Sub-processor Register
LodgeHQ Pty Ltd · ABN 52 696 192 677 · 12 Rindle Street, Lara VIC 3212
- Last updated:
- 7 August 2026
- Last reviewed against the running system:
- 4 August 2026
- Next scheduled review:
- 4 November 2026
What this page is
LodgeHQ is a case-management platform for Australian registered migration agents. To run it we use a number of third-party services. Some of those services receive personal information belonging to your clients — the people whose visa matters you manage in LodgeHQ.
This page lists them: the legal entity, the country, what the service is for, what data it receives, whether you can switch it off, and where the processing happens.
We publish it because you cannot properly assess a supplier you cannot see. If you are completing a due-diligence questionnaire, a professional indemnity disclosure, or a collection notice for your own clients, this page is where the detail comes from.
How this register was compiled. It was derived on 4 August 2026 from the production source code and the live production configuration — not from an internal wiki, and not by reading the previous version of the list. A service appears here where it handles information about your practice or your clients, whether we hold the credential for it or your own firm does.
On completeness. We do not claim this list is exhaustive, and we would rather say so than have you assume it. It covers the services that handle your practice and client information, reviewed on the cadence in section 7. Where we know a gap exists the table says so rather than leaving it silent — the individual translators who complete a translation order are the current example. If a service you care about is not here, ask us at support@lodgehq.com.au and we will tell you its position in writing.
Where the entity names come from. Which service receives what, and whether it is live, is derived from the running system, and we stand behind those columns. The legal entity column is different in kind: a contracting entity cannot be read out of our own configuration, so unless the cell says otherwise those names are taken from the vendor’s own published terms, data-processing addendum or privacy notice as at the date at the top of this page — not from an invoice or an order form we hold, and not independently confirmed against a corporate register. Group structures change, and the acquisition of a vendor can change the contracting entity without changing anything we would see. If you are relying on a specific entity name for your own assessment, ask us at support@lodgehq.com.au and we will confirm it from the contract or tell you plainly that we cannot.
Where this sits in the Privacy Act. This page is how we give effect to Australian Privacy Principles 1.4(f) and 1.4(g) — the kinds of personal information we disclose to overseas recipients, and the countries they are in. It is the detail behind the overseas-disclosure section of our Privacy Policy (APP 8), and it exists so that you can see what we disclose and to whom before you decide whether our security arrangements are reasonable for your practice.
What this page is not. It is not advice about your own obligations. Where you connect one of your own accounts to LodgeHQ, we are not telling you where the APP 8 accountability line falls for your practice, because that depends on your arrangements and not on ours. We are telling you exactly what is sent and to whom, so that you can decide.
How to read the table
Sub-processor — a third party that stores or handles personal information on our behalf, or on your behalf at your direction.
Always on means the service is part of how LodgeHQ works. You cannot switch it off and keep using the platform. Firm-enabled means nothing is transmitted until an administrator at your firm connects an account.
Client case data means information about your clients: names, dates of birth, passport and travel-document numbers, transaction reference numbers, addresses, questionnaire answers, file notes, and uploaded documents such as passports, birth certificates, police clearances and English-test results.
Where processed. Where we can prove the region from configuration, we state it. Where we cannot, we say so and treat the service as an overseas disclosure. We do not describe a service as Australian because its vendor has an Australian office, and we do not treat an edge or content-delivery point of presence as a storage location.
LodgeHQ stores your practice’s records, your clients’ records and your uploaded documents in Australia — on Amazon Web Services infrastructure in the Sydney region (ap-southeast-2) — and AI processing runs on Amazon Bedrock in Australia (Sydney and Melbourne, ap-southeast-4).
Some data does leave Australia. It leaves through parts of the platform that are always on — outbound email and its attachments, card payments, SMS and WhatsApp, browser push notifications, and document translation — and it leaves through optional integrations your practice chooses to connect, such as a mailbox, a calendar, an accounting connection or a cloud-storage mirror. Which data leaves, to which recipient, in which country and for what purpose is set out in the cross-border disclosure section of our Privacy Policy.
