What does “personal information” mean?
Personal information is any information about you that identifies you or by which your identity may be reasonably determined.
What personal information do we collect?
HECSA may collect personal information and sensitive information about you. The kind of personal information we collect and hold is that in which you tell us when completing an application or otherwise when you specifically provide us with it. The types of information include:
- mailing or street address;
- email address;
- telephone number and other contact details;
- details of the goods we have provided to you or that you have enquired about, including any additional information necessary to deliver those goods and respond to your enquiries;
- any additional information relating to you that you provide to us directly through our website or indirectly through your use of our website or online presence or through other websites or accounts from which you permit us to collect information;
- information you provide to us through customer surveys; or
- any other personal information that may be required to facilitate our dealings with you or your dealings with us.
What does “sensitive information” mean?
Certain information which may be collected by HECSA will be regarded as sensitive information. Sensitive information includes information or an opinion about an individual’s race, religion, political or trade association, among others. The disclosure of sensitive information can only be made by HECSA with your direct consent, where it is required by law to be disclosed or if the information is reasonably necessary for us to provide our services.
How does HECSA collect your personal information?
We will always collect your personal information directly from you where possible. Where we are unable to obtain personal information directly from you we will obtain your consent before information is obtained from another party.
Collection of your personal information may occur in a number of ways including:
- website interactions;
- credit reporting agencies;
- telephone conversations; and
- in person.
How does HECSA hold your personal information
We hold personal information:
- physically on our premises; and
- on internal servers; and
- where you utilise certain services from our website hecsa.com.au, with a third party data storage provider in United State of America (currently Amazon AWS Servers).
The purpose of collecting and using your personal information
We collect your personal information for purposes including:
- supplying to you the goods in which you have requested;
- sending you statements and invoices and collecting payments from you;
- enabling access to website services;
- conducting feedback surveys;
- sending to you marketing communications.
Who does HECSA disclose your personal information to?
We may disclose your personal information to a person outside of HECSA:
- where necessary in connection with the purpose for which it was collected;
- if required by law;
- if you consent to the disclosure; or
- otherwise as permitted by the Privacy Act 1988 (Cth).
Does HECSA transfer any of your data overseas?
Your personal information will not be disclosed to recipients outside Australia unless you expressly request us to do so. If you request us to transfer your personal information to an overseas recipient, the overseas recipient will not be required to comply with the APPs and we will not be liable for any mishandling of your information in such circumstances.
Accessing your personal information
APP 12 permits you to obtain access to the personal information we hold about you in certain circumstances, and APP 13 allows you to correct inaccurate personal information subject to certain exceptions. If you would like to obtain such access, please contact HECSA by:
- phone on 1300 087 786;
- email on email@example.com; or
- in writing at PO Box 894, Oxenford QLD 4210.
HECSA may from time to time use your personal information, such as your address or contact details, to provide you with information about other goods that we offer.
If at any time you do not wish to receive any information about these goods or services, please feel free to contact us on 1300 087 786 or at firstname.lastname@example.org and we will not send you any further material.
Complaints about breaches of privacy
- emailing 1300 087 786;
- phoning email@example.com; or
- posting to PO Box 894, Oxenford QLD 4210.
HECSA will, within 30 days, respond to you and attempt to resolve with you your issues as they pertain to your personal information.
If you are not satisfied with the response you receive from HECSA, you may contact the Australian Information Commissioner and Privacy Commissioner by:
- sending a letter to the Director of Privacy Case Management, Office of the Australian Information Commissioner, GPO Box 5218, Sydney NSW 2001;
- using the online Privacy Complaint Form located at www.oaic.gov.au;
- emailing your complaint to firstname.lastname@example.org; or
- faxing your complaint to 02 9284 9666.