Privacy Policy, multi-jurisdictional.
How MUSE Security WorX Australia Pty Ltd and its related entities collect, use, disclose, and protect personal information across Australia, New Zealand, and — where applicable — the EEA and United Kingdom.
01
Introduction
This Privacy Policy explains how MUSE Security WorX Australia Pty Ltd and related entities (collectively, MUSE, we, us, our) collect, use, disclose, and protect personal information in accordance with applicable privacy laws in the jurisdictions where we operate.
02
Applicable laws
MUSE is committed to providing quality services while respecting your privacy rights. This policy has been designed to comply with:
- The Australian Privacy Principles (APPs) contained in the Privacy Act 1988 (Cth) (Australia).
- The Privacy Act 2020 (New Zealand).
- Regulation (EU) 2016/679 (General Data Protection Regulation, GDPR) and the United Kingdom General Data Protection Regulation (UK GDPR), where applicable to international transfers.
03
Your consent
By engaging with MUSE, including using our websites, products, or services, you agree to the collection and use of your personal information as set out in this Privacy Policy.
A copy of the Australian Privacy Principles may be obtained from the Office of the Australian Information Commissioner at www.oaic.gov.au.
04
Personal information we collect
Personal information is information or an opinion that identifies an individual. The types of personal information we may collect include:
- Identification details (for example, name, title, organisation, role, date of birth).
- Contact details (for example, email address, phone number, postal address, business address).
- Account and profile information (for example, login credentials, usernames, passwords, preferences, communication settings).
- Transaction information (for example, records of products or services you purchase or use from us, billing information, payment details).
- Communication records (for example, emails, support tickets, feedback, survey responses, correspondence, interview notes).
- Technical and usage information (for example, IP address, device identifiers, browser type, operating system, pages viewed, access times, and other usage data collected via cookies or similar technologies).
- Business records (for example, contractual documentation, compliance records, regulatory submissions).
05
Sensitive information
Sensitive information, as defined by the Australian Privacy Act 1988, includes information or opinion about an individual’s racial or ethnic origin, political opinions, religious beliefs, trade union membership, criminal record, health information, genetic or biometric data, or sexual orientation.
We will only collect, use, or disclose sensitive information:
- For the primary purpose for which it was obtained.
- For a secondary purpose directly related to the primary purpose, where you would reasonably expect such use.
- With your express consent; or
- As required or authorised by law.
06
How we collect personal information
Where reasonably practicable, we collect personal information directly from you, for example:
- When you contact us via phone, email, or our website.
- When you sign up for our services or create an account.
- When you use our websites, applications, or online services.
- Through interviews, correspondence, or business meetings.
- When you provide information via forms, surveys, or feedback mechanisms.
We may also collect personal information from third parties where permitted by law, including:
- Your employer or organisation (where our services are provided in a business context).
- Public sources (for example, business directories, regulatory filings).
- Service providers, integration partners, or contracted vendors.
- Regulatory authorities or government agencies.
When we collect personal information from third parties, we will comply with any applicable notice requirements under the Privacy Act 2020 (New Zealand) and the Australian Privacy Principles, including indirect collection obligations.
Consequences of not providing information
If you do not provide the personal information we request, we may not be able to provide some or all of our services to you, process your requests, or fulfil our contractual or regulatory obligations.
07
Purposes for collecting and using personal information
Primary purposes
We collect, use, and disclose personal information for the following purposes (and any directly related purposes):
- To provide, operate, deliver, and support our products and services.
- To manage our relationship with you or your organisation, including billing, account administration, contract management, and responding to enquiries.
- To personalise and improve our websites, products, and services, including analytics, troubleshooting, quality assurance, and security monitoring.
- To communicate with you about updates, notices, marketing, events, or other information you may be interested in, in accordance with applicable law and your communication preferences.
- To support compliance with contractual and regulatory obligations, including the Australian Government Information Security Manual (ISM), ISO/IEC 27001:2022, SOC 2, Essential Eight, Defence Industry Security Programme (DISP), export control requirements (ITAR, DSPF), and other applicable standards.
