FLOSMOSIS PTY LTD
ACN 697 323 925 · ABN 80 697 323 925
Registered office: 55 Reginald Road, Googong NSW 2620
Effective Date: 27 April 2026
Version: 1.0
Last Updated: 27 April 2026
This Privacy Policy describes how FLOSMOSIS PTY LTD (ACN 697 323 925; in this document, "FLOSMOSIS," "we," "our," or "us") handles personal information in connection with:
This Policy governs all FLOSMOSIS-handled personal information, including data arising from use of the FLOSTRUCTION product and from FLOSMOSIS's activities as the Foundation Entity. WLES Foundation governance materials are published at flosmosis.com/wles per WLES Foundation Constitution v1.0 clause 7.3 (open standard commitment).
FLOSMOSIS is an Australian Privacy Principles entity within the meaning of the Privacy Act 1988 (Commonwealth). We comply with the Australian Privacy Principles and with the Australian Privacy Act in our handling of personal information.
FLOSMOSIS collects personal information in the following categories and for the following purposes.
FLOSTRUCTION operates under a dual-party data model: the employer (FLOSTRUCTION's direct customer) contracts for the service, and workers of the employer use the worker-facing PWA. Information is collected from both parties.
From employers and their administrators:
From workers using the FLOSTRUCTION PWA:
From supervisors:
In our capacity as the Foundation Entity for the WLES (per Constitution v1.0 clause 1), we may collect:
Such information is held by FLOSMOSIS as the Foundation Entity and is governed by this Policy. The full WLES Foundation Constitution is published at flosmosis.com/wles/foundation/constitution.
We use personal information only for the following purposes.
Operating the FLOSTRUCTION product: processing shift events, generating WLES receipts, delivering receipts to workers and employers, producing payroll export files, providing customer administration tools.
Authenticating users: verifying identity for access to the worker PWA, the supervisor SMS approval flow, and the employer admin dashboard.
Supporting customers: responding to enquiries, providing technical support, investigating issues raised by users, onboarding new customers.
Improving the product: analysing usage patterns, identifying bugs and performance issues, developing new features. This analysis is performed on aggregated or de-identified data wherever feasible.
Complying with legal obligations: meeting our record-keeping obligations under Australian law, responding to lawful requests from regulators, courts, and tribunals.
Communications: sending transactional messages (shift approvals, receipt delivery, billing notices) and, with your express consent, product updates and marketing communications.
Standards development: in our capacity as the Foundation Entity for the WLES, supporting the development of the WLES specification and related standards artefacts. Information collected in this context is handled in accordance with this Policy and with the Foundation Entity's open-standard commitment under WLES Foundation Constitution clause 7.3.
We do not use personal information for purposes unrelated to these functions. We do not sell personal information to third parties.
A distinctive feature of FLOSTRUCTION is that shift records are cryptographically sealed using the WLES v1.0 standard. This has specific consequences for personal information handling that users should understand.
Once a WLES event is sealed, its content cannot be altered without the alteration being detectable. This integrity property is the feature that gives WLES records their evidentiary value. It also means that corrections to shift records are handled through new events appended to the chain (rather than through modification of the original event).
For personal information handling, this architectural choice has the following implications:
Identity binding is separable from the cryptographic chain. Identities of workers, supervisors, and employers are represented in WLES events by opaque identifiers (UUIDs), not by names or direct personal identifiers. The mapping from identifier to real-world identity is stored separately from the chain. This design permits compliant response to deletion requests: the identity-to-identifier mapping can be deleted, rendering historical chain records no longer linkable to the individual, while preserving chain integrity for remaining subjects.
Deletion requests are honoured at the identity mapping layer. Where an individual exercises rights under the Privacy Act to request deletion of their personal information, we delete the identity mapping for that individual from the operational systems within reasonable timeframes, subject to the exceptions described in Section 8.
Historical shift data is retained. Historical WLES records (containing opaque identifiers, shift times, site identifiers, and verified event hashes) are retained for the periods described in Section 8, reflecting our obligations under Australian employment, tax, and evidence law. After identity mapping deletion, such records cannot be linked to the individual.
We disclose personal information only in the following circumstances.
To the employer who engages FLOSTRUCTION services in relation to their workers: the employer receives shift data, approval records, and worker identity information for the workers engaged through their organisation. This is inherent in the nature of the service.
To the worker in relation to their own data: workers receive their own shift records, receipt URLs, and verification data. Workers may share their own WLES receipts with third parties (such as unions, legal advisers, or tribunals) at their own discretion.
To payroll platforms and related counterparties integrated at the employer's direction: where an employer has authorised integration between FLOSTRUCTION and a third-party payroll platform, accounting system, or similar service, we share shift data with that service in accordance with the employer's authorisation.
