Legal · Privacy
Privacy policy
What personal information we collect, why we collect it, how we hold it, who we disclose it to, and how you can access it or complain about how we have handled it.
This document is in draft
This document is provided in draft and is under legal review. It will be finalised before the site accepts live enquiries.
Marlow Facility Services is a registered business name of Marlow Services Group Pty Ltd · ABN [ABN-TBC]
Broadmeadows VIC 3047 · South Guildford WA 6055
Version 2.0 · Effective 1 September 2026 · Review 1 September 2027
1. Who we are and what this policy covers
Marlow Services Group Pty Ltd, trading as Marlow Facility Services, provides commercial and residential cleaning services in two states: across Melbourne's northern suburbs from a base in Broadmeadows, Victoria, and across Perth's eastern corridor and wider metropolitan area from a base in South Guildford, Western Australia. This policy applies to both, and to every person we deal with in either. It explains what personal information we collect, why we collect it, how we hold it, who we disclose it to, and how you can access it or complain about how we have handled it.
It covers information collected through our website, by phone, by email, at a site inspection, during the provision of our services, and in the course of employing people.
In this policy, personal information means information or an opinion about an identified individual, or an individual who is reasonably identifiable.
2. Are we bound by the Privacy Act? An honest answer
Probably not at launch, and we will comply anyway.
The Privacy Act 1988 (Cth) exempts a small business operator — an organisation with an annual turnover of $3 million or less. Marlow Facility Services will be well under that threshold in its first years, so on turnover alone the Australian Privacy Principles would not bind us.
But the exemption is lost, regardless of turnover, if the business does any of the following. Three on the list are live possibilities for us.
| Exception | Our position |
|---|---|
| Provides services under a Commonwealth contract | Realistic. The strategy targets government and government-adjacent work. A single Commonwealth cleaning contract makes us an APP entity for all purposes, immediately. |
| Is related to a body corporate that is subject to the Privacy Act | Must be checked. The director operates multiple entities. If any related body corporate exceeds $3 million turnover or is otherwise covered, this company is covered with it. This is a question about the group, not about this business, and it must be answered before the policy is published. |
| Is a health service provider, or holds health information | Not applicable. We clean medical premises; we do not provide a health service and we do not hold patient information. If we ever did hold health information about anyone, the exemption would be lost. |
| Trades in personal information | We do not, and will not, buy or sell personal information. |
| Operates a residential tenancy database | No. |
| Credit reporting, AML/CTF reporting entity, employee association, protected action ballots, Consumer Data Right accreditation, telecommunications data retention | None applicable. |
| Opts in voluntarily | Available to us — see below. |
Our position. We treat the Australian Privacy Principles as binding on us as a matter of policy, whether or not they bind us as a matter of law, for four reasons.
We hold keys to other people's buildings. The most sensitive information this business holds is not a name and an email address — it is knowledge of how to get inside a client's premises, and when nobody will be there. That is a higher-consequence data set than most small businesses hold, and it deserves to be handled to a higher standard than the legal minimum.
Our clients require it contractually. Medical practices, childcare centres, strata managers and government buyers ask contractors for a privacy policy. "We are exempt" is not an answer that wins a tender.
The exemption may be lost the day we win the wrong contract. Building compliant practices now costs nothing; retrofitting them under a contractual deadline costs a great deal.
The exemption does not protect us from everything. It does not affect our obligations of confidence to clients, our contractual privacy obligations, the Surveillance Devices Act 1998 (WA), or common law and statutory causes of action available to an individual whose privacy is invaded.
We may also formally opt in to Privacy Act coverage by notifying the Information Commissioner. That decision is deferred until the group question above is resolved.
