Yira Yarkiny Security Services Privacy Policy

 

1. Introduction

Yira Yarkiny Security Services is part of the Yira Yarkiny Group, a 100% Aboriginal-owned, Supply Nation Certified organisation operating in Western Australia. Yira Yarkiny Security Services provides licensed security services, including static guarding, mobile patrols, crowd control, alarm monitoring and response, and control room operations.

This Privacy Policy explains how Yira Yarkiny Security Services collects, holds, uses, discloses, stores and retains personal information in the course of delivering these services and operating this website. It applies to website visitors, clients and prospective clients, job applicants, contractors, employees, and members of the public whose information we handle at sites we protect (for example, through CCTV or sign-in records).

This Policy applies only to Yira Yarkiny Security Services and to the Yira Yarkiny Security Services website.

This website: www.yirayarkinysecurity.com.au (or equivalent domain) [confirm live domain before publication].

We are committed to protecting personal information in accordance with the Privacy Act 1988 (Cth) (“Privacy Act”) and the 13 Australian Privacy Principles (APPs) it contains, as amended by the Privacy and Other Legislation Amendment Act 2024 (Cth), and where relevant to our security services, the Surveillance Devices Act 1998 (WA) and the Security and Related Activities (Control) Act 1996 (WA).

2. What Counts as Personal Information?

“Personal information” has the meaning given in section 6(1) of the Privacy Act: information or an opinion about an identified individual, or an individual who is reasonably identifiable — whether the information is true or not, and whether it is recorded in a document or not.

In practice, this can include, for example:

  • Name, address, date of birth, and contact details (phone, email)
  • Photographs, video or CCTV images, and voice recordings that show or identify a person
  • An IP address, device identifier, or online activity that can be linked back to a person
  • Identification, licence, and qualification numbers
  • Financial, billing, and payroll details
  • Employment, performance, and reference information

Sensitive Information

“Sensitive information” is a special category of personal information that the Privacy Act protects more strictly. Under section 6(1), it includes information about a person’s:

  • Racial or ethnic origin
  • Health, disability, or genetic information
  • Criminal record
  • Biometric information (such as fingerprints) used for identification
  • Religious beliefs, political opinions, or trade union membership
  • Sexual orientation or practices

We only collect sensitive information where it is reasonably necessary for our functions, and with your consent or as otherwise permitted by law (APP 3).

3. Personal Information We Collect

The personal information we collect depends on how you interact with us. This may include:

Website Visitors

  • Contact details submitted through enquiry, quote request, tender-interest, or careers forms (name, email, phone number, organisation, message content)
  • Technical and usage information collected automatically, such as IP address, browser and device type, pages viewed, and date/time of visit
  • Information collected through cookies (see Section 9)

Clients and Prospective Clients

  • Business contact details, billing and contract information, and correspondence
  • Site and operational information relevant to the security services delivered (for example, site layouts, incident details)
  • Information provided in tenders, pre-qualification questionnaires, and supplier evaluations

Security Sites and the Public

  • CCTV and surveillance footage captured at monitored sites, in accordance with the Surveillance Devices Act 1998 (WA) and site-specific authorisations
  • Alarm activation, access control, and incident/occurrence report data, which may include images, vehicle details, and descriptions of individuals involved in an incident
  • Visitor and contractor sign-in records at sites where we provide guarding or access control services

Job Applicants and Personnel

  • Resumes, security licence and certification details, police clearances, working rights, referee details, and interview notes
  • Employment, payroll, work health and safety, training, and performance information for current employees
  • Where voluntarily provided, information supporting participation in the Group’s Aboriginal and Torres Strait Islander Employment and Participation Policy

Sensitive Information

  • Where necessary and permitted by law, we may collect limited sensitive information, such as criminal history checks and security licensing information required for security industry roles, or health information relevant to workplace safety. We only collect this with consent, or where otherwise authorised or required by law.

