VORAST
Back to home
Legal

Privacy Policy

Updated: 23 September 2026

VORAST respects your privacy and is committed to protecting personal information entrusted to us.

This Privacy Policy explains how VORAST collects, uses, stores, shares and protects personal information when you visit our website, use the VORAST platform or mobile application, communicate with us, or use services provided by VORAST.

1Who We Are

VORAST provides digital operational assurance solutions designed to support organisations in managing People, Assets and Readiness.

Our services may include workforce management, operational readiness, competence and training records, CPD records, attendance, asset management, inspections, compliance monitoring, reporting and other operational assurance functions.

For privacy enquiries, please contact:

VORAST
Email: privacy@vorast.com
Registered Address: [Insert registered company address]

2Information We Collect

Depending on how VORAST is used, we may process information including:

  • Name, employee number and contact details.
  • Employer, job title, department, site and work location.
  • User account and login information.
  • Training, qualifications, competence and CPD records.
  • Attendance, shift, roster and operational availability information.
  • Licence, certification and expiry information.
  • Records relating to operational roles and authorisations.
  • GPS or location information where an authorised VORAST function requires location verification.
  • Information entered into inspections, checklists, forms, reports or operational records.
  • Asset allocation and user-to-asset records.
  • Photographs or supporting evidence uploaded through the platform.
  • Device, browser, IP address and system usage information.
  • Communications sent to VORAST.
  • Website enquiry or contact-form information.

The information collected will depend on the services being used and the configuration selected by the organisation using VORAST.

3Customer-Controlled Data

Where an organisation uses VORAST to manage its employees, contractors, assets or operations, that organisation will normally determine why the personal information is being collected and how it is used.

In these circumstances, VORAST generally acts as a data processor or service provider on behalf of the customer.

The customer remains responsible for ensuring that it has the appropriate authority and lawful basis to collect and process information entered into VORAST.

Requests relating to customer-controlled employee or workforce records may therefore need to be referred to the relevant employer or customer organisation.

Where VORAST determines the purpose and manner in which personal information is processed, VORAST will act as the data controller.

4How We Use Personal Information

We may process personal information to:

  • Provide and operate the VORAST platform.
  • Create and manage user accounts.
  • Verify attendance or presence where location-enabled functions are activated.
  • Manage competence, training and CPD records.
  • Monitor qualifications, licences and certification expiry dates.
  • Support workforce and operational readiness.
  • Manage assets, inspections and compliance records.
  • Generate operational reports, dashboards and alerts.
  • Maintain audit trails and system records.
  • Provide technical and customer support.
  • Protect the security and integrity of our systems.
  • Investigate system misuse or security incidents.
  • Meet legal, regulatory or contractual requirements.
  • Improve the functionality, reliability and performance of VORAST.
  • Communicate with customers and users about the service.

We will not use personal information for purposes that are materially different from those for which it was collected without an appropriate legal basis or notification.

5Location Data

Where location functionality is enabled:

Certain VORAST functions may use device location information.

  • For example, location services may be used to verify that an employee is at an authorised workplace when registering attendance, completing an inspection or undertaking another location-dependent activity.
  • location information will only be collected where required for the relevant function;
  • users will be informed where location access is required;
  • VORAST will not continuously track a user's location unless a specific authorised function requires this and the user or relevant organisation has been appropriately informed; and
  • location information will only be available to authorised users in accordance with applicable permissions.

Users may control device permissions through their device settings, although disabling location services may prevent certain VORAST functions from operating.

6Training, Competence and CPD Records

VORAST may store professional training, competence, qualification and Continuing Professional Development records.

This may include:

  • courses completed;
  • training hours;
  • CPD hours;
  • assessment results;
  • assessor or supervisor sign-off;
  • qualification and certificate details;
  • expiry and renewal dates;
  • supporting evidence; and
  • competence status.

These records may be made available to authorised representatives of the user's employer or other organisation responsible for verifying competence and operational readiness.

7Sensitive Personal Information

Some customers may configure VORAST to process information that requires additional protection under applicable data protection legislation.

Customers should only enter sensitive or specially protected information into VORAST where there is a legitimate requirement and an appropriate legal basis for doing so.

Where additional permissions, safeguards or regulatory approvals are required, VORAST and the relevant customer will apply appropriate controls.

8Sharing Personal Information

VORAST may share personal information with:

  • the organisation responsible for the user's VORAST account;
  • authorised managers, supervisors, administrators or assessors;
  • technology and cloud infrastructure providers;
  • service providers supporting hosting, security, communications, analytics or technical operations;
  • professional advisers where reasonably necessary;
  • regulators, courts or government authorities where legally required; and
  • another organisation in connection with a legitimate corporate transaction, subject to appropriate safeguards.

