Sub-processor Register

LodgeHQ Pty Ltd · ABN 52 696 192 677 · 12 Rindle Street, Lara VIC 3212

Last updated:
4 August 2026
Last reviewed against the running system:
4 August 2026
Next scheduled review:
4 November 2026

What this page is

LodgeHQ is a case-management platform for Australian registered migration agents. To run it we use a number of third-party services. Some of those services receive personal information belonging to your clients — the people whose visa matters you manage in LodgeHQ.

This page lists them: the legal entity, the country, what the service is for, what data it receives, whether you can switch it off, and where the processing happens.

We publish it because you cannot properly assess a supplier you cannot see. If you are completing a due-diligence questionnaire, a professional indemnity disclosure, or a collection notice for your own clients, this page is where the detail comes from.

How this register was compiled. It was derived on 4 August 2026 from the production source code and the live production configuration — not from an internal wiki, and not by reading the previous version of the list. Where LodgeHQ authenticates to a service, that service is listed only if a working credential for it exists in the running production environment. Where no LodgeHQ credential is involved — an unauthenticated public API, a service your own firm supplies the credentials for, a browser push service your browser chooses, or a government system — the test is whether a production code path sends data there. Both kinds appear below.

On completeness. We believe this list is complete as at the date at the top of the page, and section 7 sets out how it is kept that way. Where we know it is not complete, the table says so rather than leaving a gap — the individual translators who complete a translation order are the current example.

Where the entity names come from. Which service receives what, and whether it is live, is derived from the running system, and we stand behind those columns. The legal entity column is different in kind: a contracting entity cannot be read out of our own configuration, so unless the cell says otherwise those names are taken from the vendor’s own published terms, data-processing addendum or privacy notice as at the date at the top of this page — not from an invoice or an order form we hold, and not independently confirmed against a corporate register. Group structures change, and the acquisition of a vendor can change the contracting entity without changing anything we would see. If you are relying on a specific entity name for your own assessment, ask us at support@lodgehq.com.au and we will confirm it from the contract or tell you plainly that we cannot.

Where this sits in the Privacy Act. This page is how we give effect to Australian Privacy Principles 1.4(f) and 1.4(g) — the kinds of personal information we disclose to overseas recipients, and the countries they are in. It is the detail behind the overseas-disclosure section of our Privacy Policy (APP 8), and it exists so that you can see what we disclose and to whom before you decide whether our security arrangements are reasonable for your practice.

What this page is not. It is not advice about your own obligations. Where you connect one of your own accounts to LodgeHQ, we are not telling you where the APP 8 accountability line falls for your practice, because that depends on your arrangements and not on ours. We are telling you exactly what is sent and to whom, so that you can decide.

How to read the table

Sub-processor — a third party that stores or handles personal information on our behalf, or on your behalf at your direction.

Always on means the service is part of how LodgeHQ works. You cannot switch it off and keep using the platform. Firm-enabled means nothing is transmitted until an administrator at your firm connects an account.

Client case data means information about your clients: names, dates of birth, passport and travel-document numbers, transaction reference numbers, addresses, questionnaire answers, file notes, and uploaded documents such as passports, birth certificates, police clearances and English-test results.

Where processed. Where we can prove the region from configuration, we state it. Where we cannot, we say so and treat the service as an overseas disclosure. We do not describe a service as Australian because its vendor has an Australian office, and we do not treat an edge or content-delivery point of presence as a storage location.

LodgeHQ stores your practice’s records, your clients’ records and your uploaded documents in Australia — on Amazon Web Services infrastructure in the Sydney region (ap-southeast-2) — and AI processing runs on Amazon Bedrock in Australia (Sydney and Melbourne, ap-southeast-4). Some data does leave Australia. It leaves through parts of the platform that are always on — outbound email and its attachments, card payments, SMS and WhatsApp, browser push notifications, and document translation — and it leaves through optional integrations your practice chooses to connect, such as a mailbox, a calendar, an accounting connection or a cloud-storage mirror. Which data leaves, to which recipient, in which country and for what purpose is set out in the cross-border disclosure section of our Privacy Policy.

1. Core platform — always on

These are our own supplier choices. They apply to every firm on LodgeHQ and cannot be switched off firm by firm.

