Privacy Policy
Last update: 28 Nov 2022
1. Introduction
Welcome to Wandora. This policy explains how we handle and use your personal information in connection with your use of our website and your rights in relation to it. Wandora Group Pty Ltd (ACN 654 960 424) and Wandora Pty Ltd (ACN 655 032 929) (together “Wandora”, “we”, “our”, or “us”) are incorporated in Victoria, Australia and can be contacted by email at hello@wandora.co.
Your privacy is important to us, and we are committed to protecting your personal data and taking all reasonable steps to protect your information from misuse and to keep it secure in compliance with the Privacy Act 1988 (Cth) and the EU General Data Protection Regulation (EU) 2016/679 (together “data protection law”).
This policy applies to our websites (www.wandora.co, www.wandora.app), our booking platform and our social media pages (collectively, our “Sites”) and the services you can access through them.
This policy explains why and how we will use the personal information that we have obtained from you, with whom we will share it and the rights you have in connection with the information we use. Please read this policy carefully.
Wandora Pty Ltd is the controller in relation to the processing activities described below. This means that we decide why and how your personal information is processed in connection with those activities listed. Please see the section at the end of this policy for our contact and legal information.
2. Information we collect about you
We receive personal information about you that you give to us (e.g. contact details and correspondence) that we collect from your use of the Sites (e.g. device and Site activity data) and that we obtain from other sources. We only collect personal information that we need, and that is relevant for the purposes for which we intend to use it.
2.1. Information you give us
This is information about you that you give to us by visiting our Sites, by corresponding with us via email or other means. This information is provided by you entirely voluntarily. The information you give to us can include your name, contact details (such as phone number and email address) and any personal information you include when corresponding with us, including your feedback on our Sites and services.
We may process health information about you in circumstances where you voluntarily provide such information, for example, if you report any specific limitations when placing a booking on our booking platform.
If you do not provide this information to us we may unable to resolve your queries or otherwise communicate effectively.
2.2. Information we collect from our Sites
When you use our Sites, we collect the following information:
- visiting frequency, pages visited, and other traffic analytics information;
- your internet protocol (IP) address, device ID, device type, browser version and location data
If you do not provide this information to us you may be unable to use the Sites or some of its features.
2.3. Information we collect from other sources
We may obtain certain information about you that is available publicly. We obtain this either directly from websites published online or from third-party data brokers who have obtained your personal information from publicly available sources. We use this information in each case, only to the extent permitted by data protection law.
3. Use of your personal information
We use your personal information for a variety of reasons. We rely on different legal grounds to process your personal information, depending on the purposes of our use and the risks to your privacy. You will always have the option to choose not to receive marketing communications from us and can opt-out of these at any time.
Data protection law requires us to have valid legal grounds (known as ‘lawful bases’) to process your personal information for each of the different purposes for which we use it. The purposes for which we use your personal information, which we have categorised by the legal grounds on which we rely, is as follows:
3.1. Where you have provided consent
We may use and process your personal information to contact you with marketing communications that you have specifically requested from us on the grounds that you have consented for us to do so.
You may withdraw your consent for us to use your information in any of these ways at any time. Please see clause 11 for further details.
3.2. Where required to comply with our legal obligations
We will use your personal information to comply with our obligations under the law, including keeping a record relating to the rights you exercise in connection with our processing of your personal information.
3.3. Where processing is necessary for us to pursue a legitimate interest
We may use and process your personal information where it is necessary for us to pursue our legitimate interests as a business for the following purposes:
Processing necessary for us to promote our business
- to contact you by email or by telephone with marketing information about our Sites (other than where we have asked you for your consent). We may use your personal information to tailor or personalise the marketing communications you receive to make them relevant to you and also to send targeted marketing messages via social media and other third-party platforms, which may involve sharing your personal information with those platforms; and
- to create a profile of you and analyse this to obtain insight about market or industry trends or user behaviours which inform our marketing strategy, and to enhance and personalise your experience, including the marketing communications you receive from us.
Processing necessary for us to support enquiries from users of our Sites
- to correspond and communicate with you in connection with the Sites;
- to identify ways of improving your experience of the Sites; and
- to train and monitor our staff and to identify ways of improving your customer service experience;
Processing necessary for us to respond to changing market conditions and our customers’ needs
- for market research, insight and intelligence to improve our understanding of our market and industry; and
- to analyse patterns of use, determine where we should focus our efforts through processing anonymised and aggregated data and to monitor the features of the Sites that have been used most frequently.
