Privacy Policy
This policy explains how we handle personal information and other data we obtain from you anytime you interact with Thunder Protection Group, such as when you browse on our website or when you use our service to upload or download content.
Privacy Policy
Thunder Dragon Protective Services Pty Ltd trading as Thunder Protection Group
Last updated: 23 July 2026
1. About this Privacy Policy
Thunder Dragon Protective Services Pty Ltd trading as Thunder Protection Group (Thunder Protection Group, we, us or our) respects the privacy of our clients, employees, contractors, job applicants, suppliers, website visitors and members of the public.
This Privacy Policy explains how we collect, hold, use, disclose, protect and otherwise manage personal information in connection with our security services, business operations, website and employment activities.
We are committed to handling personal information responsibly and, to the extent applicable to our operations, consistently with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. The Privacy Act generally applies to organisations with annual turnover above $3 million and to certain smaller organisations based on their activities or circumstances.
This Policy does not create contractual rights or obligations beyond those imposed by applicable law.
2. Who We Are
Thunder Protection Group is a Queensland security provider delivering services including:
- static security guarding;
- mobile security patrols;
- lock-up and unlock services;
- commercial property security;
- residential and body corporate security;
- construction and vacant-property security;
- access control and visitor management;
- security escorts and protective services;
- incident response and reporting;
- risk management and security consulting; and
- related security and operational support services.
Our legal entity is:
Thunder Dragon Protective Services Pty Ltd
Trading as: Thunder Protection Group
ABN: 11639500011
Queensland security firm licence: 4386026
3. Meaning of Personal Information
Personal information is information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether the information is true or recorded in material form.
Depending on the circumstances, personal information may include a person’s name, contact details, identification information, employment information, photographs, video footage, location information or records of interactions with us.
Sensitive information is a category of personal information that may include health information, biometric information used for identification, racial or ethnic origin, religious beliefs, political opinions, trade union membership, sexual orientation or criminal-record information.
We only collect sensitive information where it is reasonably necessary for our functions or activities and where collection is authorised by law or the individual has provided any consent required by law.
4. Personal Information We May Collect
The kinds of personal information we collect depend on a person’s relationship with us and the nature of the services being provided.
We may collect:
Client and prospective-client information
- names and position titles;
- business names and addresses;
- telephone numbers and email addresses;
- billing and payment details;
- authorised contact details;
- emergency contact details;
- property, site and access information;
- service requirements and operating instructions;
- correspondence, enquiries, quotations and agreements;
- complaints, feedback and service records; and
- information necessary to assess security risks or prepare services.
Site and operational information
- visitor names and contact details;
- sign-in and sign-out records;
- identification details;
- vehicle registration numbers;
- access-card or key records;
- photographs and video footage;
- CCTV images;
- body-worn camera footage where lawfully used;
- patrol checkpoint activity;
- time, date and location records;
- incident reports;
- witness accounts;
- descriptions of people, vehicles or events;
- emergency-response information;
- details provided to or recorded by security personnel; and
- information concerning suspected trespass, theft, damage, misconduct, safety risks or other incidents.
Employee, contractor and applicant information
- names and contact details;
- residential addresses;
- dates of birth;
- employment history and references;
- résumés and application documents;
- proof of identity and work rights;
- security licences and qualifications;
- training and competency records;
- availability and rostering information;
- payroll, tax, superannuation and bank details;
- emergency contacts;
- performance and disciplinary records;
- workplace incident and injury information;
- licence checks, background checks and screening information;
- photographs and uniform records; and
- other information reasonably required to administer employment or contractor relationships.
Some employee records directly related to a current or former private-sector employment relationship may be subject to an exemption under the Privacy Act. Where that exemption applies, we will continue to manage such information in accordance with applicable workplace laws and our internal policies.
Supplier and business-partner information
- names and business contact details;
- insurance and licensing information;
- financial and payment information;
- contracts and correspondence;
- service-performance information; and
- information required for due diligence, compliance or account administration.
