Why WattleDBFeaturesPricingvs SupabaseIndustriesBlogFAQContactAddress API (WattleAddr) Sign inStart free

Who builds on WattleDB

WattleDB is the database layer under Australian software. This page says who builds on it today, what the platform provides for each of them, what each still has to do themselves, and who we are not the right fit for yet. WattleDB helps you meet your obligations; it cannot make you compliant on its own.

The Privacy Act 1988 (Cth) and its thirteen Australian Privacy Principles govern how personal information is collected, stored, used and disclosed. Since December 2024, APP 11 says in terms that “reasonable steps” to secure personal information include technical and organisational measures; a three-tier civil penalty regime applies; and since June 2025 individuals can sue directly for serious invasions of privacy. The $3 million small-business exemption still stands, but it has never applied to health service providers, and from 1 July 2026 it does not apply to the AML/CTF handling of accountants, lawyers, conveyancers and real estate agents. An exposure draft released on 31 August 2026 would make a data processor directly responsible for APP 1 and APP 11 and move breach notification to 72 hours.

What WattleDB gives every customer on this page:

What we are not: we do not hold ISO 27001, SOC 2, IRAP or PCI DSS attestations in our own name. If your regulator or contract requires one, we will say so plainly rather than sell around it.

SaaS builders & SMBsAustralian software teams, startups, and anyone moving off Supabase or Firebase

Most teams on WattleDB are building ordinary Australian software: a booking system, a portal, an internal tool, a product for one of the sectors below. Their customers ask two questions in writing: where is the data, and who can reach it. WattleDB answers both with one Australian company, and a Postgres database with an instant REST API that developers already know how to use.

If you are moving from Supabase, WattleDB shares its open-source core. PostgREST clients and tooling work against the REST API, and migration is a standard pg_dump and pg_restore over your direct connection string.

Privacy Act 1988, APP 11

Reasonable steps to protect personal information now expressly include technical and organisational measures. You remain accountable for personal information your provider holds for you.

Source: OAIC — APP 11 guidelines, December 2024 amendments

Notifiable Data Breaches scheme

Assess a suspected eligible breach within 30 days and notify the OAIC and affected individuals as soon as practicable. The 31 August 2026 exposure draft proposes 72 hours to the Commissioner.

Source: OAIC — NDB scheme; Attorney-General’s Department exposure draft

Statutory tort, June 2025

Individuals can sue any person or company for a serious invasion of privacy, including misuse of information. It is not gated by the small-business exemption.

Source: OAIC — Statutory tort for serious invasions of privacy

How WattleDB helps

Your database runs on a primary in Sydney with automated backups and a continuous change log streamed to Melbourne, both inside Australia, both on Australian-owned infrastructure. Every connection is TLS. Row-level security lets you enforce tenant isolation in the database rather than in application code. You can restore to a point in time yourself from the console, and export at any time. The Data Processing Addendum states where data lives and who our sub-processors are. If your app collects Australian addresses, WattleAddr, our sister product, gives you address autocomplete and verification from the same company.

What you still have to do:

  • Publish your own privacy policy and breach response plan.
  • Write the row-level security policies for your schema.
  • Keep your own master copy of files you cannot re-create; the Melbourne copy of object storage guards against losing Sydney, not against deleting a file.
  • Tell us in writing if a customer’s obligations flow down to us.

Agencies & freelancersAustralian software agencies building and hosting for SMB clients

An agency that builds for a clinic, a practice or a shop usually ends up hosting the database too, and then fields the client’s security questions for years. WattleDB gives an agency one place to run many client databases, each isolated, each with its own credentials, on one invoice.

Many databases, one workspace

Run as many databases as you like on a workspace and mix tiers. Each database is its own isolated Postgres instance with its own connection strings and its own bucket.

Source: WattleDB pricing and console

Per-person access on Launch and Scale

Invite colleagues by email with a role. Everyone who can connect gets their own database login, so removing a person actually revokes their access.

Source: WattleDB team access

How WattleDB helps

Isolation per client, standard Postgres so any developer can pick the work up, and an Australian company you can name in your client’s privacy policy and security questionnaire. Export is standard tooling, so a client who leaves you takes their data with them. For client apps that collect addresses, WattleAddr adds Australian address autocomplete and verification under the same company.

