PRIVACY POLICY

Ubomi Pty Ltd (ABN 48 662 004 444) Last updated: January 2026

1. Introduction Ubomi Pty Ltd (“Ubomi”, “we”, “us”, “our”) operates a software-as-a-service platform and digital marketplace. This Privacy Policy explains how we collect, use, and protect information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

2. Our Role Ubomi acts as the data controller for personal information processed to maintain your account. Personal Trainers (“Trainers”) operate as independent service providers who use Ubomi’s tools to manage their own business records and client relationships.

3. Information We Collect (Sensitive Health Data) We collect personal information including name, email, and billing details. Crucially, for Clients, we collect fitness-related data (including but not limited to workout logs, reps, weights, and nutrition plans). Under Australian law, this is classified as Health Information (Sensitive Information). By using the Platform, you provide express consent for Ubomi to collect and process this sensitive data on behalf of your Trainer.

4. How We Collect Information Information is collected directly from you during account setup, via the AI-assisted Health Questionnaire, and through your ongoing interactions with your Trainer’s programs on the Platform.

5. Purpose of Collection Data is collected to facilitate the software's core functions, including program delivery, payment processing via Stripe, and providing AI-assisted drafting tools for Trainers. We do not use this data for third-party advertising.

6. Notifiable Data Breaches (NDB) In accordance with the Australian NDB scheme, we maintain a response plan for data breaches. If a breach occurs that is likely to result in serious harm, we will notify you and the Office of the Australian Information Commissioner (OAIC) as soon as practicable.

7. AI Processing & Analytics Ubomi uses AI to analyze Health Questionnaire results for the purpose of matching Clients with suitable Trainers. AI is also used as a drafting assistant for Trainers. We do not engage in "solely automated decision-making" that has legal or medical effects.

8. Marketing Communications We may send you essential service updates. You may opt-out of any promotional communications at any time.

9. Third-Party Links The Platform may contain links to third-party sites. Ubomi is not responsible for the privacy practices of external entities.

10. Trainer-Specific Data We collect professional credentials and business details from Trainers to maintain the integrity of the Platform infrastructure.

11. Direct Marketing and Opt-Out Users can manage communication preferences in their settings or by contacting support@ubomi.co.

12. Disclosure of Personal Information We do not sell your personal data. Disclosure occurs only to essential service providers (e.g., Stripe for payments) or if required by law.

13. Data Integrity and Quality We take reasonable steps to ensure the data we hold is accurate. AI-generated data is always flagged as "system-generated" for Trainer review.

14. Service Providers & AWS Sydney Hosting All primary cloud infrastructure and database systems (including AWS and MongoDB) are located in the Sydney, Australia region. This ensures that your sensitive health data is stored and managed within Australian jurisdiction.

15. Overseas Processing Specific sub-processors (such as AI model providers) may process de-identified data overseas. We ensure these providers adhere to security standards equivalent to Australian privacy laws.

16. Security and Data Retention We use industry-standard encryption to protect your data. Data is retained only as long as necessary for the operation of your account or as required by legal obligations.

17. Access, Correction, and Complaints You have the right to access and correct the personal information we hold about you. Complaints can be directed to support@ubomi.co or escalated to the OAIC.

18. Changes to This Policy We may update this policy to reflect changes in law or technology. Continued use of the platform constitutes acceptance of the updated terms.