Australian time & attendance specialists since 1964
Home/Privacy policy
Legal

Privacy Policy

Reset Pty Ltd (ACN 005 259 861) as trustee for the Dickson Business Trust (ABN 78 634 316 430)

Workforce management systems, time and attendance data, customer records and biometric information.

Version 2.1 (web) · Effective 1 January 2026 · Next review December 2026

Compliance framework: Privacy Act 1988 (Cth) — Australian Privacy Principles (APPs 1–13). Biometric templates are classified as sensitive information and receive heightened protection under this policy.

1. Introduction

Reset Pty Ltd ("Reset", "we", "us" or "our") is an Australian company headquartered in Melbourne, Victoria. We supply and support workforce management and time and attendance solutions, including the TA100 and Genesis applications, integrations with time-clock hardware, and associated customer support services.

We are committed to protecting the privacy and security of the personal information entrusted to us by our customers, their employees, and other individuals with whom we interact. This Privacy Policy explains, in plain language, how we collect, hold, use and disclose personal information in connection with our products and services.

This Policy is issued in compliance with the Privacy Act 1988 (Cth) (the "Privacy Act") and the Australian Privacy Principles ("APPs") contained in Schedule 1 of that Act.

2. Scope

This Policy applies to:

  • all personal information collected or handled by Reset while operating its business;
  • personal information processed by our software on behalf of customer organisations (businesses and employers who license our software — referred to in this Policy as "Clients");
  • biometric information and biometric templates generated by time-clock hardware integrated with our software; and
  • personal information of prospective and current Clients, their authorised contacts, and employees of those Clients whose records appear within our workforce management systems.

Note to Clients: where Reset processes personal information on behalf of a Client organisation (for example, employee attendance records), the Client is the primary data controller responsible for its own obligations under the Privacy Act in respect of that data. Reset acts as a processor or service provider in that context. Clients should ensure their own employees are notified of their privacy practices, including this Policy where relevant.

3. Personal information we collect

3.1 Client and contact information

When an organisation engages Reset as a software or support provider, we may collect the following personal information about authorised contacts: full name and job title; business email address and telephone number; billing and postal address; payment information (processed via secure third-party payment providers); support correspondence and service records.

3.2 Employee workforce data (processed on behalf of Clients)

Our workforce management software processes the following categories of employee data on behalf of our Clients: employee name and employee or badge ID number; employment type, department and work schedule; clock-in and clock-out times, shift hours and attendance records; leave balances and leave transactions; payroll-related calculations (where enabled); any other workforce data a Client elects to configure within the system.

Tax File Numbers: our software includes an optional field allowing Clients to record employee TFNs. Where a Client uses this feature, TFN data is stored solely on the Client's own systems and is not transmitted to or retained on Reset's systems. Reset support staff may incidentally encounter TFN data when accessing a Client's system during a support engagement; they are bound by confidentiality obligations and must not access, copy or record TFN information beyond what is incidentally visible during the performance of support duties.

3.3 Biometric information

Where a Client deploys time-clock hardware with biometric capability, the system processes biometric templates derived from employee biometric data. Reset supports two types of biometric time-clock device:

  • facial recognition terminals, which analyse facial geometry; and
  • fingerprint-capable terminals, which analyse fingerprint ridge and valley patterns.

In both cases the biometric data is classified as sensitive information under the Privacy Act and is subject to the heightened handling requirements described in Section 5.

3.4 Website and support interactions

Name and contact details submitted through enquiry or support forms; technical and diagnostic information submitted during support engagements; communications via email or phone.

Website analytics and cookies: reset.com.au does not currently use website analytics or advertising cookies, and does not set cookies to track visitors between sites. We do not sell visitor data. Our web host records standard server logs (including IP address and pages requested) for security and diagnostic purposes.

4. How we collect personal information

We collect personal information: directly from individuals, when they contact us, sign up for services or correspond with us; from Client organisations, when they provide employee data for loading into our software or for support purposes; automatically, when time-clock hardware integrated with our software captures attendance events (including biometric matching events); and from publicly available sources, where permitted.

We will only collect personal information that is reasonably necessary for one or more of the purposes described in this Policy. We will not collect personal information by unlawful means.

5. Biometric information — special handling

We recognise that biometric information is particularly sensitive. This section explains exactly what biometric data is collected, how it is handled, and what protections are in place.