What you still have to do:

  • Decide who the customer of record is. WattleDB contracts with the workspace owner, and breach notices go to the workspace owner.
  • If you host several end-clients in one workspace, you receive our notice and pass it on. Put that in your own client agreements.

Not the right fit yet: we do not offer a white-label or reseller programme today, and we do not say we do.

NDIS, aged care & community servicesParticipant records, care plans, rosters, incident reports

NDIS providers and aged-care providers are, in most cases, health service providers under the Privacy Act, so the small-business exemption does not apply to them. Their auditors ask for the same things every year: where records are held, who can see them, that backups exist and have been tested, and what happens when something goes wrong.

The NDIS Practice Standards require accurate, secure, access-controlled records handled in line with privacy law. The Aged Care Act 2024 and the strengthened Aged Care Quality Standards that commenced on 1 November 2025 require an information management system, digital where possible, managed under privacy law, with personal information used only for providing care and safeguarded with reasonable security measures.

NDIS Practice Standards, information management

Records must be accurate, secure and access-controlled, and handled in line with the Privacy Act.

Source: NDIS Quality and Safeguards Commission — Practice Standards, Core Module

Aged Care Act 2024 and strengthened Quality Standards

Use and disclosure limited to care purposes, consent, or what the law otherwise permits; reasonable security measures; and an information management system under Standard 2.

Source: Aged Care Quality and Safety Commission — strengthened Quality Standards, 1 November 2025

How WattleDB helps

This is the sector WattleDB fits best. The auditor’s questions have direct answers: participant and care records held in Australia on Australian-owned infrastructure; row-level security for who sees what; daily backups on every tier and hourly on Scale, with point-in-time recovery you can run yourself; a Data Processing Addendum; and one company to name. We are producing an auditor-facing one-page summary of these controls for NDIS and aged-care customers to hand to their assessor.

What you still have to do:

  • Your own worker screening, and your own incident and breach process.
  • Your own retention rules for records the Act requires you to keep.
  • Keep records you must retain in the database, not only in object storage, whose Melbourne copy guards against losing Sydney, not against deleting a file.

Accounting & bookkeepingPractice tools, client portals, bookkeeping software that does not talk to the ATO

Tax practitioners handle Tax File Numbers, financial statements and deeply sensitive client information. The Privacy (Tax File Number) Rule 2015 governs how TFN information is collected, used, stored and disclosed. The Tax Practitioners Board expects practitioners who use cloud services to know, and be able to disclose, where client data is stored and who can access it.

From 1 July 2026, accountants, bookkeepers and conveyancers who provide designated services are AML/CTF reporting entities, and the Privacy Act applies to their AML-related handling of personal information regardless of turnover, with records kept for at least seven years.

TFN Rule 2015

Strict requirements on collection, use, storage and disclosure of Tax File Number information. TFN data must be secured and access restricted.

Source: Privacy (Tax File Number) Rule 2015

TPB guidance on cloud computing

Practitioners must be able to say where client data is stored, under which jurisdiction, and who has access, and must keep client confidentiality under the Code of Professional Conduct.

Source: Tax Practitioners Board — Practice Note 1/2017

AML/CTF Tranche 2, July 2026

Accounting firms providing designated services become reporting entities. Seven-year record retention. The Privacy Act applies to AML-related handling regardless of turnover.

Source: AUSTRAC; OAIC guidance for reporting entities

How WattleDB helps

The TPB disclosure sentence writes itself: client data is stored in NEXTDC Sydney with backups in NEXTDC Melbourne, on infrastructure owned and operated by Australian companies, and the only parties who can reach it are WattleDB and our Australian hosting and data-centre providers. Encryption in transit and at rest, row-level security per client, and point-in-time recovery cover the rest of the questionnaire.

What you still have to do:

  • Your own AML/CTF programme and record retention.
  • Your own client confidentiality undertakings under the TPB Code.

Not the right fit yet: if your software is an ATO Digital Service Provider, the ATO’s Operational Security Framework requires ISO 27001 certification or an IRAP assessment covering the hosting scope. We hold neither, so we are not the right fit for ATO-connected software today.

