CnX Modular
Back

Privacy Policy

CnX Modular Suite ComSafe Holdings Pty Ltd (ABN 17 640 122 149), trading as "CnX Modular"

Effective date: 10/07/2026 Last updated: 16/08/2026


1. Introduction and scope

1.1 This Privacy Policy ("Policy") explains how ComSafe Holdings Pty Ltd (ABN 17 640 122 149) ("ComSafe", "we", "us", "our") handles Personal Information in the course of operating its business, including its public marketing website (the "Website") and the CnX Modular Suite software platform (the "Suite" or "CnX"), which a User may access through a web browser or through the CnX Modular mobile application. This single Policy applies to both the Website and the Suite.

1.2 ComSafe treats the security and proper handling of Personal Information as a high priority. ComSafe has adopted the Australian Privacy Principles set out in the Privacy Act 1988 (Cth) (the "Privacy Act") as the standard by which it collects, holds, uses and discloses Personal Information, and this Policy describes how it applies them.

1.3 ComSafe has also chosen to follow the approach of the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act (see section 17). In respect of commercial electronic messages, ComSafe complies with the Spam Act 2003 (Cth) (the "Spam Act").

1.4 By using the Website or the Suite, you acknowledge that your Personal Information will be handled in the manner described in this Policy.

2. Who we are

2.1 ComSafe is an Australian proprietary company whose principal place of business is in New South Wales, Australia. ComSafe trades as "CnX Modular".

2.2 ComSafe develops and provides the Suite, which comprises modular safety and compliance software for Australian supply chain businesses.

2.3 Our contact details are set out in section 21 (How to contact us).

3. Definitions

In this Policy:

APPs means the Australian Privacy Principles set out in Schedule 1 to the Privacy Act.

Customer means a business or organisation that subscribes to the Suite under an agreement with ComSafe.

Personal Information has the meaning given in the Privacy Act: information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether or not true and whether or not recorded in a material form.

Personnel means the staff, drivers, contractors and other individuals whose records a Customer inputs into, or maintains within, the Suite.

Sensitive Information has the meaning given in the Privacy Act and includes, relevantly, health information about an individual.

User means an individual who is issued with login credentials to access the Suite (typically Personnel of a Customer).

Other capitalised terms are defined where they first appear.

4. Our two roles

4.1 ComSafe handles Personal Information in two distinct capacities, and it is important to understand the distinction.

4.2 Information ComSafe collects directly. ComSafe collects and holds Personal Information about its Customers and about the Users who access the Suite. ComSafe determines the handling of this information and is responsible for it.

4.3 Information a Customer inputs about its Personnel. Customers use the Suite to create and maintain records about their own Personnel. ComSafe holds that information on the relevant Customer's behalf. As between ComSafe and the Customer, the Customer is responsible for the lawfulness of what it inputs, including for giving its Personnel any collection notice required under APP 5, for obtaining any consent required (including for the collection of Sensitive Information), and for discharging its own privacy obligations to those individuals.

4.4 Accordingly, an individual whose records are held in the Suite but who does not hold a login should, in the first instance, direct any request to access or correct those records to the Customer that controls them (see section 15).

4.5 ComSafe's commitment. However Personal Information comes to be held by ComSafe, ComSafe applies the security standard in APP 11 to it and will handle any eligible data breach affecting it in the manner described in section 17.

5. Personal Information we collect

5.1 The categories of Personal Information handled through the Suite are set out below. Most of this information is about Customers' Personnel and is input by the Customer.

(a) Identity and contact information: name, preferred name, email address, mobile number, home address, job title or role, department, employment basis, start date and timezone.

(b) Account information: hashed password, last login time, and the timestamp at which terms were accepted.

(c) Driver licence information: driver, high-risk-work and dangerous-goods licence numbers, class, state and expiry.

(d) Driver work records: pre-start and other safety checks, shifts and breaks (work and rest hours), fuel and AdBlue records, trip compliance records, driver reviews, and infringement and defect notices.

(e) Contractor evidence: uploaded safety manuals and safety management systems, and insurance, accreditation and licence evidence (which may contain the names and signatures of the contractor's own staff).

(f) Contractor business profile: the contractor's legal and trading name, ABN, business structure, contact name, position, email and phone, and business address.

(g) Training information: enrolments, quiz scores, attendance and progress.

(h) Maintenance information: identity of the staff who performed and signed off maintenance work.

(i) Service-operation information:

(j) Sensitive Information: as described in section 6.

