Logo


Version 1.1 · Effective 28 June 2026 · Next review June 2027

This Privacy Policy explains how Mibowork Pty Ltd (ABN 68 640 006 980 / ACN 640 006 980) (“Mibowork”, “we”, “us”, “our”) collects, uses, discloses, stores, and protects personal and sensitive information obtained through the Mibo psychosocial risk management platform, our websites, application programming interfaces (APIs), and related services (collectively, the “Services”).

It applies to users and customers of the Mibo platform, employees, contractors, suppliers, and any individual whose personal information we handle.

This Policy aligns with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), the EU General Data Protection Regulation (EU GDPR), the UK General Data Protection Regulation (UK GDPR), and the controls maintained as part of Mibowork’s ISO/IEC 27001:2022 certified Information Security Management System.

1. Lawful basis for processing

Where the EU GDPR or UK GDPR applies, Mibowork relies on the following lawful bases for processing personal data:

  • Consent — for participation in well-being surveys, psychosocial assessments, and any optional submission of health-related information;
  • Contractual necessity — to deliver and support the Mibo platform under our customer agreements;
  • Legitimate interests — to operate, secure and improve the Services and to perform analytics, where those interests are not overridden by individual rights;
  • Legal obligation — to meet reporting, retention or other obligations imposed by law.

Where the Privacy Act 1988 (Cth) applies, sensitive information (including health information) is collected only with the individual’s consent under APP 3.3, or otherwise as permitted under the APPs. Under the EU GDPR / UK GDPR, sensitive information is processed only on the basis of explicit consent under Article 9(2)(a) or another lawful condition under Article 9.

2. Categories of information collected

Mibowork collects only the information reasonably necessary for the purposes set out in this Policy, including:

  • Identifiers — name, work email, employee identifier (where supplied by the customer), and contact details;
  • Demographic information — age range, gender, work role, business unit, location and country (where supplied);
  • Well-being and engagement information — survey responses, psychosocial risk indicators, and related metrics;
  • Technical and usage information — device identifiers, IP address, session logs, and audit logs of platform actions;
  • Sensitive information (with consent) — information about psychological well-being, mental health, or other health-related indicators relevant to psychosocial risk.

3. Purpose of processing

We process personal information to:

  • provide, secure, and support the Services to our customers;
  • enable customers to assess, manage and report on psychosocial risks and employee well-being in accordance with their instructions and applicable workplace health and safety obligations;
  • produce aggregated and de-identified analytics for customer reporting and product improvement;
  • comply with legal, regulatory, audit and contractual obligations;
  • administer accounts, billing and customer support.

Mibowork does not make automated decisions that produce legal effects or similarly significant effects concerning individuals.

4. Disclosure of information

We may disclose personal information to:

  • authorised Mibowork personnel who require access to perform their duties;
  • service providers and sub-processors engaged to support the Services (including Microsoft Azure for hosting). A current list is maintained under the Mibowork Data Processing Agreement;
  • our customers, in respect of the personnel they have authorised to use the Mibo platform. Survey results are returned to customers in aggregated or de-identified form unless the individual has expressly consented otherwise;
  • professional advisers (legal, accounting, auditors) under obligations of confidence;
  • regulators or law enforcement, where required or authorised by law.

We do not sell or trade personal information.

5. International transfers

Production data for the Mibo platform is hosted in Microsoft Azure regions within Australia (Australia East and Australia Southeast). Personal information is stored at rest within Australia.

Where cross-border transfers occur — for example, where customer personnel access the platform from outside Australia, or where a sub-processor is engaged outside Australia — Mibowork relies on appropriate transfer mechanisms, including adequacy decisions, the Standard Contractual Clauses, the UK International Data Transfer Agreement or Addendum, or other safeguards under the EU GDPR (Articles 44–49) and UK GDPR.

In respect of cross-border disclosures of personal information subject to the Privacy Act 1988 (Cth), Mibowork takes reasonable steps to ensure that overseas recipients do not breach the APPs, in accordance with APP 8.

6. Information security

Mibowork is certified to ISO/IEC 27001:2022 (Certificate No. 500-24206-IS, Citation Certification under UKAS, valid 19 August 2025 to 18 August 2028). Our Information Security Management System includes:

  • encryption of data in transit (TLS 1.2 or higher) and at rest (AES-256), with key management via Azure Key Vault;
  • multi-factor authentication and role-based access control with least-privilege defaults;
  • web application firewall, DDoS protection, network segregation, and vulnerability management;
  • centralised security event logging, with retention managed in accordance with our Data Retention Policy and Backup and Recovery Policy;
  • annual independent penetration testing of production environments;
  • annual security awareness and privacy training for all personnel.

Despite these measures, no method of transmission or storage is completely secure. If we become aware of a Personal Data Breach affecting customer data, we notify the affected customer in accordance with our Incident Response Policy and the Data Processing Agreement.

7. Data retention and deletion

Retention periods are governed by our Data Retention Policy and Backup and Recovery Policy. Personal information is retained only for as long as required for the purposes for which it was collected, or as required by applicable law, and is then securely deleted or de-identified.

On expiry or termination of a customer agreement, personal information processed on behalf of that customer is returned or deleted in accordance with the Data Processing Agreement.

8. Your rights

Subject to applicable law, you may request to:

  • access the personal information we hold about you;
  • correct information that is inaccurate or out of date;
  • request deletion of your information, where a legal basis for retention does not apply;
  • restrict or object to certain processing;
  • request portability of your information; or
  • withdraw any consent previously given (without affecting the lawfulness of processing carried out before withdrawal).

Where a customer has provided your information to Mibowork in connection with the Mibo platform, that customer is the controller of your information and we will direct your request to them. Where Mibowork is the controller, we will respond to your request without undue delay and in any event within one month of receipt, in accordance with Article 12(3) of the EU GDPR and UK GDPR (extendable by up to two further months where the request is complex or numerous), and within 30 days under the Privacy Act 1988 (Cth).

Requests may be made to security@mibowork.com.au.

9. Cookies and analytics

Our websites use cookies and similar technologies. Necessary cookies are required for the operation of the site. Analytical and non-essential cookies are used only with your consent, in accordance with the Mibowork Cookie Notice published on our website.

10. Research and statistical use

De-identified or aggregated data may be used for research, statistical analysis, benchmarking and publication, in line with the OAIC De-Identification Decision-Making Framework and recital 162 of the EU GDPR. Where data has been de-identified, it cannot be re-identified by reasonably available means and is not personal information.

11. Complaints and contact

If you have a privacy-related question, request, or complaint, please contact:

Privacy Officer
Mibowork Pty Ltd
321 Indooroopilly Road, Indooroopilly QLD 4068
Email: security@mibowork.com.au

We will acknowledge your contact promptly and respond within the timeframes set out in clause 8.

If you are not satisfied with our response, you may contact the relevant supervisory authority:

  • In Australia: the Office of the Australian Information Commissioner (OAIC) — www.oaic.gov.au;
  • In the European Economic Area: your local Data Protection Authority;
  • In the United Kingdom: the Information Commissioner’s Office (ICO) — www.ico.org.uk.

12. Updates to this Policy

This Policy may be amended from time to time to reflect changes in our practices, in technology, in legal requirements, or other factors. The current version is published at mibowork.com.au, with the effective date and version number shown at the top of this page. Material changes are highlighted on our website.

13. Certification and assurance

Mibowork is certified to ISO/IEC 27001:2022 (Certificate No. 500-24206-IS, Citation Certification under UKAS). The privacy controls in this Policy are supported by the Mibowork Information Security Management System and are subject to internal audit and annual external surveillance.