|
|
|
PRIVACY POLICY
- INTRODUCTION
- This Privacy Policy explains how BORANIC PTY LTD ABN 25 701 987 279 (we, us or our) collects, holds, uses, discloses and otherwise handles personal information in connection with our website (Website), software-as-a-service supply chain and compliance platform (Platform) and the services, functionality and features made available through the Platform (Services).
- In this Privacy Policy, Account means an account created to access or use the Platform or Services, and Customer Materials means information, documents, photographs, images, data and other materials uploaded, submitted, stored or otherwise provided through the Platform by or on behalf of a customer.
- This Privacy Policy applies to personal information we handle about individuals who interact with us, including:
- personnel, representatives and authorised users of our customers;
- individuals whose personal information is included in Customer Materials uploaded, stored or processed through the Platform;
- visitors to our website;
- people who contact us or request support; and
- other individuals whose personal information we lawfully receive in connection with our business, the Platform or the Services.
- Personal information generally means information or an opinion about an identified individual, or an individual who is reasonably identifiable.
- Our customers may use the Platform to upload, store and process information relating to their own business activities. Where a customer provides personal information about another individual through the Platform, the customer must ensure that it is authorised to provide that information and that its collection, disclosure and proposed use comply with applicable law; however, this does not limit our own obligations under applicable privacy law.
- This Privacy Policy should be read together with our Cookies Policy and, where applicable, the terms and conditions governing use of the Platform.
- If you have any questions or concerns about how we handle personal information, you can contact us using the details set out in this Privacy Policy.
- PRIVACY LAWS THAT MAY APPLY
- We handle personal information in accordance with the privacy and data protection laws that apply to us and the relevant processing activities.
- These may include:
- the Privacy Act 1988 (Cth) and the Australian Privacy Principles, to the extent they apply to us; and
- the European Union General Data Protection Regulation 2016/679 (GDPR), to the extent the GDPR applies to our handling of personal data.
- Where another privacy or data protection law applies to a particular individual, activity or processing operation, we will handle the relevant personal information in accordance with our applicable obligations under that law.
- Nothing in this Privacy Policy is intended to represent that we hold any particular information security accreditation, certification or government security approval unless expressly stated by us in writing.
- OUR ROLE IN HANDLING PERSONAL INFORMATION
- The role we have in relation to personal information depends on the circumstances in which we handle it.
- We generally determine how and why we handle personal information relating to our own business operations, including information relating to:
- our customers and their representatives;
- Account administration;
- subscriptions, billing and payments;
- support, enquiries and communications;
- security, fraud prevention and Platform administration; and
- our own marketing and business activities.
- Where a customer uploads, stores or processes personal information through the Platform as part of its own business activities, the customer generally determines the purposes for which that information is collected and used.
- Where the GDPR applies:
- we may act as a controller in relation to personal data where we determine the purposes and means of the relevant processing; and
- we may act as a processor where we process personal data contained in Customer Materials on behalf of and in accordance with the instructions of a customer acting as controller.
- Where we process personal information on behalf of a customer, that customer must ensure that it has an appropriate legal basis or other authority to collect and provide the information to us and to instruct us to process it through the Platform; however, this does not limit our obligations under applicable privacy law in respect of that processing.
- TYPES OF PERSONAL INFORMATION WE COLLECT
- The types of personal information we collect or hold will depend on how you interact with us, the Platform and the Services and may include:
- name, job title and role;
- business name, trading name and other business-related information connected with an individual;
- email address, telephone number, mailing address and other contact details;
- Account information, usernames and other authentication or access information;
- billing information, payment status, subscription information and transaction records;
- information contained in documents, photographs, images, records and other Customer Materials uploaded, stored or processed through the Platform;
- information relating to suppliers, customers, employees, contractors or other individuals that a customer or authorised user provides through the Platform;
- information included in requests, instructions, prompts or other material submitted to functionality that summarises, generates, extracts, classifies or otherwise processes information;
- information contained in outputs generated or processed through the Platform where those outputs relate to an identifiable individual;
- communications with us, including enquiries, support requests, complaints and other correspondence;
- information about how you access and use the website, Platform and Services, including IP address, device information, browser information, access times, activity logs, pages or features accessed and other technical or usage information;
- information collected through cookies and similar technologies as described in our Cookies Policy; and
- any other personal information that you or an authorised third party provides to us in connection with our website, Platform, Services or business operations.
