← Back
Last updated: 15 April 2026

PRIVACY POLICY

FLOSMOSIS PTY LTD

ACN [To be inserted]

Effective Date: [Date]
Version: 1.0


1. WHO WE ARE

FLOSMOSIS PTY LTD (ACN [insert]) (FLOSMOSIS, we, us, our) operates a workforce time verification platform for the Australian construction labour hire industry.

Our registered office is at [address].

We are committed to protecting the privacy of the personal information we collect and hold. This Privacy Policy explains how we collect, use, disclose, and protect personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

1.1 Application of the Privacy Act

⚠️ Regulatory note: The Privacy Act 1988 (Cth) applies to FLOSMOSIS. The previous small business exemption (for businesses with annual turnover of $3 million or less) has been progressively removed through 2024–2025 reforms, bringing approximately 95% of Australian businesses under the Act's scope. Additionally, FLOSMOSIS handles personal information of third-party workers (not its own employees), which would have triggered obligations even under the previous regime. FLOSMOSIS is therefore subject to the full requirements of the Australian Privacy Principles (APPs 1–13).


2. WHAT INFORMATION WE COLLECT

2.1 Worker Information

We collect the following personal information about Workers whose time is recorded and verified through the Platform:

CategoryInformation CollectedPurpose
IdentityFull nameIdentifying the Worker for shift records
ContactMobile phone numberOTP verification via SMS for clock-in/clock-out
LocationGPS coordinates at clock-in and clock-outVerifying the Worker's presence at the designated worksite
Shift DataClock-in time, clock-out time, shift duration, worksite, verification statusRecording and verifying hours worked
VerificationOTP verification records, hash chain verification recordsMaintaining the integrity of shift records

2.2 Supervisor Information

CategoryInformation CollectedPurpose
IdentityFull nameIdentifying the Supervisor
ContactEmail address, phone numberCommunicating shift confirmations and notifications
ActionsShift confirmation records, approval timestampsRecording Supervisor confirmations

2.3 Customer (Employer) Information

CategoryInformation CollectedPurpose
BusinessCompany name, ABN, business addressIdentifying and administering the Customer account
ContactContact person name, email, phoneAccount management and support
BillingPayment information (processed via third-party payment provider)Subscription billing

3. HOW WE COLLECT INFORMATION

3.1 Collection Methods

We collect personal information:

3.2 Consent


4. WHY WE COLLECT INFORMATION

We collect personal information for the following purposes:

Strictly for time verification: We collect and use personal information strictly for the purpose of workforce time verification. We do NOT use personal information to calculate wages, award entitlements, superannuation, or tax, and we do NOT provide payroll services.


5. HOW WE USE INFORMATION

We use personal information in accordance with APP 6 — only for the primary purpose for which it was collected, or for a directly related secondary purpose that would reasonably be expected by the individual.

Specifically:


6. WHO WE SHARE INFORMATION WITH

6.1 Customer Access

Each Customer can only access the personal information of their own Workers and Supervisors. Customers cannot access the data of other Customers' Workers.

6.2 Third-Party Service Providers

We share personal information with the following third-party service providers, who process data on our behalf:

ProviderServiceData SharedLocation
TwilioSMS delivery (OTP verification)Worker mobile phone numbers, OTP messagesUSA (with data processing agreements in place)
SupabaseDatabase hosting and data storageAll Customer Data, Worker Data, Shift DataAustralia / USA (depending on instance configuration)
ResendEmail deliveryEmail addresses, notification contentUSA
VercelApplication hostingApplication data processed during server-side renderingUSA / Australia (edge network)

6.3 Overseas Disclosure — APP 8

Where personal information is disclosed to overseas recipients (as listed above), FLOSMOSIS takes reasonable steps to ensure that the overseas recipients:

6.4 Other Disclosures

We may also disclose personal information:

6.5 No Sale of Personal Information

FLOSMOSIS does not sell personal information to third parties for marketing or any other purpose.


