-out for the console.
  • CAPTCHA protection on public sign-up and consultation pages.
  • The console on its own web address, separate from public pages.
  • An independent penetration test and a security pack for agency assessments.
Connectproject website, jobs and local industry

Connect is a website built on established platforms, with the routing rules set up for each project.

Where data lives

The website and job listings run on Webflow, business accounts on Memberstack, and form routing on Make. Some of these services store data outside Australia, and the project's privacy statement says which and where.

  • Job listings and pages are published from the website's content system.
  • Form submissions pass through Make to the right team's inbox.
  • Diversity answers are removed from emails to the hiring business.

Who can see what

Each person sees only what their part of the project needs.

  • Applications go to the business that is hiring.
  • Optional diversity answers stay with the joint venture's workforce team. They are only shared with the hiring business for roles set aside for First Nations applicants.
  • Subcontractors sign in to post and manage their own ads.
  • Every subcontractor ad is approved before it goes live.

Terms and privacy

Written for each project and reviewed before launch.

  • A privacy statement covering enquiries, applications, the talent pool, briefings and business accounts.
  • Job board terms that make clear the advertiser is the employer.
  • Both are drafted for your lawyers and partner HR to review before the site goes live.

What's next

Things we are adding as projects ask for them.

  • Resume file uploads, on a paid site plan.
  • Approved subcontractor ads going straight into the jobs list.
  • Applications for subcontractor ads sent straight to the advertiser's inbox.
Impactworkforce, local industry and environment targets

Impact switches on inside the same console as Engage, and its access rules sit in the database in the same way.

Workers stay in control

Workers' details count only where they have said yes.

  • Each worker chooses, detail by detail, what can count in project reports.
  • Employers see a detail only if the worker has also agreed to that.
  • Until a worker claims their profile, an employer can enter details from a signed consent form.

Reports that protect people

Project reports show totals, not individuals.

  • Groups too small to stay anonymous are hidden, five people by default.
  • Employers upload monthly hours exports from their own systems. We never connect to anyone's payroll, and hours typed in by hand are marked as typed.
  • A subcontractor sees its own returns and those of the businesses it engages, never another company's.

Have a security assessment coming up?

Tell us what your agency or partner IT team needs to see, and we'll walk them through how each product handles data.