Privacy Policy
How Vareon Group collects, uses, and protects personal information.
PRIVACY POLICY
Vareon Group
1. Introduction
Vareon Group (ABN/ACN to be inserted) ("Vareon", "we", "us", or "our") is committed to protecting the privacy and security of personal information. This Privacy Policy describes how we collect, use, store, disclose, and protect personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
This Privacy Policy applies to all personal information collected through our website at vareonhq.com (the "Site"), our services, and any related communications. By accessing or using our Site or services, you acknowledge that you have read, understood, and consent to the collection, use, and disclosure of your personal information as described in this Privacy Policy.
We reserve the right to update this Privacy Policy at any time. Your continued use of our Site or services following any changes constitutes acceptance of those changes.
2. Personal Information We Collect
We collect and process various categories of personal information depending on your interaction with our services. The types of personal information we may collect include:
Identity and Contact Information:
- Full name, job title, and professional designation
- Business and personal email addresses
- Telephone and mobile numbers
- Company name, business address, and organizational details
Business and Operational Information:
- Business processes, operational workflows, and organizational structures
- Technical documentation and system specifications
- Project requirements, objectives, and deliverables
- Data provided for automation engineering and consulting services
Technical and Usage Information:
- Internet Protocol (IP) addresses and geolocation data
- Browser type, version, and configuration settings
- Device identifiers and operating system information
- Pages visited, time spent on pages, and navigation patterns
- Referral sources and exit pages
Communications and Correspondence:
- Inquiry content submitted through contact forms
- Email correspondence, meeting notes, and consultation records
3. How We Collect Information
We collect personal information through multiple channels:
Direct Collection:
- Information you provide when completing contact forms on our Site
- Data submitted during service engagement, project onboarding, or consultation processes
- Communications via email, telephone, or video conferencing
- Documents, specifications, and materials provided for project delivery
Automated Collection:
- Cookies, web beacons, and similar tracking technologies deployed on our Site
- Server logs and analytics platforms that record website usage patterns
- Device and network information transmitted during Site access
4. How We Use Personal Data
We collect and process personal information for the following purposes:
- Service Delivery: To provide AI-driven operational consulting, automation engineering services, process optimization, and related professional services as requested or contracted
- Client Communication: To respond to inquiries, provide support, deliver project updates, and maintain ongoing client relationships
- Business Operations: To manage client accounts, process invoices, maintain records, and perform administrative functions
- Service Improvement: To analyze usage patterns, evaluate service effectiveness, enhance user experience, and develop new offerings
- Legal Compliance: To comply with applicable laws, regulations, legal processes, and enforceable governmental requests
- Security and Fraud Prevention: To protect against security threats, detect fraudulent activity, and maintain the integrity of our systems
- AI and Automation Processing: To analyze business processes using artificial intelligence models and develop customized automation solutions (subject to Section 14)
5. Legal Basis for Processing
Under Australian privacy law and for international compliance, we process personal information on the following legal bases:
- Consent: Where you have provided explicit consent for specific processing activities, which may be withdrawn at any time
- Contract Performance: Where processing is necessary to fulfill contractual obligations for services you have engaged
- Legal Obligations: Where processing is required to comply with legal or regulatory requirements
- Legitimate Interests: Where processing is necessary for legitimate business interests that do not override your fundamental rights and freedoms
7. Data Storage & Security
We implement industry-standard security measures to protect personal information against unauthorized access, alteration, disclosure, or destruction. Our security framework includes:
- Encryption of data in transit and at rest using current cryptographic standards
- Secure authentication mechanisms and access controls limiting data access to authorized personnel
- Regular security audits, vulnerability assessments, and penetration testing
- Secure data storage infrastructure with redundancy and backup protocols
- Employee training on data protection obligations and secure handling procedures
While we employ reasonable security measures, no method of electronic transmission or storage is completely secure. We cannot guarantee absolute security of personal information transmitted to or stored by us. You are responsible for maintaining the confidentiality of any credentials used to access our services.
8. Third-Party Services
To deliver our services effectively, we engage selected third-party service providers and technology platforms. Personal information may be processed by these providers solely for the purposes described in this Privacy Policy and subject to appropriate contractual safeguards.
