top of page

Privacy Policy

1. ABOUT THIS POLICY

Rundas ("we", "us" and "our") operates www.rundas.com.au.

This Privacy Policy explains how we collect, hold, use and disclose personal information through our website, enquiries, business relationships and advisory services. It also explains how you can request access or correction and raise a privacy concern.

We handle personal information in accordance with laws that apply to our activities, including the Privacy Act 1988 (Cth) and the Australian Privacy Principles where applicable. Additional notices may explain arrangements for a particular engagement, interview, survey or other activity.

​

2. PERSONAL INFORMATION WE COLLECT

Personal information is information or an opinion about an identified individual or someone who is reasonably identifiable.

Depending on your interaction with Rundas, we may collect:

• Contact and professional details, such as your name, email address, telephone number, organisation and role.
• Enquiries, correspondence, meeting arrangements, feedback and communication preferences.
• Information relevant to an agreed engagement, including personal information in governance records, interviews, surveys, financial or workforce models and performance assessments.
• Administrative and technical information, such as billing contacts, transaction records, website interactions and device information described in section 8.

If you apply for a role with Rundas, we may collect relevant application documents, qualifications, employment history and referee information.

We limit collection to information reasonably necessary for the relevant activity and permitted by law.

​

3. HOW WE COLLECT INFORMATION

We generally collect personal information directly from you through enquiries, forms, correspondence, meetings and agreed engagement activities.

Where direct collection is unreasonable or impracticable and collection is lawful, we may obtain relevant information from a client organisation, authorised representative, referee, referral partner or public professional source. Our work may also generate personal information, such as an assessment or opinion about an identifiable person.

You may deal with us anonymously or use a pseudonym where lawful and practicable. If information is necessary to respond, verify authority or provide a service, not supplying it may limit our ability to proceed.

​

4. HOW WE USE PERSONAL INFORMATION

We use personal information to respond to enquiries, understand requirements, prepare proposals and deliver agreed services. This can include conducting analysis and preparing reports, models and recommendations.

Information may also be used to arrange meetings, administer engagements, manage billing and recruitment, protect our systems, address complaints or disputes, and meet legal obligations.

We use or disclose information for the purpose for which it was collected, or another purpose permitted by applicable law. Where consent is required, we obtain it. Providing information to Rundas does not authorise unrestricted use or disclosure.

​

5. SENSITIVE INFORMATION AND INFORMATION ABOUT OTHER PEOPLE

General website enquiries do not require sensitive information, identity documents, passwords, detailed personnel records or confidential Board papers. Please contact us before sending this material so we can discuss its relevance and appropriate transfer arrangements.

Where sensitive information, such as health information, is necessary for an agreed assignment, we collect it with the individual's consent unless a lawful exception applies.

Only provide information about another person where you have a lawful basis to disclose it. Provide any required notices and obtain necessary consent. These responsibilities do not replace Rundas's own obligations.

If we receive information we did not request, we assess whether it could lawfully have been collected. Where required, we destroy or de-identify it as soon as practicable, subject to applicable law.

 

6. BOARD, EXECUTIVE AND CLIENT ENGAGEMENTS

Advisory work may involve information about directors, executives, employees, stakeholders or service users. We handle this information for the agreed purpose and other lawful purposes, subject to applicable confidentiality obligations.

For interviews and surveys, we explain the collection purpose, intended recipients and whether responses will be attributed, summarised or de-identified. Reports may be shared with authorised client representatives, such as a Board, Chair or executive sponsor, consistently with the collection notice and applicable law.

Confidentiality does not necessarily mean anonymity. We do not promise anonymity where the collection or reporting arrangements could identify a participant, or absolute confidentiality where disclosure is legally required.

Identifiable participant information and attributed comments are not automatically available for case studies, testimonials or marketing. Appropriate permissions and any required consent must be obtained before publication.

​

7. WHO WE SHARE INFORMATION WITH

Where relevant and lawful, personal information may be shared with:

• Authorised Rundas personnel, contractors and specialist advisers involved in the work.
• Authorised client representatives and other recipients identified for the engagement.
• Service providers supporting website hosting, forms, email, storage, scheduling, accounting and other business systems.
• Professional advisers, insurers, regulators, courts or other parties where disclosure is necessary and legally permitted or required.

We limit disclosures to information relevant to the permitted purpose and take reasonable steps to establish appropriate privacy, confidentiality and security arrangements with service providers. Using a provider does not, by itself, remove our legal responsibilities.

​

8. WEBSITE INFORMATION, COOKIES AND ANALYTICS

Depending on the technologies used, our website and its service providers may collect technical information such as IP addresses, browser and device details, pages visited and interactions with website features.

Cookies and similar technologies may support website functionality, security, preferences and usage analysis. The following details describe the technologies actually used on this website.

Website technologies and choices: [Insert the website hosting, form, analytics and any advertising or tracking tools actually used; the information collected and purposes; relevant recipients and retention periods; and available privacy controls.]

You can manage cookies through your browser settings. Restricting cookies may affect website features, and browser settings may not control every tracking technology.

Where consent is required, we obtain it before the relevant collection or use. Simply visiting our website does not provide blanket consent to tracking or disclosure.

​

9. MARKETING COMMUNICATIONS

Where we send marketing emails or messages, we do so with the consent required by applicable law. Making an enquiry does not automatically subscribe you to ongoing marketing.

