Privacy Policy
Last updated: 7 August 2026
1. About This Policy
LodgeHQ (“we”, “us”, “our”) is operated by LodgeHQ Pty Ltd (ABN 52 696 192 677), founded by Awais Nisar, a Registered Migration Agent (MARN 2318017). We are committed to protecting the privacy of our users and their clients in accordance with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth).
This policy explains how we collect, use, store, and disclose personal information through the LodgeHQ platform at app.lodgehq.com.au.
LodgeHQ is a cloud-based practice-management and client-relationship-management (CRM) platform used by migration agents and lawyers to manage their matters. It includes optional features that use artificial intelligence (AI) to help agents work more efficiently (see Section 9). Where your information is held, and which parts of it are disclosed overseas, is set out in Section 5 and Section 7.
2. Information We Collect
We collect the following categories of personal information:
- Account information: Name, email address, phone number, business name, business address, MARN (for migration agents).
- Client data: Information entered by migration agents about their clients, including names, dates of birth, passport numbers, visa application details, and other immigration-related data.
- Documents: Files uploaded by agents or their clients, including identity documents, qualifications, and supporting evidence.
- Payment information: Billing details processed securely through Stripe. We do not store credit card numbers on our servers.
- Usage data: Log data, IP addresses, browser type, and interaction patterns for security and service improvement.
3. How We Use Your Information
We use personal information to:
- Provide and maintain the LodgeHQ platform and its features.
- Process subscription payments and manage billing.
- Send transactional emails (verification codes, signature requests, questionnaire invitations).
- Respond to support enquiries.
- Ensure platform security, detect fraud, and prevent unauthorised access.
- Comply with legal obligations, including OMARA regulatory requirements.
4. Data Security
We implement industry-standard security measures including:
- AES-256-GCM encryption for sensitive personal identifiers (passport numbers, TRN numbers, DHA file numbers).
- HMAC-signed session tokens and CSRF protection.
- Two-factor authentication (2FA) support.
- Content Security Policy headers and rate limiting.
- All data transmitted over HTTPS/TLS.
- Regular automated security audits of dependencies.
5. Where Your Data Is Held
LodgeHQ stores your practice’s records, your clients’ records and your uploaded documents in Australia — on Amazon Web Services infrastructure in the Sydney region (ap-southeast-2) — and AI processing runs on Amazon Bedrock in Australia (Sydney and Melbourne, ap-southeast-4).
Some data does leave Australia. It leaves through parts of the platform that are always on — outbound email and its attachments, card payments, SMS and WhatsApp, browser push notifications, and document translation — and it leaves through optional integrations your practice chooses to connect, such as a mailbox, a calendar, an accounting connection or a cloud-storage mirror. Which data leaves, to which recipient, in which country and for what purpose is set out in the cross-border disclosure section of our Privacy Policy.
AI features run on Amazon Bedrock in Australia — the inference profiles in use resolve only to the Sydney (ap-southeast-2) and Melbourne (ap-southeast-4) regions. The model vendor is Anthropic (Claude). Under Bedrock, AWS operates the model deployment accounts: Anthropic does not receive your prompts, your documents or the model output, and the data is not used to train models. That is the position AWS publishes for Bedrock, and it is the basis on which we use it.
The database is encrypted at rest under a customer-managed key, sits in a private subnet and has no public endpoint. Uploaded documents are held in a private encrypted Amazon S3 bucket in Sydney and are served through links that expire after one hour. Amazon Web Services holds ISO 27001 and SOC 2 certification as our infrastructure provider; LodgeHQ holds neither, and we do not present those certifications as ours.
The third parties that handle personal information through LodgeHQ — the legal entity, the country, what each one receives, and whether you can switch it off — are set out on our Sub-processor Register.
Retention
We retain your data for as long as your account is active.
When an account ends, your data remains available for export for 30 days. After that it is deleted from our active systems, and the last remaining copy ages out of our Amazon Web Services infrastructure 90 days later — 120 days from closure in total. That 90 days is the longest of three expiry rules set on the infrastructure itself: point-in-time recovery on the database runs a 14-day window, database exports expire at 35 days, and superseded document versions expire at 90. No manual database snapshots exist outside those rules.
