Privacy and Personal Data Protection Policy
Ignition Wealth Ltd (ACN 602 351 968)
Address: Level 17, 100 Miller Street, North Sydney, 2060 NSW Australia
Phone: 1300 656 924
Australian Financial Services Licence Number: 470 605
Ignition makes use of a variety of data about identifiable individuals, including data about current, past and prospective employees, customers & prospects, subscribers and other stakeholders. In collecting and using this data, the organisation is subject to a variety of legislation controlling how such activities may be carried out and the safeguards that must be put in place to protect it. Specifically, Ignition must comply with the Australian Privacy Act 1988 (‘Privacy Act’), including the Australian Privacy Principles (‘APPs’) and the European General Data Protection Regulation (GDPR). We are required by law to notify you of the information contained in this privacy notice.
This notice applies to current and former employees, workers and contractors. This notice does not form part of any contract of employment or other contract to provide services. We may update this notice at any time. The purpose of this policy is to set out the relevant legislation and to describe the steps Ignition is taking to ensure that it complies with it. This control applies to all systems, people and processes who have access to Ignition systems.
2. Data Protection Principles
We will comply with data protection legislation. This states the personal information we hold about you must be:
- Used lawfully, fairly and in a transparent way.
- Collected only for valid purposes that we have clearly explained to you and not used in any way that is incompatible with those purposes.
- Relevant to the purposes we have told you about and limited only to those purposes
- Accurate and kept up to date.
- Kept only as long as necessary for the purpose we have told you about.
- Kept securely.
3. What kinds of personal information do we collect and hold?
Personal data or personal information means any information about an individual from which that person can be identified. It does not include data where the identify has been removed (anonymous data). There are ‘special categories’ of more sensitive personal data which require a higher level of protection (indicated with a *). We may collect and hold a range of information about you to provide you with our services, including:
- Personal contact details, including full name, title, address, telephone number and personal email address.
- Date of birth.
- Marital status and dependants.
- Next of kin, and emergency contact information.
- PPS, National Insurance Number, Tax File Number.
- Bank account details, payroll records and tax status information.
- Salary, annual leave, pension and benefits information.
- Start date.
- Location of employment or workplace.
- Copy of driver’s licence.
- Recruitment information – including copies of right to work documentation, reference and other information included in a CV or cover letter as part of the application process.
- Immigration data.
- Passport details.
- Employment records – including job titles, work history, working hours, training records and professional memberships.
- Compensation history.
- Performance information.
- Disciplinary and grievance information.
- CCTV footage and other information obtained through electronic means such as swipe card records.
- Information about your use of our information and communications systems, including IP Address, and your social media accounts.
- * Information about your race or ethnicity, religious beliefs, sexual orientations and political opinions.
- * Information about your health, including any medical conditions, health and sickness records.
- * Genetic information and biometric data.
- * Information about criminal convictions and offences.
4. How do we collect personal information?
5. Unsolicited personal information
We may receive unsolicited personal information about you. We destroy or de-identify all unsolicited personal information we receive, unless it is relevant to our purposes for collecting personal information. We may retain additional information we receive about you if it is combined with other information we are required or entitled to collect. If we do this, we will retain the information in the same way we hold your other personal information.
6. Who do we collect personal information about?
The personal information we may collect, and hold includes (but is not limited to) personal information about the following individuals:
- potential customers;
- visitors to our website;
- service providers or suppliers.
7. How will we use your information?
We will only use your personal information when the law allows us to. Most commonly, we will use your personal information in the following circumstances:
- Where we need to perform the contract we have entered into with you;
- Where we need to comply with a legal obligation;
- Where it is necessary for our legitimate interests (or those of a third party) and your interests and fundamental rights do not override those interests.
We may use your personal information in the following situations, in the unlikely event they arise
- Where we need to protect your or someone else’s interest;
- Where it is needed in the public interest or for official purposes.
For an example of situations we might use your personal information, please refer to . This list is not exhaustive and is a guide only. Your data may be used in other scenarios falling within the scope of the circumstance listed above. We will only use your personal information for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose. If we need to use your personal information for an unrelated purpose, we will notify you and we will explain the legal basis which allows us to do so. Please note that we may process your personal information without your knowledge or consent, in compliance with the above rules, where this is required or permitted by law.
Special categories of particularly sensitive personal information require higher levels of protection. We need to have further justification for collecting, storing, and using this type of personal information. We may process special categories of personal information in the following circumstances:
- With your explicit consent;
- Where we need to carry out our legal obligations or exercise rights in relation to your employment with his. We have in place an appropriate policy document and safeguards which we are required by law to maintain when processing such data;
- Where it is needed in the public interest, such as for equal opportunities monitoring or in relation to our occupational pension scheme. We have in place an appropriate policy document and safeguards which we are required by law to maintain when processing such data.
Less commonly, we may process this type of information where it is needed in relation to legal claims or were it is needed to protect yours or others interests, and you are not capable of giving consent, or have already made the information public. We may also process such information about members or former members in the course of legitimate business activities with the appropriate safeguards.
