Privacy Policy

Northmore Gordon Pty Ltd, Northmore Gordon Environmental Pty Ltd and their related entities, collectively referred to as Northmore Gordon, NG, we, us or our, respect your privacy and are committed to protecting the personal information we collect and hold.

This Privacy Policy explains how we collect, hold, use and disclose personal information, how you can access or correct your information, and how you can raise a privacy concern or complaint.

We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), where they apply to us, as well as other applicable privacy, communications and regulatory requirements.

  1. What is personal information?

Personal information is information or an opinion about an identified individual, or an individual who is reasonably identifiable.

Depending on how you interact with Northmore Gordon, the personal information we collect may include:

  • your name;

  • business or organisation name;

  • job title or position;

  • email address;

  • telephone number;

  • postal or business address;

  • information you provide through website forms;

  • information you provide when making an enquiry or requesting a proposal;

  • correspondence and records of communications with us;

  • information relating to services we provide to you or your organisation;

  • billing, payment and transaction information;

  • information required to administer environmental certificate, energy efficiency, renewable energy, carbon or other government or industry schemes;

  • project, site, equipment, installation or property information where that information relates to an identifiable individual;

  • information collected when you attend an event, webinar, presentation or other activity;

  • marketing and communication preferences;

  • information about how you interact with our emails and other communications; and

  • technical and website usage information, such as your IP address, browser and device information, referral source, pages viewed, dates and times of visits and other online identifiers.

We may also collect other information where it is reasonably necessary for our business activities or required by a law, government program, certificate scheme or regulatory requirement.

  1. Sensitive information

In most circumstances, Northmore Gordon does not need to collect sensitive information.

If we need to collect sensitive information, we will generally do so with your consent and where the information is reasonably necessary for our functions or activities, or otherwise where permitted or required by law.

  1. How we collect personal information

We generally collect personal information directly from you, including when you:

  • contact us by telephone, email or through our website;

  • complete an enquiry, registration, application or other form;

  • request information, a quotation, proposal or service;

  • engage us to provide advisory, consulting, certificate or other services;

  • subscribe to newsletters or other communications;

  • attend a webinar, seminar, event or meeting;

  • interact with our website or digital communications;

  • participate in a survey or provide feedback;

  • apply for employment with us; or

  • otherwise communicate or do business with Northmore Gordon.

We may also collect personal information from third parties where appropriate. These may include:

  • your employer, customer, contractor, consultant or business representative;

  • installers, equipment providers, project partners or other parties involved in a project;

  • government departments, regulators, scheme administrators and registry operators;

  • publicly available sources;

  • professional advisers;

  • business partners and service providers; and

  • other third parties where you have authorised the disclosure or where collection is otherwise permitted by law.

Where practical, we will collect personal information directly from you.

  1. Information collected through our website

When you visit a Northmore Gordon website, certain technical information may be collected automatically.

This may include:

  • your IP address;

  • browser type;

  • device information;

  • operating system;

  • referring website or source;

  • pages and content you view;

  • links you click;

  • dates and times of visits;

  • approximate geographic information derived from technical data; and

  • other information about your interaction with our website.

We use this information to operate, protect and improve our website, understand how visitors use our website, measure the effectiveness of our communications and marketing, and improve our services.

  1. Cookies and similar technologies

Our website uses cookies and similar technologies.

Cookies are small data files placed on or associated with your device when you visit a website. They may be used to make websites function correctly, remember preferences, understand website usage and support analytics and marketing activities.

Depending on the technologies and settings in use, we may use:

  • essential cookies required for website operation;

  • preference or functionality cookies;

  • analytics cookies; and

  • marketing or tracking cookies.

You may be able to control non-essential cookies through the cookie preferences available on our website and through your browser settings.

Disabling certain cookies may affect the functionality of parts of our website.

  1. HubSpot

Northmore Gordon uses HubSpot as part of its customer relationship management, website, forms, marketing, analytics and communications activities.

When HubSpot technologies are enabled on our website, HubSpot may use cookies and similar technologies to collect information about visits and interactions with our website.

This information may include website activity, IP addresses, online identifiers and information about interactions with our forms and communications.

When you identify yourself to us, for example, by submitting a website form or interacting with certain tracked communications, information about your website activity may, depending on your cookie preferences and our system configuration, be associated with your contact record in our customer relationship management system.

