Privacy
This privacy policy outlines the personal information handling practices of Acidgreen Pty Ltd which collects, uses and holds personal information of its users (hereinafter ‘User/s’) to exercise its functions as a digital commerce agency.
Acidgreen Pty Ltd (“Acidgreen”, “we”, “us”, “our”) is committed to protecting your personal information in accordance with:
- The Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs)
- The EU General Data Protection Regulation (GDPR) where applicable
Acidgreen is a subsidiary of DATASOLUTION (European Union) and this privacy policy aims to give a clear and brief outline of its personal information handling practices.
This policy is written in simple language. The legal obligations of Acidgreen as an Australian-based digital agency in respect of collecting and handling personal information are outlined in the Privacy Act and, in particular in the Australian Privacy Principles (APPs), found in Schedule 1 of that Act. In addition, Acidgreen also upholds European data handling norms conforming to the laws and regulation in effect.
Definitions
Personal information hereby means information or an opinion about an identified individual, or an individual who is reasonably identifiable:
- whether the information or opinion is true or not; and
- whether the information or opinion is recorded in a material form or not.
A cookie is a small file that a website stores on your computer or mobile device when you visit the site. It contains specific information about the server that dropped the cookie, an identifier with a unique number and an eventual expiration date. This data can be stored as a text file on a User’s computer that the server will access to read and save information. The information collected about you using cookies will not ordinarily be your personal information, because you will not be identified or reasonably identifiable from it.
Data Controller
Acidgreen Pty Ltd
ABN: 38 163 003 003
Registered Offices: 100 Market Street Sydney NSW 2000
E-mail: [email protected]
As Acidgreen Pty Ltd is a subsidiary of the DATASOLUTION Group, privacy-related inquiries and requests to exercise your data protection rights may be handled centrally by DATASOLUTION’s privacy team in France, in accordance with applicable data protection laws including the EU General Data Protection Regulation (GDPR) and the Australian Privacy Act 1988.
The contact address remains the same for EU-related matters.
What personal data we collect
Acidgreen collects User information to be able to provide the services the User has requested through the site.
The main way Acidgreen collects personal information about this site’s Users is when they provide it. When a User fills out the contact form or an open listing application, the personal information is collected to allow a provision of services.
All required and sometimes obligatory information collected in forms is necessary for, or directly related to, one or more of Acidgreen’s functions or activities. The optional feature of some collected information is marked by the absence of an asterisk on the field name.
In addition, some information can be collected after the User’s consent (check cookie policy).
Legal Basis for information handling – GDPR
Acidgreen Pty Ltd collects personal information from Users in order to provide the services to which they have subscribed or that are made available through our platform.
Certain information is mandatory in order to create an account, respond to inquiries, or deliver requested services. Mandatory fields are clearly indicated at the time of collection. Failure to provide mandatory information may prevent us from processing your request or providing the relevant services.
Under the EU General Data Protection Regulation (GDPR), the legal bases for processing are:
- Performance of a contract (Article 6(1)(b)) where processing is necessary to provide requested services;
- Legitimate interests (Article 6(1)(f)) where processing is necessary for business operations, security, or service improvement;
- Legal obligation (Article 6(1)(c)) where we are required to retain or disclose information under applicable laws;
- Consent (Article 6(1)(a)) where required, particularly for marketing communications or optional data collection.
Under the Australian Privacy Act 1988 (Cth), personal information is collected and handled in accordance with Australian Privacy Principles 3 and 6, for lawful and reasonable business purposes.
In addition, certain technical information may be collected following user interaction with the website. Where required under applicable law, such collection is based on user consent and further explained in our Cookie Policy.
Where required, processing is subject to user consent.
EU users may lodge a complaint with their local data protection authority or contact our HQ conformity team at: [email protected].
Data and personal information transfers
As part of DATASOLUTION, personal information may be transferred between Australia and the European Union.
Because Australia does not benefit from an EU adequacy decision, transfers from the EU to Australia are protected by:
- Appropriate technical and organisational safeguards
Transfers from Australia comply with APP 8.
All collected personal information is intended to fulfill business requirements and therefore can be sent to the marketing, sales and financial departments of Acidgreen and possibly DATASOLUTION. Personal information can be sent to other subsidiaries or subcontractors Acidgreen calls upon to provide their services.
In the event of a cross-continental transfer, the User will always be warned and asked to consent explicitly. Acidgreen and other subsidiaries apply the necessary measures to guarantee the safety and protection of all personal information in accordance with laws and regulations that are in effect.
No personal information is handed over or sold to third parties for marketing purposes, however divulgations may happen if:
- Prior consent is given
- An authority with legal jurisdiction demands personal information on the basis of judicial requisition or in case of litigation
Retention time of personal information
Acidgreen Pty Ltd retains personal information only for as long as necessary to fulfil the purposes for which it was collected, including for the provision of services, compliance with legal obligations, resolution of disputes, enforcement of agreements, and legitimate business operations.
Client and contractual records are retained for the duration of the commercial relationship and up to seven (7) years thereafter, unless a longer retention period is required by law. Marketing contact information is retained until consent is withdrawn or the individual opts out. Technical logs are retained for a limited period necessary for security and operational integrity.
Retention schedules are reviewed periodically to ensure compliance with evolving legal and regulatory requirements.
User Rights
Under GDPR (if applicable), the User has the right to:
- Access your personal data,
- Rectify inaccurate data,
- Request erasure (“right to be forgotten”),
- Restrict processing,
- Data portability,
- Object to processing,
- Withdraw consent at any time.
The User also has the right to notify the French supervisory authority, CNIL, in case of a breach of confidence or to report misuse regarding the handling of Your personal information.
Under Australian Privacy Law, you may request:
- Access your personal information,
- Correct inaccurate personal information,
- Request details about how your information is handled.
Under Australian law, you can also notify or escalate to the Office of the Australian Information Commissioner (OAIC).
All requests regarding User rights about personal information can be made to our privacy contact [email protected].
Cookies Policy (tbd)
A policy and CMP might be required once we can determine if Cookiebot can be deployed on the website.
Security
Acidgreen has implemented the appropriate technical and organisational measures to protect personal data from tampering or unauthorized access by third parties. A non-exhaustive list includes:
- Multi-level firewalls
- Trusted anti-virus solutions and intrusion detection software
- Encryption where appropriate through SSL/https/VPN technology
- Secure hosting with Tier 3 and PCI DSS abiding solutions
All access to data and date processing within Acidgreen and other DATASOLUTION subsidiaries requires data receivers to authenticate with a unique password and keycard that respects security requirements. Any data being exchanged on insecure channels is protected with technical measures to ensure no unauthorized third party can decipher it.
All questions about the Acidgreen website security can be addressed to [email protected].
Privacy policy updates
This privacy policy can be updated by the Acidgreen team to keep up with the laws and regulations in effect.
Contact
Feel free to contact us for any privacy-related inquiries or in regard to the Privacy Policy by e-mail at: