1. Introduction
At Notifyre we are strongly committed to maintaining the privacy of our customers' and users' personal information. We strictly comply with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth), as amended. We will not sell or disclose your information to any other organisation unless required by law. This policy explains how and why we collect, use, hold and disclose your personal information.
2. Information Collection and Use
To provide our services and/or to improve our users' and visitors' experience, we may collect personal information from visitors, enquiries and customers on our website. Personal information such as (but not limited to) name, company name, email, contact numbers and credit card details may be requested through relevant and suitable channels such as telephone, email, website enquiry forms, website free trial offers or general account registration forms. Account usernames and passwords for relevant services may also be collected and stored, enabling users to access our secure sites. If you do not provide us with your personal information, we may not be able to provide you with our services, communicate with you or respond to your enquiries.
To access and/or improve our services, cookies (a piece of text placed or stored by a user's web browser for record keeping) may be used. Cookies are generally used to enable our online services, to manage and improve our visitors' experiences, and to improve our advertising and/or web traffic monitoring. Depending on a user's web browser and settings, computers can be configured to accept or reject cookies, or they can be deleted and/or may expire after a period of time. In some instances, if cookies are disabled, it may affect access to some of the content and facilities on our website.
For Notifyre to provide its services, information on account usage, reports and transmission/document history may be stored securely online for a limited period of time or as required by law. See the Terms and Conditions of the relevant service. Such information will only be used to provide users' relevant Notifyre services and/or to provide support or to improve our services to our customers. We will also take reasonable steps to destroy or de-identify personal information once we no longer require it for the purposes for which it was collected, when a default or configured retention period has passed or for any secondary purpose permitted under the APPs. In accordance with the Telecommunications (Interception and Access) Act 1979 (Cth), customer metadata will be stored for two years after cancellation of the account with Notifyre.
We will be open and clear about the information we collect and what we do with information you provide. If you do not wish to receive information from Notifyre, unless required to use our services, you can opt out at any time.
We will use your personal information to offer you products and services we believe may interest you, but we will not do so if you tell us not to. Where you receive electronic marketing communications from us, you may opt out of receiving further marketing communications by following the opt-out instructions provided in the communication.
3. Anonymity and Pseudonymity
Where it is lawful and practicable to do so, you have the option of not identifying yourself, or of using a pseudonym, when dealing with us, for example for general enquiries that do not require us to act on your behalf. However, in most cases we need to verify your identity to provide our services, such as account creation, billing, and fax, SMS or email transmission services, so it will often not be practicable for us to deal with you anonymously or under a pseudonym. Where this is the case, we will tell you why at the time.
4. Sensitive Information
Sensitive information is a special category of personal information under the APPs and includes information such as health information, and information about racial or ethnic origin. Notifyre does not seek to collect sensitive information as part of its ordinary services. Where sensitive information is incidentally contained within content that customers choose to send, store or transmit using our services, for example the content of a fax, SMS or email, we collect and hold that information only as a service provider acting on the customer's instructions, and we do not use or disclose it for any purpose other than providing the service, unless required or authorised by law. Where Notifyre itself needs to collect sensitive information directly from an individual for its own purposes, we will only do so with that individual's consent, or where an exception under APP 3.4 applies.
5. Unsolicited Personal Information
If we receive personal information that we did not solicit, we will assess whether we could have lawfully collected it had we sought it. If we could not have, and the information is not contained in a Commonwealth record, we will destroy or de-identify that information as soon as practicable, provided it is lawful and reasonable to do so.
6. Security of Information
Strict guidelines are followed to ensure our users' and customers' information is protected. These guidelines include, but are not limited to, secure websites for collecting and storing information, secure hosting sites requiring authorised access, dedicated processes for information collection and data management, and strict employee training and confidentiality obligations.
All information will be kept confidential to the best of our ability. However, due to the nature of online communication, we cannot guarantee the security of transmissions that occur beyond our security control, such as transmissions across the open internet.
In line with the Terms and Conditions of Notifyre services, account holders and users are responsible for securely managing their account access and login details. Notifyre will take no responsibility for the mismanagement or disclosure of account access or login details on the customer's behalf.
You may access or request correction of the personal information that we hold about you by contacting us using the details set out below. There are some circumstances in which we are not required to give you access to your personal information, and if this applies, we will tell you why.
There is no charge for requesting access to your personal information, but we may require you to meet our reasonable costs in providing you with access, such as the cost for time spent collating large amounts of material.
We will respond to your requests to access or correct personal information within a reasonable time and will take all reasonable steps to ensure that the personal information we hold about you remains accurate, up to date and complete.
7. Cross-Border Disclosure of Personal Information
Notifyre may use suppliers, hosting providers, routing carriers or other contractors located outside Australia to help deliver our services, for example alternate telecommunications routing providers that use gateways located overseas.