- To meet our legal and regulatory obligations, including responding to government requests, regulatory audits, and law enforcement requirements.
- To exercise or defend legal claims, protect our rights and property, and ensure the security of our systems and data.
- For business administration, operational management, risk assessment, and strategic planning.
- For any other purpose that you authorise or that is permitted by the Privacy Act 1988 (Australia), the Privacy Act 2020 (New Zealand), or other applicable privacy laws.
Ancillary purposes
Personal information may also be used for ancillary purposes closely related to the primary purpose, in circumstances where you would reasonably expect such use.
Marketing communications
We may use your contact details to send you marketing communications about our products, services, events, or industry information that we believe may be of interest to you, in accordance with applicable laws (including anti-spam requirements under the Spam Act 2003 (Australia) and equivalent legislation) and your communication preferences.
You may unsubscribe from marketing communications at any time by:
- Following the unsubscribe instructions in the communication.
- Contacting us in writing using the details in Section 17.
- Updating your communication preferences in your account settings.
08
Disclosure of personal information
Categories of recipients
Your personal information may be disclosed to the following categories of recipients:
- Internal personnel. Our employees, officers, directors, related entities, and subsidiaries who need the information to assist with the purposes described in this Privacy Policy.
- Third-party service providers. External organisations who help us operate our business and deliver our services, including IT hosting providers, cloud infrastructure providers (subject to appropriate security standards); security and cybersecurity service providers; analytics, monitoring, and diagnostic service providers; communications and marketing platforms; payment processing and financial services providers; and professional advisers (lawyers, accountants, auditors, consultants).
- Your organisation or employer. Where our services are provided to you in a business or organisational context.
- Regulatory and government authorities. Where we are required or permitted to do so by law, regulation, court order, or regulatory process, including regulators and oversight bodies, law enforcement agencies, defence and national security agencies, and tax authorities and revenue agencies.
- Integration partners and contracted vendors. Subject to compliance with relevant legislation, data security standards (such as ISO/IEC 27001), and explicit data protection agreements.
- Third parties with your consent. Any other third party where you have given your express consent to the disclosure.
- Acquirers or successors. In connection with any merger, acquisition, sale of assets, or business restructure (subject to confidentiality obligations).
Safeguards for third-party disclosures
Where we share personal information with third parties, we will:
- Take reasonable steps to ensure those third parties protect the information in a manner consistent with the Privacy Act 2020 (New Zealand), the Australian Privacy Principles, and applicable data security standards.
- Require third parties to implement appropriate technical and organisational measures, including encryption, access controls (such as role-based access via Microsoft Entra ID), secure storage, and audit logging.
- Enter into explicit data protection agreements that specify the permitted uses, security requirements, confidentiality obligations, and breach notification procedures.
- Regularly review and audit third-party compliance with our security and privacy requirements.
Circumstances for disclosure
Your personal information may be disclosed in the following circumstances:
- Where you consent to the use or disclosure.
- Where required or authorised by law.
- Where necessary to provide the services you have requested.
- Where reasonably necessary to protect the rights, property, or safety of MUSE, our customers, or others.
09
International transfers and cross-border disclosure
Overseas transfers
Some of the third parties to whom we disclose personal information, and some of our own systems and infrastructure, may be located outside Australia and New Zealand, including in:
- The United States of America.
- The European Economic Area (EEA).
- The United Kingdom.
- Singapore.
- Other jurisdictions where our service providers, cloud infrastructure, or business partners operate.
Compliance with Australian Privacy Principles
When transferring personal information overseas from Australia, we will comply with Australian Privacy Principle 8 (Cross-border disclosure of personal information), including by:
- Taking reasonable steps to ensure the overseas recipient does not breach the Australian Privacy Principles.
- Ensuring you have been informed that APP 8 will not apply, or that we will be responsible for any breach by the overseas recipient; or
- Obtaining your express consent to the transfer; or
- Relying on another permitted exception under the Privacy Act 1988.