Health softwareAllied health, GP and specialist practices, health-tech, as the database layer

Health information is sensitive information under the Privacy Act, and health service providers have never had the small-business exemption. Under the My Health Records Act 2012, section 77 prohibits the System Operator, registered repository and portal operators and registered contracted service providers from holding or handling My Health Record data outside Australia. WattleDB is not a registered repository or portal operator, and does not claim to be; what it offers is that nothing you store with us leaves Australia.

General practices are accredited against the RACGP Standards, whose Criterion C6.4 asks for unique logins with role-based access, a business continuity and information recovery plan with a backup schedule that is tested, a secure off-site backup location, and agreements signed by external IT providers. State health records laws in Victoria and New South Wales permit records to be held interstate where the recipient is bound to equivalent protections, which a contract can do; we are adding a health annex that binds us to those principles expressly.

My Health Records Act 2012, section 77

My Health Record data may not be held or handled outside Australia by the System Operator, registered repository and portal operators or registered contracted service providers.

Source: My Health Records Act 2012 (Cth) s 77

Privacy Act 1988, health services

Health service providers must comply with the APPs regardless of turnover. Health information is sensitive information.

Source: OAIC — small business exemption guidance

RACGP Standards, Criterion C6.4

Unique logins and role-based access, a tested backup schedule with a secure off-site location, and signed agreements with external IT providers.

Source: RACGP — Standards for general practices, 5th edition

How WattleDB helps

Patient records belong in PostgreSQL, where they are backed up cross-state with point-in-time recovery and stay in Australia. Row-level security enforces access control at the database layer. We provide the Data Processing Addendum and residency statement a practice files for accreditation, and we are adding a health annex that binds us to the Victorian and NSW health privacy principles.

What you still have to do:

  • Your own access policy and breach response plan.
  • Your own copies of any file that is a clinical record, because the Melbourne copy of object storage guards against losing Sydney, not against deleting a file.

Not the right fit yet: we do not hold ISO 27001 or IRAP, so if your product is a My Health Record conformant clinical system whose conformance names those hosting controls, we are not the right fit yet. HIPAA is a United States law that does not apply in Australia, so we make no HIPAA claim.

Other sectorsWhere we serve on the same terms, and where we are not the right fit yet

Childcare, construction, education technology, real estate and retail or hospitality software build on WattleDB on the same terms as any Australian SaaS team above. Two things to know. Card numbers and verification codes should never be stored in a WattleDB database or bucket; tokenise them with your payment provider (they keep the card and hand you a reference) so the database stays out of PCI DSS scope. And education technology vendors are assessed on their own product under Safer Technologies 4 Schools; we appear as evidence inside your answers, not as a certification of our own. Real estate and any other software that collects Australian addresses can pair WattleDB with WattleAddr, our address autocomplete and verification API.

Small ISPs, MVNOs (mobile resellers) and VoIP resellers can run billing, CRM and customer-portal databases with us. We have not yet published a Telecommunications Act Part 13 confidentiality clause; we will agree one in writing before you sign. We are not suitable for retained data under the data-retention regime, for carriage infrastructure, or for anything a carrier would declare as a critical asset.

APRA-regulated entities, government agencies and defence need an independent attestation in the provider’s own name, audit rights and assessed recovery times. We do not hold ISO 27001, SOC 2, IRAP or Hosting Certification Framework status today, so we are not the right fit for those workloads, and we would rather say so here than in month two of your procurement.

Your data. One Australian company behind it.

Whatever you build, WattleDB holds it in Australia, on Australian-owned infrastructure, with one company and one jurisdiction on the data path, and tells you plainly what it does not yet offer.

Disclaimer: This page provides general information about Australian regulatory requirements as at September 2026 and does not constitute legal advice. Regulatory frameworks evolve and individual circumstances vary. Consult a qualified legal professional for advice specific to your situation. References to legislation, regulators and industry standards are based on publicly available sources and may change.

© 2026 RR Sols Pty Ltd (ABN 56 672 722 486). All rights reserved. WattleDB™ is a trade mark of RR Sols Pty Ltd.