1.1 In this Policy, Flowtherm, we, our or us is a reference to Flowtherm Australia Pty Ltd (ACN 096 858 909).
1.2 Personal information is any information about you where your identity is apparent, or can reasonably be ascertained, and may include Sensitive Information (defined below).
1.3 Sensitive Information is information or an opinion about a person’s racial or ethnic origin, political opinions, membership of a political association, religious beliefs or affiliations, philosophical beliefs, sexual preferences, health or medical information or criminal records.
2. What this Policy is about
2.2 This Policy covers Personal Information collected directly on our website (https://www.flowtherm.com.au/) and via email or telephone (collectively Website) from individuals who enquire about, access, register for, or use our services (Services).
2.3 We endorse fair information handling practices and uses of information in compliance with our obligations under the privacy laws in force in Australia from time to time. Any information provided, including identification of individuals, will be used only for the purpose(s) intended and where the intention includes confidentiality, information will be treated as such unless otherwise required by law.
2.4 This Policy represents the default position that Flowtherm will take in its treatment of Personal Information. Flowtherm will treat all Personal Information in a manner consistent with this Policy unless you have provided your express consent otherwise.
2.5 If there is any inconsistency between the Privacy Act and this Policy, this Policy shall be read and interpreted to comply with the Privacy Act.
3. Other Policies and Terms and Conditions
3.1 Your use of our Website is subject to our terms and conditions. The terms and conditions for your use of our Website may be found here: Click Here
4. Collection of Personal Information
4.1 Flowtherm collects the following Personal Information of users or prospective users of the Services:
- phone number; and
- email address.
4.2 Flowtherm collects Personal Information about our employees, contractors and job applicants, including name, address, contact details and work experience.
4.3 Personal Information will be typically collected when provided directly to Flowtherm by you:
- when you contact us through an online form on our Website or by email;
- when you contact us through our live chat function on our Website;
- during phone calls or other communications between you and us;
- when you contact or communicate with us by any other means.
4.4 Flowtherm may collect Personal Information indirectly from third parties who provide lead generation services such as Linkedin.
4.5 Our Website automatically collects anonymous usage data about visitors, including the URL that the visitor came from, the browser being used and the IP address. This data is utilised to improve the services of Flowtherm and does not include any personally identifying information.
4.6 Flowtherm also reserves the right to collect anonymous usage data through other websites and online systems in order to provide our customers with a better user experience. This data does not include any personally identifying information.
4.7 ‘Cookies’ are alphanumeric identifiers that are stored by the web browser on a computer’s hard-drive that enable our system to recognise a visitor to our Website. This helps Flowtherm to track basic visitor information for the purposes of optimising the design of our systems and marketing activities.
4.8 Most web browsers automatically accept cookies and this function can be disabled by changing the browser settings of the user.
4.9 Please note that the Website may contain links to other websites which are not hosted or operated by Flowtherm. Flowtherm is not responsible for the privacy policies of such other websites and you should independently review the privacy policies on such websites.
5. Underage User information
5.1 We are obligated to comply with the Mandatory Vaccination Directions which commenced on 7 October 2021 (Directions) imposed by the Victorian Government under emergency powers arising from the declared state of emergency in Victoria. In accordance with the Directions, we must collect and store COVID-19 vaccination information from employees and contractors. We acknowledge that this information is classified as ‘sensitive information’ under the Act. Employees and contractors will be asked to provide their vaccination information to us, which will be recorded and stored in accordance with this policy.
5.2 In accordance with the Act, and notwithstanding any other provision of this policy, we will not disclose your vaccination information to any third party without obtaining your prior written consent.
6. Underage User information
6.1 We do not intentionally collect Personal Information of individuals below the age of 18 (Underage User).
6.2 If you believe an Underage User has provided Personal Information and wish that it be deleted, please contact our Privacy Officer, details of which are set out in clause 0 of this Policy, and we will delete it within 30 days.
7. Use of Personal Information
7.1 Flowtherm uses Personal Information in the following ways:
- to assist us in providing the Services to you;
- for our own internal administration purposes, for example entering into employment contracts, processing payroll and recruiting new staff;
- for sending occasional marketing materials to you; and
- other marketing and remarketing purposes.
7.2 We may also use Personal Information we collect for related purposes such as:
- to record information about your usage, preferences and behaviour in relation to the Services, as well as any feedback provided by you;
- when combined with the deidentified Personal Information of other users (in which case such combined information will no longer be personal) to analyse and develop products and services that suit our users;
- to perform statistical analyses of user behaviour;
- to optimise marketing activities, user experience, and content;
- any other use for which we obtain permission from you.
7.3 We do not pass on any Personal Information to a third party except in accordance with this Policy.
7.4 As a user of the Services, you may occasionally receive email, promotional material or other updates from us about new information, briefings or products or services being offered by Flowtherm, or any of its related companies or business partners, along with newsletters and any noteworthy changes to the Website. You may always opt out from receiving these promotional/marketing update messages by contacting our Privacy Officer.
8. Disclosure of Personal Information
8.1 We may share Personal Information with employees, service providers (for example our IT service providers or couriers), suppliers and affiliates of Flowtherm on a need to know basis to allow the provision of the Services to you as requested by you. Access to Personal Information by these people is subject to such people protecting your Personal Information to at least the degree set out in this Policy, and such access will be revoked within a reasonable timeframe of access no longer being required. To the extent that these organisations and service providers gain access to Personal Information, their use is governed by their own privacy policies, the Privacy Act, GDPR and any other relevant law.
