1. Introduction
This Privacy Policy is issued by Safetrac Pty Ltd (ACN 098 914 848) (“Safetrac”, “we”, “us”, “our”) and explains how Safetrac collects, uses, discloses, stores and otherwise manages personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
Safetrac Pty Ltd is part of the Safetrac Group, which includes Safetrac NZ Limited, Boardtrac Pty Ltd and any related entities that adopt this Policy.
This Policy applies to personal information we handle about:
- clients;
- users;
- prospective clients;
- employees;
- contractors;
- former employees and contractors;
- job applicants and candidates;
- suppliers;
- business partners;
- website visitors; and
- other individuals who interact with us.
This Policy explains:
- what personal information we collect;
- how we collect, use, disclose and protect it;
- how long we retain it;
- how you can access or correct it; and
- how you can make a privacy complaint.
Additional internal policies, notices and agreements may also apply to workplace-related information.
We may update this Policy from time to time to reflect changes to our practices, services or legal obligations. The current version, including its effective date, will be available on our website.
This Policy describes Safetrac’s general personal information handling practices. It does not create independent contractual obligations except where expressly incorporated into a written agreement. Client agreements may contain additional or more specific privacy, security or data-handling obligations that apply to the relevant services.
2. How Safetrac Works
Safetrac provides compliance training, governance and related services to organisations.
In most cases:
- your employer, organisation or an authorised administrator may provide information about you to us;
- we use that information, often on behalf of your employer or organisation, to provide user access, course delivery, reporting, support, administration and related compliance services;
- your training results, compliance records and related platform analytics may be made available to your employer, organisation or its authorised administrators;
- we may also use platform and operational information internally for security, support, reporting, analytics, benchmarking and service improvement; and
- we use trusted service providers and secure systems to operate and support our platform and services.
3. Privacy Notices and Consent
This Policy provides notice of Safetrac’s general personal information handling practices. By providing personal information to us, engaging our services, or using our platforms, you acknowledge that your personal information may be collected, used, disclosed and stored as described in this Policy.
Where consent is required by law, we will seek consent that is appropriate to the circumstances. We may also provide additional privacy notices at or before the time personal information is collected.
4. Anonymity and Pseudonymity
Where practicable, individuals may interact with us anonymously or by using a pseudonym. However, we may need to identify or verify an individual’s identity where this is required or authorised by law, or where it is impracticable to provide the requested services or respond to the request without identifying the individual.
5. What is Personal Information?
Personal information means information or an opinion about an identified individual or an individual who is reasonably identifiable.
Sensitive information is a category of personal information that is subject to additional protections under applicable privacy laws.
6. Platform and Business Information
Safetrac handles personal information in different contexts. Information held within the Safetrac platform generally includes user access details, course allocations, training records, completion records, assessment results, reporting information, audit trails, client-configured data and client-uploaded content.
Safetrac may also handle personal information through ordinary business systems, such as name, email, customer relationship management systems, support systems, meeting and recording tools, accounting systems, document management systems and internal reporting systems.
The same information may be handled in more than one context. The way information is handled may depend on the context in which it is collected, used, stored or processed, the relevant service, any applicable contract terms, and this Policy.
7. What Personal Information We Collect
Depending on your interaction with us, the personal information we collect or process may include:
- identity and contact information;
- employment or role information;
- organisation and billing information;
- platform, courseware and training information;
- compliance and governance information;
- meeting, governance and approval information;
- workforce information;
- client-uploaded content;
- integration information;
- business and support information;
- preferences, feedback and testimonials;
- technical and usage information; and
- audio and video recordings.
We may also collect or process sensitive information where it is:
- provided, uploaded, or configured by a client, authorised administrator or user; or
- incidentally captured in connection with the services.
Unless specifically requested by Safetrac or reasonably necessary for the relevant service, clients, authorised administrators and users should not upload or provide sensitive information through the platform or to Safetrac.
