Privacy Policy for Viaductium Limited
Effective Date: 25.12.2024
Welcome to Foreman! We value the trust you place in us when providing us with your Personal Data, and we aim to protect your data to the highest of standards as we provide our products and services to you. This Privacy Policy was last updated on 25 December 2024.
It is important for users of the Foreman App to know that ‘Foreman’ is a brand created by Viaductium Limited, and this Privacy Policy also applies to the Personal Data you provide to us when using the Foreman App.
This Privacy Policy describes how we process the Personal Data of our existing and prospective customers, end-users who use or request our Services, visitors of our websites, vendors, partners, and those who participate in our promotions or events (‘you’ or ‘your‘). It also describes your data protection rights, including your right to object to some of the processing activities which we carry out.
This policy applies to all Personal Data that we collect, use, or disclose when providing our websites, platforms, apps, products, and services owned or operated by us.
What ‘Services’ does this Privacy Policy apply to?
Services | Features + Description |
Foreman Platform/App | Time tracking, attendance management and employee rostering |
Implementations services | Services that provide smooth onboarding and transition onto our platform for our business customers. Employers will provide us with relevant HR data relating to their employees to support the implementation process. |
We treat your Personal Data with the utmost care and in compliance with the applicable data protection laws. We may also provide you with additional information when we collect Personal Data where we feel it would be helpful to provide relevant and timely information.
This Privacy Policy does not apply to the following.
When we say ‘Foreman’, ‘us’, ‘our’, or ‘we’ in this Privacy Policy, we’re referring to Viaductium Limited and its affiliates.
data classification | Description |
Personal Data | Personal Data (also known as “Personal Information”) is any information relating to an identified or identifiable natural person, i.e. one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person |
Special Categories of Personal Data | Special Categories of Personal Data (also known as “Sensitive Information”) include data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health, or data concerning a natural person’s sex life or sexual orientation. |
If you cannot be identified, then this notice does not apply to you. An example of this is when your Personal Data has been aggregated and/or anonymised.
The Personal Data we collect and process will vary depending on your dealings with us and the Services we provide to you.
We may also collect and process Special Categories of Personal Data with your explicit consent when providing our Services to you, which includes Special Categories of Personal Data submitted by you, or on your behalf, through our Services.
Personal Data we may collect | Relevant Services |
Individual account information including name, username, date of birth and age, details regarding gender, sex, profile photo, and login credentials |
|
Individual contact information including residential and/or postal address, email address, telephone number, emergency contact information, |
|
Business contact information including administrator and account owner names, signatures, information about the company’s employees (if provided), and the name and contact details of any personnel involved in the recruitment process |
|
Employment related information including occupation or job title, information relating to your current employer, citizenship and visa status for work eligibility purposes, and tax information |
|
Location information including specific location information you provide us via your device using GPS, wireless, or Bluetooth technology, including IP addresses and information about your internet service provider, computer and device information like device, application, or browser type and version, and location information you manually input (you can control access to precise location information through your device settings) |
|
Billing information including payment details such as banking, or debit/credit card details |
|
Special Categories of Personal Data including health or disability information, biometric information, immigration information, criminal history and background checks, and certain diversity related information |
Only as necessary and with consent. |
We may collect Personal Data through our Services provided to you, or through other means when we engage with you or third-parties.
From time to time, you may provide us, and we may collect from you, Personal Data of or about a third party (for example, information you put into our systems as an employer on behalf of your employees). When you provide the Personal Data of a third party, it is your responsibility to ensure that the necessary consent has been acquired or other lawful basis is relied on, and that those individuals are aware of this Privacy Policy, and that they understand it and agree to accept it.
We must have a legal basis to process your Personal Data and we explain these legal bases below.
In the table below, we have explained the reasons for which we process your Personal Data, the processing activity that we carry out, the legal basis that applies in each instance, and the categories of data that we use for such activities.
