Privacy Policy

 

Updated: April 2026

Overview

This privacy policy (Policy) sets out how Quartex Software Pty Ltd ABN 50 162 477 965 (Quartex, or we, our, us) collects and treats your personal information. We supply hosted commercial application services and related products and services for workforce management, health & safety, governance, risk & compliance, and disclosure.

We respect your right to privacy and are committed to safeguarding the privacy of our customers and users in accordance with applicable data protection laws globally. We process your personal information in accordance with applicable laws which may include, depending on your location, the Privacy Act 1988 (Cth) in Australia, New Zealand’s Privacy Act 2020, the EU and UK General Data Protection Regulation (GDPR), Brazil’s Lei Geral de Protecao de Dados (LGPD), Switzerland’s Federal Act on Data Protection (FADP), Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA) and Quebec’s Act Respecting the Protection of Personal Information in the Private Sector (Law 25), as well as relevant US State privacy laws, to the extent applicable (Applicable Law).

What is personal information?

When we refer to “personal information”, we mean any information or opinion about an identified or reasonably identifiable individual. This includes information that, either alone or in combination with other information, can be used to identify a natural person directly or indirectly. For residents of the European Economic Area, the UK, and other jurisdictions where “personal data” is defined by Applicable Law, the term “personal information” is intended to have the same meaning as “personal data” (or equivalent terms) in the Applicable Law.

What personal information we collect and hold generally

The types of personal information we collect depends on the nature of our engagement with you. Examples of personal information we may collect include names, addresses (including email addresses and physical work addresses) and other contact details and work-related information (such as employer name and role/position).

We may collect additional information at other times, including when you apply for employment, provide feedback, when you provide information about your personal, employment or business affairs, change your content or email preference, respond to surveys and/or promotions or provide financial or credit card information.

What personal information we collect and hold if you create a profile in our application services

If you (or someone on your behalf) creates a user profile in our application services, we collect certain core profile data which may include your full name, salutation, date of birth, address, gender, employer and job details, contact details and certain other data fields as described on the Customer Hub (“Core Profile Data”). Core Profile Data is managed by us in accordance with this Policy.

Our customers may also input personal information into our application services or ask you to upload additional personal information into our application services. This could include information such as evidence of identification or licensing, training and certification data (“Customer Data”). This data is collected and processed by and on behalf of the relevant customer (who acts as a “controller” of that data) and is handled by us in accordance with our agreements with that customer.

Why do we collect, hold and use your personal information generally?

We collect, hold and use your personal information so that we can:

  1. verify your identity;
  2. provide you and our customers (for example, if your employer is our customer or does business with one of our customers) with products and services, including support, and manage our relationship with you, your employer or our customer;
  3. verify or manage your compliance with any agreements between us;
  4. contact you, for example, to respond to your enquiries or complaints, or if we need to tell you something important, e.g. about products and services you consume or your relationship with us;
  5. help improve our products and services;
  6. process job and other applications received from you; and
  7. comply with our legal obligations, including verification and reporting obligations under Applicable Law, and to assist government and law enforcement agencies or regulators, subject to Applicable Law.

If you do not provide us with your personal information, we may not be able to communicate with you or respond to your enquiries.

Why do we collect, hold and use your personal information when you create a profile in our application services?

We collect and hold Core Profile Data to create and manage universal user profiles across multiple products and customers, enabling identity-based functions across the platform (such as login, authentication, account and information linking, profile continuity and displaying user identity details to our customers). We do not use Customer Data in this way, only Core Profile Data.

We also use Core Profile Data to help us improve our services. When we use it for this purpose, we de-identify and aggregate that personal information with other data, to provide a statistical analysis.

We collect and hold Customer Data only to provide products and services to the customer using the product or service, and to fulfil our agreements with them.

If you do not provide us with your personal information as required to complete any mandatory Core Profile Data fields, or if you don’t allow us to use your Core Profile Data as intended, you may not be able to use or create a profile in the application services and customers may not be able to associate with you via the application services.

Controller vs Processor

Where we process Customer Data on behalf of our customers who use our products and services, and that data contains personal information, then we are acting as a “data processor” (or service provider) and our customer is the “data controller” (or customer business). Our processing of Customer Data is governed by our agreement with the customer, including any data processing agreement (if required by Applicable Law).

Where we process personal information in other circumstances, we are the “data controller” and process the personal information in accordance with this Policy. This includes where:

  1. we engage with you outside the context of our products and services;
  2. we collect and manage any Core Profile Data; and
  3. you use our products on behalf of our customer (e.g. you use our application services on behalf of your employer). In that situation, we may collect metadata relating to your use of our products such as which Customer Data you upload, when you log in and other product usage metadata, and any information you share when you request product support.

For the purposes of the Australian Privacy Act 1988 (Cth), the provisions in this Policy regarding storage, security, disclosure, and breach response apply to all personal information we hold, even if it is part of Customer Data, subject to the contract we have agreed with our customer concerning that Customer Data.

Lawful Basis

Where we process Customer Data, our customer determines the lawful basis for that processing and we process it in accordance with our agreement with the customer (including any data processing agreement).

