Policies · 2021 (current)
Privacy Policy
Versions 2021 (current)
This Privacy Policy describes how Formation Systems Pty Ltd manages personal information of our end users and clients. In this Privacy Policy, “we”, “our” and “us” are all references to Formation Systems Pty Ltd ABN 20 626 349 899 of 51-53 Spring Street, Bondi Junction, NSW 2022 Australia.
Our legal obligations
We are committed to respecting your privacy and complying with our privacy obligations in accordance with all applicable data protection laws, including the Australian Privacy Principles contained in Schedule 1 to the Privacy Act 1988 (Cth) (the “Privacy Act”) and Part 13 of the Telecommunications Act 1997 (Cth). We also comply with the EU General Data Protection Regulation (“GDPR”) in relation to personal data that we process but only to the extent that it is governed by the GDPR (“GDPR Data”).
About this Privacy Policy
This Privacy Policy sets out our policy on the collection, use and disclosure of personal data of end users via our platform at www.formationsystems.com.au (“Platform”) (collectively, our “Cloud Services”) in accordance with our statutory obligations under the Privacy Act.
It also describes:
- The period for which we store personal data;
- Your rights to access and rectify or to request erasure of personal data;
- Your right to withdraw consent to the processing of personal data;
- The right to lodge a complaint with the Office of the Australian Information Commissioner (or in the case of the GDPR, the relevant supervisory authority);
- Why we collect and process personal data, the categories of personal data that we process, and who we disclose it to;
- Details of the security measures that we take to help protect your personal data; and
- Other information about how we collect, use, disclose and process personal data.
Summary of Key Points
Our identity and contact details
The Cloud Services are owned and operated by Formation Systems Pty Ltd ABN 20 626 349 899 of 51-53 Spring Street, Bondi Junction, NSW 2022. Other relevant contact details are set out at the end of this Privacy Policy.
Personal data that we process
- Profile and demographic data
- Personal preferences, habits, attitudes, lifestyles, behaviors, opinions;
- financial and transactional information;
- Subscription/registration;
- Data relating to communications between us and our Clients and end users;
- Analytics data;
- Telecommunications data heath information, sensitive information and personal data which could constitute special categories of personal data; and any other data entered into and/or uploaded into the Cloud Services by Clients and/or end users when accessing the Cloud Services.
The purposes for the processing
We process personal data in order to provide our Cloud Services and for other reasons set out in our Privacy Policy. We only process personal data in accordance with our legitimate interests and otherwise in accordance with applicable data protection laws.
Who we disclose personal data to
We only disclose personal data to third parties who perform services on our behalf to the extent necessary for them to perform those services such as our hosting providers. We do not sell personal data to third parties for their own marketing purposes and we only disclose the minimum amount of personal data required. We may disclose personal data that we collect to third parties for all or any of the purposes set out in this Privacy Policy.
Security
We take our privacy obligations very seriously. Accordingly, we only process personal data in a manner that ensures appropriate security of the personal data, including by protecting the personal data against unauthorised or unlawful processing and against accidental loss, destruction or damage using appropriate technical or organisational measures. Our Privacy Policy provides detailed information about the security measures that we take to protect personal data.
Transfer of data to other countries
We may transfer your personal data to our contractors and service providers who assist us with providing our products and services to you, where we consider it necessary for them to provide that assistance. They are located in Australia and the United Kingdom. We comply with the Privacy Act and where applicable, the GDPR, when we transfer personal data overseas.
Cookies
We do not use cookies on our Cloud Services. How we may use cookies on the public website is described in our Cookie Policy.
Your rights
If we collect personal data about you, you have rights under the Privacy Act (and the GDPR – where the GDPR applies) that we must and will honour in relation to your personal data. These rights are described in this Privacy Policy, the Privacy Act and the GDPR.
How long we store personal data for
Only for as long as is necessary. In relation to personal data that we collect through our online platform, we only retain this personal data for 30 days after the end of the provision of services relating to the processing. We will destroy (or de-identify the personal data where we are entitled to do so) or return it to the relevant data subject.
Automated decision making
We do not use automated-decision making in our business.