Before we disclose your personal information to an overseas recipient, we will take reasonable steps to ensure that the recipient does not breach the APPs in relation to that information, for example by requiring the recipient to comply with the APPs or an equivalent privacy law under contract. Where an exception under APP 8.2 applies, such as your express consent or a requirement of law, we may disclose personal information overseas without taking those steps. We will not otherwise disclose your personal information to overseas recipients.
8. Accuracy of Information
We will, where possible, keep all information about our users and account holders up to date and relevant. However, in many instances, users can control and update their own information online via their secure web account access. We may also, from time to time, contact you through various methods to request up-to-date information.
9. External Links
Where there are links to external sites, unless through direct supply of our services, Notifyre is not responsible for the information or data collection processes these external sites manage.
10. Customer Access
Customers are secured by a personal username and password; and where activated, other controls made available such as multi-factor authentication. No details are accessible regarding passwords by any employee, and information is stored with secure access only by the individual creator. Customers can request a change of password or a new password via their registered email address. Account change requests will require verification; no information or account transfers will be undertaken without the authorised consent of the account owner or admin user.
11. Customer Information Obtained for Account Management
Due to the nature of the services provided, there are minimum details required to gain access to Notifyre services, including but not limited to:
12. How We Disclose Your Information
We may disclose your information to third parties who provide services to us, including organisations and contractors that assist us with the purposes for which we use your information. These services include:
We may also disclose your information:
Some of the third parties described above may be located overseas. See Cross-Border Disclosure of Personal Information above.
13. Notifiable Data Breaches
Notifyre has processes in place to identify, assess and respond to data breaches in accordance with Part IIIC of the Privacy Act 1988 (Cth), the Notifiable Data Breaches scheme.
If we become aware of, or reasonably suspect, a data breach involving personal information we hold, we will promptly investigate and assess whether the breach is an eligible data breach, that is, whether it is likely to result in serious harm to any individual to whom the information relates.
Where we determine that an eligible data breach has occurred, we will, as soon as practicable:
Our internal breach response procedures set out the detailed steps our employees must follow when a suspected breach is identified. This policy is to be read together with, and does not replace, those internal procedures.
Where a breach involves protected health information (PHI) that Notifyre processes on behalf of a U.S. HIPAA covered entity or business associate, we will additionally comply with the HIPAA Breach Notification Rule (45 CFR 164.400-414) and the notification obligations set out in the applicable Business Associate Agreement, including notifying the affected covered entity or business associate without unreasonable delay and no later than 60 days after discovery of the breach.
14. Complaints
If you have a complaint about the way in which we have handled any privacy issue, including your request for access to or correction of your personal information, you should contact us using the details set out below.
We will consider your complaint and determine whether it requires further investigation. We will acknowledge your complaint, investigate it, and notify you of the outcome within a reasonable time.
If you are not satisfied with our response to your complaint, or with how we have handled it, you may complain to the Office of the Australian Information Commissioner (OAIC):
15. United States - HIPAA (Health Insurance Portability and Accountability Act)
Where Notifyre creates, receives, maintains or transmits protected health information (PHI) on behalf of a U.S. HIPAA covered entity or another business associate, for example health-related content sent via fax, SMS or email through Notifyre, Faxaroo or Notifyre, Notifyre acts as a business associate under HIPAA and enters into a Business Associate Agreement (BAA) with that covered entity or business associate before processing PHI on its behalf.
As a business associate, Notifyre:
Individuals seeking to exercise the HIPAA rights listed above, or to obtain a copy of a covered entity's Notice of Privacy Practices (45 CFR 164.520), should contact the covered entity that provided their health information to Notifyre's services, as that entity - not Notifyre - is responsible for responding to such requests. Notifyre will support that entity's response where Notifyre holds the relevant PHI.
In addition to the complaint rights described above, individuals may lodge a complaint about a potential HIPAA violation directly with the U.S. Department of Health and Human Services, Office for Civil Rights (OCR):
No individual will be subject to retaliation, intimidation or any other adverse action for filing a complaint or exercising any right under HIPAA (45 CFR 164.530(g)).
Notifyre's Privacy Officer is the individual designated as responsible for HIPAA compliance, including developing and implementing this policy, receiving HIPAA-related complaints, and workforce training on the handling of PHI (45 CFR 164.530(a)-(b)). Workforce members who fail to comply with this policy or an applicable BAA are subject to sanctions under Notifyre's internal disciplinary procedures (45 CFR 164.530(e)).
16. Contact Details
If you have any questions, comments, or concerns, please contact us at:
Notifyre
ABN: 53105263974
100/1 Gardak St, Alexandra Headland, QLD. 4572. Australia
Phone: 1300 032 936 / + 617 5227 8333
Attention: Privacy Officer compliance@notifyre.com
17. Changes to This Policy
From time to time, we may change our policy on how we handle personal information or the types of personal information which we hold. Any changes to our policy will be published on our website. You may obtain a copy of our current policy by downloading a copy from our website or by contacting us at the contact details above.