Introduction
This privacy policy pertains to the information stored in our Client Portal system that we maintain on behalf of our customer, being the company (the subscriber) who has taken a subscription to the Online Services.
What information do we store about your staff and clients?
The Client Portal is all about information relating to the clients of the subscriber, the representatives of those clients and may contain sensitive information. The application will store primarily information about those clients which is sourced from connected systems amended with some corrections and workflow related data.
The system stores minimal information about staff of the subscriber and only that what is required for the operation of the system and is generally limited to first and last name, display name, email address and potentially a phone number.
Note that with further development of capabilities of the system and extended use of these capabilities, other information might be stored as well such as invoices or contracts between you and your clients.
How long do we keep this information?
Because information can be sensitive, we do advise that the subscriber removes client-data from the system as soon as it is not need it anymore. This will remove all information related to that client.
Employee data covers on the one hand information created as a user of the system and on the other hand as sourced from the connected systems. Their elementary identity information can be tagged against client data. That means that as long as this client data exists in the system, the respective employee data will exist. However, if a user has been removed from the system and all respective client-data has been removed, the employee data is also removed. The only exception is that certain user-actions within the system are logged in the Audit-log which the administrator of the subscriber can query for auditing purposes.
When the subscriber terminates the usage of the system, we will destroy all data and do not keep anything. Backup-data will exist for a limited period. After this period, there will be no more data of the subscriber, its clients or employees on our systems.
Marketing and access to your data
We will not use any of the data in the system relating to staff of the subscriber, clients of the subscriber or their representatives of those clients for marketing purposes. We have full access to the data to provide support to the subscriber and to assure that the system operates correctly and securely. We will not use our ability to access the information for any other purpose.
We will contact the users of the system only when necessary to provide support. Normally we will do this in agreement with the subscriber, but if the security of the information requires it and it is urgent, we might need to contact them directly. This is further detailed in our subscription agreement with the subscriber.
We will not disclose information in the system to any third party unless required by law and where required and practical, in consultation with the subscriber. This is also further detailed in our subscription agreement.
Cookies and re-authentication
We use only temporary cookies that are required for the application to function. These cookies will expire automatically when the browsing session ends or after a few hours. To keep information secure, we require a user to login within a few hours after the last time of use.
Geography
The data will be stored within Australia and we will not transfer data outside Australia without the consent of the subscriber.
Contractual information
Of course we will keep our business to business information such as relating to the contract and financial transactions as long as this is relevant to our business operations or as long as it is required by law. This also applies to information recorded as part of the support that we provide. We will keep this information for as long as we deem necessary to help us improve our services.