A. General
I. What does this privacy policy regulate?
We attach great importance to the protection and security of your personal data. It is therefore important for us to inform you about what personal data we use for which purposes and what rights you have in relation to your personal data.
MyLiebherr Account
The "MyLiebherr Account" is your central user account at Liebherr-Hausgeräte GmbH. You have to register in order to create a MyLiebherr Account. Your can register on the “MyLiebherr Portal" (https://home.myliebherr.com). When you register via the MyLiebherr Portal, you will receive an e-mail with a confirmation link at the end of the registration process. You must click on the confirmation link in order to complete the registration process. Alternatively, you can also sign up for the MyLiebherr Account using your Google, Facebook or Microsoft accounts (hereinafter referred to as "Social Login"). Please note that we have no influence on the processing of your personal data by Google, Facebook and Microsoft. With your MyLiebherr Account you can use the Single-sign-on service of Liebherr-Hausgeräte GmbH (hereinafter referred to as "SSO"). SSO allows you to use other access-restricted digital services (hereinafter referred to as "Modules") connected to the SSO using identical access data. SSO allows you to navigate between modules without the need for a separate registration and login process. SSO automatically transfers the data stored in your MyLiebherr Account which are required for the use of the relevant modules to the respective module providers in order to offer you the best possible comfort. The modules are operated either by Liebherr-Hausgeräte GmbH or by subsidiaries of Liebherr-Hausgeräte GmbH.
Liebherr SmartDevice app
The Liebherr SmartDevice app allows you to view and configure the data of your Liebherr refrigerator and freezer. To use the Liebherr SmartDevice app, you need a WLAN-enabled module (hereinafter referred to as "SmartDeviceBox"), a MyLiebherr Account and an Internet connection. The SmartDeviceBox connects your Liebherr refrigerator and freezer to the Internet via a WLAN-enabled router. The SmartDeviceBox can be retrofitted to SmartDevice-enabled Liebherr refrigerators and freezers. Some Liebherr refrigerators and freezers already have the SmartDeviceBox integrated. In combination with the SmartDeviceBox, the Liebherr SmartDevice app allows you to control various functions of your Liebherr refrigerator and freezer, such as the cooling temperature, while on the move. With the Liebherr SmartDevice app, you can immediately see any important alarm messages, such as a door accidentally left open. The Liebherr SmartDevice app has a notification function that reminds you when the next air filter change is due or when the ventilation grille needs to be cleaned, for instance.
II. What are personal data and what does processing mean?
1. "Personal data" (hereinafter also referred to as "data") are any information that reveal something about a natural person. In addition to information that allows a direct inference about a specific person (such as a person’s name or e-mail address), personal data also include information that can be linked to a certain person with appropriate additional knowledge.
2. "Processing" refers to any action taken on your personal data (such as the collection, recording, organisation, ordering, storage, use or deletion of data).
B. Who is responsible for processing my data?
The Controller responsible for processing your data is Liebherr-Hausgeräte GmbH, Memminger St. 77-79, 88416 Ochsenhausen, Germany, Phone: +4973529280; Fax: +497352928408; E-mail: info.hau@liebherr.com.
C. Data processing in relation to the MyLiebherr Account
I. What data are collected for which purposes?
When calling up the MyLiebherr Portal, the following data are processed by our web server and stored in what are known as log files:
1. date of access to the MyLiebherr Portal
2. time of access to the MyLiebherr Portal
3. Internet address of the website on which you were when you called up the MyLiebherr Portal (URL)
4. files you access through the MyLiebherr Portal
5. amount of data transferred to you
6. your browser type and version
7. your operating system
8. the domain name of your Internet access provider (e.g. Telekom, Vodafone, etc.)
9. your (external) IP address
When registering and using a MyLiebherr Account via the MyLiebherr Portal without the use of Social Login, we process the following data in addition to the data mentioned in points 1-9 hereinabove:
10. registration date
11. your unique user ID (UPN)
12. date and time of the last successful login
13. your e-mail address
When registering and using a MyLiebherr Account via Social Login, we process the following data in addition to the data mentioned in points 1-13 hereinabove:
14. Social Login identification feature (so-called identifier)
Note: If you register or authenticate yourself with a Facebook Social Login, Facebook will also provide us with your last name, first name and profile picture in addition to the data listed in points 13 and 14. We do not process such data for any purpose.
