Privacy Policy

Affix Group Pty Ltd (ACN 605 589 955) (“we”, “us” or “our”) is committed to respecting your privacy. Our Privacy Policy sets out how we collect, use, process, store, share and disclose your personal information.

Openness and transparency

We are committed to protecting your privacy and respecting and upholding your rights under the Australian Privacy Principles (“APPs”) contained in the Privacy Act 1988 (Cth) and the General Data Protection Regulation (EU 2016/679) (the “GDPR”) (collectively, “Privacy Laws”). We ensure that we will take all necessary and reasonable steps to comply with the relevant Privacy Laws and to deal with inquiries or complaints from individuals about compliance with the relevant Privacy Laws.

By accessing and using our platform, website, products and services, you freely and expressly consent to the collection, use, processing, storage and disclosure of personal information by us as set out in this Privacy Policy.

Personal information

Personal information is any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.

The type of personal information we collect from you includes, without limitation, the following:

- your full name;
- address;
- email address;
- telephone number(s);
- date of birth (in limited circumstances);
- credit card information (to process client payments through secure third-party payment providers);
- your device ID, device type, geo-location information, computer and connection information, statistics on page views, traffic to and from the sites, ad data, - IP address and standard web log information;
details of the products and services we have provided to you or that you have enquired about, including any additional information necessary to deliver those products and services and respond to your enquiries;
- any additional information relating to you that you provide to us directly through our website or app or indirectly through your use of our website or app or online presence or through other websites or accounts from which you permit us to collect information;
- information you provide to us through customer surveys;
- billing information (including credit and bank details); or

any other personal information that may be required in order to facilitate your dealings with us.

Collection

We will collect Personal Information only by lawful and fair means and not in an unreasonably intrusive way. Generally, we will collect personal information directly from you, and only to the extent necessary to provide our products and services requested or ordered by you and to carry out our administrative functions or as required by a relevant Privacy Law. In limited instances, we will collect sensitive personal information (as defined under the relevant Privacy Laws) from you. We also do not knowingly seek or collect Personal Information from children below the age of 16 years.

The Privacy Act defines ‘sensitive information’ as information or an opinion about an individual’s racial or ethnic origin, political membership, associations or opinions, religious or philosophical beliefs or affiliations, membership of a professional association or trade union, sexual orientation or practices, criminal record, health information and genetic or biometric information.

We may also collect Personal Information from you when you fill in an application form, communicate with us, visit our website, provide us with feedback, complete online surveys or participate in competitions. We may collect Personal Information about you that you have provided to our business partners or from third parties and in respect of which you have given the third party permission to share with us.

If you use a pseudonym when dealing with us or you do not provide identifiable information to us, we may not be able to provide you with any or all of our services as requested. If you wish to remain anonymous when you use our website, do not sign into it or provide any information that might identify you.

We require individuals to provide accurate, up to date and complete Personal Information at the time it is collected.

What is our legal basis?

Under the GDPR, we must have a legal basis to process Personal Information collected from individuals residing in the European Union. We rely on several legal bases to process your Personal Information, including:

where it is necessary to provide you with access to, and use of, our platforms, products, services and websites;
for our legitimate interests to provide, operate and improve our products, services or website;
where you have freely and expressly consented to the processing of your Personal Information by us, which you may withdraw at any time; or
where we are under a legal obligation to process your Personal Information.
What do we do with your Personal Information?

We use, process and disclose your Personal Information for the purposes for which the information is collected, or for a directly related purpose, including (but not limited to):

- providing our website, products and services to you;
- administering, protecting, improving or optimising our website, products and services (including performing data analytics, conducting research and for advertising and marketing purposes);
- billing you for purchasing or using our website, products and services;
- informing you about our website, products, services, rewards, surveys, contests, or other promotional activities or events sponsored or managed by us or our business partners;
- responding to any inquiries or comments that you submit to us;
- verifying your identity;
- any other purpose you have consented to; and

any use which is required or authorised by a relevant Privacy Law.

Disclosure of Personal Information

As part of our commitment to respecting your privacy, we will always endeavour to inform you before disclosing your Personal Information, We may disclose your Personal Information to:

third-parties we ordinarily engage from time to time to perform functions on our behalf for the above purposes;
any person or entity to whom you have expressly consented to us disclosing your Personal Information to;
our external business advisors, auditors, lawyers, insurers and financiers; and
any person or entity to whom we are required or authorised to disclose your Personal Information to in accordance with the relevant Privacy Laws.
Access and management

Subject to some exceptions provided by the relevant Privacy Laws, you may request access to your Personal Information in our customer account database, or seek correction of it, by contacting us. See section 13: Contact information. Should we decline you access to your Personal Information, we will provide a written explanation setting out our reasons for doing so.

We may charge a reasonable fee that is not excessive to cover the charges of retrieving your Personal Information from our customer account database. We will not charge you for making the request.

If you believe that we hold Personal Information about you that is not accurate, complete or up-to-date then you may request that your Personal Information be amended. We will respond to your request to correct your Personal Information within a reasonable timeframe and you will not be charged a fee for correcting your Personal Information.