4. How We Collect Personal Information

  • Directly from you, via website forms, email, telephone, in person, or through contracts and tender submissions
  • Automatically through website analytics, cookies, and server logs
  • From surveillance and access control systems deployed at client sites we are contracted to protect
  • From third parties, such as referees, background-check and licensing bodies, recruitment platforms, and government or industry bodies (for example, WA Police, Supply Nation)
  • From publicly available sources, such as company registers, where relevant to tendering and due diligence

Where practicable, we collect personal information directly from the individual concerned. Where we receive information from a third party or from a client’s own systems, we rely on that party having obtained any necessary notices or consents.

5. Why We Collect, Hold, and Use Your Information

We use personal information for purposes including:

  • Responding to enquiries and providing quotes for security services
  • Delivering, managing, and invoicing contracted services (guarding, alarm monitoring and response, mobile patrols, crowd control)
  • Verifying identity, licensing, and eligibility to work in the security industry and on client sites
  • Meeting work health and safety, insurance, incident investigation, and public liability obligations
  • Recruitment, onboarding, training, and management of our workforce
  • Participating in tenders, panels, and Supply Nation / Aboriginal procurement processes
  • Complying with legal, regulatory, and contractual obligations, including under the Security and Related Activities (Control) Act 1996 (WA)
  • Direct marketing about our services, where you have not opted out (see Section 10)

We will not use or disclose personal information for a purpose other than the one it was collected for, unless an exception under APP 6 applies — for example, you have consented, the new purpose is related and reasonably expected, or the law requires or authorises it.

6. How We Store and Secure Your Information

Yira Yarkiny Group holds ISO/IEC 27001:2022 (information security) certification. Consistent with Australian Privacy Principle 11 — including APP 11.3, which confirms that “reasonable steps” to secure personal information must include both technical and organisational measures — we apply protections such as:

  • Classifying information (including personal information) and applying storage, transmission and disposal controls based on that classification
  • Hosting Group email, documents, and business systems within a managed Microsoft 365 environment with data-loss-prevention and sensitivity controls
  • Restricting access to systems and information on a need-to-know, least-privilege basis, with secure log-on and multi-factor authentication where required
  • Encrypting data in transit and, where supported, at rest
  • Physical security controls over hard-copy records, premises, and CCTV/alarm system access, restricted to authorised control room and operations personnel
  • Contractual and technical safeguards over subcontractors and third parties who handle personal information on our behalf
  • Detecting, containing, investigating, and remediating information security incidents

No method of electronic storage or transmission is completely secure, and while we take reasonable steps to protect personal information from misuse, loss, and unauthorised access, we cannot guarantee absolute security.

7. How Long We Keep Information

We keep personal information only for as long as it is needed for the purpose it was collected, or as required by law, whichever is longer. Indicative periods are set out below; a specific contract, licence, or law may require a different period.

Information TypeIndicative Retention Period
Website enquiry and contact form submissionsUp to 24 months from last contact, or until the enquiry is closed, unless a business relationship continues
Client and contract recordsDuration of the contract plus 7 years, to meet contractual, insurance, and taxation obligations
CCTV and surveillance footageTypically 30–90 days, unless required for an active incident, investigation, or legal proceeding, consistent with the Surveillance Devices Act 1998 (WA)
Incident and occurrence reports7 years from the date of the incident, or longer if subject to a claim or investigation
Job applications (unsuccessful candidates)Up to 12 months from the closing date of the role, unless consent is given to retain longer
Employee records7 years from the end of employment
Financial and taxation records7 years, as required under Australian taxation law
Website analytics and cookie dataTypically no longer than 26 months

When information is no longer required and we are not required by law to keep it, we take reasonable steps to securely destroy or de-identify it.

8. Who We Share Information With

We may disclose personal information to:

  • Subcontractors and personnel engaged to deliver security services on our behalf
  • IT and cloud service providers who host or process data on our behalf under confidentiality and security obligations
  • Insurers, brokers, and their advisers, in connection with public liability or workers’ compensation claims
  • Regulatory bodies and government agencies (for example, WA Police, the OAIC, WorkSafe WA, Supply Nation), where required or authorised by law
  • Professional advisers, including lawyers, accountants, and auditors, where reasonably necessary
  • A prospective buyer or its advisers in connection with a proposed sale, merger, or restructure of the business, subject to confidentiality obligations
  • Any other party where you have consented, or disclosure is required or authorised by law

We do not sell personal information. Where a service provider stores or processes data outside Australia (for example, a cloud platform), we take reasonable steps consistent with APP 8 to ensure it continues to be handled in line with the Australian Privacy Principles.

