Privacy policy

TriMation Privacy Policy (Australia)

Last updated: 01 September 2025

TriMation Pty Ltd (ABN [82 626 516 952]) (“TriMation”, “we”, “us”, “our”) respects your privacy and is committed to managing personal information in an open and transparent way in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

This Privacy Policy explains the kinds of personal information we collect, how we collect, use, disclose and store it, whether we disclose it overseas, and how you can access and correct your information or make a complaint.

How to contact us (privacy enquiries):
Email: privacy@trimation.com.au
You may request this policy in another format (e.g., large print).


1. What this policy covers (APP 1)

This policy applies to personal information we handle in the course of:

  • Website and marketing (e.g., enquiries, newsletter sign-ups, cookies/analytics).

  • Sales and account administration (quotes, contracts, billing).

  • Service delivery (consulting, integration support, training, and managed services).

Controller/processor roles: For many service engagements we act as a service provider processing data on our client’s instructions (e.g., when we help a council or school implement an integration platform). In those cases, the council remains the controller for its residents’ and staff personal information. We also collect and control personal information about our own contacts and users (e.g., website users, attendees at training, billing contacts).


2. The kinds of personal information we collect (APP 1.4(c), APP 3)

Depending on context, we may collect:

  • Identification & contact: name, job title, organisation, email, phone, address.

  • Account/admin: login details for TriMation portals we operate for you, role/permissions, support interactions, training records.

  • Business relations: procurement data, statements of work, purchase orders, invoices, payment status (we use PCI-compliant processors for payment; we do not store card numbers).

  • Website/analytics: device/browser information, IP address, pages viewed, referral source, and cookie/pixel identifiers (see Cookies & Tracking).

  • Service delivery data: artefacts needed to deliver services (e.g., configuration notes, test data you provide). When we support your integration projects, client data sets (including residents/staff information) remain under your control; we only access such data if you instruct us and with least-privilege access.

Sensitive information: We do not seek to collect sensitive information (e.g., health, biometrics) and will only do so with your consent or if permitted/required by law.

Government identifiers: We do not adopt, use or disclose government-related identifiers (e.g., Medicare/TFN) as our own except as permitted by law (APP 9).


3. How we collect personal information (APP 1.4(c), APP 5)

We collect personal information:

  • Directly from you: via our website forms, emails, phone, online meetings, events, training, and during service engagements.

  • From your authorised representatives: colleagues who add you as a contact or user.

  • From systems you ask us to integrate with: when you authorise us to access certain tools (e.g., ticketing or identity systems) for support or build work.

  • Automatically: through cookies/analytics when you visit our website (see Cookies & Tracking).

If you don’t provide information we request, we may be unable to respond to your enquiry, provide a quote, create an account, or deliver some services.

Collection notice (APP 5)
At or before the time we collect personal information (or as soon as practicable), we will take reasonable steps to inform you of: our identity and contact details; the purposes of collection; the consequences if you don’t provide it; the usual disclosures; how to access and correct; how to complain; and whether we are likely to disclose overseas.


4. Purpose of collection and use/disclosure (APP 6 & APP 7)

We use personal information to:

  • Provide and support our services (consulting, integration support, training, managed services).

  • Operate our business (quotes, contracts, billing, account management, service notifications).

  • Improve our website/services (analytics, security, quality assurance).

  • Direct marketing: We may send you updates about relevant services or events in compliance with APP 7 and Spam Act 2003 (Cth). You can opt out at any time via unsubscribe links or by contacting us. On request, we will tell you the source from which we obtained your personal information, unless unreasonable or impracticable.

We may disclose personal information to:

  • Our personnel and Australian delivery partners (e.g., specialist subcontractors), on a least-privilege, need-to-know basis under confidentiality obligations.

  • Your nominated platforms/providers where you instruct us to integrate or support them.

  • Our service providers (e.g., secure cloud/IT, email, document, analytics, payment processors).

  • Regulators, law enforcement, or as required by law (e.g., court orders, statutory notices).

