Third Party Index

Snapshot 77720

Document
Privacy policy
URL
https://altus.digital/privacy
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
static
Size
34972 bytes
SHA-256 (raw)
f2f7f179983c68f07d88be600f5f745821ce5486fcb42819144b1477ac415e0b
SHA-256 (normalized text)
5610131e5136d4d0f5970222258785caa753ab6562cf8598bb112cfd25d37ba7

Normalized text

Scripts and page chrome removed; this is what change detection compares.

1. About this policy
Altus Digital Pty Ltd (Altus Digital, we, us, our) is an Australian consultancy specialising in Salesforce and marketing technology. Protecting personal information is central to how we work, because most of our engagements involve systems that hold our clients’ customer data.
We act consistently with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. Altus Digital may fall below the annual turnover threshold at which the Privacy Act applies automatically, but we do not rely on that exemption. We conduct ourselves as though we are bound by the Australian Privacy Principles, and in our client engagements we accept that obligation contractually.
This policy explains what personal information we collect, why we collect it, who we share it with, where it is stored, how long we keep it, how we protect it, and how you can access it, correct it or complain. Section 4 deals separately with personal information we handle on behalf of our clients, because different rules apply to that information.
Where we provide services to a client established in the United Kingdom or the European Economic Area, the UK GDPR or the EU GDPR may also apply to that engagement. Where it does, we comply with it in addition to this policy.
2. Personal information we collect for our own business
“Personal information” means information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether or not it is true and whether or not it is recorded in a material form.
We collect only what we reasonably need for our business functions and activities, which primarily consist of providing consultancy services. The categories we collect are:
Contact information. Your name, email address, telephone number and the organisation you work for, so we can communicate with you and provide our services. We generally collect this directly from you.
Engagement information. If you are an employee, contractor or representative of one of our clients, we may collect your name, job title, business unit and business contact details in the course of delivering services to your employer.
Information from third parties and public sources. Where you have permitted a third party to share your information with us, or where you have made the information publicly available, for example on a professional networking profile.
Website and device information. When you visit our website we may collect your IP address, information about your device and browser, and the pages you view.
We do not collect sensitive information as defined in the Privacy Act, including health information, biometric information, or information about racial or ethnic origin, political opinions, religious beliefs, sexual orientation or criminal record, and we ask that you do not send it to us.
Where it is reasonably practicable, we will tell you at the point of collection why we are collecting your information and who we may disclose it to.
3. Why we collect, use and disclose personal information
We use personal information to:
offer and provide our services to existing and prospective clients;
respond to your enquiries and provide information you have asked for;
communicate with you, including issuing invoices and, where you have not opted out, sending updates about our services;
seek feedback and improve our services and website;
meet our legal, regulatory and contractual obligations; and
manage and administer our business, including payments, IT, insurance and professional advice.
We may disclose personal information to our personnel and approved associates who need it to perform their role, to our professional advisers, insurers and auditors, and to the operators of the systems we use to run our business, which are listed in section 11. We require anyone we disclose personal information to for these purposes to protect it to a standard no lower than our own, and to use it only for the purpose we provided it.
We do not sell personal information, we do not disclose it to third parties for their own marketing, and we do not use it to train artificial intelligence or machine learning models.
If our business is sold or merged, personal information may be disclosed to the acquirer as part of that transaction. We would require the acquirer to continue handling it in accordance with this policy.
4. Personal information we handle for our clients
Most of the personal information Altus Digital comes into contact with does not belong to us. It belongs to our clients, and it relates to their customers and employees. We handle it only as a service provider, on the client’s instructions and for the client’s purposes.
The following controls apply to every engagement:
We hold as little as possible. We do not request, collect or retain client personal information where the work can be performed using aggregated or de-identified information, and on most advisory engagements it can.
We work inside the client’s environment. Where an engagement requires access to client personal information, that access is exercised inside the client’s own systems, under named accounts the client provisions and controls, at the minimum privilege the task requires, with multi-factor authentication, and in non-production environments wherever the task allows.
We do not export customer records. We do not extract, export or copy subscriber, contact or customer records out of a client environment unless the client directs us to in writing. Analysis is performed in place, or on extracts the client has de-identified.
We do not use client information for our own purposes. We do not use it to market to anyone, we do not use it to benchmark other clients, and we do not enter it into any artificial intelligence tool that could use it for model training.
We do not add subprocessors without approval. Where a client engagement requires a new system, subcontractor or tool that would hold or process the client’s information, we identify it and seek the client’s written approval before it is used.
We surrender access promptly. Access to client systems is revoked within one business day of an engagement completing, or of a person ceasing to work on it, and we confirm that in writing.
Our client remains the entity responsible for deciding how that personal information is collected and used, for the notices and consents given to the individuals concerned, and for any notification to a regulator or to affected individuals. If you are a customer or employee of one of our clients and you want to access, correct or complain about your personal information, please contact that organisation directly. If you contact us instead, we will refer your request to them promptly and tell you that we have done so.
5. How we collect personal information
We collect personal information directly from you wherever it is reasonable and practicable to do so: when you submit our website enquiry form, when you contact us by telephone or email, when you meet with us, and in the course of delivering an engagement.
We collect it lawfully and fairly, and not in an unreasonably intrusive way.
Unsolicited information
If we receive personal information we did not ask for, and we determine that we could not lawfully have collected it had we asked, we will destroy or de-identify it if it is lawful and reasonable to do so. Otherwise we will handle it in accordance with this policy.
Dealing with us anonymously
You may deal with us anonymously or under a pseudonym where it is lawful and practicable. In most client engagements this is not practicable, because we need to know who we are working with. If you choose not to provide information we have asked for, we may not be able to provide the service or the response you have requested.