We may use this information to:

  • respond to your enquiry;

  • understand your interests and requirements;

  • maintain our business relationship with you or your organisation;

  • provide relevant information about our services;

  • understand the effectiveness of our website and communications;

  • improve our services and customer experience;

  • manage events, webinars and registrations;

  • administer marketing preferences and subscriptions; and

  • maintain records of our interactions with you.

You can manage applicable cookie preferences through the consent tools made available on our website.

  1. Why we collect, hold, use and disclose personal information

We may collect, hold, use and disclose personal information for purposes including:

  • responding to enquiries;

  • providing our services;

  • preparing quotations, proposals and agreements;

  • managing customer, supplier, partner and stakeholder relationships;

  • delivering energy, carbon, sustainability and advisory services;

  • administering environmental certificate and related projects;

  • creating, registering, transferring, surrendering, purchasing, selling or otherwise administering certificates, credits or environmental instruments;

  • complying with government scheme, audit, verification and record-keeping requirements;

  • managing projects and service delivery;

  • processing transactions and payments;

  • managing our website and digital systems;

  • maintaining our CRM and business records;

  • conducting analytics and business reporting;

  • improving our products, services and customer experience;

  • communicating with customers and stakeholders;

  • administering webinars, events and other activities;

  • sending marketing and informational communications where permitted;

  • maintaining the security of our systems, premises and information;

  • preventing or investigating fraud, misuse or unlawful activity;

  • recruiting and managing employees and contractors;

  • complying with legal and regulatory obligations; and

  • establishing, exercising or defending legal rights.

We may also use or disclose your information for another purpose where you have consented, where you would reasonably expect us to do so and the purpose is related to the original purpose of collection, or where otherwise permitted or required by law.

  1. Environmental certificates and regulatory information

Northmore Gordon operates in regulated environmental, renewable energy, energy efficiency and carbon markets.

When we assist with the creation, registration, transfer, surrender, sale, purchase or administration of certificates, credits or other environmental instruments, we may be required to collect and retain information about customers, project participants, sites, equipment, installations, contractors and other relevant parties.

We may be required to provide some of this information to government agencies, regulators, scheme administrators, registry operators, auditors, inspectors or other authorised parties.

We retain records associated with these activities for periods required by the relevant legislation, program rules, scheme requirements, contractual obligations or other applicable record-keeping requirements.

  1. Direct marketing

Where permitted by law, we may use your personal information to communicate with you about:

  • Northmore Gordon services;

  • energy and carbon market developments;

  • environmental certificates;

  • regulatory or industry updates;

  • events and webinars;

  • reports, articles and educational content;

  • new services or capabilities; and

  • other information we believe may be relevant to you or your organisation.

We may send these communications by email, telephone or other electronic means.

You can opt out of receiving marketing communications at any time by:

  • using the unsubscribe facility included in an electronic marketing communication;

  • changing your available communication preferences; or

  • contacting us.

We will action opt-out requests in accordance with applicable law.

Opting out of marketing communications will not prevent us from sending communications that are necessary to provide services to you, administer a transaction or project, meet regulatory requirements, or otherwise manage our existing relationship with you.

  1. When we disclose personal information

We may disclose personal information to third parties where reasonably necessary for our business activities or where permitted or required by law.

These third parties may include:

  • government agencies and regulators;

  • environmental certificate and energy scheme administrators;

  • registry operators;

  • auditors and verification bodies;

  • contractors, installers and project partners;

  • technology and IT service providers;

  • website, hosting and cloud-service providers;

  • CRM and marketing technology providers, including HubSpot;

  • analytics providers;

  • payment and financial service providers;

  • professional advisers, including accountants, lawyers and insurers;

  • related companies;

  • potential purchasers or participants in a corporate transaction involving our business; and

  • other parties with your consent or where disclosure is authorised or required by law.

We do not sell personal information to third parties as a standalone commercial product.

  1. Overseas disclosure and processing

Some of the service providers and technology platforms used by Northmore Gordon operate internationally.

As a result, personal information may be disclosed to, accessed by, stored by or processed by organisations located outside Australia.

For example, we use HubSpot for customer relationship management, website, marketing, forms, analytics and communications. HubSpot operates internationally and uses affiliates and service providers in Australia and overseas.

Depending on the particular services and systems being used, overseas recipients may be located in countries including the United States, Singapore, countries in the European Union, the United Kingdom, Canada and other jurisdictions in which our service providers, their affiliates or their sub-processors operate.

