This Privacy Policy (Section I to XV and XVII) applies to Personal Information collected by us. We are bound by the Australian Privacy Principles and the Privacy Act 1988 (Cth), which governs the way private sector organisations collect, use, keep secure and disclose Personal Information.
The Privacy Act 1988 (Cth) defines “Personal Information” to mean any information or an opinion about an identified individual, or an individual who is reasonably identifiable:
If you are a resident of the European Union, we are required to comply with the GDPR (as defined in Section XVI) in relation to your Personal Data.
Sections I and XVI of this Privacy Policy apply primarily to Personal Data collected by us. We are bound by the GDPR (defined in Section XVI below), which governs the way that we, as a controller of Personal Data, must process that Personal Data. If you are a resident of the European Union, please have reference primarily to Section XVI to understand how we process your Personal Data and your rights as a Data Subject (as defined in Section XVI).
The purpose of the Privacy Policy is generally to inform people of:
If you have any questions or comments about this policy please email our privacy officer at info@hindsiteind.com (or if you are a European Union resident, please refer to the details at Section XVI below) and we will attend to your query promptly.
We will only use or disclose your Personal Information or Personal Data (as applicable) for the primary purpose for which it was collected or as consented to by you.
At or around the time we collect Personal Information or Personal Data (as applicable) from you, we will endeavour to provide you with a notice which details how we will use and disclose that specific information.
We set out some common collection, use and disclosure instances below.
Type of Information
Contact information such as your name, company name, address, billing address, email address, phone numbers, username and password.
Transaction sales such as credit card information and billing contacts.
Uses
The types of uses we will make of Personal Information or Personal Data (as applicable) collected for this type of purpose include:
Disclosures
The types of disclosures we will make of Personal Information or Personal Data (as applicable) collected for this type of purpose include, without limitation, to:
Type of Information
Contact and identifying information, such as:
Uses
For full details relating to uses of Personal Information or Personal Data (as applicable) in relation to the use of credit information, please refer to our Credit Reporting Policy.
The types of uses we will make of information collected in connection with purchase of our services for this purpose include:
Disclosures
For full details relating to disclosures of Personal Information or Personal Data (as applicable) in relation to any credit information, please refer to our Credit Reporting Policy.
In summary, we may disclose this type of Personal Information or Personal Data (as applicable) to:
Type of Information
Contact information such as your name, company name, address, billing address, email address, phone numbers, username and password.
Website enquiries, such as your name, email address, phone number and any information you provide to us as part of your message.
Information in connection with our social media pages, including “likes”, comments posted, any of your oppositions or feedback, photos posted or uploaded and other information pertaining to your social media activities which concern, or relate, to us.
Uses
We may use your Personal Information or Personal Data (as applicable) to:
We may also use your Personal Information or Personal Data (as applicable) if you create an online account with us or participate in our social media platforms (such as, Facebook, Twitter and LinkedIn) and you provide us with your Personal Information or Personal Data (as applicable), we will use it for:
We may also use your Personal Information or Personal Data (as applicable) if you create an online account with us or participate in our social media platforms (such as, Facebook, Twitter and LinkedIn) and you provide us with your Personal Information or Personal Data (as applicable), we will use it for:
Disclosures
We may disclose your Personal Information or Personal Data (as applicable) to third parties connected with the marketing process who assist us in providing our products and services to you.
Type of Information
Contact information such as name, email address, current postal and residential address, phone numbers, country of residence, next of kin, emergency contact details.
Employee record information.
Identifying information such as your photos, passport and residency details, date of birth.
CV resume or application related information, such as the details provided in your resume or CV, your eligibility to work in Australia, your education, previous employment details.
Tax, superannuation and payroll information.
Background check information from third parties.
Medical or health information that you voluntarily provide to us as part of your pre-employment screening.
Performance related information.
Information collected from referees (as nominated by you).
Security information, such as CCTV footage and photographs taken on our premises.
Uses
Background checks are collected for the purpose of assessing the candidate for suitability for the role.
Utilising the information collection for administrative and performance monitoring use.
Disclosures
We may disclose your Personal Information or Personal Data (as applicable) to:
As much as possible or unless provided otherwise in this Privacy Policy or a notification, we will collect your Personal Information or Personal Data (as applicable) directly from you
We may collect Personal Information or Personal Data (as applicable):
We may also collect Personal Information or Personal Data (as applicable) about you from other sources. For instance, when we collect information about you from third parties or from publicly available sources (e.g. court judgments, bankruptcy searches, Australia Post or social media platforms).
If we collect information about you from someone else, we will, wherever reasonably possible, make you aware that we have done this and why, unless this information is collected from any personal referee, from a publicly available source or as otherwise required by law.
