Privacy Policy · policy version c4b5a0e
Privacy Policy — SNS ClockedIn
Version: 1.0.0
Effective date: 1 May 2026
Last updated: 28 April 2026
SNS Tech Pty Ltd (ABN: [COMPANY ABN]) ("we", "us", "our") operates SNS ClockedIn, a cloud-based HR, attendance, and payroll platform ("the Platform"). This Privacy Policy explains how we collect, use, disclose, and manage personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs 1–13).
1. Who we are (APP 1)
SNS Tech Pty Ltd
Address: [REGISTERED ADDRESS]
Email: privacy@snsclockedin.com.au
Phone: [CONTACT PHONE]
Our Privacy Officer is responsible for handling enquiries, access requests, and complaints about our handling of personal information.
2. What personal information we collect (APP 3)
We collect personal information necessary to provide the Platform's HR, attendance, payroll, and related services. This includes:
Employee and contractor data:
- Full name, date of birth, gender
- Contact details (email, phone, address)
- Employment information (role, department, start date, salary, award classification)
- Attendance and leave records
- Payroll data including Tax File Number (TFN), bank account details, superannuation fund information
- PAYG withholding details and tax declarations
- Performance reviews and training records
- Identity documents required by Fair Work or ATO regulations
Business (tenant) data:
- ABN, ACN, and business registration details
- Contact persons and administrators
- Billing and payment information
Platform usage data:
- Login timestamps and device information
- IP addresses and browser/app metadata (for security and audit purposes)
- Activity logs retained for the periods required by applicable law
We collect this information directly from you or from your employer (the Platform subscriber). We may also receive information from government agencies (e.g. the ATO's stapled super fund lookup) where you or your employer has authorised this.
3. Why we collect personal information — the primary purpose (APP 3, APP 5)
We collect and use personal information to:
- Provide attendance tracking, leave management, payroll processing, and HR management services.
- Comply with our legal obligations under the Fair Work Act 2009, Superannuation Guarantee (Administration) Act 1992, Single Touch Payroll (STP) Phase 2 requirements, and the Income Tax Assessment Act 1997.
- Communicate with you about your account, service updates, and security matters.
- Process payments and manage billing.
- Improve the Platform through aggregated, de-identified analytics.
- Investigate and respond to incidents, complaints, or security threats.
We will tell you (or your employer) the primary purpose for collecting information at or before the time of collection (APP 5).
4. Secondary purposes and direct marketing (APP 3.3)
We do not use employee data for direct marketing without separate, explicit consent. We may send administrative or service communications related to your employer's subscription.
If you receive direct marketing from us and wish to opt out, contact privacy@snsclockedin.com.au or use the unsubscribe mechanism in any marketing email. We honour all opt-out requests within 5 business days.
5. Disclosure of personal information (APP 6)
We disclose personal information only:
- To the employer (tenant) who subscribes to the Platform, for workforce management purposes.
- To government bodies where required by law (e.g. ATO STP reporting, Fair Work Ombudsman requests).
- To sub-processors who assist in delivering the Platform (see Section 10 — Sub-processors and APP 8).
- In response to a court order, legal process, or law enforcement request.
- To protect the safety of any person or to prevent fraud.
We do not sell personal information to third parties.
6. Tax File Numbers (TFN)
Where TFNs are collected, we handle them strictly under the Privacy (Tax File Number) Rule 2015:
- TFNs are encrypted at rest using AES-256-GCM.
- TFNs are never logged, included in error messages, or disclosed beyond their authorised purpose.
- Only authorised payroll processing systems access TFNs; access is logged.
- TFNs are used solely for payroll withholding, STP reporting, and superannuation purposes.
7. Security and storage (APP 11)
We take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access including:
- Encryption of sensitive data in transit (TLS 1.2+) and at rest (AES-256).
- Role-based access controls enforced at the application layer.
- Multi-factor authentication for all administrative access.
