Tivunorel Logo Tivunorel
Legal

Privacy policy

This policy explains how Tivunorel Competition Intelligence Pty Ltd (ABN 45 123 456 789), trading as Tivunorel Intelligence, handles personal information. It is written to meet our obligations as an APP entity under the Privacy Act 1988 (Cth) and the thirteen Australian Privacy Principles contained in Schedule 1 of that Act.

Version
4.2
Effective from
1 July 2026
Next review
July 2027

1. Who this policy covers

This policy applies to every interaction with our practice: visitors to tivunorel.com, people who submit an enquiry or consultation request, representatives of client organisations, suppliers and subcontractors, applicants for employment, and recipients of our published research notes. It covers our Adelaide office, our staff working remotely within Australia, and the systems we use to deliver engagements.

It does not cover the internal privacy practices of our clients. When we analyse data on behalf of a sporting organisation, that organisation remains responsible for the collection notices and consents that apply to its athletes and members; our role is that of a service provider bound by the engagement agreement and by this policy.

2. Information we collect

We deliberately collect as little personal information as our work allows. In practice we hold the following categories:

CategoryTypical fields
Professional contact detailsName, position, employing organisation, work email, telephone number.
Enquiry contentThe mandate you select, your preferred timing and the free-text description of the decision you want supported.
Engagement recordsCorrespondence, meeting notes, scoping documents, invoices and remittance details.
Client-supplied datasetsPerformance, positional and competition data provided for analysis, which may include information about identified individuals.
Technical informationServer log entries: truncated IP address, user agent, referring page, timestamp.
Recruitment informationCurriculum vitae, qualifications and referee details supplied by applicants.

We do not seek government identifiers, financial account numbers belonging to individuals, or sensitive information as defined in section 6 of the Privacy Act, except where a client dataset contains medical or injury fields and the engagement agreement expressly authorises us to process them.

3. How information is collected

Most information reaches us directly from you: through the consultation request on our home page, the message form on our contact page, email to one of our published addresses, telephone conversations, or documents exchanged during an engagement. Where it is lawful and practicable to do so, we collect personal information only from the individual concerned.

Some information necessarily reaches us indirectly. Client organisations transfer datasets that describe their athletes and staff. Referees provide comment on job applicants. Publicly available competition records and published league statistics are used in benchmarking work. In each case we take reasonable steps to satisfy ourselves that the disclosing party was entitled to give us the information.

4. Why we hold information

Personal information is held for the purposes for which it was collected: to answer enquiries, to scope and price prospective work, to deliver contracted analysis and advisory services, to issue invoices and maintain accounting records, to meet our professional and statutory obligations, and to consider applications for employment.

We do not use personal information for automated profiling of individuals, we do not sell or rent it, and we do not add enquirers to a marketing list. If we ever wish to use information for a purpose that is not related to the original purpose, we will seek your consent first.

5. Athlete and player data

A substantial part of our work involves datasets that describe identified athletes: global positioning traces, accelerometer output, heart-rate series, availability records and, in some engagements, injury classifications. We treat this material as the most sensitive category of information we handle.

  • Athlete datasets are processed only within the scope defined in the engagement agreement and only by the named consultants assigned to that engagement.
  • Wherever the analytical question permits it, we work with pseudonymised identifiers supplied by the client rather than names.
  • Athlete data is never combined across clients, and never used to build models offered to another organisation.
  • Datasets are held in a project-specific encrypted workspace that is closed and destroyed at the end of the engagement, subject to the retention period described in section 9.
  • Any request from an athlete about their own data is referred to the employing organisation, which is the entity holding the primary relationship and the applicable consents.

6. Disclosure to third parties

We disclose personal information only where it is necessary and only to the following classes of recipient: our professional advisers, our accountants and auditors, providers of the technology infrastructure that supports our practice, and any party to whom disclosure is required or authorised by Australian law.

Each supplier that may come into contact with client information is engaged under written terms that impose confidentiality obligations and restrict processing to the services we have commissioned. We do not disclose the identity of client organisations without their prior written agreement, which is why our published research notes describe competitions and cohorts rather than named clubs.

7. Overseas storage

Our primary systems are hosted in Australian data centre regions. A small number of supporting services — notably email filtering and error monitoring — are operated by providers with infrastructure in New Zealand, Singapore and the United States, so limited personal information may be stored or accessed outside Australia.

Before engaging any such provider we assess whether it is subject to a law or binding scheme that offers protection substantially similar to the Australian Privacy Principles, and we impose contractual obligations to that effect under APP 8. We will tell you, on request, which providers are involved in an engagement that concerns you.

8. Cookies and site analytics

This website is deliberately simple. It sets a single first-party item in your browser's local storage to remember whether you have dismissed the cookie notice, so that the notice is not shown on every page. That item contains no identifier and is not transmitted to us.

We do not embed advertising pixels, social network tracking scripts or cross-site behavioural analytics. Our web server keeps standard access logs with truncated IP addresses for security and capacity purposes; these are retained for ninety days and then deleted. You may block or clear browser storage at any time without losing access to any part of the site.

9. Security and retention

We take reasonable steps to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure. Controls include encryption of data in transit and at rest, multi-factor authentication on every staff account, least-privilege access aligned to engagement teams, separate project workspaces, quarterly access reviews, and a documented response plan for eligible data breaches under the Notifiable Data Breaches scheme.

Record typeRetention period
Unsuccessful enquiries12 months from last contact
Engagement correspondence and deliverables7 years from completion
Client-supplied athlete datasets90 days after final report, unless the agreement requires earlier destruction
Accounting and tax records7 years, as required by Australian law
Unsuccessful job applications6 months, then destroyed
Web server access logs90 days

When information is no longer needed for any purpose for which it may be used or disclosed, and we are not required by law to retain it, we destroy it or de-identify it.

10. Access and correction

You may ask what personal information we hold about you, request a copy of it, and ask us to correct anything that is inaccurate, out of date, incomplete, irrelevant or misleading. Write to [email protected] or to the postal address on our contact page.

We will acknowledge your request within five business days and respond substantively within thirty days. We do not charge for making a request; if a request requires substantial retrieval work we may charge a reasonable cost-based fee, which we will tell you about before proceeding. If we refuse access or decline to make a correction, we will explain why in writing and set out the complaint options available to you.

11. Complaints

If you believe we have breached the Australian Privacy Principles, please raise it with us first at [email protected]. Complaints are handled by a director rather than the consultant involved. We will acknowledge receipt within five business days and give you a written outcome within thirty days.

If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner, GPO Box 5288, Sydney NSW 2001, by telephone on 1300 363 992, or through the OAIC website. You are not required to come to us first, although it usually resolves matters faster.

12. Changes and contact

We review this policy annually and whenever our systems or obligations change materially. The version number and effective date at the top of this page identify the current text; material changes affecting existing clients are notified by email to the engagement contact.

Privacy contact

Privacy Officer, Tivunorel Competition Intelligence Pty Ltd

Level 8, 108 King William Street, Adelaide SA 5000, Australia

Email: [email protected] · Telephone: +61 8 8123 4567