Privacy Policy

Peritus Technology Pty Ltd is committed to protecting personal information and handling it lawfully, fairly, transparently and securely.

This Privacy Policy explains how we collect, hold, use, disclose, protect and manage personal information in connection with our business, including our parking technology, access-control, enforcement, permit, payment, maintenance, customer-support and related services.

1. Who this policy applies to

This policy applies to personal information handled by Peritus Technology Pty Ltd in relation to:

  • customers, prospective customers and client representatives;

  • parking users, permit holders and vehicle operators;

  • suppliers, contractors and business partners;

  • job applicants, employees and former employees;

  • people who contact us, visit our website, use our services or make an enquiry or complaint; and

  • individuals whose information we handle on behalf of a client.

Where we provide services to a council, parking operator, property owner or other client, we may handle personal information on that client’s behalf. In those circumstances, the client may also have its own privacy policy and may be responsible for some collection notices, decisions and responses to privacy requests.

2. Personal information we may collect

The types of personal information we collect depend on the nature of the relationship or service. This may include:

  • name, address, email address, telephone number, job title and organisation;

  • customer, supplier, contract, billing, service and support records;

  • vehicle registration numbers, permit details, parking location, parking time and duration, access events, payment or transaction status, review or appeal records and enforcement-related information;

  • photographs, video, ANPR records, device identifiers, system logs and audit records where relevant to the services we provide;

  • payment, refund, invoicing and account information;

  • recruitment and employment information, including resumes, licences, qualifications, right-to-work information, payroll, tax, superannuation, training, leave, performance, safety and workers compensation records;

  • health, injury or sensitive information where reasonably necessary, consented to, or required or authorised by law;

  • website, cookie, enquiry, marketing preference and communication information; and

  • any other information reasonably required for our business, services, legal obligations or client contracts.

We do not generally retain full payment-card details. Where card payments are processed, these may be handled directly by authorised payment service providers.

3. How we collect personal information

We usually collect personal information directly from the individual, including through forms, contracts, emails, telephone calls, websites, service requests, support interactions, parking or access-control equipment, recruitment processes and workplace systems.

We may also collect personal information from clients, councils, parking operators, employers, authorised representatives, technology platforms, payment providers, recruitment agencies, referees, insurers, public registers, regulatory bodies and other lawful sources.

Where required, we will provide or make available a collection notice explaining why information is collected, how it may be used, who it may be disclosed to and how privacy rights can be exercised.

4. Why we collect, use and disclose personal information

We collect, hold, use and disclose personal information for purposes including:

  • supplying, installing, operating, maintaining and supporting parking, permit, enforcement, access-control, payment and related technology;

  • managing customer, supplier, contractor and business relationships;

  • providing help-desk, field-service, fault-response, call-centre, training and professional services;

  • processing parking, permit, access, vehicle, payment, review or enforcement information where authorised by a client, contract or law;

  • verifying identity, managing access, protecting systems, preventing fraud and investigating incidents;

  • processing accounts, invoices, payments, refunds, warranties and service levels;

  • recruitment, employment, payroll, taxation, superannuation, training, work health and safety and workers compensation administration;

  • responding to enquiries, complaints, disputes, legal claims and regulatory requirements;

  • quality assurance, reporting, analytics, business planning and service improvement;

  • direct marketing where permitted by law and subject to opt-out rights; and

  • any other purpose required or authorised by law, consented to, or reasonably expected in connection with our services.

5. Who we may disclose personal information to

We may disclose personal information where reasonably necessary to:

  • the relevant client, council, parking operator, property owner, employer or authorised representative;

  • software, cloud hosting, telecommunications, payment, data storage, cyber security and technology-support providers;

  • field-service, installation, logistics, printing, mailing and customer-support providers;

  • professional advisers, auditors, insurers, banks, payroll providers and superannuation funds;

  • regulators, courts, tribunals, law-enforcement bodies and government agencies where required or authorised by law;

  • another party involved in a business transaction, restructure or transfer of assets, subject to appropriate confidentiality controls; and

  • any other person or organisation where the individual has consented or where disclosure is permitted or required by law.

We require service providers and contractors who handle personal information for us to protect that information and use it only for authorised purposes.

