Privacy Policy

Effective date: 4 October 2026

Who we are and what this policy covers

Employment Compass is a business name of Progredi Pty Ltd ABN 47 667 125 788. In this policy, “Employment Compass”, “we”, “us” and “our” mean Employment Compass.

We help Australian businesses with HR advice (including our HR advice line), HR policies and documents, compliance, employee relations, workplace investigations, onsite HR (Compass Onsite) and representation in Fair Work matters.

This policy explains how we collect, hold, use and disclose personal information, and how you can access or correct your information or make a complaint. It applies to personal information we handle through our website, when we provide our services, and in running our business. We handle personal information in line with the Privacy Act 1988 (Cth), including the Australian Privacy Principles.

“Personal information” means information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether or not it is true and whether or not it is recorded in a material form.

This policy covers the personal information we handle about our clients’ employees and other people involved in the matters we help with. Where the Privacy Act’s employee records exemption applies, it does not cover how we handle employee records about our own current and former staff.

How to contact us

If you have a question about this policy or about how we handle your personal information, please contact our Privacy Officer:

Employment Compass is a business name of Progredi Pty Ltd ABN 47 667 125 788. We also have an office at 11 York Street, Sydney NSW 2000.

This policy is available free of charge. If you would like a copy in another form, such as a printed copy, please ask us.

The personal information we collect

The kinds of personal information we collect and hold depend on how you deal with us.

If you visit our website or make an enquiry

  • your name, position, business name, email address, phone number and postcode
  • the number of employees in your business
  • what you tell us about your enquiry, for example in the “How can we help?” or “Question” field of our forms
  • information about your visit, such as your IP address, device and browser type, the pages you view, the website that referred you, and the campaign details in the link you used to reach us (see “Cookies, analytics and similar technologies” below).

If you are a client or work for one of our clients

  • the names, positions and contact details of the people we deal with
  • business, billing and payment details
  • records of our advice and services, and of our calls, meetings, emails and text messages with you, including call recordings and transcripts if a call is recorded
  • information about your workplace, your people and your HR practices that you share with us so we can help.

If you work in, or are involved in, a client’s workplace

When a client asks us to help with an HR matter, we may collect personal information about its employees, former employees, contractors, job candidates and other people involved, such as complainants, respondents and witnesses. Depending on the matter, this may include:

  • name, contact details, position, employment history and terms of employment
  • pay, leave, performance, conduct and disciplinary records
  • information about complaints, grievances, disputes and claims
  • statements, interview notes and other evidence gathered in a workplace investigation
  • information about a person’s health, capacity for work or need for workplace adjustments, where it is relevant to the matter.

Sensitive information

Some information in HR matters is “sensitive information” under the Privacy Act. It includes health information, genetic information, some biometric information, and information or an opinion about a person’s racial or ethnic origin, political opinions, membership of a political association, religious beliefs or affiliations, philosophical beliefs, membership of a professional or trade association or a trade union, sexual orientation or practices, or criminal record.

We collect sensitive information only when it is reasonably necessary for our services and the person has consented, or where the law otherwise allows it, for example where the collection is required or authorised by law, or is reasonably necessary to establish, exercise or defend a legal or equitable claim. We limit access to it to the people working on the matter.

Please do not include health or other sensitive details about anyone in our website forms. Tell us briefly what your enquiry is about, and we will ask for the information we need.

If you apply to work with us

We collect the information in your application, such as your resume, qualifications, work history and referees, and notes from interviews and reference checks.

Suppliers, referrers and other contacts

We collect the names, contact details and business details of our suppliers, referral partners and other people we deal with in running our business.

How we collect personal information

We collect personal information only by lawful and fair means. Where it is reasonable and practicable, we collect it directly from you, for example when you:

  • complete a form on our website
  • call us, email us or send us a text message
  • meet with us in person or by video call
  • become a client or use our services
  • apply for a job with us.