Where we process your personal information as “data controller” (including where we process any Core Profile Data), we use and process it on one or more of the following bases:

  1. to perform our contract with you, if any;
  2. to comply with legal obligations;
  3. to pursue our legitimate interests in operating and improving our services (unless those interests are overridden by your rights);
  4. with your consent, where we rely on it (e.g. for marketing); or
  5. to protect vital interests where necessary.

Sensitive Data

We do not generally collect sensitive or special category personal data as a controller.

However, our products and services may be used by customers to process Customer Data that includes special category data or sensitive data. In those situations, we act as a data processor only. We process that Customer Data subject to our customers’ instructions and agreements with them. Our customers determine the lawful basis for processing the data.

How do we collect your personal information?

We collect personal information from you in a variety of ways, including:

  1. when you create (or someone else creates, on your behalf) a user profile in our application services;
  2. when you interact with us electronically (e.g. via email or completing a form on our website), over the phone or in person;
  3. when you access our website or use our products or services;
  4. when we provide our products or services to you (or your employer or another organisation that supplies your data to us as part of their use of our products and services); and
  5. from your employer or third parties if they provide us with your personal information.

Generally, we collect personal information from you directly. However, in some cases we may collect your personal information from a third party. We may collect your personal information from, e.g.:

  1. your employer, if your employer creates a user profile on your behalf in our application services; or
  2. your relative or other associate if a person creates a user profile in our application services and nominates you as their next of kin or emergency contact.

Online Interactions

Website

We may collect information about how you access, use and interact with our website and online application services, our support site and our online chat facilities via our website, including by using a range of third-party tools such as Google Analytics, Google Ads (for remarketing), Pendo.io (for internal usage analytics) and other web analytic tools. This includes the use of third-party cookies and similar technologies to provide website or application services functionality, analyse usage, show personalised advertisements to you on third-party websites across the internet, and improve your experience or website speed.

The information we collect may include your geographical region, IP address, device type, browser version, time zone, and page interactions (e.g. scrolls, clicks and search terms).

You can choose to save your name and email address in cookies for your convenience, so you don’t have to fill out your details again when you return to the website.

You can also manage or refuse cookies through your browser settings or modify your Google Ad settings (http://www.google.com/settings/ads). Where required by law, we only set non-essential cookies with your consent. However, note that disabling cookies may limit website functionality, and that some tools like Google Analytics and Pendo.io can still collect data without using cookies.

Google reCAPTCHA

We use third-party security services (e.g. Google reCAPTCHA) to help some login processes to distinguish genuine users from bots and protect against automated abuse. They collect data on user interactions, e.g. mouse movements, device IP address, date and time of access, device type, operating system, browser information and location (city). This data is stored on third-party servers which may be overseas.

Devices

A limited number of our services integrate with connected telematics devices (where our customer has chosen to use such a service and devices). These devices collect vehicle/asset geolocation information and operational data (e.g. speed, stop/idle events), which may also relate to the location of a person (e.g. the driver). If such data collection is disabled, the performance of our services will be limited.

How do we store personal information?

We store most personal information about you in computer systems and databases operated by either us or our external service providers.

We implement and maintain processes and security measures designed to protect personal information we hold from misuse, interference, or loss, and from unauthorised access, modification or disclosure. These processes and systems include:

  1. the use of identity and access management technologies to control access to systems on which personal information is processed and stored;
  2. requiring all employees to comply with internal personal information security policies and keep personal information secure; and
  3. ensuring only personnel who need access to perform their duties, have access, and have signed agreements binding them to comply with our relevant policies.

We will also take reasonable steps to securely destroy or de-identify personal information once we no longer require it for the purposes for which it was collected, for any secondary purpose permitted under Applicable Law, as otherwise required or permitted by Applicable Law or as required for legitimate business needs (e.g. to maintain business records, enforce agreements or to initiate or manage disputes and legal claims). When determining how long to retain data, we consider factors such as the nature of the information, the purposes of processing, legal or regulatory requirements under Applicable Law, and our need to maintain records to resolve disputes or enforce agreements.

Core Profile Data is retained while your user profile in our application services is active, until you request that we close your account and remove it, or if our periodic review shows that it has been inactive for a sustained period. Where this occurs, we will notify you (where reasonably practicable) and delete or de-identify your Core Profile Data within a reasonable period, unless we are required or permitted to retain it under Applicable Law or for legitimate business purposes.

Customer Data is processed on behalf of customers and is therefore subject to the retention and deletion arrangements agreed with the customer. While retention periods may vary depending on the product, deployment model and customer configuration, Customer Data will generally be deleted 120 days after our agreement with the relevant customer ends. We may retain Customer Data for longer where required or permitted under Applicable Law or for legitimate business purposes (for example, in backups, or for audit, compliance and dispute resolution purposes).

Who do we disclose your personal information to, and why?

We may disclose personal information for the purposes described in this Policy:

  1. to our employees and related bodies corporate;
  2. to third party suppliers and service providers (including providers for the operation of our website, business, products, and providers of legal, technology, accounting and audit services), where we do so in the normal course of our business;
  3. to our existing or potential agents, business partners or professional advisors;
  4. where we are required or authorised by Applicable Law to do so; or
  5. where you have consented to the disclosure or the consent may be reasonably inferred from the circumstances (for example, where you accept an invitation from a customer via our application services to register an account or associate with that customer).

