Security overview
BetterUs Workplace, Security & Privacy Overview
A one-page summary for buyers and their security teams. Send this to procurement, legal, or your CISO, they should find every answer they need without a follow-up email.
Last updated: 1 May 2026. For questions or a custom DPA: support@theschoolofplay.co.
Company & infrastructure facts
- Founded
- 2024
- Legal entity
- The School of Play Pty Ltd (AU)
- ABN
- Available on request
- Primary data region
- Australia (Sydney)
- Backup region
- Australia (Melbourne)
- Production access
- Limited to named individuals; logged
- Data classification
- Customer Restricted by default
- Encryption in transit
- TLS 1.2+, HSTS
- Encryption at rest
- AES-256 (database + backups)
- Authentication
- Email + password (admins), PIN (packmates); scoped session tokens
- MFA on admin tools
- Required
- Customer SSO
- Google, Microsoft (optional per workspace)
- Customer SAML
- On our roadmap, not yet available
- Customer SCIM
- On our roadmap, not yet available
- Audit log retention
- 12 months, 36 months on Enterprise
- Backups
- Daily encrypted snapshots
Sub-processors
These third parties process customer data on our behalf. We notify customers before adding a new one.
| Vendor | Purpose | Region | Data handled |
|---|---|---|---|
| Vercel | Web hosting + edge runtime | Global edge | Encrypted in transit; ephemeral compute, no persistence. |
| Replit | Application hosting + database | Australia (primary data region) | Application data, encrypted at rest. Access limited and logged. |
| Firebase | Live multiplayer / real-time rooms | Google Cloud | Transient session state for live rooms. No mood or recognition free-text. |
| Stripe | Payment processing | US/EU/AU per Stripe routing | Cardholder name, card token (PCI-DSS compliant). No PAN stored by us. |
| Resend | Transactional email | US | Recipient email + email body. Retention: 30 days for delivery logs. |
| Sentry | Error tracking | US (with EU region available) | Error stack traces, browser metadata. PII masked by default. |
| PostHog | Product analytics | EU (eu.posthog.com) | Anonymous event stream. Identifiers hashed, no email. |
| OpenAI | AI feature surfaces (optional, off by default) | US | First names + aggregate counts only. No mood text or recognition free-text. |
Compliance
- In place
Australian Privacy Principles
We are an Australian company bound by the AU Privacy Act 1988. Customer data is hosted in Australia. DPA available on request.
- Roadmap
SOC 2
Not certified yet. SOC 2 is on our roadmap. We'll update this page when an audit is genuinely underway, with no dates we can't stand behind.
Data handling
- Customer data ownership. The customer is the data controller; we are the data processor. Workspace data is exportable on demand from /admin/export and deletable on demand within 30 days.
- Aggregation by default. Managers and admins see aggregate distributions, not individual answers. Mood logs and pulse responses are individual-level only to the packmate who created them.
- No model training on customer data. We do not use customer data to train, fine-tune, or improve any model, including third-party models we call (e.g. OpenAI). Where AI is enabled, we send first names + aggregate counts only, never free-text recognitions or mood entries.
- Retention. Active workspace data is retained for the life of the subscription plus 90 days. After that, check-in history is anonymised and recognition free-text is deleted. Audit logs are retained 12 months (36 months on Enterprise).
- Access controls. Production access is limited to named individuals, MFA-required. All admin actions are logged to an audit trail.
- Backups. Daily encrypted snapshots, encrypted at rest with AES-256. Restores are tested.
Incident response
- Detection. Sentry, UptimeRobot, and Vercel logs alert us to error spikes or downtime.
- Triage. We assess severity and prioritise anything involving data exposure or a production outage first.
- Customer notification. If customer data is materially affected, we notify named admin contacts promptly.
- Write-up. Material incidents get a written summary, available to affected customers on request.
Vulnerability disclosure
Report security issues to support@theschoolofplay.co. We acknowledge within one business day, triage within five, and credit reporters publicly on /security/hall-of-fame on request. We do not currently run a paid bounty programme.
This overview describes BetterUs Workplace as of the date above. Changes that materially affect customer data handling are announced 30 days in advance via email to named admin contacts and on /changelog. For a custom DPA, BAA, or SIG questionnaire response: support@theschoolofplay.co.
BetterUs Workplace is operated by The School of Play Pty Ltd, an Australian private company. © 2026 The School of Play Pty Ltd. All rights reserved.