This Privacy Policy relates to enableHR Pty Ltd trading as enableHR (“the Company”). The Company is a Citation Group Pty Ltd Group Company and this Privacy Policy conforms with the Citation Group Policy.
The Company is committed to safeguarding the privacy of information provided to us and information about visitors to our website and users of the enableHR platform.
This Privacy Policy explains how we may collect and use information that we obtain about you, and your rights in relation to that information. Your use of our online services or your provision of information to us constitutes your acknowledgment of the terms of this Privacy Policy. Please do not send us any information which we have not requested, or which is not necessary or relevant to the purpose for which Company is engaged by you.
1.1. From time to time the Company is required to collect, hold, use and/or disclose personal information relating to individuals (including, but not limited to prospective employees, clients, suppliers, investors, referees, contractors and employees) in the performance of its business activities.
1.2. This Privacy Policy sets out the Company’s policy in relation to the protection of personal information, as under the Privacy Act 1998 (Cth) (“the Act”) and the Australian Privacy Principles (“APP”).
1.3. The APPs regulate the handling of personal information.
Last Updated: 28 September 2022
2.1. Personal information means information or an opinion (including information or an opinion forming part of a database), whether true or not, and whether recorded in a material form or not, about an individual whose identity is apparent, or can reasonably be ascertained, from the information or opinion.
3.1. This Privacy Policy does not apply to the collection, holding, use or disclosure of personal information that is an employee record.
3.2. An employee record is a record of personal information relating to the employment of an employee. Examples of personal information relating to the employment of the employee include, but are not limited to, health information and information about the engagement, training, disciplining, resignation, termination, terms and conditions of employment of the employee. Please see the Act for further examples of employee records.
3.3. The exemption applies to current or former employees. It does not apply to contractors, volunteers or prospective employees. Despite this exemption, the Company may have other obligations regarding employee records, for example under the Fair Work Act 2009 (Cth) and the Fair Work Regulations 2009 (Cth).
4.1. The Company collects personal information that is reasonably necessary for one or more of its functions or activities.
4.2. The type of information that the Company collects and holds may depend on your relationship with the Company. For example:
4.3. Sensitive information: the Company will only collect sensitive information where you consent to the collection of the information (unless one of the exceptions to the APPs apply) and the information is reasonably necessary for one or more of the Company’s functions or activities. Sensitive information includes, but is not limited to, information or an opinion about racial or ethnic origin, political opinions, religious beliefs, philosophical beliefs, membership of a trade union, sexual preferences, criminal record, health information or genetic information.
4.4. By providing this information to use, or consenting to a third party (such as your employer) providing that information to us, you consent to our collection and use of that information as set out in this Privacy Policy.
5.1. The Company will only collect personal information by lawful and appropriate means. The Company will collect personal information directly from you if it is reasonable or practicable to do so.
5.2. The Company and any Group Company may collect personal information in a number of ways, including without limitation:
5.3. When the Company collects personal information about you through third parties, it will manage such information in accordance with the APPs.
5.5. Unsolicited personal information is personal information that the Company receives which it did not solicit. Unless the Company determines that it could have collected the personal information in line with the APPs or the information is contained within a Commonwealth record, it must destroy the information to ensure it is de-identified.
5.6 Monitoring of telephone calls
When the Company speaks to you on the phone, calls may be recorded for security, training and quality assurance purposes.
6.1. The Company will collect personal information if it is reasonably necessary for one or more of its functions or activities.
6.2. In most cases, you will be required to identify yourself when you deal with us, such as when you (or an associated company or other entity) become a client of ours. If you do not provide us with the personal information detailed above, some or all of the following may happen:
6.3. We will normally hold your personal information in a database. We collect, hold, use and disclose your personal information for some or all of the following purposes:
6.4. The Company may also collect, hold, use and/or disclose personal information if you consent or if required or authorised under law. For example, the Company may be required or authorised to collect your Tax File Number, if you choose to provide it, by the Income Tax Assessment Act 1936 (Cth).
7.1. The Company or any of the Group Companies may use or disclose personal information (other than sensitive information) about you for the purpose of direct marketing (for example, advising you of new goods and/or services being offered by the Company and the Group Companies).
7.2. The Company may use or disclose sensitive information about you for the purpose of direct marketing if you have consented to the use or disclosure of the information for that purpose.
7.3. The Company or any of the Group Companies may use or disclose personal information (other than sensitive information) about you to the other Group Companies for the purpose of cross promotions and direct marketing of the other Group Company’s products and services.
7.4. You can opt out of receiving direct marketing communications from the Company by contacting our Privacy Officer in writing or if permissible accessing the Company’s website and unsubscribing appropriately.
