Last updated: July 2018
Contacta Pty Limited, ABN 65 624 829 214 of 51 Victoria Crescent, Abbotsford Victoria, Australia 3067 and its affiliates (“we“, “us“, “our” or “Contacta“) is responsible for your personal information and we understand that the privacy of your personal information is important to you. We also understand that providing your personal information to us is an act of trust. We take a meeting that trust very seriously.
We provide a range of marketing and promotion tools to our customers and partners, which involve the collection and storage of your personal information. These tools include an online marketing platform which enables our customers and partners to target-market their products and services to you.
For the purposes of relevant data protection laws (including the EU General Data Protection Regulation (GDPR)), the Contacta entity with whom you primarily do business (for example, if you are a supplier, the Contacta entity to whom you provide services, or if you are a website visitor, the Contacta entity operating the relevant website) will be the primary data controller of your personal information.
This Policy explains how we collect, use and share personal information in the course of our business activities, including:
We may amend this Policy from time to time to keep it up to date with legal requirements and the way we operate our business and will place any updates on this webpage. Please regularly check these pages for the latest version of this notice. If we make fundamental changes to this Policy, we will seek to inform you by notice on our website or email.
Third Party Websites
Persons We Collect Information From
Primarily, we collect personal information from you if you are:
The Policy applies to your personal information collected on our marketing platform and website in order to contribute to our marketing platform, as well as personal information provided to us by our data suppliers, and provided by our Customers and Partners to enable us to provide our services to them and so that they can market their services to you (known as third-party-provided information).
What personal information does Contacta collect and process?
The kinds of personal information that we collect are generally categorised as follows:
Aggregated Data Analytics: We routinely analyse information in our various systems and databases to help improve the way we run our business, to provide a better service and to enhance the accuracy of our products and services. We therefore collect, use and share data for analytics purposes aggregated and anonymised data (“Aggregated Data’) including statistical or demographic data for any purpose. Aggregated Data may be derived from your customer personal data but is not considered personal data in law as this data does not directly or indirectly identify you or reveal your identity. For example, we may aggregate your usage data to calculate the percentage of users accessing a specific website feature. However, if we combine Aggregated Data with your personal data such that we identify you or your identity is revealed, we will treat this combined data as person data to be used in accordance always with this Policy.
Cookies, Web Beacons and other Tracking Technologies
For which purposes does Contacta collect and Process personal information?
We use and process personal information for the following purposes:
For example: If you have previously indicated that your birthday is in the month of May when you visit a hotel or travel package online, the hotel or online travel company can send you a birthday offer of their services with specialised discounts.
For EU/UK individuals – Legal basis for using your personal information
For information collected about you in the European Union or the United Kingdom, which is subject to the EU General Data Protection Regulation (GDPR), we will only collect, use and share your personal information where we are satisfied that we have an appropriate legal basis to do this. This may be because:
If you would like to find out more about the legal basis for which we process personal information please contact us for more information.
Direct marketing by MGL and how do I opt out of direct marketing
In addition to the services, we provide on behalf of our Customers and Partners we may also use your personal information to let you know about our products, offers, services and competitions that we believe will be of interest to you. We may contact you by email, post, or telephone or through other communication channels that we think you may find helpful. In all cases, we will respect your preferences for how you would like us to manage marketing activity with you.
We will only engage in direct marketing in accordance with the laws of the relevant country or jurisdiction you are located in.
To protect privacy rights and to ensure you have control over how we manage marketing with you:
We recommend you routinely review the privacy notices and preference settings that are available to you on any social media platforms as well as your preferences within your account with us.
When and how we carry out profiling
We may use profiling for security purposes to assess if your (online) account with us may be fraudulent, a spam account or suspect in any way. We may also associate your personal information with interest segments or profiles as part of the provision of our online marketing platform services to our Customers and Partners. Interest segments mean a subgroup of specific consumers or individuals who share a common behaviour or preference used for direct marketing by our Customers and/or Partners. Profiling means processing information about a specific consumer or device, or a set of multiple consumers or devices sharing common attributes used for marketing by our Customers and/or Partners. In certain cases, you have a right to object to the processing of your information used for profiling as further explained in the Legal Rights section below.
Who does Contacta disclose or share personal information with?
We share your personal information in the manner and for the purposes described below:
Does Contacta disclose personal information to overseas recipients?
We disclose personal information to recipients located overseas. For instance, we store, and back up to mitigate risks associated with hardware failure, all of the personal information we hold on our servers hosted by AWS who are located in the United States of America (USA). We take reasonable steps to ensure that the personal information stored offshore is handled in accordance with strict privacy safeguards.
For information collected about you in the European Union or the United Kingdom, which is subject to the GDPR you should note that countries such as the USA and Canada are subject to different standards of data protection.
We will take appropriate steps ensure that transfers of personal information are in accordance with applicable law and carefully managed to protect your privacy rights and interests and transfers are limited to countries which are recognized as providing an adequate level of legal protection or where we can be satisfied that alternative arrangement is in place to protect your privacy rights. To this end:
You have a right to contact us for more information about the safeguards we have put in place (including a copy of relevant contractual commitments) to ensure the adequate protection of your personal information when this is transferred as mentioned above.