Note: When you register or authenticate with a Google Social Login, Google will provide us with your last name, first name, and the link to your Google Plus profile in addition to the information listed in points 13 and 14. We do not process such data for any purpose.
Note: If you register or authenticate with a Microsoft Social Login, Microsoft will provide us with your last name and first name in addition to the information listed in points 13 and 14. We do not process such data for any purpose.
For the optimal use of the modules connected to the MyLiebherr Portal, we collect the following data on a voluntary basis in addition to the data mentioned in points 1-14:
15. your preferred language
16. your title
17. your address
18. your phone number
19. your Liebherr refrigerator and freezer serial number
20. your Liebherr refrigerator and freezer device type
21. your SmartDeviceBox serial number
We process the data listed in points 1- 21 for the following purposes:
1. to protect our website offer (data categories used: 1-9)
2. to register a MyLiebherr Account via the MyLiebherr Portal (data categories used: 10-13)
3. to register a MyLiebherr Account via Social Login (10-14)
4. for the central administration of user and profile data for SSO (data categories used: 10-21)
5. for the use of SSO (data category used: 11)
6. for transmission to the provider of the selected module (data categories used: 13, 15-21)
7. to support your MyLiebherr Account (data categories used: 1-21)
Note: Please note that your personal data could be transferred to countries outside the EU/EEA if the provider of one of your modules is based in such a country. We will seek your express consent prior to any transmission to such provider.
Processing for other purposes may only occur in so far as legal requirements under Article 6 (4) of the General Data Protection Regulation (GDPR) apply. In this case, we will of course comply with any requirements to provide information according to Art. 13 (3) GDPR and Art. 14 (4) GDPR.
II. On what legal basis do we process your data?
In principle, the legal basis for processing your data is Art. 6 GDPR, in so far as there are no further specific legal provisions.
The processing of your data is based on the following legal bases:
1. Data processing for the performance of contracts (Article 6 (1) (b) GDPR) (applies to purposes 2-7)
2. Data processing based on a balance of interests (Article 6 (1) (f) GDPR) (applies to purpose 1)
3. Data processing to fulfil a legal obligation (Art. 6 (1) (c) GDPR) (applies to purpose 1)
4. Consent (Article 6 (1) (a) GDPR) (applies to any transmission of your data to non-EU/EEA countries for purpose 6)
Our legitimate interests are:
Improvement of the stability, functionality and security of the Portal (applies to purpose 1)
If we process your data on the basis of a balance of interests, you have the right to object to the processing of your data under the provisions of Art. 21 GDPR.
We process your data only to the extent necessary for the fulfilment of the above mentioned purposes.
IV. To whom and for what purposes do we transfer which categories of your data?
Where necessary, we will transfer your data:
1. To the providers of the modules you actively use and possibly of other services (data categories 13, 15-21)
2. To other companies of the Liebherr Group, if this is necessary for the initiation, execution or termination of a contract or if there is a legitimate interest in the transfer on our part and your predominant legitimate interest is not in conflict with the same; (data categories 13-21)
3. To the Social Login provider of your choice (data category 14)
4. To the service providers we use to achieve the above purposes; (data categories 1-21)
5. To any court, arbitration tribunal, public authorities or legal advisor when required to comply with applicable law, or to assert, exercise or defend legal claims. (data categories 1-21)
IV. Will my data be processed outside the European Union?
Data transfer to Processors in countries outside the European Union (known as third countries) is only permitted (1) if you have given us your consent or (2) if the European Commission has decided that an adequate level of protection exists in a third country (Art. 45 GDPR). If the Commission has not made such a decision, we may only transfer your data to third parties located in a third country in so far as appropriate safeguards exist (e.g. standard data protection clauses adopted by the Commission or the supervisory authority in a specific procedure) and the enforcement of your rights is ensured.
V. When do we delete or anonymise your data?
We process your data as long as this is necessary for the relevant purpose, unless you have effectively objected to the processing of your data or have effectively revoked your consent.
As far as statutory retention obligations exist - e.g. in commercial law or tax law - we will have to save the relevant data for the duration of the retention obligation. After the expiry of the retention period, we check whether there is any further need for processing. If there is no such further necessity, your data will be deleted.