Processing necessary for us to operate the administrative and technical aspects of our business efficiently and effectively
- to authenticate your access to the Sites;
- to resolve technical issues and provide the most-up to date version of the Sites, with improved features;
- to administer the Sites and for internal operations, including troubleshooting, testing and statistical reporting purposes;
- for the detection and prevention of fraud and other criminal activities and to apprehend offenders;
- to verify the accuracy of information we hold about you and create a better understanding of you as a customer;
- for network and information security purposes in order for us to take steps to protect your information against loss or damage, theft or unauthorised access;
- to comply with a request from you in connection with the exercise of your rights (for example where you have asked us not to contact you for marketing purposes, we will keep a record of this on a suppression list to be able to comply with your request);
- for the purposes of a corporate restructure or reorganisation or sale of our business or assets;
- for efficiency, accuracy or other improvements of our databases and systems e.g. by combining systems or consolidating records we hold about you;
- to enforce or protect our contractual or other legal rights or to bring or defend legal proceedings; and
- for general administration including managing your queries, complaints, or claims, to send service messages and to provide you with important information about our business.
4. Disclosure of your personal information by us
We only disclose your personal information outside our business in limited circumstances. If we do, we will put in place a contract that requires recipients to protect your personal information unless we are legally required to share that information. Any contractors or recipients that work for us will be obliged to follow our instructions. We do not sell your personal information to third parties.
As the controller of your personal information, we decide why and how it is processed. Our responsibility for that processing extends to processing by our service providers if they process your personal information based on our instructions. We also work with other organisations in connection with some of the processing activities described in this statement, such as our group companies, social media platforms and certain suppliers.
Where that personal information is collected and sent to other organisations for a processing purpose that is in both our and their interests or where we make decisions together in relation to that particular processing, we will be “joint controllers” with the organisations involved. This includes, for example, disclosing your personal information to our customers (the “Vendor”) with whom you are placing a booking so that you can be supplied with the relevant products and services. Where this applies, the other organisation and we will be jointly responsible to you under data protection law for this processing. If we pass your personal information to an organisation that independently decides why and how to use your personal information (such as payment service providers and Vendors), then it will be separately responsible to you for that processing and use of your personal information in the ways described in its privacy policy (and not ours).
We may disclose your information to our third-party service providers, agents and subcontractors (“Suppliers”) for the purposes of providing services to us or directly to you on our behalf, including the operation and maintenance of our Sites and social media pages. Our Suppliers can be categorised as follows:
Recipient / Relationship | Industry Sector & Sub-Sector |
---|---|
Advertising, PR, digital and creative agencies | Media (Advertising & PR) |
Cloud software system providers, including database, email and document management providers | IT (Cloud Services) |
Customer care/service providers | Customer Services (Support) |
Delivery and mailing services providers | Logistics (Delivery Service) |
Facilities and technology service providers including scanning and data destruction providers | IT (Data Management) |
Social media platforms | Media (Social Media) - see clause 5 |
Insurers and insurance brokers | Insurance (Underwriting & Broking) |
Legal, security and other professional advisors and consultants | Professional Services (Legal & Accounting) |
When we use Suppliers, we only disclose to them any personal information that is necessary for them to provide their services and only where we have a contract in place that requires them to keep your information safe and secure.
We may disclose the personal information to other third parties as follows:
- any third party who is restructuring, selling or acquiring some or all of our business or assets or otherwise in the event of a merger, re-organisation or similar event; and
- if we are under a duty to disclose or share your information to comply with any legal or regulatory obligation or request, including by the police, courts, tribunals or regulators.
5. Our use of social media
We use social media platforms in a variety of different ways, including by publishing pages through which you can interact, running competitions or advertising to you using the information you have provided those platforms or which has been provided by us or collected from our Sites. Our legal relationship with each platform will vary with the particular way we are using that platform.
We process your personal information using social media platforms, as follows:
- We use your personal information when you post content or otherwise interact with us on our official pages on Facebook, Linkedin and other social media platforms.
- We use insights and analytics services on social media platforms to view statistical information and reports regarding your interactions and content. Where those interactions are recorded and form part of the information we access through the insights and analytics services, we and the relevant platform are joint controllers of the processing necessary to provide that service to us. As we are joint controllers for certain processing, we and each platform have:
- entered into agreements in which we have agreed to each of our data protection responsibilities for the processing of your personal information described above;
- agreed that we are responsible for providing to you the information in this privacy statement about our relationship with each platform; and
- agreed that each platform is responsible for responding to you when you exercise your rights under data protection law in relation to that platform’s processing of your personal information as a joint controller.
Further information
The Facebook company that is a joint controller of your personal information is Facebook Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. For further information regarding this platform’s use of your personal information, please see Facebook’s Controller Addendum for Page Insights, Facebook’s Controller Addendum for Business Tools and Facebook’s Privacy Policy
The Linkedin company that is a joint controller of your personal information is Linkedin Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland. For further information regarding this platform’s use of your personal information, please see Linkedin’s Page Insights Joint Controller Addendum and Linkedin’s Privacy Policy
6. Use of financial information
If you use our Sites to make bookings or other financial transactions (such as payment of products you purchase from a Vendor), we may collect information about the purchase or transaction. This includes payment information, such as your credit card or debit card number (stored as a secure token), billing details and other account and contact information (“Financial Information”).
We will only collect Financial Information from you with your prior knowledge. You can access and browse our Sites without disclosing Financial Information.
We use your Financial Information solely to process payments for bookings, products or services you request to purchase through the use of our Sites. We only use and retain your Financial Information to complete payments you initiate, any Financial Information that is collected is solely for the purpose of transaction approval and the transfer of funds.
We provide data encryption throughout the payment process and only share your Financial Information with your credit card provider, third-party payment processor or financial institution to process payments. The Financial Information we collect from you is strictly confidential and held on secured servers in controlled facilities.
We may store your Financial Information against your verified phone number or email address after the transaction is complete for your convenience, so you don’t have to type in your credit card each time you use our Sites. You can contact us if you wish to remove your user account and/or card details from your database, and we will do this immediately.
We may use third-party agents to manage online payment processing. These agents are not permitted to store, retain, or use your Financial Information or other personally identifiable information except for the sole purpose of payment processing on our behalf. Any third-party agent used by us is not authorised to use your Financial Information in any way other than to process payments and is required to keep any Financial Information it uses or collects confidential.
7. Transfers of your personal information outside of Australia
We may transfer your personal information outside of Australia. If we do disclose personal information to other overseas persons or entities, we will take reasonable steps to ensure that the overseas recipients of your personal information do not breach the data protection law relating to your personal information.
If we transfer your information outside of Australia, we will take steps to ensure that appropriate measures are taken with the aim of ensuring that your privacy rights continue to be protected as outlined in this policy. These steps include selecting recipients located in countries that have been declared adequately protective of your personal information by the relevant authorities or ensuring that the recipients are subscribed to ‘international frameworks’ that aim to ensure adequate protection. Where they do not, we ensure that we impose contractual obligations on them that are broadly equivalent as required by data protection law.
Please contact us using the details at the end of this policy for more information about the protections that we put in place and to obtain a copy of the relevant documents.
8. Security and links to third parties
We take the security of your personal information seriously and use a variety of measures based on good industry practice to keep it secure. Nonetheless, transmissions to and from our Sites may not always be completely secure, so please exercise caution.
We employ security measures to protect the information you provide to us, to prevent access by unauthorised persons and unlawful processing, accidental loss, destruction and damage.
If you suspect any misuse or loss of, or unauthorised access to, your personal information, please let us know immediately.
If we suspect any misuse or loss of, or unauthorised access to, your personal information, we may inform you of that suspicion and take immediate steps to limit any further access to or distribution of your personal information. If we determine that the breach is likely to result in serious harm to you and we are unable to prevent the likely risk of serious harm with remedial action, we will take action in accordance with data protection law.
If we receive unsolicited personal information that we are not permitted to collect under this privacy policy or within the confines of the law, we will destroy or de-identify the unsolicited personal information as soon as practicable if it is lawful and reasonable to do so. We will destroy or de-identify your personal information if we no longer require it to deliver our services as soon as practicable if it is lawful and reasonable to do so.
9. How we use cookies
When you use our Sites, we may obtain information using technologies such as cookies, tags, web beacons, and navigational data collection (log files, server logs, and clickstream data) to better understand your user experience. For example, we may collect information like the date, time and duration of visits and which Sites are accessed.
When you access our Sites, we may send a cookie (“Cookies”) (which is a small summary file containing a unique ID number) to your computer or mobile device. This enables us to recognise your computer or device and greet you each time you visit our Sites without bothering you with a request to register or log in. It also helps us keep track of products or services you view so that we can send you information about those products or services.
We also use cookies to measure traffic patterns, to determine which areas of our Sites have been visited, and to measure transaction patterns in the aggregate. We use this to research our users’ habits so that we can improve our services. If you do not wish to receive cookies, you can set your browser so that your computer does not accept them.
We may also log IP addresses (the electronic addresses of computers connected to the internet) to analyse trends, administer the Sites, track user movements, and gather broad demographic information.
This information is generally not linked to your identity except where it is accessed via links in our communications to you or where you have otherwise identified yourself. We may also collect anonymous data (which is not personal information) relating to your activity on our Sites (including IP addresses) via cookies. We generally use this information to report statistics, analyse trends, administer our services, diagnose problems and target and improve the quality of our services. To the extent this information does not constitute personal information because it does not identify you or anyone else, the data protection law does not apply, and we may use this information for any purpose and by any means whatsoever.
10. Retention of your personal information
We will not hold your personal information in an identifiable format for any longer than is necessary for the purposes for which we collected it. The periods for which we hold your personal information will depend on the type of personal information. These periods also apply where we share your information with suppliers who process your personal information on our behalf.
We retain your personal information for the purposes of accounting purposes for up to seven years from the date we no longer require it for the purposes listed above.
The only exceptions to the period mentioned above are where:
- you exercise your right to have the information erased (where it applies), and we do not need to hold it in connection with any of the reasons permitted or required under the law (see clause 11);
- we bring or defend a legal claim or other proceedings during the period we retain your personal information, in which case we will retain your personal information until those proceedings have concluded and no further appeals are possible;
- your account is subject to an investigation of criminal or fraudulent activity; or
- in limited cases, existing or future law or a court or regulator requires us to keep your personal information for a longer or shorter period.
We also retain an anonymised version of the submitted personal information for as long as we require it for reporting and other statistical and analytical purposes. Such anonymised information will not identify you and may be derived from personal information that was contained within accounts that have subsequently been deleted.
11. Your rights over your personal information
You have a number of rights in relation to your personal information under data protection law. In relation to certain rights, we may ask you for information to verify your identity and, where applicable, to help us to search for your personal information. Except in rare cases, we will respond to you within one month after we have received this information or, where no such information is required after we have received full details of your request.
You have the following rights, some of which may only apply in certain circumstances:
- to be informed about the processing of your personal information (this is what this Privacy Policy sets out to do);
- to have your personal information corrected if it is inaccurate and to have incomplete personal information completed;
If you change your name or email address, or you discover that any of the other information we hold is inaccurate or out of date, please let us know by emailing or writing to us at the address at the end of this policy.
- to object to processing of your personal information;
Where we rely on our legitimate interests as the legal basis for processing your personal information for particular purposes, you may object to us using your personal information for these purposes by emailing or writing to us at the address at the end of this policy. Except for the purposes for which we are sure we can continue to process your personal information, we will temporarily stop processing your personal information in line with your objection until we have investigated the matter. If we agree that your objection is justified in accordance with your rights under data protection law, we will permanently stop using your data for those purposes. Otherwise, we will provide you with our justification as to why we need to continue using your data.
You may object to us using your personal information for direct marketing purposes and we will automatically comply with your request. If you would like to do so, please click on the unsubscribe message on our emails.
- to withdraw your consent to processing your personal information;
Where we rely on your consent as the legal basis for processing your personal information, you may withdraw your consent at any time by contacting us, using the details at the end of this policy. If you withdraw your consent, our use of your personal information before you withdraw is still lawful.
- to restrict processing of your personal information;
You may ask us to restrict the processing of your personal information in the following situations:
- where you believe it is unlawful for us to do so, you have objected to its use, and our investigation is pending, or you require us to keep it in connection with legal proceedings.
In these situations, we may only process your personal information whilst its processing is restricted if we have your consent or are legally permitted to do so, for example, for storage purposes, to protect the rights of another individual or company or in connection with legal proceedings.
- to have your personal information erased;
In certain circumstances, you may ask for your personal information to be removed from our systems by emailing or writing to us at the address at the end of this policy. Unless there is a reason that the law allows us to use your personal information for longer, we will make reasonable efforts to comply with your request.
- to request access to your personal information and information about how we process it;
You have the right to ask for a copy of the information that we hold about you by emailing or writing to us at the address at the end of this policy. We may not provide you with a copy of your personal information if this concerns other individuals or if we have another lawful reason to withhold that information.
- to electronically move, copy or transfer your personal information in a standard form (data portability); and
Where we rely on your consent as the legal basis for processing your personal information, you may ask us to provide you with a copy of that information in a structured data file. We will provide this to you electronically in a structured, commonly used and machine-readable form, such as a CSV file.
You can ask us to send your personal information directly to another service provider, and we will do so if this is technically possible. We may not provide you with a copy of your personal information if this concerns other individuals or if we have another lawful reason to withhold that information.
- rights relating to automated decision-making, including profiling.
We do not envisage that any significant decisions will be taken about you using purely automated means, however, we will update this policy if this position changes.
To exercise these rights, please let us know by emailing or writing to us at the address at the end of this policy.
You have the right to request that an independent person (usually the Commonwealth Privacy Officer) investigate where your personal information has or is being used in a way that you believe does not comply with data protection law. However, we encourage you to contact us before making any complaint, and we will seek to resolve any issues or concerns you may have.
12. Changes to this policy
We may review our Privacy Policy from time to time, and any changes will be notified to you. Any changes will take effect 30 days after we post the modified terms on our Sites. We recommend you regularly check for changes and review this policy when you visit our Sites. If you do not agree with any aspect of the updated policy, you must promptly notify us and cease visiting our Sites.
13. Contact information
You can contact us with your queries in relation to this policy or for any other reason at any time. To contact us, please email privacy@wandora.co.