If we decide to change this Privacy Policy, we will post the updated version on this webpage so that you will always know what personal data we gather, how we might use that information, and whether we will disclose it to anyone. If you are an end user of our Cloud Services that we make available via the Platform, we will notify you of any changes to our Privacy Policy by sending an email to you using the email address that you provide to us when subscribing to the Platform or any new email address that you specify in your account on the Platform.
Personal data
In this Privacy Policy, “personal data” has the meaning given in the GDPR.
The Privacy Act defines “personal information” as information or an opinion about an identified individual, or an individual who is reasonably identifiable:
- whether the information or opinion is true or not; and
- whether the information or opinion is recorded in a material form or not.
Note: Section 187LA of the Telecommunications (Interception and Access) Act 1979 extends the meaning of personal information to cover information kept under Part 5‑1A of that Act.
Article 4(1) of the GDPR defines “personal data” as any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
Principles relating to the collection of personal data
Our policy is to minimise the amount of personal data we collect. Accordingly, we only collect personal data that is adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed.
We collect personal data that you give us, whether by email, telephone, in person, via application forms or otherwise. We may also obtain personal data directly from third parties such as our resellers, related companies, installers, sales agents and any of their representatives. In addition, we may obtain personal data from public sources, where available. However, if it is reasonable and practicable to do so, we will collect personal data about an individual only from that individual.
We will only collect personal data for specified, explicit and legitimate purposes and we will not further process personal data that we collect in a manner that is incompatible with those purposes. If you enter and/or upload into the Cloud Services and/or otherwise provide us with personal data about any person other than you, please notify us so that we can ensure that the data subjects are provided with the information required by Australian Privacy Principle 5 and Article 14 of the GDPR.
We may collect personal and sensitive information if the information is reasonably necessary for one or more of our entity’s functions or activities and/or you consent to the collection, or we collect it pursuant to subclause 3.4 of the Australian Privacy Principles. Please notify us if you are not old enough or not otherwise able to provide us with your consent. If so, do not provide us with any consent for the purposes of applicable privacy law.
We may process any data that is personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person’s sex life or sexual orientation, with your consent and where permitted by the Australian Privacy Principles and/or the GDPR.
Personal data that we collect and how we use it
Our policy is to minimise the amount of personal data we collect. Accordingly, we only collect personal data that is adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed.
The personal data that we collect and how we use it is as follows:
- Subscription/registration, payment, transactional data and profile data: If you register or subscribe to our Cloud Services as a client or end user, we will collect and otherwise process names, telephone numbers, mobile numbers, email addresses, tax file numbers, bank account details, payment and transactional information, records of products and services purchased, postal addresses and business addresses, in order to administer subscriptions and accounts, provide the Cloud Services, enforce payment and contract terms, protect intellectual property, send maintenance and renewal notices, and provide assistance.
- Data entered into and/or uploaded into the Cloud Services: We collect collated survey data such as personal preferences, habits including purchasing habits, attitudes, lifestyles, behaviours, knowledge, opinions, job and salary details, personal finances, race, nationality, age, health information and sensitive information, and any other personal information voluntarily entered or uploaded. We process this as a processor on our clients’ instructions (unless law requires otherwise) and as a controller to monitor agreement compliance, enforce IP, maintain backups, detect unauthorised use and faults, and provide professional services where contracted.
- Communications: When Clients and end users contact us, we collect IP addresses and any personal data provided, to answer questions, provide support, and communicate about breach, expiry, termination or suspension of the Cloud Services.
- Analytics data: We collect location, IP addresses, cookie data, time spent and navigation paths for statistical purposes, to detect unauthorised use, and to improve the Cloud Services. Aggregated data that remains personal data is treated in accordance with this Privacy Policy.
Automated decision making
We do not use automated-decision making in our business.
Who we share personal data with
We only disclose personal data to third parties who perform services on our behalf to the extent necessary for them to perform those services. We do not sell personal data to third parties for their own marketing purposes and we only disclose the minimum amount of personal data required. We may disclose personal data that we collect to third parties for all or any of the following purposes:
- To provide you with the Cloud Services — we disclose personal data to our upstream hosting suppliers who host the Platform and the personal data that you enter into and/or upload into the Cloud Services.