D. Data processing in relation to the Liebherr SmartDevice App
I. What data are collected for which purposes?
To use the Liebherr SmartDevice app, you need a MyLiebherr Account. In addition to the data in C.I., we also collect the following data from you:
1. the device data of your Liebherr refrigerator and freezer (serial number, selected name, model and type)
2. the sensor data of your Liebherr refrigerator and freezer (temperature status, compressor speed, open door status)
3. the device data of your Liebherr SmartDeviceBox (serial number, model, type, connection status)
4. the technical configuration of your device (model, manufacturer, operating system used, connection status)
We generally process such data only for the following purposes:
1. Provision of the functions of the Liebherr SmartDevice app (data categories used: 1-7)
2. Error analysis and improvement of the app (data categories used: 1-6 and data categories in C.I. 1-9)
Processing data for other purposes may only occur in so far as the legal requirements of Article 6 (4) GDPR apply. In this case, we will of course comply with any requirements to provide information according to Art. 13 (3) GDPR and Art. 14 (4) GDPR.
II. On what legal basis do we collect your data?
In principle, the legal basis for processing your data is Art. 6 GDPR, in so far as there are no further specific legal provisions.
Your data is processed based on one or more of the following legal bases:
1. Consent (Article 6 (1) (a) GDPR) (applies to purpose 2)
2. Data processing for the performance of contracts (Article 6 (1) (b) GDPR)(applies to purpose 1)
If we process your information based on your consent, you have the right to withdraw your consent at any time with future effect.
We process your data only to the extent necessary for the fulfilment of the above mentioned purposes.
III. To whom and for what purposes do we transfer which categories of your data?
Where necessary, we will transfer your data:
1. To other companies of the Liebherr Group, if this is necessary for the initiation, execution or termination of a contract or if there is a legitimate interest in the transfer on our part and your predominant legitimate interest is not in conflict with the same; (data categories 1-7)
2. To the service providers we use to achieve the above purposes; (data categories 1-7)
3. To any court, arbitration tribunal, public authorities or legal advisor when required to comply with applicable law, or to assert, exercise or defend legal claims. (data categories 1-7)
IV. Will my data be processed outside the European Union?
Data transfer to Processors in countries outside the European Union (known as third countries) is only permitted (1) if you have given us your consent or (2) if the European Commission has decided that an adequate level of protection exists in a third country (Art. 45 GDPR). If the Commission has not made such a decision, we may only transfer your data to third parties located in a third country in so far as appropriate safeguards exist (e.g. standard data protection clauses adopted by the Commission or the supervisory authority in a specific procedure) and the enforcement of your rights is ensured.
V. When do we delete or anonymise your data?
We process your data as long as this is necessary for the relevant purpose, unless you have effectively objected to the processing of your data or have effectively revoked your consent.
As far as statutory retention obligations exist - e.g. in commercial law or tax law - we will have to save the relevant data for the duration of the retention obligation. After the expiry of the retention period, we check whether there is any further need for processing. If there is no such further necessity, your data will be deleted.
VI. Liebherr SmartDevice App Skill for Amazon Alexa
Amazon Echo is Amazon hardware for voice input and output. Amazon Echo devices allow Amazon to analyse, evaluate and execute voice commands. Amazon Echo devices require an Amazon user account to function and can be extended to include additional features by adding so-called "skills". The Liebherr SmartDevice app skill allows you to control some functions of the Liebherr SmartDevice app via your Amazon Echo device through voice commands. This requires you to activate the Liebherr SmartDevice app skill in your Amazon account and link your MyLiebherr Account to this skill. Through this link, voice commands given by you can be interpreted by Amazon and sent to the Liebherr SmartDevice app for execution via an anonymous digital signature. Except for the data indicating that you have an Amazon account and a MyLiebherr Account, no personal data will be sent by us to Amazon or by Amazon to us.
VII. Liebherr SmartDevice App functions for Conrad Connect
Conrad Connect is a service of Conrad Connect GmbH that allows you to link the functions of the Liebherr SmartDevice app with various smart devices and apps supported by Conrad Connect. This makes it possible for a certain event (e.g. time) to trigger an action (e.g. activate SuperCool function). The use of Conrad Connect requires a Conrad Connect user account and can be extended with interfaces for additional functions by adding the manufacturer or brand. This connection enables you to control some functions of the Liebherr SmartDevice app via Conrad Connect. For this purpose you need to activate the Liebherr SmartDevice app in your Conrad Connect user account and link it to your MyLiebherr account. Except for the data indicating that you have a Conrad Connect user account and a MyLiebherr account, no Personal Data will be sent by us to Conrad Connect or by Conrad Connect to us.
