1) Introduction

  1. In this Policy, CSM, we, our or us is a reference to CSM Sec Pty Ltd (ACN 618 009 680).
  2. Personal information is any information about you where your identity is apparent, or can reasonably be ascertained, and may include Sensitive Information (defined below).
  3. Sensitive Information is information or an opinion about a person’s racial or ethnic origin, political opinions, membership of a political association, religious beliefs or affiliations, philosophical beliefs, sexual preferences, health or medical information or criminal

2)What this Policy is about?

  1. This Policy explains the key measures we have taken to implement the requirements of the Privacy Act 1988 (Privacy Act), the Australian Privacy Principles and where applicable, other data protection laws. This Privacy Policy outlines the Personal Information collection practices utilised by CSM, how that information is collected, used and disclosed and your rights in relation to your Personal Information.
  2. This Policy covers Personal Information collected directly collected directly on our website (www.csmsec.com.au) (Website) and via email or telephone from individuals who access, register for, or use our training and support services, or purchase goods and services offered on our Website (Goods and Services).
  3. We endorse fair information handling practices and uses of information in compliance with our obligations under the privacy laws in force in Australia from time to time. Any information provided, including identification of individuals, will be used only for the purpose(s) intended and where the intention includes confidentiality, information will be treated as such unless otherwise required by law.
  4. This Policy represents the default position that CSM will take in its treatment of Personal Information. CSM will treat all Personal Information in a manner consistent with this Policy unless you have provided your express consent otherwise.
  5. If there is any inconsistency between the Privacy Act and this Policy, this Policy shall be read and interpreted to comply with the Privacy Act.

3)Collection of Personal Information

  1. CSM collects the following Personal Information:
    1. Personal Information about you, which you provide to us as a user or purchaser, or prospective user or purchaser of the Goods and Services which may include your:
      • name;
      • phone number;
      • address; and
      • email
    2. Personal Information about our employees, contractors and job applicants, including name, address, contact details and work experience.
    3. Personal Information will be typically collected when provided directly to CSM by you:
      1. when you contact us through an online form on the Website or by email;
      2. when you purchase Goods and Services on the Website;
      3. during phone calls or other communications between you and us; and
      4. when you contact or communicate with us by any other
      5. Our Website automatically collects anonymous usage data about visitors, including the URL that the visitor came from, the browser being used and the IP This data is utilised to improve the services of CSM and does not include any personally identifying information.
      6. CSM also reserves the right to collect anonymous usage data through other websites and online systems in order to provide our users with a better user This data does not include any personally identifying information.
      7. ‘Cookies’ are alphanumeric identifiers that are stored by the web browser on a computer’s hard-drive that enable our system to recognise a visitor to our This helps CSM to track basic visitor information for the purposes of optimising the design of our systems and marketing activities.
      8. Most web browsers automatically accept cookies and this function can be disabled by changing the browser settings of the user.
      9. Please note that the Website contains links to other websites which are not hosted or operated by CSM is not responsible for the privacy policies of such other websites, and you should independently review the privacy policies on such websites. 

4) Use of Personal Information

  1. CSM uses Personal Information in the following ways:
    1. to assist us in providing the Goods and Services;
    2. for our own internal administration purposes; and
    3. for sending newsletters and other marketing materials to subscribers;
  1. We may also use Personal Information we collect for related purposes such as:
    1. to record information about your usage, preferences and behaviour in relation to the Services, as well as any feedback provided by you;
    2. when combined with the deidentified Personal Information of other users (in which case such combined information will no longer be personal) to analyse and develop products and services that suit our users;
    3. to perform statistical analyses of user behaviour;
    4. to optimise marketing activities, user experience, and content; and
    5. any other use for which we obtain permission from
    6. We do not pass on any Personal Information to a third party except in accordance with this Policy.

5) Newsletters

  1. As a purchaser of the Goods and Services and/or user of the Website, you may receive email, newsletter or other updates from us about new information, goods or services being offered by CSM, or any of its related companies or business partners, along with any noteworthy changes to the Website. You may always unsubscribe and opt out from receiving these promotional/marketing update messages.

6) External System Providers

  1. We use external system providers to assist us in providing the Goods and Services, including Mailchimp (https://mailchimp.com/) for email communication and marketing services (External System Providers).
  2. All data collected, disclosed and stored by an External System Provider is governed by the relevant External System Provider’s privacy policy, the Privacy Act and any other relevant
  3. Although CSM attempts to ensure that External System Providers have extensive data protection policies and protect Personal Information to at least the degree set out in this Policy, CSM is not responsible for the data protection policies of any External System Provider or any losses, expenses, damages and costs, including legal fees, resulting from such policies.

