Safetrac Pty Ltd is part of the Safetrac Group, which includes Safetrac NZ Limited, Boardtrac Pty Ltd and any related entities that adopt this Policy.
This Policy applies to personal information we handle about:
This Policy explains:
Additional internal policies, notices and agreements may also apply to workplace-related information.
We may update this Policy from time to time to reflect changes to our practices, services or legal obligations. The current version, including its effective date, will be available on our website.
This Policy describes Safetrac’s general personal information handling practices. It does not create independent contractual obligations except where expressly incorporated into a written agreement. Client agreements may contain additional or more specific privacy, security or data-handling obligations that apply to the relevant services.
This Privacy Policy is issued by Safetrac Pty Ltd (ACN 098 914 848) (“Safetrac”, “we”, “us”, “our”) and explains how Safetrac collects, uses, discloses, stores and otherwise manages personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
Safetrac Pty Ltd is part of the Safetrac Group, which includes Safetrac NZ Limited, Boardtrac Pty Ltd and any related entities that adopt this Policy.
This Policy applies to personal information we handle about:
This Policy explains:
Additional internal policies, notices and agreements may also apply to workplace-related information.
We may update this Policy from time to time to reflect changes to our practices, services or legal obligations. The current version, including its effective date, will be available on our website.
This Policy describes Safetrac’s general personal information handling practices. It does not create independent contractual obligations except where expressly incorporated into a written agreement. Client agreements may contain additional or more specific privacy, security or data-handling obligations that apply to the relevant services.
Safetrac provides compliance training, governance and related services to organisations.
In most cases:
This Policy provides notice of Safetrac’s general personal information handling practices. By providing personal information to us, engaging our services, or using our platforms, you acknowledge that your personal information may be collected, used, disclosed and stored as described in this Policy.
Where consent is required by law, we will seek consent that is appropriate to the circumstances. We may also provide additional privacy notices at or before the time personal information is collected.
Where practicable, individuals may interact with us anonymously or by using a pseudonym. However, we may need to identify or verify an individual’s identity where this is required or authorised by law, or where it is impracticable to provide the requested services or respond to the request without identifying the individual.
Personal information means information or an opinion about an identified individual or an individual who is reasonably identifiable.
Sensitive information is a category of personal information that is subject to additional protections under applicable privacy laws.
Safetrac handles personal information in different contexts. Information held within the Safetrac platform generally includes user access details, course allocations, training records, completion records, assessment results, reporting information, audit trails, client-configured data and client-uploaded content.
Safetrac may also handle personal information through ordinary business systems, such as name, email, customer relationship management systems, support systems, meeting and recording tools, accounting systems, document management systems and internal reporting systems.
The same information may be handled in more than one context. The way information is handled may depend on the context in which it is collected, used, stored or processed, the relevant service, any applicable contract terms, and this Policy.
Depending on your interaction with us, the personal information we collect or process may include:
We may also collect or process sensitive information where it is:
Unless specifically requested by Safetrac or reasonably necessary for the relevant service, clients, authorised administrators and users should not upload or provide sensitive information through the platform or to Safetrac.
Clients, authorised administrators and users are responsible for ensuring they have the necessary authority, and have provided any required notices or obtained any required consents, before providing personal information to Safetrac. Safetrac will also handle personal information in accordance with its own obligations under applicable privacy laws and contractual obligations.
We may collect personal information:
Where practicable, we collect information directly from the individual concerned.
If we receive personal information that we did not solicit and determine that we could not otherwise lawfully collect it, we will take reasonable steps to securely destroy or de-identify the information, where appropriate, unless we are required or authorised by law to retain it.
We may also notify the sender not to provide unsolicited personal information in future.
Client organisations may provide personal information about employees, contractors, officers or other personnel for purposes including:
In many cases, Safetrac handles personal information on behalf of client organisations in connection with the services they configure or administer.
Safetrac processes this information to provide, operate, support, secure and improve the relevant services and related business functions.
Safetrac does not independently determine the purposes for which workforce data is initially collected by clients.
Where a client provides, uploads, configures, imports or directs Safetrac to process personal information, the client is responsible for ensuring that it has the necessary authority to do so.
From time to time, clients may provide bulk workforce datasets to facilitate:
Safetrac processes such data only for the purposes agreed with the client, to deliver and support the relevant services, or as otherwise described in this Policy.
Safetrac may also generate aggregated, statistical or de-identified analytics from workforce datasets for reporting, benchmarking, operational, security and service improvement purposes.
Clients are responsible for ensuring that bulk workforce datasets are accurate, relevant and reasonably necessary for the relevant service.
Bulk workforce data uploads are protected using reasonable security measures, which may include encryption, secure transfer methods and role-based access controls where appropriate.
Clients may configure the Safetrac platform to collect and manage information through features including:
Safetrac does not determine what personal information clients collect through the platform.
Clients are responsible for ensuring their collection, use and disclosure of personal information complies with applicable laws.
Clients and users must not upload or transmit unlawful, misleading, defamatory, infringing or otherwise inappropriate content.
The Safetrac platform may store documents, records or other content uploaded by clients or users that contain personal or sensitive information.
Access to governance, compliance and other client-hosted content within the platform is generally controlled by the client and its authorised users.
Such information within the platform:
Safetrac personnel only have access to platform administration and operational information reasonably necessary to provide and support the services such as:
Safetrac personnel may access client-hosted content only where:
Safetrac does not routinely monitor, review or access the legality, accuracy, appropriateness or necessity of client-hosted content as part of normal service operations.