(k) Field photographs: photographs a User captures using their device camera and attaches to a safety check, fault report or incident record.

5.2 Website visitors. If you browse the Website, we collect standard server log information and any details you choose to submit through an enquiry or contact form so that we may respond. The Website does not use analytics services or tracking cookies.

5.3 Information we deliberately do not collect. Consistent with the principle of data minimisation, the Suite does not collect: date of birth (only the next-medical-due date is recorded); tax file numbers; bank account details; raw credit-card data (card payments are tokenised by PayWay); photo-identification scans (deliberately not permitted); next-of-kin or emergency-contact details; or biometric information.

6. Sensitive Information

6.1 The Suite holds certain Sensitive Information (chiefly health information), namely:

(a) medical due dates and uploaded medical certificates;

(b) fatigue-induction status and fatigue accreditation certificates or schemes;

(c) fitness-for-duty declarations (that the individual is rested, illness-free, substance-free and medication-free), together with a signature; and

(d) incident records, which may include details of injuries and of the persons involved and any witnesses.

6.2 Where ComSafe collects Sensitive Information directly, it does so only with the individual's consent (APP 3.3), or where the collection is required or authorised by or under an Australian law, or where another exception in APP 3.4 applies. Where a Customer inputs Sensitive Information about its Personnel (including, in the case of incident records, Sensitive Information about third parties such as injured persons and witnesses), the Customer is responsible for obtaining any consent required under APP 3 and for giving any collection notice required under APP 5. ComSafe holds that information on the Customer's behalf.

7. How we collect it

7.1 We collect Personal Information by the following means:

(a) Directly from you, when you register, log in and use the Suite, or when you contact us or submit a form on the Website;

(b) From a Customer, as most records in the Suite are about a Customer's Personnel and are input by the Customer; and

(c) Automatically, where certain technical information, such as IP address, device and browser details and login-session information, is collected when the Suite and Website are used.

7.2 Where it is reasonable and practicable to do so, we collect Personal Information directly from the individual concerned. Where a Customer inputs information about its Personnel, we collect that information from the Customer.

8. Why we collect, hold, use and disclose it

8.1 We collect, hold, use and disclose Personal Information for the following purposes:

(a) to provide the safety and compliance service, including maintaining records, issuing statutory and expiry reminders, and producing reports;

(b) to identify, verify and contact Users;

(c) to administer driver, fatigue, training and safety compliance;

(d) to bill for the service;

(e) to secure and maintain the integrity of the service;

(f) to provide support; and

(g) to provide safety and compliance consulting services, where a Customer has engaged ComSafe to provide them.

8.2 We use and disclose Personal Information only for a purpose set out in section 8.1; for a secondary purpose the individual would reasonably expect that is related to that purpose (or, in the case of Sensitive Information, directly related to that purpose); or as otherwise permitted or required by law. Direct marketing is addressed separately in section 11.

9. Disclosure to third parties

9.1 We do not sell Personal Information, and we do not disclose Personal Information to third parties for those third parties' own purposes without the Customer's express opt-in consent.

9.2 We disclose Personal Information to service providers engaged to help us operate the Suite, and only to the extent necessary for them to provide their services to us. These providers include:

(a) an Australian hosting provider, with which Suite data is stored;

(b) email delivery, which is handled within our Australian hosting environment rather than through any third-party or overseas email service; and

(c) PayWay (an Australian payment processor) for payment processing.

9.3 These service providers handle Personal Information only to provide services to ComSafe, under confidentiality obligations, and not for their own purposes.

9.4 A disclosure of Personal Information to ComSafe's AI provider occurs only where a Customer enables the optional AI feature, as described in section 10.

9.5 We may also use or disclose Personal Information where required or authorised by or under law, or where otherwise permitted under the APPs.

9.6 Sharing between Customers, at a Customer's direction. The Suite allows a Customer that engages transport operators (an Engaging Party) and a Customer that performs transport work (an Operator) to form a connection, so that the Operator can make compliance evidence available to the Engaging Party for Chain of Responsibility due diligence. Either party may send the invitation, and it has no effect unless the other party accepts it. An unaccepted invitation expires after 14 days, and either party may withdraw the connection at any time, after which the sharing described below stops.

