Emprovia OnSite Privacy Policy

Last updated: 31 August 2026

Emprovia OnSite is a product of Fair Supports Pty Ltd (ABN 85 677 767 761) (“Fair Supports”, “we”, “us”, “our”). This policy explains how we collect, use, store, and disclose personal information through the Emprovia OnSite website (emprovia.com.au) and the Emprovia OnSite app (onsite.emprovia.com.au), and how you can access or correct your information or make a complaint.

We are committed to handling personal information in accordance with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth).

1. Who this policy covers

Emprovia OnSite is used by three groups of people, and all are covered by this policy:

  • Business customers — the organisation that signs up for Emprovia OnSite and the individuals (managers, admins) who set up and run the account.
  • Workers — people rostered, invited, or added to shifts by a business customer, whose location, attendance, and shift-evidence data is recorded through the app even though they are not the paying customer.
  • Clients and participants — people whose support is delivered or recorded through the Service. Records about them (attendance confirmations, notes, and incident records) may include health or disability information, which is sensitive information under the Privacy Act. We handle it with the protections that classification requires, we collect it only as configured by the business customer, and we never use it for any purpose beyond providing the Service.

If you are a worker whose employer or labour-hire agency uses Emprovia OnSite, your employer is responsible for telling you Emprovia OnSite is in use and for configuring what evidence is collected. This policy explains what Emprovia OnSite itself does with that information once collected.

2. What we collect

From business customers, at signup and during use:

  • Business name, industry, and country
  • Contact name, mobile number, and work email
  • Number of workers and payroll system in use
  • Billing details (processed by our payment provider, Stripe — we do not store full card numbers)
  • Free-text information submitted through the “Book a walkthrough” form (organisation, work email, worker headcount, shift-scenario description)

From workers, through the worker app, only where an organisation configures it:

  • Shift acceptance and clock-in/clock-out timestamps
  • Location information captured during an active shift, used to support attendance evidence
  • Notes and any evidence submitted as part of a shift record
  • Client/site confirmation of attendance
  • In future, if we launch the planned automated voice/IVR calling feature, call metadata and any information provided during that call (this section will be updated and you will be notified before this feature goes live)

About clients and participants:

  • Attendance confirmations
  • Support and shift notes, and incident records, entered by workers or managers
  • Contact details the business customer adds

Automatically collected:

  • We use essential cookies only to keep you signed in — these can’t be switched off and don’t track you.
  • We do not currently use analytics, advertising, or tracking cookies on the Emprovia OnSite website or app. If this changes, we will update this policy and add a cookie consent mechanism before any such technology is deployed.

3. Why we collect it

We collect and use personal information to:

  • Provide and operate the Emprovia OnSite service, including shift scheduling, attendance verification, and evidence/audit records
  • Support disputes between businesses, workers, and clients about attendance or hours worked
  • Communicate with business customers about their account, billing, and service updates
  • Respond to enquiries submitted through the booking form
  • Improve and maintain the service, and meet our legal obligations

We do not sell personal information, and we do not use worker location or attendance data for advertising purposes.

4. Who we share it with

We disclose personal information only to:

  • Stripe, to process subscription payments
  • Vercel and Supabase (hosted in the Sydney region), which host the Emprovia OnSite application and store account and shift data
  • Resend (email) and ClickSend (SMS), to deliver account notifications and messages. The planned voice/IVR calling feature is not yet in use; this list will be updated before it launches
  • The business customer that manages a worker’s shifts, who can see that worker’s attendance and location records within their organisation’s account
  • Regulators, law enforcement, or courts where required by law
  • A prospective buyer or successor entity in the event of a business sale, merger, or restructure, subject to confidentiality obligations

We do not disclose personal information to any other third party, and in particular we do not share data with advertising networks.

5. Cross-border disclosure

Your data is hosted in Australia (Vercel and Supabase, Sydney region). Stripe (payments) and Resend (email) process limited data in the United States; ClickSend (SMS) is Australian-based. We take reasonable steps to ensure any personal information processed overseas is handled consistently with the Australian Privacy Principles, as required by APP 8.

6. Data security

We take reasonable technical and organisational steps to protect personal information from misuse, interference, loss, and unauthorised access, including encryption of data in transit and restricted access to shift/location records within each organisation’s account. No system is completely secure, and we cannot guarantee absolute security.

7. Data retention

We retain shift, attendance, and location evidence for as long as the business customer’s account is active, and for a reasonable period afterward to support payroll, audit, or legal requirements. Business customers can request deletion of specific records subject to any legal retention obligations (for example, employment or payroll record-keeping laws).

8. Notifiable data breaches

If we experience a data breach that is likely to result in serious harm to affected individuals, we will notify the Office of the Australian Information Commissioner (OAIC) and affected individuals in accordance with the Notifiable Data Breaches scheme.

9. Your rights — access, correction, and complaints

You can ask us to access or correct personal information we hold about you. Workers, clients, and participants should generally raise this with the business customer that manages their account first, since that organisation controls day-to-day account access; we will also respond directly to requests sent to us.

To make a request or complaint, contact onsite@emprovia.com.au.

If you’re not satisfied with our response, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au.

10. Changes to this policy

We may update this policy from time to time. We will post the updated version on this page with a new “last updated” date, and for material changes affecting how worker data is used, we will notify business customers directly.

11. Contact us

Fair Supports Pty Ltd (ABN 85 677 767 761)
Trading as Emprovia OnSite
onsite@emprovia.com.au