Compliance with New Zealand Privacy Act
If we transfer your personal information overseas from New Zealand, we will comply with Information Privacy Principle 12 of the Privacy Act 2020 or any applicable equivalent, including by:
- Taking reasonable steps to ensure the overseas recipient is subject to privacy protections that, overall, provide comparable safeguards to those in New Zealand.
- Ensuring the overseas recipient is in a jurisdiction with privacy laws substantially similar to the Privacy Act 2020; or
- Obtaining your authorisation for the transfer; or
- Relying on another permitted exception.
International transfers to New Zealand and Australia (GDPR / UK GDPR)
Scope
This section applies to any transfer of personal data that is subject to Regulation (EU) 2016/679 (GDPR) and/or the United Kingdom General Data Protection Regulation (UK GDPR) (together, EU Data Protection Law) from a controller in the EEA/UK (Data Exporter) to MUSE in New Zealand or Australia (Data Importer) in connection with the licensing, installation, configuration, support, or maintenance of software or services (including any related updates, patches, diagnostic data, logs, or support materials).
The parties agree that, unless expressly stated otherwise in a written agreement, the Data Exporter acts as controller and the Data Importer acts as processor in respect of such personal data.
Transfers to New Zealand (adequacy)
The parties acknowledge that New Zealand is the subject of an adequacy decision of the European Commission under Article 45 GDPR. Personal data may therefore be transferred from the EEA/UK to New Zealand, or accessed in New Zealand for remote support or maintenance, without additional transfer safeguards under Articles 46 or 49 GDPR, provided that MUSE complies with:
- Any applicable data processing agreement.
- EU Data Protection Law to the extent applicable; and
- New Zealand privacy law (including the Privacy Act 2020) when processing such personal data.
Transfers to Australia (Standard Contractual Clauses — Module 2)
To the extent personal data is transferred from the EEA/UK to, or accessed in, Australia for the purposes described above, or otherwise transferred to a jurisdiction that is not the subject of an adequacy decision under Article 45 GDPR, the parties shall ensure that an appropriate safeguard under Article 46 GDPR is implemented.
Unless the parties expressly agree another safeguard in writing, the parties agree that:
- The European Commission’s Standard Contractual Clauses for the transfer of personal data to third countries (Commission Implementing Decision (EU) 2021/914), Module 2 (Controller to Processor), are incorporated by reference into the applicable agreement as if set out in full between the Data Exporter (as “data exporter”) and the Data Importer (as “data importer”); and
- The description of the transfers (Annex I), the technical and organisational measures (Annex II), and any sub-processor list (Annex III) are as set out in the applicable data processing agreement, data protection schedule, or order form between the parties.
Alternative SCC modules and roles
If, for any specific transfer, MUSE acts as controller (for example, where it determines its own purposes for certain diagnostic or licensing data) or the parties otherwise agree different roles, the parties shall instead implement the appropriate SCC module(s) (Module 1, 3, or 4, as applicable) and document the roles, transfer details, and annexes in a data protection schedule that expressly incorporates the relevant module(s).
Local law and supplementary measures
For transfers to Australia or any other non-adequate third country under the SCCs, the parties shall:
- Assess, where required by EU Data Protection Law, whether the laws and practices of the recipient jurisdiction may affect the effectiveness of the SCCs in the context of the support, maintenance, remote access, or other processing envisaged; and
- Implement any additional technical, contractual, or organisational measures necessary to ensure a level of protection for personal data that is essentially equivalent to that guaranteed within the EEA, which may include:
- Encryption of diagnostic logs, support materials, and data in transit and at rest.
- Strict access controls for support personnel, including multi-factor authentication and role-based access.
- Minimisation of personal data in support materials and diagnostic tools.
- Restrictions on onward transfers and sub-processing.
- Regular security audits and penetration testing.