9.7 While a connection is active, the Engaging Party may see the following about the Operator, and nothing else:

(a) documents the Operator has expressly made available to its engaging parties. This is a per-document opt-in choice of the Operator;

(b) a summary of the Operator's Master Code self-assessment, as totals by section and by Master Code Activity together with a plain read-out of each item's outcome. The Operator's individual answer selections, and any verbatim text taken from the Operator's own manuals, are not included;

(c) where the Operator has signed off its assessment, the fact that it was signed off, the date and the name of the individual who signed; and

(d) for each of the Operator's drivers, the driver's name, whether they hold a dangerous goods licence, whether they hold a fatigue accreditation, and whether their driver licence is current, expiring or expired. No other information, including licence numbers, exact expiry dates, or medical or health records, is disclosed to the Engaging Party.

9.8 This sharing happens because the Operator chooses to connect and chooses what to make available. ComSafe provides the mechanism; the decision to share, and the scope of it, remain the Operator's, and section 4.3 applies to the Personal Information the Operator has entered.

9.9 Individuals named in shared information. Where an Operator shares information under 9.7, that information may name the Operator's Personnel, including the individual who signed off an assessment and the drivers listed under 9.7(d). An Operator has an obligation to its Personnel to advise them that this information may be shared with the businesses that engage it, as part of the collection notice the Operator gives them under section 4.3.

9.10 Where a Customer invites another business to connect, the Suite collects the contact name, email address and business details supplied for the invitation, and uses them only to deliver and manage that invitation.

10. Overseas disclosure

10.1 Optional AI feature. The Suite includes an optional, opt-in artificial-intelligence feature that is off by default and is enabled only at the Customer's request and with the Customer's authorisation. Where a Customer enables this feature, the documents that the Customer submits to that feature for processing are disclosed to ComSafe's AI provider, Anthropic, in the United States, so that they may be read, used to pre-fill fields, and evaluated. This is an overseas disclosure for the purposes of APP 8.

10.2 The AI feature applies to the contractor Safety Assessment, which includes reading the safety policy and procedure documents a Customer uploads to it, and to the licence and medical-certificate auto-reader. Consequently, the content disclosed may include a Customer's complete safety policy and procedure documents, together with any Personal Information contained in them, such as the names, positions and contact details of the Customer's Personnel, as well as driver licence information and uploaded medical certificates.

10.3 Under ComSafe's agreement with the AI provider and the provider's applicable API terms as they apply to this feature, that content is not used to train the provider's models and is subject to the provider's limited data retention and processing terms. ComSafe does not control the provider's systems, but takes such steps as are reasonable in the circumstances, in accordance with APP 8.1, in relation to this disclosure.

10.4 Where the AI feature is not enabled, the relevant information is entered manually and no such overseas disclosure occurs.

11. Direct marketing

11.1 We use contact details for direct marketing consistent with APP 7 and the Spam Act, to provide support and to send service communications and product-update communications (for example, notice of new modules).

11.2 We send commercial electronic messages on the basis of your consent (whether express, or inferred from an existing customer or service relationship). Each such message includes a means of identifying ComSafe as the sender and a functioning unsubscribe facility, consistent with the Spam Act. You may opt out of receiving marketing communications from us at any time, using the unsubscribe facility in the relevant message or by contacting us using the details in section 21.

12. Data security

12.1 ComSafe takes such steps as are reasonable in the circumstances, in accordance with APP 11, to protect the Personal Information it holds from misuse, interference and loss, and from unauthorised access, modification or disclosure. Those steps include the following.

(a) Encryption in transit. All traffic to and from the Website and the Suite is encrypted using HTTPS/TLS, with HTTP Strict Transport Security (HSTS) enforced.

(b) Encryption at rest. ComSafe applies field-level encryption at rest to a defined set of sensitive fields: home address, mobile number, and driver, high-risk-work and dangerous-goods licence numbers. Uploaded documents (for example, medical certificates and licence evidence) are stored as encrypted files on a private, non-public store and are served only after access-control checks.

(c) Passwords. Passwords are hashed and are not stored in plain text.

(d) Tenant isolation. There is strict logical separation between different Customers' data (multi-tenant isolation).

(e) Audit log. A tamper-evident audit log is maintained.

12.2 Access by ComSafe personnel. ComSafe personnel may access a Customer's data within the Suite where it is necessary to provide support, to investigate or resolve a technical issue, or to carry out consulting services that the Customer has engaged ComSafe to provide. Access is limited to those personnel who require it for those purposes.

