Last updated: April 2026
1. About This Policy
This Privacy Policy describes how Network 1 Media Group Pty Ltd (ABN 82 633 114 753) (“we”, “us”, “our”) collects, uses, stores, discloses, and protects personal information in connection with the ActivityPulse platform, website, agent software, and related services (collectively, the “Service”).
We are committed to handling personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
Two distinct relationships: This policy covers two separate situations. First, when we collect information directly from you as a website visitor, prospect, or customer. Second, when we process workforce monitoring data on behalf of our customers, where the customer is the data controller and we act as a data processor.
2. Information We Collect Directly
We collect the following types of personal information directly from website visitors, prospects, customers, and other individuals who interact with us:
- Contact information. Name, email address, phone number, organisation name, job title, and country, which you provide when you request a demo, request a trial, contact us, subscribe to communications, or enter into a customer agreement.
- Account information. Login credentials, multi factor authentication details, role assignments, and account preferences for users of the ActivityPulse portal.
- Billing information. Billing contact details, ABN, billing address, and payment records. We accept payment by Australian bank transfer only. We do not store credit card details and do not use third party payment processors.
- Communications. Records of correspondence, support requests, sales enquiries, and feedback you provide to us.
- Website usage information. Pages visited, referral sources, IP address, browser type, device type, and timestamps. This is collected through standard server logs and analytics tools (see Section 10).
3. Workforce Data Processed on Behalf of Customers
When organisations deploy ActivityPulse to monitor their employees’ work computers, the ActivityPulse agent collects activity data from those endpoints. In this scenario:
- The customer is the data controller. Our customer (the employer) determines what is monitored, who is monitored, how the data is used, and how long it is retained. The customer is responsible for the lawfulness of the monitoring under applicable workplace surveillance and privacy legislation.
- We are the data processor. We host, process, and store the data on behalf of the customer, but we do not use it for our own purposes. We do not access customer data except where necessary to provide the Service, respond to support requests, or comply with legal obligations.
- Categories of workforce data. Depending on which modules the customer has enabled, the agent may collect application usage, web browsing, input activity counts (not content), clipboard metadata, USB and removable media activity, email metadata (Outlook), print job metadata, file operation metadata, system events, screenshots, AI prompt content, terminal commands, geolocation, and network connection details.
- Employees should contact their employer. If you are an employee whose computer is being monitored by ActivityPulse, your employer is responsible for that monitoring. For requests about your data (access, correction, deletion), please contact your employer’s privacy officer or HR team.
4. How We Use Personal Information
We use the personal information we collect directly for the following purposes:
- To provide, maintain, and improve the Service
- To respond to enquiries, provide support, and process orders
- To process payments and manage subscriptions
- To send service related communications such as billing notices, security alerts, and account updates
- To send marketing communications where you have opted in or where permitted by law (you may opt out at any time)
- To investigate and prevent fraud, abuse, or misuse of the Service
- To comply with legal obligations and respond to lawful requests from authorities
We do not use workforce monitoring data processed on behalf of customers for our own marketing, analytics, or any other purpose beyond providing the Service to that customer.
4a. Automated Decision Making
The ActivityPulse platform uses automated processes to compute risk scores and behavioural indicators about individuals whose activity has been collected by the Service. These automated processes include:
- Insider Threat risk scoring (based on multiple signal vectors)
- Retention Risk scoring
- Burnout Risk scoring
- Productivity scoring
- AI prompt sentiment analysis (pattern based, performed on platform without external AI services)
- Data Loss Prevention event scoring
Scores are computed using configurable weightings and thresholds set by the customer. They are advisory only and are intended to direct the attention of authorised personnel within the customer organisation.
ActivityPulse does not make any employment, disciplinary, performance, or other decisions about individuals on the basis of these scores. Such decisions are made (if at all) by our customers, and our customers are responsible for ensuring that human review is undertaken before any adverse action is taken in connection with a score.
Individuals whose data has been collected by the Service can request information about how a score relating to them was produced by contacting their employer (the customer organisation that controls the data). Customers can request information from ActivityPulse about the methodology used by any of the scoring engines through their portal account or by contacting [email protected].
