This Privacy Policy explains how ACT Plasterboard Pty Ltd, 151 324 748 trading as Plastamasta Canberra and its related bodies corporate (as defined in the Corporations Act 2001 (Cth)) (we, us or our) collect, hold, use, disclose and otherwise handle personal information.
Where the Privacy Act 1988 (Cth) (Privacy Act) applies to our handling of personal information, we will handle that information in accordance with the Privacy Act, including the Australian Privacy Principles (APPs).
By completing a credit application, entering into contracts with us (including a personal guarantee and indemnity), using our website or otherwise providing us with your personal information, you acknowledge and agree that your personal information will be collected, used, disclosed and otherwise handled in accordance with this Privacy Policy. We may update this Privacy Policy from time to time. The current version will be made available on request and, where applicable, on our website.
What is personal information?
Personal information means information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether the information or opinion is true or not and whether or not it is recorded in a material form.
The kinds of personal information we collect and hold
The kinds of personal information we may collect and hold depend on the nature of your dealings with us and may include:
-
- Identity and contact details, such as your name, business name, residential or business address, telephone number, email address and date of birth;
- Details relating to your dealings with us, including enquiries, orders, returns, payment history, account details and correspondence;
- Information supplied in credit applications, personal guarantees, references or supporting documents;
- Information required to verify your identity or authority to act on behalf of another person or entity;
- Website, device and usage information collected when you interact with our website, emails or online services, including IP address, browser type, pages viewed and cookie data;
- Recruitment or employment-related information if you apply for a role with us; and
- Any other personal information reasonably necessary for our functions and activities or otherwise permitted by law.
How we collect and hold personal information
We collect personal information in a number of ways, including when you:
-
- Complete forms, including account applications, personal guarantees, quote requests, order forms, warranty claims or other documents;
- Communicate with us by phone, email, post, through our website, social media or in person;
- Purchase, return or enquire about goods or services;
- Subscribe to updates, marketing communications or mailing lists;
- Apply for employment or make an employment-related enquiry; or
- Otherwise interact with us in connection with our business
Where reasonable and practicable, we collect personal information directly from you. In some circumstances, we may collect personal information from third parties, including your representatives, referees, agents, contractors, service providers, related bodies corporate, publicly available sources and other persons or organisations involved in providing goods, services or credit to you.
If you choose not to provide requested personal information, we may be unable to provide you with goods, services, credit, account facilities, access to certain website functions, or other assistance.
Unsolicited information
If we receive personal information that we did not solicit and we determine that we could not have collected that information under the Privacy Act (and it is not contained in a Commonwealth record), we will, where lawful and reasonable, destroy or de-identify that information as soon as practicable.
Anonymity and Pseudonymity
Where lawful and practicable, you may deal with us anonymously or by using a pseudonym. However, this will often be impracticable where we need to verify your identity, process an order, provide credit, manage an account, respond to a complaint, or comply with legal obligations.
Website information, cookies and analytics
When you visit our website or interact with our electronic communications, we and our service providers may collect technical and usage information using cookies, web beacons, analytics tools and similar technologies. This helps us operate, secure and improve our website and services, analyse traffic and user behaviour, and tailor content.
You can usually adjust your browser settings to refuse cookies, but some functions may not work properly if you do so.
Why we collect, hold, use and disclose personal information
We may collect, hold, use and disclose personal information for purposes including:
-
- Supplying goods and services, administering accounts and processing payments, refunds or claims;
- Assessing applications, including trade credit applications and guarantees, and managing credit or account facilities;
- Communicating with you about our goods, services, accounts and business activities
- Verifying identity, authority and instructions
- Conducting due diligence, risk management, fraud prevention, debt recovery and enforcement activities;
- Obtaining professional advice and managing insurance, legal, compliance and regulatory matters;
- Recruitment and employment administration;
- Improving our business systems, website and customer experience;
- Direct marketing in accordance with applicable law; and
- Any other purpose permitted or required by law or otherwise notified to you at the time of collection.
