Legal

Privacy Policy

How ICE HRM Pty Ltd collects, uses, discloses and protects personal information, and how you can access, correct or complain about it.

Last updated 26 September 2026 14 sections
Contents
  1. About this Policy
  2. Personal Information We Collect
  3. Employee Data Stored in IceHrm
  4. How We Use Personal Information
  5. Direct Marketing
  6. How We Disclose Personal Information
  7. Overseas Disclosure
  8. How We Protect Personal Information
  9. Access and Correction
  10. EEA and UK Residents
  11. Children
  12. Complaints
  13. Changes to this Policy
  14. Contact Us

This Privacy Policy explains how ICE HRM Pty Ltd ("IceHrm", "we", "us" or "our") collects, holds, uses and discloses personal information in connection with our website at icehrm.com, the IceHrm Cloud service, IceHrmPro, our mobile applications and our other related services (together, the "Service"), and in connection with our customer, supplier and partner relationships.

Use of the Service is also subject to our Terms of Use. Terms that are not defined in this Privacy Policy have the meaning given to them in the Terms of Use.

About this Policy

We are bound by the Privacy Act 1988 (Cth) (the "Privacy Act") and the Australian Privacy Principles ("APPs"). Where we handle personal information of individuals in the European Economic Area or the United Kingdom, we also comply with the General Data Protection Regulation ("GDPR") and the UK GDPR as they apply to us.

In this Privacy Policy, "personal information" means information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether or not the information is true and whether or not it is recorded in a material form. It includes "personal data" as defined in the GDPR.

Where it is lawful and practicable, you may deal with us anonymously or using a pseudonym, for example when browsing our website or asking a general question. We cannot provide an account, a trial or a paid subscription without identifying you.

Personal Information We Collect

We collect personal information directly from you wherever reasonably practicable. We tell you at the point of collection whether providing the information is required and what happens if you do not provide it. If you do not provide information we need, we may not be able to provide the Service to you.

Information you provide to us

Registration. When you sign up for a trial or an account, request information or subscribe to updates, we collect your name, email address, phone number, company name, user name, password, city and time zone.

Customer support. We collect the information you provide when you contact our support team, including the content of your messages.

Purchases. When you pay for the Service we collect your billing contact details and billing address. Card payments are processed by our payment providers; we do not store full card numbers.

Business relationships. We collect contact details of people we deal with at our customers, suppliers and partners.

Information collected automatically

Log data

When you use the Service, our servers automatically record information your browser or device sends, such as your IP address, browser and device type, the pages you visit, the referring page, and the date and time of your visit ("Log Data").

Cookies and similar technologies

We use cookies and similar technologies to keep you signed in, remember your preferences, understand how the Service is used and improve it. Session cookies are deleted when you close your browser; persistent cookies remain until they expire or you delete them. We may also use web beacons in our emails to understand whether they are opened.

You can set your browser to refuse cookies or to alert you when cookies are being sent. If you disable cookies, some parts of the Service may not work properly.

Do Not Track

The Service does not currently respond to browser "Do Not Track" signals.

Third party content and links

Our website may include third party content and links to third party websites, which may collect information about you under their own privacy policies. We are not responsible for the privacy practices of third party websites, and we encourage you to read their privacy policies.

Employee Data Stored in IceHrm

Our customers use IceHrm to manage information about their employees and job applicants. This can include sensitive information, such as health information, where a customer chooses to record it. We handle this information on behalf of the customer, who decides what is collected and how it is used.

Each customer is responsible for having a lawful basis to collect and store that information and for providing any notices and obtaining any consents their employees are entitled to. We only access, use or disclose customer data to provide and support the Service, as instructed by the customer, or as required by law. If you are an employee of one of our customers, please contact your employer about your information in the first instance.

How We Use Personal Information

We collect, hold and use personal information to:

  • create and manage your account, provide the Service, process payments and respond to your enquiries;
  • authenticate users, including through two-factor authentication;
  • communicate with you about your account, the Service, maintenance and security, including service announcements by email;
  • provide customer support;
  • remember your preferences and tailor the Service;
  • operate, evaluate and improve the Service and develop new products and services, including by analysing how the Service is accessed and used;
  • measure the effectiveness of our advertising, including through advertising platforms such as Google Ads;
  • send you marketing communications, in line with the "Direct Marketing" section below;
  • protect the security and integrity of the Service and prevent fraud or misuse;
  • manage our relationships with customers, service providers and partners;
  • enforce our agreements and legal rights; and
  • comply with our legal obligations.