Information from our clients and others

We often collect personal information about people from someone else, usually our client. For example, an employer may give us information about an employee so we can advise on a performance or conduct issue, or a witness may give us information about another person during a workplace investigation. We may also collect information from publicly available sources, such as Fair Work Commission decisions, ABN Lookup and business websites.

When we collect information about you from our client, we generally rely on our client to let you know, where that is appropriate. When we deal with you directly, for example in an investigation interview, we will tell you who we are, why we are collecting your information and who it is likely to be given to.

If you give us personal information about someone else, please make sure you are allowed to do so.

Calls, video meetings and messages

We may record and transcribe calls for quality and training purposes, and to keep an accurate record of our advice. If we do, we will tell you at the start of the call. The same applies to video meetings, for example on Google Meet or Microsoft Teams: if we record or transcribe a meeting, we will tell you at the start. If you would prefer a call or meeting not to be recorded, please tell us.

We keep records of the text messages (SMS) sent to and from our phone lines.

Our website

When you visit our website, our website host and the analytics and other tools described in “Cookies, analytics and similar technologies” below automatically collect information about your device and your visit.

Information we did not ask for

If we receive personal information that we did not ask for, we will decide within a reasonable time whether we could have collected it for our services. If we could not, we will destroy or de-identify it as soon as practicable, where it is lawful and reasonable to do so.

Dealing with us without identifying yourself

You can browse our website, and ask us general questions, without telling us who you are or by using a pseudonym. However, we usually need your name and contact details to respond to an enquiry, and it is not practicable for us to provide our services without knowing who we are dealing with.

Why we collect, hold, use and disclose personal information

We collect, hold, use and disclose personal information to:

  • respond to enquiries and prepare quotes and proposals
  • provide our services, including HR advice, HR policies and documents, compliance reviews, employee relations support, workplace investigations, onsite HR and representation in Fair Work matters
  • manage our relationship with our clients, including billing and payments
  • keep records of the advice and services we provide
  • check identity and protect against fraud and misuse
  • understand how people find and use our website, measure which of our marketing leads to enquiries, and improve our website, services and client experience, including through quality checks and training
  • send you information about our services, HR updates and events, where you have agreed or the law allows (see “Direct marketing” below)
  • recruit our staff
  • comply with our legal obligations, and establish, exercise or defend legal claims.

We use and disclose personal information for the purpose we collected it, for a related purpose you would reasonably expect (for sensitive information, a directly related purpose), with your consent, or where the law requires or allows it.

If you do not give us the information we ask for, we may not be able to respond to your enquiry or provide our services.

Who we disclose personal information to

Depending on the matter, we may disclose personal information to:

  • our client, where the information relates to an HR matter we are handling for that client (for example, an investigation report goes to the employer that engaged us)
  • our staff and contractors who need it to do their work
  • service providers who help us run our business, such as providers of website hosting, forms, analytics, customer relationship management (CRM), email, phone, SMS, video meetings, transcription, document storage, IT support, accounting and payments
  • the Fair Work Commission, courts, tribunals, regulators and other government bodies, and other parties to a dispute and their representatives, when a client asks us to act for them, with consent, or where the law requires or allows it
  • our professional advisers and insurers
  • anyone else you ask us to disclose it to, or where the law requires or allows it.

We do not sell personal information.

Disclosure outside Australia

Some of our service providers store or process personal information outside Australia, so we are likely to disclose personal information to overseas recipients. The main ones are:

  • Webflow, which hosts our website and stores the details you submit through our website forms
  • Google, which provides Google Analytics and Google Tag Manager
  • Microsoft, which provides Microsoft Clarity
  • Elfsight, which provides the reviews widget on some of our pages
  • HubSpot, which provides the customer relationship management (CRM) platform that forms on some of our landing pages are set up to work with.

These recipients are likely to store or process information in the United States, and may also do so in other countries where they or their subcontractors operate.

