Last Reviewed: August 2026 | Version 3.0
Introduction
This Privacy Policy explains what personal information Salt Space Coworking (Salt Space, us, our, we) collects, why we collect it, how we use and protect it, and your rights in relation to it.
Salt Space is committed to handling all personal information in accordance with the Privacy Act 1988 (Cth) as amended by the Privacy and Other Legislation Amendment Act 2024 and associated reforms, including the Australian Privacy Principles (APPs). We comply with all applicable obligations.
This policy applies to information collected when you visit our premises at Level 1, 888 Brunswick Street, New Farm, use our website (www.saltspace.com.au), contact us by email or telephone, or use any of our services.
Definitions
In this Privacy Policy:
“Client” means any person or entity that uses our services on a casual or ad hoc basis (meeting room hire, studio hire, hot desk day passes) without being a registered Member.
“Member” means any person or entity registered with Salt Space to use our coworking space, virtual office, or mailing address services.
“Personal Information” means information or an opinion that identifies, or is reasonably capable of identifying, an individual, directly or indirectly, whether true or not and whether recorded in a material form or not.
“Prospective Member” means anyone who contacts Salt Space to enquire about our services.
“Sensitive Information” has the meaning given in the Privacy Act 1988 (Cth) and includes health information, biometric data, and similar categories attracting heightened protection.
“Verification Record” means the written record — comprising name, identity document type, document number, and date of verification — retained after your photographic identity document has been permanently deleted, for compliance with mail receiving obligations.
“Visitor” means any person who enters our premises who is not a Member or Client.
“We”, “us”, “our” means Salt Space and its employees and authorised contractors.
“Website” means www.saltspace.com.au and any other web pages or online offerings that link to this policy.
“You”, “your” means, depending on context, a Member, Client, Prospective Member, or Visitor.
What Personal Information We Collect
We collect only the personal information necessary to operate our business, including:
- Contact details: Full name, email address, telephone number, and mailing or business address.
- Business information: Job title, organisation or business name, ABN, and ACN.
- Financial information: Payment card details (processed exclusively by Stripe — we do not store full card numbers), bank account details for invoicing, and billing records.
- Identity verification — mailing address: For personal mailing address services (individuals): identity document type, document number, and issuing authority — recorded as a Verification Record after the photographic copy has been permanently deleted, as required under the Australia Post MRA Code of Practice.
- Identity verification — virtual office: For virtual office and registered office services (businesses): identity document type, document number, issuing authority, and CDD documentation — recorded as required by the AML/CTF Act 2006 (Cth) as a AUSTRAC reporting entity.
- Network information: IP address, device identifiers, and bandwidth data when you use our internet service.
- Physical security data: CCTV footage and electronic door access records.
- Communications: Feedback, enquiries, and correspondence you send us.
We do not collect Sensitive Information unless you volunteer it.
How We Collect and Hold Personal Information
Collection
Personal information is collected directly from you when you register, enquire, or communicate with us; automatically when you use our premises or internet service; and, where relevant, from publicly available sources such as social media profiles or ASIC registers.
Storage
We hold personal information on secure, access-controlled cloud systems. Third-party platforms we use include Google Workspace (United States), Stripe (United States), Xero (New Zealand / United States), and Mailchimp (United States). See “Sharing of Information and Cross-Border Disclosure” below.
Identity Verification Records
Following identity verification for any identity-verified service, we retain a Verification Record — name, document type, document number, issuing authority, and date of verification — in a secured, access-restricted file. The photographic copy of your identity document is permanently deleted within two (2) business days of successful verification. Retention periods differ by service type — see “Accuracy and Retention of Personal Information” below.
Sensitive Information
We do not request Sensitive Information as defined under the Privacy Act 1988 (Cth). If you voluntarily provide Sensitive Information, we will treat it with the highest level of confidentiality, use it only for the purpose for which it was provided, and will not disclose it without your consent except as required by law.
Identity Services: Personal Mailing Address and Virtual Office
Salt Space offers two distinct identity-verified services, each governed by a different regulatory framework. Your obligations and our data handling differ depending on which service you use.
Personal Mailing Address Service (individuals)
Our personal mailing address service is available to individual Members who wish to use our address for personal correspondence. Identity verification for this service is governed by:
- Australia Post’s Mail Receiving Agent (MRA) Code of Practice; and
- Applicable Australian Communications and Media Authority (ACMA) guidelines.
Provision of identity information is a legal condition of service under the MRA Code. We cannot activate a personal mailing address without first verifying your identity.
Virtual Office and Registered Office Service (businesses)
Our virtual office service, which includes use of our address as a registered business address with ASIC or other bodies, is a designated service under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) (AML/CTF Act), as amended by the AML/CTF Amendment Act 2024, effective 1 July 2026.
