Our Privacy Policy
Introduction
This Website and the Complyify business is owned and operated by
Complyify Pty Ltd
. The company is committed to providing quality products and services to you. This Privacy Policy outlines our ongoing obligations to you in respect of how we manage your Personal Information. It explains how and when we collect, use, disclose, store, and protect your Personal Information and applies to all Personal Information we collect.
Your privacy is important to us. We are committed to protecting your Personal Information in accordance with the
Australian Privacy Principles (APPs) contained in the
Privacy Act 1988 (Cth) (Privacy Act).
We have adopted the Australian Privacy Principles (APPs), which govern the way in which we collect, use, disclose, store, secure, and dispose of your Personal Information.
A copy of the Australian Privacy Principles may be obtained from the Office of the Australian Information Commissioner (OAIC) website at:
https://www.oaic.gov.au/
What is Personal Information and why do we collect it?
Personal Information is information or an opinion that identifies an individual. Examples of Personal Information we may collect include, but are not limited to, names, addresses, email addresses, phone numbers, system access credentials, usage logs, compliance documentation, and other information necessary to provide our services.
Personal Information may be collected through appointments, correspondence, surveys, online forms, telephone calls, emails, via our website www.complyify.com.au, through platform usage, from public sources, or from authorised third parties. We do not guarantee the content or privacy practices of third-party websites.
We collect Personal Information for the primary purpose of:
- providing our software, compliance, and related services;
- administering accounts and authorised users;
- meeting regulatory and scheme obligations;
- responding to enquiries and support requests; and
- internal business operations, analytics, and marketing.
We may also use Personal Information for secondary purposes that are closely related to the primary purpose, where you would reasonably expect such use.
You may opt out of marketing communications at any time by contacting us using the details at the end of this Policy.
Sensitive Information
Sensitive information is defined in the Privacy Act and includes information or opinions about an individual’s racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, criminal record, or health information.
Sensitive information will only be used:
-
for the primary purpose for which it was obtained;
-
for a directly related secondary purpose;
-
with your consent; or
-
where required or authorised by law.
Third Parties
Where reasonable and practicable, we collect Personal Information directly from you. In some circumstances, we may receive Personal Information from third parties such as authorised users, customers, compliance partners, or scheme participants. We take reasonable steps to ensure individuals are aware when this occurs.
Disclosure of Personal Information
Personal Information may be disclosed:
- to authorised users, customers, contractors, or service providers for the purpose of delivering our services;
- where you have provided consent;
- where required or authorised by law or regulatory obligation; or
- to professional advisers (such as legal, accounting, or compliance advisers).
Cloud Hosting, Data Storage & Security
Complyify operates a cloud-based software platform. Personal Information may be stored electronically using secure third-party cloud infrastructure providers.
We take reasonable steps to ensure that all Personal Information is protected from misuse, loss, unauthorised access, modification, or disclosure. These steps include administrative, technical, and physical safeguards appropriate to the nature of the information.
Access to Personal Information is restricted to authorised personnel and users who require access to perform their duties or use the platform in accordance with their permissions.
Overseas Data Storage and Transfers
& Security
Some of our service providers or cloud infrastructure may store or process data outside Australia. Where this occurs, we take reasonable steps to ensure that overseas recipients handle Personal Information in a manner consistent with the Australian Privacy Principles or applicable privacy laws.
Access by Authorised Users, Contractors and Sub-Processors
Personal Information stored within the Complyify platform may be accessed by:
-
authorised users nominated by our customers;
-
Complyify employees and contractors; and
-
third-party service providers engaged to support platform functionality, security, or compliance obligations.
All such access is subject to confidentiality obligations and appropriate access controls.
Data Breach Notification
In the event of a suspected or actual data breach involving Personal Information, Complyify will assess the incident and, where required under the Notifiable Data Breaches scheme, notify affected individuals and the Office of the Australian Information Commissioner in accordance with legal requirements.
Retention of Personal Information
Personal Information is retained only for as long as necessary to fulfil the purposes for which it was collected, including legal, regulatory, compliance, and record-keeping obligations. Certain information may be retained for a minimum of
seven (7) years
where required by law or industry practice.
When no longer required, Personal Information is securely destroyed or permanently de-identified.
Access to Your Personal Information
You may request access to the Personal Information we hold about you and request corrections, subject to legal exceptions. Requests must be made in writing.We do not charge a fee for access requests, but may charge a reasonable administrative fee for providing copies.Proof of identity may be required before access is granted.
Maintaining the Quality of Personal Information
We take reasonable steps to ensure Personal Information is accurate, complete, and up to date. If you believe any information we hold is incorrect, please notify us so it can be corrected.
Policy Updates
This Privacy Policy may be updated from time to time. The current version will always be available on our website.
By accessing or using our website, platform, or services, you acknowledge that you have read and understood this Privacy Policy and consent to the handling of your Personal Information in accordance with it.
Privacy Policy Enquiries and Complaints