You may unsubscribe using the option in a marketing message or by contacting us. We action requests to stop marketing emails or messages within five working days, without an unsubscribe fee.

Necessary non-promotional communications about an enquiry, engagement, invoice or privacy request may continue. We may retain a limited opt-out record to respect your preference.

​

10. OVERSEAS HANDLING OF PERSONAL INFORMATION

Information storage and access arrangements depend on the systems and service providers used, including their support and subcontracting arrangements.

Overseas arrangements: [State whether personal information is likely to be disclosed to overseas recipients. If so, identify the likely recipient countries where practicable, recipient categories and purposes, and any relevant overseas storage or support arrangements.]

Where we disclose personal information overseas, we meet applicable cross-border privacy requirements. This policy does not seek a general waiver of the protections that would otherwise apply.

​

11. STORAGE, SECURITY AND RETENTION

Personal information is held in business records, including correspondence and engagement documents, using electronic systems and, where necessary, paper records. Relevant records may also be held by service providers supporting our business.

We restrict access according to business need and take reasonable technical and organisational steps to protect personal information against misuse, interference, loss and unauthorised access, modification or disclosure.

No electronic transmission or storage system can be guaranteed completely secure. We do not guarantee that a security incident can never occur. This does not exclude any applicable security obligation or responsibility.

We retain information for as long as reasonably needed for a permitted purpose or applicable record-keeping requirement. Retention may also be necessary to address complaints, disputes or other legal obligations.

When information is no longer needed and retention is not legally required, we take reasonable steps to destroy or effectively de-identify it, including relevant copies held by providers, in archives and in backups.

 

12. RECORDINGS, ARTIFICIAL INTELLIGENCE AND AUTOMATED PROCESSING

Any recording, transcription or automated processing involving personal information is subject to applicable privacy requirements, collection notices and consent requirements. This policy does not provide blanket consent to recording, AI training or automated decision-making.

Our practices: [Describe any actual use of recording, transcription, AI or automated tools to process personal information, including purposes, information involved, providers, disclosures, retention, any model-training use and human oversight. Remove this section only if no such processing is used or planned.]

Proposed recording or transcription is explained before it begins, and any legally required consent is obtained.

​

13. ACCESSING AND CORRECTING YOUR INFORMATION

You can contact us to request access to personal information we hold about you or to request correction of information that is inaccurate, out of date, incomplete, irrelevant or misleading.

We may need to verify your identity or a representative's authority using proportionate information. We respond within a reasonable period, generally within 30 calendar days, subject to applicable legal requirements. Where additional time is reasonably needed, we explain the delay and expected timeframe.

There is no charge to make a request or correct information. Any reasonable charge for providing access applies only where legally permitted and is explained in advance.

If access or correction is refused on a lawful basis, we provide reasons and complaint information where required. Where applicable, you may ask for a statement of disagreement to be associated with the information.

You can also ask us to stop an optional use or delete information. We assess these requests against applicable rights, permitted purposes and retention obligations; immediate deletion may not always be possible.

​

14. DATA BREACHES

We assess suspected privacy or security breaches and take appropriate containment, investigation and remedial steps consistent with our legal obligations.

Where the Notifiable Data Breaches scheme or another law requires notification, we notify affected individuals and the relevant regulator in the required manner and timeframe.

Please contact us promptly if you suspect a privacy or security issue involving information handled by Rundas.

​

15. EXTERNAL WEBSITES AND SERVICES

External websites and independently operated services have their own privacy practices. Review their policies before providing information directly to them.

A link does not mean Rundas controls an external operator or guarantees its practices. This does not exclude any responsibility we have for our own handling of information or for providers handling information on our behalf.

​

16. PRIVACY ENQUIRIES AND COMPLAINTS

For privacy questions, access or correction requests, or complaints, contact:

Privacy Contact Rundas
Email: info@rundas.com.au
Telephone: +61 (3) 9112 3706
Website: www.rundas.com.au

Please explain the issue, relevant dates and the outcome you seek without including unnecessary sensitive information. We review complaints, make appropriate enquiries and aim to respond within 30 calendar days. If further investigation is needed, we explain the expected timeframe.

If you are dissatisfied with our response or have not received a response within 30 days, you may contact the Office of the Australian Information Commissioner where it has jurisdiction. Its telephone number is 1300 363 992, and complaint information is available at www.oaic.gov.au.

Other regulators may be relevant depending on the information and applicable law. Nothing in this policy restricts an available complaint or legal remedy.

This policy is available free of charge. Contact us to request an alternative accessible format; we take reasonable steps to accommodate such requests.

 

17. CHANGES TO THIS POLICY

We may update this policy to reflect changes to our services, information-handling practices or legal requirements. The updated version will be published on our website with its revision date.

An update does not retrospectively authorise unlawful handling, remove existing rights or replace any legally required notice or consent. Continued website use does not automatically authorise a new use of personal information.

 

18. POLICY STATUS AND LEGAL RIGHTS

This policy explains our information-handling practices. It is not intended, by itself, to create a separate contract, guarantee absolute security or expand the scope of an advisory engagement.

​

Submitting an enquiry or sending documents does not, by itself, establish an advisory engagement. Service scope and contractual responsibilities are addressed in separately agreed engagement terms, subject to applicable law.

Nothing in this policy excludes, restricts or modifies any right, remedy, duty or liability that cannot lawfully be excluded, restricted or modified. This policy does not override an existing confidentiality agreement or other binding obligation.

bottom of page