- 1. About this policy
- it will then apply through your acceptance of it by subsequent or continued use of the Platform and/or our Services.
- Primary and Secondary Purposes. We collect personal information from you and, subject to clause 3.3, you consent to us using your personal information (other than sensitive information) for the following Primary and Secondary Purposes:
|Purpose/Activity||Type of personal information||Basis for use|
To deliver our Services to you including but not limited to:
To provide you with information about Services you requested
To personalise and customise your experiences with us
To help us meet our warranty obligations
To help us assess an application submitted by you or on your behalf in relation to your employment with CASPA
To process donations
To communicate with you, including by email, mobile and in-application notifications
To investigate any complaints about or made by you, or if we have reason to suspect you have breached any relevant terms
To do anything else as required or permitted by any law
3. What we collect
- personal information . Personal information we collect about you may include identification information such as your name, address, email address, phone number(s), financial and payment information and such other information necessary or convenient for delivering our Services. We also may collect additional information as part of our collection of Identity, Contact, Financial, Transaction, Technical, Marketing and Communications, Client and Profile information used for the Primary and Secondary Purposes.
- Other information. We may collect, and you consent to us collecting, information relating to you that is not personal information, such as data relating to your activity on our Platforms, including:
- the Internet Protocol address or MAC address and a component of the domain name used (e.g., .com or .net);
- the type of browser and operating system you used;
- the date and time you visited our Platforms;
- the web pages or services you accessed at our Website;
- the time spent on individual pages and our Website overall;
- which files you downloaded;
- information about your computer and Internet connections using cookies;
4. How we collect
- How we collect. Your personal information may be collected:.
- when you complete an application, consent, purchase, account sign-up or similar form via our Platforms or otherwise;
- when you contact us to submit a query or request;
- when you post information or otherwise interact with the Platforms;
- when you participate in one of our surveys;
- from those who request our Services on your behalf;
- from publicly available sources of information;
- from government regulators, law enforcement agencies and other government entities;
- from business contacts, external service providers and suppliers; or
- by other means reasonably necessary.
- has authorised you to provide their personal information to us; and
- consents to us using their personal information in order for us to provide our Services.
- Anonymity. If you would like to access any of our Services on an anonymous or pseudonymous basis we will take reasonable steps to comply with your request, however:
- you may be precluded from taking advantage of some or all of our Services; and
- we will require you to identify yourself if: a) we are required by law to deal with individuals who have identified themselves; or b) it is impracticable for us to deal with you if you do not identify yourself.
- Destruction. We will destroy or de-identify your personal information if:
- the purpose for which we collected the personal information from you no longer exists or applies; or
- you request us to destroy your personal information, and we are not required by law to retain your personal information.
- Cookies. We may use ‘cookie’ technology to assist us to determine in the aggregate the total number of visitors to the Platforms on an ongoing basis and the types of internet browsers and operating systems used by users of the Platforms. This information is used to enhance the usability and functionality of our Platforms and for marketing, advertising and analytic purposes.
- Social Media Tools. We use Facebook and LinkedIn and may from time to time use other social media tools.
- Primary use. We will only use and disclose your personal information:
- for purposes which are related to the Primary and Secondary Purposes; or
- Reasonable uses. We will not use your personal information for any purpose for which you would not reasonably expect us to use your personal information.
- Third parties. We will not sell, trade, rent or licence your personal information to third parties.
- Direct marketing. We will offer you a choice as to whether you want to receive direct marketing communications about services. If you choose not to receive these communications, we will not use your personal information for this purpose.
- We will otherwise only use or disclose your personal information for the purposes of direct marketing if:
- we collected the information from you;
- it is reasonable in the circumstances to expect that we would use or disclose the information for direct marketing purposes;
- we provide you with a simple means to ‘opt-out’ of direct marketing communications from us; and
- you have not elected to ‘opt-out’ from receiving such direct marketing communications from us.
- Opt-out. You may opt out of receiving such communications by:
- checking the relevant box on the form used to collect your personal information;
- clicking a link on the email communication sent to you; or
- contacting us using our contact details set out at clause 11.
- How we disclose. We may disclose personal information and you consent to us disclosing such personal information to:
- Third Party Service Providers who perform functions or provide Services on our behalf;
- relevant regulatory bodies in the industry in which we or you operate;
- our professional advisors, including our accountants, auditors and lawyers;
- our Related Bodies Corporate;
- persons authorised by you to receive information held by us;
- a government authority, law enforcement agency, pursuant to a court order or as otherwise required by law; or
- a party to a transaction involving the sale of our business or its assets.
- Overseas disclosure. We may in some circumstances send your personal information to overseas recipients, including but not limited to recipients in the United States, to enable us to provide our Services to you.
- Overseas recipients. Overseas recipients that may handle or process your data include (but are not limited to) the server hosts of our email services, cloud storage services and the Platforms.
- Reasonable protections. If we send your personal information to overseas recipients, we will take reasonable measures to protect your personal information from misuse, interference, loss, unauthorised access or modification. However, you acknowledge and agree that if we disclose your personal information to overseas recipients, we are not obliged to take reasonable steps to ensure overseas recipients of your personal information comply with the Privacy Act and the APPs.
7. Access & Correction
- Access. If you require access to your personal information, please contact us using our contact details set out at clause 11. You may be required to put your request in writing and provide proof of identity.
