Privacy Policy
1. Purpose
This Privacy Policy outlines how Bryan + Petersen (“we”, “our”, “us”) collects, uses, stores, retains, and discloses personal information in the course of providing insurance repairs and related services.
We are committed to protecting the privacy of insured parties, clients, and stakeholders in accordance with the Privacy Act 1988 and the Australian Privacy Principles (APPs).
2. Scope
This policy applies to all:
- Employees
- Directors
- Contractors and subcontractors
- Third-party service providers
It covers all personal information collected during:
- Insurance claim handling
- Repair works
- Client communications
- Administrative and financial processes
3. Types of Personal Information Collected
We may collect and hold the following types of personal information:
3.1 Identification & Contact Details
- Full name
- Residential and postal address
- Email address
- Phone numbers
3.2 Claim & Insurance Information
- Claim numbers and insurer details
- Property details and insured address
- Scope of works and damage reports
- Insured values and policy coverage
3.3 Financial Information
- Payment details and banking details
- Invoice and transaction records
- Insurance settlement details
3.4 Personal Circumstances
- Occupancy and living arrangements
- Vulnerability or hardship indicators (where relevant)
- Communications relating to claims
- Special requirements impacting repairs
3.5 Sensitive or Supporting Information
- Photos of property and contents
- Inspection notes and specialist reports
- Communications relating to claims
- Property condition and maintenance records
4. How Personal Information is Collected
We collect personal information through:
- Insurers, Loss Adjusters, Assessors and Insurance Brokers
- Directly from clients/insured parties
- Site inspections and reports
- Phone, email, and digital communications
- Claim management systems (e.g., Crunchworks, Endata)
5. Use of Personal Information
We use personal information strictly for legitimate business purposes, including:
- Deliver insurance repair services
- Assess and scope works
- Communicate with insurers and insured parties
- Process payments and claims
- Meet contractual, legal, and regulatory obligations
- Ensure safety, compliance, and quality control
Strict Limitation
Personal information must not be used:
- For unrelated business activities
- For marketing without explicit consent
- For personal or unauthorised purposes by staff
6. Disclosure of Personal Information
Personal information may be shared with:
6.1 Insurers and Related Parties
- Insurance companies (e.g., Panel Insurers)
- Loss adjusters, brokers and assessors
6.2 Contractors and Suppliers
- Only use information for the specific job
- Not retain or reuse information
- Comply with confidentiality obligations
6.3 Professional Services
- Engineers, surveyors, and consultants
- Specialist reporting and assessing partners
- Legal and financial advisors
6.4 Regulatory Authorities
- Government or regulatory bodies where required by law
7. Storage and Security of Personal Information
We take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access.
7.1 Security Measures
- Secure digital systems and password protection
- Restricted access based on role
- Secure cloud-based platforms
- Secure physical storage for hardcopy files
7.2 Data Handling
- Personal information is only accessible to authorised personnel
- Systems are monitored and regularly reviewed
8. Retention of Personal Information
We retain personal information only for as long as necessary to:
- Complete the insurance repair and claim process
- Meet contractual obligations with insurers
- Comply with legal, taxation, and regulatory requirements
Retention Period
- Minimum 7 years from claim completion (or longer if required by insurer agreements or legal obligations)
Disposal
- When no longer required, information is:
- Securely deleted from digital systems, or
- Shredded/destroyed if in hardcopy
9. Access and Correction
Individuals may request access to their personal information or request corrections if it is inaccurate.
Requests must be:
- Submitted in writing
- Verified for identity
We will respond within a reasonable timeframe in accordance with the Privacy Act.
10. Data Breaches
In the event of a data breach involving personal information, we will:
- Immediately (within 24 hours internally): report and assess the breach
- Contain and mitigate the breach
- Notify affected individuals where required
- Notify the Office of the Australian Information Commissioner (OAIC) if the breach is notifiable
- Take corrective action to prevent recurrence
11. Overseas Disclosure
We do not typically disclose personal information overseas.
If required, it will only occur:
- With insurer approval, and
- Where adequate data protection safeguards are in place
12. Responsibilities
Management
- Ensure compliance with this policy
- Maintain contractual confidentiality requirements
- Ensure systems meet security standards
Employees & Contractors
- Protect all personal information
- Access only what is required
- Not copy, store, or misuse information
- Report breaches immediately
13. Complaints
If a person believes their privacy has been breached, they may submit a complaint to:
Bryan + Petersen
Info@bpij.com.au
If unresolved, complaints can be escalated to the
Office of the Australian Information Commissioner.
14. Policy Review
This policy will be reviewed regularly or Following regulatory or contractual changes.