How Grunt IP collects, uses, and protects your information.
We take our obligations to protect personal information seriously. We are bound and abide by the Australian Privacy Principles in the Privacy Act 1988 (Cth) (Privacy Act) including the Federal Government changes to the Act that took effect from 11 December 2024.
This document contains our privacy and credit reporting policy. We simply refer to it in the remainder of the document as “Privacy Policy” or “this Policy”.
It sets out in detail how we manage the “Personal Information” and/or “Credit Information” of or about our customers, employees and other individuals we deal with in the course of our business activities.
We have defined the terms “Personal Information” in section 4 (Personal Information defined) and “Credit Information” in section 5 (Credit Information defined).
Amongst other things, our Privacy Policy contains information on: changes to the policy, our names, the purposes for collecting information, the categories of information we collect, how we collect, hold, use and disclose that information, credit reporting, overseas transfers, security, access, correction, complaints and contact details.
We will make changes to this Privacy Policy as often as necessary without notice to ensure it remains relevant and effective in achieving its objectives and goals.
Any changes we make to this Policy will become effective immediately after we have published them, and we will apply them to how we will manage the Personal Information or Credit Information of our customers in the future.
We are Grunt C.E.A. Pty Ltd ACN 673 085 133 trading as Grunt Invoice Protection (Grunt), an invoice protection and recovery organisation which is headquartered in Nerang, Queensland, Australia.
In the remainder of this Policy, we refer to any of the above business names we use simply as “we”, “us” or “our”.
Personal Information means information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether the information or opinion is true or not and whether it was recorded in material form or not.
For the purposes of this Policy, Personal Information includes details such as names, addresses, dates of birth, contact details, account details, employment information, identification documents, bank details, invoice and credit information, and other information reasonably necessary to provide our services.
“Credit Information” is Personal Information that includes information about a person’s credit worthiness, credit standing, credit history, personal insolvency, repayment behaviour and related credit information, as defined under the Privacy Act and related credit reporting laws.
In general, we will only collect Personal Information that is reasonably necessary for us to achieve any or a combination of the primary purposes mentioned in section 6(a) and 6(b) below and the secondary purposes mentioned in section 6(c).
We collect, hold, use and disclose Personal Information for the following primary purposes:
We also collect Personal Information in compliance with our legal or regulatory obligations including those we have under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006, the National Consumer Credit Protection Act 2009, the Corporations Act 2001, thePrivacy Act and various Australian employment, taxation and immigration laws.
Furthermore, we will collect Personal Information if we are required by or under a court or tribunal order to collect that information.
If the collection of Personal Information is required by any other law or court or tribunal order, we will advise you of the relevant law or the details of the court or tribunal order at the time of collecting the information or as soon as practicable after we have collected the information.
We collect, hold, use and disclose your Personal Information for any or a combination of the following secondary purposes:
In the remainder of this page, we will refer to the reader of this Privacy Policy or any individuals whose Personal Information we collect, use, disclose and hold in connection with our business activities as “you” or “your”.
We will collect your Personal Information if you are an individual who:
We will collect Personal Information (from you) in the following circumstances:
In addition to the circumstances mentioned above, we may collect Credit Information from a Credit Reporting Body (CRB) when we are assessing an application you have made to us or you have made on behalf of a business, organisation or agency.
Also, we will collect and use Credit Information in our own records including information on your payments, repayments or default.
Furthermore, we will obtain Credit Information from other Credit Providers with whom you have or had a credit account.
Finally, we will collect your Credit Information from publicly available sources including personal insolvency information entered or recorded in the National Personal Insolvency Index (as defined in the Bankruptcy Act 1966).
We will only collect Personal Information by lawful, fair and transparent means.
We will try to collect personal information directly from you unless it is unreasonable or impracticable to do so.
You are under no legal or moral obligation to provide Personal Information we ask for and we will not oblige you to provide Personal Information.
If you fail or refuse to provide any Personal Information we ask for, we may not be able to do any or a combination of the things mentioned in section 6(a) or section 6(b) above. In some cases if we do not collect, use and/or disclose the Personal Information we ask for we may not only risk providing you an unsuitable product or service, but we may also be in breach of our legal or regulatory obligations.
If the information we are collecting includes Credit Information, we will comply with the applicable requirements of the Privacy Act and the Credit Reporting Code, and we will notify you of the purpose of the collection and any credit reporting bodies involved where required.
If reasonable and practicable, we will collect Personal Information or Credit Information directly from you. In some cases, we may authorise another person, such as a licensed builder, a recruitment organisation or background checking service provider, to collect your Personal Information on our behalf.
With the exception of circumstances involving related organisations, we will only collect your Personal Information from another person with your express or implied consent. Some third parties from whom we may collect Personal Information include customer referees, service providers, credit reporting bodies, accountancy or legal advisers, and verification partners.
Finally, we may collect Personal Information (other than sensitive information) from someone else if it is unreasonable or impracticable to collect the information from you.
In some cases we may collect your Personal Information from an organisation or person that is related to us if the primary purpose for which that organisation or person collected your information in the first place was or is related to the primary purpose for which we would collect your information.
