Nous Group Pty Ltd ABN 66 086 210 344 and its related bodies corporate , including Cubane Consulting Group Pty Ltd ABN 15 613 111 443 and its related bodies corporate (referred to as Nous, we, us or our) respect your right to privacy and are committed to safeguarding the privacy of individuals, including our suppliers, customers and website visitors, and to the protection of personal information that relates to them in accordance with the laws of the jurisdictions in question, including, as applicable
- Australia: Australian Privacy Principles (APPs) as set out in the Privacy Act 1988(Cth) (AU Privacy Act);
- Canada: the Personal Information Protection and Electronic Documents Act (PIPEDA), or any substantially similar law of a Province (collectively, Canadian Privacy Law);
- European Union: the “Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016”, known as the EU General Data Protection Regulation (GDPR);
- New Zealand: New Zealand Information Privacy Principles (NZIPPs) set out in the Privacy Act 2020 (New Zealand) (NZ Privacy Act); and
- United Kingdom: the GDPR as it forms part of UK law (UK GDPR).
Where relevant laws apply to the way we handle the Personal Information we will comply with our obligations.
1. What is considered Personal Information?
“Personal Information” is information or an opinion by or about an identified individual, or an individual who is reasonably identifiable, whether the information is true or not, and whether recorded in a material form or not. Personal Information does not include information that is aggregated or anonymized.
“Sensitive Information”, depending on the applicable Privacy Law, would include Personal Information about an individual that includes health information, genetic information, biometric information or templates, or personal information that is also information or an opinion about an individual’s race or ethnicity, their religious, political or philosophical beliefs, opinions or affiliations, their sexual orientation or criminal record.
2. Why do we collect Personal Information?
2.1 Why do we collect your information?
2.2 How we contact you and how you may deal with us
Nous may contact you using a variety of means including, but not limited to telephone, email, SMS and post.
You have the option to deal with us anonymously or by using a pseudonym. However, you acknowledge that where this is impractical or where the law or a court order provides otherwise, we are not required to provide these options to you.
If you choose not to provide your Personal Information to us, we may not be able to undertake certain activities for you (such as providing you with requested information, products or services, or including the information you provide to us in the course of our delivery of recommendations on a consultancy project to a client).
3. Collection of Personal Information
3.1 When and how do we collect your information?
We may collect and hold Personal Information about you such as your name, gender, date of birth, contact details (including your address, phone numbers and emails, whether personal or for work), employment information, credit card details, and in some cases, information related to your education, health and use of social services.
We collect Personal Information directly from you in the following circumstances: in the course of delivering a project, when we consult with you directly or in a workshop, when you complete a survey, or when you correspond with us; when we otherwise supply you with services; when you request information about us or our products or services, provide feedback, change your content or email preferences, enter into an agreement or contract with us, fill in a form or a request for services, fill in a form on our website, attend an event, become an employee of Nous, or otherwise contact us by telephone, facsimile, email, post or in person.
If the GDPR, or the UK GDPR apply, we are entitled to use your Personal Information in the circumstances stated above because:
- we have legal and regulatory obligations that we must discharge;
- we may need to in order to establish, exercise or defend our legal rights or for the purpose of legal proceedings; or
- the use of your Personal Information as described is necessary for our legitimate business interests (or the legitimate interests of one or more of our related bodies corporate), such as:
- management consulting services; and
- research into any market we operate in or are seeking to operate in, including, but not limited to education, health, defence, leadership, and public policy.
If the GDPR or UK GDPR applies to how we collect, use or disclose your Personal Information (including Sensitive Information), we will request that you provide us with your consent to collect, use or disclose your Personal Information. You may withdraw your consent any time in the same way you gave consent or by contacting us in any of the ways set out in clause 11.
Where required by the applicable Privacy Law, we will seek your consent to the processing of your Personal Information for specific purposes or your explicit consent when processing Sensitive Information (if applicable).
3.2 Do we collect information about you in other ways?
We may also collect Personal Information about you, such as names and email addresses, via third parties including from our clients, suppliers, through events or online marketing.
We may also process your Personal Information in performance of our contractual obligations when we receive it from a third party with whom you have entered a contract or at your request.
In some circumstances we may receive Personal Information that we have not requested. If this occurs, we will comply with our obligations under applicable Privacy Law. You acknowledge that we may de-identify and/or destroy this information unless we are required to keep it by law.
4. Information collected via our Website
We will not collect any Personal Information about users of our Website except when they knowingly provide it.
4.2 Click Stream Data
When you visit and browse our Website, our Website host may collect Personal Information for statistical, reporting and maintenance purposes. Subject to clause 6.2, the Personal Information collected by our Website host will not be used to identify you. The information may include: the number of users visiting our Website and the number of pages viewed; the date, time and duration of a visit; the IP address of your computer; the path taken through our Website; or the browser type, operating system or website visited immediately before coming to our Website.
