As an Australian-based business, our information security and data privacy practices and policies are also guided by applicable Australian law, namely the Australian Privacy Act 1988 (Cth).
The Australian Privacy Principles are a cornerstone of the Privacy Act, and govern standards, rights, and obligations concerning:
the collection, use and disclosure of personal information;
an organization or agency’s governance and accountability;
integrity and correction of personal information; and
the rights of individuals to access their personal information.
We have outlined below the measures we have taken to align our services and operations with the 13 Australian Privacy Principles (APPs).
There is no requirement for you to provide personal information when using our services or when communicating with us. Our services have been designed to give you full control over the information that you provide to us.
Through providing our services we may, at times, solicit personal information from you, such as when you create a user account for our services, complete profile information, contact us for support, or make a credit card payment. Solicitation of personal information does not remove your right to anonymity and pseudonymity as described in APP 2, except where is it deemed reasonably necessary.
Through your use of our services, there may be circumstances where you supply us with the personal information of your customers, or research participants (for example). This is personal information that is unsolicited by us and solely provided and held by you. Because the nature of our services relies on processing this information on your behalf, it is unreasonable for us to destroy or de-identify any unsolicited personal information that you provide to us through your use of the services as this would affect our ability to adequately provide the services to you. You are solely responsible for managing any personal information held by you and provided to us through your use of the services. Any unsolicited personal information that you provide to us is dealt in accordance with APPs 5–13 where applicable.
We do not process or disclose personal information for any purpose other than to provide the services to you (our 'primary purpose'). We take technical and organizational measures to ensure that any entity authorized by us to process personal informational does so solely to the extent necessary to provide the services to you. Where disclosure is required by law, to the extent legally permitted, we will notify you of such disclosures.
From time-to-time we may use solicited personal information to communicate directly with you and our customers to advertise and promote improvements to our product and services. In these circumstances, we will always provide a facility for you to opt-out of receiving such communications. Upon request, we are able to provide a source for an individual's personal information used in direct marketing communications.
As part of providing our services, personal information may be disclosed through transfers to our services infrastructure that may be located in foreign countries, such as the United States. We publish a full list of our data subprocessors who we may disclose personal information to through our provision of the services to you.
We take reasonable steps to ensure that all overseas recipients of personal information will handle it in accordance with the APPs. In circumstances where an overseas recipient may not comply with the APPs, we take measures to ensure that the overseas recipient is subject to laws and binding schemes that have the effect of protecting information in a way that is substantially similar to the APPs, such as the Standard Contractual Clauses for data transfers under the GDPR.
We do not solicit the collection of government related identifiers through our provision of the services. We do not adopt any government related identifier in the design of our services.
We take reasonable steps to ensure that the personal information we collect is accurate, up-to-date and complete. To help maintain the quality of personal information, we have implemented a number of features and controls within the services to give you the ability to review, manage, and maintain the personal information that we collect about you.
We actively take measures to ensure the security of personal information that we hold. We have implemented a number of technical and organizational security measures to protect information from misuse, interference and loss, as well as unauthorized access, modification or disclosure.
Where we hold personal information about an individual, we are committed to providing the individual access to that information on request. If we receive a request to access personal information related to your use of our services that is held by you then, to the extent legally permissible, we will advise the requester to submit the request to you. To the extent that you are unable to address a particular request, we will, upon your request and taking into account the nature of the personal information requested, provide reasonable assistance in addressing the personal information (provided we are legally permitted to do so and that you have verified the request in accordance with applicable privacy law).
We take reasonable steps to correct personal information and ensure that it is accurate, up-to-date, complete, relevant, and not misleading. To help correct the quality of personal information, we have implemented a number of features and controls within the services to give you the ability to review, manage, and maintain the personal information that we collect about you.
Give us feedback
Was this article useful?