Call to chat to our team Find your
nearest location

APEX STEEL GROUP

PRIVACY POLICY

Version: 2.0
Effective Date: 24 September 2026
Last Reviewed: 24 September 2026
Next Review: September 2027
Policy Owner: Apex Steel Group


1. Purpose

Apex Steel Group is committed to protecting the privacy and security of personal information.

This Privacy Policy explains how Apex Steel Group collects, holds, uses, discloses, protects and manages personal information and how individuals can access or correct information we hold about them, make a privacy complaint, or otherwise exercise their privacy rights.

Apex Steel Group complies with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) to the extent those laws apply to us.

This Policy is intended to provide clear and transparent information about our privacy practices.


2. Who this Policy applies to

This Privacy Policy applies to the businesses operated by Apex Steel Group (Apex Building Products Pty Ltd & Controlled Entities) in Australia, including entities within the Apex Group that are subject to the Privacy Act.

In this Policy, “Apex”, “we”, “us” or “our” means the relevant Apex Steel Group entity or entities responsible for collecting or handling your personal information.

This Policy applies to personal information we collect about individuals including:

  • customers and prospective customers;
  • suppliers and prospective suppliers;
  • contractors and service providers;
  • employees and former employees, to the extent the Privacy Act applies;
  • employment applicants;
  • visitors to our premises;
  • website users;
  • individuals who contact or communicate with us; and
  • other individuals whose personal information we lawfully collect.

Certain information relating to current and former employees may be subject to the employee records exemption under the Privacy Act. Where that exemption applies, the relevant information may not be subject to all of the requirements described in this Policy.


3. What is personal information?

For the purposes of this Policy, personal information generally means information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether the information or opinion is true or not and whether it is recorded in a material form or not.

Personal information may include:

  • name and contact details;
  • residential, postal or business address;
  • telephone number and email address;
  • date of birth;
  • occupation and employment information;
  • information contained in employment applications;
  • identification information;
  • financial and payment information;
  • banking details;
  • customer account and trading information;
  • credit-related information;
  • transaction and purchasing history;
  • delivery and site information;
  • correspondence and communications with us;
  • information contained in complaints, warranty claims or enquiries;
  • photographs, images and CCTV footage;
  • information relating to access to our premises;
  • website and device information;
  • IP addresses and online activity;
  • information supplied by customers, suppliers, contractors or other third parties; and
  • other information that identifies, or could reasonably identify, an individual.

We aim to collect only personal information that is reasonably necessary for our functions and activities.


4. Sensitive information

Sensitive information is a particular category of personal information that receives additional protection under the Privacy Act.

It may include information or opinions about matters such as:

  • racial or ethnic origin;
  • political opinions or associations;
  • religious or philosophical beliefs;
  • trade union or professional association membership;
  • sexual orientation or practices;
  • criminal record;
  • health information;
  • genetic information; and
  • certain biometric information.

We will only collect sensitive information where permitted or required by law.

Where consent is required, we will generally seek consent before collecting sensitive information.

Sensitive information will only be used or disclosed for purposes permitted by the Privacy Act or otherwise authorised by the individual.


5. How we collect personal information

We may collect personal information in a number of ways, including:

  • directly from you;
  • through our websites and online forms;
  • by telephone, email, SMS or other electronic communications;
  • when you purchase or enquire about our products or services;
  • when establishing or maintaining a customer account;
  • when applying for a credit or trading account;
  • when submitting a warranty claim, complaint or enquiry;
  • through employment applications and recruitment activities;
  • when you supply goods or services to us;
  • through contractors and other service providers;
  • through our customer, supplier, accounting, ERP and other business systems;
  • through CCTV and security systems at our premises;
  • through cookies, analytics tools and similar online technologies;
  • from publicly available sources;
  • from credit reporting bodies and other credit-related sources where permitted;
  • from other customers, suppliers or business partners;
  • from professional advisers and service providers; and
  • from other third parties where collection is lawful.

We may also collect information generated, observed or inferred from information we already hold, where permitted by law.

Where reasonable and practicable, we will collect personal information directly from the individual concerned.

Where we collect personal information about an individual from a third party, we will take reasonable steps as required by the Privacy Act to notify the individual or otherwise provide the relevant privacy information.


6. What happens if you do not provide personal information?

In many circumstances, providing personal information is voluntary.

