Privacy Statement

Holistic Services Group Pty Ltd (ABN 47 116 447 628) — referred to in this policy as HSG, we, us or our — is committed to protecting the privacy of the personal information we hold. This policy explains how we collect, hold, use, disclose and protect personal information across the whole of our business, not only through our website. This includes information about clients, program participants, enquirers, job applicants, specialist facilitators and other contractors, and suppliers.

We are bound by the Australian Privacy Principles (APPs) contained in the Privacy Act 1988 (Cth) (the Privacy Act). The APPs govern the way in which we collect, use, hold, disclose and dispose of personal information. A copy of the Australian Privacy Principles is available from the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au.

What personal information do we collect?

Personal information you provide to us

We may collect personal information such as your name, email address, phone number, job title, employer or organisation, and business address when you make an enquiry, request a quote, book a program, subscribe to our newsletter, apply for a role with us, or otherwise contact us.

Information about program participants

Where a client organisation books a workshop, assessment or wellbeing program, we may collect limited contact and attendance information about the individual staff members who participate — for example, name and email address for booking or feedback purposes. In some services, such as health assessments, ergonomic assessments or wellbeing consultations, a participant may provide health or other sensitive information directly to a facilitator. We only collect sensitive information with the individual’s consent, and only use it for the purpose of delivering that specific service.

Website and usage data

When you visit our website, we automatically collect usage data such as your device’s IP address, browser type and version, the pages you visit, the date and time of your visit, time spent on those pages, and other diagnostic data.

Cookies

We use cookies and similar tracking technologies, including web beacons, to operate our website and understand how it is used. A cookie is a small file placed on your device; you can set your browser to refuse cookies, though some parts of our website may not function properly if you do so. Persistent cookies remain on your device until deleted or expired; session cookies are deleted when you close your browser.

How we collect personal information

We collect personal information directly from you — for example, through our website enquiry form, by phone, by email, or in person — from the client organisation that has booked a program on behalf of its staff, from job applicants and their referees, and occasionally from publicly available sources for recruitment purposes. We do not collect personal information covertly.

Why we collect, hold, use and disclose personal information

We collect, hold, use and disclose personal information to:

Where we rely on your consent — for example, to send you marketing communications or to collect sensitive information — we will seek that consent specifically, and you may withdraw it at any time.

Disclosure of personal information

We do not sell, trade or otherwise transfer your personal information to outside parties for their own use.

We may disclose personal information to:

Overseas disclosure

Some of the service providers we use to run our website, email and customer relationship management (CRM) systems may store personal information on servers located overseas, including in the United States. Where our specialist facilitators deliver a program in New Zealand or elsewhere in the Asia-Pacific region, they may receive limited contact or attendance information necessary to deliver that session in-country. Before disclosing personal information overseas, we take reasonable steps to ensure the recipient handles it consistently with the Australian Privacy Principles, including through contractual protections where appropriate.

Storage and security of personal information

Personal information is stored electronically, primarily within our customer relationship management (CRM) system, which is protected by two-factor authentication (2FA) and password controls. Our website uses SSL encryption to protect information submitted through our enquiry forms. We take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access, modification or disclosure. No method of transmission over the internet or electronic storage is completely secure, and while we use commercially reasonable safeguards, we cannot guarantee absolute security. In the event of a data breach likely to result in serious harm, we will act in accordance with the Notifiable Data Breaches scheme administered by the OAIC.

How long we keep your personal information

We keep personal information only for as long as it is reasonably needed for the purpose it was collected, or as required by law. As a general rule, we retain enquiry and client records for seven (7) years after our last interaction with you, after which the information is securely destroyed or de-identified, unless we are required to retain it for longer to meet a legal, regulatory or contractual obligation.

Access to and correction of your personal information

You may request access to the personal information we hold about you, and ask us to correct it if it is inaccurate, out of date, incomplete, irrelevant or misleading. We will respond to a request for access or correction within a reasonable time, generally within 30 days, and may ask you to verify your identity first. There is no charge for making a request, though we may charge a reasonable fee to cover the cost of giving access where permitted by law.

Deleting your personal information

You may ask us to delete the personal information we hold about you. We will consider each request individually. Australian law does not provide a general right to have all personal information deleted on request, unlike some overseas privacy regimes, and we may need to retain some information where we have a legal, regulatory or contractual obligation to do so, or where it is otherwise reasonably necessary, for example to complete a service already underway or to meet our record-keeping obligations. Where we are able to delete your information, we will do so, or de-identify it, within a reasonable time.

How to make a complaint

If you have a concern about how we have handled your personal information, please contact us using the details below. We will acknowledge your complaint and aim to resolve it within a reasonable time, generally within 30 days. If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au, or by phone on 1300 363 992.

Changes to this policy

We may update this policy from time to time to reflect changes in our practices or the law. The current version will always be available on this page, together with the date it was last updated.

Contact us

If you have any questions about this Privacy Statement, or wish to make an enquiry, access request, correction request or complaint, please contact us via our contact page.

Last updated: 21 July 2026.