Who we are
Work Sync is operated by Abbier Pty Ltd ABN 87 101 231 029, trading as Work Sync (Work Sync, we, us or our).
Our contact details are:
- Email: hello@worksync.com.au
- Address: 18 Second Ave, Maroochydore QLD 4558, Australia
This Privacy Policy explains how we collect, hold, use and disclose personal information through the Work Sync website, individual purchases, participant access and support activities.
If a school or other organisation arranges access to Work Sync, that organisation may also have its own privacy obligations and notices. Any organisation-specific agreement or notice should be read with this policy.
The information we collect
The information we collect depends on how you interact with Work Sync.
Website visitors and enquiries
When you use our public website or submit an enquiry, we may collect:
- your organisation name, contact name and work email address;
- your phone number and role, if you choose to provide them;
- the message you submit and whether you asked for a demonstration or made another enquiry;
- campaign details contained in the link you used to reach the website, such as UTM source, medium or campaign values;
- technical and security information such as request time, IP address, browser or device information and records used to prevent duplicate or abusive submissions; and
- records showing whether acknowledgement and internal notification emails were sent.
Campaign details are held in your browser's session storage for the current browser session and may be included with an enquiry. We also use Google Analytics 4 on the public marketing website to understand visitor numbers, referral sources, campaign performance and website activity. This can include page views, engagement, successful enquiry and demo submissions, purchase-button clicks, FAQ questions opened, video play-button clicks and playback progress, browser and device information, approximate location and cookie identifiers. Purchase-button clicks do not confirm a completed purchase. Google signals and advertising personalisation are disabled in our website tag. Our hosting and security providers also process ordinary technical logs needed to deliver and protect the website.
Purchasers of individual access
When you purchase individual Work Sync access, we may collect:
- the purchaser email address confirmed through Stripe;
- limited order and transaction details, including transaction identifiers, date, amount, GST, currency and payment or refund status;
- records needed to deliver the payment confirmation and setup emails; and
- support, security and audit information relating to the purchase and access unit.
Stripe processes the information needed to operate Checkout, process and protect the payment and prevent fraud. Depending on the transaction, this can include contact and transaction details, card and billing information, IP address, device and browser information, fraud-prevention signals and information about an incomplete Checkout. Work Sync may access the billing address in Stripe when confirming a transaction, but the Work Sync database does not store the purchaser's card details or copy the Stripe billing address.
Stripe explains its own handling in its Privacy Policy.
Participants using individual access
For an individual participant, we may collect:
- the participant's first-name profile label and assigned email address;
- the Sent from label selected for the participant's initial-access email;
- discovery responses and completed results;
- changes made when videos are rewatched and occupations or other exploration choices saved in Wayfinder;
- records needed to send initial-access, return-link and verification-code emails; and
- limited session, access, security and support records.
Each individual access unit has one authorised participant email address. That address controls the profile's initial and return access and receives verification codes. Before the participant selects Start exploring, the purchaser can correct the participant details. Selecting Start exploring locks the access to that participant, profile and email address.
Participants using Work Sync through an organisation
Where a school or another organisation provides access, we may receive participant details from that organisation, such as a student identifier, authorised email address, organisation association and access record. We may also collect the participant's discovery responses, completed Work Interest Summary and saved Wayfinder choices. Authorised organisation users may be able to view participant results and saved choices in accordance with their agreement and access permissions.
Organisation representatives
If you act for a school or another organisation, we may collect:
- your name, work contact details, role and organisation association;
- information needed to create and administer authorised dashboard access;
- records of participant invitations, allocations and other actions taken through the dashboard; and
- support, session and security records associated with the organisation relationship and authorised access.
We use this information to manage the organisation relationship, provide authorised features, protect participant information and respond to support or security issues.
Support and communications
If you contact us, we collect the information in your message and the information reasonably needed to verify the request, investigate the issue and record the outcome. Please do not send us passwords, verification codes or complete access links by ordinary email.
How we collect personal information
We may collect personal information:
- directly from you when you use Work Sync, buy access, complete a form or contact us;
- from a purchaser who assigns individual access to a participant;
- from a school or organisation that arranges participant access;
- automatically from the browser, device and service systems needed to provide and protect Work Sync; and
- from service providers such as Stripe and Postmark when they report payment or email-delivery events.
