1. Purpose and scope
This Policy outlines Payroll Metrics’ ongoing obligations in respect of how personal information is managed. Personal information is information about an identified individual, or an individual who is reasonably identifiable. Payroll Metrics may also refer to this information internally as personally identifiable information, or PII, which is the term used in ISO/IEC 27701.
Payroll Metrics has adopted the Australian Privacy Principles (APPs) contained in Schedule 1 to the Privacy Act 1988 (Cth), which govern the way in which personal information is collected, used, disclosed, stored, secured and disposed of. The APPs are explained in the Australian Privacy Principles guidelines published by the Office of the Australian Information Commissioner (OAIC). Because Payroll Metrics provides services to customers in New Zealand, Payroll Metrics is also subject to the Privacy Act 2020 (NZ). Section 9 sets out how this Policy applies to individuals in New Zealand.
Payroll Metrics maintains a Privacy Information Management System aligned to ISO/IEC 27701, operating alongside its Quality, Privacy and Information Security Management System (QP&ISMS).
This Policy applies to all personal information Payroll Metrics handles.
2. Payroll Metrics’ role: processor and controller
Payroll Metrics acts as a processor. Substantially all of the personal information Payroll Metrics holds is information about its customers’ employees, entered into, generated by or transmitted through the Payroll Metrics platform. Payroll Metrics holds it on behalf of, and on the documented instructions of, the customer. The customer, as the employer, determines what personal information is collected, why it is collected and how long it is kept. ISO/IEC 27701 refers to this role as a PII processor.
In this role Payroll Metrics handles personal information only to deliver the contracted services, to meet a legal obligation, or as otherwise instructed in writing by the customer. Payroll Metrics does not use it for its own purposes, does not sell it, does not use it for direct marketing, and does not use it to train artificial intelligence or machine learning models other than as expressly agreed with the customer in writing. Any subcontractor Payroll Metrics engages is bound by obligations no less protective than those Payroll Metrics owes the customer.
Payroll Metrics acts as a controller only for a limited set of information it holds to run its own business, records relating to its own personnel and job applicants, business contact details for customers, vendors, partners and suppliers, enquiries and support requests, feedback submitted to the online assistant and website usage data. No customer employee payroll data is held in this role. ISO/IEC 27701 refers to this role as a PII controller.
Payroll Metrics’ obligations apply in both roles. The Privacy Act 1988 does not distinguish between a controller and a processor: an entity that holds personal information, whether it controls that information or holds it on behalf of another organisation, is subject to the APPs in its own right. Payroll Metrics does not rely on its role as a processor to reduce its obligations. The employee records exemption in section 7B(3) of the Privacy Act 1988 applies only to an employer’s handling of its own employee records, and does not apply to Payroll Metrics’ handling of its customers’ employee records.
3. The personal information Payroll Metrics collects and holds
As processor: identity and contact details including date of birth; tax file number (Australia) or IRD number (New Zealand); employment details such as start date, job classification, work pattern and cost centre; hours worked, timesheets, rosters and leave records; pay, allowances, deductions and payment history; bank account and superannuation or KiwiSaver fund details; child support and other statutory or voluntary deductions; work rights and visa information; termination details and final payments; and information contained in documents attached to an employee record.
As controller: names, business contact details, job titles and employer; account credentials and access logs; correspondence, support requests and enquiries; marketing preferences; website and product usage data including IP address and session identifiers; feedback submitted to the online assistant; and recruitment and employment records for Payroll Metrics’ own personnel.
Sensitive information, as defined in section 6(1) of the Privacy Act 1988, is held where a customer’s payroll configuration requires it, for example, health information supporting personal, carer’s or workers compensation leave, and information from which membership of a professional or trade association may be inferred through a payroll deduction. It is handled only for the purpose for which the customer provided it and is subject to additional access restrictions.
4. How Payroll Metrics collects and holds personal informationPayroll Metrics collects personal information from customers and their authorised administrators; from customers’ employees through the employee self-service portal; through integrations and application programming interfaces that a customer has authorised via Payroll Metrics application; directly from individuals through the Payroll Metrics website, contact forms, support channels and online assistant; and automatically through system and security logs. Where it is reasonable and practicable, personal information is collected directly from the individual concerned. Where Payroll Metrics collects personal information about an individual from a customer, the customer is responsible for notifying that individual under APP 5.
All personal information Payroll Metrics holds is stored in Australia, in Microsoft Azure data centres in the Australia East and Australia Southeast regions. Personal information is classified and handled as sensitive information under Payroll Metrics’ data classification framework, and is backed up in accordance with documented backup standards.
