InStrand Pty Ltd (ACN 646 487 747) trading as InStrand of 1 Somerville St, Bendigo, VIC 3550 (“we”, “us” or “our”) and our operation of the Platform, comprising of https://instrand.co/ and https://getbackpocket.com (collectively, the “Platform”) is committed to respecting your privacy.
We are committed to protecting your privacy and respecting and upholding your rights under the Australian Privacy Principles (“APPs”) contained in the Privacy Act 1988 (Cth) and the General Data Protection Regulation (EU 2016/679) (the “GDPR”) (collectively, “Privacy Laws”). We are a data controller for the purposes of the GDPR. We ensure that we will take all necessary and reasonable steps to comply with the relevant Privacy Laws and to deal with inquiries or complaints from individuals about compliance with the relevant Privacy Laws.
We will collect Personal Information on our Platform only by lawful and fair means and not in an unreasonably intrusive way. Generally, we will collect Personal Information directly from you, and only to the extent necessary to provide our services requested by you and to carry out our administrative functions or as required by a relevant Privacy Law.
We may also collect Personal Information from you when you enter a draw for the randomly generated opportunity to buy a product displayed on the Platform (“Draw”), fill in an application form, communicate with us, visit our Platform, provide us with feedback, complete online surveys or participate in competitions. We may collect Personal Information about you that you have provided to our business partners or from third parties and in respect of which you have given the third-party permission to share with us.
If you use a pseudonym when dealing with us or you do not provide identifiable information to us, we may not be able to provide you with any or all of our services as requested. If you wish to remain anonymous when you use our Platform, do not sign into it or provide any information that might identify you.
We require individuals to provide accurate, up to date and complete Personal Information at the time it is collected.
Personal information is any information relating to an identified or identifiable natural person (“Personal Information”). An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
Under the GDPR, we must have a legal basis to process Personal Information collected from individuals residing in the European Union. We rely on several legal bases to process your Personal Information, including:
We use, process and disclose your Personal Information for the purposes for which the information is collected, or for a directly related purpose, including (but not limited to):
we may use and process your Personal Information to send you information about products and services we believe are suited to you and your interests or we may invite you to attend special events.
At any time, you may opt out of receiving direct marketing communications from us. Unless you opt out, your consent to receive direct marketing communications from us and to the handling of your Personal Information as detailed above will continue. You can opt out by following the unsubscribe instructions included in the relevant marketing communication, or by contacting us in writing at firstname.lastname@example.org.
We may disclose your Personal Information to:
Cookies are small files that can be stored on and accessed from a user’s device when the user accesses a Platform. They enable authorised web servers to recognise you across different Platforms, services, devices and browsing sessions.
The data collected through Cookies will not be kept for longer than is necessary to fulfil the purposes mentioned above.
We will handle any Personal Information collected by Cookies in the same way that we handle all other Personal Information.
You can delete and refuse to accept browser Cookies by activating the appropriate setting on your browser. However, if you select this setting, you may be unable to access certain parts of the Platform.
When transmitting Personal Information from your computer to our Platform, you must keep in mind that the transmission of information over the internet is not always completely secure or error-free. Other than liability that cannot lawfully be excluded, we will not be liable in any way in relation to any breach of security or any unintended loss or disclosure of that information.
We may hold your Personal Information in either electronic or hard copy. We take reasonable steps to protect your Personal Information from misuse, interference and loss, as well as unauthorised access, modification or disclosure and we use a number of physical, administrative, personnel and technical measures to protect your Personal Information. For example, our protection includes, but it not limited to, our services and data being hosted in Google Workspaces, which is, amongst other, ISO/IEC 27001, ISO/IEC 27017, ISO/IEC 27018, and ISO 9001 compliant, and all data sent to and from InStrand is encrypted in transit using 256-bit encryption.
We are also constantly updating and innovating to enhance our protection mechanisms. Where we enhance or update our Platform, we will attempt to do so without interrupting our services to you. We will also ensure that we provide you with an update via an email where changes are made to our Platform.
However, we cannot guarantee the security of any Personal Information transmitted over the internet and therefore you disclose information and Personal Information to us at your own risk. We will not be liable for any unauthorised access, modification or disclosure, or misuse of your Personal Information.
Under the GDPR, an individual residing in the European Union has enhanced privacy rights, including the right to:
Subject to some exceptions provided by the relevant Privacy Laws, you may request access to your Personal Information in our customer account database, or seek correction of it, by contacting us. See Section 11: Contact information. Should we decline you access to your Personal Information, we will provide a written explanation setting out our reasons for doing so.
We may charge a reasonable fee that is not excessive to cover the charges of retrieving your Personal Information from our customer account database. We will not charge you for making the request.
If you believe that we hold Personal Information about you that is not accurate, complete or up-to-date then you may request that your Personal Information be amended. We will respond to your request to correct your Personal Information within a reasonable timeframe and you will not be charged a fee for correcting your Personal Information.
We will cooperate with the appropriate regulatory authorities, including local data protection authorities, to resolve any complaints regarding the transfer of personally identifiable information that cannot be resolved between us and the individual.