This policy explains what information Chamberless handles, why, and your choices. It is a draft and should be reviewed by an Australian lawyer before public launch.
Chamberless is operated by Nepoz Group Pty Ltd trading as Chamberless (ABN 98 147 717 913). Contact: support@chamberless.com.
1. Who we are and what this covers
This Privacy Policy explains how Nepoz Group Pty Ltd trading as Chamberless ("Chamberless", "we") handles personal information in connection with the Chamberless website (chamberless.com), the Chamberless app (app.chamberless.com) and our emails. We handle personal information in line with applicable Australian privacy law, including the Privacy Act 1988 (Cth) where it applies to us. [Legal review: confirm APP coverage.]
2. Workforce data belongs to your employer
Most information in Chamberless is entered by a customer organisation about its own people — for example employee records, attendance and leave. That organisation decides what is entered and controls it. Chamberless provides the software and stores and processes that information on the organisation's behalf to provide the service.
If you are an employee and have a question about your employment records in Chamberless — including access or correction — please contact your employer first. We will help your employer respond where appropriate, and you may still contact us.
3. Information we collect
- Account holders: name, email address, organisation name, country, timezone and settings, and your role in the organisation.
- Authentication: email and a password (stored by our authentication provider in hashed form, not readable by us), sign-in sessions, and email-confirmation and password-reset requests.
- Workforce information entered by organisations: employee number, name, work and personal email, phone, department, position, manager, employment type and status, start and probation dates, and work schedule.
- Attendance: clock-in and clock-out times, scheduled hours and breaks, attendance status (for example present, late, absent) and correction requests with reasons and review notes.
- Leave: leave types, balances, requested dates, reasons, approval decisions and notes.
- Clients and allocation: client names and codes, client contact details, services, employee assignments and planned allocation (hours or percentage). This is planned capacity, not time tracking.
- Billing: plan, billing cycle, subscription status and Stripe customer/subscription references. Card details are collected and held by Stripe; we do not store full card numbers.
- Email activity: which system emails were sent (type, recipient, time, delivery status). We do not store email bodies or sign-in tokens in this log.
- Technical information: IP address, browser and device information and request logs collected by our hosting and infrastructure providers to run and secure the service.
- Support: messages you send us and our replies.
Chamberless does not use GPS or location tracking, biometric data, or continuous employee monitoring.
4. How we use information
- to provide, operate and maintain Chamberless, including sign-in, role-based access and reporting;
- to send service emails such as invitations, trial reminders, billing and security notices;
- to process subscriptions and payments;
- to secure the service and prevent fraud, abuse and unauthorised access;
- to provide support and respond to enquiries;
- to comply with legal obligations and enforce our Terms;
- to understand and improve the service, using aggregated or operational information.
We do not sell personal information and we do not use workforce information for advertising.
5. Who can see workforce information
Access inside an organisation depends on the role the organisation assigns. Currently, Owners and Admins can see their whole organisation; Managers see information for their direct reports; Employees see their own records. Client contact details and notes are limited to Owners and Admins. Organisations can change roles at any time, and access rules may be refined as the product develops.
Chamberless platform staff can see account-level information (such as organisation name, plan, status, user list and aggregate counts) to operate the service. Our platform tools are designed so that staff do not have routine access to organisations' employee records, attendance details, leave reasons, client contacts or reports. We may access Customer Data where needed to provide support you request, investigate security issues, or comply with law.
6. Service providers
We use trusted providers to run Chamberless, who process information on our behalf:
- Stripe — payments and subscription billing;
- Transactional email infrastructure — to deliver system emails from notify.chamberless.com;
- Cloud hosting, database and authentication infrastructure — to host the app and store data;
7. Overseas processing
Some of our providers are located, or store and process information, outside Australia (for example Stripe and cloud infrastructure providers operating in the United States and other countries). We take reasonable steps to choose providers with appropriate security and privacy practices. [Legal review: identify hosting regions and APP 8 cross-border disclosure position.]
8. Security
We protect information with measures including role-based access, organisation-level data isolation enforced in the database, server-side permission checks, secure authentication, and HTTPS for connections to the app. No system is completely secure, and we cannot guarantee security. Customers are responsible for managing their users' access and keeping credentials secure.
9. Data breaches
If we become aware of a data breach affecting personal information we hold, we will assess it promptly, take steps to contain it, notify affected customers without undue delay, and notify individuals and the Office of the Australian Information Commissioner where required under the Notifiable Data Breaches scheme. [Legal review.]
10. Retention and deletion
We keep information while an organisation's account is active. After cancellation, see our Data Handling Statement. Billing and transaction records may be kept for as long as required for tax and accounting purposes. An organisation's Owner can request deletion from within Chamberless under Company → Data & deletion, and Chamberless reviews and processes each request securely before anything is removed; you can also contact support@chamberless.com for assistance.
11. Access, correction and complaints
You can view and update much of your own information in the app. To request access to or correction of personal information we hold, or to make a privacy complaint, email support@chamberless.com. We will respond within a reasonable time (generally within 30 days). If you are not satisfied, you may contact the Office of the Australian Information Commissioner (oaic.gov.au).
12. Cookies and local storage
Chamberless uses essential browser storage to keep you signed in and to run the app. We do not currently use analytics, advertising pixels or marketing trackers. If that changes, we will update this policy and seek consent where required.
13. Children
Chamberless is a workplace product for authorised business users. It is not intended for children to use independently. Organisations that employ young workers are responsible for handling their information appropriately.
14. Changes to this policy
We may update this policy. The version and effective date appear at the top of this page, and we will notify customers of material changes.
15. Contact
Privacy questions: support@chamberless.com. Postal address: 10–12 Nelson St, Penshurst NSW 2222, Australia.