However, certain personal information may be reasonably necessary for us to provide products or services, establish or maintain an account, process payments, assess credit, arrange deliveries, administer employment, respond to enquiries or otherwise conduct our business.

If you do not provide information that we reasonably require, we may be unable to:

  • provide particular products or services;
  • process an order;
  • establish or maintain an account;
  • assess or provide credit;
  • arrange delivery;
  • process a payment;
  • respond fully to an enquiry or claim;
  • assess an employment application; or
  • provide another service or undertake another activity.

Where appropriate, we will explain why particular information is required.


7. Purposes for which we collect and use personal information

We may collect, hold, use and disclose personal information for purposes including:

Customers and prospective customers

  • providing products and services;
  • processing orders;
  • arranging deliveries and transport;
  • establishing and administering customer accounts;
  • assessing and managing credit applications;
  • processing payments and invoices;
  • managing accounts receivable and debt recovery;
  • responding to enquiries and complaints;
  • administering warranties, returns and claims;
  • communicating with customers;
  • improving products and services; and
  • maintaining business records.

Suppliers and contractors

  • establishing and managing supplier and contractor relationships;
  • obtaining goods and services;
  • processing invoices and payments;
  • verifying business, insurance, licensing or qualification information;
  • managing contracts;
  • managing site access and safety requirements; and
  • communicating about business activities.

Employees and applicants

  • recruitment and selection;
  • verifying qualifications, licences and experience;
  • employment administration;
  • payroll and benefits administration;
  • workplace health and safety;
  • training and development;
  • security and access control;
  • complying with employment and other legal obligations; and
  • managing our workforce.

Website users and other individuals

  • responding to enquiries;
  • administering our websites;
  • understanding website usage;
  • improving our online services;
  • marketing and communications;
  • preventing fraud, misuse or unlawful activity;
  • maintaining security; and
  • complying with legal obligations.

We may also use personal information for other purposes where permitted or required by law.


8. Disclosure of personal information

We may disclose personal information where reasonably necessary for the purposes described in this Policy or otherwise where permitted or required by law.

Depending on the circumstances, we may disclose personal information to:

  • companies within the Apex Group;
  • employees and authorised representatives;
  • customers, suppliers and contractors where reasonably necessary;
  • transport, logistics and delivery providers;
  • IT, software, cloud storage and technology providers;
  • website, hosting and analytics providers;
  • payment processors and financial institutions;
  • accountants, auditors, lawyers and other professional advisers;
  • insurers and claims administrators;
  • recruitment and employment service providers;
  • debt recovery agencies;
  • credit reporting bodies and credit providers, where applicable;
  • marketing and communications providers;
  • security and facilities providers;
  • government agencies and regulators;
  • law enforcement agencies where authorised or required by law; and
  • other parties where you have provided consent or disclosure is otherwise permitted by law.

We do not generally sell personal information.


9. Credit information

Where relevant to our business activities, we may collect and use information relating to the creditworthiness of customers or prospective customers.

This may include information provided in connection with applications for trading accounts or commercial credit and information obtained from credit reporting bodies or other lawful sources.

Where credit information is collected, used or disclosed, we will comply with applicable provisions of the Privacy Act, the Privacy (Credit Reporting) Code 2025 and other applicable requirements.

Where applicable, additional notices or consents may be provided as part of our credit application process.


10. Direct marketing

We may use personal information to communicate with you about our products, services, promotions, events and other business activities where permitted by law.

Marketing communications may be sent by:

  • email;
  • SMS;
  • telephone;
  • post; or
  • other communication channels.

You may opt out of receiving direct marketing communications at any time by:

  • using the unsubscribe facility provided in the communication;
  • contacting us using the details in Section 22; or
  • otherwise notifying us that you no longer wish to receive marketing communications.

We will process opt-out requests within a reasonable period and maintain appropriate records of marketing preferences.

Our direct marketing activities will also comply with applicable requirements under the Spam Act 2003 (Cth) and other applicable laws.


11. Cookies, analytics and online technologies

Our websites may use cookies, pixels, tags, scripts and similar technologies.

These technologies may be used to:

  • operate and secure our websites;
  • remember preferences;
  • understand website usage;
  • measure website performance;
  • analyse traffic and user behaviour;
  • improve our websites and services;
  • measure marketing effectiveness; and
  • support advertising or other communications where applicable.