Other service providers we use, for example for email, document storage, phone and SMS, video meetings and transcription, may store or access personal information in Australia or overseas, including in the United States. Before we disclose personal information to an overseas recipient, we take reasonable steps to make sure it will handle the information consistently with the Australian Privacy Principles, for example by using reputable providers that make privacy and security commitments in their terms.

Cookies, analytics and similar technologies

Our website uses cookies and similar technologies, such as your browser’s local storage. A cookie is a small file that a website saves in your browser. We use these tools to keep the website working, to understand how people find and use it so we can improve it, and to measure which of our marketing leads to enquiries.

Google Analytics and Google Tag Manager

Google Analytics collects information such as the pages you visit, how long you stay, the website or ad that brought you to us, your approximate location (based on your IP address), and your device and browser type. It uses cookies such as _ga. We use Google Tag Manager to load and manage tools like Google Analytics, to count clicks on the phone number and email links on our website, and we may use it to load advertising measurement tags, such as Google Ads conversion tracking. Google uses this information as described in How Google uses information from sites or apps that use its services.

Microsoft Clarity (session recording and heatmaps)

Microsoft Clarity records how visitors use our pages, such as mouse movements, clicks, taps, scrolling and the pages viewed, and creates session replays and heatmaps from this. It also collects device and browser details and your approximate location, and uses cookies such as _clck and _clsk. We use Clarity’s masking settings so that the text you type into our forms is not captured in recordings. Microsoft handles this information as described in the Microsoft Privacy Statement.

Marketing attribution

When you first arrive on our website, a script on our website saves some details about that visit in your browser’s local storage: the campaign details in the link you followed (UTM parameters that show the source, medium and campaign of an ad or email, and any Google or Facebook ad click identifier), the page you landed on, and the website that referred you. These details stay in your browser for 90 days. If you send us an enquiry through one of our forms during that time, they are sent to us with your enquiry, so we can see which of our marketing brought you to us. We use them only for analytics and marketing attribution.

Website forms

When you submit a form on our website, Webflow stores the details you enter so that we can respond. Forms on some of our landing pages are also set up to work with HubSpot, so the details you submit through those forms may also be stored in HubSpot.

Reviews widget

Some pages show client reviews through a widget provided by Elfsight. When the widget loads, Elfsight receives technical information such as your IP address, operating system and browser type, and may set a cookie.

Our website platform

Our website is hosted on Webflow, which may use cookies and similar technologies that are needed for the website to work securely.

Other websites and social media

Our website links to other websites and to our social media pages. Those websites and platforms have their own privacy policies, and we are not responsible for how they handle personal information.

Your choices

  • You can block or delete cookies, and clear local storage, in your browser settings (for example, by clearing the cookies and site data for our website). Our website will still work, although some features may not.
  • You can stop Google Analytics collecting information about your visits with the Google Analytics Opt-out Browser Add-on, and manage Google ad personalisation in My Ad Center.
  • Microsoft Clarity supports the Global Privacy Control (GPC) signal, if your browser sends it. You can also opt out of Microsoft through the Digital Advertising Alliance’s WebChoices tool.

Direct marketing

We may use your contact details to send you information about our services, HR and employment law updates and events, by email, SMS or phone. We send marketing emails and text messages only if you have agreed to receive them, or where the Spam Act 2003 (Cth) allows us to infer your consent, for example because you are a client and the message relates to our services. Every marketing email and text message identifies Employment Compass as the sender, tells you how to contact us and tells you how to unsubscribe.

You can opt out at any time by using the unsubscribe link or opt-out instructions in the message, by telling us during a call, or by contacting us. Opting out is free, and we will act on an unsubscribe request within 5 business days. You can also ask us where we got your details, and we will tell you unless that is impracticable or unreasonable. After you opt out, we will still contact you about services we are providing to you.

We do not use sensitive information for marketing, and we do not sell or give your details to other organisations for their marketing.