- Contractual prohibitions on access by government authorities except where legally required and with notice to the data exporter (where permitted by law).
10
Website, cookies, and analytics
Cookies and similar technologies
When you visit our websites (including musesecworx-au.com and related domains), we may use cookies and similar technologies to collect technical information, including:
- IP address.
- Device and browser information (type, version, operating system).
- Pages visited and content viewed.
- Date, time, and duration of visits.
- Referring website or source.
- User interactions, clicks, and navigation patterns.
This information helps us to:
- Understand and improve how our websites are used.
- Personalise your experience and remember your preferences.
- Analyse website performance and identify technical issues.
- Monitor security and prevent fraud or unauthorised access.
- Deliver relevant content and marketing (where you have consented).
Managing cookies
You can usually disable or manage cookies by changing your browser settings. However, disabling cookies may affect the functionality of our websites or online services, and some features may not work properly.
For more information about cookies and how to manage them, please visit www.aboutcookies.org or www.allaboutcookies.org.
Third-party links and services
Our websites may contain links to third-party websites, applications, or services that are not controlled by us. Those sites will have their own privacy policies, terms of use, and data collection practices. We do not guarantee the privacy practices or content of authorised third-party sites, and we are not responsible for their privacy practices or security. We encourage you to review the privacy policies of any third-party sites you visit.
11
Storage, security, and retention
Security measures
We take the security of personal information seriously and will take reasonable steps to protect personal information from loss, unauthorised access, use, modification, disclosure, and other misuse, in accordance with the Privacy Act 1988 (Australia), the Privacy Act 2020 (New Zealand), and applicable data security standards. Our security measures include:
- Technical controls. Encrypted databases, secure cloud platforms, firewalls, intrusion detection systems, multi-factor authentication, and secure network configurations.
- Access controls. Role-based access via Microsoft Entra ID (Azure Active Directory), privileged access management, least-privilege principles, and regular access reviews.
- Organisational controls. Security policies and procedures, staff training and awareness programs, background checks for personnel handling sensitive information, confidentiality agreements.
- Physical controls. Secure facilities, restricted access to data centres, visitor management, and environmental controls.
- Monitoring and logging. Continuous security monitoring, audit logging, security information and event management (SIEM), and regular security assessments.
- Compliance frameworks. ISO/IEC 27001:2022, SOC 2, Essential Eight Maturity Level 2 (ML2), Australian Government Information Security Manual (ISM), and Defence Industry Security Programme (DISP) requirements.
Storage methods
Personal information may be stored in electronic and/or hard copy form, including:
- On our own systems and servers (located in Australia and/or approved jurisdictions).
- On the systems of our trusted service providers and cloud infrastructure providers (subject to appropriate security agreements and compliance with relevant legislation).
- In encrypted databases, secure file storage systems, and approved collaboration platforms.
- In physical files stored in secure, access-controlled facilities.
Retention periods
We will retain personal information only for as long as it is required for the purposes for which it was collected, or as otherwise required or permitted by law. Retention periods will vary depending on:
- The nature of the information and the purposes for which it was collected.
- Legal, regulatory, and contractual obligations (for example, taxation records, defence contracts, export control documentation).
- Business operational requirements (for example, contract management, warranty support, dispute resolution).
- Audit, compliance, and quality assurance requirements.
Typical retention periods include:
- Customer and contract records: duration of contract plus 7 years (or as required by applicable law or regulation).
- Financial and taxation records: 7 years from the end of the financial year to which they relate.
- Employee records: duration of employment plus 7 years.
- Audit and compliance records: as required by the relevant regulatory framework or contractual obligation.
- Marketing and communications: until you unsubscribe or withdraw consent, or as required by law.
Secure disposal
When personal information is no longer required, we will securely destroy or de-identify it in line with relevant procedures and industry best practices, including:
- Cryptographic wipe or secure erasure for digital media and storage devices.
- Cross-cut shredding or incineration for physical documents.
- De-identification or anonymisation where retention is required for statistical or analytical purposes.
