Privacy Policy

This document declares the Undertakings by the ENDTOEND Visuals Pty Ltd. (E2E) in relation to its handling of Your Data, as those terms are defined in the Definitions section below.

The terms ‘undertake’ and ‘undertaking’ are used in order to make clear that E2E’s commitments give rise to legal obligations. These Undertakings are additional to the formal legal requirements that AIS is subject to in various jurisdictions throughout the world.

The term ‘Your Data’ refers to identified personal data about you that may arise from multiple roles that you may play, and multiple relationships that you may have with E2E, including as site-visitor, member, officer, candidate for office, employee or contractor, and through associations with E2E publications, including as author, editor, reviewer and website contributor.


Contents

  • Data Collection
  • Data Security
  • Data Use
  • Data Disclosure
  • Data Retention and Destruction
  • Access by You to Your Personal Data
  • Information about Data Handling Practices
  • Handling of Enquiries, General Concerns and Complaints
  • Enforcement
  • Changes to These Privacy Undertakings
  • Definitions

Data Collection

E2E undertakes to collect Your Data by means that are:

  • fair;
  • legal; and
  • transparent.

If you visit E2E’s web-site, your web-browser automatically discloses, and E2E’s web-server automatically logs, the following information: the date and time, the IP address from which you issued the request, the type of browser and operating system you are using, the URL of any page that referred you to the page, the URL you requested, and whether your request was successful. This data may or may not be sufficient to identify you.

Any additional data that you provide, e.g. in a web-form, may also be logged. This data may or may not be sufficient to identify you.

Any additional data that your web-browser automatically provides may also be logged. This will be the case, for example, if your browser has previously been requested to store data on your computer in ‘cookies’ and submits them each time you request a web-page within a particular domain (such as E2E.com). This data may or may not be sufficient to identify you.

If you disclose personal data to E2E in conjunction with an identifier such as your name or your credit-card details, E2E will collect Your Data. Moreover, any data that becomes available to E2E through any of the means described in the preceding paragraphs may be able to be associated with that identifier, and hence become Your Data.

Subject to the qualifications immediately below, E2E undertakes to collect Your Data from you and not from other parties. This undertaking is qualified as follows:

  • where E2E reasonably considers that the protection of its financial interests requires that it gather Your Data from other sources, or from additional sources. This applies in particular where E2E has a lending exposure to you, and seeks information about your creditworthiness;
  • where E2E reasonably considers that its capability to deliver quality services to you will be materially enhanced by gathering Your Data from other sources. This applies in particular to consumer profile data.

Where E2E collects Your Data from sources other than you, it undertakes:

  • to do so only by legal means;
  • to do so only with your Consent; and
  • to declare to you what sources it uses, and under what circumstances.

E2E undertakes to declare the purpose of collection in a manner which is clear and meaningful, and to avoid vague, highly inclusive statements such as ‘to support our operations’.


Data Security

E2E undertakes to store Your Data in a manner that ensures security against unauthorised access, alteration or deletion, at a level commensurate with its sensitivity.

E2E undertakes to store Your Data only in jurisdictions where data protections are at least equivalent to those required under the OECD Guidelines.

E2E undertakes to transmit Your Data in a manner that ensures security against unauthorised access, alteration or deletion, at a level commensurate with its sensitivity.

E2E undertakes to implement appropriate measures to ensure security of Your Data against inappropriate behaviour by E2E’s staff-members and contractors. These include:

  • training for staff in relation to privacy;
  • access control, to limit access to Your Data to those staff and contractors who have legitimate reasons to access it;
  • particularly in the case of sensitive data, audit trails of accesses, including the identities of staff and contractors accessing the data;
  • reminders to staff and contractors from time to time about the importance of data privacy, and the consequences of inappropriate behaviour;
  • declaration of appropriately strong sanctions that are to be applied in the event of inappropriate behaviour
  • clear communication of policies and sanctions; and
  • processes to audit, to investigate and to impose sanctions

Data Use

Use refers to the application of Your Data by any part of E2E, or any staff-member or contractor of E2E in the course of their work.