9. Cookies and Website Analytics

Our website may use cookies and similar technologies to run core functions, understand how visitors use the site, and support enquiry forms. You can control or disable cookies through your browser, though some website features may not work correctly if you do.

Our website is not designed to knowingly collect personal information from children, and we do not knowingly market our services to children.

10. Direct Marketing

We may use your contact details to tell you about Yira Yarkiny Security Services services and related Group initiatives.

You can opt out at any time using the unsubscribe link in any message, or by contacting us using the details in Section 14.

We do not use sensitive information for direct marketing.

11. Data Breaches

We have processes to identify, contain, and assess any suspected or actual data breach, coordinated by our Cyber Incident Response Team.

Where a breach is likely to result in serious harm, we will comply with the Notifiable Data Breaches scheme in the Privacy Act, including notifying affected individuals and the Office of the Australian Information Commissioner (OAIC) as required.

Since 10 June 2025, individuals also have a statutory right to bring a civil claim for a serious invasion of privacy under Commonwealth law.

12. Access to, and Correction of, Your Information

You may ask us for access to the personal information we hold about you, and ask us to correct it if it is inaccurate, out of date, incomplete, irrelevant, or misleading, in line with APPs 12 and 13.

Contact us using the details in Section 14.

We aim to respond within 30 days. We may charge a reasonable fee to cover the cost of retrieving information, but not for making the request. In some circumstances permitted by law, we may need to refuse a request, and if so, we will explain why.

13. How to Make a Privacy Complaint

If you believe we have breached the Australian Privacy Principles or mishandled your personal information, contact us using the details in Section 14.

We will acknowledge, investigate, and aim to respond to your complaint within 30 days.

If you are not satisfied with our response, you can contact the Office of the Australian Information Commissioner (OAIC):

  • Website: www.oaic.gov.au
  • Phone: 1300 363 992
  • Post: GPO Box 5218, Sydney NSW 2001

14. Contact Us

For questions about this Privacy Policy, or to make an access, correction, opt-out, or complaint request, contact:

Privacy Officer — Yira Yarkiny Security Services

Yira Yarkiny Investments Pty Ltd (trading as Yira Yarkiny Security Services)

Suite 6, 178 Great Eastern Highway, Ascot WA 6104

Email: info@yirayarkiny.com.au

Phone: 1800 201 030

15. Changes to This Policy

We may update this Privacy Policy to reflect changes in our practices, technology, legal requirements, or the services we offer.

It is reviewed annually, or earlier if there is a material change in law, systems, or business activity.

The current version is always available on our website, with the effective date shown on the cover of this document.

 
 
 

This Privacy Policy explains how Yira Yarkiny Security Services collects, holds, uses, discloses, stores and retains personal information in the course of delivering these services and operating this website. It applies to website visitors, clients and prospective clients, job applicants, contractors, employees, and members of the public whose information we handle at sites we protect (for example, through CCTV or sign-in records).

This Policy applies only to Yira Yarkiny Security Services and to the Yira Yarkiny Security Services website.

This website: www.yirayarkinysecurity.com.au (or equivalent domain) [confirm live domain before publication].

We are committed to protecting personal information in accordance with the Privacy Act 1988 (Cth) (“Privacy Act”) and the 13 Australian Privacy Principles (APPs) it contains, as amended by the Privacy and Other Legislation Amendment Act 2024 (Cth), and where relevant to our security services, the Surveillance Devices Act 1998 (WA) and the Security and Related Activities (Control) Act 1996 (WA)

Our experienced and licensed security professionals provide tailored security solutions for commercial, industrial, government, and community organisations. From security guard services, mobile patrols, construction site security, corporate security, retail security, mine site security, event security, CCTV monitoring, and alarm response to asset protection and loss prevention, we help businesses reduce risk, protect people and property, and maintain safe, secure environments across Australia.