Privacy policy.

Effective date: 30 July 2026

1. About this Privacy Policy

VUCA Risk Pty Ltd (ABN 32 664 289 927) ("VUCA Risk", "we", "our" or "us") is an Australian workplace risk and incident response provider.

We provide membership-based governance, escalation readiness and access to specialist response capability. We also arrange and distribute certain insurance products, including Safety Assist and Biz Assist, as an authorised representative of Chase Underwriting Solutions Pty Ltd.

This Privacy Policy explains how we collect, hold, use and disclose personal information in connection with:

  • Our website and online forms

  • VUCA Risk Membership

  • Insurance enquiries, applications, policies and claims

  • Psychosocial incident and crisis-response services

  • Broker, insurer and partner relationships

  • Training, onboarding and organisational readiness activities

  • General enquiries and communications

We manage personal information in accordance with the Privacy Act 1988 (Cth), the Australian Privacy Principles and any other applicable Australian privacy or health-records legislation.

Where consent is required by law, including for certain sensitive information, we will seek that consent. This Privacy Policy does not itself replace any consent, collection notice, insurance policy wording or contractual term that may apply to a particular service.

2. The personal information we collect

The information we collect depends on how you interact with us and the nature of the service or incident involved.

It may include:

  • Your name, date of birth and contact details

  • Your address, location and emergency contact information

  • Your employer, position, workplace and organisational role

  • Details of your broker, insurer, policyholder or membership sponsor

  • Membership, insurance policy, application and renewal information

  • Incident notifications, activation requests and claims information

  • Payment, billing and transaction information

  • Identification documents and government-issued identifiers where reasonably necessary

  • Records of meetings, telephone calls, emails and other communications

  • Complaints, feedback and dispute information

  • Website usage information, including IP address, browser, device and pages visited

3. Incident and sensitive information

Because VUCA operates in workplace incident response, the information we receive may include highly sensitive circumstances.

Depending on the incident, this may include information relating to:

  • Workplace threats, aggression, violence or assault

  • Stalking, harassment or intimidation

  • Domestic and family violence affecting the workplace

  • Cyber threats, technology-facilitated abuse or malicious communications

  • Workplace complaints, allegations and investigations

  • Physical or psychological health

  • Disability, injury or medical treatment

  • Safety plans, location, travel or temporary accommodation

  • Dependants, family members, witnesses or other affected people

  • Alleged unlawful conduct, criminal activity or criminal records

  • Legal, reputational or operational business incidents

We only collect sensitive information where it is reasonably necessary for our functions or activities and where:

  • You have provided consent

  • The information has been provided to us with appropriate authority

  • Collection is required or authorised by law

  • Collection is reasonably necessary to lessen or prevent a serious threat to life, health or safety

  • Another exception under applicable privacy law applies

We aim to collect only the information reasonably necessary to assess, manage, document or respond to the relevant matter.

4. Remaining anonymous or using a pseudonym

You may contact us anonymously or use a pseudonym where it is lawful and practical to do so.

We may need to confirm your identity where it is necessary to:

  • Provide an accurate response

  • Verify membership or policy entitlement

  • Arrange, issue or administer insurance

  • Assess or manage a claim

  • Coordinate an incident response

  • Protect the safety of an individual

  • Comply with legal or regulatory requirements

5. How we collect personal information

We may collect personal information:

  • Directly from you through forms, applications, meetings, telephone calls, email or other communications

  • Through your use of our website or digital services

  • From your employer, policyholder or membership sponsor

  • From an employee, manager, witness, family member or other person reporting an incident

  • From an insurance broker, insurer, underwriter, reinsurer or claims administrator

  • From specialist response providers engaged in connection with an incident

  • From legal, medical, psychological, security, investigative or other professional advisers

  • From police, emergency services, regulators or government bodies where lawful

  • From publicly available records and sources

  • From other third parties with consent or where authorised or required by law

Where information is provided to us about another person, the person providing it should ensure that they are authorised to do so where required and that the information is accurate.

We may also receive unsolicited personal information. Where this occurs, we will determine whether we could lawfully have collected it. If not, we will take reasonable steps to destroy or de-identify it, subject to any legal requirement to retain it.

