Privacy Policy
About
Risk & Security Management Pty Ltd (RiskSec, we, us, our) provides receivables management, repossessions and asset recovery, field services, process serving, skip tracing, investigations and due diligence, floor plan audits and brand protection services across Australia. Handling personal information is central to what we do, and we are committed to managing it responsibly, lawfully and transparently.
We are an APP entity bound by the Privacy Act 1988 (Cth) (Privacy Act) and the Australian Privacy Principles (APPs). Where or if we handle credit-related information, we are also bound by Part IIIA of the Privacy Act and the Privacy (Credit Reporting) Code (CR Code). This document is our APP privacy policy for the purposes of APP 1. It explains what personal information we collect and hold, how and why we handle it, when it may be sent overseas, how we use artificial intelligence, and how you can access or correct your information or make a complaint.
Definitions
The following definitions apply in this policy:
“Artificial Intelligence”, or “AI” refers to a tool that uses algorithmic or machine learning functionality to perform tasks that would ordinarily require a human to complete. This includes, but is not limited to, generative AI, machine learning, natural language processing and large language models.
Site means the RiskSec website (www.risksec.com.au) including without limitation all subpages, portal or other system that you use to provide instructions or information to RiskSec.
What do we mean by personal information
Personal information has the meaning given to it in the Privacy Act 1988 (Cth), and means information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether or not it is true and whether or not it is recorded in a material form.
Sensitive information has the meaning given in the Privacy Act. It includes information about a person’s health, racial or ethnic origin, religious beliefs, political opinions, membership of a professional or trade association or a trade union, sexual orientation and criminal record, and attracts a higher level of protection.
Given the nature of our work (including investigations and skip tracing), we may from time to time collect sensitive information, and where we do we handle it in accordance with APP 3.
Credit information and credit eligibility information have the meanings given in the Privacy Act and are handled under Part IIIA and the CR Code.
The kinds of personal information we collect and hold
Depending on our relationship with you and the services we are engaged to provide, the personal information we collect and hold may include:
identity and contact details - name, aliases and former names, date of birth, residential, postal and business addresses, email addresses and telephone numbers;
financial and account information - account numbers, balances, payment history, the details of debts owed and arrangements to repay them;
asset information - vehicle, equipment or property details relevant to a repossession, audit or recovery;
information collected in the field - records of attempted and completed service of documents, repossessions, inspections and audits, including file notes, photographs, location/GPS data and, where used, body-worn or vehicle camera footage;
information collected during investigations, due diligence and skip tracing - including information lawfully obtained from public registers, databases and other sources;
call recordings and communications - recordings of inbound and outbound telephone calls and records of our correspondence with you;
employment and contractor information - for our staff, contractors, agents and job applicants; and
website and technical information - see “Our website, cookies and analytics” below.
We collect sensitive information only where it is reasonably necessary for one or more of our functions or activities and where you have consented or another exception under APP 3 applies.
How we collect personal information
Where it is reasonable and practicable to do so, we collect personal information directly from you - for example when you contact us, complete a form on our website, instruct us, make a payment, or communicate with our staff.
Because of the nature of our services, we also lawfully collect personal information about individuals from sources other than the individual - for example from the clients who instruct us (such as creditors, financiers, insurers, lawyers and their agents), from public registers and records, and from other third parties - where it is unreasonable or impracticable to collect it directly, or where we are engaged to locate, investigate, serve, audit or recover from an individual.
Call recording. We record inbound and outbound telephone calls for the purposes described in “Why we collect, hold, use and disclose personal information” below. Where required, we notify you at the start of the call that it is being, or may be, recorded. Our call recording practices are governed by the Telecommunications (Interception and Access) Act 1979 (Cth) and the surveillance, listening and tracking devices laws of the relevant State or Territory.
User consent
By submitting personal information through our Site or by otherwise providing it to us, you agree to the terms of this policy on your own behalf or on behalf of the person whose information you are submitting, and you expressly consent to the collection, use and disclosure of that personal information in accordance with this policy.