- Secure disposal certificates from approved vendors where third-party disposal services are used.
Data breach management
A privacy breach occurs when personal information is accessed, disclosed, altered, lost, destroyed, or made unavailable in an unauthorised or accidental way, or where we are prevented from accessing personal information on a temporary or permanent basis.
When we become aware of a suspected or actual privacy breach, we will act promptly to:
- Contain the breach where practicable and prevent further unauthorised access or disclosure.
- Preserve relevant logs, evidence, and forensic data.
- Convene our internal incident response and privacy team to coordinate the response.
- Assess the nature, severity, and impact of the breach.
- Determine whether the breach is a notifiable privacy breach (see Section 14).
- Take reasonable steps to reduce the risk of harm to affected individuals.
- Identify and implement improvements to our technical, organisational, and procedural safeguards to prevent recurrence.
- Keep appropriate records of the breach, our assessment, decisions, and remedial actions in line with regulatory expectations.
12
Access, correction, and your rights
Right to access
You have the right to request access to any personal information we hold about you. We will respond to access requests in accordance with the Privacy Act 1988 (Australia) and the Privacy Act 2020 (New Zealand). To request access, please contact us using the details in Section 17.
Identity verification
We may require you to verify your identity before we provide access to or correct personal information. This is to protect your privacy and prevent unauthorised access. Proof of identity may include government-issued identification, verification of account details, or other reasonable means.
Access fees
No fee is charged for making an access request. However, an administrative fee may apply for providing copies of documents or compiling information in a particular format. We will inform you of any applicable fees before processing your request.
Right to correction
You have the right to request corrections to your personal information if you believe it is inaccurate, incomplete, out of date, irrelevant, or misleading. We will respond to correction requests in accordance with applicable privacy laws. If we agree that the information should be corrected, we will take reasonable steps to correct it and, where appropriate, notify any third parties to whom we have disclosed the information.
Refusal of access or correction
In some circumstances, we may lawfully refuse to provide access to or correct personal information, including where:
- Providing access would pose a serious threat to the life, health, or safety of any individual, or to public health or public safety.
- Providing access would have an unreasonable impact on the privacy of other individuals.
- The request is frivolous or vexatious.
- The information relates to existing or anticipated legal proceedings and would not be accessible through the discovery process.
- Providing access would reveal our commercially sensitive decision-making processes or trade secrets.
- Providing access would be unlawful or would prejudice enforcement activities, an investigation, or national security.
- Denying access is required or authorised by law or a court order.
If we refuse to provide access or make a correction, we will explain the reasons for our decision in writing, subject to any legal restrictions, and inform you of your right to complain.
Response timeframes
We aim to respond to access and correction requests within a reasonable timeframe, typically:
- Australia: within 30 days of receiving the request.
- New Zealand: as soon as reasonably practicable, and no later than 20 working days.
If we require more time or additional information to process your request, we will notify you and provide an estimated timeframe.
Maintaining data quality
We aim to ensure that the personal information we hold about you is accurate, complete, up to date, relevant, and not misleading. Please advise us of any changes to your personal information so that our records can remain current.
13
Direct marketing and communications
Marketing communications
We may use your contact details to send you marketing communications about our products, services, events, industry updates, or other information we believe may be of interest to you, in accordance with:
- The Spam Act 2003 (Australia) and associated regulations.
- The Unsolicited Electronic Messages Act 2007 (New Zealand).
- Other applicable anti-spam and direct marketing laws.
- Your communication preferences and any consents you have provided.
Marketing communications may be sent via email, SMS or text message, telephone (where you have provided express consent), mail or post, or in-product notifications or messages.
Opt-out and unsubscribe
You can opt out of receiving marketing communications at any time, at no cost, by:
- Following the unsubscribe instructions in the communication (for example, clicking the “unsubscribe” link in an email).
- Contacting us using the details in Section 17.
- Updating your communication preferences in your account settings (if available).
