Frequently asked questions
Privacy and Data Protection Policy
1. INTRODUCTION
1.1 Purpose
Ad On Workforce ("Ad On Workforce", "we", "us" or "our") is committed to protecting the confidentiality, integrity and security of all information entrusted to us by our clients, employees, contractors and business partners.
As an Australian outsourcing and workforce solutions provider, Ad On Workforce provides businesses with skilled personnel who perform operational, administrative, technical, marketing, financial and support functions on behalf of Australian businesses.
Due to the nature of outsourced workforce arrangements, our personnel frequently access and work within systems, software platforms and digital environments owned and controlled by our clients.
These systems may include, but are not limited to:
- Customer relationship management systems (CRM);
- Accounting platforms;
- Practice management systems;
- Project management systems;
- Enterprise resource planning platforms;
- Email systems;
- Cloud storage environments;
- Marketing platforms;
- Customer databases;
- Booking systems;
- Internal business applications; and
- Other software platforms selected and managed by the client.
This Policy establishes the framework by which Ad On Workforce protects information accessed, processed or handled by our personnel and defines the responsibilities of both Ad On Workforce and our clients regarding information security.
1.2 Relationship Between Ad On Workforce and Client Systems
A fundamental principle of our security framework is that Ad On Workforce generally does not own, control or host the client's operational data.
Rather:
- the client owns and controls their software platforms;
- the client determines what information our personnel can access;
- the client determines the level of permissions granted;
- the client remains responsible for the security configuration of those systems; and
- Ad On Workforce personnel access those systems only to perform agreed services.
Accordingly, Ad On Workforce acts primarily as a service provider processing information on behalf of clients and according to client instructions.
1.3 Purpose of This Policy
This Policy is designed to:
- demonstrate Ad On Workforce's commitment to data protection;
- establish security expectations for employees and contractors;
- explain our information handling practices;
- define responsibilities between Ad On Workforce and clients;
- outline our cyber security controls;
- establish procedures for managing security incidents; and
- provide transparency regarding our privacy practices.
2. DEFINITIONS
For the purposes of this Policy:
"Client"
Means any individual, company or organisation that engages Ad On Workforce to provide outsourcing or workforce services.
"Client Data"
Means any information supplied by, accessed through, or processed on behalf of a client, including:
- customer information;
- employee information;
- financial information;
- commercial information;
- business records;
- confidential information;
- intellectual property; and
- any other information contained within client systems.
"Personal Information"
Has the meaning given under the Privacy Act 1988 (Cth), being information or an opinion about an identified individual or an individual who is reasonably identifiable.
"Client Systems"
Means software platforms, databases, applications or digital environments owned, controlled or licensed by a client.
Examples include:
- Microsoft 365;
- Google Workspace;
- Xero;
- MYOB;
- HubSpot;
- Salesforce;
- Monday.com;
- Simpro;
- ServiceM8;
- industry-specific platforms; and
- other business software.
"Security Incident"
Means any actual or suspected:
- unauthorised access;
- unauthorised disclosure;
- misuse of information;
- loss of information;
- cyber security event;
- compromise of credentials; or
- breach of security controls.
"Personnel"
Means employees, contractors, consultants, temporary workers and any authorised representatives engaged by Ad On Workforce.
3. PRIVACY COMMITMENT
3.1 Compliance With Australian Privacy Laws
Ad On Workforce is committed to complying with applicable Australian privacy legislation including:
- the Privacy Act 1988 (Cth);
- the Australian Privacy Principles (APPs); and
- applicable contractual privacy obligations agreed with clients.
3.2 Collection of Personal Information
Ad On Workforce collects personal information reasonably necessary to operate our business and provide workforce services.
Information collected may include:
Client Information
Including:
- names;
- business contact details;
- billing information;
- correspondence;
- service requirements; and
- account information.
Employee and Contractor Information
Including:
- identification details;
- employment information;
- qualifications;
- performance information;
- training records;
- payroll information; and
- security screening information.
3.3 Use of Personal Information
Personal information may be used for:
- providing outsourcing services;
- managing workforce arrangements;
- quality assurance;
- employee management;
- security monitoring;
- compliance obligations;
- improving services;
- communicating with clients; and
- maintaining business records.
