1. Introduction
1.1 This Privacy Policy explains how Z Advisory (ABN 14 674 462 928) collects, holds, uses, discloses and otherwise manages personal information in connection with our website, enquiries, assessments, consulting engagements, research activities and digital services.
1.2 Z Advisory provides services including Digital Presence, Business Intelligence and reporting, Business Transformation, process improvement and automation, ESG and sustainability support, research, and the Z Advisory Business Health Check.
1.3 This Policy is intended to provide transparent information about our information-handling practices. Where the Privacy Act 1988 (Cth) and Australian Privacy Principles (APPs) apply to Z Advisory, we will seek to comply with those requirements. We also use the APPs as a practical privacy framework for responsible handling of information where appropriate.
2. Privacy framework
2.1 Australian privacy requirements may include the Privacy Act 1988 (Cth), the Australian Privacy Principles, the Notifiable Data Breaches scheme and other laws applying to particular information, activities or communications.
2.2 Information about the Australian Privacy Principles is available from the Office of the Australian Information Commissioner (OAIC).
2.3 Privacy Act coverage depends on the circumstances of the organisation and activity. Nothing in this Policy is intended to represent that every provision of the Privacy Act applies to every activity undertaken by Z Advisory where the law provides otherwise.
3. Information we may collect
3.1 Depending on how you interact with us, we may collect identity and contact information such as your name, organisation, job title, email address, telephone number and business address.
3.2 We may collect business information including industry, business size, website, ABN where relevant, operational information, objectives, challenges, systems used and information supplied as part of an enquiry or engagement.
3.3 We may collect technical and usage information including IP address, browser type, device type, operating system, referring pages, approximate location derived from technical data, website usage and session information.
3.4 Where required to provide services, clients may provide files or records including Excel workbooks, CSV files, Power BI files, database extracts, reports, financial or management information, policies, procedures, process maps, organisation charts, KPI registers, sustainability data, governance information, website content, domain information and CMS or system access credentials.
4. Information collected through services
4.1 Business Health Check
We may collect assessment responses, organisation details, contact details, calculated scores, maturity classifications, generated reports and recommendations. These records may be used to provide the assessment, improve methodology, conduct aggregated research and, where permission exists, communicate relevant Z Advisory services.
4.2 Digital Presence
We may receive website content, brand assets, hosting and domain information, SEO data, analytics configuration, CMS information and access credentials reasonably required to deliver the agreed work.
4.3 Business Intelligence and reporting
We may receive spreadsheets, datasets, database extracts, operational metrics, KPI definitions, management reports and related business records necessary to build or improve analytics and reporting solutions.
4.4 Business Transformation and automation
We may receive process documentation, workflow information, policies, internal forms, organisational structures, system information and other records used to understand and improve business processes.
4.5 ESG and sustainability
We may receive environmental, social and governance data, utilities information, emissions inputs, waste records, workforce information, governance records, stakeholder information and sustainability reports.
5. How information is collected
5.1 Information may be collected directly from you through website forms, assessment forms, consultations, booking tools, email, telephone, meetings, file transfers, surveys and project collaboration.
5.2 Information may also be generated through our services, for example assessment scores, reports, dashboard calculations, process analysis and recommendations.
5.3 We may receive information from third-party platforms you or we use for the relevant service, subject to those providers' terms and privacy practices.
6. Why we use information
6.1 We may use information to respond to enquiries, scope and deliver services, administer client relationships, produce reports and recommendations, operate the Business Health Check, maintain and improve our website and services, secure our systems, manage billing and administration, meet legal obligations and resolve issues.
6.2 We may also use appropriately de-identified or aggregated information for research, benchmarking, service improvement and the Australian Business Observatory, provided the information is not presented in a manner intended to identify an individual or client unless authorised.
6.3 Marketing communications will be sent only where permitted. You may unsubscribe from electronic marketing at any time using the unsubscribe method provided or by contacting us.
7. AI-assisted analysis and automation
7.1 Z Advisory may use artificial intelligence, machine-assisted tools and automation to support activities such as classification, summarisation, drafting, research support, document analysis, reporting, coding support and preparation of preliminary recommendations.
7.2 AI tools are supporting technologies and do not replace appropriate professional judgement. Outputs may be reviewed, interpreted or refined before being incorporated into client deliverables where appropriate to the engagement.
7.3 We seek to limit the disclosure of confidential or personal information to AI systems to what is reasonably necessary for the relevant task, subject to the chosen service, contractual settings, available safeguards and client instructions.
7.4 Our Business Health Check may use automated calculations to create indicative scores and recommendations. It is not intended to make decisions that determine legal rights, eligibility, employment, credit, insurance, financial products or similarly significant individual interests.
7.5 From 10 December 2026, additional APP Privacy Policy obligations may apply to APP entities that arrange for computer programs to use personal information in certain decisions that could significantly affect an individual's rights or interests. Z Advisory will review its practices as its services evolve.
8. Service providers and disclosure
8.1 We may use third-party service providers for hosting, cloud storage, email, forms, booking, analytics, collaboration, automation, AI-assisted tools, database services, website infrastructure and other business functions.
8.2 Depending on the service in use, providers may include companies such as Microsoft, Google, Supabase, Amazon Web Services, OpenAI, email delivery providers, booking platforms and hosting or domain providers. A provider is not necessarily used for every client or every service.
8.3 We may also disclose information where reasonably required to professional advisers, contractors, insurers, regulators or authorities, or where authorised or required by law.
9. Overseas processing and storage
9.1 Some technology providers operate global infrastructure. As a result, information may be stored, backed up, accessed or processed outside Australia depending on the provider, account configuration and service used.
9.2 Where cross-border disclosure obligations under APP 8 apply, Z Advisory will take reasonable steps appropriate to the circumstances to address those obligations. Exact data locations may change as providers update infrastructure.
9.3 Clients with specific data-residency, sovereignty or contractual requirements should raise them before information is supplied so they can be addressed in the engagement scope.
10. Security, confidentiality and retention
10.1 Z Advisory uses reasonable administrative, technical and organisational measures appropriate to the nature of the information and services involved. Measures may include access controls, account security, restricted permissions, encryption offered by service providers, backups and controlled credential handling.
10.2 No internet transmission, cloud service or electronic storage system can be guaranteed to be completely secure. Clients should use secure channels and avoid sending unnecessary sensitive information.
10.3 We retain information for as long as reasonably required for the purposes for which it was collected, to maintain business and project records, resolve disputes, meet legal or contractual obligations, or support legitimate operational requirements. Information may then be deleted, de-identified or archived as appropriate.
11. Data breaches
11.1 Z Advisory will investigate suspected data-security incidents appropriate to their nature and impact.
11.2 Where the Notifiable Data Breaches scheme applies and an eligible data breach occurs, Z Advisory will take steps required by applicable law, which may include notification to affected individuals and the OAIC.
See the OAIC's Notifiable Data Breaches guidance.
12. Access, correction and complaints
12.1 You may contact us to request access to, or correction of, personal information we hold about you. We may need to verify identity and may refuse or limit a request where permitted by law.
12.2 Privacy questions or complaints should first be sent to Z Advisory. We will consider the matter and respond within a reasonable period.
12.3 Where applicable, individuals may also have the right to contact the OAIC. Information about making a privacy complaint is available at oaic.gov.au.
13. Contact
For privacy enquiries, access or correction requests, or complaints:
13.1 We may update this Privacy Policy as our services, technology or legal obligations change. The version published on the website will state its effective date.