Privacy Policy
How Hexar Solutions collects, uses, stores, discloses and protects personal information across our industrial, automation, commercial and EV charging work — and the rights you have under the Privacy Act 1988 (Cth).
The short version
- We collect only what we need to quote, deliver, invoice and warrant electrical and automation work.
- We never sell or rent personal information.
- We share it with subcontractors, suppliers and software providers only where needed to do the job; some of those providers store data outside Australia.
- You can ask for a copy of your information, ask us to correct it, or complain — email [email protected]. If we don’t resolve it, you can escalate to the OAIC.
1. Purpose, scope and who this covers
This policy applies to Hexar Solutions Pty Ltd (ABN 29 642 429 169), a specialist automation and industrial electrical contractor operating from Wynnum, Queensland and licensed in QLD, NSW, VIC, SA and WA. In this policy “we”, “us” and “our” mean Hexar Solutions Pty Ltd.
It covers the personal and commercially sensitive information we handle about clients, homeowners, site contacts, suppliers, subcontractors, job applicants, employees and visitors to our website and premises — across our corporate IT systems, engineering workstations, PLC/SCADA platforms, cloud collaboration tools, email, portable storage and paper records. Personal information means information or an opinion about an identified individual, or an individual who is reasonably identifiable.
2. Our privacy principles
We handle information in line with the thirteen Australian Privacy Principles, and hold ourselves to seven working rules inside our ISO 9001-aligned quality system: lawful, fair and transparent handling; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability.
3. Information we collect
What we hold depends on your relationship with us:
- name, business name and role, phone numbers, email, postal and site addresses;
- enquiry and quoting information — what you submitted through our website forms, the scope you described, and notes taken during calls and site visits;
- site and job information — supply and switchboard details, existing installation records, access and induction requirements, site contacts, test results and compliance certificates;
- photographs of the work area, equipment and completed installation;
- documents you send us, including electricity bills and supply details;
- quotes, purchase orders, invoices, payment records and, for commercial accounts, credit application and trade reference details;
- records of calls to and from our office line, including notes and, where we tell you at the time, recordings;
- website and device information — IP address, browser and device type, pages viewed and referring links;
- marketing subscription status and email engagement;
- supplier and subcontractor contact, contractual, payment and compliance documentation;
- employment information for staff, subcontractors and applicants;
- technical and operational data — configuration files, control system code, network configurations, maintenance and commissioning records.
4. How we collect it
We collect personal information directly from you wherever it is reasonable and practicable to do so — when you call, email, submit a website form, request a quote, meet us on site or engage us for works — and we tell you the purpose at the time. Sometimes we collect it from someone else: a builder, head contractor, facilities manager, agent, body corporate or tenant who engages us to attend a site; a manufacturer arranging a warranty visit; a credit reporting body or trade referee for commercial credit accounts; or a referee you nominate during recruitment. Where we collect your information from a third party and you would not reasonably expect it, we take reasonable steps to notify you.
5. Why we collect and use it
We use personal information for the purpose it was collected and for related purposes you would reasonably expect:
- preparing quotes and scoping works, including site surveys and supply calculations;
- scheduling, delivering and supervising electrical, automation and EV charging works;
- arranging site access, inductions and safety compliance;
- invoicing, taking payment and managing credit accounts;
- keeping the compliance, test and certification records we must keep as a licensed electrical contractor;
- handling warranty claims, defects, service calls and maintenance;
- quality assurance, training and internal review under our ISO 9001-aligned systems;
- sending service and permitted marketing communications;
- meeting our legal, insurance, work health and safety and tax obligations.
Our lawful bases are contractual necessity, legal and regulatory obligation, legitimate business interest, employment requirements, and consent where required. If we intend to use your information for an unrelated purpose we will seek your consent, unless the law permits or requires the use without it.
6. Site surveys, job photos and site records
We photograph work areas, switchboards, cable routes and completed installations for quoting, compliance, warranty and defect purposes. Those photographs may incidentally show property interiors, vehicles, equipment or personal belongings. Photographs and site records are kept in the job file and used internally. We will only use non-confidential images of completed work for marketing where the client has not objected, and we will not publish images that identify a person, a residential address or a client’s confidential processes without consent. Tell us in writing if you do not want images of your site used at all.
7. EV charging, automation and control system data
To specify and install EV charging equipment we often need details of your electricity supply, and clients commonly send us a recent electricity bill or metering details so we can size the supply correctly. Those documents are stored in the job file in our job management and cloud storage systems and are not used for any other purpose.