4. DATA PROCESSING PRINCIPLES
4.1 Client-Controlled Information
Where Ad On Workforce personnel access Client Systems, Ad On Workforce acknowledges that:
- the client determines the purpose for which information is collected;
- the client determines how information is used within their systems;
- the client determines user permissions; and
- the client remains responsible for the underlying system environment.
4.2 Limited Processing Authority
Ad On Workforce personnel will only:
- access information necessary to perform assigned duties;
- use information for authorised business purposes;
- follow client instructions; and
- comply with confidentiality obligations.
Personnel are prohibited from:
- copying client databases without approval;
- transferring client information to unauthorised locations;
- sharing credentials;
- downloading information for personal use;
- storing client data on personal devices without approval; or
- disclosing confidential information.
5. INFORMATION SECURITY FRAMEWORK
Ad On Workforce maintains a layered security approach incorporating:
5.1 Administrative Controls
Including:
- employment agreements;
- confidentiality obligations;
- security policies;
- staff training;
- access approval procedures;
- supervision processes;
- incident reporting procedures; and
- regular policy reviews.
5.2 Technical Controls
Where applicable, controls include:
- multi-factor authentication;
- secure passwords;
- access restrictions;
- endpoint protection;
- encryption;
- monitoring software;
- audit logging;
- system updates;
- malware protection; and
- secure communication channels.
5.3 Physical Controls
Including:
- secure offices;
- controlled access;
- workstation security;
- visitor restrictions;
- clean desk requirements;
- secure document disposal; and
- supervision of office-based personnel.
6. EMPLOYEE SECURITY REQUIREMENTS
6.1 Staff Screening
Before receiving access to client information, personnel may undergo:
- identity verification;
- reference checks;
- employment verification;
- skills assessment;
- background checks where appropriate; and
- confidentiality agreement execution.
6.2 Confidentiality Obligations
All personnel are contractually required to maintain confidentiality regarding:
- client information;
- customer information;
- business processes;
- financial information;
- intellectual property; and
- commercially sensitive information.
These obligations continue after employment or engagement ends.
6.3 Security Awareness Training
Personnel receive ongoing education regarding:
- cyber security awareness;
- phishing risks;
- password protection;
- privacy obligations;
- handling confidential information;
- acceptable system usage; and
- incident reporting.
7. CLIENT SYSTEM ACCESS & SECURITY RESPONSIBILITIES
7.1 Client-Controlled Platforms
Clients acknowledge that Ad On Workforce personnel operate within environments selected and controlled by the client.
The client remains responsible for:
- selecting appropriate software;
- maintaining software subscriptions;
- implementing security settings;
- configuring permissions;
- maintaining backups;
- enabling multi-factor authentication;
- managing administrator accounts;
- removing access when required; and
- maintaining their own cyber security practices.
7.2 User Access Management
Clients are responsible for ensuring:
- personnel receive appropriate access levels;
- unnecessary permissions are not granted;
- privileged access is restricted;
- former users are removed promptly; and
- access reviews are performed regularly.
7.3 Third Party Software Risks
Ad On Workforce is not responsible for vulnerabilities, failures, outages or security weaknesses within third-party platforms selected by clients.
This includes:
- software vulnerabilities;
- provider outages;
- cyber attacks against third parties;
- software configuration errors;
- credential compromise;
- inadequate client security settings; and
- failures by software providers.
8. WORKFORCE LOCATION SECURITY MODEL
8.1 Hybrid Workforce Approach
Ad On Workforce operates a hybrid workforce model consisting of:
- supervised office-based personnel; and
- approved remote personnel.
Both groups operate under Ad On Workforce security policies and confidentiality requirements.
9. OFFICE-BASED WORKERS
9.1 Enhanced Physical Controls
Office-based personnel benefit from additional physical safeguards including:
- supervised working environments;
- controlled office access;
- management oversight;
- secure workstations;
- restricted visitor access;
- physical monitoring; and
- controlled document handling.
9.2 Recommended Use for Highly Confidential Information
Where a client requires handling of highly sensitive information, Ad On Workforce recommends selecting an office-based worker where practical.
Examples may include:
- sensitive financial information;
- legal information;
- medical information;
- government-related information;
- personally identifiable customer information;
- intellectual property; or
- commercially sensitive material.
An office-based arrangement provides additional physical security layers.
