Privacy Policy

1. INTRODUCTION

  • (a) This website (www.thornetix.com) (Website) and the goods, products, services, hardware and software sold on, or via, the Website (collectively, Products) are created, operated and controlled by Thornetix Pty Ltd (ABN 23 622 832 311) or its ‘Related Bodies Corporate’ (as that term is defined in the Corporation Act 2001 (Cth)) (Thornetix, we, us or our).
  • (b) We are committed to ensuring your Personal Information is protected. We manage your Personal Information in accordance with the Australian Privacy Principles (APPs) set out in the Privacy Act 1988 (Cth) (Privacy Act).
  • (c) By accessing, using and continuing to use, Thornetix Website and/or Products, you agree to this Privacy Policy.
  • (d) This Privacy Policy outlines how we collect, store, use, process and disclose your Personal Information, and how you may access your Personal Information kept by us or how you may make a privacy complaint.
  • (e) For the purpose of this Privacy Policy:
    • Personal Information has the same meaning that it has under the Privacy Act, namely, information or an opinion about a natural person which identifies a natural person, or which is reasonably capable of identifying a natural person, whether or not the information is true or recorded in a material form; and

2. THE INFORMATION WE COLLECT ABOUT YOU

2.1 Personal Information

  • (a) We will only collect and hold Personal Information about you that is reasonably necessary to undertake our business activities and functions, deliver the Products to you, or as otherwise permitted by law.
  • (b) The type of Personal Information and non-Personal Information that we may collect and use depends on the type of dealings that you have with us and includes the following:
    • (i) user contact details (for example, full name, address, date of birth, email address,);
    • (ii) user registration information (such username and password);
    • (iii) payment and billing information;
    • (iv) information regarding your access to, and use of, the Products (whether as a user or visitor), including location information, IP address, products you viewed or searched for, length of visits to certain pages, page interaction information, methods used to browse away from the page and any third party Websites you access; and
    • (v) other information that you provide to us or that we may collect in the course of our relationship with you.

3. HOW WE COLLECT PERSONAL INFORMATION

3.1 Direct collection from you

  • (a) We collect your Personal Information (directly or automatically) from you in a variety of ways, including if you:
    • (i) set up or update an account or other registration in relation to a Service offered by Thornetix;
    • (ii) visit, access and use the Products offered by Thornetix;
    • (iii) purchase, access and use our Products made available to you on;
    • (iv) when you use any support services that are provided by us;
    • (v) submit an enquiry to us via the Thornetix Website or other Thornetix portal or platform;
    • (vi) participate in our surveys, competitions, promotions, questionnaires or other promotional activities or complete any forms or documents for our products or services or subscribe to our publications, alerts and newsletters; or
    • (vii) interact or communicate with us, such as by telephone, email or in person or make a comment on our social media sites.
  • (b) This policy is subject to any further specific provisions contained in collection notices and the terms and conditions of any offers, products and services.
  • (c) By providing your Personal Information to us, you acknowledge that you are authorised to provide such information to us.

3.2 Collection from third parties

  • (a) We may also collect Personal Information from publicly available sources and third parties, including:
    • (i) from third parties (including our related bodies corporate, business partners, service providers and government agencies);
    • (ii) social media platforms including Instagram, Facebook or LinkedIn;
    • (iii) banks, credit unions, financial institutions and third party payment processors;
  • (b) If you provide us with Personal Information about another individual, we rely on you to:
    • (i) inform them that you are providing their Personal Information to us; and
    • (b) advise them that they can contact us for further information.
  • (c) You must take reasonable steps to ensure the individual is aware of, and consents to, the matters outlined in this Privacy Policy.
  • (d) Upon our request, you must also assist us with any requests by the individual to access or update the Personal Information you have collected from them and provided to us.

