1.2 The purpose of this Policy is to detail how we protect your privacy and how we comply with the requirements of the following (“Privacy Laws”):
1.2.1 In Australia, Privacy Act 1988 (Cth) and the Australian Privacy Principles; and 1.2.2 In Europe, the European Union’s General Data Protection Regulation (Regulation (EU) 2016/679.
1.3 By visiting our website, or by purchasing or using the Service, you accept the privacy practices described in this Policy.
1.4 “Personal information” is any information that allows an individual to be personally identified and “personal data” means any information relating to an identified or identifiable natural person (together “Personal Information”).
1.5 “Client Data” means Information, data, reports, addresses, and other files, folders or documents in electronic form that a user stores within the Service.
1.6 This policy describes:
1.6.1 From whom we collect Personal Information;
1.6.2 The types of Personal Information collected and held by us;
1.6.3 How this Personal Information is collected and held;
1.6.4 The purposes for which your Personal Information is collected, held, used and disclosed;
1.6.5 How you can gain access to your Personal Information and seek its correction;
1.6.6 How you may complain or inquire about our collection, handling, use or disclosure of your Personal Information and how that complaint or inquiry will be handled;
1.6.7 Whether we are likely to disclose your Personal Information to any overseas recipients;
1.6.8 How we report any data breaches.
2. Who do we collect Personal Information from?
3. What kinds of Information do we collect?
3.2 You may provide us with Personal Information in various ways. For example, when you register for an account, use the Service, post Client Data, interact with other users of the Service through communication or messaging capabilities, or send us customer service -related requests.
3.3 The kinds of Personal Information Hillogic collects are largely dependent upon whose Personal Information we are collecting and why we are collecting it, however, generally we collect Personal Information such as name, address, telephone numbers, email address. Sometimes we may collect other Personal Information from you, such as the type of services you may be interested in Hillogic providing to you or even billing information. We endeavour not to collect Personal Information that we do not require.
3.4 We endeavour to collect Personal Information directly from the individuals concerned. However, if this is not practicable, we may collect Personal Information about individuals from third parties, including from publicly available sources. If we do, we will take reasonable steps to ensure that the individuals concerned are made aware of the collection of their Personal Information.
3.5 If you are a business contact, such as a supplier or from a government agency, we may collect basic business contact information from you, such as your name, title and work contact details. We will not ask to collect sensitive information about you (such as details of your racial or ethnic origin, political affiliation, religious beliefs, sexual preferences, criminal convictions or health information) unless it is needed for the purposes of providing the Service.
3.6 A client or user may store or upload Personal Information to our applications and to the Service. We have no direct relationship with the individuals whose Personal Information we host as part of Client Data. Each client is responsible for providing notice to its customers and third persons concerning the purpose for which client collects their Personal Information and how this Personal Information is processed in or through the Service as part of Client Data.
3.7 When you use the Service, we may automatically record certain Personal Information from your device by using various types of technology, including cookies, “clear gifs" or “web beacons.” This “automatically collected" information may include IP address or other device address or ID, web browser and/or device type, the web pages or sites visited just before or just after using the Service, the pages or other content you view or interact with on the Service, and the dates and times of the visit, access, or use of the Service. We also may use these technologies to collect information regarding your interaction with email messages, such as whether you open, click on, or forward a message. This information is gathered from all users.
3.9 We may obtain Personal Information from third parties and sources other than the Service, such as our partners, advertisers, credit rating agencies, and Integrated Services. If we combine or associate Personal Information from other sources with Personal Information we collect through the Service, we will treat the Personal Information in accordance with this Policy.
4. How do we collect your Personal Information?
4.1.1 Instruct Hillogic to provide you with services;
4.1.2 Purchase or subscribe to a Hillogic online service;
4.1.3 Subscribe to a Hillogic newsletter;
4.1.4 Attend a Hillogic seminar or marketing event
4.1.5 Have business dealings with Hillogic; or
4.1.6 Apply or register your interest for employment with Hillogic.
5. How do we use your Personal Information?
5.2 We use automatically collected information and other information collected on the Service through cookies and similar technologies to:
5.2.1 Personalise our Service, such as remembering a user’s information so that the user will not have to re-enter it during a visit or on subsequent visits;
5.2.2 Provide customised advertisements, content, and information;
5.2.3 Monitor and analyse the effectiveness of Service and third-party marketing activities;
5.2.4 Monitor aggregate site usage metrics such as total number of visitors and pages viewed; and
5.2.5 Track your entries, submissions, and status in any promotions or other activities on the Service. You can obtain more information about cookies by visiting: http://www.allaboutcookies.org.