Website and digital information
- IP address;
- browser and device information;
- operating system;
- pages viewed;
- date and time of visits;
- referring website;
- approximate location derived from technical information;
- website enquiry details;
- cookie identifiers;
- analytics information; and
- records of electronic communications with us.
5. How We Collect Personal Information
We may collect personal information:
- directly from an individual;
- through our website, enquiry forms, telephone calls, emails or correspondence;
- when a client requests a quotation or engages our services;
- when a person visits, works at or accesses a site where we provide services;
- from visitor registers, access-control systems or security records;
- through CCTV, photographs, body-worn cameras or other security technology where lawfully operated;
- through GuardPro or another approved reporting and workforce-management platform;
- from a client, property manager, body corporate, tenant, employer or site representative;
- from employees, contractors or security personnel;
- from referees, recruitment providers or licensing authorities;
- from publicly available sources;
- from law-enforcement, emergency or regulatory bodies where lawful;
- from insurers, legal advisers and professional service providers; or
- from another person authorised to provide the information.
Where reasonable and practicable, we collect personal information directly from the individual concerned. In security operations, it may be necessary to collect information indirectly, particularly when investigating or documenting an incident, responding to an emergency, managing site access or receiving instructions from a client.
6. Unsolicited Personal Information
We may sometimes receive personal information that we did not request.
Where this occurs, we will determine whether we could lawfully have collected the information. If not, and where lawful and reasonable to do so, we may destroy or de-identify it.
Thunder Protection Group does not generally accept unsolicited employment applications or résumés through its general client-contact channels. Unsolicited recruitment information may be deleted without consideration or response.
7. Why We Collect and Use Personal Information
We may collect, hold and use personal information to:
- respond to enquiries;
- prepare quotations and proposals;
- assess risks and service requirements;
- enter into and administer contracts;
- provide security services;
- identify authorised persons;
- control access to premises;
- conduct security patrols;
- respond to alarms, incidents and emergencies;
- document security activity;
- prepare patrol, incident and operational reports;
- communicate with clients and emergency contacts;
- manage keys, access cards and security credentials;
- protect people, property and assets;
- investigate suspected incidents or breaches;
- assist police, emergency services or regulators where lawful;
- administer client accounts, invoicing and debt recovery;
- maintain business and operational records;
- manage insurance and legal matters;
- recruit and manage employees and contractors;
- verify licences, qualifications and work rights;
- administer training, rostering, payroll and workplace safety;
- improve our services, systems and procedures;
- manage complaints and feedback;
- maintain website security and performance;
- prevent fraud, misuse, unlawful conduct or cybersecurity threats;
- comply with legal, licensing, contractual and regulatory obligations; and
- perform other activities reasonably necessary for our business functions.
We may also use information for a purpose related to the purpose for which it was collected where the individual would reasonably expect that use, or where otherwise permitted or required by law.
8. Security Reports, Photographs and Incident Records
As part of our services, security personnel may create records containing personal information, including:
- patrol reports;
- checkpoint records;
- photographs;
- incident reports;
- witness details;
- descriptions of individuals;
- access records;
- time and location information; and
- records of communications or actions taken.
These records may be provided to the client or an authorised client representative where reasonably necessary for service delivery, incident management, contractual reporting, safety, risk management or legal compliance.
Clients receiving such records are responsible for handling them securely and limiting access to authorised persons.
Security reports represent the observations and information reasonably available to the reporting officer at the relevant time. They are not formal findings of criminal, civil or disciplinary liability.
9. CCTV and Body-Worn Cameras
CCTV or body-worn cameras may be used at some client locations or during some security operations where permitted by law, client instructions and site procedures.
Footage may be collected for purposes including:
- protecting people and property;
- deterring and detecting security incidents;
- documenting interactions and events;
- supporting incident investigation;
- responding to complaints;
- protecting employees and members of the public;
- providing evidence to police, insurers, courts or regulators; and
- reviewing safety, service quality or compliance.
