Who else can see your data
Everyone involved in running this service, what each one can actually see, and where it is. Written from what a provider can see rather than what it is meant to see — a hosting provider that never opens a database still runs the process that reads every row into memory, and that is the disclosure a customer is entitled to know about.
This is one list, and both the privacy policy and the data processing agreement are generated from it. A sub-processor added to one document and not the other is a false document, and that is the commonest way a set of these goes wrong.
Supabase
What it does: Database, file storage and sign-in.
What it can see: Every record in the system — customers, contacts, instruments, readings, certificates, invoices — and the stored PDFs.
Where: Sydney, Australia (ap-southeast-2). Supabase Inc is incorporated in the United States. (Australia)
Data at rest never leaves Australia. The corporate parent is American, which is a different question from where the data is, and both are stated because procurement asks about both.
AWS App Runner
What it does: Runs the application, and the public marketing website.
What it can see: Reads records into memory to render pages, certificates and invoices. It does not store or log them to disk, but it can see them in memory.
Where: Sydney, Australia (ap-southeast-2). (Australia)
The end of ADR 0009. Records are now stored in Australia *and* processed in Australia — two claims a procurement questionnaire asks separately, and which this system had to answer differently until 25 August 2026. Moving was a deployment rather than a migration, because nothing in the software names a host.
Hostinger
What it does: The mailbox this business receives mail at.
What it can see: Nothing from any laboratory’s records — it runs neither the application nor the marketing site and cannot reach the database. What it does hold is mail sent *to* us: an enquiry, or a privacy request sent to the address named in this policy.
Where: Asia. Hostinger has no Australian data centre; its Sydney presence is a cache for static files. (outside Australia)
Until 25 August 2026 this ran the application, which is what ADR 0009 was about and what `npm run activation` reported as the difference between storing records in Australia and processing them there. That is finished. Somebody who would rather not send us a privacy request through an offshore mailbox can post it to the address at the top of this document.
SMTP2GO
What it does: Delivers recall notices, certificates, quotes and invoices.
What it can see: Recipient name and address, the subject line, and the message — which for a certificate or invoice includes the customer’s name and the instrument concerned.
Where: Sydney, Australia. SMTP2GO Ltd is incorporated in New Zealand. (Australia)
Sends from their Sydney data centre (mail-au.smtp2go.com). Replaced Amazon SES on 1 September 2026, which had itself replaced Brevo in the European Union a week earlier — AWS declined twice to lift the SES sending sandbox, so no message could reach a laboratory’s own customer. Recipient addresses stay in Australia either way, which is the point of both moves. Plain SMTP throughout rather than a vendor API, which is what makes changing provider a matter of credentials rather than of software — three times now.
Brevo — not yet connected
What it does: Sends our own marketing email from the commercial website.
What it can see: The name and address of somebody who asked us to keep in touch through calibraworks.com, and whether they opened what we sent. **No laboratory record and no laboratory’s customer.** A prospect who has not become a customer is the only person in this list.
Where: European Union. (outside Australia)
Deliberately kept apart from the mail a laboratory sends. Marketing and transactional mail share a sending reputation when they share a domain, and a complaint rate earned by a product announcement would then be paid for by a recall notice landing in a spam folder — which is a missed recall, and the one failure in this system that has a safety consequence rather than a commercial one. So this must send from its own subdomain, never from calibraworks.com itself, and it is not connected until that subdomain exists.
Stripe
What it does: Takes the laboratory’s subscription payment, and card payments from its customers.
What it can see: Billing name, email and card details. Card numbers never reach this system — they are entered on Stripe’s own hosted page.
Where: United States and Australia. (outside Australia)
A laboratory’s takings settle to its own bank account through its own Stripe account, and never pass through a platform-held account. That separation is deliberate: money landing in a platform account and being paid out later would make the platform a payment facilitator, with AUSTRAC and possibly AFSL consequences.
Amazon Bedrock
What it does: Reads a customer’s written list of instruments into intake lines a person then confirms, and drafts the text of a laboratory’s calibration procedure for its staff to edit and approve.
What it can see: For intake, only the text somebody pastes into the intake screen — typically an instrument list, which may carry a contact name if the customer signed their email (ADR 0018). For a procedure draft, only the laboratory’s own method records: the instrument type, its measurement model and check plan, its reference standards and decision rule, and any notes the laboratory adds — never a customer, instrument, reading or certificate (ADR 0023). Each is sent, read, and answered. No record, reading, certificate or price is sent, and none can be.
Where: Australia: Sydney (ap-southeast-2) for a region-direct model, or Sydney and Melbourne through an au. profile. Any profile that could route abroad is refused by configuration. (Australia)
Both features are switched on by naming a model; production names Google Gemma 3 27B, region-direct in Sydney, and the application’s role may call that model and no other. Amazon is the processor; the model’s author does not receive the requests. A pasted spreadsheet is still read by splitting it — no model at all — and a procedure can always be written by hand.