Protecting Your Privacy and Personal Information

Noonan Real Estate Agents is committed to protecting the privacy, confidentiality and security of the personal information entrusted to us.

This Privacy Policy explains how we collect, use, disclose, store and protect personal information when providing our real estate services and conducting our business. It also outlines your privacy rights and our commitment to complying with the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs) and other applicable Australian privacy laws.

Whether you are a vendor, purchaser, landlord, tenant, applicant, contractor or visitor to our website, we are committed to handling your personal information responsibly, transparently and securely.

SECTION 1

Introduction, Commitment, Scope & Definitions

1. Our Commitment to Privacy

At Noonan Real Estate Agents Pty Ltd ("Noonan", "we", "our" or "us"), we recognise that protecting the privacy and personal information of our clients, landlords, tenants, vendors, purchasers, employees, contractors and business partners is fundamental to the way we conduct business.

We are committed to handling personal information lawfully, fairly, transparently and securely. We recognise that individuals entrust us with their personal information when buying, selling, leasing, renting or managing property, and we treat that responsibility seriously.

We continually review our systems, procedures and technologies to ensure our privacy practices remain consistent with Australian privacy laws, industry best practice and our commitment to providing professional real estate services.

2. About Noonan Real Estate Agents

Noonan Real Estate Agents Pty Ltd is a licensed real estate agency providing professional services including, but not limited to:

Residential property sales

Commercial sales and leasing

Residential property management

Commercial property management

Property leasing

Auctions

Property appraisals

Buyer enquiries

Landlord services

Tenant services

Maintenance coordination

Trust account administration

Anti-Money Laundering and Counter-Terrorism Financing (AML/CTF) compliance

Recruitment and employment activities

General business administration

To deliver these services, we collect, hold, use and disclose personal information in accordance with this Privacy Policy.

3. Legislative Framework

This Privacy Policy has been developed in accordance with:

Privacy Act 1988 (Cth)

Australian Privacy Principles (APPs)

Notifiable Data Breaches Scheme

Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)

AML/CTF Rules

Spam Act 2003 (Cth)

Do Not Call Register Act 2006 (Cth)

Electronic Transactions Act 1999 (Cth)

Any other applicable Commonwealth or State legislation relating to privacy, real estate services or information management.

Where legislation changes, we will review and update this Privacy Policy as required.

4. Scope of this Policy

This Privacy Policy explains how we collect, use, disclose, store, protect and otherwise manage personal information.

It applies to personal information collected through:

our offices

our website

online enquiry forms

rental applications

sales enquiries

open homes

auctions

inspections

telephone conversations

emails

SMS messages

social media platforms

electronic identity verification services

customer relationship management systems (CRM)

third-party referral sources

publicly available information

government agencies

business partners

any other lawful means.

This Privacy Policy applies to all individuals whose personal information we collect, regardless of whether they ultimately become a client.

5. Who this Policy Applies To

This Privacy Policy applies to:

Vendors

Purchasers

Landlords

Tenants

Rental Applicants

Auction Bidders

Prospective Buyers

Prospective Tenants

Guarantors

Occupants

Company Directors

Trustees

Beneficial Owners

Attorneys

Authorised Representatives

Contractors

Tradespeople

Suppliers

Consultants

Strata Managers

Body Corporate Representatives

Mortgage Brokers

Conveyancers

Solicitors

Valuers

Building Inspectors

Insurance Providers

Job Applicants

Employees (except where the employee records exemption applies)

Visitors to our offices

Visitors to our website

Users of our online services

Any individual who communicates with us.

6. Our Privacy Principles

Noonan is committed to:

collecting only the personal information reasonably necessary to conduct our business and comply with our legal obligations;

being transparent about how personal information is handled;

collecting personal information by lawful and fair means;

using personal information only for legitimate business or legal purposes;

maintaining accurate, complete and up-to-date information where reasonably practicable;

protecting personal information against misuse, interference, loss, unauthorised access, modification and disclosure;

providing individuals with access to their personal information where required by law;

correcting inaccurate or outdated personal information when requested;

securely destroying or de-identifying personal information when it is no longer required and legal retention obligations have expired; and

continually reviewing and improving our privacy practices.

7. Definitions

For the purposes of this Privacy Policy:

Australian Privacy Principles (APPs) means the Australian Privacy Principles contained in Schedule 1 of the Privacy Act 1988 (Cth).

Personal Information means information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether true or not and whether recorded in material form or not.

Sensitive Information includes information such as health information, racial or ethnic origin, religious beliefs, political opinions, trade union membership, sexual orientation, criminal history, biometric information and any other information defined as sensitive information under the Privacy Act.

Processing includes collecting, recording, storing, organising, accessing, using, analysing, verifying, disclosing, transmitting, retaining, archiving, de-identifying and destroying personal information.

Disclosure means making personal information available to another person or organisation outside Noonan Real Estate Agents.

Identity Verification means any process undertaken to verify an individual’s identity, including electronic identity verification, document verification and AML/CTF customer due diligence.

AML/CTF means Anti-Money Laundering and Counter-Terrorism Financing obligations under Australian legislation.

Privacy Officer means the person appointed by Noonan Real Estate Agents to oversee privacy compliance, respond to privacy enquiries and manage privacy complaints.

Business Day means a day other than a Saturday, Sunday or public holiday in New South Wales.

8. Changes to this Privacy Policy

We may amend this Privacy Policy from time to time to reflect changes in legislation, regulatory guidance, technology, our business practices or the services we provide.

The most current version of this Privacy Policy will always be available on our website.

Where significant changes are made, we will take reasonable steps to notify individuals where appropriate.

9. What Personal Information We Collect

The type of personal information we collect depends on the nature of your relationship with us, the services you request, and our legal and regulatory obligations.

We only collect personal information that is reasonably necessary for our business activities, to provide our services, comply with our legal obligations, protect our legitimate business interests, or where you have otherwise consented.

The information we collect may include the categories described below.

Vendors and Property Owners

If you engage us to sell, lease or manage your property, we may collect:

Full name

Residential address

Postal address

Telephone numbers

Email address

Date of birth (where required)

Identification documents

Driver licence

Passport

Medicare card (where permitted)

Proof of ownership

Property ownership details

Property history

Mortgage information where relevant

Banking details for payment of sale proceeds or rental income

Taxation information where required

Trust details

Company information

Beneficial ownership information

Emergency contact details

Correspondence with us

Instructions provided to us

Records of meetings and telephone conversations

Electronic communications

Digital signatures

Audio or video recordings where permitted by law

Purchasers and Prospective Purchasers

We may collect:

Name

Address

Telephone number

Email address

Buyer preferences

Inspection history

Property enquiries

Auction registrations

Identification documents

Proof of identity

Financial capacity information voluntarily provided

Deposit payment details

Contract information

Communication history

Property search preferences

Feedback regarding inspections

Marketing preferences

Where required by law, additional information may be collected to satisfy our AML/CTF obligations.

