Nanosonics privacy statement applies to the personal data of consumers that is collected or used by Nanosonics or its affiliates or subsidiaries (“we”, “us”, or “our”). This privacy statement describes why and how we collect and use personal data and provides information about individuals’ rights.
We may use personal data provided to us for any of the purposes described in this privacy statement or as otherwise stated at the point of collection. Personal data is any information relating to an identified or identifiable living person. Nanosonics processes personal data for numerous purposes, and the means of collection, lawful basis of processing, use, disclosure, and retention periods for each purpose may differ. When collecting and using personal data, our policy is to be transparent about why and how we process personal data.
Individuals who get in touch with us
Collection of personal data
We collect personal data when an individual gets in touch with us with a question, complaint, comment or feedback (such as name, contact details and contents of the communication). In these cases, the individual is in control of the personal data shared with us and we will only use the data for the purpose of responding to the communication.
Visitors to our website
Collection of personal data
We receive personal data, such as name and email address from website visitors; for example when an individual subscribes to updates from us.
Visitors are also able to send an email to us through the website. Their messages will contain the user’s email address, as well as any additional information the user may wish to include in the message. We ask that you do not provide sensitive information (such as race or ethnic origin; political opinions; religious or philosophical beliefs; trade union membership; physical or mental health; genetic data; biometric data; sexual life or sexual orientation; and, criminal records) to us when using our website; if you choose to provide sensitive information to us for any reason, the act of doing so constitutes your explicit consent for us to collect and use that information in the ways described in this privacy statement or as described at the point where you choose to disclose this information.
Use of personal data
When a visitor provides personal data to us, we will use it for the purposes for which it was provided to us as stated at point of collection (or as obvious from the context of the collection).
Typically, personal data is collected to:
- Subscribe to updates
• Enquire for further information
• Distribute requested reference materials
• Monitor and enforce compliance with our terms and conditions for use of our website
• Administer and manage our website, including confirming and authenticating identity and preventing unauthorised access to restricted areas, premium content or other services limited to registered users, and
• Aggregate data for website analytics and improvements.
Should visitors subsequently choose to unsubscribe from mailing lists or any registrations, we will provide instructions on the appropriate webpage, in our communication to the individual, or the individual may contact us.
Our websites do not collect or compile personal data for the dissemination or sale to outside parties for consumer marketing purposes or host mailings on behalf of third parties. If there is an instance where such information may be shared with a party that is not a Nanosonics company, the visitor will be asked for their consent beforehand.
Personal data collected via our websites will be retained by us for as long as it is necessary (e.g. for as long as we have a relationship with the relevant individual).
We take the security of all the data we hold very seriously. We have a framework of policies, procedures and training in place covering data protection, confidentiality and security and regularly review the appropriateness of the measures we have in place to keep the data we hold secure.
When and how we share personal data and locations of processing
We will only share personal data with others when we are legally permitted to do so as required. When we share data with others, we put contractual arrangements and security mechanisms in place to protect the data and to comply with our data protection, confidentiality and security standards.
We are part of a global organisation and in common with other businesses, we use third parties located in other countries to help us run our business. As a result, personal data may be transferred outside the countries where we and our clients are located. This includes to countries outside the European Union (“EU”) and to countries that do not have laws that provide specific protection for personal data. We have taken steps to ensure all personal data is provided with adequate protection and that all transfers of personal data outside the EU are done lawfully. Where we transfer personal data outside of the EU to a country not determined by the European Commission as providing an adequate level of protection for personal data, the transfers will be under an agreement which covers the EU requirements for any transfer of personal data outside the EU, such as the European Commission approved standard contractual clauses. The European Commission approved standard contractual clauses are available here. Personal data held by us may be transferred to:
- Third party organisations that provide applications/functionality, data processing or IT services to us
We use third parties to support us in providing our services and to help provide, run and manage our internal IT systems. For example, providers of information technology, cloud based software as a service providers, identity management, website hosting and management, data analysis, data back-up, security and storage services. The servers powering and facilitating that cloud infrastructure are located in secure data centres around the world, and personal data may be stored in any one of them where necessary to deliver goods and services.
- Third party organisations that otherwise assist us in providing goods, services or information
- Law enforcement or other government and regulatory agencies or to other third parties as required by, and in accordance with, applicable law or regulation
Occasionally, we may receive requests from third parties with authority to obtain disclosure of personal data, such as to check that we are complying with applicable law and regulation. We will only fulfil requests for personal data where we are permitted to do so in accordance with applicable law or regulation.
Changes to this privacy statement
We recognise that transparency is an ongoing responsibility so we will keep this privacy statement under regular review. This privacy statement was last updated on 4 June 2018.
Data controller and contact information
The data controller is Nanosonics Limited with its registration address at 14 Mars Road, Lane Cove, 2066 NSW for the purposes of providing or receiving services.
If you have any questions about this privacy statement or how and why we process personal data, please contact us.
Individuals’ rights and how to exercise them
Individuals have certain rights over their personal data and data controllers are responsible for fulfilling these rights. Where we decide how and why personal data is processed, we are a data controller and include further information about the rights that individuals have and how to exercise them below.
Access to personal data
You have a right of access to personal data held by us as a data controller. This right may be exercised by emailing us at firstname.lastname@example.org. We may charge for a request for access in accordance with applicable law. We will aim to respond to any requests for information promptly, and in any event within the legally required time limits (currently 40 days).
Amendment of personal data
To update personal data submitted to us, you may email us at email@example.com or, where appropriate, contact us via the relevant website registration page or by amending the personal details held on relevant applications with which you registered. When practically possible, once we are informed that any personal data processed by us is no longer accurate, we will make corrections (where appropriate) based on your updated information.
Withdrawal of consent
Where we process personal data based on consent, individuals have a right to withdraw consent at any time. To withdraw consent to our processing of your personal data please email us at firstname.lastname@example.org.
Other data subject rights
This privacy statement is intended to provide information about what personal data we collect about you and how it is used. As well as rights of access and amendment referred to above, individuals may have other rights in relation to the personal data we hold, such as a right to erasure/deletion, to restrict or object to our processing of personal data and the right to data portability. Some of these rights will only be available from 25 May 2018.
If you wish to exercise any of these rights, please send an email to email@example.com.
We hope that you won’t ever need to, but if you do want to complain about our use of personal data, please send an email with the details of your complaint to firstname.lastname@example.org.