  • A purchaser in the event of a business transfer, under confidentiality and subject to law.

We do not sell personal information.


5. Anonymity and pseudonymity (APP 2)

Where lawful and practicable (e.g., general website enquiries), you may interact with us anonymously or under a pseudonym. Some activities—such as account creation, service delivery, security checks and billing—require identification.


6. Cross-border disclosure (APP 8)

Our default position is to host and process personal information in Australia.
If a specific service requires an overseas disclosure, we will first take reasonable steps to ensure the overseas recipient will handle your personal information consistently with the APPs. Such steps may include enforceable contractual terms, due-diligence, and appropriate technical/organisational controls. Where practicable, we will inform you of the countries involved before disclosure.

For client engagements where we act on your instructions, we will work with you to ensure any cross-border handling aligns with your policies and legal obligations.


7. Data quality (APP 10)

We take reasonable steps to ensure personal information we collect, use or disclose is accurate, up-to-date, complete and relevant. Please let us know if your details change.


8. Security and retention (APP 11) + Notifiable Data Breaches (NDB)

We take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access, modification or disclosure, including:

  • Access control and least-privilege role management;

  • Encryption in transit; secure hosting providers;

  • Staff confidentiality undertakings and privacy/security training;

  • Vendor and subcontractor due-diligence and contractual safeguards;

  • Secure development and change management practices;

  • Logging and monitoring appropriate to the risk.

We retain personal information only as long as needed for our functions or legal obligations and then destroy or de-identify it safely.

Data breach response (NDB scheme): If we suspect an eligible data breach, we will promptly assess the incident and, where required, notify affected individuals and the Office of the Australian Information Commissioner (OAIC), including steps individuals should take.


9. Access to and correction of personal information (APP 12 & 13)

  • Access: You may request access to the personal information we hold about you. We will respond within a reasonable period (generally within 30 days). We do not charge for making an access request; if a fee applies for providing access (e.g., copying), it will not be excessive. If we refuse access, we will provide written reasons and details of how to complain.

  • Correction: You may request correction if you believe your personal information is inaccurate, out-of-date, incomplete, irrelevant or misleading. We will respond within a reasonable period (generally within 30 days) and we do not charge for correction or for associating a statement with your record.

Contact: privacy@trimation.com.au


10. Cookies & tracking (APP 1 & 5 transparency)

We use cookies and may use third-party analytics/advertising tags (e.g., Google) to understand site usage and improve services. Cookies are small files stored on your device. You can manage cookies in your browser settings; some features may not function without them.

We aim to provide clear choices about cookies/third-party tracking. See our Cookie Notice (linked from our website footer) for:

  • The categories of cookies we use;

  • Third-party analytics/advertising partners;

  • How to manage/opt out (browser settings, partner opt-outs).

We do not seek to collect personal information covertly via tracking technologies.


11. Third-party websites

Our website may contain links to third-party sites. We are not responsible for the privacy practices of those sites. We recommend you review their privacy policies.


12. Complaints (APP 1.4(f))

If you have concerns about how we have managed your personal information, please contact our Privacy Officer at privacy@trimation.com.au. We will acknowledge your complaint and aim to provide a written response within 30 days.

If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC):
Website: www.oaic.gov.au | Phone: 1300 363 992 | Mail: GPO Box 5218, Sydney NSW 2001


13. Changes to this policy

We may update this policy from time to time. The “Last updated” date will change accordingly. For material changes, we will take reasonable steps to notify you (e.g., website notice or email where appropriate).


14. Additional notes for government clients

Where we deliver services to public sector clients (e.g., councils), we will:

  • Operate under client-approved RBAC with least-privilege access;

  • Follow the client’s data-handling policies and recordkeeping schedules;

  • Avoid overseas disclosures unless explicitly approved and protected as per APP 8;

  • Support audit and evidence requirements (e.g., staff confidentiality, training, vendor due-diligence);

  • Assist with retention/export of logs/records to client-controlled systems to meet legislation (e.g., State Records Acts).

Scroll to Top