Policy Overview

Workfast is committed to protecting the privacy and security of personal information in accordance with the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs), and applicable state and territory legislation. This Privacy Policy explains how Workfast collects, uses, discloses, stores, and protects personal information, and outlines individual rights regarding that information.

This Policy applies to all personal information collected by Workfast through its websites, mobile applications, services, and business operations, including information collected from employees, customers, suppliers, and other stakeholders.

Definitions

  • Personal Information: means information or an opinion about an identified individual or an individual who is reasonably identifiable, whether true or not, and whether recorded in material form or not.
  • Sensitive Information: includes information about an individual's racial or ethnic origin, political opinions, religious beliefs, philosophical beliefs, professional or trade association membership, sexual orientation, criminal record, health information, genetic information, or biometric information.
  • Data Breach: means unauthorized access to or disclosure of personal information, or loss of personal information, that could result in serious harm to affected individuals.
  • Serious Invasion of Privacy: a statutory cause of action under Schedule 2 of the Privacy Act 1988 (Cth) arising where an individual’s privacy is intentionally or recklessly invaded, by intrusion upon seclusion or misuse of personal information, in circumstances where the invasion is serious and the individual had a reasonable expectation of privacy.

Information Collected

Types of Information Collected

Workfast collects personal information that is reasonably necessary for our business functions and activities, including:

  • Contact and identity information: name, address, telephone numbers, email addresses, date of birth, and identification documents.
  • Business information: employment details, business affiliations, professional qualifications, and transaction histories with Workfast or its clients.
  • Technical information: IP addresses, device identifiers, browser information, location data, website usage patterns, and system access logs.
  • Financial information: bank account details, payment information, credit checks, and financial assessments where relevant to Workfast’s services.
  • Communication records: records of communications with Workfast, including emails, telephone calls, and meeting notes.

Collection Methods

Personal information is collected through direct interactions including service applications, account registrations, inquiries, surveys, and business communications. Workfast also collects information indirectly through its websites, mobile applications, third-party service providers, publicly available sources, and business partners where consent has been provided for such disclosure. Wherever practical, Workfast collects personal information directly from the individual. Where collection from third parties is necessary, appropriate consent mechanisms are put in place and individuals are notified of such collection where required by law.

Website and Digital Collection

Our digital platforms use cookies, web beacons, and similar technologies to collect information about your interactions with our services. This includes page views, click patterns, session duration, and technical performance data. You can manage cookie preferences through your browser settings, though disabling certain cookies may limit website functionality.

Use and Disclosure of Personal Information

Primary Purposes

Workfast uses personal information for the following primary purposes:

  • Service delivery: providing services, managing customer relationships, processing applications, and fulfilling contractual obligations.
  • Business operations: internal administration, financial management, risk assessment, quality assurance, and operational planning.
  • Legal compliance: meeting regulatory requirements, responding to lawful requests from authorities, and protecting legal interests.
  • Communication: responding to inquiries, providing service updates, and maintaining business relationships.

Secondary Purposes

With appropriate consent or where permitted by law, we may use personal information for:

  • Marketing and Promotion: Sending newsletters, promotional materials, and service announcements through email, SMS, or postal mail.
  • Business Development: Market research, service improvement, product development, and strategic planning.
  • Analytics: Analyzing usage patterns, customer preferences, and service performance to enhance user experience.

Disclosure to Third Parties

Personal information may be disclosed to:

  • Service providers: third-party vendors providing technology services, payment processing, marketing support, data analytics, and professional services, subject to appropriate confidentiality agreements.
  • Business partners: where specific consent has been given or where necessary for service delivery.
  • Legal authorities: where required by law, court order, or to assist law enforcement investigations.
  • Professional advisors: lawyers, accountants, auditors, and other professional service providers bound by confidentiality obligations.
  • Related entities: other entities within the Workfast corporate group, subject to equivalent privacy protections.

Workfast does not sell personal information to third parties for commercial purposes.

Cross-Border Data Transfers

Personal information may be transferred to or accessed from overseas locations where Workfast engages international service providers or business partners. Current overseas locations include cloud storage facilities in the United States, Singapore, and Ireland, and customer support services in the Philippines. Before transferring personal information overseas, Workfast ensures appropriate safeguards are in place through contractual arrangements, adequacy assessments, or other mechanisms approved under Australian privacy law, and Workfast remains accountable for the protection of information processed overseas.

Data Security and Retention

Security Measures

Workfast implements comprehensive security measures to protect personal information against unauthorised access, modification, disclosure, or destruction:

  • Technical safeguards: multi-factor authentication, encryption of data in transit and at rest, secure network architecture, intrusion detection systems, and regular security testing.
  • Physical security: restricted access to facilities, secure document storage, surveillance systems, and environmental controls.
  • Administrative controls: staff training programs, confidentiality agreements, access control policies, incident response procedures, and regular security audits.
  • Vendor management: due diligence assessments of service providers, contractual security requirements, and ongoing monitoring of third-party security practices.

Data Retention

Personal information is retained only for as long as necessary to fulfil the purposes for which it was collected, comply with legal obligations, or resolve disputes. Specific retention periods include:

  • Customer records: seven years from last interaction or as required by relevant industry regulations.
  • Employee records: seven years following termination of employment.
  • Financial records: seven years as required under taxation and corporations law.
  • Marketing communications: until consent is withdrawn or the individual opts out.

