1. Introduction

Green Light Australia Pty Ltd and its associated entities (‘Green Light’, ‘we’, ‘us’ or ‘our’) operate as an APP entity as defined under the Privacy Act 1988 (Cth) (‘Privacy Act’). We are an outcomes focused service provider that delivers technology capability ‘on demand’ across Australia.

This Privacy Policy explains how Green Light collects, uses, stores and discloses personal information, including information collected through our website, through engagements with us, and via third-party systems where you have consented to the collection of your information. This policy applies to all personal information collected in connection with:

  • The delivery of managed services, consulting, and professional services engagements;
  • Recruitment, management and payroll of employees and contractors
  • Interactions with clients, suppliers, contractors, and other business partners;
  • Access to and use of our website, client portals, and digital platforms; and
  • Any other activities undertaken in the ordinary course of our business.

By interacting with Green Light, using our website, or providing personal information to us, you acknowledge that you have read and understood this Privacy Policy and consent to the collection, use, and disclosure of your personal information as described herein.

 

2. Definitions

The following key terms are used throughout this Privacy Policy:

Term Meaning
Personal Information Information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether true or not and whether in a material form or not, as defined in the Privacy Act 1988 (Cth).
Sensitive Information A subset of personal information including racial or ethnic origin, political opinions, religious beliefs, health information, biometric data, criminal records, and other categories specified in the Privacy Act.
APP Australian Privacy Principle — one of the thirteen principles set out in Schedule 1 of the Privacy Act 1988 (Cth).
Candidate An individual who has submitted an expression of interest, application, resume or CV, or who has otherwise engaged with us in connection with a potential employment, contract, or placement opportunity.
Client An organisation or individual that engages or has engaged Green Light to deliver technology resourcing, managed services, or professional services.
Related Entities Any entity that is related to Green Light Australia Pty Ltd within the meaning of the Corporations Act 2001 (Cth). Any Green Light controlled, affiliated, subsidiary, parent or related business entity operating in Australia, New Zealand, Singapore, Hong Kong or the Philippines.
Third Party Any person or organisation that is not the individual to whom the personal information relates and is not Green Light.

 

3. What Personal Information We Collect

Green Light may collect personal information that is reasonably necessary for our business functions and activities. The type of information collected depends on your interaction with us and the nature of the engagement.

3.1 Applicant Information for Employment

When you apply for a role, register with us as a candidate, or are referred to us, we may collect:

  • Full name, date of birth, and contact details (address, phone number, email address);
  • Employment history, qualifications, educational background, professional certifications, and skills;
  • Resume or CV, cover letters, and portfolio materials;
  • References and details of referees;
  • Right-to-work documentation, including copies of visas, passports, or other identity documents;
  • Results of background verification checks, including criminal history checks (where legally permissible and with your consent), qualification verifications, and professional licence confirmations;
  • Remuneration history and expectations;
  • Career goals, availability, and work preferences; and
  • Any other information you choose to provide in connection with a role or engagement.

3.2 Client and Contact Information

When we engage with client organisations, we may collect personal information about client representatives, including:

  • Name, position title, employer, and professional contact details;
  • Information provided during service delivery, including instructions and feedback;
  • Billing and invoicing information; and
  • Personal information voluntarily shared during meetings or correspondence.

3.3 Contractor and Supplier Information

For individuals engaged as contractors, or organisations providing services to us, we may collect:

  • Contact and identification information;
  • Bank account and payment details;
  • Tax file numbers and superannuation details, where required by law;
  • Insurance and licence documentation; and
  • Performance-related information arising during an engagement.

3.4 Website and Platform Users

When individuals interact with our website or digital platforms, we may collect:

  • Contact details voluntarily submitted via forms or enquiries;
  • IP address, browser type and version, operating system, and referring URLs;
  • Pages viewed, time and duration of visits, and usage data; and
  • Cookie and tracking data as described in Section 10 below.

3.5 Information Received from Third Parties

In some circumstances, we may receive personal information from third-party systems or service providers where you have provided consent, including recruitment or service delivery platforms. We may also collect information from referees, background check providers, and professional networking platforms where information is publicly available, or you have indicated openness to contact.  Where personal information is provided to Green Light by a third party, we will take reasonable steps to ensure the third party had authority to disclose that information to us.

