VC VAULT
PricingSign inStart free ↗
LEGAL / VC VAULT

Privacy Policy

How Vital Consult Pty Ltd handles personal information in VC Vault — including tax file numbers, bank details and other sensitive employee information our customers store on the platform.

Current document
Version
2026-09-10
Effective
10 September 2026
Entity
Vital Consult Pty Ltd
01

Clear terms.
Plain language.
No small-print theatre.

Privacy policyTerms of serviceContact us
Vital Consult Pty LtdABN 98 606 631 001

1. Who we are

VC Vault is operated by Vital Consult Pty Ltd (ABN 98 606 631 001) (we, us, our). This policy explains how we handle personal information, and is our APP privacy policy for the purposes of Australian Privacy Principle 1.3 under the Privacy Act 1988 (Cth).

Privacy questions, access and correction requests, and complaints: admin@vitalconsult.com.au.

2. Two different roles — please read this first

We handle personal information in two distinct capacities, and your rights differ depending on which applies to you.

a. Information we collect for ourselves

When you visit our website, sign up for an account, or subscribe, we collect information about you or your organisation directly. We decide how that information is used, and this policy governs it in full.

b. Information our customers put into the platform

VC Vault is a tool that organisations (our customers — typically employers) use to run their own HR and compliance paperwork. When an employer sends you a form and you fill it in, the employer is the organisation collecting your information, not us. They decide what to ask for, why, how long to keep it and who sees it. We hold it on their behalf and act on their instructions.

If you are an employee, contractor or job applicant and want to access, correct or delete information you submitted through a form, contact the organisation that sent you the form — they control it. If you can't reach them, or they don't respond, write to us at admin@vitalconsult.com.au and we will help you identify the right contact.

3. What information we collect

CategoryWhat it includesWhy we hold it
Account informationOrganisation name, ABN, business address, phone, email, password (stored only as a bcrypt hash — never in readable form), logo and brand settingsTo create and operate your account
Billing informationSubscription tier and status, and identifiers issued by StripeTo take payment and manage subscriptions. We never see or store your full card number — Stripe handles card data directly
Customer contentDocuments, letters, policies, asset registers, uploaded files and completed forms created by your organisationTo provide the service
Employee informationWhere your organisation's chosen forms request it: full name, date of birth, residential address, contact details, employment details, emergency contact, superannuation fund details, bank account (BSB and account number) and tax file numberBecause your employer asked for it on a form. See section 4
Signing recordsSignature images, the IP address and timestamp of signing, and an audit trail of signing eventsTo make electronic signatures verifiable and defensible
Technical informationIP address, browser type, pages visited and server logsSecurity, abuse prevention, rate limiting and diagnostics

Some of this is sensitive information or otherwise carries heightened obligations under Australian law. We do not ask for it for our own purposes — it reaches us only because a customer's form requests it.

4. Tax file numbers

Some forms on the platform — in particular new-starter and TFN declaration forms — ask an individual to provide their tax file number (TFN). TFNs are subject to the Privacy (Tax File Number) Rule 2015, which applies in addition to the Australian Privacy Principles.

  • The employer collects it, not us. The legal authority to ask for a TFN comes from taxation law and rests with the employer as the payer. We provide the form; the employer decides to use it.
  • Providing a TFN is voluntary. It is not an offence to decline. If you do not quote your TFN, your employer must withhold tax at the highest marginal rate, and you may not receive certain entitlements.
  • We never use a TFN as an identifier. It is not used to link records, index accounts, or identify anyone within the platform.
  • We do not disclose TFNs to anyone other than the customer that collected it, except where required or authorised by law.
  • Links that collect TFNs expire. Form links we email to individuals stop working 30 days after they are issued, and become invalid once the form is submitted.

If you believe a TFN has been mishandled, contact us at admin@vitalconsult.com.au. You may also complain to the Office of the Australian Information Commissioner (OAIC) — see section 12.

5. How we use personal information

  • To provide, maintain and support the platform
  • To generate the documents, letters and PDFs you ask us to generate
  • To send transactional email — form requests, signing requests, acknowledgement reminders, password resets and verification codes
  • To take payment and manage your subscription
  • To secure the platform, prevent abuse and investigate incidents
  • To meet our legal obligations

We do not sell personal information. We do not use customer content or employee information to train artificial intelligence models, and we do not use it for advertising or profiling.

