Privacy policy
Overview
Thank you for using our platform!
Our platform is owned and operated by Australian Carbon Reduction Collective Pty Ltd (ERC Australia), and assists businesses to reduce their emissions and communicate progress with their clients through a five stage emissions reduction plan. Your privacy is important to us and we are committed to protecting your privacy in accordance with the Privacy Act 1988 (Cth) (Privacy Act), which includes the Australian Privacy Principles (APPs) and any related privacy codes.
This Policy outlines how we collect, use, disclose and store your personal information and lets you know how you can access that information. This Policy applies to our obligations when handling information in Australia.
Please read this Policy carefully and contact us using the details below if you have questions.
Consent
By providing personal information, you consent to us collecting, using, storing and disclosing your personal information in accordance with this Policy or as required or permitted by law. If you continue using our services, then we will treat your use as your consent to us handling your personal information in accordance with this Policy.
We will generally obtain consent from the owner of personal information to collect their personal information. Consent will usually be provided in writing; however, sometimes it may be provided orally or may be implied through a person’s conduct. We endeavour to only ask for your personal information if it is reasonably necessary for the activities that you are seeking to be involved in.
What personal information to do we collect and why do we collect it?
About our users
- Your name, email address and phone number.
- Any photos that you upload, such as a profile picture.
- Your device ID, device type and information, geo-location information, Internet Protocol (IP) address, standard web log information browser session data, device and network information, statistics on page views, acquisition sources, search queries, browsing behaviour and information gathered through internet cookies.
- Information contained in any communications between you and us.
- For the purpose for which the personal information was originally collected.
- To identify and interact with you.
- To perform administrative and operational functions.
- To comply with any legal requirements, including any purpose authorised or required by an Australian law, court or tribunal.
- For any other purpose for which you give your consent.
Directly from you when you:
- use our services;
- set up a profile with us;
- interact or share personal information with us via our platforms and social media; and
- communicate with us.
Through our third party service providers.
About our general users that have may not subscribed to our Platform but interact with us
- Information you have provided in communications we have with you.
- Information about your access and use of our website, including browser session data, device and network information, statistics on page views, acquisition sources, search queries, browsing behaviour and information gathered through internet cookies.
- To identify and interact with you.
- To perform administrative and operational functions.
Directly from you when you:
- use our Platform;
- interact or share personal information with us via social media; and
- communicate with us.
Through our third party service providers.
About contractors or prospective staff members
- Your name, email address and phone number.
- Your nationality and which countries you hold citizenship of.
- Educational details, such as schools you have attended, any qualifications you have received, transcripts and/or English language test results.
- Employment details, such as a CV, qualifications attained or examples of work.
- To enable us to carry out our recruitment functions.
- To correspond with you.
- To fulfil the terms of any contractual relationship.
- To ensure that you can perform your duties.
Directly from you when you:
- provide us with your CV;
- communicate with us; and
- via social media.
- From your references.
If you choose not to provide information as requested, we may not be able to service your needs. For example, it will not be possible for us to provide you with our service if you want to remain anonymous or use a pseudonym.
We sometimes receive unsolicited personal information. In circumstances where we receive unsolicited personal information we will usually destroy or de-identify the information as soon as practicable if it is lawful and reasonable to do so unless the unsolicited personal information is reasonably necessary for, or directly related to, our functions or activities.
Disclosing your personal information
We may disclose your personal information to the following third parties:
- our business or commercial partners;
- our professional advisers, dealers and agents;
- third parties and contractors who provide services to us, including customer enquiries and support services, IT service providers, data storage, webhosting and server providers, marketing and advertising organisations, payment processing service providers;
- payment system operators and debt-recovery functions;
- third parties to collect and process data, such as IBM Cloud, PayPal, SendGrid and Xero; and
- any third parties authorised by you to receive information held by us.
- If you are a contractor, we may disclose your information to payment system operators and debt-recovery functions.
We may also disclose your personal information if we are required, authorised or permitted by law.
We may send information to third parties that are located outside of Australia for the purposes of providing our services. These third parties are located in the United States of America, although this may change from time to time. Disclosure is made to the extent that it is necessary to perform our functions or activities.
We may from time to time provide de-identified corporate customer lists (Lists) to third parties. These Lists may include information about the corporate entities who use our Platform, such as information about the company name, location, number of employees, and the Projects the company has sponsored on the Platform. For the avoidance of doubt, we will make all commercially reasonable efforts to ensure that any such Lists do not disclose the details of an ERC Australia account holder or include any personal information.
Using your personal information for direct marketing
From time to time, and in support of our future development and growth, we may use your personal information to contact you to promote and market our products and services.
We may provide publicly available corporate entity information including the name of the company and its ACN, the industry in which it operates and how many employees it has, to third party companies for the purpose of helping you achieve your goal as entered by you on the Platform. We will make all commercially reasonable efforts to ensure any personal information is not disclosed. You can opt-out from being contacted for direct marketing purposes by contacting us at [email protected] or by using the unsubscribe facility included in each direct marketing communication we send. Once we receive a request to opt out from receiving marketing information, we will stop sending such information within a reasonable amount of time.
Security
We take all reasonable steps to protect personal information under our control from misuse, interference and loss and from unauthorised access, modification or disclosure. We hold your personal information electronically in secure databases operated by our third-party service providers.
We protect the personal information we hold through a number of different layers including:
- list security measures i.e. encrypted browsing through HTTPS; storing authentication details, such as passwords and user access tokens, in hashed or non reversible formats; actively monitoring errors; and logs using industry level tooling.
Our servers are hosted with IBM Cloud and are rebuilt with each deployment to prevent persistent access to rogue services. Server access and deployment are limited to revokable access keys that can only be regenerated on a master account. Access to servers can only be gained by using industry standard encryption keys that are generated and regularly updated, including when employees leave ERC Australia.
User logs redact certain types of information, such as passwords, before they are logged to prevent user information leaking to third parties.
Servers and databases are limited to internal access only to prevent database access to the public, unless it relates to certain whitelisted services or for monitoring and troubleshooting
While we take reasonable steps to ensure your personal information is protected from loss, misuse and unauthorised access, modification or disclosure, security measures over the internet can never be guaranteed.
We encourage you to play an important role in keeping your personal information secure, by maintaining the confidentiality of any passwords and account details used on our website.
Accessing or correcting your personal information
If you would like to access your personal information, please contact us using the details below. In certain circumstances, we may not be able to give you access to your personal information, in which case we will write to you to explain why we cannot comply with your request.
We try to ensure any personal information we hold about you is accurate, up-to-date, complete and relevant. If you believe the personal information we hold about you should be updated, please update this information within Member Information section on the ERC Australia platform or contact us using the details below and we will take reasonable steps to ensure it is corrected if appropriate.
Destroying or de-identifying personal information
We destroy or de-identify personal information when we no longer need it unless we are otherwise required or authorised by law to retain the information.
Making a complaint
If you believe your privacy has been breached or you have a complaint about our handling of your personal information, please contact us using the details below.
We take privacy complaints seriously. If you make a complaint, we will respond within 5 days to acknowledge your complaint. We will try to resolve your complaint within 30 days. When this is not reasonably possible, we will contact you within that time to let you know how long we will take to resolve your complaint.
We will investigate your complaint and write to you to explain our decision as soon as practicable.
If you are not satisfied with our decision, you can refer your complaint to the Office of the Australian Information Commissioner by phone on 1300 363 992 or online at www.oaic.gov.au.
Changes
We may, from time to time, amend this Policy. Any changes to this Policy will be effective immediately upon the posting of the revised Policy on our website. By continuing to use the services following any changes, you will be deemed to have agreed to such changes.
Contact us
All questions or queries about this Policy and complaints should be directed to:
Privacy Officer
Email: [email protected]
This Policy was last updated in March 2023.