top of page

Privacy Policy

Effective date: 27 August 2026

Last updated: 27 August 2026

1. About this Privacy Policy

C‑Connect (Aust) Pty Ltd ACN 643 930 223 (“C‑Connect”, “we”, “us” or “our”) respects your privacy and is committed to protecting personal information.

This Privacy Policy explains how we collect, hold, use, disclose, secure and otherwise manage personal information in connection with:

  • the C‑Connect website, including www.c-connect.com.au;

  • the C‑Connect Platform;

  • C‑Connect web and mobile applications;

  • Solutions made available through the C‑Connect Platform, including iPIMS;

  • customer support, demonstrations, onboarding and training;

  • integrations and Connected Apps; and

  • other services we provide.

We handle personal information in accordance with the Privacy Act 1988 (Cth), the Australian Privacy Principles where applicable, contractual obligations and this Privacy Policy.


2. Key terms

In this Privacy Policy:

Customer means an organisation that subscribes to, trials or otherwise uses the C‑Connect Platform or a C‑Connect Solution.

Customer Content means information, documents, records and other content submitted to or processed through the C‑Connect Platform by or for a Customer.

Connected App means a third-party service connected to C‑Connect at the direction of a Customer or User, such as Google Workspace, Google Drive, Xero, Microsoft SharePoint or another supported service.

Google User Data means information received through Google Sign‑In or another Google API.

Personal information means information or an opinion about an identified individual, or an individual who is reasonably identifiable.

Services means the C‑Connect website, Platform, applications, Solutions and associated services.

User means an individual who visits our website, uses the Services, receives communications through the Services or otherwise interacts with us.


3. Our role and the role of our Customers

C‑Connect provides business software to organisations. A Customer will often decide:

  • what personal information is entered into its C‑Connect workspace;

  • why that information is collected and used;

  • which Users may access it;

  • how long it should be retained; and

  • whether it is connected to other systems.

In those circumstances, C‑Connect handles Customer Content as a service provider acting on the Customer’s instructions. The Customer remains responsible for ensuring that it has authority to collect, use and disclose the information and for providing any notices or obtaining any consents required by law.

C‑Connect independently determines how it handles information required for account administration, authentication, billing, security, support, product operation, legal compliance and management of our business.

If your personal information was entered by your employer, principal contractor or another Customer, you may need to direct an access, correction or deletion request to that Customer. We will reasonably assist the Customer in responding to valid requests.


4. Personal information we may collect

The information we collect depends on how you interact with C‑Connect and which Solutions and features your organisation enables.


4.1 Identity and account information

This may include:

  • name;

  • email address;

  • telephone number;

  • profile photograph;

  • job title, role or occupation;

  • employer or organisation;

  • C‑Connect account identifier;

  • Google account identifier;

  • organisation memberships;

  • invitations, permissions and access profiles;

  • authentication and session information; and

  • records of account creation, login and access.

We do not receive or store your Google password when you use Google Sign‑In.


4.2 Professional and organisation information

This may include:

  • business contact details;

  • company, customer, supplier and subcontractor relationships;

  • office, project and worksite details;

  • professional qualifications, licences and competencies;

  • employment or engagement details;

  • user roles and responsibilities; and

  • records of communications with an organisation.

4.3 Project, construction and operational information

Depending on the Solution being used, Customer Content may include:

  • project names, addresses and work locations;

  • estimates, tenders, programs of work and schedules;

  • tasks, activities, resources and resource allocations;

  • timesheets, attendance, daily dockets and work records;

  • labour, plant, equipment and material records;

  • costs, revenue, margins, forecasts and variations;

  • invoices, purchase orders and accounting records;

  • rosters and workforce communications;

  • safety, quality and environmental records;

  • forms, registers, reports and approvals;

  • photographs, videos, attachments and documents;

  • signatures, acknowledgements and workflow records;

  • comments, messages and notifications; and

  • document access, revision and approval history.

Some operational information may not be personal information on its own but may become personal information when associated with an identifiable person.


4.4 Financial and subscription information

This may include:

  • billing contact details;

  • subscription plans and licence information;

  • invoices and payment status;

  • transaction references;

  • accounting integration records; and

  • information required for financial reporting, debt recovery or fraud prevention.

Payment card or bank account information may be collected directly by a payment or financial services provider. C‑Connect may receive a transaction confirmation without receiving the complete payment credentials.