If a purchaser or organisation gives us information about another person, they should make sure the person knows that their information will be provided to Work Sync and can access this Privacy Policy.
Why we use personal information
We use personal information to:
- provide the public website and respond to enquiries;
- create, confirm and support purchases;
- create and protect participant access;
- administer authorised organisation and dashboard access;
- provide the discovery experience, results, rewatch and Wayfinder features;
- send payment, setup, access, return-link and verification emails;
- verify authority before handling access or correction requests;
- detect abuse, protect accounts and investigate delivery, payment or security problems;
- keep records needed for accounting, tax, dispute management and legal obligations;
- maintain, troubleshoot and improve the reliability and accessibility of the service; and
- enforce our terms and protect the rights, safety and security of participants, customers, Work Sync and others.
Work Sync automatically processes a participant's discovery responses to generate their Work Interest Summary and related result views. Work Sync does not use those results to make admission, employment, course-eligibility or other high-impact decisions about the participant.
Where an organisation arranged access, its authorised representatives may use the results to support education or career-exploration conversations. The organisation is responsible for its own decisions and should not use Work Sync results as the sole basis for a decision that materially affects a participant.
We do not sell personal information.
Children and young people
Work Sync is recommended for participants aged 10 and over, but the service does not currently impose or verify a minimum age.
If you're under 18, we encourage you to involve a parent or guardian.
Work Sync does not currently use an age gate or a parental-consent check. Because we do not ask participants to prove their age, we apply the same default privacy and security protections to every participant.
A short explanation for younger participants
- We use your first name and email address to give you access and help keep your profile secure.
- We save your discovery answers, results and later changes so you can return to them.
- We send access links and verification codes to the email address connected to your profile.
- If a school or organisation arranged your access, its authorised staff may be able to see your Work Interest Summary and saved Wayfinder choices.
- You can ask us what information we have about you or tell us if something is wrong.
If a young person does not understand this policy or the choices they are being asked to make, they should ask a trusted adult to help them before continuing.
When we disclose personal information
We disclose personal information only where reasonably needed for the purposes described in this policy, including to:
- Stripe, which hosts Checkout and processes contact and transaction details, card and billing information, device and browser information, fraud-prevention signals, refunds and payment disputes;
- Postmark, which processes recipient addresses and email content to deliver Work Sync transactional emails;
- MongoDB Atlas, which provides database hosting;
- Netlify, which hosts the public website and Work Sync application and runs server functions;
- Cloudflare Turnstile, which helps protect the website enquiry form from automated abuse;
- Vimeo, when a visitor or participant loads embedded video content;
- Google, which processes public marketing website usage and campaign information through Google Analytics 4;
- professional advisers, insurers, auditors or contractors who need the information to provide services to us and are subject to appropriate duties; and
- regulators, courts, law-enforcement bodies or other parties where required or authorised by law, or where reasonably necessary to protect rights, safety or security.
We may also disclose participant information to an authorised school or organisation where that organisation arranged the participant's access and its agreement and permissions allow that access.
We do not disclose an individual participant's access link, verification code or protected email information merely because someone asks for it. We first take reasonable steps to verify the request and the relevant authority.
Overseas disclosure and processing
Some service providers process or support personal information outside Australia. Based on the services currently identified:
- Stripe may process information in Australia, Ireland, the United States and other countries in which Stripe and payment-network participants operate;
- Postmark processes email-delivery information in the United States;
- Google may process website analytics information on servers in the United States and other countries where it operates;
- Netlify, Cloudflare and Vimeo may process technical or service information in the United States and other countries in which their contracted services and support teams operate; and
- MongoDB Atlas stores and processes Work Sync data in the selected production cluster region.
The exact countries can depend on the provider account, selected hosting region and support arrangements. We take reasonable steps to use providers with appropriate privacy and security commitments, but overseas recipients may be subject to the laws of their location.
Cookies and browser storage
Work Sync uses essential cookies and browser storage to provide and protect the website and application. The public marketing website also uses Google Analytics cookies to distinguish visits and measure website use. These analytics cookies are optional for using the website and are separate from the essential storage used by the Work Sync application.