If there is or will be a change of control in our business or a sale or transfer of business assets, we may transfer (to the extent permissible by Applicable Law) our data and databases, including all personal information and Customer Data contained in them, to a potential purchaser subject to an agreement to maintain confidentiality. We would only disclose information in good faith and where required by any of the above circumstances.

Overseas recipients of personal information

For Customer Data and Core Profile Data (including any personal information contained in that data), we store and process data in the locations and using the sub-processors listed in the Customer Hub, and ensure that cross-border transfers occur under a lawful mechanism under Applicable Law. These may include service providers located in Australia, the United States, and other jurisdictions in which our cloud hosting and infrastructure providers operate.

For all other personal information, we store information in Australia and may disclose your personal information to recipients located outside Australia or your country of residence, including in the United States.

We may process personal information in or transfer personal information to countries outside your country of residence, including locations where our group companies, service providers, or cloud hosting partners operate. Where we do so, we ensure that appropriate safeguards are in place to protect the information, such as adequacy decisions issued by relevant authorities or the use of Standard Contractual Clauses approved by the relevant authorities. Copies or details of these safeguards are available on request by contacting us. When we process personal information as a “data processor”, for example, as part of our processing of data provided by customers who use our products and services, our transfer of personal information is governed by our agreement, including any applicable data processing agreement, with the customer.

Do we use your personal information for marketing?

We will use your personal information to offer you products and services we believe may interest you, as well as newsletters, surveys, information about offers and events, and product improvements, where permitted by law or with your consent. You can opt out of receiving marketing communications at any time by following the relevant unsubscribe instructions or by contacting us. These products and services may be offered by us and other Quartex Group companies listed on the Customer Hub.

Where you receive electronic marketing communications from us, you may opt out of receiving further marketing communications by following the opt-out instructions provided in the communication or by contacting us (see below). We also work with Google AdWords, Google Display Network, LinkedIn, X and other advertising networks to display our ads on other websites and track the effectiveness of our marketing efforts. You can opt out of this by contacting us at legal@quartexsoftware.com.

Your Rights

Depending on your location and Applicable Law, you may have the following rights in relation to your personal information:

  1. to access and obtain a copy of your personal data;
  2. to request correction or update of inaccurate or incomplete data;
  3. to request deletion of your personal data where it is no longer needed or where required by law;
  4. to restrict or object to certain processing, including direct marketing;
  5. to request transfer of your personal data to another organisation (data portability);
  6. to withdraw consent at any time where we rely on consent as the lawful basis; and
  7. to obtain information about how we collect, use, and disclose your personal information, including the third parties with whom it is shared.

To exercise these rights, please contact us using the details below. We will respond as required by Applicable Law. You may also have the right to lodge a complaint with your local data protection authority.

Security and data breaches

We apply technical and organisational measures to protect personal information against unauthorised access, loss, misuse, or alteration. These measures include access controls, encryption, secure storage, and regular security reviews. For Customer Data and Core Profile Data, please refer to the Customer Hub for more detail on how we manage data security.

If we become aware of a data breach involving personal information, we will investigate and notify affected individuals and regulators as required by Applicable Law.

If a data breach affects Customer Data, we’ll comply with our agreement with the customer and Applicable Law.

How do you make a complaint?

If you have a complaint about the way in which we have handled any privacy issue, including your request for access or correction of your personal information, you should contact us by emailing us at legal@quartexsoftware.com.

We will consider your complaint and determine whether it requires further investigation. We will notify you of the outcome of this investigation and any subsequent internal investigation.

If you are not satisfied we have handled a privacy issue, you may approach an independent advisor, contact the Office of the Australian Information Commissioner or contact a local data protection authority for guidance on alternative courses of action which may be available.

Contact details

To contact us in relation to this privacy policy, make an enquiry or complaint, or exercise any of your privacy rights under Applicable Law, please use the following addresses with attention to our Head of Legal:

Post: PO Box 239, West Perth 6872, Western Australia
Phone: +61 8 6373 2900
Email: privacy@quartexsoftware.com

We may take steps to verify your identity before responding.

Changes to this Policy

We may modify this Policy at any time, in our sole discretion and all modifications will be effective immediately upon posting of the modifications on our website. Please check back from time to time to review our current Privacy Policy.

You may obtain a copy of our current policy from our website or by contacting us at the contact details above.

US Addendum

Residents of certain US states (including California, Colorado, Connecticut, Utah, and Virginia) have additional rights regarding their personal information. These may include the right to:

  1. know what categories of personal information we collect, use, and disclose;
  2. request access to or deletion of your personal information;
  3. request correction of inaccurate information; and
  4. opt out of the sale or sharing of personal information for targeted advertising.

We do not sell personal information as that term is defined under US state laws. To exercise any applicable rights, please contact us using the details below.

It’s time to run every site right

Only Quartex makes this all possible

Get in touch
run
every
site
right
icon