4.5 Communications and support information

This may include:

  • website enquiry forms;

  • emails, telephone calls and messages;

  • demonstration, onboarding and support requests;

  • survey responses and feedback;

  • training attendance;

  • records of reported issues;

  • communications preferences; and

  • recordings or transcripts of calls or meetings where notice has been provided.


4.6 Technical and usage information

When you access our website or Services, we may automatically collect:

  • IP address;

  • browser type and version;

  • device type and operating system;

  • app version;

  • device or session identifiers;

  • login time and activity;

  • pages, screens and features used;

  • referring website;

  • error, diagnostic, security and audit logs;

  • approximate location derived from an IP address; and

  • cookie and similar technology information.

4.7 Device permissions

A C‑Connect mobile application or Solution may request permission to use features such as:

  • camera or photo library;

  • notifications;

  • file storage;

  • microphone; or

  • location.

We only access these features when they are required for an enabled function and the required device permission has been granted. Precise device location will not be collected merely because you use C‑Connect.

You may manage device permissions through your device settings, although disabling a required permission may prevent the related feature from working.


4.8 Sensitive information

Customer Content may sometimes contain sensitive information, such as health or injury information within a workplace safety or incident record.

C‑Connect does not seek to collect sensitive information unless it is reasonably required for an enabled feature or legitimate customer activity. Where required, sensitive information must be collected with the individual’s consent or under another lawful authority.

Customers must not enter unnecessary sensitive information into C‑Connect.


5. How we collect personal information

We may collect personal information:

  • directly from you when you contact us, complete a form, create an account or use the Services;

  • from a Customer, organisation administrator or another authorised User;

  • from documents, records or data uploaded to the Services;

  • through Google Sign‑In or another Connected App that you or your organisation authorises;

  • automatically through cookies, logs and similar technologies;

  • from service providers supporting authentication, billing, communications, analytics or security;

  • from business referrals and professional contacts; and

  • from publicly available business sources where lawful and appropriate.

If we receive personal information that we did not request and could not lawfully have collected, we will take reasonable steps to delete or de-identify it where lawful and reasonable.


6. Anonymity and pseudonyms

You may browse general areas of our public website without creating an account.

It is generally impracticable to use the C‑Connect Platform anonymously because we must identify Users to authenticate access, apply permissions, maintain audit records and protect Customer Content.


7. Why we collect, hold, use and disclose information

We may use personal information to:

  • provide, operate and administer the Services;

  • create and manage accounts and organisation workspaces;

  • authenticate Users and maintain secure sessions;

  • apply roles, permissions and access restrictions;

  • deliver iPIMS and other enabled Solutions;

  • process Customer Content according to Customer instructions;

  • provide Connected App functionality;

  • display information to authorised members of the relevant organisation;

  • send operational messages, invitations, rosters, alerts and notifications;

  • provide demonstrations, onboarding, training and support;

  • respond to enquiries and resolve technical issues;

  • manage subscriptions, invoicing and payments;

  • monitor performance, availability, security and misuse;

  • investigate suspected fraud, unauthorised access or breaches;

  • maintain backups, audit trails and business records;

  • understand how the Services are used and improve their usability;

  • develop and test new or improved features using appropriately protected data;

  • send marketing communications where permitted;

  • comply with laws, court orders and regulatory requirements;

  • establish, exercise or defend legal rights; and

  • manage a proposed or completed corporate transaction.

Where practical, we use aggregated or de-identified information for analytics, capacity planning and product improvement. We do not attempt to re-identify information that has been properly de-identified.

We do not use identifiable Customer Content to train a general-purpose artificial intelligence model unless the relevant Customer has expressly agreed in writing.


8. Google Sign‑In and Google API Services

8.1 Google Sign‑In information

If you select “Sign in with Google”, Google may provide C‑Connect with basic account information authorised through the Google consent process. This may include:

  • your unique Google account identifier;

  • name;

  • email address;

  • profile photograph; and

  • other basic profile information included within the approved Google Sign‑In permissions.

We use this information to:

  • authenticate you;

  • create or match your C‑Connect account;

  • display your identity within the relevant organisation workspace;

  • manage invitations, permissions and access;

  • protect account security; and

  • provide support.

Signing in with Google does not, by itself, give C‑Connect access to your Gmail messages, Google Drive files, Google Calendar or other Google content.


8.2 Optional Google-connected features

Some C‑Connect Solutions may offer separate Google-connected features, such as connecting an authorised Google Drive location.

These features are separate from basic Google Sign‑In. They require an additional authorisation process showing the requested Google permissions.

If you or your organisation enables such a feature, C‑Connect may access the Google data covered by the permissions you approve. Depending on the feature, this may include:

  • file and folder names;

  • file identifiers and metadata;

  • document content;

  • permissions and sharing information; and

  • files or folders selected, created, uploaded, edited, copied or organised through C‑Connect.

We use this information only to provide the connected, user-facing function requested by you or your organisation. C‑Connect will not access a category of Google User Data unless the relevant permission has been requested and approved.

Where supported, Google permissions are requested when the relevant feature is enabled rather than being requested solely for possible future use.


8.3 Storage and security of Google User Data

C‑Connect may securely store:

  • the basic profile information needed to maintain your account;

  • OAuth tokens or protected token references needed to maintain an authorised connection;

  • information imported, linked or created through a connected feature; and

  • logs needed for security, troubleshooting and audit purposes.

OAuth tokens and Google User Data are protected using technical and organisational safeguards appropriate to the nature of the information. We do not store your Google password.

We retain Google User Data only while it is needed for the authorised feature, account administration, security, Customer instructions or applicable legal requirements.


8.4 Sharing and human access to Google User Data

Google User Data may be made available to:

  • you;

  • authorised Users within your Customer organisation where required by the feature;

  • contracted infrastructure or service providers acting for C‑Connect;

  • support or security personnel where access is necessary and appropriately controlled; and

  • authorities where disclosure is legally required.

We do not sell Google User Data, use it for targeted advertising, provide it to data brokers or use it to determine creditworthiness.

C‑Connect personnel will not access the content of Google files or other Google User Data unless:

  • you or the relevant Customer has affirmatively authorised access for support or another specific purpose;

  • access is reasonably necessary to investigate security, misuse, fraud or a technical fault;

  • access is required by law; or

  • the information is appropriately aggregated or de-identified and used for lawful internal operations.

Access by service providers is limited to what they need to provide contracted services to C‑Connect.


8.5 Google Limited Use requirements

Our handling of information received from Google APIs complies with the Google API Services User Data Policy, including its Limited Use requirements.

In particular, Google User Data is used only to provide or improve the user-facing features for which access was granted. We do not use Google User Data to train general-purpose artificial intelligence or machine-learning models.


8.6 Revoking Google access and requesting deletion

You can review or revoke C‑Connect’s Google access through your Google Account connections.

Revoking access prevents C‑Connect from obtaining further information through the revoked authorisation. It may also prevent you from signing in or using a connected feature.

Revocation does not necessarily delete information already held within a Customer workspace. To request deletion, email info@c-connect.com.au with:

  • the subject “Data deletion request”;

  • your name;

  • the email address associated with your account;

  • the relevant Customer organisation; and

  • a description of the information or connection concerned.

We may need to verify your identity before processing a request.

Where the information is controlled by a Customer, we may refer the request to that Customer or act according to its lawful instructions. We will delete or de-identify Google User Data when it is no longer required, subject to legal obligations, security requirements, legitimate recordkeeping and backup retention cycles.


9. Connected Apps and third-party integrations

Customers may choose to connect C‑Connect with services such as Google Workspace, Google Drive, Xero, Microsoft SharePoint, OneDrive or other supported business systems.

When a Connected App is enabled, information may pass between C‑Connect and that service in accordance with:

  • the permissions approved by the Customer or User;

  • the purpose of the connected feature;

  • the Customer’s instructions;

  • this Privacy Policy; and

  • the third party’s own terms and privacy policy.

C‑Connect does not control the independent privacy practices of a third-party service. Customers and Users should review the permissions requested and the third party’s privacy information before enabling a connection.

You or your organisation may disconnect a Connected App, although information previously imported, created or linked may remain subject to applicable Customer and C‑Connect retention requirements.


10. Artificial intelligence and automated processing

Some C‑Connect features may use artificial intelligence or automated processing to assist with tasks such as:

  • extracting information from invoices or documents;

  • classifying or organising information;

  • identifying possible errors or inconsistencies;

  • generating summaries;

  • preparing suggested records; or

  • analysing project or operational information.