4. HOW WE USE YOUR PERSONAL INFORMATION

4.1 Purposes of use and disclosure

  • (a) We only use, process, share and disclose your Personal Information for the purposes for which it is collected.
  • (b) In particular, we use, process, share and disclose your Personal Information to:
    • (i) to provide or deliver our Products to you;
    • (ii) to assist with, or responding to, your queries (including support service requests);
    • (iii) improve, develop and manage our Products, and to assist us in providing a better service to you;
    • (iv) operate, maintain, test and upgrade our systems and solutions; and
    • (v) notify you of opportunities we think you might be interested in, including new product or service offerings, information about our Products, offers, promotions, events and surveys and general information relating to our Products;
    • (vi) to verify your identity and conduct fraud, risk reduction and creditworthiness checks;
    • (vii) to comply with regulatory or other legal requirements; and
    • (viii) for any other purpose notified to you at the time of collection.
  • (c) In the event of a merger, acquisition or sale of the whole or part of our business or assets, we reserve the right to transfer your personal information as part of the transaction, without your consent or notice to you.

4.2 Disclosure to third parties

  • (a) You consent for us to provide your Personal Information to the following recipients:
    • (i) our employees, related entities, business partners, third party contractors, suppliers and agents from time to time for the purpose of delivering, providing and administering our Products;
    • (ii) third party service providers who process or use your Personal Information for the purpose of performing functions on our behalf, but may not process or use such information for any other purpose. Examples of these third-party service providers include, but are not limited to, such as cloud-based accounting software, marketing and analysis organisations, financial and credit card institutions to process payments, hosting companies, web developers, internet service providers, customer service providers, customer support specialists, fulfilment companies and research and data analysis firms;
    • (iii) external business advisors, such as auditors, lawyers, insurers and financiers,
      collectively, Authorised Affiliates.
  • (b) When we disclose your Personal Information to any of our Authorised Affiliates, we will ensure that they undertake to protect your privacy. These Authorised Affiliates are not permitted to use the information for any purpose other than the purpose for which they have been given access.
  • (c) Our Authorised Affiliates may also provide us with Personal Information collected from you. If you disclose personal information to an Authorised Affiliate, we rely on you to provide the Authorised Affiliate with consent for us to collect, store, use, process, alter and disclose your Personal Information.
  • (d) We may also disclose any Personal Information we consider necessary to comply with any applicable law, regulation, legal process, governmental request or industry code or standard.

4.3 Disclaimer

  • This policy only covers the use and disclosure of information we collect from you. The use of your Personal Information by any third party is governed by their privacy policies and is not within our control.

5. STORAGE AND SECURITY

5.1 Protecting your Personal Information

  • (a) We take reasonable steps in the circumstances to keep your Personal Information safe. We use a combination of technical, administrative, and physical controls to protect and maintain the security of your personal information.
  • (b) Our officers, employees, agents and third-party contractors are expected to observe the confidentiality of your Personal Information.
  • (c) Wherever possible, we procure that Authorised Affiliates who have access to your Personal Information take reasonable steps to:
    • (i) protect and maintain the security of your Personal Information; and
    • (ii) comply with the relevant APPs when accessing and using your Personal Information.

5.2 No guarantee

  • (a) The transmission of information via the internet is not completely secure. While we do our best to protect your Personal Information, we cannot guarantee the security of any Personal Information transmitted through the Thornetix Website or any other portal or platform used in providing or administering the Products.
  • (b) You provide your Personal Information to us at your own risk and we are not responsible for any unauthorised access to, and disclosure of, your Personal Information.

5.3 Destruction of Personal Information

  • We may destroy or de-identify Personal Information where it is no longer required, unless we are required or authorised by law to retain the information.

6. GENERAL DATA PROTECTION REGULATION (GDPR) FOR THE EUROPEAN UNION (EU)

If you are an individual residing in the EU, Thornetix will comply with the principles of data protection set out in the GDPR for the purpose of fairness, transparency and lawful data collection and use. Thornetix agrees the following:

  • (a) We process your Personal Information as a Processor and/or to the extent that we are a Controller as defined in the GDPR.
  • (b) We must establish a lawful basis for processing your Personal Information. The legal basis for which we collect your Personal Information depends on the data that we collect and how we use it.
  • (c) We will only collect your Personal Information with your express consent for a specific purpose and any data collected will be to the extent necessary and not excessive for its purpose. We will keep your data safe and secure.
  • (d) We will also process your Personal Information if it is necessary for our legitimate interests, or to fulfill a contractual or legal obligation.
  • (e) We process your Personal Information if it is necessary to protect your life or in a medical situation, it is necessary to carry out a public function, a task of public interest or if the function has a clear basis in law.
  • (f) We do not collect or process any Personal Information from you that is considered Sensitive Personal Information under the GDPR, such as Personal Information relating to your sexual orientation or ethnic origin unless we have obtained your explicit consent, or if it is being collected subject to and in accordance with the GDPR.

7. YOUR RIGHTS UNDER THE GDPR

  • (a) If you are an individual residing in the EU, you have certain rights as to how your Personal Information is obtained and used. Thornetix complies with your rights under the GDPR as to how your Personal Information is used and controlled if you are an individual residing in the EU.
  • (b) If you are an individual residing in the EU, you have the following rights:
    • (i) to be informed how your Personal Information is being used;
    • (ii) to access your Personal Information (we will provide you with a free copy of it);
    • (iii) to correct your Personal Information if it is inaccurate or incomplete;
    • (iv) to delete your Personal Information (also known as “the right to be forgotten”);
    • (v) to restrict processing of your Personal Information;
    • (vi) to retain and reuse your Personal Information for your own purposes;
    • (vii) to object to your Personal Information being used; and
    • (viii) to object against automated decision making and profiling,
      except as otherwise provided in the GDPR.
  • (b) Please contact us at any time to exercise your rights under the GDPR using the contact details provided in this Privacy Policy.
  • (c) We may ask you to verify your identity before acting on any of your requests.

8. HOSTING AND INTERNATIONAL DATA TRANSFERS

  • (a) We operate in various locations around the world and may host data in those countries. Information that we collect may from time to time be stored, processed in or transferred between parties or sites located in those countries.
  • (b) If your Personal Information is disclosed to a recipient overseas, we will do so in compliance with this Privacy Policy. Transfer of your Personal Information will be protected by appropriate safeguards, including to the extent required by GDPR.
  • (c) You acknowledge that personal data that you submit for publication through our website or services may be available, via the internet, around the world. We cannot prevent the use (or misuse) of such personal data by others.
  • (d) Where we employ data processors to process Personal Information on our behalf, we only do so on the basis that such data processors comply with the requirements under applicable privacy laws (including Privacy Act and the GDPR) and that have adequate technical measures in place to protect Personal Information against unauthorised use, loss and theft.
  • (e) If you have any questions in relation to the transfer of your Personal Information please contact us using the contact details set out below.

9. NOTIFIABLE DATA BREACHES SCHEME

In the event of any loss, or unauthorised access or disclosure of your Personal Information that is likely to result in serious harm to you, we will investigate and notify you and the Australian Information Commissioner as soon as practicable, in accordance with notifiable data breach scheme contained in Part IIIC of the Privacy Act.

10. DO NOT TRACK

At this time, we do not respond to browser ‘do not track’ signals.

11. DIRECT MARKETING

11.1 Your consent

  • (a) We may use and disclose your Personal Information to send you information about our Products as well as other products, services and information that may be of interest to you.
  • (b) We may send this information to you via the communication channels specified at the time you provide your consent.
  • (c) These communication channels may include mail, email, SMS telephone or social media.
  • (d) If you do not wish to receive any of these marketing communications, you can opt out by following the unsubscribe instructions included in the relevant marketing communication, or by contacting us using the contact details set out below.