As an employer, we may use your particularly sensitive information in the following ways:
- We will use information relating to leaves of absence, which may include sickness absence or family related leaves, to comply with employment and other laws.
- We will use information about your physical or mental health, or disability status, to ensure your health and safety in the workplace and to assess your fitness to work, to provide appropriate workplace adjustments, to monitor and manage sickness absence and to administer benefits.
- We will use information about your race or national or ethnic origin, religious beliefs to ensure meaningful equal opportunity monitoring and reporting.
- We will use your biometric information for the purpose of developing, testing and training biometric algorithms and demonstrating Ignition’s products (with your explicit consent).
We do not need your consent if we use special categories of your personal information in accordance with our written policy to carry out our legal obligations or exercise specific rights in the field of employment law. In limited circumstances, we may approach you for your written consent to allow us to process certain particularly sensitive data, including your biometric information. If we do so, we will provide you with full details of the information that we would like and the reason we need it, so that you can carefully consider whether you wish to consent. You should be aware that it is not a condition of your contract with us that you agree to any request for consent from us.
We may only use information relating to criminal convictions where the law in your jurisdiction allows us to do so. This will usually be where such processing is necessary to carry out our obligations and provided we do so in line with our data protection policy.
Less commonly, we may use information relating to criminal convictions where it is necessary in relation to legal claims, where it is necessary to protect your or someone else’s interests and you are not capable of giving your consent, or where you have already made the information public. We may also process such information about members or former members in the course of legitimate business activities with the appropriate safeguards.
We will only collect information about criminal convictions if it is appropriate given the nature of the role and where we are legally able to do so. Where appropriate and lawful, we will collect information about criminal convictions as part of the recruitment process or we maybe notified of such information directly by you in the course of you working for us. We will use information about criminal convictions and offenses in the following ways:
Job Applicants UK: An offer of employment will be contingent upon consideration of the results of any background check including information about criminal convictions.
Job Applicants other European countries: We may seek information regarding criminal convictions in any other European jurisdiction where this is legally permissible, for the purpose of considering an offer of employment.
Existing Employees: Where it is reasonably required for our legitimate business interests, for example, for the purpose of complying with customer security requirements when employees enter a customer’s premises, a background check may be undertaken during your employment even if a previous check was already completed. This may include information about criminal convictions where this is legally permissible.
Automated Decision Making
Automated decision making takes place when an electronic system uses personal information to make a decision without human intervention. We are allowed to use automated decision making in the following circumstances:
- Where we have notified you of the decision and given you 21 days to request a reconsideration;
- Where it is necessary to perform the contract with you and the appropriate measures are in place to safeguard your rights;
- In limited circumstances, with your explicit consent and where appropriate measures are in place to safeguard your rights.
If we make an automated decision on the basis of any particularly sensitive personal information, we must have either your explicit written consent or it must be justified in the public interest, and we must also put in place appropriate measures to safeguard your rights. You will not be subject to decisions that will have a significant impact on you based solely on automated decision-making, unless we have a lawful basis for doing so and we have notified you. We do not envisage that any decisions will be taken about you using automated means, however we will notify you in writing if this position changes.
8. Data Sharing
We may disclose data and personal information with third parties, including third party service providers and other entities in the group. We require third parties to respect the security of your data and treat it in accordance with the law. We will share data with third parties where required by law, where necessary to administer the working relationship with you or where we have another legitimate interest in doing so. All our third-party service providers and other entities in the group are required to take appropriate security measures to protect your personal information in line with our policies. We do not allow our third-party service providers to use your personal data for their own purposes. We only permit them to process your personal data for specified purposes and in accordance with our instructions. We will share your personal information with other entities in our group as part of our regular reporting activities on company performance, in the particularly context of a business reorganization or group restructuring exercise, for system maintenance support and hosting of data. Sensitive information will be used and disclosed only for the purpose for which it was provided (or a directly related secondary purpose), unless you agree otherwise or there is a relevant legislated restriction.
Notice for Australian Employees
We may disclose your Tax File Number to other persons when we are acting on your behalf in the conduct of your affairs (for example, to our execution broker, or to share registries). When we do so, we are acting in accordance with Section 8WB(1A) (c) of the Taxation Administration Act 1953. We do not adopt identifiers assigned by the Government (such as driver’s licence numbers) for our own file recording purposes, unless one of the exemptions in the Privacy Act applies.
If we disclose your personal information to service providers that perform business activities for us, they may only use your personal information for the specific purpose for which we supply it. We require that all contractual arrangements with third parties adequately address privacy issues and will make third parties aware of this Policy.
9. Sending information overseas
- we have taken reasonable steps to ensure that the recipient does not breach the Privacy Act, the APPs or GDPR;
- the recipient is subject to a similar information privacy regime.