3. What we collect, and why
3.1 Through the website quote form
| Field | Why we need it |
|---|---|
| Name | To address the quote and identify the enquiry |
| Email address | To send the quote and to correspond |
| Phone number | To arrange a site inspection and to contact you on the day of service |
| Service address or suburb | To determine the service zone, travel and pricing |
| Property type, bedrooms and bathrooms, or floor area | To price the job. Residential is priced by property size; commercial by area and scope |
| Service required and preferred frequency | To quote the correct service |
| Preferred start date and access notes | To schedule |
| How you heard about us | Marketing attribution only. Optional |
We collect what is needed to produce a quote and nothing else. We do not ask for a date of birth, a licence number, a rental agreement, or any government identifier on the quote form. If a field is not needed to price the job, it is not on the form.
Cookies and analytics. Our website uses cookies for basic function and may use analytics to understand how the site is used. Analytics data is aggregated and is not used to identify individuals. You can block cookies in your browser; the site will still work.
3.2 When you become a client
- Billing name, address and contact details
- Payment details — see section 4
- Access information — see section 5, which is the part of this policy that matters most
- Site details: floor plans, room counts, surface types, alarm zones, special instructions
- Service history, quality inspection reports and photographs
- Complaints, damage reports and rectification records
- For commercial clients, the names, positions and contact details of your staff who deal with us
3.3 Photographs
We take photographs of work performed, for quality documentation, for the monthly written quality inspection issued to commercial clients, and to evidence the condition of a property before and after a bond clean.
- Photographs record surfaces and spaces, not people. We do not photograph people, and if a person appears incidentally the photograph is deleted and retaken
- We do not photograph documents, screens, whiteboards, patient or client records, or anything that could disclose the confidential information of a client's own customers — this matters particularly at medical, dental, allied health and legal premises
- Photographs are not used in marketing without the client's express written consent, obtained separately from the service agreement
- Photographs are stored in our job management system with access limited to the staff who need it
3.4 Employees and job applicants
We collect from applicants and employees: contact details, work history, right to work evidence, tax file number declaration data, superannuation fund details, bank account details, emergency contact, National Police Certificate results, Working With Children Check and NDIS Worker Screening details where applicable, licences and tickets, training records, timesheets, and injury and incident records.
Tax file numbers are handled under the Privacy (Tax File Number) Rule and are used only for the purposes for which they were provided.
Screening results are treated as the most sensitive employee information we hold. They are stored separately from general personnel files, access is limited to the director, and only a yes/no clearance status and expiry date — never the underlying result — is disclosed to a client who asks for evidence of screening.
Note on the employee records exemption. The Privacy Act contains an exemption for acts and practices directly related to a current or former employment relationship. We do not rely on it to justify poor handling. Employee records are held securely and used only for employment purposes.
4. Payment information
- Residential recurring clients provide card details for a card-on-file arrangement, charged the day after service
- We do not store full card numbers on our own systems. Card details are held by our payment processor, which is PCI DSS compliant, and we hold only a token and the last four digits
- Bank account details provided for direct payment are held in our accounting system with restricted access
- We will never ask for card details by email or SMS. If you receive a message that appears to be from us asking for card details, do not respond — call us on 1300 672 034
5. Keys, access codes and premises information
This is the most sensitive information we hold and it is handled under a separate operational control, not just this policy.
Knowing a client's alarm code, key location and cleaning schedule is functionally equivalent to holding a key to their building and a timetable of when it is empty. We treat it accordingly.