When personal information is no longer required, it is securely destroyed or de-identified in accordance with established procedures.

Data Breach Management

Breach Response Procedures

Workfast maintains comprehensive data breach response procedures in accordance with the Notifiable Data Breaches (NDB) scheme under the Privacy Act 1988 (Cth). Upon discovering a suspected breach, Workfast immediately assesses the incident, contains any ongoing breach, and evaluates whether the breach is likely to result in serious harm to affected individuals.

Notification Requirements

Where a breach is likely to result in serious harm, Workfast will notify the Office of the Australian Information Commissioner (OAIC) as soon as practicable after forming a reasonable belief that an eligible data breach has occurred, and will notify affected individuals as soon as practicable thereafter. Notifications will include details of the breach, potential consequences, and recommended actions for affected individuals. Workfast’s incident response team includes representatives from IT security, legal, compliance, and senior management to ensure coordinated and effective breach response.

Individual Rights

Access Rights

Individuals may request access to personal information Workfast holds about them by contacting the Privacy Officer. Workfast will respond to access requests within 30 days and provide information in a readily understandable format. Reasonable costs may be charged for processing complex access requests. Access may be refused where providing access would unreasonably impact others’ privacy, reveal confidential commercial information, prejudice law enforcement activities, or be prohibited by law.

Correction Rights

Individuals may request correction of personal information that is inaccurate, out-of-date, incomplete, irrelevant, or misleading. Workfast will take reasonable steps to verify and correct information where appropriate and notify relevant third parties of corrections where practicable. Where Workfast refuses a correction request, the individual may request that a statement be associated with the relevant information setting out their view of its accuracy.

Statutory Tort for Serious Invasions of Privacy

In addition to rights under the APPs, individuals have a statutory right of action for serious invasions of privacy under Schedule 2 of the Privacy Act 1988 (Cth), in force since 10 June 2025. This applies where an individual’s privacy is seriously, intentionally, or recklessly invaded through intrusion upon seclusion or misuse of personal information, in circumstances where a reasonable expectation of privacy existed. Workfast’s practices and systems are designed to prevent conduct that could give rise to liability under this cause of action.

Complaints Process

Complaints about Workfast’s handling of personal information should be directed to the Privacy Officer. Workfast will acknowledge complaints within five business days and provide a substantive response within 30 days. If dissatisfied with the response, individuals may complain to the Office of the Australian Information Commissioner at enquiries@oaic.gov.au or 1300 363 992.

Marketing and Communications

Consent and Opt-Out

Marketing communications are sent only with appropriate consent or where permitted by law. All marketing communications include clear opt-out mechanisms, and opt-out requests are processed within five business days. Individuals can manage communication preferences by updating account settings, using unsubscribe links in emails, replying “STOP” to SMS messages, or contacting the Privacy Officer.

Direct Marketing

Workfast may use personal information for direct marketing where an individual would reasonably expect such use, Workfast provides clear opt-out mechanisms, and the individual has not opted out. For sensitive information or information obtained from third parties, explicit consent is required for direct marketing use.

Children’s Privacy

Workfast does not knowingly collect personal information from children (individuals under 18 years of age) without appropriate consent. Consistent with the approach adopted in the OAIC’s Children’s Online Privacy Code framework, a child may provide their own consent to the collection, use, or disclosure of their personal information where they are at least 15 years of age; where a child is under 15, consent must be obtained from a parent or guardian, unless it is not practicable or appropriate to do so, having regard to the child’s maturity and the circumstances. Where Workfast becomes aware that it has collected personal information from a child without appropriate consent, it will take steps to delete that information promptly.

Automated Decision-Making

Where Workfast uses automated systems for decision-making that significantly affects an individual, including decisions made, or substantially and directly contributed to, by artificial intelligence or another computer program, it will provide information about the logic involved and seek appropriate human review of decisions where requested. This includes credit assessments, eligibility determinations, and service recommendations. Individuals have the right to request human review of automated decisions and to challenge decisions believed to be incorrect. Consistent with amendments to the Privacy Act 1988 (Cth), Workfast will ensure this Policy discloses its use of automated decision-making that could reasonably be expected to significantly affect individual rights or interests, in line with requirements taking effect from 11 December 2026.

Privacy Governance

Role / Process Description
Privacy Officer Responsible for privacy compliance, handling complaints, managing access and correction requests, and coordinating privacy training; reports regularly to senior management on privacy matters and compliance status.
Staff Training All staff receive privacy training upon commencement and regular updates on privacy requirements. Specialised training is provided to staff handling sensitive information or involved in system administration.
Privacy Impact Assessments Conducted for new systems, processes, or activities that may have significant privacy implications, identifying risks and ensuring appropriate safeguards before implementation.
Regular Reviews This Privacy Policy is reviewed annually or when significant changes occur to Workfast’s operations, systems, or legal requirements. Privacy practices are regularly audited to ensure ongoing compliance and effectiveness.

Updates to the Policy

This Privacy Policy may be updated from time to time to reflect changes in Workfast’s practices, technology, or legal requirements. Significant changes will be notified through Workfast’s website, email communications, or other appropriate channels.

Get In Touch

Contact Us

Please fill out the form below and a member of our team will be in contact shortly.

First Name
Last Name
Company
Email
Contact Number
Location
Message
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.