VIII. Liebherr SmartDevice App Trigger for IFTTT
IFTTT is a service of IFTTT Inc., which allows you to combine the functions of the Liebherr SmartDevice app with various applications supported by IFTTT. In this way, a particular event (e.g. entering your home) can trigger a specific action (e.g. activating the Supercool feature). To use IFTTT, you will need to activate the Liebherr SmartDevice App Trigger in your IFTTT account and link your MyLiebherr Account to the Liebherr SmartDevice App Trigger. Except for the data indicating that you have an IFTTT account and a MyLiebherr Account, no personal information will be sent by us to IFTTT Inc. or sent by IFTTT Inc. to us.
IX. Liebherr SmartDevice app functions for HomeConnect Plus
HomeConnect Plus is an app that allows you to link the functions of the Liebherr SmartDevice app with various smart devices supported by HomeConnect Plus. In this way, a particular event (e.g. entering the home) can trigger an action (e.g. activate SuperCool function). The use of HomeConnect Plus requires a HomeConnect Plus user account and can be extended with interfaces for additional functions by adding the manufacturer or brand. This connection allows you to control some functions of the Liebherr SmartDevice app via HomeConnect Plus. For this purpose you need to activate the Liebherr SmartDevice app in your HomeConnect Plus user account and link your MyLiebherr account. With the exception of the date that you have a HomeConnect Plus user account and a MyLiebherr account, no personal data will be transmitted from us to HomeConnect Plus or by HomeConnect Plus to us.
X. Liebherr SmartDevice App Actions for Google Home
The Google Home Smart Speaker is Google hardware for voice input and output. With the Google Home Smart Speaker voice commands can be analysed, evaluated and executed by Google. The Google Home Smart Speaker devices require a Google user account to function and can be extended with interfaces for additional features by adding so-called “actions". The Liebherr SmartDevice app actions allow you to control some functions of the Liebherr SmartDevice app via your Google Home Smart Speaker device through voice commands. This requires you to activate Liebherr SmartDevice app actions in your Google account and link your MyLiebherr Account to these actions. Through this link, voice commands given by you can be interpreted by Google and sent to the Liebherr SmartDevice app for execution via an anonymous digital signature. Except for the data indicating that you have a Google account and a MyLiebherr Account, no personal data will be sent by us to Google or by Google to us.
E. How are my personal data secured against unauthorised access and loss?
We use technical and organisational security measures in order to secure your data against loss, incorrect modification and unauthorised access by third parties. Moreover, on our part, only authorised persons will ever have access to your data and they can only access it to the extent required within the framework of the purposes named above. All data is transferred in encrypted form.
F. Cookies
We use what are known as cookies in order to recognise your preferences and achieve optimum website design. This facilitates navigation and ensures a high level of user friendliness.
I. What are cookies?
Cookies are small files that are stored on your terminal device. They can be used to determine if there has already been communication between your terminal device and our MyLiebherr Portal. Only the cookie is identified on your terminal device. Personal data can then be stored in cookies if you have given your consent for this or where this is technically essential, e.g. for a secure login.
Further information on cookies is available at www.allaboutcookies.org.
II. What do we use cookies for?
We use cookies
- to check your registration status and user identification after successful registration
- to ensure a secure Internet environment;
- to check our website performance;
- to evaluate the manner in which you use our sites in order to improve our services. For example, we can detect when a process is too time-consuming and results in the user cancelling the process underway This knowledge enables the process steps to be simplified and made more customer-oriented;
- to improve user-friendliness, traceability for our user customers and the online experience.
We do not use your cookies in order to track your Internet activity outside of the MyLiebherr Portal and connected modules.
