
HR practitioners are trusted with privileged information in almost everything they do. That trust carries weight, and it deserves to be matched by the systems that support it.
Nooma is being built from the ground up to meet
SOC 2 Type II and ISO 42001:2023 compliance standards,
in partnership with Scrut Automation, with certification targeted by 2027.
That means security controls, policies, access management and risk frameworks are embedded into the architecture from day one. Not retrofitted. Not patched on before launch. Designed in.
We chose this path deliberately because HR systems hold information that affects people's livelihoods, careers and wellbeing. The standard of protection should match the weight of what's being handled.

Governance experience behind the product
The decisions behind how this platform is designed, what data is collected, how AI is used, and where the boundaries sit are made by someone with formal governance training and real governance experience.
Nooma's creator is a member of the Australian Human Resources Institute, a Graduate of the Australian Institute of Company Directors (GAICD), an active AICD member, and was the first HR practitioner to complete the AI in Business program at Melbourne Business School. Someone who has held ultimate accountability for the personal data of tens of thousands of employees across nearly twenty years of leading HR functions in complex organisations. Someone who knows what it means when that data is handled badly, and has built this platform so that it cannot be.
Our Charter describes the priciples that guide how O-HR delivers on its mission.Read our Charter


How your data is protected
Security and privacy are not features we added. They are how the platform is built.

O-HR has a designated Data Protection Officer (DPO). They are our enterprise security leader, overseeing data privacy, compliance and liaison between O-HR, regulatory authorities and consumers. For enquiries, contact our DPO at dpo@o-hr.com.au.
Yes. We provide security documentation to prospective customers under NDA as part of the procurement process. Contact us at security@o-hr.com.au to request it.
Workflow records are retained for seven years, consistent with employer obligations under the Fair Work Regulations 2009 (Cth), then permanently deleted. Personal identifier fields can be left blank or populated with non-identifying references such as employee numbers, meaning personally identifiable information may never enter the platform at all.
Individuals have rights to access and correct personal information held about them under the Privacy Act 1988 (Cth). Because employee data is entered into the platform by the subscribing client, access and correction requests should be directed to that organisation in the first instance. For enquiries about how Nooma handles personal information, contact us at privacy@o-hr.com.au.
From December 2026, Australian privacy law will require organisations to demonstrate transparency over how personal information is used in consequential decision-making. Nooma already meets this standard. Every consequential decision is human-made, consciously recorded, and locked into an uneditable audit trail before the workflow progresses. This is not a compliance feature added in response to the incoming requirements. It is how the platform is built.
We maintain a defined incident response framework so that if something goes wrong, there is a clear process to contain, communicate, and resolve it. In the event of a data breach likely to cause serious harm, we will notify affected customers and the Office of the Australian Information Commissioner in accordance with the Notifiable Data Breaches scheme under the Privacy Act 1988 (Cth).
We maintain a current subprocessor list covering all third-party services that may handle data as part of platform operations, including our cloud infrastructure provider, AI services provider, vector storage, and payment processing. Our full subprocessor list is available to prospective customers on request.
ISO 42001:2023 is the first international standard for AI management systems. It independently verifies that an organisation has the governance frameworks, controls, and accountability structures in place to develop and deploy AI responsibly. For an HR platform handling sensitive employment data and supporting consequential workforce decisions, independent verification of AI governance is not a nice-to-have. It is the appropriate standard of care. Very few HR technology platforms are pursuing it.
Nooma is being built to SOC 2 Type II and ISO 42001:2023 (AI management systems) standards, in partnership with Scrut Automation, with certification targeted by 2027. Our security controls, policies, access management and risk frameworks are embedded into the platform architecture from day one. Security documentation is available to prospective customers under NDA. Contact us at security@o-hr.com.au to request it.
Your platform data is hosted in Australia on Google Cloud Platform with Australian data residency configuration. AI processing occurs via a US-based provider under our Data Processing Agreement. No platform data is stored by the AI provider beyond the 30-day deletion window.
Yes. We hold a Data Processing Agreement with our AI services provider that legally prohibits the use of customer data for model training, requires deletion of inputs within 30 days, and mandates data handling standards consistent with the Australian Privacy Principles.