Legal
Privacy policy
Last updated: 27 July 2026
Noble Performance Solutions Pty Ltd (ABN 45 107 629 149) of PO Box 83, Keiraville NSW 2500, Australia ("Noble Performance Solutions", "we", "us", "our") operates the Noble Performance platform at www.nobleperformance.com (the "Service"). This policy explains what personal information we collect, why we collect it, who we disclose it to, how long we keep it, and how you can access, correct or complain about it. For the personal information you provide and generate while using the Service we are the entity responsible for it, except where we handle information on behalf of an organisation that has enrolled you in a program — see Enterprise & cohort data below.
How this policy applies
We are an Australian company with an annual turnover below AU$3 million, which means the Privacy Act 1988 (Cth) does not apply to us automatically. We have chosen to comply with it anyway. This policy is written to meet the Australian Privacy Principles (APPs) and we handle your personal information as though we were an APP entity, including the Notifiable Data Breaches scheme described under Security & data breaches. If you are in the United Kingdom or the European Economic Area, the additional rights described under UK & EEA visitors also apply to you.
What we collect
- Account & identity — your email address, and your name where you provide it. We sign you in with a one-time emailed link (a "magic link") processed by Supabase Auth. We never ask for, store, or see a password.
- Your work in the product — diagnostic results, action plans, goals, journal entries, and saved chat history.
- Program data — for the Safety Leadership Program and similar programs: pre-work and self-assessment responses, reflections, knowledge-check answers and scores, report-backs, your personal leadership declaration, and any files you upload (for example project briefs or photos).
- Billing — billing identifiers and subscription or invoice status from Stripe when you or your organisation pays. We do not collect or store full card numbers; card data goes directly to Stripe and never touches our servers.
- AI coaching content — when you use the AI-assisted features ("Ask the Coach"), the messages you send are processed by Anthropic to generate a response.
- Usage & device information — product analytics events, approximate location derived from your IP address, browser and device information, and rate-limiting counters, used to operate, secure and improve the Service.
- Support & correspondence — anything you send us by email.
We do not collect sensitive information as defined in the Privacy Act (such as health, racial or ethnic origin, political opinions, or criminal record) and ask that you do not enter it into free-text fields, journal entries or uploads.
Why we collect it, and what happens if you don't give it
We collect personal information because we need it to create your account, deliver the programs and tools, save and sync your work across devices, operate the cohort and manager features your organisation uses, take payment, keep the Service secure, meet our tax and accounting obligations, and improve reliability and content.
You can browse the public site and take the Performance Diagnostic without giving us your name. You do need to give us an email address to create an account, because that address is how we sign you in — without it we cannot provide the Service. Providing your name is optional; if you leave it out we simply greet you by the first part of your email address.
Who we disclose it to
We do not sell your personal information, and we do not disclose it for any organisation's direct marketing. We disclose it to vetted service providers who handle it only on our instructions to run the Service — hosting, database and authentication, payments, email, AI, and analytics. The current list, what each one receives, and where each one processes it is maintained on our sub-processors page. We may also disclose information where we are required or authorised by law, or in connection with a sale of our business, in which case this policy continues to apply to the information transferred.
Overseas disclosure (APP 8)
Application data is stored in Supabase (PostgreSQL and object storage) in the Australia (Sydney) region where configured. Some of our service providers are located overseas and will receive your personal information there. Based on our current sub-processors, the likely countries are the United States (Anthropic, Stripe, Resend, PostHog, Vercel) and, depending on region configuration, the European Union.
Before disclosing personal information overseas we take reasonable steps to ensure the recipient handles it consistently with the APPs, including binding contractual data protection terms with each provider. Where we transfer personal data out of the UK or EEA we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses and the UK Addendum. The sub-processors page lists each provider's processing location.
How long we keep it
We keep your personal information for as long as your account is active and for as long as we need it to provide the Service. When you delete your account we delete or de-identify your personal information within 30 days, except where we are required to keep it — billing and tax records are retained for seven years as required by Australian tax law, and we keep a hashed (non-reversible) record of certain administrative actions for audit purposes.
