Privacy Policy
The George Baini Group

Privacy Policy

About this policy

The George Baini Group Proprietary Limited (ACN 603 593 068, ABN 68 603 593 068) ('The George Baini Group', 'TGBG', 'we', 'our' or 'us') respects your privacy and is committed to handling your personal information openly and responsibly.

This policy explains the kinds of personal information we collect and hold, how and why we collect, use and disclose it, how we protect it, and how you can access it, correct it or make a complaint. It applies to all of the products and services we supply, including the software and platform services we supply, operate and maintain, our cloud and hosting services, the professional and support services we provide, our telecommunications and internet services, and our websites, portals and applications.

We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

This policy is a general statement of our practices. Where a product, service or feature involves handling your information in a way that would not be apparent from the circumstances, we will tell you at the relevant point, such as on the page or form where the information is collected or where the feature is enabled.

What personal information is

Personal information is information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether or not it is true and whether or not it is recorded in a material form. Information that does not identify anyone, and from which no one can reasonably be identified, is not personal information and is not subject to this policy. Information about a company or other incorporated body is generally not personal information, although information about a sole trader or a partnership may be.

The kinds of information we collect and hold

The information we collect depends on the products and services you use, the way you interact with us, and what we are required to collect by law. Our services differ from one another, and so does the information each of them requires.

The categories below describe the kinds of personal information we may collect and hold. They are examples rather than an exhaustive list, and they will change over time as our products and services change.

  • Identity information, including your name and any previous name, date of birth, gender where relevant, occupation, role, and the organisation you represent
  • Contact information, including residential, business, service and postal addresses, email addresses, telephone and mobile numbers, and emergency contact details
  • Identity, authority, eligibility and verification information, including identity document details, evidence of your authority to act for an organisation, and the results of identity, eligibility and fraud checks
  • Account and authentication information, including usernames, credentials, multi-factor authentication details, device identifiers, session records and access logs
  • Financial information, including bank account details, payment authorities, payment tokens and masked card details held by our payment providers, billing and payment history, and amounts owing
  • Employment and remuneration information, where we provide payroll or workforce services, including pay, allowances, deductions, leave, timesheets, tax treatment and offsets, and superannuation fund and member details
  • Government and regulatory identifiers, including tax file numbers, business and company numbers, and registrations or authorisations we hold or lodge on your behalf
  • Service, technical and equipment information, including usage records and metadata, service and premises identifiers, equipment identifiers and configuration, network and system logs, and diagnostic data
  • Asset information, where a service relates to an asset, being the identifiers and details of that asset
  • Transaction and usage information, including records of the products and services you acquire, how you use them, and the transactions processed through them
  • Risk and conduct information, including records of suspected fraud, misuse, non-payment or breach of our terms, and any resulting restriction or refusal of service
  • Communications and interaction records, including correspondence, support tickets, appointments, file notes, call recordings, and your interactions with any assistive or artificial intelligence feature we provide
  • Any other information we are required or authorised by law to collect, or that we reasonably need to provide a particular product or service

We collect only what is reasonably necessary for the service concerned, or what we are required to collect by law. If you choose not to provide information we ask for, we may be unable to supply the product or service you have requested.

Sensitive information

Some information is treated as sensitive information under the Privacy Act and attracts additional protection. We do not generally seek sensitive information. Where a service requires it, for example information bearing on residency or entitlement that we must collect to meet a payroll or reporting obligation, we collect it only with your consent and where it is reasonably necessary for one of our functions or activities, or where we are required or authorised by law to collect it. We use and disclose sensitive information only for the purpose for which it was collected, or as permitted by law.

Tax file numbers

Where we collect or hold a tax file number, we do so only because it is required or authorised for a taxation, personal assistance or superannuation purpose, and we handle it in accordance with the Privacy (Tax File Number) Rule 2015 and the Taxation Administration Act 1953 (Cth).

We use and disclose tax file numbers only for the purpose for which they were provided, including lodgement to the Australian Taxation Office and reporting to superannuation funds, or where required or authorised by law. We do not use a tax file number to identify individuals in our systems, to link records, or for any other purpose. We do not include tax file numbers in any analysis, research or aggregation we undertake, and we do not send them to any artificial intelligence or general purpose processing service. We take reasonable steps to protect tax file numbers from misuse, interference, loss and unauthorised access, and to securely destroy or permanently de-identify them once we are no longer required by law to retain them.