Landlords

Where we provide property management services we may collect:

Name

Residential address

Contact details

Identification documents

Banking information

Taxation information

Ownership documentation

Trust account payment instructions

Insurance details

Property information

Emergency contact details

Maintenance instructions

Authority to incur expenditure

Correspondence

Communication history

Complaint history

Records of inspections

Photographs relating to the property

Tenants and Prospective Tenants

For tenancy applications and property management purposes we may collect:

Name

Residential history

Employment information

Employer details

Income information

Identification documents

Driver licence

Passport

Visa information where applicable

Date of birth

Contact details

Rental history

Previous agent references

Landlord references

Personal references

Emergency contacts

Vehicle registration details

Pet information

Utility information where relevant

Maintenance requests

Inspection reports

Routine inspection photographs

Communications with our office

Rent payment history

Trust account transactions

Tribunal or court information where relevant

Insurance claims relating to the tenancy

Guarantors

Where a guarantor is required we may collect:

Name

Address

Contact details

Identification documents

Relationship to the applicant

Financial information reasonably necessary to assess the guarantee

Signature

Communication records

Contractors, Tradespeople and Suppliers

We may collect:

Business name

Contact details

ABN

Company details

Trade licence information

Qualifications

Insurance certificates

Banking details

Payment information

Tax invoices

Service history

Work orders

Compliance documentation

Safety certifications

Communication records

Job Applicants

If you apply for employment with Noonan, we may collect:

Name

Address

Telephone numbers

Email address

Resume

Qualifications

Employment history

Professional memberships

Licences

References

Interview notes

Right to work documentation

Police checks where required

Working with Children Checks where applicable

Background verification information where permitted by law

Superannuation details (if employed)

Banking details (if employed)

Information collected during recruitment will only be used for employment-related purposes unless otherwise permitted by law.

Employees

For employees, we collect personal information necessary to administer the employment relationship.

The handling of employee records is generally exempt from the Australian Privacy Principles where the employee records exemption under the Privacy Act applies.

Website Visitors

When you visit our website we may automatically collect information including:

IP address

Browser type

Device type

Operating system

Pages visited

Date and time of access

Time spent on our website

Referral website

Search terms

Cookies

Analytics data

Website preferences

Geographic location (approximate)

Device identifiers

Website performance information

This information helps us improve our website, analyse usage trends, maintain security and enhance the user experience.

Social Media

Where you interact with us through social media platforms such as Facebook, Instagram, LinkedIn or other platforms, we may collect information that you make publicly available or provide directly to us, including:

Name

Username

Profile information

Messages

Comments

Reviews

Photographs

Videos

Enquiries

Marketing preferences

Your use of social media platforms is also governed by the privacy policies of those platforms.

CCTV and Office Visitors

Where CCTV is installed at our offices, we may collect:

Video footage

Date and time of entry

Images of visitors

Vehicle details where visible

CCTV is used for the safety and security of our staff, visitors, contractors and property, and for the prevention and investigation of unlawful activity.

Sensitive Information

Sensitive information is afforded additional protection under Australian privacy law.

We will only collect sensitive information where:

you have given your consent;

the information is reasonably necessary for our functions or activities;

collection is required or authorised by law; or

another exception under the Privacy Act applies.

Sensitive information may include:

health information;

biometric information used for identity verification (where applicable);

criminal history information where required by law;

information relating to legal proceedings where necessary to provide our services; and

any other information classified as sensitive under the Privacy Act.

We do not seek to collect sensitive information unless it is genuinely necessary.

Information Required by Law

Certain laws require us to collect and verify personal information before providing particular services.

This includes information collected to comply with:

the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth);

taxation laws;

trust accounting requirements;

real estate licensing legislation;

court or tribunal orders;

lawful requests from government authorities; and

any other applicable legislation.

Where you choose not to provide information that we are legally required to collect, we may be unable to provide our services or continue acting on your behalf.

Our Commitment to Data Minimisation

We are committed to the principle of data minimisation. This means we only collect personal information that is reasonably necessary for our business functions, legal obligations, or the services you have requested. We do not intentionally collect excessive or irrelevant personal information.

From time to time, we review the categories of personal information we collect to ensure they remain appropriate, relevant and consistent with our legal obligations and operational requirements.

10. How We Collect Personal Information

We collect personal information by lawful, fair and transparent means and only where it is reasonably necessary for our business activities or required by law.

Where it is reasonable and practicable to do so, we collect personal information directly from you. In some circumstances, we may collect personal information from authorised third parties or publicly available sources where permitted by law.

The way we collect your personal information depends on the nature of your relationship with us and the services we provide.

Information You Provide Directly

We may collect personal information directly from you when you:

enquire about buying, selling, leasing or renting a property;

request a market appraisal;

engage us to sell, lease or manage a property;

submit a rental application;

register to attend an open home or auction;

register as an auction bidder;

complete property enquiry forms;

subscribe to property alerts or newsletters;

contact us by telephone, email, SMS or social media;

attend one of our offices;

provide instructions to us;

submit maintenance requests;

make complaints or provide feedback;

apply for employment;

participate in surveys or promotional activities; or

otherwise communicate with us.

Property Management Services

As part of our property management services, we collect personal information throughout the tenancy lifecycle, including when:

tenancy applications are submitted;

lease agreements are entered into;

rent payments are administered;

maintenance requests are lodged;

inspections are conducted;

repair work is arranged;

tenancy disputes arise;

insurance claims are managed;

tribunal proceedings occur; or

the tenancy concludes.

Sales and Auctions

When buying or selling property, we may collect personal information during:

property inspections;

private appointments;

contract negotiations;

auction registrations;

contract execution;

settlement processes;

post-settlement communications; and

customer service enquiries.

Identity Verification

Where required by law or where reasonably necessary to protect our clients and business, we may collect information to verify your identity.

This may include:

government-issued identification documents;

proof of residential address;

company documentation;

trust documentation;

beneficial ownership information;

authority to act on behalf of another person; and

information required to comply with our AML/CTF obligations.

Identity verification may be undertaken electronically using secure identity verification service providers.

Anti-Money Laundering and Counter-Terrorism Financing (AML/CTF)

Where required by law, we collect personal information to comply with our obligations under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth).

This may include collecting information for:

customer identification;

customer due diligence;

enhanced customer due diligence;

ongoing customer monitoring;

beneficial ownership verification;

politically exposed person (PEP) screening;

sanctions screening;

source of funds enquiries;

source of wealth enquiries where required;

transaction monitoring;

risk assessments; and

compliance with our legal reporting obligations.

Further information regarding our AML/CTF obligations is outlined later in this Privacy Policy.

Information Collected from Third Parties

In some circumstances, we may collect personal information from third parties where authorised by you, where required by law, or where it is reasonably necessary to provide our services.

These third parties may include:

previous landlords;

previous managing agents;

referees;

employers;

mortgage brokers;

financial institutions;

solicitors;

conveyancers;

strata managers;

building managers;

insurers;

valuers;

building and pest inspectors;

utility providers;

government departments;

courts and tribunals;

regulatory authorities;

identity verification providers;

AML/CTF service providers;

credit reporting bodies where permitted by law;

publicly available registers; and

your authorised representatives.

