Encryption, everywhere
Every connection to Oraoki — from the web dashboard, the housekeeper mobile app, and the reception-desk widget — runs over HTTPS with TLS encryption, so information can't be read in transit. Behind the scenes, the connections between our own services (the database and cache) are encrypted too. The data itself is encrypted at rest: the database and every backup are stored encrypted, so a stolen disk or backup file is unreadable. The mobile app goes a step further with certificate pinning, which means it will only ever connect to the real Oraoki and refuses impostors on public Wi-Fi.
Your property's data stays your property's data
Oraoki serves many hostels from one platform, and keeping each one walled off from the others is the single most important thing we do. Every record is tagged with the organisation it belongs to, and the database enforces that boundary itself using row-level security — not just application code that could be bypassed by a bug. On top of that, an automated check runs on every single change to our code and blocks anything that could let one property's data leak into another's. It is defence in depth, by design.
Strong sign-in, sensible access
Passwords are hashed, never stored in plain text. The mobile app uses short-lived access tokens that rotate automatically and are revoked the moment we detect anything suspicious. Repeated failed logins trigger lockouts to slow down guessing attacks, and the app locks itself after a period of inactivity so an unattended phone doesn't expose your floor. Access inside a property is role-based: a housekeeper, an inspector, and a manager each see only what their job needs.
Hosted in Australia, with recovery built in
Oraoki runs on Amazon Web Services in the Sydney region, inside a private network with no part of the database exposed to the public internet. Backups are taken continuously — the database keeps 35 days of point-in-time history — and copies are replicated to a second Australian region (Melbourne) so we can restore service even if an entire region has a bad day. A small number of trusted providers help us run the service: email delivery and our content-delivery/security layer may process limited information (such as an email address or an IP address) outside Australia. We publish every one of them, what they do, and what data they see, on our sub-processor page.
If you're in the UK or Europe
When a UK or EU property uses Oraoki, the GDPR applies to your staff data and you are the controller — we process it on your instructions. Here is exactly where that stands, including the parts still in progress.
What is in place today:
- A data processing agreement built on the European Commission's 2021 Standard Contractual Clauses and the UK Addendum, which is the mechanism the law requires for sending data to Australia.
- A written transfer impact assessment covering Australian law and government access powers, which we will share with you.
- A published sub-processor list, with advance notice before we ever add one and a right for you to object.
- Data subject rights built into the product: staff can access, export in a machine-readable format, correct, and delete their data themselves.
- A breach process that meets the GDPR's 72-hour notification deadline, not just Australia's 30-day one.
- A DPIA support pack, because workforce monitoring means you will most likely need to complete one — we give you the detail rather than leaving you to reverse-engineer how the system works.
What we are still doing: appointing our Article 27 representatives in the EU and UK, and completing independent legal review of the agreement. We would rather tell you that plainly than let you find out later. If you need those finished before you commit, ask us where they are up to.
One thing worth being direct about: Australia does not have an EU adequacy decision. Any vendor telling you their Australian hosting makes GDPR transfers automatically fine is wrong. It is handled through the Standard Contractual Clauses and the assessment behind them, which is why we have done that work rather than waving it away.
Your rights over your data
The information in Oraoki belongs to your property and your team. Staff can exercise these from Account → Privacy in the app at any time — under the Australian Privacy Principles, and under the GDPR where it applies:
- Access. Staff can export their personal information as a downloadable file from within their account.
- Portability. That export is machine-readable, so it can be taken elsewhere.
- Correction. Details like name and phone can be corrected directly in the app, with the change recorded. Email changes go through support so we can verify identity first — that address is how an account is recovered.
- Deletion. An account can be closed and its personal information erased after a short grace period — some employment and financial records are kept only as long as the law requires.
- Restriction, objection, and complaint. Email us, and for UK and EU staff, the right to complain to your own data protection authority.
If something ever goes wrong, we have a documented breach-response plan and will notify affected people and the Office of the Australian Information Commissioner where the Notifiable Data Breaches scheme requires it. You can reach us any time with a privacy question through the contact details on our privacy policy.