Dystech Australia Pty Ltd (ACN 617 116 518) (“we”, “us” or “our”) of Shop 1, 19-23 Seymour Street, Traralgon VIC 3844, and the operation of the website at www.dystech.com.au (“Website”) and mobile application (“Application”)(collectively, the “Platform”) is committed to respecting your privacy.
- Openness and transparency
We are committed to protecting your privacy, and upholding your rights under the Australian Privacy Principles (“APPs”) contained in the Privacy Act 1988 (Cth) (“Privacy Act”) and the General Data Protection Regulation (EU 2016/679) (the “GDPR”) (collectively, “Privacy Laws”). We are a data controller for the purposes of the GDPR. We ensure that we will take all necessary and reasonable steps to comply with the relevant Privacy Laws and to deal with inquiries or complaints from individuals about compliance with the relevant Privacy Laws.
- Section 6 of the Privacy Act defines ‘Personal Information’ as ‘information or an opinion about an identified individual, or an individual who is reasonably identifiable’. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
- Your Personal Information:
We will collect Personal Information only by lawful and fair means, and not in an unreasonably intrusive way.
We will only collect Personal Information about you if you voluntarily provide it to us or if you explicitly give consent to us collecting it. If you provide us with Personal Information, this will constitute your consent.
We may also collect Personal Information from you when you fill in an application form, register an Account with us, use our Services, communicate with us, visit our Platform, provide us with feedback or complete online surveys. We may collect Personal Information about you that you have provided to our business partners or from third parties, and in respect of which you have given the third party permission to share with us.
If you use a pseudonym when dealing with us or you do not provide identifiable information to us, we may not be able to provide you with any or all of our Services as requested. If you wish to remain anonymous when you use our Platform, do not sign into it or provide any information that might identify you.
We require individuals to provide accurate, up to date and complete Personal Information at the time it is collected.
- Information we may collect
- The type of Personal Information we collect from a User of the Platform (such as you) includes, without limitation, the following:
- your full name;
- email address;
- phone number;
- your device ID, device type, geo-location information, computer and connection information, statistics on page views, traffic to and from the sites, ad data, IP address and standard web log information;
- any additional information relating to you that you provide to us directly through our Platform or indirectly through your use of our website or app or online presence or through other websites or accounts from which you permit us to collect information;
- information you provide to us through customer surveys;
- billing and payment method information; and/or
- any other Personal Information that may be required in order to facilitate your dealings with us.
(collectively, the “Personal Information”).
- “De-identified Data” or “De-identifiable Data” refers to data in respect of which all personally identifiable information has been removed and/or anonymised, so that the information is no longer identifiable as belonging or relating to a reasonably identifiable individual.
- We collect both Personal Information and De-Identified Data from Users of the Platform. The type of information we collect specifically about each Assessee when producing Reports is De-identifiable Data and includes, but is not limited to, information relating to the Assessee’s:
- language skills;
- writing and comprehension abilities;
- experience with learning difficulties such as dyslexia, dyscalculia and dysgraphia;
- experience with visual and hearing impairments; and
- other relevant information to provide Reports and Services on our Platform.
- What is our legal basis?
- Under applicable Privacy Laws, including the GDPR, we must have a legal basis to process Personal Information collected from individuals, including sharing such information with third parties. We rely on several legal bases to collect, process and share your Personal Information, including:
- where it is necessary to provide the User and/or Assessee with access to, and use of our Platform and Services;
- for our legitimate interests in providing, operating and improving our Platform and Services;
- in accordance with a User’s or Assessee’s consent to the collection and processing of Personal Information by us, and such consent must be freely and expressly given and may be withdrawn at any time; or
- where we are under a legal obligation to collect and/or process such Personal Information.
- How your information is used
- We use, process and disclose your Personal Information for the purposes for which the information is collected, or for a directly related purpose, including (but not limited to):
- providing our Platform and Services to you;
- providing you with Reports;
- administering, protecting, improving or optimising our Platform, products and services (including performing data analytics, conducting research and for advertising and marketing purposes);
- creating industry reports from de-identified data;
- informing you about our Platform, products, memberships, services, surveys, contests or other promotional activities or events sponsored or managed by us;
- responding to any inquiries or comments that you submit to us;
- verifying your identity;
- any other purpose you have consented to; and
- any use which is required or authorised by a relevant Privacy Law.