Some information may be retained longer where required by law. If you want your data deleted sooner, email support@lodgehq.com.au from the address on the account and we will action it and confirm in writing.
Registered migration agents are reminded that their own record-keeping obligations under the Code of Conduct continue after a LodgeHQ account is closed, and are independent of anything set out here. Take an export before you close an account.
6. Disclosure of Information
We may share personal information with the recipients below. Further detail — the legal entity, the country, exactly what each one receives and whether it is optional — is on our Sub-processor Register.
Always on — part of how the platform works:
- Amazon Web Services: hosting, the database, encrypted document storage and AI inference (Amazon Bedrock), in the Sydney (Australia) region.
- Google: relays every email the platform sends — including the full message body and any attachment, such as an invoice, a signed service agreement or a generated letter — and hosts our support mailbox. This applies whether or not you connect your own mailbox under Section 7.
- Stripe: subscription billing, and card payment of the invoices you send your own clients — which means your client’s email address, the invoice number, the description of services and the amount. Card details are entered on Stripe’s own page and never reach us.
- Twilio: SMS and WhatsApp — the destination number and the full message body.
- Your browser’s push service (Google, Mozilla, Apple or Microsoft) if you turn on notifications: routing metadata and a payload encrypted end-to-end to your browser.
- NAATI-certified translators, where you order a translation: the document itself, through our translation service.
- Law enforcement: where required by law, court order, or regulatory authority.
Only if your firm connects them: your own Gmail, Outlook or IMAP mailbox; your own Google, Outlook or Apple calendar; Dropbox, Google Drive, OneDrive, SharePoint or Zoho WorkDrive for document mirroring; Xero; eWAY; Bitrix24; and our social-post scheduler. In each case you choose the recipient, the destination is normally your own tenancy, and your agreement with that provider governs where the data lands.
We take reasonable steps to ensure all personal information is handled consistently with the Australian Privacy Principles.
We do not sell personal information to third parties.
7. Overseas Disclosure (APP 8)
Australian Privacy Principle 8 requires us to tell you which of your information is disclosed to recipients outside Australia, and which countries they are in. This section does that. We would rather set it out plainly than leave you to infer it from a supplier list.
Always on — you cannot switch these off and keep using LodgeHQ:
| Recipient | Country | What it receives |
|---|---|---|
| Google (mail relay and our support mailbox) | United States / global | Recipient, sender, subject, the full body of every email the platform sends, and every attachment — including invoices, signed agreements and generated letters. Also anything you email us, including screenshots and documents from a client file. |
| Stripe | Ireland and global | Your billing details; and where you invoice a client through LodgeHQ, that client’s email address, the invoice number, the description of services, the GST line and the amount. No documents. |
| Twilio | United States (global endpoint) | Destination mobile number and the full text of every SMS or WhatsApp message, which routinely carries a client name, matter reference or deadline. |
| Our translation service, and the NAATI-certified translator who completes the order | Not confirmed — treated as overseas | The raw document files you send for translation: passports, birth and marriage certificates, police clearances. Requests reach it through a content-delivery edge in Melbourne, but the hosting region of the service itself is unconfirmed, so we treat it as an overseas disclosure rather than assert a region we have not verified. |
| Browser push services (Google, Mozilla, Apple, Microsoft) | Global | A browser-assigned endpoint and a payload encrypted end-to-end to that browser. The service sees ciphertext and routing metadata only. |
Optional — only where your firm connects the account: a Gmail, Outlook or IMAP mailbox; a Google, Outlook or Apple calendar; Dropbox, Google Drive, OneDrive, SharePoint or Zoho WorkDrive for document mirroring; Xero; eWAY; Bitrix24; and our social-post scheduler. Where you connect one of these, you choose the recipient and the destination is normally your own tenancy. We do not verify or control the region of an account you connect, and we cannot give you an assurance about what that provider does with the data once it arrives. Cloud Mirror in particular sends the full case file— client documents, questionnaire PDFs, e-signed agreements, letters and invoices.