Our Website host uses this information to administer and improve the performance of our Website, including to assist with the diagnosis of and to provide support for any issues with our Website or services. This information is used in an aggregated manner to analyse how people use our Website, so that we can improve our service.
Cookies are small text files that are transferred to a user’s computer hard drive by a website for the purpose of storing information about a user’s identity, browser type or website visiting patterns.
4.4 Web Beacons
Web beacons are images that originate from a third-party site to track visitor activities. We may use web beacons to collect aggregate data and provide this information to our Website host to administer and improve the performance of our Website.
4.5 Links to external websites
5. How we use Personal Information?
5.1 How we use the Personal Information we collect about you?
We use the Personal Information we collect about you for our business functions and activities, which may include the following:
(a) to provide you with information or services you have requested;
(b) to promote and market our services to you;
(c) to personalise and customise your experiences on our Website;
(d) to deliver our consulting services to our clients;
(e) to provide you with ongoing information about us and our activities;
(f) to use and disclose aggregated or de-identified information for the purposes of data analysis, research and reporting;
(g) to comply with regulatory or other legal requirements;
(h) to protect the copyright, trademarks, legal rights, property or safety of Nous, its customers or third parties;
(i) for purposes related to the recruitment and employment of our personnel and providing internal services to our staff; and
(j) for any other use required or permitted by law or any other purpose communicated to you at the time that the Personal Information was collected or for which you subsequently provided your consent.
We may, if permitted by the applicable law use your Personal Information for a secondary purpose if that secondary purpose is related to the purposes listed in this clause 5.1, if we have your consent or if otherwise provided for under applicable Privacy Law. In some jurisdictions, you may have the right to opt-out of use of your Personal Information for secondary purposes.
5.2 Direct marketing
Depending on the applicable Privacy Law, we may use your Personal Information to provide you with direct marketing materials if you consent to receive direct marketing materials, or as may be permitted by the law in your jurisdiction, if we have an existing relationship with you or if you would reasonably expect us to send you direct marketing materials. If required, we will seek your consent to provide you with direct marketing materials if we have obtained your Personal Information from a third party. Direct marketing material may include promotional material about us or the products or services we offer.
You may opt out of receiving direct marketing material by clicking the unsubscribe facility in the direct marketing materials or by contacting us in any of the ways specified in the direct marketing materials or as set out in clause 11. We may continue to send you non-promotional communications, such as service-related emails and billing information.
5.3 Employee records
6. When do we disclose Personal Information?
6.1 Who do we disclose your Personal Information to?
Depending on the applicable Privacy Law and the nature of your relationship with us, we may disclose your Personal Information to our shareholders, officers and employees, other businesses within our group of companies, service providers who assist us in our business operations and recruitment activities (including third party service providers based overseas), government agencies, other third parties, (including parties that we engage to provide you with services on our behalf or who are connected with or involved in our relationship with you), or otherwise as required by law.
If there is an actual or prospective change of control in our business or a sale or transfer of business assets, we reserve the right to transfer to the extent permissible at law our user databases, together with any Personal Information and non-personal information contained in those databases. This information may be disclosed to a potential purchaser under an agreement to maintain confidentiality.
6.2 Service providers
We may also disclose your Personal Information to our service providers in certain limited circumstances, for example when our Website experiences a technical problem or to ensure that it operates in an effective and secure manner.
Personal information is only disclosed to a third party when it is required for the delivery of our services. To the extent that we do share your Personal Information with a service provider, we would only do so if that party has agreed to a confidentiality regime in relation to their services and access to your Personal Information.
We may also share non-personal, de-identified and aggregated information for research or promotional purposes in connection with providing requested information or services to you, or for the purpose of improving our services. We will not sell your Personal Information to third parties for their own purposes, including for marketing purposes.
7. Overseas disclosure and individuals based in Europe
7.1 Disclosure of your Personal Information overseas
Your Personal Information may be disclosed outside of your home country to an entity in a foreign country, including entities in which we have an ownership interest or to third party service providers (Overseas Entities). The country in which these Overseas Entities are located/likely to be located include the United Kingdom and Canada, where we have offices.
It is possible that the Overseas Entities may be subject to foreign laws that do not provide the same level of protection of information as in your home country or that provide a greater level of protection than in your home country. We take reasonable steps to ensure that these Overseas Entities do not breach the applicable Privacy Law and that they are obliged to protect the privacy and security of your Personal Information and use it only for the purpose for which it is disclosed.
7.2 Personal Information to which the GDPR or UK GDPR applies
If the GDPR or UK GDPR applies to how the Personal Information is transferred to us, how we deal with that Personal Information and how we may transfer that Personal Information to third countries will be subject to the requirements of the GDPR or UK GDPR.
Where we transfer your Personal Information outside the European Economic Area (EEA) or UK, we will ensure that it is protected in a manner that is consistent with how your Personal Information will be protected by us in the EEA or the UK. This can be done in a number of ways, for instance:
- the country that we send the data to might be approved by the European Commission or the UK Government; or
- the recipient might have signed up to a contract based on “model contractual clauses” approved by the European Commission or equivalent clauses approved by the UK Government, obliging them to protect your personal data.
