Production

Privacy Policy

Workplace Safe Pty Ltd (ABN 95 631 676 769) operates the Workplace Safe website, web portal, mobile applications and related services. This policy explains how we handle personal information across that system. Contact us at support@workplacesafe.com.au about privacy, access, correction or deletion requests.

1. Information we handle

Depending on how you and your organisation use Workplace Safe, we handle:

  • Account and contact information, including names, email addresses, contact details, organisation associations, account roles and access permissions.
  • Workplace records, including project assignments, policies and acknowledgements, inductions, training records, equipment and prestart activity, hazards, incidents, corrective actions and supporting attachments.
  • Injury and health information included in incident reports, descriptions, photographs or other attachments. This information can be sensitive even when it is entered into a general text field.
  • Billing information, including business details, billing contacts, invoices, payment references and limited card information such as a masked card number and expiry details.
  • Technical and support information, including IP addresses, browser or app details, device or installation identifiers, app versions, authentication and activity records, notification identifiers, error reports and correspondence with support.

The mobile app does not currently collect GPS location. A workplace address, location written in a report or information contained in an uploaded file may still identify a location.

2. How information is collected

We collect information when you register, use the service, submit records, contact support or make payments. Your organisation and its authorised users may also enter information about you, including before you complete registration. Some technical information is generated automatically when you use the service.

Organisations must ensure they have a lawful basis for providing information about workers and others, give appropriate collection notices and obtain consent where required, particularly for health information. Please avoid entering unnecessary sensitive information. Accepting general terms is not a substitute for consent where specific consent is required.

You can browse public information without creating an account. We need identifying information for workplace accounts and many support requests; without it, we may be unable to provide the requested service.

3. Why we use information

We use information to operate accounts, control access, maintain workplace records, deliver safety workflows and notifications, administer subscriptions and payments, provide support, diagnose faults, protect the service, and respond to authorised requests and legal obligations.

We may analyse technical usage information to improve performance and develop the service. We may also prepare de-identified aggregate statistics, provided individuals and customer organisations cannot reasonably be identified, including through combination with other available information. Removing a name alone does not necessarily de-identify a record. This permission does not by itself authorise unrelated marketing uses of injury information or training general-purpose AI models on private customer content. New processing requires a separate assessment, appropriate notices and any legally required consent.

Workplace Safe is not an emergency monitoring or emergency response service. Recording an incident or receiving a notification does not mean that we monitor it or will arrange assistance.

4. Who can access information

Within an organisation, access depends on permissions, roles, project access and the relevant feature. Authorised administrators, managers and other authorised users may see information needed for their responsibilities. Workplace submissions are not necessarily private from your organisation's administrators.

We may access records when reasonably needed to operate, troubleshoot, secure or support the service. We also use providers for hosting, payments, communications and related technical services. Information may be disclosed where required or otherwise permitted by law. We do not make private workplace records public merely because they are uploaded.

5. Hosting and service providers

We currently host application data on Microsoft Azure servers in Australia, use Pin Payments to process payments and use Firebase Cloud Messaging to deliver mobile notifications. Payment processing involves information supplied to Pin Payments; Workplace Safe retains billing records and limited payment metadata. Notification delivery involves device or installation identifiers and message delivery information.

Providers may change as the service develops. We will update this policy for material changes to information handling and give notice or obtain consent where required. A provider change does not remove our privacy obligations.

Australian hosting does not mean every provider processes all information exclusively in Australia. Providers may process information overseas under their service arrangements. Firebase uses global infrastructure, which may involve processing outside Australia. Contact us for information about the providers and overseas processing relevant to your request.

If our business is proposed to be sold, merged or reorganised, we may disclose information to prospective purchasers and professional advisers only as reasonably necessary for that transaction, subject to confidentiality safeguards and applicable law. We will use de-identified information where practicable. A successor may receive information needed to continue the service, subject to applicable privacy obligations; a business transfer does not permit unrestricted new uses of workplace records.

6. Cookies and communications

We use authentication cookies and related storage to keep you signed in and support the operation of the service. Blocking these may prevent login or affect functionality.

Account, security, billing and workplace notifications are service communications. You can manage mobile notification permission through your device settings; disabling notifications does not remove your workplace responsibilities.

We do not currently send promotional marketing emails or display advertising. If we introduce marketing communications, we will obtain consent where required and provide a way to unsubscribe. We will explain any new advertising or tracking practices before introducing them and obtain consent where required. This policy does not itself enrol you in marketing or authorise unrelated uses of health information.

7. Retention and deletion requests

Records are not automatically deleted when a trial expires, a subscription ends, a person leaves an organisation or their access is disabled. We currently retain those records rather than applying an automatic deletion schedule. Retention must be considered against the purposes of holding the information and applicable legal requirements; account closure does not itself establish a right to retain information indefinitely.

You may request access, correction or deletion of your personal information by emailing support@workplacesafe.com.au. The business account owner may request removal of the organisation's records through the same address. We verify identity, the scope of the request and authority before acting.

A personal account request does not automatically delete an organisation's historical safety records. We assess individual privacy rights separately from the owner's authority over business-wide requests. Information may need to be retained for lawful compliance, accounting or dispute-related purposes. We will explain relevant limitations when responding; we do not promise immediate erasure of all live records, logs or backup copies.

8. Access, correction and exports

Contact support to request access to or correction of personal information, or assistance obtaining business records. In-product export options are limited. We will assess the request and explain the available format, scope and any lawful restrictions. Access may need to protect information about other people. We may work with your organisation to locate or correct workplace records, without treating its approval as a condition overriding your legal rights.

9. Younger workers

Authorised workers under 18 may use Workplace Safe. Organisations should explain how their information is handled in a way they can understand and obtain any consent or authorisation required by law. We do not assume a parent or guardian has consented merely because a younger worker registers.

10. Security

The service uses authentication and permissions to control access to workplace information. Keep your credentials secure, manage device access and report suspected unauthorised access promptly. No online system can guarantee absolute security.

11. Questions and complaints

Email support@workplacesafe.com.au with your concern and enough information for us to identify the relevant account or records. Do not send passwords. We will assess your concern, seek clarification where necessary and respond. If a request cannot be fulfilled, we will explain the reason and available next steps.

If you are dissatisfied with our response, you may contact the Office of the Australian Information Commissioner, which can explain whether it can consider your complaint.

12. Policy changes

We will update this policy when our practices change and make it available through the website and applications. We will provide additional notice or seek consent where required. A policy update does not retrospectively authorise an unrelated use of information.

Last updated 14 September 2026