This Privacy Policy applies to InnovationClub Pty Ltd trading as Nupal ACN 639 668 723 ("we" or "us").
This Privacy Policy applies to all of our customers, suppliers, contractors, users and prospective employees ("you") and activities. By using our website at https://nupal.eco (Site), you consent to us handling your personal information in accordance with this Privacy Policy.
Our Site is hosted on Hostmate.coma.au, an internet hosting platform that allows us to promote and sell our products to you online. Any personal information referred to in this policy that is provided to us through the Site will also be collected and stored through Hostmate databases. For further information, you can review Hostmate's terms of service and privacy policy at https://hostmate.com.au.
Purpose
Australia
One purpose of this Privacy Policy is to ensure that we comply with the Privacy Act 1988 (Cth) (Privacy Act) (including any amendments to the Privacy Act) and the Australian Privacy Principles (APP), which govern the way that APP entities must manage personal information (as defined in the Privacy Act), and to protect your personal information.
Under the Privacy Act, "personal information" is defined to mean information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether the information or opinion is true or not, and whether the information or opinion is recorded in a material form or not.
Personal information can include sensitive information. Sensitive information includes without limitation any information or an opinion about a person's race, ethnic origin, political opinions, religious
beliefs, sexual orientation criminal record or health information.
European Economic Area
Another purpose of this Privacy Policy is to ensure that we comply with the General Data Protection Regulation 2016/679 (GDPR) (and any legislation in other jurisdictions which give effect to the GDPR), which regulates the way we process information, from which you can be identified or from which you are identifiable, that we collect about you while you reside in a country within the European Economic Area (EEA).
This Privacy Policy refers to that information as "personal data." For GDPR purposes, we process personal data about you when we collect and use that personal data. We are the controller of that personal data that we collect.
When we collect personal data, we manage that personal data under this Privacy Policy, the GDPR and any other law that applies to processing that personal data.
If you reside in an EEA country and we process personal data about you, there is more information about particular rights the GDPR gives you under the heading “Data Protection Rights under the GDPR” in this Privacy Policy.
Collecting Personal Information
How we collect information
We collect, hold and use personal information during the course of your dealings with us (for example, when you visit or purchase products from the Site).
We may collect personal information from you in a number of ways. These include, but are not limited to:
- information that you give to us (for example through the Site, social media channels, email (including if you choose to subscribe to us) or telephone);
- information that we obtain from your use of the Site;
- information that you provide to us in person;
- information we receive from third party service providers, for example our payment gateway service provider;
- information you provide when you create an account or subscribe to us; and
- publicly available sources; and
- using cookies and similar technologies via the Site.
Types of information collected
The types of personal information that we can collect and hold include (without limitation):
- your name;
- your contact details including residential address, email address and telephone number;
- order and quotation information including details of all products purchased by you; and
- payment details to complete payment of your purchases which may include details of credit
cards, debit cards or any other applicable method of payment.
We may also collect other personal and sensitive information from you (for example, if you are applying for employment then we may collect your resume, qualifications, skills, education provider and history, work history and residency status). We may also collect any details contained within identity documents provided to us. We do not generally collect (or, if it is provided by you to us, retain) any sensitive information about you.
Purpose of collection
In general, we collect personal information so that we can perform our business activities and functions and to provide best possible quality of customer service to you.
We will collect, hold and use your personal information for one or more of the following purposes:
- so we can provide products and services to you;
- responding to your enquiries and otherwise communicating with you;
- managing support and contact requests;
- internal record keeping, management and administration;
- to meet contractual obligations;
- analytics;
- remarketing and behavioural targeting;
- marketing and advertising; and
- in respect of any application for employment with us.
Google Analytics
We use Google Analytics to collect information about the use of the Site. Google Analytics collects information about your visit to the Site but does not collect your personal information.
Some of the information that Google Analytics collects includes:
- server and IP address;
- domain name;
- type of browser used;
- date and time of visit;
- pages accessed and documents downloaded;
- the previous website that you visited; and
- if you have visited the Site before.