8.2 Other than disclosure of Personal Information of service providers (as set out above) or as required by law, our policy is that we do not give Personal Information to other organisations unless we have disclosed the use in this Policy or you have expressly consented for us to do so.
8.3 Occasionally, Flowtherm might also use Personal Information for other purposes or share Personal Information with another organisation because:
- we believe it is necessary to protect your rights, property or personal safety;
- we believe it is necessary to do so to prevent or help detect fraud or serious credit infringements – for example, we may share information with credit reporting agencies, law enforcement agencies and fraud prevention units; or
- we believe it is necessary to protect the interests of Flowtherm – for example, disclosure to a Court in the event of legal action to which Flowtherm is a party.
8.4 In the event that the Flowtherm is sold, the data, including your Personal Information may be transferred to the purchasing entity which would be bound to comply with the Privacy Act in relation to the access, storage and use of your Personal Information. Further, in circumstances where Flowtherm is merged with another entity, the data, including your Personal Information, may be transferred to that entity, which would be bound to comply with the Privacy Act in relation to the access, storage and use of your Personal Information. Your Personal Information would not be disclosed to a buyer in either circumstance, other than as a part of the transfer of all data related to the Website to that buyer.
9. Confidentiality and Data Security
9.1 All Personal Information collected is stored on secure cloud servers provided by Nexis ICT Pty Ltd in a Tier 4 data centre in Kilsyth, Victoria operated by Micron 21 Data Centre Pty Ltd.
9.2 The cloud server is protected with Barracuda Application Aware firewall, runs automated fully patched Windows operating system and has cloud-controlled Web Root Antivirus software installed.
9.3 We take all reasonable steps to manage data stored by us to ensure data security and to prevent the loss, misuse or alteration of Personal Information. Notwithstanding the above, Flowtherm is not responsible for any third-party access to Personal Information as a result of:
- interception while it is in transit over the internet;
- an unpatched vulnerability, a zero-day vulnerability, or an attack within 48 hours of a vendor releasing a patch or update;
- spyware or viruses on the device (such as a computer or phone) from which you access our Website or otherwise contact us; or
- as a result of your failure to adequately protect your username or password (if applicable).
9.4 Flowtherm is also not responsible for any losses, expenses, damages and costs, including legal fees, resulting from such third-party access.
9.5 If we have reasonable grounds to believe that your Personal Information that we hold may be subject to unauthorised access or disclosure (eligible data breach), we will investigate and assess the suspected eligible data breach to determine whether the eligible data breach is likely to result in serious harm to you (Notifiable Data Breach). If a Notifiable Data Breach occurs, then we will notify you and the Australian Information Commissioner as soon as practicable after we become aware of the Notifiable Data Breach in accordance with our obligations under the Privacy Act. We will comply in every way with our obligations under Part IIIC – “notification of eligible data breaches” of the Privacy Act.
10. Retention and Disposal of Personal Information
10.1 We will retain Personal Information for as long as is required for us to fulfil the purposes for which the Personal Information was collected, including where applicable to provide you with the Services and to comply with legal requirements.
10.2 If we no longer require Personal Information for any purpose, including legal purposes, we will take reasonable steps to securely destroy or permanently de-identify the Personal Information.
11. Access to Personal Information
11.1 You can access the Personal Information held about you at any time by contacting our Privacy Officer.
11.2 We will always endeavour to meet requests for access. However, in some circumstances we may decline a request for access. This includes the following circumstances:
- we no longer hold or use the information;
- providing access would have an unreasonable impact on the privacy of other persons;
- the request is frivolous or vexatious;
- the information relates to existing or anticipated legal proceedings and would not normally be disclosed as part of those proceedings;
- providing access would be unlawful;
- providing access would be likely to prejudice the detection, prevention, investigation and prosecution of possible unlawful activity; or
- the information would reveal Flowtherm’s commercially sensitive information.
11.3 If we decline a request for access, we will provide reasons for our decision when we respond to the request.
11.4 We reserve the right to charge you a reasonable fee for access to your Personal Information. These charges will be limited to the cost of recouping our expenses for providing you with your Personal Information, such as document retrieval, photocopying, labour and delivery.
11.5 Despite anything contained in this Policy to the contrary, if the Freedom of Information Act 1982 applies to a person on whose behalf we hold Personal Information, the access and correction requirements in the Privacy Act operate alongside and do not replace other informal or legal procedures by which an individual can be provided access to, or correction of, their Personal Information.
12. Changing or deleting Personal Information
12.1 We will take reasonable steps to ensure that Personal Information is accurate, complete and up-to-date at the time of collecting the Personal Information from you, using or disclosing the Personal Information, or during other interactions with you or suppliers in accordance with this Policy.
12.2 If you believe that any Personal Information that we hold about you is inaccurate, incomplete or out-of-date, you may contact our Privacy Officer.
12.3 We will do our best to correct any Personal Information that is inaccurate, incomplete or out-of-date or dispose of it in accordance with this Policy.
13.2 If you have a complaint in relation to the way your Personal Information has been handled by Flowtherm, the complaint should be made in writing to our Privacy Officer in the first instance. Flowtherm will investigate the complaint and prepare a response to you in writing within a reasonable period of time.
13.3 Our Privacy Officer can be contacted by:
– Email: firstname.lastname@example.org
From time to time, our policies will be reviewed and may be revised.
Flowtherm reserves the right to change this Policy at any time.