Legal
AirStaff privacy policy
The document of record, published in full. Version 1.1, effective 22 September 2026.
Version 1.1 — effective 22 September 2026 (screenshot default changed to detailed low-resolution)
Who we are: Open Pantry Tech Pty Ltd trading as AirStaff, info@airstaff.net.
The two hats we wear
- For account data (names, emails, passwords, billing, support tickets) we decide how data is used — we act as the controller.
- For staff monitoring data (tracked time, activity, screenshots, app/site usage) we process it on the employer's instructions — the employer is the controller and we are the processor. Staff questions about why monitoring happens go to the employer; questions about how AirStaff stores it can come to us.
What the agent collects — and what it never collects
Collected (only after the staff member accepts the monitoring notice, and only while clocked in): 10-minute time slots with keyboard/mouse counts (never keystroke contents), activity percentages, periodic screenshots (detailed but low-resolution by default; the employer can choose blurred or off, and staff see the mode in their notice and on My data), active app name and browser domain (not full URLs unless the employer enables URL tracking — staff see the setting), agent version and device check-ins.
Never collected: keystroke contents, webcam or microphone, files, message contents, anything while clocked out.
Consent and notice
Tracking is blocked until the staff member accepts a monitoring notice. Notice periods are enforced by jurisdiction (e.g. 14 days in NSW). Sending an updated notice pauses tracking until re-acceptance. Staff can view their own data, request corrections or deletion, and download everything AirStaff holds about them ("My data" → download).
Retention
- Screenshots: employer-set cap, 60 days included (7–180 configurable; >60 days is a paid add-on). Auto-deleted nightly.
- Raw 10-minute slots: rolled up to daily summaries after 90 days, then deleted.
- Account deletion: all organisation data purged within 30 days.
- Sent email bodies are scrubbed after delivery; credentials are stored only as cryptographic digests.
Where data lives and who touches it
Hosted on Amazon Web Services (Sydney region): S3 (screenshots), RDS Postgres (records), SES (email). Payments: Stripe (we never store card numbers). Marketplace fulfilment (e.g. AppSumo) receives only code-redemption status. Help-centre chat: PrimeCX/aicxagent widget (loads only on the Help screen).
Security
Passwords hashed with scrypt; session, invite, consent and device tokens stored as SHA-256 digests only; TLS in transit; tenancy isolation enforced on every query; rate limiting and captcha on public endpoints; audit logging of privileged actions.
Your rights
Access, correction, deletion, portability and complaint — email info@airstaff.net. Staff monitoring-data requests are routed to the employer where the employer is the controller; AirStaff provides the tooling (self-serve download, deletion requests). Australian users have rights under the Privacy Act 1988 (Cth) and the Australian Privacy Principles; EU/UK users have the equivalent GDPR/UK-GDPR rights where those laws apply.
Breach notification
We notify affected customers and, where required, regulators without undue delay after becoming aware of an eligible data breach.
Changes
Material changes are emailed to account owners 14 days ahead.
Questions about any of this?
Email info@airstaff.net and a person will answer.