Policies

Here are our policies regarding our operations, website and services.

Effective as of 1st May 2022.

Purpose

The purpose of this policy is to establish controls to ensure compliance with all applicable anti-bribery and corruption regulations, and to ensure that ESM Professional's business is conducted in a socially responsible manner.


Policy statement

Bribery is the offering, promising, giving, accepting or soliciting of an advantage as an inducement for action which is illegal or a breach of trust. A bribe is an inducement or reward offered, promised or provided in order to gain any commercial, contractual, regulatory or personal advantage.

It is our policy to conduct all of our business in an honest and ethical manner. We take a zero tolerance approach to bribery and corruption. We are committed to acting professionally, fairly and with integrity in all our business dealings and relationships by implementing and enforcing effective systems to counter bribery.

We will uphold all laws relevant to countering bribery and corruption in Australia.


Who is covered by the policy?

In this policy, third party means any individual or organisation you come into contact with during the course of your work for us, and includes actual and potential clients, business contacts, agents, and government and public bodies.

This policy applies to all employees and contractors engaged by ESM Professionals, collectively referred to as personnel.


What does this policy cover?

This policy covers:

  • Bribes

    Personnel must not engage in any form of bribery, either directly or indirectly.

  • Gifts and hospitality
    Personnel must not offer or give any gift or hospitality:
    • which could be regarded as illegal or improper, or which violates the recipient’s policies or
    • to any public employee or government officials or representatives.

    Employees may not accept any gift or hospitality from any business associates unless previously authorised by the owner of ESM Professionals.

  • Charitable contributions

    Charitable support and donations are acceptable (and indeed are encouraged), whether of knowledge, time, or direct financial contributions. However, personnel must be careful to ensure that charitable contributions are not used as a scheme to conceal bribery.


Your responsibilities

You must ensure that you read, understand and comply with this policy. The prevention, detection and reporting of bribery and other forms of corruption are the responsibility of all those working for and with esm professionals.

All employees are required to avoid any activity that might lead to, or suggest, a breach of this policy. You must notify your manager as soon as possible if you believe or suspect that a conflict with or breach of this policy has occurred, or may occur in the future.

Personnel breaching this policy will face disciplinary action, which could result in dismissal for gross misconduct. We reserve our right to terminate our contractual relationship with other workers if they breach this policy.


How to raise a concern

You are encouraged to raise concerns about any issue or suspicion of malpractice at the earliest possible stage. If you are unsure whether a particular act constitutes bribery or corruption, or if you have any other queries or concerns, these should be raised with your manager.


What to do if you are a victim of bribery or corruption

It is important that you tell your manager as soon as possible if you are offered a bribe by a third party, are asked to make one, suspect that this may happen in the future, or believe that you are a victim of another form of unlawful activity.


Protection

Personnel who refuse to accept or offer a bribe, or those who raise concerns or report another's wrongdoing, are sometimes worried about possible repercussions. We aim to encourage openness and will support anyone who raises genuine concerns in good faith under this policy, even if they turn out to be mistaken.

We are committed to ensuring no one suffers any detrimental treatment as a result of refusing to take part in bribery or corruption, or because of reporting in good faith their suspicion that an actual or potential bribery or other corruption offence has taken place, or may take place in the future.


Training and communication

Training on this policy forms part of the induction process for all new employees. All existing employees will receive regular, relevant training on how to implement and adhere to this policy. In addition, all employees will be asked to formally accept conformance to this policy on an annual basis. Our zero-tolerance approach to bribery and corruption must be communicated to all suppliers, contractors and business partners at the outset of our business relationship with them and as appropriate thereafter.


Who is responsible for the policy?

The owner of ESM Professionals has overall responsibility for ensuring this policy complies with our legal and ethical obligations, and that all personnel comply with it.

Personnel have primary and day-to-day responsibility for implementing this policy, and for monitoring its use and effectiveness and dealing with any queries on its interpretation.


Monitoring and review

The owner of ESM Professionals will monitor the effectiveness and review the implementation of this policy, regularly considering its suitability, adequacy and effectiveness. Any improvements identified will be made as soon as possible. Internal control systems and procedures will be subject to regular audits to provide assurance that they are effective in countering bribery and corruption.

All personnel are responsible for the success of this policy and should ensure they use it to disclose any suspected danger or wrongdoing.

Personnel are invited to comment on this policy and suggest ways in which it might be improved. Comments, suggestions and queries should be addressed to the owner of ESM Professionals.