8.1. The Company may disclose your personal information for any of the purposes for which it is was collected, as indicated under clause 5 of this Privacy Policy, or where it is under a legal duty to do so.
8.2. Disclosure will usually be internally, to related entities but may otherwise include third parties such as contracted service suppliers (CSP). Examples of CSPs include, but are not limited to, financial institutions for payment processing, information technology service providers, marketing and communications agencies, printers and distributers of direct marketing material and external business advisors.
8.3. Before the Company discloses personal information about you to a third party, the Company will take steps as are reasonable in the circumstances to ensure that the third party does not breach the APPs in relation to the information. While we take all reasonable steps to ensure the security of our system, we cannot provide any guarantee regarding security of the personal information and other data transmitted to the enableHR platform or services and we will not be held responsible for events arising from unauthorised access of your personal information.
9.1. If the Company holds personal information about you, you may request access to that information by putting the request in writing and sending it to our Privacy Officer. The Company will respond to any request within a reasonable period, but no more than 30 days. The Company may charge a fee to provide access to the personal information.
9.2. There are certain circumstances in which the Company may refuse to grant you access to the personal information. For example, we may need to refuse access if granting access would interfere with the privacy of others or if it would result in a breach of confidentiality or legal professional privilege.
9.3. In such situations the Company will give you written notice that sets out:
10.1 If you wish to access, verify, or correct of any of the personal information you have submitted to us, you may do so by contacting us via privacyofficer@citationgroup.com.au . As soon as practicable after your request, we will take reasonable steps to allow for corrections to be made to this information unless an exception under the relevant privacy or data protection laws apply.
10.2. There are certain circumstances in which the Company may refuse to correct the personal information. In such situations the Company will give you written notice that sets out:
10.3. If the Company corrects personal information that it has previously supplied to a third party and you request us to notify the third party of the correction, the Company will take such steps as are reasonable to give that notification unless impracticable or unlawful to do so.
11.1. The Company will take such steps (if any) as are reasonable in the circumstances to ensure that the personal information that it:
11.2. The Company will take steps as are reasonable in the circumstances to protect the personal information from misuse, interference, loss and from unauthorised access, modification or disclosure.
11.3. If the Company holds personal information, it no longer needs the information for any purpose for which the information may be used or disclosed, the information is not contained in any Commonwealth record and the Company is not required by law to retain the information, it will take such steps as are reasonable in the circumstances to destroy the information or to ensure it is de-identified.
12.1. You have the option of not identifying yourself, or using a pseudonym, when dealing with the Company in relation to a particular matter. This does not apply:
12.2. However, in some cases if you do not provide the Company with your personal information when requested, the Company may not be able to respond to your request or provide you with the goods or services that you are requesting.
13.1. The Company may disclose Personal information about an individual overseas. This is likely to occur where the Company uses “cloud” service providers.
13.2. When disclosing Personal information, the Company will do so in accordance with the APPs.
14.1. A Notifiable Data Breach occurs when Personal information of an individual held by the Company is accessed by, or is disclosed to, an unauthorised person, or is lost, and:
14.2. If the Company suspects that a Notifiable Data Breach has occurred, it will conduct a reasonable and expeditious assessment to determine if there are reasonable grounds to believe that a Notifiable Data Breach has occurred.
14.3. The Company will take all reasonable steps to ensure that the assessment is completed within 30 days of becoming aware of the suspected Notifiable Data Breach.
14.4. Please refer to the Notifiable Data Breach Procedure if you suspect a breach has occurred.
14.5. Subject to any restriction under the Act, in the event a Notifiable Data Breach occurs, the Company will, as soon as practicable, prepare a statement outlining details of the breach, and:
a. notify the individual of the unauthorised access, disclosure or breach; and
b. notify the Office of the Australian Information Commissioner of the unauthorised access, disclosure or breach.
15.1. You have a right to complain about the Company’s handling of your personal information if you believe the Company has breached the APPs.
15.2. If you wish to make such a complaint to the Company, you should first contact the Privacy Officer in writing. Your complaint will be dealt with in accordance with the Company’s complaints procedure and the Company will provide a response within a reasonable period.
15.3. If you are unhappy with the Company’s response to your complaint, you may refer your complaint to the Office of the Australian Information Commissioner.
16.1. We use cookies. When you use the enableHR platform or any of our services, certain information may be recorded for statistical purposes. Such information enables us to improve our products and services. The information that may be recorded includes information regarding your:
The Company’s Privacy Officer can be contacted in the following ways:
Company Privacy Officer
Telephone number: 02 9922 5188
Email address: privacyofficer@citationgroup.com.au
Postal address: Level 11, 83 Mount Street, North Sydney NSW 2060