BundyPlus Pty Ltd (“we”, “our”, “us”) is committed to protecting your privacy and handling personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
This Privacy Policy outlines how we collect, use, disclose, and manage personal information, including data processed via our time and attendance solutions and related services.
This policy applies to personal information collected from:
- Visitors to our website (https://www.bundyplus.com.au, https://my.bundyplus.com.au/)
- Our customers and business partners
- End users of our products, including employees whose information is input, stored, or processed through BundyPlus systems.
1. What Personal Information We Collect
From customers and website users:
- Full name, contact details, and job title
- Company or organisation name
- Email address, phone number
- Purchase and account information
- IP address, browser type, and device information
- Website usage and cookies data
From end users (via our products and services):
BundyPlus provides time and attendance solutions used by our customers to manage workforce operations. As a service provider, we may process the following personal and sensitive information of our customers’ employees or users:
- Full name and employee ID
- Employment details (e.g. position, department, work schedule)
- Time and attendance records (e.g. clock-in/out times, locations, and shift details)
- Payroll or HR reference numbers
- Contact information (e.g. email address, mobile or phone number)
- Government-issued identifiers (e.g. Tax File Number or similar, where applicable)
- Biometric information, including facial recognition data and fingerprint data
This data is collected only when configured and authorised by our customers, and processed securely for legitimate workplace operations.
2. How We Collect Personal Information
We collect personal information through:
- Direct interactions (e.g. enquiries, purchases, support requests)
- Website interactions and cookies
- BundyPlus timekeeping devices (e.g. biometric terminals, mobile apps)
- Software integrations and APIs with third-party systems (such as payroll, HR, or ERP platforms)
- Customer input or uploads into our platforms
- Automated data feeds from customer-configured systems
When our products integrate with third-party payroll or HR systems via API, employee data may flow between systems. This data sharing is managed and authorised by the customer (data controller), not BundyPlus.
3. Purpose of Collecting Personal Information
We collect and use personal information to:
- Provide and support our time and attendance products and services
- Accurately track employee attendance and time records
- Enable biometric or secure login verification
- Support payroll, HR, and compliance processes
- Facilitate data exchange with customer-authorised systems, including third-party payroll platforms via API integration
- Detect unauthorised or fraudulent activity
- Improve our products and services
- Comply with legal and regulatory obligations
BundyPlus only processes information passed to or from external systems through secure, authorised API channels, and never uses this data for unauthorised purposes.
4. Use and Processing of Biometric Data
Where biometric information (facial or fingerprint data) is used, it is processed solely for the purpose of verifying identity for secure access or time tracking.
- Depending on customer configuration, either biometric templates or raw images may be stored.
- All stored data (templates or raw images) are encrypted and access is strictly controlled.
- Biometric data is not used for any other purpose beyond identity verification or attendance tracking.
Our customers are responsible for obtaining valid consent from their employees, as required under APP 3 and APP 6, and for ensuring lawful collection and use of biometric information under relevant workplace laws.
5. Disclosure of Personal Information
We may disclose personal information to:
- Third-party service providers (e.g. hosting, IT support, customer service platforms)
- Customer-authorised third parties (e.g. payroll or HR systems connected via API)
- System integrators or resellers supporting your implementation
- Regulatory authorities as required by law
- Our legal, financial, or professional advisors
- Prospective acquirers in the event of a merger, acquisition, or restructure
When data is exchanged between BundyPlus and external payroll systems via API, this is done only under the customer's control and configuration. BundyPlus acts as a data processor in these integrations.
6. Overseas Disclosure
Some of our service providers and support personnel may operate from or store data in countries outside Australia. When transferring data overseas, we ensure appropriate safeguards are in place and take reasonable steps to ensure compliance with APP 8 (Cross-border disclosure).
7. Security of Personal Information
We use industry best practices to safeguard all personal information, including biometric and time-based data:
- Encryption of data (in transit and at rest)
- Strict access controls and multifactor authentication
- Biometric data protection measures (encryption and restricted access, even where raw images are stored)
- Firewalls, antivirus, and continuous monitoring tools
- Secure data retention and disposal policies
8. Retention and Deletion of Data
We retain personal information only as long as necessary for the purposes for which it was collected or as required by law. Upon expiry of retention periods or upon request by the customer, data is securely deleted or de-identified.
9. Access and Correction
You have the right to request:
- Access to personal information we hold about you
- Corrections to any inaccurate or outdated information
For data collected or processed on behalf of a customer (e.g. your employer), requests should first be directed to them.
10. Cookies and Website Analytics
Our website uses cookies and third-party analytics tools (e.g. Google Analytics) to:
- Improve user experience and performance
- Track website traffic and usage patterns
- Remember user preferences
You can manage or disable cookies via your browser settings.
11. Direct Marketing
We may use your contact details to send you product updates, promotions, or news. You may opt out at any time using the “unsubscribe” link in our emails or by contacting us directly.
12. Complaints and Enquiries
If you have a question, concern, or complaint about our handling of your personal information, please contact:
Privacy Officer – BundyPlus Pty Ltd
Website: https://www.bundyplus.com.au
Email: privacy@bundyplus.com.au
Phone: +61 3 9873 0355
Address: Unit 74 / 585 Burwood Hwy, Knoxfield Vic 3180
If you're not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) via https://www.oaic.gov.au