6. Who we share it with

We use a small number of service providers to run the platform. They may access personal information only to perform their function for us.

ProviderPurposeLocation
Amazon Web ServicesApplication hosting, database and file storageSydney, Australia (ap-southeast-2)
Amazon SESSending transactional emailAustralia
StripeSubscription payments and card processingUnited States / global
AnthropicConverting blank policy and form templates into platform format, at our staff's initiation only. Completed forms and employee information are never sentUnited States
Google & Meta advertising toolsMeasuring the effectiveness of our advertising on our public marketing pagesUnited States / global

We may also disclose personal information where we are required or permitted by law, to enforce our terms, or to protect the rights and safety of any person.

7. Overseas disclosure

Customer content and employee information — including all documents, completed forms, TFNs and bank details — is stored in Australia, in AWS's Sydney region.

The exceptions in the table above (Stripe, Anthropic, and advertising tools) involve overseas recipients, primarily in the United States. None of them receive completed forms or employee information. Where we disclose personal information to an overseas recipient we take reasonable steps as required by Australian Privacy Principle 8.

8. How we protect it

Measures currently in place include:

  • Encryption in transit (TLS) for all traffic, and encryption at rest for our database and file storage
  • Passwords stored only as bcrypt hashes; administrative access protected separately from customer accounts
  • Strict separation between customer organisations — every request is scoped to the signed-in organisation
  • Documents, completed forms and signed PDFs are stored in private storage with public access blocked, and are served only through short-lived, expiring links. Branding assets you upload for your letterhead — your logo and letterhead image — are served from public URLs so they can be embedded in your documents
  • Form and signing links expire after 30 days and are invalidated on completion
  • Rate limiting on authentication, and email verification on new accounts
  • Regular security review of the platform, including independent adversarial review of the codebase

No system can be guaranteed completely secure. If a data breach occurs that is likely to result in serious harm, we will notify affected individuals and the OAIC as required by the Notifiable Data Breaches scheme, and we will notify affected customers promptly so they can meet their own obligations.

9. How long we keep it

  • Customer content is kept for as long as the customer's account is active, because employment records must be kept for at least seven years under the Fair Work Act 2009 (Cth) and taxation law.
  • After an account closes, we retain content for 90 days so it can be exported or recovered, then delete it, unless we are required to keep it longer by law.
  • Record controls depend on the record’s status. Unused drafts can be deleted. Issued or signed records are protected to preserve their evidence; where available, archiving removes a record from the working register without deleting the retained file. Contact us about a permanent-deletion request so we can assess any retention obligations.
  • Technical logs are kept for a limited period for security and diagnostic purposes.

10. Accessing and correcting your information

You may ask for access to the personal information we hold about you, and ask us to correct it if it is inaccurate, out of date or incomplete. Write to admin@vitalconsult.com.au. We will respond within 30 days. We may need to verify your identity first, and there are limited circumstances in which we may refuse — if we do, we will tell you why in writing.

If your information was submitted through a form sent by an employer, that employer controls it — see section 2b. We will refer your request to them.

11. Cookies and analytics

We use two kinds of cookies:

  • Essential cookies — these keep you signed in and protect against cross-site request forgery. The platform cannot work without them.
  • Advertising and analytics cookies — on our public marketing pages only, we use Google Ads and the Meta pixel to measure advertising performance. These do not run on the signed-in application, or on pages where individuals complete forms.

You can block or delete cookies through your browser settings, though essential cookies are required to sign in.

12. Children

The platform is a business tool and is not directed at children. Employee forms may be completed by workers under 18 where their employer lawfully employs them; that information is handled under the same protections as any other employee information.

13. Complaints

If you think we have breached the Australian Privacy Principles or the TFN Rule, please complain to us first at admin@vitalconsult.com.au. We will acknowledge within 5 business days and respond substantively within 30 days.

If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner: oaic.gov.au · 1300 363 992 · GPO Box 5218, Sydney NSW 2001.

14. Changes to this policy

We may update this policy. The version and effective date at the top of this page always show the current text. If we make a change that materially affects how we handle personal information, we will notify account holders by email before it takes effect.

15. Contact us

Vital Consult Pty Ltd · ABN 98 606 631 001
Privacy enquiries: admin@vitalconsult.com.au
General enquiries: admin@vitalconsult.com.au

VC VAULT

Workplace records, kept in order.

PrivacyTermsHome

© 2026 Vital Consult Pty Ltd