Who we are

The websites we operate are https://www.esmprofessionals.com.au and https://www.eservicemanager.com.au. Emails are generated and sent by us using our esmprofessionals.com.au domain at all times and all originate from the same IP address.

ESM Professionals is a service and operations management consultancy and software development business with a fresh, energetic approach to helping organisations reach a mature level of service management efficiency.


What personal data we collect and why we collect it

Your privacy is important to us. It is esm professionals' policy to respect your privacy regarding any information we may collect from you across our websites, and other systems we own and operate under these domains.

We only ask for personal information when we truly need it to provide a service to you. We collect it by fair and lawful means, with your knowledge and consent. We also let you know why we’re collecting it and how it will be used.

  • Analytics

    We use Google Analytics to provide us with information about how you are browsing our website. Information collected includes your generalised location, device type, internet provider, browser information, and whether you used any search engines or social media sites to find us.

    We use this information to better tailor our website content to our clients and potential customers.

  • Contact Form

    If you use the contact form on our website, an email is generated to our mailbox using the information you provide. The information is transmitted securely from your device to our website and then formed into an email.

  • SaaS and Community Websites

    If you have an account on our eservicemanager SaaS and/or Community websites, or have left comments, you can request to receive an exported file of the personal data we hold about you, including any data you have provided to us. You can also request that we erase any personal data we hold about you. This does not include any data we are obliged to keep for administrative, legal or security purposes.


How long we retain your data

We only retain collected information for as long as necessary to provide you with your requested service. If you leave a comment or interact with our eservicemanager SaaS or Community websites, interactions are retained indefinitely. This is to allow a continued flow of events using our products and to allow us to interact with our customers.


How we protect your data

The data we store, we'll protect within commercially acceptable means to prevent loss and theft, as well as unauthorised access, disclosure, copying, use or modification. Our systems that record sensitive data such as passwords are stored using encrypted technology. We also ensure our websites use Secure Socket Layer (SSL) technology to transmit data. Our cloud-based servers are also regularly patched for security issues and are protected by a complex series of firewall rules and security access techniques.


Where we send your data

We don’t share any personally identifying information publicly or with third-parties, except when required to by law. If you subscribe to our systems such as our eservicemanager SaaS or Community sites, your name and contact information may be visible to other members.

Our website may link to external sites that are not operated by us. Please be aware that we have no control over the content and practices of these sites and cannot accept responsibility or liability for their respective privacy policies.


What data breach procedures we have in place

Australian Legislation requires us to publish and report data breaches. Therefore, if any data breaches occur, we will report this to the relevant authorities and inform our customers about the breach and an assessment on what data was leaked via email. Depending on the seriousness of the breach, we will consider legal action against the 'hacker'.


Your consent

You are free to refuse our request for your personal information, with the understanding that we may be unable to provide you with some of your desired services.

Your continued use of our website and products will be regarded as acceptance of our practices around privacy and personal information. If you have any questions about how we handle user data and personal information, feel free to contact us.


Changes to our Privacy Policy

We reserve the right to revise our privacy policy at any time by posting changes to this page. Any changes to the privacy policy will be communicated to active customers by email. Changes will become active immediately upon being posted on this site.

About this policy

The security of our systems is a top priority and we take every care to keep them secure. Despite our efforts, there may still be vulnerabilities.

We are keen to engage with the security community. This policy allows security researchers to share their findings with us. If you think you have found a potential vulnerability in one of our systems, services or products, please tell us as quickly as possible.

We will not compensate you for finding potential or confirmed vulnerabilities.


What this policy covers

This policy covers:

  • any product or service hosted on our website to which you have lawful access

This policy does not cover:

  • clickjacking
  • social engineering or phishing
  • weak or insecure SSL ciphers and certificates
  • denial of service (DoS)
  • physical attacks
  • attempts to modify or destroy data

How to report a vulnerability

To report a vulnerability, use the contact form on our website.

Include enough detail so we can reproduce your steps.

If you report a vulnerability under this policy, you must keep it confidential. Do not make your research public until we have finished investigating and fixed or mitigated the vulnerability.


What happens next?

We will:

  • respond to your report within 5 business days
  • keep you informed of our progress
  • agree upon a date for public disclosure
  • credit you as the person who discovered the vulnerability unless you prefer us not to

People who have disclosed vulnerabilities to us

Below are the names or aliases of people who have identified and disclosed vulnerabilities to us:

{Nobody yet}