What this means for your own clients. If you are drafting a collection notice or a privacy statement for the people whose matters you manage, this section and the Sub-processor Register are the detail you need. Where you connect one of your own accounts, we are not telling you where the APP 8 accountability line falls for your practice — that depends on your arrangements, not ours. We are telling you exactly what is sent and to whom, so you can decide.
We do not sell or rent personal information, and we do not disclose it to anyone for their own marketing purposes. We do not use client case data to train, fine-tune or improve any AI model, and we have not licensed any sub-processor to do so.
8. Connected Email Accounts (Google & Microsoft)
LodgeHQ lets a migration agent optionally connect their own Gmail (Google) or Outlook / Microsoft 365 (Microsoft)mailbox, so that client correspondence can be sent from, and automatically filed against, the agent’s own email address. This feature is optional and is only ever activated when the agent explicitly connects a mailbox and grants consent on the provider’s own permission screen.
Google account data we access, and why:
gmail.send— to send emails (questionnaire invitations, document requests, letters and client correspondence) from the agent’s own connected address instead of a generic platform address.gmail.readonly— to read messages in the connected mailbox so that emails to and from the agent’s clients can be matched and filed against the correct client matter (“email filing”).userinfo.email— to identify which email address has been connected.
Microsoft account data we access, and why: the equivalent Mail.Send, Mail.Read and offline_accesspermissions, used for the same send and email-filing features on Outlook / Microsoft 365.
How this mailbox data is handled:
- OAuth access and refresh tokens are stored encrypted (AES-256-GCM) and are used solely to provide the send and email-filing features the agent enabled.
- Messages identified as correspondence with the agent’s clients are stored within the agent’s own LodgeHQ account and linked to the relevant client matter, so the case file is complete.
- We do not use Google or Microsoft mailbox data for advertising; we do not sell or transfer it to third parties; and we do not use it to develop, improve, or train generalised artificial-intelligence or machine-learning models.
- Mailbox content is not read by any human at LodgeHQ except where strictly necessary to provide support the agent has specifically requested, to maintain security or investigate abuse, or to comply with applicable law.
- An agent can disconnect a mailbox at any time from Settings → Email, which stops all further access, revokes our tokens with the provider, removes the stored connection credentials from our systems, and deletes synced mailbox content that has not been filed to a client matter. Correspondence filed to a client matter is retained as part of that client’s case record, consistent with agents’ record-keeping obligations under the Migration Agents Regulations 1998. Access can also be revoked directly at myaccount.google.com/permissions (Google) or account.microsoft.com (Microsoft) — revocation is detected and triggers the same clean-up.
LodgeHQ’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
9. Artificial Intelligence (AI) Features
LodgeHQ includes optional features that use artificial intelligence to help migration agents and lawyers work more efficiently — for example, drafting letters and document summaries, generating client questionnaires, extracting information from uploaded documents, mapping client data onto visa application forms, and answering in-product help questions. These features may process personal information that an agent has entered about themselves and their clients.
AI features run on Amazon Bedrock in Australia — the inference profiles in use resolve only to the Sydney (ap-southeast-2) and Melbourne (ap-southeast-4) regions. The model vendor is Anthropic (Claude). Under Bedrock, AWS operates the model deployment accounts: Anthropic does not receive your prompts, your documents or the model output, and the data is not used to train models. That is the position AWS publishes for Bedrock, and it is the basis on which we use it. That is a configuration of the service rather than a permission boundary, and if we ever change it this policy changes first. The following protections apply:
- Information sent to the AI provider is used only to generate the specific output requested. It is not used to train, fine-tune, or improve any AI models.
- Information sent to the AI provider is not retained by that provider once the request has been completed.
- AI output is a draft or working aid only. The registered migration agent or lawyer using LodgeHQ reviews all AI-assisted work and remains fully responsible for the advice and documents provided to their clients.