- Replying “STOP” or “UNSUBSCRIBE” to SMS messages.
Once you opt out, we will process your request within a reasonable timeframe (typically within 5 business days) and will not send you further marketing communications, except as required to fulfil our contractual or legal obligations (for example, service notifications, security alerts, or transactional messages).
Ongoing relationship communications
Even if you opt out of marketing communications, we may still contact you for non-marketing purposes, including:
- Account administration and service delivery.
- Billing, payment, and transaction notifications.
- Security alerts, system updates, and critical notices.
- Responses to your enquiries or support requests.
- Legal, regulatory, or compliance communications.
14
Notifiable privacy breaches and notification
What is a notifiable privacy breach
A notifiable privacy breach is a data breach that is likely to result in serious harm to one or more individuals, as described in:
- Part IIIC of the Privacy Act 1988 (Australia) — Notifiable Data Breaches (NDB) scheme.
- Part 7 of the Privacy Act 2020 (New Zealand) — Notifiable privacy breaches.
A notifiable privacy breach occurs when:
- There is unauthorised access to, or unauthorised disclosure of, personal information held by MUSE; or
- Personal information held by MUSE is lost in circumstances where unauthorised access or disclosure is likely to occur; and
- A reasonable person would conclude that the access, disclosure, or loss would be likely to result in serious harm to any of the individuals to whom the information relates.
Assessment of serious harm
When we become aware of a suspected privacy breach, we will promptly assess whether the breach is likely to cause serious harm to affected individuals. We will take into account factors including:
- The sensitivity and volume of the personal information involved.
- Who has obtained or may obtain the information, and their likely intentions.
- The types of potential harm, including identity theft or fraud; financial loss or economic harm; loss of employment or business opportunities; damage to reputation; significant humiliation, loss of dignity, or injury to feelings; physical harm or threats to safety; and psychological harm or emotional distress.
- The security safeguards that were in place and whether they have been compromised.
- The characteristics and vulnerabilities of the affected individuals, including any relevant cultural perspectives of harm.
- Whether remedial action has been taken to reduce the likelihood of serious harm (for example, recovery of lost data, disabling compromised accounts).
Use of self-assessment tools
For breaches occurring in New Zealand, we may use the Office of the Privacy Commissioner’s (OPC) NotifyUs self-assessment tool to assist in determining whether a breach is notifiable. However, we remain responsible for making the final decision and ensuring compliance with our legal obligations.
Notification to regulators
Australia — Office of the Australian Information Commissioner (OAIC)
If we reasonably believe a privacy breach is a notifiable data breach under the Australian scheme, we will notify the OAIC as soon as practicable after becoming aware that the breach is notifiable, and in any event without unreasonable delay. Notification will be made via the OAIC’s online data breach notification form at www.oaic.gov.au.
New Zealand — Office of the Privacy Commissioner (OPC)
If we reasonably believe a privacy breach is a notifiable privacy breach under the New Zealand scheme, we will notify the OPC as soon as practicable after becoming aware that the breach is notifiable. Our aim is to notify the OPC within 72 hours of forming the view that a breach is notifiable, in line with OPC expectations, recognising that this timeframe is a guide rather than a strict statutory deadline. Notification will normally be made via the OPC’s NotifyUs online reporting tool at www.privacy.org.nz.
Notification to affected individuals
Where a privacy breach is notifiable, we will also notify affected individuals directly as soon as practicable, unless an exception applies under the Privacy Act 1988 (Australia) or the Privacy Act 2020 (New Zealand), including where:
- Notification would prejudice a law enforcement investigation or other enforcement activities.
- Notification would pose a serious threat to the life, health, or safety of any individual, or to public health or public safety.
- Notification is prohibited by law or a court order.
- We have taken remedial action that has reduced the likelihood of serious harm to a level where notification is no longer required (Australia only).
