Privacy Policy
SysGuard is operated by K and M Finance Solutions Pty Ltd (ABN 99 653 784 064) ("we", "us", "our"). Registered address: Unit 22/67-71 Eton Street, Sutherland NSW 2232 Contact: office@sysguard.com.au
Effective: 1 July 2026
This policy explains how we handle personal information in operating SysGuard. It is written to meet our obligations under the *Privacy Act 1988* (Cth) and the Australian Privacy Principles ("APPs").
1. Two different roles
Please read this first, because it determines who is responsible for what.
(a) Information we hold as a service provider ("Customer Data"). Most personal information in SysGuard — worker records, shift records, pay information, client contacts — is uploaded by our business customers about their own workers and clients. The customer decides what to collect and why. We hold and process it on their behalf and under their instructions, as described in the Data Processing Addendum. If you are a worker or a client contact and you want your information corrected or removed, please contact the business that engaged you in the first instance; we will refer such requests to them.
(b) Information we collect for ourselves. Information about our own account holders, prospects and website visitors — for example the name and email of the person who administers an account. We are the controller of that information and this policy governs it directly.
2. What we collect
Depending on your relationship with us, this may include:
- Account and contact information — name, business name, work email, phone, role, and login credentials (passwords are stored only as salted hashes; we never store them in readable form).
- Worker and client information submitted by our customers — names, contact details, dates of birth, addresses, licence and accreditation numbers and expiry dates, employment and engagement details, rosters and hours worked, pay rates and payment records, and where the customer chooses to use those features, bank account details and tax file numbers.
- Documents uploaded — including photographs, scans and PDFs of timesheets and related records, which may contain handwriting and signatures.
- Technical and usage information — IP address, device and browser type, pages accessed, actions taken, timestamps, and error and audit logs, used for security, troubleshooting and improving the Platform.
- Communications — correspondence with us, and records of emails the Platform sends on a customer's behalf.
We do not seek to collect sensitive information beyond what is described above, and we ask customers not to upload health, biometric or other sensitive information except where genuinely required and lawfully collected.
3. Tax file numbers
Where a customer uses payroll features, tax file numbers may be stored. TFN information is subject to the Privacy (Tax File Number) Rule 2015. We use and disclose TFN information only for the purpose for which the customer provided it, restrict access to it, and do not use it as an identifier. Customers are responsible for collecting TFNs lawfully from their workers.
4. How we collect it
Mostly directly — from customers and their Authorised Users entering it or uploading documents, and from people who contact us. We also collect technical information automatically when the Platform is used. Where a customer connects a third-party service (for example an accounting system), information may be exchanged with that service at their direction.
5. Why we use it
- to provide, operate, secure and support the Platform;
- to perform the functions our customers ask of it — rostering, timesheet processing, pay and invoice calculation, document generation, and sending emails on their behalf;
- to authenticate users and prevent unauthorised access, fraud and misuse;
- to diagnose faults, monitor performance and improve the Platform;
- to communicate about the service, including changes, incidents and support; and
- to meet our legal obligations.
We do not sell personal information. We do not use Customer Data to train third-party AI models — see clause 7.
6. Who we disclose it to
- Service providers who help us run the Platform — hosting, database, email delivery, payment processing and AI processing. These are listed in the Data Processing Addendum.
- Third-party systems you connect, at your direction (for example when you push invoices into an accounting system).
- Your own recipients — for example when the Platform emails an invoice to your client on your behalf.
- Authorities, where required or authorised by law.
- A purchaser, if our business is sold or restructured, subject to equivalent protection.
7. Artificial intelligence processing
To read timesheets and similar documents, document content is sent to a third-party AI provider for processing and returned as structured data. We select providers that, under their terms, do not use the content of API requests to train their models. Extracted data is presented for human review before it becomes a record. Automated extraction is assistive and is not used to make any decision producing legal or similarly significant effects about an individual without human involvement.
8. Overseas disclosure (APP 8)
Some of our providers store or process data outside Australia, including in the United States and other jurisdictions. Where we disclose personal information overseas we take reasonable steps to ensure the recipient handles it consistently with the APPs, including through contractual commitments. The current list of providers and their processing locations is maintained in the Data Processing Addendum.
9. Security
We take reasonable steps to protect personal information, including: encryption in transit; access controls and role-based permissions; hashed credentials; audit logging; separation of each customer's data; least-privilege administrative access; and routine backups.
No system is completely secure. We cannot guarantee that unauthorised access will never occur. Customers must also play their part — using strong unique passwords, not sharing logins, removing access promptly when people leave, and configuring permissions appropriately.
10. Data breaches
We maintain a process for identifying, containing and assessing suspected data breaches. Where a breach is likely to result in serious harm and the Notifiable Data Breaches scheme applies, we will notify the Office of the Australian Information Commissioner and affected individuals as required by law. Where the breach concerns Customer Data, we will notify the affected customer without undue delay so they can meet their own obligations, and we will co-operate reasonably with them.
11. Retention
We keep personal information while it is needed for the purposes above, while an account is active, and afterwards as described in the Terms (clause 22) or as required by law. Residual copies may remain in routine backups for a limited period until overwritten. When no longer needed and not legally required, information is deleted or de-identified.
12. Access and correction
You may ask for access to, or correction of, personal information we hold about you by contacting office@sysguard.com.au. We will respond within a reasonable period, normally 30 days. We may need to verify your identity, and there are limited grounds on which access may be refused, which we will explain. If your information sits within a customer's account (see clause 1(a)), we will direct the request to that customer.
13. Complaints
If you think we have breached the APPs, contact office@sysguard.com.au with details. We will acknowledge promptly and aim to respond substantively within 30 days. If you are not satisfied, you may complain to the Office of the Australian Information Commissioner (oaic.gov.au, 1300 363 992).
14. Cookies and similar technologies
We use strictly necessary cookies and local storage to keep you signed in, remember preferences and maintain security. We do not use them to build advertising profiles. Blocking them may stop the Platform working.
15. Changes
We may update this policy. Material changes will be notified as set out in clause 20 of the Terms.