CHANGE LOCATION?

It looks like you are located in United States.
Our nearest location is United Kingdom.
Take me there

Privacy & Personal Data Protection Policy

Background

In this privacy policy, “we”, “our” and “us” are references to Access 4 Pty Ltd and Access4 Limited.

 

For the purposes of this policy, “personal information” means personal information as defined in the Privacy Act 1988 (Aus Cth) and the Privacy Act 2020 (NZ) (the “Act”).  Essentially, this is any information that can reasonably be used to identify you as a natural person including but not limited to your name, email, contact details and financial information such as credit card details.

 

This Privacy Policy explains what information we may collect about you and how we use, hold and share that information.  We review our Privacy Policy regularly to ensure it is up-to-date so we encourage you to review it from time to time on our website.  Any updates to this policy become effective when they are published on our website. 

 

These updates may reflect changes in legal or regulatory requirements, our products, services or technology, or our business practices, and your continued use of our products and services after an update indicates acceptance of the updated policy.

 

If you would like a copy sent to you or you have any questions or concerns, please contact our Privacy Officer (details below) and we will provide you a copy free of charge.

By interacting with us, you agree that we can use information about you in accordance with this policy.

 

Some of our products and services are AI-enabled – that is, they use artificial intelligence, machine learning and automated processing to handle interactions and generate responses. This policy applies to personal information handled through those services in the same way as it applies to our other products and services.

 

Open and Transparent Management

We take our obligations under the Act, the Australian Privacy Principles, and the NZ Information Privacy Principles very seriously and have implemented practices, procedures and systems to ensure we comply with those laws.

We are committed to maintaining the confidentiality and security of your personal information and managing it in an open and transparent way.

 

Collection of Personal Information

Types of information collected.

In the process of conducting our businesses, we collect a broad range of personal information about our current and prospective customers, contractors, suppliers, agents, service providers, other business associates, the people associated with the businesses we deal with, current, past and prospective employees, users of our websites, subscribers and other stakeholders. This information can include:

  • Identifiers such as your name, company name, title, date of birth, contact details (such as your phone number(s) and email and mailing addresses)
  • Information about the products and services you have with us or our channel partners
  • Financial and credit information (including banking and payment information) and supporting documentation (including credit history details), identification and transaction history information, and personal references
  • User data, including contact numbers and call detail records
  • Website visitor data including access data and site usage information
  • If you are an employee – employment information and information about your educational background
  • Information about your interests, preferences, opinions or comments you have made to us
  • Other information about your identity including when your image is recorded on surveillance camera when you visit our offices.
  • Voice and call recordings and transcripts, the content of your messages, calls and enquiries, and related metadata such as call time, duration and interaction logs
  • Sensitive information (such as health information, biometric information or government identifiers) attracts additional protection under the Privacy Laws. We will only collect sensitive information where it is reasonably necessary for our functions or activities and either you have consented, or the collection is otherwise required or authorised by law. For example, we may hold health information about our employees for employment, work health and safety and insurance purposes.
  • Our AI-enabled services are not designed to collect sensitive information, payment card or financial account data, or information about children. We will only process such information through those services where the consents required by law have been obtained and we have approved the relevant use case in writing and any authorisations and safeguards required by us and our service providers are in place. Where such information is provided to us without the necessary consents, approvals or safeguards, we may remove or delete it, unless we are required to retain it by law.

 

How We Collect Personal Information

Our preference is to collect personal information from you directly and we will endeavour to do this unless it is unreasonable or impractical to do so. We collect personal information in a variety of ways including via our software applications, online enquiries you submit on our websites, over the telephone, social media, apps, through correspondence (whether by letter, fax or email), and on our forms when you enter into agreements and contracts with us.  We may also collect personal information from you when you attend our events.

 

We may also collect personal information from third parties including from credit reporting bodies, contractors, channel partners and other entities.

We may also collect information automatically through system logs and monitoring tools used to operate and secure our services, and from third-party systems, applications or integrations that our services are configured to access on your behalf or on behalf of a business we deal with (such as booking, CRM or practice-management systems).

 

Cookies

We may from time to time use cookies on our website.  “Cookies”, are small files that a website uses to identify a user when they come back to the site and to store details about their use of the site.   Cookies may collect and store personal information about you. 

