Nubius Security Network

Privacy Policy

Operated by DRS Abundance Pty Ltd (ABN 25 695 734 037)

Last updated: 28 September 2026

1. Introduction

DRS Abundance Pty Ltd (ABN 25 695 734 037) (“DRS Abundance”, “Nubius”, “we”, “us”, “our”) operates Nubius Security Network (“Nubius” or the “Platform”), a website and associated services at nubiusnetwork.com connecting verified security professionals, security businesses, and organisations seeking security services across Australia.

Nubius is an introduction, discovery and networking platform that verifies credentials, facilitates discovery and connection between security professionals, businesses and organisations, and provides supporting tools such as messaging, opportunity posting and a public security-services directory.

This Privacy Policy explains what personal information we collect, how we use it, who we share it with, how we protect it, and the rights you have. It applies to all users of Nubius, including Security Professionals, Businesses (including Security Companies), Organisations using our Contact and Browse Security Services features, and their representatives.

DRS Abundance has lodged its election under section 6EA of the Privacy Act 1988 (Cth) to be treated as an organisation bound by that Act. The election takes effect on registration by the Office of the Australian Information Commissioner. Pending registration, we handle personal information in accordance with the Australian Privacy Principles (APPs) as a matter of policy.

2. Information We Collect

2.1 Security Professionals

  • Account information: full name, email address, mobile phone number, and password (stored as a hash).
  • Identity verification: full legal name, date of birth, government-issued photo ID (driver licence or passport) and a copy of that document.
  • Security licence verification: licence number, issuing state/territory, licence class(es), expiry date, and a copy of the licence document.
  • Profile information: photo, professional headline, location (a free-text field intended for suburb-level entry), work categories, experience, availability, shift preferences, and a visibility setting.
  • Additional credentials (optional, self-declared): credential type, issuing organisation, credential/certificate number, expiry date and, where the professional chooses to provide it, supporting evidence documentation (e.g. a First Aid certificate). Credentials with supporting evidence are shown to Businesses as “Evidence Provided”, distinct from Nubius’s own identity and licence verification (“Nubius Verified”). Nubius does not independently verify self-declared credentials or their supporting evidence unless expressly stated.
  • Communications: messages sent through the Platform’s messaging feature, and notification preferences and history.
  • Payment information: Security Professional membership is currently free of charge and does not require payment details.
  • Push notification data (if using the Nubius mobile application): a device token used solely to deliver notifications to your device.

2.2 Businesses (including Security Companies)

  • Account information: representative name, email, phone, and password (stored as a hash).
  • Business verification information: legal business name, ABN/ACN, business address, and business phone and email (verification contact details, held privately and separately from any public-facing contact details).
  • Profile information: logo, trading name, business type, general location, description, operating areas, and services offered.
  • Public Security Services Directory listing (optional, opt-in): where a Business elects to be listed in Nubius’s public “Browse Security Services” directory, it may provide a public phone number and public email address, distinct from the private verification contact details above, specifically intended for public display to organisations seeking security services.
  • Opportunity information: details of security roles or shifts posted, including a general public location; the exact site address is private and shared only with a Security Professional whose expression of interest has been accepted.
  • Membership and payment: Business membership is a paid subscription with an initial free trial period, processed via our payment processor, Stripe. We do not collect or store full card details; these are collected directly by Stripe.

2.3 Organisations and Members of the Public

Organisations and members of the public may use Nubius’s public Browse Security Services directory and Contact page without creating an account. Where an individual submits a contact form or a quote/enquiry request to a listed business, we collect the name, email address and message content they choose to provide, solely to deliver that enquiry to Nubius or the relevant business, as applicable.

2.4 Automatically Collected Information

When you use the Platform we automatically collect standard technical information, including your IP address, browser and device type, device identifiers, and usage data, for security, troubleshooting and service improvement. IP addresses and device identifiers are recorded in our server and authentication logs and retained for 90 days.

Where a visitor uses the public Browse Security Services directory, we record pseudonymous event data in our own database, such as that a search occurred, that a listing appeared in results, that a profile was viewed, or that a contact action (e.g. a phone, email or website click) was taken. This data is attributed to a pseudonymous session identifier, not to a named individual, and is used to provide Businesses with visibility and discovery analytics regarding their own listing. It does not include your name, email address or any other directly identifying information unless you separately provide it (for example, via the Contact form).

Cookies and similar technologies. We use cookies and similar technologies that are necessary for the Platform to operate, for example to keep you signed in and to protect against misuse. We do not use any third-party analytics, error-tracking or advertising tools. You can control cookies through your browser settings, but disabling necessary cookies may prevent parts of the Platform from working.

