PRIVACY POLICY

Document Version: 9   |   Date: 6 March 2026

1. Policy Statement

Advent Security is committed to managing personal information in an open and transparent way in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

This policy explains how we collect, hold, use, disclose and protect personal information relating to employees, clients, contractors, visitors, and other individuals who interact with our organisation.

2. Scope

This policy applies to:

  • All Advent Security employees and line managers
  • Visitors and clients
  • Contractors, subcontractors, and service providers
  • Any person whose personal information is handled by Advent Security in any form (digital, paper, CCTV, access systems, communications)

3. Definitions

Personal Information

Information or an opinion about an identified individual, or an individual who is reasonably identifiable.

Sensitive Information

Includes health information, criminal history, biometric data, racial or ethnic origin, political opinions, membership of professional or trade associations, etc.

Employee Records

Records directly related to a current or former employment relationship. The Privacy Act includes an employee records exemption that may apply to certain acts and practices by a private sector employer in relation to employee records. Advent Security nevertheless aims to handle employee personal information in a consistent, careful and secure way.

3.1 Anonymity and Pseudonymity

Where lawful and practicable, individuals may interact with Advent Security anonymously or by using a pseudonym.

However, anonymity or pseudonymity may not be possible where identification is required to:

  • provide security services
  • comply with legal or regulatory obligations
  • manage employment relationships
  • conduct background checks or licensing verification
  • investigate incidents or security events

In such circumstances Advent Security may require sufficient information to verify the individual’s identity.

4. Types of Personal Information We Collect

Depending on the individual and reason for interaction with Advent Security, we may collect:

4.1 Employees, Contractors & Applicants

  • Full name, date of birth, address, and contact details
  • Employment history, qualifications, licences, certificates
  • National Police Checks, Working With Children Checks
  • Health information relevant to fitness for work
  • Tax File Number (TFN) information is handled in accordance with the Privacy Act 1988 (Cth) and the Tax File Number Guidelines (as applicable), and is used only for authorised taxation, superannuation and payroll purposes.
  • Incident reports and investigation material
  • Site access logs, security clearance information

Where we collect sensitive information (such as health information or criminal history information), we will do so only with the individual’s consent or where otherwise permitted or required by law (for example, to meet licensing, screening, work health and safety, or client contractual requirements).

Government related identifiers

We do not adopt, use or disclose government related identifiers (such as driver licence numbers or passport numbers) as our own identifier for individuals, except where required or authorised by law.

4.2 Clients & General Public

  • Contact details
  • CCTV footage
  • Access control logs
  • Incident and investigation information
  • Information provided when making enquiries

5. How We Collect Personal Information

We collect personal information in several ways:

  • Directly from individuals through forms, interviews, onboarding, emails, phone calls
  • Through CCTV and security systems at controlled premises
  • Through electronic access systems and monitoring tools
  • From third-party service providers (e.g., Police Checks, training providers)
  • From publicly available sources where lawful and relevant
  • Through incident reporting and workplace inspection processes

We will only collect information that is reasonably necessary for our business activities or to meet legal obligations.

Unsolicited personal information

If we receive personal information that we did not request, we will determine whether the information is reasonably necessary for our functions or activities. If it is not, we will, where lawful and reasonable, destroy or de-identify the information as soon as practicable.

Collection notice

At or before the time we collect personal information (or as soon as practicable afterwards) we will take reasonable steps to notify individuals of: the purpose of collection; the main consequences if information is not provided; the types of third parties we usually disclose to; whether we are likely to disclose information overseas (and, if practicable, the countries); and how individuals can access, correct and complain about the handling of their personal information.

CCTV and Security Monitoring

Advent Security may operate CCTV and other security monitoring systems at sites where services are provided.

These systems are used for purposes including:

  • safety and security
  • incident investigation
  • access control and site monitoring
  • compliance with client and regulatory requirements

Where surveillance is conducted, appropriate signage is displayed in accordance with applicable legislation.

Access to CCTV footage (including copies) may be limited or refused where permitted by law—for example, where providing access would unreasonably impact the privacy of other individuals, prejudice an investigation, or disclose security-sensitive information.

6. Purposes for Collecting, Using & Disclosing Personal Information

Advent Security uses and discloses personal information for the following purposes:

  • Recruitment, onboarding, and workforce management
  • Compliance with legislative and regulatory requirements
  • Health & safety management and incident investigation
  • Client contract fulfilment
  • Payroll administration and HR management
  • Training, competency verification, and licensing
  • Security monitoring, access control, and emergency response
  • Communication with clients and stakeholders
  • Risk management, insurance and legal processes
  • Maintaining operational records and service quality

We do not sell or provide personal information for marketing purposes.