Where ComSafe acts as a safety and compliance consultant to a Customer, that engagement involves reviewing the Customer's compliance records, including Personnel records such as driver licence details and medical certificates, in order to confirm that the correct and current document is held and that the record is complete, and correcting or completing those records as part of that work. For that purpose, ComSafe personnel hold the same level of access within the Customer's organisation as the Customer's own administrators, which includes creating, amending and deleting records. Access of that kind is inherent in the consulting service and is available to ComSafe for the duration of the engagement, so that a Customer can obtain assistance at the time they need it. Activity within the Suite is recorded in the change-history audit log referred to in section 12.1(e).

12.3 No absolute guarantee. No method of transmission over the internet, or of electronic storage, is completely secure. Encryption at rest mitigates the risk arising from theft of storage media or backups; it is not a guarantee against compromise of the running application. While we take reasonable steps to protect Personal Information, we cannot guarantee its absolute security.

13. Data quality

13.1 We take such steps as are reasonable in the circumstances to ensure that the Personal Information we collect is accurate, up to date and complete, and that the Personal Information we use or disclose is, having regard to the purpose, accurate, up to date, complete and relevant, in accordance with APP 10.

13.2 Because much of the information in the Suite is input and maintained by Customers about their own Personnel, the accuracy of that information depends in part on the Customer. If you believe information we hold about you is inaccurate, please contact us, or your organisation, as set out in section 15.

14. Retention and destruction

14.1 We retain Personal Information while a Customer's account is active.

14.2 Deletion of Personal Information is performed manually upon a verified request; it does not occur automatically on cancellation of an account.

14.3 Following cancellation, ComSafe retains Personal Information only for as long as it is needed for a permitted purpose or is required by law to be retained, pending any verified deletion request, and periodically reviews retained Personal Information for destruction or de-identification in accordance with APP 11.2.

14.4 The change-history audit log is purged automatically after a configured period (6, 9 or 12 months).

14.5 Where ComSafe or a Customer is required by law to retain particular records (for example, driver work and rest records under the Heavy Vehicle National Law as applied in participating jurisdictions, or work health and safety incident records), those records are retained in identifiable form for the period required by law and are then destroyed or de-identified.

14.6 In accordance with APP 11.2, where we no longer need Personal Information for any purpose for which it may be used or disclosed, and we are not required by law to retain it, we take such steps as are reasonable in the circumstances to destroy it or to ensure that it is de-identified.

15. Access and correction

15.1 Individuals with a login. If you hold a login to the Suite, you may access and correct your own profile and documents directly within the Suite.

15.2 Individuals without a login. If you do not hold a login, the organisation that controls your record (the relevant Customer) handles access and correction on your behalf. You should contact that organisation in the first instance.

15.3 Requests to ComSafe. You may also make a request for access to, or correction of, Personal Information to ComSafe using the details in section 21. We will verify your identity and respond within a reasonable time (generally within 30 days). The grounds on which we may refuse access or correction, and our obligation to give written reasons for a refusal, are as set out in APP 12 and APP 13 respectively.

16. Anonymity and pseudonymity

16.1 APP 2 provides that individuals may have the option of dealing with an entity anonymously or by pseudonym. Because the Suite is an identity-based compliance record system in which records must be attributable to identified individuals, it is generally impracticable for us to deal with Users, or with individuals whose records are held in the Suite, anonymously or by pseudonym.

17. Notifiable data breaches

17.1 As a matter of good practice, we voluntarily follow the approach of the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act, even though we are not required to do so.

17.2 If we suspect that an eligible data breach involving Personal Information we hold may have occurred, we will assess the matter and, where that approach calls for it, notify the affected individuals and the Office of the Australian Information Commissioner (OAIC).

18. Complaints

18.1 If you have a complaint about how we have handled your Personal Information, please contact us using the details in section 21. We will acknowledge your complaint and respond within a reasonable time (generally within 30 days).

18.2 If you are not satisfied with our response, you may refer your complaint to the OAIC. The OAIC's current contact details are available at oaic.gov.au.

19. Changes to this policy

19.1 We may update this Policy from time to time to reflect changes to the Suite, our practices, or legal requirements. The current version is identified by the "Last updated" date at the top of this Policy, and the updated Policy takes effect from the date of publication. We encourage you to review this Policy periodically.

20. Governing law

20.1 This Policy is governed by, and is to be construed in accordance with, the laws of New South Wales, Australia.

21. How to contact us

ComSafe Holdings Pty Ltd (trading as CnX Modular) ABN 17 640 122 149

If you wish to contact our office responsible for privacy matters, or make a request or complaint under this Policy, please use the details above.