Privacy Policy

Privacy Policy

Castlegate James Australasia Pty Ltd and Castlegate James (NZ) Limited

Castlegate James Australasia Pty Ltd ACN (098 051 846) is bound by the Privacy Act 1988 (Cth) (“Privacy Act”), including the Australian Privacy Principles (APPs).

Castlegate James (NZ) Limited NZBN (942 903 579 4066) is bound by the Privacy Act 2020 (NZ) (“Privacy Act”), including the Information Privacy Principles (IPPs).

References to “we”, “us”, or “our” in this Privacy Policy refers to Castlegate James Australasia Pty Ltd in relation to Australian operations, and Castlegate James (NZ) Limited in relation to New Zealand Operations, unless otherwise stated.

This Privacy Policy sets out how we treat the personal information that we collect, use and disclose and our procedures regarding the handling of personal and sensitive information, including the collection, use, disclosure and storage of information, as well as the right of individuals to access and correct that information.

From time to time, we may revise or update this Privacy Policy or our information handling practices. If we do so, the revised Privacy Policy will be published on our website www.castlegatejames.com. We may collect personal information in order to conduct our business, to provide and market our products and services and to meet our legal obligations. By using our website or our services, or by providing any personal information to us, you acknowledge and agree that your personal information will be collected, used and disclosed as set out in this Privacy Policy.

The types of personal information we collect and hold

The types of personal information we may collect and hold includes (but is not limited to) personal information about:

  • customers, business associates and potential customers and their employees;
  • suppliers and their employees; and
  • prospective employees and contractors.

Personal information that we collect and may hold include:

  • your name, address, contact telephone number and other contact details such as your email address;
  • payment information (such as credit card or bank details);
  • other personal information required to provide our services in specific cases, for example, certain information to complete police checks and property transactions, if relevant; and
  • details of your use of our products or services.

Where required under the Privacy Act 2020, New Zealand, we will inform individuals of the purpose of collection, how the information will be used, who it may be disclosed to, and whether providing it is voluntary.

You are not obliged to provide personal information to us. However, in many cases, if you do not provide your personal information to us, we may not be able to supply the relevant product or service that you have requested from us.

Where the provision of personal information is optional, we will clearly indicate this and explain the consequences (if any) of not providing the information.

In some circumstances, you may provide to us, and we may collect from you, personal information of a third party. Where you provide the personal information of a third party, you must ensure that the third party is aware of this Privacy Policy, understands it and agrees to accept it.

If it is necessary to provide specific services to you, we may collect sensitive information about you. Under the Privacy Act, “sensitive information” includes but is not limited to information or an opinion about an individual’s racial or ethnic origin, religious belief, or criminal record and also includes health information about an individual. However, we will only collect sensitive information from you if you agree to provide it to us, you authorise us to obtain it from a third party or where the collection of the information is required or authorised by or under an Australian law or a Court/Tribunal order or otherwise where the collection is not prohibited under the Privacy Act. We will only use sensitive information in accordance with the Privacy Act and for the purpose for which it is provided.

Data Minimisation and Purpose Limitation

We only collect, use and hold personal information that is reasonably necessary for, or directly related to, our business activities, functions or the provision of our products and services.

We take reasonable steps to ensure that the personal information we collect is relevant, adequate and limited to what is required for the specific purposes for which it is collected. We do not collect personal information in an unreasonably intrusive way or retain it for longer than necessary to fulfil those purposes, unless required or authorised by law. We only collect this information to fulfil the purposes outlined above.

How personal information is collected and held by us

We collect personal information in the following ways:

  • when you fill in a company application for employment;
  • when you fill in and return to us a signed credit application form;
  • when you fill in and return to us a signed new vendor form;
  • when you submit personal information through our website (such as when you send us a message or fill out a form);
  • in person, for example, when you engage with our Key Account Managers;
  • when you submit personal information via email (such as when you communicate with our accounts receivable or payable teams);
  • in the course of providing products and services to you.

We may also collect information about you from third party suppliers and government database services.

We store personal information in computer storage facilities and paper-based files. We take steps to protect your personal information against loss, unauthorised access, use, modification or disclosure. Some examples of the steps we take to protect your personal information include:

  • ensuring there are suitable password protection measures and access privileges in place to monitor and control access to our IT systems;
  • imposing restrictions on physical access to paper files;
  • requiring any third parties engaged by us to provide appropriate assurances to handle your personal information in a manner consistent with the Privacy Act; and
  • taking reasonable steps to destroy or de-identify personal information after we no longer need it for our business or to comply with the law.
  • we retain personal information only for as long as necessary to fulfil the purposes outlined in this Privacy Policy or to comply with legal, regulatory or contractual requirements. Retention periods may vary depending on legal, contractual, or operational requirements. When personal information is no longer required, we take reasonable steps to destroy or de-identify it.

Collection of personal information through website activity

We may collect information that identifies you as a user when you access and use our website.

Our website uses cookies and similar technologies. Cookies are small data files placed on your device that allow us to recognise your browser, improve your experience, and understand how users interact with our website. Some cookies are essential for the operation of the website, while others are non-essential and used for analytics, performance, or marketing purposes.

Where required by law, including for visitors from the EU or UK, we will obtain your consent before placing non-essential cookies on your device, including through cookie banners or preference settings where applicable. Non-essential cookies will not be set until consent is obtained.

You can configure your web browser to refuse cookies or manage or withdraw your consent at any time via your browser or our website settings. Please note that if you disable cookies, some parts of our website may not function correctly.

Adoption, use and disclosure of government related identifiers

We, or our related body corporates in the Group, may collect some personal information that is a government related identifier.

Personal information from identity documents may be provided to the document issuer or official record holder via third party systems for the purpose of confirming your identity, for example, the Australian Government’s Document Verification Service (DVS). Where we do collect government related identifiers, they are maintained on a separate database for audit and compliance purposes.

We may use or disclose a government related identifier where:

  • it is reasonably necessary for us to verify the identity of the individual for the purposes of our business activities or functions; or
  • as required or authorised by law or in accordance with the order of a Court or Tribunal, or where it is otherwise permitted to do so under the Privacy Act.

Codes of Practice and Regulatory References

In New Zealand, the Privacy Act 2020 allows for approved Codes of Practice that may modify how privacy principles are applied in specific circumstances. We comply with relevant Codes of Practice where applicable and continue to meet our obligations under the Privacy Act 2020.

We also comply with applicable privacy and consumer protection laws in Australia, including the Privacy Act 1988 (Cth) and associated Australian Privacy Principles (APPs).

The purposes for which we collect, use and disclose personal information

We collect, hold, use and disclose personal information for a variety of business purposes including:

  • to provide the products or services you have requested from us;
  • to process payments;
  • to improve our business, products and services;
  • to promote our business to you;
  • to market our other services or products to you;
  • to handle and respond to your enquiries, complaints or concerns;
  • to assess prospective new employees; and
  • to provide personal information to third parties as set out in this Privacy Policy.

Direct Marketing

We also collect, hold, use and disclose your personal information to:

  • notify you about the details of new services and products offered by us;
  • notify you of the details of meetings, events and seminars that may be of interest to our customers and prospective customers;
  • send you our newsletters and other marketing publications;
  • administer our databases for client service, marketing and financial accounting purposes; and
  • to comply with our legal requirements regarding the collection and retention of information concerning the products and services that we provide.

If you do not wish to receive direct marketing communications from us, or you wish to opt-out at any time, you may do so by contacting the Company’s Privacy Officer using the contact details set out below or by following the unsubscribe instructions contained in our communications.

We will action all opt-out requests promptly and at no cost to you. Once you have opted out, we will not send you further direct marketing communications unless you later choose to opt back in.

Who do we disclose personal information to?

The Group and Related Companies

The Group includes our parent company Castlegate James Australasia Pty Ltd and Castlegate James (NZ) Limited.

Third Party Service Providers.

We may disclose your personal information to third party service providers who assist us in providing the services you request, including public authorities and providers of information services.

We may also disclose your personal information to third parties who work with us in our business to promote, market or improve the services that we provide, including:

  • providers of customer relations management database services and marketing database services;
  • marketing consultants, promotion companies and website hosts; and
  • consultants and professional advisers.

We may also combine your personal information with information available from other sources, including the entities mentioned above, to help us provide better services to you.

Where we do share information with third parties, we require that there are contracts in place that only allow use and disclosure of personal information to provide the service and that protect your personal information in accordance with the Privacy Act. Otherwise, we will disclose personal information to others if you’ve given us permission, or if the disclosure relates to the main purpose for which we collected the information and you would reasonably expect us to do so.

Disclosure of consumer credit information

Where we collect and handle consumer credit information, we do so in accordance with applicable consumer credit reporting laws and industry standards, including:

  • Part IIIA of the Privacy Act 1988;
  • the Privacy (Credit Reporting) Code 2014, and;
  • Privacy Regulation 2013.

These standards ensure that your personal information in relation to your consumer credit is managed in relation to:

  • the types of personal information that credit providers can disclose to a credit reporting body (CRB), for the purpose of that information being included in an individual’s credit report;
  • what entities can handle that information, and;
  • the purposes for which that information may be handled.

Disclosure of personal information to overseas recipients

We do not ordinarily disclose personal information to organisations located outside Australia or New Zealand. However, in some circumstances, we may disclose personal information to some multinational organisations that operate in or have operations in other countries, including the United Kingdom, the United States and New Zealand, for the purposes described in this Privacy Policy.

Where we disclose personal information overseas, we take reasonable steps to ensure that the overseas recipient handles personal information in a manner consistent with the Australian Privacy Principles, unless an exception under the Privacy Act applies.

Cross Border Disclosures (New Zealand)

Where we disclose personal information about New Zealand residents to third parties located outside of New Zealand (including Australia, the United States, and the United Kingdom), we will comply with the requirements of Information Privacy Principle 12. This means we will only disclose such information where:

  • the recipient is subject to similar privacy protections, or
  • you have authorised the disclosure, or
  • we have taken reasonable steps to ensure the recipient protects your information in a way that is comparable to the protections of the New Zealand Privacy Act 2020.

European Union – General Data Protection Regulation (GDPR)

If you are a resident of the European Union for the purposes of the GDPR, then in addition to what is set out above, the following applies to you.

We act as a data controller and, in some circumstances, a data processor for the purposes of the GDPR and by your consenting to this Privacy Policy, we are able to process your Personal Information in accordance with this Privacy Policy.

In providing services to you, we may use automated processes, including profiling, to help improve our services and provide information that is more relevant to you. These processes do not involve automated decision-making that produces legal effects or similarly significant effects on individuals, unless otherwise permitted by law or disclosed to you at the time.

In addition to your rights set out above, you may update or rectify any of your Personal Information that we hold about you, in the manner described in the “How you can access your personal information” paragraph above.

Lawful basis for processing (GDPR)

Where the General Data Protection Regulation (GDPR) applies, we collect and process your Personal Information only where we have a lawful basis to do so. Depending on the circumstances, this may include where:

  • processing is necessary for the performance of a contract with you or to take steps at your request prior to entering into a contract;
  • processing is necessary for compliance with a legal obligation;
  • processing is necessary for our legitimate interests (including operating our business, improving our services, fraud prevention, credit assessment and direct marketing), except where those interests are overridden by your rights; or
  • you have provided your consent, where consent is required by law.

Where we rely on consent, you may withdraw your consent at any time by contacting us using the details set out in this Privacy Policy.

How we handle requests to access your personal information

You have a right to request access to your personal information which we hold about you and to request its correction. You can make such a request by contacting the Company’s Privacy Officer using the contact details set out in this policy.

We will respond to any such request for access as soon as reasonably practicable. Where access is to be given, we will provide you with a copy or details of your personal information in the manner requested by you where it is reasonable and practicable to do so.

We will not charge you a fee for making a request to access your personal information. However, we may charge you a reasonable fee for giving you access to your personal information.

In some cases, we may refuse to give you access to the information you have requested or only give you access to certain information. If we do this, we will provide you with a written statement setting out our reasons for refusal, except where it would be unreasonable to do so.

New Zealand Residents and your Privacy Rights

If you are a resident of New Zealand, we handle your personal information in accordance with the New Zealand Privacy Act 2020 and it’s 13 Information Privacy Principles (IPPs). You have the right to:

  • Request access to, or correction of, the personal information we hold about you.
  • Be informed about how your information is collected and used.
  • Raise a complaint with the New Zealand Office of the Privacy Commissioner if you believe your privacy rights have been breached.

You may contact us using the details below in the How to contact us or make a complaint section of this Privacy Policy.

Notifiable Privacy Breaches

We take data security seriously. In the event of a data breach involving personal information, and where the breach is likely to result in serious harm, we will take steps to promptly assess the situation and notify affected individuals in accordance with our legal obligations.

For residents of New Zealand, if we experience a privacy breach involving your personal information that is likely to cause serious harm, we will notify both you and the New Zealand Privacy Commissioner, as required under the New Zealand Privacy Act 2020.

Privacy Breach Response

We have procedures to identify and respond to privacy breaches involving personal information.

If a breach is likely to result in serious harm, we will promptly notify affected individuals and relevant regulators, in accordance with Australian and New Zealand law. We will also take reasonable steps to contain and remediate the breach.

We maintain documented procedures for assessing the severity of a breach, notifying regulators, and informing affected individuals promptly.

How we handle requests to correct your personal information

We will take such steps (if any) as are reasonable in the circumstances to make sure that the personal information we collect, use or disclose is accurate, complete, up to date and relevant.
If you believe the personal information we hold about you is inaccurate, irrelevant, out of date or incomplete, you can ask us to update or correct it. To do so, please contact us using the contact details listed below.

If we refuse your request to correct your personal information, we will let you know why. You also have the right to request that a statement be associated with your personal information that says you believe it is inaccurate, incomplete, irrelevant, misleading or out of date.

How to contact us or make a complaint

If you have any questions about this Privacy Policy, or if you wish to correct or update information we hold about you or if you wish to request access or correction of your personal information or make a complaint about a breach by us of the APPs or IPPs (including the way we have collected, disclosed or used your personal information), please contact:
      Privacy Officer
      PO Box 1370, Tullamarine VIC 3043, Australia
      privacy@castlegatejames.com.au

We will acknowledge and investigate any complaint about the way we manage personal information as soon as practicable. We will take reasonable steps to remedy any failure to comply with our privacy obligations.

If you are located in Australia and are unhappy with our handling of the complaint, you may contact the Australian Information Commissioner on either www.oaic.gov.au or 1300 363 992.

If you are located in New Zealand and are unhappy with our handling of the complaint, you may contact the Office of the Privacy Commissioner (New Zealand) on either www.privacy.org.nz or 0800 803 909.