6. Overseas disclosure and cloud services

Peritus Technology may use technology, hosting, software, support or cloud-service providers that operate in Australia or overseas. This means personal information may be stored in, accessed from or disclosed to overseas locations where those approved providers operate.

This may include the United Kingdom and other countries used by our approved technology, hosting, support or software providers.

Where personal information is disclosed overseas, we will take reasonable steps required by Australian privacy law to ensure the recipient handles the information appropriately, unless a lawful exception applies.

7. Security of personal information

We take reasonable technical, physical and organisational steps to protect personal information from misuse, interference, loss, unauthorised access, modification and disclosure.

These steps may include:

  • role-based access controls and least-privilege permissions;

  • password, authentication and access-review processes;

  • secure storage, transmission and backup controls;

  • system monitoring, logging, patching and cyber-security measures;

  • physical security for premises, equipment, files and devices;

  • confidentiality obligations for employees, contractors and service providers;

  • supplier due diligence and contractual security obligations;

  • privacy and security training;

  • data minimisation, retention review and secure disposal; and

  • incident response and breach-assessment procedures.

No method of electronic transmission or storage is completely secure. However, we seek to apply controls that are proportionate to the nature and sensitivity of the information we handle.

8. Data retention and disposal

We retain personal information only for as long as reasonably required for the purpose for which it was collected, for a related lawful purpose, to satisfy a client contract, to resolve a dispute, to meet insurance or legal requirements, or to comply with record-keeping obligations.

When personal information is no longer required and no legal hold applies, we will take reasonable steps to securely destroy or de-identify it.

9. Accessing or correcting personal information

An individual may request access to personal information we hold about them or ask us to correct information that is inaccurate, out of date, incomplete, irrelevant or misleading.

Requests should be made using the contact details below. We may need to verify identity and authority before responding.

We will respond within a reasonable period. Access or correction may be refused or limited where permitted by law, including where it would affect another person’s privacy, reveal commercially sensitive information, prejudice an investigation or legal proceeding, or where another lawful ground applies.

Where we hold information solely on behalf of a client, we may refer the request to that client for decision and response.

10. Direct marketing

We may use personal information to provide information about Peritus Technology products, services, updates or opportunities where permitted by law.

Marketing communications will include an unsubscribe or opt-out option where required. Service, account, safety, contractual and transactional messages may still be sent where necessary.

11. Monitoring, images, location and recordings

Some Peritus Technology services or workplaces may involve CCTV, ANPR, photographs, system monitoring, access logs, call recording, vehicle records, device location or similar technologies.

These technologies are used only for legitimate purposes, such as service delivery, parking or access administration, safety, security, quality assurance, fraud prevention, asset protection, legal compliance or client contract requirements.

Notices, consent and workplace consultation will be provided where required by law.

12. Computer-assisted and automated decisions

Peritus Technology and the technology solutions it supports may use software to validate data, match vehicle registration information, identify exceptions, prioritise work, generate alerts or assist authorised personnel to make operational decisions.

Where appropriate, material decisions should be capable of review by an authorised person. Individuals may contact us if they believe information used in a decision is incorrect or requires review.

13. Data breaches

Peritus Technology maintains a data-breach response process.

If a suspected data breach occurs, we will take reasonable steps to contain the incident, assess the information involved, evaluate potential harm, take remedial action, preserve relevant evidence, notify affected clients or parties where required, and comply with any notification obligations under the Notifiable Data Breaches scheme.

Where required by law, we will notify the Office of the Australian Information Commissioner and affected individuals as soon as practicable.

14. Privacy complaints

A privacy complaint should be made in writing using the contact details below. The complaint should describe the issue, relevant dates, information or service involved, and the outcome sought.

We will usually acknowledge a complaint within five business days and aim to provide a written response within 30 calendar days. More complex matters may take longer, in which case we will explain the delay.

If the individual is not satisfied with our response, they may contact the Office of the Australian Information Commissioner.

15. Contact details

Privacy Officer
Peritus Technology Pty Ltd
292 City Road
Southbank VIC 3006

Email: [email protected]

Office of the Australian Information Commissioner: www.oaic.gov.au

16. Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in law, technology, contracts, services or our information-handling practices.

The current version will be made available on our website.