
Privacy Policy
InsideEDGE Privacy Policy
1. About This Policy
Inside Edge Novated Leasing Pty Ltd (Inside Edge, we, us or our) respects your privacy. This policy explains how we manage personal information under the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). We also comply with the Australian Finance Industry Association (AFIA) Code of Practice where it applies to us.
This policy applies to personal information about customers and prospective customers, employer representatives, suppliers, referrers, business partners, contractors, job applicants, employees, website visitors and other people who interact with us.
This policy applies to personal information about customers and prospective customers, employer representatives, suppliers, referrers, business partners, contractors, job applicants, employees, website visitors and other people who interact with us.
2. What personal information we collect and hold
Personal information is information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether or not it is true or recorded in a material form. Depending on our relationship with you, we may collect and hold:
- identity and contact details, including name, date of birth, address, email address, telephone number and signature;
- government-related identifiers and verification information, including driver licence, passport details or visa status, where reasonably necessary for identity verification or another lawful purpose;
- employment, employer, payroll, salary packaging and novated leasing information;
- financial and transaction information, including bank account details, income, expenditure, lease budgets, deductions, reimbursements and payment history;
- vehicle and driving-related information, including vehicle details, kilometres, fuel, registration, maintenance, insurance and claims information;
- information about your personal circumstances, including marital or relationship status, spouse or partner details and dependant information where relevant;
- application and service information, including preferences, quotes, contracts, consents, authorities, complaints, hardship requests and support records;
- communications and interaction records, which may include emails, correspondence, call recordings, authentication events and records of dealings with our staff;
- digital and technical information, including IP address, device and browser information, login activity, website or portal usage, cookies and similar technology data; and
- business contact, supplier, recruitment and professional information relevant to our dealings with you.
3. Sensitive information
We collect sensitive information only where reasonably necessary for our functions and where you consent or the law otherwise permits. This may include health information relevant to hardship assistance, accessibility, an insurance service or a workplace matter, and criminal record information relevant to employment, recruitment or insurance. We will explain the purpose at or before collection where required.
4. How we collect and hold personal information
We usually collect personal information directly from you, including through applications, forms, telephone calls, email, meetings, our website and AutoDash. We may also collect it from:
If you provide personal information about another person, you must be authorised to do so and must make them aware of this policy where appropriate. If we receive unsolicited personal information, we will determine whether we could lawfully have collected it. If not, and it is lawful and reasonable to do so, we will destroy or de-identify it.
We hold information in electronic systems and, in some cases, paper records. Information may be held in our systems or by contracted service providers on our behalf.
- your employer, payroll provider or previous salary packaging provider;
- financiers, insurers, brokers, vehicle dealers and vehicle service providers;
- referrers, introducers, authorised representatives and people acting on your behalf;
- identity verification, technology, payment, data, analytics and other service providers;
- government agencies, regulators, public registers and publicly available sources; and
- another person, where you have authorised them or where collection is otherwise lawful.
If you provide personal information about another person, you must be authorised to do so and must make them aware of this policy where appropriate. If we receive unsolicited personal information, we will determine whether we could lawfully have collected it. If not, and it is lawful and reasonable to do so, we will destroy or de-identify it.
We hold information in electronic systems and, in some cases, paper records. Information may be held in our systems or by contracted service providers on our behalf.
5. Why we collect, hold, use and disclose personal information
We collect, hold, use and disclose personal information where reasonably necessary for our functions and activities, including to:
If we cannot collect information that is reasonably necessary, we may be unable to verify your identity, process an application, establish or administer an arrangement, make a payment or provide another requested service.
- identify you, communicate with you and manage our relationship;
- provide quotes and arrange, establish, administer, vary or end novated leasing, finance, insurance and related services;
- manage payroll deductions, lease budgets, payments, bank detail changes, reimbursements, fuel, maintenance, registration, insurance and claims;
- provide and secure AutoDash and other digital services, verify transactions, prevent fraud and resolve disputes;
- assess and support complaints, hardship requests and customer service needs;
- manage employer, supplier, referrer and business-partner relationships;
- conduct analytics, quality assurance, audit, risk management, training, business continuity and service improvement;
- protect our staff, customers, systems, property and legal rights;
- consider employment applications and manage contractor arrangements; and
- comply with legal, regulatory, taxation, reporting and governance obligations, including obligations of the employer who provides or provided the benefit.