In other circumstances the law may permit us to otherwise transfer your Personal Information outside the EEA or the UK. In all cases, however, we will ensure that any transfer of your Personal Information is compliant with data protection law.
You can obtain more details of the protection given to your Personal Information when it is transferred outside the EEA or the UK (including a copy of the standard data protection clauses which we have entered with recipients of your Personal Information) by contacting us in accordance with the clause 11 below.
8. Storage and data security
Nous is committed to ensuring that the information you provide to us is secure. To prevent unauthorised access to or disclosure of Personal Information, we have taken steps to put in place suitable physical, electronic and managerial procedures designed to safeguard and secure Personal Information and protect it from misuse, interference, loss and unauthorised access, modification and disclosure.
We aim to keep your Personal Information secure and up to date. We will comply with our obligations under applicable Privacy Law in relation to any Personal Information that we handle, including information which is held on our computer systems.
The Notifiable Data Breaches Scheme (NDB scheme) in Part IIIC of the AU Privacy Act sets out obligations for notifying affected individuals, and the Australian Information Commissioner, about an “eligible data breach” (as defined in the AU Privacy Act) which is likely to result in serious harm.
To the extent required by law, where a data or privacy breach occurs and serious harm to affected individuals has occurred or is likely, we will notify those individuals and the relevant supervisory authority in accordance with our obligations under applicable Privacy Law.
If the GDPR or the UK GDPR applies, or processed by us, you may have additional rights under the GDPR relating to security and protection of data, notification of “personal data breaches” (as defined in the GDPR and UK GDPR), and a right to compensation for damage arising from a personal data breach. If the GDPR or UK GDPR applies we will comply with our legal obligations.
If you reside in Canada, Canadian Privacy Law may also require us to notify affected individuals and privacy regulators with respect to breaches of security safeguards that give rise to a real risk of significant harm to an individual.
You may contact our Privacy Officer via the contact details below should you require additional information.
9. How long will we keep your Personal Information?
We will keep your Personal Information only for as long as required for our business purposes and otherwise as required by Australian, Canadian EU, New Zealand, and UK law.
Where we no longer need to keep your Personal Information in accordance with this clause 9, we will take steps required by the applicable Privacy Law to destroy or de-identify your Personal Information.
If you wish to have your Personal Information destroyed or de-identified, please let us know and we will take steps required by the applicable Privacy Law to do so (unless we need to keep it for legal, auditing or internal risk management reasons, or as otherwise required or permitted by law).
10. Accessing, updating and correcting your Personal Information
We will take reasonable steps to ensure that the Personal Information that we hold is accurate, up-to-date and complete. You can request a correction of, or update to your Personal Information at any time by contacting us in any of the ways specified in clause 11. We welcome any changes to your Personal Information to keep our records up to date.
You are entitled to request access to Personal Information that we hold about you. If you request access to your Personal Information, we will grant your request to the extent required or permitted by applicable Privacy Law. If we refuse your request to access your Personal Information, to the extent required under applicable Privacy Law, we will provide you with written reasons for the refusal.
If the GDPR or UK GDPR applies, you may have additional rights under the GDPR, including in relation to the right to access your Personal Information, to rectify your Personal Information, to erase your Personal Information (the ‘right to be forgotten’), to restrict processing of your Personal Information and the right to receive your Personal Information (the ‘right of portability’). If the GDPR or the UK GDPR applies we will comply with our obligations in relation to the exercise of your rights under the GDPR or the UK GDPR.
If you are a resident of Canada, you may have similar additional rights under Canadian Privacy Law, including in relation to the right to access your Personal Information, to request correction of your Personal Information and to withdraw your consent to the continued use of your Personal Information (including retention), subject to statutory restrictions. If Canadian Privacy Law applies we will comply with our obligations in relation to the exercise of your rights under such law.
To exercise any of your rights in relation to Personal Information, including making a request for access, please contact us in any of the ways specified in clause 11. We are entitled to charge you a fee to comply with your request for information, however, if the GDRP or UK GDPR applies, we will not charge you for information we provide to you unless we are entitled to do so in accordance with GDPR or UK GDPR Article 12(5).
To the extent the GDPR or UK GDPR applies, you have the right to lodge a complaint with the data protection regulator (details of which are provided below) if you think that any of your rights have been infringed by us.
11. How to contact us, find out more information or make a complaint
Name: Nous Group Pty Ltd
Att: Privacy Officer
Post: Level 19, 567 Collins Street, Melbourne, Victoria 3000, Australia
When contacting us please provide as much detail as possible in relation to your query, problem or complaint. We take all complaints seriously and will respond to your complaint in accordance with any applicable timeframes imposed by law and otherwise within a reasonable period. We request that you cooperate with us during this process and provide us with any relevant information that we may need.