Categories of Third-Party Services:
- Artificial Intelligence Platforms: We utilize advanced AI models and services (including but not limited to OpenAI and Anthropic platforms) to analyze business processes, generate insights, and develop automation solutions. Client data processed through these platforms is not used to train external AI models (see Section 14).
- Automation and Integration Tools: We employ workflow automation platforms (such as n8n and Zapier) to build, test, and deploy automation solutions for client engagements.
- Database and Infrastructure Services: We use database management systems (including Supabase) and cloud infrastructure providers to securely store and process client data.
- Analytics and Performance Monitoring: We utilize website analytics services to understand usage patterns and improve service delivery.
- Communication and Collaboration Tools: We use email services, video conferencing platforms, and project management tools to facilitate client communications.
All third-party service providers are carefully selected based on their security practices, compliance standards, and data protection commitments. We require these providers to implement appropriate technical and organizational measures to protect personal information and restrict its use to authorized purposes only.
10. International Data Transfers
As a business operating with global technology infrastructure, personal information may be transferred to, stored in, or accessed from jurisdictions outside Australia, including but not limited to the United States, the European Economic Area, and other countries where our service providers maintain data centers or operations.
When transferring personal information internationally, we ensure appropriate safeguards are in place, including:
- Standard contractual clauses or equivalent mechanisms approved under applicable privacy laws
- Verification that recipient jurisdictions provide adequate data protection standards
- Contractual requirements for service providers to implement equivalent security measures
By using our services, you acknowledge and consent to the international transfer of your personal information as described in this Privacy Policy. We remain accountable for personal information transferred to third parties and take steps to ensure compliance with applicable privacy obligations.
11. Data Retention
We retain personal information only for as long as necessary to fulfill the purposes for which it was collected, comply with legal obligations, resolve disputes, and enforce our agreements. Retention periods vary based on the nature of the information and applicable requirements:
- Client Engagement Data: Retained for the duration of the client relationship and for a minimum of seven years thereafter to comply with taxation and business records obligations
- Contact Form Submissions: Retained for up to three years from the date of submission, or until the inquiry is resolved and any potential service engagement is concluded
- Website Analytics Data: Retained in aggregated, anonymized form for up to 26 months for analytical and service improvement purposes
- Project Documentation: Retained for the duration required to deliver services and for a period thereafter as necessary for legal, accounting, or legitimate business purposes
Upon expiration of applicable retention periods, personal information is securely deleted or anonymized in accordance with data disposal procedures. Where legal obligations require extended retention, data is isolated and restricted to authorized access only.
12. Your Rights
Under the Privacy Act 1988 (Cth) and the Australian Privacy Principles, you have certain rights regarding your personal information:
- Right of Access: You may request access to the personal information we hold about you. We will provide a copy of your personal information in a commonly used format within a reasonable timeframe.
- Right to Correction: You may request correction of inaccurate, incomplete, or outdated personal information. We will take reasonable steps to correct the information and notify any third parties to whom the information was disclosed.
- Right to Deletion: You may request deletion of your personal information, subject to legal retention obligations and legitimate business requirements. We will assess such requests on a case-by-case basis.
- Right to Restrict Processing: You may request restriction of processing in certain circumstances, such as when contesting accuracy or objecting to processing.
- Right to Object: You may object to processing of your personal information where processing is based on legitimate interests or for direct marketing purposes.
- Right to Withdraw Consent: Where processing is based on consent, you may withdraw consent at any time. Withdrawal does not affect the lawfulness of processing prior to withdrawal.
- Right to Lodge a Complaint: You may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) if you believe we have not handled your personal information in accordance with privacy law.
To exercise any of these rights, please contact us using the details provided in Section 18. We will respond to requests within 30 days. In certain circumstances, we may decline requests where permitted or required by law, and will provide reasons for any such refusal.
We do not charge a fee for reasonable access requests or corrections. However, we reserve the right to charge an administrative fee for excessive, repetitive, or manifestly unfounded requests.