3.6 Sensitive Information

Sensitive personal information, such as identification documents, bank details, tax details, pension details, background check results, and employment-related health information, may be required as part of application processing or the delivery of services. We only collect sensitive information where we have your express consent and the collection is reasonably necessary, or where we are otherwise authorised or required to do so by law. Sensitive information is handled using secure channels, processes, and systems to always protect your personal information throughout its lifecycle.

 

4. How We Collect Personal Information

We collect personal information through lawful, fair, and transparent means, and only for the purpose for which it is intended. We collect personal information only through secure systems and channels appropriate to that purpose.

4.1 Direct Collection

In most circumstances, we collect personal information from you when you:

  • Submit an application, resume, or expression of interest through our website, portal, or directly to our consultants;
  • Complete registration, onboarding, or engagement documentation;
  • Correspond with us by email, phone, video conference, or in person;
  • Respond to our requests in the course of service delivery; or
  • Subscribe to our communications or .

4.2 Collection via Secure Systems and Channels

All personal information is collected through secure systems and channels, including:

  • Encrypted online forms and candidate portals protected by industry-standard TLS/HTTPS protocols;
  • Secure email communication with virus scanning and content filtering;
  • Access-controlled recruitment and applicant tracking systems (ATS) with role-based permissions;
  • Video conferencing platforms subject to data processing agreements; and
  • Physical document handling procedures with secure storage and controlled access.

We collect only the personal information reasonably necessary for our business activities and use it only for the purposes for which it was collected, unless otherwise permitted or required by law.

4.3 Collection from Third Parties

We may also collect personal information from third parties, including referees nominated by candidates, background check and verification providers, professional networking platforms, recruitment partner organisations, and government or licensing bodies. Where we collect personal information from third parties, we take reasonable steps to ensure the collection is lawful and consistent with this policy, and we will, where practicable, notify you.

 

5. Use of Personal Information

Personal information is used only for purposes reasonably related to why it was collected, or for directly related secondary purposes that you would reasonably expect, or as permitted or required by law.

5.1 Applicant Information

We use candidate personal information to:

  • Assess suitability for current and future employment, contract, or opportunities;
  • Conduct background, reference, and verification checks with your consent;
  • Match your skills, experience, and preferences to requirements;
  • Communicate with you regarding opportunities and application progress;
  • Maintain a talent database for future opportunities;
  • Administer engagements, including payroll and performance management; and
  • Comply with legal obligations, including right-to-work verification, tax reporting, and superannuation.

5.2 Client and Service Delivery

We use client and service-related personal information to:

  • Deliver the technology resourcing, managed services, and consulting services engaged;
  • Administer contracts and manage client relationships;
  • Process invoices and manage accounts; and
  • Identify and propose suitable candidates or solutions for client needs

5.4 Direct Marketing

Green Light may use personal information to communicate with current or prospective clients, contractors and candidates regarding services, employment opportunities, industry insights, events and business updates.

All marketing communications will be conducted in accordance with applicable privacy and electronic communications laws and will include an opportunity to opt out of future communications. If you want to request communications at any time, please contact at privacy@greenlightworldwide.com or any unsubscribe function with the relevant marketing communication.

5.5 Business Operations

We may also use personal information to maintain and improve our internal systems, conduct aggregated or de-identified data analytics, manage legal and commercial risk, and respond to regulatory inquiries or legal proceedings.

 

6. Disclosure of Personal Information

Personal information is protected from unauthorised disclosure and is not sold or traded to third parties for any purpose. We disclose personal information only as necessary and only to parties with a legitimate need in connection with the purpose for which it was collected, or as otherwise required or permitted by law.

6.1 Disclosure to Clients

In connection with our delivery of services to our clients, we may disclose candidate personal information to prospective or current clients for the purpose of assessing suitability for a role or project engagement. We take reasonable steps to ensure clients handle such information consistently with the APPs, including through contractual obligations.

