Privacy Policy
Last updated: 17 August 2026
By using or accessing gentia.ai (the "Website"), or the Gentia psychosocial safety management platform, or the Gentia mobile or desktop applications (collectively, the "Services"), you acknowledge that you accept the practices and policies described in this Privacy Policy. You also consent to the collection, use, and sharing of your information as outlined here.
Gentia is operated by balance2life Pty Ltd, an Australian company. We handle personal information in accordance with the Privacy Act 1988 (Cth) and the 13 Australian Privacy Principles.
If you have any questions or concerns about our Privacy Policy, please email us at hello@gentia.ai, and we will do our best to address them.
Definitions
"Personally identifiable information": Information that can directly identify an individual, including user-generated content, names, addresses, telephone numbers, email addresses, and other contact details. When non-personally identifiable information is combined with personally identifiable information, it is treated as personally identifiable information.
"Personal information": Combines personally identifiable information with any other data indirectly associated with an individual (e.g., IP addresses, pseudonymous identifiers) that is linked or linkable to that individual.
"User-generated content": Content that a user creates within or uploads to the Services.
Who This Privacy Policy Covers
Website Visitors and Correspondents
This policy covers individuals who visit our Website or correspond with us through it, but are not users of our Services.
Services Users
This policy also covers individuals who use our Services.
We gather different types of personally identifiable information and personal information from these groups and may use and handle that information differently for each, as explained below.
Organisation Use of Our Services
We provide the Services to organisations rather than individuals. You can use our Services only with others in your organisation. Our legal obligations to your organisation are governed by a separate written agreement, which may sometimes differ from this Privacy Policy. That agreement exists between Gentia and the organisation that owns the email domain you used to register.
If you use our Services through your organisation, be aware that:
- Your organisation may provide personal information about you to Gentia.
- Many organisations require that legal notices affecting you (for example, any requests to access your personal information) be provided first to the organisation itself.
If you have questions about that separate agreement, please contact your organisation's administrator or an appropriate authority within your organisation.
Information You Provide
1. Correspondents
If you communicate with us outside the Services — via a web form, email, or other means — we treat that correspondence like ordinary business communications, subject to our standard information retention and legal requirements.
2. Users of the Services
To deliver the Services, we collect and store the personally identifiable information you provide:
Registration and Account Setup. We require your name, organisation-owned email address, and organisational affiliation. We do not accept public email domains (e.g., gmail.com, outlook.com). If your organisation uses a third-party single sign-on ("SSO"), we may also receive additional personally identifiable information as described in "Third Party SSO Information" below. Some of this data may come directly from your organisation.
User-Generated Content. We collect any content you create or upload in the Services.
Third Party SSO Information
If your organisation uses a third-party SSO provider (e.g., Google or Okta), you may need to give us your username (or user ID) so we can authenticate your identity through that SSO Account. Once authenticated, we can link your Services account to that SSO Account. This may allow us to access certain personal information, such as your name, email address, user ID, data tokens used for single sign-on, and other information permitted by your SSO Account's privacy settings. However, we do not store or have access to any SSO passwords.
Information Collected Automatically
1. Log Data
Like most web and mobile services, our systems automatically receive and record certain technical information from your browser or device ("Log Data"). Log Data may include your IP address, browser or device type, capability details, and any requested pages or features. We use Log Data to keep the Services secure, diagnose faults and maintain performance. We do not use Log Data to build advertising profiles, and we do not share it with advertising networks.
2. Cookies on Our Website
Our Website uses strictly necessary cookies only — the small number required for the site to function and remain secure.
We do not use analytics cookies, tracking pixels or web beacons on our Website. We do not run third-party advertising scripts. We do not profile visitors, and we do not share visitor data with advertising networks or data brokers. We do not sell your personal information.
3. Cookies in the Services
Within the Services, we use essential cookies to keep you signed in, protect your account, and remember your preferences. These are first-party cookies necessary for the Services to work.
We also record how often features within the Services are used, so we can maintain and improve them. This measurement is first-party and is not shared with advertising networks. See "Product Usage Data" below.
4. Disabling Cookies
You can usually disable cookies in your browser settings. Because we use only strictly necessary and essential cookies, disabling them may prevent parts of the Website or Services from working correctly.
5. Do Not Track
Our Services respect the Do Not Track browser setting and other standard opt-out mechanisms. Because we do not run third-party analytics or advertising trackers, there are no third-party trackers to opt out of.
Use and Sharing of Personal Information
We do not sell your personal information.
1. Provide, Maintain, and Improve the Services
We use the information we collect to operate and refine the Services. Specifically:
- Delivering the Services: This includes diagnosing and fixing errors and enabling communication within your organisation.
- Development and Research: We may use information that has been de-identified or aggregated for development, research, and improvement of the Services. We only share de-identified or aggregated data with third parties.
Since we work with organisations, the administrators of your organisation's Services account can access your personally identifiable information. Other users within your organisation may also have access to any user-generated content you provide, depending on their permissions.
If you have questions about how your organisation or its personnel handle your personal information, please contact an appropriate person in your organisation.
