Privacy Policy
Last updated: 26 May 2026
Introduction
Percova (we, us, our) is a management consultancy providing advisory services to the private and public health sectors. We are committed to protecting the privacy and security of personal information we collect through our website at [www.percova.com] (Website) and in connection with our services.
This Privacy Policy explains what personal information we collect, why we collect it, how we use and disclose it, and what rights you have in relation to it.
This Policy is structured in two parts:
- Part A — Australian Privacy Policy: applies to all users and governs our obligations under Australian law.
- Part B — European Privacy Notice (GDPR): applies additionally to individuals located in the European Economic Area (EEA), the United Kingdom, and Switzerland.
By using our Website, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with its terms, please cease using the Website.
PART A — AUSTRALIAN PRIVACY POLICY
This section applies to all users of the Website and governs Percova's obligations under the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
A1. Our Legal Framework
Percova complies with the Privacy Act 1988 (Cth) (Privacy Act) and the thirteen Australian Privacy Principles (APPs) contained in Schedule 1 of that Act. The APPs regulate how organisations like Percova collect, use, hold and disclose personal information.
Where Percova handles health information (as defined under the Privacy Act), we also comply with the additional obligations that apply to sensitive information under APP 3 and APP 6.
A2. What Personal Information We Collect
Personal information means information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether the information or opinion is true or not, and whether or not it is recorded in a material form.
We may collect the following types of personal information through the Website:
- Full name
- Email address
- Phone number
- Organisation or employer name and role
- The nature of your enquiry or the subject matter of any message you send us
- Technical data such as your IP address, browser type, device type, and pages visited (collected automatically via cookies and analytics tools)
We do not collect sensitive information (including health information) through the Website. If you engage Percova for consulting services, the collection of any sensitive or health-related information will be governed by a separate agreement.
A3. How We Collect Personal Information
We collect personal information directly from you when you:
- complete and submit a contact or enquiry form on the Website
- send us an email or otherwise communicate with us
- subscribe to any mailing list or newsletter
We may also collect certain technical information automatically when you visit the Website, through cookies and similar technologies.
We will only collect personal information by lawful and fair means. Where it is reasonable and practicable to do so, we will collect personal information directly from you.
A4. Why We Collect and Use Your Personal Information
Percova collects and uses personal information for the following primary purposes:
- to respond to your enquiries and communicate with you
- to provide, manage and improve our services
- to send you information about Percova that may be of interest to you, where you have consented or we are otherwise permitted to do so
- to comply with our legal and regulatory obligations
- to maintain and improve the functionality of the Website
- for internal record-keeping and administration
We will not use your personal information for a secondary purpose unless that purpose is related to the primary purpose and you would reasonably expect us to use it in that way, or you have consented to such use.
A5. Disclosure of Personal Information
We may disclose your personal information to:
- our employees, contractors and professional advisers who need access to perform their roles
- third-party service providers who assist us in operating the Website or delivering our services (such as IT providers, cloud hosting services, and analytics platforms), subject to appropriate confidentiality arrangements
- government agencies or regulators where required or authorised by law
We do not sell, rent or trade your personal information to third parties for marketing purposes.
Cross-border disclosure: Some of our third-party service providers may be located outside Australia. Where we disclose personal information to overseas recipients, we take reasonable steps to ensure that the recipient handles the information in a manner consistent with the APPs, in accordance with APP 8.
A6. Data Quality and Security
Percova takes reasonable steps to ensure that the personal information it holds is accurate, up to date, complete and relevant to the purposes for which it is held.
We implement reasonable technical and organisational measures to protect personal information from misuse, interference, loss, and from unauthorised access, modification or disclosure. These measures include:
- secure data storage with access controls
- encrypted communications where appropriate
- restricting access to personal information to authorised personnel only
No method of transmission over the internet or electronic storage is completely secure. While we strive to protect your personal information, we cannot guarantee its absolute security.
A7. Retention of Personal Information
We retain personal information only for as long as is necessary for the purposes for which it was collected, or as required by applicable law. When personal information is no longer needed, we will take reasonable steps to destroy or de-identify it.
A8. Your Rights Under Australian Law
Under the Privacy Act and the APPs, you have the right to:
- Access: request access to personal information we hold about you
- Correction: request that we correct personal information that is inaccurate, out of date, incomplete, irrelevant or misleading
- Complaints: make a complaint if you believe we have interfered with your privacy
To make an access or correction request, please contact us using the details in section A10. We will respond within a reasonable period (generally within 30 days). We may ask you to verify your identity before processing your request.
We will not charge a fee for making a request, though we may charge a reasonable fee to cover the cost of providing access if the request is complex or voluminous.
A9. Complaints
If you believe that Percova has breached your privacy or your rights under the Privacy Act, we encourage you to contact us in the first instance so we can attempt to resolve your concern.