10. REMOTE WORKER SECURITY REQUIREMENTS
10.1 Approved Remote Work Environment
Remote personnel must:
- maintain a secure workspace;
- prevent unauthorised viewing of screens;
- secure devices when unattended;
- avoid public work environments;
- protect passwords;
- use secure internet connections; and
- comply with monitoring requirements.
10.2 Remote Work Limitations
Clients acknowledge that remote work inherently involves different physical security considerations compared with controlled office environments.
Accordingly, clients requiring the highest level of physical security should consider selecting an office-based resource.
11. MONITORING AND SCREEN SECURITY
11.1 Purpose of Monitoring
Ad On Workforce may utilise monitoring technologies to:
- protect client information;
- verify work completion;
- improve productivity;
- provide quality assurance;
- investigate suspected misuse;
- support training; and
- maintain accountability.
11.2 Monitoring Activities
Monitoring may include:
- task tracking;
- application usage;
- productivity reporting;
- system activity logs;
- screenshots;
- screen recording where applicable;
- login activity; and
- audit records.
11.3 Monitoring Limitations
Monitoring systems are security controls designed to reduce risk.
They do not guarantee that every security event can be prevented.
No organisation can completely eliminate cyber security risk.
12. CLEAN DESK AND INFORMATION HANDLING POLICY
Personnel must:
- secure confidential documents;
- avoid leaving sensitive information visible;
- lock screens when away;
- securely dispose of documents;
- prevent unauthorised persons viewing information; and
- maintain professional security standards.
13. CLIENT RESPONSIBILITIES
Clients acknowledge that effective data security requires cooperation.
Clients are responsible for:
- providing appropriate system access;
- ensuring permissions are suitable;
- maintaining secure software environments;
- protecting administrator credentials;
- implementing MFA where available;
- notifying Ad On Workforce of confidentiality requirements;
- advising if office-based personnel are required due to sensitivity;
- maintaining backups;
- maintaining cyber insurance where appropriate; and
- ensuring their own compliance obligations are met.
14. CONFIDENTIAL INFORMATION FRAMEWORK
14.1 Protection of Confidential Information
Ad On Workforce recognises that clients entrust us with commercially valuable and confidential information.
All Client Data, regardless of format, is treated as confidential information.
This includes:
- customer databases;
- pricing information;
- financial records;
- business strategies;
- intellectual property;
- marketing information;
- operational processes;
- employee information;
- supplier information;
- system access information;
- passwords and credentials;
- reports;
- documents;
- communications; and
- any information identified as confidential or reasonably understood to be confidential.
14.2 Confidentiality Obligations
Ad On Workforce agrees that it will:
- only use Client Data for the purpose of providing agreed services;
- restrict access to authorised Personnel;
- ensure Personnel are aware of confidentiality obligations;
- implement reasonable security measures;
- prevent unauthorised disclosure; and
- notify the client where required under applicable law or this Policy.
14.3 Personnel Confidentiality
All Ad On Workforce Personnel accessing client information are required to sign confidentiality obligations as part of their employment or engagement arrangements.
These obligations include restrictions against:
- copying client information;
- disclosing information to unauthorised parties;
- using information for personal benefit;
- removing information from approved environments;
- storing information in unauthorised locations; or
- accessing information outside authorised duties.
14.4 Confidentiality After Termination
Confidentiality obligations continue after:
- employment ends;
- contractor arrangements conclude;
- client engagements terminate; or
- access permissions are removed.
15. DATA BREACH AND SECURITY INCIDENT MANAGEMENT
15.1 Commitment to Incident Management
Ad On Workforce maintains procedures designed to identify, respond to, investigate and manage suspected security incidents.
A security incident may include:
- unauthorised access;
- accidental disclosure;
- loss of confidential information;
- compromised credentials;
- malware incidents;
- inappropriate system usage;
- unauthorised copying;
- suspicious activity; or
- cyber security events.
15.2 Incident Response Process
Where Ad On Workforce becomes aware of a suspected security incident, we may undertake the following actions:
Step 1 – Identification
The incident is assessed to determine:
- what occurred;
- what information may be affected;
- whether client information is involved;
- whether access remains active; and
- immediate containment requirements.
Step 2 – Containment
Actions may include:
- disabling access;
- changing credentials;
- restricting permissions;
- isolating systems;
- securing devices;
- preserving evidence; and
- preventing further disclosure.
