The Business Operating System Pty Ltd – Privacy Policy

The Business Operating System Pty Ltd (ACN 661 748 465) (The BOS) values your right to know about the collection, use, and sharing of the personal information you provide, directly or indirectly, when using the Business Operating System Software (The BOS Software).

Accordingly, The BOS has adopted the Australian Privacy Principles contained in the Privacy Act 1988 (Cth) to support its commitment to maintaining transparency in its processes and the collection, use, disclosure, storage, security, and disposal of personal information.

What is Personal Information?

Personal information means any information or opinion, whether true or not, and whether recorded in a material form or not, about an identified individual or an individual who is reasonably identifiable either directly (e.g. full name) or indirectly (e.g. email addresses, phone numbers), and includes sensitive information.

What is Sensitive Information?

Sensitive information is a subset of personal information and means any information or opinion about an individual’s racial or ethnic origin, political opinions, membership of a political association, religious or philosophical beliefs, trade union or other professional body membership, criminal record, or most relevantly for The BOS, health information.

The BOS Software may require you to enter sensitive information from time to time. You may also authorise the software to receive such information from other software, such as Xero, Hubspot, Nookal, and Cliniko. Otherwise, we will collect such sensitive information with your consent, if it is necessary to prevent a serious and imminent threat to life or health, or as otherwise required or authorised by law. As this information is sensitive, we take reasonable steps to implement appropriate security measures to keep it secure.

Where this policy refers to personal information, it also includes sensitive information.

What Personal Information Do We Collect and Store?

The BOS will collect and store the personal information you directly enter into The BOS Software and which it collects from your other software (e.g., Xero, Hubspot, Nookal, and Cliniko). The BOS will collect all your and your client’s personal information from this other software to the extent the other software permits that collection.

The personal information collected by The BOS concerning your business includes, but is not limited to, financial records, bank transaction information, employee payslips, and employee information (e.g. full name, gender, mailing or street address, date of birth, etc.)

The BOS also collects personal information concerning other individuals, most commonly your customers/patients. Personal and sensitive information is collected and stored together. Such personal information includes but is not limited to the patient’s full name, date of birth and residential address. Sensitive information collected and stored includes but is not limited

to medicare numbers, private health insurance providers and membership numbers, illness, disabilities, or injuries, and patient treatment notes and records.

Do We Collect Personal Information?

The BOS may collect personal information from you in various ways, such as:

(a) you directly entering the personal information into The BOS Software;

(b) when The BOS Software facilitates communication between your software products (i.e. Xero, Hubspot, Nookal, and Cliniko); and

(c) indirectly through various means such as transactions, emails, forms, face-to-face meetings, interviews, surveys, registration and attendance at events, business cards, online queries, telephone conversations, and the services available through our websites, applications, and social media channels.

How We Hold Personal Information

The BOS stores all personal information collected from you by The BOS Software on secure premises located in Australia with a third-party data storage provider. The personal information held by The BOS in providing its services is combined and linked to operate The BOS Software as outlined below.

We will take reasonable steps to ensure the safety and security of all personal information we collect and hold. This includes implementing physical, electronic, and procedural safeguards to protect against unauthorised access, modification, or disclosure of personal information in possession or control of The BOS.

We will retain your personal information indefinitely to ensure the efficient functioning of The BOS Software. You can issue a written request to destroy or de-identify such information by contacting our Privacy Contact Officer at the email or postal address below.

Purpose of Collecting, Holding, and Using Your Personal Information

The personal information collected by The BOS is held and used to operate The BOS Software, including to:

(a) provide you with information and services that you request from us;

(b) deliver to you a more personalised experience and service offering; and

(c) improve the quality of the services for:

(i) Reporting and Analysis – monitoring and tracking analytics and data concerning employees and your customers/patients;

(ii) Automation and function sharing – by facilitating communication of personal information between your databases and software for automation of processes concerning business, patient, and account management; and

(iii) Customer and Account management – to reduce the time spent on bookkeeping and account reconciliation through automated middle management, payment adjustment and modification management, and compiling customer/patient personal information across platforms, software and databases.

Disclosure of Personal Information to third parties

The disclosure of personal information to third parties will occur in accordance with the purpose and uses outlined in this Privacy Policy in circumstances where you would reasonably expect us to disclose your information. For example, The BOS will disclose your personal information to:

(a) our third-party service providers (for example, our IT providers, professional services providers, etc.), and

(b) your third party software providers (e.g. Xero, Hubspot, Nookal, and Cliniko).

Use of The BOS Software necessitates the transfer of your and your client’s/patient’s personal information to and between your third party software providers. Although we take reasonable measures to ensure the safety and security of all personal information we collect and hold, we are not responsible for the safety and security of personal information in the possession or control of a third party.

Personal information will also be used to tell you about products or services that interest you. If you do not want your personal information used for these direct marketing purposes, you can “opt-out” by contacting our Privacy Contact Officer at the email, postal address, or telephone number below.

Transfer of Personal Information Overseas

Third party software compatible with The BOS Software may have a branch located in Australia and/or overseas, including in the United States of America, the United Kingdom, Germany, Ireland, Japan, and the Netherlands.

You may wish to review the privacy policies of each third party software provider and consider their procedures for transferring personal information to branches and servers located overseas. Other than outlined above the BOS will not disclose personal information to recipients located outside Australia. If personal information needs to be transferred overseas to perform one of our functions or activities, we will obtain your consent and use our best endeavours to ensure its protection in its disclosure. Changes to this Privacy Policy

The BOS reserves the right to amend this Privacy Policy at any time.

If you object to the Privacy Policy, please let us know, and you should not access or use The BOS Software or other services until we resolve your concern.

Accessing and Correcting your Personal Information

You have a right to access the personal information we hold, or if you consider any personal information we hold about you incorrect in any way, request that we correct that personal information, subject to any exceptions allowed by law.

If you wish to request access to / correct the personal information held by us, you should issue a request in writing by contacting our Privacy Contact Officer at the email or postal address below.

The BOS reserves the right to charge a fee for searching for and providing access to your information on a per-request basis.

How you may Complain and how we will Deal with the Complaint

We have an internal dispute resolution system that covers complaints. If you consider that we have failed to comply with Division 3 of Part IIIA of the Privacy Act 1988 or the Australian Privacy Principles, you should contact our Privacy Contact Officer at the email, postal address, or telephone number below. Please allow up to 28 days for The BOS to respond to your complaint.

If you are unsatisfied with the decision, you may complain to the Office of the Australian Information Commissioner (OAIC). The contact details for the OAIC are:

Telephone: 1300 363 992

Facsimile: (02) 9284 9666

Website: www.oaic.gov.au

Mail: The Office of the Australian Information Commissioner

GPO Box 5218

SYDNEY NSW 2001

Contacting Us

The BOS welcomes your comments regarding this Privacy Policy. If you have any questions about it and would like further information, please get in touch with our Privacy Contact Officer at the email, postal address, or telephone number below.

Attention: Privacy Contact Officer

Email: Info@thebos.com.au

or

Postal Address: C/- Batch Mewing Lawyers, GPO Box 518, Brisbane QLD 4000

or

Phone Number: +61 433 772 313