- We may receive payment-related information from our payment processor, but payment card details may be collected and processed directly by the relevant payment processor rather than stored by us.
- We do not intend the Platform to be used to collect or process sensitive information unless the collection and processing are reasonably necessary for the relevant business purpose, expressly permitted by the Platform and undertaken with any consent or other authority required by applicable law. If you provide sensitive information to us, you must ensure that you are authorised to do so and that any consent or other legal requirement applicable to that information has been satisfied.
- The types of personal information we collect or hold will depend on how you interact with us, the Platform and the Services and may include:
- HOW WE COLLECT PERSONAL INFORMATION
- We may collect personal information directly from you, automatically through your use of the website, Platform or Services, or from third parties where it is lawful and appropriate for us to do so.
- We may collect personal information when you:
- create, administer or use an Account;
- subscribe to, purchase or use the Platform or Services;
- provide or update Account, business, billing or contact information;
- upload, submit, store or otherwise provide Customer Materials through the Platform;
- submit information, documents, photographs, prompts, instructions or other material for processing through the Platform;
- use features of the Platform, including document management, document summarisation, label generation, quality control or other functionality;
- make or receive payments in connection with the Services;
- contact us, request support, make an enquiry or complaint, or otherwise communicate with us;
- complete a form, survey or other request for information; or
- otherwise interact with our website, Platform, Services or business.
- We may automatically collect technical and usage information when you access or use the website, Platform or Services, including:
- IP address, browser type, device information and operating system information;
- login, access and authentication information;
- dates and times of access;
- pages, features or functionality accessed or used;
- system logs, error information, security events and other technical records; and
- information collected through cookies and similar technologies as described in our Cookies Policy.
- We may also receive personal information from third parties, including:
- our customers, where they provide personal information about their personnel, suppliers, customers, contractors or other individuals through the Platform;
- authorised users or representatives of our customers;
- payment processors in connection with subscription, billing and transaction information;
- service providers and other third parties that assist us to provide, secure, maintain or support the Platform and Services; and
- other persons or organisations where you have authorised the disclosure or where the disclosure is otherwise permitted by law.
- Where reasonably practicable, we will collect personal information directly from the individual to whom it relates. However, because the Platform is used by business customers to store and process Customer Materials, we may receive personal information about individuals directly from our customers or their authorised users without interacting with those individuals ourselves.
- Information collected through cookies and similar technologies is handled in accordance with this Privacy Policy and our Cookies Policy.
- USE OF YOUR PERSONAL INFORMATION
- We may collect, hold, use and disclose personal information only for the purposes described in this Privacy Policy, where reasonably necessary to provide, operate and support the Platform and Services, for a related purpose that an individual would reasonably expect, with any required consent, or as otherwise permitted or required by applicable law.
- We may use personal information to:
- create, administer and secure Accounts and manage authorised users;
- provide, operate, maintain and support the Platform and Services;
- process Customer Materials and perform functionality requested or enabled by customers, including document management, document summarisation, label generation, quality control and related functionality;
- process subscriptions, billing and payments;
- communicate with customers and authorised users about Accounts, subscriptions, the Platform and Services;
- respond to enquiries, support requests, complaints and other communications;
- monitor, maintain, secure, troubleshoot and improve the Website, Platform and Services;
- detect, investigate and respond to suspected fraud, misuse, security incidents or unauthorised activity;
- maintain business, administrative, transaction, support and compliance records;
- understand how the Website, Platform and Services are used and improve our products, functionality and customer experience;
- enforce our agreements and protect our rights, property, systems, customers and other persons;
- comply with applicable laws, lawful requests, court orders and requirements of competent regulatory or government authorities; and
- carry out other purposes that are disclosed to you at the time the personal information is collected or that are otherwise permitted by law.
