This policy relates to CAAAS Audit Services’ collection and handling of personal information that is covered by the Privacy Act. It is not intended to cover categories of personal information that are not covered by the Privacy Act.
Collection of Personal Information
CAAAS Audit Services collects and holds personal information from clients, customers, employees, contractors and other individuals. We collect and hold this information when it is necessary for business purposes.
The main types of personal information CAAAS Audit Services collects and holds relate to the contact details and organisational roles of our clients, suppliers and other business contacts. Typically, this information includes names, addresses, telephone numbers, e-mail addresses and job titles. In the course of providing professional services to our clients, we may collect and hold more detailed personal information (for instance financial details if we are engaged to perform financial services or credit information).
We collect most information from the businesses, through their staff, when we deal with them. The personal information we collect is primarily so that we can undertake and complete the services we provide although this information may be from forms filled out by individuals, face to face meetings, email messages, telephone conversations or by third parties. If you contact us, we may keep a record of that contact.
Because of the nature of our business, it is generally impracticable for us to deal with individuals on an anonymous basis or through the use of a pseudonym, although sometimes this is possible (for example, when seeking staff or client feedback generally).
Use of Personal Information
The main purposes for which we collect, hold and use personal information are:
to provide our services;
to respond to an individual's request;
to maintain contact with clients;
to keep clients and other contacts informed of the services we offer and industry developments that may be of interest to them, and to notify them of service offerings and other events we are holding;
for general management and reporting purposes, such as invoicing and account management;
for recruitment purposes;
for purposes related to the employment of our personnel and providing internal services to our staff; and
other purposes related to our business.
If you choose not to provide us with personal information, we may be unable to do such things.
We may collect, hold and use personal information about individuals to market our services, including by email. However, individuals always have the opportunity to elect not to receive further marketing information from us by emailing us at email@example.com. Please allow 28 days for your request to be processed.
Alternatively, if we have contacted you by email, you may use the unsubscribe function in that email to notify us that you do not want to receive further marketing information from us by email.
If we collect, hold or use personal information in ways other than as stated in this policy, we will ensure we do so pursuant to the requirements of the Privacy Act.
Employee records are not generally subject to the Privacy Act and therefore this policy may not apply to the handling of information about employees by CAAAS Audit Services. For information about our practices relating to employee information, please contact us directly.
Disclosure of Personal Information
CAAAS Audit Services does not routinely disclose personal information to other organisations unless:
use or disclosure is permitted by this policy;
we believe it is necessary to provide you with a product or service which you have requested (or, in the case of a director, employee or contractor of CAAAS Audit Services, it is necessary for maintaining or related to your role at CAAAS Audit Services);
to protect the rights, property or personal safety of any member of the public or a customer of CAAAS Audit Services or the interests of CAAAS Audit Services;
some or all of the assets or operations of CAAAS Audit Services are or may be transferred to another party as part of the sale of some or all of CAAAS Audit Services' business;
you give your consent; or
such disclosure is otherwise required or permitted by law, regulation, rule or professional standard.
We may also share non-personal, de-identified and aggregated information for research or promotional purposes. Except as set out in this policy, we do not sell to or trade personal information with third parties.
CAAAS Audit Services uses a range of service providers to help us maximise the quality and efficiency of our services and our business operations (including internal business requirements, such as recruitment and human capital requirements). This means that individuals and organisations outside of CAAAS Audit Services will sometimes have access to personal information held by CAAAS Audit Services and may collect or use it from or on behalf of CAAAS Audit Services. This may include, but is not limited to, independent contractors and consultants, off-site security storage providers, information technology providers, and debt collecting agencies. We require our service providers to adhere to our privacy guidelines and not to keep, use or disclose personal information we provide to them for any unauthorised purposes.
Transfer of Information Outside Australia
CAAAS Audit Services does not transfer any personal information outside of Australia.
However, if such transfer of information does happen, this will not change any of our commitments to safeguard your privacy, and the information remains subject to existing confidentiality obligations.
Privacy on Our Web Site and Applications
This policy also applies to any personal information we collect via our website, including caaas.com.au, and applications including mobile applications. In addition to personal information you provide to us directly (such as where you make a request or complete a registration form), CAAAS Audit Services may also collect personal information from you via its website, applications including mobile applications.
In order to properly manage our websites and applications, we may log certain statistics about the users of the facilities, for example the users' domains and browser types. None of this information specifically identifies an individual and it is used solely to ensure that our websites and applications present the best possible navigational experience for users.
If you have registered an account with us, you will be identified by a user name and password when you log into our website or applications. The information we collect about members' use of our websites may be used for measuring use and performance and in assisting to resolve any technical difficulties.
Security of Personal Information
Depending on the purpose for which we have collected personal information (for example, request for particular information or material), we may store some of the information electronically in CAAAS Audit Services' customer relationship management system. Some or all of this personal information may be available to directors and authorised staff of CAAAS Audit Services for use in accordance with this policy.
CAAAS Audit Services will endeavour to take all reasonable steps to keep secure any information which we hold about you, whether electronically or in hard-copy, and to keep this information accurate and up to date. We also require our employees and data processors to respect the confidentiality of any personal information held by CAAAS Audit Services.
CAAAS Audit Services aims to achieve industry best practice in the security of personal information which it holds. It is our policy not to retain personal information, other than contact details, once there is no longer a legal or business need for us to do so.
Access to Information
We will provide access to personal information upon request by an individual, except in the limited circumstances in which it is permitted for us to withhold this information (for instance, where granting access would infringe another person's privacy).
When you make a request to access personal information, we will require you to provide some form of identification (such as a driver's licence or passport) so we can verify that you are the person to whom the information relates. In some cases we may also request an administrative fee to cover the cost of access.
If at any time you want to know what personal information we hold about you, you may contact us by emailing us at firstname.lastname@example.org.
Corrections and Concerns
If you believe that information we hold about you is incorrect or out of date, or if you have concerns about how we are handling your personal information, please contact us and we will try to resolve those concerns.
If you wish to have your personal information deleted, please let us know and we will take reasonable steps to delete it (unless we need to keep it for legal, auditing or internal risk management reasons).
Effect of Policy
CAAAS Audit Services operates in a dynamic business environment and we aim to review this policy annually to keep it current.
The amended policy will apply between us whether or not we have given you specific notice of any change.
This policy was last updated January 2019.