11.2 Opting-out

  • (a) You can opt out of receiving these communications by:
    • (i) contacting us using the details below; or
    • (ii) using the unsubscribe function in the email or SMS.

12. LINKS TO OTHER SITES

  • (a) The Thornetix Website, and other portals or platforms used by Thornetix to provide or administer the Products, may contain hyperlinks or banner advertising to or from third-party Websites.
  • (b) We do not endorse any of these third parties, their products or services, or the content on these Websites.
  • (c) These Websites are not subject to our privacy standards, policies and procedures. Therefore, we recommend that you make your own enquires about their privacy practices.
  • (d) We are in no way responsible for the privacy practices or content of these third-party Websites.

13. COOKIES POLICY

  • (a) We may collect information when you access and use the Website or Products by utilising features and technologies of your internet browser, including cookies, pixel tags, web beacons, embedded web links and similar technologies. A cookie is a piece of data that enables us to track and target your preferences.
  • (b) The type of information we collect may include statistical information, details of your operating system, location, your internet protocol (IP) address, the date and time of your visit, the pages you have accessed, the links which you have clicked and the type of browser that you were using.
  • (c) We may use cookies and similar technologies to:
    • (i) enable us to identify you as a return user and personalise and enhance your experience and use of the Website or Products; and
    • (ii) help us improve our service to you when you access the Website or Products and to ensure that the Website or Products remain easy to use and navigate.
  • (d) Most browsers are initially set up to accept cookies. However, you can reset your browser to refuse all cookies or warn you before accepting cookies.
  • (e) If you reject our cookies or similar technologies, you may still use the Website or Products but may only have limited functionality of the Website or Products.
  • (f) We may also use your IP address to analyse trends, administer the Website or Products, track traffic patterns and gather demographic information.

14. ACCESS RIGHTS & DELETION

  • (a) We will use our reasonable endeavours to keep your Personal Information accurate, up-to-date and complete.
  • (b) You have the right to access, and/or request that we delete, any Personal Information that we hold about you, subject to some exceptions provided by the Privacy Act.
  • (c) You can access, or request that we correct or delete, your Personal Information by writing to us on info@thornetix.com. We may require proof of identity.
  • (d) If we do not allow you to access any part of your Personal Information, we will tell you why in writing.
  • (e) We will not charge you for requesting access to your Personal Information but may charge you for our reasonable costs in supplying you with access to this information.

15. CONSENT

  • You expressly and freely acknowledge and agree that we, our Authorised Affiliates and each of their officers, employees, agents and contractors are permitted to collect, process, use, share, store, disclose, alter and destroy your Personal Information in accordance with this Privacy Policy and the Privacy Act.

16. CHANGES TO THE POLICY

  • (a) We may amend this Privacy Policy from time to time at our sole discretion.
  • (b) Any revised Privacy Policy will be posted on the Website and effective from the time of posting.
  • (c) Your continued use of our products, services or the Website or Products following the posting of any revised Privacy Policy indicates your acceptance of the changes to the Privacy Policy.
  • (d) You should regularly check and read the Privacy Policy.

17. COMPLAINT

  • (a) If you have any issues about this Privacy Policy or the way we handle your Personal Information, please contact us on info@Thornetix.com and provide full details of your complaint and any supporting documentation.
  • (b) At all times, privacy complaints:
    • (i) will be treated seriously;
    • (ii) will be dealt with promptly;
    • (iii) will be dealt with in a confidential manner; and
    • (iv) will not affect your existing obligations or your commercial arrangements with us.
  • (c) Our Privacy Officer shall endeavour to:
    • (i) respond to you within 10 business days; and
    • (ii) investigate and attempt to resolve your concerns within 30 business days or any longer period necessary and notified to you by our Privacy Officer.
  • (d) If you are dissatisfied with the outcome of your complaint, you may refer the complaint to the Office of the Australian Information Commissioner.

18. CONTACT US