These obligations apply to us regardless of any other exemption available to us under the Privacy Act 1988 (Cth). It is an offence to use or disclose a tax file number other than as permitted by law.

Government-related identifiers

Other than tax file numbers, which are dealt with above, we collect government-related identifiers only to verify your identity, to confirm authority or eligibility, or where we are required or authorised by law. We do not adopt a government-related identifier as our own identifier for you, and we do not use or disclose one except as permitted under APP 9.

How we collect information

Directly from you. Most of the information we hold is given to us by you. We collect it when you enquire about or apply for a product or service, enter into an agreement with us, complete a form, configure or use a service, contact us for support, or enter information into a system we operate for you. If you contact us by telephone, your call may be recorded for training, quality assurance and record-keeping purposes, and we will tell you at the start of the call if it is being recorded.

Automatically, when you use our websites and online services. When you visit our websites, portals or applications, our systems automatically record certain technical information. This includes your IP address, the approximate location derived from it, your device type, operating system and browser, the page or source that referred you, the pages and features you view, the actions you take, the dates, times and duration of your visit, and diagnostic and error information. Where you use a mobile application, this may also include a device identifier and a push notification token.

From third parties. We may collect information about you from sources other than you, including government agencies, registries and verification services, identity verification and fraud prevention providers, suppliers and other parties involved in delivering a service, your authorised representatives and advisers, our business partners, and publicly available sources.

We do this to verify your identity, to confirm that you are authorised to act for an organisation, to confirm eligibility for a product, service or entitlement, to assess whether we are able to supply a service and on what terms, to keep our records accurate, to prevent and detect fraud and misuse, to manage risk, where we are required or authorised by law, and for the other purposes described in this policy. We collect information in this way only where it is reasonably necessary for one of our functions or activities.

Unsolicited information. If we receive personal information we did not ask for, we will determine whether we could have collected it ourselves for one of the purposes described in this policy. If we could not, and the information is not contained in a Commonwealth record, we will destroy the personal information or remove it so that no individual is identifiable, as soon as practicable and provided it is lawful and reasonable to do so.

Information about other people

You may need to give us personal information about other individuals, such as your authorised representatives, contacts or emergency contacts. If you do, we rely on you to tell those individuals that you have provided their information to us and to make them aware of this policy.

Information we hold on behalf of our business customers

Where we supply and operate a platform or system for a business customer, that customer decides what personal information is entered into it. This may include information about their own clients, suppliers, employees and contractors.

In that situation, the business customer is responsible for that information and for its own compliance with the Privacy Act, including for giving the notices, obtaining the consents and holding the authority required to collect the information, to store it with us, and to have us process, lodge or report it on their behalf. We hold and handle that information on the customer's behalf, in accordance with our agreement with them and this policy.

Where an employer uses our systems, the employee records exemption in the Privacy Act may apply to that employer's own handling of its employee records. It does not apply to us as a service provider. We handle that information as we handle all other personal information, in accordance with this policy and the Australian Privacy Principles.

If you are an individual whose information is held in a system we operate for one of our business customers, and you wish to access or correct that information or make a complaint about it, please contact that business directly. They control the information and hold the context needed to deal with your request. If you contact us instead, we will refer your request to them.

Why we collect, hold, use and disclose information

We use and disclose personal information for the purposes for which it was collected, for related purposes you would reasonably expect, and where you have consented or where we are required or authorised by law. Those purposes include:

  • assessing applications, verifying identity and authority, and determining whether we can supply a product or service and on what terms
  • establishing, provisioning, configuring, supporting, maintaining and managing the products and services we supply
  • understanding how our websites, products and services are used, including associating that information with a customer account
  • billing and charging, processing payments, and recovering amounts owing
  • making or receiving payments, lodgements or reports where you have authorised us to do so
  • responding to your enquiries, requests and complaints
  • operating, monitoring, securing, testing, developing and improving our systems, networks and services, including developing, training and evaluating automated and artificial intelligence features
  • detecting, investigating and preventing fraud, misuse, security incidents and other unlawful activity, and assessing and managing the risk of them
  • conducting analysis, research and development to understand and improve our products and services, and to develop new ones
  • producing statistical, benchmarking and market insights, as described under de-identified and aggregated information below
  • telling you about products and services that may interest you, subject to your marketing preferences
  • managing our business, including accounting, auditing, insurance, risk management and professional advice
  • meeting our legal, regulatory, reporting and record-keeping obligations, and exercising or defending legal rights

Artificial intelligence and assistive features

Some of our services include features that use artificial intelligence. These features are not a condition of using our services. An administrator of your organisation controls whether they are enabled, and individual users must additionally be permitted to use them.