5.1 What we hold
- Physical keys, swipe cards, fobs and remote controls
- Alarm codes and PINs
- Lock box codes and key safe locations
- After-hours access procedures and security company contacts
- The cleaning schedule itself — which, combined with the above, discloses when a building is unoccupied
5.2 How we handle it
- Every key, card and fob is recorded in the key and access register on issue, transfer and return, with signatures
- Keys are tagged with a code, never with the client's name or address. A lost key must not identify the building it opens
- Keys are held in a locked key cabinet at the business premises and signed out for each shift. They are not kept permanently in vehicles and not taken to a cleaner's home unless a specific written arrangement is in place with that client
- Alarm codes are stored encrypted, separately from the key register, and are disclosed only to the specific cleaners rostered to that site
- Access information is disclosed on a need-to-know basis — a cleaner receives the access details for their own sites only
- On termination of employment, every key is returned before the final pay is processed, and every code that the departing worker knew is changed at our cost. This is not a discretionary step
- On loss of a key, the client is notified immediately — the same day, not at the next service — and we meet the cost of re-keying in accordance with our terms of service and our insurance. Loss-of-keys cover is a specific item on our public liability policy
- On termination of a client contract, all keys, cards and fobs are returned to the client within 7 days, and access records are destroyed or securely archived
- Access information is never sent by unencrypted email or SMS, never written on a run sheet, and never stored in a shared spreadsheet
5.3 Confidential information seen at a client's premises
Cleaners work in medical practices, dental surgeries, allied health clinics, legal offices and childcare centres. They will inevitably see documents, screens and files.
Standing instruction to every worker: do not read it, do not photograph it, do not move it, do not discuss it. Every employee signs a confidentiality undertaking as part of their employment contract, and it survives the end of employment.
We report to the client, and to nobody else, if we find sensitive material left unsecured — a patient file on a reception desk, a screen left logged in. That is a courtesy to the client and it is also the only appropriate response.
6. CCTV footage a client shares with us
Clients sometimes share CCTV footage — to show us a cleaning issue, to raise a concern about a cleaner's conduct, or in connection with a theft or damage allegation. When a client gives us footage:
- We treat it as personal information about every identifiable person in it, including our own workers, the client's staff and third parties
- We use it only for the purpose for which it was provided — investigating that specific incident or complaint
- We do not use it for performance management unrelated to the incident, we do not copy it to personal devices, and we do not share it on any messaging platform
- Access is limited to the director and, where the footage concerns a specific worker, that worker, who is entitled to see the material relied on against them
- It is stored in a restricted folder, separately from general job records
- It is destroyed as soon as the matter it relates to is concluded, and in any event within 12 months, unless it is evidence in an ongoing insurance claim, workers compensation claim or legal proceeding
- Receipt and destruction are logged
We do not operate CCTV or any recording device at a client's premises, and our workers do not record audio or video at a client's premises. Recording without consent may be an offence under the Surveillance Devices Act 1998 (WA). A worker who is asked to record something at a site refers the request to the director.
Where footage is relied on in a disciplinary process, the worker is shown it and given a fair opportunity to respond before any decision is made.
7. Who we disclose information to
We disclose personal information only where it is necessary.
| To | What | Why |
|---|---|---|
| Our employees and supervisors | Site address, access details, scope, and any special instruction | To perform the service, on a need-to-know basis |
| Specialist subcontractors | Site address and scope only | Where a specialist service is required. They are bound by a written subcontract including confidentiality |
| Our insurers and broker | Claim details | To make or defend a claim |
| Our accountant, bookkeeper and tax agent | Billing and payroll data | Accounting, payroll and lodgement |
| Our payment processor | Tokenised payment data | To process payments |
| Our software providers | Client and job data | Accounting, payroll and scheduling systems |
| A client, on request | A worker's screening clearance status and expiry date only | To satisfy the client's own compliance requirements. We do not disclose the underlying police check content |
| Regulators and insurers | Incident and injury information | Where required by the WHS Act, the workers compensation legislation, or a lawful request |
| Real estate agents and landlords | Bond clean scope, completion and photographs | Only where the client has asked us to deal with the agent directly |
We do not sell, rent or trade personal information. We do not disclose personal information for another organisation's marketing.
Overseas disclosure. Some of our software providers may store data on servers outside Australia. We select providers who state that they hold Australian customer data in Australia where that option exists, and we will identify the countries concerned on request. The specific providers and their data locations are being confirmed as part of the legal review of this document and will be listed here before it is finalised.
