Privacy Policy

Privacy Policy

Exsead Group Pty Ltd, Exsead is committed to protecting personal information and managing it in an open, transparent and responsible manner.
The Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) define how we collect, use, share, store, and protect personal information.
By engaging with us, accessing our website, or using our services, you acknowledge that you have read and understood this Privacy Policy.
 

What Personal Information We Collect

 
We collect personal information that is reasonably necessary for our business functions and activities. Depending on the nature of your interaction with us, this may include:
  • Business & Contact Information
  • Full name
  • Job title and organisation
  • Business email address
  • Telephone number
  • Business address
  • Client & Service-Related Information
  • Information provided in enquiries, proposals, or contracts
  • Support and service interaction records
  • Project documentation and communications
  • Information required for service delivery, system implementation, or integration
Recruitment Information
 
  • Resume/CV
  • Employment history
  • Qualifications and references
  • Interview notes
 
Marketing & Engagement Information
 
  • Newsletter subscriptions
  • Event registrations
  • Participation in webinars or promotions
  • Preferences and interests
 
Digital & Technical Information
  • IP address
  • Browser type and device information
  • Website usage data
  • Cookies and analytics data
  • Interaction with our emails and digital communications
 

We do not generally collect sensitive information unless required for lawful business purposes and with appropriate safeguards.

How we collect Personal Information

We collect personal information:

  • Directly from you (e.g. via forms, email, phone, contracts, events)
  • When you engage our services
  • When you apply for a position
  • When you subscribe to communications
  • Using automatic methods like cookies and analytics tools
  • From third parties where authorised (e.g. referees, business partners)
  • We only collect information by lawful and fair means.

Why We Collect and Use Personal Information

We collect and use personal information to operate our business effectively, including to:

  • Deliver consulting, implementation, managed and technical services
  • Fulfil contractual obligations
  • Manage customer and supplier relationships
  • Provide support and service management
  • Improve our services and customer experience
  • Conduct research, analytics and service optimisation
  • Send business communications and marketing materials (where permitted by law)
  • Recruit employees and contractors
  • Comply with legal and regulatory obligations
  • We will not sell personal information to third parties.

Marketing Communications

  • Where permitted under the Spam Act 2003 (Cth) and other applicable laws, we may send you communications about our services, insights, events, or updates.
  • You may withdraw your consent or amend your marketing choices at any time by:
  • Using the unsubscribe link in our communications, or
  • Contacting our Privacy Officer.

Disclosure of Personal Information

  • We may disclose personal information where reasonably necessary to:
  • Employees, contractors, and consultants involved in delivering services
  • Cloud service providers and technology vendors
  • Professional advisers (legal, accounting, insurance)
  • Payment processors and financial institutions
  • Regulatory or government authorities where required by law
  • We only disclose personal information necessary for the relevant purpose and require third parties to maintain appropriate confidentiality and security standards.
 

Overseas Disclosure

Some of our service providers may be located outside Australia. This may include cloud hosting providers, software vendors, or operational support companies.
Countries where data may be processed or accessed could include (but are not limited to):
  1. United States
  2. United Kingdom
  3. European Union member states
  4. Asia-Pacific regions
 
Where personal information is disclosed overseas, we take reasonable steps to ensure recipients comply with privacy protections consistent with the Australian Privacy Principles.
 

Client Data & Contractual Commitments

In the course of delivering services, clients may provide business data, documents, and personal information (including potentially sensitive information).
Where we process personal information on behalf of a client:
 
  • We act in accordance with contractual commitments and documented instructions
  • We comply with agreed data residency and storage requirements
  • We restrict access based on “least privilege” and “need-to-know” principles
  • We implement appropriate technical and organisational safeguards
  • Clients remain responsible for ensuring they have lawful authority to provide such information to us.
 

Data Security

We take reasonable physical, administrative and technical measures to safeguard personal information from misuse, interference, loss, unauthorised access, modification or disclosure.
Our security measures may include:
  • Role-based access controls
  • Multi-factor authentication
  • Encryption of data in transit and at rest (where applicable)
  • Secure cloud infrastructure
  • Staff confidentiality obligations
  • Ongoing security monitoring and risk assessment
  • Documented security policies and procedures
  • Despite our efforts, no mode of electronic transmission or storage is totally secure.

Data Retention

We retain personal information only for as long as necessary to fulfil the purposes outlined in this policy, comply with legal obligations, resolve disputes, and enforce agreements.
When information is no longer necessary, we take reasonable steps to securely discard or de-identify it.
 

Access and Correction

You have the right to request access to personal information we hold about you and to request correction if it is inaccurate, incomplete or outdated.
To request access or correction, please contact our Privacy Officer using the details below. We will respond within a reasonable timeframe and in accordance with legal requirements.
 

Complaints

If you believe we have breached your privacy rights, you may submit a complaint in writing to our Privacy Officer.
We will investigate your complaint and react as soon as practically practicable.
If you are not satisfied with our response, you may lodge a complaint with:
Office of the Australian Information Commissioner (OAIC)
 
Website: www.oaic.gov.au

 

Changes to This Policy

We may amend our Privacy Policy from time to time. The latest version will be published on our website with the updated effective date.
 

Contact us

Privacy Officer
Exsead Group Pty Ltd
Melbourne, Victoria, Australia