Governance

Privacy Policy

Policy owner
RIVIRhouse Pty Ltd · ABN 38 642 120 956
Last updated
August 2026

RIVIRhouse Pty Ltd complies with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. When engaged as a contracted service provider to a Queensland Government agency, we also comply with the Information Privacy Act 2009 (Qld), the Queensland Privacy Principles, and the applicable Queensland Government Enterprise Architecture (QGEA) policies.

01Compliance

We comply with the Privacy Act 1988 (Cth) and the Australian Privacy Principles.

When engaged as a contracted service provider to a Queensland Government agency, we also comply with:

  • The Information Privacy Act 2009 (Qld) and the Queensland Privacy Principles.
  • Applicable QGEA policies, including the information security policy (IS18) and the records governance policy.
  • The privacy, security, and recordkeeping terms of the engagement contract.

In those engagements the agency remains the custodian of the information. We handle it on the agency's behalf and under its direction.

02Who we share it with

We do not sell information. We disclose it only where necessary to deliver a service, where you have consented, or where required or permitted by law.

Our service providers, including cloud hosting, email, and professional advisers, are contractually bound to the same standard.

We do not routinely disclose information overseas. Our website and business systems are hosted in Australia. Where a supporting service stores data offshore, we require equivalent protection.

03How we protect it

We store information securely, restrict access to those who require it, and apply encryption in transit and at rest, access controls, and multi-factor authentication.

Queensland Government client information is managed to the applicable QGEA information security and records governance policies, and retained only as long as the contract and public records legislation require. Other information is retained only as long as required, then destroyed or de-identified.

Where a data breach is likely to cause serious harm, we notify affected individuals and the Office of the Australian Information Commissioner under the Notifiable Data Breaches scheme. Where the breach involves Queensland Government information, we notify the agency immediately so it can meet its obligations under the Queensland mandatory notification of data breach scheme.

04Review

We review this policy annually and when our obligations change. It sits alongside our Human Rights Policy and Modern Slavery Statement.