1. Core platform — always on
These are our own supplier choices. They apply to every firm on LodgeHQ and cannot be switched off firm by firm.
| Sub-processor | Legal entity and country | Purpose | Data categories | Always on / firm-enabled | Where processed |
|---|---|---|---|---|---|
| Amazon Web Services | Amazon Web Services Australia Pty Ltd, ABN 63 605 345 891 (Australia) — the Australian contracting party under the AWS Customer Agreement | Application hosting, the production database, document storage, secrets management and system logging | All client case data, including the raw uploaded document files. All firm and user account data. | Always on | Australia — Sydney (ap-southeast-2). The database has no public endpoint. Documents are encrypted at rest. |
| Amazon Bedrock (AI inference) | Amazon Web Services Australia Pty Ltd (Australia). The models are Anthropic’s Claude family. Anthropic PBC does not receive the data — see the note below the table. | Document data extraction, letter and email drafting, questionnaire generation, eligibility assessment, in-app support answers, semantic search, and form-field mapping for the eLodge extension | Matter context (client name, date of birth, passport number, transaction reference number, visa subclass, grant and reference numbers, fees, file notes, deadlines) and, for extraction, the raw bytes of the document being read | Always on. AI features are metered per firm, but there is no firm-level switch that disables AI processing. | Australia — Sydney and Melbourne (ap-southeast-2 / ap-southeast-4). Production uses the au. Bedrock inference profiles, which resolve only to Australian regions. That is a configuration setting rather than a physical constraint: if we ever change it, this page changes before it does. |
| Google Workspace — outbound mail relay and our support mailbox | Google LLC (United States) operates the infrastructure. Where an Australian contracting entity applies to a Workspace subscription that entity is Google Australia Pty Ltd; the relay and mailbox infrastructure is Google LLC’s in either case. | (i) Sending every email LodgeHQ generates: portal invitations, questionnaire links, document requests, invoices, signature requests, deadline digests and support replies. (ii) Hosting support@lodgehq.com.au, the mailbox you reach us on. | (i) Recipient email address, sender, subject, the full message body, and any attached file — which includes invoices, signed service agreements and generated letters. (ii) Anything you send us by email, including attachments. If you email us a screenshot or a document from a client file, it is stored in that mailbox. | Always on | Overseas. smtp-relay.gmail.com is a global endpoint. We have not set a Workspace data region, so we do not claim one. |
| Twilio | Twilio Australia Pty Ltd (Australia); group parent Twilio Inc. (United States) | SMS and WhatsApp messages sent from LodgeHQ to your clients | Sending number, destination mobile number and the full message body. Message bodies routinely contain a client’s name, matter reference, appointment time or deadline. | Always on wherever a firm sends SMS or WhatsApp from the platform | Overseas. We call api.twilio.com, Twilio’s global endpoint. We do not use an Australian regional edge. |
| LodgeHQ translation service — translate.lodgehq.com.au, running on Railway | The service is operated by LodgeHQ Pty Ltd (Australia). The underlying hosting platform is Railway Corp. (United States). | Instant translation quotes and NAATI translation orders | Raw client document files — passports, birth and marriage certificates, police clearances — plus file names, languages, page counts and order details | Always on as a platform feature; used per order, at the agent’s election | Not confirmed. Treated as an overseas disclosure. Requests reach it through a content-delivery edge in Melbourne, which decrypts and forwards them, but an edge point of presence is not where the container runs and we will not present it as one. Railway does not publish an Australian container region. We will state the region here when we can prove it, and until then this row stands as an overseas disclosure. |
| NAATI-certified translators (downstream of the translation service) | Individual NAATI-certified translators and translation providers engaged to complete an order. We do not currently publish the panel. | Performing a translation you order | The client document being translated, and the translated document produced from it | Used per order, at the agent’s election | Not published. If you need to know who will handle a particular document, or in what country, ask us before you place the order. |
| Web push services — Google (Chrome), Mozilla (Firefox), Apple (Safari), Microsoft (Edge) | Determined by each user’s own browser; we do not choose or contract with the service | Browser notifications to agents | The browser-assigned push endpoint, and a payload that is encrypted end-to-end to that browser. The push service sees ciphertext and routing metadata only. | Always on where an agent turns notifications on | Overseas (global). |
| Have I Been Pwned — Pwned Passwords range API | Operating entity not confirmed. The service is publicly operated from Australia. | Checking a chosen password against known breach corpora at sign-up and password reset | The first five characters of a SHA-1 hash, plus our server’s own IP address — nothing else. The check is made by our server, not by your browser, so no user IP address is sent. The password never leaves our server, and neither does the full hash. This is a k-anonymity lookup: the service cannot tell which password was checked. | Always on | Overseas (global). No personal information is transmitted. |
