McKercher Corporation applies a consistent privacy and information-security approach across its group businesses, public website, and staff systems.
This public explanation sets out the operating principles. The Privacy Policy remains the governing website document for the types of information collected, permitted uses, service providers, overseas processing, access and correction requests, and privacy complaints.
Collect for a defined purpose
Personal information should be collected only where it supports a defined business, service, employment, security, or legal purpose. The information may come from website forms, customer or staff interactions, authenticated systems, service records, and technical logs.
People should be told why information is requested and how it will be used where the context does not already make that clear. Information should not be kept indefinitely merely because storage is available.
Apply controls in proportion to the information
McKercher Corporation takes reasonable steps to protect personal information from misuse, interference, loss, unauthorised access, modification, and disclosure.
Controls may include:
- access permissions based on business need
- multi-factor authentication where supported
- encryption where appropriate
- system and security monitoring
- staff instruction and access removal when responsibilities change
- retention and deletion processes
No online system can be described as completely secure. The appropriate position is to maintain safeguards, review them against changing risks, and respond when a weakness or incident is identified.
Use service providers with clear boundaries
Group businesses use external providers for functions such as hosting, communication, authentication, customer administration, workforce management, and payments.
Those providers receive only the information required for their role, subject to the applicable account configuration, contract, and provider terms. The Privacy Policy identifies relevant provider categories and explains that some processing may occur outside Australia.
Assess suspected data breaches
A suspected privacy or security incident must be assessed through the relevant internal response process. Where the Notifiable Data Breaches scheme applies, eligible data breaches are notified to affected people and the Office of the Australian Information Commissioner as required.
Speed matters, but so do accuracy and evidence. Public or customer communication should describe what is known, what is being investigated, the steps people should take, and when the next update will be provided.
Access, correction, and complaints
People may request access to personal information held about them and ask for inaccurate, incomplete, or outdated information to be corrected. Identity may need to be verified before a request is completed.
Privacy questions, access or correction requests, and complaints should be sent through the contact details in the Privacy Policy. The Terms and Conditions explain the rules that apply when using the public website and restricted staff areas.
This commitment is a governance position, not a claim that risk can be eliminated. The practical standard is responsible collection, proportionate protection, documented response, and transparent correction when something goes wrong.