Sub-processorLegal entity and countryPurposeData categoriesAlways on / firm-enabledWhere processed
Amazon Web ServicesAmazon Web Services Australia Pty Ltd, ABN 63 605 345 891 (Australia) — the Australian contracting party under the AWS Customer AgreementApplication hosting, the production database, document storage, secrets management and system loggingAll client case data, including the raw uploaded document files. All firm and user account data.Always onAustralia — Sydney (ap-southeast-2). The database has no public endpoint. Documents are encrypted at rest.
Amazon Bedrock (AI inference)Amazon Web Services Australia Pty Ltd (Australia). The models are Anthropic’s Claude family. Anthropic PBC does not receive the data — see the note below the table.Document data extraction, letter and email drafting, questionnaire generation, eligibility assessment, in-app support answers, semantic search, and form-field mapping for the eLodge extensionMatter context (client name, date of birth, passport number, transaction reference number, visa subclass, grant and reference numbers, fees, file notes, deadlines) and, for extraction, the raw bytes of the document being readAlways on. AI features are metered per firm, but there is no firm-level switch that disables AI processing.Australia — Sydney and Melbourne (ap-southeast-2 / ap-southeast-4). Production uses the au. Bedrock inference profiles, which resolve only to Australian regions. That is a configuration setting rather than a physical constraint: if we ever change it, this page changes before it does.
Google Workspace — outbound mail relay and our support mailboxGoogle LLC (United States) operates the infrastructure. Where an Australian contracting entity applies to a Workspace subscription that entity is Google Australia Pty Ltd; the relay and mailbox infrastructure is Google LLC’s in either case.(i) Sending every email LodgeHQ generates: portal invitations, questionnaire links, document requests, invoices, signature requests, deadline digests and support replies. (ii) Hosting support@lodgehq.com.au, the mailbox you reach us on.(i) Recipient email address, sender, subject, the full message body, and any attached file — which includes invoices, signed service agreements and generated letters. (ii) Anything you send us by email, including attachments. If you email us a screenshot or a document from a client file, it is stored in that mailbox.Always onOverseas. smtp-relay.gmail.com is a global endpoint. We have not set a Workspace data region, so we do not claim one.
TwilioTwilio Australia Pty Ltd (Australia); group parent Twilio Inc. (United States)SMS and WhatsApp messages sent from LodgeHQ to your clientsSending number, destination mobile number and the full message body. Message bodies routinely contain a client’s name, matter reference, appointment time or deadline.Always on wherever a firm sends SMS or WhatsApp from the platformOverseas. We call api.twilio.com, Twilio’s global endpoint. We do not use an Australian regional edge.
LodgeHQ translation service — translate.lodgehq.com.au, running on RailwayThe service is operated by LodgeHQ Pty Ltd (Australia). The underlying hosting platform is Railway Corp. (United States).Instant translation quotes and NAATI translation ordersRaw client document files — passports, birth and marriage certificates, police clearances — plus file names, languages, page counts and order detailsAlways on as a platform feature; used per order, at the agent’s electionNot confirmed. Treated as an overseas disclosure. Railway does not publish an Australian container region, and the Melbourne edge identifier in its response headers identifies a point of presence, not where the container runs. We will state the region here when we can prove it, and until then this row stands as an overseas disclosure.
NAATI-certified translators (downstream of the translation service)Individual NAATI-certified translators and translation providers engaged to complete an order. We do not currently publish the panel.Performing a translation you orderThe client document being translated, and the translated document produced from itUsed per order, at the agent’s electionNot published. If you need to know who will handle a particular document, or in what country, ask us before you place the order.
CloudflareCloudflare, Inc. (United States)Authoritative DNS for lodgehq.com.au, and TLS termination in front of the translation serviceFor the application: none. app.lodgehq.com.au and lodgehq.com.au resolve directly to AWS, so Cloudflare is not in the application’s live data path. For the translation service: Cloudflare terminates TLS and therefore sees the request contents, including document files. Separately, Cloudflare still holds historic copies of documents in our former R2 storage bucket — see section 4A.Always onCloudflare’s global network. An edge point of presence is not a storage location.
Web push services — Google (Chrome), Mozilla (Firefox), Apple (Safari), Microsoft (Edge)Determined by each user’s own browser; we do not choose or contract with the serviceBrowser notifications to agentsThe browser-assigned push endpoint, and a payload that is encrypted end-to-end to that browser. The push service sees ciphertext and routing metadata only.Always on where an agent turns notifications onOverseas (global).
Have I Been Pwned — Pwned Passwords range APIOperating entity not confirmed. The service is publicly operated from Australia and is served through Cloudflare, Inc. (United States).Checking a chosen password against known breach corpora at sign-up and password resetThe first five characters of a SHA-1 hash, plus our server’s own IP address — nothing else. The check is made by our server, not by your browser, so no user IP address is sent. The password never leaves our server, and neither does the full hash. This is a k-anonymity lookup: the service cannot tell which password was checked.Always onOverseas (global). No personal information is transmitted.
Department of Home Affairs — ImmiAccount (via the eLodge browser extension)Commonwealth of Australia, Department of Home AffairsPrefilling ImmiAccount application forms from LodgeHQ dataClient name, date of birth, passport number, address, family and employment history — written into the form fields in the agent’s own browser. The extension prefills; it does not submit.Always on where an agent installs the extensionAustralia.