6. Why we collect and use personal information

We may collect, hold, use and disclose personal information to:

  • Respond to enquiries and explain our services

  • Establish and administer VUCA Risk Membership

  • Assess organisational response readiness and escalation pathways

  • Provide structured incident guidance and decision support

  • Receive, triage and assess incident notifications

  • Coordinate specialist psychosocial, safety or crisis response

  • Arrange emergency safety, security, accommodation, transport or logistical assistance

  • Coordinate legal, investigative, cyber, communications or business-continuity services

  • Arrange, quote, distribute, administer or renew insurance products

  • Assess and manage claims or insurance-backed response activations

  • Confirm eligibility and applicable policy or membership entitlements

  • Liaise with employers, brokers, insurers, underwriters, claims administrators and response providers

  • Document decisions, escalations, actions and outcomes

  • Manage complaints, disputes and enquiries

  • Prevent fraud, misuse, unlawful activity and security threats

  • Meet legal, insurance, regulatory and reporting obligations

  • Operate, secure and improve our website, systems and services

  • Conduct research, benchmarking and service analysis using aggregated or de-identified information

  • Communicate relevant service, regulatory or educational information

We may use de-identified or aggregated information to identify trends, improve response systems and develop reporting about workplace psychosocial and incident risk. We will not use de-identified information in a way that is intended to identify an individual.

7. Employer-sponsored and organisational access

A person may access VUCA services through an employer-sponsored membership, insurance policy or partner arrangement.

In those circumstances, we may provide the relevant employer, policyholder, broker, insurer or membership sponsor with information reasonably necessary to:

  • Confirm membership or policy access

  • Administer the service or insurance arrangement

  • Manage an activation or claim

  • Coordinate an organisational response

  • Meet legal, safety, governance or reporting obligations

  • Provide information about service usage and emerging risk trends

Where practicable, organisational reporting will be aggregated or de-identified.

We will only disclose identifying incident information to an employer or sponsoring organisation where:

  • The individual has consented

  • It is reasonably necessary to provide or administer the service

  • It is necessary to manage a policy, claim or response activation

  • Disclosure is required or authorised by law

  • Disclosure is reasonably necessary to address a serious threat to life, health or safety

  • Another applicable legal exception permits the disclosure

The precise information shared will depend on the circumstances, the relevant policy or membership terms and the safety needs of the people involved.

8. Digital and technology-assisted tools

We may use secure digital and technology-assisted tools to:

  • Collect and organise information

  • Guide users through incident-response steps

  • Document decisions and actions

  • Identify potential escalation pathways

  • Manage workflows and referrals

  • Support risk and service reporting

These tools support, rather than replace, human judgment and specialist assessment.

They do not determine insurance coverage, guarantee an outcome or replace professional legal, medical, psychological, security or emergency advice.

Personal information processed through these tools may be handled by technology and cloud-service providers acting on our behalf and subject to appropriate contractual, privacy and security requirements.

9. Who we may disclose information to

Where reasonably necessary for the purposes described in this policy, we may disclose personal information to:

  • Chase Underwriting Solutions Pty Ltd

  • Insurers, underwriters and reinsurers

  • Insurance brokers and authorised representatives

  • Claims administrators, loss adjusters and case managers

  • Employers, policyholders and membership sponsors

  • Specialist psychosocial and crisis-response providers

  • Security, protective-services and investigative providers

  • Police, emergency services and government agencies

  • Medical practitioners, psychologists and other health-service providers

  • Legal advisers, mediators, accountants and auditors

  • Crisis communications and reputation advisers

  • Cybersecurity and technology specialists

  • Accommodation, transport, childcare and logistical providers

  • Business-continuity and operational-response specialists

  • IT, cloud-storage, communications, website, customer-management and payment providers

  • Regulators, courts, tribunals and law-enforcement bodies

  • Professional advisers and contractors supporting our business

  • A prospective purchaser or adviser in connection with a business restructure, merger or sale

  • Any other person authorised by you or permitted or required by law

We seek to limit disclosure to the information reasonably necessary for the recipient to perform their role.

Some specialist providers are independent organisations and may collect information directly from you. Their handling of information may also be governed by their own privacy policies and professional obligations.

10. Safety, emergency and legally permitted disclosures

There may be circumstances in which we use or disclose personal information without consent.

This may occur where we reasonably believe it is necessary to:

  • Lessen or prevent a serious threat to the life, health or safety of an individual or the public

  • Respond to suspected unlawful activity or serious misconduct

  • Protect an individual from violence, abuse, stalking or other serious harm

  • Contact police, emergency services or another appropriate authority

  • Comply with an Australian law, court order or regulatory requirement

  • Establish, exercise or defend a legal or insurance claim

Any such decision will be made having regard to the circumstances, the sensitivity of the information and the immediate risks involved.

11. Overseas storage and disclosure

Some of the organisations and technology providers we work with may store, process or access personal information outside Australia.

Depending on the service involved, overseas recipients may be located in:

  • The United Kingdom

  • The United States

  • European Union countries

  • Countries within the Asia-Pacific region

These recipients may include insurers, reinsurers, cloud-service providers, communications providers, software platforms and specialist service providers.

Where personal information is disclosed to an overseas recipient, we take reasonable steps required by Australian privacy law to ensure that it is handled appropriately.

