1. Who we are
VC Vault is operated by Vital Consult Pty Ltd (ABN 98 606 631 001) (we, us, our). This policy explains how we handle personal information, and is our APP privacy policy for the purposes of Australian Privacy Principle 1.3 under the Privacy Act 1988 (Cth).
Privacy questions, access and correction requests, and complaints: admin@vitalconsult.com.au.
2. Two different roles — please read this first
We handle personal information in two distinct capacities, and your rights differ depending on which applies to you.
a. Information we collect for ourselves
When you visit our website, sign up for an account, or subscribe, we collect information about you or your organisation directly. We decide how that information is used, and this policy governs it in full.
b. Information our customers put into the platform
VC Vault is a tool that organisations (our customers — typically employers) use to run their own HR and compliance paperwork. When an employer sends you a form and you fill it in, the employer is the organisation collecting your information, not us. They decide what to ask for, why, how long to keep it and who sees it. We hold it on their behalf and act on their instructions.
If you are an employee, contractor or job applicant and want to access, correct or delete information you submitted through a form, contact the organisation that sent you the form — they control it. If you can't reach them, or they don't respond, write to us at admin@vitalconsult.com.au and we will help you identify the right contact.
3. What information we collect
| Category | What it includes | Why we hold it |
|---|---|---|
| Account information | Organisation name, ABN, business address, phone, email, password (stored only as a bcrypt hash — never in readable form), logo and brand settings | To create and operate your account |
| Billing information | Subscription tier and status, and identifiers issued by Stripe | To take payment and manage subscriptions. We never see or store your full card number — Stripe handles card data directly |
| Customer content | Documents, letters, policies, asset registers, uploaded files and completed forms created by your organisation | To provide the service |
| Employee information | Where your organisation's chosen forms request it: full name, date of birth, residential address, contact details, employment details, emergency contact, superannuation fund details, bank account (BSB and account number) and tax file number | Because your employer asked for it on a form. See section 4 |
| Signing records | Signature images, the IP address and timestamp of signing, and an audit trail of signing events | To make electronic signatures verifiable and defensible |
| Technical information | IP address, browser type, pages visited and server logs | Security, abuse prevention, rate limiting and diagnostics |
Some of this is sensitive information or otherwise carries heightened obligations under Australian law. We do not ask for it for our own purposes — it reaches us only because a customer's form requests it.
4. Tax file numbers
Some forms on the platform — in particular new-starter and TFN declaration forms — ask an individual to provide their tax file number (TFN). TFNs are subject to the Privacy (Tax File Number) Rule 2015, which applies in addition to the Australian Privacy Principles.
- The employer collects it, not us. The legal authority to ask for a TFN comes from taxation law and rests with the employer as the payer. We provide the form; the employer decides to use it.
- Providing a TFN is voluntary. It is not an offence to decline. If you do not quote your TFN, your employer must withhold tax at the highest marginal rate, and you may not receive certain entitlements.
- We never use a TFN as an identifier. It is not used to link records, index accounts, or identify anyone within the platform.
- We do not disclose TFNs to anyone other than the customer that collected it, except where required or authorised by law.
- Links that collect TFNs expire. Form links we email to individuals stop working 30 days after they are issued, and become invalid once the form is submitted.
If you believe a TFN has been mishandled, contact us at admin@vitalconsult.com.au. You may also complain to the Office of the Australian Information Commissioner (OAIC) — see section 12.
5. How we use personal information
- To provide, maintain and support the platform
- To generate the documents, letters and PDFs you ask us to generate
- To send transactional email — form requests, signing requests, acknowledgement reminders, password resets and verification codes
- To take payment and manage your subscription
- To secure the platform, prevent abuse and investigate incidents
- To meet our legal obligations
We do not sell personal information. We do not use customer content or employee information to train artificial intelligence models, and we do not use it for advertising or profiling.