Clients, authorised administrators and users are responsible for ensuring they have the necessary authority, and have provided any required notices or obtained any required consents, before providing personal information to Safetrac. Safetrac will also handle personal information in accordance with its own obligations under applicable privacy laws and contractual obligations.
8. How We Collect Personal Information
We may collect personal information:
- directly from individuals;
- from client organisations, employers, authorised administrators or their representatives;
- through system integrations, APIs, bulk uploads, structured imports, migration files and client-authorised data transfers;
- from third-party systems, service providers, regulators, business partners, suppliers or other third parties where authorised or permitted by law;
- through our websites, platforms, support channels and services;
- through communications and business dealings;
- through marketing, sales, recruitment and workplace processes; and
- through technology, security and operational systems.
Where practicable, we collect information directly from the individual concerned.
Unsolicited Personal Information
If we receive personal information that we did not solicit and determine that we could not otherwise lawfully collect it, we will take reasonable steps to securely destroy or de-identify the information, where appropriate, unless we are required or authorised by law to retain it.
We may also notify the sender not to provide unsolicited personal information in future.
9. Client-Provided Workforce Information
Client organisations may provide personal information about employees, contractors, officers or other personnel for purposes including:
- platform access;
- system integration;
- training administration;
- compliance reporting; and
- governance tracking.
In many cases, Safetrac handles personal information on behalf of client organisations in connection with the services they configure or administer.
Safetrac processes this information to provide, operate, support, secure and improve the relevant services and related business functions.
Safetrac does not independently determine the purposes for which workforce data is initially collected by clients.
Where a client provides, uploads, configures, imports or directs Safetrac to process personal information, the client is responsible for ensuring that it has the necessary authority to do so.
10. Bulk Workforce Data Transfers
From time to time, clients may provide bulk workforce datasets to facilitate:
- system integrations;
- migrations;
- onboarding and training allocation;
- reporting updates;
- governance and compliance management reviews; and
- compliance audits, surveys, checklists, votes and attestations.
Safetrac processes such data only for the purposes agreed with the client, to deliver and support the relevant services, or as otherwise described in this Policy.
Safetrac may also generate aggregated, statistical or de-identified analytics from workforce datasets for reporting, benchmarking, operational, security and service improvement purposes.
Clients are responsible for ensuring that bulk workforce datasets are accurate, relevant and reasonably necessary for the relevant service.
Bulk workforce data uploads are protected using reasonable security measures, which may include encryption, secure transfer methods and role-based access controls where appropriate.
11. Platform Configuration and Client-Controlled Data
Clients may configure the Safetrac platform to collect and manage information through features including:
- custom fields;
- incident and risk registers;
- governance registers;
- document uploads;
- workflow processes; and
- compliance reporting tools.
Safetrac does not determine what personal information clients collect through the platform.
Clients are responsible for ensuring their collection, use and disclosure of personal information complies with applicable laws.
Clients and users must not upload or transmit unlawful, misleading, defamatory, infringing or otherwise inappropriate content.
12. Hosted Documents and Sensitive Information
The Safetrac platform may store documents, records or other content uploaded by clients or users that contain personal or sensitive information.
Access to governance, compliance and other client-hosted content within the platform is generally controlled by the client and its authorised users.
Such information within the platform:
- may be encrypted where appropriate or otherwise controlled by the client;
- is protected by role-based access controls and other security measures, where appropriate; and
- is not ordinarily accessed by Safetrac personnel except where reasonably necessary to provide, secure or support the services.
Safetrac personnel only have access to platform administration and operational information reasonably necessary to provide and support the services such as:
- user access and enrolment information;
- training allocations and completion records;
- reporting information;
- audit and operational logs; and
- related platform administration, support data and technical support.
Safetrac personnel may access client-hosted content only where:
- the client or an authorised user expressly authorises or enables access;
- access is reasonably necessary for technical support, system maintenance, security monitoring, incident response or legal compliance purposes; or
- access is otherwise required by law.
Safetrac does not routinely monitor, review or access the legality, accuracy, appropriateness or necessity of client-hosted content as part of normal service operations.