Where such a feature is used, the information sent for processing is limited to what the feature requires. This may be the content of a document you choose to submit, or the words a user types into an assistant together with earlier messages in the same conversation so that the assistant can follow the discussion. Where a feature needs particular information beyond this, it will show you what is being sent and ask you to confirm first. If you prefer not to, the feature will continue without it where it can.

The artificial intelligence features described above are assistive. They prepare drafts and pre-filled entries for a person to review, and the decision to accept them rests with that person rather than with the system.

We also use artificial intelligence and automated tools internally in operating our business.

Some of these tools are provided by third parties, and some may process information outside Australia. In the ordinary course of providing their services, providers may hold the information sent to them for a period. Before using a provider we assess its published terms, security documentation and data handling commitments, and we select providers whose practices are consistent with the standards described in this policy. Many providers supply their services on standard terms that we do not negotiate. We do not identify individual providers in this policy, and we may change providers from time to time. Where a feature involves processing outside Australia, the terms that apply to that feature set this out, and the controls available to your organisation are described under where your information is stored and processed below.

We may use information we collect and hold in providing our services to develop, train, test and improve our own automated and artificial intelligence capabilities, using de-identified information wherever practicable.

We do not send tax file numbers to any artificial intelligence service.

Automated decision-making

Some of our systems use personal information in automated processes that make decisions, or that substantially assist in making decisions, which could reasonably be expected to significantly affect the rights or interests of an individual. This section describes the kinds of personal information used and the kinds of decisions involved.

Onboarding, identity and authority. When a business applies for our services, we use identity, contact, verification and authority information, together with information obtained from identity verification services, registries and other third party sources, in automated checks that assess whether the applicant business is legitimate and whether the individuals acting for it are who they say they are and are authorised to do so. The outcome may be that an application proceeds, is referred for manual review, or is declined.

Risk, fraud and misuse assessment. We use identity, account, transaction, usage, technical and risk and conduct information in automated processes that assess whether an application, an account, a transaction or a pattern of activity presents a risk of fraud, misuse or unlawful conduct, including misuse of reporting and lodgement functions. The outcome may be that activity proceeds, is flagged for review, is restricted, or that a service is refused, suspended or terminated.

These processes are not limited to a single product, and we expect their use to expand as our systems develop. Where we introduce automated decision-making of a materially different kind, we will update this policy.

Business customers. Where a system we supply is operated by one of our business customers, that customer configures how it is used and is responsible for decisions it makes using it.

Review. If a decision affecting you has been made or substantially assisted by an automated process, you may ask us to explain it and to have it reviewed by a person. Contact us using the details below. We will tell you the outcome, although we may not be able to disclose information that would reveal how our fraud and risk detection operates.

If you believe information we hold about you that has contributed to such a decision is inaccurate, out of date or incomplete, you may ask us to correct it. Please see accessing and correcting your information below.

Direct marketing

We may use your contact details to tell you about our products and services by email, SMS, post or telephone. Every marketing message we send includes a simple way to opt out, and you can opt out at any time by contacting us or by changing your communication preferences in your account. Opting out of marketing does not stop service, billing, security and other operational messages, which we must send you in order to provide your service. We do not sell or provide your contact details to third parties for their own marketing.

De-identified and aggregated information

We produce statistical and analytical information from the data we collect and hold in providing our services, and we may use, share, publish or commercialise that information. Examples include industry benchmarks, market and usage trends, service performance statistics and similar insights.

Where we do this:

  • analysis is carried out within the environment in which the underlying data is held, and only the resulting statistical output is brought together centrally
  • information that identifies any individual, including names and contact details, is removed before that output leaves the environment, and we do not retain a means of linking the output back to an individual
  • the output may include general attributes such as a broad geographic area, an industry, and the types of products or services involved
  • we apply minimum group sizes, so that where too few businesses or individuals share a given set of attributes, information relating to that group is suppressed rather than collected or published
  • we do not attempt to re-identify the information, and we require anyone we provide it to not to attempt to re-identify it
  • where the underlying data has been entered into a system we operate for a business customer, we do this in accordance with our agreement with them

We maintain internal documentation setting out how this is carried out in practice, and we review it periodically.