Security and storage of personal information
We take all reasonable steps and measures to ensure that the personal information we hold about you is kept secure at all times.
For information collected about you in the European Union or the United Kingdom, which is subject to the GDPR, you should note that some of the measures we take include:
As the security of information depends in part on the security of the computer or device you use to communicate with us and the security you use to protect User IDs and passwords, please take appropriate measures to protect this information.
You acknowledge that the internet is not a completely secure medium for communications, and accordingly, we cannot guarantee the security of any information you send to us (or we send to you) or your place on our website or via the internet. We are not responsible for any damages which you or others may suffer as a result of the loss of confidentiality of such information.
Storing your personal information
To determine the appropriate retention periods, we consider the amount, nature and sensitivity of the personal data potential risk of harm from unauthorised use or disclosures the purposes for which we process your personal information and whether we can achieve those purposes through other means and the applicable legal requirements. In some circumstances, we may store your personal information for longer periods of time than others; for instance where we are required to do so in accordance with legal, regulatory, tax, accounting requirements.
How can you access and correct the personal information Contacta holds about you?
You may access or request correction of the personal information that we hold about you by contacting us. We will respond to your request within a reasonable timeframe. There are some circumstances in which we are not required to give you access to your personal information.
As we also provide a service for our Customers and Partners to securely store their data, depending upon the nature of your request, we may need to direct your enquiry to our relevant Customer or Partner to provide you with access to the information you request.
If you reside in Australia then, in accordance with the provisions of the Australian Privacy Act 1988 (Cth), we can make your personal information accessible to you by providing you with a copy of the relevant information (ordinarily in the form of an electronic printout or photocopy). Please note that we may charge you a fee for the reasonable cost of providing such access.
We will take reasonable steps to ensure that the information we have about you is accurate, complete, relevant and up to date when we collect and use it. To this end, we may, from time to time, contact you in regards to keeping this data accurate and up to date.
For EU / UK individuals – Legal Rights
For information collected about you in the European Union or the United Kingdom, which is subject to the GDPR, there are additional rights available to you. Subject to certain exemptions, and in some cases dependent upon the processing activity we are undertaking, you have certain rights in relation to your personal information. Click on the links below to learn more about each right you may have:
If you wish to access any of the above-mentioned rights, we may ask you for additional information to confirm your identity and for security purposes, in particular before disclosing personal information to you. We reserve the right to charge a fee where permitted by law, for instance, if your request is manifestly unfounded or excessive.
You can exercise your rights by contacting us. Subject to legal and other permissible considerations, we will make every reasonable effort to honour your request promptly or inform you if we require further information in order to fulfil your request.
We may not always be able to fully address your request, for example, if it would impact the duty of confidentiality we owe to others, or if we are legally entitled to deal with the request in a different way.
Right to access personal information
You have a right to request that we provide you with a copy of your personal information that we hold and you have the right to be informed of; (a) the source of your personal information; (b) the purposes, legal basis and methods of processing; (c) the data controller’s identity; and (d) the entities or categories of entities to whom your personal information may be transferred.
Right to rectify or erase personal information
You have a right to request that we rectify inaccurate personal information. We may seek to verify the accuracy of the personal information before rectifying it.
You can also request that we erase your personal information in limited circumstances where:
We are not required to comply with your request to erase personal information if the processing of your personal information is necessary:
Right to restrict the processing of your personal information
You can ask us to restrict your personal information, but only where:
We can continue to use your personal information following a request for the restriction, where:
Right to transfer your personal information
You can ask us to provide your personal information to you in a structured, commonly used, machine-readable format, or you can ask to have it transferred directly to another data controller, but in each case only where:
Right to object to the processing of your personal information
You can object to any processing of your personal information which has our legitimate interests as its legal basis if you believe your fundamental rights and freedoms outweigh our legitimate interests.
If you raise an objection, we have an opportunity to demonstrate that we have compelling legitimate interests which override your rights and freedoms.
Right to object to how we use your personal information for direct marketing purposes
You can request that we change any manner in which we contact you for marketing purposes.
You can request that we not transfer your personal information to unaffiliated third parties for the purposes of direct marketing or any other purposes.
Right to obtain a copy of personal information safeguards used for transfers outside your jurisdiction
You can ask to obtain a copy of, or reference to, the safeguards under which your personal information is transferred outside of the European Union.
We may redact data transfer agreements to protect commercial terms.
Right to lodge a complaint with your local supervisory authority
You have a right to lodge a complaint with your local supervisory authority if you have concerns about how we are processing your personal information.
We ask that you please attempt to resolve any issues with us first, although you have a right to contact your regulator / supervisory authority at any time.
How can you make a complaint or contact us?
You have the right to make a complaint about the way we handle your personal information. If you wish to make a complaint, please set it out in writing and send it to email@example.com.
If you have any questions, concerns or complaints regarding our compliance with this Policy, the information we hold about you or if you wish to exercise your rights, we encourage you to first contact us at the above email address.
We will deal with all complaints within a reasonable timeframe.
If you are not satisfied with our response, you have a right to lodge a complaint with your local regulator including, if you are in the EU / UK, your local data protection supervisory authority (i.e. your place of habitual residence, place of work or place of alleged infringement)
If you are located in Australia, you can contact the Office of the Australian Information Commissioner at www.oaic.gov.au.