5. Disclosure of Personal Information
We may disclose personal information in the following limited circumstances:
- To service providers and subprocessors. We use a small number of trusted service providers for hosting infrastructure, email delivery, and security filtering. Where these providers process personal information on our behalf, they are bound by contractual obligations to handle it securely and only for the purposes we specify. A complete and current list of our subprocessors, including provider name, location, and purpose, is published in our Subprocessor List.
- To comply with legal obligations. We may disclose personal information where required by Australian law, court order, or lawful request from a regulatory authority.
- To protect rights and safety. We may disclose personal information where necessary to investigate or prevent fraud, security incidents, or threats to safety.
- In the event of a business transfer. If our business or the ActivityPulse product is merged, acquired, sold, or restructured, personal information and customer workforce data may be transferred to the acquiring entity as part of that transaction. Any acquirer will be bound by the same Australian data sovereignty commitments and privacy obligations described in this Policy. Customer data will continue to be hosted on Australian infrastructure following any such transfer.
We do not sell personal information. We do not share personal information with advertising networks or data brokers. We do not use customer workforce data for our own purposes, including marketing, analytics, or product development.
6. Australian Data Sovereignty and Infrastructure
All ActivityPulse application data, customer accounts, and workforce monitoring data is collected, processed, and stored exclusively on Australian infrastructure. ActivityPulse is Australian made, Australian owned, and Australian hosted.
Our infrastructure is structured as follows:
- Application hosting. All ActivityPulse application servers, databases, and customer workforce data are hosted on Australian infrastructure within Australian jurisdiction. Customer data is stored in dedicated per organisation databases with complete tenant isolation.
- Email delivery. Transactional and operational email is sent through Microsoft 365 (Australian region) and Amazon Web Services Sydney region. Both providers process email delivery within Australian jurisdiction.
- Security and content delivery. Our public website (activitypulse.com.au) and customer portal (portal.activitypulse.com.au) are protected by Cloudflare for web application firewall, DDoS mitigation, and content delivery. Cloudflare is a United States company that operates a global edge network including Australian nodes. As traffic flows through Cloudflare’s network, request metadata such as IP addresses, user agents, and HTTP headers may be processed across Cloudflare’s infrastructure for security filtering and threat detection. Cloudflare does not have access to decrypted application data or stored customer workforce data, which remains entirely on Australian application servers.
- No overseas processing of customer data. Customer workforce monitoring data (the data collected by ActivityPulse agents from employee endpoints) is never transferred to or processed by overseas systems. All ingestion, storage, analysis, and reporting occurs on Australian infrastructure.
- Sentiment analysis is processed locally. AI prompt sentiment analysis is performed using pattern matching and algorithmic classification on our Australian servers. We do not call external AI services or APIs for sentiment analysis. No customer data is sent to OpenAI, Anthropic, Google, Microsoft, or any other AI provider.
- Australian support team. Our support and engineering team is based in Australia and consists of Australian citizens. Customer support and incident response is handled within Australian jurisdiction.
- No overseas payment processors. We accept payment by Australian bank transfer only. We do not use Stripe, PayPal, or any other third party payment processor that would route financial information overseas.
7. Security of Personal Information
We take reasonable steps to protect personal information from misuse, interference, loss, unauthorised access, modification, and disclosure. Our security measures include:
- Encrypted at rest on the agent. The ActivityPulse agent stores collected data in a local database encrypted with AES-256 using machine-bound keys. The database is unreadable on any other computer, even with physical disk access.
- Encrypted in transit. All data transmitted between the agent and our portal is double encrypted using application layer AES-256-GCM on top of TLS transport encryption. Data remains protected even if TLS is terminated at a load balancer.
- Portal access controls. The ActivityPulse portal is protected by role based access control, mandatory multi factor authentication on all accounts, CSRF protection, secure cookies, session regeneration, and full admin audit logging. Access to customer data is restricted to authorised customer administrators and a small number of our support staff for the purpose of providing the Service.
- Tenant isolation. Customer workforce data is stored in dedicated per organisation databases. There is no shared data store across customers. Network and application level controls prevent cross tenant access.
- Web application protection. Both the public website and the customer portal are protected by Cloudflare’s web application firewall, bot mitigation, and DDoS protection.
- Comprehensive audit logging. All admin actions, configuration changes, data exports, and user access are recorded in audit logs.
Despite these measures, no method of transmission or storage is completely secure. We cannot guarantee absolute security, but we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) where required by the Notifiable Data Breaches scheme.
