PRIVACY POLICY · 4 OCTOBER 2026
Your information.
Frederik Muller trading as Ozzie Spark (Ozzie Spark Services), ABN 11 317 453 573, operates Ozzie Spark Safety from Toowoomba, Queensland. For privacy questions, access or correction requests, account closure or complaints, contact infoozziespark@gmail.com.
What we collect
We collect account email addresses and authentication information; business names and locations; worker names, employee references and roles; job descriptions and manager-confirmed duties; assignment details; reading acknowledgements; assessment answers, attempts, results and dates; content versions; and completion declarations and certificate identifiers. Technical services may process IP addresses, device/browser information, security events and operational logs.
When subscription billing is enabled, Stripe handles payment details. We store billing identifiers, subscription status, amount and access dates. The app does not need or store your full card number. Transactional email providers process recipient addresses, message contents and delivery information.
Support enquiries include your name, email, optional business name, subject and message. We send them to our support inbox through Resend to respond to you. Short-lived, keyed hashes of network addresses and email addresses help limit form abuse; contact-form rate-limit entries expire after one hour and are removed during subsequent submissions.
Where information comes from and why we use it
Information comes from you, your employer or business administrator, your use of the app and providers handling authentication, payments or messages. We use it to provide accounts and training, match workers to assignments, assess knowledge questions, retain evidence, notify managers, administer subscriptions, provide support and investigate security or service problems.
Managers should tell workers about this collection before entering their information. If required information is not provided, we may be unable to create an account, assign training or record completion. Do not enter health records, identity documents, payment-card details or other sensitive information into job descriptions or free-text fields.
Who can access it
Authorised managers and viewers can access their business's records according to their role. Workers can access training assigned to their verified account. Ozzie Spark administrators use account and subscription information to operate the service; support or security access to other information is limited to legitimate operational needs. We may also disclose information where required or authorised by law.
We use Supabase for authentication and data storage, Vercel for hosting, OpenAI for optional AI guidance, and Stripe and Resend for billing and email when enabled. These providers process information needed to perform their services. We do not sell employee training records or use them for advertising.
AI guidance
When a manager requests AI duty suggestions, the app sends the position and supplied job-description text to OpenAI. Worker name and employee reference are not deliberately included. Managers must remove personal and sensitive details from that text first. Suggestions are temporary and do not approve training, decide employment outcomes or become completion evidence. The app requests that responses are not stored by the API; provider security and abuse-monitoring retention can still apply.
Hosting and overseas processing
The primary application database is hosted in Sydney, Australia. This does not mean every processing activity stays in Australia. Hosting, email, AI, billing, support and security services may process information overseas, including in the United States and other countries used by their infrastructure and subprocessors. Our configured email service region is in Japan. Contact us for current provider information if this affects your business requirements.
Security, retention and account closure
We use authenticated access, business-specific permissions and server-side checks to limit access and protect recorded results. No online service can promise absolute security. Protect your credentials and report suspected unauthorised access promptly.
Training records remain stored while the account exists, including after subscription expiry, so authorised users can retrieve them. We do not automatically erase training evidence when billing stops. Request account closure or deletion through our privacy contact. We verify authority, discuss affected records and remove information no longer needed, subject to lawful retention, dispute, fraud-prevention and backup requirements. Deleted data may remain in protected backups until those backups expire. Keep your own copies of records your business must retain.
Access, correction and complaints
You can inspect available records in the app or contact us to request access or correction. We may ask for information needed to verify identity and authority. Corrections to historical assessments may need an explanatory record rather than overwriting what was submitted. If we cannot fulfil a request, we will explain why and available options.
We will acknowledge a privacy complaint and aim to respond substantively within 30 days. If unresolved, you may contact the Office of the Australian Information Commissioner at oaic.gov.au, where its jurisdiction applies.
Cookies and policy changes
Authentication cookies or equivalent browser storage keep you signed in. The app does not currently use advertising trackers. Third-party services may use their own cookies on their pages. We will update this policy when our practices change and notify account holders of material changes.