Privacy Policy

 

Purpose of the policy
 

This is the privacy policy of Australian Vintage Limited ABN 78 052 179 932 and our related entities (herein collectively, AVL).

The purpose of this policy is to clearly express an up-to-date policy about our company's management and handling of personal information.

We are committed to protecting the privacy of your personal information. We will only collect, use or disclose personal information in accordance with relevant laws and this policy.

Personal information means information or an opinion (including information or an opinion forming part of a database), whether true or not, and whether or not recorded in a material form, about an individual whose identity is apparent, or can reasonably be ascertained, from the information or opinion.

By submitting your personal information to us, or by using our services, you acknowledge and consent to us using your personal information in accordance with this policy.

This policy is intended to enhance the transparency of our company's operations, notify you of your rights and our privacy-related obligations, and provide information regarding:

  1. the kinds of personal information which we will collect and hold;
  2. how we will collect, hold, use and disclose personal information;
  3. the purpose for which we collect, hold, use and disclose personal information;
  4. how you may access personal information that is held by us and seek correction of such information;
  5. how you may complain about a breach of the Australian Privacy Principles (APP) or registered APP code (if any) that binds us and how we will deal with such complaint;
  6. whether we are likely to disclose personal information to overseas recipients;
  7. If we are likely to disclose personal information to overseas recipients, the countries in which such recipients are likely to be located, and if practical specify those countries in the policy.

 

This privacy policy sets out how we comply with our obligations under the Privacy Act 1988 (Cth) (the Act), the General Data Protection Regulation (GDPR) and China's Personal Information Protection Law.

 

Acknowledgment

We acknowledge that we must take reasonable steps when handling personal information.

While we cannot warrant that this policy will be followed in every instance, we will endeavor to follow this policy on each occasion. Likewise, while we cannot warrant that loss, misuse or alteration of personal information will never occur, we will take all reasonable steps to prevent these things from occurring.

AVL has taken reasonable steps to endeavor to comply with the APPs and the Act, some examples are noted below.

  1. Implementation and review of this privacy policy from time to time.
  2. Staff training and education (including a handbook for our employees).
  3. Use of checklists to ensure that all APPs are complied with.
  4. Clear and transparent procedures regarding handling of complaints and disclosure of information.

 

Our policy is available on our website however should you require a hard copy please contact us and we will provide you with a copy.

How we collect and hold your personal information


We only collect and hold personal information by lawful and fair means.


This will likely occur in instances where:

  • you have provided personal information directly to us in the course of business dealings, through use of our mobile application, when you transact with us online, over the phone or in person, when you enter a promotion or competition conducted by us, when you use one of our websites or participate in social media run by us, when you visit one of our brand or corporate locations, or participate in an employment opportunity;
  • you have consented for this collection (which would usually be via our privacy policy and/or credit application form);
  • you would reasonably expect us to collect your personal information in this way and it is necessary for us to collect this information for a specific purpose (such as investigation of a complaint); or
  • the collection is authorized or required by law.


We will take steps to hold personal information in a manner which is secure and protected from unauthorized access and disclosure.


In some circumstances, we may collect and hold personal information that has been collected from a third party or publicly available source. If we collect personal information about you from someone else, we will advise you as soon as practicable that this information has been collected and the circumstances which surround the collection. Alternatively, the third party that we collect personal information about you from will advise you as soon as practicable that this information has been, or will be, disclosed to us.


Your information may be held in either a physical form or in electronic form on our IT system.

Where stored in electronic form on our IT system, we will take steps to protect the personal information against modification, disclosure or misuse by including such things as physical restrictions, password protections, internal and external firewalls, and anti-virus software.


We will also endeavor to ensure that our service providers have protection for electronic IT systems and other necessary restrictions.


We will endeavor to ensure our staff are trained with respect to the security of the personal information we hold, and we will restrict any access where necessary.


While we retain information for as long as necessary in relation to the purposes for which it is collected, we will endeavor to destroy and de-identify the personal information once it is no longer required, except as required for business record purposes.


In the event we hold personal information that is unsolicited, and we are not permitted to collect it, the personal information will be destroyed as soon as practicable.