E2E undertakes to use Your Data only for:

  • the purposes for which it was collected;
  • such other purposes as are subsequently agreed between E2E and You;
  • such additional purposes as may be required by law. In these circumstances, E2E will take any reasonable steps available to it to communicate to You that the use has occurred, unless it is precluded from doing so by law; and
  • such additional purposes as are authorised by law (in particular to protect E2E’s interests, e.g. if it believes on reasonable grounds that You have failed to fulfil your undertakings to E2E or have committed a breach of the criminal law).

E2E undertakes to use Your Data only if it has demonstrable relevance to the particular use to which it is being put.

E2E undertakes to use Your Data in such a manner as to take into account the possibility that it is not of sufficient quality for the purpose, e.g. because it is inaccurate, out-of-date, incomplete, or out-of-context.


Data Disclosure

Disclosure refers to making Your Data available to any party other than E2E and You. The term disclosure may include many different conditions of data transfer, including selling, renting, trading, sharing and giving.

E2E undertakes to disclose Your Data only under the following circumstances:

  • in the course of business being conducted between You and E2E, where disclosure is necessary to a contractor, such as a transport company. Where Your Data is disclosed in this way, E2E undertakes to exercise control over E2E’s contractors to ensure that their actions are compliant with these Terms;
  • in other circumstances that are directly implied by the purpose agreed between You and E2E at the time of data collection or subsequently. Where Your Data is disclosed in this way, E2E undertakes to exercise control over E2E’s contractors to ensure that their actions are compliant with these Terms;
  • with your consent, or at your request;
  • where required by law, such as a provision of a statute, or a court order such as a search warrant or subpoena. In these circumstances, E2E will take any reasonable steps available to it to communicate to You that the disclosure has occurred, unless it is precluded from doing so by law;
  • where permitted by law (e.g. the reporting of suspected breach of the criminal law to a law enforcement agency; and in an emergency, where E2E believes on reasonable grounds that the disclosure of Your Data will materially assist in the protection of the life or health of some person), provided that E2E will apply due diligence to ensure that the exercise of the permission is justifiable.

In all cases, E2E undertakes to disclose only such of Your Data as is necessary in the particular circumstances.


Data Retention and Destruction

Subject to the qualifications immediately below, E2E undertakes:

  • to retain Your Data only as long as is consistent with its purpose; and
  • to destroy Your Data when its purpose has expired, and to do so in such a manner that Your Data is not subsequently capable of being recovered.

This undertaking is qualified as follows:

  • Your Data may be retained in E2E’s logs, backups and audit trails within short-term retention cycles that are devised to protect the company’s operations. In such cases, Your Data will be destroyed in accordance with those cycles;
  • Your Data may be retained beyond the expiry of its purpose if that is required by law, such as a provision of a statute, or a court order such as a search warrant or sub poena, or a warning by a law enforcement agency that delivery of a court order is imminent. In these circumstances, E2E:
    • will take any reasonable steps available to it to communicate to You that Your Data is being retained, unless it is precluded from doing so by law; and
    • will only retain Your Data while that provision is current, and will then destroy Your Data;
  • Your Data may be retained beyond the expiry of its purpose if it is authorised by law (in particular to protect E2E’s interests, e.g. if it believes on reasonable grounds that You have failed to fulfil your undertakings to E2E or have committed a breach of the criminal law). In these circumstances, E2E will only retain Your Data while that situation is current, and will then destroy Your Data.

Access by You to Your Personal Data

E2E undertakes to provide you with access to Your Data, subject to only such conditions and processes as are reasonable in the circumstances. In particular, E2E undertakes to enable access:

  • conveniently;
  • without unreasonable delay; and
  • without cost.