III. What type of cookies do we use and what is their purpose?
a. Session cookies
Session cookies are deleted when the browser is closed. They record navigation on the MyLiebherr Portal as well as the length of your visit, and save the content of your registration information for the duration of your visit to the MyLiebherr Portal. Session cookies also keep your login active during the session.
b. Persistent Cookies or Tracking Code
Persistent Cookies or Tracking Codes do not contain any personal data. They record where the website was accessed from, which search engine was used, which link was clicked and which search term was selected, as well as the user's location when accessing a website. They record the number of visits and the duration of the first, current and previous visit. These cookies only register visits to the MyLiebherr Portal. They are not activated when visiting other websites.
c. Re-Targeting or Remarketing
Our website uses so-called re-targeting technologies to make the website more interesting for you. This means your visit to certain websites is marked by cookies, which later identify visits to other websites. We are convinced that the insertion of personalised, interest-based advertising is generally more interesting to Internet users than non-personal advertising. The insertion of this advertising material on our partners’ pages is based on cookie technology and an analysis of previous usage behaviour. This form of advertising takes place completely anonymously. No personal data will be stored and no user profiles will be merged with your personal data.
d. Conversion Tracking
See Use of Google technology
I. Can I delete cookies that are stored on my terminal device?
You can delete the cookies that are saved for the MyLiebherr Portal. In this case, however, your individual data and content, including your cookie settings, will be lost and you will not be recognised as a returning visitor the next time you visit the MyLiebherr Portal.
II. Do you agree to our use of cookies?
The user concept of our MyLiebherr Portal includes some online features designed to make your visit as comfortable as possible. However, these only work with the help of cookies. Continued navigation on our website indicates your agreement to the use of these cookies. You can revoke your agreement at any time.
III. How can I withdraw my consent regarding the use of cookies?
If you do not want us to recognise your terminal device, you can prevent the storage of cookies on your terminal device by selecting "Do not accept cookies" in your browser settings. Please refer to the instructions from your browser producer for more details.
You can set your browser so that cookie storage is only accepted if you give your agreement. If you do not want to accept cookies from our service providers then you can select the setting 'block cookies from third party providers' in your browser.
You can usually search in the help function in the menu of your web browser to find out how to reject new cookies or deactivate those you have already received.
Please note, however, that certain 'essential' cookies are indispensable for unobstructed navigation on the MyLiebherr Portal and for selection and design. We use these cookies only to check the efficiency of MyLiebherr Portal and record visitor frequency.
G. Use of Google technology
I. How can I prevent the storage of Google technology (cookies)?
If you do not want Liebherr-Hausgeräte GmbH to collect and analyse data about your visit, you can object to this at any time with future effect (so-called "Opt-Out").
For the technical implementation of this objection, an "Opt-Out cookie" will be set in your browser. This cookie is only used to signify your objection. Please note that for technical reasons "Opt-Out cookies" can only be used for the browser from which they are set. If you delete cookies or use another browser or device, you will need to opt out again.
Install the “Opt-Out-Cookie” directly here. Alternatively, you can download and install the browser plug-in available under the following link
II. What is Google Analytics?
MyLiebherr Portal uses Google Analytics, a web analytics service provided by Google Inc., 1600 Amphitheater Parkway, Mountain View, CA 94043, USA ("Google"). Google Analytics uses cookies that are stored on your device to analyse your use of the website. The information generated by the cookie about your use of this website is usually transmitted to and stored by Google on servers in the United States.
We have activated IP anonymisation on the MyLiebherr Portal, so your IP address will be shortened by Google within the member states of the European Union or other parties to the Agreement on the European Economic Area. Only in exceptional cases will the full IP address be sent to a Google server in the USA and shortened there. On behalf of Liebherr-Hausgeräte GmbH, as the operator of the MyLiebherr Portal, Google will use the above information to evaluate your use of the MyLiebherr Portal, to compile reports on website activity and to provide other services related to website activity and internet usage to Liebherr-Hausgeräte GmbH.
The IP address provided by Google Analytics as part of Google Analytics will not be merged with other Google information. You can prevent the storage of cookies through the corresponding settings in your browser software; however, please be aware that if you do this you may not be able to use the full functionality of this website.
You may also prevent Google from collecting the data (including your IP address) generated by the cookie in relation to your use of the website, as well as from processing such data with effect for the future, by downloading and installing the browser plug-in available from the following link: http://tools.google.com/dlpage/gaoptout?.
III. What is Google AdWords?
We use the Google AdWords online advertising program and conversion tracking as part of Google AdWords. The conversion tracking cookie is set when a user clicks on a Google-served ad. These cookies lose their validity after 30 days and are not used for personal identification.