The kinds of personal information which we will collect and hold
 

Collection

The types of personal information that AVL collects will depend on the nature of your dealings with us. Please note that while we seek to minimize the personal information we collect, if you do not provide us with the personal information we request, we may not be able to provide you with the services in the most effective or efficient manner, or at all, or you may not be able to be an AVL employee, contractor, supplier, or customer if the personal information requested is not provided.


It is our usual practice to collect personal information directly from the subject individual or their authorized representative(s).

Some examples of some personal information we might collect are:

  1. general identification information such as name, job title, and date of birth;
  2. contact details such as address, email address, phone and mobile phone number and Internet Protocol (IP) address;
  3. Information contained in identification documents such as passport or driver's licence;
  4. Financial information such as payment details/credit card information.

AVL also collects personal information necessary for employment and labor-contracting purposes. This information may include:

  • name, date of birth / age, business and personal contact (including emergency contact) information, photograph, national insurance number or equivalent, driver license number, passport number and other details;
  • citizenship and, where relevant, residency and work permit status and other immigration-related information;
  • relevant information regarding health and disabilities;
  • employment terms and conditions, date of hire and resignation / termination (with reasons and related information), employment history (with and before joining AVL), educational history, qualifications and results of background checks and assessment results;
  • contractor terms and conditions and related details;
  • vocational suitability, and criminal record;
  • Records of working hours, sickness and other absence records, records of training and development activities and plans and of performance appraisals and records of disciplinary and grievance processes, and depending on the nature of your position or engagement with AVL, records of your aspirations, mobility, and job competency assessments.

Sensitive information is a type of personal information and includes information about your health, race, ethnic origin, and religious and political beliefs, among other things.


AVL will not ask to collect sensitive information about you except where it is needed for the purposes of AVL's business or another reason for which we have your consent and collection is necessary for that purpose.


If we do collect sensitive information about you, we will only do so with your consent or where the collection is required or authorized by law (for example, any relevant public health directions or other laws in the jurisdiction or the request for your COVID-19 vaccination status).


We also use different types of technology to collect your personal information, including tracking technologies such as cookies. Please refer below and to our Terms of Use for more information regarding how we use cookies.

Identification

You may choose to interact with us using a pseudonym and/or not identify yourself.


In circumstances where we are required to do so, or are authorized by law, a court or tribunal to ask for your identification, we will request your personal information.


Further, it is likely that it will be impractical for us to interact with you without some form of identification, and therefore we will request identification details from you at the beginning of each transaction.


For example, we will not be able to open a commercial credit trading account or process a commercial credit application for you without obtaining identification details.


If you do not consent to the collection or your personal information, in accordance with this privacy policy, we may not be able to assist you with the provision of certain services.

 

Cookies and the collection of personal information via our website and mobile application

When you visit one of our websites, or use our mobile application, we may collect information about the session between your computer or mobile device and our website and/or mobile application through the use of cookies.

Cookies are text files which are stored on your computer or mobile device (by your web browser) that record specific information, such as which pages you visit, the information you have searched for, or the device you are using to access our website or mobile application.


We use cookies for the purposes of managing and improving our website and mobile application, improving our business functions, and gathering demographic information about the people who visit our websites and use our mobile application, among other things.


By using our websites or mobile applications, and not opting-out of cookies, you consent to our use of cookies in accordance with the terms of this Privacy Policy. You may elect to disable or turn off cookies in your web browser, however, this may impact upon the services we are able to offer you on our websites and may impact upon your ability to access certain features of our websites.


We also use Google Analytics (provided by Google Inc.), which enables us:

  1. to perform statistical analyzes of the demographics and interests of those who visit our websites (eg number of visitors, information on gender, age, location, interests and the like) to learn about our visitors; and
  2. to improve website friendliness and usability (eg on the basis of website traffic measurements).

 

Google Analytics collects demographics and interests data from the following sources:

  1. third-party DoubleClick cookie;
  2. Android Advertising ID; and
  3. IOS Identifier for Advertisers (IDFA).

 

The above information will be available to Google Analytics when the user is logged into Google services, which include, but are not necessarily limited to: 

  1. Google Chrome browser
  2. YouTube;
  3. Gmail;
  4. Chromebook laptop devices;
  5. Android mobile devices.

 

Our server will also automatically record your Internet Protocol address (IP address).