These technologies may collect information such as:

  • IP address;
  • browser type;
  • device information;
  • operating system;
  • pages visited;
  • referring website;
  • approximate location;
  • website interactions; and
  • other technical or usage information.

We may use third-party providers to assist with website analytics, advertising, hosting and related services.

Our websites may use services such as Google Tag Manager, Google Analytics or other third-party technologies from time to time.

The specific technologies used may change as our website and digital services develop.

Where required by law, we will obtain consent before using cookies or similar technologies that require consent.

You can also manage cookies through your browser settings, although disabling certain cookies may affect website functionality.


12. CCTV, security and access systems

Apex may operate CCTV and other security or access-control systems at some premises for purposes including:

  • protecting employees, customers, visitors and property;
  • preventing and investigating theft, fraud, vandalism or other unlawful activity;
  • managing site security;
  • investigating incidents;
  • workplace and public safety;
  • managing access to premises; and
  • complying with legal or insurance requirements.

CCTV footage may contain images of identifiable individuals and is therefore capable of constituting personal information.

Access to CCTV and security information is restricted to authorised persons and is managed in accordance with our security requirements.

CCTV footage will be retained only for as long as reasonably necessary for the relevant purposes, subject to legal, insurance, investigation and other applicable requirements.

Where biometric information or facial recognition technology is used, Apex will implement any additional privacy requirements applicable to that technology.


13. Disclosure outside Australia

Some of our service providers, technology providers, related entities or other recipients may be located outside Australia.

Depending on the services and systems used by Apex, personal information may be disclosed to recipients located in:

  • United States of America
  • Singapore
  • Thailand
  • Philippines
  • Vietnam

These locations may include countries in which our software, cloud, technology, administration, support or other service providers operate.

Before disclosing personal information overseas, we take reasonable steps to comply with the requirements of the Privacy Act, including applicable requirements concerning overseas recipients.

Where required, we will take reasonable steps to ensure that overseas recipients handle personal information consistently with applicable Australian privacy requirements.

The countries to which information may be disclosed may change from time to time as our service providers and technology systems change.


14. Storage and security of personal information

We hold personal information in electronic and physical forms.

We take reasonable steps to protect personal information from:

  • misuse;
  • interference;
  • loss;
  • unauthorised access;
  • unauthorised modification; and
  • unauthorised disclosure.

Depending on the nature of the information and the circumstances, security measures may include:

  • user access controls;
  • authentication and password controls;
  • multi-factor authentication where appropriate;
  • role-based permissions;
  • network and endpoint security;
  • security monitoring;
  • secure backups;
  • physical security controls;
  • staff training and awareness;
  • contractual controls with service providers;
  • secure disposal procedures; and
  • other administrative, technical and physical safeguards.

No method of storing or transmitting information is completely secure. While we take reasonable steps to protect personal information, we cannot guarantee that information will never be subject to unauthorised access or a security incident.


15. Data breaches

Apex maintains processes for identifying, containing, assessing and responding to actual or suspected data breaches involving personal information.

If we become aware of a suspected or actual data breach, we will take reasonable steps to:

  1. contain the incident;
  2. investigate what occurred;
  3. identify affected information and individuals;
  4. assess the potential impact;
  5. take remedial or preventative action; and
  6. determine whether notification obligations apply.

Where an eligible data breach is likely to result in serious harm to affected individuals, Apex will comply with the Notifiable Data Breaches scheme, including notification to affected individuals and the Office of the Australian Information Commissioner where required.


16. Retention, destruction and de-identification

We retain personal information only for as long as reasonably necessary for the purposes for which it was collected, including to:

  • provide products and services;
  • administer accounts and relationships;
  • comply with legal and regulatory obligations;
  • maintain financial and business records;
  • resolve disputes;
  • enforce agreements;
  • investigate incidents;
  • protect our business and property; and
  • otherwise conduct legitimate business activities.

Retention periods vary depending on the nature of the information and the purpose for which it is held.

When personal information is no longer required and we are not legally required to retain it, we take reasonable steps to securely destroy or de-identify it.

Information may be retained for longer where required by law, reasonably necessary for legal proceedings, investigations, dispute resolution, insurance or other legitimate purposes.


17. Anonymity and pseudonymity

Where lawful and practicable, you may choose not to identify yourself or may use a pseudonym when dealing with us.

