Directioneering maintains the highest ethical and professional standards. We comply with The Privacy Act 1988 (Cth) (Privacy Act), which sets out a number of principles that private sector organisations must comply with in the open and transparent collection, storage, use and disclosure of personal information. These principles are known as the Australian Privacy Principles.
This privacy policy details how we collect personal information and how we use, store and disclose that information.
Personal information is information or an opinion (including information forming part of a database), whether true or not, and whether recorded in material form or not, about an individual whose identity is reasonably apparent, or can be reasonably ascertained, from the information or opinion.
We only collect personal information in order to properly and efficiently carry out the services for which we are engaged by our clients, who may be either your current or former employer.
If you choose not to provide the personal information we need, we may not be able to provide the requested product or service.
The types of personal information we may collect include:
This information may be collected by way of forms filled out by individuals, emails, telephone conversations, face-to-face meetings, virtual meetings and interviews conducted by us.
In some situations, we may supplement the information we receive from you with information from third parties, such as Our Client. Regardless of the source, we respect and protect the privacy of all personal information we collect.
If you provide information to us about another person, then you are responsible for telling the other person that you have provided information about them to us. You should tell them who we are, that they may access their personal information, and you may also wish to refer them to this Privacy Policy.
Sensitive information is a subset of personal information which is given a higher level of protection under the Australian Privacy Principles. It includes things like health information, and information about an individual’s political opinion, membership of a professional or trade association, political beliefs and racial or ethnic origin.
In most cases, we will not require any sensitive information from you in order to provide our services. However, Directioneering may collect your sensitive information where it is directly related to or is reasonably necessary to carry out the services for which we are engaged by Our Clients. If we do collect sensitive information about you, for example health information, we will do so in accordance with the Australian Privacy Principles.
We may use your personal information for the following purposes:
To the extent that we receive information that gives us any concerns regarding ethical or conflict of interest issues, we may provide your personal information to Our Client for the purpose of reporting these concerns, after first obtaining your approval where possible.
We may disclose information about you to other service providers and third parties that carry out activities on our behalf, for example our external consultants who provide expert advice on research, financial management, small business development etc, or an external party who collects survey information in which you participate. We impose security and confidentiality requirements on how they handle personal information. They are not permitted to use personal information about you for any purpose except the functions we have asked them to perform as our representatives.
We may disclose your name in group workshops, face-to-face or virtual group meetings, or on group webinars that you attend. If you are uncomfortable with that, please let your consultant or one of our staff know and we will arrange for anonymity where possible.
We may disclose information about you to Our Client to satisfy any reporting requirements we may have in place with them, including in relation to a career or executive coaching service or career transition service, or so that we and/or Our Client can comply with our duties under work health and safety legislation.
In the event we collect sensitive information from you, we will usually seek your further express consent prior to disclosing this sensitive information to Our Client or to any other third parties, unless an exception under the Australian Privacy Principles applies.
We may also disclose your personal information (including sensitive information) where disclosure is necessary to prevent a threat to life, health or safety.
Other than as set out above, we will not disclose information about you to a third party unless the disclosure is required or authorised by law or a court/tribunal order, or you have consented to our disclosing the information about you.
We do not sell or license your personal information to third parties for direct marketing.
In certain circumstances, such as if you are undergoing an Expatriation program or are planning to work overseas, we may disclose personal information to overseas recipients located in the country of your choice.
We take reasonable steps to protect your personal information from misuse, interference and loss, as well as unauthorised access, modification or disclosure. All of the personal information held by us is stored on secure systems, with protections including SSL security, Penetration testing, Password-protected access and Authentication and Authorisation protocols in place.
Access to personal information is limited to the employees, contractors and consultants who specifically need it to conduct their business responsibilities. We also maintain physical security procedures to manage and protect the use and storage of paper records containing personal information. Staff who handle personal information are educated about and act in accordance with the requirements of the Australian Privacy Principles and the Privacy Act.
Some of the information we hold is on our cloud-based SAS business system, Momentum. This data is ultimately stored on Microsoft Azure servers in the USA. Microsoft Azure has SOC 2 attestation plus a range of other data security certifications.
We will take reasonable steps to ensure that the personal information we collect, use or disclose is accurate, complete and up-to-date. However, we rely on the accuracy of the personal information provided to us both directly and indirectly.
You have a right to request access to, and correction of, any personal information we hold about you. You can do this by making a request:
In writing: Chief Operating Officer
Directioneering Pty Ltd
Level 17, 330 Collins Street
Melbourne, Victoria, 3000
By email: paul.ward@directioneering.com
By phone: (03) 9691 7900
If you think that we have breached this privacy policy or the Privacy Act, or wish to make a complaint about the way we have handled your personal information, please contact us at the address listed above.
We will acknowledge your complaint and respond to you regarding your complaint within a reasonable period of time. If you think that we have failed to resolve the complaint satisfactorily, you can contact the Australian Information Commissioner via the website located at www.oaic.gov.au, or by telephoning 1300 363 992.
Our Organisation may amend this Privacy Policy from time to time by publishing changes to it on our website. We encourage you to check our website periodically to ensure that you are aware of our current privacy policy.