5.1 What is a biometric template?

When a Client deploys biometric time-clock hardware, the device analyses the employee's biometric data and creates a mathematical template (sometimes called a "faceprint" for facial devices, or a "fingerprint template" for fingerprint devices):

  • facial recognition devices measure the geometry of the face — distances between features such as eyes, nose, mouth and jaw — and encode these measurements as a binary data file;
  • fingerprint devices analyse the unique ridge and valley patterns of the finger and encode those measurements as a binary data file.

In both cases the template is a series of numbers — not a photograph, image or scan of the original biometric. The algorithm is one-directional: it is computationally infeasible to reconstruct the original face image or fingerprint from the template data.

Key point: no face image or fingerprint image is stored on the device, in our software, or transmitted across a network. Only the mathematical template is retained.

5.2 How the template is used

The biometric template is used solely to verify an employee's identity at the time they clock in or clock out. The same four-stage process applies to facial and fingerprint devices:

  1. Capture — a scan is taken by the device during enrolment.
  2. Extraction — unique measurement data is extracted and a template is created.
  3. Comparison — on subsequent clock events, the device compares a new scan against the stored template.
  4. Matching — the system confirms or denies a match, recording the attendance event accordingly.

The template is device-specific: it is meaningless to, and cannot be used by, any biometric system outside the closed system in which it was created.

5.3 Consent

As biometric templates are classified as sensitive information under the Privacy Act, Reset recommends that Client organisations consider their own privacy notification obligations when deploying biometric time-clock hardware. This may include informing employees about the type of biometric device in use, the purposes for which their biometric data will be processed, and the protections in place.

5.4 Retention and deletion

Biometric templates are retained on the time-clock device and/or within the Client's system only for as long as is necessary for attendance verification purposes. Under APP 11.2, Clients are responsible for ensuring that biometric templates are destroyed or de-identified once no longer required for that purpose. Reset recommends reviewing biometric data holdings when employees leave, when devices are decommissioned, or upon an individual's request, and will provide Clients with guidance and tooling to purge biometric records on request.

5.5 Security

Biometric templates are protected by proprietary algorithms and data encryption. The closed-system architecture ensures templates cannot be matched against external biometric databases; the stored mathematical value is meaningless to any third-party biometric device or system.

6. Purposes for which we use personal information

We use personal information only for purposes directly related to our business activities and the services we provide:

  • Delivering our software and services — configuring, installing and supporting workforce management software; processing and displaying employee attendance records for Client payroll and HR functions; providing remote or on-site technical support; verifying employee identity at time-clock events (including biometric verification).
  • Managing our Client relationships — communicating with Client contacts about their accounts, licences and service requests; invoicing and processing payments; responding to support tickets and general enquiries.
  • Improving our products — analysing anonymised or aggregated usage data to improve software features; internal testing and quality assurance.
  • Legal and compliance obligations — complying with applicable laws, regulations, and court or regulatory orders; protecting the rights, property or safety of Reset, our Clients, or others.

Direct marketing: we may send promotional communications to Client contacts about our products and services. Recipients may opt out at any time by contacting us using the details in Section 15. We do not use sensitive information (including biometric templates) for direct marketing purposes.

7. Disclosure of personal information

We do not sell personal information. We may disclose personal information to third parties only in the following limited circumstances: third-party service providers who assist us in delivering our services (for example cloud hosting, email and payment processors), contractually required to handle information only as directed by us and to maintain appropriate security; hardware manufacturers or distributors for the purpose of technical support related to time-clock devices; professional advisers (lawyers, accountants, auditors) under obligations of confidentiality; regulatory bodies or law enforcement agencies where required by law; and a successor entity in the event of a merger, acquisition or sale of assets, subject to equivalent privacy protections.

8. Overseas disclosure

Some of our third-party service providers may be located outside Australia. Before disclosing personal information to an overseas recipient, we take reasonable steps to ensure the recipient is subject to privacy or data protection laws at least substantially similar to the APPs, or we obtain the individual's consent, in accordance with APP 8. Key overseas service providers currently include Microsoft, and our hardware manufacturers' overseas support channels. We will update this description as our third-party arrangements change.

9. Cloud and enterprise deployments

Our software may be deployed on-premises on a Client's own servers (data never leaves the Client's network), hosted on infrastructure managed by Reset or a designated third-party cloud provider, or in hybrid configurations. In hosted deployments we ensure all personal information — including employee data transmitted between time-clock hardware and the hosted platform — is encrypted in transit and at rest, with access controls restricting data to authorised users. Clients in regulated industries should discuss their specific compliance requirements with us before selecting a deployment model.

10. Data quality and accuracy (APP 10)

We take reasonable steps to ensure the personal information we collect and use is accurate, up to date and complete. We rely on Clients and individuals to notify us of changes. Clients are responsible for maintaining the accuracy of employee records within the system.