- Authentication and session cookies keep a purchaser setup session, participant session or authorised organisation dashboard session secure. Some are browser-session cookies and are removed when the browser session ends; others are removed or replaced when the applicable session is finished, revoked or expires.
- Session storage supports short-lived navigation and session handoffs, keeps an authorised dashboard session scoped to its browser tab and retains campaign details for the current website session when those details were present in the arrival link.
- Local storage supports inactivity protection across browser tabs and keeps limited stage-navigation records used by the application. It does not contain payment-card details or complete access links.
- Google Analytics uses cookies such as _ga and _ga_* to distinguish browsers and sessions. Our marketing website tag does not enable Google signals or advertising personalisation, and does not send enquiry field values, payment details or participant results to Google Analytics.
Cloudflare Turnstile and Vimeo may use their own cookies or similar technologies when their protected form or embedded video service is loaded. Their handling is governed by their own privacy information.
You can manage or block cookies using your browser settings. Blocking Google Analytics does not prevent you from browsing the marketing website or making an enquiry. Blocking essential cookies or browser storage may prevent Checkout setup, participant return, dashboard access, inactivity protection or other core functions from working correctly.
For more information, see how Google uses information from sites that use its services.
Google also provides an Analytics opt-out browser add-on for supported browsers.
Security
We take reasonable technical and organisational steps to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure.
These steps include access controls, secure browser sessions, restricted support procedures and encryption or secure hashing of certain identifiers where appropriate. Card details are handled by Stripe rather than stored in the Work Sync database.
No method of transmission or storage is completely secure. If you believe an access link, email account or Work Sync interaction has been compromised, contact hello@worksync.com.au promptly.
How long we keep information
We keep personal information only for as long as it is reasonably needed for the purposes described in this policy, subject to the following current rules:
- An unpaid staged order and its remaining browser reference are scheduled for deletion 30 days after the order expires.
- A limited paid transaction record is retained for seven years after payment for financial, tax and dispute records.
- Detailed finalised email-delivery and provider-reconciliation information is scheduled for deletion 90 days after final resolution. A minimal, non-sensitive outcome may remain where needed to explain the access or delivery history.
- An active access unit, the participant's protected email address, completed results and current return access have no fixed expiry while the paid Work Sync service remains available. This supports the promised lifetime access described in the Purchase Terms.
- Minimal security and owner-support audit records remain while the access unit exists and for 365 days after an authorised deletion. They are then deleted or irreversibly de-identified. These audit records do not contain raw email addresses, access links, verification codes, provider payloads or discovery responses.
- Website enterprise-enquiry records currently receive a retention review date 18 months after submission. The outcome of that review depends on whether the enquiry remains active and whether the information is still reasonably needed for the relationship or business records.
Some information may need to be kept for longer where required by law or reasonably needed for a current complaint, dispute, security investigation or legal claim. When information is no longer required, we take reasonable steps to delete it or irreversibly de-identify it.
Access and correction requests
You may contact us to ask for access to or correction of personal information that we hold about you.
We will need to verify the request before acting. For an individual purchase, this may include checking the purchaser email and a matching Stripe receipt or order reference. After participant access has been locked, support may correct the email only for the same participant; it cannot transfer the access to another person.
Send requests to hello@worksync.com.au. We aim to respond within 30 days.
Privacy questions and complaints
Our Privacy Contact receives questions and complaints at hello@worksync.com.au. You can also write to:
Work Sync, 18 Second Ave, Maroochydore QLD 4558, Australia
Please describe the issue and the outcome you are seeking. We will acknowledge the complaint, investigate it, ask for any additional information we reasonably need and provide a written response explaining the outcome and any action we will take. We aim to complete this process within 30 days. If we need more time, we will explain why and provide an updated timeframe.
If you are not satisfied with our response, you can contact the Office of the Australian Information Commissioner to find out whether it can consider your complaint.
Changes to this policy
We may update this Privacy Policy when our services, providers or legal obligations change. The current version and effective date will be published on this page. If a change materially affects how we handle existing participant information, we will take reasonable steps to provide additional notice where appropriate.