Form of notification to individuals
Direct notification to affected individuals may be made by email (to the last known email address), letter or post, telephone (where appropriate), secure in-product notice or account notification, or in-person notification (in appropriate circumstances). Where direct notification is not reasonably practicable, or where direct notice may itself cause further harm, we may provide notification by public notice on our website, media or press release, or indirect notice through representative organisations or intermediaries.
Content of notifications
Notifications to affected individuals will explain, in clear and plain language:
- A description of the privacy breach, including what happened and when.
- The kinds of personal information involved in the breach.
- The recommendations or steps we suggest individuals take to reduce the risk of harm (for example, changing passwords, monitoring accounts, contacting financial institutions).
- The steps we have taken or will take in response to the breach (for example, containment, remediation, additional security measures).
- Contact details for further information or to ask questions.
Post-breach remediation
Following any privacy breach (whether notifiable or not), we will:
- Take reasonable steps to reduce the risk of harm to affected individuals, including offering support, guidance, or remedial services (such as credit monitoring, identity protection).
- Identify and implement improvements to our technical, organisational, and procedural safeguards to prevent recurrence.
- Conduct a post-incident review to analyse root causes, lessons learned, and opportunities for improvement.
- Keep appropriate records of the breach, our assessment, decisions, notifications, and remedial actions in line with regulatory expectations and our internal governance requirements.
- Report to senior management and, where appropriate, the Board of Directors.
Regulatory consequences
Failure to comply with notifiable privacy breach obligations can result in:
- Regulatory investigations, determinations, and enforcement actions.
- Civil penalties and fines (in Australia, up to AU$2.5 million for a body corporate under current legislation).
- Reputational harm and loss of customer trust.
- Mandatory undertakings, enforceable commitments, or corrective action orders.
We take these obligations seriously and are committed to full compliance with all applicable privacy breach notification requirements.
15
Children’s information
General position
Our products and services are generally directed at business customers, government agencies, and organisational users. We do not knowingly or intentionally collect personal information about children (individuals under the age of 18, or such other age as may be defined by applicable law).
Parental consent
If we become aware that we have collected, or intend to collect, personal information about a child, we will take additional steps appropriate in the circumstances, including:
- Seeking consent from a parent, guardian, or person with parental responsibility, where required by law.
- Verifying the identity and authority of the person providing consent.
- Limiting the collection, use, and disclosure of the child’s information to what is strictly necessary.
- Providing enhanced security and privacy protections for children’s information.
Notification of inadvertent collection
If you believe we have collected personal information about a child without appropriate consent or authority, please contact us immediately using the details in Section 17 so that we can address the issue, including by:
- Investigating the circumstances of the collection.
- Ceasing further collection, use, or disclosure.
- Deleting or de-identifying the information, where appropriate and lawful.
- Notifying relevant parties, including parents or guardians.
16
Changes to this Privacy Policy
Policy updates
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, business operations, or other factors. Updates may be made to address:
- Changes in applicable privacy laws, regulations, or regulatory guidance.
- New products, services, or business activities.
- Changes in data processing technologies or security standards.
- Feedback from customers, regulators, or privacy assessments.
- Corporate restructures, mergers, or acquisitions.
Review schedule
This Privacy Policy is scheduled for review annually, or upon material change in legislation, regulatory guidance, or business operations.
Notification of changes
The updated Privacy Policy will be posted on our website (musesecworx-au.com and related domains) with the effective date and review date clearly indicated.
Where changes are material or affect your rights in a significant way, we may also notify you by:
- Email to your registered email address.
- Prominent notice on our website or in our products.
- In-product notification or alert.
- Direct communication from our Privacy Officer.
Continued use
Your continued use of our products, services, or websites after any changes take effect will constitute your acceptance of the updated Privacy Policy. If you do not agree with the updated Privacy Policy, you should discontinue use of our services and contact us to discuss your concerns or request deletion of your personal information (subject to our legal obligations to retain certain records).