Where we commission chargers, PLC, SCADA or building control systems we may configure accounts and access on the manufacturer’s or client’s platform, and may hold commissioning data, configuration files, control system code, network configurations and diagnostic logs. Those platforms are operated by the manufacturer or by the client under their own privacy terms. Engineering files and control system configurations are restricted to authorised personnel, version-controlled, backed up securely and subject to change management. Where we retain remote access for support it is controlled and logged, used only for diagnosis, maintenance and rectification, and removed on request.
8. Site access credentials
Delivering works often means we are given site access credentials — keys, swipe cards, gate and alarm codes, induction logins and, on automation projects, system or network credentials. We hold them only for as long as the engagement requires, issue them only to the workers who need them, never store them in shared documents or unsecured notes, and return or have them revoked at completion. If you believe a credential has been compromised, tell us immediately and we will support the reissue.
9. Sensitive information
We collect sensitive information only where it is reasonably necessary and, generally, with your consent. This is limited to health and injury information collected for site inductions, first aid, incident and injury reporting and workers’ compensation, and to the results of police checks or working-with-children checks where a site, client or law requires them. Sensitive information is accessible only to the staff who need it, is used solely for the purpose it was collected, and is not disclosed except as required by law or with your consent.
10. Commercial credit information
Where a client applies for a credit account we collect credit application details, trade references and, for individuals and sole traders, information needed to assess commercial creditworthiness. We may disclose that information to, and obtain a report from, a credit reporting body or trade reference, and may disclose default and payment information where permitted under Part IIIA of the Privacy Act. Credit information is used only to assess and manage the account and to recover amounts owing.
11. Tax file numbers
We collect tax file numbers from employees and, where required, contractors solely to meet our obligations to the Australian Taxation Office and superannuation funds. TFNs are handled under the Privacy (Tax File Number) Rule 2015, are accessible only to payroll and management, are never used as an identifier, and are not disclosed except to the ATO, your superannuation fund or our payroll and accounting providers.
12. Who we disclose information to
We do not sell, rent or trade personal information, and we do not disclose it to third parties without lawful justification. We disclose it only where needed for the purposes in section 5, to:
- subcontractors and labour hire we engage on your works;
- suppliers, wholesalers and equipment manufacturers, for ordering, delivery, commissioning and warranty;
- builders, head contractors, facilities managers, landlords or tenants where they are party to the works;
- electrical safety regulators, network distributors and certifiers, where notification or certification is required;
- our accountants, bookkeepers, insurers, brokers, lawyers and debt recovery agents;
- IT, software and service providers who host or process data on our behalf under confidentiality agreements;
- credit reporting bodies and trade references;
- courts, tribunals, regulators and law enforcement where required or authorised by law.
13. Overseas disclosure
Some of the software and cloud services we rely on store or process personal information outside Australia — principally in the United States, and in some cases in other countries where our providers operate data centres. This includes our email, document storage and analytics provider (Google), our email marketing platform, our payment provider (Stripe) and some cloud hosting. Our accounting and job management systems are Australian-hosted. Before disclosing information overseas we take reasonable steps to satisfy ourselves that the recipient handles it consistently with the Australian Privacy Principles, including through contractual data protection clauses or equivalent safeguards. By providing your information to us you acknowledge this overseas disclosure.
14. Our website, cookies and analytics
Our website uses cookies and similar technologies. Essential cookies keep the site working and secure. Analytics cookies, set through Google Analytics 4 and Google Tag Manager, tell us how visitors find and move through the site and may collect your IP address, device and browser type and pages viewed. We use that information in aggregate to improve the site and measure our advertising. You can block or delete cookies in your browser, and can opt out of Google Analytics using Google’s browser opt-out add-on; some parts of the site may not work as well if you block essential cookies. We do not use website analytics to make decisions about individuals.
15. Marketing and how to opt out
We may send you service updates, safety notices, compliance reminders and occasional marketing about our services where you are an existing client or have consented. Every marketing email carries an unsubscribe link, and you can opt out at any time by using it or by emailing [email protected]. Opting out of marketing does not stop operational messages about works in progress, warranty or invoicing. We do not disclose your details to third parties for their own marketing.
16. CCTV at our premises
Our Wynnum premises and yard are monitored by CCTV for the security of people, vehicles, stock and equipment. Signage is displayed at the entry points. Footage is recorded, retained for a limited period on a rolling basis and then overwritten, is accessible only to management, and is disclosed only to police, insurers or as required by law, or where needed to investigate an incident or safety matter. CCTV is not used to monitor employee performance.
