Privacy Policy
Plus Ultra Innovations Pty Ltd
Wellbeing Dashboard Platform
Effective Date: 28 January 2026
Last Updated: 3 September 2026
Version: 1.3
1. Introduction
Plus Ultra Innovations Pty Ltd (ABN: 23 686 310 850) ("we", "us", "our", "Plus Ultra") is committed to protecting the privacy of individuals who use our workplace psychosocial risk platform ("Platform"). This Privacy Policy explains how we collect, use, disclose, and protect personal information in accordance with:
- Australia: Privacy Act 1988 (Cth) and Australian Privacy Principles (APPs)
- Singapore: Personal Data Protection Act 2012 (PDPA)
This policy applies to all users of our Platform, including employees, administrators, and organisational clients.
2. Information We Collect
2.1 Information You Provide
| Data Category | Examples | Purpose | |--------------|----------|---------| | Account Information | Name, email address, job title, team membership | Account creation, platform access | | Psychosocial risk check-in responses | Stress levels, sleep quality, energy levels, job satisfaction | Psychosocial risk measurement and insights | | Validated instrument scores | WHO-5 Well-Being Index scores, BAT-23 burnout scores | Psychosocial risk measurement | | Productivity Data | Self-rated performance, days missed due to health | Organisational productivity metrics | | Feedback | Free-text comments, suggestions | Service improvement |
2.2 Information Collected Automatically
| Data Category | Examples | Purpose | |--------------|----------|---------| | Usage Data | Login times, features accessed, session duration | Platform improvement | | Device Information | Browser type, operating system | Technical support | | Log Data | IP addresses, access logs | Security and troubleshooting |
2.3 Sensitive Information
We collect health-related information through our check-ins and validated instruments. This is classified as "sensitive information" under Australian privacy law and "sensitive personal data" under Singapore's PDPA. We only collect this information:
- With your explicit consent
- For the primary purpose of psychosocial risk measurement and insights
- In accordance with applicable privacy laws
2.4 Information Collected Through Our Website
When you contact us through our website, we collect the details you submit in the enquiry form: your name, work email, organisation, and message. We use this information only to respond to your enquiry and follow up on it. We do not use it for marketing without your consent, and we do not sell it. We retain website enquiries only as long as needed to respond and follow up, then delete them.
3. How We Use Your Information
3.1 Primary Purposes
- Psychosocial risk insights: Generating personal scores and trends from validated instruments
- Early risk identification: Surfacing elevated psychosocial risk indicators (for example, burnout signals from validated instruments) as measurement — for the individual, and for team-level insight subject to the minimum group size. We measure and surface indicators; we do not diagnose or provide clinical or support services
- Organisational Analytics: Providing de-identified, aggregated insights to your employer (subject to privacy thresholds)
- Platform Operation: Account management, authentication, and technical support
3.2 Secondary Purposes
- Service Improvement: Analysing usage patterns to enhance the Platform
- Research: Conducting anonymised research to improve psychosocial risk measurement (with separate consent)
- Communications: Sending Platform-related notifications and updates
3.3 What We Never Do
- ❌ Sell your personal information to third parties
- ❌ Share individual-level data with your employer without your explicit consent
- ❌ Use your data for advertising or marketing purposes
- ❌ Make automated decisions that significantly affect you without human oversight
4. Privacy Thresholds & Anonymisation
To protect individual privacy, we enforce a strict minimum group size before any team-level data is shared with organisational administrators.
Team-level reporting requires a minimum group of 10 — in every market, the same number, with no jurisdiction split. This floor is our own design choice; it is not a statutory minimum in Australia or Singapore. The floor cannot be reconfigured: there is no admin setting, environment variable, feature flag or per-organisation field that can lower it for any customer, at any price. It is enforced across the aggregation surfaces, not left to the display layer where it could be bypassed.
What this means:
- If your team has fewer than 10 members, your data will NOT appear in team-level reports
- All organisational reporting uses aggregated, de-identified data
- Individual responses are never shared with employers
4.1 Anonymous batch feedback — the one exception below 10
There is a single channel in which a number below 10 can appear, and it exists because the privacy model there is structurally different — no author identity is recorded at submission at all — not because the floor was negotiated down. In the anonymous batch feedback channel, free-text comments carry no author identity, are shuffled, and are reported at the organisation level only, never by team. This channel releases at 5 comments in organisations under 50 people, and 3 comments in larger organisations. Team-level reporting is always 10.
Participation in this channel is recorded. When you submit anonymous batch feedback we record that your account took part in that month — your account and the month, and nothing else. No content is stored against you, and there is no key connecting you to any comment. It is not a link to what you wrote. It is, however, a correlation surface: if a release contained a single comment and a single participant, the two could in principle be inferred. That is exactly what the release thresholds above are for. This is how the channel has always worked; it did not change when confidential feedback was introduced.