Although Google Analytics adds a permanent cookie on your web browser to identify you as a unique user the next time you visit the Site, the cookie cannot be used by anyone except Google. Google’s ability to use and share information collected by Google Analytics about your visits to this site is restricted by the Google Analytics Terms of Use and the Google Privacy Policy. You can prevent Google Analytics from recognising you on return visits to this site by disabling cookies on your
browser.
Google Analytics is a tool to measure website traffic and usage. You can opt out of the collection of this information using a tool like the Google Analytics Opt-out Browser Add-on.
Cookies
The Site uses cookies. A cookie is a small text file which may be placed on your Internet browser and which we access each time you visit the Site. Without limitation, we may use cookies:
- to help the Site to function correctly or to improve the usability, content or user experience of the Site;
- to monitor the Site's performance;
- for security;
- build up a picture of the websites, products and services you prefer, so that we can then provide you with a personalised experience of the Site and provide you with information of interest to you;
- place advertisements for our products on other external sites; and
- monitor how our marketing is performing.
Most browsers automatically accept cookies, but you can usually modify your browser settings to decline cookies. You may delete or decline cookies by changing your browser settings. If you do so, some of the features and services of the site may not function properly.
Use and disclosure of Personal Information
We only use and disclose personal information about you for the purpose for which it was collected, or for a related purpose as permitted by the Privacy Act or for uses for which you have given consent (which may be express or implied). We may disclose personal information about you to:
- our related entities;
- our agents, associates and business partners;
- personnel involved in the operation of the Site;
- service providers (including Shopify) who assist us in operating our business, perform
functions on our behalf or provide services to us; - an actual or prospective purchaser of the assets and/or operation of our business;
- market research agencies for conducting research;
- anyone to whom we are required or authorised by law to do so;
- relevant authorities when we believe that unlawful or undesirable activity is being or has been
conducted; or - anyone authorised by you to receive your personal information (your consent may be express
or implied, and can be withdrawn at any time).
Marketing and advertising
We will never use or disclose any sensitive information for marketing or advertising purposes.
We may use and disclose your personal information (other than sensitive information) to provide you with information about products or services offered by us or other companies or entities.
If at any time you do not wish to receive marketing communications from us or you do not want your personal information disclosed for marketing purposes, please contact us and we will remove your details from our marketing database.
Data Integrity
We endeavour to ensure that all personal information that it holds is accurate, complete and up-todate. To assist us with this, we strongly encourage that you contact us if any of your personal information changes, or if you believe that the personal information we have is not accurate or complete.
When personal information that we collect is no longer required by us, we will destroy or de-identify that personal information unless we are required by law or a court/tribunal to retain the personal information.
We may retain personal information for so long as it is required for any of our business purposes, for the prevention of fraud, for insurance and governance purposes and in our IT back-up.
Security
We may hold your personal information in electronic formats or in hard copy. Generally, we aim to store your personal information securely to ensure that your personal information is not protected from unauthorised access, modification and disclosure, and from other types of misuse, interference and loss.
While we will take reasonable steps to protect the personal information that we hold from misuse, loss or unauthorised access, you acknowledge that all activities in which you intentionally or unintentionally supply information to us carries an inherent risk of loss of, misuse of, or unauthorised access to such information.
You should contact us immediately if you believe that there has been unauthorised access or disclosure with respect to any personal information that we hold about you.
Information about third parties
If you provide us with personal information about a third party, in doing so you will be representing to us that you have that person's consent for us to collect and handle their personal information in accordance with this Privacy Policy – and we will be collecting the information on that basis.
Overseas disclosure
In some circumstances, we may disclose your personal information to overseas recipients located in the UK, Europe of the US. Otherwise, generally we will not disclose your personal information to overseas recipients, except with your consent or where we are required or authorised to do so by law.
Accessing and correcting your personal information
You may lodge a request to correct personal information that we hold about you if you believe it is inaccurate, incomplete, out-of-date, irrelevant or misleading please contact our Privacy Officer via the contact details shown below.
