Australian data residency
All client data is held in accredited enterprise cloud data centres located in Australia. Data is not replicated, backed up or processed offshore.
Winner — Best WHS Training Program, 2026 Hunter Safety Awards
Trust Centre
Gentia is an end-to-end psychosocial safety management platform operated by balance2life Pty Ltd, an Australian company. Client data is stored in accredited data centres in Australia and is not transferred offshore. Personal details are removed before any AI processing, individual-level data is never stored in identifiable form, and client data is never used to train AI models. This page sets out how that works.
Security documentation is available on request. See the bottom of this page.
Data Residency
In accredited data centres in Australia. It does not leave the country.
All client data is held in accredited enterprise cloud data centres located in Australia. Data is not replicated, backed up or processed offshore.
Because the data stays in Australia, it remains subject to Australian law, including the Privacy Act 1988 (Cth). We will not transfer client data outside Australia without the client's written agreement.
The platform runs on enterprise cloud infrastructure with network segmentation, continuous monitoring, vulnerability management and automated threat detection.
Security Controls
Data moving between your systems and Gentia is encrypted using TLS 1.2 or above. Data stored in the platform is encrypted at rest.
Access is granted only where it is required to perform a role, and no further. Permissions are reviewed on a scheduled basis, and every access event is logged.
Multi-factor authentication is required for staff access. Role-based permissions, session management and privileged access management govern who can reach what, and for how long.
Actions taken in the platform are recorded, so it is possible to reconstruct who accessed what, when, and what they changed.
Privacy by Design
No. Gentia assesses how work is designed and managed, not individual people.
This is a deliberate design decision rather than a policy applied afterwards. Psychosocial risk lives in the conditions of the work — workload, role clarity, support, span of control, how change is managed. Gentia is built to find risk in those conditions, which means it does not need to identify individuals in order to work.
Names, email addresses, phone numbers and similar identifiers are detected and removed before data enters the analysis pipeline. Analysis is carried out on the pattern of work, not on identified people.
Findings are produced and reported at team, group or organisational level.
We collect only what is needed to deliver the service, and use it only for the purpose it was provided for.
Gentia is not designed to monitor individuals, build cases against them, or support disciplinary, performance or termination decisions. Our Acceptable Use Policy prohibits using it that way.
AI Governance
Your data is never used to train AI models. It remains exclusively yours.
Gentia does not train its models on client data, and does not permit client data to be used to train third-party models.
Every material finding is reviewed by a psychosocial safety specialist before it is relied on. AI increases speed, specificity and consistency. It does not replace expert judgment.
Every finding traces back to the evidence it came from. Where the system is inferring rather than observing, it says so, and states what would confirm it.
How AI models are used within the platform — for what purpose, over what data, with what controls — is documented and available on request.
Governance
Gentia's data governance and information security practices are designed and operated in alignment with recognised international frameworks: ISO/IEC 27001 and ISO/IEC 27002 for information security management, NIST for cyber security controls, and ITIL and COBIT for service management and IT governance. Our psychosocial safety practice is aligned to ISO 45003 and Australian work health and safety law across all eight jurisdictions.
Gentia does not currently hold ISO 27001 or SOC 2 certification. We describe our controls as aligned to these frameworks because that is accurate. We will say so plainly if and when certification is achieved, and not before.
Operational Security
Personnel are screened before they are given access to client environments.
Staff complete security awareness training, and it is refreshed rather than treated as a one-off.
A documented incident response plan sets out how a security incident is identified, contained, escalated and communicated. Where an incident is likely to result in serious harm, we notify affected clients and the Office of the Australian Information Commissioner in line with the Notifiable Data Breaches scheme.
Documented plans cover continuity of service and recovery of data.
Security requirements are built into how the platform is designed, built, reviewed and released, rather than tested for at the end.
Our security posture is subject to independent third-party assessment.
Almost nothing.
This website uses strictly necessary cookies only. We do not use analytics cookies or tracking pixels. We do not run third-party advertising scripts. We do not profile visitors, and we do not share visitor data with advertising networks or data brokers. We do not sell personal information.
Full details are in our Privacy Policy.
Procurement, security and privacy teams can request the following documents. Email hello@gentia.ai and tell us which you need.
Data Processing Agreements are available on request.
FAQ
In accredited enterprise cloud data centres located in Australia. Client data is not replicated, backed up or processed offshore, and it is not transferred outside Australia without the client's written agreement.
No. Gentia does not train its models on client data, and does not permit client data to be used to train third-party models. Your information remains exclusively yours.
No. Personal details are removed before any AI processing, and individual-level data is never stored in identifiable form. Findings are reported at team, group or organisational level. Gentia assesses how work is designed and managed, not individual people, and our Acceptable Use Policy prohibits using it as a performance management or surveillance tool.
No. Gentia's data governance and information security practices are designed and operated in alignment with ISO/IEC 27001 and ISO/IEC 27002, but Gentia does not currently hold certification. We describe our controls as aligned to these frameworks because that is accurate, and we will say so plainly if and when certification is achieved.
Yes. Data in transit is encrypted using TLS 1.2 or above, and data stored in the platform is encrypted at rest.
Access is granted on a least-privilege basis — only where it is required to perform a role. Multi-factor authentication is required for staff access, permissions are reviewed on a schedule, privileged access is separately managed, and every access event is logged.
A documented incident response plan governs how an incident is identified, contained, escalated and communicated. Where a breach is likely to result in serious harm, we notify affected clients and the Office of the Australian Information Commissioner in accordance with the Notifiable Data Breaches scheme under the Privacy Act 1988 (Cth).
Gentia is operated by balance2life Pty Ltd, an Australian company, and handles personal information in accordance with the Privacy Act 1988 (Cth) and the 13 Australian Privacy Principles. Where the GDPR applies, Gentia acts as data processor and the client organisation is the data controller.
You do. Client data remains the property of the client organisation, which also controls who can access it, who can be added or removed, and its retention and export.
Yes. Data Processing Agreements are available on request. Email hello@gentia.ai.
No. The site uses strictly necessary cookies only. There are no analytics cookies, no tracking pixels, no third-party advertising scripts, no visitor profiling and no data sharing with advertising networks.
Information Security Policy, Incident Response Plan, Business Continuity and Disaster Recovery Plan, Gentia Architecture Diagram, Privacy Policy, Cookie Policy, AI Usage Model Mapping, Master Service Agreement and Data Processing Addendum. Email hello@gentia.ai to request them.
No. Work health and safety duties sit with the organisation and cannot be transferred to a supplier or a software platform. Gentia helps you identify hazards, design and apply controls, and evidence what you have done. The duty remains yours.
Questions this page does not answer? Email hello@gentia.ai.