The availability, activation and retention of footage will depend on the relevant site, equipment, instructions, circumstances and legal requirements. Thunder Protection Group does not guarantee that every event will be recorded or that all footage will be retained.
Audio recording will only be undertaken where authorised by applicable law.
Footage may be owned or controlled by a client, building owner, body corporate, technology provider or another party rather than Thunder Protection Group. Requests concerning client-controlled footage may need to be directed to the relevant owner or operator.
10. GuardPro and Other Service Platforms
We may use GuardPro or other approved digital platforms to support:
- employee rostering;
- attendance verification;
- GPS-supported patrol activity;
- checkpoint verification;
- photographs;
- incident and patrol reports;
- client communications;
- service records; and
- operational quality assurance.
Information entered into these systems may be accessible to authorised Thunder Protection Group personnel, authorised client representatives and relevant technology providers.
Access is limited according to operational requirements, user permissions and applicable contractual arrangements.
11. Location Information
Where reasonably necessary for security operations, we may collect location information relating to company devices, vehicles or personnel, including through:
- mobile patrol systems;
- GPS-enabled reporting applications;
- vehicle-management systems;
- checkpoint scans;
- time-and-attendance systems; and
- emergency or lone-worker safety systems.
Location information may be used for employee safety, dispatch, attendance verification, patrol verification, incident management, service quality and protection of company or client assets.
We do not use operational location information for unrelated personal monitoring.
12. Disclosure of Personal Information
We may disclose personal information to:
- our employees, officers and authorised contractors;
- the client that engaged our services;
- property owners, occupiers, managers or body corporates;
- authorised client representatives;
- emergency contacts;
- police, ambulance, fire or other emergency services;
- government agencies, courts and regulators;
- security licensing or workplace safety authorities;
- insurers, insurance brokers and claims managers;
- legal, accounting, auditing and professional advisers;
- debt-recovery providers;
- banks and payment-service providers;
- recruitment, payroll, superannuation and training providers;
- technology, cloud-hosting, telecommunications and cybersecurity providers;
- GuardPro or other operational platform providers;
- subcontractors engaged to assist in service delivery;
- prospective purchasers or advisers involved in a business restructure, sale or transfer; and
- other parties where authorised or required by law.
We do not sell personal information.
We require service providers to handle information only for authorised purposes and to maintain appropriate confidentiality and security, subject to the nature of the engagement and applicable law.
13. Disclosure to Police and Authorities
We may disclose personal information to police, emergency services, courts, government agencies or regulatory authorities where:
- required or authorised by law;
- responding to a lawful request;
- reasonably necessary to prevent or investigate suspected unlawful activity;
- necessary to protect life, health or safety;
- necessary for the establishment, exercise or defence of a legal claim; or
- otherwise permitted under applicable privacy laws.
We may preserve records where we reasonably anticipate a police investigation, legal proceeding, insurance claim, regulatory inquiry or contractual dispute.
14. Overseas Disclosure
Some technology, cloud-storage, email, software, analytics or support providers may store or process information outside Australia.
The countries involved may vary depending on the provider, hosting arrangements and services used. They may include countries in which our technology providers or their subcontractors operate.
Where the Australian Privacy Principles apply, we will take reasonable steps required by law before disclosing personal information to an overseas recipient.
By using our website or services, an individual acknowledges that electronic information may be processed through infrastructure located outside Australia. This acknowledgement does not remove any rights that cannot legally be excluded.
15. Direct Marketing
We may use business contact information to communicate about:
- requested services;
- service updates;
- related security services;
- business announcements;
- client information; and
- offers that may reasonably be relevant to an existing or prospective business relationship.
We will provide a reasonable means to opt out of direct marketing communications.
A person may unsubscribe by:
- using the unsubscribe option in the relevant communication;
- replying with an opt-out request; or
- contacting us using the details at the end of this Policy.
