Cairn holds compliance records, so this policy is written to be read rather than skimmed. It describes what actually happens, not what a template says usually happens.
LAST UPDATED 8 AUGUST 2026
Drafted for launch — pending review by an Australian lawyer.
Cairn is a work health and safety documentation tool operated from Perth, Western Australia. Contact us at hello@cairnwhs.au about anything in this policy, including a request to access or delete your data.
We collect three kinds of information, and no more:
We do not use analytics, advertising or tracking cookies. We do not build a profile of you. The only cookie Cairn sets is the session cookie that keeps you signed in.
Voice dictation, where your browser supports it, is handled by your browser and its operating system. Cairn receives only the resulting text, in the same form as if you had typed it.
Account records, subscription records and generated documents are stored in Supabase (PostgreSQL and Supabase Storage). Rendered PDFs are held in a private storage bucket that is not publicly readable; downloads are served through short-lived signed links after we check that the document belongs to your account.
The Supabase project region is set by the operator at deployment. If you need the specific region for your own compliance purposes, ask us and we will tell you.
Cairn relies on three processors, each for a single purpose:
Generated documents and their inputs are kept for as long as your account exists, because they are compliance records and deleting them without being asked would defeat the purpose of the product.
Cancelling a subscription does not delete anything. Your records remain until you ask us to remove them.
Email hello@cairnwhs.au and we will delete your account, your documents, their stored PDFs, and your worker and site records. We will confirm when it is done.
Note that deletion is permanent and we cannot recover the records afterwards. If they are records you may need to produce to a regulator or a principal contractor, export them first.
Every table is protected by row-level security scoped to your account, and every write to a document, review record, worker or site goes through a server-side check of who you are and what you are entitled to. Stored PDFs are in a private bucket with no public read access.
No system is perfectly secure. If you believe your account has been accessed by someone else, email us and we will revoke its sessions.
If we change how your data is collected, stored or processed, we will update this page and email existing customers before the change takes effect.