We require service providers processing personal information on our behalf to protect that information and only use it for authorised purposes.

VORAST does not sell personal information.

9International Data Transfers

VORAST may use technology or service providers located outside the country in which a user is based.

Where personal information is transferred internationally, VORAST will implement appropriate contractual, organisational and technical safeguards and will comply with applicable requirements governing cross-border transfers of personal information.

Where required, customers will be informed of relevant hosting or data-processing locations.

10Data Security

VORAST applies reasonable technical and organisational measures designed to protect information against:

  • unauthorised access;
  • accidental loss;
  • misuse;
  • alteration;
  • disclosure; and
  • destruction.

These measures may include access controls, authentication, encryption, audit logging, system monitoring, backups and role-based permissions.

Access to customer information is limited according to operational need and authorised user permissions.

No digital service can guarantee absolute security. VORAST will continually review and improve its security controls as the platform develops.

11Data Retention

Personal information will only be retained for as long as reasonably necessary for the purpose for which it was collected or as required by legal, regulatory, contractual or legitimate business requirements.

Retention periods may differ depending on the type of information.

Customer-controlled records may be retained in accordance with the customer's agreed retention settings or contractual requirements.

When information is no longer required, it will be deleted, anonymised or securely disposed of in accordance with applicable requirements.

12Your Rights

Depending on applicable law and the circumstances of the processing, individuals may have rights relating to their personal information, including the right to:

  • request information about how their personal data is processed;
  • request access to their personal information;
  • request correction or updating of inaccurate information;
  • request deletion of personal information where applicable;
  • withdraw consent where processing is based upon consent;
  • request a copy of their personal information;
  • object to or question certain processing activities;
  • request transfer of personal information where applicable; and
  • raise a complaint regarding the processing of their information.

Some rights may be restricted where information must be retained to comply with legal obligations, resolve disputes, maintain legitimate operational records or protect the rights of others.

Where information is controlled by your employer or another VORAST customer, we may refer your request to that organisation.

To exercise a privacy right, contact:

privacy@vorast.com

We may need to verify your identity before processing a request.

13Cookies and Website Technology

The VORAST website may use cookies and similar technologies to:

  • operate essential website functions;
  • maintain security;
  • understand website performance;
  • remember user preferences; and
  • improve the user experience.

Where required, non-essential cookies will only be used after appropriate consent has been provided.

Users can manage cookies through their browser settings or through any cookie management options made available on the VORAST website.

14Automated Alerts and Decision Support

VORAST may automatically generate alerts, flags, reminders or status indicators based on information stored within the system.

Examples may include:

  • qualification expiry warnings;
  • minimum staffing alerts;
  • competence status;
  • outstanding training;
  • inspection failures;
  • asset status;
  • readiness indicators; and
  • compliance exceptions.

These features are designed to support operational decision-making.

Unless expressly stated otherwise, VORAST does not replace the judgement, responsibility or authority of the employer, competent person or authorised manager responsible for the relevant operational decision.

15Children's Data

VORAST is primarily a business and professional platform and is not designed for use by children.

We do not knowingly collect children's personal information through the public VORAST website.

Where a customer has a legitimate requirement to process information relating to a child, appropriate legal requirements, permissions and safeguards must be established before such information is processed.

16Third-Party Links

The VORAST website or platform may contain links to third-party websites or services.

VORAST is not responsible for the privacy practices or content of third-party services. Users should review the privacy policies of those organisations separately.

17Data Breaches

VORAST maintains procedures for identifying, investigating and responding to suspected personal data breaches.

Where notification is required under applicable law, VORAST will notify the relevant customer, regulatory authority or affected individuals as appropriate.

18Changes to This Privacy Policy

We may update this Privacy Policy to reflect:

  • changes to VORAST services;
  • changes in technology;
  • changes to our processing activities; or
  • changes in legal or regulatory requirements.

The latest version will be published on the VORAST website together with its effective date.

Where a change materially affects how personal information is processed, we will take reasonable steps to bring the change to the attention of affected users.

19Contact Us

Questions, concerns or requests regarding privacy or the processing of personal information should be sent to:

VORAST Privacy
Email: info@vorast.co

Where applicable, individuals may also have the right to raise a complaint with the relevant data protection or regulatory authority in their jurisdiction.

VORAST
Visibility. Operations. Readiness. Assurance. Systems. Technology.
Know Now. Act Fast.

VORAST

Know Now. Act Fast.

People. Assets. Readiness.

HomePrivacy Policyinfo@vorast.co
© 2026 VORAST. All rights reserved.Visibility. Operations. Readiness. Assurance. Systems. Technology.