01About this policy
This policy explains how OMBR Systems Pty Ltd (OMBR, we, us) collects, holds, uses, discloses and protects personal information. It applies to this website at ombr.com.au, to the OMBR product, and to the dealings we have with customers, prospective customers, suppliers and anyone who contacts us.
We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) in that Act. Where we send commercial electronic messages, we also comply with the Spam Act 2003 (Cth).
“Personal information” means information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether or not it is true and whether or not it is recorded in a material form.
02The two kinds of information we handle
OMBR is business software sold to traffic control contractors. That means personal information reaches us in two very different ways, and the distinction matters for your rights and our obligations.
Information we hold about you directly
This is information about our own customers, the people at those customers who use or buy the software, and people who contact us through this website. We decide what to do with this information, and this policy governs it in full.
Information our customers put into OMBR
A traffic control contractor using OMBR enters information about their own employees, crews, clients and suppliers. We hold that information on their behalf, as their service provider. The customer decides what goes in, who may see it, and how long it stays. We do not use it for our own purposes.
If you are a traffic controller, supervisor or office worker whose employer uses OMBR, and you want to see or correct the information held about you, please contact your employer first. They control that information. We will help them respond, and we will refer any request that comes to us directly on to them.
03Information we collect about you
Depending on your dealings with us, we may collect:
- Contact and identity details — name, business email address, telephone number, job title, and the company you work for.
- Account information — the account you create in OMBR, including your username, the role assigned to you within your organisation’s account, and authentication data. Passwords are stored as cryptographic hashes and are not readable by us.
- Enquiry and support information — the content of enquiries, demo requests and support requests, and our correspondence with you about them.
- Billing information — the business name, address, ABN, plan and billing contact for a subscription, and a record of invoices and payments. Card details are handled by our payment provider and are not stored on our systems.
- Usage and technical information — records of activity within the product such as sign-ins, actions taken and records changed, together with IP address, device and browser information. We use this to run, secure and support the service.
We collect this information directly from you wherever we can — when you fill in a form, sign up, email us, or use the product. Sometimes we collect it from someone else at your organisation, for example when an administrator creates an account for you. If we collect information about you from a third party, we take reasonable steps to make sure you are aware of it.
You do not have to identify yourself when you make a general enquiry, but we usually cannot answer a question about an account, or provide a demonstration, without knowing who you are and which company you are from.
04Information our customers store in OMBR
Customers use OMBR to run their operations, and the records they create can contain personal information about their people and their clients’ people. Depending on how a customer uses the product, that can include:
- Employee and contractor records: name, contact details, employment details and pay-related information.
- Tickets, licences and competencies held by field personnel, including expiry dates.
- Rosters, shift allocations, hours worked, timesheets and pay run data.
- Dockets, including the name and signature of the client representative who signed them.
- Photographs and notes taken on site by crews.
- Contact details for the customer’s own clients and suppliers.
We handle that information only to provide, support, secure and maintain the service for the customer, and as their agreement with us requires. We do not sell it, we do not use it to market to the individuals in it, and we do not disclose it to anyone except as set out in this policy or as the customer directs.
Each customer works in a separate tenant, and access is controlled by the roles and permissions that customer sets. Our staff access customer data only where it is necessary to provide support, resolve a fault, or meet a legal obligation.
05This website
This marketing website does not set cookies, does not use third-party analytics or advertising trackers, and does not attempt to identify you as you browse it. In the interests of being complete about it:
- Hosting. The site is served by a content delivery network, which records standard request logs including IP address, request time, the page requested and browser user agent. These are used for delivery, security and abuse prevention.
- Web fonts. Typefaces are loaded from Google Fonts. Your browser therefore makes a request to Google’s servers, which will see your IP address. Google states that it does not use Google Fonts requests to build advertising profiles.
- Forms. If you send us a message through the contact form, we receive what you typed and use it to answer you.
The OMBR product itself is a separate application and does use cookies, which are necessary to keep you signed in and to keep your session secure.
06How we use personal information
We use personal information to:
- provide, operate, support and improve the OMBR product;
- create and administer accounts, and authenticate the people using them;
- answer enquiries, provide demonstrations and quote for subscriptions;
- invoice customers and collect payment;
- send service messages about the product, including notifications generated by the software;
- secure the service, investigate suspected misuse, and keep audit records;
- meet our legal, accounting and record-keeping obligations; and
- where you have not opted out, tell existing customers about changes and features relevant to their use of OMBR.
We do not sell personal information. We do not disclose personal information to third parties for their own marketing purposes.
07Email and messages we send
OMBR sends two kinds of email, and we treat them differently.
Service messages
These are generated by the product because someone asked for them or because an account requires them: sign-in and password reset emails, account and billing notices, invoices and statements, purchase orders, quotes and dockets sent to a client or supplier, shift notifications, and support correspondence. They are sent to the address held for the recipient in the account, they relate to a transaction or relationship that already exists, and they are not promotional. Customers cannot opt out of the messages needed to run their account, though most notification types can be turned off within the product.
