Effective date: 4 October 2026
Employment Compass is a business name of Progredi Pty Ltd ABN 47 667 125 788. In this policy, “Employment Compass”, “we”, “us” and “our” mean Employment Compass.
We help Australian businesses with HR advice (including our HR advice line), HR policies and documents, compliance, employee relations, workplace investigations, onsite HR (Compass Onsite) and representation in Fair Work matters.
This policy explains how we collect, hold, use and disclose personal information, and how you can access or correct your information or make a complaint. It applies to personal information we handle through our website, when we provide our services, and in running our business. We handle personal information in line with the Privacy Act 1988 (Cth), including the Australian Privacy Principles.
“Personal information” means information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether or not it is true and whether or not it is recorded in a material form.
This policy covers the personal information we handle about our clients’ employees and other people involved in the matters we help with. Where the Privacy Act’s employee records exemption applies, it does not cover how we handle employee records about our own current and former staff.
If you have a question about this policy or about how we handle your personal information, please contact our Privacy Officer:
Employment Compass is a business name of Progredi Pty Ltd ABN 47 667 125 788. We also have an office at 11 York Street, Sydney NSW 2000.
This policy is available free of charge. If you would like a copy in another form, such as a printed copy, please ask us.
The kinds of personal information we collect and hold depend on how you deal with us.
When a client asks us to help with an HR matter, we may collect personal information about its employees, former employees, contractors, job candidates and other people involved, such as complainants, respondents and witnesses. Depending on the matter, this may include:
Some information in HR matters is “sensitive information” under the Privacy Act. It includes health information, genetic information, some biometric information, and information or an opinion about a person’s racial or ethnic origin, political opinions, membership of a political association, religious beliefs or affiliations, philosophical beliefs, membership of a professional or trade association or a trade union, sexual orientation or practices, or criminal record.
We collect sensitive information only when it is reasonably necessary for our services and the person has consented, or where the law otherwise allows it, for example where the collection is required or authorised by law, or is reasonably necessary to establish, exercise or defend a legal or equitable claim. We limit access to it to the people working on the matter.
Please do not include health or other sensitive details about anyone in our website forms. Tell us briefly what your enquiry is about, and we will ask for the information we need.
We collect the information in your application, such as your resume, qualifications, work history and referees, and notes from interviews and reference checks.
We collect the names, contact details and business details of our suppliers, referral partners and other people we deal with in running our business.
We collect personal information only by lawful and fair means. Where it is reasonable and practicable, we collect it directly from you, for example when you:
We often collect personal information about people from someone else, usually our client. For example, an employer may give us information about an employee so we can advise on a performance or conduct issue, or a witness may give us information about another person during a workplace investigation. We may also collect information from publicly available sources, such as Fair Work Commission decisions, ABN Lookup and business websites.
When we collect information about you from our client, we generally rely on our client to let you know, where that is appropriate. When we deal with you directly, for example in an investigation interview, we will tell you who we are, why we are collecting your information and who it is likely to be given to.
If you give us personal information about someone else, please make sure you are allowed to do so.
We may record and transcribe calls for quality and training purposes, and to keep an accurate record of our advice. If we do, we will tell you at the start of the call. The same applies to video meetings, for example on Google Meet or Microsoft Teams: if we record or transcribe a meeting, we will tell you at the start. If you would prefer a call or meeting not to be recorded, please tell us.
We keep records of the text messages (SMS) sent to and from our phone lines.
When you visit our website, our website host and the analytics and other tools described in “Cookies, analytics and similar technologies” below automatically collect information about your device and your visit.
If we receive personal information that we did not ask for, we will decide within a reasonable time whether we could have collected it for our services. If we could not, we will destroy or de-identify it as soon as practicable, where it is lawful and reasonable to do so.
You can browse our website, and ask us general questions, without telling us who you are or by using a pseudonym. However, we usually need your name and contact details to respond to an enquiry, and it is not practicable for us to provide our services without knowing who we are dealing with.
We collect, hold, use and disclose personal information to:
We use and disclose personal information for the purpose we collected it, for a related purpose you would reasonably expect (for sensitive information, a directly related purpose), with your consent, or where the law requires or allows it.
If you do not give us the information we ask for, we may not be able to respond to your enquiry or provide our services.
Depending on the matter, we may disclose personal information to:
We do not sell personal information.
Some of our service providers store or process personal information outside Australia, so we are likely to disclose personal information to overseas recipients. The main ones are:
These recipients are likely to store or process information in the United States, and may also do so in other countries where they or their subcontractors operate.
Other service providers we use, for example for email, document storage, phone and SMS, video meetings and transcription, may store or access personal information in Australia or overseas, including in the United States. Before we disclose personal information to an overseas recipient, we take reasonable steps to make sure it will handle the information consistently with the Australian Privacy Principles, for example by using reputable providers that make privacy and security commitments in their terms.
Our website uses cookies and similar technologies, such as your browser’s local storage. A cookie is a small file that a website saves in your browser. We use these tools to keep the website working, to understand how people find and use it so we can improve it, and to measure which of our marketing leads to enquiries.
Google Analytics collects information such as the pages you visit, how long you stay, the website or ad that brought you to us, your approximate location (based on your IP address), and your device and browser type. It uses cookies such as _ga. We use Google Tag Manager to load and manage tools like Google Analytics, to count clicks on the phone number and email links on our website, and we may use it to load advertising measurement tags, such as Google Ads conversion tracking. Google uses this information as described in How Google uses information from sites or apps that use its services.
Microsoft Clarity records how visitors use our pages, such as mouse movements, clicks, taps, scrolling and the pages viewed, and creates session replays and heatmaps from this. It also collects device and browser details and your approximate location, and uses cookies such as _clck and _clsk. We use Clarity’s masking settings so that the text you type into our forms is not captured in recordings. Microsoft handles this information as described in the Microsoft Privacy Statement.
When you first arrive on our website, a script on our website saves some details about that visit in your browser’s local storage: the campaign details in the link you followed (UTM parameters that show the source, medium and campaign of an ad or email, and any Google or Facebook ad click identifier), the page you landed on, and the website that referred you. These details stay in your browser for 90 days. If you send us an enquiry through one of our forms during that time, they are sent to us with your enquiry, so we can see which of our marketing brought you to us. We use them only for analytics and marketing attribution.
When you submit a form on our website, Webflow stores the details you enter so that we can respond. Forms on some of our landing pages are also set up to work with HubSpot, so the details you submit through those forms may also be stored in HubSpot.
Some pages show client reviews through a widget provided by Elfsight. When the widget loads, Elfsight receives technical information such as your IP address, operating system and browser type, and may set a cookie.
Our website is hosted on Webflow, which may use cookies and similar technologies that are needed for the website to work securely.
Our website links to other websites and to our social media pages. Those websites and platforms have their own privacy policies, and we are not responsible for how they handle personal information.
We may use your contact details to send you information about our services, HR and employment law updates and events, by email, SMS or phone. We send marketing emails and text messages only if you have agreed to receive them, or where the Spam Act 2003 (Cth) allows us to infer your consent, for example because you are a client and the message relates to our services. Every marketing email and text message identifies Employment Compass as the sender, tells you how to contact us and tells you how to unsubscribe.
You can opt out at any time by using the unsubscribe link or opt-out instructions in the message, by telling us during a call, or by contacting us. Opting out is free, and we will act on an unsubscribe request within 5 business days. You can also ask us where we got your details, and we will tell you unless that is impracticable or unreasonable. After you opt out, we will still contact you about services we are providing to you.
We do not use sensitive information for marketing, and we do not sell or give your details to other organisations for their marketing.
We do not currently make decisions about individuals solely by automated means.
We may use software, including artificial intelligence (AI) tools, to help our people with tasks such as transcribing calls, summarising notes, organising information and drafting documents. Our people review this work. Our advisers and investigators, not computer programs, make the findings and recommendations in our advice and investigations, and decisions about employees, such as whether to take disciplinary action, are made by their employer.
If we start to use computer programs to make decisions, or to do things substantially and directly related to making decisions, that could reasonably be expected to significantly affect an individual’s rights or interests, we will first update this policy to describe the kinds of personal information used and the kinds of decisions involved.
We hold personal information mainly in secure cloud-based systems, and sometimes in paper files. We take reasonable steps, including technical and organisational measures, to protect it from misuse, interference and loss, and from unauthorised access, modification or disclosure. These steps include:
No way of sending information over the internet is completely secure, so please take care when you send us personal information.
If we suspect a data breach, we act quickly to contain it and assess whether it is likely to result in serious harm to anyone whose information is involved, and we take all reasonable steps to complete that assessment within 30 days. If it is an eligible data breach under the Notifiable Data Breaches scheme in the Privacy Act, we will notify the Office of the Australian Information Commissioner (OAIC) and the people at risk as soon as practicable, and tell them what happened, what kinds of information were involved and the steps we recommend they take. If a breach involves information we hold for a client, we will also tell that client promptly and work with them on the response.
We keep personal information only for as long as we need it for the purposes in this policy, or for as long as the law requires, for example under tax and business record-keeping laws. We generally keep client records, including advice and investigation records, for 7 years after our work for that client ends, because they may be needed to respond to a claim or a regulator. Details from enquiries that do not lead to work are kept only for as long as we reasonably need them. Campaign details saved in your browser for marketing attribution are kept there for 90 days.
When we no longer need personal information, we take reasonable steps to destroy it or de-identify it.
You can ask for access to the personal information we hold about you, and ask us to correct it if it is inaccurate, out of date, incomplete, irrelevant or misleading. Contact us using the details above. We will need to confirm your identity first.
We will respond within a reasonable time, usually within 30 days. There is no charge for making a request or for correcting information. If giving you access involves a lot of work, we may charge a reasonable fee for it, and we will tell you the amount first.
If we hold your information because we are working for your employer or another client, we may need to consult them before we respond. In some cases the law allows us to refuse access, for example where giving access would unreasonably affect someone else’s privacy (which can apply to workplace investigation records), or where the information relates to existing or anticipated legal proceedings. If we refuse access, we will consider whether we can give you access in another way, such as through an intermediary we both agree on.
If we refuse access or correction, we will tell you why in writing and how you can complain. If we do not correct your information, you can ask us to attach a statement saying that you believe it is inaccurate, out of date, incomplete, irrelevant or misleading. If we correct information that we previously gave to someone else, you can ask us to let them know.
If you think we have breached the Australian Privacy Principles or mishandled your personal information, please contact our Privacy Officer in writing using the details above. Tell us what happened and how you would like it resolved.
We will acknowledge your complaint within 5 business days, look into it, and aim to give you a written response within 30 days. If we need more time, we will tell you why.
If you are not satisfied with our response, or you have not heard from us within 30 days, you can complain to the Office of the Australian Information Commissioner (OAIC):
We may update this policy from time to time, for example when our practices or the law change. The current version is always available on this page, with the date it took effect.
This policy took effect on 4 October 2026.