 

Other Sources

We may also collect personal information from:

  • people with permission from you to give us your information
  • our channel partners and distributors
  • recruitment agencies, previous employers or referees
  • third party websites and social media platforms that collect and disclose information about you (including via the use of cookies and similar technologies) such as google
  • credit reporting bodies
  • service providers that work with us or help us provide products and services to you or identity and fraud checking services, or analytics and advertising related services
  • Related entities of Access4

 

Use or Disclosure of Personal Information

Why do we collect, hold, use or disclose personal information?

We collect, hold, use and disclose your information for the primary purpose of enabling us to carry out our business functions and activities which includes but is not limited to:

  • the provision of products or services to you (including the improvement of those products or services)
  • providing fault, fraud and maintenance notifications
  • communicating with you, managing your account and billing and delivering customer or technical support
  • verifying your identity
  • conducting checks and searches of your credit information to assess your credit rating from time to time
  • debt recovery including assigning a debt you owe us
  • communicating with you including via email, mail, telephone or SMS
  • personalising and customising your experience
  • managing, monitoring and enhancing our products and services
  • delivery, provision, installation or repair of hardware, accessories or service and maintenance of our products, systems and networks
  • promoting and marketing our products and services including updating you with news and information about our existing and new products and services
  • providing you with information about events, products or services that may interest you
  • developing products and services that may be of interest to you
  • communicating with you when you have previously expressed an interest in our products or services
  • managing our relationship with you
  • employment related purposes (eg. Verifying your work experience or undertaking criminal history checks)
  • facilitating our internal business operations
  • conducting internal investigations, including in relation to fraud and crime
  • investigating any complaints made by you
  • deriving insights about you and who you interact with to identify market segments, market products and services or carry out market research
  • use of cookies to monitor website visitor traffic patterns and site usage for improving our website design, layout and functionality
  • assessing the effectiveness of our marketing campaigns to optimise our marketing spend and to personalise our products, services and marketing messages
  • analysing audience ratings information and anonymous viewing and browsing data to understand how you and others engage with our products and services
  • handling and responding to your calls, messages and enquiries, and generating summaries, transcripts or structured records of those interactions
  • we may de-identify information about you to use and share with our channel partners.  This information may be combined with other demographic information or anonymous identifiers to develop aggregated insights to improve our products, services and offers to our customers
  • as otherwise required or permitted by law.

 

Automated Processing and AI-Enabled Services

Our AI-enabled services use machine learning and automated processing to generate responses and summaries. These systems operate probabilistically and may produce imperfect or incomplete outputs, and where enabled, they may take automated actions (such as making, altering or cancelling bookings or appointments). Such actions are generated automatically and may be inaccurate, incomplete or unintended.  Our AI-enabled services do not make legally binding decisions about individuals.

 

Use of Data for AI Training

We do not use data handled through our AI-enabled services to train or fine-tune general AI models outside the service environment in which it was collected. We may use de-identified, aggregated or schema-level data that does not identify any individual to improve system performance, configuration and accuracy, to produce aggregated analytics, and to detect systemic issues or misuse. No personal information is intentionally retained in training datasets used outside your service instance. Our upstream vendors do not use this data to train or improve their own AI models, except to the extent necessary to provide the services.

 

De-Identified and Aggregated Data

Notwithstanding the above, we may create and use de-identified, aggregated or schema-level data derived from customer usage and feature-adoption data that does not identify, and is not reasonably capable of identifying, any individual. We use such data to operate, support, secure and improve our products and services and to produce analytics, reporting and volume-based or other statistical insights. In particular, we may process this data to generate internal business insights and to identify product and service opportunities that we may share with our channel partners. This processing is carried out at an aggregate level only and is not used to profile, or to conduct direct marketing to, individual customers or end users.

 

Disclosure of Personal Information

From time to time we may disclose your personal information, in so far as it is necessary for the purposes set out in this policy, including to:  

  • Our service providers and channel partners who manage or deliver our services on behalf of, or to, end customers and technology and infrastructure providers (including cloud hosting and data processing providers) that help us operate and deliver our services.
  • Our analytics and advertising related organisations
  • Our debt recovery agents and credit reporting bodies
  • Other telecommunications companies (to administer number portability requests)
  • Our insurers
  • Professional advisers
  • Agents
  • Subcontractors
  • Companies who collect information and data from cookies and other similar technologies
  • Companies working with us to prevent or investigate unlawful activity (particularly fraud and identify theft)
  • Related entities of Access4.

 

We do not sell personal information.

 

We may also share your information: 

  • To comply with our legal obligations in response to warrants, subpoenas or similar lawful requests for this information
  • For the purpose of a transfer, sale or restructure of some or all of our assets or business
  • With government and regulatory authorities and law enforcement agencies as required or authorised by law
  • With the operator of the Australian Integrated Public Number Database to assist with the provision of directories, emergency services and safeguard national security
  • With directory providers when you elect to have your information disclosed to such organisations e.g. If you choose to have your number listed
  • With emergency call service centres and relevant emergency service organisations.

 

We may also use personal information to protect copyright, trademarks, legal rights, property or safety of Access4, its clients or third parties.

 

If there is a change of control in our business or a sale or transfer of business assets, we reserve the right to transfer to the extent permissible at law our user databases, together with any personal information and non-personal information contained in those databases. This information may be disclosed to a potential purchaser under an agreement to maintain confidentiality. We would seek to only disclose information in good faith and where required by any of the above circumstances.

 

By providing us with personal information, individuals consent to the terms of this Policy and the types of disclosure covered by this Policy. Where we disclose personal information to third parties, we will request that the third party follow this Policy regarding handling personal information.

 

Withdrawing your consent: Where we are relying on your consent to collect, use or disclose your personal information, you have the right to withdraw your consent at any time. You can do so by contacting our Privacy Officer using the contact details below, and we will effect the change within a reasonable time and without charge. However, withdrawing your consent will not affect the lawfulness of any processing carried out before its withdrawal, nor will it affect the processing of your personal information conducted in reliance on lawful grounds other than consent. Withdrawing your consent may also mean that we are unable to provide you with some or all of our products or services.

 

Direct Marketing

What is direct marketing?

For the purposes of this policy, “direct marketing” is the promotion and sale of goods and services directly to you including through emails, SMS, MMS, phone calls, social media, digital advertising and the post.

Where you have consented, or where otherwise permitted by law, we may use your personal information to send you – either directly or via one of our service providers – information and promotional material about us and our channel partners in relation to products or services they offer, by means of direct mail, email, SMS and MMS messaging and telephone. You can opt out of receiving direct marketing from us at any time (see clause 5.2 below).

 

 

No direct marketing.

We will not use or disclose your personal information for the purposes of direct marketing material if you have told us not to.

If at any time you do not want us (or one of our service providers) to send you direct marketing material or you wish to cancel a previous consent, then you can simply inform our Privacy Officer by contacting them (details below). We will effect the change in a reasonable time and without charge.

 

Cross-Border Disclosure of Personal Information

We may transfer, store, and provide access to your personal information across international locations to ensure the efficient delivery of our services and support global operations. In doing so, we adhere to applicable privacy laws and international best practices. We ensure that these international data transfers are conducted with appropriate safeguards in place, such as standard contractual clauses or other legally recognised mechanisms, to protect your personal information. Our commitment is to maintain the privacy and security of your data in line with legal and industry standards.

 

In particular, where you use our AI-enabled services, your data may be processed by our upstream vendors and their sub-processors (including third-party large language model and voice-processing providers) that are incorporated or operating in overseas jurisdictions, for the purpose of converting speech to text and text to speech and generating responses. Call transcripts and recordings are stored by us on servers we operate in Australia.  

 

Where personal information is processed outside Australia or New Zealand, we take reasonable steps to ensure overseas recipients handle it in accordance with the APPs and, in New Zealand, the IPPs (including through the data processing provisions of our agreements with those vendors), or we rely on a permitted exception under the applicable Act.

Individuals retain rights regarding their personal information, even when it is transferred or stored internationally. For inquiries or to exercise these rights, please contact our Privacy Officer using the contact information below.

 

Security of Personal Information

Protection.

We will take such steps as are reasonable in the circumstances to protect your personal information that we hold. 

 

In order to prevent unauthorised access or disclosure, we have put in place suitable physical, electronic and managerial procedures to safeguard and secure information and protect it from misuse, interference, loss and unauthorised access, modification and disclosure.

 

Depending on the relevant service, these measures may include: encryption of data transmitted over public networks using industry-standard protocols such as TLS and IPSEC, with strong cryptographic ciphers and minimum key-length enforcement; access controls including user authentication, role-based access control and multi-factor authentication (MFA); separation of data between partners and end users in our multi-tenanted platforms; logging and monitoring of system access; and regular security testing and reviews. Where we engage third-party providers, we require them to maintain appropriate security measures and to impose substantially equivalent obligations on their sub-processors.