5.4 We take measures to protect the technical information collected by our use of Google Analytics. The data collected will only be used on a need to know basis to resolve technical issues, administer the Site and identify visitor preferences; but in this case, the data will be in non-identifiable form. We do not use any of this information to identify users.
6. Will your Personal Information be given to anyone else?
6.2 We may disclose Personal Information to external service providers who help us operate our business. We limit the information provided to these service providers to that which is reasonably necessary for them to perform their functions, and our contracts with them require them to maintain the confidentiality of such information. We will take steps to ensure that those external service providers comply with the Privacy Laws when they handle Personal Information about you (even if they may be exempt from the Privacy Laws) and are authorised only to use Personal Information for the limited purposes specified in our agreement with them.
6.4 Where we engage external information technology service providers, we ensure that wherever possible, our data is stored within Australia or Europe, however some of our vendors do store data in other locations, including but not limited to the USA.
6.5 We have no direct relationship with a client’s customers or third party whose Personal Information it may process on behalf of a client. An individual who seeks access, or who seeks to correct, amend, delete inaccurate data or withdraw consent for further contact should direct his or her query to the client they deal with directly. If the client requests us to remove the data, we will respond to its request within thirty (30) days. We will delete, amend or block access to any Personal Information that we are storing only if we receive a written request to do so from the Client who is responsible for such Personal Information, unless we have a legal right to retain such Personal Information. We reserve the right to retain a copy of such data for archiving purposes, or to defend our rights in litigation. Any such request regarding Client Data should be addressed as indicated in the “How to Contact Us” section, and include sufficient information for us to identify the Client or its customer or third party and the information to delete or amend.
6.6 Otherwise, we will only disclose personal information if this is required by law or permitted under the Privacy Act. We are bound by professional obligations of confidentiality, including in relation to personal information.
6.7 We reserve the right to disclose Personal Information or other information that we believe, in good faith, is appropriate or necessary to
(i) take precautions against liability,
(ii) protect ourselves or others from fraudulent, abusive, or unlawful uses or activity,
(iii) investigate and defend ourselves against any third-party claims or allegations,
(iv) protect the security or integrity of the Service and any facilities or equipment used to make the Service available, or
(v) protect our property or other legal rights, enforce our contracts, or protect the rights, property, or safety of others.
7. Minors and Children’s Privacy
7.2 The Service is not intended to be used by minors, and is not intended to be used to post content to share publicly or with friends. To the extent that a minor has posted such content on the Service, the minor has the right to have this content deleted or removed using the deletion or removal options detailed in this Policy. If you have any question regarding this topic, please contact us as indicated in the “How to Contact Us” section. Please be aware that, although we offer this deletion capability, the removal of content may not ensure complete or comprehensive removal of that content or information.
8. Storage and security of Personal Information
8.2 The security of your Personal Information is important to us and we take reasonable steps to protect the Personal Information we hold about you from misuse, loss, unauthorised access, modification or disclosure. These steps include:
8.2.1 Restricting access to information on our databases on a need to know basis with different levels of security being allocated to staff based on their roles and responsibilities and security profile.
8.2.2 Ensuring all staff are aware that they are not to reveal or share personal passwords.
8.2.3 Implementing ICT security systems, policies and procedures, designed to protect personal information storage on our computer networks.
8.2.4 Implementing human resources policies and procedures, such as email and internet usage, confidentiality and document security policies, designed to ensure that staff follow correct protocols when handling personal information.
8.2.5 Undertaking due diligence with respect to third party service providers who may have access to personal information, including cloud service providers, to ensure as far as practicable that they are compliant with the Privacy Laws.
8.3 However, no method of transmission over the internet, or method of electronic storage, is 100% secure. We cannot ensure or warrant the security of any information you transmit to us or store on the Service, and you do so at your own risk. We also cannot guarantee that such information may not be accessed, disclosed, altered, or destroyed by breach of any of our physical, technical, or managerial safeguards. If you believe your Personal Information has been compromised, please contact us as set forth in the “How to Contact Us” section. If we learn of a security systems breach, we will inform you and the authorities of the occurrence of the breach in accordance with applicable law.
