Privacy

Privacy policy

How SFP Online handles personal information. Effective: [DRAFT — not yet in effect].

Who we are

SFP Online is operated by [LEGAL ENTITY NAME, ABN — placeholder]. We provide a work health & safety management system to Australian organisations. You can contact us about privacy at dev@safetyfirstprofessionals.online.

Our role: your organisation's system

Most personal information in SFP Online is collected and controlled by the organisation you work for or visit — your employer, host site or principal contractor — which uses SFP Online to run its safety system. That organisation decides what it collects and who in its team may see it; we store and process the information on its behalf and never sell it or use it for advertising. Questions about a specific record are usually best directed to your organisation's administrator first.

What we collect

  • Account details — name, email, phone, and optionally date of birth, address and a profile photo.
  • Safety and employment records — qualifications and licences (with evidence documents), training records, emergency contacts, and — where your organisation records them — medical details such as allergies and conditions. Medical details are visible only to you and to people your organisation has given profile-management permission.
  • Signatures — drawn signatures for SWMS sign-on, toolbox talks, training and site inductions, kept per version as compliance evidence.
  • Site attendance — sign-in and sign-out times, and on sites that check location, the GPS position captured at the moment you sign in.
  • Location — a position is recorded at specific moments, never continuously and never in the background. Those moments are: signing in to a site or an area that has a geofence; each check-in during a lone-worker session (so help can find you if you stop responding); and, if you choose to attach it, the position on a hazard, injury, safety-observation or maintenance report. Attaching your location to a report is optional and asked for each time. Your organisation decides which of these features it uses and is responsible for telling you about, and obtaining your agreement to, any location recording in your workplace — in Victoria the Surveillance Devices Act 1999 requires consent before a tracking device is used to determine a person's location.
  • Vehicle and plant records — trips, odometer readings, advisory driver-hours records and pre-start checks, where your organisation uses those features.
  • Incident and hazard reports — including injury details where an incident involves you. Confidential psychosocial reports can be made anonymously; anonymous reports record no identity — not in the report, not in the audit trail, and not in our server logs.
  • Technical data — sign-in events and security logs kept for the integrity of the system.

Why we collect it

To operate your organisation's safety management system: recording and managing hazards, incidents, inductions, competencies, attendance and plant; meeting statutory WHS duties (for example notifiable-incident reporting and statutory record retention); and keeping the system secure. We do not use personal information for marketing to workers, and we do not sell it.

Access and correction

You can see and correct your own profile in the app at any time, and download a copy of your personal information — profile, qualifications, training, trips, sign-ons and attendance — using Download my data in your account settings (also in the mobile app under Me). For anything you cannot access or correct yourself, contact your organisation's administrator or us at dev@safetyfirstprofessionals.online; we respond within 30 days. Some records cannot be altered after the fact — signed compliance records are kept as given, and the audit trail has been tamper-evident since 25 July 2026 — but corrections can always be recorded alongside them.

Retention and deletion

Safety records are kept for the periods Australian law requires — some are very long: health-monitoring records are kept for 30 years, asbestos-related health monitoring for 45 years, an asbestos management plan for 100 years, and an asbestos register for the life of the workplace. Statutory retention and legal holds override deletion requests for those records. Where no legal duty applies, we delete or de-identify information that is no longer needed.

Once you are no longer a member of any organisation, you can delete your account yourself using Delete my account in your account settings. We email you a link to confirm, and you have seven days after confirming to change your mind. Deletion erases your email address, password and sign-in methods, phone and address, emergency contacts, medical details, profile photo, your devices and preferences, and the history of changes to those details. Your name stays on the safety records that name you — training, inductions, sign-ons and incident records your former employers are required by law to keep — together with signatures you gave as their evidence, and the audit trail, which records that an action happened and by whom and is not rewritten to remove you. While you are still a member of an organisation, ask its administrator to remove you first, and download a copy of your data before they do. If you cannot sign in, use our account-deletion request page to start a verified request.

Health information in Victoria

Where your organisation records health information about you — health-monitoring results, injury details, return-to-work plans, or the medical fields on your profile — and that information is collected or handled in Victoria, the Health Records Act 2001 (Vic) and its Health Privacy Principles apply in addition to the Australian Privacy Principles. Those obligations do not carry the Privacy Act's small-business exemption, so they apply regardless of an organisation's size. In practice this means the same things we already do. Health-monitoring results are visible only to you and to the people who arrange and review that monitoring; the medical fields on your profile are visible only to you and to the people your organisation has given profile-management permission. The two are separate — managing profiles does not show someone your monitoring results, and being able to see that monitoring is due, or overdue, does not show the result either. Health information is included in your data download, and it is kept only as long as the law requires.

Disclosure

  • To your organisation and the people it authorises, per its role settings.
  • To service providers that host and run the system — hosting in [HOSTING REGION — placeholder], email delivery, and error monitoring — bound to use the information only to provide the service.
  • To WHS regulators and others where the law requires or authorises it.
  • Industry benchmarks are computed only from de-identified, aggregated data with a minimum-peer threshold so no organisation's numbers are inferable; organisations can opt out.

Automated decision-making

Some features act automatically, configured by your organisation: site sign-in can be blocked when a required competency, induction or contractor requirement is missing, or when a sign-in is outside a site's geofence; driver-hours records produce advisory fatigue prompts (not compliance determinations); and AI-assisted drafting can suggest content that a person always reviews before it is used. Your organisation's administrators can see why a gate blocked a sign-in and can correct the underlying records.

Security

Information is protected by per-organisation isolation enforced in the database, role-based access with need-to-know gating for sensitive fields, an audit trail protected by a per-organisation hash chain that is re-verified daily, and modern sign-in including passkeys. See Security & compliance for detail.

Data breaches

We maintain a data-breach response process consistent with the Notifiable Data Breaches scheme. If a breach is likely to result in serious harm, we notify the affected organisations, affected individuals and the OAIC as soon as practicable.

Complaints

Contact us at dev@safetyfirstprofessionals.online and we will respond within 30 days. If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner (oaic.gov.au, 1300 363 992). Complaints about health information handled in Victoria can instead go to the Victorian Health Complaints Commissioner (hcc.vic.gov.au, 1300 582 113), which is the regulator for the Health Records Act 2001 (Vic).

Changes

We update this policy as the product and the law change, and note the effective date above. Significant changes are communicated to organisation administrators.