- We may also use contact information to send marketing or promotional communications about our products or Services only where permitted by applicable law, including the Privacy Act 1988 (Cth) and Spam Act 2003 (Cth), and each electronic marketing communication will include a functional unsubscribe facility where required. Where required, we will obtain any necessary consent before sending those communications.
- You may opt out of receiving direct marketing communications from us at any time by:
- using the unsubscribe or opt-out mechanism provided in the relevant communication; or
- contacting us using the details set out in this Privacy Policy.
- Opting out of marketing communications will not prevent us from sending service-related, transactional, security, billing or other communications reasonably necessary in connection with your Account or use of the Platform and Services.
- We may disclose personal information to the following categories of third parties only where reasonably necessary for a purpose described in this Privacy Policy, with any required consent, or as otherwise permitted or required by applicable law:
- our employees, officers and personnel who require access to perform their duties;
- contractors, consultants and professional advisers;
- hosting, cloud infrastructure, software, security, support and other technology service providers;
- payment processors and billing service providers;
- providers of third-party functionality or integrations used in connection with the Platform or Services;
- our professional advisers, insurers, auditors and other business advisers;
- a purchaser, investor or other relevant party in connection with a proposed or completed sale, merger, restructuring or transfer of all or part of our business, subject to appropriate confidentiality arrangements;
- government, regulatory, law enforcement or judicial authorities where disclosure is required or authorised by law; and
- other persons where you have authorised the disclosure or where it is otherwise permitted by law.
- Some of our service providers or other recipients may be located outside Australia or may store or process information in other countries, and, where practicable, we will identify those countries or otherwise make current information about them available on request. Where we disclose personal information overseas, we will take reasonable steps required by applicable privacy law in connection with that disclosure.
- LEGAL BASES FOR PROCESSING UNDER THE GDPR
- Where the GDPR applies and we act as a controller, the legal basis on which we process personal data will depend on the circumstances and the purpose of the processing.
- We may process personal data where:
- the processing is necessary to enter into or perform a contract with you;
- the processing is necessary for our legitimate interests or the legitimate interests of another person, except where those interests are overridden by your rights and interests;
- the processing is necessary for us to comply with a legal obligation;
- you have given consent to the processing, where consent is the appropriate legal basis; or
- another legal basis permitted by the GDPR applies.
- Our legitimate interests may include:
- providing, operating, supporting and improving the Platform and Services;
- administering customer relationships and Accounts;
- maintaining the security and integrity of the Platform and Services;
- preventing fraud, misuse and unauthorised activity;
- communicating with customers and authorised users;
- managing and improving our business operations; and
- establishing, exercising or defending legal rights.
- Where we rely on consent, you may withdraw that consent at any time, subject to applicable law. Withdrawal of consent does not affect the lawfulness of processing carried out before consent was withdrawn.
- DE-IDENTIFIED AND AGGREGATED INFORMATION
- We may de-identify or aggregate information so that it no longer identifies, and cannot reasonably be used to identify, an individual.
- We may use and retain information that has been de-identified or aggregated so that no individual is reasonably identifiable for purposes including:
- analysing how the Platform and Services are used;
- monitoring performance, security and reliability;
- identifying trends and usage patterns;
- improving and developing the Platform, Services and functionality; and
- preparing internal business, operational or statistical information.
- We will take reasonable steps appropriate to the circumstances not to re-identify information that has been de-identified except where permitted or required by law.
- AUTOMATED PROCESSING AND AI
- The Platform may use automated systems, including artificial intelligence and other software-based processing, to perform functionality requested or enabled by customers.
- This functionality may include:
- summarising documents or information;
- extracting, organising or classifying information;
- generating or assisting with the generation of labels;
- processing information for quality control or other Platform functionality; and
- generating other outputs based on information or Customer Materials submitted through the Platform.
- Personal information contained in Customer Materials may be processed through these functions only where reasonably necessary to provide the relevant Service and will not be used to train a general-purpose artificial intelligence model unless the relevant customer has expressly authorised that use and the use is otherwise lawful.