17. Job applicants and careers
If you apply for a role or apprenticeship with us we collect your application, resume, licences and tickets, qualifications, work history, right-to-work evidence, referee comments and the results of any check we tell you about, including police checks and pre-employment medical or drug and alcohol screening where the role requires it. We use it only to assess your application and, if you are successful, to establish your employment or engagement. We may hold unsuccessful applications for up to twelve months in case a suitable role arises, unless you ask us to delete them.
18. Employees and subcontractors
We hold employment records including contracts, payroll, tax and superannuation details, identification documents, licence, training and competency records, inductions, timesheets, leave, performance, and health and safety incident records. Acts of a private-sector employer directly relating to a current or former employment relationship and an employee record are exempt from the Australian Privacy Principles under section 7B(3) of the Privacy Act. We nonetheless apply this policy’s security, access and retention standards to employee records as a matter of practice, and the exemption does not apply to subcontractors, job applicants or health information held for other purposes.
19. How we store and secure information
Job, client and compliance records are held in our job management system, our cloud document storage, our accounting system and our email platform, with a limited amount of paper held at our premises. We protect information with role-based access granted on a need-to-know basis and reviewed periodically, multi-factor authentication on business accounts, encryption in transit and where appropriate at rest, firewall and antivirus protection, secure VPN for remote access, secure backups, secure premises with controlled access to server rooms, controlled disposal including shredding and secure device wiping, confidentiality agreements, staff training, and audits under our ISO 9001-aligned management system. Payment card details are captured and stored by our payment provider under PCI DSS, not by us. No system is perfectly secure; we cannot guarantee the security of information you send us over the internet or by email.
20. How long we keep information
As a default we keep client, job, financial and compliance records for seven years from the end of the engagement, consistent with our tax, corporations, work health and safety and limitation-period obligations. Some records are kept longer where a law requires it, or where they relate to an ongoing claim, dispute, warranty or insurance matter. When information is no longer needed for any purpose and we are not required to keep it, we destroy or de-identify it securely.
| Record | Retention |
|---|---|
| Quotes, job files, site records, photos, compliance certificates | 7 years |
| Invoices, payments, credit accounts, electricity bills in job files | 7 years |
| Employee and subcontractor records, payroll, safety and incident records | 7 years+ |
| Control system code, configurations and commissioning records | Life of installation |
| Site access credentials | Duration of engagement |
| Unsuccessful job applications | 12 months |
| CCTV footage | Rolling, then overwritten |
| Marketing subscription records | Until you opt out |
21. Data breach response
We maintain a data breach response plan. If we suspect a breach we will contain it, assess it promptly, and take reasonable steps to remediate the harm. Where a breach is likely to result in serious harm and we cannot remediate it, we will notify affected individuals and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme, and will tell you what happened, what information was involved and what you should do in response.
22. Access, correction and anonymity
You can ask for access to the personal information we hold about you, and ask us to correct anything inaccurate, out of date, incomplete or misleading. You may also object to particular handling, or ask us to delete information, and we will do so unless a law, contract or ongoing matter requires us to keep it. Email [email protected] with enough detail to identify the records. We will respond within thirty days and will verify your identity before releasing anything. Access is free; we may charge a reasonable cost for retrieving or copying a large volume of records, and will tell you the cost first. If we refuse access or correction we will tell you why in writing and how to complain. You can deal with us anonymously or by pseudonym for general enquiries, but not where we need your details to quote, attend a site, invoice or meet a legal obligation.
23. Complaints
If you think we have breached the Australian Privacy Principles, contact us in writing at [email protected] or Hexar Solutions Pty Ltd, PO Box 5547, Manly QLD 4179, marked “Privacy”. We will acknowledge your complaint within five business days, investigate it and give you a written response within thirty days. If you are not satisfied with our response, or we do not respond in time, you can complain to the Office of the Australian Information Commissioner: oaic.gov.au, 1300 363 992, or GPO Box 5218, Sydney NSW 2001.
24. Changes to this policy
We review this policy annually, or sooner following a material system change or a change in the law, and it is maintained as controlled documented information within our management system. The current version is always available on this page and free on request. Material changes are noted by the version and effective date at the top of this page.
Privacy questions or requests?
Ask for your information, correct it, or lodge a complaint — we respond within 30 days.