Privacy_Policy

PRIVACY POLICY

PRIVACY POLICY

Effective Date: [DD Month YYYY]    |    Last Updated: [DD Month YYYY]

1. Introduction

This Privacy Policy explains how [Company Name] (“we”, “us”, or “our”) is committed to protecting the privacy and security of personal information that we collect, hold, use, and disclose in the course of providing governance, risk, and compliance (GRC) consulting services and operating our website at [www.example.com] (the “Website”).

This Privacy Policy explains how we handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), and, where applicable, the EU General Data Protection Regulation (GDPR), the UK GDPR, and other applicable privacy laws.

By accessing the Website or engaging our services, you acknowledge that you have read and understood this Privacy Policy.

2. Information We Collect

We collect personal information that is reasonably necessary for, or directly related to, our business functions and activities. The categories of information we collect include:

2.1 Information you provide to us

  • Identification details such as your full name, job title, and employer.
  • Contact details including email address, postal address, and telephone number.
  • Information contained in enquiries, service requests, proposals, and engagement correspondence.
  • Billing and payment information where you engage us for paid services.
  • Information you submit through our contact forms, newsletter sign-ups, or downloadable resource requests.

2.2 Information collected automatically

  • Technical data including IP address, browser type and version, operating system, device identifiers, and referring URLs.
  • Usage data including pages viewed, time spent on the Website, links clicked, and approximate geographic location derived from IP address.
  • Cookie and similar tracking technology data (see our separate Cookie Policy for details).

2.3 Information from third parties

  • Publicly available sources such as professional networking platforms, company registers, and your employer’s website.
  • Referrals from existing clients or business partners.
  • Analytics and marketing service providers.

We do not knowingly collect sensitive information (as defined under the Privacy Act 1988) unless it is necessary for the services you have engaged us to provide and you have consented to its collection.

3. How We Use Your Information

We use personal information for purposes that are directly related to our business activities, including:

  • Responding to enquiries and providing requested information about our services.
  • Delivering, administering, and improving our GRC consulting and managed security services.
  • Preparing proposals, statements of work, and tender responses.
  • Issuing invoices, processing payments, and maintaining financial records.
  • Sending you newsletters, service updates, and marketing communications where you have opted in (you may unsubscribe at any time).
  • Maintaining the security, integrity, and availability of the Website and our information systems.
  • Complying with our legal, regulatory, audit, and contractual obligations.
  • Conducting internal research, analytics, training, and quality assurance.

4. Legal Basis for Processing

Where the GDPR or UK GDPR applies, we rely on one or more of the following legal bases to process personal information:

  • Performance of a contract to which you are a party, or to take steps at your request prior to entering into a contract.
  • Compliance with a legal obligation to which we are subject.
  • Our legitimate interests in operating, securing, and improving our business, where these are not overridden by your rights and interests.
  • Your consent, which you may withdraw at any time without affecting the lawfulness of processing carried out before withdrawal.

5. Disclosure of Information

We do not sell personal information. We may disclose personal information to the following categories of recipients, on a need-to-know basis and subject to appropriate confidentiality and security obligations:

  • Our employees, contractors, and authorised personnel involved in delivering services to you.
  • Service providers that support our business operations, including cloud hosting providers, email and collaboration platforms, customer relationship management systems, accounting and billing platforms, and analytics providers.
  • Professional advisers including lawyers, auditors, and insurers.
  • Government, regulatory, law enforcement, or judicial bodies where disclosure is required or authorised by law.
  • Successors in interest in connection with a merger, acquisition, restructure, or sale of all or part of our business.

6. Cross-Border Disclosure

Some of our service providers may be located, or store data, outside Australia, including in the United States, the European Union, the United Kingdom, and other jurisdictions. Before disclosing personal information to an overseas recipient, we take reasonable steps to ensure that the recipient handles the information in a manner consistent with the Australian Privacy Principles, the GDPR, or other applicable privacy laws. These steps may include contractual safeguards, standard contractual clauses, or reliance on the recipient’s certification under a recognised privacy framework.

7. Information Security

We implement appropriate technical and organisational measures designed to protect personal information against unauthorised access, loss, misuse, alteration, or disclosure. These measures are aligned with recognised standards including ISO/IEC 27001:2022 and the Australian Government Information Security Manual (ISM), and may include access controls, encryption in transit and at rest, network segregation, logging and monitoring, vulnerability management, and personnel training.

No method of transmission over the internet or electronic storage is completely secure. While we strive to protect personal information, we cannot guarantee absolute security, and any transmission is at your own risk.

8. Data Retention

We retain personal information for only as long as is necessary to fulfil the purposes for which it was collected, including to satisfy legal, accounting, regulatory, or reporting requirements. Retention periods are determined by reference to:

  • The nature and sensitivity of the information.
  • Applicable contractual obligations and statutory limitation periods.
  • The Corporations Act 2001 (Cth), taxation laws, and other applicable record-keeping requirements.
  • Our internal records management and information lifecycle policies.

When personal information is no longer required, we will take reasonable steps to securely destroy or de-identify it.

9. Your Rights

Subject to applicable law, you have the following rights in relation to your personal information:

  • Access — to request a copy of the personal information we hold about you.
  • Correction — to request that we correct information that is inaccurate, out of date, incomplete, or misleading.
  • Erasure — to request deletion of your personal information in certain circumstances.
  • Restriction — to request that we restrict the processing of your personal information.
  • Objection — to object to processing based on our legitimate interests or for direct marketing purposes.
  • Portability — to receive your personal information in a structured, commonly used, and machine-readable format.
  • Withdrawal of consent — where processing is based on consent, you may withdraw it at any time.

To exercise any of these rights, please contact us using the details in Section 12. We may need to verify your identity before responding. We will respond within the timeframes required by applicable law.

10. Direct Marketing

We may send you marketing communications about our services where you have provided your consent or where we are otherwise permitted to do so under applicable law, including the Spam Act 2003 (Cth). You may opt out of marketing communications at any time by following the unsubscribe instructions in the relevant communication or by contacting us directly. Opting out of marketing will not affect communications relating to the services we provide to you.

11. Cookies and Tracking Technologies

Our Website uses cookies and similar tracking technologies to operate, analyse, and improve our services. For details on the cookies we use and how to manage your preferences, please refer to our Cookie Policy, available at [www.example.com/cookie-policy].

12. Contact Us and Complaints

If you have any questions about this Privacy Policy, wish to exercise your rights, or wish to make a complaint about how we have handled your personal information, please contact:

Privacy Officer

[Company Name]

Email: [privacy@example.com]

Postal Address: [Street Address, Suburb, State, Postcode, Country]

We will acknowledge your complaint within a reasonable period and aim to resolve it within 30 days. If you are not satisfied with our response, you may lodge a complaint with the relevant supervisory authority:

  • Australia: Office of the Australian Information Commissioner (OAIC) — www.oaic.gov.au
  • European Union: Your local Data Protection Authority
  • United Kingdom: Information Commissioner’s Office (ICO) — www.ico.org.uk

13. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or for other operational reasons. The updated version will be posted on the Website with a revised “Last Updated” date. We encourage you to review this Privacy Policy periodically. Where changes are material, we will provide additional notice as required by applicable law.

14. Governing Law

This Privacy Policy is governed by the laws of [Queensland, Australia], without regard to conflict of law principles. Nothing in this Policy limits the operation of mandatory rights you may have under applicable privacy laws.

Scroll to Top