- Regular security assessments and penetration testing.
- Audit logging of all access to sensitive records.
8. Data retention (APP 11.2, Fair Work Act)
We retain personal information for the minimum period required by law:
| Record type | Retention period | Legal basis |
|---|---|---|
| Payroll records | 7 years from creation | Fair Work Regulations 3.44 |
| Attendance records | 7 years | Fair Work Regulations 3.33 |
| Leave records | 7 years | Fair Work Regulations 3.38 |
| TFN records | For the duration of employment + 7 years | Privacy (Tax File Number) Rule |
| STP submission records | 5 years | ATO record-keeping rules |
| Superannuation records | 5 years | SG Administration Act s. 46 |
After the retention period, records are securely deleted or de-identified. A 90-day grace window applies before deletion occurs.
9. Access and correction (APP 12, APP 13)
You have the right to request access to your personal information held by us and to request corrections.
Submit requests via:
- In-Platform: Settings → Privacy → My Data Export
- Email: privacy@snsclockedin.com.au
We will respond within 30 days. We may charge a reasonable fee to cover retrieval costs for large access requests.
If we correct your information, we will notify third parties to whom it was recently disclosed (where practicable).
10. Sub-processors and cross-border disclosure (APP 8)
Some personal information may be transferred to, or accessed by, our sub-processors:
| Sub-processor | Location | Purpose |
|---|---|---|
| MongoDB Atlas (AU) | Australia (ap-southeast-2) | Tenant data storage |
| Amazon Web Services (AU) | Australia (ap-southeast-2) | Infrastructure and storage |
| Redis Cloud (AU) | Australia | Session and cache storage |
| SendGrid / SES | United States | Transactional email delivery |
| Firebase (Google) | United States | Push notifications |
| Sentry | United States | Error monitoring |
| PayPal | United States | Payment processing |
For transfers outside Australia, we ensure equivalent protection under APP 8.2 through contractual clauses and adherence to applicable data protection frameworks.
11. Notifiable Data Breaches (NDB scheme — Part IIIC Privacy Act)
If we experience an eligible data breach that is likely to result in serious harm to affected individuals, we will:
- Notify the Office of the Australian Information Commissioner (OAIC) as soon as practicable (target: within 72 hours of completing the assessment).
- Notify affected individuals directly via email where contact details are available.
Notifications will include the nature of the breach, the information involved, and recommended steps to protect affected individuals.
12. Complaints (APP 1.3)
If you have a complaint about our handling of your personal information:
- Contact our Privacy Officer at privacy@snsclockedin.com.au.
- We will acknowledge your complaint within 5 business days and respond within 30 days.
- If you are not satisfied with our response, you may lodge a complaint with the OAIC at oaic.gov.au.
13. Changes to this policy
We may update this policy from time to time. We will notify affected parties by email or in-Platform notification at least 14 days before significant changes take effect. The current version is always available at /legal/privacy-policy.
APP compliance index
| APP | Requirement | Section |
|---|---|---|
| APP 1 | Open and transparent management | Section 1 |
| APP 2 | Anonymity and pseudonymity | Not applicable (identity required for payroll/FW obligations) |
| APP 3 | Collection of solicited personal information | Sections 2–3 |
| APP 4 | Unsolicited personal information | Treated per APP 3 on receipt |
| APP 5 | Notification of collection | Section 3; Collection Notice provided at registration |
| APP 6 | Use and disclosure | Sections 4–5 |
| APP 7 | Direct marketing | Section 4 |
| APP 8 | Cross-border disclosure | Section 10 |
| APP 9 | Adoption of government identifiers | TFN — Section 6; no other gov identifiers adopted |
| APP 10 | Quality of personal information | Employees correct via APP 13 |
| APP 11 | Security of personal information | Sections 7–8 |
| APP 12 | Access to personal information | Section 9 |
| APP 13 | Correction of personal information | Section 9 |