Note on Amazon Bedrock and Anthropic. Anthropic is the vendor of the Claude models we run, but under Amazon Bedrock, Anthropic is not a recipient of your data. AWS operates the model deployment accounts, and AWS’s published Bedrock terms state that model providers have no access to those accounts, to Bedrock logs, or to customer prompts and completions, and that Bedrock does not share inputs or outputs with model providers or use them to train models. We name Anthropic here because you should know whose model is reading your client’s passport; we do not list Anthropic as a recipient because it is not one.

Note on the Department of Home Affairs. DHA is not a sub-processor of ours — it is the regulator you lodge with, and the disclosure to it is one you make. We list it because omitting it from a register of where client data goes would be misleading.

2. Integrations your firm enables

Nothing in this section transmits anything until an administrator at your firm connects an account. When you connect one, you are choosing the recipient, and in most cases the destination is your own tenancy — your Dropbox, your Microsoft 365, your Xero. Your agreement with that provider governs where the data lands. We do not verify or control the region of an account you connect, and we cannot give you any assurance about what that provider does with the data once it arrives. We list them anyway, because they are still disclosures of your clients’ personal information and your clients are entitled to know they exist.

Sub-processorLegal entity and countryPurposeData categoriesAlways on / firm-enabledWhere processed
Dropbox (Cloud Mirror)Dropbox, Inc. (United States); customers outside the United States and Canada contract with Dropbox International Unlimited Company (Ireland)One-way copy of your matter files into your own DropboxThe full case file — client documents, agent documents, questionnaire PDFs, e-signed documents, service agreements, generated letters, invoices and deposit requests — in folders named for the client and matterFirm-enabledYour Dropbox account. Overseas unless you have arranged otherwise with Dropbox.
Google Drive (Cloud Mirror)Google LLC (United States), or Google Australia Pty Ltd where your own Workspace agreement so providesAs above, into your Google DriveAs aboveFirm-enabledYour Google account. Region governed by your own Workspace configuration.
Microsoft OneDrive / SharePoint (Cloud Mirror)Microsoft Corporation (United States); many non-US customers contract with Microsoft Ireland Operations LimitedAs above, into your OneDrive or a SharePoint document libraryAs aboveFirm-enabledYour Microsoft 365 tenancy. Region governed by your own tenancy configuration.
Zoho WorkDrive (Cloud Mirror)Zoho Corporation Pty Ltd (Australia) operates the Australian data centres; group parent Zoho Corporation Private Limited (India)As above, into your Zoho WorkDriveAs aboveFirm-enabledWe connect to Zoho’s Australian data centre by default (accounts.zoho.com.au, zohoapis.com.au). This is the only mirror destination that is Australian by our configuration. Where the data ultimately rests is governed by your own Zoho account region, which we do not verify.
Gmail — connected firm mailboxGoogle LLC (United States), or your own Workspace contracting entitySending client correspondence from your own address, and filing inbound mail to the right matterFull email bodies, headers, recipients and attachments, in both directionsFirm-enabled, per mailboxYour Google tenancy.
Microsoft Outlook / Microsoft 365 — connected firm mailboxMicrosoft Corporation (United States), or your own M365 contracting entityAs aboveAs aboveFirm-enabled, per mailboxYour Microsoft 365 tenancy.
IMAP — any other connected mailboxYour own mail host, whoever that isAs above, for mail providers that are neither Google nor MicrosoftFull message content and attachmentsFirm-enabled, per mailboxWherever your mail host is. We cannot know this, and we do not represent that we do.
Google CalendarGoogle LLC (United States)Two-way appointment sync and free/busy lookupEvent title, description, start and end times, attendee email addresses. Event titles routinely carry a client’s name and matter reference.Firm- or agent-enabledYour Google account.
Microsoft Outlook CalendarMicrosoft Corporation (United States)As aboveAs aboveFirm- or agent-enabledYour Microsoft 365 tenancy.
Apple iCloud Calendar (CalDAV)Apple Inc. (United States); Apple Pty Limited is the Australian contracting entity for consumer iCloudAs aboveAs aboveAgent-enabled, using an app-specific password you supplyApple’s global infrastructure.
XeroXero Australia Pty Ltd (Australia); group parent Xero Limited (New Zealand)Pushing invoices, credit notes, contacts and payments into your Xero organisationClient name, given and family name, email address, phone number, postal and street address, invoice line-item descriptions and amounts. No documents.Firm-enabledXero’s infrastructure. Xero does not offer a customer-selectable region, so we do not claim one.
eWAYEway Payments Pty Ltd (Australia), part of the Global Payments groupCard payment for consultation bookings, using your firm’s own eWAY merchant accountBooker’s name and email address, amount, currency, invoice description and reference. Card details are entered on eWAY’s hosted page and never reach LodgeHQ.Firm-enabled — you supply your own eWAY credentials and funds settle to you. There is no LodgeHQ-level eWAY account.eWAY is an Australian gateway and acquirer. We have not independently verified its processing locations beyond eWAY’s own published position, so we state that rather than asserting a region.
Bitrix24We hold no Bitrix24 credential and have no agreement with Bitrix24. The recipient is your own Bitrix24 portal, operated under your agreement, in the region you chose when you created it.Pushing leads and contacts into your CRMContact and lead fields: name, email address, phone number, enquiry textFirm-enabled — you supply the inbound webhook URLWherever your portal is hosted. We cannot know this.
Zernio (social post scheduling)Registered entity and country of incorporation not established. Zernio was formerly known as Late / getlate.dev. We have not been able to establish the contracting entity from the vendor’s published terms; we have asked, and we will publish the answer here.Scheduling and publishing your firm’s own social media postsPost text and images, and the OAuth grant for the social account you connected. No client case data, unless a user puts client information into a post.Firm-enabledNot confirmed. Treated as overseas.
Social platforms — Meta, LinkedIn, X, Google Business Profile, TikTok, YouTubeVarious (United States and elsewhere)Publication of your own posts, downstream of ZernioPost content onlyFirm-enabled, per connected accountOverseas.

