Privacy policy
Updated 8 October 2026
Who we are
Daniele Rosito is a sole trader trading as Astrafifo Australia, ABN 16 377 646 505, Australia. Privacy contact: support@astrafifo.com, covering astrafifo.com and astrafifo.it. This policy covers both websites and our current FIFO placement service.
What we collect
We collect only what we need to assess your eligibility and place you in FIFO work. Identity and contact: name, email, phone or WhatsApp number, date of birth, nationality, current location. Work profile: CV, work history, licences and tickets, desired role and roster, availability, referees. Sensitive information: medical or fitness-to-work results, police check results, and identity documents (passport, visa or work-rights evidence, driver licence). We collect these only with your consent. Account access details: if you ask us to act for you, your written authorisation and the login details of the job and email accounts we set up or use for your applications. Communications: emails, texts, WhatsApp messages and call notes with our team. Website data: pages visited, device and browser type, and, with your consent, analytics and advertising identifiers. We collect this from you directly (forms, calls, messages, uploads), from the booking and e-signing tools you use with us, from clinics and check providers you authorise, and from job platforms and employers during an application. The initial website enquiry asks for first and last name, email, WhatsApp number and your current situation in relation to Australia. Do not send passwords or sensitive documents through that enquiry form. The form uses Google Apps Script, then opens an external Typeform questionnaire; eligibility links also open Typeform directly.
Why we use it
Assess your eligibility for FIFO roles, including an automated eligibility score that a team member reviews before any decision is made. Match you with employers and roles, prepare your CV, and submit applications on your behalf. Arrange tickets, medicals and police checks you ask for. Contact you by email, phone, text and WhatsApp about your application and next steps. Prepare and sign contracts, take payment, and keep financial and tax records. Improve our service, measure our marketing, and meet legal obligations. We rely on your consent for sensitive information and for non-essential cookies, on performing our contract with you for placement services, and on our legitimate interests for service improvement and fraud prevention. We do not sell your personal information. We handle an initial enquiry to take precontractual steps at your request. Necessary technical connection data supports site operation and security. Sending an enquiry does not constitute consent to marketing or optional measurement.
Who we share it with
We share information only as needed to deliver the service: Employers, recruiters and job platforms you apply to through us. Clinics, check providers and training providers you ask us to book. Service providers that run our systems: CRM and email, scheduling, e-signature, forms, payments, cloud storage, automation and analytics tools. Our virtual assistants and contractors, who are bound by confidentiality and access only what their work requires. Authorities and advisers where the law requires, or to protect our legal rights. We do not give your information to anyone for their own marketing.
Overseas disclosure
We store personal information with providers in Australia and Europe. Some team members and contractors work outside Australia, including in the Philippines, and can access it remotely to do their work. Before disclosing information overseas we take reasonable steps to make sure the recipient handles it consistently with the Australian Privacy Principles, as required by APP 8, for example through contracts and access controls. We do not rely on your consent alone for these transfers.
Cookies and analytics
The site stores your privacy choice in your browser for up to 180 days. Google Tag Manager routes optional Google Analytics 4 measurement to separate properties for Italy and International. Analytics starts only after consent. You can accept, reject or change your choice through Privacy preferences on the homepage; rejection does not prevent browsing or using the service. Analytics cookies may last up to two years, depending on configuration and browser. GA4 event/user retention is configured for two months with activity renewal, separately from enquiry and service retention. Names, emails, phone numbers and form contents are not sent in Analytics event parameters. Advertising and conversion tags in the new website configuration remain paused; their activation will require a verified lead conversion and consent. Optional advertising identifiers will only be used with consent when enabled.
Retention and security
We keep personal information only as long as needed for the purposes above and our legal obligations: up to 7 years for contracts, payments and tax records, and up to 2 years after your last contact for other client and lead records. Sensitive documents such as medical results and identity documents are deleted or de-identified once the application they support is complete, unless the law requires otherwise. We protect information with access controls, strong passwords and multi-factor authentication where available, encrypted connections, and limiting access to people who need it. Account login details are used only for the applications you request. When the engagement ends, we hand the accounts over to you and delete our copy of the login details. No system is perfectly secure; we will notify you and the OAIC of an eligible data breach as the law requires.
Your rights and complaints
You can ask to access or correct the personal information we hold about you, or ask us to delete it, by emailing support@astrafifo.com. We respond within 30 days and may need to verify your identity. You can also withdraw consent or opt out of marketing at any time. If you are unhappy with how we handled your information, contact us first. If we do not resolve it, you can complain to the Office of the Australian Information Commissioner (oaic.gov.au, 1300 363 992).
EEA and Italian residents (GDPR)
For processing subject to the GDPR, including our offering of services to people in the European Economic Area and Italy, the following additional rights and safeguards apply. Our legal bases are consent (including explicit consent for health data), contract, and legitimate interests. You have the right to access, rectify, erase, restrict or object to processing, to data portability, and to withdraw consent. Our eligibility score supports, but does not replace, human review: you can ask for a person to review any decision and to contest it. Where we transfer personal data outside the EEA, we do so only with appropriate safeguards, such as the European Commission's standard contractual clauses, or on another basis the GDPR allows. You may complain to your local authority, in Italy the Garante per la protezione dei dati personali (garanteprivacy.it).
Changes and contact
We may update this policy and will post the new version on this page with a new date. For any privacy question, email support@astrafifo.com.