5. Why Payroll Metrics uses and discloses personal information
As processor, Payroll Metrics uses personal information to calculate earnings, tax, superannuation and other entitlements; interpret modern awards and enterprise agreements as configured by the customer; produce payslips, payment files, reports and general ledger extracts; lodge Single Touch Payroll reports with the Australian Taxation Office and payday filing with Inland Revenue New Zealand on the customer’s behalf; enable authorised integrations; and provide technical support.
As controller, Payroll Metrics uses personal information to manage customer, contractors and partner relationships including billing; respond to enquiries, support requests and complaints; secure, monitor, test and improve its products; recruit and manage its own personnel; send service and marketing communications as described in Section 6; and meet its legal, regulatory and certification obligations.
Payroll Metrics does not sell personal information. Personal information may be disclosed:
• where the individual consents, or where required or authorised by law;• to the customer and its authorised administrators, in respect of their own employees;
• on a customer’s instruction, to the government agencies, regulators and financial institutions needed to complete a payroll, including the Australian Taxation Office, Inland Revenue New Zealand, Services Australia, superannuation and KiwiSaver funds and clearing houses, and banks and payment providers;
• on a customer’s instruction, to partners and third-party systems through which that customer has licensed or integrated the platform;
• to Payroll Metrics’ auditors and certification bodies.
6. Marketing and service communications
Payroll Metrics distinguishes between service communications and marketing communications.
Service communications are notices required to deliver the services or to support the customer relationship — for example, release notes, planned maintenance and outage notices, security advisories, legislative and compliance updates, billing notices and support correspondence. These are sent to customer administrators and nominated contacts. They are not marketing, and they continue for as long as the service relationship continues because they are necessary to deliver the service.
Marketing communications — for example, product announcements are sent only to business contacts at customers, prospective customers and partners, and to individuals who have asked to receive them. Payroll Metrics does not use customer employee payroll data for its own marketing purposes, does not disclose it to any third party for marketing, and does not send marketing communications to customers’ employees in their capacity as employees.
7. Website and cookies
The Payroll Metrics website does not set cookies. It does not use advertising or marketing cookies, and does not use third-party analytics or tracking technologies. Individuals are not tracked across other websites, and no cookie consent banner is required.
When an individual visits the website, limited technical information is processed by the hosting provider in order to deliver and secure the site, including IP address, browser and device type, the pages requested, and the date and time of the request. This information is used to operate and protect the website and is not used to build a profile of the individual.
Where an individual submits a contact or demonstration request through the website, the information they provide is used to respond to that enquiry and is otherwise handled as described in this Policy.
The Payroll Metrics platform and the employee self-service portal are separate from the website and use cookies that are strictly necessary for authentication, session management and security. These are not used for marketing, advertising or analytics.
8. Tax File Number (TFN) and Inland Revenue Department (IRD) numbers
Tax file number information is handled in accordance with the Privacy (Tax File Number) Rule 2015, which is legally binding and issued under section 17 of the Privacy Act 1988. Payroll Metrics collects and holds tax file numbers only where a customer is authorised by taxation, superannuation or personal assistance law to collect them, and only for the purposes those laws permit. Tax file numbers are never used as a general identifier, are accessible only to personnel with an operational need, and are destroyed or de-identified once no longer required to be retained by law. Equivalent controls apply to New Zealand IRD numbers.
9. New Zealand customers and individuals
Payroll Metrics provides payroll services to customers in New Zealand and is therefore treated as carrying on business in New Zealand. Payroll Metrics is an agency for the purposes of the Privacy Act 2020 (NZ) and applies the Information Privacy Principles (IPPs) to personal information about individuals in New Zealand. This applies regardless of where that information is held.
Access and correction. Individuals in New Zealand may request access to, and correction of, their personal information. The pathway is the same as that described in Section 11: where the individual is an employee of a Payroll Metrics customer, the request should be made to their employer, and Payroll Metrics will refer the request and assist the customer to respond. All other requests should be directed to the Payroll Metrics Privacy Officer.
Privacy breaches. Where Payroll Metrics becomes aware of a privacy breach affecting individuals in New Zealand that has caused, or is likely to cause, serious harm, Payroll Metrics will notify the Office of the Privacy Commissioner (New Zealand) and affected individuals as soon as practicable, and will notify the affected customer so that it can meet its own obligations.
Storage outside New Zealand. Personal information about individuals in New Zealand is stored in Microsoft Azure data centres in Australia. Information provided to a supplier that holds or processes it solely on Payroll Metrics’ behalf, and does not use or disclose it for its own purposes, is not a disclosure for the purposes of IPP 12. Where IPP 12 does apply to a disclosure, Payroll Metrics relies on the recipient being subject to privacy laws that provide comparable safeguards to the Privacy Act 2020 (NZ), or on contractual obligations that provide comparable safeguards.