To our service providers: we engage third-party service providers (hosting, payment processing, SMS delivery, email delivery, error monitoring) who process personal information on our behalf. These providers are bound by contractual obligations to handle personal information only for our purposes and in accordance with applicable privacy law.
To regulators, courts, and tribunals: where we are required by law to disclose personal information, or where we in good faith believe disclosure is necessary to protect our rights, to comply with a legal obligation, or to respond to a valid government request.
In connection with business transactions: if we are involved in a merger, acquisition, or sale of assets, personal information may be transferred as part of that transaction, subject to the acquiring entity's commitment to respect the privacy obligations set out in this Policy.
We do not disclose personal information for commercial purposes unrelated to the services we provide.
We primarily store personal information within Australia. Some service providers we engage (for example, cloud infrastructure providers, email delivery providers, error monitoring services) may store, process, or have access to personal information outside Australia.
Where personal information is disclosed to an overseas recipient, we take reasonable steps to ensure that the recipient does not breach the Australian Privacy Principles in relation to the information. We enter into contractual arrangements with overseas service providers requiring them to comply with privacy obligations substantially similar to those under Australian law.
Specific overseas jurisdictions in which personal information may be processed include the United States (cloud infrastructure, payment processing, email delivery) and the European Union (certain infrastructure services). Users who wish to understand the specific jurisdictional processing arrangements for particular service providers may contact us at privacy@flosmosis.com.
We take reasonable steps to protect personal information from misuse, interference, loss, and from unauthorised access, modification, or disclosure. Our security measures include:
Despite these measures, no method of electronic storage or transmission is perfectly secure. Users should understand that any disclosure of personal information to FLOSMOSIS carries residual risk.
We retain personal information for the following periods.
Worker shift records and WLES chain data: retained for a minimum of seven years from the date of each shift, consistent with the record-keeping obligations under section 535 of the Fair Work Act 2009 (Commonwealth) and associated regulations. For workers whose shifts occurred under employers subject to state labour hire licensing regimes, retention periods may be longer where state legislation requires.
Identity mapping (linking WLES opaque identifiers to named individuals): retained for the same period as the underlying shift records, subject to deletion requests under the Privacy Act. When a deletion request is honoured, the identity mapping is removed but the underlying chain records remain (with their opaque identifiers, no longer linkable to the individual).
Customer billing and account information: retained for at least seven years after the end of the customer relationship, consistent with tax and business record-keeping obligations.
Communications with users: retained for up to seven years after the communication, or longer where retention is required by law.
Technical logs: retained for up to twelve months, used for security monitoring and incident investigation.
Foundation-related correspondence: retained by FLOSMOSIS as the Foundation Entity in line with the underlying business and legal record-keeping obligations applicable to the correspondence.
After the applicable retention period, personal information is either deleted or irreversibly anonymised.
Under the Australian Privacy Principles, you have the following rights in relation to your personal information held by FLOSMOSIS:
Right of access: you may request access to the personal information we hold about you.
Right of correction: you may request that we correct personal information that is inaccurate, incomplete, or out-of-date.
Right of deletion: you may request that we delete personal information we hold about you, subject to exceptions where retention is required by law or by our legitimate business interests (such as outstanding obligations under existing customer agreements).
Right to withdraw consent: where we process personal information on the basis of your consent, you may withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing conducted before withdrawal.
Right to complain: you may complain to us about our handling of your personal information by contacting privacy@flosmosis.com. If you are dissatisfied with our response, you may complain to the Office of the Australian Information Commissioner at oaic.gov.au.
To exercise any of these rights, contact privacy@flosmosis.com. We will respond within thirty days.
FLOSTRUCTION is designed for use by workers over the age of 18. We do not knowingly collect personal information from children under 18. If you believe we have inadvertently collected such information, contact privacy@flosmosis.com and we will take reasonable steps to delete it.
Where a worker over 18 operates under a specific labour arrangement involving young workers (for example, in some agricultural or apprenticeship contexts), FLOSMOSIS does not separately process information about those young workers unless they are themselves registered users of the FLOSTRUCTION system with appropriate consents.
The flosmosis.com website uses cookies and similar technologies for the following purposes:
We do not use cookies for third-party advertising or for tracking users across non-FLOSMOSIS websites.
Users may disable non-essential cookies through their browser settings. Disabling essential cookies will impair the operation of the FLOSTRUCTION applications.
We may update this Policy from time to time. The current version is always published at flosmosis.com/privacy. Material changes are notified to existing users by email at least thirty days before the changes take effect. The date at the top of this Policy indicates when it was last updated.
For privacy enquiries:
FLOSMOSIS PTY LTD Privacy Officer: Lauren Kate de Mestre, Corporate Counsel Email: privacy@flosmosis.com Post: 55 Reginald Road, Googong NSW 2620
For Foundation-related privacy matters: Email: standards@flosmosis.com