If we no longer need your Personal Information for any of the purposes set out in this Privacy Policy, or as otherwise required by the relevant Privacy Laws, we will take such steps as are reasonable in the circumstances to destroy your Personal Information or to de-identify it.

Direct marketing

Where we:

- have your express consent (which you may withdraw at any time by contacting us);
- have a legal basis; or
- are otherwise permitted by relevant Privacy Laws,
- we may use and process your Personal Information to send you information about products and services we believe are suited to you and your interests or we may invite you to attend special events.

At any time, you may opt out of receiving direct marketing communications from us. Unless you opt out, your consent to receive direct marketing communications from us and to the handling of your Personal Information as detailed above, will continue. You can opt out by following the unsubscribe instructions included in the relevant marketing communication, or by contacting us in writing at [email protected].

Cross-border disclosure

We may disclose your Personal Information to third party recipients located in or outside of the European Union in order to provide our website, products and services to you. As at the date of this Privacy Policy, all third party recipients are located in Australia (“Recipients”), whose laws are recognised by the EU Commission as providing an adequate level of protection to Personal Information.

When entering into a transaction with us you expressly and freely consent to your Personal Information being disclosed or transferred to such Recipients. We will take steps reasonably necessary to ensure your Personal Information is treated securely and in accordance with this Privacy Policy. We use reasonable endeavours to ensure that each Recipient receiving your Personal Information is bound by the relevant Privacy Laws (including the standard contractual clauses approved by the European Commission). The standard contractual clauses are available on the European Commission’s website at https://ec.europa.eu/info/law/law-topic/data-protection_en.

Our Website & Services

When transmitting Personal Information from your computer to our services, you must keep in mind that the transmission of information over the Internet is not always completely secure or error-free. Other than liability that cannot lawfully be excluded, we will not be liable in any way in relation to any breach of security or any unintended loss or disclosure of that information.

Our digital platforms may use ‘cookies’ or other similar tracking technologies on our website that help us track your website usage and remember your preferences. Cookies are small files that store information on your computer, TV, mobile phone or other device. They enable the entity that put the cookie on your device to recognise you across different websites, services, devices and/or browsing sessions. You can disable cookies through your internet browser but if you do so, you may not be able to fully experience the interactive features of our services.

(Marketing) Force24 Cookies & Tracking

Our organisation utilises Force24’s marketing automation platform.

Force24 cookies are first party cookies and are enabled at the point of cookie acceptance on this website. The cookies are named below:

F24_autoID
F24_personID
They allow us to understand our audience engagement thus allowing better optimisation of marketing activity.

f24_autoId – This is a temporary identifier on a local machine or phone browser that helps us track anonymous information to be later married up with f24_personid. If this is left anonymous it will be deleted after 6 months . Non-essential, first party, 10 years, persistent.

f24_personId – This is an ID generated per individual contact in the Force24 system to be able to track behaviour and form submissions into the Force24 system from outside sources per user. This is used for personalisation and ability to segment decisions for further communications. Non-essential, first party, 10 years, persistent.

The information stored by Force24 cookies remains anonymous until:

Our website is visited via clicking from an email or SMS message, sent via the Force24 platform and cookies are accepted on the website.
A user of the website completes a form containing email address from either our website or our Force24 landing pages.
The Force24 cookies will remain on a device for 10 years unless they are deleted.

Other Tracking

We also use similar technologies including tracking pixels and link tracking to monitor your viewing activities

Device & browser type and open statistics

All emails have a tracking pixel ( a tiny invisible image ) with a query string in the URL. Within the URL we have user details to identify who opened an email for statistical purposes.

Link Tracking

All links within emails and SMS messages sent from the Force24 platform contain a unique tracking reference, this reference help us identify who clicked an email for statistical purposes.

Security

We may hold your Personal Information in either electronic or hard copy. We take reasonable steps to protect your Personal Information from misuse, interference and loss, as well as unauthorised access, modification or disclosure and we use a number of physical, administrative, personnel and technical measures to protect your Personal Information. For example, we utilise SSL across all our cloud hosting infrastructure for the transmission of Personal Information.

However, we cannot guarantee the security of any Personal Information transmitted over the internet and therefore you disclose information to us at your own risk. We will not be liable for any unauthorised access, modification or disclosure, or misuse of your Personal Information.

Enhanced privacy rights (European Union only)

Under the GDPR, an individual residing in the European Union has enhanced privacy rights, including the right to:

- require us to correct any Personal Information held about you that is inaccurate or incomplete;
- require the deletion of Personal Information concerning you in certain situations;
- data portability for Personal Information you provide to us;
- object or withdraw your consent at any time to the processing of your Personal Information;
- object to decisions being taken by automated means which produce legal effects concerning you or similarly significantly affect you; or
otherwise restrict our processing of your Personal Information in certain circumstances.

Contact information

If you require further information regarding our Privacy Policy or wish to make a privacy complaint, please contact us at [email protected], call us on 1300 233 493 or send mail to Level 4, 54 Wellington Street, Collingwood Victoria 3066.

Miscellaneous

We reserve the right to modify this Privacy Policy in whole or in part from time to time without notice and amendments will be effective immediately upon posting of the amended Privacy Policy on our website.

Dated: 18th January, 2024