Legal

Privacy policy

Last updated: 23 July 2026

Welcome to Vitr Pathways. We respect your privacy and are committed to protecting your personal information. This privacy policy explains how we collect, use, store and disclose your personal information when you visit our website, engage our services, or otherwise interact with us, and outlines your privacy rights and how the law protects you.

1. Who We Are

This privacy policy applies to Vitr Pathways Pty Ltd (referred to as "Vitr", "Vitr Pathways", "we", "us" or "our"). We provide strategy, change management, leadership development, coaching, mentoring and organisational diagnostic services.

Contact details:

Vitr Pathways Pty Ltd
Email: admin@vitr.au
Phone: 1300 863 500
Location: Melbourne, Australia

We are bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). Where we handle personal information of individuals located in the European Union or United Kingdom, we also have regard to the requirements of the GDPR and UK GDPR.

If you have a concern about how we have handled your personal information, please contact us in the first instance and we will work to resolve it. You also have the right to lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au.

2. The Information We Collect

Personal information means any information about an individual from which that person can be identified. It does not include information where identity has been removed (de-identified or aggregated data).

We may collect, use, store and disclose the following kinds of personal information:

  • Identity Data: first name, last name, job title, organisation, and similar identifiers.
  • Contact Data: billing address, email address, and telephone numbers.
  • Financial Data: bank account and payment details, collected only where required for billing.
  • Transaction Data: details about payments and services you have engaged us for.
  • Technical Data: internet protocol (IP) address, browser type and version, time zone setting and location, operating system and platform, and other technology on the devices you use to access our website.
  • Usage Data: information about how you use our website and services.
  • Marketing and Communications Data: your preferences in receiving marketing and communications from us, including newsletter subscriptions.
  • Engagement and Diagnostic Data: information collected through our professional services, including coaching sessions, surveys, 360 degree feedback, interviews and focus groups. Section 4 explains how this information is treated.

3. How We Use Your Personal Information

We only collect personal information by lawful and fair means, for purposes that are clearly explained at or before the time of collection. We use personal information:

  • To deliver the services we have been engaged to provide.
  • To communicate with you about engagements, enquiries, and our newsletter and content (where you have subscribed).
  • To manage billing, payments and our business operations.
  • To improve our services, website and methodologies.
  • To comply with our legal obligations.

We use or disclose personal information only for the purpose it was collected, for related purposes you would reasonably expect, or where you have consented to another use. Where the GDPR applies, we rely on contractual necessity, legitimate interests, consent, and compliance with legal obligations as our lawful bases for processing.

We do not sell personal information.

4. Survey, 360 Degree Feedback and Diagnostic Information

Our diagnostic work depends on the trust of the people who participate in it. Where we conduct surveys, 360 degree feedback, interviews, focus groups or similar diagnostic activities:

  • Individual responses are treated as confidential and reported only in aggregated and de-identified form.
  • We do not disclose individual responses or attributable data to a client organisation, its leadership, or any third party, except where the participant has provided express written consent, disclosure is required by law, or information indicates a serious and imminent risk to a person's safety, in which case we follow appropriate escalation protocols.
  • Coaching and mentoring session records are held securely and disclosed only with the express permission of the participant, unless required by law.

5. Data Security

We have put in place appropriate security measures to prevent your personal information from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. We limit access to your personal information to those employees, agents, contractors and other third parties who have a business need to know. They will only process your personal information on our instructions, and they are subject to a duty of confidentiality.

Our website may include embedded content from other websites (for example videos or articles) and links to third-party services. Embedded content behaves as if you had visited the other website directly, and those websites may collect data about you, use cookies, and monitor your interaction with that content. We encourage you to review the privacy policies of any third-party sites you interact with.

6. Data Retention

We retain personal information only for as long as reasonably necessary to fulfil the purposes for which it was collected, including to satisfy any legal, accounting, insurance or reporting requirements. In general:

  • Client engagement records and financial records are retained for a minimum of seven years, consistent with Australian tax and corporations law requirements.
  • Diagnostic and survey data is retained in identifiable form only for as long as needed to deliver the engagement, after which it is de-identified or securely destroyed.
  • Marketing data, such as newsletter subscriptions, is retained until you unsubscribe or ask us to remove it.

When personal information is no longer required, we take reasonable steps to destroy or de-identify it.

7. Your Rights

You have the right to:

  • Request access to the personal information we hold about you.
  • Request correction of inaccurate or incomplete information.
  • Ask us to delete your personal information, subject to our legal retention obligations.
  • Opt out of marketing communications at any time.
  • Withdraw consent where processing is based on consent.

Where the GDPR applies, you may also have rights to object to processing, request restriction of processing, and request data portability.

To exercise any of these rights, contact us at admin@vitr.au. We will respond within a reasonable period.

8. Changes to This Policy

We may update this privacy policy from time to time. The current version will always be available on our website, and material changes will be noted when they are made.

Questions about this policy? Email admin@vitr.au.