Access, correction and your choices
Under APP 12 and APP 13 you may ask us for access to the personal information we hold about you, and ask us to correct it if it is inaccurate, out of date, incomplete, irrelevant or misleading. You can do most of this yourself, immediately, from your account settings — export a copy of your data, correct your name, or delete your account and its data.
You can also email us at hello@nobleperformance.com. We will respond within a reasonable period and in any case within 30 days. We do not charge for making a request. If we refuse access or correction we will tell you why in writing and how to complain.
You can opt out of our non-essential emails at any time using the unsubscribe link in any such email, or by emailing us. Transactional messages you cannot opt out of while you hold an account — sign-in links, receipts, and security notices — because they are how the Service works.
Cookies & analytics
We use cookies and similar technologies that are strictly necessary to sign you in and keep the Service secure. We also use PostHog for product analytics to understand how the Service is used and improve it; analytics profiles are created only for signed-in users, and we do not use analytics for cross-site advertising or for building a profile of you for anyone else. If you would like the analytics data associated with you deleted, email us and we will action it.
Security & data breaches
We take reasonable steps to protect your personal information from misuse, interference, loss, and unauthorised access, modification or disclosure. In practice that means access controls and row-level database policies so accounts can only reach their own records, encryption in transit, a private default-deny store for program videos served only through short-lived signed links to enrolled learners, scoped server-side database access, rate limiting, and audit logging of administrative actions.
No system is perfectly secure. If a data breach occurs that is likely to result in serious harm to you, we will notify you and the Office of the Australian Information Commissioner in accordance with the Notifiable Data Breaches scheme, and — where the UK or EU GDPR applies — the relevant supervisory authority within 72 hours.
Enterprise & cohort data
When your employer or another organisation enrols you in a program, that organisation decides how your program data is used and we handle it on their behalf under a data processing agreement. Nominated managers or sponsors at that organisation can see your program progress, assessment outcomes, report-backs, and uploaded artefacts on a manager dashboard, so they can support your development and measure the program.
If you want your program data accessed, corrected or deleted, you can ask us and we will help, but we may need to refer the request to that organisation, because it is their information to direct. Our enterprise terms are set out in our Data Processing Agreement.
UK & EEA visitors
If you are in the United Kingdom or the European Economic Area, the UK GDPR or EU GDPR applies to you and we act as the data controller for the personal data described above. Our legal bases are: performance of a contract (creating your account, delivering the programs and tools, syncing your work, enforcing subscription access); legitimate interests (securing the Service, preventing abuse, operating the cohort features your organisation uses, improving reliability and content, in a way that does not override your rights); consent (non-essential analytics and optional communications, which you may withdraw at any time); and legal obligation (tax and accounting records).
In addition to access and correction, you have the right to erasure, to restrict or object to certain processing, to data portability, and to withdraw consent where we rely on it. You may lodge a complaint with your local supervisory authority or, in the UK, the Information Commissioner's Office.
Children
The Service is intended for workplace use by adults and is not directed to children. We do not knowingly collect personal information from anyone under 16. If you believe a child has given us personal information, email us and we will delete it.
Complaints
If you think we have mishandled your personal information or breached the Australian Privacy Principles, email us at hello@nobleperformance.com with the detail of your concern. We will acknowledge your complaint within 5 business days and give you a written response within 30 days.
If you are not satisfied with our response, you can refer the complaint to the Office of the Australian Information Commissioner at oaic.gov.au, by phone on 1300 363 992, or by post to GPO Box 5218, Sydney NSW 2001.
Changes to this policy
We may update this policy from time to time. We will change the "last updated" date above and, for material changes, take reasonable steps to notify you before they take effect.
Contact
Noble Performance Solutions Pty Ltd. ABN 45 107 629 149. PO Box 83, Keiraville NSW 2500, Australia. For privacy questions, access, correction or deletion requests: hello@nobleperformance.com. This policy is governed by the laws of New South Wales, Australia. See also our terms of use and sub-processors.