At RMGC Consulting Pty Ltd (ABN 74 609 884 899) your privacy is very important to us.
This Privacy Policy details how we protect your privacy and how we comply with the requirements of the Privacy Act 1998 (Cth) and the 13 National Privacy Principles (NPP). This policy also describes:
- the types of personal information collected and held by us;
- how this information is collected and held;
- the purposes for which your personal information is collected, held, used and disclosed;
- how you can gain access to your personal information and seek its correction; and
- how you may complain or inquire about our collection, handling, use or disclosure of your personal information and how that complaint or inquiry will be handled.
We believe that this policy will address any potential concerns you may have about how personal information you provide to RMGC Consulting Pty Ltd is collected, held, used, corrected, disclosed and transferred. If you require more information, please contact us.
Collection
We will not collect any personal information about you except when you have knowingly provided that information to us or authorised a third party to provide that information to us.
Generally, collection of your personal information will be by way of either face-to-face meetings, email, phone or electronic (or hard copy) forms. From time to time additional and/or updated personal information may be collected through one or more of those methods.
Unsolicited personal information
We don’t usually collect unsolicited personal information. Where we receive unsolicited personal information, we’ll determine whether or not it would have been permissible to collect that personal information if it had been solicited. If we determine that collection would not have been permissible, to the extent permitted by law, we’ll destroy or de-identify that personal information as soon as practicable.
Use & Disclosure
We only use personal information that is reasonably necessary to deliver one or more of our risk management, governance and compliance consulting services (the primary purpose) or for a related secondary purpose that would be reasonably expected by you, or to which you have consented.
We will not use or disclose personal information collected by us for any purpose other than:
- the purposes for which it was provided or secondary related purposes in circumstances where you would reasonably expect such use of disclosure; or
- where you have consented to such disclosure; or
- where the NPP authorise use or disclosure where required;
- or when authorised under law and in connection with certain operations by or on behalf of an enforcement body.
We may use the personal information collected from you for the purpose of providing you with direct marketing material such as articles that may be of interest to you. If you do not want to receive such information you can let us know us by phone, post or email, and we will action your request with 48 hours.
Our website may contain links to other websites. We do not share your personal information with those websites and we are not responsible for their privacy practices.
Your personal information may be provided to one of our agents or authorised representatives/contractors so they can adequately deliver the services you require of RMGC Consulting. Our Representatives/agents and contractors must adopt and adhere to this privacy policy by way of contractual obligations.
We may disclose your personal information to potential purchasers for the purpose of them conducting due diligence investigations – in the event that we sell RMGC Consulting. Any such disclosure will be made in confidence and it will be a condition of that disclosure that no personal information will be used or disclosed by them. In the event that a sale of our business is affected, we may transfer your personal information to the purchaser of the business. We will let you know if we transfer your personal information.
Storage and security of your personal information
We store personal information in a variety of formats including on databases, in hard copy files, and on personal devices, including laptop computers.
We take all reasonable steps to protect the personal information we hold about you from misuse, loss, unauthorised access, modification or disclosure.
These steps include:
- Password restricted access to databases and other personal information stored electronically;
- Ensuring all staff, representatives/agents and contractors are aware of the protocols for handling personal information including that they are not to reveal or share personal passwords;
- Ensuring any hard copy files are stored in lockable filing cabinets. ;
- Implementing physical security measures at our premises to prevent break-ins; and
- Implementing IT security systems designed to protect personal information stored digitally.
In the event you cease to be a client of RMGC Consulting, any personal information that we hold about you will be stored electronically and held on our server for a period of 7 years in order to comply with legislative and personal requirements, following which time the information will be deleted.
Your privacy on the Internet
Our Website
We take care to ensure that the personal information you give us on our website is protected. For example, our website may have electronic security systems in place, including the use of firewalls and data encryption. User identifiers, passwords or other access codes may also be used to control access to your personal information.
Links to Other Sites
You may be able to access external websites by clicking on links we have provided. Those other websites are not subject to our privacy standards, policies and procedures. You will need to contact or review those websites directly to ascertain their privacy standards, policies and procedures.