Information is provided to an artificial intelligence or automation provider only where required to deliver the enabled feature. Such providers are engaged as service providers and are not authorised to use the information for advertising or their independent purposes.

AI-generated or automated output may be incomplete or inaccurate and should be reviewed by an appropriately qualified person.

C‑Connect does not itself use automated processing to make decisions having a legal or similarly significant effect on an individual. Customers may use reports or decision-support outputs in managing their businesses and remain responsible for appropriate human review and their decisions concerning workers, contractors or other individuals.

If this practice changes, we will update this Privacy Policy and provide any additional notice required by law.


11. Who we may disclose information to

We may disclose personal information to:

  • the Customer organisation associated with your account;

  • authorised Users within that organisation;

  • service providers that supply hosting, storage, authentication, security, analytics, billing, communications, support or software services;

  • Google Cloud and other cloud infrastructure providers;

  • Wix and providers supporting our public website;

  • Google and providers of authorised Connected Apps;

  • Xero or other accounting providers where an integration is enabled;

  • Twilio or other email, SMS, mobile or push-notification providers;

  • Apple, Google or another application marketplace in connection with our mobile applications;

  • professional advisers, including lawyers, accountants, auditors and insurers;

  • contractors and consultants who are subject to appropriate confidentiality and security obligations;

  • law enforcement, regulators, courts or government authorities where required or authorised by law;

  • a prospective purchaser, investor, financier or successor in connection with a proposed corporate transaction, subject to appropriate confidentiality protections; and

  • another person where you or the relevant Customer has authorised the disclosure.

We do not sell personal information or Google User Data to data brokers or information resellers.


12. Overseas storage and disclosure

C‑Connect uses cloud technology and service providers that may store, process or support information from outside Australia.

Depending on the Services and Connected Apps used, overseas recipients may be located in countries including:

  • the United States;

  • New Zealand;

  • Israel;

  • Ireland and other European Economic Area countries;

  • the United Kingdom; and

  • Singapore.

The precise countries may change as providers update their infrastructure and support arrangements.

Where required, we take reasonable steps to select reputable providers, apply contractual and technical protections, restrict access and require information to be handled consistently with applicable privacy obligations.

Some information may be transferred directly to a third-party service at your or your organisation’s direction. That service’s privacy policy and data-location arrangements will also apply.


13. Cookies and website analytics

Our website and Services may use cookies, local storage, pixels and similar technologies to:

  • keep Users signed in;

  • maintain security and session integrity;

  • remember preferences;

  • understand website and feature usage;

  • diagnose errors;

  • measure performance; and

  • improve the Services.

Some cookies are necessary for the website or Platform to function. Other cookies may be provided by Wix, analytics services or embedded third-party content.

You can control cookies through your browser settings. Blocking essential cookies may prevent parts of the website or Services from operating correctly.

We do not use Google User Data for interest-based or targeted advertising.


14. Communications and direct marketing

We may send:

  • account and security notices;

  • invitations and authentication messages;

  • subscription and billing communications;

  • project, roster, workflow and operational notifications;

  • service announcements;

  • support and training communications;

  • email, SMS, in-app and push notifications; and

  • marketing information about C‑Connect products and services.

Operational and security communications are part of providing the Services and may continue while your account remains active.

You may unsubscribe from marketing emails using the unsubscribe facility in the message or by contacting info@c-connect.com.au. You may manage push notifications through your device settings.

Where an operational message is sent on a Customer’s instructions, requests concerning those messages may need to be directed to the relevant Customer or organisation administrator.

We do not use or disclose sensitive information for direct marketing.


15. Data security

C‑Connect takes reasonable technical and organisational steps to protect personal information against misuse, interference, loss, unauthorised access, modification and disclosure.

Measures may include:

  • encryption in transit and at rest;

  • secure cloud infrastructure;

  • authentication and session controls;

  • role-based permissions;

  • separation of Customer organisation data;

  • logging, monitoring and audit records;

  • controlled administrative access;

  • backups and recovery procedures;

  • security updates and vulnerability management;

  • provider due diligence; and

  • confidentiality obligations for personnel and contractors.

No electronic service can be guaranteed to be completely secure. Users are responsible for protecting their devices, accounts and authentication methods and must notify us promptly if they suspect unauthorised access.