 

As our website and online services are linked to the internet, and the internet is inherently insecure, we cannot provide any assurance regarding the security of transmission of information you communicate to us online. We also cannot guarantee that the information you supply will not be intercepted while being transmitted over the internet. Accordingly, any personal information or other information which you transmit to us online is transmitted at your own risk.

 

Destruction.

When we no longer need your personal information for a permitted purpose and we are not required to keep it to comply with any laws, we will take such steps as are reasonable in the circumstances to destroy your personal information or to ensure that the information is de-identified.  Individuals may request the erasure of their personal data where there is no compelling reason for its continued processing, unless required by law.

 

We retain personal information only for as long as necessary to provide our services, meet contractual requirements or comply with legal obligations. When a service ends, we delete or de-identify personal information within a reasonable timeframe unless retention is required by contract or law.

 

Complaints

If you have a query or concern in relation to this privacy policy or wish to make a complaint regarding a breach of privacy you may do so by contacting our Privacy Officer (details below). All complaints will be investigated and dealt with promptly and confidentially.

 

Access to Personal Information

Individuals may request details to personal data held about them and/or corrections to the personal information that we hold about them in accordance with the provisions of the Privacy Act 1988 (Aus Cth), or the Privacy Act 2020 (NZ).

 

This information will be provided within a reasonable time frame, free of charge.

If an individual would like a copy of the information, which we hold about them or believe that any information we hold on them is inaccurate, out of date, incomplete, irrelevant or misleading, please email the Privacy Officer using the contact details below.

We reserve the right to refuse to provide you with information that we hold, in certain circumstances set out in the Act.

 

Where your personal information has been handled by us on behalf of one of our partners or their customers, access and correction requests should be directed to that partner or customer in the first instance, or to us where appropriate.

 

Correction of personal information.

We will take reasonable steps to correct your personal information (at no charge) if it is inaccurate, out-of-date, incomplete, irrelevant or misleading. This extends to third parties that we have provided your personal information to unless it is impracticable or unlawful to do so.

 

Circumstances when we decline to make corrections.

In certain circumstances we may decline a request from you to correct your personal information. When this occurs we will:

  • provide you with a written notice that sets out:
  • the reasons for the refusal and
  • the mechanisms available to complain about the refusal;
  • take reasonable steps to note on your personal information that you requested the correction.

 

Third-Party Sites

Our site may from time to time have links to other websites not owned or controlled by us. These links are meant for individual convenience only. Links to third-party websites do not constitute sponsorship or endorsement or approval of these websites. Please be aware that Access4 is not responsible for the privacy practices of other such websites. We encourage our users to be aware, when they leave our website, to read the privacy statements of each and every website that collects personally identifiable information.

 

Breaches

In Australia, it is a requirement of the Privacy Act 1988 Notifiable Data Breaches (NDB) Scheme that when an organisation or agency the Privacy Act 1988 covers has reasonable grounds to believe an eligible data breach has occurred, they must promptly notify any individual at risk of serious harm. They must also notify the Office of the Australian Information Commissioner (OAIC).

 

Similarly, in New Zealand under the Privacy Act 2020, if we have a privacy breach that either has caused or is likely to cause anyone serious harm, we must notify the Privacy Commissioner and any affected people as soon as we are practically able.

 

Our notifications to affected individuals and regulators will include the information required under the applicable scheme, including a description of the breach, the kinds of information involved, and the steps affected individuals can take in response. Where direct notification to affected individuals is not practicable, we will publish a statement on our website in accordance with the applicable scheme.

 

Breaches must be handled in accordance with the Access4 Personal Data Breach Notification Procedure (MP-IS-07).

 

Our Obligations as a Cloud Service Provider

In addition to holding personal data on our own account, Access4 also stores and processes personal data for our cloud clients. Our role may vary depending on the specific circumstances and jurisdiction. In cases where we handle personal data on behalf of our clients:

 

  • Any request or inquiry we receive about personal data that we store or process for our cloud clients will be forwarded to the relevant client for them to address, unless otherwise required by applicable law.

 

Privacy Officer Contact

Privacy Officer
Access 4 Pty Ltd
Building 1,
Level 4/658 Church St
Richmond VIC 3121
Email to: privacy@access4.com