2.5 Sources of Information

We collect personal information:

  • directly from you, when you create an account, complete your profile, submit verification documents, post or respond to opportunities, send messages, or contact us;
  • from the Australian Business Register, to verify a Business’s ABN or ACN and legal name;
  • from state and territory security licensing registers, to verify a Security Professional’s licence details;
  • from Stripe, limited to the status of a Business’s subscription and free trial (we do not receive card details); and
  • automatically through your use of the Platform, as described in Section 2.4.

3. How We Use Your Information

We use personal information to:

  • create and administer accounts and the public directory listing (where applicable);
  • verify identity, security licence and business/ABN details;
  • operate core Platform features: opportunity browsing and posting, expressions of interest, invitations, messaging, notifications, and the public Browse Security Services directory;
  • process Business membership payments via Stripe;
  • respond to enquiries submitted via the Contact page or a business quote-request form, and provide customer care and support;
  • provide Businesses with pseudonymous discovery analytics regarding their own public listing (searches, views, contact actions), without identifying the individuals who generated that activity;
  • communicate with users about their account, verification status and Platform updates;
  • maintain the safety, security and integrity of the Platform, including detecting fraud and misuse and enforcing our Terms and Conditions;
  • provide, maintain and improve the Platform, including monitoring usage and detecting, preventing and addressing technical issues; and
  • comply with legal obligations.

Direct marketing. We do not currently send marketing communications. If we do so in future, about Nubius features, updates and offers, by email or push notification, every marketing communication we send will include a simple means to unsubscribe. We do not currently provide a notification-preferences setting in your account; if we introduce direct marketing, we will also provide a way to manage your marketing preferences at that time. Service notifications, such as verification outcomes, expression-of-interest and invitation updates, security alerts, and notice of changes to this Policy or our Terms and Conditions, are not marketing communications and will continue to be sent while you hold an account. We do not provide your personal information to third parties for their own marketing purposes.

4. Verification Documents

Identity documents, security licence documents and any supporting evidence for additional credentials are used solely to verify eligibility and are:

  • stored in a private, access-restricted storage system, accessible only to authorised Nubius administrators for the purpose of verification review;
  • never made visible to other Security Professionals, Businesses, Organisations or the public (where a Security Professional provides supporting evidence for an additional credential, Businesses viewing that professional’s profile see only that evidence was provided, never the underlying document itself); and
  • not shared with third parties except where required by law or to verify a licence against a relevant government or regulatory register.

Copies of identity documents are deleted within 90 days of Nubius’s verification decision; we retain only the document type, verification outcome and date. Copies of security licence documents are handled in the same way. Licence numbers and passport or driver licence numbers are used only to verify your identity and licence status; we do not adopt them as an account identifier and do not disclose them to other users.

Our verification currently involves manual review of your submitted licence document by an authorised administrator. We do not currently cross-check licence details against state or territory licensing registers, whether by automated or manual means, though we may introduce this in the future. A “Verified” status reflects the position at the time of that review and is not automatically re-checked or removed when a licence expiry date passes; you are responsible for keeping your licence details current. Nubius verification does not constitute a police check, background check or government endorsement, and must not be relied upon as such.

5. Messaging

Nubius’s messaging feature allows any authenticated user to message any other authenticated user. Messaging displays only your display name, profile photo and verification status to the other user; it does not reveal your phone number or email address. No automated scanning of message content is performed. Nubius does not currently provide an in-Platform mechanism for reporting a message. Authorised administrators have the technical ability to access message content stored in our database and may do so where misuse or a safety risk is suspected or where the law requires it; administrator access to message content is not currently separately logged. We intend to introduce an in-Platform reporting mechanism and administrator-access logging for messages in a future update, and will update this Policy accordingly.

6. Public Directory and Contact Features

Businesses that opt in to the public Browse Security Services directory should only provide contact details, service descriptions and other information they genuinely intend to be publicly visible to any visitor to the Platform, including non-members. A Business may withdraw from public listing at any time via its account settings, which will remove its public profile from the directory.

Enquiries submitted through the Contact page are delivered by email directly to Nubius and are not separately stored in our database. Quote requests submitted to a Business through the Browse Security Services directory are stored in our database, disclosed to that Business, and retained for the period stated in the section headed “Data Retention”.

7. How We Share Your Information

We do not sell personal information. We share information:

  • with other users as necessary for the Platform to function (for example, a Business can view a verified Security Professional’s profile, and an Organisation can view a Business’s public directory listing); where you submit an enquiry or quote request to a listed Business, your name, contact details and message are disclosed to that Business, which handles them under its own privacy policy;
  • with service providers who help operate the Platform: Supabase (database hosting, file storage and authentication) in Sydney, Australia; Stripe (payment processing) in the United States; Resend (transactional email delivery) in the United States; Vercel (website hosting) in the United States; and Apple and Google (mobile application distribution and push-notification delivery) in the United States. We are likely to disclose personal information to recipients located in the United States, and before doing so we take reasonable steps, including contractual terms, to ensure it is handled consistently with the APPs;
  • where required by law or legal process, or to protect the rights, property or safety of Nubius, our users or the public; and
  • in connection with a business transaction (merger, acquisition, sale of assets), subject to equivalent privacy protections.

