Advent Security is committed to managing personal information in an open and transparent way in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
This policy explains how we collect, hold, use, disclose and protect personal information relating to employees, clients, contractors, visitors, and other individuals who interact with our organisation.
This policy applies to:
Information or an opinion about an identified individual, or an individual who is reasonably identifiable.
Includes health information, criminal history, biometric data, racial or ethnic origin, political opinions, membership of professional or trade associations, etc.
Records directly related to a current or former employment relationship. The Privacy Act includes an employee records exemption that may apply to certain acts and practices by a private sector employer in relation to employee records. Advent Security nevertheless aims to handle employee personal information in a consistent, careful and secure way.
Where lawful and practicable, individuals may interact with Advent Security anonymously or by using a pseudonym.
However, anonymity or pseudonymity may not be possible where identification is required to:
In such circumstances Advent Security may require sufficient information to verify the individual’s identity.
Depending on the individual and reason for interaction with Advent Security, we may collect:
Where we collect sensitive information (such as health information or criminal history information), we will do so only with the individual’s consent or where otherwise permitted or required by law (for example, to meet licensing, screening, work health and safety, or client contractual requirements).
We do not adopt, use or disclose government related identifiers (such as driver licence numbers or passport numbers) as our own identifier for individuals, except where required or authorised by law.
We collect personal information in several ways:
We will only collect information that is reasonably necessary for our business activities or to meet legal obligations.
If we receive personal information that we did not request, we will determine whether the information is reasonably necessary for our functions or activities. If it is not, we will, where lawful and reasonable, destroy or de-identify the information as soon as practicable.
At or before the time we collect personal information (or as soon as practicable afterwards) we will take reasonable steps to notify individuals of: the purpose of collection; the main consequences if information is not provided; the types of third parties we usually disclose to; whether we are likely to disclose information overseas (and, if practicable, the countries); and how individuals can access, correct and complain about the handling of their personal information.
Advent Security may operate CCTV and other security monitoring systems at sites where services are provided.
These systems are used for purposes including:
Where surveillance is conducted, appropriate signage is displayed in accordance with applicable legislation.
Access to CCTV footage (including copies) may be limited or refused where permitted by law—for example, where providing access would unreasonably impact the privacy of other individuals, prejudice an investigation, or disclose security-sensitive information.
Advent Security uses and discloses personal information for the following purposes:
We do not sell or provide personal information for marketing purposes.
Advent Security does not use personal information for direct marketing purposes and does not sell personal information to third parties.
If Advent Security ever intends to use personal information for marketing communications, individuals will be given the opportunity to opt out of receiving such communications.
We may disclose personal information to:
All disclosures are limited to what is lawful, necessary, and reasonable for business or legal purposes.
Some service providers (e.g., cloud hosting, email systems, HR platforms) may store or process personal information outside Australia.
This may include, for example, the United States, United Kingdom or Singapore (noting that locations may change depending on providers and services used). Where personal information is disclosed overseas, Advent Security will take reasonable steps to ensure the disclosure is handled consistently with the Privacy Act and the APPs (including through due diligence and appropriate contractual and security measures), unless an exception under the Privacy Act applies.
Advent Security takes all reasonable steps to secure personal information from misuse, loss, unauthorised access, modification, and disclosure.
Controls include:
Advent Security complies with the Notifiable Data Breaches Scheme under the Privacy Act 1988 (Cth).
If a data breach occurs that is likely to result in serious harm to an individual, Advent Security will:
Incident management procedures are implemented to ensure data breaches are identified, assessed and reported in accordance with legal requirements.
Individuals may request access to or correction of personal information held about them.
Requests must be made to the Privacy Officer using the contact details provided in this policy. We may ask for further information to verify identity and to help us locate the relevant information.
Advent Security will:
Access will generally be provided free of charge; however, we may charge a reasonable fee to cover the cost of providing access where permitted by law. We will respond within a reasonable timeframe and, where we refuse access or correction, we will provide reasons (where required) and information about complaint options.
Access may be refused where permitted by law, including where providing access would:
Where access is refused, written reasons will be provided where required.
Advent Security retains personal information only for as long as necessary to fulfil the purposes for which it was collected, including legal, contractual, regulatory and operational requirements.
When personal information is no longer required it will be securely destroyed or permanently de-identified in accordance with organisational procedures and applicable records management requirements.
If you believe your privacy has been breached:
Privacy Officer – Casey Benney
Advent Security
Email: casey.benney@adventsecurity.com.au
Phone: 03 9464 1666
Postal Address: 41 Commercial Drive, Thomastown, Vic 3074
Or -
Office of the Australian Information Commissioner
www.oaic.gov.au
This policy is reviewed at least annually and may be updated from time to time to reflect changes in legislation, regulatory guidance and business operations. The most current version will be available internally and on request.
Australia’s privacy framework is being reformed, including amendments made by the Privacy and Other Legislation Amendment Act 2024. Advent Security will monitor updates to privacy legislation and OAIC guidance and will update this policy and associated procedures as required.
Authorization
Peter Benney
Owner
March 06, 2026