Terms and Conditions

1. 1. Introduction and Scope

1.1 GHEORG Pty Ltd (“GHEORG,” “we,” “our,” or “us”) provides an AI-supported mental wellness platform for children aged approximately 4 to 12 (the “Service”). GHEORG Pty Ltd operates the Service and is the entity that collects, uses, stores, discloses, and protects personal information in connection with it. Gheorg Corp, a United States affiliate of GHEORG Pty Ltd, acts as the contracting party for institutional customers (including schools, clinics, employers, and government agencies) in the United States, but does not itself process or hold personal information collected through the Service. Gheorg Global Inc., a Delaware corporation, is GHEORG Pty Ltd’s parent holding company; as of the date of this Policy it does not operate the Service or process personal information. This Privacy Policy explains how GHEORG Pty Ltd collects, uses, stores, discloses, and protects personal information in connection with the Service, including information relating to children, and will be updated to reflect any change in this structure.

1.2 This Policy applies to parents, guardians, teachers, school administrators, and other adults who interact with GHEORG (“Adult Users”), and to children who use the Service under the supervision and consent of an Adult User (“Child Users”).

1.3 GHEORG currently operates in Australia, the United States, the United Kingdom, and the European Union. Where local law imposes requirements stricter than this Policy — including but not limited to the EU/UK (GDPR and the UK GDPR, including Article 8 conditions for children’s consent), the United States (COPPA), and Australia (Privacy Act 1988 (Cth) and the Australian Privacy Principles) — we comply with the stricter requirement in that jurisdiction.

2. Children's Data and Parental Consent

2.1 GHEORG is directed, in significant part, to children. We do not knowingly permit a child to create an account independently. An account for a Child User may only be created and activated by a parent or legal guardian (“Consenting Adult”), or by a school, clinic, employer, government agency, or other institution acting under a separate institutional agreement with GHEORG Pty Ltd or Gheorg Corp that itself documents the basis for processing children’s data and identifies which Gheorg entity processes that data.

2.2 By creating an account on behalf of a Child User, the Consenting Adult confirms that they are the child’s parent or legal guardian, or are otherwise authorised to consent on the child’s behalf, and consents to the collection and use of the Child User’s personal information as described in this Policy.

2.3 We collect only the personal information about Child Users that is reasonably necessary to provide and improve the Service, including: account and profile information provided by the Consenting Adult; the Child User’s interactions with the Service (including conversational content with GHEORG’s AI features); and usage and device data described in Section 5.

2.4 Consenting Adults may review, correct, export, or request deletion of their child’s personal information at any time by contacting support@gheorg.com. We will action verified requests within 30 days, subject to any legal obligation to retain specific records.

2.5 We do not use Child User personal information for behavioural advertising, and we do not sell Child User personal information.

3. Information We Collect

3.1 Account and contact information: name, email address, and other details provided by the Consenting Adult or institution when creating an account.

3.2 Child interaction data: content generated through the Child User’s use of the Service, including conversational input and platform responses, mood or wellbeing indicators captured through the Service’s intended features, and related usage patterns.

3.3 Technical and usage data: device identifiers, IP address, operating system, browser type, and app usage data, collected in the aggregate to understand how the Service is used and to maintain its security and performance.

3.4 We do not collect precise geolocation data from Child Users, and do not use location data for advertising purposes.[C1] 

4. How We Use Personal Information

4.1 To provide, maintain, and improve the Service, including personalising the Child User’s experience within the bounds of GHEORG’s clinical and safety design.

4.2 To monitor and improve the safety, reliability, and clinical appropriateness of GHEORG’s AI features, including detection of safety-relevant content and escalation pathways consistent with GHEORG’s safeguarding protocols.

4.3 To communicate with Consenting Adults about their account, the Service, and material updates to this Policy.

4.4 To comply with legal obligations, and to protect the rights, safety, and property of GHEORG, its users, and others.

4.5 For research and publication purposes, strictly as set out in Section 6 below.

5. Aggregate and Technical Data

5.1 We collect certain technical information automatically, including device type, unique device identifiers, IP address, operating system, and app usage patterns. This information is used in aggregated, statistical form to understand how the Service is used and to improve it.

5.2 Aggregated technical data of this kind does not include the substantive content of a Child User’s interactions with the Service and is treated separately from the research and publication framework described in Section 6.

6. Research, Safety Reporting, and Publication

6.1 GHEORG conducts and supports clinical and academic research relating to children’s mental wellness and the safety and efficacy of AI-supported mental health tools, including the VERA-MH-P research programme.

6.2 Personal information, including Child User interaction data, will only be used for research or external publication (including academic papers, conference presentations, regulatory submissions, or public safety/transparency reporting) where:

•        the specific use has been reviewed and approved by an independent Human Research Ethics Committee (HREC) or equivalent ethics body prior to use; and

•        the information is de-identified or aggregated to a standard consistent with that HREC approval before any external use, publication, or disclosure; and

•        the use is consistent with the scope of consent given by the Consenting Adult at the time of data collection, or separate specific consent has been obtained for that use.