6.2 Disclosure to Third-Party Service Providers

We engage third-party service providers to support our operations. These may include background check and verification providers, payroll and workforce management platforms, cloud hosting and IT infrastructure providers, and professional services advisers. We require these providers to handle personal information securely and only for the purposes for which it is disclosed.

6.3 Legal and Regulatory Disclosure

Disclosure may occur to regulators or law enforcement where required or authorised by law, including compliance with legal obligations, court orders, or regulatory requirements. We may also disclose personal information where necessary to prevent or investigate suspected fraud or to protect an individual’s life, health, or safety.

6.4 Related Entities

We may share personal information with related entities of Green Light Australia Pty Ltd for purposes consistent with this policy and our ordinary business operations.

6.5 Overseas Disclosure

Green Light operates across multiple countries, and personal information may be accessed, processed or stored by Green Light entities, employees, contractors or service providers located in:

  • Australia
  • New Zealand
  • Singapore
  • Hong Kong
  • Philippines

Personal information may also be processed by trusted technology and cloud service providers that operate internationally.

Where personal information is transferred across borders, Green Light takes reasonable steps to ensure appropriate security, privacy and contractual protections are maintained in accordance with applicable privacy laws.

6.6 Intra-Group Sharing

Green Light may share personal information between its related entities in Australia, New Zealand, Singapore, Hong Kong and the Philippines where necessary for:

  • recruitment activities;
  • contractor management;
  • payroll administration;
  • service delivery;
  • sales and account management;
  • legal and compliance functions; and
  • internal business administration.

Such sharing will only occur where reasonably necessary and subject to appropriate privacy safeguards.

 

7. Security of Personal Information

We take all reasonable steps to protect personal information from misuse, interference, and loss, and from unauthorised access, modification, and disclosure throughout its lifecycle, from collection through to secure destruction or de-identification.

7.1 Our Security Measures

Our security practices include:

  • Encryption of data in transit using TLS/HTTPS protocols across all digital channels;
  • Encryption of data at rest within our systems and those of our key service providers;
  • Role-based access controls ensuring personal information is accessible only to staff with a legitimate need;
  • Multi-factor authentication (MFA) for access to systems holding personal information;
  • Regular security assessments and vulnerability management;
  • Staff training on privacy obligations and appropriate data handling;
  • Physical security measures for personal information held in physical form; and
  • Secure disposal and destruction procedures for information no longer required.

Personal information may be stored electronically within Green Light systems or approved cloud environments located in Australia or other jurisdictions in which Green Light operates. Security controls apply regardless of storage location.

7.2 Supplier Relationships and Vendor Assessment

We recognise that the security of personal information extends to the third-party platforms and providers we rely upon. We carefully assess the security and privacy practices of our technology vendors and service providers to ensure they align with the requirements of the Privacy Act and our own obligations.

Our vendor assessment and management process includes:

  • Data risk assessment prior to engaging any provider that will access, process, or store personal information;
  • Review of vendor privacy policies, data processing agreements, and security certifications (such as ISO 27001, SOC 2, or equivalent);
  • Contractual data processing agreements imposing obligations regarding security, confidentiality, use limitation, and breach notification;
  • Data resides in Australia for core systems
  • Ongoing monitoring of vendor compliance
  • Review of vendor practices annually, or when significant changes occur.

We will only engage a vendor where we are satisfied that its practices provide an appropriate level of protection for the personal information concerned.

7.3 Data Breach Response

In the event of a data breach likely to result in serious harm to affected individuals, we will comply with our obligations under the Notifiable Data Breaches (NDB) scheme. This includes notifying the Office of the Australian Information Commissioner (OAIC) or local equivalent and affected individuals as soon as practicable.

Individuals may also lodge complaints with the relevant privacy authority in the jurisdiction in which they reside or where the relevant Green Light entity operates.

 

8. Data Governance and Retention

8.1 Quality and Accuracy

Measures are in place to ensure the personal information we hold is accurate, up to date, and complete. We take reasonable steps to maintain the quality of information and encourage individuals to notify us of any changes to their personal information. You can update your information by contacting us at privacy@greenlightworldwide.com.

8.2 Retention Periods

Personal information is retained only for as long as necessary for the purpose for which it was collected, or as required by applicable laws and regulations. Client and Contractor records are generally retained for seven years in accordance with the Australian Taxation Office’s record-keeping requirements.

