Privacy policy
The QA Portal is the quality-assurance system Supreme Precast uses on its jobs, on the web and in its iPhone app, which shows the same portal. This page sets out what they store about the people who use them, where it is kept, and who can see it.
Last updated 9 October 2026. It applies from the day it was published on this page.
Who has an account
There is no public sign-up. Every account is created by an administrator at Supreme Precast.
What is stored about you
- Your name, the username you sign in with, your role, and which parts of the portal you have been given access to.
- Your password, stored only as a one-way hash, so nobody — administrators included — can read it. An administrator can set a new password for you.
- The work you record: QA reports and defects, with your answers, comments and measurements, the photographs you take or choose, any mark-up you draw on them, the signatures you draw, and documents you attach.
- The name and contact details of anybody who countersigns a report, when they are entered.
- A history of who created, changed, reviewed, signed or closed each report and defect, and when.
- Which jobs and forms you have been rostered to on a given day, and the notifications you have chosen to receive.
- For a report or defect filled in with no signal and sent later: the time the phone says it was filled in, and the name of the person who was signed in on the phone at the time. Both are recorded as the phone’s own claim.
- In the server’s own log: a username that has failed to sign in ten times within a quarter of an hour; the username of an administrator who signs everyone out, and when; how long each download took; and the addresses and text of any email that was not sent because no email service is set up.
- The portal itself stores no IP addresses in its records. When the web server in front of it cannot pass a request on to the portal — for example during the minute or so while an update is being installed — it writes that request’s IP address, the address asked for and the browser’s details to its own error log.
The web server’s error log and the portal’s own log are each capped at about 30 MB: once that fills, the oldest lines are deleted as new ones are written.
Location and photographs
The portal and the app never ask your phone or computer for your location.
A photograph taken or chosen in the portal is redrawn on the phone and saved as a new picture before it is sent, which leaves behind the location and camera details stored inside the original. If a phone cannot redraw a picture, it is sent as it is, with those details still inside it.
A document attached as a file — including a photo attached as a document — is stored exactly as it was uploaded, with any details stored inside it, which for a photo can include where it was taken.
Cookies, and what is kept on your phone
The portal uses cookies only to sign you in and keep you signed in. There are no advertising, analytics or tracking cookies.
So that work can carry on with no signal, the phone keeps reports and defects waiting to be sent, with their photographs and signatures; what you are part-way through filling in; and copies of the pages you need with no signal.
- Copies of pages are kept for the person signed in. They are deleted when that person signs out, when somebody else signs in on the phone, or when the phone next reaches the portal after an administrator has ended that person’s session. Until then they open on that phone with no signal, so sign out before handing a phone on.
- Work waiting to be sent stays on the phone, even after a sign-out, until it is sent or somebody discards it. It is sent only when the person who filled it in is signed in on that phone. Anybody else signed in on the phone can see that it is waiting, what it is, which job and level it belongs to and who filled it in, and can discard it. Something the portal refused to accept stays until it is tried again or discarded.
- Something part-way filled in and left unchanged for seven days is deleted from the phone.
- Deleting the app, or clearing the website’s data in the phone’s settings, deletes anything still waiting to be sent.
In the iPhone app, a report you download is saved inside the app so you can open it.
Downloaded reports are deleted from the phone when you sign out, when somebody else signs in on it, and seven days after they were downloaded. A copy saved or sent out of the app — to Files, email or another app — is outside the portal, which cannot delete it, and it carries the same names, signatures and details as the report.
Where it is kept
The portal runs on servers in Sydney, Australia, provided by Amazon Web Services (AWS). Photographs and documents are kept in private storage that is not open to the public: the portal gives a signed-in user a link to one that stops working after five minutes.
The whole database is copied to the same private storage every night as a backup. Archives of a day’s reports that the portal saves for downloading are kept for 30 days.
Nightly backups are kept for 90 days and then deleted.
Who can see it
- People at Supreme Precast who use the portal, according to the access an administrator gives each account. A report you have filed can be read by other signed-in users; one you have not finished is seen only by you and by people an administrator allows. Administrators can see everything.
- Printed reports (PDFs) carry names, signatures, photographs, attached documents and the contact details of anybody who countersigned. The company gives them only to the builder — the client — of the job they belong to.
- The portal can send an end-of-day email summarising flagged issues and reports to addresses the company chooses. It is switched off. Before it is switched on, this policy will be updated to name the email service that sends it.
- The only outside service involved is Amazon Web Services (AWS), which hosts the portal and stores its files. AWS stores and processes the information on behalf of Supreme Precast, under AWS’s standard terms, which do not allow AWS to use it for its own purposes.
- Nothing is sold. There is no advertising, no analytics and no tracking, and nothing is shared with anybody for marketing.
How long it is kept
A report, defect, job or account deleted in the portal goes to the Recycle Bin, where an administrator can restore it, and is removed for good after 30 days: its record is removed from the database, and the photographs, signatures and documents it held are deleted from storage, unless another record still uses them. The history of who made and changed a report or defect, and when, is kept. A photograph, signature or document that was taken off a report or defect, or replaced, can stay in the portal’s private storage after the record itself is removed. Copies of removed records stay in the nightly backups until those expire, after 90 days. Some things are deleted at once and never go to the Recycle Bin — a day’s roster, for example.
QA records name the people who made them. The reports, defects and history you created keep your name after your account is closed. You can ask for your account to be deleted at any time (Support → Deleting your account): an administrator closes it, which takes effect at once, and it can be deleted once none of the QA records it made is kept any more.
QA records are the company’s record of how the work on each job was done and checked. They are kept for at least one year after the job is complete.
Your information and your choices
You can change your password, and which notifications you receive, on your account page once you are signed in.
You can ask for your account to be deleted at any time. Deleting your account on the Support page says what then happens to it, and to the records you made.
To ask for a copy of the information held about you, to have it corrected, or to have your account deleted, email qa@supremeprecast.com.au. Supreme Precast answers within 30 days.
Supreme Precast
ABN 96 647 781 146
12/50 Bakers Road, Coburg North VIC 3058
Email: qa@supremeprecast.com.au