Files already copied cannot be recalled. Cloud Mirror writes into storage you control. If you disconnect it, we stop sending — but the files already in your Dropbox, Drive, OneDrive or WorkDrive are yours and stay there. That is the point of the feature, and it is also a limit on what disconnecting achieves.

3. Business operations

These support the business of selling and running LodgeHQ. Most of them handle your information as our subscriber rather than your clients’ information. One does not, and it is set out in full: Stripe receives your client’s email address and the description of your services whenever you invoice a client through LodgeHQ.

Sub-processorLegal entity and countryPurposeData categoriesAlways on / firm-enabledWhere processed
StripeStripe Payments Australia Pty Ltd (Australia), with Stripe Payments Europe, Limited (Ireland) as an additional party solely for processing personal data under the Stripe Services AgreementSubscription billing, AI credit top-ups, add-on billing, and payment of your invoices by your clientsSubscriber: your account email address and billing details. Your client, where you send an invoice or booking payment through LodgeHQ: the client’s email address, the invoice number, the description of professional services, the GST line and the amount. Card details are entered on Stripe’s hosted page and never reach LodgeHQ. No documents.Always onIreland (as the declared data-processing party) and Stripe’s global infrastructure. We do not set a region.
Google Ads / Google tag (gtag.js)Google LLC (United States). Advertising for Australian advertisers is billed through Google Australia Pty Ltd; the tag itself delivers to Google LLC.Measuring the effectiveness of our own advertisingPage URL and path, referrer, user agent, IP address, and the _gcl_* and _ga advertising cookies set on .lodgehq.com.au. The tag transmits no names, email addresses, phone numbers, client case data or document contents. A Google Ads enhanced-conversions code path exists in the application but is switched off; if we ever switch it on, hashed sign-up email addresses and phone numbers would be transmitted, and we will update this row before that happens rather than after.Always on, on our marketing website only — the home page, the comparison pages, the blog and the sign-up page. It does not load inside the signed-in application, on any page we host for your clients (questionnaire, status, checklist, document upload), on our legal pages, or on a firm’s white-label domain. There is currently no consent gate.Overseas (Google’s global infrastructure).
Apollo.ioApollo.io, Inc. (United States)Stopping our own outbound sales emails once someone books a demo with usAn email address only. Normally this is a prospective LodgeHQ customer — a migration agent — not one of your clients. The exception: where a firm uses a LodgeHQ-hosted booking page for its own client bookings, that booker’s email address is also sent. That is the position today; the change we intend to make to it is in section 8.Always onOverseas (United States).

4. What we do not do, and services we do not use

This section exists because a register that only lists what we do use is half an answer. Everything below is a deliberate statement of absence, correct as at 4 August 2026.