17
How to contact us or make a complaint
Privacy Officer contact details
If you have any questions about this Privacy Policy, wish to exercise your privacy rights, or wish to make a complaint about how we have handled your personal information, please contact our Privacy Officer:
- Privacy Officer
- Colin C Stone, Director
- Phone
- +61 455 112 322
- Postal address
- MUSE Security WorX Australia Pty Ltd
13 Gladman Close
ISAACS ACT 2607
Australia - Alternative contact
- rob.slattery@musesecworx.com
Complaint handling process
We are committed to resolving privacy complaints fairly, efficiently, and in a timely manner. When you make a complaint, we will:
- Acknowledge your complaint promptly, typically within 2–5 business days.
- Investigate the matter thoroughly, which may include reviewing relevant records, systems, and communications; consulting with relevant personnel and departments; seeking clarification or additional information from you; and engaging external advisers or specialists where appropriate.
- Respond to your complaint within a reasonable timeframe, typically within 30 days (Australia) or 20 working days (New Zealand), or inform you if we require additional time.
- Work with you to resolve the complaint, which may include correcting inaccurate or incomplete information, providing access to information you have requested, ceasing or modifying certain uses or disclosures of your information, implementing additional safeguards or controls, or providing an apology, explanation, or other remedy.
- Keep records of the complaint, our investigation, and the outcome, in accordance with our internal governance and regulatory requirements.
External complaint bodies
If you are not satisfied with how we have handled your complaint, or if you prefer to raise your complaint directly with a regulator, you can contact the relevant privacy authority in your jurisdiction.
Australia
Office of the Australian Information Commissioner (OAIC)
- Website
- oaic.gov.au
- Phone
- 1300 363 992
- Post
- GPO Box 5218, Sydney NSW 2001
New Zealand
Office of the Privacy Commissioner (OPC)
- Website
- privacy.org.nz
- Phone
- 0800 803 909
- Post
- PO Box 10094, The Terrace, Wellington 6143
EEA & United Kingdom
Local data protection authority
If your personal data is subject to GDPR or UK GDPR, you may also contact your local supervisory authority. A list of EU data protection authorities is available at edpb.europa.eu.
18
Definitions and interpretation
Key definitions
In this Privacy Policy, unless the context otherwise requires:
- Australian Privacy Principles (APPs)
- The principles set out in Schedule 1 of the Privacy Act 1988 (Cth).
- GDPR
- Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation).
- Personal Information
- Information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether the information or opinion is true or not, and whether the information or opinion is recorded in a material form or not (as defined in the Privacy Act 1988 (Australia), and substantially equivalent to “personal data” under GDPR and “personal information” under the Privacy Act 2020 (New Zealand)).
- Privacy Act 1988
- The Privacy Act 1988 (Cth) of Australia, as amended from time to time.
- Privacy Act 2020
- The Privacy Act 2020 of New Zealand, as amended from time to time.
- Sensitive Information
- Has the meaning given in section 6 of the Privacy Act 1988 (Australia), and includes information or opinion about an individual’s racial or ethnic origin, political opinions, membership of a political association, religious beliefs or affiliations, philosophical beliefs, membership of a professional or trade association, membership of a trade union, sexual orientation or practices, criminal record, health information, genetic information, or biometric information.
- MUSE
- MUSE Security WorX Australia Pty Ltd (ACN 697 559 185, ABN 58 697 559 185), MUSE Security WorX, LLC (its parent entity, Tampa, Florida), and any related bodies corporate, as the context requires.
- UK GDPR
- The General Data Protection Regulation as it forms part of the law of England and Wales, Scotland, and Northern Ireland by virtue of section 3 of the European Union (Withdrawal) Act 2018, as amended from time to time.
Interpretation
In this Privacy Policy:
- Headings are for convenience only and do not affect interpretation.
- The singular includes the plural and vice versa.
- References to legislation include any amendment, replacement, or re-enactment.
- References to a person include an individual, company, partnership, or other legal entity.
- References to “writing” include electronic communications.
- Where a word or phrase is defined, other grammatical forms of that word or phrase have corresponding meanings.
End of Privacy Policy