If the user visits certain pages on the advertiser's website and the cookie has not expired, Google and the customer will be able to recognize that the user clicked on the ad and was redirected to that page. Each customer receives a different cookie. Cookies cannot therefore be tracked through the websites of AdWords customers.
The information obtained using the conversion cookie is used to generate conversion statistics for AdWords customers who have opted for conversion tracking. Customers are told the total number of users who clicked on their ad and were redirected to a conversion tracking tag page. However, they do not receive any information which would make it possible to personally identify users.
Google AdWords is only used if you expressly agree to this use through the so-called cookie canner. If you want to disable cookies for conversion tracking, you can set your browser to block cookies from the domain "googleadservices.com".
For more information on "Data Protection" in relation to the online advertising program Google AdWords, please visit https://www.google.com/policies/privacy.
IV. What is DoubleClick?
DoubleClick by Google is a service provided by Google Inc., 1600 Amphitheater Parkway, Mountain View, CA 94043, USA ("Google"). DoubleClick by Google uses cookies to show you advertisements that are relevant to you. Your browser will be assigned a pseudonymous identification number (ID) to monitor which ads have appeared in your browser and which ads have been viewed. The cookies do not contain any personal information. Using the DoubleClick cookie allows Google and its affiliate websites to serve ads based on previous visits to our or other websites on the Internet. The information generated by the cookies is transmitted for evaluation by Google to a server in the USA and stored there. Google only transfers data to third parties due to legal regulations or in the context of order data processing. Under no circumstances will Google merge its data with other data collected by Google.
By agreeing to this through the banner displayed on your first visit to the Liebherr website, you consent to the processing of the data collected by Google about you, the manner of processing described above and the stated purpose. You can prevent the storage of cookies through the corresponding settings in your browser software; however, we would like to point out that in this case you may not be able to use all functions of the Liebherr website in full.
You may also prevent Google from collecting the data generated by the cookies relating to your use of the Liebherr website and processing such data by downloading and installing the browser plug-in available at https://adssettings.google.com/ under the item DoubleClick Deactivation Extension. Alternatively, you can disable DoubleClick cookies on the Digital Advertising Alliance website at the following link: http://optout.aboutads.info/?c=2#!/
H. Data Subject Rights and Right of Appeal
Within the legal framework, you have the right to
1. information about your data;
2. the correction of incorrect data and completion of incomplete data;
3. the deletion of your data, in particular, if (1) they are no longer necessary for the purposes stated in this privacy policy, (2) you withdraw your consent and there is no further legal basis for processing, (3) your data have been unlawfully processed or (4) you have objected to the processing and there are no legitimate reasons for processing.
4. Limitation of the processing of your data, especially should you dispute the accuracy of the data or the processing of your data is illegal and you demand limitation of use in place of deletion.
5. The right to receive your data in a structured, standard and machine-readable form and to demand that we transfer your data directly to another responsible party.
Please note that the lawfulness of processing based on consent prior to your withdrawal of such is not affected by your withdrawal of consent.
We ask for your understanding that, where the above rights are not asserted in writing, we may require you to provide evidence proving that you are the person you claim to be. You also have a right of appeal with the responsible supervisory authority.
I. How do I contact the Data Protection Officer?
Should you have any questions regarding data protection please contact:
Data Protection
Liebherr-IT Services GmbH
St. Vitus 1
88457 Oberopfingen, Germany
J. Australian customers
The following terms apply to you if you are located in Australia when you create an account for the SmartDevice app (and then subsequently when you use the SmartDevice app or otherwise interact with us).
I. Application of Privacy Act
Liebherr-Hausgeräte GmbH is a foreign organisation with an Australian link, as those terms are defined in the Privacy Act 1988 (Cth) ("Privacy Act"), and is therefore an "APP entity" for the purposes of the Privacy Act, and is bound by the Australian Privacy Principles contained in the Privacy Act.
II. Collection of personal information
We will collect your personal information directly from you, unless it is unreasonable or impracticable to do so. If circumstances require, we may collect personal information about you from third parties (such as from employees or representatives of our service providers or other entities that we engage with in providing products or services to you) or publicly available resources. All personal information we collect is limited to that which is reasonably necessary for our functions or activities. If your MyLiebherr Account is to be registered using an account you hold with a third party (such as Facebook, Google or Microsoft) we may collect your personal information from that third-party organisation.
