Resolute ("we," "our," or "us") is a global business process outsourcing and consulting firm headquartered in Melbourne, Australia. We are committed to protecting the privacy and security of personal information entrusted to us by our clients, their customers, and visitors to our website. This Privacy Policy outlines how we collect, use, store, and protect data in the course of delivering our BPO services, contact center operations, back-office processing, and consulting engagements.
As a trusted outsourcing partner serving clients across multiple industries and jurisdictions, we understand that data protection is fundamental to our business relationships. We have implemented comprehensive data governance frameworks aligned with international standards including the GDPR, CCPA, and ISO 27001 to ensure your information is handled with the highest level of care and compliance.
By using our website or engaging our services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with the practices described herein, please refrain from using our services or providing personal data through our platforms.
We collect personal information that you voluntarily provide when contacting us, requesting a quote, registering for our services, or interacting with our website. This may include your full name, email address, phone number, company name, job title, mailing address, and any other details you choose to share in correspondence or through our online forms.
In the course of delivering BPO and consulting services, we may process business data on behalf of our clients. This can include customer records, transaction data, financial information, employee details, supply chain data, and operational metrics. The specific types of data processed depend on the scope of the engagement and the services being provided. All such data is processed under the terms of our Data Processing Agreements and in accordance with applicable data protection regulations.
When you visit our website, we automatically collect certain technical information including your IP address, browser type and version, operating system, device information, referring URLs, pages visited, time spent on pages, and other diagnostic data. This information is collected through cookies, log files, and similar tracking technologies to help us understand how visitors interact with our website and to improve the user experience.
We use the information we collect for the following purposes, all of which are grounded in legitimate business interests, contractual necessity, or your explicit consent where required by applicable law:
Your information is used to deliver the BPO and consulting services you have engaged us to provide. This includes processing transactions, managing client accounts, operating contact centers on behalf of clients, performing back-office functions such as data entry and document management, and executing any other services outlined in our service agreements. We process client data strictly in accordance with the instructions provided in our Data Processing Agreements.
We use your contact information to respond to inquiries, send service-related notifications, provide updates about our offerings, and maintain ongoing communication regarding your account. This may include sending proposals, service reports, invoices, and important notices about changes to our services or policies.
We analyze usage data and service performance metrics to identify trends, optimize our operations, enhance the quality of our services, and develop new solutions. Aggregated and anonymized data may be used for benchmarking, research, and strategic planning purposes. We ensure that any such analysis does not identify individuals or expose confidential client information.
We process information as necessary to comply with legal obligations, including tax and accounting requirements, anti-money laundering regulations, data protection laws, and industry-specific compliance mandates. We may also use data to enforce our terms of service, protect our legal rights, and respond to lawful requests from public authorities.
We do not sell, rent, or trade your personal information to third parties. We share data only in the following limited circumstances and always with appropriate safeguards in place:
We engage trusted third-party service providers to support our operations, including cloud hosting providers, IT support vendors, payment processors, and communication platforms. These providers are contractually obligated to protect your data, use it only for the purposes we specify, and comply with applicable data protection standards. We conduct due diligence assessments before engaging any subprocessor and maintain an updated list of all subprocessors involved in service delivery.
We may disclose information when required by law, regulation, legal process, or governmental request. This includes responding to subpoenas, court orders, and regulatory inquiries. We will notify you of such disclosure unless legally prohibited from doing so, and we will limit disclosure to the minimum information required.
In the event of a merger, acquisition, sale of assets, or business reorganization, your information may be transferred to the acquiring entity or successor organization. We will notify you of any such change in ownership and ensure that the receiving party honors the commitments made in this Privacy Policy. You will retain all rights regarding your data following any such transfer.
We employ a comprehensive, multi-layered approach to data security designed to protect your information from unauthorized access, alteration, disclosure, or destruction. Our security program is aligned with ISO 27001 standards and is regularly audited by independent third parties.
All data transmitted between your browser and our systems is encrypted using TLS 1.3 protocol. Data at rest is encrypted using AES-256 encryption across all storage systems. Sensitive personal information, including financial data and authentication credentials, is subject to additional encryption layers and is never stored in plaintext. We maintain robust key management practices and regularly rotate encryption keys.