If we receive your Personal Information which we did not ask for and determine that we are not entitled to collect the information, we will take reasonable steps as soon as practicable to destroy or de-identify the information if it is not contained in a record or document of the Commonwealth government of Australia. If the information is contained in a record or document of the Commonwealth government of Australia we will attempt to return it to you, and failing that, we will return the record to the relevant Commonwealth government agency.
If we determine that we are entitled to collect the Personal Information we did not ask for and you are an existing customer of ours or you are a guarantor or a person acting on behalf of an existing customer of ours, we will advise you about the information and seek your consent to manage the information in accordance with the requirements of this Privacy Policy, unless we have obtained your consent on a previous occasion.
If it is lawful, practicable and reasonable when collecting Personal Information, we will give you the option of not identifying yourself or the option of your use of a pseudonym.
An example would be where we are conducting a customer, product or market survey or research and it is practicable to obtain the information we want for the purposes of that survey or research without the need for you to tell us your names, date of birth or residential address in particular.
We will take all reasonable steps in the circumstances to ensure that Personal Information we collect from or about you is accurate, complete and up-to-date.
Accordingly, in some cases, we may ask you for an independent and reliable document or use an electronic data source to verify that the Personal Information you have given us is accurate, complete and up-to-date.
If we identify any discrepancy between information you provided us and information in an independent and reliable document or electronic data source, we will give you an opportunity to correct or reconcile the discrepancy, if it is reasonable or practicable for us to do so, before using the information for the purposes for which we have collected it.
We may terminate a product or service we have agreed to provide you, your employment with us or your business or contracting relationship with us if we find that the Personal Information we relied on to offer you the product, service, job or business or contracting opportunity was not accurate, complete or up-to-date at the time we collected or used it.
We will not send data containing Personal Information overseas.
We will use or disclose Personal Information we hold if the use or disclosure is required for the primary purposes outlined in this Policy, the secondary purposes described in this Policy, if you have consented to it, or if it is otherwise permitted or required by law.
We may disclose Personal Information to our service providers, related entities, credit reporting bodies, legal advisers, fraud prevention agencies, regulators, auditors and government agencies where we reasonably believe that disclosure is necessary to provide our services, manage risk, comply with legal obligations or protect our interests.
The security of your Personal Information which we hold is important to us and we take all reasonable steps in the circumstances to protect it from unauthorised access, misuse, interference, loss, disclosure or modification.
We keep your Personal Information in various formats including paper and electronic formats. Some of the ways we secure your Personal Information are by restricting access, using secure systems, requiring authentication, applying encryption in transit and storage where appropriate, and using contractual arrangements with third-party service providers.
We can store Personal Information physically or electronically with third party data storage providers. Where we do this, we use contractual arrangements to ensure those providers take appropriate measures to protect that information and restrict the uses to which they can put that information.
In general, we will destroy your Personal Information or any document or record containing Personal Information we no longer need the information or if we are not required by or under an Australian law to keep the information or the document or record beyond a required period.
If it is not practicable to destroy the information or the document or record containing the Personal Information, we will put the document “beyond use” as defined in the Credit Reporting Code.
In some circumstances, we will “de-identify” Personal Information instead of destroying it including circumstances we are required by or under an Australian law to keep the information or the document or record.
You can request access to your Personal Information by contacting us.
Also, you may use a third party (access-seeker) to make a request to us for access to your Personal Information.
In whatever manner and whenever you contact us, we will verify your identity or that of any person you have authorised to be given access to your Personal Information before we agree to give access.
Also, if you authorise an access-seeker to request access to your Personal Information you must do so in writing before we can give them access.
We reserve the right to change our identity verification requirements from time to time without notice.
We will endeavour to respond to your request for access to your Personal Information within a reasonable period of time after the date we have verified your identity. If for any reason we cannot or refuse to give access within that timeframe, we will give you a written notice that sets out the reason for the refusal and/or the reasons we are unable to provide access within the timeframe.
For a request to access your Credit Information, we will endeavour to provide access to you within 30 days of receiving your request, unless unusual circumstances apply.
Your request for access may specify the form or manner you wish your information to be provided to you including whether you wish the information to be given to you over the telephone or in writing and by regular post, email or facsimile.
If reasonable or practicable, we will give you access in the form or manner you have specified. If it is not reasonable or practicable, we will take reasonable steps to provide access in a way that meets both your and our needs, including by a mutually agreed intermediary.
In general, we will not charge you a fee for making a request for access to your Personal Information. We may charge a fee for retrieving and preparing the information and/or giving it to you in the manner you have requested, but any such fee will not be excessive in the circumstances.
We may refuse you access to your Personal Information if the law permits us to do so or if giving access would breach privacy, legal, contractual or security obligations. We may refuse access to Credit Information in similar circumstances, including where the request is vexatious, unreasonable or would expose confidential information.
If we are satisfied on reasonable grounds that the Personal Information we hold about you is inaccurate, out-of-date, incomplete, irrelevant or misleading, we will take appropriate steps to correct the information.
