Client Portal Privacy Notice
Version 1.0, effective 20 July 2026 | Cameron Facilities Pty Ltd ABN 17 639 270 947 | 396 Walcott Street, Mount Lawley WA 6050
This notice explains how Cameron Facilities Pty Ltd ("Cameron Facilities", "we", "us", "our") collects and handles personal information when you use the SiteIQ client portal. It supplements, and should be read together with, the Cameron Facilities Privacy Policy. We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
1. What We Collect Through the Portal
- Account details: your name, work email address, organisation, portal role, and, where provided for sign-in verification, a mobile number.
- Sign-in and security records: login attempts, session details, and security events, kept to protect your account and our platform.
- Activity records: an audit trail of actions taken in the portal (for example viewing, creating, or exporting records), kept for accountability and security.
- Content you submit: work requests, support tickets, messages, and documents you upload or send through the portal.
2. Why We Collect It
- To operate the portal and provide the contracted facilities management services to your organisation.
- To secure the platform, verify sign-ins, and investigate suspicious activity.
- To respond to your requests, tickets, and communications.
- To meet our legal and contractual obligations, including record-keeping requirements.
3. Cookies
The portal uses essential cookies only: a sign-in session cookie and security protections. We do not use advertising or tracking cookies on the portal.
4. Where Your Information Is Stored
Portal data is hosted on Microsoft Azure infrastructure in Australian data centre regions. Backups are maintained and periodically restore-tested. Some of our service providers, as listed in our Privacy Policy, may store limited data on servers located outside Australia; before disclosing information to overseas recipients we take reasonable steps to ensure they do not breach the APPs.
5. Who Can See Your Information
- Your organisation: portal records relating to your organisation are visible to your organisation's authorised portal users, according to their access level.
- Cameron Facilities staff: on a need-to-know basis, controlled by role-based permissions.
- Other clients: never. Each client's data is isolated to that client's portal, and this isolation is enforced on every request.
6. Service Providers
We use a small number of service providers to run the platform: Microsoft Azure (hosting), Microsoft 365 (email delivery), Xero (accounting and invoicing), n8n (workflow automation), and Anthropic (AI-assisted features, where used). These providers process data only as needed to provide their services. Details are in our Privacy Policy.
7. Data Handling Statement
This statement summarises how portal data is protected in practice:
- Encryption: all portal traffic is encrypted in transit (HTTPS/TLS), and data is encrypted at rest on Azure infrastructure.
- Passwords: stored only as cryptographic hashes, never in plain text.
- Access control: every request is authenticated and authorised against role-based permissions, and every query is scoped to your organisation, so one client's data is never served into another client's view.
- Multi-factor authentication: supported for portal accounts and required for Cameron Facilities staff.
- Sessions: portal sessions expire automatically after a period of inactivity.
- Audit logging: significant actions, including data exports, are recorded in an audit trail.
- Retention: records are kept for the periods described in our Privacy Policy and the platform's data retention schedule, then deleted or de-identified.
- Data breach response: if a data breach is likely to result in serious harm, we will comply with the Notifiable Data Breaches scheme, including notifying affected individuals and the OAIC.
8. Access, Correction, and Export
You may request access to, or correction of, personal information we hold about you at any time by contacting our Privacy Officer. Authorised client administrators can also export their organisation's portal data directly using the Data Export feature in the portal, consistent with APP 12. We respond to access requests within 30 days.
9. Complaints
If you believe we have breached the Australian Privacy Principles, contact our Privacy Officer first and we will investigate and respond within 30 days. If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (www.oaic.gov.au, phone 1300 363 992).
10. Contact, Privacy Officer