Privacy Policy
Serata Pty Limited (ACN 629 385 511), including its Availe AI practice
Version 1.0 – adopted by the Board of Directors on 7 October 2026. Reviewed annually and whenever our services, systems or legal obligations change.
1. About this policy
Serata Pty Limited (Serata, we, us) is a Canberra-based digital and AI consultancy providing service design, user experience, digital strategy, web and Drupal/GovCMS development, AI advisory and implementation, and specialist personnel to Australian Government agencies and other organisations. This policy explains how we manage personal information in line with the Privacy Act 1988 (Cth) (Privacy Act) and the Australian Privacy Principles (APPs). It applies to everyone who works for or with Serata, including directors, employees, contractors and subcontractors.
When we deliver services under a contract with a Commonwealth agency, we act as a contracted service provider. We comply with the APPs as if we were an agency, with the privacy, security and data-handling terms of that contract, and with any lawful directions from the agency. Where those terms are stricter than this policy, the contract terms apply.
2. Personal information we collect
We collect only the personal information we reasonably need for our functions and activities (APP 3). This may include:
· Clients and stakeholders – names, roles, organisations and work contact details.
· Job applicants, employees, contractors and Key Personnel – CVs, qualifications, work history, referee reports, security clearance status, tax, superannuation and payment details, and emergency contacts.
· Research and testing participants – contact details, demographic information relevant to the research, responses, recordings and consent records. Participation is voluntary and based on informed consent.
· Website and enquiry users – information you send us and limited technical data such as browser type and pages visited.
· Client data – personal information held in an agency's systems or content that we access only to deliver contracted services.
We collect sensitive information (such as health information or information about racial or ethnic origin) only with consent and where reasonably necessary, or where required or authorised by law – for example, inclusive user research with consenting participants or pre-employment security clearance processes (APP 3.3). You may deal with us anonymously or using a pseudonym where that is lawful and practicable, such as in surveys and some research activities (APP 2).
3. How we collect personal information
We collect personal information directly from you wherever we can – through correspondence, meetings, research sessions, forms, our websites and recruitment processes. We may also collect it from third parties such as clients, referees, recruitment partners, clearance agencies and publicly available sources, where it is unreasonable or impracticable to collect it from you directly. When we collect personal information we take reasonable steps to tell you who we are, why we are collecting it and how to contact us (APP 5). If we receive unsolicited personal information we do not need, we destroy or de-identify it where lawful (APP 4).
4. How we use and disclose personal information
We use and disclose personal information for the primary purpose for which it was collected, for related purposes you would reasonably expect, with your consent, or where required or authorised by law (APP 6). These purposes include delivering and managing our services, recruiting and engaging personnel, conducting user research and testing, responding to tenders and meeting contractual obligations, administering payments, and meeting legal, tax and work health and safety requirements.
We may disclose personal information to clients (for example, CVs of nominated personnel), subcontractors and partners who help deliver our services, professional advisers, insurers, government agencies and IT service providers. Subcontractors are bound by written agreements that flow down our privacy, security and confidentiality obligations. We do not sell personal information and we do not use it for direct marketing without consent and an easy way to opt out (APP 7). We do not adopt government-related identifiers as our own identifiers (APP 9).
5. Artificial intelligence
We use AI systems in line with our AI Use Procedure and, on Commonwealth contracts, only with the prior written approval required by the contract. We do not input personal information into an AI system unless that use has been expressly approved, and we never allow client data or personal information to be used to train or improve AI models. AI outputs are reviewed by a qualified person before use.
6. Storage, security and overseas disclosure
We take reasonable steps to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure (APP 11). Our controls include role-based access, multi-factor authentication, encryption in transit and at rest, secure Australian-hosted cloud services, security-cleared personnel where required, and secure disposal. Client and Commonwealth data is held within the systems and locations the client approves and is not moved outside Australia without written approval. We destroy or de-identify personal information when it is no longer needed, unless we are required to keep it by law or contract.
Some of our business systems are provided by reputable cloud providers that may store or process data in other countries. Before any personal information is disclosed overseas, we take reasonable steps to ensure the recipient handles it consistently with the APPs (APP 8).
7. Quality, access and correction
We take reasonable steps to keep personal information accurate, up to date and complete (APP 10). You may ask to access or correct the personal information we hold about you (APPs 12 and 13). We will respond within 30 days and will not charge for a request. If we refuse access or correction, we will tell you why in writing and how to complain. Requests relating to information we hold for a Commonwealth agency are handled with, or referred to, that agency.
8. Data breaches
We maintain a data breach response plan. If we suspect a data breach we act immediately to contain and assess it. Where a breach is likely to result in serious harm, we notify affected individuals and the Office of the Australian Information Commissioner (OAIC) under the Notifiable Data Breaches scheme. On Commonwealth contracts we notify the relevant agency immediately and follow its directions.
9. Questions and complaints
Please contact us via the contact us form
We will acknowledge a complaint within five business days and aim to resolve it within 30 days. If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner at www.oaic.gov.au or on 1300 363 992.