Privacy Policy
VEIL GROUP PTY LTD Privacy Policy
Privacy Policy – VEIL GROUP PTY LTD (VGPL)
Last updated: 2025 October 10
1. Introduction
VEIL GROUP PTY LTD (VGPL) protects personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). VGPL manages personal information in an open and transparent way (APP 1) and maintains internal practices and systems designed to ensure ongoing compliance.
This policy explains:
- the kinds of personal information VGPL collects and holds;
- how VGPL collects and holds personal information;
- the purposes for which VGPL collects, uses and discloses personal information;
- how you may access and correct your personal information;
- how you may complain about a breach of the APPs and how VGPL will deal with such a complaint; and
- whether VGPL is likely to disclose personal information to overseas recipients and, if so, the steps VGPL takes to protect it (APP 1.4 and APP 8).
2. Collection of Information (APP 3 & APP 5)
2.1 Necessity & Fairness. VGPL only collects personal information that is reasonably necessary for VGPL’s functions or activities and does so by lawful and fair means.
2.2 What VGPL Collects. Depending on your interactions with VGPL, VGPL may collect your name, contact details (email address, phone number), organisation, role/title, and any information you include in enquiries or documents you provide to VGPL.
2.3 Transactional Records. VGPL collects information from invoices issued and payments received into VGPL accounts. VGPL does not collect credit card numbers or other payment instrument details beyond what is required for bookkeeping and tax compliance.
2.4 Interaction Data. VGPL collects interaction data from its website and services (e.g., IP address, device and browser type, pages viewed, timestamps, referral URLs) to operate, secure, and improve services. VGPL may use cookies, log files, analytics tools and, where applicable, third‑party pixels. Where online identifiers are reasonably identifiable, VGPL treats them as personal information. Controls are provided to manage cookies/analytics where practicable.
2.5 De‑Identified Data. VGPL may de‑identify information and use it in aggregate for research, reporting, and service improvement. VGPL assesses re‑identification risk, applies technical/organisational controls, and does not attempt to re‑identify individuals.
2.6 Sensitive Information. VGPL does not collect “sensitive information” as defined by the Privacy Act (e.g., health, religious or political beliefs) unless you provide it to VGPL with your consent and it is necessary for VGPL’s functions (which VGPL aims to avoid).
2.7 If You Do Not Provide Information. If you choose not to provide requested information, VGPL may be unable to respond to your enquiry, provide certain services, or enter into/perform a contract.
2A. Anonymity and Pseudonymity (APP 2)
Where lawful and practicable, you may interact with VGPL without identifying yourself or by using a pseudonym (for example, when making a general enquiry). Some services require your identity (e.g., where required by law or to respond to a specific request).
2B. Unsolicited Information (APP 4)
If VGPL receives personal information VGPL did not ask for, VGPL assesses whether VGPL could have lawfully collected it. If not, and if lawful and reasonable, VGPL destroys or de‑identifies it as soon as practicable.
2C. Notice at or Before Collection (APP 5)
At or before the time VGPL collects personal information (or as soon as practicable afterwards), VGPL will inform you of: VGPL’s identity and contact details; the purposes of collection; the main consequences if information is not provided; the types of third parties VGPL usually discloses to (including cloud, email, and analytics providers); whether VGPL is likely to disclose to overseas recipients and, if so, the countries or classes of recipients; and how to access/correct your information and lodge a complaint.
3. Use and Disclosure (APP 6 & APP 7)
3.1 Primary Purpose. VGPL uses personal information only for the purposes for which VGPL collected it, or for directly related purposes you reasonably expect, unless another lawful basis applies.
3.2 Third Parties. VGPL discloses personal information to third parties only where necessary for VGPL’s functions, where you consent, or where required/permitted by law. Typical recipients include VGPL’s cloud hosting, email, analytics, security, accounting, and professional service providers.
3.3 Direct Marketing (APP 7 & Spam Act). VGPL may use your contact details to send updates about VGPL services where permitted by law. You can opt out at any time using the unsubscribe link or by contacting VGPL. VGPL processes unsubscribe requests promptly (within 5 business days) and does not require you to create an account or pay a fee to opt out.
3.4 De‑Identified and Aggregated Data. VGPL may use de‑identified or aggregated information for research, reporting and service improvement and will not attempt to re‑identify individuals from such data.
4. Storage, Security and Cross‑Border Disclosures (APP 8 & APP 11)
4.1 Where VGPL Stores Data. VGPL primarily stores personal information in Australia on infrastructure such as AWS within Australian regions. Some service providers or their support teams may operate outside Australia. Where VGPL discloses personal information to an overseas recipient, VGPL takes reasonable steps to ensure the recipient protects the information in a manner consistent with the APPs (other than APP 1), including through contractual terms, due diligence, and technical controls.
4.2 Security Controls. VGPL takes reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access, modification or disclosure. Controls include encryption at rest and in transit (TLS), least‑privilege access, multi‑factor authentication, secure software development practices, vendor risk assessments, audit logging and monitoring, regular access reviews, and secure destruction.
4.3 Retention and Destruction (APP 11.2). VGPL retains personal information only as long as needed for VGPL’s functions and to meet legal obligations. For example, company financial records are generally retained for 7 years under the Corporations Act, and many tax/business records for 5 years. After the applicable period, VGPL securely destroys or de‑identifies personal information.
5. Access and Correction (APP 12 & APP 13)
5.1 Access. You may request access to your personal information by contacting privacy@veilgroup.au. VGPL may need to verify your identity and may provide access in the format you request if it is reasonable and practicable.
5.2 Correction. You may request correction of your personal information. VGPL will respond within a reasonable period (generally within 30 days) and will notify you of the outcome.
5.3 Refusals. If VGPL refuses access or correction, VGPL will provide written reasons and information on how to complain.
6. Complaints and Data Breaches
6.1 How to Complain. If you believe VGPL has mishandled your personal information, contact privacy@veilgroup.au. Provide as much detail as possible so VGPL can investigate.
6.2 Our Response. VGPL acknowledges complaints promptly, investigates, and responds within a reasonable period (generally within 30 days). If you are not satisfied, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC).
6.3 Notifiable Data Breaches. If an eligible data breach is likely to cause serious harm, VGPL will notify affected individuals and the OAIC in accordance with the Notifiable Data Breaches scheme under the Privacy Act 1988. VGPL maintains and tests a data breach response process.
7. Contact Details
VEIL GROUP PTY LTD (VGPL)
- Privacy Department: privacy@veilgroup.au
- Privacy Officer: privacyofficer@veilgroup.au
- Postal Address: See “Registered Address for Service”
8. Updates
VGPL may update this privacy policy from time to time. The latest version will be published on VGPL’s website with the “Last updated” date above.
Appendix – References and Operational Context
- Privacy Act 1988 (Cth), including Schedule 1 – Australian Privacy Principles (APPs).
- OAIC Guidance: APP Guidelines; Guide to securing personal information; De‑identification Decision‑Making Framework; Data analytics & privacy; Notifiable Data Breaches scheme; Privacy complaints handling.
[1] Privacy Act 1988 (Cth)
Legislation.gov.au – Privacy Act 1988 (Cth)
[2] OAIC, APP Guidelines, Chapter 3 – Collection of solicited personal information
OAIC link