What we do and why | Legal basis | Personal Data |
Fulfilling our contract, or taking steps linked to our contractual obligations | Contractual performance, consent | Any types of data identified as is necessary for this purpose |
Providing implementations services to implement our products and services for you, and onboard you on to our platform | Contractual performance, consent | Individual account information, Individual contact information, Employment related information |
Providing our Services, including ancillary Services such as customer support and implementations | Contractual performance, consent | Any types of data identified as is necessary for this purpose |
Processing payments for our Services | Contractual performance | Billing information |
Storing payment history information | Legal obligation | Billing information |
Sending direct marketing | Consent, legitimate interest | Individual account information, Individual contact information, Business contact information, Employment related information |
Reporting on marketing campaign activities and understanding effectiveness of the campaigns | Legitimate interest, consent | Individual account information, Individual contact information, Business contact information, Employment related information |
Conducting surveys and other market research to ensure our Services are relevant to your needs | Consent, legitimate interest | Individual account information, Individual contact information, Business contact information, Employment related information |
Managing our use of tracking technologies such as cookies and analysing collected data to learn about our Services | Consent | Device data and data relating to the usage of Services |
Sending service, technical and other administrative messages relating to our Services | Contractual performance, legitimate interest | Individual account information, Individual contact information, Employment related information |
Ensuring Services are working as intended, and tracking outages or troubleshooting issues | Contractual performance | Data relating to the usage of Services |
Personalising your experience with the Services, and tailoring our communications and marketing to you | Legitimate interest, consent, contractual performance | Individual account information, Employment related information, Location information, Search function inputs |
Investigating any complaints by or about you | Legitimate interest | Any types of data identified as is necessary for this purpose |
Investigating, raising or defending ourselves from legal claims | Legitimate interest, legal obligation | Any types of data identified as is necessary for this purpose |
Investigating any suspected breach of any of our terms and conditions or unlawful activity engaged in by you | Legal obligation | Any types of data identified as is necessary for this purpose |
Responding to legal matters, including court orders, subpoenas, or other legal processes | Legal obligation | Any types of data identified as is necessary for this purpose |
Complying with our compliance, regulatory, auditing, and investigative obligations (including disclosure of such information in connection with legal process or litigation) | Legal obligation | Any types of data identified as is necessary for this purpose |
Verifying your identity and/or carrying out credit report checks, and enabling us to monitor suspicious or fraudulent activity | Consent, legal obligation | ID verification and credit report information, Special Categories of Personal Data |
Assessing data to protect the security of our premises, assets, systems, and intellectual property, and to enforce company policies, including monitoring communications as permitted by law | Legal obligation, legitimate interest | Any types of data identified as is necessary for this purpose |
Processing data when undertaking mergers, acquisitions, reorganisations, or disposals, as permitted/required in accordance with applicable law | Legitimate interest, legal obligations | Any types of data identified as is necessary for this purpose |
We do not use Personal Data to train any AI models or for machine learning. We may analyse data relating to your activity and engagement on our Services to improve and develop our products, services, algorithms and models using machine learning. We may also analyse the performance of our Services to do things like optimise the product design, and develop and improve our products and services.
When we send you direct marketing based on our legitimate interests or where you have provided us with consent, these communications may be sent in various forms, including email, SMS, or social media.
You have a right to opt out of direct marketing at any time. You can do this by following the instructions in the communication within the electronic message we send to you, or by contacting us via email at support@foreman-app.com. Outside of such direct marketing, you may receive push notifications on your device, which can be controlled by your device settings.
We may also send you system trigger notifications about your use of the Services that you may be able to turn off using the preference settings within the platform.
We will still send you important notices relating to your account, operational activities, and technical updates, even after you have opted out of receiving direct marketing communications.
The Services we provide use cookies and similar technologies on our platform, app and websites. Cookies are small text files containing a string of alphanumeric characters which are sent to your computer that uniquely identifies your browser and lets us enhance your experience when using our Services. Cookies also convey information to us about how you use our Services. Additionally, we do not use 3rd party cookies.
When you use our Services, we may use cookies and similar technologies for the purpose of authenticating your use, remembering your preferences and settings, determining the popularity of content, and analysing and understanding your interactions with our Services.
The information that may be recorded includes information regarding your:
We may share your Personal Data with our affiliates and with other third parties from time to time for the purposes and means described in this Privacy Policy. We may disclose your information to:
We may disclose Personal Data outside of the country in which our customers and users are based in connection with the purposes identified in this Privacy Policy, and the Services described. International data transfers may occur when we share Personal Data with Viaducitum’s team members and affiliates based globally, including in Australia, United Kingdom, New Zealand, Singapore, Malaysia, Vietnam, and the Philippines and other locations from which the team members may work remotely. International data transfers may also occur when we share Personal Data with third party service providers located globally where it is deemed reasonably necessary for us to make such transfers.
We take measures to ensure that international data transfers take place in compliance with applicable laws relating to international data transfers and in accordance with at least the standards that apply in the country whose privacy or data protection laws apply to that Personal Data. If you are a EEA or UK customer or user of our Services, your Personal Data is transferred outside the EEA or the UK in compliance with the relevant requirements under the GDPR.
Adequacy decisions
Where the European Commission or the UK government has determined that certain countries outside of the EEA or the UK have an adequate level of Personal Data protection, e.g., New Zealand, Personal Data can be transferred to such a country from the EEA or UK without any further safeguards being necessary. A full list of such adequate countries is available here (for the EEA) and here (for the UK).