8. How we keep it secure
- Access to client and employee records is limited to the staff who need it for their role
- Devices are password-protected; multi-factor authentication is used on email, accounting, payroll and scheduling systems
- Access codes are stored encrypted and separately from the key register
- Paper records are stored in a locked cabinet
- Access is removed on the day a worker leaves, and codes they held are changed
- Systems are kept updated; backups are maintained
- Workers are trained on confidentiality and access handling at induction
No system is perfect. If we become aware of unauthorised access to or disclosure of personal information, we will investigate immediately, contain it, assess whether it is likely to result in serious harm, and, where the assessment indicates it, notify the affected individuals and the Office of the Australian Information Commissioner under the Notifiable Data Breaches scheme. A breach involving keys or access codes will be notified to the affected client immediately and the affected premises re-keyed at our cost, regardless of whether any notification obligation is legally triggered.
9. How long we keep it, and how we destroy it
| Record | Retention | Basis |
|---|---|---|
| Quote enquiries that do not convert | 12 months | Follow-up, then no longer needed |
| Client records, service history, invoices | 7 years from the end of the relationship | Corporations Act 2001 s 286 and tax record-keeping |
| Employee records, payslips, time and wage records | 7 years | Fair Work Act 2009 and Fair Work Regulations |
| Superannuation records | 7 years | SGAA |
| Tax records | 5 years minimum; kept 7 to align with company records | TAA 1953 |
| Screening results (police, WWC, NDIS) | Duration of employment plus 12 months, then destroyed | No longer needed |
| Incident and injury records | 7 years, or longer where a claim is open | WHS and workers compensation |
| Keys, cards and fobs | Returned to the client within 7 days of the contract ending | Section 5 |
| Access codes and alarm PINs | Deleted within 7 days of the contract ending | Section 5 |
| CCTV footage received from a client | Until the matter concludes, and in any event 12 months maximum | Section 6 |
| Quality inspection photographs | 2 years | Dispute and warranty period |
| Marketing contact details | Until you unsubscribe | Consent |
Destruction method. Paper is shredded. Electronic records are deleted from live systems and from backups at the next backup rotation. Destruction of screening records, CCTV footage and access codes is logged.
10. Direct marketing
- We send service reminders, quotes and account correspondence because you asked us to provide a service. That is not marketing
- We will send marketing — newsletters, offers, referral programme material — only where you have consented or where you would reasonably expect it because you are a current client
- Every marketing message contains an unsubscribe function that works. Unsubscribing takes effect immediately and does not affect service correspondence
- We comply with the Spam Act 2003 (Cth) and the Do Not Call Register
11. Accessing and correcting your information
You may ask for a copy of the personal information we hold about you, and ask us to correct it if it is wrong.
- Email hello@marlowfacility.com.au or write to us at the address below
- We will verify your identity before releasing anything — this is a protection for you
- We will respond within 30 days
- Access is free. If a request requires substantial work we may charge a reasonable cost, and we will tell you what it is before we do the work
- If we refuse access, we will tell you why in writing
- If we correct information we have already disclosed, we will tell the recipient where it is reasonable to do so
12. Complaints
If you believe we have mishandled your personal information:
Contact us. Email hello@marlowfacility.com.au, marked "Privacy complaint", or call 1300 672 034. We will acknowledge within 5 business days and respond substantively within 30 days.
If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner: oaic.gov.au, 1300 363 992, or GPO Box 5218, Sydney NSW 2001.
Note on the OAIC route. If we are not an APP entity at the time of your complaint, the OAIC may not have jurisdiction. That does not change our commitment to investigate and resolve your complaint properly, and we will tell you honestly what our status is if you ask.
13. Changes to this policy, and how to contact us
We will update this policy when our practices change or when the law changes. The current version is always at marlowfacility.com.au and is dated. Material changes will be notified to current clients by email.
Privacy contact
The Director, Marlow Services Group Pty Ltd
hello@marlowfacility.com.au
Melbourne 1300 672 034 ·
Perth 1300 672 034
Broadmeadows VIC 3047 · South Guildford WA 6055 · ABN [ABN-TBC]
See also our terms of service.