| Department of Home Affairs — ImmiAccount (via the eLodge browser extension) | Commonwealth of Australia, Department of Home Affairs | Prefilling ImmiAccount application forms from LodgeHQ data | Client name, date of birth, passport number, address, family and employment history — written into the form fields in the agent’s own browser. The extension prefills; it does not submit. | Always on where an agent installs the extension | Australia. |
| Australian Federal Police — National Police Check portal (via the eLodge browser extension) | Commonwealth of Australia, Australian Federal Police. The application portal is operated on the AFP’s behalf by Converga Pty Ltd (Australia). | Prefilling the AFP National Police Check application (Commonwealth purpose Code 33 — immigration and citizenship) from LodgeHQ data | Applicant name and former names, date of birth, sex, place of birth, contact details, residential address history and driver-licence details — written into the form fields in the agent’s own browser, together with the Code 33 purpose of check. The extension prefills; it does not tick consent, attach identity documents, pay or submit. Nothing is sent to the AFP or Converga by our servers: the information reaches them when the agent or applicant reviews the form and submits it. | Always on where an agent installs the extension | Australia. |
Note on Amazon Bedrock and Anthropic. Anthropic is the vendor of the Claude models we run, but under Amazon Bedrock, Anthropic is not a recipient of your data. AWS operates the model deployment accounts, and AWS’s published Bedrock terms state that model providers have no access to those accounts, to Bedrock logs, or to customer prompts and completions, and that Bedrock does not share inputs or outputs with model providers or use them to train models. We name Anthropic here because you should know whose model is reading your client’s passport; we do not list Anthropic as a recipient because it is not one.
Note on the Department of Home Affairs. DHA is not a sub-processor of ours — it is the regulator you lodge with, and the disclosure to it is one you make. We list it because omitting it from a register of where client data goes would be misleading.
2. Integrations your firm enables
Nothing in this section transmits anything until an administrator at your firm connects an account. When you connect one, you are choosing the recipient, and in most cases the destination is your own tenancy — your Dropbox, your Microsoft 365, your Xero. Your agreement with that provider governs where the data lands. We do not verify or control the region of an account you connect, and we cannot give you any assurance about what that provider does with the data once it arrives. We list them anyway, because they are still disclosures of your clients’ personal information and your clients are entitled to know they exist.
| Sub-processor | Legal entity and country | Purpose | Data categories | Always on / firm-enabled | Where processed |
|---|---|---|---|---|---|
| Dropbox (Cloud Mirror) | Dropbox, Inc. (United States); customers outside the United States and Canada contract with Dropbox International Unlimited Company (Ireland) | One-way copy of your matter files into your own Dropbox | The full case file — client documents, agent documents, questionnaire PDFs, e-signed documents, service agreements, generated letters, invoices and deposit requests — in folders named for the client and matter | Firm-enabled | Your Dropbox account. Overseas unless you have arranged otherwise with Dropbox. |
| Google Drive (Cloud Mirror) | Google LLC (United States), or Google Australia Pty Ltd where your own Workspace agreement so provides | As above, into your Google Drive | As above | Firm-enabled | Your Google account. Region governed by your own Workspace configuration. |
| Microsoft OneDrive / SharePoint (Cloud Mirror) | Microsoft Corporation (United States); many non-US customers contract with Microsoft Ireland Operations Limited | As above, into your OneDrive or a SharePoint document library | As above | Firm-enabled | Your Microsoft 365 tenancy. Region governed by your own tenancy configuration. |
| Zoho WorkDrive (Cloud Mirror) | Zoho Corporation Pty Ltd (Australia) operates the Australian data centres; group parent Zoho Corporation Private Limited (India) | As above, into your Zoho WorkDrive | As above | Firm-enabled | We connect to Zoho’s Australian data centre by default (accounts.zoho.com.au, zohoapis.com.au). This is the only mirror destination that is Australian by our configuration. Where the data ultimately rests is governed by your own Zoho account region, which we do not verify. |
| Gmail — connected firm mailbox | Google LLC (United States), or your own Workspace contracting entity | Sending client correspondence from your own address, and filing inbound mail to the right matter | Full email bodies, headers, recipients and attachments, in both directions | Firm-enabled, per mailbox | Your Google tenancy. |
| Microsoft Outlook / Microsoft 365 — connected firm mailbox | Microsoft Corporation (United States), or your own M365 contracting entity | As above | As above | Firm-enabled, per mailbox | Your Microsoft 365 tenancy. |
