Office interior with potted plant and floor lamp by windows overlooking the city

Security and Privacy

HR practitioners are trusted with privileged information in almost everything they do. That trust carries weight, and it deserves to be matched by the systems that support it.

Benchmark security standards,
by design

Nooma is being built from the ground up to meet
SOC 2 Type II and ISO 42001:2023 compliance standards,
in partnership with Scrut Automation, with certification targeted by 2027.

That means security controls, policies, access management and risk frameworks are embedded into the architecture from day one. Not retrofitted. Not patched on before launch. Designed in.

We chose this path deliberately because HR systems hold information that affects people's livelihoods, careers and wellbeing. The standard of protection should match the weight of what's being handled.

Governance experience behind the product

The decisions behind how this platform is designed, what data is collected, how AI is used, and where the boundaries sit are made by someone with formal governance training and real governance experience.

Nooma's creator is a member of the Australian Human Resources Institute, a Graduate of the Australian Institute of Company Directors (GAICD), an active AICD member, and was the first HR practitioner to complete the AI in Business program at Melbourne Business School. Someone who has held ultimate accountability for the personal data of tens of thousands of employees across nearly twenty years of leading HR functions in complex organisations. Someone who knows what it means when that data is handled badly, and has built this platform so that it cannot be.

Our Charter describes the priciples that guide how O-HR delivers on its mission.Read our Charter

Australian Institute of Company Directors logoMelbourne Business School Generative AI for Business completion badge

Governance in the product

Nooma uses enterprise-grade API access to AI services. This means every Nooma subscriber benefits from a Data Processing Agreement that legally prohibits use of your data for model training and mandates handling standards consistent with the Australian Privacy Principles. These protections are not available through a standard paid personal or teams account directly with an AI provider.

Our AI governance is being built to ISO 42001:2023, the international standard for AI management systems. Independent certification is expected by 2027, making Nooma one of the few HR technology platforms pursuing it.

AI is deployed only where it measurably improves HR practice, within defined boundaries and configuration controls. It generates, supports, and surfaces. It does not decide.

Where AI is not the right tool, we do not use it. The test is simple: does this make HR practice safer, more consistent, or more confident?

Read our AI Transparency Statement

Not human in the loop, human in control

Our platform is designed with the human decision-maker in control. AI tools assist with document generation and compliance guidance. Employment decisions are made by the user, never the platform.

The AI cannot initiate, progress, or complete any workflow independently. Every step requires explicit human action before anything moves forward. Decision gates are a hard stop: no progression without a human.

Every human decision is timestamped and recorded at the point it is made. Workflows have an automatic audit trail, uneditable and recorded as you work.

Access is governed by role, seniority, and organisational remit. Users see only what they are permitted to see, and the platform enforces those boundaries structurally.

How your data is protected

Security and privacy are not features we added. They are how the platform is built.

  • Your platform data is hosted in Australia. AI processing occurs via a US-based provider under a formal Data Processing Agreement (DPA).
  • Your data is never used to train AI models and inputs are deleted within 30 days.
  • Multi-factor Authentication (MFA)
  • Role-based access controls. Users only see what their role requires. Sensitive HR data is restricted by design.
  • Automatic timeshout and session controls reduce the risk of unattended access.
  • Data minimisation by design. Personal identifier fields can be left balnk or populated with non-identifying references such as employee numbers. Documents can be exported and completed offline, soo personally identifiable information never needs to enter the AI processing layer.
  • Workflow records are retained for seven years, consistent with employer obligations under the Fair Work Regulations 2009 (Cth), then permanently deleted.
  • Independent penetration testing is conducted on the platform infrastructure, separate from our internal team.
  • We assess and monitor our technology partners and suppliers against the same standards we hold ourselves to. Read our Privacy Policy
Meeting room window with views over the Melbourne city skyline

Learning together

We are committed to constructive engagement with the industry and beyond.
Our Industry Council brings together senior HR leaders who actively review how AI is deployed, test whether outputs reflect real HR practice, and challenge design decisions where AI should be constrained.

Our advisor panel extends that scrutiny to complementary disciplines, including legal and risk specialists who hold us to account beyond the boundaries of HR alone.

Our partnership with the University of Sydney creates real opportunity for the next generation of business leaders and technologists to engage with the intersection of AI and HR practice.

Read our Charter

Our responsibilities

HR decisions shape the livelihoods, careers, safety, and daily experience of every person in every Australian workplace.

