PRIVACY POLICY
CROSS APAC Group Pty Ltd
Privacy Policy
Version 2 | Last updated: 13 June 2026
Applies to: crossapac.com and all subdomain pages
1. About This Policy
CROSS APAC Group Pty Ltd (ACN 601 923 657) (“CROSS APAC”, “we”, “us”, “our”) is committed to protecting your privacy. This Privacy Policy explains how we manage your personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). It details the kinds of personal information we collect, how we use and disclose it, and how you can access and
correct your information.
Privacy in plain English
-
What we collect
-
Why we collect it
-
Who we share it with
-
Where it’s stored
-
Your rights
This Policy applies across all three operating divisions of CROSS APAC Group: CROSS Safety, CROSS Recruit, and CROSS Aviation.
CROSS APAC Group meets the threshold for coverage under the Privacy Act 1988 (Cth) by reason of annual turnover exceeding $3 million and/or the provision of services under Commonwealth, State or Territory government contracts. Where CROSS Recruit collects sensitive information as part of recruitment and placement activities, the higher consent and collection standards under APP 3 and
section 6 of the Act apply.
2. What Personal Information We Collect
The types of personal information we collect depend on your interaction with us. This may include:
-
Identity and Contact Data: Name, position title, company name, email address, phone number, business address, personal address.
-
Engagement and Transaction Data: Details of services provided, project requirements, feedback, survey responses, and communication records.
-
Accounting is handled via invoices or a third-party provider (Stripe), and we do not hold your financial details.
-
Technical and Website Usage Data: IP address, browser type, operating system, referring URLs, pages visited on our website, and other analytical data.
-
Recruitment and Candidate Data (CROSS Recruit): Where you interact with CROSS Recruit’s talent placement and workforce services, we may collect résumés, employment history, qualifications, referee details, right-to-work documentation, and, where required for specific roles, health and medical assessments and criminal history check outcomes. This information constitutes sensitive information under section 6 of the Privacy Act 1988 (Cth) and is subject to heightened collection and consent obligations under APP 3. Such information is collected only with your express consent or as otherwise permitted by law.
3. How We Collect Your Personal Information
We collect personal information in several ways, including:
-
Directly from you when you enquire about or use our services, contact us, complete a form on our website, or correspond with us by phone, email, or otherwise.
-
From third parties, such as your employer, publicly available sources, or our business partners, where you have consented to this or it is otherwise reasonable.
-
Automatically when you visit our website via cookies and other tracking technologies (see Section 11).
4. How We Use Your Personal Information
We collect, hold, use, and disclose your personal information for purposes directly related to our
business operations, including to:
-
Provide, administer, and improve our WHS consulting, aviation charter brokerage, recruitment, and compliance services.
-
Communicate with you, respond to your enquiries, and manage our relationship
-
with you.
-
Process payments and manage billing via invoices.
-
Conduct business analysis, reporting, and improve our service delivery.
-
Comply with our legal and regulatory obligations.
-
Conduct recruitment activities.
We will not use or disclose your personal information for a secondary purpose unless you have consented, or an exception under APP 6 of the Privacy Act 1988 (Cth) applies (for example, where the secondary purpose is directly related to the primary purpose and you would reasonably expect such use, or where required by law).
Retention periods may vary depending on the nature of the engagement, including recruitment processes, compliance requirements, and legal obligations
Sensitive information is only retained as long as necessary for recruitment or compliance purposes.
5. Disclosure of Your Personal Information
We may disclose your personal information to:
-
Our related companies and third-party service providers who perform functions on our behalf (e.g., IT support, data storage, payment processors). These providers are contractually bound to protect your information and comply with the APPs.
-
Professional advisors, including lawyers, accountants, and auditors.
-
Government, regulatory, or law enforcement authorities as required or authorised by law.
6. Data Storage on Australian Servers
Your personal information is stored on secure servers located within Australia. We primarily store data in Australia. Some service providers may access data from overseas. All personal information we hold is retained on infrastructure that is physically located in Australia and subject to Australian jurisdiction.