Automated decisions and AI tools

We do not currently make decisions about individuals solely by automated means.

We may use software, including artificial intelligence (AI) tools, to help our people with tasks such as transcribing calls, summarising notes, organising information and drafting documents. Our people review this work. Our advisers and investigators, not computer programs, make the findings and recommendations in our advice and investigations, and decisions about employees, such as whether to take disciplinary action, are made by their employer.

If we start to use computer programs to make decisions, or to do things substantially and directly related to making decisions, that could reasonably be expected to significantly affect an individual’s rights or interests, we will first update this policy to describe the kinds of personal information used and the kinds of decisions involved.

How we hold and protect personal information

We hold personal information mainly in secure cloud-based systems, and sometimes in paper files. We take reasonable steps, including technical and organisational measures, to protect it from misuse, interference and loss, and from unauthorised access, modification or disclosure. These steps include:

  • limiting access to the people who need it, with sensitive matters such as workplace investigations restricted to the people working on them
  • password-protected systems and multi-factor authentication where available
  • confidentiality obligations for our staff and contractors
  • choosing reputable service providers with appropriate security.

No way of sending information over the internet is completely secure, so please take care when you send us personal information.

Data breaches

If we suspect a data breach, we act quickly to contain it and assess whether it is likely to result in serious harm to anyone whose information is involved, and we take all reasonable steps to complete that assessment within 30 days. If it is an eligible data breach under the Notifiable Data Breaches scheme in the Privacy Act, we will notify the Office of the Australian Information Commissioner (OAIC) and the people at risk as soon as practicable, and tell them what happened, what kinds of information were involved and the steps we recommend they take. If a breach involves information we hold for a client, we will also tell that client promptly and work with them on the response.

How long we keep personal information

We keep personal information only for as long as we need it for the purposes in this policy, or for as long as the law requires, for example under tax and business record-keeping laws. We generally keep client records, including advice and investigation records, for 7 years after our work for that client ends, because they may be needed to respond to a claim or a regulator. Details from enquiries that do not lead to work are kept only for as long as we reasonably need them. Campaign details saved in your browser for marketing attribution are kept there for 90 days.

When we no longer need personal information, we take reasonable steps to destroy it or de-identify it.

Accessing and correcting your personal information

You can ask for access to the personal information we hold about you, and ask us to correct it if it is inaccurate, out of date, incomplete, irrelevant or misleading. Contact us using the details above. We will need to confirm your identity first.

We will respond within a reasonable time, usually within 30 days. There is no charge for making a request or for correcting information. If giving you access involves a lot of work, we may charge a reasonable fee for it, and we will tell you the amount first.

If we hold your information because we are working for your employer or another client, we may need to consult them before we respond. In some cases the law allows us to refuse access, for example where giving access would unreasonably affect someone else’s privacy (which can apply to workplace investigation records), or where the information relates to existing or anticipated legal proceedings. If we refuse access, we will consider whether we can give you access in another way, such as through an intermediary we both agree on.

If we refuse access or correction, we will tell you why in writing and how you can complain. If we do not correct your information, you can ask us to attach a statement saying that you believe it is inaccurate, out of date, incomplete, irrelevant or misleading. If we correct information that we previously gave to someone else, you can ask us to let them know.

Making a complaint

If you think we have breached the Australian Privacy Principles or mishandled your personal information, please contact our Privacy Officer in writing using the details above. Tell us what happened and how you would like it resolved.

We will acknowledge your complaint within 5 business days, look into it, and aim to give you a written response within 30 days. If we need more time, we will tell you why.

If you are not satisfied with our response, or you have not heard from us within 30 days, you can complain to the Office of the Australian Information Commissioner (OAIC):

Changes to this policy

We may update this policy from time to time, for example when our practices or the law change. The current version is always available on this page, with the date it took effect.

This policy took effect on 4 October 2026.

1300 144 002