- Automated or AI-generated outputs may contain errors, omissions or inaccuracies and should be appropriately reviewed before being relied on or used for business, compliance or other purposes.
- The Platform is not intended to use automated processing to make decisions that significantly affect an individual’s legal rights or interests unless that functionality is expressly identified and used in accordance with applicable law.
- Where applicable law requires us to provide specific information, safeguards or review rights in relation to automated decision-making, we will do so as required.
- SECURITY
- We take reasonable steps to protect personal information we hold from misuse, interference, loss, unauthorised access, modification and disclosure.
- The measures we use may include administrative, technical and organisational safeguards appropriate to the nature of the information and the circumstances in which it is held or processed.
- We also require customers and authorised users to take reasonable steps to protect their Account credentials, devices and systems used to access the Platform.
- No method of electronic transmission, storage or information security can be guaranteed to be completely secure. Accordingly, despite the measures we take, we cannot guarantee that personal information will never be subject to unauthorised access, disclosure, loss or other security incidents; however, this statement does not limit any obligation or liability that cannot lawfully be excluded or limited.
- If we become aware of a suspected data breach affecting personal information, we will promptly investigate and respond to the incident and, where the Privacy Act 1988 (Cth) applies, assess any suspected eligible data breach and notify affected individuals and the Office of the Australian Information Commissioner as required by law.
- RETENTION OF PERSONAL INFORMATION
- We retain personal information only for as long as reasonably necessary for the purposes for which it was collected or subsequently lawfully used, or as otherwise required or permitted by applicable law.
- The period for which we retain personal information may depend on matters including:
- the nature and sensitivity of the information;
- the purposes for which the information is held;
- the duration of a customer relationship or subscription;
- legal, regulatory, tax, accounting or record-keeping requirements;
- security, fraud prevention and dispute resolution requirements;
- the need to establish, exercise or defend legal claims; and
- our technical backup and disaster recovery processes.
- Personal information contained in Customer Materials may be retained while the relevant customer uses the Platform and afterwards only for the shortest period reasonably necessary for documented backup, security, legal or compliance purposes, subject to any agreed deletion requirements and applicable law.
- Information retained in backup systems may remain until the relevant backup is overwritten or deleted in accordance with our ordinary backup and retention processes.
- When personal information is no longer reasonably required, we will take reasonable steps to delete or de-identify it where required by applicable law.
- Nothing in this clause requires us to delete information that we are required or permitted by law to retain.
- LINKS
- Our Website or Platform may contain links to websites, services or resources operated by third parties.
- We do not control those third parties and are not responsible for their privacy practices, content or handling of personal information.
- If you access a third-party website or service through a link provided by us, you should review the privacy policy and other applicable terms of that third party before providing personal information to it.
- ACCESS, CORRECTION AND OTHER PRIVACY RIGHTS
- You may contact us using the details set out in this Privacy Policy if you wish to request access to, or correction of, personal information that we hold about you.
- Before responding to a request, we may take reasonable steps to verify your identity and authority to make the request.
- Where the Privacy Act 1988 (Cth) applies, we will respond to requests for access or correction within a reasonable period and in accordance with our obligations under that Act.
- We may refuse or limit access where permitted or required by law. If we refuse a request for access or correction, we will provide any notice or explanation required by applicable law.
- If you believe that personal information we hold about you is inaccurate, out of date, incomplete, irrelevant or misleading, you may ask us to correct it. We will take reasonable steps to correct personal information where required by applicable law.
- Where the GDPR applies to our handling of your personal data and we are acting as a controller in relation to that data, you may have rights including the right to:
- request access to personal data we hold about you;
- request correction of inaccurate or incomplete personal data;
- request deletion of personal data in certain circumstances;
- request restriction of processing in certain circumstances;
- object to certain processing activities;
- request portability of personal data in certain circumstances;
- withdraw consent where processing is based on consent, without affecting the lawfulness of processing carried out before withdrawal; and
- lodge a complaint with an applicable data protection supervisory authority.