Disclosure of personal information
Depending on the circumstances, we may disclose personal information to:
-
- Our related bodies corporate, employees, agents, contractors and advisers;
- Third party service providers who assist us with information technology, cloud hosting, data storage, payment processing, marketing, administration, security, recruitment, logistics, debt recovery or other business functions;
- Insurers, insurance brokers, financiers, professional advisers and auditors;
- Credit reporting bodies (discussed below), other credit providers, guarantors and trade references where you apply for or obtain credit and the disclosure is permitted by law;
- Courts, tribunals, regulators, government agencies, law enforcement bodies and other persons where disclosure is required or authorised by law; and
- Any other person or entity with your consent or where otherwise permitted by law.
We are likely to disclose credit-related information to the following credit reporting bodies and their successors and assigns:
-
- Equifax Australia, GPO Box 964, North Sydney NSW 2059, www.equifax.com.au, 138 332
- Creditor Watch, GPO Box 276, Sydney NSW 2001, creditorwatch.com.au, 1300 501 312
- Experian, PO Box 7405, St Kilda Road, Melbourne Vic 3004, www.experian.com.au, 1300 783 684
- CMSA Pty Ltd, STE 203, 91–99 Mann Street, Gosford NSW 2250, www.cmsa.au, (02) 4322 6855
- NCI, PO Box 3315, Rundle Mall SA 5000, nci.com.au, 1800 882 820
Direct marketing
We may use your personal information to send you information about our products, services or promotions where permitted by law. You may opt out of receiving marketing communications at any time by using the unsubscribe facility in the communication (if applicable), contacting us using the details below, or otherwise asking us not to send you marketing material. We will action your request within a reasonable time.
Overseas disclosure
We do not usually disclose personal information to recipients located outside Australia. However, some service providers that assist with technology, data storage or administration may have overseas operations or access. Where we disclose credit-related information overseas, we will do so only as permitted by law and will take reasonable steps to ensure the information is handled appropriately.
Security and retention
We take reasonable steps in the circumstances to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure. Those steps may include physical, administrative and technical safeguards such as access controls, password protection, secure storage, staff training, and secure destruction processes.
We retain personal information only for as long as reasonably necessary for our business purposes and to comply with legal, accounting and record-keeping obligations. When personal information is no longer required, we will take reasonable steps to destroy it or permanently de-identify it, unless we are required or authorised by law to retain it.
If we experience an eligible data breach under the Privacy Act, we will comply with our notification obligations under the Notifiable Data Breaches scheme.
Use of AI-enabled tools and automated systems
We may use AI-enabled tools, automated systems and third-party technology providers to assist us in carrying out our business functions and activities. This may include using those tools to help us process applications, assess information, communicate with customers, respond to enquiries, review documents, detect risks, improve our systems and maintain the quality, security and efficiency of our services.
Access to personal information
You may request access to the personal information we hold about you by contacting our Privacy Officer using the details below. We will respond to your request within a reasonable period, and generally within 30 days after the request is made. We may need to verify your identity before giving you access.
We may refuse access where permitted by the Privacy Act. If we refuse access, we will give you written reasons (unless it would be unreasonable to do so) and details of available complaint avenues.
Correction of personal information
We take reasonable steps to ensure the personal information we collect, use and disclose is accurate, up to date, complete, relevant and not misleading. If you believe personal information we hold about you is inaccurate, out of date, incomplete, irrelevant or misleading, you may request correction by contacting our Privacy Officer. We will respond to your request within a reasonable period and, in any event, within 30 days after the request is made.
If we correct information at your request and it is reasonably practicable and lawful to do so, we will, on your request, notify any other entities to which we have previously disclosed that information. If we refuse to correct the information, we will give you written reasons (unless it would be unreasonable to do so), together with information about how you may make a complaint and, where required, take such steps as are reasonable to associate with the information a statement that you believe it to be inaccurate, out of date, incomplete, irrelevant or misleading.
Complaints
If you believe we have breached the Privacy Act, the APPs or an applicable privacy code, you may lodge a complaint with our Privacy Officer. Please provide enough detail for us to investigate. We will acknowledge receipt within a reasonable time and aim to investigate and respond to your complaint within 30 days, although more complex matters may take longer. If we need more time, we will let you know.
If you are dissatisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC). Details are available at www.oaic.gov.au.
Contact details
Privacy Officer
ACT Plasterboard Pty Ltd
45 Val Reid Crescent, Hume ACT 2620
Email: receivables@pmcbr.com.au
Phone: 02 6260 2200