We may continue to hold and use this information after a service ends or an account becomes inactive. We do not sell information that identifies you, and we do not sell the contents of your account, your records or your customer lists.

Who we disclose information to

We disclose personal information only where it is necessary for the purposes described in this policy. The kinds of recipients include:

  • service providers who perform functions on our behalf, such as hosting, storage and backup, payment processing, identity verification and fraud prevention, communications delivery, automated and artificial intelligence processing, information technology, software development and support
  • government agencies, regulators and registries, including where we lodge or report on your behalf
  • financial institutions, superannuation funds and clearing houses, where necessary to process payments or contributions you have authorised
  • suppliers and other parties involved in delivering a service to you
  • your authorised representatives, advisers and nominated contacts, or anyone else you ask us to deal with
  • our professional advisers, auditors and insurers, and our business partners
  • law enforcement agencies, courts, tribunals and regulatory authorities, where required or authorised by law
  • a prospective or actual purchaser, investor or successor in connection with a sale, merger, restructure or transfer of all or part of our business, subject to appropriate confidentiality protections

This is not an exhaustive list, and the recipients we use change over time. We may also disclose personal information where it is necessary to give effect to something you have asked us to do, or where you would reasonably expect us to do so in the ordinary course of providing a service, or where we are required or authorised by law. We take reasonable steps to ensure our service providers protect personal information and use it only for the purposes for which we provided it.

Where your information is stored and processed

Customer data is stored at rest in Australia. Information may also be held in physical form, and physical media and backups may be stored at a number of locations within Australia, including at premises operated by third parties.

Where a service involves a third party, that third party stores and processes information in accordance with its own arrangements, which we do not control. Some technology providers we rely on, including providers of artificial intelligence processing, may store or process information outside Australia. The countries in which overseas recipients are most likely to be located are the United States, the United Kingdom, and countries in the European Union.

Where we disclose personal information to an overseas recipient, we take reasonable steps to ensure that the recipient does not breach the Australian Privacy Principles in relation to that information, as required by APP 8. Because many providers supply their services on standard terms that we do not negotiate, those steps consist of assessing the provider's published terms, security documentation and data handling commitments before we use it, limiting the information sent to what the service requires, and selecting providers whose practices are consistent with the standards described in this policy.

Where a feature involves processing outside Australia, this is set out in the terms that apply to that feature. Depending on the feature, your organisation may be able to disable it, restrict it to processing within Australia, or leave it enabled. These controls are managed by an administrator of your organisation.

Banking data and the Consumer Data Right

Where our services can retrieve banking data on your behalf, that data is obtained through an accredited data recipient under the Consumer Data Right. This service is available to business customers only. You give your consent directly to the accredited provider, which then discloses the data to us.

We are not an accredited person, data holder or designated gateway under the Consumer Data Right. Once banking data is disclosed to us, it is no longer regulated under the Consumer Data Right, and the CDR Privacy Safeguards in Part IVD of the Competition and Consumer Act 2010 (Cth) do not apply to our handling of it. The accredited provider should further inform you about this at the time you give your consent.

We handle banking data disclosed to us in accordance with this policy. You may withdraw your consent, or stop using the feature, at any time. If you do, we will stop retrieving further data. Banking data already received forms part of your business records and is dealt with in the same way as your other records.

If our role under the Consumer Data Right changes, we will update this policy and publish any separate policy required by the CDR Rules.

How we protect your information

We take reasonable steps to protect personal information from misuse, interference and loss, and from unauthorised access, modification and disclosure. Our controls include encryption, access controls and authentication appropriate to the sensitivity of the information, logging and monitoring of access and activity, and internal policies limiting access to those who need it.

Security is a shared responsibility. If you hold an account with us, you are responsible for keeping your credentials confidential, for managing the access rights of the users you authorise, and for notifying us promptly if you believe your account has been compromised.

If you use a system that we operate for one of our business customers, and you believe your access has been compromised, please contact that business. They administer their own users and access, and they will contact us if our assistance is needed.

No method of transmission or storage is completely secure. While we take the steps described above, we cannot guarantee absolute security.

Data breaches

We maintain a data breach response plan. If we suspect a data breach has occurred, we will assess it promptly and take steps to contain and remediate it. Where a breach is likely to result in serious harm to any individual whose information is involved, we will notify the affected individuals and the Office of the Australian Information Commissioner in accordance with the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act 1988 (Cth). Where a breach affects information we hold on behalf of a business customer, we will notify that customer so that they can meet their own obligations.

