HOME > DATA PROTECTION
Information Security & Data Protection
Last updated: 21 July, 2026
We hold personal information about the parents, guardians, students and schools who use our uniform ordering services, and protecting it is a core part of how we operate. This page sets out the specific measures we maintain, not just the steps we might take.
Where your information is held
We run two separate ordering channels, and it helps to be clear about each:
-
Wholesale-supplied schools and P&C associations place orders through our partner portal, which runs on Salesforce (independent certifications: ISO/IEC 27001, SOC 2, IRAP and PCI DSS; encryption in transit at TLS 1.2 orabove and at rest at AES-256). Orders through the portal are invoiced on account, so no card payments are taken in the portal.
-
Outsourced-school online stores, where parents buy uniforms directly, run on WordPress with WooCommerce.Connections are secured with SSL/HTTPS encryption; each parent orders through their own password-protected account; and the stores are hardened against abuse with website security, anti-spam and reCAPTCHA (bot-protection) controls.
-
Card payments on the online stores are processed by Square, a PCI DSS compliant payment provider. Card details are not stored on our systems.
-
Our email, documents and staff accounts run on Microsoft 365 (ISO/IEC 27001, SOC 2), and our public information website is hosted on Wix.
-
Where our providers offer Australian data hosting, we use it.
How we control who can see it
-
Every staff member has their own individual login. We do not use shared accounts.
-
Multi-factor authentication (MFA) is enforced on all staff and administrator accounts.
-
Access is granted on a least-privilege basis (people can see only what their role requires), is reviewed at least annually, and is removed the same day a person leaves.
-
Passwords must be at least 14 characters with complexity requirements.
-
Staff who can access personal information are subject to employment screening and complete privacy and security awareness training at induction and at least once a year.
-
Customers ordering through our online stores have their own password-protected account and can see only their own account details and order history.
How we protect it
-
Information is encrypted in transit whenever it moves between you and our systems: SSL/HTTPS on our online stores, and TLS 1.2 or above on our Salesforce portal.
-
Payment card data is handled entirely by Square and is never stored on our own systems.
-
Our enterprise platforms (Salesforce, Microsoft 365, Square) are patched, monitored and security-tested by their providers, including vulnerability scanning and penetration testing of their infrastructure.
-
Our own websites and online stores are kept current with security updates and protected with the website security, anti-spam and bot-protection controls described above.
If something goes wrong
-
We maintain a documented Data Breach and Incident Response Plan, and all staff are required to report a suspected incident immediately.
-
If a data breach affects a school's or family's information, we will notify the affected school without undue delay, and within 72 hours of becoming aware of it, and we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) as required under the Notifiable Data Breaches scheme.
How long we keep it
-
Order and transaction records are kept for up to 7 years for financial record-keeping. Other records are kept only foras long as they are needed, then securely deleted or de-identified.
Your rights and how to reach us
-
You can ask us what personal information we hold about you, ask us to correct it, or raise a privacy concern at anytime. Contact our Privacy Officer at info@pcuniforms.com.au or 1800 811 202.
-
This statement sits alongside our Privacy Policy (www.pcuniforms.com.au/privacy-policy), which sets out in full what we collect and why. We handle personal information in line with the Australian Privacy Principles.