13. How We Protect Data
Data protection is fundamental to our operations. We have implemented comprehensive technical and organizational measures to safeguard personal information:
Technical Safeguards:
- Transport Layer Security (TLS) encryption for data in transit
- AES-256 encryption for data at rest in production databases
- Multi-factor authentication for administrative access
- Firewall protection and intrusion detection systems
- Regular security patches and system updates
Organizational Safeguards:
- Role-based access controls limiting data access to necessary personnel only
- Confidentiality agreements and privacy training for all staff members
- Incident response procedures for potential data breaches
- Regular review and testing of security controls
- Secure disposal procedures for data no longer required
In the event of a data breach that is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner as required under the Notifiable Data Breaches scheme, in accordance with our obligations under the Privacy Act 1988 (Cth).
14. AI & Automation Usage Disclosure
As an AI-driven operational consulting and automation engineering firm, we utilize artificial intelligence technologies as a core component of our service delivery. This section provides transparency regarding our AI usage:
How We Use AI:
- We employ advanced AI models to analyze business processes, identify optimization opportunities, and develop automation solutions tailored to client requirements
- Client-provided data, including business process documentation, operational workflows, and system specifications, may be processed through AI platforms to generate insights and recommendations
- AI technologies are used to design, test, and refine automation workflows and integration solutions
Critical Data Protection Commitment:
Client data processed through AI platforms is NOT used to train external AI models or shared with third-party model training datasets. We utilize enterprise-tier AI services with specific contractual provisions prohibiting the use of client data for model training purposes.
Data Processing Safeguards:
- All AI processing occurs within secure, controlled environments with appropriate access restrictions
- Data inputs and AI-generated outputs are subject to the same security and confidentiality protections as other client information
- We maintain audit logs of AI processing activities for accountability and compliance purposes
- AI-generated recommendations are reviewed by qualified professionals before delivery to clients
Clients retain full ownership and control over their proprietary data. AI processing is conducted solely to deliver contracted services and does not confer any rights or licenses to Vareon or third-party AI providers beyond temporary processing necessary for service delivery.
15. Children's Privacy
Our services are designed for businesses and professional organizations. We do not knowingly collect, use, or disclose personal information from individuals under the age of 18 years. Our Site and services are not directed at, marketed to, or intended for use by children.
If we become aware that we have inadvertently collected personal information from an individual under 18 years of age without appropriate parental or guardian consent, we will take immediate steps to delete such information from our records. If you believe we may have collected information from a minor, please contact us immediately using the details in Section 18.
16. Links to Other Websites
Our Site may contain links to third-party websites, services, or resources that are not owned or controlled by Vareon. This Privacy Policy applies solely to information collected by our Site and services.
We are not responsible for the privacy practices, content, or security of any third-party websites. When you navigate to a third-party site via a link from our Site, you are subject to that site's terms of service and privacy policy. We do not endorse or make representations about third-party websites.
We strongly encourage you to review the privacy policies of any third-party websites you visit to understand how they collect, use, and protect your personal information.
17. Changes to This Privacy Policy
We reserve the right to modify, update, or replace this Privacy Policy at any time to reflect changes in our practices, legal requirements, or business operations. Material changes will be communicated through prominent notice on our Site or via direct communication to affected individuals where appropriate.
The "Last Updated" date at the end of this Privacy Policy indicates when the most recent revisions were made. We encourage you to periodically review this Privacy Policy to stay informed about how we protect personal information.
Continued use of our Site or services following the posting of changes constitutes acceptance of those changes. If you do not agree to any modifications, you should discontinue use of our services and contact us to request deletion of your personal information, subject to legal retention obligations.
18. Contact Information
If you have questions, concerns, or requests regarding this Privacy Policy or our handling of personal information, or if you wish to exercise any of your rights described in Section 12, please contact us:
We will respond to your inquiry or request within 30 days of receipt. For complex requests, we may require additional time and will inform you of any extension.
If you are not satisfied with our response to your privacy concern or complaint, you have the right to contact the Office of the Australian Information Commissioner:
Office of the Australian Information Commissioner (OAIC)
Website: www.oaic.gov.au
Phone: 1300 363 992
Email: enquiries@oaic.gov.au
By using our Site or services, you acknowledge that you have read, understood, and consent to the practices described in this Privacy Policy.
Last updated: November 24, 2025
Discuss your next build ↗