Security Professional profile visibility.

If you are a Security Professional, the following applies to your profile:

  • your profile is visible only to verified, subscribing Businesses that are signed in; it is not visible to unauthenticated visitors and is not indexed by search engines;
  • your profile location is a free-text field intended for suburb-level entry and is shown to Businesses as you enter it; do not enter your street address or other precise location details;
  • Businesses see only whether your licence has been verified (a “Verified” or “Not Verified” indicator); your licence number, licence class(es) and expiry date are never shown to Businesses;
  • your mobile number and email address are never shown or released to Businesses; all communication takes place through the Platform’s messaging feature, as described in Section 5; and
  • you can hide your profile from Businesses at any time using the visibility setting in your account.

When you create a Security Professional account we ask for your express consent to your profile information being made available to subscribing Businesses, and we record that consent. You may withdraw consent at any time by hiding your profile or closing your account.

8. Data Storage and Security

Our primary database and file storage are hosted via Supabase, with infrastructure located in Sydney, Australia; some of our service providers process information overseas (see the section headed “How We Share Your Information”). We protect personal information with encryption in transit and at rest, access controls that restrict sensitive information (including identity and licence documents and private business verification details) to authorised personnel, and authentication requirements for administrators. No method of electronic storage or transmission is completely secure, and we cannot guarantee absolute security.

If we suspect that personal information we hold has been lost or subject to unauthorised access or disclosure, we will promptly assess whether the incident is likely to result in serious harm to any individual. Where it is, we will notify affected individuals and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act.

9. Data Retention

We retain personal information for as long as an account remains active. After an account is closed or deactivated we retain personal information only for the periods below, after which it is securely deleted or de-identified:

  • account and profile information: 12 months after closure;
  • messages: 12 months after they are sent, or on account closure if earlier;
  • identity and licence documents: as set out in the section headed “Verification Documents”;
  • financial and subscription records: 7 years, as required by tax and corporations law;
  • quote requests submitted through Browse Security Services: 12 months after delivery. Contact-form enquiries submitted through the Contact page are not stored in our database and are not subject to a database retention period; and
  • server, authentication and administrator-access logs: 90 days.

We may retain information for longer where required by law or where it is needed to resolve a dispute or enforce our Terms and Conditions. Pseudonymous analytics data (see Section 2.4) may be retained for longer periods for business reporting purposes.

10. Automated Processes

Search results shown to Businesses are ordered by a Security Professional’s availability status and then alphabetically by name or, where the Business selects it, by recency of activity, based on the professional’s most recent sign-in to the Nubius website. (Sign-ins via the Nubius mobile app are not yet reflected in this measure.) Verification outcomes are decided by manual administrator review, not by automated processes. We do not use computer programs to make decisions that could reasonably be expected to significantly affect your rights or interests. If you have a question about how any Platform process has affected your account, you may contact our Privacy Officer.

11. Your Rights

Under the Australian Privacy Principles, you may ask to access the personal information we hold about you and to correct information that is inaccurate, out of date, incomplete, irrelevant or misleading. You may also ask us to delete your personal information, and we will do so unless we are required or permitted to retain it.

To make a request, write to our Privacy Officer using the details in the section headed “Contact Us”. We will verify your identity before releasing or changing any information, respond within 30 days, and give you written reasons if we refuse a request in whole or in part, together with the complaint options available to you.

Because we verify the identity and licences of members, Security Professionals and Businesses cannot deal with us anonymously or under a pseudonym. Visitors to the public Browse Security Services directory may browse without identifying themselves.

Complaints. If you believe we have breached the Australian Privacy Principles, please complain in writing to our Privacy Officer. We will acknowledge your complaint within 7 days and give you a written response within 30 days. If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.

12. Children

Nubius is intended for use by individuals at least 18 years of age. We do not knowingly collect personal information from children.

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify account holders of material changes by email at least 14 days before they take effect, and will also post a notice on the Platform. Where a change would permit a new use or disclosure of personal information we have already collected, we will seek your consent before relying on it.

14. Contact Us

Privacy Officer: Shan Berih
Email: connect@nubiusnetwork.com
Post: Privacy Officer, DRS Abundance Pty Ltd, 1/60 Deakin Street, Essendon VIC 3040
Entity: DRS Abundance Pty Ltd (ABN 25 695 734 037)

If you are not satisfied with our response to a request or complaint, you may contact the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.

Read our Terms & Conditions.