E2E undertakes to establish and operate identity authentication protections for access to Your Data that are appropriate to its sensitivity, but practical. This may involve some inconvenience; for example, relatively straightforward procedures may be involved in order to provide you with access through a channel that you have previously registered with E2E (such as a particular email-address), but may impose more onerous procedures if you wish to use some other channel.

In the event that you dispute some aspect of Your Data, E2E undertakes to take reasonable steps in relation to the amendment, supplementation or deletion of Your Data.

You undertake:

  • not to seek access for frivolous purposes, or unreasonably frequently;
  • to accept that deletion of some data may not be consistent with the provision of particular services by E2E to you.

Information about Data-Handling Practices

E2E undertakes to make information available to you about the manner in which E2E handles your data:

  • in general terms, in a readily accessible manner; and
  • in more specific terms, on request.

Where Your Data is disclosed to a contractor, E2E undertakes to make information available to you on request about the manner in which E2E’s contractors handle your data.

E2E undertakes to ensure that the information provided is meaningful, and addresses your concerns.

You undertake:

  • not to seek such information for frivolous purposes, or unreasonably frequently; and
  • to accept that the disclosure of excessive detail may harm the security of Your Data and E2E’s business processes, and may harm E2E’s commercial interests.

Handling of Enquiries, General Concerns and Complaints

If you have enquiries, general concerns, or complaints about these Terms, or about E2E’s behaviour in relation to these Terms, you undertake:

  • to communicate them in the first instance:
    • to E2E only;
    • in sufficient detail;
    • through a channel made available by E2E for that purpose;

E2E undertakes:

  • to provide one or more channels for communications to E2E, which are convenient to users;
  • to promptly provide acknowledgement of the receipt of communications, including the provision of a copy of the communication, the date and time it was registered, and E2E’s reference-code for the communication;
  • to promptly provide a response to the communication, in an appropriate and meaningful manner.

You further undertake to not pursue E2E through any Regulator or the media:

  • until and unless E2E has had a reasonable opportunity to respond to the initial communication; and
  • while E2E and you are conducting a meaningful dialogue about the matter.

Enforcement

E2E declares that its undertakings in these Terms are intended to create legal obligations, and that those obligations are intended to be enforceable under appropriate laws in appropriate jurisdictions. These include laws relating to data protection, privacy, fair trading, corporations and criminal laws.

You undertake to seek enforcement only in a jurisdiction that is relevant to the transactions that have taken place between You and E2E, in particular the jurisdiction in which you live or in which you performed the relevant acts, and the jurisdiction in which E2E is domiciled or performed the relevant acts.

If you wish to discover the relevant laws in any particular jurisdiction, E2E draws your attention to the following resources:


Changes to These Privacy Undertakings

E2E undertakes:

  • not to unilaterally make any material change to these Terms in a manner that reduces the protections for Your Data;
  • to take all practicable steps to prevent any company that acquires this company or any of its relevant assets from materially changing the Terms applicable to Your Data in a manner that reduces the protections for Your Data;
  • where it is considering making changes to these Terms, or creating more specific Terms relating to specific services, to consult with appropriate representative and advocacy organisations;
  • where it makes changes to these Terms, to ensure that the differences between successive versions are readily accessible;
  • to maintain all prior versions of these Terms in such a manner that they are dated, and readily accessible.

Definitions

E2E means E2E Pty Ltd., and which can be contacted here.

Your Data means data that is capable of being associated with you, whether or not it includes an explicit identifier such as your name or customer number. In particular, it encompasses all data that E2E is capable of correlating with you, using such means as server-logs and cookie-contents.

Your Data does not refer to data that can no longer be associated with you. This includes aggregated data that does not and cannot identify the individuals whose data are included in the aggregation.

Consent means your concurrence with an action to be taken by E2E. Consent may be express or implicit, but in either case must be informed and freely-given.

 

This document is a licensed adaptation of the Privacy Statement Template published by Xamax Consultancy Pty Ltd. The Template has been adapted to the extent necessary to customise it to the context in which E2E operates.