We do not sell your data

We do not sell or rent personal information— yours or your clients’ — to anyone, and we do not disclose it to anyone for their own marketing purposes. We receive no payment or other benefit for any disclosure described on this page. For completeness, because the word “sell” gets used loosely: Apollo.io in section 3 is a sales-intelligence service we buy from, not one we supply. We send it a single email address to stop our own sales sequence, and we receive nothing for doing so. That flow is disclosed above rather than tucked behind this sentence.

We do not train AI on your client files

We do not use client case data to train, fine-tune or improve any AI model, and we have not licensed any sub-processor to do so. Our AI features run on Amazon Bedrock; AWS’s published Bedrock terms state that Bedrock does not use inputs or outputs to train models and does not share them with model providers. Data from a connected mailbox is used only to deliver the send and email-filing features you switched on — it is not used for advertising, is not sold or transferred, and is not used to train generalised AI or machine-learning models. Our use of information received from Google APIs complies with the Google API Services User Data Policy, including its Limited Use requirements. The limit of that statement: where you connect one of your own accounts under section 2, what that provider does with data in your own tenancy is governed by your agreement with them. We are not a party to it and we cannot warrant it.

Services people assume we use, and we do not

4A. A service we have stopped using that still holds data

We have separated this from section 4 deliberately. “We do not use it” and “it does not hold anything of ours” are different statements, and putting this in the list above would have implied the second.

Cloudflare R2 (Cloudflare, Inc., United States) is no longer a storage destination. R2 held our document storage until the move to AWS Sydney in July 2026, and the platform writes only to Amazon S3 in Sydney today — no R2 credential exists in the production environment. Copies written before the move have not been deleted.They include client documents, e-signature artefacts and historic database exports. The bucket is also still permitted by our content security policy. Deleting the contents, deleting the bucket, rotating the credentials and removing that permission are all recorded in section 8; this entry will be updated with the completion date. This row is the only reason the phrase “documents are stored only in Australia” does not appear anywhere on this page.

5. Objecting to a sub-processor

Integrations your firm enables (section 2). Disconnect it. An administrator can do this from LodgeHQ’s Settings without contacting us.

There is no penalty and no consequence beyond losing that feature.

Core platform and business operations (sections 1 and 3). These are not individually optional, and we will not pretend otherwise. LodgeHQ cannot run without its hosting provider, its database, its mail relay or its billing processor. If you object to one of them, tell us at support@lodgehq.com.au. We will tell you within five business days whether we can accommodate the objection — for example by disabling an optional feature that uses that service for your firm, or by changing our own configuration; tell you plainly if we cannot; and where we cannot, treat it as grounds for you to terminate without penalty. We will not charge an early-termination fee.

Taking your data with you. An administrator can request a firm-wide export from within LodgeHQ at any time, whether or not you are leaving, and it keeps working after a subscription lapses. It runs as a background job and produces a single archive containing your records in both JSON and CSV, the uploaded document files themselves, and a manifest listing what is in the archive and anything the run could not include. Platform credentials and access tokens are stripped; your casework is not.

A note on the AI features. AI processing currently has no firm-level off switch. If your practice requires one, tell us — we are tracking the request, and we will say so on this page if and when it is built rather than describing it before it exists.

We would rather lose a subscription than misrepresent what a service does.

6. Notice before we add a sub-processor

Before we engage a new sub-processor that will receive client case data, we will publish the new entry on this page with an effective date, and give at least 30 days’ notice before that entry takes effect, by an in-app announcement visible to firm administrators and by email to every current administrator address we hold. During those 30 days you may object under section 5. If we cannot accommodate the objection, you may terminate without penalty and export your data.

Where a shorter notice applies. For a change that does not involve client case data — for example replacing a marketing or analytics tool — we will publish the change here within 10 business days of it taking effect, without advance notice. Emergency substitutions to restore service will be published here within five business days of the change, with the reason. We would rather commit to a period we will actually meet than to one that reads better.

7. Who maintains this page

Why we are specific about this. Between March and August 2026 this list drifted twice: a provider we had stopped using stayed on it for three weeks, and services we had started using were never added. A list maintained by recollection will drift again. The commitments above — a named owner, a fixed cadence, and re-derivation from the running system rather than from the previous document — are the part of this page we ask you to hold us to.

8. Changes we have committed to and have not yet made

Everything in sections 1 to 4A describes the system as it runs today. This section is the opposite: it is work we have decided to do and have not done. Nothing here is a description of the current state. Each item moves into the change log with a date when it is finished.

9. Change log

Related pages

Questions about anything on this page: support@lodgehq.com.au