Privacy Policy
Last updated: 25 June 2026
[REVIEW: …] require sign-off from an Australian tech/privacy lawyer before being relied on commercially.1. About this policy
Apex Workforce Development Pty Ltd (ABN [REVIEW: ABN]) ("Apex", "we", "us") is bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). This policy explains how we handle personal information when you use our platform, websites, and related services.
2. The information we collect
- Account data: name, email, phone, organisation, role.
- Employee records (provided by employers): name, contact details, employment status, job role, department, start date.
- Compliance evidence: licence numbers, ticket types, VOC records, qualification documents, hours logbook entries, induction acknowledgements, photos of cards and certificates.
- Sensitive information (limited): medical/fitness-for-work documents only where uploaded by the employer or employee for compliance purposes. We treat all such records as sensitive under APP 3.
- Billing data: tax invoice details. Card numbers are handled by Stripe; we never store full PANs.
- Technical data: IP address, browser/device, session tokens, audit logs, error reports.
- Communications: support emails, demo bookings, training enquiries.
3. Why we collect it (purpose)
- To provide, operate and improve the platform.
- To produce competency, expiry and compliance reports for employers.
- To route training enquiries to relevant RTOs (only with the employer's instruction).
- To send essential service emails (receipts, security alerts, expiry alerts, password resets).
- To meet legal, tax and audit obligations.
- To investigate suspected misuse, fraud or breaches.
We do not sell personal information, share it with advertisers, or use it to train third-party AI models.
4. Sensitive information — APP 3
We only collect sensitive information (such as health/fitness-for-work records) where it is reasonably necessary for compliance recordkeeping and either (a) the individual has consented, or (b) collection is required or authorised by law.
5. How we share information
- Within your organisation: records visible to authorised users in your company only. Strict row-level security prevents cross-company access.
- RTO partners: when you submit a training enquiry, we share the minimum necessary information (typically: company name, contact person, employee count, ticket type and region) with matched RTOs.
- Service providers (subprocessors): see our subprocessor list.
- Legal: where required by law, court order, or to protect rights and safety.
- Business transfer: in the event of a merger or acquisition, subject to equivalent protections.
6. Cross-border disclosure — APP 8
Data is stored in Australia (Sydney region, AWS ap-southeast-2) via our managed infrastructure provider. Some subprocessors (e.g. Stripe, email delivery) may process limited data outside Australia. See the subprocessor list for jurisdictions. We take reasonable steps under APP 8 to ensure overseas recipients handle personal information consistently with the APPs.
7. Security
- Encryption in transit (TLS 1.2+) and at rest.
- Row-level security enforced at the database layer for tenant isolation.
- Files served via short-lived signed URLs.
- Passwords hashed with bcrypt; new passwords screened against the Have I Been Pwned breach corpus.
- Role-based access control. Administrative access is logged.
- Backups retained for 30 days with point-in-time recovery.
8. Retention and deletion
- Active account data is retained for the life of the account.
- On account deletion, personal data is removed within 30 days, except records we are required to retain by law (e.g. tax invoices: 5 years; workplace safety audit records: typically 7 years
[REVIEW: confirm retention period for VIC]). - De-identified, aggregated analytics may be retained indefinitely.
9. Your rights (APP 12 & 13)
You may request to:
- Access the personal information we hold about you.
- Correct inaccurate or out-of-date information.
- Have your account deleted, subject to legal retention.
- Withdraw consent to non-essential processing.
Email privacy@apexworkforce.com.au. We respond within 30 days. Where an employer uploaded the data about you, we may direct your request to that employer first.
10. Notifiable data breaches
We comply with the Notifiable Data Breaches scheme. If a breach likely to result in serious harm occurs, we will notify affected individuals and the OAIC as soon as practicable.
11. Cookies and tracking
See our Cookie Notice for details. We use only essential cookies and privacy-respecting analytics; no third-party advertising trackers.
12. Complaints
Email privacy@apexworkforce.com.au. If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
13. Changes
We will notify you of material changes by email and update the "Last updated" date above.
See also: Help · Status · Terms · Privacy · Acceptable Use · Cookies · DPA · Employee Privacy Notice · Refunds · Subprocessors · RTO Partner Agreement