Step 3 – Investigation
Ad On Workforce may investigate:
- the cause of the incident;
- personnel involved;
- systems affected;
- information accessed;
- whether misconduct occurred; and
- required remediation actions.
Step 4 – Notification
Where required by applicable law or contractual obligations, Ad On Workforce will notify affected parties.
Where the incident relates primarily to a Client System controlled by the client, notification obligations may depend on:
- the nature of the incident;
- the client’s legal obligations;
- the third-party platform involved; and
- the contractual arrangements between parties.
15.3 Client Cooperation
Clients agree to reasonably cooperate with Ad On Workforce during any investigation, including providing:
- system access information;
- relevant logs;
- details of affected systems;
- information regarding permissions;
- relevant evidence; and
- instructions regarding remediation.
16. DATA RETENTION AND SECURE DISPOSAL
16.1 Retention Principles
Ad On Workforce retains information only for as long as reasonably necessary for:
- providing services;
- complying with legal obligations;
- maintaining business records;
- resolving disputes;
- protecting legitimate business interests; or
- satisfying contractual requirements.
16.2 Client Data Within Client Systems
Where Client Data remains stored within client-controlled systems:
- Ad On Workforce does not control retention periods;
- the client remains responsible for deletion, archival and backup policies;
- the client remains responsible for system configuration.
16.3 Disposal
When information controlled by Ad On Workforce is no longer required, reasonable steps may be taken to:
- securely delete electronic information;
- destroy physical documents;
- remove access permissions;
- dispose of storage devices securely.
17. CROSS-BORDER INFORMATION PROCESSING
17.1 International Workforce Operations
Ad On Workforce may provide services using personnel located outside Australia.
Clients acknowledge that outsourcing arrangements may involve personnel working from approved international locations.
17.2 Security Obligations Apply Regardless of Location
Regardless of where Personnel are located:
- confidentiality obligations apply;
- security procedures apply;
- monitoring requirements apply;
- client instructions apply; and
- access controls apply.
17.3 Client Acknowledgement
By engaging Ad On Workforce, clients acknowledge that offshore workforce arrangements may involve international access to information and consent to such access where necessary to deliver services.
18. THIRD PARTY SERVICE PROVIDERS
18.1 Use of Technology Providers
Ad On Workforce may utilise third-party providers to support operations, including providers of:
- communication systems;
- workforce management systems;
- security software;
- monitoring tools;
- cloud services;
- business software; and
- infrastructure services.
18.2 Third Party Security
While Ad On Workforce seeks reputable providers, third-party systems remain subject to their own:
- security controls;
- policies;
- vulnerabilities;
- service availability; and
- contractual terms.
Ad On Workforce is not responsible for security failures caused by third-party providers outside its reasonable control.
19. CYBER SECURITY CONTROLS
Ad On Workforce maintains reasonable security practices including:
19.1 Access Management
Controls may include:
- unique user accounts;
- restricted permissions;
- password requirements;
- multi-factor authentication;
- access reviews;
- removal of inactive users.
19.2 Device Security
Controls may include:
- endpoint security software;
- operating system updates;
- encryption;
- password protection;
- device monitoring;
- malware protection.
19.3 Network Security
Controls may include:
- secure internet connections;
- firewall protection;
- access restrictions;
- secure authentication;
- monitoring of suspicious activity.
19.4 Human Security Controls
Including:
- employee training;
- phishing awareness;
- confidentiality agreements;
- acceptable use requirements;
- disciplinary procedures.
20. PROFESSIONAL INSURANCE
20.1 Insurance Coverage
Ad On Workforce maintains professional insurance arrangements appropriate for the nature of services provided.
This may include:
- Professional Indemnity Insurance;
- Public Liability Insurance;
- Cyber-related insurance coverage; and
- other commercial insurance policies.
20.2 Insurance Does Not Expand Liability
The existence of insurance does not:
- create additional liability;
- remove contractual limitations;
- guarantee recovery for every circumstance;
- increase obligations beyond those agreed.
Insurance exists as a risk management measure and not as an unlimited guarantee against loss.
21. LIMITATION OF LIABILITY
21.1 General Limitation
To the maximum extent permitted by law, Ad On Workforce excludes liability for any loss, damage, cost or expense arising from:
- client-controlled systems;
- third-party software;
- software vulnerabilities;
- cyber attacks;
- ransomware;
- phishing;
- compromised client credentials;
- inadequate client security controls;
- incorrect permissions;
- client instructions;
- client negligence;
- system failures outside Ad On Workforce's reasonable control.