However, this may not be possible where:

  • we are required by law to identify you;
  • identification is reasonably necessary for the relevant transaction or service;
  • we need to verify your identity;
  • the matter involves a customer or supplier account; or
  • we cannot reasonably provide the requested service without identifying you.

18. Quality and correction of personal information

We take reasonable steps to ensure that personal information we collect, use and disclose is accurate, up-to-date, complete and relevant for the purposes for which it is used.

If you believe that personal information we hold about you is inaccurate, incomplete, out-of-date, irrelevant or misleading, you may request that we correct it.

We will take reasonable steps to correct information where appropriate.

If we refuse a correction request, we will provide written reasons where required by law and, where applicable, explain how you may request that a statement be associated with the information.


19. Access to personal information

You may request access to personal information that we hold about you, subject to exceptions under the Privacy Act.

Requests should be made using the contact details in Section 22.

We may need to verify your identity before providing access.

We will respond to access requests within the timeframe required by applicable privacy laws.

In some circumstances, we may refuse access where permitted or required by law. If we refuse access, we will provide reasons where required and explain any available review or complaint options.

We will not generally charge for making a request. Where a charge may lawfully apply for providing access, we will advise you before proceeding.


20. Privacy complaints

If you believe that Apex has mishandled your personal information or breached the Privacy Act or Australian Privacy Principles, you may make a privacy complaint using the contact details in Section 22.

To assist us in investigating your complaint, please provide:

  • your name;
  • contact details;
  • details of the issue or complaint;
  • relevant dates;
  • relevant documents or correspondence; and
  • the outcome you are seeking, where applicable.

We will acknowledge and investigate privacy complaints and respond within a reasonable period and in accordance with applicable legal requirements.

We will not charge you for making a privacy complaint.

If you are not satisfied with our response, or if you believe your complaint has not been appropriately addressed, you may contact the Office of the Australian Information Commissioner (OAIC).

The OAIC can be contacted through:

Website: www.oaic.gov.au
Phone: 1300 363 992
Post: GPO Box 5218, Sydney NSW 2001

You should generally give Apex an opportunity to investigate and respond to your complaint before contacting the OAIC.


21. Automated decision-making and artificial intelligence

Apex may use software, computer programs, artificial intelligence, analytics tools or other automated systems to assist with business processes.

These systems may use personal information for purposes such as:

  • processing and managing customer or supplier information;
  • detecting fraud or security risks;
  • analysing transactions or business activity;
  • recruitment or administration;
  • customer service;
  • website and marketing analytics; or
  • other legitimate business purposes.

From 10 December 2026, additional requirements apply under the Privacy Act where an organisation arranges for a computer program to use personal information to make, or substantially and directly assist in making, a decision that could reasonably be expected to significantly affect an individual’s rights or interests.

Where these requirements apply to Apex, this Policy will identify:

  • the kinds of personal information used by the relevant computer programs;
  • the kinds of decisions made solely through automated operation; and
  • the kinds of decisions for which automated systems perform an act substantially and directly related to making the decision.

Apex will review its use of automated decision-making systems and update this Policy where required by law.


22. Contacting Apex

For privacy enquiries, requests for access or correction, privacy complaints, or to opt out of direct marketing, please contact:

Privacy Officer
Apex Steel Group

Email: claims@apexsteel.com.au

You may also contact your usual Apex representative, who can refer your enquiry to the appropriate person within Apex.

We may require sufficient information to verify your identity before processing requests relating to personal information.


23. Third-party websites

Our websites may contain links to websites operated by third parties.

Those websites are not controlled by Apex and may have their own privacy policies and practices.

We are not responsible for the privacy practices of third-party websites.

We recommend reviewing the privacy policy of any third-party website before providing personal information.


24. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect:

  • changes to our business;
  • changes to our information-handling practices;
  • changes to our technology and service providers;
  • changes to applicable privacy laws;
  • regulatory guidance; or
  • other relevant developments.

The current version of this Privacy Policy will be published on the Apex website.

We encourage individuals to review this Policy periodically.


25. Policy administration

Policy: Apex Steel Group Privacy Policy
Version: 2.0
Effective: 24 September 2026
Last Reviewed: 24 September 2026
Next Review: September 2027
Policy Owner: Apex Steel Group

This Policy should be reviewed earlier if there is a material change to Apex’s information-handling practices, technology systems, overseas service providers, business structure or applicable privacy legislation.