Privacy Policy
Last updated: 28 August 2026
RiskRinger is committed to protecting the privacy, confidentiality and security of personal information entrusted to us.
This Privacy Policy explains how we collect, use, store, disclose and protect personal information when you visit the RiskRinger website, communicate with us, or use the RiskRinger platform and related services.
Where applicable, we handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
1. Information We Collect
The information we collect depends on how you interact with RiskRinger.
Website and enquiry information
When you visit our website, request information, book a demonstration, attend a workshop or contact us, we may collect information such as:
- your name;
- business email address;
- telephone number;
- company or organisation;
- position or job title;
- information contained in enquiries or correspondence; and
- technical information relating to your interaction with our website.
Account information
When an organisation uses RiskRinger, we may collect information required to establish, administer and support user accounts, including:
- name;
- work contact details;
- organisation;
- role or position;
- account permissions and access information; and
- platform activity and security logs.
Information processed through the RiskRinger platform
RiskRinger enables organisations to manage operational risk, safety, quality, environmental, compliance and assurance activities.
Depending on how a customer configures and uses the platform, information entered into RiskRinger may include information associated with:
- incidents and safety reports;
- hazards and risk assessments;
- investigations and corrective actions;
- audits and inspections;
- training and competency records;
- compliance and assurance activities;
- supporting documents and evidence; and
- individuals involved in, or associated with, these activities.
Our customers determine the information they enter into the RiskRinger platform and are responsible for ensuring that their collection and use of that information is lawful and appropriate.
2. Why We Collect and Use Information
We may collect, hold and use personal information to:
- provide and operate the RiskRinger platform;
- establish and administer customer and user accounts;
- respond to enquiries and provide demonstrations;
- deliver implementation, training and customer support;
- maintain the security, reliability and performance of our services;
- diagnose technical problems and improve our products;
- manage our commercial relationships;
- communicate important service, security or administrative information;
- provide information about RiskRinger products and services where permitted by law;
- comply with legal and regulatory requirements; and
- protect the rights, security and legitimate interests of RiskRinger, our customers and users.
We aim to collect only information that is reasonably necessary for our functions and activities.
3. Customer Data
Organisations using RiskRinger retain responsibility for the information they submit to and manage through the platform.
We do not claim ownership of customer operational data simply because it is stored or processed through RiskRinger.
We access or process customer data only where reasonably necessary to provide, secure, maintain or support the service, fulfil contractual obligations, comply with applicable law, or where authorised by the customer.
Where an individual wishes to access, correct or raise a concern regarding information that has been entered into RiskRinger by their employer or another organisation, the request may need to be directed to that organisation in the first instance.
4. Disclosure of Information
We do not sell personal information.
We may disclose information where reasonably necessary to:
- service providers that assist us in operating and supporting RiskRinger;
- hosting, infrastructure, communications, security, analytics or support providers;
- professional advisers such as legal, accounting or insurance advisers;
- comply with a lawful request, court order or regulatory requirement;
- investigate or prevent fraud, security incidents or unlawful activity; or
- facilitate a corporate transaction such as a restructuring, acquisition or transfer of business, subject to appropriate safeguards.
Service providers are expected to handle information only for authorised purposes and subject to appropriate confidentiality, privacy and security obligations.
5. Overseas Disclosure and Data Processing
Some technology or service providers supporting RiskRinger may process or store information outside Australia.
Where personal information is disclosed to overseas recipients, RiskRinger will take appropriate steps required under applicable privacy law in relation to that disclosure.
6. Information Security
Protecting customer and personal information is an important part of the way RiskRinger operates.
We maintain reasonable technical and organisational measures designed to protect information against unauthorised access, misuse, interference, loss, alteration and disclosure.
These measures may include access controls, authentication mechanisms, system monitoring, backups, logging and other administrative and technical safeguards appropriate to the nature of the information and the services being provided.
No online system can guarantee absolute security. We continually assess and improve our security practices as technologies, risks and regulatory expectations evolve.
7. Data Retention
We retain personal information only for as long as reasonably necessary for the purposes for which it was collected, to provide our services, meet contractual requirements, resolve disputes, maintain appropriate business records or comply with legal obligations.
Customer data is retained and managed in accordance with the applicable customer agreement and RiskRinger's data management practices.
Where information is no longer required, we take reasonable steps to securely delete, destroy or de-identify it where appropriate and permitted by law.
8. Cookies, Analytics and Website Information
The RiskRinger website may use cookies and similar technologies to support website functionality, understand how visitors interact with the site, maintain security and improve the user experience.
These technologies may collect information such as browser type, device information, IP address, pages visited and interaction information.
You may be able to restrict or disable cookies through your browser settings, although some website functionality may be affected.
9. Marketing Communications
Where permitted, we may use business contact information to communicate with you about RiskRinger products, services, demonstrations, workshops, updates and other relevant information.
You may opt out of marketing communications at any time using the unsubscribe option contained in the communication or by contacting us.
We may still send service-related, security, contractual or administrative communications where these are necessary for an existing relationship with you or your organisation.
10. Access and Correction
You may request access to personal information we hold about you or ask us to correct information that is inaccurate, incomplete or out of date.
We may need to verify your identity before processing a request.
In some circumstances, applicable law may permit or require us to refuse access. If this occurs, we will provide an explanation where required.
For information submitted to RiskRinger by one of our customers, we may refer your request to the relevant customer organisation.
11. Data Breaches
RiskRinger takes suspected privacy and security incidents seriously.
Where a data breach involving personal information occurs, we will assess and respond to the incident in accordance with applicable legal requirements, including the Notifiable Data Breaches scheme where it applies.
Where notification is legally required, affected individuals and the Office of the Australian Information Commissioner will be notified as required.
12. Privacy Complaints
If you have a concern about the way RiskRinger has handled your personal information, please contact us so that we can investigate and respond.
Please provide sufficient information for us to understand the nature of your concern.
We will endeavour to acknowledge and investigate privacy complaints within a reasonable period.
If you are not satisfied with our response, you may have the right to make a complaint to the Office of the Australian Information Commissioner (OAIC).
13. Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect changes to our services, technology, business practices or legal requirements.
The current version will be published on the RiskRinger website and the "Last updated" date will be revised accordingly.
We encourage users to review this page periodically.