Property Portals and Online Platforms

We may collect personal information when you interact with us through third-party platforms, including:

realestate.com.au;

Domain;

real estate comparison websites;

online rental application platforms;

inspection registration platforms;

electronic signature platforms;

property management software;

customer relationship management (CRM) systems; and

other online services used to deliver our real estate services.

Information collected through these platforms is also subject to the privacy practices of the relevant provider.

Publicly Available Information

Where permitted by law, we may collect personal information from publicly available sources, including:

property ownership records;

ASIC registers;

electoral rolls where authorised;

court judgments;

government publications;

publicly available websites;

professional networking platforms;

social media platforms; and

other publicly accessible records.

We only collect such information where it is reasonably necessary for our legitimate business purposes or legal obligations.

Website Collection

When you visit our website, we may automatically collect technical information about your interaction with the site.

This may include:

IP address;

browser type and version;

operating system;

pages viewed;

referring website;

date and time of access;

session duration;

clickstream data;

approximate geographic location;

device identifiers;

website preferences; and

diagnostic information.

This information assists us in maintaining website security, improving performance, understanding visitor behaviour and enhancing the user experience.

Cookies and Similar Technologies

Our website may use cookies, pixels, tags and similar technologies to improve functionality, analyse website traffic and support marketing activities.

These technologies may:

remember your preferences;

keep you logged into secure areas;

analyse website usage;

measure marketing effectiveness;

personalise content;

improve website performance; and

assist with fraud prevention and website security.

You may configure your browser to refuse or delete cookies. However, doing so may affect the functionality of certain parts of our website.

Analytics and Online Advertising

We may use analytics and advertising services to better understand how visitors use our website and to improve our online services.

These services may collect information about your interaction with our website using cookies and similar technologies.

Where used, these services may include:

Google Analytics;

Google Ads;

Microsoft Advertising;

Meta (Facebook) advertising services;

LinkedIn advertising services; and

other reputable analytics or advertising platforms.

Information collected through these services is generally aggregated and used to improve our services, marketing and website performance.

CCTV

For the safety and security of our staff, clients, contractors and visitors, CCTV may operate at our offices and other premises under our control.

CCTV recordings may be used for:

security monitoring;

investigating incidents;

protecting people and property;

preventing unlawful activity; and

complying with legal obligations.

CCTV recordings are retained only for as long as reasonably necessary unless required for an investigation or by law.

Telephone Calls and Electronic Communications

We maintain records of communications with clients and other individuals to provide our services, maintain accurate business records and comply with legal obligations.

This may include:

telephone calls;

voicemail messages;

emails;

SMS messages;

online chat messages;

video conference communications; and

correspondence through social media platforms.

Where telephone calls are recorded, we will do so in accordance with applicable laws.

Collection from Children

Our services are generally intended for adults.

We do not knowingly collect personal information from children unless:

the information is reasonably necessary to provide our services;

a parent or legal guardian has authorised the collection; or

collection is otherwise permitted or required by law.

If You Choose Not to Provide Personal Information

You are generally not required to provide us with your personal information.

However, if you choose not to provide information that we reasonably request or are legally required to collect, we may be unable to:

provide our services;

enter into contracts with you;

verify your identity;

comply with our legal obligations;

process tenancy applications;

conduct property transactions;

administer trust account payments; or

otherwise act on your behalf.

Where possible, we will explain the consequences of not providing the requested information.

11. Why We Collect, Hold, Use and Disclose Personal Information

We collect, hold, use and disclose personal information only where it is reasonably necessary to conduct our business, provide our services, comply with our legal obligations, protect our legitimate interests, or where you have otherwise consented.

The purposes for which we collect, hold, use and disclose personal information include, but are not limited to, the following.

Providing Real Estate Services

We collect and use personal information to provide professional real estate services, including:

selling residential and commercial property;

leasing residential and commercial property;

managing rental properties;

conducting auctions;

arranging inspections;

negotiating contracts;

preparing documentation;

communicating with buyers, sellers, landlords and tenants; and

providing ongoing customer support.

Property Management

Where we manage rental properties, personal information is used to:

assess tenancy applications;

verify applicant information;

prepare tenancy agreements;

manage rental payments;

administer trust account transactions;

arrange repairs and maintenance;

conduct routine inspections;

communicate with landlords and tenants;

manage lease renewals;

administer bond matters;

coordinate insurance claims;

manage disputes;

represent landlords where authorised; and

comply with residential tenancy legislation.

Property Sales

Where we act in the sale of property, personal information is used to:

market properties;

arrange inspections;

respond to buyer enquiries;

register auction attendees;

negotiate sales;

prepare contracts;

coordinate settlement;

liaise with solicitors and conveyancers;

maintain transaction records; and

comply with legislative obligations.

Customer Service

We use personal information to:

respond to enquiries;

provide requested information;

resolve complaints;

investigate concerns;

improve customer service;

maintain communication records;

provide updates regarding transactions;

arrange appointments; and

administer customer relationships.

Identity Verification

We use personal information to verify identity where required by law or reasonably necessary to protect our clients, our business and the integrity of property transactions.

Identity verification assists us to:

confirm identity;

reduce fraud;

prevent identity theft;

protect trust account transactions;

comply with AML/CTF legislation; and

satisfy other legal requirements.

Compliance with AML/CTF Obligations

Where applicable, we collect, hold, use and disclose personal information to comply with our obligations under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) and associated Rules.

This may include:

customer identification;

customer due diligence;

enhanced customer due diligence;

beneficial ownership identification;

ongoing customer monitoring;

politically exposed person (PEP) screening;

sanctions screening;

transaction monitoring;

source of funds enquiries;

source of wealth enquiries where appropriate;

suspicious matter reporting;

record keeping; and

compliance reporting to AUSTRAC.

Failure to provide information required under AML/CTF legislation may prevent us from providing particular services.

Compliance with Legal and Regulatory Obligations

We may collect, hold, use or disclose personal information to comply with:

Commonwealth legislation;

State legislation;

court orders;

tribunal proceedings;

regulatory investigations;

statutory notices;

law enforcement requests;

licensing requirements;

taxation obligations;

trust accounting requirements;

audit requirements; and

other lawful obligations.

Employment and Recruitment

Where you apply for employment with us, we use personal information to:

assess applications;

verify qualifications;

conduct interviews;

undertake reference checks;

determine suitability for employment;

comply with employment legislation; and

administer the employment relationship where applicable.

Contractors and Suppliers

Where you provide goods or services to us, we may use personal information to:

engage contractors;

verify licences and qualifications;

process payments;

manage service agreements;

administer work orders;

communicate regarding services;

monitor performance; and

comply with legal obligations.

Marketing and Communications

We may use your personal information to:

provide property updates;

advise of new listings;

notify you of inspections and auctions;

send newsletters;

provide market information;

invite you to events;

conduct customer satisfaction surveys;

provide information about our services; and

send other communications which may reasonably be expected.

Where required by law, we will obtain your consent before sending marketing communications.

You may opt out of receiving marketing communications at any time by:

clicking the unsubscribe link included in electronic communications;

contacting our Privacy Officer;

emailing us; or

updating your communication preferences.

Opting out of marketing communications will not affect service-related communications that we are required to send.

Website Improvement and Analytics

We use information collected through our website to:

improve website functionality;

analyse visitor behaviour;

identify website performance issues;

enhance user experience;

improve security;

understand customer preferences;

develop new services;

measure marketing effectiveness; and

prevent fraud or misuse of our systems.

Where possible, we use aggregated or de-identified information for these purposes.

Business Administration

We may use personal information for legitimate business administration, including:

record keeping;

financial management;

trust account administration;

accounting;

auditing;

insurance;

risk management;

business continuity planning;

information technology support;

cybersecurity;

policy development;

legal advice;

dispute resolution;

corporate governance; and

internal reporting.

Artificial Intelligence and Technology-Assisted Services

To improve efficiency and customer service, we may use technology-assisted tools, including artificial intelligence (AI), to support administrative and operational activities.

These tools may assist with tasks such as:

drafting correspondence;

summarising documents;

preparing reports;

organising information;

identifying trends;

improving customer service; and

enhancing operational efficiency.

Where AI-assisted tools are used, we implement reasonable safeguards to protect personal information. We do not make decisions that have a legal or similarly significant effect on individuals solely through automated processing without appropriate human oversight.

Research, Planning and Business Improvement

We may use personal information to:

analyse business performance;

identify service improvements;

understand customer needs;

develop new services;

improve staff training;

enhance operational efficiency; and

support strategic planning.

Where practical, this information will be aggregated or de-identified.

Other Lawful Purposes

We may also collect, hold, use or disclose personal information:

where you have provided your consent;

where required or authorised by law;

where necessary to protect the life, health or safety of an individual;

where necessary to establish, exercise or defend legal claims;

where necessary to investigate suspected unlawful activity, fraud or misconduct; or

for any other purpose permitted under the Privacy Act 1988 (Cth).

Our Commitment to Purpose Limitation

We are committed to the principle of purpose limitation.

We will not use or disclose your personal information for a purpose that is unrelated to the reason it was collected unless:

you have provided your consent;

you would reasonably expect the use or disclosure;

the use or disclosure is required or authorised by law; or

another exception under the Privacy Act applies.

Where we intend to use personal information for a new purpose that is not reasonably expected, we will obtain your consent where required by law.

12. Disclosure of Personal Information

We recognise that personal information is entrusted to us and will only disclose personal information where it is reasonably necessary to provide our services, comply with our legal obligations, protect our legitimate business interests, or where you have otherwise consented.

We do not sell personal information to third parties.

We do not disclose personal information for unrelated commercial purposes.

Where personal information is disclosed to another organisation, we take reasonable steps to ensure that the recipient handles the information appropriately and, where required, in accordance with the Australian Privacy Principles or equivalent privacy obligations.

Disclosure Within Noonan Real Estate Agents

Personal information may be shared internally between authorised directors, managers, employees and contractors where access is reasonably necessary for the performance of their duties.

Access to personal information is limited on a need-to-know basis and is subject to appropriate access controls and confidentiality obligations.

Vendors, Purchasers, Landlords and Tenants

To facilitate property transactions and property management services, we may disclose personal information between parties involved in the same transaction where reasonably necessary.

For example:

vendors and purchasers;

landlords and tenants;

landlords and authorised contractors;

tenants and maintenance providers (where required to arrange repairs);

authorised representatives; and

legal representatives acting for any party.

Only information reasonably necessary to perform the relevant service will be disclosed.

Solicitors, Conveyancers and Settlement Agents

We may disclose personal information to legal professionals involved in a property transaction or dispute, including:

solicitors;

conveyancers;

settlement agents;

legal advisers; and

barristers where appropriate.

This enables contracts to be prepared, settlements completed, legal advice obtained and disputes resolved.

Financial Institutions

We may disclose personal information to:

banks;

financial institutions;

mortgage brokers;

lenders;

payment processors; and

trust account service providers.

This assists with financial transactions, settlements, trust accounting and payment processing.

Contractors and Maintenance Providers

Where repairs, maintenance or property services are required, we may disclose relevant personal information to contractors including:

plumbers;

electricians;

builders;

locksmiths;

cleaners;

painters;

pest control providers;

Bliższe przyjrzenie się lizaroscasino.org pokazuje, dlaczego ten adres zyskuje coraz większą rozpoznawalność. Program poleceń pozwala trwale budować pasywne środki bonusowe dzięki poleconym znajomym. Często zadawane pytania bonusowe są zebrane w osobnej sekcji pomocy. Biblioteka gier regularnie rozszerza się o nowości największych studiów deweloperskich. Spersonalizowany pasek rekomendacji sugeruje pasujące gry na podstawie dotychczasowego zachowania. Gracze mogą również mobilnie edytować i zarządzać listą ulubionych. Przegląd wszystkich transakcji jest zawsze dostępny w obszarze gracza. Zakłady poboczne rozszerzają strategiczne możliwości przy klasycznych stołach. Generatory liczb losowych są regularnie certyfikowane przez niezależne instytucje, takie jak eCOGRA. Konsekwencja w jakości serwisu przemawia za poważnym dostawcą.

gardeners;

handymen;

appliance repair technicians;

roofers;

glaziers;

carpet cleaners;

security providers; and

other appropriately qualified contractors.

Information disclosed will generally be limited to the property address, contact details, access arrangements and details necessary to complete the requested work.

Property Service Providers

We may disclose personal information to organisations assisting us in delivering our real estate services, including:

strata managers;

owners corporations;

body corporate managers;

valuers;

surveyors;

building inspectors;

pest inspectors;

insurance assessors;

utility providers;

removal companies;

property photographers;

floor plan providers;

marketing agencies;

signboard contractors; and

auction service providers.

Technology and Software Providers

To operate our business efficiently, we use a range of reputable technology providers.

Depending on the services being provided, personal information may be processed by providers of:

property management software;

real estate CRM systems;

trust accounting software;

document management systems;

cloud storage;

secure file sharing;

email hosting;

electronic signature platforms;

customer communication platforms;

website hosting;

cyber security services;

managed IT services;

backup and disaster recovery services;

accounting software; and

business productivity platforms.

These providers are contractually or otherwise required to protect personal information and use it only for authorised purposes.

Identity Verification Providers

Where identity verification is required, we may disclose personal information to trusted identity verification providers to:

verify identity documents;

verify biometric information where applicable;

confirm residential address;

detect identity fraud;

prevent financial crime; and

comply with applicable legislation.

Identity verification providers may compare information provided by you with reliable and independent data sources.

AML/CTF Compliance Providers

To comply with the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth), we may disclose personal information to specialist compliance providers, including electronic identity verification and AML screening services such as AML Smart Guard, or equivalent providers engaged by us from time to time.

These providers may assist us with:

electronic identity verification;

customer due diligence;

enhanced due diligence;

politically exposed person (PEP) screening;

sanctions screening;

beneficial ownership verification;

ongoing customer monitoring;

transaction monitoring; and

compliance reporting.