6. How we protect personal information
We hold personal information electronically, and occasionally in paper form. We maintain security measures appropriate to the sensitivity of the information and the harm that would result from its loss or misuse, including:
full-disk encryption, screen lock, current patching and endpoint protection on every device used for client work;
multi-factor authentication on all accounts used in connection with our business and our client engagements;
access granted on a least-privilege basis under named accounts, never shared credentials, and a record kept for each engagement of who holds access, at what level, granted when and removed when;
role-based access controls on our own document storage; and
written confidentiality, security and data-handling obligations binding every member of our personnel and every approved associate.
We destroy or de-identify personal information securely once it is no longer needed for a purpose set out in this policy and we are not required by law to keep it.
No system is perfectly secure. We do not claim that our measures eliminate risk, and we hold cyber liability insurance against the possibility that they fail.
7. Data breaches
If we become aware of an actual or suspected unauthorised access to, disclosure of, or loss of personal information we hold, we will act immediately to contain it, isolate the affected account or device, rotate credentials, and assess what has happened.
Where the information is our own, we will assess within 30 days whether the incident is an eligible data breach under Part IIIC of the Privacy Act and, if it is, notify the Office of the Australian Information Commissioner and the affected individuals as soon as practicable.
Where the information belongs to a client, the client decides whether to notify a regulator or affected individuals, because it is their information and their relationship with those individuals. Our obligation is to tell them, quickly and completely. We will notify the client’s nominated contact without delay and within the timeframe set in the governing agreement, provide the information they need to run their own assessment, preserve relevant evidence, and cooperate fully with their containment, remediation and notification activities. We will not make any public statement about an incident affecting a client’s information without that client’s agreement, except where we are independently required to do so by law or by a regulator.
8. How long we keep personal information
We keep personal information only for as long as we need it for the purposes described in this policy, or for as long as we are required to keep it by law.
Contract, invoicing and compliance records are retained for seven years after the relevant engagement ends, consistent with our tax and record-keeping obligations.
Enquiry and marketing contact information is retained until you ask us to remove it, or until it has been inactive for two years, whichever comes first.
Client working material is returned or securely destroyed at the client’s direction on completion or termination of the engagement, or on the client’s written request at any time, and we confirm completion in writing. We may retain one copy where we are required to by law, and copies held in routine backup systems that are not readily retrievable expire on the ordinary backup cycle.
9. Direct marketing
We may send you information about our services if you are a client or have enquired about them. Every marketing email we send contains an unsubscribe link, and you can opt out at any time by using it or by contacting our Privacy Officer. We will action your request promptly and at no cost to you.
We do not send marketing on behalf of our clients to their customers, and we do not provide your contact details to anyone else for marketing purposes.
10. Cookies and our website
Our website uses cookies, which are small text files stored by your browser. We use them to understand how visitors use the site in aggregate, so we can improve it. Cookies do not tell us your name or email address. Our analytics reports may include IP addresses, which we use to count unique visitors and understand broad geographic trends, not to identify individuals.
You can refuse or delete cookies through your browser settings. Some parts of the site may not work as intended if you do.
11. Overseas disclosure and where your information is stored
Altus Digital is based in Australia, and all our personnel are in Australia. We do not use offshore subcontractors on client engagements without the client’s prior written approval.
We are, however, transparent about where our own systems store data. We use Google Workspace to run our business, including email, document storage and collaboration. Google Workspace data region options are currently limited to the United States, the European Union, or no preference. Australia is not offered. We therefore do not claim Australian data residency for information held in our Google Workspace tenancy, and personal information held there may be stored or processed in the United States or the European Union by Google and its subprocessors.
Where a client requires Australian data residency, we agree an alternative arrangement in the engagement contract, or we work exclusively within the client’s own environment so that their information never enters our tenancy. As set out in section 4, client customer records are not copied into our systems in any event.
Before we disclose personal information to an overseas recipient, we take the steps required by Australian Privacy Principle 8 to ensure the recipient does not breach the Australian Privacy Principles in relation to it. Where a client agreement requires it, we disclose the systems we use, their operators and the locations in which they store data, and we are formalising that disclosure into a standing subprocessor register.
12. Accessing and correcting your personal information
You may ask our Privacy Officer at any time for access to the personal information we hold about you, or to correct it if it is inaccurate, out of date, incomplete, irrelevant or misleading.
We will respond within a reasonable time and normally within 30 days. We do not charge for making a request, though we may charge a reasonable cost for providing access in a particular format. We will verify your identity before releasing information.
If we refuse access or refuse to make a correction, we will tell you in writing why, unless it would be unreasonable to do so, and explain how you can complain about that decision.
13. Complaints
If you think we have breached the Australian Privacy Principles or mishandled your personal information, please tell our Privacy Officer using the details in section 15. Please describe what happened and what you would like us to do.
We will acknowledge your complaint within five business days, investigate it, and give you a written response within 30 days. If we need longer, we will tell you why and agree a new timeframe with you.
If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner at oaic.gov.au, by telephone on 1300 363 992, or by writing to GPO Box 5218, Sydney NSW 2001.
14. Changes to this policy
We review this policy at least annually, and whenever privacy legislation changes materially or our systems or delivery model change in a way that affects how we handle personal information. Each version carries its own effective date, and the current version is published at altus.digital/privacy.
Where a change materially affects how we handle personal information we already hold, we will take reasonable steps to tell affected individuals rather than relying on the published update alone.
15. Contact us
Our Privacy Officer is the Director of Altus Digital Pty Ltd.
Email
[email protected]
Entity
Altus Digital Pty Ltd, ABN 94 638 335 716