Privacy Policy
Vertruen Pty Ltd (“Vertruen”, “we”, “us”, or “our”) is an Australian-based business specialising in wage and salary auditing, data modelling, and compliance-related services. Our mission is to deliver accurate, reliable, and secure solutions to help businesses ensure compliance with employment regulations, ensure payroll accuracy, and leverage data-driven insights through advanced modelling and AI tools. We are committed to protecting the privacy and security of personal information we collect, hold, use, and disclose while providing these services. This Privacy Policy outlines how we manage personal information in accordance with the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs), and, where applicable, the General Data Protection Regulation (GDPR) for individuals in the European Union.
About Our Business
Vertruen operates across Australia, serving clients ranging from small businesses to large enterprises in various industries. Our core services include:
- Wage and Salary Auditing: Ensuring accuracy and compliance with Australian employment laws, including fair work regulations and payroll obligations.
- Data Modelling: Utilising advanced analytics to provide insights into workforce trends, payroll efficiency, and compliance risks.
- Compliance Services: Assisting clients in meeting regulatory requirements, including tax, superannuation, and workplace standards.
We collect personal information as a necessary part of delivering these services, ensuring that all data handling practices align with our commitment to transparency, security, and compliance. Our operations are supported by a team of trained professionals and secure technological infrastructure, including cloud-based solutions and encrypted communication systems.
1. Types of Personal Information We Collect
We collect personal information necessary to deliver our services, which may include:
- Identity Information: Names, dates of birth, gender, and other identifying details.
- Contact Information: Email addresses, phone numbers, and postal addresses.
- Employment Information: Wage and salary details, employment contracts, superannuation account details, job titles, and employment history.
- Financial Information: Bank account details, payment records, or other financial data relevant to payroll auditing.
- Sensitive Information: Health information, criminal history, or other sensitive data, where relevant to compliance services (e.g., for workplace safety or legal obligations).
- Data Modelling Inputs: Aggregated or individual-level data provided by clients for analysis, such as workforce demographics or payroll metrics.
- Other Data: Information provided voluntarily by individuals or collected during service delivery, such as feedback or correspondence.
We collect this information directly from individuals, their employers, or authorised representatives, or through secure data transfers as part of our services.
2. How We Collect Personal Information
We collect personal information in the following ways:
- Direct Collection: Through secure online portals, encrypted email communications, or direct interactions with clients, employees, or their representatives.
- Client-Provided Data: From businesses or organisations engaging our services, such as payroll data or employee records for auditing or compliance purposes.
- Third-Party Sources: From government agencies, regulatory bodies, or other authorised entities, where legally permitted and necessary.
- Automated Collection: Limited collection of technical data (e.g., IP addresses, browser details) when individuals interact with our secure portals or website.
We collect personal information only by lawful and fair means and, where applicable, with the individual’s consent or as required by law.
3. Purposes of Collecting, Holding, Using, and Disclosing Personal Information
We collect, hold, use, and disclose personal information for the following primary purposes:
- To deliver wage and salary auditing services, ensuring compliance with Australian employment laws and regulations.
- To perform data modelling and provide actionable insights for workforce planning, payroll optimisation, and compliance risk management.
- To provide compliance-related services, including reporting to regulatory bodies or verifying adherence to superannuation obligations.
- To ensure the accuracy of data used in our auditing and compliance processes.
- To communicate with clients, employees, or their representatives regarding our services.
- To meet legal and regulatory obligations under Australian law and, where applicable, GDPR.
- To improve our services through anonymised data analysis, research, and development of our data modelling capabilities.
- To manage client relationships, including billing, account management, and service updates.
We may disclose personal information to:
- Third-Party Service Providers: Such as IT providers, cloud service providers (e.g., AWS), or software vendors, under strict confidentiality agreements.
- Regulatory Authorities: Such as the Australian Taxation Office or Fair Work Ombudsman, as required by law.
- Other Entities: Where necessary to deliver our services, such as sharing data with a client’s authorised representatives or with the individual’s consent.
We do not sell or share personal information for marketing purposes.
4. Data Storage and Security
We prioritise the security of personal information and implement robust measures to protect it from misuse, interference, loss, unauthorised access, modification, or disclosure. Our security practices include:
- Data Storage: Personal information is stored on Amazon Web Services (AWS) servers in secure, ISO-compliant data centres. All data is encrypted at rest and in transit using AES-256 encryption or equivalent industry-standard protocols.
- Device Security: All employee and contractor laptops are equipped with encrypted hard drives and endpoint protection software to prevent unauthorised access.
- Secure Communication: Data transfers occur via secure, encrypted portals and Microsoft SharePoint, utilising HTTPS and TLS 1.3 protocols.
- Access Controls: Access to personal information is restricted to authorised personnel who require it for their duties, with multi-factor authentication and role-based access controls.
- Security Audits: We conduct regular security assessments, penetration testing, and compliance audits to maintain robust protections.
- Incident Response: We maintain a data breach response plan to promptly address and mitigate any security incidents.
In the event of a data breach, we will comply with the Notifiable Data Breaches (NDB) scheme under the Privacy Act 1988 and, where applicable, GDPR notification requirements, notifying affected individuals and authorities as required.
5. Compliance with Privacy Laws
We are committed to complying with:
- Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), which govern the handling of personal information in Australia.
- General Data Protection Regulation (GDPR) for personal data of individuals in the European Union, where applicable, including rights to access, rectification, erasure, restriction of processing, and data portability.
Our compliance framework includes regular staff training, internal audits, and adherence to industry best practices to ensure ongoing alignment with these laws.
6. Access and Correction of Personal Information
Individuals have the right to:
- Request access to the personal information we hold about them.
- Request correction of inaccurate, incomplete, or outdated personal information.
- Request deletion of their personal information, subject to legal obligations to retain certain data (e.g., for tax or compliance purposes).
- Object to or restrict the processing of their personal information, where permitted under GDPR or the Privacy Act.
To exercise these rights, please contact our Privacy Officer (details below). We will respond within 30 days (or as required by law) and may charge a reasonable fee for processing complex requests, where permitted.
7. Data Retention
We retain personal information only for as long as necessary to fulfil the purposes for which it was collected, provide our services, or comply with legal obligations (e.g., tax or employment record-keeping requirements). When no longer required, personal information is securely deleted or anonymised in accordance with our data retention policies.
8. Third-Party Links
Our website may contain links to external sites. We are not responsible for the privacy practices of other websites and encourage you to review their policies.
9. Cookies and Analytics
Our website uses cookies and analytics tools to improve functionality and measure performance. You can manage cookie preferences via your browser settings.
10. Complaints
If you have a concern about how we handle your personal information, please contact our Privacy Officer. We will investigate and respond to complaints within 30 days, in accordance with the Privacy Act 1988 and, where applicable, GDPR. If you are not satisfied with our response, you may lodge a complaint with:
- Office of the Australian Information Commissioner (OAIC): www.oaic.gov.au
- EU Data Protection Authorities: For GDPR-related matters, the relevant supervisory authority in your country.
11. Contact Us
For questions, requests, or complaints about this Privacy Policy or our handling of personal information, please contact:
12. Changes to This Privacy Policy
We may update this Privacy Policy to reflect changes in our business operations, services, or legal obligations. The updated policy will be published on our website (vertruen.com.au), and where required, we will notify affected individuals of significant changes via email or other appropriate channels.
Last Updated: 28 May 2025
