Plain English Guide

Privacy is our foundation,
not just a policy.

When dealing with workplace harm and psychosocial risk, trust is everything. We believe you shouldn't need a law degree to understand how your data is protected. This is our plain English commitment to your safety and anonymity.

What Information We Collect

To provide you with the appropriate support and to generate high-level risk insights, we collect:

  • Account Details: Your email address and secure password for logging in.
  • Assessment Data: Your responses to psychosocial and workplace safety questionnaires.
  • Voluntary Demographics: Non-identifying demographic data to ensure equitable reporting.

We only ask for what is strictly necessary to help you and to improve workplace safety.

What We Do NOT Share

We draw a strict, non-negotiable boundary between your personal identity and your employer.

  • We never share your name, email, or contact details with your employer.
  • We never provide individual assessment responses to management or HR.
  • We never share your IP address, device details, or location data.
  • We never sell any data to third-party advertisers or brokers.

Individual Ownership of Data

You own your narrative. Your data belongs to you, not your employer.

At any point, you have the absolute right to view the data you have provided, update it, or permanently delete your account and all associated assessment records. If you choose to delete your account, your data is scrubbed from our active databases immediately.

How Organisational Reporting Works

Organizations use WorkRight23 to identify systemic risks (like burnout, bullying, or unsafe conditions). To do this safely, we use a process called Aggregation and Cryptographic Decoupling.

This means your individual answers are grouped together with at least several other colleagues before the data is analyzed. The organization receives a high-level "Risk Constellation" (e.g., "15% of the sales team is experiencing high burnout"). It is mathematically impossible for them to trace that 15% back to you.

Security Protections

We employ banking-grade security to ensure your data cannot be intercepted or breached.

  • End-to-End Encryption: All data transmitted between your device and our servers is secured using AES-256 encryption.
  • Strict Access Controls: Even our own engineers cannot view the raw, unencrypted contents of your clinical assessments.
  • Compliance: We are fully compliant with GDPR, HIPAA, and Australian Privacy Principles.

Our Confidentiality Commitment

WorkRight23 was built to protect vulnerable individuals, whistleblowers, and victims of workplace and domestic harm. We will fiercely protect your confidentiality. We will never voluntarily disclose your identity unless we are legally compelled by a court order, or if there is an imminent threat to human life.

Need the legal specifics?

While this page summarizes our approach in plain English, our formal Privacy Policy contains the exact legal clauses and regulatory references governing our platform.

Read the Legal Privacy Policy