Personal information is any information relating to an identified or identifiable natural person (“Personal Information”) and generally when used in this policy has the meaning given to it in the Privacy Laws. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier (including phone numbers and email addresses) or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
You may need to provide Personal Information about other users to us, for example, personal information about your authorised representatives, or employees. If so, you are responsible for informing those individuals that you are providing their Personal Information to us, to ensure they agree to their information being provided to us, and to advise them of this Policy.
Stripe is an online payment system that is used to process payments on the Website. Personal Information will also be collected from you for the purpose of processing such payments.
We may collect Personal Information about you that you have provided to our business partners or from third parties and in respect of which you have given the third party permission to share with us.
We may also collect technical information related to your visit to our Websites and/or Services, which includes, but is not limited to, your internet protocol (IP) address (which can provide general information about your location, country, region, or city, but not your precise location), login information, device data such as device/browser type and version, time zone setting, and the operating system and platform you use when visiting our Websites or Services.
If you use a pseudonym when dealing with us or you do not provide identifiable information to us, we may not be able to provide you with any or all of our services as requested. If you wish to remain anonymous when you use our Websites, do not sign into them or provide any information that might identify you.
We require individuals to provide accurate, up to date and complete Personal Information at the time it is collected.
INFORMATION ABOUT CHILDREN UNDER 18
Our Websites are not intended for users under the age of 18. We acknowledge that the definition of a “minor” changes between jurisdictions, however we do not knowingly seek or collect Personal Information from any children below the age of 18 years.
WHAT IS OUR LEGAL BASIS?
Under the GDPR, we must have a legal basis to process Personal Information collected from individuals residing in the European Union. We rely on several legal bases to process your Personal Information, including:
where it is necessary to provide you, with access to, and use of the services and the Websites;
for our legitimate interests to provide, operate and improve our services or the Websites to our customers;
where you have freely and expressly consented to the processing of your Personal Information by us, which you may withdraw at any time; or
where we are under a legal obligation to process your Personal Information.
HOW YOUR INFORMATION IS USED
We use, process and disclose your Personal Information for the purposes for which the information is collected, or for a directly related purpose, including (but not limited to):
providing our Websites and services to you and/or our customers (including providing our Customers with Personal Information for their internal analytics);
administering, protecting, improving or optimising our Websites and services (including performing data analytics, conducting research and for advertising and marketing purposes);
creating industry reports from de-identified data;
verifying your age and/or identity;
billing you via Stripe for purchasing Services;
informing you about our Websites, services, rewards, surveys, contests, or other promotional activities or events sponsored or managed by us or our business partners;
responding to any inquiries or comments that you submit to us;
any other purpose you have consented to; and
any use which is required or authorised by a relevant Privacy Law.
We may also use, process, and disclose your Personal Information for the purposes for which the information is collected, or for a directly related purpose, where we:
have your express consent (which you may withdraw at any time by contacting us in writing at firstname.lastname@example.org);
have a legal basis to do so; or
are otherwise permitted by relevant Privacy Laws
Where you complete an enquiry form, about a specific project provided on one of our Websites, we may share personally identifiable information (such as your email address) with our customers who have paid to list the relevant project. In such an instance, we will request and you grant us permission to provide our Customer with your Personal Information in order for them to provide you further information relating to the project that you enquired about and to provide you with assistance with your future property purchase or lease.
We may also provide non-personal information (such as email domain addresses) to a third party for the purposes for which the information is collected, or for a directly related purpose, including (but not limited to):
providing our Websites and services to you and/or our customers; and
administering, protecting, improving or optimising our Websites and services (including performing data analytics, conducting research and for advertising and marketing purposes).
DISCLOSURE OF PERSONAL INFORMATION
We may disclose your Personal Information to:
a Customer of our Services who has listed a project on our Websites through which you have enquired about, as provided for in section 5.3 above;
third-parties we ordinarily engage from time to time to perform functions on our behalf for the above purposes;
any person or entity to whom you have expressly consented to us disclosing your Personal Information to;
our external business advisors, auditors, lawyers, insurers and financiers;
our payment processing service provider Stripe; and
any person or entity to whom we are required or authorised to disclose your Personal Information to in accordance with the relevant Privacy Laws.
