Privacy Policy
Effective Date: 19/07/2026
Last Updated: 19/07/2026
Clear Vision Compliance (“Company”, “we”, “our”, or “us”) is committed to protecting the privacy, confidentiality, integrity, and security of information entrusted to us. This Privacy Policy explains how we collect, use, disclose, store, and protect personal information and confidential customer information through our cloud-based software platform (“Platform”).
By accessing or using the Platform, you acknowledge that you have read and understood this Privacy Policy.
1. Scope
This Privacy Policy applies to:
- Our cloud-based software platform.
- Our websites and customer portals.
- Customer support services.
- Any information collected during the provision of our services.
This Policy applies to customers, authorised users, contractors, partners, and website visitors.
2. Information We Collect
Depending on how our Platform is used, we may collect and process the following categories of information.
- Provide and improve our compliance services
- Respond to inquiries and support requests
- Communicate service updates and important notices
- Analyze website performance and user behavior
- Ensure regulatory and legal compliance
Personal Information
Examples include:
- Name
- Address
- Email address
- Telephone number
- Job title
- Organisation
- User account details
- Authentication credentials
- IP address
- Device identifiers
- Login history
3. Sensitive Information
Where required to provide our services, we may store:
- Medical records
- Clinical notes
- Health assessments
- Health identifiers
- Disability information
- Treatment records
- Medication records
- Mental health information
- Workers compensation information
- Insurance claim information
Where required to provide our services, we collect and process sensitive information, including health information, only where reasonably necessary and where we have consent, customer authorisation, or another lawful basis or permitted legal ground. Where required, collection notices will explain the information collected, the purposes of collection, consequences of not providing information, usual disclosures, overseas disclosure arrangements, and how individuals may access, correct, or complain about our handling of personal information. Sensitive information is stored securely and handled with enhanced security controls.
4. Commercially Sensitive Information
Customers may upload or create:
- Intellectual property
- Trade secrets
- Financial information
- Business strategies
- Pricing information
- Internal reports
- Contracts
- Tender documentation
- Product designs
- Source code
- Engineering documents
Ownership of this information remains with the customer.
5. Security-Sensitive Information
Customers may store:
- Security assessments
- Risk registers
- Incident reports
- Security architecture
- Vulnerability information
- Infrastructure documentation
- Physical security information
- Emergency management information
Ownership of this information remains with the customer.
6. Legally Sensitive Information
Customers may store:
- Legal advice
- Privileged communications
- Court documents
- Litigation files
- Employment investigations
- Regulatory investigations
- Compliance records
- Governance documentation
Ownership of this information remains with the customer.
7. Technical Information
We automatically collect:
- Browser type
- Operating system
- IP addresses
- Device information
- Error logs
- Usage statistics
- Security logs
- Audit logs
8. How We Collect Information
Information may be collected:
- Directly from customers
- From authorised users
- Through API integrations
- From connected systems
- Through website interactions
- Automatically through system logs
- Through customer support interactions
9. Purpose of Collection
We collect information only where reasonably necessary to:
- Deliver our software services
- Authenticate users
- Maintain audit records
- Provide customer support
- Improve system reliability
- Detect fraud
- Detect cyber threats
- Meet legal obligations
- Maintain business continuity
- Conduct backups and disaster recovery
We do not sell customer information.
Where the General Data Protection Regulation (GDPR) or UK GDPR applies, we process personal data only where a lawful basis applies. Depending on the processing activity, this may include performance of a contract, compliance with a legal obligation, legitimate interests, consent, vital interests, public task, or another lawful basis recognised by applicable law. For special category data, including health information, we rely on an additional lawful condition such as explicit consent, health or social care purposes, employment or social protection obligations, legal claims, substantial public interest, or another applicable condition.
10. Customer Data Ownership
Unless otherwise agreed in writing:
- Customers retain ownership of all data stored within the Platform.
- We act as a data processor or service provider on behalf of our customers where applicable
- We access customer data only when necessary to provide services, resolve technical issues, comply with legal obligations, or where authorised by the customer.
Depending on the services and applicable law, we may act as an independent privacy-regulated organisation, data controller, data processor, service provider, or business associate. Where we process customer data on behalf of a customer, we process it only in accordance with the customer’s documented instructions, our contract, and applicable law.
11. Customer Responsibilities and Limitations
Customer responsibilities
Customers are responsible for ensuring they have the rights, consents, notices, authorisations, and lawful bases needed to collect, upload, disclose, use, retain, and instruct us to process customer data through the Platform. Customers are also responsible for the accuracy, legality, classification, retention requirements, and appropriateness of the information they upload or submit.
Customer instructions
Where we process customer data on behalf of a customer, we follow the customer’s documented instructions, our agreement, and applicable law. Unless applicable law requires otherwise, we are not responsible for determining whether a customer’s instructions, configurations, disclosures, retention practices, or use of the Platform comply with laws that apply to the customer.
Customer content
Except as required to provide the services or comply with law, we do not control, verify, review, or assume responsibility for the content, completeness, legality, or accuracy of customer data uploaded to the Platform. Customers remain responsible for ensuring customer data is lawful, appropriate, current, and not misleading.
