JOBTORQ / LEGAL
Privacy Policy
Last updated: 24 September 2026
Draft for review. Please confirm the public contact email before publication.
This policy explains how JobTorq handles personal information when you visit our website or use our job management platform, including the Safety Torq module.
Who we are
JobTorq is operated by 2M Systems. ABN: 20 613 465 900. For privacy questions, access requests or complaints, contact [public contact email to be confirmed].
When your employer or another organisation provides your workspace, that organisation decides what work and employee records to collect and who may access them. We provide the platform and process workspace information to deliver the service. Your organisation’s own privacy and employment policies may also apply.
Information handled by JobTorq
- People and account details: names, email addresses, roles, organisation membership and account or invitation records.
- Work and safety records: customer and site details, work orders, assignments, tasks, notes, photos, files, toolbox talks, risk assessments, acknowledgements and revision history.
- Asset records: equipment assignments, bookings, prestarts, recorded issues, tag-out reasons and supporting photos.
- Personnel records: licences, credential numbers, qualifications, training dates, expiry dates, renewal reminders, employee notes and uploaded evidence. Uploaded documents may contain additional personal or sensitive information.
- Technical and support information: browser requests, session identifiers, activity and audit records, and information supplied when seeking support.
Information is provided by you, your organisation, authorised workspace users or configured service providers. Only upload information you are authorised to provide. Avoid unnecessary identity documents, medical details or other sensitive material. You can browse the public website without creating an account; using a named workplace record requires enough information to identify the relevant person.
How information is used
We use information to operate workspaces; organise jobs and asset checks; maintain safety and personnel records; display reminders; respond to support requests; protect the service; investigate misuse; and meet applicable legal obligations. Providing some information is optional, but leaving it out may prevent the associated feature from working.
We do not sell personal information or use workspace records for advertising. The public website does not include advertising trackers or third-party analytics scripts.
Microsoft and Google sign-in
Where enabled, Microsoft or Google sign-in uses the identity information and permissions shown in the provider’s consent screen to identify your account and connect it to your organisation. JobTorq does not ask you to provide your Microsoft or Google password directly to us. Sign-in alone does not give JobTorq access to your mailbox, calendar or documents.
The owner portal supports Microsoft sign-in for designated accounts in the operator’s Microsoft directory. Customer workspace users still use simulated identities in the development application; Microsoft, Google and email-code sign-in for those users are not yet connected. Real personnel information should not be entered into the development demo.
AI-assisted features
When you use an AI feature, relevant information is sent to OpenAI for processing. This can include the business summary, work order title, scope and tasks, your wizard answers, proposed hazards and controls, and selected equipment context. For personnel document prefill, the selected person’s name and the photos or PDFs you choose are sent to extract an editable draft.
Manual entry is available. Remove unnecessary personal information before using AI. AI output may be inaccurate and must be reviewed before saving or using it. Our requests disable storage of retrievable AI responses, but this is not a guarantee that the provider retains no data for security or other permitted purposes.
Storage, security and retention
Records are stored in the application database and uploaded files in Wasabi storage. Private personnel record contents and their attachments have additional encryption at rest. This does not mean every platform field has the same encryption or that authorised administrators cannot read records. No system can guarantee absolute security.
We keep information for service delivery, workspace history, dispute handling and applicable record-keeping requirements. Archiving a record does not delete it. Removing sign-in permissions does not automatically erase workplace records. Retention and deletion must also take account of safety, employment, audit and backup requirements; there is no universal automatic deletion period currently configured. Contact us and your organisation about a specific record or account closure.
Access, corrections and complaints
Contact your organisation’s administrator about workplace records, or contact [public contact email to be confirmed] for help with information we hold. Tell us what you want to access, correct or raise a complaint about. We may need to verify your identity and authority. Access or deletion may be limited by another person’s rights or applicable retention requirements; we will explain an applicable limitation.
We will assess privacy complaints and aim to respond within 30 days. If the issue remains unresolved, you may contact the Office of the Australian Information Commissioner where it has jurisdiction.
Changes to this policy
We will update this page when our practices change and show the revision date. Material changes will be communicated through the service or another appropriate channel. Contact us if you need a copy of this policy in another format.