If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC):
- Website: www.oaic.gov.au
- Phone: 1300 363 992
- Post: GPO Box 5218, Sydney NSW 2001
A10. Contact — Australian Privacy Enquiries
For any privacy-related enquiries, access or correction requests, or complaints under Australian law, please contact:
Privacy Officer — Percova
Email: privacy@percova.com
PART B — EUROPEAN PRIVACY NOTICE (GDPR)
This section applies additionally to individuals located in the European Economic Area (EEA), the United Kingdom, and Switzerland. It supplements Part A and governs Percova's obligations under the EU General Data Protection Regulation (Regulation (EU) 2016/679) (GDPR) and, where applicable, the UK GDPR.
B1. Our Legal Framework
The GDPR applies to Percova's processing of personal data belonging to individuals in the EEA where Percova offers services to, or monitors the behaviour of, those individuals. Personal data under the GDPR means any information relating to an identified or identifiable natural person (data subject).
For the purposes of the GDPR, Percova acts as the data controller in respect of personal data collected through the Website.
B2. What Personal Data We Collect
The categories of personal data we collect through the Website are set out in section A2 above. Under the GDPR, we do not process special categories of personal data (including health data) through the Website.
B3. Legal Bases for Processing
We process your personal data only where we have a valid legal basis to do so. The legal bases we rely on are:
- Legitimate interests (Article 6(1)(f)): We process data such as enquiry details and technical data to operate and improve the Website and to respond to your communications. We have assessed that our legitimate interests are not overridden by your rights and interests.
- Consent (Article 6(1)(a)): Where you have opted in to receive marketing communications or have consented to non-essential cookies, we process your data on the basis of your consent. You may withdraw consent at any time without affecting the lawfulness of prior processing.
- Legal obligation (Article 6(1)(c)): We may process your data where required to comply with a legal obligation to which we are subject.
- Contract (Article 6(1)(b)): Where you engage Percova's consulting services, we process your data as necessary to perform or enter into a contract with you.
B4. International Transfers of Personal Data
Percova is based in Australia, which is outside the EEA. When we receive personal data from individuals in the EEA, we transfer that data to Australia and process it there.
Australia does not currently hold a European Commission adequacy decision. Accordingly, where required, we rely on appropriate safeguards for such transfers, which may include Standard Contractual Clauses (SCCs) approved by the European Commission under Article 46(2) GDPR, or other lawful transfer mechanisms.
You may request further information about the transfer mechanisms we use by contacting us at the details in section B9.
B5. Your Rights Under the GDPR
If you are located in the EEA, the UK, or Switzerland, you have the following rights in relation to your personal data:
- Right of access (Article 15): to obtain confirmation of whether we process your data and to receive a copy of it
- Right to rectification (Article 16): to have inaccurate personal data corrected or incomplete data completed
- Right to erasure (Article 17): to request deletion of your personal data in certain circumstances (the 'right to be forgotten')
- Right to restriction of processing (Article 18): to request that we restrict processing of your data in certain circumstances
- Right to data portability (Article 20): to receive your personal data in a structured, commonly used and machine-readable format and to transmit it to another controller, where technically feasible
- Right to object (Article 21): to object to processing based on legitimate interests or for direct marketing purposes
- Right to withdraw consent: where we rely on consent as our legal basis, to withdraw it at any time without affecting prior lawful processing
- Rights related to automated decision-making (Article 22): Percova does not engage in automated decision-making or profiling that produces legal or similarly significant effects
To exercise any of these rights, please contact us using the details in section B9. We will respond within one month of receipt of your request. This period may be extended by a further two months in complex cases, and we will notify you if this is the case.
We may need to verify your identity before responding to a request. We will not charge a fee for handling requests unless they are manifestly unfounded or excessive.
B6. Retention
We retain personal data for no longer than is necessary for the purposes for which it was collected, taking into account our legal obligations and any applicable limitation periods. In general:
- enquiry and contact data is retained for up to 3 years from last contact
- technical and analytics data is retained in accordance with our cookie and analytics provider settings (typically 12–26 months)
Where we are required to retain data for longer periods by law, we will do so. When data is no longer required, it is securely deleted or anonymised.
B7. Data Security
We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, in accordance with Article 32 GDPR. These measures are described in section A6 above.
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, and will notify affected individuals where required under Article 34 GDPR.
B8. Complaints to a Supervisory Authority
You have the right to lodge a complaint with the relevant data protection supervisory authority in the EU Member State of your habitual residence, place of work, or place of the alleged infringement.
For UK residents, the relevant authority is the Information Commissioner's Office (ICO):
- Website: www.ico.org.uk
- Phone: 0303 123 1113
We encourage you to contact us in the first instance to resolve any concern before escalating to a supervisory authority.
B9. Contact — GDPR Enquiries
As Percova is based outside the EEA, please note that we do not currently have a designated EU or UK representative for the purposes of Article 27 GDPR. If this changes, we will update this Policy accordingly.
For any GDPR-related enquiries, or to exercise any of your rights under Part B, please contact:
Data Protection Contact — Percova
Email: [privacy@percova.com]
GENERAL PROVISIONS
Updates to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will post the revised Policy on the Website with an updated 'Last updated' date. We encourage you to review this Policy periodically.
Where changes are material, we will take reasonable steps to bring them to your attention (for example, by placing a notice on the Website).