No professional advice
The Platform and related materials are provided for operational, recordkeeping, workflow, compliance support, and information management purposes only. Unless expressly agreed in writing, we do not provide legal, medical, clinical, insurance, cybersecurity, financial, or other professional advice.
Security limitations
We use reasonable administrative, technical, and organisational safeguards, but no method of transmission, storage, hosting, or electronic processing is completely secure. To the maximum extent permitted by law, we do not warrant that the Platform or information processed through it will be uninterrupted, error-free, immune from unauthorised access, or free from vulnerabilities.
Events outside our control
To the maximum extent permitted by law, we are not responsible for failure, delay, loss, unauthorised access, disclosure, corruption, or unavailability caused by events outside our reasonable control, including customer or user acts or omissions, third-party failures, internet or telecommunications failures, cyberattacks, malware, denial-of-service events, natural disasters, industrial action, government action, changes in law, or other force majeure events.
Third-party providers
The Platform may rely on third-party infrastructure, hosting, telecommunications, identity, security, payment, analytics, and support providers. To the maximum extent permitted by law, we are not responsible for their failures, acts, omissions, or security incidents except as expressly agreed in writing or required by applicable law.
Jurisdiction-specific obligations
Privacy, data protection, health information, cybersecurity, and confidentiality obligations vary by jurisdiction and may depend on the customer’s location, sector, use case, configuration, data types, and instructions. Customers are responsible for assessing whether the Platform meets their legal, regulatory, operational, and risk requirements.
Resolving concerns
Without limiting any non-excludable rights, individuals and customers are encouraged to contact us first so we can investigate and try to resolve concerns promptly. Nothing in this Policy limits any right to contact a regulator or supervisory authority.
No contractual warranty
This Privacy Policy explains our information handling practices. It does not create contractual warranties, guarantees, representations, or obligations beyond those required by law or expressly agreed in a written contract with us.
Non-excludable rights
Nothing in this Policy excludes, restricts, or modifies rights, remedies, guarantees, warranties, or obligations that cannot lawfully be excluded, restricted, or modified. Any exclusions or limitations apply only to the maximum extent permitted by law.
12. Security Measures
We implement reasonable administrative, technical, and physical safeguards designed to protect customer information against unauthorised access, disclosure, alteration, and destruction.
Security controls may include:
- Encryption in transit using current TLS standards.
- Encryption at rest using strong industry-standard encryption
- Multi-factor authentication.
- Role-based access controls
- Least privilege access principles.
- Audit logging.
- Security event monitoring.
- Vulnerability scanning.
- Regular penetration testing.
- Backup and disaster recovery procedures.
- Infrastructure redundancy.
- Secure software development practices.
- Employee confidentiality agreements.
- Security awareness training.
- Incident response procedures.
13. Data Residency
Customer data may be stored, processed, accessed, or supported from Australia or other countries, depending on customer configuration, hosting region, support arrangements, sub-processors, and legal requirements.
Before disclosing personal information overseas, we take reasonable steps to ensure appropriate safeguards are in place, including contractual protections, technical and organisational controls, due diligence, and transfer safeguards required by applicable law.
Where Australian Privacy Principle 8 applies, we take reasonable steps to ensure overseas recipients do not breach the Australian Privacy Principles in relation to the information unless an exception applies. Where the GDPR or UK GDPR applies, we use recognised transfer mechanisms such as adequacy decisions, standard contractual clauses, international data transfer agreements, transfer risk assessments, or other lawful safeguards. Where New Zealand privacy law applies, we ensure overseas disclosures meet Information Privacy Principle 12 or obtain informed authorisation where required. Customers may request information regarding available hosting locations.
14.Third-Party Service Providers
We may engage trusted third parties to provide services including:
- Cloud hosting
- Data storage
- Monitoring
- Email delivery
- Identity management
- Payment processing
- Customer support
- Security monitoring
- Analytics
We conduct risk-based due diligence before engaging providers that handle personal information or customer data and require them to maintain confidentiality, appropriate security controls, restricted processing purposes, breach notification obligations, deletion or return obligations, and onward-transfer controls. Where required, we enter into data processing agreements, business associate agreements, standard contractual clauses, international data transfer agreements, or equivalent contractual safeguards.
15. Medical Information
Where the Platform stores health information, we:
- Process health information only for authorised purposes.
- Restrict access to unauthorised personnel.
- Maintain audit logs.
- Protect information using enhanced security controls.
- Comply with applicable health privacy legislation where required.
- Support customer compliance obligations.
User organisations remain responsible for lawful collection, use, disclosure, and retention of sensitive information. Where HIPAA applies and we act as a business associate, we use and disclose protected health information only as permitted by the applicable business associate agreement and HIPAA, safeguard that information, report breaches as required and support the covered entity’s compliance obligations.
16. Confidential and Privileged Information
We recognise that customers may store:
- Legal professional privilege material
- Commercially confidential information
- Government-sensitive information
- Security-classified documentation (where permitted)
- Intellectual property
We treat such information as confidential and implement controls designed to prevent unauthorised disclosure.