Why we collect, hold, use and disclose personal information
We collect, hold, use and disclose personal information for purposes connected with providing our services and running our business, including to:
receive and act on instructions from our clients and provide the services we are engaged to perform;
locate individuals and assets, serve documents, recover debts and assets, conduct inspections, audits and investigations, and report outcomes to our clients;
communicate with you, respond to enquiries, and administer accounts, invoices and payments;
verify identity and conduct due diligence;
train our staff and undertake compliance reviews and quality assurance, including by reviewing call recordings and field records to monitor and improve the safety, quality and integrity of our services;
manage risk, protect our staff and clients, and detect and prevent fraud and misconduct;
comply with our legal and regulatory obligations and establish, exercise or defend legal claims; and
for other related purposes that you would reasonably expect.
We use and disclose personal information for the primary purpose for which it was collected, for related purposes you would reasonably expect (or, for sensitive information, directly related purposes), and otherwise where you have consented or the use or disclosure is required or authorised by or under an Australian law or a court or tribunal order.
Use of artificial intelligence and automated processing
We use technology, including software that applies artificial intelligence (AI) and machine learning, to help us deliver and improve our services and to operate efficiently. For example, we may use these tools to process emails, invoices or other data that is sent to us, detect errors, support quality assurance and training, prioritise and allocate work, and otherwise provide services. AI may also support administrative, operational and quality assurance activities, including document review, summarisation, transcription where enabled, internal reporting, staff training and service improvement.
Where we use AI tools, personal information may be processed by those tools. Some are provided by third parties who may store or process that information overseas. We take reasonable steps to ensure that our AI tools and the providers of them handle personal information consistently with this policy and the APPs, including through contractual protections, access controls, staff training and human oversight, and we do not permit our providers to use personal information you have entrusted to us to train their own general-purpose models except where this is disclosed to you and permitted by law.
Automated decision-making
From 10 December 2026, new transparency obligations under the Privacy Act (APP 1.7–1.9, inserted by the Privacy and Other Legislation Amendment Act 2024 (Cth)) require us to describe in this policy any arrangement under which a computer program uses personal information to make, or to substantially and directly assist in making, a decision that could reasonably be expected to significantly affect an individual's rights or interests.
We do not use solely automated processing to make decisions that could significantly affect your rights or interests without meaningful human involvement.
To whom we disclose personal information
In providing our services and running our business, we may disclose personal information to:
the clients who instruct us, and their agents and advisers;
our related bodies corporate;
our contractors, agents and field officers who perform services on our behalf;
IT, cloud, communications, AI and other service providers and consultants;
credit reporting bodies, financiers, insurers, and other debt recovery and mercantile agents;
our professional advisers, including lawyers and accountants;
courts, tribunals, regulators, law enforcement and government agencies; and
any other person where you have consented or the disclosure is required or authorised by or under law.
We do not sell or rent your personal information, and we do not disclose it to other organisations for their own marketing.
We take reasonable steps to ensure that these recipients do not use or disclose your personal information other than for the purposes for which we provided it
Other disclosures
Regardless of any choices you make regarding your personal information, we may disclose personal information to third parties if we believe in good faith that such disclosure is necessary:
in connection with any legal investigation;
to comply with relevant laws, or to respond to subpoenas or warrants served on us;
to lessen or prevent a serious threat to the life, health or safety of an individual or to public safety;
to investigate or assist in preventing any violation or potential violation of the law;
where another “permitted general situation” or “permitted health situation” (as defined in the Privacy Act) applies; and/or
where disclosure is reasonably necessary for a law enforcement related activity.
Sending personal information overseas
Some of the service providers we rely on - including cloud hosting, communications and AI providers - may store or process personal information outside Australia. As a result, we are likely to disclose some personal information to overseas recipients. The countries in which those recipients are likely to be located include the United States of America or Europe.
Before disclosing personal information overseas, we take reasonable steps to ensure that the overseas recipient handles it in a way consistent with the APPs, for example through contractual commitments.