If we cannot collect information that is reasonably necessary, we may be unable to verify your identity, process an application, establish or administer an arrangement, make a payment or provide another requested service.
6. Who we disclose personal information to
Where reasonably necessary for the purposes above, or where authorised or required by law, we may disclose personal information to:
A recipient may have its own legal obligations and privacy policy. For example, a financier or insurer will generally be responsible for its own handling of information once it receives an application or administers its product.
- your employer or payroll provider;
- financiers, insurers, vehicle dealers and suppliers;
- fuel, maintenance, roadside assistance, accident management, registration, toll, payment and other vehicle-related providers;
- identity verification, communications, document management, hosting, cloud, cyber security, analytics and other technology providers;
- professional advisers, auditors, consultants, debt recovery providers and dispute resolution bodies;
- government agencies, courts, law enforcement and regulators where lawful;
- a person you authorise, including a legal representative or adviser; and
- a prospective purchaser or successor in connection with a proposed or completed sale, restructure or transfer of all or part of our business, subject to appropriate safeguards.
A recipient may have its own legal obligations and privacy policy. For example, a financier or insurer will generally be responsible for its own handling of information once it receives an application or administers its product.
7. Finance applications and credit-related information
Inside Edge is not a credit provider or credit reporting body. When you ask us to assist with a lease or finance application, we may collect information required by a financier and disclose it to that financier or an intermediary acting for it. The financier may obtain and handle credit information and credit eligibility information under the Privacy Act and the Privacy (Credit Reporting) Code 2025.
Where appropriate and with your authorisation, Inside Edge may obtain a preliminary soft credit eligibility assessment from Equifax or an equivalent provider to help determine whether your application is likely to satisfy a financier's minimum credit requirements. A soft credit eligibility assessment is a preliminary screening enquiry. It is intended not to affect your credit score or appear on your credit file as a visible formal credit enquiry. It does not constitute finance approval and does not replace a finance provider's own assessment.
The relevant financier's privacy or credit reporting policy explains which credit reporting bodies it uses, the credit-related information it collects and discloses, and how you may access or correct that information or make a complaint. Inside Edge does not disclose repayment history information to a credit reporting body or list a default unless it is legally entitled and authorised to do so. You may contact us if you need help identifying the relevant financier.
Where appropriate and with your authorisation, Inside Edge may obtain a preliminary soft credit eligibility assessment from Equifax or an equivalent provider to help determine whether your application is likely to satisfy a financier's minimum credit requirements. A soft credit eligibility assessment is a preliminary screening enquiry. It is intended not to affect your credit score or appear on your credit file as a visible formal credit enquiry. It does not constitute finance approval and does not replace a finance provider's own assessment.
The relevant financier's privacy or credit reporting policy explains which credit reporting bodies it uses, the credit-related information it collects and discloses, and how you may access or correct that information or make a complaint. Inside Edge does not disclose repayment history information to a credit reporting body or list a default unless it is legally entitled and authorised to do so. You may contact us if you need help identifying the relevant financier.
8. Overseas Disclosure
We are likely to disclose personal information to service providers or personnel located in the Philippines for operational and administrative support. Some technology and cloud providers may also process or store information outside Australia. Where it is practicable to identify other countries to which we are likely to disclose personal information, we will do so in the relevant collection notice or an updated version of this policy.
Before disclosing personal information to an overseas recipient, we take reasonable steps required by APP 8 to ensure the recipient does not breach the APPs in relation to the information, unless an exception applies. Depending on the circumstances, those steps may include due diligence, contractual privacy and security requirements, access controls and ongoing oversight.
