Privacy Policy
Last updated 1 August 2026
McKercher Corporation Pty Ltd (ACN 164 130 581) ("McKercher Corporation", "we", "us") is committed to protecting your privacy. This policy explains what personal information we collect through mckercher.com.au, how we use and protect it, and the rights you have over it.
This policy is written to meet the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), and, for visitors in the European Union, the European Economic Area, and the United Kingdom, the General Data Protection Regulation (GDPR) and UK GDPR.
Who is responsible for your data
The data controller is McKercher Corporation Pty Ltd, Operations: 3/90 Discovery Drive, Bibra Lake, Western Australia 6163, Australia. For any privacy request, contact us at hello@mckerchercorp.com or (08) 6171 4111.
What we collect
- Enquiry details. When you use our contact form we collect your name, email address, and, if you provide them, your phone number, subject, and message.
- Career enquiry details. When you submit an expression of interest, we also collect your selected role family and any licences, accreditations, work experience, or professional profile link you choose to provide.
- Workforce account details. Employees and subcontractors using McKercher OS have a private account record containing their name, email, relationship to the group, business, position, assigned manager relationship, account status, and relevant work dates.
- Time, clock, and work records. Workforce members may record hours, breaks, business allocation, project or job references, and work notes. When a workforce member deliberately clocks on or off, we also record a server timestamp, the device timestamp, the assigned job where selected, browser-provided latitude and longitude, reported accuracy, and the outcome of the location request. Location is requested once for each clock action. McKercher OS does not collect continuous or background location between clock events. These records support review and business record keeping. They do not calculate pay or leave entitlements.
- Leave and supporting evidence. Employees may submit leave dates, leave type, requested hours, a short note, and supporting evidence when reasonably required. Evidence may include health information such as a medical certificate and is treated as sensitive information.
- Readiness and supporting evidence. Employees and subcontractors may receive role-based requirements covering licences, qualifications, training, insurance, onboarding, and controlled-policy acknowledgements. They may provide expiry dates, completion notes, and private evidence for authorised review.
- Assigned jobs and safety records. Workforce members may be assigned to job records containing a site, scope, schedule, crew role, and Safe Work Method Statement (SWMS). SWMS records may include site conditions, hazards, controls, responsible people, review decisions, revision history, and each assigned worker's briefing acknowledgement.
- Internal HSEQ reports. Employees and subcontractors may record hazards, near misses, injuries or illness, environmental events, and property or equipment damage. A report may include the event time and location, assigned job, people involved, witnesses, immediate actions, medical or emergency-response indicators, a ServiceM8 reference, photographs or documents, later corrections, administrator triage, restricted investigation notes, and the recorded outcome. The reporter, an HSEQ reviewer with an active grant for the report, and authorised administrators can access the report. Reporter-visible and restricted investigation activity are separated in the register.
- Delegated manager authority and workbench activity. McKercher OS records a manager capability, its workforce-member, job, or business scope, who granted it, when it starts and expires, and actions taken under it. A capability grants access only to the record class and scope required for that duty. Leave managers can view leave dates, type, status, and notes but cannot view medical certificates or other workforce documents. Readiness reviewers can view supporting evidence only when it is required for the review. HSEQ reviewers can view restricted investigation activity only for reports within their active grant scope. Time and SWMS authority does not grant access to leave information, readiness evidence, or restricted HSEQ activity.
- Workforce notifications. McKercher OS may create in-app notices for assigned reviews, decisions, due dates, expiries, and escalations. We record delivery and read status where needed to manage the action. Related email alerts contain only the minimum context needed to direct the recipient back to the authenticated workspace. Medical evidence, readiness evidence, restricted HSEQ notes, and detailed workforce records are not included in notification email.
- Staff communication receipts. McKercher OS records when an authenticated workforce member views or acknowledges a published group update so required communication can be followed up.
- Enquiry workflow records. Administrators may record an internal owner, workflow status, response timing, and operational notes against a contact enquiry. These notes are restricted to authorised administrators.
- Consent-based analytics. If you accept analytics cookies, we collect usage data (pages viewed, approximate location, device and browser type) through Google Analytics / Google Tag Manager. These do not load until you consent.
- Technical logs. Our hosting and network providers automatically process your IP address and browser user-agent to deliver the site securely and to prevent abuse.
We do not sell personal information. We ask workforce members to provide only the information reasonably needed for the relevant work or leave record.