We only use personal information for the purpose for which it was collected, for related purposes you would reasonably expect, with your consent, or as otherwise permitted or required by law.

Direct Marketing

We may send you information about IceHrm products, services and offers where you have consented or where the law otherwise permits. Every marketing email includes a way to unsubscribe, in line with the Spam Act 2003 (Cth). You can also opt out at any time by emailing [email protected].

Even if you opt out of marketing, we will continue to send you messages about your account and the Service.

How We Disclose Personal Information

We do not sell personal information. We may disclose personal information to:

Service providers who help us operate our business and the Service, such as hosting and storage, error and performance monitoring, payment processing, customer relationship management and email delivery. They may only use the information to provide services to us and are required to protect it.

Professional advisers, such as our lawyers, accountants and auditors.

Government and law enforcement bodies and other parties where we are required or authorised by law, or where we reasonably believe disclosure is necessary to protect the rights, property or safety of IceHrm, our customers or others, or to investigate or prevent unlawful activity.

A purchaser or successor in connection with a merger, acquisition, restructure or sale of all or part of our business, subject to that party handling the information in line with this Privacy Policy.

We may also share information that has been de-identified or aggregated so that it no longer identifies any individual.

Overseas Disclosure

Our servers are located in the United States, and some of our service providers store or process information in other countries, including the United States and member states of the European Union. As a result, your personal information is likely to be disclosed to recipients outside Australia.

Before disclosing personal information overseas, we take reasonable steps to ensure the recipient handles it in a way that is consistent with the APPs, including through contractual obligations. Where the GDPR applies, we use a lawful transfer mechanism such as the European Commission's standard contractual clauses.

How We Protect Personal Information

We take reasonable steps to protect the personal information we hold from misuse, interference and loss, and from unauthorised access, modification or disclosure. Our safeguards include encryption, access controls and monitoring, as described in our Information Security Policy. No method of transmission or storage is completely secure, so we cannot guarantee the security of information.

Data breaches. If we experience a data breach that is likely to result in serious harm to the individuals concerned, we will notify the affected individuals and the Office of the Australian Information Commissioner ("OAIC") as required by the Notifiable Data Breaches scheme in the Privacy Act. Where the breach affects data we hold for a customer, we will notify the customer without undue delay so it can meet its own obligations. We will also give any notices required by other applicable laws.

Retention. We keep personal information only for as long as we need it for the purposes described in this Privacy Policy, or as required by law, for example tax and accounting records. When we no longer need it, we take reasonable steps to destroy it or de-identify it. Customer data is deleted in accordance with our Terms of Use after a customer's account is closed.

Access and Correction

You may ask for access to the personal information we hold about you, and ask us to correct it if it is inaccurate, out of date, incomplete, irrelevant or misleading. To make a request, email [email protected]. We will need to verify your identity before acting on your request.

We will respond within a reasonable period, usually within 30 days. We do not charge for making a request, and we will only charge a reasonable fee for giving access where the law allows it. If we refuse a request, we will give you our reasons in writing and tell you how you can complain.

EEA and UK Residents

If the GDPR or UK GDPR applies to our handling of your personal data, we rely on the following legal bases:

  • performance of a contract with you, or steps you ask us to take before entering into one;
  • our legitimate interests, such as ensuring and improving the safety, security and performance of the Service, where those interests are not overridden by your rights;
  • compliance with a legal obligation; and
  • your consent, for example for certain cookies and marketing. You may withdraw consent at any time without affecting processing that took place before the withdrawal.

You also have the right to request erasure of your personal data, to restrict or object to its processing, and to data portability, and the right to lodge a complaint with your local supervisory authority.

Children

The Service is designed for businesses and is not directed to people under 16. We do not knowingly collect personal information from children under 16. If you believe a child has provided us with personal information, please contact us at [email protected] and we will delete it.

Complaints

If you have a concern about how we have handled your personal information, please contact us at [email protected] with the details of your complaint. We will acknowledge your complaint promptly, investigate it and respond in writing, usually within 30 days.

If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner at www.oaic.gov.au or on 1300 363 992. If you are in the EEA or the UK, you may also complain to your local supervisory authority.

Changes to this Policy

We may update this Privacy Policy from time to time. We will publish the updated policy on this page with a new "last updated" date. If a change materially affects how we handle your personal information, we will take reasonable steps to let you know, for example by email or a notice in the Service.

Contact Us

ICE HRM Pty Ltd is responsible for the handling of your personal information. For privacy questions, requests or complaints, please contact our Privacy Officer at [email protected].