AI features are a productivity tool for the agent; they do not make decisions about a client’s matter. An agent may have their own professional obligations to inform clients about the use of AI and to obtain any consent required. LodgeHQ provides tools to help agents meet those obligations — including suggested service-agreement wording — but responsibility for meeting them rests with the agent.
10. Your Rights
Under the Australian Privacy Principles, you have the right to:
- Access the personal information we hold about you.
- Request correction of inaccurate information.
- Request deletion of your data (subject to legal retention requirements).
- Export your data in a portable format.
- Lodge a complaint with the Office of the Australian Information Commissioner (OAIC) if you believe your privacy has been breached.
11. LodgeHQ eLodge Chrome Extension
LodgeHQ also publishes an optional Chrome browser extension called LodgeHQ eLodge, which allows registered migration agents to auto-fill two Australian government forms using client data they have previously entered into their LodgeHQ account: Department of Home Affairs ImmiAccount visa and citizenship applications, and the Australian Federal Police National Police Check application.
What the extension accesses:
- The currently open tab on
online.immi.gov.au— only to read the form field structure and write the user’s selected client data into those fields. - The currently open tab on
afpnationalpolicechecks.converga.com.au— the official AFP National Police Check application portal, which Converga operates on the Australian Federal Police’s behalf. The extension reads the form field structure on that page and writes the applicant’s factual details into fields that are still empty: their names and any former names or aliases, date of birth, sex, place of birth, contact details, residential address history and driver-licence details. It also sets the purpose of check to Commonwealth purpose, Code 33 (immigration and citizenship). It does not tick a declaration or a consent, does not choose or upload identity documents, does not enter a mailing address or any payment detail, and does not move between pages or submit. It never replaces an answer that is already there. - The user’s LodgeHQ account at
app.lodgehq.com.au— to fetch the list of the user’s clients, their completed questionnaire answers, and the user’s agent profile (via the same authenticated session that the user has already signed into). - Chrome extension storage — to remember the selected client and the server URL between side-panel sessions. Which kind of storage that is changed in version 1.8.11; the next list explains both.
How extension data is handled:
- Where the cache lives depends on your extension version, so here is both. To keep the side panel responsive, the extension caches the client list and the selected client’s questionnaire answers while you work. Up to and including version 1.8.10 that cache was written to Chrome local storage, which is stored on the disk of the machine and persists until the extension is removed. From version 1.8.11 it is held in session storage instead: kept in memory, never written to disk, and discarded when the browser closes. Only two settings still persist — your server address and the capture-mode toggle — and neither contains personal information. Upgrading to 1.8.11 also clears whatever an earlier version left on disk, so an install that has been running for a while is cleaned up rather than merely changed going forward.
- How to check which one you are on. Open
chrome://extensionsand read the version under LodgeHQ eLodge. The Chrome Web Store updates installed extensions automatically, but a new release is only available once Google has reviewed it, so there is a period after we publish a change during which installs are still on the previous version. We are not going to describe 1.8.11 as though every install already has it. - The extension is not sent portal access tokens. Since 4 August 2026 the data sent to it excludes the token that authorises a client’s questionnaire, status and document-upload links: it is stripped server-side before the record ever leaves us.
- Nothing goes from us to the AFP. No LodgeHQ server sends client information to the Australian Federal Police or to Converga, and we have no relationship with either of them. The extension writes the applicant’s details into the AFP form in the agent’s own browser; those details reach the AFP only when the agent or the applicant reviews the completed form, gives the consent the AFP asks for, and submits it. That submission is the agent’s or the applicant’s act, not ours, and from that point the AFP’s own privacy notice governs the application. The purpose of check the extension pre-selects is Commonwealth purpose Code 33 — immigration and citizenship — and it is the agent’s responsibility to confirm that is the correct purpose before submitting. Where a purpose is already selected on the page, the extension leaves it alone and warns the agent instead of changing it.
- Two limits worth stating. While you are working, client information is in the memory of your own browser — so an unlocked, shared or compromised machine is still a way for someone to see it, exactly as an open case file on a desk would be. And a browser session can be long; the cache clears when the browser closes, not when the tab does.