Operational, contractual, safety, account or service-related communications are not marketing communications and may continue where reasonably necessary.
16. Cookies and Website Analytics
Our website may use cookies and similar technologies to:
- operate website functions;
- remember user preferences;
- understand website usage;
- improve website performance;
- protect against misuse;
- measure traffic and engagement; and
- support limited advertising or analytics functions.
A cookie is a small file stored on a user’s device by a website.
Users may adjust their browser settings to reject or delete cookies. Some parts of the website may not function correctly if cookies are disabled.
Third-party services may collect technical information according to their own privacy policies. Our use of cookies and similar technologies is further explained in our Cookie Policy.
17. External Websites and Social Media
Our website may contain links to third-party websites, platforms or social-media services.
We are not responsible for the privacy, content or security practices of third parties. Individuals should review the relevant third party’s privacy terms before providing personal information.
Information posted publicly on social media may be accessible, copied or disclosed by other users. Individuals should avoid posting confidential, sensitive or security-related information through public channels.
18. Security of Personal Information
We take reasonable steps appropriate to the nature of the information and our operations to protect personal information against:
- misuse;
- interference;
- loss;
- unauthorised access;
- unauthorised modification; and
- unauthorised disclosure.
Protective measures may include:
- access controls;
- password and authentication requirements;
- role-based permissions;
- secure cloud services;
- staff confidentiality obligations;
- device and account controls;
- physical security;
- incident-response procedures;
- secure disposal processes;
- software updates and cybersecurity safeguards; and
- limiting access to personnel with an operational need.
No physical or electronic system is completely secure. We cannot guarantee that unauthorised access, cyberattack, human error, equipment failure or another security incident will never occur.
Individuals should not send highly sensitive information through unsecured email or website forms unless requested and appropriate safeguards have been arranged.
19. Data Breaches
We maintain procedures for responding to suspected loss, unauthorised access or disclosure of personal information.
Where the Notifiable Data Breaches scheme applies, an organisation must notify affected individuals and the Office of the Australian Information Commissioner when an eligible breach is likely to result in serious harm.
Where we identify a suspected breach, we may:
- contain the incident;
- investigate what occurred;
- assess the information and individuals affected;
- take remedial action;
- engage cybersecurity, legal or forensic advisers;
- notify clients, individuals, insurers or regulators where appropriate; and
- review systems and procedures to reduce future risk.
20. Retention and Disposal
We retain personal information for as long as reasonably necessary for the purpose for which it was collected, or as required for:
- service delivery;
- contractual obligations;
- employment administration;
- taxation and financial records;
- insurance requirements;
- licensing and regulatory obligations;
- workplace health and safety;
- dispute management;
- legal proceedings;
- limitation periods;
- incident investigation; and
- legitimate business-record requirements.
Retention periods may differ according to the type of information and the circumstances.
When information is no longer reasonably required, we may securely destroy or de-identify it, subject to legal and operational requirements.
Electronic backups may retain residual copies for a limited period until they are overwritten or securely deleted through ordinary system processes.
21. Access to Personal Information
An individual may request access to personal information we hold about them.
Requests should:
- be made in writing;
- provide sufficient information to identify the requester;
- describe the information being requested; and
- include reasonable identity verification.
We will respond within a reasonable period.
Access may be refused or limited where permitted by law, including where disclosure would:
- unreasonably affect another person’s privacy;
- reveal confidential or commercially sensitive information;
- compromise security arrangements;
- prejudice an investigation;
- disclose legally privileged material;
- be unlawful; or
- create a serious threat to life, health or safety.
Where access is refused, we will provide reasons where required and lawful.
We may charge reasonable administrative costs for providing access where permitted, but will not charge merely for making a request.
22. Correction of Personal Information
Individuals may ask us to correct personal information they believe is inaccurate, incomplete, out of date, irrelevant or misleading.
We may take reasonable steps to verify the requested correction.