Some client-hosted documents or records may be encrypted or otherwise configured so that Safetrac personnel cannot readily access or review their contents during ordinary service operations.
Clients remain responsible for:
- determining what information, including any personal or sensitive information, is uploaded to or managed through the platform;
- determining who is authorised to access, view, manage, export or delete that information;
- ensuring they have the necessary rights, notices, consents and lawful basis to upload, store, manage, disclose, retain and delete that information; and
- determining applicable retention and destruction requirements for client-hosted information.
Retention, deletion and accessibility of client-hosted information may depend on client configuration choices, available platform functionality, operational requirements, backup and archival processes, and applicable contractual arrangements.
Once information is exported, downloaded, copied or transferred outside the Safetrac platform, Safetrac may no longer control how that information is stored, secured, retained, deleted or otherwise handled.
13. Call Recording and AI-Assisted Analysis
Safetrac may record business telephone or video calls, including screen activity, for purposes including:
- quality assurance;
- training and coaching;
- compliance monitoring;
- dispute resolution;
- service improvement;
- customer support; and
- record keeping and follow-up.
Individuals will be notified at or before the commencement of recorded calls or meetings and given an opportunity to raise any concerns before substantive discussions continue. Where consent is required by law, Safetrac will seek consent that is appropriate to the circumstances.
Recorded calls or meetings may incidentally capture other individuals who are nearby, visible or audible during the session.
Recordings and screen captures may be processed by Safetrac and third-party platforms located in Australia or overseas, including Europe and the United States, for transcription, summarisation and AI-assisted analysis.
AI-assisted tools may be used to support transcription, summarisation, reporting, operational workflows, compliance activities, quality control and training purposes. Safetrac does not use AI systems as the sole basis for making legal, employment or contractual decisions.
14. Use of Personal Information
We may use personal information for purposes including:
- providing, and administering services;
- supporting clients and users;
- integrations and data transfers;
- business administration;
- security and service operations;
- reporting, analytics and service improvement;
- communications and relationship management;
- marketing and business development;
- staff and workplace matters; and
- legal and compliance purposes.
We may use aggregated, anonymised or de-identified information for analytics, testing, benchmarking, reporting and service improvement purposes.
Where personal information is used for analytics or improvement activities, we seek to limit the use to what is reasonably necessary.
15. Disclosure of Personal Information
We may disclose personal information:
- to related Safetrac entities where reasonably necessary to provide, support, administer or improve the services and the operation of the Safetrac business;
- to employers, client organisations or authorised administrators;
- to platform administrators and authorised users;
- to service providers who assist us to deliver, host, support, secure, analyse, integrate or improve services;
- to third-party systems or providers where requested, enabled or authorised by a client;
- to courts, regulators, law enforcement agencies or authorities where required or permitted by law; and
- to professional advisers, insurers and other parties where reasonably necessary to establish, exercise or defend legal claims, investigate suspected misconduct, or protect individuals, Safetrac, its clients, its systems or its services from serious threats, misuse or unlawful activity.
We seek to limit disclosures to what is reasonably necessary in the circumstances.
16. Overseas Handling and Disclosure
Some service providers may store or process personal information overseas, including in:
- New Zealand;
- the United States;
- Europe; and
- other jurisdictions where providers operate.
Where personal information is disclosed overseas, we take reasonable steps to ensure recipients handle personal information consistently with applicable privacy obligations. These steps may include privacy and security due diligence, contractual safeguards, access controls and ongoing supplier review.
17. Information Quality, Security and Breach Response
We take reasonable steps, having regard to the nature and sensitivity of the information and the relevant risks, to protect personal information we hold from misuse, interference, loss and unauthorised access, modification or disclosure.
We also take reasonable steps to ensure personal information we collect, use or disclose is accurate, up-to-date, complete and relevant, having regard to the purposes for which it is used or disclosed.