8.4 Personal information we hold that is no longer needed is destroyed in a secure manner, deleted or de-identified as appropriate.
8.5 Our website may contain links to other websites. We do not share your Personal Information with those websites and we are not responsible for their privacy practices. Please check their privacy policies.
9. When we disclose Personal Information
9.2 We may disclose your Personal Information to government agencies, our service providers, agents, contractors, business partners and other recipients from time to time, only if one or more of the following apply:
9.2.1 You have consented;
9.2.2 You would reasonably expect us to use or disclose your personal information in this way;
9.2.3 We are authorised or required to do so by law;
9.2.4 Disclosure will lessen or prevent a serious threat to the life, health or safety of an individual or to public safety;
9.2.5 Where another permitted general situation or permitted health situation exception applies;
9.2.6 Disclosure is reasonably necessary for a law enforcement related activity.
10. Notification of Data Breaches
10.1.1 Complete an assessment of the suspected data breach within 30 days; 10.1.2 If appropriate, take remedial action to address any potential harm to individuals that may arise due to a relevant data breach before any serious harm is caused to individuals to whom the information relates.
10.2 We will otherwise comply with privacy data breach notification requirements as set out in the Privacy Laws, including notifying affected individuals and the Office of the Australian Information Commissioner as applicable, and as required by the GDPR.
11. Access to your Personal Information
11.2 You may update, correct, or delete your Account information and preferences at any time by accessing your Account settings page on the Service. Please note that while any changes you make will be reflected in active user databases instantly or within a reasonable period of time, we may retain all information you submit for backups, archiving, prevention of fraud and abuse, analytics, satisfaction of legal obligations, or where we otherwise reasonably believe that we have a legitimate reason to do so.
11.3 You may decline to share certain Personal Information with us, in which case we may not be able to provide to you some of the features and functionality of the Service.
11.4 Under the Privacy Laws, you have the right to:
11.4.1 Seek access to your personal information handled by us;
11.4.2 Ask us to update or correct your personal information when it is inaccurate, incomplete or out of date; and
11.4.3 Opt-out of receiving direct marketing communications from us.
11.5 If you wish to access the personal information that Hillogic holds about you, please set out your request in writing, and forward this to Hillogic.
12. Data Controller and Data Processor
12.2 Because we do not collect or determine the use of any Personal Information contained in the Client Data and because we do not determine the purposes for which such Personal Information is collected, the means of collecting such Personal Information, or the uses of such Personal Information, we are not acting in the capacity of data controller in terms of the GDPR and do not have the associated responsibilities under the GDPR. We are a processor on behalf of our Clients and users as to any Client Data containing Personal Information that is subject to the requirements of the GDPR. Except as provided in this Policy, we do not independently cause Client Data containing Personal Information stored in connection with the Services to be transferred or otherwise made available to third parties, except to third party subcontractors who may process such data on behalf of us in connection with the provision of Services to Clients. Such actions are performed or authorised only by the applicable Client or user.
12.3 The Client or the user is the data controller under the Regulation for any Client Data containing Personal Information, meaning that such party controls the manner such Personal Information is collected and used as well as the determination of the purposes and means of the processing of such Personal Information.
12.4 We are not responsible for the content of the Personal Information contained in the Client Data or other information stored on servers (or subcontractors’ servers) at the discretion of the Client or User nor are we responsible for the manner in which the Client or User collects, handles disclosure, distributes or otherwise processes such information.
13. Privacy Complaints
13.3 If you wish to make a complaint about a breach by us of the Australian Privacy Principles you may do so by providing your written complaint by email, letter, or by personal delivery to Principal. You may also make a complaint verbally.
13.4 We will respond to your complaint within a reasonable time (usually no longer than 30 days) and we may seek further information from you in order to provide a full and complete response.
13.5 Your complaint may also be taken to the Office of the Australian Information Commissioner.
14. How to Contact Us
14.3 You can contact us about this Policy or about your personal information by emailing us at firstname.lastname@example.org.
14.4 If practical, you can contact us anonymously (i.e. without identifying yourself) or by using a pseudonym. However, if you choose not to identify yourself, we may not be able to give you the information or provide the assistance you might otherwise receive if it is not practical to do so.