An IP address is a numerical design assigned to each device connected to a computer network by your internet service provider. While IP addresses can be used to identify the general physical location of a computer, they are otherwise anonymous, and we will not use your IP address to identify you.


Our websites may contain links to other websites, for your convenience and information. When you access a website other than an AVL operated website, please understand that AVL is not responsible for the privacy practices of that site or for the content, product or services provided by, or contained on, that website. We suggest that you review the privacy policies of each site you visit.

 

Your personal information and AVL's mobile application
 

Personal information of children

Our mobile application does not address any person under the age of 18.


We do not knowingly collect personal information from persons under the age of 18 years. In the event we have collected personal information from a person under 18 without parental consent, we will take steps to ensure that the personal information is destroyed.

Consent and usage

You consent to the use of your personal information to the extent set out above upon downloading our mobile application. Should you not wish us to collect and store your personal information, you must immediately inform us that you do not consent.


You may at any time after downloading our mobile application withdraw your consent for us collecting and using your personal information.


When using our mobile application, we will provide you with a prompt as to whether you want to provide access to your microphone, camera and/or location services (or any other service that may collect personal information) and any data that may be collected from those mobile phone functions.


Our mobile application may contain links to other sites that are not operated by us. If you click a third-party link, you will be directed to that third party's site. We strongly recommend that upon being re-directed to a third party's site, that you review the privacy policy of each site you may visit.


We have no control over and assume no responsibility for the contact, privacy policies or practices of any third-party sites or services.


We will take all reasonable steps to ensure that your personal information is kept secure. We cannot however guarantee its absolute security given that no method of electronic transmission or storage is 100% secure.

Third Party service providers

We may from time to time use third party service providers (such as Google Analytics) in order to:

  1. facilitate the use of our mobile application;
  2. provide our mobile application services on our behalf; or
  3. assist us in analyzing how our mobile application is used (including website traffic tracking and reporting).

 

These third-party service providers will have access to your personal information only for the functions listed above. They are under an obligation not to disclose or use your personal information for any other purpose.  

 

The purpose for which we collect and hold personal information
 

AVL will only use personal information for the purpose for which it was collected or for related purposes permitted by law. These uses include (but are not limited to) use of your personal information:

  • to effectively manage, operate and conduct its business;
  • to process transactions, process credit applications, and to send notices to you about your transactions;
  • to assess credit worthiness, review existing credit terms, assess credit guarantees (current and prospective);
  • to send administrative or account-related information to you;
  • to carry out human resource and legal / regulatory compliance functions, including to manage recruitment processes and assessing compliance with employment contracts and related AVL policies;
  • in connection with the fulfillment of a legal or regulatory obligation;
  • to deliver targeted marketing;
  • to send legal or other updates or correspondence relevant to us or you, and to market our goods to you;
  • to allow you to participate in interactive features of our mobile application (if you choose to do so);
  • to gather analysis or valuable information in order to improve our mobile application;
  • to monitor the use of our mobile application (including addressing and preventing technical issues);
  • in connection with your job or contractor application;
  • where we have a legitimate interest that is not overridden by your rights under the law;
  • for any reason that you (or your organisation) has provided consent;
  • for insurance purposes;
  • for the performance of a contract with you or your company;
  • to respond to any enquiries or complaints;
  • to comply with our legal and regulatory obligations and requests, including reporting to and/or being audited by national regulatory bodies;
  • to comply with court orders and exercise and/or defend our legal rights; and
  • for any purpose related and/or ancillary to any of the above or any other purpose for which your personal information was provided to us; and
  • providing customer support

We may also collect personal information (including sensitive information) for both the primary purposes specified herein and purposes other than the primary purposes, including the purpose of direct marketing.


We may also collect personal information from other credit providers, Credit Reporting Body (CRB) and any other third parties for the purposes of our functions and activities including, but not limited to, credit, sales, marketing and administration.

 

The purposes for which use and disclose personal information
 

We will endeavour to only use and disclose personal information for the primary purposes noted above in relation to the functions or activities of our company.


In addition, we may also use and disclose personal information (including sensitive information) for both the primary purposes specified herein and purposes other than the primary purposes, including the purpose of direct marketing.


Unless one or more of the below scenarios has occurred, we will take necessary steps to prevent personal information from being given to government agencies or other organisations.

  1.  You have provided your consent.
  2.  You would reasonably expect that your information would be so disclosed.
  3.  We have informed you that your personal information will be provided to a third party.
  4.  We are required by law to provide your personal information (including sensitive information) to a government agency or other organisation.
  5.  The disclosure of the information will prevent a serious threat to somebody's life or health.
  6.  The disclosure of the information is reasonably necessary for the enforcement of criminal law.
     

Further, we will endeavor to only disclose personal information for the purpose in which it was collected, unless disclosure is reasonably necessary to:

  1.   assist in locating a missing person;
  2.   lessen or prevent a serious threat to life, health or safety;
  3.   take appropriate action with suspected unlawful activity or serious misconduct;
  4.  facilitate or assist with diplomatic or consular functions or activities;
  5.  assist certain defense force activities outside Australia;
  6.  establish or exercise a defined legal or equitable claim; or
  7.  facilitate or assist confidential alternative dispute resolution activities.

 

Direct Marketing

We will take steps not to disclose personal information for direct marketing purposes unless consent has been provided.

In any event you will be provided with an opt out option with respect to direct marketing should you wish to be excluded from direct marketing communications.

If you do not elect to ‘opt out’ to receiving direct marketing material from us, you consent to us using personal information (other than sensitive information) provided to us for direct marketing purposes.

We may however use sensitive information for direct marketing purposes if you provide your consent to do so.

You may at any point in time, request to no longer receive direct marketing material from us by opting out.

We will record this information on our opt out register.

 

Direct Marketing and Third Parties

We may also from time to time, if we have received your consent, provide your personal information to a third party for the purposes of direct marketing.

You may at any time request the source of the personal information that has been disclosed.

 

Government Related Identifiers
 

We will endeavor not to use or disclose a government related identifier unless:

  1. The use or disclosure of the identifier is reasonably necessary for us to verify your identity for the purposes of our activities or functions; or
  2. the use or disclosure of the identifier is reasonably necessary for us to fulfill our obligations to an agency or a State or Territory authority; or
  3. the use or disclosure of the identifier is required or authorized by or under an Australian law or a court/tribunal order; or
  4. A permitted general situation (as that term is defined in the Act) exists in relation to the use or disclosure of the identifier; or
  5. We reasonably believe that the use or disclosure of the identifier is reasonably necessary for one or more enforcement related activities conducted by, or on behalf of, an enforcement body.

 

Disclosure to CRB's

We may disclose personal information to a CRB in accordance with the permitted disclosures as defined under the Act.

We may disclose your Credit Information to the following CRB's listed below.

Equifax
Level 15,
100 Arthur Street
NORTH SYDNEY
NSW 2060
Tel: 1300 921 621

NCI
Level 2,
165 Grenfell St
ADELAIDE SA 5000
Tel: 1800 882 820

Illion
Level 2,
143 Coronation Drive
MILTON QLD 4064
Tel: 07 3360 0600

Creditor Watch
Level 13,
109 Pitt Street
SYDNEY NSW 2000
Tel: 1300 501 312

Experian
Level 6,
549 St Kilda Road
MELBOURNE VIC 3004
Tel: 03 9699 0100

 

A copy of the credit reporting policy for the CRB's listed above will be available on their website or will be provided in hard copy upon request.

 

How you may access your personal information
 

You are entitled to access your personal information held in our possession. 

We will endeavor to respond to your request for personal information within a reasonable time period or as soon as practicable in a manner as requested by you. We will normally respond within 30 days.  

You can make a request for access by sending an email or letter addressed to our Privacy Officer, details specified below.  

The Privacy Officer  
Australian Vintage Limited 
275 Sir Donald Bradman Drive COWANDILLA SA 5033 
Phone: 08 8172 8301 
Fax: 08 8172 8399 
Email: [email protected]

 

With any request that is made we will need to authenticate your identity to ensure the correct person is requesting the information.   

We will not charge you for making the request, however if reasonable we may charge you with the costs associated with your request.   

You will only be granted access to your personal information where we are permitted or required by law to grant access. We are unable to provide you with access that is unlawful.  

Correction
 

Should we hold personal information and it is inaccurate, out of date, incomplete, irrelevant or misleading, or incorrect you have the right to make us aware of this fact and request that it be corrected.  

If you would like to make a request to correct your information, please contact our Privacy Officer on the details above.   

In assessing your request, we need to be satisfied that the information is inaccurate, out of date, incomplete, irrelevant or misleading. We will then take all reasonable steps to ensure that it is accurate, up to date, complete and not misleading.  

It is our normal policy to resolve any correction requests within 30 days. If we require further time, we will notify you in writing and seek your consent.  

Should we refuse to correct your personal information, written notice will be provided to you setting out:  

  1. the reasons for the refusal (except to the extent that, having regard to the grounds for the refusal, it would be unreasonable to do so); and
  2. the mechanisms available to complain about the refusal; and
  3. any other matter prescribed by the regulations.

 

We will endeavor to notify any relevant third parties of the correct personal information where necessary and required.   

 

Complaints
 

In the event that you wish to make a complaint about a failure of us to comply with our obligations in relation to the Act or the APP’s please raise this with our Privacy Officer on the contact details above.


We will provide you with a receipt of acknowledgment as soon as practicable.

We will then endeavour to respond to your complaint and attempt to resolve the issues within 30 days.

In dealing with your complaint, we may need to consult another credit provider or third party.

If you are not satisfied with the process of making a complaint to our Privacy Officer, or our response, you may make a formal complaint to the Office of the Australian Information Commissioner, details of which are below.

Office of the Australian Information Commissioner
GPO Box 5218 Sydney NSW 2001
Email: [email protected]
Telephone: 1300 363 992
Facsimile: 02 9284 9666

 

Disclosure to overseas recipients
 

We may choose to, if permitted by law, share and/or disclose your personal information with recipients outside of Australia.


We are required to notify you with a list of any countries which personal information may be transmitted to or disclosed, where it is practical for us to do so.


At this point in time, we may share and/or disclose personal information to overseas entities in countries including the UK, the USA and Japan.


If you have any queries regarding our credit reporting policy or wish to find out more regarding any of privacy policies, please contact our Privacy Officer on the details listed above.

Residents outside of Australia

For EU or UK residents, additional information regarding the data subject rights you may have is found in the “European Union - General Data Protection Regulation” section below.

For individuals within the territory of the People's Republic of China (the PRC), additional information regarding the categories of personal information we collect and the details for personal information protection is found in the “People’s Republic of China – Personal Information Protection Law (PIPL)” section below.

European Union - General Data Protection Regulation
 

We are bound by the GDPR when dealing with the personal information of EU residents.

For EU residents, set out below is a list of additional rights in relation to the handling of your personal information by us.

These rights are subject to restrictions under the GDPR, including exemptions. These rights may only apply to certain types of information and processing.


We note that we may not be able to fulfil a request made by you regarding your personal information due to our legal requirements or where the request would compromise the privacy of others.


For the avoidance of doubt, in the event of an inconsistency between this section of the privacy policy and the remainder of the policy, the former will prevail to the extent of the inconsistency in relation to EU residents.

 

  • Consent: We are required to obtain your consent for some of the ways we use your personal information. You may withdraw your consent at any time.
  • Access: You may request confirmation from us regarding whether your personal information is being processed and, if so, for what purpose.
  • Erasure: You may request that all records of your personal information be deleted.
  • Correction: you may request correction of inaccurate personal information.
  • Object to processing: You may object to the processing of your personal information.
  • Restriction to processing: You may request a restriction to the processing of your personal information.
  • Automated processing: You may request that we be restricted from making decisions about you based solely on automated processing.
  • Data portability: You may request that your personal information be transferred to you in a structured, commonly used and machine-readable format. You are entitled to transmit the personal information to another entity, or request that we do this for you.
  • Data breach notification: If a data breach occurs, we will, where feasible, notify the supervisory authority within 72 hours after becoming aware of the breach, unless it is unlikely to result in a risk to the rights and freedoms of individuals. We will also notify you without undue delay where the breach is likely to result in a high risk to your rights and freedoms.
  • Overseas transfer: Your personal information may be transferred to countries or international organisations outside the EU, provided that:

(a) The EU Commission has decided that the country or organisation ensures an adequate level of data protection; or

(b) Appropriate safeguards have been implemented and enforceable rights and remedies are available for individuals.

 

Any requests to us in accordance with the GDPR can be made by contacting the Privacy Officer on the details above.


Where applicable, you can find contact information for your data protection supervisory authority on the European Data Protection Board’s website, https://edpb.europa.eu/about-edpb/about-edpb/members_en, or through other publicly available sources.

People’s Republic of China – Personal Information Protection Law (PIPL)

We are bound by the PIPL when dealing with the personal information of China residents.


Under the PIPL, personal information refers to information related to identified or identifiable natural persons recorded by electronic or other means. Sensitive personal information refers to the personal information that is likely to result in damage to the personal dignity of any natural person or damage to his or her personal or property safety once disclosed or illegally used.


Except where required or permitted by law, AVL will not disclose your personal information with any person or organisation except in the following cases:

  • after obtaining your express consent or approval, we may share your personal information with other parties;
  • we may share your personal information in accordance with laws and regulations, litigation needs, or requirements of administrative and judicial authorities;
  • we may share your personal information with our related entities in order for us to jointly provide goods and services to you with our related entities, conduct business operations and comply with laws and regulations. We will only share necessary personal information subject to the purposes stated in this privacy policy.
  • your personal information may be shared with our third-party suppliers and partners in order for us to provide some services to you and for operational reasons. The types of personal information processed by these recipient(s) and the purposes and methods of their processing activities are the same as described in this privacy policy. We will only share necessary personal information subject to the purposes stated in this privacy policy, and will endeavour to ensure that these third parties who obtain your personal information will provide similar and/or comparable personal information protection measures.

You may withdraw your consent at any time. You may also object to the processing of your personal information.


You have the following rights:

  • the right to access, copy, correct and supplement your personal information, unless otherwise provided for by laws and administrative regulations;
  • to request us to delete your personal information If our purpose of processing has been fulfilled, you withdraw your consent, if AVL processes personal information in violation of laws or administrative regulations, or as otherwise provided by law and administrative regulations;
  • to obtain a copy of your personal information, subject to meeting the conditions specified by the national cyberspace department, and where technically feasible;
  • to change the scope of your consent for us to continue processing your personal information or withdraw your consent at any time by contacting us;
  • to require AVL to explain this privacy policy.

Any requests to us in accordance with the PIPL can be made by contacting the Privacy Officer on the details above.


AVL does not collect any data or information concerning persons who are under the age of 18, which is the legal age for alcohol drinking and purchasing in the PRC. We will try to delete the relevant information as soon as we are expressly aware that the subject is under the age of 18.


If a data breach occurs, we will, where feasible, notify the supervisory authority within 72 hours after becoming aware of the breach. We will also notify you without undue delay where the breach is likely to result in a high risk to your rights and freedoms.


AVL will retain your personal information for the period necessary to fulfil the purposes for which your personal information has been collected (as outlined in this privacy policy) unless a longer retention period is required by law.


AVL’s website, and its other brand websites, are hosted on servers outside of China. When you submit a request, make an inquiry or otherwise interact with us via our websites, your personal information will be transmitted to AVL and stored on its servers outside of China.


We may not be able to fulfil a request made by you regarding your personal information due to our legal requirements or where the request would compromise the privacy of others.


For the avoidance of doubt, in the event of an inconsistency between this section of the privacy policy and the remainder of the policy, the former will prevail to the extent of the inconsistency in relation to China residents.


Any requests to us in accordance with the PIPL can be made by contacting the Privacy Officer on the details above.

Changes to this privacy policy
 

We will update this privacy policy from time to time. In the case of any such changes, we will post the changed privacy policy on our website. The changes will take effect as soon as they are posted on this website. We therefore recommend that you read it each time you visit our website. If you do not agree with the privacy policy at any time, please do not continue to use or website. If you do continue to use our website, you are deemed to have accepted the terms of the privacy policy as they appear at the time of use.