Nooma was built to make expert HR accessible to everyone who carries that responsibility, not just well-resourced organisations.

How we build, who we work with, and the environmental cost of the technology we deploy are all part of that same commitment.

Read our Social and Environmental Impact Statement.

"We partnered with O-HR to strengthen Nooma's ESG strategy. At USYD, we're taught that responsible business goes beyond compliance; it’s about embedding accountability into every decision as a genuine commitment to people and impact. Jessie embodies this. Her vision for Nooma reflects a clear commitment to responsible AI adoption and to building a business grounded in real social and environmental impacts. Working alongside her allowed us to witness what true responsible business leadership looks like in practice."

Practera Industry Project client badge

Angie Su

Project Lead, The University of Sydney

"We are all navigating AI adoption in one way or another in our respective companies and wanting to understand how we can apply it safely and responsibly to our areas of accountability. The cohort comes together to learn, support each other and share the journey."

AI/HR Industry Council logo

Jess Sherlock

General Manager, People and Culture

Have a question, a suggestion, or a perspective to share? We'd like to hear it.
FAQs

Before you apply

Who is responsible for the privacy and security governance of Nooma?

O-HR has a designated Data Protection Officer (DPO). They are our enterprise security leader, overseeing data privacy, compliance and liaison between O-HR, regulatory authorities and consumers. For enquiries, contact our DPO at dpo@o-hr.com.au.

Can we request security documentation for our procurement process?

Yes. We provide security documentation to prospective customers under NDA as part of the procurement process. Contact us at security@o-hr.com.au to request it.

How long is data retained?

Workflow records are retained for seven years, consistent with employer obligations under the Fair Work Regulations 2009 (Cth), then permanently deleted. Personal identifier fields can be left blank or populated with non-identifying references such as employee numbers, meaning personally identifiable information may never enter the platform at all.

Can employees access or correct personal information held about them?

Individuals have rights to access and correct personal information held about them under the Privacy Act 1988 (Cth). Because employee data is entered into the platform by the subscribing client, access and correction requests should be directed to that organisation in the first instance. For enquiries about how Nooma handles personal information, contact us at privacy@o-hr.com.au.

How does Nooma handle the upcoming automated decision-making transparency requirements under the Privacy Act?

From December 2026, Australian privacy law will require organisations to demonstrate transparency over how personal information is used in consequential decision-making. Nooma already meets this standard. Every consequential decision is human-made, consciously recorded, and locked into an uneditable audit trail before the workflow progresses. This is not a compliance feature added in response to the incoming requirements. It is how the platform is built.

What happens in the event of a data breach?

We maintain a defined incident response framework so that if something goes wrong, there is a clear process to contain, communicate, and resolve it. In the event of a data breach likely to cause serious harm, we will notify affected customers and the Office of the Australian Information Commissioner in accordance with the Notifiable Data Breaches scheme under the Privacy Act 1988 (Cth).

Who else has access to data processed through the platform?

We maintain a current subprocessor list covering all third-party services that may handle data as part of platform operations, including our cloud infrastructure provider, AI services provider, vector storage, and payment processing. Our full subprocessor list is available to prospective customers on request.

What is ISO 42001:2023 and why does it matter for an HR platform?

ISO 42001:2023 is the first international standard for AI management systems. It independently verifies that an organisation has the governance frameworks, controls, and accountability structures in place to develop and deploy AI responsibly. For an HR platform handling sensitive employment data and supporting consequential workforce decisions, independent verification of AI governance is not a nice-to-have. It is the appropriate standard of care. Very few HR technology platforms are pursuing it.

What security certifications does Nooma hold?

Nooma is being built to SOC 2 Type II and ISO 42001:2023 (AI management systems) standards, in partnership with Scrut Automation, with certification targeted by 2027. Our security controls, policies, access management and risk frameworks are embedded into the platform architecture from day one. Security documentation is available to prospective customers under NDA. Contact us at security@o-hr.com.au to request it.

Where is customer data hosted?

Your platform data is hosted in Australia on Google Cloud Platform with Australian data residency configuration. AI processing occurs via a US-based provider under our Data Processing Agreement. No platform data is stored by the AI provider beyond the 30-day deletion window.

Do you have a Data Processing Agreement in place with your AI services provider?

Yes. We hold a Data Processing Agreement with our AI services provider that legally prohibits the use of customer data for model training, requires deletion of inputs within 30 days, and mandates data handling standards consistent with the Australian Privacy Principles.