If our data hosting practices change in the future, we will update this Privacy Policy accordingly and take all reasonable steps to ensure any overseas recipient complies with the APPs in accordance with APP 8.
7. Cross-Border Data Disclosure
We do not currently disclose personal information to overseas recipients. Where we engage third-party providers, we take reasonable steps to ensure they protect personal information in accordance with the APPs, consistent with our obligations under APP 8.
Note on overseas-based service provider access: Under APP 8.1 of the Privacy Act 1988 (Cth), a disclosure of personal information to an overseas recipient occurs when an overseas entity is able to access that information, not merely when data is stored overseas. Certain technology platforms we use in the ordinary course of business, including cloud-based CRM, HR, accounting, and website hosting services, may be headquartered overseas, and their support or administrative personnel outside Australia may have incidental technical access to data hosted on those platforms. All such providers are contractually required to handle personal information consistently with the APPs. Our primary data storage remains on Australian servers subject to Australian jurisdiction (see Section 6).
8. Data Security
We take reasonable steps to protect your personal information from misuse, interference, loss, unauthorised access, modification, or disclosure. These steps include physical, electronic, and procedural safeguards, employee training, and regular security assessments. No system is completely secure, and we cannot guarantee absolute security.
9. Accessing and Correcting Your Personal Information
You may request access to, or correction of, the personal information we hold about you by contacting us (see Section 14). We will respond to your request within a reasonable period. We may charge a reasonable fee for access, but not for making a correction request. If we refuse an access request in whole or in part, we will provide you with written reasons for the refusal and inform you of the mechanisms available to lodge a complaint about the refusal, as required by APP 12.9 of the Privacy
Act 1988 (Cth).
10. Data Breach Notification
If we suspect a data breach that is likely to result in serious harm to affected individuals, we will investigate and follow the procedures under the Notifiable Data Breaches (NDB) scheme. This includes notifying affected individuals and the Office of the Australian Information Commissioner (OAIC) as required.
11. Cookies and Website Analytics
Our website uses cookies to enhance your experience, analyse site traffic, and for marketing purposes. We use the following categories of cookies:
-
Essential cookies: Necessary for the website to function correctly. These cannot be disabled.
-
Analytical cookies: Used to understand how visitors interact with the website (e.g., Google Analytics). Data collected is aggregated and anonymous where possible. Google Analytics is operated by Google LLC (United States); data may be processed in accordance with Google’s Privacy Policy.
-
Marketing and functional cookies: Used to personalise content and may be set by our website platform provider (Wix). These cookies will track your visit across websites.
You can manage or disable cookies through your browser settings at any time. Disabling essential cookies may affect website functionality. To opt out of Google Analytics tracking, you may install the Google Analytics Opt-out Browser Add-on at tools.google.com/dlpage/gaoptout. Where a consent management banner is displayed on our website, you may withdraw consent to non-essential cookies at any time by clicking “Cookie Settings”.
12. Third-Party Links
Our website may contain links to other websites. We are not responsible for the privacy practices of those sites and recommend you review their respective privacy policies before providing any personal information.
13. Changes to This Policy
We may update this Privacy Policy from time to time. The latest version will always be available on our website, and we encourage you to review it periodically.
Where changes are material — for example, a change to the types of personal information we collect, the purposes for which we use it, or our data storage arrangements — we will notify you by prominent notice on our website or, where we hold your contact details, by direct communication prior to the change taking effect.
14. Contact Us & Complaints
If you have any questions, concerns, or wish to make a complaint about how we handle your personal
information, please contact us:
CROSS APAC Group Pty Ltd
Email: legal@crossapac.com
Phone: 1300 395 583
Mail: The Privacy Officer, CROSS APAC Group Pty Ltd, P.O. Box 8500, Allenstown QLD 4700
We will acknowledge your complaint within 5 business days and aim to resolve it within 30 days. If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au or by calling 1300 363 992.