10. Data Security
We recognise the importance of securing the personal information of our customers. We have put in place appropriate security measures to prevent your personal information from being accidentally lost, used or accessed in an unauthorized way, altered or disclosed. In addition, we limit access to your personal information to those employees, agents, contractors and other third parties who have a business need to know. They will only process your personal information on our instructions and they are subject to a duty of confidentiality. Details of these measures may be obtained from Ignition’s Information Security Manager. We have put in place procedures to deal with any suspected data security breach and will notify you and any applicable regulator of a suspected breach where we are legally required to do so.
11. Direct Marketing
We may only use personal information we collect from you for the purposes of direct marketing without your consent if:
- the personal information does not include sensitive information; and
- you would reasonably expect us to use or disclose the information for the purpose of direct marketing; and
- we provide a simple way of opting out of direct marketing; and
- you have not requested to opt out of receiving direct marketing from us.
If we collect personal information about you from a third party, we will only use that information for the purposes of direct marketing if you have consented (or it is impracticable to obtain your consent), and we will provide a simple means by which you can easily request not to receive direct marketing communications from us. We will draw your attention to the fact you may make such a request in our direct marketing communications. You have the right to request us not to use or disclose your personal information for the purposes of direct marketing, or for the purposes of facilitating direct marketing by other organisations. We must give effect to the request within a reasonable period of time. You may also request that we provide you with the source of their information. If such a request is made, we must notify you of the source of the information free of charge within a reasonable period of time.
13. Updates to this policy
It is the responsibility of management to inform employees and other relevant third parties about this Policy. Management must ensure that employees and other relevant third parties are advised of any changes to this Policy. All new employees are to be provided with timely and appropriate access to this Policy, and all employees are provided with training in relation to appropriate handling of personal information. Employees or other relevant third parties that do not comply with this Policy may be subject to disciplinary action.
14. Your Rights
It is important that the personal information we hold about you is accurate and current. Please keep us informed if your personal information changes during your working relationship with us.
Under certain circumstances, by law you have the right to:
- Request access to your personal information (commonly known as a “data subject access request”). This enables you to receive a copy of the personal information we hold about you and to check that we are lawfully processing it.
- Request correction of the personal information that we hold about you. This enables you to have any incomplete or inaccurate information we hold about you corrected.
- Request erasure of your personal information. This enables you to ask us to delete or remove personal information where there is no good reason for us continuing to process it. You also have the right to ask us to delete or remove your personal information where you have exercised your right to object to processing (see below).
- Object to processing of your personal information where we are relying on a legitimate interest (or those of a third party) and there is something about your particular situation which makes you want to object to processing on this ground. You also have the right to object where we are processing your personal information for direct marketing purposes.
- Request the restriction of processing of your personal information. This enables you to ask us to suspend the processing of personal information about you, for example if you want us to establish its accuracy or the reason for processing it.
- Request the transfer of your personal information to another party.
If you want to review, verify, correct or request erasure of your personal information, object to the processing of your personal data, or request that we transfer a copy of your personal information to another party, please contact the HR Department in writing. You will not have to pay a fee to access your personal information (or to exercise any of the other rights). However, we may charge a reasonable fee if your request for access is clearly unfounded or excessive. Alternatively, we may refuse to comply with the request in such circumstances. We may need to request specific information from you to help us confirm your identity and ensure your right to access the information (or to exercise any of your other rights). This is another appropriate security measure to ensure that personal information is not disclosed to any person who has no right to receive it.
In the limited circumstances where you may have provided your consent to the collection, processing and transfer of your personal information for a specific purpose, you have the right to withdraw your consent for that specific processing at any time. To withdraw your consent, please contact the HR Department. Once we have received notification that you have withdrawn your consent, we will no longer process your information for the purpose or purposes you originally agreed to, unless we have another legitimate basis for doing so in law.
15. Updates to this Statement
This Statement will be reviewed from time to time to take account of new laws and technology, and changes to our operations and the business environment.
16. Our responsibilities
It is the responsibility of management to inform employees and other relevant third parties about this Statement and of any changes to this Statement. All new employees are provided with timely and appropriate access to this Statement, and all employees are provided with training in relation to appropriate handling of personal information as part of our ISO/IEC27001 certification. Employees or other relevant third parties that do not comply with this Statement may be subject to disciplinary action.
17. Making a complaint
If you have any questions about this Statement, or wish to make a complaint about how we have handled your personal information, you can lodge a complaint with us by:
- telephoning 1300 656 924
- writing to the Privacy Officer, Ignition, Level 17, 100 Miller St, North Sydney, NSW 2060
- emailin – firstname.lastname@example.org
If you are not satisfied with our response to your complaint, you can also refer your complaint to the relevant Authorities in your country:
Office of the Australian Information Commissioner
- Phone – 1300 363 992
- Postal Address – Director of Complaints, Office of the Australian Information Commissioner, GPO Box 5218, SYDNEY NSW 2001, Australia
- emailing – email@example.com
Irish Data Protection Commissioner
- Phone +353 578 684 800
- Postal Address – Data Protection Commission, 21 Fitzwilliam Square South, Dublin 2, D02 RD28, Ireland
- Website – https://www.dataprotection.ie/en/contact/how-contact-us