| IMAP — any other connected mailbox | Your own mail host, whoever that is | As above, for mail providers that are neither Google nor Microsoft | Full message content and attachments | Firm-enabled, per mailbox | Wherever your mail host is. We cannot know this, and we do not represent that we do. |
| Google Calendar | Google LLC (United States) | Two-way appointment sync and free/busy lookup | Event title, description, start and end times, attendee email addresses. Event titles routinely carry a client’s name and matter reference. | Firm- or agent-enabled | Your Google account. |
| Microsoft Outlook Calendar | Microsoft Corporation (United States) | As above | As above | Firm- or agent-enabled | Your Microsoft 365 tenancy. |
| Apple iCloud Calendar (CalDAV) | Apple Inc. (United States); Apple Pty Limited is the Australian contracting entity for consumer iCloud | As above | As above | Agent-enabled, using an app-specific password you supply | Apple’s global infrastructure. |
| Xero | Xero Australia Pty Ltd (Australia); group parent Xero Limited (New Zealand) | Pushing invoices, credit notes, contacts and payments into your Xero organisation | Client name, given and family name, email address, phone number, postal and street address, invoice line-item descriptions and amounts. No documents. | Firm-enabled | Xero’s infrastructure. Xero does not offer a customer-selectable region, so we do not claim one. |
| eWAY | Eway Payments Pty Ltd (Australia), part of the Global Payments group | Card payment for consultation bookings, using your firm’s own eWAY merchant account | Booker’s name and email address, amount, currency, invoice description and reference. Card details are entered on eWAY’s hosted page and never reach LodgeHQ. | Firm-enabled — you supply your own eWAY credentials and funds settle to you. There is no LodgeHQ-level eWAY account. | eWAY is an Australian gateway and acquirer. We have not independently verified its processing locations beyond eWAY’s own published position, so we state that rather than asserting a region. |
| Zernio (social post scheduling) | Registered entity and country of incorporation not established. Zernio was formerly known as Late / getlate.dev. We have not been able to establish the contracting entity from the vendor’s published terms; we have asked, and we will publish the answer here. | Scheduling and publishing your firm’s own social media posts | Post text and images, and the OAuth grant for the social account you connected. No client case data, unless a user puts client information into a post. | Firm-enabled | Not confirmed. Treated as overseas. |
Files already copied cannot be recalled. Cloud Mirror writes into storage you control. If you disconnect it, we stop sending — but the files already in your Dropbox, Drive, OneDrive or WorkDrive are yours and stay there. That is the point of the feature, and it is also a limit on what disconnecting achieves.
3. Business operations
This covers the business of selling and running LodgeHQ rather than the casework itself. Stripe is here because it does touch your clients: when you invoice a client through LodgeHQ, it receives that client’s email address and the description of your services.
| Sub-processor | Legal entity and country | Purpose | Data categories | Always on / firm-enabled | Where processed |
|---|---|---|---|---|---|
| Stripe | Stripe Payments Australia Pty Ltd (Australia), with Stripe Payments Europe, Limited (Ireland) as an additional party solely for processing personal data under the Stripe Services Agreement | Subscription billing, AI credit top-ups, add-on billing, and payment of your invoices by your clients | Subscriber: your account email address and billing details. Your client, where you send an invoice or booking payment through LodgeHQ: the client’s email address, the invoice number, the description of professional services, the GST line and the amount. Card details are entered on Stripe’s hosted page and never reach LodgeHQ. No documents. | Always on | Ireland (as the declared data-processing party) and Stripe’s global infrastructure. We do not set a region. |
4. What we do not do
This section exists because a register that only lists what we do use is half an answer. Both statements below are deliberate, and correct as at 4 August 2026.
We do not sell your data
We do not sell or rent personal information — yours or your clients’ — to anyone, and we do not disclose it to anyone for their own marketing purposes. We receive no payment or other benefit for any disclosure described on this page.
We do not train AI on your client files
We do not use client case data to train, fine-tune or improve any AI model, and we have not licensed any sub-processor to do so. Our AI features run on Amazon Bedrock; AWS’s published Bedrock terms state that Bedrock does not use inputs or outputs to train models and does not share them with model providers. Data from a connected mailbox is used only to deliver the send and email-filing features you switched on — it is not used for advertising, is not sold or transferred, and is not used to train generalised AI or machine-learning models. Our use of information received from Google APIs complies with the Google API Services User Data Policy, including its Limited Use requirements. The limit of that statement: where you connect one of your own accounts under section 2, what that provider does with data in your own tenancy is governed by your agreement with them. We are not a party to it and we cannot warrant it.
5. Objecting to a sub-processor
Integrations your firm enables (section 2). Disconnect it. An administrator can do this from LodgeHQ’s Settings without contacting us.
