Acceptable Use and Privacy Policy
v3.0
Purpose. This policy sets the rules for using Nova and client systems and describes how personal information is collected, used and protected.
1.Purpose and scope
This policy applies to every person who uses a Nova device, account, network or client system. It supports the Information Security Policy and the obligations of the business under the Privacy Act 1988, the Australian Privacy Principles and the Spam Act 2003.
2.Acceptable use
Nova systems and client access must be used for authorised work. Personal use of Nova devices is permitted where it is brief, lawful and does not introduce risk. Staff must not install unapproved software, disable security tools, share accounts or connect unapproved storage devices.
- Work accounts and devices for work purposes
- No shared or generic accounts
- No unapproved software or browser extensions
- Lock the screen when away from the device
- Report lost or stolen devices within one hour
3.Handling personal information
Staff will see personal information in client mailboxes, files and databases while doing support work. That information must be viewed only as far as the task requires, must not be copied, discussed or disclosed, and must not be used for any purpose other than the ticket or project it relates to. Health, financial and student information attracts extra care and must never leave the client environment.
4.Intellectual property and ethics
Code, documentation and designs produced for clients belong to the client under their contract unless the contract says otherwise. Staff must respect software licences, must not use unlicensed tools and must not copy client code or data between clients. Conflicts of interest must be declared to the Business Services Manager.
5.Monitoring
Nova monitors its systems, endpoints and privileged access sessions for security purposes. Staff are informed of this monitoring at induction. Monitoring data will be used only for security, compliance and incident investigation.
6.Privacy enquiries and breaches
Requests from individuals about their personal information will be referred to the Business Services Manager. A suspected privacy breach must be reported immediately and will be assessed within 72 hours to decide whether notification is required.
7.Review
This policy will be reviewed annually and every staff member will re-acknowledge it each year.