11. Data security (APP 11)

We apply technical and organisational security measures including: encryption of data in transit (TLS/HTTPS) and at rest; access control and role-based permissions within our software; secure coding practices and regular security review; restricted physical and logical access to development and production systems; and incident response procedures for suspected data breaches.

In the event of a data breach likely to result in serious harm, we will comply with the Notifiable Data Breaches (NDB) scheme under Part IIIC of the Privacy Act, including notifying affected individuals and the Office of the Australian Information Commissioner (OAIC) as required.

Please note that transmission of information via the internet is not completely secure. While we apply strict security procedures once we have received your information, we cannot guarantee the security of data during transmission to us; any such transmission is at your own risk.

11.1 Biometric-specific security measures

In addition to the general measures above, biometric templates are protected by proprietary one-way mathematical algorithms that prevent reverse-engineering to the original image; device-level encryption, so templates cannot be read by third-party biometric systems; and closed-system architecture, so templates are not transmitted to any external network or database beyond the Client's own environment.

12. Data retention

We retain personal information only as long as necessary for the purposes for which it was collected, or as required by law: Client contact information for the duration of the contractual relationship plus seven (7) years for legal and audit purposes; employee workforce data held on behalf of Clients in accordance with the Client's own retention policy, deleted or returned upon termination of the service agreement; biometric templates per Section 5.4; support and correspondence records for seven (7) years following the close of the matter.

13. Access to and correction of personal information (APPs 12–13)

You have the right to request access to the personal information we hold about you, and to ask us to correct information that is inaccurate, out of date, incomplete, irrelevant or misleading. Contact our Privacy Officer using the details in Section 15; we will respond within 30 days of a written request and may ask you to verify your identity. If we are unable to grant access (for example, because doing so would unreasonably prejudice another individual's privacy), we will provide written reasons.

Employee records: employees whose personal information is processed by our software on behalf of their employer should direct access and correction requests to their employer (the Client) in the first instance. Reset will cooperate with Clients to facilitate such requests.

14. Privacy complaints

If you have a concern about how we have handled your personal information, please contact our Privacy Officer in the first instance. We take all privacy complaints seriously and will endeavour to respond within 30 days. If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC): www.oaic.gov.au · 1300 363 992 · GPO Box 5218, Sydney NSW 2001.

15. Contact us

Privacy Officer, Reset Pty Ltd

16. Updates to this policy

We may update this Privacy Policy from time to time to reflect changes in our business practices, legal requirements or technology. The current version is always available at reset.com.au/privacy-policy.

Appendix A — Australian Privacy Principles summary

The table below summarises the 13 Australian Privacy Principles and how Reset Pty Ltd gives effect to each.

PrincipleWhat it requiresHow Reset Pty Ltd complies
APP 1Open and transparent management of personal informationWe publish this Privacy Policy and make it available to all individuals whose information we handle.
APP 2Anonymity and pseudonymityWhere practicable, individuals may interact with us without identifying themselves (e.g. general website enquiries).
APP 3Collection of solicited personal informationWe collect only information reasonably necessary for our stated purposes, using lawful and fair means.
APP 4Unsolicited personal informationIf we receive information we did not solicit and could not have lawfully collected, we destroy or de-identify it.
APP 5Notification of collectionWe notify individuals of the purposes for collection at or before the time of collection (e.g. via this Policy and Client-facing notices).
APP 6Use or disclosureWe use and disclose personal information only for the purposes for which it was collected, or for directly related secondary purposes the individual would reasonably expect.
APP 7Direct marketingWe send marketing only to Client contacts and only in compliance with APP 7 and the Spam Act 2003. Opt-out is available at any time. Sensitive information (including biometric data) is never used for marketing.
APP 8Cross-border disclosureBefore disclosing information overseas, we take reasonable steps to ensure equivalent privacy protections are in place. See Section 8.
APP 9Government-related identifiersWe do not adopt, use, or disclose government-related identifiers (e.g. Tax File Numbers) as our own identifiers.
APP 10Quality of personal informationWe take reasonable steps to keep personal information accurate, complete, and up to date. See Section 10.
APP 11Security of personal informationWe apply technical and organisational security controls. Biometric templates have additional dedicated protections. See Section 11.
APP 12Access to personal informationIndividuals may request access to their personal information. We respond within 30 days. See Section 13.
APP 13Correction of personal informationIndividuals may request correction of inaccurate information. We respond within 30 days. See Section 13.