6.1 Direct Marketing

Advent Security does not use personal information for direct marketing purposes and does not sell personal information to third parties.

If Advent Security ever intends to use personal information for marketing communications, individuals will be given the opportunity to opt out of receiving such communications.

7. Disclosure to Third Parties

We may disclose personal information to:

  • Government and law enforcement agencies
  • Licensing and regulatory bodies
  • External auditors and compliance assessors
  • Insurers, legal advisers, and investigators
  • Payroll, HR, and IT service providers
  • Clients, where required for operational or security purposes

All disclosures are limited to what is lawful, necessary, and reasonable for business or legal purposes.

8. Overseas Disclosure

Some service providers (e.g., cloud hosting, email systems, HR platforms) may store or process personal information outside Australia.

This may include, for example, the United States, United Kingdom or Singapore (noting that locations may change depending on providers and services used). Where personal information is disclosed overseas, Advent Security will take reasonable steps to ensure the disclosure is handled consistently with the Privacy Act and the APPs (including through due diligence and appropriate contractual and security measures), unless an exception under the Privacy Act applies.

  • we conduct due diligence on overseas providers and their security practices
  • contractual and technical measures are in place to protect the information
  • Only the minimum required information is transferred

9. Security of Personal Information

Advent Security takes all reasonable steps to secure personal information from misuse, loss, unauthorised access, modification, and disclosure.

Controls include:

  • Role-based access restrictions
  • Encryption of information in transit and at rest
  • Multi-factor authentication for key systems
  • Secure storage for physical documents
  • CCTV monitoring and restricted areas
  • Regular audits and access reviews
  • Employee confidentiality obligations
  • Secure destruction of records when no longer required

9.1 Data Breach Notification

Advent Security complies with the Notifiable Data Breaches Scheme under the Privacy Act 1988 (Cth).

If a data breach occurs that is likely to result in serious harm to an individual, Advent Security will:

  • promptly assess the breach (including completing any required assessment within 30 days)
  • take steps to contain and mitigate the incident
  • notify affected individuals where required
  • notify the Office of the Australian Information Commissioner (OAIC)

Incident management procedures are implemented to ensure data breaches are identified, assessed and reported in accordance with legal requirements.

10. Access and Correction

Individuals may request access to or correction of personal information held about them.

Requests must be made to the Privacy Officer using the contact details provided in this policy. We may ask for further information to verify identity and to help us locate the relevant information.

Advent Security will:

  • verify the identity of the individual making the request
  • respond within a reasonable timeframe
  • provide access unless an exception under the Privacy Act applies
  • correct inaccurate, incomplete or outdated information where appropriate

Access will generally be provided free of charge; however, we may charge a reasonable fee to cover the cost of providing access where permitted by law. We will respond within a reasonable timeframe and, where we refuse access or correction, we will provide reasons (where required) and information about complaint options.

Access may be refused where permitted by law, including where providing access would:

  • pose a serious threat to health or safety
  • prejudice law enforcement activities
  • reveal commercially sensitive or security sensitive information
  • breach legal privilege

Where access is refused, written reasons will be provided where required.

Retention and Destruction of Personal Information

Advent Security retains personal information only for as long as necessary to fulfil the purposes for which it was collected, including legal, contractual, regulatory and operational requirements.

When personal information is no longer required it will be securely destroyed or permanently de-identified in accordance with organisational procedures and applicable records management requirements.

11. Privacy Complaints

If you believe your privacy has been breached:

  • Contact Advent Security’s Privacy Officer.
  • We will investigate the matter and respond within a reasonable period (usually within 30 days).
  • If unresolved, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC).

12. Contact Details

Privacy Officer – Casey Benney

Advent Security

Email: casey.benney@adventsecurity.com.au

Phone: 03 9464 1666

Postal Address: 41 Commercial Drive, Thomastown, Vic 3074

Or -

Office of the Australian Information Commissioner

www.oaic.gov.au

13. Changes to This Policy

This policy is reviewed at least annually and may be updated from time to time to reflect changes in legislation, regulatory guidance and business operations. The most current version will be available internally and on request.

Regulatory updates

Australia’s privacy framework is being reformed, including amendments made by the Privacy and Other Legislation Amendment Act 2024. Advent Security will monitor updates to privacy legislation and OAIC guidance and will update this policy and associated procedures as required.

Authorization

Peter Benney

Peter Benney signature

Owner

March 06, 2026