6. Who we share it with
We use a small number of service providers to run the platform. They may access personal information only to perform their function for us.
| Provider | Purpose | Location |
|---|---|---|
| Amazon Web Services | Application hosting, database and file storage | Sydney, Australia (ap-southeast-2) |
| Amazon SES | Sending transactional email | Australia |
| Stripe | Subscription payments and card processing | United States / global |
| Anthropic | Converting blank policy and form templates into platform format, at our staff's initiation only. Completed forms and employee information are never sent | United States |
| Google & Meta advertising tools | Measuring the effectiveness of our advertising on our public marketing pages | United States / global |
We may also disclose personal information where we are required or permitted by law, to enforce our terms, or to protect the rights and safety of any person.
7. Overseas disclosure
Customer content and employee information — including all documents, completed forms, TFNs and bank details — is stored in Australia, in AWS's Sydney region.
The exceptions in the table above (Stripe, Anthropic, and advertising tools) involve overseas recipients, primarily in the United States. None of them receive completed forms or employee information. Where we disclose personal information to an overseas recipient we take reasonable steps as required by Australian Privacy Principle 8.
8. How we protect it
Measures currently in place include:
- Encryption in transit (TLS) for all traffic, and encryption at rest for our database and file storage
- Passwords stored only as bcrypt hashes; administrative access protected separately from customer accounts
- Strict separation between customer organisations — every request is scoped to the signed-in organisation
- Documents, completed forms and signed PDFs are stored in private storage with public access blocked, and are served only through short-lived, expiring links. Branding assets you upload for your letterhead — your logo and letterhead image — are served from public URLs so they can be embedded in your documents
- Form and signing links expire after 30 days and are invalidated on completion
- Rate limiting on authentication, and email verification on new accounts
- Regular security review of the platform, including independent adversarial review of the codebase
No system can be guaranteed completely secure. If a data breach occurs that is likely to result in serious harm, we will notify affected individuals and the OAIC as required by the Notifiable Data Breaches scheme, and we will notify affected customers promptly so they can meet their own obligations.
9. How long we keep it
- Customer content is kept for as long as the customer's account is active, because employment records must be kept for at least seven years under the Fair Work Act 2009 (Cth) and taxation law.
- After an account closes, we retain content for 90 days so it can be exported or recovered, then delete it, unless we are required to keep it longer by law.
- Record controls depend on the record’s status. Unused drafts can be deleted. Issued or signed records are protected to preserve their evidence; where available, archiving removes a record from the working register without deleting the retained file. Contact us about a permanent-deletion request so we can assess any retention obligations.
- Technical logs are kept for a limited period for security and diagnostic purposes.
10. Accessing and correcting your information
You may ask for access to the personal information we hold about you, and ask us to correct it if it is inaccurate, out of date or incomplete. Write to admin@vitalconsult.com.au. We will respond within 30 days. We may need to verify your identity first, and there are limited circumstances in which we may refuse — if we do, we will tell you why in writing.
If your information was submitted through a form sent by an employer, that employer controls it — see section 2b. We will refer your request to them.
11. Cookies and analytics
We use two kinds of cookies:
- Essential cookies — these keep you signed in and protect against cross-site request forgery. The platform cannot work without them.
- Advertising and analytics cookies — on our public marketing pages only, we use Google Ads and the Meta pixel to measure advertising performance. These do not run on the signed-in application, or on pages where individuals complete forms.
You can block or delete cookies through your browser settings, though essential cookies are required to sign in.
12. Children
The platform is a business tool and is not directed at children. Employee forms may be completed by workers under 18 where their employer lawfully employs them; that information is handled under the same protections as any other employee information.
13. Complaints
If you think we have breached the Australian Privacy Principles or the TFN Rule, please complain to us first at admin@vitalconsult.com.au. We will acknowledge within 5 business days and respond substantively within 30 days.
If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner: oaic.gov.au · 1300 363 992 · GPO Box 5218, Sydney NSW 2001.
14. Changes to this policy
We may update this policy. The version and effective date at the top of this page always show the current text. If we make a change that materially affects how we handle personal information, we will notify account holders by email before it takes effect.
15. Contact us
Vital Consult Pty Ltd · ABN 98 606 631 001
Privacy enquiries: admin@vitalconsult.com.au
General enquiries: admin@vitalconsult.com.au