Who is responsible for your data
TurnProof is operated by SISR consulting of Queensland, Australia. SISR consulting is the data controller for the personal data described in this notice. You can reach us at sisrconsulting@gmail.com.
// Legal · Privacy Notice
Last updated 6 September 2026
This notice explains what personal data SISR consulting collects through TurnProof, why we collect it, who we share it with, and the rights you have over it.
TurnProof is operated by SISR consulting of Queensland, Australia. SISR consulting is the data controller for the personal data described in this notice. You can reach us at sisrconsulting@gmail.com.
This notice covers hosts who hold accounts, and people who use property access codes or links we call “crew access” — cleaners, maintenance workers, lawn and garden crews and other contractors completing a report on a host's behalf. It also touches on guests, who may appear incidentally in evidence photos taken at a property; we do not collect anything directly from guests.
We share personal data only with the categories of recipients below, never for their own marketing:
Evidence photos are stored for 90 days from the moment the report is submitted, then permanently deleted. Before the deadline we show countdowns in the workspace and send reminder emails to the host. Hosts are expected to download the high-resolution PDF records during that window; the PDFs are the host's permanent archive.
Report text, checklists, server timestamps, submitter identity and SHA-256 hashes are kept indefinitely, because they are what make an archived photo verifiable years later.
Account data is kept while your account is open, and for a short period afterwards to handle any follow-up, then deleted or anonymised. Billing records are kept for the period required by Australian tax and commercial law. Data that is no longer needed is deleted or anonymised.
We use appropriate technical and organisational measures to protect personal data, including encryption in transit and at rest, access controls so a host's evidence photos can only be opened by that host (or via the specific links they share), and immutable records that cannot be quietly altered after submission. No system is perfectly secure, but we design the platform so that tampering is detectable.
TurnProof uses only strictly necessary cookies and equivalent browser storage: keeping you signed in, securing forms, and remembering workspace preferences. We do not use advertising or cross-site tracking cookies. You can clear or block these in your browser settings, but the workspace needs them to function.
Our service providers may process data outside Australia, including in the United States and the European Union. Where personal data leaves the UK or EEA, we rely on appropriate safeguards such as the European Commission's standard contractual clauses or an adequacy decision for the destination country.
Under the Australian Privacy Principles, you can ask us for access to the personal data we hold about you, ask us to correct it, and complain if you think we have mishandled it. We respond to requests and complaints within a reasonable time.
If you are in the UK or EEA, you additionally have the right to: access your data; rectify inaccurate data; erase data; restrict or object to processing; data portability; withdraw consent where processing is based on consent; and lodge a complaint with your local supervisory authority. We respond within one month.
To exercise any of these rights, email sisrconsulting@gmail.com. If you are unhappy with our response, you can complain to the Office of the Australian Information Commissioner (oaic.gov.au) or your local supervisory authority.
We may update this notice as the service changes. The “last updated” date at the top shows the current version, and material changes will be highlighted in the workspace.