7. GPS AND LOCATION DATA

7.1 GPS Data Collection

7.2 Purpose

GPS data is collected for the sole purpose of verifying that the Worker was at or near the designated worksite at the time of clock-in and clock-out. It is used to:

7.3 Sensitivity of GPS Data

⚠️ Regulatory analysis: Under the Privacy Act 1988 (Cth), "sensitive information" is defined in s 6(1) and includes information about health, genetics, biometrics, criminal record, and sexual orientation — but does NOT explicitly include location data. GPS coordinates are therefore classified as personal information (not sensitive information) under the current Act. However:

  • (a) The Office of the Australian Information Commissioner (OAIC) has recognised that location data can reveal sensitive details about individuals and should be treated with a high degree of care.
  • (b) Privacy reform proposals have considered whether location data should be classified as sensitive information.
  • (c) As a matter of best practice, FLOSMOSIS treats GPS data with the same level of care as sensitive information, including limiting collection to what is strictly necessary and not using GPS data for any purpose other than worksite verification.

7.4 Worker Awareness

Workers are informed of GPS data collection through:


8. DATA SECURITY

8.1 Security Measures

FLOSMOSIS implements the following security measures to protect personal information:

Note: FLOSMOSIS does not warrant that the SHA-256 hash chain creates legally admissible evidence or constitutes a legally recognised digital signature. The hash chain provides a technical mechanism for detecting unauthorised modifications to shift records. Its legal status and evidentiary weight are matters for the relevant court or tribunal.

8.2 Notifiable Data Breaches

FLOSMOSIS complies with the Notifiable Data Breaches (NDB) scheme under Part IIIC of the Privacy Act 1988 (Cth). If FLOSMOSIS becomes aware of an eligible data breach (or suspects an eligible data breach has occurred), it will:

8.3 Customer Notification

In the event of a data breach affecting Customer Data, FLOSMOSIS will notify the Customer as soon as practicable after becoming aware of the breach.


9. DATA RETENTION

9.1 Retention Period

9.2 Legal Requirements

FLOSMOSIS may retain personal information for longer periods where required by law, including:

9.3 De-identification

Where FLOSMOSIS de-identifies personal information for analytical or research purposes, the de-identified data will not be re-identified.


10. ACCESS AND CORRECTION

10.1 Access

10.2 Correction

10.3 Worker Access

Workers who wish to access or correct their personal information should, in the first instance, contact their employer (the Customer). If the Customer is unable to assist, the Worker may contact FLOSMOSIS directly.


11. COMPLAINTS

11.1 Internal Complaints

If you have a complaint about how FLOSMOSIS handles personal information, you may contact us at the details in clause 12. We will:

11.2 External Complaints

If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC):


12. CONTACT DETAILS

Privacy Officer
FLOSMOSIS PTY LTD
[Registered office address]

Email: privacy@flosmosis.com
Phone: [phone number]
Website: www.flosmosis.com


13. CHANGES TO THIS POLICY

FLOSMOSIS may update this Privacy Policy from time to time. We will notify Customers of material changes by email and will update the "Effective Date" at the top of this Policy. The current version of this Privacy Policy is always available on the FLOSMOSIS website.


14. AUSTRALIAN PRIVACY PRINCIPLES — COMPLIANCE SUMMARY

APPSubjectFLOSMOSIS Compliance
APP 1Open and transparent management of personal informationThis Privacy Policy; internal privacy procedures
APP 2Anonymity and pseudonymityWorkers must be identified for time verification; anonymity is not practicable for this service
APP 3Collection of solicited personal informationOnly personal information reasonably necessary for time verification is collected
APP 4Dealing with unsolicited personal informationAny unsolicited personal information not required is destroyed or de-identified
APP 5Notification of the collection of personal informationWorkers are notified via Customer, initial SMS, and this Policy
APP 6Use or disclosure of personal informationUsed only for primary purpose (time verification) or directly related secondary purposes
APP 7Direct marketingFLOSMOSIS does not use Worker personal information for direct marketing
APP 8Cross-border disclosure of personal informationOverseas disclosures to Twilio, Supabase, Resend, Vercel — contractual protections in place
APP 9Adoption, use or disclosure of government related identifiersFLOSMOSIS does not collect government identifiers (TFN, Medicare, etc.)
APP 10Quality of personal informationReasonable steps to ensure accuracy and currency
APP 11Security of personal informationEncryption, access controls, hash chain verification, NDB compliance
APP 12Access to personal informationIndividuals may request access (clause 10.1)
APP 13Correction of personal informationIndividuals may request correction (clause 10.2)

End of Document

© 2026 FLOSMOSIS PTY LTD. Flostruction is a product of FLOSMOSIS PTY LTD.