Only the information reasonably necessary to perform these services will be disclosed.

Government and Regulatory Authorities

We may disclose personal information where required or authorised by law to government agencies and regulatory authorities, including but not limited to:

AUSTRAC;

Office of the Australian Information Commissioner (OAIC);

NSW Fair Trading;

NSW Civil and Administrative Tribunal (NCAT);

courts and tribunals;

Australian Taxation Office;

Australian Securities and Investments Commission (ASIC);

law enforcement agencies;

police;

local councils;

government departments; and

other regulators with lawful authority.

Professional Advisers

We may disclose personal information to our professional advisers where reasonably necessary, including:

accountants;

auditors;

insurers;

insurance brokers;

legal advisers;

risk advisers;

compliance consultants;

external investigators; and

other professional advisers engaged by us.

Business Transfers

If all or part of our business is sold, restructured, merged or otherwise transferred, personal information may be disclosed to prospective purchasers, advisers and financiers involved in the transaction.

Any disclosure will be subject to appropriate confidentiality obligations and applicable privacy laws.

Emergencies

We may disclose personal information where reasonably necessary to:

protect the life, health or safety of an individual;

prevent serious threats;

respond to emergencies;

investigate suspected unlawful activity; or

protect our legal rights.

With Your Consent

We may disclose personal information to another person or organisation where:

you have requested us to do so;

you have authorised another person to act on your behalf;

you have otherwise consented to the disclosure; or

the disclosure is incidental to providing the services you have requested.

We Do Not Sell Personal Information

Noonan Real Estate Agents does not sell, rent, trade or otherwise commercially exploit personal information.

We do not permit third parties to use personal information for their own direct marketing purposes unless you have separately provided your consent or such use is otherwise authorised by law.

Data Sharing Principles

Whenever we disclose personal information, we seek to ensure that:

only the minimum amount of personal information reasonably necessary is disclosed;

disclosures are made securely;

recipients are subject to appropriate confidentiality or contractual obligations;

access is restricted to authorised persons;

information is disclosed only for legitimate business or legal purposes; and

disclosures comply with applicable Australian privacy laws.

Our Commitment to Responsible Disclosure

We recognise that every disclosure of personal information carries privacy obligations.

Accordingly, we regularly review our information-sharing practices, service providers and contractual arrangements to ensure they continue to meet our legal obligations, reflect industry best practice and appropriately protect the personal information entrusted to us.

13. Overseas Disclosure of Personal Information

As part of operating a modern real estate business, Noonan Real Estate Agents may engage trusted third-party service providers, cloud-based technology providers and overseas contractors to assist us in delivering our services efficiently and securely.

Where this involves the disclosure of personal information outside Australia, we take reasonable steps to ensure that the information continues to be protected in accordance with the Australian Privacy Principles and this Privacy Policy.

Overseas Contractors

From time to time, we engage suitably qualified overseas contractors to provide administrative and operational support services to our Australian business.

At the date of this Privacy Policy, our overseas contractors are primarily located in the Republic of the Philippines.

These contractors may assist with activities including:

administrative support;

property management administration;

document preparation;

data entry;

customer service support;

maintenance coordination;

marketing administration;

CRM administration;

compliance administration;

reporting;

scheduling;

file management; and

other administrative tasks authorised by Noonan.

Our overseas contractors work remotely from their own premises and access our systems using secure technology approved by Noonan.

Information Accessible by Overseas Contractors

Depending on their authorised duties, overseas contractors may have access to personal information reasonably necessary to perform their work.

This may include:

names;

contact details;

property addresses;

tenancy information;

landlord information;

purchaser and vendor information;

maintenance records;

inspection records;

communication history;

property documentation;

trust account administration information (where authorised);

compliance documentation; and

other information necessary to perform their contracted services.

Access is restricted according to each contractor’s role and responsibilities.

Security Measures

Before granting overseas contractors access to personal information, Noonan implements reasonable safeguards designed to protect the confidentiality and security of that information.

These safeguards may include:

confidentiality agreements;

contractual privacy obligations;

role-based system access;

unique user accounts;

password protection;

multi-factor authentication (where implemented);

secure cloud-based systems;

audit logging;

restricted permissions;

supervision by Australian management;

ongoing monitoring of access;

privacy and confidentiality training; and

prompt removal of system access when no longer required.

We continually review our security measures to ensure they remain appropriate having regard to the nature of the personal information we hold.

Cloud-Based Technology Providers

Many of the technology platforms used by Noonan are cloud-based.

Accordingly, personal information may be stored, processed or backed up on secure servers located in Australia or overseas by reputable technology providers.

These providers may include organisations supplying:

cloud hosting;

email services;

document management;

data backup;

cyber security;

accounting software;

customer relationship management systems;

electronic signature services;

identity verification services;

AML/CTF compliance platforms;

property management software;

trust accounting software; and

business productivity platforms.

The location of data centres used by these providers may change from time to time.

Cross-Border Disclosure

Where personal information is disclosed outside Australia, we take reasonable steps to ensure that overseas recipients:

handle personal information in a manner consistent with Australian privacy laws;

are subject to appropriate contractual confidentiality obligations;

implement appropriate security controls;

use the information only for authorised purposes;

protect the information against unauthorised access, misuse and disclosure; and

comply with any additional contractual requirements imposed by Noonan.

Where required by law, we will take additional steps before disclosing personal information overseas.

Our Responsibility

Noonan remains committed to protecting personal information regardless of where it is processed.

Although overseas contractors and technology providers may assist us in delivering our services, responsibility for the proper handling of personal information remains with Noonan.

We regularly review our overseas service arrangements to ensure they continue to meet our legal obligations, operational requirements and privacy expectations.

Changes to Overseas Arrangements

As our business evolves, we may engage additional overseas contractors or service providers located in other countries.

Where this occurs, we will take reasonable steps to ensure that any overseas disclosure of personal information complies with applicable Australian privacy laws and reflects the commitments contained in this Privacy Policy.

Transparency

By engaging our services or otherwise providing us with your personal information, you acknowledge that, where reasonably necessary for the delivery of our services or compliance with our legal obligations, your personal information may be accessed or processed by approved overseas contractors or technology providers acting on our behalf.

Such access will always be subject to appropriate security controls, contractual obligations and our ongoing oversight.

14. Protecting Personal Information

Noonan Real Estate Agents is committed to protecting the personal information entrusted to us against misuse, interference, loss, unauthorised access, modification and disclosure.

We recognise that protecting personal information is an ongoing responsibility requiring appropriate governance, technology, staff awareness and operational practices.

We maintain a privacy and information security framework designed to safeguard personal information throughout its lifecycle.

Our Security Principles

Our approach to protecting personal information is based on the following principles:

confidentiality;

integrity;

availability;

accountability;

least privilege access;

continuous improvement; and

compliance with Australian privacy laws.

These principles guide the way we collect, store, access, use and dispose of personal information.

Physical Security

We implement reasonable physical security measures to protect paper records and physical assets that contain personal information.