Northmore Gordon also operates internationally, including in Singapore, and information may be shared between our operations where reasonably necessary to provide services or manage our business.

Where required, we take reasonable steps in the circumstances to ensure that overseas disclosures of personal information are handled consistently with applicable Australian privacy requirements.

The locations used by cloud and technology providers may change from time to time. We periodically review our service-provider arrangements and this Privacy Policy.

  1. Storage and security

Northmore Gordon may hold personal information electronically and, in some circumstances, in physical records.

Electronic information may be stored in our own systems or in systems operated by service providers on our behalf.

We take reasonable steps to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure.

These measures may include, as appropriate:

  • access controls;

  • authentication and password controls;

  • restricted staff permissions;

  • security monitoring;

  • secure cloud services;

  • backups;

  • staff policies and training;

  • contractual protections with relevant service providers; and

  • physical security measures.

No method of transmitting or storing information is completely secure, and we cannot guarantee the security of information transmitted over the internet.

  1. Data breaches

Northmore Gordon maintains procedures for responding to suspected or actual data breaches.

If a data breach occurs, we will assess and respond to the incident in accordance with applicable law, including the Notifiable Data Breaches scheme under the Privacy Act where it applies.

Where we are required to notify affected individuals and the Office of the Australian Information Commissioner, we will do so in accordance with our legal obligations.

  1. How long we keep personal information

We retain personal information for as long as reasonably necessary for the purposes for which it was collected and to meet our legal, regulatory, contractual, taxation, insurance, audit and record-keeping obligations.

Some environmental certificate and government scheme records must be retained for minimum periods specified by the relevant scheme or legislation.

When we no longer require personal information and are not required by law to retain it, we will take reasonable steps to destroy it securely or de-identify it.

Information may remain in secure backups for a period after deletion from active systems.

  1. Quality of personal information

We take reasonable steps to ensure that the personal information we collect, use and disclose is accurate, up to date, complete and relevant for the purposes for which it is being used.

You can help us by letting us know when your contact details or other information change.

  1. Accessing your personal information

You may request access to personal information that we hold about you.

To make a request, contact us using the details below.

We may need to verify your identity before giving you access.

In some circumstances, the Privacy Act permits or requires us to refuse access to some or all of the requested information. If we refuse a request where the law requires us to provide reasons, we will explain the reason for the refusal and the available complaint mechanisms.

We will not charge you for making an access request. We may, where permitted, charge reasonable costs associated with providing access.

  1. Correcting your personal information

If you believe personal information we hold about you is inaccurate, out of date, incomplete, irrelevant or misleading, you may ask us to correct it.

We will take reasonable steps to correct information where required under applicable privacy law.

If appropriate, you can also contact your usual Northmore Gordon representative to update ordinary contact or business information.

  1. Anonymity and pseudonyms

Where it is lawful and practical, you may interact with Northmore Gordon anonymously or using a pseudonym.

In many circumstances, however, we will need to know your identity or contact details in order to provide services, respond to an enquiry, enter into a business relationship, process a transaction or comply with legal or scheme requirements.

  1. Third-party websites

Our website may contain links to websites operated by third parties.

Northmore Gordon is not responsible for the privacy practices or content of third-party websites. We recommend reviewing the privacy policy of any third-party website before providing personal information.

  1. Privacy complaints and enquiries

If you have a question about this Privacy Policy, wish to access or correct your personal information, or believe that Northmore Gordon has not handled your personal information appropriately, please contact us.

Please provide sufficient information for us to understand and investigate your request or complaint.

We will endeavour to acknowledge and investigate privacy complaints promptly and respond within a reasonable period.

If you are not satisfied with our response to a privacy complaint, you may be entitled to lodge a complaint with the Office of the Australian Information Commissioner (OAIC).

Information about how to contact the OAIC is available at www.oaic.gov.au.

  1. Contact us

Northmore Gordon

Suite 1, Level 4
607 Bourke Street
Melbourne VIC 3000
Australia

Advisory: 1300 854 561
Certificates: 1300 878 500

Email: info@northmoregordon.com

You may also contact us through the contact form on the Northmore Gordon website.

  1. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes to our business, systems, service providers, technologies or legal obligations.

The current version will be published on our website together with its effective date.

We recommend reviewing this Privacy Policy periodically for changes.

Last Updated: 08/17/26