Because service-provider locations can change, you may contact us for more information about the countries relevant to a particular service or disclosure.

12. Security and storage

We take reasonable steps to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure.

These steps may include:

  • Controlled access to systems and records

  • Password protection and multi-factor authentication

  • Encryption and secure communications

  • Role-based user permissions

  • Confidentiality obligations

  • Staff and contractor training

  • Secure cloud and technology providers

  • System monitoring, backups and security controls

  • Incident-response and data-breach procedures

  • Secure destruction and de-identification processes

No electronic or physical storage system is completely secure. Where a data breach occurs or is suspected, we will take reasonable steps to contain, assess and respond to the incident.

Where required under the Notifiable Data Breaches scheme, we will notify affected individuals and the Office of the Australian Information Commissioner.

13. Retention of personal information

We retain personal information only for as long as reasonably necessary for the purposes for which it was collected or as required by law.

Retention periods may be affected by:

  • Insurance and claims requirements

  • Regulatory record-keeping obligations

  • Contractual requirements

  • Legal limitation periods

  • Complaints or disputes

  • Continuing safety or risk-management needs

When information is no longer required, we will take reasonable steps to securely destroy or de-identify it.

14. Accessing and correcting your information

You may request access to personal information we hold about you.

You may also ask us to correct information that is inaccurate, out of date, incomplete, irrelevant or misleading.

We may need to verify your identity before processing a request.

In some circumstances, the law permits us to refuse access or correction. Where this occurs, we will generally explain the reason and the available complaint options.

We will not ordinarily charge you for making a request. We may charge reasonable administrative costs where permitted by law and will notify you before doing so.

Requests should be sent to the contact details at the end of this policy.

15. Direct marketing and service communications

We may use your contact information to send you:

  • Information about VUCA services

  • Regulatory or industry updates

  • Educational material

  • Invitations to events or briefings

  • Information relevant to workplace or organisational risk

We will only send direct marketing where permitted by law.

You can opt out at any time by:

  • Selecting the unsubscribe option in the communication

  • Replying to the communication

  • Contacting us at admin@vucarisk.com

Opting out of marketing will not prevent us from sending essential communications about an existing membership, insurance arrangement, claim, incident or service.

16. Website analytics and cookies

Our website may use cookies, analytics tools, embedded content and similar technologies.

These tools may collect information such as:

  • IP address

  • Browser and device information

  • Pages visited

  • Referral source

  • Time spent on the website

  • Interactions with website features and forms

We use this information to operate, secure and improve the website and understand how people engage with our content.

You can manage or disable cookies through your browser settings. Some website functions may not operate correctly if cookies are disabled.

Third-party websites or services linked from our website are governed by their own privacy practices.

17. Privacy complaints

If you believe that we have mishandled your personal information or breached an applicable privacy obligation, please contact us in writing.

Please include:

  • Your name and contact details

  • A description of the issue

  • The outcome you are seeking

  • Any relevant supporting information

We will acknowledge and investigate your complaint and aim to provide a response within 30 days. If additional time is required, we will explain why and provide an updated timeframe.

This process relates to privacy complaints. Separate complaints processes may apply to insurance products, claims or financial services.

If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner.

Office of the Australian Information Commissioner

Website: www.oaic.gov.au
Telephone: 1300 363 992

18. Changes to this Privacy Policy

We may update this Privacy Policy when our services, technology, legal obligations or information-handling practices change.

The current version will be published on our website and will display its effective date.

Where a change is significant, we may also notify affected clients, members or users through an appropriate communication channel.

19. Contact us

For privacy enquiries, access or correction requests, or complaints, contact:

VUCA Risk Pty Ltd

ABN 32 664 289 927
Authorised Representative No. 1300778

Level 5, 145 Eagle Street
Brisbane QLD 4000

Telephone: 07 4516 3300
Email: 
admin@vucarisk.com

Important insurance information

VUCA Risk Pty Ltd (ABN 32 664 289 927) is an Authorised Representative, No. 1300778, of Chase Underwriting Solutions Pty Ltd (ABN 50 156 554 808, AFSL 454344).

VUCA Risk arranges and distributes certain insurance products for and on behalf of Chase Underwriting Solutions Pty Ltd. Insurance policies are issued by Chase Underwriting Solutions Pty Ltd.

Information provided on this website is general advice only and does not take into account your objectives, financial situation or needs.

Before making a decision, you should consider whether the product is appropriate for your circumstances and read the relevant Product Disclosure Statement and any applicable Supplementary Product Disclosure Statement.

Insurance benefits are subject to the applicable policy terms, conditions, limits, waiting periods and exclusions. Nothing on this website guarantees that a claim or response activation will be accepted.