New Zealand customers. Because Payroll Metrics carries on business in New Zealand and is subject to the Privacy Act 2020 (NZ), a New Zealand customer’s disclosure of personal information to Payroll Metrics is a disclosure to an entity that is itself subject to New Zealand privacy law.
10. Security, accuracy and retention
Personal information is to be stored in a manner that protects it from misuse and loss and from unauthorised access, modification or disclosure. Specifically, personal information is to be:
• transmitted using strong encryption, regardless of whether such transmission takes place inside or outside the company’s network, and encrypted at rest;
• protected by role-based access controls, multi-factor authentication and logging of privileged activity, applied on the principle of least privilege;
• removed from desks, computer screens and common areas unless currently in use, stored under lock and key where held in physical form, and not left on voicemail systems inside or outside the company’s network; and
• destroyed or permanently de-identified when no longer required for the purpose for which it was obtained, in accordance with Payroll Metrics’ documented information handling standards.
Payroll Metrics personnel are screened before engagement, are bound by confidentiality obligations, and complete privacy and information security training on induction and routinely. Payroll Metrics’ controls are independently certified and subject to internal audit, management review and periodic penetration testing.
Payroll Metrics takes reasonable steps to ensure personal information is accurate, up to date and complete. Because payroll data is entered and maintained by customers and their employees, accuracy in the platform depends on the customer; Payroll Metrics will correct personal information, or assist a customer to correct it, promptly on request.
Where Payroll Metrics acts as processor, personal information is retained for as long as the customer instructs and the services agreement requires, and on termination is returned or securely destroyed in accordance with that agreement. Where Payroll Metrics acts as controller, personal information is retained only as long as needed for the purpose for which it was collected or as the law requires.
11. Access, correction and complaints
Customers and their employees access employee personal information through the Payroll Metrics application — administrators through the administrator interface, and employees through the employee self-service portal. Access is controlled by user login and password, plus two-factor authentication.
Individuals may request access to the personal information Payroll Metrics holds about them and request its correction, under APP 12 and APP 13. Where Payroll Metrics holds that information as processor — that is, where the individual is an employee of a Payroll Metrics customer — the request must be made to their employer; Payroll Metrics will refer the request and assist the customer to respond. All other requests should be made to the Privacy Officer. Payroll Metrics will respond within 30 days, and if access or correction is refused will give written reasons and explain how to complain.
If an individual believes Payroll Metrics has breached the APPs, the Information Privacy Principles, the TFN Rule or this Policy, they should write to the Payroll Metrics Privacy Officer. Payroll Metrics will acknowledge the complaint within 5 business days and respond within 30 days. If the individual is not satisfied with that response, they may contact:
• the Office of the Australian Information Commissioner — oaic.gov.au, 1300 363 992; or
• for individuals in New Zealand, the Office of the Privacy Commissioner — privacy.org.nz.
Individuals may deal with Payroll Metrics anonymously or by pseudonym for general enquiries where lawful and practicable. This is not practicable for payroll services, which require an individual to be identified.
12. Automated processing and artificial intelligence
The platform performs automated calculations that are configured and controlled by the customer, including award and enterprise agreement interpretation, leave accrual, taxation and superannuation calculations. The customer, as employer, remains responsible for the employment decisions those outcomes support, and every calculation is visible to and adjustable by the customer’s authorised administrators before a pay run is finalised. The Payroll Metrics online assistant answers questions using published product documentation; it is not given access to payroll data, is not trained on personal information, and does not make decisions about individuals.
13. Data breaches
Payroll Metrics maintains a documented incident response plan. Where Payroll Metrics becomes aware of grounds to suspect a data breach it assesses the matter promptly and takes all reasonable steps to complete that assessment within 30 days, in accordance with the Notifiable Data Breaches scheme.
Where Payroll Metrics holds the affected personal information as processor, it notifies the affected customer without undue delay so that the customer can meet its own obligations, and supports the customer’s response. Where an eligible data breach affects personal information Payroll Metrics holds as controller, Payroll Metrics notifies the Office of the Australian Information Commissioner and affected individuals as soon as practicable under the Privacy Act 1988. Notification of privacy breaches affecting individuals in New Zealand is dealt with in Section 9.
14. Contact and review of this Policy
Privacy Officer, Payroll Metrics
Suite 304, 3 Chester Street, Oakleigh VIC 3166
[privacy@payrollmetrics.com.au] | 1300 233 246
This Policy is reviewed at least annually and whenever there is a material change to the services, the systems used to deliver them, or the law. Material changes are notified to customers in accordance with their services agreement.