- Connected mailboxes — Settings → Email. Disconnecting revokes our tokens with the provider on a best-effort basis, deletes the stored connection and credentials, stops all further access, and purges synced mailbox content that has not been filed to a matter. Correspondence already filed to a matter stays in the case record, so that disconnecting an integration does not cut across your own file-retention obligations.
- Xero — disconnecting revokes our access grant with Xero and clears the stored connection. Records already written into your Xero organisation are yours and remain there.
- Cloud Mirror — disconnecting clears the stored access and refresh tokens from our systems and stops all further transfer, and we write a short note into the mirrored folder so that anyone looking at it knows the files have stopped updating. Two limits, both deliberate: it does not revoke our OAuth grant at the provider, so we recommend you also remove LodgeHQ from the connected-apps screen of that provider; and we keep the index of which files were already mirrored — file names and identifiers, not contents — so that reconnecting resumes rather than re-uploading everything. Files already mirrored remain in your own storage.
- Calendars and eWAY — disconnect in Settings; nothing further is transmitted.
There is no penalty and no consequence beyond losing that feature.
Core platform and business operations (sections 1 and 3). These are not individually optional, and we will not pretend otherwise. LodgeHQ cannot run without its hosting provider, its database, its mail relay or its billing processor. If you object to one of them, tell us at support@lodgehq.com.au. We will tell you within five business days whether we can accommodate the objection — for example by disabling an optional feature that uses that service for your firm, or by changing our own configuration; tell you plainly if we cannot; and where we cannot, treat it as grounds for you to terminate without penalty. We will not charge an early-termination fee.
Taking your data with you. An administrator can request a firm-wide export from within LodgeHQ at any time, whether or not you are leaving, and it keeps working after a subscription lapses. It runs as a background job and produces a single archive containing your records in both JSON and CSV, the uploaded document files themselves, and a manifest listing what is in the archive and anything the run could not include. Platform credentials and access tokens are stripped; your casework is not.
A note on the AI features. AI processing currently has no firm-level off switch. If your practice requires one, tell us — we are tracking the request, and we will say so on this page if and when it is built rather than describing it before it exists.
We would rather lose a subscription than misrepresent what a service does.
6. Notice before we add a sub-processor
Before we engage a new sub-processor that will receive client case data, we will publish the new entry on this page with an effective date, and give at least 30 days’ notice before that entry takes effect, by an in-app announcement visible to firm administrators and by email to every current administrator address we hold. During those 30 days you may object under section 5. If we cannot accommodate the objection, you may terminate without penalty and export your data.
Where a shorter notice applies. For a change that does not involve client case data — for example replacing a marketing or analytics tool — we will publish the change here within 10 business days of it taking effect, without advance notice. Emergency substitutions to restore service will be published here within five business days of the change, with the reason. We would rather commit to a period we will actually meet than to one that reads better.
7. Who maintains this page
- Accountable owner: Awais Nisar, Director, LodgeHQ Pty Ltd
- Contact: support@lodgehq.com.au
- Review cadence: quarterly, and on every occasion a production credential for a new external service is added
- Method of review: the register is re-derived from the production source code and the live production configuration, rather than read through from the previous version.
- Last full re-derivation: 4 August 2026
Why we are specific about this. Between March and August 2026 this list drifted twice: a provider we had stopped using stayed on it for three weeks, and services we had started using were never added. A list maintained by recollection will drift again. The commitments above — a named owner, a fixed cadence, and re-derivation from the running system rather than from the previous document — are the part of this page we ask you to hold us to.
8. Changes we have committed to and have not yet made
Everything in sections 1 to 4 describes the system as it runs today. This section is the opposite: it is work we have decided to do and have not done. Nothing here is a description of the current state. Each item is removed from this list, and this page reissued with a new date, when it is finished.
- Delete the copies written before the move to AWS Sydney, which remain in the object storage we used previously, and rotate the credentials for it. Not done.
- Establish and publish Zernio’s contracting entity and country. Not done. We have asked the vendor.
- Confirm and publish where the translation service actually runs. Not done. Until it is, that row stands as an overseas disclosure.
- Publish the translator panel that receives documents on a translation order, or a way for you to be told before you order. Not done.
- Confirm each contracting entity against the contract rather than against the vendor’s published terms, and mark each cell with which of the two it came from. Not done. See “Where the entity names come from” above.
Related pages
- Privacy Policy — including how personal information is collected, held and disclosed overseas
- Security — infrastructure, access control, certifications
- Terms of Service
Questions about anything on this page: support@lodgehq.com.au