Direct marketing
We may use your contact details to tell you about our services where you would reasonably expect us to do so or where you have consented. You can ask us to stop sending you direct marketing at any time using the contact details in “How to contact us” below, and we will action your request. We do not use or disclose sensitive information for direct marketing without your consent.
Keeping personal information accurate
We take reasonable steps to ensure the personal information we collect, use and disclose is accurate, up to date, complete and relevant. We rely in part on you to tell us when your information changes. If you believe information we hold about you is inaccurate, please contact us.
How we keep personal information secure
Keeping personal information secure is a high priority. We take reasonable steps to protect the personal information we hold from misuse, interference and loss, and from unauthorised access, modification or disclosure. These steps include a combination of physical, technical and organisational measures such as access controls, encryption where appropriate, staff training and supplier due diligence.
When personal information is no longer needed for any purpose for which it may be used or disclosed, and we are not required by law to retain it, we take reasonable steps to destroy it or de-identify it.
You may request deletion of your personal information by us, but please note that we may not delete it if we feel it is reasonable to keep the information (or choose to keep this information for a certain time, in which case we will comply with your deletion request only after we have fulfilled such requirements).
How long we keep personal information
We keep personal information only for as long as it is needed for the purposes described in this policy or as required by law. Retention periods vary depending on the type of information and the legal, contractual and evidentiary reasons for holding it - for example, records relating to debt recovery, repossessions, service of process and investigations may need to be retained to meet client, regulatory or evidentiary requirements.
Accessing and correcting your personal information
You may ask us for access to the personal information we hold about you, and to correct it if it is inaccurate, out of date, incomplete, irrelevant or misleading. To make a request, please contact our Privacy Officer. We will respond within a reasonable period. There are some circumstances in which we may not be able to give access or make a correction - for example where doing so would be unlawful, would prejudice an investigation or enforcement activity, or where another exception under APP 12 or APP 13 applies. If we refuse, we will tell you why in writing (except where it would be unreasonable to do so) and how you can complain.
Dealing with us anonymously
Where it is lawful and practicable, you have the option of dealing with us anonymously or using a pseudonym. In many cases, however, we will not be able to provide our services, respond to your enquiry, or act on instructions, unless we can identify you and the individuals concerned.
Government-related identifiers
We do not adopt a government-related identifier (such as a driver licence, Medicare or tax file number) as our own identifier of you, and we use or disclose such identifiers only where permitted under APP 9 - for example where reasonably necessary to verify identity or fulfil our obligations to an agency or where required or authorised by law.
Our website, cookies and analytics
When you visit our website we may collect information about your use of it, some of which may identify you. This can include the pages you visit, your browser and operating system, the referring site, your IP address and clickstream information. We may use cookies and analytics tools to understand how our website is used and to improve it. You can set your browser to refuse cookies, though some parts of the site may not work as intended if you do.
Data breaches
We maintain procedures to detect, assess, contain and respond to data breaches. If a data breach involving your personal information is likely to result in serious harm, we will notify you and the Office of the Australian Information Commissioner (OAIC) as required by the Notifiable Data Breaches scheme under Part IIIC of the Privacy Act.
Making a privacy complaint
If you have a concern or complaint about how we have handled your personal information, please contact our Privacy Officer using the details in “How to contact us” below. We will acknowledge your complaint, investigate it, and respond to you within a reasonable period, usually within 30 days.
If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner: online at www.oaic.gov.au, by phone on 1300 363 992, or by writing to GPO Box 5288, Sydney NSW 2001.
Changes to this policy
We may update this policy from time to time to reflect changes in our practices or the law. The current version is available on our website, and the effective date appears at the top of this document. We encourage you to review it periodically.
How to contact us
You can contact our Privacy Officer:
by email at compliancedepartment@risksec.com.au;
by telephone on 1300 712 978; or
by post to The Privacy Officer, Risk & Security Management, GPO Box 2940, Brisbane QLD 4001