How long we keep information

We keep personal information for as long as we need it for the purposes described in this policy, or for as long as we are required to keep it by law. Retention periods vary according to the type of information and the service concerned.

  • While you hold an account with us. We retain your information for as long as you hold an account with us, whether or not the account is currently active. An account that is not currently in use is generally made inactive rather than deleted, so that it retains its history and can be used again if you return to us.
  • When a service ends. When a service you hold with us ends, we retain the information associated with it for a period after it ends. How long depends on the service, our legal obligations, and whether the information is still needed for the purposes described in this policy.
  • Records we must keep by law. Some information is retained for longer than it otherwise would be because we are required to keep it, including our own financial and taxation records and information we must retain in connection with particular services.
  • Tax file numbers. We securely destroy tax file numbers once we are no longer required by law to retain them.
  • Security and audit records. Authentication, access and system logs are retained for security, investigation and compliance purposes.
  • Statistical and de-identified information. We may produce statistical and de-identified information as described above. That information does not identify you and may be retained indefinitely.

Where you are a business customer, you remain responsible for your own record-keeping obligations, including any obligation to retain employee or financial records.

When we no longer need personal information, and we are not required by law to retain it, we take reasonable steps to destroy it or to permanently de-identify it.

Cookies and similar technologies

Our websites, portals and applications use cookies and similar technologies. We use them for the purposes described in this policy, including keeping you signed in and protecting your session.

You can control or delete cookies through your browser settings. Because some of them are necessary for our services to function, disabling them will prevent you from signing in or using parts of our services.

Dealing with us anonymously

You may deal with us anonymously or using a pseudonym for general enquiries. Once you apply for or acquire a service this is not practicable, because we cannot supply, support or bill a service without knowing who you are, and identity and authority verification is a requirement for our services.

Accessing and correcting your information

You may ask for access to the personal information we hold about you, and you may ask us to correct it if you believe it is inaccurate, out of date, incomplete, irrelevant or misleading. Please contact us using the details below. We will ask you to verify your identity before we act on a request.

We do not charge for making a request. We may charge a reasonable fee for the cost of giving access where a request requires significant time or resources, and we will tell you the amount before we proceed. Any such fee will not be excessive and will not apply to the making of the request itself.

If your information is held in a system we operate for one of our business customers, please contact that business rather than us. We will refer any request we receive to them, and any assistance we provide to that business is subject to our agreement with them.

We will respond within a reasonable period. In limited circumstances the Privacy Act permits us to refuse access or correction, for example where giving access would unreasonably affect the privacy of other individuals, would prejudice an investigation of unlawful activity, or where the request is frivolous or vexatious. If we refuse, we will tell you in writing why, and explain how you may complain.

If we correct information that we have previously disclosed to a third party, and you ask us to, we will take reasonable steps to notify that third party of the correction.

Complaints

If you believe we have breached the Australian Privacy Principles or otherwise mishandled your personal information, please contact us using the details below and tell us what happened and how you would like it resolved.

We will acknowledge your complaint within five business days and aim to resolve it within 30 days. If we need longer, we will tell you why and keep you informed of our progress. We will tell you the outcome of our investigation in writing.

If you are not satisfied with our response, you may refer the matter to the Office of the Australian Information Commissioner at www.oaic.gov.au, by telephone on 1300 363 992, or by post to GPO Box 5218, Sydney NSW 2001. If your complaint relates to a telecommunications service we supply, you may also contact the Telecommunications Industry Ombudsman at www.tio.com.au or on 1800 062 058.

Changes to this policy

We review this policy periodically and may update it to reflect changes in our practices, our services or the law. The current version is always published at https://www.gb.au/about/policies/privacy. Where a change is material, we will take reasonable steps to notify you before it takes effect, such as by email or by a notice within your account.

How to contact us

For any privacy question, request or complaint, contact us at info@gb.au and mark your message for the attention of the Privacy Officer.

Terms of Use | Privacy Policy | Unsolicited Information and Ideas


Copyright (C) The George Baini Group Proprietary Limited 2026. All rights reserved.
The George Baini Group Proprietary Limited (ACN: 603593068 ABN: 68603593068) trades as ("The George Baini Group") and ("TGBG")