Privacy Policy

A committment to protecting your privacy.

Last updated 01 March 2026

Written by
Name Surname
Position, Company name

Part 1 - Personal Information

Why do we collect personal information?

We will collect personal information in the process of conducting business. That information may be collected directly from individuals, or through a third party that has engaged us to provide services (a “Discloser”)who may or may not be under obligation to inform you beforehand. We will only store information if it is relevant to you (or the Discloser) doing business with us.

In some cases, Disclosers may provide us access to systems that hold information that is deemed by state or Australian Federal privacy legislation to be sensitive information or health information (“Sensitive Information”). We don't collect (as defined in legislation) this information, although it may reside on systems we support. Please see Part 2- Sensitive Information of this policy, which describes how we handle this information.

What information do we collect?

The personal information we collect and use depends on the context of our engagement. It is usually limited to individuals’ names, email addresses, phone numbers and addresses so we can communicate and deliver our services to organisations which engage us for software development and support services, or in the case of "Employment Information”, so we can employ them.

How do we collect the information?

We will only collect personal information directly from individuals or as disclosed to us lawfully by a Discloser when we work with them.

How do we use personal information?

We will only use your personal information for the primary purpose for which it was collected.

You may provide your personal information when you engage us for software development and support services, to contact you. We may subsequently use limited personal information such as your name or email address or phone number to market our services to you in accordance with our Ethical Marketing Policy which is on our website. You may opt out of such marketing activities at any time via unsubscribe functionality within such emails or by contacting our Privacy Officer on (03) 9691 0500.

In the case of Employment Information, this is so we may lawfully employ you and communicate with you. Our recruitment process requires that we obtain one or more local and national criminal background checks about prospective and current staff; these are deleted or destroyed after being assessed by our People and Culture team. We will store resumes submitted to us securely and keep them private and accessible on a strict need-to-know basis.

How do we store personal information?

Your personal information is held mainly in electronic records and rarely on paper. We take all reasonable steps to protect personal information we hold from misuse and loss and from unauthorised access, modification or disclosure. We utilise cloud-based services (such as hosted email, productivity applications, development and backup platforms) to efficiently provide our services. If this results in personal information being transferred to locations outside of Australia, we will ensure that is stored in a location that has equivalent privacy, physical and logical protections as if it was stored in Australia.

We will also take reasonable steps to destroy or permanently de-identify personal information when it is no longer needed for the purpose we collected it.

When do we disclose personal information?

We do not normally disclose personal information but from time to time, to deliver the services, we may disclose limited personal information to trusted organisations we deal with (eg. your contact details). We take all reasonable steps to ensure that these organisations are bound by confidentiality and the privacy obligations in relation to the protection of your personal information.

If, as an employee or contractor, you disclose Sensitive Information to us (for instance about allergies or medical conditions), then we will only disclose relevant information to emergency personnel in the event of an emergency.

Access to your personal information

You have a right to access and have us update your personal information, subject to some exceptions allowed by law. If you would like to access your personal information, please contact our Privacy Officer on (03) 9691 0500. You may be required to put your request in writing for security reasons.

Our website

Our website may use cookies which contain small amounts of information about your visit to our website. These cookies help us track traffic patterns to our website and do not contain any personal or private information about you. If you submit a request for us to contact you, you have control over the personal information you may choose to share.

Part 2 - Handling Sensitive Information

Aside from collecting relevant Sensitive Information that employees share with us to assist us manage their health or safety, Kiandra does not collect Sensitive Information.

There are situations where a provider of health services (including public health departments and agencies and private health service providers) may indirectly make available to us Sensitive Information collected by them – for example, granting us access to their systems so that we can develop or support software for that provider.

In most cases we don’t have access to systems with Sensitive Information; we usually work with test or de-identified data. Where it is not feasible to work with de-identified data, we implement isolation controls to restrict access to it by our staff and contractors on a strict need-to-know basis.

How do we handle Sensitive Information?

Where personal information or Sensitive Information is made accessible to us by a Discloser, we will not unnecessarily view, access, copy, store or use it for any purpose other than what is strictly required for us to deliver relevant services to that provider.

The handling requirements for Sensitive Information are detailed in our internal policy “Working with Client Data” and there are consequences for misuse or non-compliance - up to and including termination of employment or engagement, in addition to civil and criminal liabilities under various legislation.

How do we store Sensitive Information?

We will store Sensitive Information according to the explicit instructions of the Discloser. We will never move, nor allow access to, Sensitive Information out of Australia. We will take all reasonable steps to destroy or permanently de-identify Sensitive Information when we no longer need it.

When do we disclose Sensitive Information?

We will not disclose Sensitive Information to anyone other than to the original discloser without their consent, except where we reasonably believe the disclosure is necessary to lessen or prevent a serious threat to the life, health or safety of any individual, or to public health or safety.

If you have any questions regarding our privacy policy and information handling please contact the Kiandra team.