16. Data retention and deletion

We retain personal information only for as long as reasonably necessary for:

  • the purposes described in this Privacy Policy;

  • the Customer’s instructions and contractual requirements;

  • operation and security of the Services;

  • support, dispute resolution and audit;

  • prevention of fraud and misuse;

  • legal, tax, accounting and regulatory obligations; and

  • the establishment, exercise or defence of legal claims.

Retention periods vary according to the type of information and the Services used.

When information is no longer required, we take reasonable steps to delete it or permanently de-identify it. Information in secure backups may remain until the relevant backup is overwritten or expires through the ordinary backup cycle, during which time it remains protected and is not used for other purposes.

Account removal does not necessarily require the deletion of Customer Content where the Customer must retain project, financial, safety, employment, contractual or audit records.


17. Accessing and correcting personal information

You may request access to personal information C‑Connect holds about you or ask us to correct information that is inaccurate, out of date, incomplete, irrelevant or misleading.

Send your request to info@c-connect.com.au and include sufficient information for us to identify you and the relevant records.

We may request proof of identity before providing access or making a correction.

We will respond within a reasonable period. We will not charge you merely for making a request, although a reasonable charge may apply where permitted by law for providing access in a particular form.

In some circumstances, the law permits or requires us to refuse access or correction. If that occurs, we will provide written reasons where reasonable and legally permitted and explain the available complaint options.

Where the information is held as Customer Content, we may refer the request to the relevant Customer or consult with the Customer before responding.


18. Your privacy choices

Depending on the circumstances, you may:

  • update certain profile information within C‑Connect;

  • ask your organisation administrator to update your details or access;

  • manage app permissions through your device;

  • disable non-essential cookies through your browser;

  • unsubscribe from marketing communications;

  • revoke a Connected App through the relevant provider;

  • revoke C‑Connect’s access through your Google Account;

  • request access to or correction of your information; or

  • request deletion where retention is not required.

Withdrawing permission or requesting deletion may prevent us from providing some or all of the Services.


19. Data breaches

If we become aware of a suspected data breach, we will assess and respond to it in accordance with our legal obligations.

Where a breach is likely to result in serious harm and notification is required under the Notifiable Data Breaches scheme, we will notify affected individuals and the Office of the Australian Information Commissioner as required.

A notification may describe:

  • what happened;

  • the types of information affected;

  • recommended protective steps; and

  • how to contact us.


20. Children and young people

The C‑Connect website and Services are designed for business and workplace use and are not directed to children.

We do not knowingly invite children to create independent consumer accounts. A Customer may enter information about a worker or apprentice who is under 18 where it has lawful authority and the information is reasonably required for legitimate employment, safety, training or project purposes.

If you believe personal information about a child has been collected without appropriate authority, contact info@c-connect.com.au.

21. Third-party websites and services

Our website and Services may contain links to third-party websites or services. C‑Connect is not responsible for the privacy, security or content practices of third parties acting independently of us.

You should review the privacy policy of a third-party service before providing information or enabling an integration.


22. Privacy complaints

If you believe we have breached this Privacy Policy, the Australian Privacy Principles or another applicable privacy obligation, please contact us at:

Privacy OfficerC‑Connect (Aust) Pty LtdEmail: info@c-connect.com.au

Please include:

  • your name and contact details;

  • the Customer organisation involved, if applicable;

  • a description of your concern;

  • relevant dates and supporting information; and

  • the outcome you are seeking.

We will acknowledge your complaint, investigate it fairly and aim to provide a substantive response within 30 days. If additional time is reasonably required, we will inform you.

If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner:

Website: www.oaic.gov.au/privacy/privacy-complaintsTelephone: 1300 363 992

You may also have the right to contact another privacy regulator where the laws of another jurisdiction apply.


23. Changes to this Privacy Policy

We may update this Privacy Policy when our Services, information-handling practices, providers or legal obligations change.

The current version will be published on the C‑Connect website with its effective date. If a change materially affects how we use previously collected personal information or Google User Data, we will provide additional notice and obtain consent where required before applying the new use.


24. Contact us

Questions, privacy requests and complaints may be directed to:

Privacy OfficerC‑Connect (Aust) Pty LtdACN 643 930 223Email: info@c-connect.com.auWebsite: www.c-connect.com.au

bottom of page