- So that we can obtain assistance with the provision of the Cloud Services — members of our corporate group who we may subcontract to.
- Conducting publicity campaigns — our marketing suppliers.
- Handling claims and complaints — our lawyers and insurers.
- Sending out a newsletter — our email and newsletter service providers.
- In order to identify our Clients and any end users when we are contacted with questions or concerns regarding the products and services we provide.
- In order to configure a new service for our Clients and end users.
- In order to record billing details — we provide bank account and credit card details to our bank and merchant facility providers.
- In order to interface with third party platforms where you configure your account to do so.
- For professional advice — legal, accounting or financial advisors/representatives or debt collectors.
- If we sell the whole or part of our business or merge with another entity — we will provide the purchaser or other entity the personal data that is the subject of the sale or merger.
- Where required by law.
We may also provide your personal data to our lawyers, insurers and professional advisors and any court or administrative body, for professional advice, insurance, prevention and investigation of crime or serious improper conduct, protection of public revenue, protection or enforcement of our rights, court or tribunal proceedings, or to protect the safety or vital interests of employees, end users or property.
Third party platforms
Formation Systems may include links to, or interface with third party websites and platforms. Our linking to those websites and platforms does not mean that we endorse or recommend them. Where an end user uses Formation Systems or the Cloud Services to provide personal data to a third party website or platform, the end user does so at its own risk. We do not warrant or represent that any third party website or platform operator complies with applicable data protection laws. You should consider the privacy policies of any relevant third party websites and platforms prior to sending your personal data to them.
You may interact with social media platforms via social media widgets and tools such as the Facebook Like button and the Facebook pixel that may be installed on Formation Systems. These widgets and tools may collect your IP address and other personal data. Your interaction with such widgets and tools, and any single sign-on services such as Open ID is governed by the privacy policies of the relevant social media operators and single sign-on service providers.
Security
We take our privacy obligations very seriously. Accordingly, we only process personal data in a manner that ensures appropriate security of the personal data, including by protecting the personal data against unauthorised or unlawful processing and against accidental loss, destruction or damage using appropriate technical or organisational measures.
The technical and organisational measures that we have implemented are as follows:
- Physical security in our buildings and offices such as locks, visitor access management, cabinet locks, surveillance and alarms;
- Privacy and confidentiality terms in employee contracts and subcontractor agreements;
- Security audits of our systems;
- A Data Breach Response Plan;
- Data backup, archiving and disaster recovery processes;
- Anti-virus and security controls for email and other applicable systems;
- Processes to ensure integrity and resilience of systems, servers and personal data.
Privacy Tools
Formation Systems includes privacy tools that you can use to control how we process personal data that you upload and/or enter into the Platform for us to process on your behalf. You can access these privacy tools by configuring your account on Formation Systems at formationsystems.com.au/privacy.
If you refuse to provide us with personal data
You can only browse limited pages of Formation Systems without registering as a subscriber, such as the pages that generally describe the services that we make available, and our Contact Us page. When you subscribe we need to collect personal data to identify you and set up an account. We also collect personal data when you use the Cloud Services, contact us for support, and when gathering analytics. You may not identify yourself when enquiring about our Cloud Services, but not if you wish to access the Cloud Services. It is not practical for us to provide you with the Cloud Services if you refuse to provide us with personal data.
Spam email
We do not send “junk” or unsolicited e-mail in contravention of the Spam Act 2003 (Cth). We will, however, use e-mail in some cases to respond to inquiries, confirm purchases, or contact Clients and end users. Anytime a Customer or end user or visitor receives e-mail it does not want from us they can request that we not send further e-mail by contacting us via email at: [email protected]. Upon receipt of any such request, we will remove the person from our database to ensure that they cease to receive automated emails from us.
Contractors and offshore providers
Subject to the following section “GDPR offshore transfers”, and provided that we comply with the provisions of the Australian Privacy Principle 8 (Cross-border disclosure of personal information), we may transfer your personal data to our contractors and service providers who assist us with providing our products and services to you, where we consider it necessary for them to provide that assistance. They are located in Australia and UK, London.