8.3 Destruction and De-identification

When personal information is no longer required, we will take reasonable steps to destroy it securely or de-identify it, consistent with our security obligations. You may request for your data to be deleted at any time by emailing

 

9. Access and Correction

9.1 Access to Your Personal Information

Individuals may request access to the personal information Green Light holds about them. We will respond to access requests within a reasonable time. We may charge a reasonable fee where costs are incurred. In limited circumstances permitted by law, we may decline to provide access and will provide reasons and information about how to complain about the decision.

9.2 Correction of Personal Information

If you believe personal information we hold is inaccurate, out of date, incomplete, irrelevant, or misleading, you have the right to request a correction. We will take reasonable steps to correct the information within 30 days. Where we cannot agree that a correction is warranted, we will advise you of our reasons and your right to complain.

9.3 Withdrawal of Consent

Where we rely on your consent to handle personal information, you may withdraw that consent at any time by contacting us. Withdrawal of consent will not affect the lawfulness of prior processing but may affect our ability to provide certain services.

9.4 Anonymity

Where lawful and practicable, we provide individuals with the option to interact with us anonymously or under a pseudonym. However, for core activities such as employment, verification checks, and service delivery under contract, it is generally not practicable to deal on an anonymous basis, and we will explain why identification is required.

9.5 Data Subject Rights

Depending on your location and applicable laws, you may have rights to:

  • access your personal information;
  • correct inaccurate information;
  • request deletion of information;
  • withdraw consent;
  • restrict or object to certain processing activities;
  • lodge a complaint with a relevant privacy regulator.
  • Green Light will respond to requests in accordance with applicable legal requirements.

 

10. Cookies and Website Usage

Our website uses cookies to improve user experience and analyse traffic. Cookies may be disabled via browser settings, though some functionality may be limited as a result. The types of cookies we use include:

  • Strictly necessary cookies: essential to the basic functioning of our website;
  • Analytics cookies: help us understand how visitors interact with our site; and
  • Functionality cookies: allow our platforms to remember your preferences.

Information collected via our website may include contact details voluntarily submitted, IP address, browser and device information, pages viewed, and usage data. This information is used to improve our website and services and is handled consistently with this Privacy Policy.

11. External Links

Our website may contain links to third-party websites. We are not responsible for the privacy practices of those websites and encourage you to review their privacy policies independently. This Privacy Policy applies only to personal information we collect and handle.

12. Privacy Complaints

12.1 How to Make a Complaint

If you have a concern about the way we have collected, used, or disclosed your personal information, or believe we have not complied with the APPs, please contact us in writing using the details in Section 13. We take all complaints seriously and will endeavour to resolve them fairly and promptly.

12.2 Our Complaints Process

On receipt of a complaint, we will:

  • Acknowledge receipt within five (5) business days;
  • Investigate the circumstances, which may require us to seek further information from you;
  • Provide a written response, including our findings and any proposed remedial steps, within thirty (30) days; and
  • Where we uphold your complaint, take such steps as are reasonably practicable to address the matter.

12.3 Escalation to the OAIC

If you are not satisfied with our response, or if we fail to resolve your complaint within a reasonable time, you have the right to refer your complaint to the Office of the Australian Information Commissioner (OAIC).

Office of the Australian Information Commissioner (OAIC)

Website: http://www.oaic.gov.au  |  Phone: 1300 363 992  |  Post: GPO Box 5218, Sydney NSW 2001

13. Contact Us

For all privacy-related enquiries, access or correction requests, and complaints, please contact us:

Privacy Enquiries

Green Light Australia Pty Ltd and its related entities

Email: privacy@greenlightworldwide.com

Website: http://www.greenlightworldwide.com

 

14. Changes to This Policy

This Privacy Policy may be updated from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. The current version of this policy will always be available on our website at http://www.greenlightworldwide.com. Where any changes are material, we will take reasonable steps to notify affected individuals.

We encourage you to review this policy periodically to stay informed about how we protect your personal information.

This Privacy Policy is issued by Green Light Australia Pty Ltd and is effective from Aug 2026.