7) Disclosure of Personal Information

  1. Other than disclosure to service providers (explained below) or as required by law, our policy is that we do not give Personal Information to other organisations unless we have disclosed the use in this Policy or you have expressly consented for us to do so.
  2. We may share Personal Information with nominated employees, service providers (for example our IT service providers) and External System Providers on a need to know basis to allow the provision of the Goods and Services to you as requested by Access to Personal Information by these parties is subject to such parties protecting your Personal Information to at least the degree set out in this Policy, and such access will be revoked within a reasonable timeframe of access no longer being required. To the extent that these organisations and service providers gain access to Personal Information, their use is governed by their own privacy policies, the Privacy Act and any other relevant law.
  3. Occasionally, CSM might also use Personal Information for other purposes or share Personal Information with another organisation because:
    1. we believe it is necessary to protect your rights, property or personal safety;
    2. we believe it is necessary to do so to prevent or help detect fraud or serious credit infringements – for example, we may share information with credit reporting agencies, law enforcement agencies and fraud prevention units; or
    3. we believe it is necessary to protect the interests of CSM – for example, disclosure to a Court in the event of legal action to which CSM is a party.
  4. In the event that the CSM is sold, its data, including your Personal Information may be transferred to the purchasing entity which would be bound to comply with the Privacy Act in relation to the access, storage and use of your Personal Information. Further, in circumstances where CSM is merged with another entity, the data, including your Personal Information, may be transferred to that entity, which would be bound to comply with the Privacy Act in relation to the access, storage and use of your Personal Information. Your Personal Information would not be disclosed to a buyer in either circumstance, other than as a part of the transfer of all data related to CSM to that buyer.

8)Confidentiality and Data Security

  1. All Personal Information collected is stored on secure cloud servers hosted by Ventra IP in
  2. We take all reasonable steps to manage data stored by us to ensure data security and to prevent the loss, misuse or alteration of Personal Information including requiring users to log in to the Website to access the Goods and Services and incorporating current anti-virus software and data protection mechanisms in our IT software. Notwithstanding the above, CSM is not responsible for any third-party access to Personal Information as a result of:
    1. interception while it is in transit over the internet;
    2. spyware or viruses on the device (such as a computer or phone) from which you access our Website or otherwise contact us; or
    3. as a result of your failure to adequately protect your username or password (if applicable).
  3. CSM is also not responsible for any losses, expenses, damages and costs, including legal fees, resulting from such third-party access.
  4. If we have reasonable grounds to believe that your Personal Information that we hold may be subject to unauthorised access or disclosure (eligible data breach), we will investigate and assess the suspected eligible data breach to determine whether the eligible data breach is likely to result in serious harm to you (Notifiable Data Breach). If a Notifiable Data Breach occurs, then we will notify you and the Australian Information Commissioner as soon as practicable after we become aware of the Notifiable Data Breach in accordance with our

obligations under the Privacy Act. We will comply in every way with our obligations under Part IIIC – “notification of eligible data breaches” of the Privacy Act.

9) Retention and Disposal of Personal Information

  1. We will retain Personal Information for as long as is required for us to fulfil the purposes for which the Personal Information was collected, including where applicable to provide the Goods and Services and to comply with legal requirements.
  2. If we no longer require Personal Information for any purpose, including legal purposes, we will take reasonable steps to securely destroy or permanently de-identify the Personal Information, which will occur on a bi-annual basis.

10)Access to Personal Information

  1. You can seek to access the Personal Information held about you at any time by contacting our Privacy Officer.
  2. We will always endeavour to meet requests for However, in some circumstances we may decline a request for access. This includes the following circumstances:
    1. we no longer hold or use the information;
    2. providing access would have an unreasonable impact on the privacy of other persons;
    3. the request is frivolous or vexatious;
    4. the information relates to existing or anticipated legal proceedings and would not normally be disclosed as part of those proceedings;
    5. providing access would be unlawful;
    6. providing access would be likely to prejudice the detection, prevention, investigation and prosecution of possible unlawful activity; or
    7. the information would reveal CSM’s commercially sensitive
  3. If we decline a request for access, we will provide reasons for our decision when we respond to the request.
  4. We reserve the right to charge you a reasonable fee for access to your Personal These charges will be limited to the cost of recouping our expenses for providing you with your Personal Information, such as document retrieval, photocopying, labour and delivery.
  5. Despite anything contained in this Policy to the contrary, if the Freedom of Information Act 1982 applies to a person on whose behalf we hold Personal Information, the access and correction requirements in the Privacy Act operate alongside and do not replace other informal or legal procedures by which an individual can be provided access to, or correction of, their Personal Information.

11)Changing or deleting Personal Information

  1. We will take reasonable steps to ensure that Personal Information is accurate, complete and up-to-date at the time of collecting the Personal Information from you, using or disclosing the Personal Information, or during other interactions with you or suppliers in accordance with this Policy.
  2. If you believe that any Personal Information that we hold about you is inaccurate, incomplete or out-of-date, you may contact our Privacy Officer.
  3. We will do our best to correct any Personal Information that is inaccurate, incomplete or out-of-date or dispose of it in accordance with this Policy.

12)Contact Information and Changes to Privacy Policy

  1. If you have any further queries relating to CSM’s Privacy Policy, please contact our Privacy Officer. If CSM becomes aware of any ongoing concerns or problems with your Personal Information, we will take these issues seriously and work to address these concerns.
  2. If you have a complaint in relation to the way your Personal Information has been handled by CSM, the complaint should be made in writing to our Privacy Officer in the first
  3. CSM will investigate the complaint and prepare a response to you in writing within a reasonable period of time.
    1. Our Privacy Officer can be contacted by: Email: privacy@csmsec.com.au
    2. From time to time, our policies will be reviewed, and may be CSM reserves the right to change this Policy at any time.

This Privacy Policy was last updated August 2022.