4.2 Named feedback is confidential, not anonymous
Feedback you submit through the named feedback channel is confidential, and it is encrypted at rest. Your private feedback stays private: no administrator view, export or report resolves it to you, and no one at Plus Ultra reads it — the first is architecture, the second is policy, and we state them separately because they are not the same kind of guarantee.
You can also choose to share a line of your feedback with a named reader you explicitly select. That line — and only that line — is delivered to that reader, word for word. Nothing is shared without that choice: if you select no reader, no one in your organisation sees what you wrote.
A record links you to your own submission — that is what lets you read back what you wrote and withdraw it. Because that record exists, and because sharing is your choice rather than impossible, "confidential" is the accurate word and "anonymous" is not. This is a different channel from the anonymous batch feedback described in section 4.1, which records no author at all.
5. Data Sharing & Disclosure
5.1 Organisational Clients
We share aggregated, de-identified psychosocial risk data with your employer to help them understand workplace psychosocial risk trends. This data:
- Cannot identify individual employees
- Is subject to privacy thresholds (see Section 4)
- Is used solely for workplace improvement purposes
5.2 Service Providers
We engage a small number of third-party service providers ("sub-processors") to operate the Platform. Our primary processor is Supabase, which hosts platform data in Australia (Sydney, ap-southeast-2). The complete, current list — what each provider processes and where — is maintained in our Subprocessor List.
Each provider is engaged under its standard Data Processing Agreement and processes personal information only as needed to provide the Platform.
5.3 Legal Requirements
We may disclose personal information if required by law, court order, or government authority, or to protect the rights, property, or safety of Plus Ultra, our users, or the public.
6. Data Security
We implement industry-standard security measures to protect your information:
6.1 Technical Controls
- Encryption: Data encrypted in transit (TLS) and at rest (AES-256, managed by Supabase)
- Access Control: Role-based access, multi-factor authentication
- Infrastructure: hosted on SOC 2 Type II-certified infrastructure (our providers' certification, not a certification held by Plus Ultra)
7. Data Retention
We retain personal information for the duration of your organisation's engagement with us. On termination, we provide a full data export and then delete your personal information (deletion verified).
You may request deletion of your personal information at any time. We action such requests within 30 days, consistent with the Privacy Act 1988.
Aggregated, de-identified analytics are no longer personal information once aggregated above our minimum group size of 10, and may be retained indefinitely for research and benchmarking.
8. Your Rights
8.1 Australian Users (Privacy Act 1988)
You have the right to:
- Access your personal information
- Correct inaccurate information
- Request deletion (subject to legal retention requirements)
- Complain to the Office of the Australian Information Commissioner (OAIC)
8.2 Singapore Users (PDPA)
You have the right to:
- Access your personal data
- Correct errors or omissions
- Withdraw consent for data processing
- Request data portability
- Complain to the Personal Data Protection Commission (PDPC)
8.3 How to Exercise Your Rights
Contact our Privacy Officer through the contact form on our website.
- Response Time: Within 30 days (Australia) or 30 business days (Singapore)
8.4 How to Make a Privacy Complaint
If you believe we have breached the Australian Privacy Principles (or, in Singapore, the PDPA), you can complain to us directly:
- Contact our Privacy Officer through the contact form on our website, describing the issue.
- We will acknowledge your complaint and investigate it.
- We will respond to you in writing within 30 days.
If you are not satisfied with our response, you may escalate to the relevant regulator — the Office of the Australian Information Commissioner (OAIC) or, in Singapore, the Personal Data Protection Commission (PDPC). Their contact details are in Section 13.
9. Cookies & Tracking
Our Platform uses essential cookies for:
- Authentication and session management
- Security (CSRF protection)
- User preferences
We do not use:
- Advertising or tracking cookies
- Third-party analytics that identify individuals
- Cross-site tracking
10. International Data Transfers
Yes — some of your personal information is disclosed to and processed by recipients overseas. Hosting and rate limiting are processed in Australia; enquiry emails are delivered and stored in the United States via Resend and Google. The current provider list — what each processes, and where — is in our Subprocessor List.
Plus Ultra relies on contractual arrangements with each overseas provider under their data processing agreements, requiring protections comparable to the Australian Privacy Principles.
11. Children's Privacy
Our Platform is designed for workplace use and is not intended for individuals under 18 years of age. We do not knowingly collect personal information from children.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by:
- Email notification to registered users
- Prominent notice on the Platform
- Updated "Last Updated" date
13. Contact Us
Privacy Officer
Plus Ultra Innovations Pty Ltd
ABN: 23 686 310 850
Reach our Privacy Officer through the contact form on our website.
For Australian Privacy Complaints:
Office of the Australian Information Commissioner
Website: www.oaic.gov.au
Phone: 1300 363 992
For Singapore Privacy Complaints:
Personal Data Protection Commission
Website: www.pdpc.gov.sg
Phone: +65 6377 3131
This Privacy Policy was last reviewed on 5 August 2026.