Cookies
We may use cookies on our website. Cookies are small data files that are downloaded from our website and stored on your computer when you visit our website. Cookies are used to allow us to see which pages and what information is of most interest to visitors to our website, which in turn enables us to improve our offerings to our customers. Your computer’s web browser will allow you to configure your computer to refuse to accept cookies. You can also delete cookies from your computer’s hard drive at any time.
Other Technology
We may use technology such beacons, tags, scripts and tracking pixels to collect, store and use anonymous data about how you use our website / mobile technology. This includes your server address, the date and time of your visit, the pages and links accessed, the type of browser used and other information about your browsing activities. This data is used to increase functionality and can also enable us to display information and content that is tailored to our understanding of your interests. This information alone cannot be used to discover your identity.
Access to Your Personal Information
You may at any time, contact us phone, post or email to request access to your personal information and we will (subject to the following exceptions) provide you with access to that information. We will provide personal information to you by either providing you with copies of the information requested, allowing you to inspect the information requested or providing you with an accurate summary of the information held. We will, (prior to providing access in accordance with this policy), require you to provide evidence of your identity.
We will not provide you with access to your personal information if:
- providing access would have an unreasonable impact on the privacy of others;
- the request for access is frivolous or vexatious;
- the information related to existing or anticipated legal proceedings between us and would not be discoverable in those proceedings;
- providing access would reveal our intentions in relation to negotiations with you in such a way as to prejudice those negotiations;
- providing access would be unlawful;
- denying access is required or authorised by or under law;
- providing access would be likely to prejudice certain operations by or on behalf of an enforcement body or an enforcement body requests that access not be provided on the grounds of national security.
We will aim to respond to any request for access within 14-30 days depending on the complexity of the information and/or the request. If your request is urgent, please let us know.
In the event we refuse you access to your personal information, we will provide you with an explanation for that refusal.
Maintaining and Updating Personal Information
Please contact us if any of the details you have provided us with change. We will aim to ensure that, at all times, the personal information that we hold about you is complete, up to date and accurate at the time of collection and when using or disclosing the personal information. On an ongoing basis, we will maintain and update personal information when we are advised by you that your personal information has changed. In the event that you become aware, or believe, that any personal information that we hold about you is inaccurate, incomplete or out of date, you should contact us.
Notifying you of certain data breaches
A data breach occurs when personal information held by us is lost or subjected to unauthorised access or disclosure. If we suspect or know of a data breach, we will take immediate steps to limit any further access or distribution of the affected personal information or the possible compromise of other information.
When we have reasonable grounds to believe that a data breach is likely to result in serious harm – for example identity theft, significant financial loss or threats to physical safety we will notify individuals at likely risk as soon as practicable and make recommendations about the steps they should take in response to the data breach. We will also notify the Office of the Australian Information Commissioner.
Notifications will be made using our usual method of communicating with you such as by a telephone call, email, SMS, physical mail, social media post, or in-person conversation. If we are unable to contact you, (or your nominated intermediary) by any of the above methods we will publish a statement on the front page of our website and place a public notice on our reception desk.
Privacy Complaints
you wish to make a complaint about a breach by us of the NPP, you may do so by providing your written complaint by email or letter to any one of our contact details noted below. You may also make a complaint verbally by phone to the Privacy Officer.
We will respond to your complaint within a reasonable time (usually no longer than 30 days). You can also take your complaint to the Office of the Australian Information Commissioner.
Contact Details
Privacy Officer: Gayle Cilfone
Address: PO Box 2218, Carlisle North WA 6101
Telephone: 0411 296017
Email: contact@rmgcconsulting.com.au
If you are not satisfied with the outcome of your complaint, you are entitled to contact the Office of the Australian Information Commissioner.
Online: www.oaic.com.au
Email: enquiries@oaic.com.au
Phone: 1300 363 992
Mail: Director of Complaints, Office of the Australian Information Commissioner GPO Box 5218, Sydney NSW 2001