- Exceptions. We are not obliged to allow access to your personal information if:
- it would pose a serious threat to the life, health or safety of any individual or to the public;
- it would have an unreasonable impact on the privacy of other individuals;
- the request for access is frivolous or vexatious;
- it relates to existing or anticipated legal proceedings between you and us and would not ordinarily be accessible by the discovery process in such proceedings;
- it would reveal our intentions in relation to negotiations with you in a way that would prejudice those negotiations;
- it would be unlawful;
- denying access is required or authorised by or under an Australian law or a court/tribunal order;
- we have reason to suspect that unlawful activity, or misconduct of a serious nature relating to our functions or activities has been, is being or may be engaged in and giving access would be likely to prejudice the taking of appropriate action in relation to the matter;
- it would likely prejudice one or more enforcement related activities conducted by, or on behalf of, an enforcement body;
- it would reveal commercially sensitive information; or
- a relevant law provides that we are not obliged to allow access to your personal information (e.g. the European General Data Protection Regulation).
- Response to access request. If you make a request for access to ,em>personal information, we will:
- respond to your request within a reasonable period after the request is made; and
- if reasonable and practicable, give access to the personal information as requested.
- Refusal of access. If we refuse to give access to the personal information, we will give you a written notice that sets out at a minimum:
- our reasons for the refusal (to the extent it is reasonable to do so); and
- he mechanisms available to complain about the refusal.
- Correction. We request that you keep your personal information as current as possible. If you feel that information about you is not accurate or your details have or are about to change, you can contact us using our contact details set out at clause 11 and we will correct or update your personal information.
- Response to correction request. If you otherwise make a request for us to correct your personal information, we will:
- respond to your request within a reasonable period after the request is made; and
- if reasonable and practicable, correct the information as requested.
- Refusal to correct. If we refuse a request to correct personal information, we will:
- give you a written notice setting out the reasons for the refusal and how you may make a complaint; and
- take reasonable steps to include a note with your personal information of the fact that we refused to correct it.
8. Security & Protection
- Reasonable protections. In relation to all personal information, we will take all reasonable steps to
- ensure that the personal information we collect is accurate, up to date and complete;
- ensure that the personal information we hold, use or disclose is, with regard to the relevant purpose, accurate, up to date, complete and relevant; and
- protect personal information from misuse, loss or unauthorised access and disclosure.
- Security. We store your personal information on a secure server behind a firewall and use security software to protect your personal information from unauthorized access, destruction, use, modification or disclosure. Only Authorised Personnel may access your personal information for the purposes of disclosure set out in clause 6 above.
- Obligation to notify. Please contact us immediately if you become aware of or suspect any misuse or loss of your personal information.
9. Data Breaches
- Compliance. We are required to comply with the Notifiable Data Breaches scheme under Part IIIC of the Privacy Act.
- Investigation and assessment. If we become aware that a Data Breach in respect of personal information held by us may have occurred, we will:
- investigate the circumstances surrounding the potential Data Breach to determine whether a Data Breach has occurred; and
- if a Data Breach has occurred, carry out a reasonable and expeditious assessment of whether there are reasonable grounds to believe that the relevant circumstances amount to an eligible data breach.
- Undertaking. If we become aware that there has been an eligible data breach in respect of personal information held by us, and the personal information relates to you or you are at risk from the eligible data breach, we will ensure that either we, or a relevant APP entity that is the subject of the same eligible data breach:
- prepare a statement that complies with subsection 26WK(3) of the Privacy Act;
- provide a copy of the statement to the Office of the Australian Information Commissioner (OAIC); and
- if it is practicable, notify you of the contents of the statement, or otherwise publish a copy of the statement on the Website and take reasonable steps to publicise the contents of the statement, as soon as practicable after the completion of the preparation of the statement.
- Complaint. If you have a complaint about how we collect, use, disclose, manage or protect your personal information, or consider that we have breached the Privacy Act or APPs, please contact us using our contact details below. We will respond to your complaint within 14 days of receiving the complaint.
- Response and resolution. Once the complaint has been received, we may resolve the matter in a number of ways:
- Request for further information: We may request further information from you. Please provide us with as much information as possible, including details of any relevant dates and documentation. This will enable us to investigate the complaint and determine an appropriate solution.
- Discuss options: We will discuss options for resolution with you and if you have suggestions about how the matter might be resolved you should raise these with our Privacy Officer.
- Investigation: Where necessary, the complaint will be investigated. We will try to do so within a reasonable time frame. It may be necessary to contact others in order to proceed with the investigation. This may be necessary in order to progress your complaint.
- Conduct of our employees: If your complaint involves the conduct of our employees we will raise the matter with the employees concerned and seek their comment and input in the resolution of the complaint.
- Notice of decision. After investigating the complaint, we will give you a written notice about our decision.
- OAIC. You are free to lodge a complaint directly with the OAIC online, by mail, fax or email. For more information please visit the OAIC website at oaic.gov.au.
17 Keen Street Lismore
Phone: 02 6627 3700
12. Interpretation & Definitions
- Personal pronouns: Except where the context otherwise provides or requires:
- the terms we, us or our refers to CASPA; and:
- the terms you or your refers to a user of the Platform and/or a customer to whom we provide the Services.
- Terms italicised and defined in the Privacy Act have the meaning given to them in the Privacy Act.