Some client-hosted documents or records may be encrypted or otherwise configured so that Safetrac personnel cannot readily access or review their contents during ordinary service operations.
Clients remain responsible for:
Retention, deletion and accessibility of client-hosted information may depend on client configuration choices, available platform functionality, operational requirements, backup and archival processes, and applicable contractual arrangements.
Once information is exported, downloaded, copied or transferred outside the Safetrac platform, Safetrac may no longer control how that information is stored, secured, retained, deleted or otherwise handled.
Safetrac may record business telephone or video calls, including screen activity, for purposes including:
Individuals will be notified at or before the commencement of recorded calls or meetings and given an opportunity to raise any concerns before substantive discussions continue. Where consent is required by law, Safetrac will seek consent that is appropriate to the circumstances.
Recorded calls or meetings may incidentally capture other individuals who are nearby, visible or audible during the session.
Recordings and screen captures may be processed by Safetrac and third-party platforms located in Australia or overseas, including Europe and the United States, for transcription, summarisation and AI-assisted analysis.
AI-assisted tools may be used to support transcription, summarisation, reporting, operational workflows, compliance activities, quality control and training purposes. Safetrac does not use AI systems as the sole basis for making legal, employment or contractual decisions.
We may use personal information for purposes including:
We may use aggregated, anonymised or de-identified information for analytics, testing, benchmarking, reporting and service improvement purposes.
Where personal information is used for analytics or improvement activities, we seek to limit the use to what is reasonably necessary.
We may disclose personal information:
We seek to limit disclosures to what is reasonably necessary in the circumstances.
Some service providers may store or process personal information overseas, including in:
Where personal information is disclosed overseas, we take reasonable steps to ensure recipients handle personal information consistently with applicable privacy obligations. These steps may include privacy and security due diligence, contractual safeguards, access controls and ongoing supplier review.
We take reasonable steps, having regard to the nature and sensitivity of the information and the relevant risks, to protect personal information we hold from misuse, interference, loss and unauthorised access, modification or disclosure.
We also take reasonable steps to ensure personal information we collect, use or disclose is accurate, up-to-date, complete and relevant, having regard to the purposes for which it is used or disclosed.
Security controls may include:
If we become aware of an actual or suspected data breach, we will manage the incident in accordance with our incident response and breach management processes.
Where required by law, we will notify affected individuals and the Office of the Australian Information Commissioner in accordance with the Notifiable Data Breaches scheme. We may also notify relevant clients, regulators and other parties where required by law or contract.
Safetrac retains personal information for as long as reasonably necessary to:
Retention periods are determined having regard to legal, regulatory, contractual, security and operational requirements.
When personal information is no longer reasonably required or permitted by applicable law, we take reasonable steps to destroy or de-identify it. Depending on the circumstances, information may first be securely archived or access-restricted for an applicable legal, contractual, audit, security or operational retention period.
Some information may continue to exist within backup systems, archival media, disaster recovery environments, system logs or historical records for a period after deletion from active systems.
Due to the nature of backup, archival and disaster recovery processes, it may not be technically practicable or reasonable to immediately delete or remove information from all systems, backups or records.
Safetrac may retain information for longer where reasonably necessary for legal, audit, evidentiary, security, dispute-management or business continuity purposes.
Clients are responsible for managing documents and content uploaded to the platform in accordance with their own retention obligations and available platform functionality.
We may use personal information for marketing, sales, event and business development communications where permitted by law.
Electronic marketing communications will provide a simple means of unsubscribing where required. You may opt out of marketing communications at any time by using the unsubscribe function or contacting us. We will action opt-out requests within a reasonable period and without charge.
Where reasonably necessary, we may continue to send service, security, administrative or transactional communications that are not marketing communications.
We use cookies, analytics tools and similar technologies to improve functionality, maintain security, analyse usage and support our websites and services.
These technologies may collect information such as IP address, device and browser information, pages viewed, referral source, session information and interaction data.
Users may adjust browser settings to manage cookies, although some functionality may not operate correctly if cookies are disabled.
Our websites or communications may contain links to third-party websites or services. We are not responsible for the privacy practices of third parties.
You may request access to, or correction of, personal information Safetrac holds by contacting [email protected].
We may need to verify your identity, request further information or consult with the relevant client organisation before responding. Where information is held by Safetrac solely on behalf of a client, we may refer the request to, or coordinate the response with, that client.
We aim to respond within 30 days or within the period required by applicable law.
In some circumstances, we may refuse access or correction where permitted or required by law. If we do so, we will provide written reasons and information about available complaint mechanisms, unless it would be unreasonable or unlawful to provide those reasons.
We will not charge for making an access or correction request. Where permitted by law, we may charge a reasonable amount for providing access and will advise the individual before incurring the cost.
If you have a question or complaint about how we have handled your personal information, please contact our Privacy Officer at [email protected].
Please provide sufficient information for us to investigate your complaint, including relevant circumstances and the outcome you are seeking.
We may need to verify your identity or consult with the relevant client organisation or service provider.
We will acknowledge and investigate the complaint and aim to provide a response within a reasonable time.
If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner at www.oaic.gov.au.
This Policy will be reviewed from time to time to take account of new laws and technology, changes to our operations and practices and the changing business environment. The most current version of this Policy is located at www.safetrac.com.au/privacy-policy/ and can also be obtained by contacting our Privacy Officer at [email protected].
Access is limited to some Safetrac platforms. We are actively working to restore access. For more information go to: Safetrac Platform Access