Before disclosing personal information to an overseas recipient, we take reasonable steps required by APP 8 to ensure the recipient does not breach the APPs in relation to the information, unless an exception applies. Depending on the circumstances, those steps may include due diligence, contractual privacy and security requirements, access controls and ongoing oversight.
9. Direct marketing
Where permitted by law, we may use personal information to communicate information about our products and services or those of selected partners that we reasonably believe may interest you. We may communicate by mail, telephone, email, SMS, social media or targeted advertising. We do not use sensitive information for direct marketing without consent.
You can opt out at any time by using the unsubscribe facility in a message or contacting us. We will action opt-out requests within the timeframe required by applicable law. You may also ask us to identify the source of personal information used for direct marketing, where the Privacy Act provides that right.
You can opt out at any time by using the unsubscribe facility in a message or contacting us. We will action opt-out requests within the timeframe required by applicable law. You may also ask us to identify the source of personal information used for direct marketing, where the Privacy Act provides that right.
10. Website, cookies and analytics
Our website and digital services may use cookies, pixels, tags and similar technologies to operate and secure services, remember preferences, understand usage, measure performance and support relevant content or advertising. These technologies may collect device identifiers, IP address, browser information, pages viewed, session activity and interaction data.
Third-party technology and advertising providers, which may include Google, Microsoft, Meta and LinkedIn, may collect or receive information through these technologies in accordance with their own privacy policies. Where consent is required, non-essential technologies will be used only after consent is obtained. You can use available cookie controls or your browser settings, although disabling some technologies may affect functionality.
Third-party technology and advertising providers, which may include Google, Microsoft, Meta and LinkedIn, may collect or receive information through these technologies in accordance with their own privacy policies. Where consent is required, non-essential technologies will be used only after consent is obtained. You can use available cookie controls or your browser settings, although disabling some technologies may affect functionality.
11. AutoDash and account security
When you use AutoDash, we may record login and authentication activity, profile and bank detail changes, reimbursement requests, declarations, consents and relevant audit logs. We use these records to provide the service, protect accounts, verify transactions, detect and prevent fraud, investigate incidents and resolve disputes. You are responsible for keeping your credentials secure and should tell us promptly if you suspect unauthorised access.
12. Artificial intelligence and automated systems
We may use artificial intelligence, machine learning and rules-based tools to support administrative triage, document classification and extraction, customer communications, workflow management, analytics, quality assurance and fraud or anomaly detection. These tools may use identity and contact details, application or document content, transaction or account activity, communications and technical data, depending on the task.
Inside Edge remains responsible for its use of these systems. Outputs are subject to controls appropriate to the risk and may be reviewed by trained personnel. We do not currently arrange for a computer program to make a decision, without appropriate human involvement, that could reasonably be expected to significantly affect an individual's rights or interests. If that practice changes, we will update this policy and provide the information required by law.
Inside Edge remains responsible for its use of these systems. Outputs are subject to controls appropriate to the risk and may be reviewed by trained personnel. We do not currently arrange for a computer program to make a decision, without appropriate human involvement, that could reasonably be expected to significantly affect an individual's rights or interests. If that practice changes, we will update this policy and provide the information required by law.
13. Data quality, security and retention
We take reasonable steps to keep personal information accurate, up to date, complete and relevant for its use or disclosure. Please tell us if your details change.
We use administrative, physical and technical safeguards designed to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure. These include role-based access, authentication controls, staff training and confidentiality obligations, system monitoring, supplier oversight, and incident response processes. No method of transmission or storage is completely secure.
We retain personal information for as long as reasonably necessary for the purpose for which it was collected and to satisfy legal, taxation, employment, contractual, dispute and record keeping requirements. Retention periods vary by record type. When information is no longer required and we are legally permitted to do so, we take reasonable steps to destroy it securely or de-identify it.
We use administrative, physical and technical safeguards designed to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure. These include role-based access, authentication controls, staff training and confidentiality obligations, system monitoring, supplier oversight, and incident response processes. No method of transmission or storage is completely secure.