Commercial messages
Any marketing message we send complies with the Spam Act 2003 (Cth). We send it only where we have consent or the recipient’s consent can reasonably be inferred from an existing business relationship, we identify ourselves clearly and include our contact details, and every message contains a working unsubscribe facility. Unsubscribe requests are actioned promptly and in any case within five business days.
We do not buy, rent or scrape email lists, and we do not send bulk email to people who have no relationship with us. If you believe you have received a message from us that you should not have, email privacy@ombr.com.au and we will remove you and look into how it happened.
08When we disclose personal information
We disclose personal information only in these circumstances:
- To service providers who help us run the business, under contracts that require them to protect the information and use it only for the services they provide to us. These fall into a small number of categories: cloud hosting and infrastructure, email delivery, error monitoring and logging, payment processing, and accounting.
- At a customer’s direction, where they ask us to send information to a party they nominate, or connect their account to another system.
- To professional advisers such as our lawyers and accountants, where needed.
- Where required or authorised by law, including in response to a subpoena, court order, or a lawful request from a government agency or regulator.
- To protect people or property, where we reasonably believe disclosure is necessary to prevent a serious threat to life, health or safety, or to investigate serious misconduct.
- In a business transfer, if the business or a part of it is sold or restructured, in which case the recipient would be bound to handle the information consistently with this policy.
09Overseas disclosure
We are an Australian business serving Australian customers, and we prefer providers that can store data in Australia. Some of the service providers we rely on — particularly for cloud infrastructure, email delivery and error monitoring — are global businesses that may store or process information outside Australia, most commonly in the United States.
Before disclosing personal information to an overseas recipient we take reasonable steps, as APP 8 requires, to ensure the recipient does not breach the Australian Privacy Principles, including through contractual commitments about how the information is handled and secured.
If you need to know the specific locations where your organisation’s data is stored, or you have a contractual requirement that it remain onshore, email privacy@ombr.com.au and we will tell you exactly where it sits.
10How we protect information
We take reasonable steps to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure. Those steps include:
- encryption of data in transit over public networks using TLS;
- encryption of data at rest on the infrastructure we use;
- separation of each customer’s data into its own tenant;
- role-based access control within the product, administered by each customer;
- restricting staff access to customer data to those who need it, for the purpose they need it;
- audit logging of significant actions;
- regular backups, and testing that they restore; and
- keeping software and dependencies patched.
No system is perfectly secure, and we do not claim otherwise. If you become aware of a security problem with OMBR, please report it to privacy@ombr.com.au. We will acknowledge a report of that kind promptly and we will not pursue anyone who reports a genuine issue to us in good faith.
11How long we keep information
We keep personal information only as long as we need it for the purposes set out in this policy, or as long as the law requires us to. In practice:
- Customer data is kept for as long as the customer’s subscription is active. After an account is closed we retain it for a limited period so the customer can export it or reactivate, then delete it. The period and the export arrangements are set out in our terms of service.
- Billing and tax records are kept for at least seven years, as Australian tax law requires.
- Enquiry and support correspondence is kept while it is useful for supporting you and then destroyed or de-identified.
12Access and correction
You may ask us for access to the personal information we hold about you, and ask us to correct it if it is wrong, out of date, incomplete or misleading. Email privacy@ombr.com.au with enough detail for us to identify you and find the information.
We will respond within 30 days. There is no charge for making a request; if a request takes substantial work we may charge a reasonable cost-based fee for giving access, and we will tell you what it is before we do the work. If we refuse access or refuse to make a correction, we will tell you in writing why, and how to complain about that decision.
If your request concerns information your employer holds in OMBR about you, we will refer you to your employer, who controls that information. See section 02.
13Data breaches
We maintain a data breach response plan. If we suspect a data breach we contain it, assess what happened and who is affected, and remediate it.
Where a breach is likely to result in serious harm to an individual, the Notifiable Data Breaches scheme under Part IIIC of the Privacy Act 1988 (Cth) applies. We will notify the affected individuals and the Office of the Australian Information Commissioner as soon as practicable, telling them what happened, what information was involved and what they should do. Where the breach involves data belonging to a customer, we will notify that customer promptly so they can meet their own obligations.
14Making a complaint
If you think we have breached the Australian Privacy Principles or mishandled your personal information, tell us first. Email privacy@ombr.com.au and set out what happened. We will acknowledge your complaint within five business days and give you a written response within 30 days.
If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner:
Office of the Australian Information CommissionerGPO Box 5218, Sydney NSW 2001Telephone 1300 363 992www.oaic.gov.au15Changes to this policy
We may update this policy as the product, the law or our providers change. The current version is always on this page, with the date it took effect at the top. If we make a change that materially affects how we handle personal information, we will tell affected customers directly before it takes effect.
16Contact us
Privacy questions, access requests and complaints go to our privacy contact:
Privacy Officer, OMBR Systems Pty LtdABN 80 604 252 824privacy@ombr.com.auFor anything else, see the contact page.