Salt Space is enrolled with AUSTRAC as a reporting entity (Enrolment No. 2688823000). As a reporting entity, we are required by law to: verify the identity of all clients and beneficial owners before activating a virtual office or registered office service; conduct sanctions screening against DFAT and UN consolidated lists; collect and retain customer due diligence (CDD) records; and maintain an AML/CTF compliance program.
Provision of identity information is a legal condition of service. We cannot activate a virtual office or registered office service without first completing identity verification and sanctions screening.
Our verification and deletion process (both services)
We collect a copy of your government-issued photographic identification solely for the purpose of verification. Once your identity is confirmed — typically within two (2) business days — the photographic copy is permanently deleted from all our systems. We retain only a written Verification Record (document type, number, and date verified) as required for compliance purposes.
What we retain and what we do not
- We DO retain: your name, identity document type (e.g. “Passport”), document number, issuing state/country, and date of verification — held securely as a Verification Record.
- We DO NOT retain: photographic copies, scans, or images of your identity document.
- We DO NOT retain: facial photographs or biometric data derived from your identity document.
- For personal mailing address clients: Verification Records are retained for the period required under the Australia Post MRA Code of Practice and ACMA guidelines. Please contact us for the current retention period applicable to your service.
- For virtual office and registered office clients: Verification Records are retained for 7 years from the date the service ends, as required by the AML/CTF Act 2006 (Cth) s.105 (AUSTRAC obligation). After 7 years, records are securely destroyed.
Mail handling
We handle incoming mail and parcels on your behalf. Your contact details are used solely to notify you of arrivals and facilitate collection or forwarding. Where you have requested mail forwarding, we may share your nominated forwarding address with Australia Post or courier services.
Business address registration
If you use our address as your registered business address with ASIC or other bodies, this is at your discretion. You remain responsible for maintaining accurate registration details with those organisations. Salt Space accepts no liability for third-party correspondence directed to our address.
Use of Artificial Intelligence Tools
Salt Space may use artificial intelligence (AI) tools to assist with internal operational tasks such as drafting communications, summarising documents, or managing administrative workflows.
Local AI tools (no external data transmission)
Where we use AI tools that operate entirely within our local or private computing environment — without transmitting personal information to any external server or third-party provider — your personal data remains within our existing secure environment and is subject to the same security controls described in the “Security” section of this policy.
Third-party or cloud AI tools
Where we use AI tools that transmit data to a third-party provider, we ensure a lawful basis exists for that processing, we do not enter Sensitive Information without explicit consent, and any relevant third-party provider is disclosed in our data register and under our cross-border disclosure obligations.
Automated decision-making
Salt Space does not currently use fully automated systems to make decisions that affect your rights or interests in a legally significant way. Where this changes, we will update this policy and ensure you can request human review of any automated determination. This commitment is consistent with our obligations under Privacy Act reforms effective December 2026.
How We Use and Disclose Personal Information
We collect, use, and disclose personal information only for the purposes set out below, for directly related secondary purposes you would reasonably expect, or with your consent.
Operational purposes
- To provide and administer our coworking, meeting room, virtual office, and mailing address services.
- To verify the identity of Members and Clients where legally required.
- To communicate with you about your account, bookings, and relevant operational matters.
- To process payments securely through Stripe (PCI-DSS compliant).
- To operate CCTV and door access systems for building security (CCTV retained 7 days; door logs retained 90 days).
- To manage bandwidth and provide reliable internet access.
- To maintain our optional Member business directory (participation is voluntary).
Communication and marketing
- To send operational notices and event information we reasonably believe you would expect.
- To send marketing communications where you have consented or where we have an existing relationship and you have not opted out. All marketing emails include a clear unsubscribe link.
- We do not sell, rent, or share your personal information with third parties for their marketing purposes.
Legal and compliance
- To comply with our obligations under the Privacy Act 1988 (Cth), ACMA guidelines, Australian tax law, and other applicable legislation.
- To respond to lawful requests from law enforcement or regulatory authorities.
Sharing of Personal Information and Cross-Border Disclosure
Third-party service providers
We share personal information with the following service providers as necessary to operate our business:
|
Provider |
Country |
Purpose |
|---|---|---|
|
Google Workspace |
United States |
Email, document storage, collaboration |
|
Stripe |
United States |
Payment processing (PCI-DSS compliant) |
|
Xero |
New Zealand / United States |
Accounting and invoicing |
|
Mailchimp (Intuit) |
United States |
Email marketing communications |
|
Australia Post / Couriers |
Australia |
Mail forwarding (forwarding address only) |
Before disclosing personal information to overseas recipients, we take reasonable steps to ensure the recipient is subject to privacy protections substantially similar to the APPs (APP 8.1). By using our services and agreeing to this policy, you acknowledge that your personal information may be transferred to the countries listed above.