These measures may include:

secure office premises;

restricted office access;

visitor management procedures;

locked filing cabinets;

secure document storage;

alarm systems;

monitored premises where appropriate;

CCTV security systems;

secure destruction bins;

controlled key access; and

clean desk practices.

Only authorised personnel are permitted access to areas containing confidential information.

Electronic Security

We use reasonable technical safeguards to protect electronic information systems.

Depending on the systems being used, these safeguards may include:

password protection;

multi-factor authentication (MFA);

encryption of data in transit and, where appropriate, at rest;

secure cloud platforms;

role-based access controls;

unique user accounts;

automatic session time-outs;

audit logging;

activity monitoring;

anti-virus software;

anti-malware software;

firewalls;

endpoint protection;

email filtering;

spam protection;

vulnerability management;

software updates and security patching;

secure backups;

disaster recovery arrangements; and

cybersecurity monitoring.

We regularly review our technical safeguards to ensure they remain appropriate having regard to the nature and sensitivity of the personal information we hold.

Access Controls

Access to personal information is restricted to individuals who require that access to perform their duties.

We apply the principle of least privilege, meaning individuals are provided with access only to the systems and information reasonably necessary for their role.

Access permissions are reviewed periodically and removed promptly where access is no longer required.

Password Management

Personnel with access to our systems are expected to:

maintain secure passwords;

protect login credentials;

avoid sharing passwords;

use multi-factor authentication where implemented;

report suspected credential compromise immediately; and

comply with our information security requirements.

Staff Awareness and Training

Protecting personal information is a shared responsibility.

Our employees and contractors receive guidance appropriate to their roles regarding:

privacy obligations;

confidentiality;

cyber security awareness;

phishing and social engineering risks;

secure handling of personal information;

reporting security incidents; and

compliance with our internal policies and procedures.

Privacy and information security training is reviewed periodically to ensure it remains current and relevant.

Confidentiality Obligations

Employees, contractors, consultants and other authorised persons with access to personal information are expected to maintain the confidentiality of that information.

Appropriate confidentiality obligations may be imposed through:

employment contracts;

contractor agreements;

confidentiality agreements;

professional obligations;

internal policies; and

other legally enforceable arrangements.

Unauthorised access, use or disclosure of personal information may result in disciplinary action, termination of engagement or other legal action where appropriate.

Information Security Monitoring

To maintain the security of our systems, we may monitor:

user access;

login activity;

system events;

network traffic;

security alerts;

audit logs;

failed login attempts;

software performance; and

other information reasonably necessary to detect, investigate or prevent security incidents.

Monitoring is undertaken for legitimate security and operational purposes.

Remote Access

Where employees or contractors access our systems remotely, including approved overseas contractors, reasonable security controls are implemented to reduce the risk of unauthorised access.

These controls may include:

secure internet connections;

encrypted communications;

authentication controls;

role-based permissions;

approved devices where applicable;

endpoint security;

access monitoring; and

prompt revocation of access when no longer required.

Third-Party Service Providers

Where third-party service providers process personal information on our behalf, we take reasonable steps to ensure they maintain appropriate privacy and information security practices.

This may include:

contractual privacy obligations;

confidentiality provisions;

information security requirements;

due diligence assessments;

periodic reviews; and

other appropriate safeguards.

Cyber Security Incidents

Despite our security measures, no method of transmitting or storing information electronically can be guaranteed to be completely secure.

If we become aware of a cyber security incident or suspected unauthorised access involving personal information, we will promptly investigate the matter and take reasonable steps to contain, assess and respond to the incident.

Where required by law, we will comply with the Notifiable Data Breaches Scheme, including notifying affected individuals and the Office of the Australian Information Commissioner (OAIC).

Business Continuity

We maintain reasonable business continuity and disaster recovery arrangements designed to support the continued availability and recovery of critical business systems following unexpected events.

These arrangements assist us in protecting information and maintaining the delivery of essential services.

Continuous Improvement

Information security risks continually evolve.

Accordingly, we regularly review and improve our privacy, cyber security and information management practices to reflect:

changes in legislation;

emerging cyber threats;

technological developments;

industry best practice;

regulatory guidance; and

operational experience.

Our Commitment

Protecting personal information is fundamental to maintaining the confidence of our clients and the integrity of our business.

We are committed to maintaining a culture in which privacy, confidentiality and information security form part of everyday business operations and decision-making.

15. Data Retention, Record Keeping and Secure Destruction

Noonan Real Estate Agents is committed to retaining personal information only for as long as it is reasonably necessary to fulfil the purposes for which it was collected, to comply with legal and regulatory obligations, to resolve disputes, enforce our legal rights, or as otherwise permitted or required by law.

When personal information is no longer required, we will take reasonable steps to securely destroy or permanently de-identify the information unless we are required to retain it by law.

Our Record Keeping Principles

We manage personal information in accordance with the following principles:

records are retained only for legitimate business or legal purposes;

information is protected throughout its lifecycle;

records are securely stored;

access is restricted to authorised persons;

retention periods are regularly reviewed; and

information that is no longer required is securely destroyed or permanently de-identified where lawful and practicable.

Why We Retain Information

We may retain personal information to:

provide ongoing services;

comply with legal obligations;

comply with taxation requirements;

comply with trust accounting obligations;

comply with AML/CTF obligations;

respond to complaints;

defend legal claims;

maintain accurate business records;

support audits;

investigate incidents;

protect our legal rights; and

meet regulatory requirements.

Retention Periods

The exact period for which personal information is retained will depend on the nature of the information, the purpose for which it was collected and applicable legal requirements.

Examples include:

Record Type

Typical Retention

AML/CTF customer due diligence records

At least the minimum period required by applicable AML/CTF legislation

Trust account records

At least the minimum period required under applicable legislation

Property transaction records

As required by law or where reasonably necessary to protect legal rights

Property management records

As required by law or where reasonably necessary for business purposes

Financial and taxation records

In accordance with applicable taxation legislation

Employment records

As required by employment and workplace legislation

Recruitment records (unsuccessful applicants)

For a reasonable period unless otherwise required by law or consented to

CCTV recordings

Generally retained only for as long as reasonably necessary unless required for an investigation or legal proceedings

Website analytics

In accordance with the settings of the relevant analytics platform and our business needs

Marketing information

Until you unsubscribe or the information is no longer required

Where different legal obligations apply, we will retain records for the longer applicable period.

Archiving

Where appropriate, older records may be archived in secure electronic or physical storage.

Archived records remain subject to the same privacy, confidentiality and security requirements as active records.

Access to archived information is restricted to authorised personnel.

Secure Disposal

When personal information is no longer required and no legal obligation exists to retain it, we take reasonable steps to securely dispose of the information.

Depending on the type of information, secure disposal may include:

secure shredding of paper records;

certified destruction of confidential documents;

secure deletion of electronic records;

permanent de-identification;

secure destruction of storage media; or

secure disposal by approved destruction providers.

De-identification

Where appropriate, personal information may be permanently de-identified rather than destroyed.

De-identified information no longer identifies an individual and may be retained for legitimate business purposes, statistical analysis, service improvement or reporting.