Where we inadvertently collect Personal Information or Personal Data (as applicable) from you, or a third party in circumstances where we have not requested that Personal Information or Personal Data (as applicable) and we consider that it is not required, we will destroy or de-identify that information.
We take security of your Personal Information or Personal Data (as applicable) seriously, and will hold it securely and store it on infrastructure owned or controlled by us or with a third party service provider who has taken reasonable steps to assist us in complying with the Privacy Act 1988 (Cth).
If you use our website, we may utilise “cookies” which enable us to monitor traffic patterns, trends and to serve you more efficiently if you revisit our website. We may also gather your IP address as part of our business activities and to assist with operational difficulties or support issues with our services. This information does not identify you personally, but may identify your internet service provider. This information combined with other sources of Personal Information or Personal Data (as applicable) may enable us to identify you. If you do not wish for this to occur, you can set your browser to notify you of this and you may then accept or reject it.
We provided a detail list in Section II of some common uses of your Personal Information or Personal Data (as applicable). Your Personal Information or Personal Data (as applicable) may be used to:
We provided a detail list in Section II of some common disclosures of your Personal Information or Personal Data (as applicable).
In providing our products and services, or collecting and using your Personal Information or Personal Data (as applicable), we will always keep your data private to the maximum extent commercially and practically possible. In the normal course of business and in order to provide your service we may be required to disclose some of your Personal Information or Personal Data (as applicable) to organisations outside HindSite. Such organisations may include:
We may also use and disclose your Personal Information or Personal Data (as applicable) and in doing so, we are not required to seek your further consent:
If we propose to or do disclose (or use) your Personal Information or Personal Data (as applicable) other than outlined in Sections II, IV or V then we must first notify you or seek your consent.
We may also collect sensitive information from you. Sensitive information is a subset of Personal Information or Personal Data (as applicable). It includes information or opinion about an individual’s racial or ethnic origin, political opinions, membership of a political organisation, religious beliefs or affiliations, philosophical beliefs, membership of a professional or trade association, membership of a trade union, sexual orientation or practices, criminal record, health information about an individual, genetic information, biometric information that is to be used for the purposes of automated biometric verification or biometric identification or biometric templates.
In general, we attempt to limit the amount of sensitive information collected from you, but inherent in the use of our product is the likelihood that we will collect sensitive information from you, and you will collect that from your employees.
We do not and will not use sensitive information to send you direct marketing communications without your express consent.
We may collect sensitive information from you, or you from your employees where you (or you employee, as the case may be) has consented and agreed to the collection of such information. We will endeavour to obtain this consent at or around the point in time in which we collect sensitive information.
You give your express and informed consent to us using your Personal Information or Personal Data (as applicable) in relation to direct marketing and sales as set out in this document.
Without limitation, if you have provided your inferred or implied consent (e.g. not opting out where an opt-out opportunity has been provided to you) or if it is within your reasonable expectation that we send you direct marketing material, then we may also use your Personal Information or Personal Data (as applicable) to send you direct marketing material.
We will provide you with the ability to opt-out from receiving any communications from us that you no longer wish to receive.
The Privacy Act 1988 (Cth) contains provisions regarding the use and disclosure of credit information, which applies in relation to the provision of both consumer credit and commercial credit. Please refer to our Credit Reporting Policy for more details.
As we provide terms of payments of accounts which are greater than 7 days, we are considered a credit provider under the Privacy Act. We use your credit information or the purposes outlined in Section II of this policy.
We will store any credit information you provide to us or we obtain about you with any other Personal Information or Personal Data (as applicable) we hold about you.
You may request access to your credit information in accordance with Section XIII, or make a complaint in accordance with Section XV.
To the extent practicable and reasonable, we will endeavour to provide you with the option of dealing with us on an anonymous basis or through the use of a pseudonym. However, there may be circumstances in which it is no longer practicable for us to correspond with you in this manner and your Personal Information or Personal Data (as applicable) may be required in order to provide you with our products and services or to resolve any issue you may have.
Any Personal Information or Personal Data (as applicable) collected and held by us may be disclosed to, and held at, a destination outside Australia, including but not limited to Brazil and Italy where we use third party service providers to assist us in providing HindSite’s platform and other services to you or overseas IT services (including software, platforms and infrastructure).
Personal Information or Personal Data (as applicable) may also be processed by staff or by other third parties operating outside Australia who work for us or for one of our suppliers, agents, partners or related companies.
Disclosure may occur in countries other than those listed above, and we use service providers and platforms that can be accessed from various countries.