21.2 Client System Responsibility
The client acknowledges that Ad On Workforce personnel operate within systems selected and controlled by the client.
Accordingly, Ad On Workforce is not responsible for:
- the security architecture of Client Systems;
- software provider failures;
- client configuration errors;
- unauthorised access caused by client-side weaknesses;
- loss caused by insufficient backups;
- improper permission settings; or
- vulnerabilities existing within client platforms.
21.3 Ad On Workforce Security Obligations
Ad On Workforce's responsibility is limited to implementing reasonable security measures within environments controlled by Ad On Workforce.
Ad On Workforce will only be responsible for loss where the client can establish that such loss was directly caused by:
- Ad On Workforce's breach of contractual obligations;
- negligence;
- wilful misconduct; or
- unlawful conduct.
21.4 Liability Cap
To the maximum extent permitted by law:
Ad On Workforce's total aggregate liability arising from or relating to the provision of services shall not exceed the fees paid by the client to Ad On Workforce during the six (6) months immediately preceding the event giving rise to the claim.
21.5 Excluded Loss
To the maximum extent permitted by law, Ad On Workforce will not be liable for:
- loss of profits;
- loss of revenue;
- loss of business opportunity;
- loss of goodwill;
- consequential loss;
- indirect loss;
- business interruption;
- anticipated savings; or
- reputational damage.
22. INDEMNITY
22.1 Client Indemnity
The client indemnifies Ad On Workforce against losses arising from:
- inaccurate information supplied by the client;
- client breaches of privacy obligations;
- misuse of Client Systems;
- unlawful client instructions;
- inadequate client security controls;
- failure to maintain appropriate permissions;
- breach of third-party software terms.
22.2 Mutual Cooperation
Both parties agree to cooperate reasonably to minimise loss arising from security incidents.
23. AUSTRALIAN CONSUMER LAW
Nothing in this Policy excludes, restricts or modifies any rights or remedies available under the Competition and Consumer Act 2010 (Cth) or other applicable legislation where such rights cannot legally be excluded.
Where permitted by law, Ad On Workforce limits its liability to:
- supplying the services again; or
- payment of the cost of having the services supplied again.
24. INCORPORATION INTO CLIENT AGREEMENT
This Policy forms part of the contractual framework between Ad On Workforce and its clients.
Where incorporated into a Client Services Agreement:
- this Policy operates as a contractual obligation;
- security obligations apply to both parties;
- liability provisions apply unless expressly varied in writing.
25. POLICY REVIEW AND CONTINUOUS IMPROVEMENT
Ad On Workforce regularly reviews:
- security practices;
- technology controls;
- employee procedures;
- monitoring systems;
- privacy requirements;
- cyber security risks.
Updates may be made to reflect:
- regulatory changes;
- operational improvements;
- technology developments;
- industry best practices.
26. GOVERNING LAW
This Policy is governed by the laws of Queensland, Australia.
The parties submit to the exclusive jurisdiction of the courts of Queensland and courts entitled to hear appeals from those courts.
27. CONTACT DETAILS
Privacy Officer
Ad On Workforce
Email:
SCHEDULE A
AD ON WORKFORCE SECURITY CONTROLS
The following controls may be implemented depending on operational requirements:
Administrative Controls
☑ Employment agreements
☑ Confidentiality agreements
☑ Security policies
☑ Staff training
☑ Access approvals
☑ Supervision procedures
☑ Incident response procedures
Technical Controls
☑ Multi-factor authentication
☑ Secure passwords
☑ Access restrictions
☑ Endpoint security
☑ Monitoring software
☑ Audit records
☑ Secure authentication
Physical Controls
☑ Controlled office access
☑ Secure workstations
☑ Clean desk requirements
☑ Document disposal procedures
☑ Visitor management
SCHEDULE B
CLIENT SECURITY RESPONSIBILITY CHECKLIST
Clients should ensure:
☐ Appropriate user permissions are granted
☐ MFA is enabled where available
☐ Passwords are secure
☐ Former users are removed promptly
☐ Backups are maintained
☐ Sensitive systems are properly configured
☐ Confidential information requirements are communicated
☐ Office-based personnel are requested where required
☐ Third-party software security is reviewed
☐ Cyber insurance requirements are considered