This Privacy Policy explains how Sandfire Consulting (we, us, our) collects, uses, holds and discloses personal information. It applies to your interactions with sfcg.au (the Website), our advisory engagements, and related communications. We are bound by the Privacy Act 1988 (Cth) (Privacy Act) and the Australian Privacy Principles (APPs).
This Policy applies to personal information about individuals collected by Sandfire Consulting in the course of operating its business, including through the Website, in advisory engagements, and through our professional and commercial relationships, whether collected in writing, by phone, electronically or in person. "Personal information" and "sensitive information" have the meanings given in the Privacy Act.
We collect personal information reasonably necessary for our functions and activities, including:
We collect personal information directly from you when you contact us, submit the Website form, engage us, or otherwise communicate with us. We may also collect it from third parties authorised by you (such as your advisers) and from publicly available sources relevant to an engagement. Where information is collected indirectly, we take reasonable steps consistent with APP 5.
We collect, hold, use and disclose personal information to provide advisory services; respond to enquiries; manage our engagements, billing and administration; comply with applicable laws and lawful requests; and communicate with clients, prospects and professional contacts about matters relevant to our services.
We do not generally collect sensitive information. Where sensitive information is incidentally provided through documents you submit, we treat it as sensitive information and handle it with additional care, including limited internal access, secure storage and restricted disclosure.
We do not sell personal information. We may share it, only to the extent permitted by law and where reasonably necessary, with professional advisers engaged by or with you; our related entities, including our associated law practice, each bound by equivalent confidentiality obligations; our service providers (such as IT, cloud and document-storage providers); and government bodies or other third parties where required or authorised by law.
Some service providers we use may store data on servers outside Australia. Where we disclose personal information to overseas recipients, we take reasonable steps to ensure they handle it consistently with the APPs. By using the Website or providing personal information to us, you consent to this disclosure on the terms of this Policy.
We hold personal information in electronic and, where relevant, physical form, and take reasonable steps to protect it from misuse, interference, loss and unauthorised access, modification or disclosure. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
You may request access to, or correction of, the personal information we hold about you by contacting us using the details below. We will respond within a reasonable period and may need to verify your identity. Where we decline access or correction, we will give you reasons as required by the APPs.
If you believe we have breached the APPs, please contact us and we will investigate and respond. If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (oaic.gov.au).
Privacy enquiries can be directed by post to 278 Barker Road, Subiaco WA 6008, or through our contact page.