- These rights are subject to applicable legal conditions, limitations and exceptions and may not apply in every circumstance.
- Where we process personal information on behalf of one of our customers and that customer determines the purposes and means of the relevant processing, the customer may be responsible for responding to requests relating to that information. If you submit such a request directly to us, we may refer you to the relevant customer or assist the customer in responding where required by applicable law or our agreement with that customer.
- We may retain information where retention is required by law or, to the extent permitted by law, only for so long as reasonably necessary to establish, exercise or defend legal claims, comply with legal obligations or address specific and documented business or security risks.
- CHANGE OF CONTROL
- If our business, or all or part of its assets, is sold, transferred, merged, restructured or otherwise subject to a change of control, personal information held by us may be disclosed or transferred to a prospective purchaser, purchaser, investor, successor or other relevant party to the extent reasonably necessary for that transaction and permitted by applicable law.
- Where appropriate, we will take reasonable steps to ensure that personal information disclosed in connection with a proposed transaction is subject to appropriate confidentiality arrangements.
- Following completion of a transaction, personal information may be transferred to and handled by the relevant successor or acquiring entity in accordance with applicable privacy and data protection laws.
- INTERNATIONAL TRANSFERS
- Personal information may be stored, processed or accessed in countries outside Australia, including where we use service providers or other third parties located overseas or whose systems or infrastructure are located overseas; where practicable, we will identify the likely countries of those recipients or otherwise make current information about them available on request.
- Where we disclose personal information to an overseas recipient, we will take the reasonable steps required by applicable privacy law to ensure that the recipient handles it consistently with applicable privacy protections, unless a lawful exception applies, and we remain accountable to the extent required by law.
- Where the GDPR applies and personal data is transferred from the European Economic Area to a country that is not recognised as providing an adequate level of data protection, we will use an appropriate safeguard or other lawful transfer mechanism where required by the GDPR.
- Depending on the circumstances, these safeguards may include contractual protections or another transfer mechanism permitted under applicable data protection law.
- Where Article 27 of the GDPR requires us to appoint a representative in the European Union, we will appoint a representative in accordance with the GDPR and make the representative’s contact details available as required.
- COMPLAINTS
- If you have a complaint about how we collect, hold, use, disclose or otherwise handle your personal information, please contact us using the details set out below.
- Your complaint should include sufficient information to allow us to understand and investigate the issue.
- We will:
- acknowledge and investigate the complaint within a reasonable period;
- take reasonable steps to address any issue identified through our investigation; and
- provide you with a response explaining the outcome of the complaint.
- If your complaint relates to personal information that we process on behalf of one of our customers, we may refer you to the relevant customer or work with that customer to respond to the complaint where appropriate.
- If you are not satisfied with our response and the Privacy Act 1988 (Cth) applies, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC).
- Where the GDPR applies to our handling of your personal data, you may have the right to lodge a complaint with the data protection supervisory authority in the country in which you reside, work or consider that an infringement of applicable data protection law has occurred.
- CHANGES TO THIS PRIVACY POLICY
- We may update this Privacy Policy from time to time to reflect changes to our business, Website, Platform, Services, privacy practices or applicable legal requirements.
- Any updated Privacy Policy will be published on our Website and will take effect prospectively from the date specified in the updated policy, except to the extent applicable law requires otherwise.
- Where a change materially affects how we handle personal information, we will take reasonable steps to provide prominent advance notice and obtain consent where required by applicable law before applying the change to personal information already collected.
- This Privacy Policy was last updated on 1 October 2026.
- CONTACT US
If you have any questions about this Privacy Policy or our privacy practices, or wish to request access to or correction of personal information, exercise an applicable privacy right or make a complaint, please contact us using the details below.
Name: BORANIC PTY LTD
Email: info@boranic.com
Address: 997 Waterworks Road, The Gap, QLD, Australia
Providing personal information to us does not of itself constitute consent to every use or disclosure of that information. We will handle personal information in accordance with this Privacy Policy, applicable law and, where required, any consent or other legal authority applicable to the relevant handling of that information.