This Privacy Policy explains how SafeComp Pty Ltd ("SafeComp", "we", "our", "us") collects, uses, stores and discloses personal information when delivering our workplace safety and compliance management platform and related services ("Platform").
We are committed to protecting your privacy and handling personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
This Policy applies to:
- Businesses (Subscribers) using SafeComp
- Workers, subcontractors, employees and visitors signing in via SafeComp
- Site supervisors and administrators
- Users accessing our website, mobile PWA, API, and related systems
"Personal information" includes any information or opinion about an identifiable individual. Where applicable, this may also include sensitive information such as incident details or health-related information.
1. Why we collect personal information
We collect personal information only where reasonably necessary for our operations, including:
1.1 To provide the SafeComp Platform
- Creating and managing Subscriber accounts
- Enabling digital inductions, SWMS assignment and signatures
- Processing daily site sign-ins/sign-outs
- Generating, storing and managing compliance documentation
- Facilitating visitor sign-in using QR codes
- Providing platform support and troubleshooting
1.2 To process payments and subscriptions
- Managing Stripe subscription billing
- Issuing invoices and receipts
- Managing account status (activation, suspension, reactivation)
1.3 To improve the Platform
- Performing analytics to optimise user experience
- Monitoring usage patterns and compliance trends
- Developing new product features and improvements
1.4 To communicate with users
- Sending induction confirmations
- Sending SWMS renewal or expiry alerts
- Notifying supervisors of non-compliant or incomplete inductions/SWMS
- Platform updates, service notifications or marketing communications (users may opt out of marketing at any time).
1.5 To comply with laws and regulations
- Assisting with WHS record-keeping obligations
- Supporting incident investigations
- Responding to legal requests or regulatory inquiries
2. What personal information we collect
The personal information we may collect includes:
2.1 Subscriber and business information
- Business name, ABN/ACN
- Contact details
- Payment and billing details
- Company logo (for document branding)
2.2 Worker, subcontractor and visitor information
Collected during induction or QR scanning:
- Name
- Phone number
- Email address
- Company and trade type
- Emergency contact details
- Digital signature
- Acknowledgement of site policies
- Time-stamped QR sign-in and sign-out data
2.3 SWMS and safety information
- Trade type
- Signed SWMS documents
- Expiry dates
- Compliance status
2.4 Technical and device data
Automatically collected:
- IP address
- Browser and device type
- Operating system
- Pages visited
- Session logs
- Location data (only if permitted by the device during QR scan)
3. How we collect personal information
We collect personal information through:
3.1 Direct collection
- Completing an induction form
- Signing a SWMS document
- Scanning a site QR code
- Creating an account or subscription
- Contacting support
3.2 Automatic collection
- Cookies and tracking tools
- Analytics services
- QR-based location/time data
3.3 Third-party integrations
- Stripe (billing)
- PDF generation services
- Cloud storage (Dropbox, Google Drive, OneDrive, iCloud)
- Email providers (e.g., SendGrid)
4. How we use personal information
We use personal information to:
- Facilitate site inductions, SWMS signing and daily sign-ins/out
- Maintain compliance logs for each site
- Provide access to site-specific safety policies
- Notify supervisors and admins of compliance exceptions
- Send automated alerts (e.g., SWMS expiring soon)
- Generate PDFs and store documents in the Subscriber's cloud storage
- Monitor Platform performance and security
- Improve site safety and digital record-keeping
- Send service updates or marketing materials
- Comply with legal obligations
5. Disclosure of personal information
We may disclose personal information to:
5.1 Subscriber administrators
Workers' induction/SWMS/sign-in details are visible to the Subscriber's nominated admins for WHS compliance.
5.2 Service providers
Who support us with:
- Payment processing (Stripe)
- Cloud storage
- Analytics
- Hosting
- Email communications
- QR code processing
- PDF generation
These providers are required to handle data according to applicable privacy laws.
5.3 Legal or regulatory bodies
Where disclosure is required by law or to protect our rights.
5.4 Business acquisitions or sale
Personal information may be transferred to a purchaser as part of a business sale or due diligence process, subject to continued protection under this Policy.
6. Overseas disclosure
SafeComp does not intentionally disclose personal information overseas.
However, several third-party providers (e.g., cloud or analytics services) may process data abroad.
We take reasonable steps to ensure any overseas providers comply with the Australian Privacy Principles.
7. Security of personal information
We take all reasonable technical and organisational steps to protect personal information, including:
- Secure server environments
- Encryption where applicable
- Restricted-access controls
- Regular security updates and audits
- Monitoring for unauthorised access
Despite these measures, no online service is completely secure. Users acknowledge inherent transmission risks.
If a data breach occurs that is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) as required by the Notifiable Data Breaches (NDB) scheme under the Privacy Act 1988 (Cth).
8. Data retention
We retain personal information only as long as reasonably necessary to:
- Provide our services
- Meet WHS record-keeping requirements
- Resolve disputes
- Meet legal or regulatory obligations
Subscribers may request deletion of their data where legally permissible.
9. Access and correction
Users may request access to, or correction of, the personal information we hold.
All requests can be sent using the contact details below. We will respond within a reasonable timeframe.
10. Complaints
If you believe we have breached the Australian Privacy Principles, please contact us.
We will investigate any complaint and respond in writing.
If unresolved, complaints may be referred to:
Office of the Australian Information Commissioner (OAIC)
www.oaic.gov.au
11. Changes to this Privacy Policy
This Policy may be updated from time to time.
The most current version will always be posted on our website or available upon request.
Continued use of the Platform constitutes acceptance of the updated Policy.
12. Contact Details
Privacy Officer – SafeComp Pty Ltd
- Email: privacy@safecomp.com.au
- Phone: +61 419 323 980
- Address: PO Box 442, Balwyn North VIC 3104, Australia