8. Data Retention
- Customer accounts. Account information is retained for the duration of your subscription and for a reasonable period after termination to meet legal, tax, and accounting obligations.
- Workforce monitoring data. Customers configure data retention periods through the portal. When data reaches the end of its retention period, it is permanently deleted unless a retention hold has been placed.
- Account termination. Upon termination of a customer subscription, monitoring data is retained for 30 days to allow for export. After 30 days, all data is permanently deleted from our systems.
- Marketing contacts. If you have provided your details for marketing communications, we retain your information until you unsubscribe or request deletion.
- Support and correspondence. Records of correspondence are retained for as long as necessary to provide ongoing support and resolve any disputes.
9. Your Rights
Under the Australian Privacy Principles, you have the following rights regarding personal information that we hold about you directly:
- Access. You may request a copy of the personal information we hold about you. We will respond within 30 days at no cost.
- Correction. You may request that we correct any personal information that is inaccurate, out of date, incomplete, or misleading. We will action correction requests within 30 days at no cost.
- Deletion. You may request that we delete personal information we hold about you, subject to our legal obligations to retain certain records (such as billing and tax records).
- Withdrawal of consent. You may withdraw consent for marketing communications at any time by clicking the unsubscribe link in any email or contacting us directly.
- Complaints. You may make a complaint about how we handle personal information. We will acknowledge your complaint within 7 days and respond substantively within 30 days.
To exercise any of these rights, contact our Privacy Officer using the details in Section 14. We may need to verify your identity before responding to a request to ensure we do not disclose information to the wrong person.
Employee data: If you are an employee whose computer is monitored by an ActivityPulse customer, requests regarding your monitoring data must be directed to your employer, not to us. Your employer controls that data and is responsible for handling such requests.
10. Cookies and Website Analytics
Our public website (activitypulse.com.au) uses cookies and analytics tools to understand how visitors interact with our content:
- Essential cookies. Required for the website to function, including session management and security. These cannot be disabled.
- Google Analytics. We use Google Analytics to understand how visitors find and use our website (page views, referral sources, browser types, geographic location at country level). Google Analytics processes this data on Google infrastructure which may include servers outside Australia. Analytics data is aggregated and is not used to identify individual visitors. You may opt out using the Google Analytics opt out browser add on or by disabling cookies in your browser.
- Cloudflare. Cloudflare provides web application firewall, DDoS protection, and content delivery for both our public website and customer portal. Cloudflare may set cookies for security purposes (such as detecting bots and managing traffic). Cloudflare may collect aggregate analytics data including request volumes, geographic distribution, and security events.
Important: Google Analytics and Cloudflare analytics apply only to public website visitors. They do not track activity within the customer portal (portal.activitypulse.com.au) and do not collect or process customer workforce monitoring data. The ActivityPulse application, customer accounts, and workforce data are not subject to third party analytics.
We do not use third party advertising cookies, retargeting pixels, or data broker tracking on either the public website or the customer portal.
11. Children
The Service is intended for use by organisations and their employees in a business context. We do not knowingly collect personal information from children under 18. If we become aware that we have collected personal information from a child under 18 without parental consent, we will take steps to delete that information.
12. Notifiable Data Breaches
We comply with the Notifiable Data Breaches scheme under the Privacy Act 1988. If we become aware of an eligible data breach that is likely to result in serious harm to affected individuals, we will:
- Notify affected individuals as soon as practicable
- Notify the Office of the Australian Information Commissioner (OAIC)
- Provide details of the breach, the information involved, the likely consequences, and the steps being taken in response
13. Changes to This Policy
We may update this Privacy Policy from time to time. The most current version will always be available on this page with an updated “Last updated” date at the top. We will notify you of material changes by email or through the portal.
14. How to Contact Us
For privacy enquiries, requests to access or correct your personal information, complaints, or any other questions about this Policy, contact our Privacy Officer:
Network 1 Media Group Pty Ltd
ABN 82 633 114 753
Email: [email protected]
Postal Address
PO Box 349
Erindale Centre
ACT, 2903
Australia
15. Lodging a Complaint with the OAIC
If you are not satisfied with our response to a privacy complaint, you may lodge a complaint with the Office of the Australian Information Commissioner:
Office of the Australian Information Commissioner
Website: www.oaic.gov.au
Phone: 1300 363 992
Email: [email protected]