2. Communicate with You
We may use your contact information to reach out if you have given us permission or have a contractual obligation with us:
- Website Visitors and Correspondents: We may send information about new Services features or invite you to participate in surveys.
- Services Users: We may send updates about new features, operational messages, legal notices, or invitations to learn about the Services.
To opt out of these emails, you can email us at hello@gentia.ai, use an unsubscribe link, or adjust your preferences in your Services account settings. However, some important operational or legal messages are mandatory.
3. Service Providers
We use trusted third-party service providers for hosting, bug tracking, data storage, and email delivery. They may access your personal information but only as needed to perform their services for us. They must keep it confidential and are not allowed to use it outside the scope of their agreement with us. We do not engage third-party advertising or visitor-tracking providers.
4. Product Usage Data
Gentia records how often users interact with different areas of the Services so we can maintain and improve them. This is first-party measurement. We may share de-identified, aggregated usage data with partners to improve or evolve our Services, but never in a way that identifies you personally, and never with advertising networks.
5. Business Transfers and Delegation
If Gentia undergoes a merger, acquisition, or sale of assets, we will transfer the necessary personal information to the successor entity. If we go out of business or enter bankruptcy, your personal information may also be transferred as part of a change of control.
6. Protection of Gentia and Others
We may access, read, preserve, or disclose personal information if we reasonably believe it is necessary to comply with laws or court orders, enforce our policies, or protect the rights, property, or safety of Gentia, its employees, users, or others. Where we are legally permitted to do so, we will notify you if we are required by law to disclose your personal information.
Security
Your Services account is password-protected. If you use a third-party SSO, additional security measures may apply. Protect your account by using a strong password and not sharing your credentials.
We follow industry-standard security practices to safeguard your personal information, including controlling physical access to servers, requiring two-factor authentication for our staff, encrypting your data in transit and at rest, and restricting access to only those who need it. However, no method is entirely foolproof, and unauthorised access is still possible.
If there is a security breach that is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner in accordance with the Notifiable Data Breaches scheme under the Privacy Act 1988 (Cth).
Administrators in your organisation also have access to your account, so please check with them about their security procedures.
Your Rights Under Australian Privacy Law
We handle personal information in accordance with the Privacy Act 1988 (Cth) and the 13 Australian Privacy Principles ("APPs"). Under the APPs you have the right to:
- Access your personal information. You can ask us what personal information we hold about you and request a copy of it.
- Correct your personal information. You can ask us to correct information that is inaccurate, out of date, incomplete, irrelevant or misleading.
- Ask how your information is handled. You can ask us to explain how we collect, hold, use and disclose your personal information.
- Deal with us anonymously or pseudonymously where it is lawful and practicable to do so. Because the Services are provided to organisations and require an identified account, this is generally not practicable within the Services, but it may apply to general Website enquiries.
To make a request, email hello@gentia.ai. We will respond within a reasonable period, and in most cases within 30 days. If your organisation is the data controller for the information in question, we may need to direct your request to your organisation's administrator, and we will tell you if that is the case.
Making a Complaint
If you believe we have breached the Australian Privacy Principles, please email hello@gentia.ai with the details. We will acknowledge your complaint and aim to resolve it within 30 days.
If you are not satisfied with our response, you can refer your complaint to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au or by calling 1300 363 992.
Access, Changes, and Deletion
We store Website-collected information separately from what is collected in the Services. For questions about non-Services information, or to request its deletion, please contact hello@gentia.ai.
Within your Services account, you may be able to view or update some personally identifiable information. In some cases, only your administrator can make these changes, so you may need to contact your organisation for assistance.
Your organisation controls whether and when to delete user data. If your organisation ends its agreement with Gentia, we generally delete all associated account data after a reasonable period, unless we receive a legal request for it. We may continue to use aggregated or de-identified data for analysis, but not in a way that identifies you.
Where Your Information Is Held
Gentia's Services are operated from Australia, and personal information collected through the Services is stored in Australian data centres.
If you access the Services from outside Australia, be aware that Australian privacy law may differ from the law in your home country. By using the Services, you consent to transferring your information to, and processing it in, Australia.
Where the General Data Protection Regulation (GDPR) applies, Gentia acts as a "data processor" for information within the Services, and your organisation is the "data controller." For any questions about GDPR, please contact us at hello@gentia.ai.
Changes to This Privacy Policy or Our Data Practices
We will notify you about material changes to this Privacy Policy, our data collection context, or any inconsistencies we find between our practices and this document. We typically do so via a notice on gentia.ai, an email, or another reasonable method. In certain urgent cases (legal compliance, security threats, or if we are granting users more rights), we may implement changes without prior notice. If you continue using the Services after these updates take effect, you accept the revised terms.
Questions; Contacting Us
If there are any questions regarding this Privacy Policy we may be contacted using the information below.
Gentia, operated by balance2life Pty Ltd
Email: hello@gentia.ai
Address: Suite 1, 2 Redleaf Avenue, Wahroonga, NSW 2076
