EXCELERIS PRIVACY POLICY

Exceleris Consulting Privacy Policy

Effective Date: 01 May 2025 | Last Updated: 12 May 2025

Welcome to Exceleris Consulting (“Exceleris,” “we,” “us,” or “our”). We are committed to protecting the privacy and security of the personal information we collect and process. This Privacy Policy describes how we collect, use, disclose, and protect personal information obtained through our website, excelerisconsulting.com (the “Site”), and in connection with our business development and client engagement activities.

Exceleris Privacy Policy

1. Introduction

This Policy is designed to comply with applicable privacy laws in the jurisdictions where we operate or where our website visitors reside, including the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth) in Australia, the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 in the United Kingdom, and relevant state laws in the United States, such as the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA).

Please read this Privacy Policy carefully. By using our Site or providing us with your personal information, you acknowledge that you have read and understood this Policy.

2. Information We Collect

We may collect different types of personal information depending on your interaction with us:

  • Information You Provide Directly:
    • Contact Information: Name, email address, phone number, company name, job title, country, when you fill out contact forms, request information, subscribe to newsletters or marketing communications, register for events, or otherwise communicate with us.
    • Recruitment Information: If you apply for a position with us through the Site (if applicable), we may collect your CV/resume, cover letter, employment history, educational background, and other information relevant to your application.
    • Client Information: Information provided by prospective or existing clients necessary for scoping or delivering consulting services (though sensitive client project data is typically governed by separate engagement agreements).
  • Information Collected Automatically:
    • Log Data: Standard server logs may record information such as your Internet Protocol (IP) address, browser type and version, operating system, the pages you visit on our Site, the time and date of your visit, the time spent on those pages, referring website addresses, and other diagnostic data.
  • Cookies and Tracking Technologies: We use cookies, web beacons, and similar technologies to operate and improve the Site, analyse usage, personalize content, and for marketing purposes. Please see Section 9 (“Cookies and Tracking Technologies”) for more details.

3. How We Use Your Information and Legal Basis for Processing

We use the personal information we collect for the following purposes, relying on specific legal bases where required (particularly under UK GDPR):

Purpose of Use

Types of Data Used

Legal Basis (primarily for UK GDPR; similar principles apply elsewhere)

To Respond to Inquiries

Contact Information

Legitimate Interest (to respond to your requests); Consent (if requested via specific opt-in)

To Provide & Improve Our Site

Contact Information, Log Data, Cookie Data

Legitimate Interest (to operate, maintain, and improve our website and user experience)

Marketing & Communications

Contact Information, Cookie Data

Consent (for newsletters/marketing emails, where required by law, e.g., non-existing clients); Legitimate Interest (to market related services to existing contacts/clients, with opt-out)

Analytics & Site Performance

Log Data, Cookie Data (often anonymized/aggregated)

Legitimate Interest (to understand site usage and improve performance)

Recruitment & Hiring

Recruitment Information

Consent (provided by you when applying); Legitimate Interest (to process applications); Necessary steps prior to entering into a contract

Security & Fraud Prevention

Log Data, Contact Information, Cookie Data

Legitimate Interest (to protect our Site, systems, and users); Legal Obligation

Legal & Regulatory Compliance

All relevant categories

Legal Obligation (to comply with applicable laws, regulations, or legal processes)

We will only use your personal information for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason compatible with the original purpose. If we need to use your personal information for an unrelated purpose, we will notify you and explain the legal basis which allows us to do so.

4. Information Sharing and Disclosure

We do not sell your personal information in the traditional sense. However, under some laws (like CCPA/CPRA), certain sharing of data for analytics or advertising purposes might be considered a “sale” or “sharing.” We may disclose your personal information to the following categories of third parties:

  • Service Providers: We engage third-party companies and individuals to perform services on our behalf, such as website hosting, data analysis, marketing automation, email delivery, IT services, customer relationship management (CRM), and recruitment platforms. These providers have access to your personal information only to perform these tasks on our behalf and are obligated not to disclose or use it for any other purpose. We have contracts in place requiring them to protect the data.
  • Business Partners: In some cases, we may collaborate with trusted business partners on joint marketing activities or service offerings. We will only share your information with your consent where required.
  • Legal Requirements: We may disclose your personal information if required to do so by law or in response to valid requests by public authorities (e.g., a court, government agency, regulator).
  • Business Transfers: If Exceleris is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or a portion of its assets, your personal information may be transferred as part of that transaction. We will notify you via email and/or a prominent notice on our Site of any change in ownership or uses of your personal information.
  • Protection of Rights: We may disclose information where we believe it necessary to investigate, prevent, or take action regarding illegal activities, suspected fraud, situations involving potential threats to the physical safety of any person, violations of our terms of service, or as otherwise required by law.

5. International Data Transfers

Exceleris Consulting operates internationally, and your personal information may be processed in countries other than your country of residence, including Australia, the United Kingdom, the United States, and potentially other locations where our service providers operate. These countries may have data protection laws that are different from the laws of your country.

  • For UK/EEA Residents: When we transfer your personal information outside the UK or European Economic Area (EEA), we ensure a similar degree of protection is afforded to it by implementing appropriate safeguards. This may include:
    • Transferring data to countries deemed to provide an adequate level of protection by the UK Secretary of State or European Commission.
    • Using specific contracts approved for use in the UK (such as the International Data Transfer Agreement or Addendum) or by the European Commission (Standard Contractual Clauses).
  • For Australian Residents: If we disclose personal information to overseas recipients (e.g., service providers outside Australia), we take reasonable steps to ensure that the overseas recipient complies with the Australian Privacy Principles (APPs), or we ensure the transfer is otherwise compliant with APP 8 (Cross-border disclosure of personal information).

