Privacy Policy · policy version c4b5a0e

Privacy Policy — SNS ClockedIn

Version: 1.0.0
Effective date: 1 May 2026
Last updated: 28 April 2026


SNS Tech Pty Ltd (ABN: [COMPANY ABN]) ("we", "us", "our") operates SNS ClockedIn, a cloud-based HR, attendance, and payroll platform ("the Platform"). This Privacy Policy explains how we collect, use, disclose, and manage personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs 1–13).


1. Who we are (APP 1)

SNS Tech Pty Ltd
Address: [REGISTERED ADDRESS]
Email: privacy@snsclockedin.com.au
Phone: [CONTACT PHONE]

Our Privacy Officer is responsible for handling enquiries, access requests, and complaints about our handling of personal information.


2. What personal information we collect (APP 3)

We collect personal information necessary to provide the Platform's HR, attendance, payroll, and related services. This includes:

Employee and contractor data:

  • Full name, date of birth, gender
  • Contact details (email, phone, address)
  • Employment information (role, department, start date, salary, award classification)
  • Attendance and leave records
  • Payroll data including Tax File Number (TFN), bank account details, superannuation fund information
  • PAYG withholding details and tax declarations
  • Performance reviews and training records
  • Identity documents required by Fair Work or ATO regulations

Business (tenant) data:

  • ABN, ACN, and business registration details
  • Contact persons and administrators
  • Billing and payment information

Platform usage data:

  • Login timestamps and device information
  • IP addresses and browser/app metadata (for security and audit purposes)
  • Activity logs retained for the periods required by applicable law

We collect this information directly from you or from your employer (the Platform subscriber). We may also receive information from government agencies (e.g. the ATO's stapled super fund lookup) where you or your employer has authorised this.


3. Why we collect personal information — the primary purpose (APP 3, APP 5)

We collect and use personal information to:

  1. Provide attendance tracking, leave management, payroll processing, and HR management services.
  2. Comply with our legal obligations under the Fair Work Act 2009, Superannuation Guarantee (Administration) Act 1992, Single Touch Payroll (STP) Phase 2 requirements, and the Income Tax Assessment Act 1997.
  3. Communicate with you about your account, service updates, and security matters.
  4. Process payments and manage billing.
  5. Improve the Platform through aggregated, de-identified analytics.
  6. Investigate and respond to incidents, complaints, or security threats.

We will tell you (or your employer) the primary purpose for collecting information at or before the time of collection (APP 5).


4. Secondary purposes and direct marketing (APP 3.3)

We do not use employee data for direct marketing without separate, explicit consent. We may send administrative or service communications related to your employer's subscription.

If you receive direct marketing from us and wish to opt out, contact privacy@snsclockedin.com.au or use the unsubscribe mechanism in any marketing email. We honour all opt-out requests within 5 business days.


5. Disclosure of personal information (APP 6)

We disclose personal information only:

  • To the employer (tenant) who subscribes to the Platform, for workforce management purposes.
  • To government bodies where required by law (e.g. ATO STP reporting, Fair Work Ombudsman requests).
  • To sub-processors who assist in delivering the Platform (see Section 10 — Sub-processors and APP 8).
  • In response to a court order, legal process, or law enforcement request.
  • To protect the safety of any person or to prevent fraud.

We do not sell personal information to third parties.


6. Tax File Numbers (TFN)

Where TFNs are collected, we handle them strictly under the Privacy (Tax File Number) Rule 2015:

  • TFNs are encrypted at rest using AES-256-GCM.
  • TFNs are never logged, included in error messages, or disclosed beyond their authorised purpose.
  • Only authorised payroll processing systems access TFNs; access is logged.
  • TFNs are used solely for payroll withholding, STP reporting, and superannuation purposes.

7. Security and storage (APP 11)

We take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access including:

  • Encryption of sensitive data in transit (TLS 1.2+) and at rest (AES-256).
  • Role-based access controls enforced at the application layer.
  • Multi-factor authentication for all administrative access.
  • Regular security assessments and penetration testing.
  • Audit logging of all access to sensitive records.

8. Data retention (APP 11.2, Fair Work Act)

We retain personal information for the minimum period required by law:

Record typeRetention periodLegal basis
Payroll records7 years from creationFair Work Regulations 3.44
Attendance records7 yearsFair Work Regulations 3.33
Leave records7 yearsFair Work Regulations 3.38
TFN recordsFor the duration of employment + 7 yearsPrivacy (Tax File Number) Rule
STP submission records5 yearsATO record-keeping rules
Superannuation records5 yearsSG Administration Act s. 46

After the retention period, records are securely deleted or de-identified. A 90-day grace window applies before deletion occurs.


9. Access and correction (APP 12, APP 13)

You have the right to request access to your personal information held by us and to request corrections.

Submit requests via:

We will respond within 30 days. We may charge a reasonable fee to cover retrieval costs for large access requests.

If we correct your information, we will notify third parties to whom it was recently disclosed (where practicable).


10. Sub-processors and cross-border disclosure (APP 8)

Some personal information may be transferred to, or accessed by, our sub-processors:

Sub-processorLocationPurpose
MongoDB Atlas (AU)Australia (ap-southeast-2)Tenant data storage
Amazon Web Services (AU)Australia (ap-southeast-2)Infrastructure and storage
Redis Cloud (AU)AustraliaSession and cache storage
SendGrid / SESUnited StatesTransactional email delivery
Firebase (Google)United StatesPush notifications
SentryUnited StatesError monitoring
PayPalUnited StatesPayment processing

For transfers outside Australia, we ensure equivalent protection under APP 8.2 through contractual clauses and adherence to applicable data protection frameworks.


11. Notifiable Data Breaches (NDB scheme — Part IIIC Privacy Act)

If we experience an eligible data breach that is likely to result in serious harm to affected individuals, we will:

  1. Notify the Office of the Australian Information Commissioner (OAIC) as soon as practicable (target: within 72 hours of completing the assessment).
  2. Notify affected individuals directly via email where contact details are available.

Notifications will include the nature of the breach, the information involved, and recommended steps to protect affected individuals.


12. Complaints (APP 1.3)

If you have a complaint about our handling of your personal information:

  1. Contact our Privacy Officer at privacy@snsclockedin.com.au.
  2. We will acknowledge your complaint within 5 business days and respond within 30 days.
  3. If you are not satisfied with our response, you may lodge a complaint with the OAIC at oaic.gov.au.

13. Changes to this policy

We may update this policy from time to time. We will notify affected parties by email or in-Platform notification at least 14 days before significant changes take effect. The current version is always available at /legal/privacy-policy.


APP compliance index

APPRequirementSection
APP 1Open and transparent managementSection 1
APP 2Anonymity and pseudonymityNot applicable (identity required for payroll/FW obligations)
APP 3Collection of solicited personal informationSections 2–3
APP 4Unsolicited personal informationTreated per APP 3 on receipt
APP 5Notification of collectionSection 3; Collection Notice provided at registration
APP 6Use and disclosureSections 4–5
APP 7Direct marketingSection 4
APP 8Cross-border disclosureSection 10
APP 9Adoption of government identifiersTFN — Section 6; no other gov identifiers adopted
APP 10Quality of personal informationEmployees correct via APP 13
APP 11Security of personal informationSections 7–8
APP 12Access to personal informationSection 9
APP 13Correction of personal informationSection 9