HeliosOps
Privacy Policy
HeliosOps is workforce software that employers use to roster, dispatch and pay their field staff. This policy explains what personal information the HeliosOps app and website collect, why, and what happens to it.
Last updated 14 September 2026
Who we are
HeliosOps is operated by Standard Plinth Pty Ltd, an Australian company (“we”, “us”). We are bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles. You can reach us about anything in this policy at admin@standardplinth.com.
Two kinds of people
Employers (the organisation you work for) subscribe to HeliosOps and create accounts for their staff. The employer decides what is recorded and is the owner of its workforce records. We process that information on the employer's behalf.
Workers use the HeliosOps app on their phone. There is no public sign-up: an account exists only because an employer created it. If you are a worker with a question about how your employer uses your information, your employer is the first place to ask; we will also help where we can.
What the app collects
The HeliosOps app collects the following, and nothing else.
- Your account. Name, work email address, employee number, job title, department and role, as entered by your employer.
- Attendance. The times you clock in and out, start and end breaks, and clock on and off jobs. These are your timesheet and are used to pay you.
- Location, at clock events only. When you clock in or out, start or end a break, or clock on or off a job, the app records your location at that moment as proof of attendance. It uses the “while using the app” permission and never tracks you in the background or between those moments. You can decline the permission; clock actions still work, just without a location.
- Kilometre claims. Kilometres you enter for a job or a day, any note you add, and the distance the app suggested from the clock-event locations above, so your employer can see both.
- Photos and files. Before-and-after job photos, receipts for expenses, and documents you upload. Only photos you choose to take or pick are uploaded; the app does not read your photo library.
- Job notes, tasks and checklists you complete on a job.
- Messages. Direct and group messages with your colleagues and office, and broadcasts from your employer, including read receipts.
- Leave and availability requests you submit.
- Document acknowledgements. When your employer issues a policy or HR document that must be read, the app records that you opened it and the time you acknowledged it.
- Private HR documents. Letters on your HR file open in a reader inside the app that does not save a copy to your phone. On Android, screenshots of that reader are blocked. On iPhone they cannot be blocked, so if you take one the app records the time on your HR file, and the reader tells you so before you read.
- Incident and complaint reports. What you report from the app — the category, description, when and where it happened, any photos, and who was involved — is stored with your name as the reporter so the office can follow it up. Other workers do not see your reports.
- Push notification token. A device token so that shift changes and messages can be delivered to your phone.
The app also keeps a few things on your device only: your sign-in session, your preferred server address, whether you turned on the biometric app lock, and clock actions queued while you were offline. Face ID or fingerprint checks are performed by your phone; no biometric data is sent to us or stored by the app.
The app contains no advertising and does not track you across other apps or websites.
What the website collects
The HeliosOps web app used by office staff holds the employer's operational records: clients and their contact details, sites and addresses, jobs, quotes, invoices, rosters, HR records and the attendance data above. Sign-in details are handled by our authentication provider (see below) and we store only a session cookie in your browser.
Why we use it
- To run your employer's operations: rostering, dispatch, job records, timesheets and payroll inputs such as hours and kilometres.
- To provide proof of service to your employer's clients and funders, for example that a visit took place at a site.
- To deliver messages and notifications you and your employer send.
- To keep the service secure and working, including audit logs of who changed what.
We do not sell personal information and we do not use it for advertising.
Who else sees it
Information is shared only with the providers we need to run the service, and only for that purpose:
- Vercel hosts the website, the API and uploaded files (photos and documents).
- Neon hosts the database, in Sydney, Australia.
- Neon Auth handles sign-in credentials and password resets.
- Expo, together with Apple and Google, delivers push notifications to your phone.
- Anthropic. If your employer has enabled the SAM assistant and you message it, the text of your message and the workspace information needed to answer it are sent to Anthropic's API to generate the reply.
- Your employer's other systems. Where an employer connects accounting software (for example QuickBooks Online) or messaging services, client and invoice information flows to those systems under the employer's own agreements with them.
Site addresses are geocoded using OpenStreetMap's Nominatim service so the app can show a map pin; this involves the address of a work site, not information about you. Some of these providers store data outside Australia (Vercel and Expo operate globally). We take reasonable steps to ensure they protect it to a standard consistent with the Australian Privacy Principles.
We will also disclose information where the law requires it, for example to a court or a regulator such as the Fair Work Ombudsman.
How long we keep it
Attendance and pay records are employment records. Australian employers must keep them for seven years under the Fair Work Act 2009, so they stay in HeliosOps for as long as your employer needs them to meet that obligation. Other records are kept while the employer's subscription is active and deleted or returned when it ends, unless the employer asks us to keep them longer.
Your account and deletion
Accounts are created and closed by employers, so the app cannot delete an account on its own. To close your account or have your personal information deleted, use Profile → About → Request account deletion in the app, which sends us the request, ask your employer, or email us at admin@standardplinth.com. We will act on the request within 30 days, keeping only what the employer is legally required to retain (such as the seven-year pay records above), and we will tell you what was kept and why.
Access and correction
You can see your own timesheets, kilometre claims, roster and documents in the app at any time. To access other information we hold about you, or to correct something, email admin@standardplinth.com. We respond within 30 days.
Security
Data travels between the app and our servers over encrypted connections (TLS). Sign-in tokens are stored in your phone's secure keychain. Access to the web app is limited by roles set by your employer, and changes to records are logged.
Children
HeliosOps is a workplace tool and is not directed at anyone under 16.
Complaints
If you think we have mishandled your information, email admin@standardplinth.com and we will investigate and reply within 30 days. If you are not satisfied with our response you can complain to the Office of the Australian Information Commissioner at oaic.gov.au.
Changes
When we change this policy we update the date at the top. If a change affects how your information is used, we will tell employers in advance so they can tell their staff.
