What this website collects

Short, because the answer is short.

This website

Almost nothing, unless you write to us

This site runs no advertising scripts and builds no profile of you. It is a set of static pages served from a content delivery network, plus the cookies described below — one necessary, and two more only if you switch on Analytics.

Fonts are loaded from Google Fonts, which means your browser makes a request to fonts.googleapis.com and fonts.gstatic.com to fetch them. No other third-party request is made by these pages.

The demo request form emails what you type to us so we can reply to it. This website does not store it anywhere else. It is only ever used to answer you, and it is not shared or sold.

To ask what we hold about an enquiry, or to have it deleted, email info@securevcms.com.

Cookies

One necessary cookie, and an optional switch

When you open this site you are asked whether to allow anything beyond what it needs to function. That choice, and nothing else, is written to a cookie called vcms_cookie_consent, so the banner does not ask you again on every page. It is set regardless of what you choose, because it exists to remember the choice itself — under Australian Privacy Principle 1 of the Privacy Act 1988 (Cth), this is the strictly-necessary kind, not a tracking cookie, and it expires after 12 months.

The banner also offers an Analytics switch, off by default. Only if you turn it on, this site records which of its pages you view and which of its main buttons you click, so we can see what visitors find useful. It sets two first-party cookies holding random identifiers: vcms_vid, which recognises a returning browser for 12 months, and vcms_sid, which groups one visit and expires after 30 minutes of inactivity. Alongside each record we keep the referring page, your browser's user agent string, and the approximate country, region and city our hosting provider derives from the connection — never your IP address itself. Nothing you type is recorded, it is not shared with any third party, and it is kept for 24 months and then deleted. Turning the switch off stops it immediately and removes both cookies.

Separately from the cookie itself, the choice you make — accept or decline, and when — is recorded once to a database as an audit trail, so it can be shown as evidence that a given decision was made, if that is ever needed. That record carries your browser's user agent string and a salted, one-way hash of your IP address — never the address itself — and nothing from your later visits is added to it. It is kept only as evidence of that one decision, not linked to your name or any other record we hold about you, and is not used to build a profile. It is kept for 24 months, the default period for evidence of a decision like this one, and then deleted.

You can change your choice at any time:

The product

Personal information inside VCMS

Different question, different answer, and mostly it is not ours to answer.

When an organisation runs VCMS, that organisation decides what it collects from its visitors and contractors, and it is that organisation which issues them a privacy notice. AIIDA GROUP PTY LTD operates the platform on their behalf.

What the platform provides is the machinery to keep those promises: retention periods per class of data with a disposal cycle that actually runs against them; identity images held in a separate store so disposal deletes rows rather than depending on somebody remembering to clear a column; consent captured as a record with a version and a timestamp; export or purge of everything held about one person; and a residency register that computes, for a running deployment, which services carry data where.

If you are a visitor or contractor asking about your own information, the organisation whose site you attended is the right place to ask. They hold the record and they set the retention period.

See also the terms & conditions for using this website, and how to ask for your account to be deleted.