Security controls may include:
- encryption in transit and at rest;
- identity and access management controls;
- secure cloud hosting and network security controls;
- logging, monitoring and audit trails;
- vulnerability, patch and change management processes;
- backup, disaster recovery and business continuity controls;
- supplier and service provider security controls;
- confidentiality obligations and personnel security controls; and
- incident detection, response and breach management processes.
If we become aware of an actual or suspected data breach, we will manage the incident in accordance with our incident response and breach management processes.
Where required by law, we will notify affected individuals and the Office of the Australian Information Commissioner in accordance with the Notifiable Data Breaches scheme. We may also notify relevant clients, regulators and other parties where required by law or contract.
18. Retention and Deletion of Information
Safetrac retains personal information for as long as reasonably necessary to:
- provide services;
- maintain training, compliance, governance and audit records;
- administer contracts, billing and operational requirements;
- comply with legal and regulatory obligations; and
- establish, exercise or defend legal claims.
Retention periods are determined having regard to legal, regulatory, contractual, security and operational requirements.
When personal information is no longer reasonably required or permitted by applicable law, we take reasonable steps to destroy or de-identify it. Depending on the circumstances, information may first be securely archived or access-restricted for an applicable legal, contractual, audit, security or operational retention period.
Some information may continue to exist within backup systems, archival media, disaster recovery environments, system logs or historical records for a period after deletion from active systems.
Due to the nature of backup, archival and disaster recovery processes, it may not be technically practicable or reasonable to immediately delete or remove information from all systems, backups or records.
Safetrac may retain information for longer where reasonably necessary for legal, audit, evidentiary, security, dispute-management or business continuity purposes.
Clients are responsible for managing documents and content uploaded to the platform in accordance with their own retention obligations and available platform functionality.
19. Marketing Communications
We may use personal information for marketing, sales, event and business development communications where permitted by law.
Electronic marketing communications will provide a simple means of unsubscribing where required. You may opt out of marketing communications at any time by using the unsubscribe function or contacting us. We will action opt-out requests within a reasonable period and without charge.
Where reasonably necessary, we may continue to send service, security, administrative or transactional communications that are not marketing communications.
20. Cookies and Website Technologies
We use cookies, analytics tools and similar technologies to improve functionality, maintain security, analyse usage and support our websites and services.
These technologies may collect information such as IP address, device and browser information, pages viewed, referral source, session information and interaction data.
Users may adjust browser settings to manage cookies, although some functionality may not operate correctly if cookies are disabled.
Our websites or communications may contain links to third-party websites or services. We are not responsible for the privacy practices of third parties.
21. Access and Correction
You may request access to, or correction of, personal information Safetrac holds by contacting [email protected].
We may need to verify your identity, request further information or consult with the relevant client organisation before responding. Where information is held by Safetrac solely on behalf of a client, we may refer the request to, or coordinate the response with, that client.
We aim to respond within 30 days or within the period required by applicable law.
In some circumstances, we may refuse access or correction where permitted or required by law. If we do so, we will provide written reasons and information about available complaint mechanisms, unless it would be unreasonable or unlawful to provide those reasons.
We will not charge for making an access or correction request. Where permitted by law, we may charge a reasonable amount for providing access and will advise the individual before incurring the cost.
22. Complaints
If you have a question or complaint about how we have handled your personal information, please contact our Privacy Officer at [email protected].
Please provide sufficient information for us to investigate your complaint, including relevant circumstances and the outcome you are seeking.
We may need to verify your identity or consult with the relevant client organisation or service provider.
We will acknowledge and investigate the complaint and aim to provide a response within a reasonable time.
If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner at www.oaic.gov.au.
Contact Safetrac New Zealand
Safetrac NZ Limited is located at:
Shed 22 Level 1, Prince’s Wharf
147 Quay Street
Auckland NZ
Updates to this Policy
This Policy will be reviewed from time to time to take account of new laws and technology, changes to our operations and practices and the changing business environment. The most current version of this Policy is located at www.safetrac.com.au/privacy-policy/ and can also be obtained by contacting our Privacy Officer at [email protected].
