Skip to content

Security overview

BetterUs Workplace, Security & Privacy Overview

A one-page summary for buyers and their security teams. Send this to procurement, legal, or your CISO, they should find every answer they need without a follow-up email.

Last updated: 1 May 2026. For questions or a custom DPA: support@theschoolofplay.co.

Company & infrastructure facts

Founded
2024
Legal entity
The School of Play Pty Ltd (AU)
ABN
Available on request
Primary data region
Australia (Sydney)
Backup region
Australia (Melbourne)
Production access
Limited to named individuals; logged
Data classification
Customer Restricted by default
Encryption in transit
TLS 1.2+, HSTS
Encryption at rest
AES-256 (database + backups)
Authentication
Email + password (admins), PIN (packmates); scoped session tokens
MFA on admin tools
Required
Customer SSO
Google, Microsoft (optional per workspace)
Customer SAML
On our roadmap, not yet available
Customer SCIM
On our roadmap, not yet available
Audit log retention
12 months, 36 months on Enterprise
Backups
Daily encrypted snapshots

Sub-processors

These third parties process customer data on our behalf. We notify customers before adding a new one.

VendorPurposeRegionData handled
VercelWeb hosting + edge runtimeGlobal edgeEncrypted in transit; ephemeral compute, no persistence.
ReplitApplication hosting + databaseAustralia (primary data region)Application data, encrypted at rest. Access limited and logged.
FirebaseLive multiplayer / real-time roomsGoogle CloudTransient session state for live rooms. No mood or recognition free-text.
StripePayment processingUS/EU/AU per Stripe routingCardholder name, card token (PCI-DSS compliant). No PAN stored by us.
ResendTransactional emailUSRecipient email + email body. Retention: 30 days for delivery logs.
SentryError trackingUS (with EU region available)Error stack traces, browser metadata. PII masked by default.
PostHogProduct analyticsEU (eu.posthog.com)Anonymous event stream. Identifiers hashed, no email.
OpenAIAI feature surfaces (optional, off by default)USFirst names + aggregate counts only. No mood text or recognition free-text.

Compliance

  • In place

    Australian Privacy Principles

    We are an Australian company bound by the AU Privacy Act 1988. Customer data is hosted in Australia. DPA available on request.

  • Roadmap

    SOC 2

    Not certified yet. SOC 2 is on our roadmap. We'll update this page when an audit is genuinely underway, with no dates we can't stand behind.

Data handling

  • Customer data ownership. The customer is the data controller; we are the data processor. Workspace data is exportable on demand from /admin/export and deletable on demand within 30 days.
  • Aggregation by default. Managers and admins see aggregate distributions, not individual answers. Mood logs and pulse responses are individual-level only to the packmate who created them.
  • No model training on customer data. We do not use customer data to train, fine-tune, or improve any model, including third-party models we call (e.g. OpenAI). Where AI is enabled, we send first names + aggregate counts only, never free-text recognitions or mood entries.
  • Retention. Active workspace data is retained for the life of the subscription plus 90 days. After that, check-in history is anonymised and recognition free-text is deleted. Audit logs are retained 12 months (36 months on Enterprise).
  • Access controls. Production access is limited to named individuals, MFA-required. All admin actions are logged to an audit trail.
  • Backups. Daily encrypted snapshots, encrypted at rest with AES-256. Restores are tested.

Incident response

  1. Detection. Sentry, UptimeRobot, and Vercel logs alert us to error spikes or downtime.
  2. Triage. We assess severity and prioritise anything involving data exposure or a production outage first.
  3. Customer notification. If customer data is materially affected, we notify named admin contacts promptly.
  4. Write-up. Material incidents get a written summary, available to affected customers on request.

Vulnerability disclosure

Report security issues to support@theschoolofplay.co. We acknowledge within one business day, triage within five, and credit reporters publicly on /security/hall-of-fame on request. We do not currently run a paid bounty programme.

This overview describes BetterUs Workplace as of the date above. Changes that materially affect customer data handling are announced 30 days in advance via email to named admin contacts and on /changelog. For a custom DPA, BAA, or SIG questionnaire response: support@theschoolofplay.co.

BetterUs Workplace is operated by The School of Play Pty Ltd, an Australian private company. © 2026 The School of Play Pty Ltd. All rights reserved.