What we collect, why we collect it, who it goes to, and how to get it back or have it corrected. Written to align with the Australian Privacy Principles.
This policy explains how Advit Pty Ltd (ACN 682 221 638, ABN 37 682 221 638), trading as Averro Technologies (Averro, we, us), handles personal information. It applies to this website, to enquiries you make, and to our dealings with clients, suppliers, applicants and contractors.
Advit Pty Ltd is the entity responsible for the personal information described here. Averro Technologies is the registered business name it trades under.
Personal information has the meaning given in the Privacy Act 1988 (Cth): information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether or not it is true and whether or not it is recorded in a material form.
A business with an annual turnover of $3 million or less is generally not an APP entity under s 6D of the Privacy Act 1988 (Cth), and several exceptions to that exemption can apply — including where a business provides services under a Commonwealth contract, or discloses personal information for a benefit.
We do not rely on the small-business exemption. This policy is written to the Australian Privacy Principles and we hold ourselves to them, because we hold other organisations’ data and an exemption is a poor answer to a client asking how their customers’ information is handled. Where an exception means the Act binds us outright, it binds us; where it does not, this policy does.
There is an important distinction in this policy.
Information we collect about you — your enquiry, your contact details, your dealings with us — is handled as described in clauses 2 to 9.
Information we handle on a client’s behalf, inside systems we manage for them, is different. There the client decides what is collected and why; we act on their instructions under a services agreement. Clause 10 covers that, and if you are a customer or employee of one of our clients it is the clause that concerns you.
You can deal with us anonymously or under a pseudonym where it is lawful and practicable — for example, to ask a general question. It is not practicable where we need to deliver a service, invoice you, or verify who is authorised to instruct us about a system.
We collect personal information only where it is reasonably necessary for our functions and activities. Specifically:
If we ever want to use your information for a purpose other than the one we collected it for, and that purpose is not one you would reasonably expect, we will ask you first.
We do not run a marketing list, a newsletter or an automated nurture sequence, and submitting an enquiry does not subscribe you to anything. If that changes, any commercial message will identify us, will include a working unsubscribe, and will comply with the Spam Act 2003 (Cth). You can tell us to stop contacting you at any time and we will.
This website does not set advertising cookies, does not run third-party analytics, and does not embed social-media tracking pixels or share buttons that phone home.
The site loads two web fonts from Google Fonts. Requesting those files sends your IP address and user-agent to Google as part of an ordinary HTTP request; Google states it does not use Google Fonts requests to build advertising profiles. No other third-party host is contacted.
Everything else on the site — stylesheets, scripts, images, illustrations — is served from our own domain.
Because there is no tracking to consent to, there is no cookie banner. That is deliberate. If we ever introduce analytics we will say so here and add a genuine choice, not a pre-ticked box.
We do not sell personal information, and we do not disclose it for another organisation’s marketing.
We disclose personal information only to:
We require our service providers to protect personal information to a standard consistent with this policy and the Australian Privacy Principles.
Some of the services we use to run our business are provided by organisations that store or process data outside Australia — most commonly in the United States, and in cloud regions operated by Amazon Web Services, Microsoft and Google.
Before we use such a provider we take reasonable steps to satisfy ourselves that it handles personal information in a way consistent with the Australian Privacy Principles, as APP 8 requires. Where we have a choice of region for data we control, we choose an Australian region.
The specific providers and countries in use are listed on request. Email us and we will tell you rather than publish a list that goes stale.
We take reasonable steps to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure. In practice that means:
No system is perfectly secure, and any organisation that tells you otherwise is selling something. What we commit to is a defensible standard, applied consistently, and told to you honestly if it fails.
If we suspect unauthorised access to, or disclosure or loss of, personal information we hold, we contain it, assess it promptly, and act on the assessment.
Where a breach is likely to result in serious harm to any individual, we will notify the affected individuals and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act 1988 (Cth).
Where a breach affects information we hold on a client’s behalf, we notify that client immediately and assist them to meet their own obligations. The decision to notify individuals in that case is theirs, as the entity with the relationship.
If you believe your information held by us has been compromised, tell us at contactus@averrotech.com and we will treat it as an incident, not a query.
We keep personal information only as long as we need it for the purpose we collected it, or as long as the law requires.
When information is no longer needed and we are not required to retain it, we destroy it or de-identify it.
When Averro manages systems for a client, we necessarily come into contact with personal information belonging to that client’s staff, customers and suppliers — mailboxes, directories, CRM records, backups, log files.
If you are a customer or employee of one of our clients and you want access to your information, or want it corrected or deleted, please contact that organisation directly. They hold the relationship and the authority to decide. If you contact us we will refer you to them; we will not act on your request without their instruction, because doing so would itself be a privacy failure.
You may ask us what personal information we hold about you, and ask for a copy. You may also ask us to correct anything that is inaccurate, out of date, incomplete, irrelevant or misleading, and to delete information we no longer need.
Email contactus@averrotech.com. We may need to verify your identity first, proportionately to the sensitivity of what is being requested.
We aim to respond within 30 days. There is no charge for making a request. If a request is complex and we need to recover a meaningful cost of providing access, we will tell you the amount before we do the work.
If we refuse a request — for example because giving access would unreasonably affect another person’s privacy, or because we are required by law to retain the information — we will tell you in writing, with our reasons and how to complain.
If you think we have mishandled your personal information or breached the Australian Privacy Principles, tell us first. Email contactus@averrotech.com with “Privacy complaint” in the subject line and enough detail for us to investigate.
We will acknowledge your complaint promptly, investigate it, and give you a written response within 30 days, including what we found and what we are doing about it.
You can escalate to the Office of the Australian Information Commissioner (OAIC), which is independent of us:
Web: oaic.gov.au · Phone: 1300 363 992 · Post: GPO Box 5288, Sydney NSW 2001
You do not need our permission to complain to the OAIC, and complaining to us first does not limit your rights.
We review this policy at least annually and update it when our practices change. The current version is always the one published here, and the date at the top records when it last changed.
Where a change is material, we will make that clear on this page rather than relying on the date alone. Where a change materially affects how we handle information we already hold about you, and the change is not one you would reasonably expect, we will seek your consent.
A copy of this policy is available free of charge in an alternative format on request, as APP 1.5 requires.