EEA residents
If you are a European Economic Area (EEA) resident, you may have additional rights under the GDPR, including the right to object to processing, request restriction, or request data portability. Please contact us to exercise these rights.
Consent
Where we rely on consent as the basis for collecting or using your personal information, we will request it in a clear, specific, and unambiguous manner. We do not use pre-ticked boxes or bundled consent. You may withdraw consent at any time by contacting us, subject to any legal obligation requiring retention of the relevant information.
Security of Personal Information
We take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access, modification, or disclosure (APP 11). Our security measures include:
- Encrypted, access-controlled cloud platforms with multi-factor authentication required for staff access.
- Restriction of access to personal information to staff who require it in their role.
- PCI-DSS compliant payment processing through Stripe. We do not store full payment card numbers.
- Prompt and permanent deletion of photographic identity documents upon verification, confirmed by internal record.
- Password protection and access restrictions applied to any file storing Verification Records.
- Physical security including CCTV and electronic door access controls.
- Regular review of security practices and staff awareness training.
Notifiable Data Breaches
In the event of a data breach likely to result in serious harm to any individual, Salt Space will comply with its obligations under the Notifiable Data Breaches (NDB) scheme under the Privacy Act 1988 (Cth), including notifying affected individuals and the Office of the Australian Information Commissioner (OAIC) as soon as practicable.
Direct Marketing
We may use your contact details to send you information about our services, events, and updates where you would reasonably expect such communications or where you have provided consent. All marketing communications include a simple opt-out mechanism. We will not use Sensitive Information for direct marketing without your specific prior consent. We do not sell or share your personal information with third parties for their marketing purposes.
To unsubscribe, click the unsubscribe link in any email or contact us at work@saltspace.com.au.
Accuracy and Retention of Personal Information
We take reasonable steps to ensure personal information we hold is accurate, up to date, complete, and relevant. If your information changes, please notify us. We retain personal information for as long as necessary to fulfil the purposes for which it was collected and to comply with legal obligations:
|
Data Type |
Retention Period |
Legal Basis |
|---|---|---|
|
Photographic identity documents (all services) |
Deleted within 2 business days of verification |
Data minimisation / APP 11.2 |
|
Verification Records — Personal Mailing Address clients |
30 days from end of service |
ACMA / Australia Post MRA Code of Practice |
|
Verification Records — Virtual Office / Registered Office clients |
7 years from date service ends |
AML/CTF Act 2006 (Cth) s.105 — AUSTRAC obligation |
|
CCTV footage |
7 days, then deleted |
APP 11.2 — security purpose fulfilled |
|
Door access logs |
90 days, then deleted |
APP 11.2 — security / audit purpose |
|
Billing and transaction records |
5 years from transaction date |
Tax Administration Act 1953 (Cth) |
|
Member/Client account records |
Duration of relationship + 5 years |
Legal obligations / dispute resolution |
|
Marketing contact list |
Until unsubscribe or withdrawal of consent |
Spam Act 2003 / APP 6 |
Your Privacy Rights
Subject to limited exceptions under the Privacy Act 1988 (Cth), you have the right to:
- Request access to the personal information we hold about you (APP 12).
- Request correction of inaccurate, incomplete, or out-of-date information (APP 13).
- Opt out of direct marketing at any time.
- Lodge a complaint about our privacy practices (see “Complaints” below).
- For EEA residents: object to processing, request restriction, or request data portability.
To exercise any right, please contact us at work@saltspace.com.au. We will respond within 30 days.
Complaints
If you have a concern or complaint about our handling of your personal information or a potential breach of the APPs, please contact us in writing:
- Email: work@saltspace.com.au
- Mail: Salt Space, Level 1, 888 Brunswick Street, New Farm, Brisbane QLD 4005
We will acknowledge your complaint within five (5) business days and endeavour to resolve it within thirty (30) days.
If your complaint is not resolved to your satisfaction, you may refer it to the Office of the Australian Information Commissioner (OAIC):
- Website: www.oaic.gov.au
- Phone: 1300 363 992
- Mail: GPO Box 5218, Sydney NSW 2001
Contact Us
- Email: work@saltspace.com.au
- Mail: Salt Space, Level 1, 888 Brunswick Street, New Farm, Brisbane QLD 4005
- Website: www.saltspace.com.au
Updates to This Policy
Salt Space reserves the right to update this policy to reflect changes in our practices, services, or legal obligations. We will notify Members and Clients of material changes by email and by posting a notice on our website at least 14 days before the changes take effect. Continued use of our services following notification constitutes acceptance of the updated policy.
This policy was last reviewed August 2026 (Version 3.0).