Where we agree that information should be corrected, we will take reasonable steps to update our records. Where appropriate and legally required, we may also notify another party that previously received the information.
Some security and incident records must preserve the original entry. In those circumstances, we may add a correction, clarification or supplementary statement rather than deleting or rewriting the original record.
23. Identity Verification
Before providing access to information or processing certain privacy requests, we may require evidence of identity.
This is intended to protect individuals against unauthorised access or disclosure.
Verification may include confirming:
- name;
- contact details;
- identification documents;
- relationship to the relevant client or site;
- details of prior communications; or
- other information reasonably necessary to establish identity or authority.
24. Anonymity and Pseudonyms
Where lawful and practicable, individuals may interact with us anonymously or using a pseudonym.
This may not be practicable where we need to:
- prepare a quotation;
- provide contracted security services;
- verify site access;
- respond to an incident;
- process a complaint;
- manage employment;
- issue an invoice;
- verify a person’s authority; or
- comply with legal, safety, licensing or security requirements.
25. Children and Young People
Our services and website are not directed toward children for the purpose of collecting personal information.
However, security operations may incidentally involve children or young people, including at residential, retail, healthcare, community or educational locations.
Where information concerning a child is collected, we will seek to handle it with appropriate care, taking into account the circumstances, safety considerations, client instructions and applicable law.
A parent, guardian or authorised representative may contact us regarding a child’s information, subject to identity, authority and legal requirements.
26. Automated Decision-Making
Thunder Protection Group does not currently use personal information in substantially automated decisions that could reasonably be expected to significantly affect an individual’s rights or interests.
We may use software to assist with administrative functions such as scheduling, reporting, communications, fraud prevention or application management, but material operational and employment decisions are subject to human involvement.
From 10 December 2026, additional privacy-policy transparency requirements apply to covered APP entities using personal information in certain automated decisions that may significantly affect individuals. We will update this Policy where required if our practices change.
27. Complaints
A person who believes we have mishandled their personal information may submit a privacy complaint.
The complaint should include:
- the complainant’s name and contact details;
- a description of the concern;
- relevant dates, communications or documents;
- the outcome sought; and
- any other information reasonably necessary to investigate.
We will acknowledge and investigate complaints within a reasonable period. We may contact the complainant for additional information and may consult relevant employees, clients, service providers or advisers.
We will seek to provide a written response after completing our review.
28. Complaints to the OAIC
Where the Privacy Act applies and a person is not satisfied with our response, they may be entitled to complain to the Office of the Australian Information Commissioner.
We encourage individuals to contact us first so that we have an opportunity to investigate and resolve the concern.
29. Client Responsibilities
Where a client provides personal information to us, the client is responsible for ensuring that:
- it is authorised to provide the information;
- the information has been collected lawfully;
- relevant notices or consents have been provided where required;
- its instructions comply with applicable law;
- only necessary information is provided; and
- authorised users of reports and systems maintain confidentiality.
Clients must promptly notify us if:
- access permissions should be changed;
- an authorised contact leaves the organisation;
- login credentials may have been compromised;
- information provided to us is inaccurate; or
- a privacy or security incident may have occurred.
30. Changes to This Privacy Policy
We may amend this Privacy Policy from time to time to reflect:
- changes to our services;
- legal or regulatory developments;
- changes to technology providers;
- operational changes; or
- improvements to our privacy practices.
The current version will be published on our website with the date of the latest update.
Material changes will apply from the date the revised Policy is published unless otherwise stated.
31. Contact Us
Privacy enquiries, access requests, correction requests and complaints may be directed to:
Privacy Officer
Thunder Protection Group
Thunder Dragon Protective Services Pty Ltd
Email: ops@thunderprotectiongroup.com.au
Telephone: 1300 520 124
Postal address: 2/8 Clunies Ross Court, Eight Mile Plains QLD 4113
Visits to our head office are by appointment only.
Please mark correspondence “Private and Confidential – Attention: Privacy Officer.”
* = mandatory fields