Legal

Privacy Policy

Version 1.0 · Approved by Haven BA Management · Applies to all data handled by Haven BA, including data collected at havenba.com.

1. Purpose of This Policy

This Internal Privacy Policy outlines how Haven BA ("the Company") collects, stores, uses, protects, and discloses personal information. It applies to all internal team members, including independent contractors engaged under the Haven BA Contractor Agreement.

The purpose is to ensure:

  • Compliance with the Privacy Act 1988 (Cth) and Australian Privacy Principles (APPs)
  • Secure handling of all client, prospect, and business data
  • Clear rules on confidentiality, data access, and authorised usage
  • Alignment with contractual confidentiality and IP clauses

2. What Personal Information Haven BA Collects

Team members may access or handle the following categories of information:

  1. Client and prospect information — names; contact details (email, phone, address); financial capacity or property-related information; purchase preferences and onboarding details; agreements, proposals, call notes, and CRM notes.
  2. Lead generation data — social media profiles; inquiry forms from havenba.com; data collected from online ads, landing pages, or cold outreach; email and phone interactions.
  3. Internal operational data — sales records; activity reports; marketing performance data; CRM system logs.
  4. Contractor/employee data — contact details; payment information required for invoicing; any compliance information required under agreements.

No team member may collect or store information beyond what is required to perform their approved duties.

3. How Personal Information Is Collected

Personal information is collected through:

  • Website forms on havenba.com
  • CRM submissions
  • Advertising platforms (Meta, Google, LinkedIn)
  • Phone calls and SMS
  • Email correspondence
  • Third-party integrations (e.g., Calendly, payment gateways)
  • Manual lead generation activities

No internal team member may create unofficial or duplicate databases.

4. How Personal Information May Be Used

Personal information may only be used for legitimate Haven BA business activities, including:

  • Lead generation, sales, and outreach
  • Onboarding and service delivery
  • Customer support
  • Marketing optimisation
  • Internal reporting
  • Payment processing
  • Client relationship management

Any use of personal information outside these functions is prohibited.

5. Data Access Requirements

Access is strictly limited according to an internal "need-to-know" basis.

Contractors and staff may access only:

  • Information required to complete assigned tasks
  • Leads and clients assigned to them
  • CRM entries relevant to their pipeline or responsibilities

Contractors and staff may not:

  • Download or extract client lists
  • Export CRM data
  • Store data on personal devices outside approved systems
  • Scrape, reuse, or retain Haven BA data upon contract termination

The restrictions in this policy align with the restraint and confidentiality obligations within your contractor agreement.

6. Data Storage and Security

Haven BA uses secure, cloud-based tools for internal operations, including CRM platforms, file storage, lead delivery tools, and communication platforms.

All team members must comply with the following:

  • Use strong passwords and multi-factor authentication
  • Do not share login credentials with any person
  • Do not store client data in personal spreadsheets, devices, or apps
  • Use only Haven BA-approved communication tools
  • Immediately report any suspected privacy or security breach

Haven BA systems must be accessed only on secure networks.

7. Disclosure of Personal Information

Internal staff and contractors must not disclose client or business information to any external party except when:

  • Required to deliver Haven BA services to the client
  • Authorised by a senior Haven BA manager
  • Legally required (e.g., court order)
  • Provided to approved third-party service providers under confidentiality terms

Unauthorised disclosure is a breach of this policy and the Independent Contractor Agreement.

8. Data Retention

Haven BA retains data for as long as necessary to fulfil business purposes and legal requirements.

Contractors and employees:

  • Must not delete or alter data unless authorised
  • Must not remove any data from Haven BA systems
  • Must return (or delete if directed) all data in their possession upon contract termination

9. Rights of Individuals

Under the Australian Privacy Principles, individuals whose data Haven BA collects have the right to:

  • Request access to their personal information
  • Request correction of inaccurate information
  • Request information about how their data is used

All such requests must be forwarded to senior management. No staff member or contractor may respond independently.

10. Confidentiality (Internal Obligation)

This privacy policy works alongside the confidentiality clause in the Haven BA Contractor Agreement.

Contractors and internal team members must:

  • Keep all client and business data strictly confidential
  • Not use data for personal gain or external business activities
  • Not copy, duplicate, or remove client information
  • Not contact clients outside the scope of their contractual work

Breaches may result in immediate termination, legal action, compensation claims for loss or damage, and reporting obligations to regulators.

11. Data Breach Protocol

Any suspected or actual breach must be reported to Haven BA management immediately.

Examples of breaches include:

  • Lost devices containing Haven BA data
  • Unauthorised exporting of CRM data
  • Stolen passwords or accounts
  • Emails sent to incorrect recipients
  • Accidental disclosures

Depending on severity, Haven BA may be required to notify affected individuals or the Office of the Australian Information Commissioner (OAIC).

12. Third-Party Tools and Integrations

Haven BA uses approved platforms such as CRM systems, lead generation and advertising tools, secure cloud storage, marketing platforms, and communication tools.

Contractors and staff:

  • May not integrate new tools or software without written approval
  • Must use systems only for legitimate business activities
  • Must follow system-specific privacy settings and controls

13. Data Handling on Termination of Contract

Upon termination of engagement, contractors and employees must:

  • Immediately cease accessing all Haven BA systems
  • Return or permanently delete any data in their possession
  • Confirm in writing that all Haven BA data has been deleted
  • Not contact or solicit Haven BA clients under restraint clauses

Retaining data after termination is a breach of contract and privacy law.

14. Policy Breaches

Breaches of this policy may result in termination of contract or employment, legal action, financial liability for damages, and reporting to relevant authorities.

Serious breaches may constitute:

  • Misuse of confidential information
  • Misuse of personal information
  • Intellectual property theft
  • Abuse of access privileges
  • Violations of Australian Privacy Principles

15. Policy Review

This policy will be reviewed annually or when legislative changes occur. Haven BA management may update the policy at its discretion. All staff and contractors will be notified of significant changes.