If we correct your Personal Information we will take appropriate steps within 7 days of the correction to notify you and any other person or organisation to which we have provided the pre-corrected information, including any affected information recipient or CRB if the information corrected is Credit Information.
You too can ask us to correct the Personal Information we hold about you if you consider the information is not accurate, up-to-date, complete, relevant or appropriately clear.
Also, you may request us to take reasonable, practicable or lawful steps to notify any other organisation to which we provided your Personal Information on a previous occasion that we have corrected your information.
If your request relates to Personal Information that is not Credit Information, we will respond to the request within a reasonable period of time of receiving it. If the request relates to your Credit Information, we will respond to the request within 30 days from the date you make the request, unless an extension is agreed.
We will not charge you any fees for making a request to us to correct your information.
If we refuse to correct your Personal Information, we will give you a written notice that sets out the reasons for refusal and the steps you may take to seek review or raise a complaint.
If we refuse to correct your Personal Information, you may request us to associate a statement with the Personal Information that you consider is inaccurate, out-of-date, incomplete, irrelevant or misleading.
Within a reasonable period of time after receiving your request, we will take any step that is reasonable, practicable and lawful in the circumstances to associate the statement in such a way that will make the statement apparent to users of the information.
We will not charge any fee for a request to associate a statement as described above.
Amongst other things, you may contact us if you wish to request access to, correct or update your Personal Information, complain about our handling of your information, or ask any questions about this Policy.
You may write to or email us as follows:
Mail:
The Privacy Officer
Grunt C.E.A. Pty Ltd
11/1 Nerang Street, Nerang QLD 4211
Email: accounts@gruntip.com
Website: www.gruntip.com
We will endeavour to acknowledge your request or complaint within 7 days after we have received it. Depending on the circumstances, we may acknowledge your request or complaint by phone, email, regular post or facsimile.
A complaint in relation to Credit Information will be acknowledged by email, regular post or facsimile.
We will take reasonable steps to investigate the subject matter of your request or complaint. Such steps may include liaising with our external representatives who are familiar with the subject matter of the request.
If the request or complaint concerns Credit Information, we may consult with other external organisations or agencies, including a relevant CRB, other credit providers and affected information recipients. Whether such consultation is necessary will depend upon whether we provided your information to those external organisations or agencies or whether we obtained your information from them.
We will give you reasonable opportunity to present your case. Any information we discover during the investigation will be analysed and evaluated before a decision is reached on the merits of your request or complaint.
You will be advised about our decision within the timeframes specified in this Policy if applicable to your request or complaint or within the timeframe specified in the Privacy Act or Credit Reporting Code.
If our decision is in writing, it will contain the reasons for the decision and information on your right to refer our decision to the Privacy Commissioner if you are not satisfied with the decision.
You may also refer our decision to the Privacy Commissioner if you are not satisfied with it. The Privacy Commissioner’s contact details are:
Mail: Privacy Commissioner GPO Box 5218, Sydney NSW 2001
Telephone: 1300 363 992
Email: enquiries@oaic.gov.au
Website: www.oaic.gov.au
Employees may make requests directly to the Human Resources team for access to their Personal Information. Employees may also request the Human Resources team to correct their Personal Information if they consider the information we hold on them is not accurate, up-to-date, complete, or relevant or if they consider the information is misleading.
Within a reasonable time after we have corrected an employee’s Personal Information, we will advise any person, organisation or agency we provided the pre-corrected information to that the information has been corrected.
Employees also have the right to make a complaint if they consider we have not handled their Personal Information appropriately, including in accordance with this Policy or in accordance with the Australian Privacy Principles or the Privacy Act.
The following definitions are based on the definitions in the Privacy Act. If there is any inconsistency between any definition in this section and a corresponding definition in the Privacy Act, the latter definition will apply.
Our website contains very high levels of security in order to protect all personal information. These security levels are standard for internet sites and involve the use of 128-bit encryption. Encryption is the standard way of protecting your information as it is transmitted between you and us. This involves converting the information into an unreadable code using a ‘key’ (and also decoding it using this ‘key’). The longer the key, the more difficult it is for others to break the encrypted code.
It is necessary for Grunt to collect your IP address for your interaction with various parts of the Grunt website. Your IP address is the identifier for your computer when you are using the internet.
For instance, Grunt collects and stores your IP address when you log into the Client and Agent CRIAS website. As part of our security for Grunt, Grunt uses this information when we attempt to detect and prevent fraudulent transactions in CRIAS. We collect and store your IP address for security and audit purposes.
Your IP address will not otherwise be used by us or released to any third party except in the case of inappropriate behaviour or for monitoring and addressing actual or potential security and fraud issues, such as unauthorised access to our computer systems or fraudulent transactions.
A “cookie” is a small text file placed on your computer by our web page server. Cookies are frequently used on websites and you can choose if and how a cookie will be accepted by configuring your preferences and options in your browser. No personal information about you is collected during this process.
We use cookies to improve usability, remember preferences, detect abuse, assist with security monitoring and support account access. We may also use analytics and other technical information to understand how the website is used and to support service improvements.