We receive any personal information that you provide to us about third parties on the understanding that you have obtained for our benefit the relevant individual's consent for us to collect and handle their personal information in accordance with this Privacy Policy.
When collecting your personal information, we will take reasonable steps to make you aware of the purposes for which we are collecting it, the types of organisations to which we would usually disclose it, whether we are likely to disclose it to overseas recipients, whether there are laws or court/tribunal orders which require or authorise us to collect it, and the main consequences for you if you fail to provide it to us. This Privacy Policy provides these details as they typically apply in most cases, however different details may apply depending on our specific interaction with you. If we do not notify you of such other details, the information in this Privacy Policy applies.
If you fail to provide personal information requested by us, or if the personal information you supply is incorrect or incomplete, there may be a range of consequences, for example we may be unable to process or respond to your request. There will not usually be Australian laws or court/tribunal orders which require or authorise us to collect your personal information.
We do not generally collect sensitive information. If we do collect sensitive information (which may include details of health or disability), we will only do so with your consent and if the information is reasonably necessary for one of our functions or activities. We will assume you have consented to us collecting, using and disclosing (in accordance with this Privacy Policy) all personal information (including sensitive information) that you provide to us (such as by allowing such information to be captured by any camera connected to the SmartDevice app).
III. Direct marketing
You consent to receive, and agree that we may send you, marketing or promotional communications by post or by electronic means (including email, SMS or through the SmartDevice app). You may request to not receive such material from us by contacting us via the details below or by using the opt-out function provided for in those communications. If you do not opt-out in either of these ways you will be taken to have consented to receiving such communications from us. There are no consequences of opting-out of receiving our marketing and promotional communications except that you will no longer receive them, and you may elect to re-join our marketing list at a later stage if you wish.
IV. Disclosure to overseas recipients
We may disclose your personal information to overseas recipients. Generally, we will obtain your consent to do so except where it is unreasonable, impractical or where we are not required to do so under the Privacy Act or other applicable law.
Your personal information that we collect may be disclosed to recipients in any of the countries in which we, our related entities or our services providers operate. We do not accept any responsibility for the actions of overseas third-party recipients of personal information.
V. Access to and correction of personal information
You may contact us to request access to or correction of the personal information we hold about you. We may refuse to allow access or to amend your personal information if we are legally required or entitled to do so. If we do that, we will provide you with written reasons for the refusal (unless it is unreasonable to do so) together with information about the options available to complain about the refusal.
We may require you to pay certain costs in order to access your personal information held by us. We will advise the amount payable (if any) once we have assessed your application for access. We will not charge a fee for you to lodge a request for access to or correction of your personal information.
If you lodge a request for access to your personal information, we may fulfil that request in any of a range of ways (for example, by supplying you with a copy of that personal information or providing you with the opportunity to inspect our records). We may require you to comply with certain procedures before we allow access to or amendment of your personal information to ensure the integrity and security of information that we hold. Depending on the nature of your request, this may include completing a personal information request form or otherwise verifying your identity to our satisfaction.
We will take reasonable steps to ensure that the personal information that we collect is accurate, up-to-date and complete and the personal information we use and disclose is accurate, up-to-date, complete and relevant. If we are satisfied that any personal information we hold about you is inaccurate, out-of-date, incomplete, irrelevant or misleading, we will amend our records accordingly.
VI. Data breach
If a data breach or suspected data breach occurs, we will undertake a prompt investigation, which will include an assessment of whether the incident is likely to result in serious harm to any individuals. In such a situation we will comply with the requirements of the Privacy Act which may require notification to the Office of the Australian Information Commissioner ("OAIC") and affected individuals. Please contact us if you have reason to believe or suspect that a data breach may have occurred, so that we can investigate and, if necessary, undertake appropriate containment, risk mitigation and notification activities as required.
VII. Complaints
If you have a complaint about the way in which we handle your personal information, or you believe that a breach of your privacy has occurred, please contact our Data Protection Officer using the information set out above.
Your complaint will be considered and dealt with by our Data Protection Officer, who may escalate the complaint internally within our organisation if the matter is serious or if necessary to resolve it.
Please allow us a reasonable time to respond to your compliant. If you are not satisfied with our resolution, you may make a complaint to the OAIC whose contact details can be found at: http://www.oaic.gov.au/.
Last updated: March 2021