- The extension sends data to one server only: the LodgeHQ address set in its side panel, which is
app.lodgehq.com.auunless a firm deliberately points it at its own LodgeHQ instance — the user’s own LodgeHQ account either way. Nothing is sent to the Department of Home Affairs, to the Australian Federal Police or to Converga, and there are no analytics, tracking pixels, or third-party SDKs in the extension. What reaches us differs between the two form sites, so here is each one.- On
online.immi.gov.au(the visa or citizenship form being filled), each time the agent fills a page the extension sends us a description of that page’s structure, so we can work out which questionnaire answer belongs in which field: each field’s selector, its question label, its type, the option lists of dropdowns and radio-button groups, the labels of the page’s buttons, and the page heading. That description is built from the page’s structure rather than its contents — the extension does not read the values in the form’s fields into it. Two qualifications we would rather state than let you assume: where a question or a button carries no label of its own, the extension falls back to a short extract of the page text around it (a few hundred characters), so anything the page itself displays on screen near that control — a summary of a record already added, for instance — can travel with it; and where a field can only be told apart by the value it holds, that value forms part of the selector. We use what is sent to produce the field mapping for that form and for nothing else. The agent’s ImmiAccount sign-in details are never read and never sent. - On
afpnationalpolicechecks.converga.com.au(the police-check form being filled) the extension sends nothing anywhere — not to us, not to the AFP, not to Converga. The part of the extension that runs on that site makes no network request of any kind; it types into the page in front of the agent, in the agent’s own browser.
- On
- No data is collected by LodgeHQ Pty Ltd purely as a result of the extension being installed. All data handled by the extension is data the user already owns inside their own LodgeHQ account.
- The extension does not sell, rent, or share user data. It is provided as a productivity feature of the LodgeHQ subscription.
Closing the browser discards the cached client data; uninstalling the extension removes everything it holds, including the two settings. No data is retained by LodgeHQ specifically as a consequence of extension use.
12. Cookies & Tracking
Inside the LodgeHQ application, and on every page we host for your clients — questionnaires, status pages, checklists and document upload — we use essential cookies for authentication and session management and nothing else. There is no advertising tag and no third-party tracking pixel on any of those pages.
On our marketing website (lodgehq.com.au, our comparison pages, our blog and the sign-up page) we run the Google Ads tag to measure whether our own advertising works. It sets the _gcl_* and _ga cookies on .lodgehq.com.au and sends Google the page path, the referrer, the user agent and the IP address. It does not send names, email addresses, client data or document contents, and there is currently no consent gate for it.
This was not always the case, and we would rather say so than let you find it: until 4 August 2026 that tag was loaded by the application’s root layout, which meant it also ran inside the signed-in product and on the client-facing pages agents send to their own clients. It no longer does. It is restricted to the marketing and sign-up paths, and it never ran on a firm’s white-label domain.
13. Data Breach Notification
If we confirm an eligible data breach affecting your firm, we will notify you within 72 hours of that confirmation — not within 72 hours of resolving it. The notice will tell you what data was affected, what we have done in response, and what you need to decide for your own clients. We anchor the commitment to confirmation because every practice carries its own notifiable-breach obligation for the same event, and you should be able to start your own assessment rather than wait for the end of ours. Separately, we handle breaches under the Notifiable Data Breaches scheme in the Privacy Act 1988: we assess a suspected eligible breach promptly and in any case within 30 days of becoming aware of it, and where the scheme requires it we notify the Office of the Australian Information Commissioner.
If you suspect a compromise of your own account — an unfamiliar sign-in, a message you did not send — email support@lodgehq.com.au with [URGENT] in the subject and we will treat it as priority.
14. Changes to This Policy
We may update this privacy policy from time to time. Material changes will be communicated via email or in-app notification. Continued use of LodgeHQ after changes constitutes acceptance of the updated policy.
15. Contact Us
If you have questions about this privacy policy or wish to make a privacy-related request, contact us at: