Privacy Notice Summary
1. ABOUT THIS NOTICE
- 1.1Who we are. Verimus Strategic Solutions Pty Ltd (ACN 676 581 570), trading as HR Command.
- 1.2Purpose. We are committed to protecting your privacy and handling your Personal Data in accordance with the Australian Privacy Principles (APPs), the Privacy Act 1988 (Cth), and other relevant data protection laws and regulations.
- 1.3Scope and Application. This Privacy Notice explains how we collect, use, disclose, and protect your Personal Data when you use the HR Command® App, Platform, or our services. It applies to all users of the HR Command® App and Platform, customers, and any other individuals whose Personal Data is collected by HR Command.
- 1.4Summary Privacy Notice. This is a summary of how we handle your Personal Data. The full Privacy Notice is available at HERE. This summary covers key points but is not a complete description of our privacy practices.
2. WHAT PERSONAL DATA WE COLLECT AND BASIS OF USE
- 2.1Types of Personal Data. We collect a broad range of Personal Data, which may include:
- 2.1.1Identity Information: Name, maiden name, last name, username, marital status, title, date of birth, gender, job function, employer, and department.
- 2.1.2Contact Information: Address, email, phone number (work or personal, as relevant).
- 2.1.3Employment and Engagement Details: Employer/engager name, job title, function, health data, and identity details.
- 2.1.4Photographs and Images: Including screen captures and mobile device screenshots.
- 2.1.5Notes and Communications: Information exchanged via the HR Command® App and Platform.
- 2.1.6Geolocation Data: Unique IDs from mobile devices, network carriers, or data providers.
- 2.1.7Biometric Data: Data used for authentication or identification.
- 2.1.8Financial and Payment Information: Bank account details, payment methods, and transaction information.
- 2.1.9Technical Information: IP address, device identifiers, browser type, operating system, and usage data.
- 2.1.10Marketing and Communications Information: Preferences for receiving marketing and communication from us.
- 2.1.11Profile Information: Username, password, preferences, feedback, and survey responses.
- 2.1.12Sensitive Personal Data: Health, biometric, genetic, racial or ethnic origin, political opinions, religious beliefs, sexual orientation, criminal record, and other sensitive information, only with your consent or as required by law.
- 2.1.1
- 2.2Other Information. We may also collect non-Personal Data, such as analytics data (e.g., via Google Analytics), device and browser information, usage patterns, and information from cookies. When using social media, we may collect information you allow those platforms to share with us.
3. HOW WE COLLECT YOUR DATA
- 3.1Direct Collection. Your Personal Data may be collected when you:
- 3.1.1complete forms via the HR Command® App or Platform;
- 3.1.2use our app, platform or services;
- 3.1.3contact us with queries or requests;
- 3.1.4post information or interact with our app or platform;
- 3.1.5participate in surveys or request a call back;
- 3.1.6subscribe to marketing lists or request further information;
- 3.1.7attend conferences or events; or
- 3.1.8enter into a Customer Agreement with us.
- 3.1.1
- 3.2Third party collection. We may collect your Personal Data from:
- 3.2.1those who request our services on your behalf;
- 3.2.2publicly available sources;
- 3.2.3government regulators, law enforcement agencies, and other government entities;
- 3.2.4business contacts, external services providers and suppliers; or
- 3.2.5other means reasonably necessary for our business.
- 3.2.1
- 3.3Authority and Unsolicited information. If you provide us with another individual’s Personal Data, you must have their authorisation and consent. If we receive unsolicited Personal Data that we could not have lawfully collected, we will destroy or de-identify it as soon as practicable.
- 3.4Anonymity. You may request to use our services anonymously or under a pseudonym, but this may limit your access to some services. We may require identification where required by law or where it is impracticable to provide services otherwise.
- 3.5Destruction of Data. We will destroy or de-identify your Personal Data when it is no longer needed for the purpose for which it was collected, or upon your request, unless we are required by law to retain it.
4. WHY WE COLLECT AND USE YOUR DATA
- 4.1Primary Purposes. We collect and use your Personal Data for the following primary purposes:
- 4.1.1Delivering Services: Preparing and delivering documents, managing payments, fees, and charges, and collecting debts.
- 4.1.2Operating the HR Command® Platform and App: Enabling your use, storing data, personalising your experience, and making information available to relevant customers.
- 4.1.3Processing Data: Acting as a data processor or controller, verifying identity, and developing insights for reports or content.
- 4.1.4Providing Information: Supplying information about services you requested or enquired about.
- 4.1.5Employment and Engagement: Assessing applications, conducting background checks, and arranging payments.
- 4.1.6Disclosing to Third Parties: Engaging professional advisors, authorised persons, business purchasers, and others as required or permitted by law.
- 4.1.7Investigating Complaints or Breaches: Ensuring compliance with terms and industry best practices.
- 4.1.8Customer Agreements: Fulfilling obligations under customer agreements.
- 4.1.9Reviewing and Enhancing Services: Developing insights and improving our offerings.
- 4.1.10Communicating with You: Via email, mobile, and in-app notifications.
- 4.1.11Processing Payments and Administering Accounts: Sending reminders and managing accounts.
- 4.1.12Legal and Regulatory Compliance: Doing anything else required or permitted by law.
- 4.1.1
- 4.2Basis of Use. We collect, use, and disclose your Personal Data only where permitted by law. The main bases for our use of your Personal Data are:
- 4.2.1To perform our obligations under a contract with you.
- 4.2.2To perform our legal and regulatory obligations.
- 4.2.3To perform functions necessary for our legitimate interests.
This is in accordance with APP 3.2, which allows us to collect personal information when it is reasonably necessary for one or more of our functions or activities.
- 4.2.1
- 4.3Secondary Purposes. We may use or disclose your data for secondary purposes if.
- 4.3.1you would reasonably expect it, and it is related to the primary purposes;
- 4.3.2you have consented; or
- 4.3.3permitted by law.
- 4.3.1
- 4.4Direct Marketing. We may use your data for direct marketing if collected from you and you have not opted out. You can opt out at any time by contacting us.
- 4.5Automated decision-making. We may use secure artificial intelligence systems and automated decision-making software to assist in providing our services, always in compliance with this Notice. Details of such decisions will be provided where relevant.
5. HOW WE DISCLOSE YOUR DATA
- 5.1Disclosure to Third Parties. We may disclose your Personal Data to:
- 5.1.1third parties engaged to perform functions related to the HR Command® App, Platform or our services;
- 5.1.2third party service providers acting on our behalf;
- 5.1.3regulatory bodies in relevant industries;
- 5.1.4professional advisors, including our accountants, auditors and lawyers;
- 5.1.5related bodies corporate;
- 5.1.6a relevant person entitled to use our services;
- 5.1.7persons authorised by you;
- 5.1.8a government authority, law enforcement, or pursuant to a court orders; or
- 5.1.9any other persons as required or permitted by any law.
- 5.1.1
- 5.2Sensitive Personal Data is only disclosed with your consent or as required by law.
- 5.3Overseas disclosure Your Personal Data may be transferred to overseas recipients, such as server hosts for email and cloud storage. Likely countries are specified in the full policy. We take reasonable steps to ensure overseas recipients protect your data in a way substantially similar to the APPs, including contractual safeguards. If you are in the EU, we will comply with the GDPR for overseas transfers where notified.
6. ACCESS & CORRECTION
- 6.1Access to Your Data. You may request access to you Personal Data by contacting us. We may require your request in writing and proof of identity. We will respond within a reasonable period and, if reasonable and practicable, provide access as requested. We may refuse access in certain circumstances (e.g., if it would impact the privacy of others, is frivolous, relates to legal proceedings, is unlawful, or would reveal commercially sensitive information). If access is refused, we will provide written reasons and information on how to make a complaint.
- 6.2Correction of Your Data. You should keep your Personal Data current. If you believe your data is inaccurate or out of date, contact us to request correction. We will respond within a reasonable period and, if reasonable and practicable, correct the data. If we refuse, we will provide written reasons and note the refusal in your records.
- 6.3Restriction (EU Residents). If you are a citizen of, or are located within, the European Union, you may request restriction of processing under Article 18 of the GDPR. Depending on the nature of the restriction, we may be unable to provide some or all services. We will advise you if this is the case.
7. SECURITY & DATA PROTECTION
- 7.1How We Protect Your Data. We take reasonable steps to:
- 7.1.1ensure Personal Data we collect and hold is accurate, up to date and complete;
- 7.1.2protect Personal Data from misuse, loss or unauthorised access and disclosure; and
- 7.1.3store data on secure servers behind firewalls, with access, modification, or disclosure.
- 7.1.1
- 7.2Obligation to notify. Please contact us immediately if you become aware of or suspect any misuse or loss of your Personal Data.
8. DATA BREACHES
- 8.1Notifiable Data Breaches Scheme. We comply with the Notifiable Data Breaches scheme under the Privacy Act. If we become aware of a data breach that is likely to result in serious harm, we will:
- 8.1.1investigate the circumstances;
- 8.1.2assess whether the breach is eligible for notification;
- 8.1.3prepare a statement for the Office of the Australian Information Commissioner (OAIC); and
- 8.1.4notify affected individuals and/or publish a statement as required.
- 8.1.1
9. COMPLAINTS
- 9.1How to Make a Complaint. If you have a complaint about how we handle your Personal Data please contact our Privacy Offer. We will respond to your complaint within 14 days of receiving it. We may request further information, discuss resolution options, and investigate as necessary. If your complaint involves an employee, we will seek their input. After investigating the complaint, we will provide a written notice of our decision.
- 9.2External Complaints. You are free to lodge a complaint directly with the OAIC. For more information please visit the OAIC website at oaic.gov.au.
10. CONTACT
- 10.1Contact. Please forward all correspondence in respect of the Privacy Notice or Summary to:
Privacy Officer
Verimus Strategic Solutions Pty Ltd
Level 2, 50 Pitt Street,
Sydney, NSW, 2000
AustraliaTel: +61 417 778 461
Email: hello@verimus.com.au