General: By using our Site or providing us with your information, you consent to the transfer, processing, and storage of your information in countries outside your country of residence, subject to the safeguards described above.

6. Data Security

We have implemented appropriate technical and organizational security measures designed to protect the security of the personal information we process. These measures include access controls, encryption (where appropriate), firewalls, regular security assessments, and staff training. However, please remember that no method of transmission over the Internet or method of electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your personal information, we cannot guarantee its absolute security.

7. Data Retention

We will retain your personal information only for as long as is necessary for the purposes set out in this Privacy Policy, unless a longer retention period is required or permitted by law (such as for tax, accounting, or other legal requirements).

The criteria used to determine our retention periods include:

  • The duration of our relationship with you or the provision of services.
  • Whether there is a legal obligation to which we are subject (e.g., certain laws require us to keep records for a certain period).
  • Whether retention is advisable in light of our legal position (such as in regard to applicable statutes of limitations, litigation, or regulatory investigations).
  • The ongoing relevance of the data for the purpose it was collected.
  • For marketing data based on consent, until you withdraw your consent.

 

When we no longer need your personal information for the stated purposes, we will securely delete or anonymize it.

8. Your Privacy Rights

Depending on your location, you may have certain rights regarding your personal information. These may include:

  • Right to Access / Know: You may have the right to request access to the personal information we hold about you and details about how we process it.
  • Right to Rectification / Correction: You have the right to request correction of inaccurate or incomplete personal information.
  • Right to Erasure / Deletion: You may have the right to request the deletion of your personal information under certain conditions (e.g., it’s no longer necessary for the purpose it was collected, you withdraw consent).
  • Right to Restrict Processing: You may have the right to request the restriction of processing of your personal information under certain circumstances.
  • Right to Data Portability: (Mainly UK GDPR) You may have the right to receive your personal information in a structured, commonly used, and machine-readable format and to transmit it to another controller.
  • Right to Object: (Mainly UK GDPR) You have the right to object to the processing of your personal information based on legitimate interests or for direct marketing purposes.
  • Right to Withdraw Consent: Where we rely on consent as the legal basis for processing, you have the right to withdraw your consent at any time. Withdrawal will not affect the lawfulness of processing before withdrawal.
  • Right to Opt-Out of Sale / Sharing (CCPA/CPRA): California residents have the right to opt-out of the “sale” or “sharing” of their personal information. While we don’t sell data in the traditional sense, certain cookie usage might qualify.
  • Right to Limit Use of Sensitive Personal Information (CCPA/CPRA): If we collect sensitive personal information (as defined by CCPA/CPRA), California residents have the right to limit its use. We generally do not collect sensitive personal information via the public website, except potentially in recruitment contexts where necessary and with explicit notice/consent.
  • Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights.
  • Right to Lodge a Complaint:
    • UK: You have the right to lodge a complaint with the Information Commissioner’s Office (ICO) (www.ico.org.uk).
    • Australia: You have the right to lodge a complaint with the Office of the Australian Information Commissioner (OAIC) (www.oaic.gov.au).
    • Other Jurisdictions: You may have the right to complain to your local data protection authority.

How to Exercise Your Rights: To exercise any of these rights, please contact us using the details provided in Section 13 (“Contact Information”). We will respond to your request in accordance with applicable laws. We may need to verify your identity before processing your request. If you are a California resident, you may designate an authorized agent to make a request on your behalf.

9. Cookies and Tracking Technologies

We use cookies and similar tracking technologies (like web beacons or pixels) to collect and use personal information about you, including to analyse trends, administer the website, track users’ movements around the website, gather demographic information about our user base, and potentially for interest-based advertising (if applicable).

  • What are Cookies? Cookies are small data files placed on your device when you visit a website.
  • Types of Cookies We Use: We may use essential cookies (necessary for site function), performance/analytics cookies (to understand usage), functional cookies (to remember choices), and potentially marketing/targeting cookies (to deliver relevant ads).
  • Your Choices: Most web browsers allow you to control cookies through their settings preferences. You can usually set your browser to refuse cookies or alert you when cookies are being sent. However, if you disable cookies, some parts of our Site may not function properly. We may also provide a cookie consent management tool on our Site where required by law, allowing you to manage your non-essential cookie preferences.
  • Do Not Track: Some web browsers offer a “Do Not Track” (“DNT”) signal. Currently, there is no industry standard for responding to DNT signals, so our Site does not currently respond to DNT signals.

10. Children's Privacy

Our Site is not intended for use by children under the age of 16 (or the relevant age of digital consent in your jurisdiction). We do not knowingly collect personal information from children under 16. If we become aware that we have collected personal information from a child under 16 without verification of parental consent, we will take steps to delete that information. If you believe we might have any information from or about a child under 16, please contact us.

11. Links to Other Websites

Our Site may contain links to other websites that are not operated by us. If you click on a third-party link, you will be directed to that third party’s site. We strongly advise you to review the Privacy Policy of every site you visit. We have no control over and assume no responsibility for the content, privacy policies, or practices of any third-party sites or services.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the “Effective Date” and “Last Updated” dates at the top. We encourage you to review this Privacy Policy periodically for any changes.

13. Contact Information

If you have any questions, comments, or concerns about this Privacy Policy or our data practices, or if you wish to exercise your privacy rights, please contact us at:

Exceleris Consulting Pty Ltd
903/50 Clarence StreetSydney, NSW 2000Australia

Email:  enquiries@excelerisconsulting.com