Access to personal data is restricted on a need-to-know basis and is governed by role-based access controls, multi-factor authentication, and strict identity verification procedures. All access to client data is logged and monitored in real time. Our Security Operations Center operates 24/7 to detect and respond to potential threats. We conduct regular penetration testing, vulnerability assessments, and security audits to identify and remediate potential weaknesses.
We retain personal information only for as long as necessary to fulfill the purposes for which it was collected, including any legal, accounting, or reporting requirements. The retention period varies depending on the type of data and the nature of our relationship with you.
Website visitor data and inquiry information is typically retained for 24 months from the date of last interaction. Client engagement data is retained for the duration of the service agreement plus seven years to satisfy legal and regulatory retention requirements. Financial records and transaction data are retained for a minimum of seven years in accordance with tax and accounting regulations.
Upon expiration of the applicable retention period, data is securely deleted or anonymized using industry-standard data destruction methods. When client engagements conclude, we follow a structured data return and destruction process as defined in our Data Processing Agreements, providing certification of destruction upon request.
Depending on your jurisdiction and the applicable data protection laws, you may have the following rights regarding your personal information:
To exercise any of these rights, please contact our Data Protection Officer at [email protected]. We will respond to verified requests within 30 days. In some cases, we may need to verify your identity before processing your request. If we are unable to fulfill your request, we will explain the reasons and provide information about any available appeal processes.
Our website uses cookies and similar tracking technologies to enhance your browsing experience, analyze website traffic, and support our marketing efforts. Cookies are small text files stored on your device that allow our website to recognize you and remember certain information.
You can manage your cookie preferences through our cookie consent banner, which is displayed when you first visit our website. You may also configure your browser settings to accept, reject, or delete cookies. Please note that disabling certain cookies may affect the functionality of our website. For more information about how to manage cookies in your specific browser, please refer to your browser's help documentation.
As a global BPO provider with operations and delivery centers in multiple countries, we may transfer personal data across international borders. These transfers are necessary for the efficient delivery of our services and are conducted in compliance with applicable data protection laws.
When transferring data from the European Economic Area (EEA) or United Kingdom to countries not deemed to provide an adequate level of data protection, we rely on approved transfer mechanisms such as Standard Contractual Clauses (SCCs), Binding Corporate Rules, or explicit consent. We conduct Transfer Impact Assessments for all international data flows and implement supplementary measures where necessary to ensure an equivalent level of protection.
All international transfers are governed by our internal data transfer policies and are subject to regular review. We maintain detailed records of all cross-border data flows and ensure that recipients of transferred data are bound by appropriate contractual obligations to protect the data in accordance with this Privacy Policy and applicable law.
Our website and services are not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If you are a parent or guardian and believe that your child has provided personal data to us, please contact us immediately at [email protected]. If we become aware that we have collected personal data from a child without verified parental consent, we will take immediate steps to delete that information and terminate any associated accounts.
In the context of our BPO services, we may process data that includes information about minors where such processing is directed by our clients and is permitted under applicable law. In these cases, we process such data strictly in accordance with our clients' instructions and the terms of our Data Processing Agreements, and we implement additional safeguards appropriate for the processing of children's data.
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or business operations. When we make material changes to this policy, we will notify you by updating the "Last Updated" date at the top of this page and, where appropriate, by providing more prominent notice through our website or via direct communication.
We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your data. For significant changes that affect your rights or how we use your information, we will provide at least 30 days' notice before the changes take effect. Your continued use of our website and services after the effective date of any changes constitutes acceptance of the revised policy.
If you disagree with any changes to this Privacy Policy, you may discontinue use of our website and request deletion of your personal data by contacting us at [email protected].
If you have any questions, concerns, or requests regarding this Privacy Policy or our data processing practices, please do not hesitate to contact us. Our Data Protection Officer and privacy team are available to assist you.
We are committed to resolving any complaints or disputes regarding our handling of your personal data. If you are not satisfied with our response, you have the right to lodge a complaint with your local data protection supervisory authority.