17. Retention of Information
We retain information only for as long as reasonably necessary for the purposes described in this Policy, including:
- For the duration reasonably necessary to provide the Platform and support services.
- In accordance with contractual obligations and customer instructions.
- To meet legal, regulatory, accounting, audit, security, and dispute-resolution requirements.
- To maintain business continuity, backups, logs, and disaster recovery capability.
- Until securely deleted, returned, exported, or de-identified where legally permissible.
Backups and logs may remain in secure backup systems for limited periods until overwritten or deleted in accordance with our backup and disaster recovery procedures, unless earlier deletion is technically feasible and legally permissible.
18. Data Deletion
Upon termination of services or written request, and subject to applicable law and contract terms, we will make customer data available for export, return, deletion, or de-identification, unless retention is required or permitted for:
- Legal, regulatory, accounting, audit, or security obligations.
- Contractual retention requirements.
- Active disputes, investigations, or enforcement matters.
- Backup, log, and disaster recovery retention schedules.
- Technical limitations that make immediate deletion impracticable.
Data is securely deleted, returned, exported, or de-identified using recognised industry practices where applicable.
19. Your Rights
Subject to applicable law, individuals may have the following rights:
- Access personal information.
- Correct inaccurate or incomplete information.
- Request deletion or erasure where available.
- Restrict or object to processing where available.
- Request data portability where available.
- Withdraw consent where processing relies on consent.
- Receive information about automated decision-making where required by law.
- Lodge complaints with us or with applicable privacy regulators.
Some rights depend on the applicable law, the individual’s location, our role, and whether we process the information for ourselves or on behalf of a customer. Where we process information on behalf of a customer, we may refer the request to that customer or assist the customer to respond. We will respond to verified requests within the timeframes required by applicable law. Requests should be submitted using the contact details below.
20. Cookies and Analytics
Our websites may use:
- Essential cookies
- Security cookies
- Session cookies
- Performance analytics
Users may disable or control cookies through browser settings, although disabling certain cookies may affect Platform functionality.
21. Automation and Artificial Intelligence
We may use analytics, automation, artificial intelligence, rules-based workflows, or similar technologies to operate, secure, monitor, improve, or support the Platform. Where these technologies make or assist decisions with legal, significant, or similarly important effects, we will provide information required by applicable law, including processing purposes, information categories used, expected consequences, and available review or objection rights. We do not use sensitive information for automated decision-making unless permitted by law, authorised by the customer, and subject to appropriate safeguards.
22. Incident Response
If we become aware of an actual or suspected security incident involving personal information, health information, protected health information, or customer data, we will investigate, contain, assess, and remediate the incident. Where required by law or contract, we will notify affected customers, individuals, regulators, supervisory authorities, covered entities, or other relevant parties within applicable timeframes and support customer notification obligations where we process data on behalf of customers.
23. Children's Information
Our Platform is not intended for use by children unless authorised by a healthcare provider, educational institution, parent, guardian, or another person or organisation with legal authority to authorise that use.
24. Compliance
We are committed to complying with privacy and data protection laws that apply to our activities, customers, users, and processing locations. Depending on the circumstances, these may include the Privacy Act 1988 (Cth), Australian Privacy Principles, Notifiable Data Breaches scheme, applicable State and Territory health records laws, GDPR, UK GDPR, Data Protection Act 2018 (UK), New Zealand Privacy Act 2020, HIPAA where we act as a business associate, and other applicable privacy, confidentiality, cybersecurity, consumer protection, and data protection laws.
- Open and transparent management of personal information.
- Collection, use, disclosure, quality, security, access, and correction of personal information.
- Appropriate handling of sensitive information and health information.
- Cross-border disclosure and international transfer safeguards.
- Data breach assessment, notification, and incident response obligations.
- Processor, service provider, subprocessor, and business associate obligations where applicable.
- Recognised information security principles, including ISO/IEC 27001 and SOC 2 security principles where applicable.
Where laws impose different requirements, we apply the requirement that is most protective or otherwise legally required for the relevant processing activity. Compliance with any specific regulation depends on the services provided, contractual commitments, customer implementation, and the jurisdictions in which information is collected, accessed, stored, or used.
25. Changes to This Policy
We may update this Privacy Policy from time to time for legal, regulatory, operational, security, technical, or business reasons.
Changes will be posted on this page with a revised “Last Updated” date.
Continued use of the Services after the effective date of an updated Privacy Policy may be treated as acceptance of the revised Policy where permitted by law and contract. If you do not agree to a material change, you may stop using the Services or cancel your account, subject to rights or obligations that have already accrued.
26. Contact Us
If you have any questions about this Privacy Policy or our privacy practices, contact us at:
If you believe your privacy has been breached, you may also contact the relevant privacy regulator in your jurisdiction.
27. Commitment
Protecting customer information is fundamental to our business. We are committed to maintaining strong privacy, confidentiality, and information security practices that reflect recognised industry standards and support the trust placed in us by our customers.
