- Privacy & Data Protection
Privacy
Policy
Your Confidentiality Matters
Privacy Policy
RIVICA Investigations & Covert Solutions Pty Ltd
Last updated: 7 September 2026
1. Our approach to privacy
2. What personal information we may collect
- names, aliases and identifying information;
- residential, postal, business and historical addresses;
- telephone numbers, email addresses and other contact information;
- dates of birth and age information;
- photographs, video recordings and physical descriptions;
- employment, professional and business information;
- company, directorship and commercial information;
- property and asset information;
- vehicle information;
- publicly available court, tribunal and regulatory information;
- information concerning relationships, associates and family connections;
- information obtained from publicly available sources, databases and authorised information services;
- correspondence, statements, instructions and documents supplied by clients, witnesses or other persons;
- observations made during lawful investigative activity;
- information about movements, locations, interactions, conduct or patterns of activity where relevant to an investigation;
- digital information obtained during authorised forensic examinations;
- technical information relating to devices, networks or communications where relevant to an authorised engagement; and
- reports, photographs, recordings, notes, intelligence assessments and other material produced during an investigation.
RIVICA will seek to limit collection to information reasonably relevant or necessary to the
legitimate purpose for which the matter is being undertaken.
3. Information provided by clients
- the identity and authority of the client;
- the legitimate purpose of the investigation;
- the relationship between the client and the subject matter;
- relevant legal, contractual or regulatory considerations;
- whether proposed investigative activity is lawful and proportionate; and
- whether RIVICA should accept, limit or decline the engagement.
4. How we collect personal information
- directly from clients;
- directly from the individual concerned;
- from witnesses, employees, contractors, associates or other persons;
- from lawyers, insurers, businesses, government bodies or other organisations where authorised or lawful;
- through publicly available records and online sources;
- through commercial databases and information services lawfully available to RIVICA;
- through enquiries and interviews;
- through physical observations undertaken during investigations or surveillance;
- from photographs, video or other recordings lawfully obtained;
- through examination of documents and records;
- from devices or digital media supplied to RIVICA with appropriate authority;
- through analysis of information obtained from multiple sources; and
- through conclusions, assessments or investigative inferences reasonably arising from collected information
5. Investigative and covert collection
- the purpose of the investigation;
- whether the proposed collection is lawful;
- whether there is a legitimate investigative need;
- the relevance of the information sought;
- whether the collection is reasonably necessary or proportionate;
- the location and circumstances in which information may be collected;
- any reasonable expectation of privacy;
- risks to third parties;
- applicable surveillance, workplace, telecommunications, privacy or other laws; and
- whether a less intrusive method could reasonably achieve the required outcome
6. Public places and observations
Information observed in a public place, or from a location where RIVICA is lawfully entitled to
be present, may be recorded where relevant to an authorised investigation.
7. Sensitive information
8. Purpose of collecting and using personal information
- assessing enquiries and proposed engagements;
- verifying client identity, authority and instructions;
- conducting investigations;
- undertaking surveillance;
- locating persons;
- conducting background, due diligence or factual enquiries;
- investigating fraud, misconduct, workplace matters or other alleged conduct;
- conducting digital forensic examinations;
- conducting technical surveillance counter-measures and related security work;
- serving legal documents;
- identifying, obtaining, preserving and documenting evidence;
- preparing investigation reports, affidavits, statements or evidentiary material;
- providing professional advice arising from investigative findings;
- responding to legal proceedings or regulatory requirements;
- protecting the lawful interests, safety or security of clients, RIVICA personnel or other persons;
- quality assurance, case management and professional record keeping;
- billing, administration and client relationship management; and
- complying with legal and regulatory obligations.
9. Disclosure of personal information
- the client who commissioned the investigation;
- the client’s legal representatives;
- courts and tribunals;
- government or regulatory authorities;
- insurers or professional advisers;
- investigators, process servers, forensic specialists, interpreters, experts or other contractors engaged for a matter;
- technology, data storage, case management or professional service providers;
- law enforcement agencies where disclosure is required or lawfully justified; and
- other persons where the disclosure is authorised, necessary or legally permitted.
10. Client reports and evidence
- distinguish observation from assessment or inference where appropriate;
- record relevant information accurately;
- avoid unnecessary personal information unrelated to the investigative purpose;
- identify evidentiary sources where professionally appropriate;
- preserve the integrity of material capable of being used in legal proceedings; and
- provide a documented and court-defensible record of investigative activity.
11. Quality and accuracy
- distinguish confirmed information from unverified intelligence;
- identify limitations affecting verification;
- corroborate information from multiple sources;
- correct identified factual errors; and
- record the evidentiary basis for significant findings.
12. Security of personal information
- access controls;
- authentication and account security;
- secure electronic storage;
- controlled case-management systems;
- encryption or other technical safeguards where appropriate;
- restrictions on staff and contractor access;
- secure transfer mechanisms;
- physical security;
- confidentiality requirements;
- controlled handling of evidentiary material;
- backup and recovery processes;
- documented operational procedures; and
- review of third-party service providers.
13. Retention and destruction
- the nature of the investigation;
- evidentiary requirements;
- anticipated or actual litigation
- statutory or contractual requirements;
- limitation periods;
- professional record-keeping requirements;
- potential complaints or disputes;
- the sensitivity of the information; and
- whether continued retention remains reasonably necessary.
14. Overseas disclosure and service providers
Because the countries involved may vary according to the particular investigation and service
provider, it may not always be practicable to identify every possible overseas location in this
Policy.
15. Anonymity and pseudonyms
- assess the legitimacy of an engagement;
- establish the client’s authority;
- conduct appropriate conflict or risk assessment;
- comply with legal obligations;
- issue contractual documentation or invoices; or
- safely and professionally undertake the investigation.
16. Access to personal information
- prejudice an existing or anticipated investigation;
- reveal information relating to another person;
- disclose confidential information;
- reveal investigative methodology or protected sources;
- prejudice legal proceedings;
- interfere with legal professional privilege;
- create a serious safety or security risk;
- be unlawful; or
- otherwise fall within an applicable ground for refusing access.
17. Correction of personal information
18. Information relating to other people
A person requesting access to information about themselves is not automatically entitled to personal information concerning another individual.
19. Data breaches
- contain and investigate the incident;
- assess the nature and sensitivity of the information involved;
- evaluate the likelihood and seriousness of potential harm;
- take remedial action;
- preserve relevant evidence; and
- make notifications required under applicable privacy or other legislation.
20. Website information
- IP address;
- browser and device information;
- pages viewed;
- date and time of access;
- referral information; and
- website usage data.
21. Direct marketing
22. Privacy enquiries and complaints
Questions, access requests, correction requests or privacy complaints may be directed to:
Privacy Officer
RIVICA Investigations & Covert Solutions Pty Ltd
Level 5, 111 Cecil Street
South Melbourne VIC 3205
Australia
Email: enquiries@rivica.com.au
- the person making the complaint;
- the conduct or information concerned;
- the reason the person considers the handling inappropriate; and
- any outcome sought.
23. Other legal rights and obligations
- obligations imposed by Australian law;
- court or tribunal orders;
- lawful investigative powers or processes;
- legal professional privilege;
- duties of confidentiality;
- evidentiary preservation requirements;
- rights or exemptions available under the Privacy Act or other legislation; or
- RIVICA’s ability to decline a request where compliance would be unlawful or professionally inappropriate.