Where information is transferred outside the UK, or the EEA to a location that is not subject to an adequacy decision by the European Commission or the UK government, we ensure data is adequately protected. We may transfer your Personal Data (as described in section 5 above) for the purposes described in section 7 above to another country by relying on the EU Standard Contractual Clauses for the transfers from the EU, or the International Data Transfer Agreement or International Data Transfer Addendum to the EU Standard Contractual Clauses for the transfers from the UK, or relying on such other data transfer mechanisms as available under applicable data protection laws.
A copy of the relevant mechanism can be obtained for your review on request by using the contact details below.
The Services may contain links to other websites operated by third parties. We make no representations or warranties in relation to the privacy practices of any third-party website. Third-party websites are responsible for informing you about their own privacy practices and policies and you are encouraged to review the privacy notices.
Personal Data held by us will be stored and managed on secure data centres in Australia and Ireland by our third-party storage provider.
Please be aware that no method of transmission over the internet, or method of electronic storage is 100% secure and we are unable to guarantee the absolute security of the Personal Data we have collected from you.
You can also play an important role in keeping your Personal Data secure by maintaining the confidentiality of any password and accounts used on the Services. Please notify us immediately if there is any unauthorised use of your account by any other internet user, or any other breach of security relating to your account via email at support@foreman-app.com.
We retain data for as long as necessary to provide our Services and in accordance with our internal Data Retention Policy. This is a case-by-case determination that depends on things such as the nature of the data, why it is collected and processed, and relevant legal or operational retention needs. We may delete (or anonymise) your Personal Data once this data is no longer needed for us to provide our Services to you, and this data will not be retrievable in the future once deleted.
You can delete some data whenever you like, some data is deleted automatically, and some data we retain for longer periods of time.
For example:
Sometimes business and legal requirements oblige us to retain certain information, for specific purposes, and for an extended period of time. Reasons we might retain some data for longer periods of time include security, fraud prevention, financial record-keeping, complying with legal or regulatory requirements, ensuring the continuity of our Services, and when you have had direct communications with us.
You have the right to access your Personal Data, or to correct, delete or restrict processing of your Personal Data. You can also obtain the Personal Data you provide to us on a contractual basis or with your consent, in a structured, machine-readable format.
To exercise your data deletion rights (or “your right to be forgotten”) and request full deletion of your data from our Services, you must reach out to us directly by submitting a support ticket or emailing us at support@foreman-app.com. You can also correct and delete some Personal Data through your account provided by our Services. Where your Personal Data has been provided to us by a third party acting in the capacity of a data controller (such as your employer), you must ask that third party to correct or delete your Personal Data on your behalf. This third party will then request us to correct or delete the Personal Data from our systems.
You can also object to the processing of your Personal Data in some circumstances where it is practicable to do so, i.e., when we are using the data for direct marketing.
These rights may be limited, for example, if fulfilling your request would reveal Personal Data about another person, or if you ask us to delete information which we are required by law to keep or have compelling legitimate interests in keeping. We will inform you of relevant exemptions we rely upon when responding to any request you make.
To exercise any of these rights, including obtaining a copy of your legitimate interest balancing test, you can get in touch with us using the details set out below. If you have unresolved concerns, you have the right to complain to a data protection authority where you live, work or where you believe a breach may have occurred.
For the provision of information marked as mandatory when you register to use our Service, if such information is not provided, then you will not be able to use our Services. All other provision of your information is optional. If you do not provide such information, our provision of certain Services to you may be detracted from.
Where we rely on your consent, such as in relation to direct marketing communications, you will always be able to withdraw that consent at any time.
If you ask to withdraw your consent to our processing of your data, this will not affect any processing which has already taken place.
If you have any questions or concerns about how we process your data, please contact us via email at support@foreman-app.com
If you have a complaint regarding this Privacy Policy or any breach of applicable data protections laws, please contact us in accordance with section 14 above. Once we receive a complaint, we will commence an investigation as soon as practicable. We may contact you during the process to seek any further clarification if necessary. We may also contact you to inform you of the outcome of the investigation.
We will aim to ensure that all questions and concerns are resolved in a timely and appropriate manner. If you are not satisfied with the outcome of your complaint, or require further information on privacy, you are entitled to contact your local data protection supervisory authority.
We reserve the right to make changes to this Privacy Policy from time to time to reflect changes in the laws or regulations, our practices, our Services, or our operational requirements. You may periodically review this Privacy Policy to stay up to date with the latest changes. In the event that we make any significant changes in terms of data processing operations or any other change that may be relevant to you or impact you, we may additionally notify you via email or in-platform notifications on our Services.
Viaductium Limited
Flat 8, 7 Owens Road, Devonport, Auckland, 0624
Email: support@foreman-app.com
Phone: +64 21 278 6766