6.3 Where GHEORG publishes aggregate statistics about patterns of use relevant to child safety (for example, summary rates of safety-relevant content detected by the Service), that publication will identify the ethics approval and methodology under which the underlying data was reviewed, consistent with Section 6.2.

6.4 GHEORG will not use identifiable Child User data, or data reasonably capable of re-identifying a specific child, in any public-facing research output, blog post, marketing material, or press communication, under any circumstances.

6.5 Consenting Adults may withdraw consent for their child’s de-identified data to be used in future research at any time by contacting support@gheorg.com. Withdrawal will not affect research already published in accordance with Section 6.2, but will be actioned for all future use.

6.6 Research participation under this Section is covered by general acceptance of this Policy at account creation and does not require a separate opt-in.

6.7 Separately from the research and publication framework in Sections 6.1 to 6.6, GHEORG may use aggregated and de-identified data about use of the Service for internal company reporting and public communications, including investor and board reporting, marketing materials, and general statements about platform usage or impact (for example, summary figures on how many children used a particular feature over a given period, or numbers of children asking for a particular type of advice).

6.8 Use under Section 6.7 does not require HREC or equivalent ethics review, but data used in this way must be aggregated or de-identified to a standard that does not reasonably permit re-identification of a specific child, family, school, or other small or identifiable group (for example, figures must not be broken down to a level, such as a single classroom or a single day at a small site, where an individual child could reasonably be inferred). Section 6.4 applies equally to use under this Section: GHEORG will not use identifiable Child User data, or data reasonably capable of re-identifying a specific child, in any public-facing output under Section 6.7, under any circumstances.

7. Disclosure of Personal Information

7.1 We may disclose personal information to employees, officers, professional advisers, contracted service providers, and subcontractors, only to the extent reasonably necessary to deliver the Service or as described in this Policy. Any third party processing Child User data on our behalf is bound by data protection obligations at least as protective as this Policy.

7.2 We may disclose personal information where required by law, regulation, court order, or lawful request by a regulatory or law enforcement authority.

7.3 If GHEORG is involved in a merger, acquisition, financing due diligence, or sale of business assets, including the current restructuring under which Gheorg Global Inc. (a Delaware corporation) will become the parent holding company of GHEORG Pty Ltd, personal information may be disclosed to the counterparty or its advisers under a confidentiality agreement, and any successor or new parent entity will be bound by this Policy or a policy providing materially equivalent protection for existing users.

7.4 We do not disclose personal information to third parties for their own direct marketing purposes, and we do not sell personal information.

8. International Data Transfers

8.1 Given GHEORG’s operations across multiple countries, and the involvement of GHEORG Pty Ltd, Gheorg Corp, and (once active) Gheorg Global Inc. described in Section 1.1, personal information may be stored or processed in a country other than the one in which the Consenting Adult or Child User is located. Where such a transfer is subject to a legal requirement for an approved transfer mechanism, such as EU Standard Contractual Clauses, GHEORG will put that mechanism in place before the transfer occurs.

9. Data Retention

9.1 We retain personal information only for as long as necessary to provide the Service, to satisfy the purposes described in this Policy, or as required by law.

9.2 Subject to confirmation under Section 9.1, our default retention periods by category of data are:

•        Account and contact data (Consenting Adult and institutional account details): retained for the life of the account, and for up to 24 months after account closure to allow for reactivation, support, and legal or accounting requirements, after which it is deleted or de-identified.

•        Child interaction data (conversational content, mood/wellbeing indicators, and related usage data described in Section 3.2): retained for the life of the account plus up to 12 months, or longer where retention is reasonably necessary for an open safety, safeguarding, or legal matter relating to that Child User, after which it is deleted or de-identified.

•        De-identified or aggregated research and reporting data (used under Sections 6 and 6.7): retained indefinitely once properly de-identified or aggregated to the applicable standard, as it is no longer reasonably linkable to an individual Child User.

•        Technical and usage data (described in Section 5): retained in identifiable or device-linked form for up to 12 months, and in aggregated form thereafter.

10. Security

10.1 We maintain physical, electronic, and managerial safeguards designed to protect personal information against unauthorised access, use, disclosure, alteration, or loss. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

11. Access, Correction, and Complaints

11.1 A Consenting Adult may request access to, correction of, or deletion of their own or their child’s personal information by contacting support@gheorg.com. We will respond in accordance with applicable law, including the Privacy Act 1988 (Cth) where applicable.

11.2 Complaints about our privacy practices may be sent to support@gheorg.com. We will acknowledge and investigate complaints in accordance with applicable law and, in Australia, in a manner consistent with the Australian Privacy Principles.

12. Opting Out

12.1 A Consenting Adult may stop further collection of information by ceasing use of the Service and requesting account deletion via support@gheorg.com. Section 6.5 separately governs withdrawal of consent for research use.

13. Changes to This Policy

13.1 We may update this Policy from time to time. Material changes affecting how Child User data is used, including any change to the research and publication framework in Section 6, will be notified to Consenting Adults in advance and, where required by law, will require renewed consent before taking effect.

14. Contact

14.1 Questions about this Policy may be directed to support@gheorg.com.