Legal Holds

Where information may be relevant to:

legal proceedings;

tribunal matters;

regulatory investigations;

insurance claims;

audits; or

law enforcement requests,

we may retain the information for longer than our usual retention periods until the relevant matter has concluded.

Backups

To support business continuity and disaster recovery, personal information may be included in secure system backups managed by Noonan or our authorised information technology service providers.

Backup data is protected using appropriate security measures and retained in accordance with our business continuity requirements.

Where information has been deleted from active systems, residual copies may remain within secure backup systems for a limited period before being overwritten through normal backup cycles.

Ongoing Review

We periodically review the personal information we hold to ensure it remains:

relevant;

accurate;

necessary;

appropriately protected; and

retained only for as long as required.

Where information is no longer required, we will securely destroy or de-identify it where lawful and practicable.

Our Commitment

Responsible management of personal information includes not only collecting and protecting information but also ensuring it is retained only for appropriate periods and securely disposed of when no longer required.

Noonan is committed to maintaining responsible record management practices that support privacy, security, legal compliance and good corporate governance.

SECTION 16

Access to Personal Information, Correction, Privacy Rights and Complaints

This section addresses Australian Privacy Principles 12 and 13, together with your internal complaint handling process.

16. Your Privacy Rights

Noonan Real Estate Agents recognises that individuals have important rights regarding their personal information.

Subject to applicable law, you have the right to:

know what personal information we collect;

understand why we collect it;

request access to your personal information;

request correction of inaccurate or incomplete information;

withdraw consent where processing is based on consent;

request that we update your information;

make a privacy complaint;

receive information about how we handle your complaint; and

contact our Privacy Officer regarding any privacy concern.

We are committed to responding to privacy requests in a fair, transparent and timely manner.

Access to Your Personal Information

You may request access to personal information that we hold about you.

Requests should be made in writing to our Privacy Officer using the contact details provided at the end of this Privacy Policy.

To protect your privacy, we may require reasonable evidence of your identity before providing access.

Responding to Access Requests

We will acknowledge your request as soon as reasonably practicable and aim to respond within 30 calendar days.

Where additional time is reasonably required due to the complexity of the request, we will advise you accordingly.

Where possible, access will be provided in the form requested by you.

Circumstances Where Access May Be Refused

In certain circumstances, the Privacy Act permits us to refuse access to personal information.

Examples include where:

giving access would unreasonably affect another person’s privacy;

legal professional privilege applies;

the request is frivolous or vexatious;

access would prejudice legal proceedings;

access would prejudice enforcement activities;

disclosure would reveal commercially sensitive information;

another law requires or authorises refusal; or

another exception under the Privacy Act applies.

If access is refused, we will provide written reasons unless we are prohibited by law from doing so.

We will also advise you of any available complaint or review mechanisms.

Charges

We do not charge a fee for making a request to access your personal information.

However, where permitted by law, we may charge a reasonable administrative fee for providing access where substantial resources are required to locate, retrieve or reproduce information.

If a fee is applicable, we will advise you before proceeding.

Correction of Personal Information

We take reasonable steps to ensure the personal information we hold is accurate, complete, relevant and up to date.

If you believe any personal information we hold is inaccurate, incomplete, out of date, irrelevant or misleading, you may request that it be corrected.

Requests should be made to our Privacy Officer.

Responding to Correction Requests

Where we are satisfied that information should be corrected, we will take reasonable steps to:

update our records;

correct inaccurate information;

notify relevant third parties where appropriate and reasonably practicable, if requested by you; and

ensure future use of the corrected information.

If we refuse a correction request, we will provide written reasons together with information about available complaint mechanisms.

Keeping Your Information Current

We encourage you to notify us promptly if your:

name changes;

address changes;

telephone number changes;

email address changes;

ownership details change;

company or trust details change; or

any other relevant personal information changes.

Maintaining accurate information helps us provide efficient services and comply with our legal obligations.

Making a Privacy Complaint

If you believe that we have mishandled your personal information or breached the Privacy Act, you may lodge a privacy complaint with us.

Complaints should be submitted in writing to our Privacy Officer.

To assist us in investigating your complaint, please provide:

your name and contact details;

details of your complaint;

any relevant dates;

copies of supporting documents (if available); and

the outcome you are seeking.

How We Handle Complaints

Upon receiving a privacy complaint, we will:

acknowledge receipt as soon as reasonably practicable;

investigate the issues raised;

request additional information where required;

consider relevant legislation;

review available evidence;

consult relevant staff where appropriate;

determine an appropriate outcome; and

provide a written response.

We aim to respond to privacy complaints within 30 calendar days.

Where additional time is reasonably required, we will keep you informed of our progress.

Complaints to the OAIC

If you are not satisfied with our response, you may refer your complaint to the:

Office of the Australian Information Commissioner (OAIC)

Website:

https://www.oaic.gov.au

Telephone:

1300 363 992

We encourage individuals to first give us the opportunity to investigate and resolve privacy concerns before referring the matter to the OAIC.

No Disadvantage

We will not treat you unfairly because you have:

requested access to your personal information;

requested correction of your information;

made a privacy complaint; or

exercised any rights available under Australian privacy law.

Continuous Improvement

Privacy complaints provide valuable opportunities to improve our services and governance.

Where appropriate, we review complaints to identify:

opportunities for improvement;

staff training requirements;

policy enhancements;

technology improvements;

operational changes; and

risk management initiatives.

Lessons learned from privacy complaints may be incorporated into our ongoing privacy management programme.

Our Commitment

We are committed to treating every privacy enquiry and complaint professionally, respectfully and fairly.

Our objective is to resolve concerns promptly while maintaining transparency, accountability and compliance with Australian privacy laws.

SECTION 17

Notifiable Data Breaches, Privacy Incidents and Data Breach Response

17.1 Our Commitment

Noonan Real Estate Agents is committed to responding promptly, responsibly and transparently to any actual or suspected privacy incident or data breach.

While we implement reasonable measures to protect personal information, no organisation can eliminate all information security risks.

Accordingly, we maintain procedures for identifying, assessing, containing, investigating and responding to privacy incidents and eligible data breaches.

Our objective is to minimise harm to affected individuals, restore the security of our systems and comply with our legal obligations under Australian privacy law.

17.2 What is a Data Breach?

A data breach occurs where personal information held by Noonan is:

lost;

accessed without authorisation;

disclosed without authorisation;

altered without authorisation; or

otherwise compromised.

A data breach may occur accidentally or deliberately and may involve electronic records, paper records or verbal disclosures.

Examples include:

emails sent to the wrong recipient;

lost laptops;

lost mobile phones;

stolen devices;

phishing attacks;

ransomware attacks;

hacked email accounts;

unauthorised access by employees or contractors;

confidential documents being misplaced;

unauthorised disclosure during conversations;

cyber attacks;

compromised cloud accounts; or

any other incident affecting the confidentiality, integrity or availability of personal information.

17.3 Privacy Incidents

Not every privacy incident will amount to an eligible data breach under the Privacy Act.

However, all suspected privacy incidents are treated seriously.