We will not share any other personally identifiable information with any third parties without your consent. We may, however, share non-Personal Information with our Customers for analytical purposes.
have your express consent (which you may withdraw at any time by contacting us in writing at email@example.com);
have a legal basis; or
are otherwise permitted by relevant Privacy Laws,
we may use and process your Personal Information to send you information about products and services we believe are suited to you and your interests or we may invite you to attend special events.
At any time, you may opt out of receiving direct marketing communications from us. Unless you opt out, your consent to receive direct marketing communications from us and to the handling of your Personal Information as detailed above will continue. You can opt out by following the unsubscribe instructions included in the relevant marketing communication, or by contacting us in writing at firstname.lastname@example.org.
Cookies are small files that can be stored on and accessed from a user’s device when the user accesses a website. They enable authorised web servers to recognise you across different websites, services, devices and browsing sessions.
identify users of our Websites and Services;
process user requests;
improve user experience;
remember user preferences on our Site;
monitor the use of our Site and for analysis of our user base;
facilitate communication with users;
control access to certain content on our Site; and
protect our Site.
The data collected through Cookies will not be kept for longer than is necessary to fulfil the purposes mentioned above.
We will handle any Personal Information collected by Cookies in the same way that we handle all other Personal Information.
You can delete and refuse to accept browser Cookies by activating the appropriate setting on your browser. However, if you select this setting, you may be unable to access certain parts of the Website.
When transmitting Personal Information from your computer to our Websites, you must keep in mind that the transmission of information over the internet is not always completely secure or error-free. Other than liability that cannot lawfully be excluded, we will not be liable in any way in relation to any breach of security or any unintended loss or disclosure of that information.
We may hold your Personal Information in either electronic or hard copy. We take reasonable steps to protect your Personal Information from misuse, interference and loss, as well as unauthorised access, modification or disclosure and we use a number of physical, administrative, personnel and technical measures to protect your Personal Information. For example, authentication is handled via Microsoft Azure and/or Auth0, both of which are AIPAA, ISO/IEC 27018, and GDPR compliant. Further, your Personal Information is stored with Microsoft Azure and/or Auth0, both of which is fully encrypted at rest.
However, we cannot guarantee the security of any Personal Information transmitted over the internet and therefore you disclose information and Personal Information to us at your own risk. We will not be liable for any unauthorised access, modification or disclosure, or misuse of your Personal Information.
ACCESS TO INFORMATION
Under the GDPR, an individual residing in the European Union has enhanced privacy rights, including the right to:
require us to correct any Personal Information held about you that is inaccurate or incomplete;
require the deletion of Personal Information concerning you in certain situations;
data portability for Personal Information you provide to us;
object or withdraw your consent at any time to the processing of your Personal Information;
object to decisions being taken by automated means which produce legal effects concerning you or similarly significantly affect you; or
otherwise restrict our processing of your Personal Information in certain circumstances.
Subject to some exceptions provided by the relevant Privacy Laws, you may request access to your Personal Information in our customer account database, or seek correction of it, by contacting us. See section 14: Contact information. Should we decline you access to your Personal Information, we will provide a written explanation setting out our reasons for doing so.
We may charge a reasonable fee that is not excessive to cover the charges of retrieving your Personal Information from our customer account database. We will not charge you for making the request.
If you believe that we hold Personal Information about you that is not accurate, complete or up-to-date then you may request that your Personal Information be amended. We will respond to your request to correct your Personal Information within a reasonable timeframe and you will not be charged a fee for correcting your Personal Information.
MailChimp and privacy consent
We will only use this information to:
create, send and manage emails relating to Inspace;
measure email campaign performance;
improve the features for specific segments of customers;
evaluate your use of our Websites;
compile reports on website activity for us and, if applicable, for our Customers, and
provide other services relating to website activity and internet usage.
MailChimp may transfer this information to third parties where required to do so by law, or where such third parties process the information on MailChimps’s behalf. MailChimp collects information about when you visit the website, when you use the services, your browser type and version, your operating system, and other similar information.
You understand and acknowledge that this service utilises a MailChimp platform, which is located in the United States of America (USA) and relevant legislation of the USA will apply. Australian Privacy Principle 8.1 contained in Schedule 1 of the Privacy Act will not apply.
You understand and acknowledge that MailChimp is not subject to the Privacy Laws and you will not be able to seek redress under the Privacy Laws but will need to seek redress under the laws of the USA.
THIRD PARTY SITES
NOTICES AND REVISIONS