WEBSITE AND APPLICATION PRIVACY POLICY

This Privacy Policy applies to all Personal Information collected by Equiptek Pty Ltd (Equiptek, we, us or our) via:

Key Definitions

Throughout this Privacy Policy:

The relationship between these parties is:

1. What Information Do We Collect?

The kind of Personal Information that we collect from you will depend on how you use our services. The Personal Information which we collect and hold may include but is not limited to:

1.1 For all Application Users and Business Partner Administration Users:

1.2 For Application Users:

1.2.1 Device Location Services

1.3 For Business Partner Administration Users:

1.4 Through Integrations:

2. Types of Information

2.1 Personal Information

The Privacy Act 1998 (Cth) (Privacy Act) defines Personal Information as information or an opinion about an identified individual or an individual who is reasonably identifiable: (i) whether the information or opinion is true or not; and (ii) whether the information or opinion is recorded in a material form or not.

If the information does not disclose your identity or enable your identity to be ascertained, it will in most cases not be classified as "Personal Information" and will not be subject to this Privacy Policy.

2.2 Sensitive Information

Sensitive Information is defined in the Privacy Act as including information or opinion about such things as an individual's racial or ethnic origin, political opinions, membership of a political association, religious or philosophical beliefs, membership of a trade union or other professional body, criminal record or health information.

Sensitive Information will be used by us only: (a) for the primary purpose for which it was obtained; (b) for a secondary purpose that is directly related to the primary purpose; and (c) with your consent or where required or authorised by law.

3. How We Collect Your Personal Information

3.1 Direct Collection

We collect Personal Information from you when you:

3.2 Indirect Collection

We may collect information:

3.3 Cookies and Analytics

We collect cookies from your devices to enable our services. These cookies help us to:

We use different types of cookies, including:

Cookies are retained for up to seven days and can be managed through your browser settings. Third-party cookies are subject to their respective privacy policies, which we encourage you to review.

4. Purpose of Collection

4.1 Primary Purposes

We collect Personal Information to:

4.2 Data Sharing

We share Personal Information:

4.3 Marketing

By using our services, you consent to receive direct marketing material. We will only use your Personal Information for this purpose if:

Our marketing communications include simple opt-out mechanisms.

5. Security, Access and Correction

5.1 Data Security

We implement comprehensive and modern security practices aligned with industry standards to protect your information. Our security approach includes:

5.1.1 System Security

5.1.2 Access Security

5.1.3 Operational Security

We regularly review and update our security practices to maintain alignment with evolving industry standards and best practices.

5.2 Data Retention

We retain different types of data for the following periods:

5.2.1 Active Data

5.2.2 Archived Data

5.2.3 Anonymised Data

Following Business Partner closure or termination, Application User deactivation or deletion, Business Partner Administration User deactivation or deletion, or equipment relationship end, we may at our discretion:

5.2.4 Data Deletion

5.3 Access and Correction

Under Australian Privacy Principles:

Contact us via legal@equiptek.com.au for access requests.

6. Data Use & Analytics

6.1 Aggregated Data Use

We collect and analyse aggregated and anonymised data to:

This data may come from:

The anonymisation process ensures that:

6.2 Partner Analytics

We may share anonymised and aggregated statistics with Business Partners, including:

6.3 Telemetry Data

Equipment telemetry data is:

7. Children's Privacy

7.1 Age Restrictions

8. Third-Party Services & Data Ownership

8.1 Integration Partners

We integrate with various third-party services including:

8.2 Data Handling and Processing

8.2.1 Data Processing

We process data in accordance with:

8.2.2 General Data

We handle Business Partner Data, Integration Partner Data, Application User Data, and Business Partner Administration User Data to:

8.2.3 Business Partner Data

We handle Business Partner Data to:

8.2.4 Platform Operations

As part of our operations, we:

8.3 Business Partner Data Access and Protection

In managing Business Partner access to our platform:

8.3.1 Access Controls

We implement controls to ensure:

8.3.2 Data Protection

When sharing Integration Partner Data, Application User Data, and Business Partner Administration User Data with Business Partners, we:

8.3.3 Business Partner Management

Our Business Partner management processes include but are not limited to:

9. Overseas Transfer

Your Personal Information may be transferred overseas or stored overseas for a variety of reasons. It is not possible to identify each and every country to which your Personal Information may be sent. If your Personal Information is sent to a recipient in a country with data protection laws which are at least substantially similar to the Australian Privacy Principles, and where there are mechanisms available to you to enforce protection of your Personal Information under that overseas law, we will not be liable for a breach of the Australian Privacy Principles if your Personal Information is mishandled in that jurisdiction. If your Personal Information is transferred to a jurisdiction which does not have data protection laws as comprehensive as Australia's, we will take reasonable steps to secure a contractual commitment from the recipient to handle your information in accordance with the Australian Privacy Principles.

10. Data Breach Procedures

10.1 Breach Response

In the event of a data breach, we will:

  1. Activate our incident response processes within one hour of detection.
  2. Assess the breach impact within 24 hours.
  3. Notify affected individuals within 72 hours if serious harm is likely.
  4. Notify the Office of the Australian Information Commissioner if required.
  5. Provide detailed incident reports to affected Business Partners.

10.2 Business Partner Notifications

Business Partners will be notified:

11. Australian Privacy Principles Compliance

We comply with all 13 Australian Privacy Principles (APPs):

11.1 Collection (APPs 1-5)

11.2 Use and Disclosure (APPs 6-9)

11.3 Integrity and Security (APPs 10-13)

12. GDPR

In some circumstances, the European Union General Data Protection Regulation (GDPR) provides additional protection to individuals located in Europe. The fact that you may be located in Europe does not, however, on its own entitle you to protection under the GDPR. Our website does not specifically target customers located in the European Union and we do not monitor the behaviour of individuals in the European Union, and accordingly the GDPR does not apply.

13. Complaint Procedure

If you have a complaint concerning the manner in which we maintain the privacy of your Personal Information, please contact us on the contact details set out at the bottom of this Privacy Policy. All complaints will be considered by a member or agent of Equiptek Pty Ltd. We may seek further information from you to clarify your concerns. If we agree that your complaint is well founded, we will, in consultation with you, take appropriate steps to rectify the problem. If you remain dissatisfied with the outcome, you may refer the matter to the Office of the Australian Information Commissioner.

14. Documentation and Response Timeline

We will acknowledge receipt of your complaint within three business days and provide you with a reference number. Our privacy team will investigate your complaint and maintain detailed records of all communications and findings. We aim to resolve all privacy complaints within 30 business days. If additional time is required, we will notify you in writing. All complaint documentation will be retained for six months following resolution. If the matter requires escalation, our Privacy Officer will personally review your case within seven business days of the escalation request.

15. How to Contact Us About Privacy

If you have any queries, or if you seek access to your Personal Information, or if you have a complaint about our privacy practices, you can contact us through: legal@equiptek.com.au.