By submitting your Personal Information or Personal Data (as applicable) to HindSite, you expressly agree and consent to the disclosure, transfer, storing or processing of your Personal Information or Personal Data (as applicable) outside of Australia. In providing this consent, you understand and acknowledge that countries outside Australia do not always have the same privacy protection obligations as Australia in relation to Personal Information or Personal Data (as applicable). However, we will take appropriate steps to ensure that your Personal Information or Personal Data (as applicable) is used by third parties securely and in accordance with the terms of this Privacy Policy.
If you do not agree to disclosure of your Personal Information or Personal Data (as applicable) outside Australia by us, you should (after being informed of the cross border disclosure) tell us that you do not consent. To do this, either elect not to submit the Personal Information or Personal Data (as applicable) to us after being reasonably informed in a collection notification or by this Policy, contact us via the details set out at the top of this document.
We take reasonable precautions to make sure that the Personal Information or Personal Data (as applicable) we hold is accurate and up-to-date. To ensure this, we recommend that you notify us of errors, omissions or changes in your Personal Information or Personal Data (as applicable). This is especially important for information required for us to communicate with you, such as a change in name, email, phone number or address.
HindSite takes reasonable steps to ensure that your Personal Information or Personal Data (as applicable) is protected from misuse, loss, unauthorised access, modification or disclosure. Some notable measures to ensure the security of your Personal Information or Personal Data (as applicable) include:
You will appreciate, however, that we cannot guarantee the security of all transmissions or Personal Information or Personal Data (as applicable), especially where human error is involved or malicious activity by a third party.
The security of this information is also dependent on your own measures to protect your email addresses and passwords from disclosure and unauthorised use.
You have the right to access any of your Personal Information or Personal Data (as applicable) that we hold, with some exceptions as allowed by law. To obtain a copy of this information, contact us and we will provide it to you. HindSite reserves the right to charge a reasonable fee for the provision of this information.
If you would like to correct any records of Personal Information or Personal Data (as applicable) we have about you, you are able to access and update that information (subject to the above exceptions) by contacting us via the details set out at the top of this Policy.
If you wish to get access to or to rectify any of your Personal Data as a resident of the European Union, please refer Section XVI below.
By continuing to use our products or services or website you consent to HindSite maintaining, using and disclosing your Personal Information or Personal Data (as applicable) as described in this document for a period of no less than seven years from the date of your last use of the system (or the date of the last use of the system by any user under your subscription, whichever is the latest).
We have put in place an effective mechanism and procedure to resolve privacy complaints. We will ensure that all complaints are dealt with in a reasonably appropriate timeframe so that any decision (if required) is made expeditiously and in a manner that does not compromise the integrity or quality of any such decision.
If you wish to make a complaint, please contact us at the details listed above (if your complaint relates to Personal Information collected from an Australian resident) or the details listed below (if your complaint related to Personal Data collected from a European resident).
In order to resolve a complaint, we:
We will maintain a register of all complaints, and any action taken.
In providing our products and services, or collecting and using your Personal Data, we are required to comply with the GDPR where you are a European Union resident.
The following defined terms have the associated meanings:
If you are a resident of the European Union for the purposes of the GDPR, then in addition to what is set out in Sections I to XV above, the following applies to you.
HindSite is a data processor for the purposes of the GDPR in the performance of services under our Services Agreement with you. HindSite is a data controller only in terms of the Personal Data of HindSite’s EU resident employees.
In general, HindSite processes the Personal Data under our services agreements with our customers, who in most cases are employers of Data Subjects.
In addition to your rights of access and correction as set out above, as a Data Subject you may:
If you wish to exercise any of your Data Subject rights, then please send your request in writing through your employer.
If we hold your Personal Data separate to your relationship as an employee of our customer, please submit your written request to the contact details set out below:
We will process your request promptly and in any event, within one month of receipt of receiving it.
If you have any concerns in relation to HindSite’s collection or processing of your Personal Data, then you also have a right to complain to a supervisory authority (within the meaning of the GDPR).
This Privacy Policy is a compliance document prescribed by law rather than a legal contract between two or more persons. However, certain contracts may incorporate all of part of this Privacy Policy.
By using our website, purchasing a product or service from us, where you have been provided with a copy of our Privacy Policy or had a copy of our Privacy Policy reasonably available to you, you are acknowledging and agreeing to provide the consents given by you in this Privacy Policy and you have been informed of all of the matters in this Privacy Policy.
We reserve the right to modify our Privacy Policy as our business needs require. We will take reasonable steps to notify you of such changes (whether by direct communication or by posting a notice on our website). If you do not agree to our continued use of your Personal Information or Personal Data (as applicable) due to the changes in our Privacy Policy, please stop providing us with your Personal Information or Personal Data (as applicable) and contact us via the details set out at the top of this Policy (if you are an Australian resident from whom we have collected Personal Information) or in Section XVI (if you are a resident of the European Union from whom we have collected Personal Data).