- Where we:
- have your express consent (which you may withdraw at any time by contacting us in writing at email@example.com);
- have a legal basis; or
- are otherwise permitted by relevant Privacy Laws,
we may use and process your Personal Information to send you information about Services we believe are suited to you and your interests or we may invite you to attend special events.
- At any time, you may opt out of receiving direct marketing communications from us. Unless you opt out, your consent to receive direct marketing communications from us and to the handling of your Personal Information as detailed above will continue. You can opt out by following the unsubscribe instructions included in the relevant marketing communication, or by contacting us in writing at firstname.lastname@example.org.
- Disclosure of Personal Information
- We may disclose your Personal Information to third party recipients located in or outside of the European Economic Area and Australia.
- We may disclose your Personal Information to:
- third parties we ordinarily engage from time to time to perform functions on our behalf for the above purposes;
- any person or entity to whom you have expressly consented to us disclosing your Personal Information to;
- our external business advisors, auditors, lawyers, insurers and financiers;
- our payment processing service provider Stripe; and
- any person or entity to whom we are required or authorised to disclose your Personal Information to in accordance with the relevant Privacy Laws.
- Dystech Platform
- When transmitting Personal Information from your computer to our Platform, you must keep in mind that the transmission of information over the internet is not always completely secure or error-free. Other than liability that cannot lawfully be excluded, we will not be liable in any way in relation to any breach of security or any unintended loss or disclosure of that information.
- Our Platform may use 'cookies' or other similar tracking technologies that help us track your usage and remember your preferences. Cookies are small files that store information on your computer, TV, mobile phone or other device. They enable the entity that put the cookie on your device to recognise you across different websites, services, devices and/or browsing sessions. You can disable cookies through your internet browser but if you do so, you may not be able to fully experience the interactive features of our Platform.
- Security and Data Storage
- We may hold and store your Personal Information in either electronic or hard copy. We take reasonable steps to protect such Personal Information from misuse, interference and loss, as well as unauthorised access, modification or disclosure and we use a number of physical, administrative, personnel and technical measures to protect Personal Information. For example, our security is managed by Amazon Web Services (“AWS”) and we utilise SSL/TLS across all our cloud hosting infrastructure for the transmission of Personal Information. Further all Personal Information is stored on AWS secure servers which are fully encrypted.
- However, we cannot guarantee the security of any Personal Information transmitted over the internet and therefore you disclose information to us at your own risk. We will not be liable for any unauthorised access, modification or disclosure, or misuse of your Personal Information
- Under the GDPR, an individual residing in the European Union has enhanced privacy rights, including the right to:
- require us to correct any Personal Information held about that individual that is inaccurate or incomplete;
- require the deletion of Personal Information concerning that individual in certain situations;
- data portability for Personal Information provided to us by that individual;
- object or withdraw consent to the processing of their Personal Information at any time;
- object to decisions being taken by automated means which produce legal effects concerning, or significantly affecting them; or
- otherwise restrict our processing of their Personal Information in certain circumstances.
- Subject to some exceptions provided by the relevant Privacy Laws, you may request access to your Personal Information in our customer account database or seek a correction to such information, by contacting us in accordance with clause 11 below. Should we decline your request to access some Personal Information, we will provide a written explanation setting out our reasons for doing so.
- We may charge a reasonable fee that is not excessive to cover the charges of retrieving your Personal Information from our customer account database. However, we will not charge you for making the request.
- If you believe that we hold Personal Information about you that is not accurate, complete or up-to-date then you may request that your Personal Information be corrected. We will respond to your request to correct your Personal Information within a reasonable timeframe and we will not charge you a fee for correcting your Personal Information.
- Contact information and complaints
- If we receive a formal written complaint about our privacy practises, we will contact the complainant regarding his or her concerns and attempt to resolve the complaint as soon as possible.
- If you are dissatisfied with the outcome of our handling of your complaint, you can lodge a privacy complaint with the Office of the Australian Information Commissioner (“OIAC”) or the European Data Protection Supervisor (“EDPS”). For further information about the EDPS or OAIC’s privacy complaint handling process, please see: http://www.oaic.gov.au/privacy/making-a-privacy-complaint or https://edps.europa.eu/node/75_en.
- Notices and Revisions
- We will cooperate with the appropriate regulatory authorities, including local data protection authorities, to resolve any complaints regarding the transfer of personally identifiable information that cannot be resolved between us and the individual.
Dated: 26 August 2020