You may request that we provide you with access to the personal information we hold about you. Generally, we will provide you with access, except in limited circumstances where the APPs permit us to deny access. Any such requests must be made in writing to the Privacy Officer via the details shown below. Under the APPs, we are permitted to charge you a reasonable fee for providing access to your personal information. Please note that no fee will be incurred for requesting access, and if
your request for access is accepted we will inform you of the fee (if any) that will be payable for providing access if you proceed with your request.
Changes to our Privacy Policy
We may amend, modify or replace this Privacy Policy at any time. You should review our Privacy
Policy each time you visit our website or provide us with personal information.
Complaints
Privacy related complaints should be directed to us in writing at the address below:
Attention: NuPAL Privacy Officer
Email: admin@nupal.eco
Address: 105 Sydney Rd, Kelso, NSW, 2795, Australia
We will confirm receipt of your complaint and set out the time frame we require to investigate your complaint and provide you with a response. We will endeavor to respond as quickly as possible, which generally, will be within 30 days of receiving your complaint.
If you are dissatisfied with our response, you can take your complaint to the Office of the Australian Information Commissioner. For more information, see https://www.oaic.gov.au.
Additional rights under the GDPR if you are located in the EEA
This section outlines how we comply with the GDPR for residents of the EEA. This section does not
apply if you reside in Australia.
Processing GDPR personal data for EEA residents
In addition to the other reasons set out in this Privacy Policy, we may process personal data about
you because you have permitted us to do so for the purposes of:
- helping us understand your requirements and develop our products;
- offering you our products or other products as they become available and that may be of interest to you;
- allowing us to perform an agreement we have with you; and
- complying with the law.
Retaining personal data for EEA residents
We will retain personal data about you only for as long as is necessary for the purposes set out in this Privacy Policy.
We will retain and use that personal data to the extent necessary to comply with our legal obligations (for example, if we are required to retain your data to comply with applicable laws), resolve disputes, and enforce our legal agreements and policies.
Transferring personal data for EEA residents
We may transfer personal data about you to, and maintain it on, computers located outside of your state, province, country or other governmental jurisdiction where the data protection laws may differ from those in your jurisdiction.
We may transfer that personal data to Australia and process it there or to other jurisdictions. Please read the particulars under the heading "Overseas disclosure" in this Privacy Policy.
We will take all steps reasonably necessary to ensure that personal data about you is treated securely and in accordance with this Privacy Policy and no transfer of that personal data will take place to an organisation or a country, unless there are adequate controls in place including the security of that personal data.
Data protection rights under the GDPR
If you are a resident of an EEA country, you have certain data protection rights with respect to personal data we collect about you while you reside in that country.
We will take reasonable steps to allow you to correct, amend, delete, or limit the use of that personal data. If you wish to do so, please email us at admin@nupal.eco
If you wish to know what personal data we hold about you and if you want us to remove that personal data from our systems, please contact us.
You can contact us and exercise the following rights in relation to the personal data we hold about you:
- the right to access, update or delete the personal data we hold about you;
- the right of rectification - you have the right to have the personal data we hold about you rectified if that personal data is inaccurate or incomplete;
- the right to object to – you have the right to object to our processing of personal data we hold about you;
- the right of restriction – you have the right to request that we restrict the processing of personal data we hold about you;
- the right to data portability – you have the right to be provided with a copy of the personal data we hold about you in a structured, machine-readable and commonly used format and the right to have us transfer, where we are technically able to do so, the personal data we hold about you to another controller; and
- the right to withdraw consent (unless we have compelling and legitimate grounds for continuing processing (such as if you hold an account with us), you have the right to withdraw your consent where we relied on your consent to process personal data, we hold about you).
Complaints under the GDPR
You have the right to complain to a data protection authority about our collection and use of personal data we hold about you. For more information, please contact your local data protection authority in the EEA country of which you were a resident when we collected personal data.
Further information
For any further information about our privacy policy, please email us at admin@nupal.eco