Examples include:

accidental disclosure;

incorrect mail or email recipients;

inappropriate access to client files;

unauthorised downloading of information;

suspicious system activity;

loss of confidential documents;

attempted cyber attacks;

malware infections;

suspected phishing; or

any event that may place personal information at risk.

All suspected incidents should be reported promptly through our internal reporting processes.

17.4 Our Response

Where we become aware of an actual or suspected privacy incident, we will take reasonable steps to:

contain the incident;

prevent further unauthorised access or disclosure;

preserve evidence;

investigate the circumstances;

assess the nature and extent of the incident;

determine whether personal information has been affected;

identify affected individuals;

assess the likelihood of serious harm;

determine whether notification is required by law;

implement corrective actions; and

review our systems and procedures to reduce the likelihood of recurrence.

17.5 Assessment

Where required by law, we will undertake a reasonable and expeditious assessment to determine whether a suspected data breach is an eligible data breach under the Privacy Act.

This assessment will consider factors including:

the nature of the information involved;

whether the information was encrypted or otherwise protected;

who obtained access;

whether the information is likely to be misused;

the sensitivity of the information;

whether the information has been recovered;

the likelihood of serious harm; and

any other relevant circumstances.

17.6 Notification

Where required under the Notifiable Data Breaches Scheme, we will notify:

affected individuals; and

the Office of the Australian Information Commissioner (OAIC),

as soon as practicable after becoming aware of an eligible data breach.

Notifications will generally include:

a description of the incident;

the kinds of information affected;

recommendations regarding steps individuals should take; and

contact details for further information.

17.7 Containment

Where reasonably practicable, we will take immediate steps to reduce the impact of a privacy incident.

Depending on the nature of the incident, this may include:

disabling user accounts;

resetting passwords;

revoking system access;

recovering documents;

isolating affected systems;

engaging our external IT provider;

notifying relevant service providers;

restoring systems from backups;

engaging cyber security specialists;

notifying insurers; and

implementing additional security controls.

17.8 Learning From Incidents

Following every significant privacy incident, we will review:

what occurred;

why it occurred;

whether policies were followed;

opportunities for improvement;

technology improvements;

staff training requirements;

contractor management;

cyber security controls; and

governance improvements.

Lessons learned will be incorporated into our privacy management programme.

17.9 Continuous Improvement

Privacy and cyber threats continually evolve.

Accordingly, we regularly review our privacy governance, cyber security controls, incident response procedures and staff awareness programmes to strengthen our ability to prevent, detect and respond to privacy incidents.

17.10 Our Commitment

If a privacy incident occurs, our priority will always be to:

protect affected individuals;

minimise harm;

restore the security of our systems;

comply with Australian law; and

continually improve our privacy and cyber security framework.

18. Privacy Governance, Accountability and Continuous Improvement

Noonan Real Estate Agents recognises that protecting personal information requires more than policies alone. Effective privacy management depends on strong governance, clearly defined responsibilities, ongoing education and continuous improvement.

Privacy forms an integral part of our broader corporate governance framework and is embedded within our business processes, risk management practices and organisational culture.

Governance Commitment

We are committed to maintaining a privacy management programme that promotes:

accountability;

transparency;

lawful handling of personal information;

responsible decision-making;

continual improvement;

staff awareness;

cyber resilience; and

compliance with applicable Australian privacy laws.

Privacy considerations are incorporated into the planning, delivery and review of our business activities wherever reasonably practicable.

Privacy Officer

Noonan has appointed a Privacy Officer responsible for overseeing our privacy management programme.

The Privacy Officer’s responsibilities include:

monitoring compliance with this Privacy Policy;

responding to privacy enquiries;

managing privacy complaints;

coordinating privacy incident responses;

overseeing access and correction requests;

monitoring legislative developments;

supporting staff awareness and training;

reviewing privacy risks;

recommending improvements to privacy practices; and

reporting significant privacy matters to senior management where appropriate.

The Privacy Officer may work with other members of management and our external advisers to ensure effective privacy governance.

Privacy by Design

Where reasonably practicable, privacy considerations will be incorporated into the design, development and implementation of new systems, technologies, business processes and services.

Before introducing significant changes that may affect the handling of personal information, we will consider:

the necessity of collecting personal information;

opportunities to minimise the information collected;

appropriate security controls;

privacy risks;

legal obligations;

access requirements; and

the potential impact on individuals.

Risk Management

Privacy risks are considered as part of our broader business risk management framework.

Where appropriate, we assess risks associated with:

new technologies;

software providers;

overseas contractors;

cyber security;

third-party service providers;

legislative change;

information sharing;

business continuity; and

operational processes.

Where privacy risks are identified, we take reasonable steps to reduce those risks through appropriate controls and governance measures.

Training and Awareness

We recognise that effective privacy protection depends upon informed and responsible personnel.

Accordingly, we promote privacy awareness among our employees and contractors through guidance appropriate to their roles and responsibilities.

Training may include:

privacy obligations;

confidentiality;

cyber security awareness;

phishing prevention;

secure handling of personal information;

recognising and reporting privacy incidents;

AML/CTF privacy obligations; and

updates regarding changes to legislation or internal procedures.

Contractor Management

Where contractors have access to personal information, we take reasonable steps to ensure they understand and comply with applicable privacy obligations.

This may include:

confidentiality agreements;

contractual privacy obligations;

role-based access controls;

privacy guidance;

ongoing supervision;

periodic review of access; and

prompt removal of access when engagement ends.

These requirements apply equally to Australian-based and overseas contractors.

Policy Review

This Privacy Policy will be reviewed:

at least annually;

following significant legislative change;

following material changes to our business;

following significant privacy incidents;

following major technology changes; or

whenever otherwise considered appropriate.

Where amendments are made, the updated version will be published on our website.

Contacting Us

If you have any questions regarding this Privacy Policy or our privacy practices, please contact our Privacy Officer.

Privacy Officer

General Manager

Noonan Real Estate Agents Pty Ltd

Telephone: 0477 225 511

Email: mgr@noonan.com.au

Postal Address:

31 Morts Road

Mortdale NSW 2223

Australia

Office of the Australian Information Commissioner

If you are not satisfied with our response to your privacy concern, you may contact:

Office of the Australian Information Commissioner (OAIC)

Website: https://www.oaic.gov.au

Telephone: 1300 363 992

Postal Address: GPO Box 5288, Sydney NSW 2001 (or the current address published by the OAIC).

Policy Availability

The current version of this Privacy Policy is available:

on our website;

upon request from our office; and

in any other format reasonably required to assist individuals in understanding our privacy practices.

Final Commitment

Protecting personal information is fundamental to the trust our clients, landlords, tenants, vendors, purchasers, employees, contractors and business partners place in us.

Noonan Real Estate Agents is committed to maintaining responsible privacy practices that support compliance with Australian law, protect personal information and promote confidence in the services we provide.

We recognise that privacy is an ongoing responsibility. We will continue to review and strengthen our privacy practices, governance arrangements and information security measures to ensure they remain effective, proportionate and aligned with evolving legal and community expectations.

Slot Gacor
situs slot gacor