How we use it, and our lawful basis
| Purpose | Lawful basis (GDPR Art. 6) |
|---|---|
| Responding to and managing your enquiry | Consent, and our legitimate interest in answering you |
| Reviewing a career expression of interest | Consent, and our legitimate interest in workforce planning and recruitment |
| Managing workforce identities, clock events, timecards, and work records | Performance of an employment or contracting arrangement, legal obligation, and legitimate interests in workforce administration and accurate time records |
| Managing employee leave and supporting evidence | Employment obligations, legal obligation, and, where required, consent or another lawful basis applying to employment and health information |
| Managing onboarding, credentials, training, insurance, and policy acknowledgements | Performance of an employment or contracting arrangement, legal obligation, and legitimate interests in workforce safety, governance, and assignment readiness |
| Managing assigned jobs, SWMS revisions, worker consultation, and briefing acknowledgements | Performance of an employment or contracting arrangement, legal obligation, and legitimate interests in workplace safety and operational control |
| Receiving, investigating, correcting, and retaining internal HSEQ reports | Performance of an employment or contracting arrangement, legal obligation, and legitimate interests in workplace health and safety, incident prevention, and accountable follow-through |
| Assigning and recording delegated manager authority, reviews, decisions, notifications, and escalations | Performance of an employment or contracting arrangement, legal obligation, and legitimate interests in accountable workforce administration, safety, and access control |
| Recording receipt of required staff communication | Legal obligation and legitimate interests in governance, safety communication, and accountable operations |
| Measuring and improving the website | Consent (analytics cookies) |
| Securing the site and preventing abuse | Legitimate interests |
| Meeting legal and regulatory obligations | Legal obligation |
Cookies and consent
Essential cookies are required for the site to function. Analytics and marketing cookies load only after you accept them in the cookie banner. You can change or withdraw that choice at any time using "Cookie preferences" in the site footer, which reopens the same banner on the page you are already on.
One exception is worth stating plainly. The map on our contact page is embedded from Google Maps, and it loads when that page loads, before the banner is answered. Google may set cookies and receive your IP address as a result. If you would rather it did not, avoid the contact page or block third-party cookies for this site; nothing else on the site behaves this way.
Service providers (sub-processors)
We use the following processors to run the website. Some are located in, or transfer data to, the United States; where that occurs, transfers are protected by Standard Contractual Clauses or equivalent safeguards.
- Google Maps: the embedded map on our contact page, which loads for every visitor to that page and is the one exception noted above.
- Supabase: database, private file storage, and authentication for enquiries and McKercher OS workforce records.
- Resend: sending transactional email, including privacy-minimised alerts that direct workforce members to authenticated McKercher OS records.
- Vercel: website hosting and delivery.
- Cloudflare: DNS, content delivery, and security.
- Google (Analytics / Tag Manager): website analytics, only with your consent.
How long we keep it
We retain contact-form enquiries and their operational history only as long as necessary to handle the request and keep reasonable business records, after which they are deleted or anonymised. Time and wages records, including clock-event location evidence associated with a timecard, are retained for the period required by applicable workplace law. Leave, onboarding, credential, training, insurance, job, SWMS, internal HSEQ, and communication receipt records are reviewed against employment, contracting, safety, legal, investigation, insurance, and records-management requirements and are not kept merely because storage remains available. Delegated authority grants, manager decisions, notifications, and audit history are retained with the workforce record needed to establish who had authority and what action was taken. Authority expiry ends future delegated access but does not erase an action or its audit history. SWMS records connected to a notifiable incident may need to be retained for at least two years, and a longer retention review period may apply where other legal or business-record obligations require it. Internal HSEQ reports use a seven-year retention review date, which is a review control rather than an automatic deletion date. Analytics data is retained according to our Google Analytics configuration.
Where the employee records exemption under the Australian Privacy Act 1988 (Cth) applies, we handle employee records within that employment context. Personal information about subcontractors, applicants, and information outside that exemption is handled in accordance with the Australian Privacy Principles.
Your rights
Subject to applicable law, you may:
- access the personal information we hold about you;
- correct inaccurate or incomplete information;
- erase your information ("right to be forgotten");
- restrict or object to certain processing;
- withdraw consent at any time (without affecting prior processing); and
- request portability of information you provided to us.
To exercise any of these, email hello@mckerchercorp.com. We will respond within the timeframes required by law. If you are in the EU/EEA/UK you may also lodge a complaint with your local supervisory authority; in Australia, with the Office of the Australian Information Commissioner (OAIC).
Security
We use authenticated access, capability and record-level controls, encryption in transit, private storage, short-lived document links, authority expiry, and audit history to protect workforce information. Delegated access requires an active grant and a matching workforce-member, job, or business scope. Leave evidence and medical certificates are not available through delegated leave authority and remain limited to the person who submitted them and authorised People administrators. Readiness evidence is available to the person, authorised administrators, and a readiness reviewer only when the evidence is required for a review within the reviewer's active scope. Clock-event location evidence is available only to the workforce member, an active time reviewer within scope, and authorised administrators. Job and SWMS records are available only to the assigned workforce, an active SWMS reviewer within job scope, and authorised administrators. Outside a recorded HSEQ delegation, internal HSEQ reports and evidence are available only to the reporter and authorised administrators. An active HSEQ reviewer with a matching business scope may also access the report, evidence, and restricted investigation activity. Restricted investigation activity is withheld from the reporter and from managers without the HSEQ review capability. Time and SWMS capabilities do not expose leave records, readiness evidence, or restricted HSEQ activity. Enquiry workflow notes are restricted to authorised administrators. No method of transmission over the internet is completely secure, but we take reasonable steps to safeguard your data.
Children
This website is not directed at children, and we do not knowingly collect information from anyone under 16.
Changes
We may update this policy from time to time. The date below indicates when it was last revised; material changes will be reflected here.