We retain personal information for as long as reasonably necessary for the purpose for which it was collected and to satisfy legal, taxation, employment, contractual, dispute and record keeping requirements. Retention periods vary by record type. When information is no longer required and we are legally permitted to do so, we take reasonable steps to destroy it securely or de-identify it.
14. Data breaches
We maintain processes to identify, contain, assess and respond to suspected data breaches. Under the Notifiable Data Breaches scheme, if an eligible data breach occurs we will notify the Office of the Australian Information Commissioner (OAIC) and affected individuals as soon as practicable, in accordance with the Privacy Act. We may also notify other parties where required or where appropriate to reduce harm.
15. Access and correction
You may ask for access to personal information we hold about you or request its correction by contacting the Privacy Officer. You do not have to use a particular form, although we may ask for information needed to verify your identity and locate the records.
We will respond within a reasonable period and generally within 30 days. We do not charge for making a request or correcting information. We may charge a reasonable amount for providing access after telling you the likely cost. If an exception permits us to refuse access or correction, we will generally give written reasons and explain available complaint avenues. If we do not correct information, you may ask us to associate a statement with the record. Where required or appropriate, we will notify relevant third parties of a correction.
We will respond within a reasonable period and generally within 30 days. We do not charge for making a request or correcting information. We may charge a reasonable amount for providing access after telling you the likely cost. If an exception permits us to refuse access or correction, we will generally give written reasons and explain available complaint avenues. If we do not correct information, you may ask us to associate a statement with the record. Where required or appropriate, we will notify relevant third parties of a correction.
16. Anonymity and pseudonymity
Where lawful and practicable, you may deal with us anonymously or using a pseudonym, for example when making a general enquiry. We will need to identify you where this is required by law or where it is impracticable to provide the service without doing so, including when providing a quote, arranging or administering a novated lease, payment or account.
17. Privacy complaints
If you believe we have mishandled your personal information or breached the APPs, please contact the Privacy Officer using the details below. Please describe the issue and the outcome you are seeking. We will treat the complaint seriously and confidentially, acknowledge it promptly, investigate it fairly and aim to respond within 30 days. If we need more time, we will explain why and provide an updated timeframe.
We generally ask that you give us a reasonable opportunity to resolve the complaint first. If you are not satisfied with our response, you may escalate your complaint to the OAIC at www.oaic.gov.au or 1300 363 992. If the issue concerns a product or service provided by another organisation, including a financier or insurer, we will assist where appropriate by providing relevant information, documents and contact details. You may also have access to an applicable external dispute resolution scheme or the AFIA Code Compliance Committee, depending on the organisation and subject matter.
We generally ask that you give us a reasonable opportunity to resolve the complaint first. If you are not satisfied with our response, you may escalate your complaint to the OAIC at www.oaic.gov.au or 1300 363 992. If the issue concerns a product or service provided by another organisation, including a financier or insurer, we will assist where appropriate by providing relevant information, documents and contact details. You may also have access to an applicable external dispute resolution scheme or the AFIA Code Compliance Committee, depending on the organisation and subject matter.
18. Contact us
Privacy Officer: Inside Edge Novated Leasing Pty Ltd
Email: privacyofficer@iedge.com.au
Telephone: 1300 551 987
Postal Address: PO Box 6806, Melbourne, VIC 3004
You may request a copy of this policy in an alternative form. We will take reasonable steps to provide it in the requested form, free of charge, as soon as reasonably practicable.
Email: privacyofficer@iedge.com.au
Telephone: 1300 551 987
Postal Address: PO Box 6806, Melbourne, VIC 3004
You may request a copy of this policy in an alternative form. We will take reasonable steps to provide it in the requested form, free of charge, as soon as reasonably practicable.
19. Changes to this policy
We review this policy periodically and may update it when our practices, services or legal obligations change. The current version and effective date will be published on our website. Material changes may also be communicated through other appropriate channels.
Effective date: 13 August 2026 / Version 1.1