We will only engage new third parties to process GDPR Data entered into and/or uploaded into the Cloud Services by you for us to process as a processor on your behalf (“subprocessors”) if you have authorised us to do so pursuant to a specific or general written authorisation and otherwise in compliance with the requirements of the GDPR.
GDPR offshore transfers
We will transfer GDPR Data about a person to any country or organisation outside of the European Union but only if the transfer is reasonably necessary for us to provide or procure the provision of the Cloud Services, or instructed by the person.
Unless otherwise agreed in writing by a data subject, any transfer by us of personal data that a data subject uploads and/or enters into the Cloud Services for us to process on their behalf (which is the subject of the GDPR) outside the European Union will not be carried out unless we have taken such measures as are necessary to ensure the transfer complies with all applicable data protection laws. This may include transferring pursuant to the standard contractual clauses approved by the European Commission, or transferring to a country or organisation that the European Commission has determined provides adequate protection for personal data.
Retention and de-identification of personal data
We will not keep personal data in a form which permits identification of any person for longer than is necessary for the purposes for which the personal data is processed. Following your cessation of use of the Cloud Services, at your option we will delete or return to you all of the personal data uploaded and/or entered into the Cloud Services by you. Where you require that personal data to be returned, it will be returned after the end of the provision of services relating to the processing (“Processing Conclusion Date”), and we will thereafter delete remaining copies as soon as reasonably practicable, but in any event not more than 30 days after the Processing Conclusion Date, unless applicable law requires us to retain the personal data.
Where the personal data is not GDPR Data and is personal information for the purposes of the Privacy Act, within the 30 day period following the Processing Conclusion Date instead of destroying the personal information we will take such steps as are reasonable in the circumstances to de-identify the personal information that we hold about an individual where we no longer need it for any purpose for which it may be used in accordance with this Privacy Policy if the information is not contained in a Commonwealth record and we are not required by Australian law (or a court or tribunal order) to retain it.
Your rights under the GDPR
Subject to the provisions and exceptions set out in the Privacy Act and GDPR, you have a number of rights, including:
- the right to request access to and rectification or erasure of your personal data or restriction of processing;
- the right to object to the processing of your data;
- the right to data portability;
- the right to withdraw consent;
- the right to lodge a complaint with the Office of the Australian Information Commissioner or any supervisory authority;
- the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you.
Please contact us if you wish to opt out of any communications that we send you or if you wish to exercise any of your rights. If you withdraw your consent, object to processing or request erasure and as a result it is not possible or practical for us to continue providing you with the Cloud Services, we may terminate your subscription and/or access and charge any applicable cancellation/termination fees in accordance with our SaaS Services Agreement.
How to access and correct personal data held by us
Please contact us if you wish to access your personal data that we hold about you. We will handle your request in accordance with our statutory obligations. To ensure that we only obtain, collect, use and disclose accurate, complete and up to date personal data, we invite you to inform us if any of your personal details change or if any of the personal data held by us is otherwise incorrect. We will provide you (or if you wish, another controller) with a copy of the personal data we hold about you in a structured, commonly used and machine-readable format. You can access, modify and delete the personal data that you have uploaded or entered into the Platform via our Cloud Services.
Notifiable data breaches
Since 22 February 2018, data breaches that are likely to result in serious harm must be reported to affected individuals and the Office of the Australian Information Commissioner, except where limited exceptions apply. For the purposes of the GDPR, certain types of data breaches must also be reported to affected individuals if the breach is likely to result in a high risk of adversely affecting individuals’ rights and freedoms. We have prepared a response plan for addressing data breaches and will notify you where we are required to do so.
Our contact details
If you wish to contact us regarding our privacy practices or the personal data that we hold about you:
Privacy Representative
Richard Want
CIO
51-53 Spring Street, Bondi Junction, NSW, 2022
[email protected]
We will use our best endeavours to resolve any privacy complaint within 10 business days following receipt of your complaint. If you are not satisfied with the outcome you may refer the complaint to the Office of the Australian Information Commissioner (“OAIC”): Call 1300 363 992 · [email protected] · GPO Box 5218, Sydney NSW 2001.
In relation to GDPR Data, you may lodge a complaint with any relevant supervisory authority.