Supplement · Australia
Australia (Privacy Act 1988) Supplement
Last updated:
1. Applicability & small-business exemption
The Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) apply to APP entities, which include most organisations with an annual turnover of AU $3 million or more. We do not currently meet that threshold and therefore qualify for the small-business exemption in s 6D of the Privacy Act. Notwithstanding the exemption, we voluntarily apply the APPs to our handling of personal information about individuals in Australia. If we exceed the threshold, or if any other limb of the “small business operator” carve-out ceases to apply (e.g., we trade in personal information), we will publish that change here.
The Australian Government has announced reforms that may abolish the small-business exemption. If and when those reforms commence, we will become bound by the Privacy Act automatically — no change to your rights is necessary.
2. The Australian Privacy Principles
Our handling of personal information aligns with APP 1–13: open and transparent management (APP 1); anonymity/pseudonymity option where practicable (APP 2); collecting only what is reasonably necessary (APP 3); dealing with unsolicited personal information (APP 4); notifying you at or before the time of collection (APP 5); using or disclosing personal information only for the primary purpose or a related purpose you would reasonably expect (APP 6); not using or disclosing personal information for direct marketing without consent (APP 7); restrictions on cross-border disclosure (APP 8); not using government identifiers as our own identifier (APP 9); ensuring quality (APP 10); securing the information (APP 11); giving access on request (APP 12); and correcting on request (APP 13). The global Privacy Policy operationalises each.
3. Cross-border disclosure (APP 8)
Personal information about Australian users is disclosed to overseas recipients — principally our sub-processors located in the United States and the European Union. Before disclosing, we take reasonable steps to ensure the recipient does not breach the APPs in relation to the information. Under APP 8.1 we remain accountable for the acts of overseas recipients as if we had done the act ourselves, subject to the exceptions in APP 8.2.
4. Notifiable data breaches
Where the Privacy Act applies to us, we will comply with the Notifiable Data Breaches scheme in Part IIIC and notify the Office of the Australian Information Commissioner (OAIC) and affected individuals as soon as practicable after we become aware of an eligible data breach. While the small-business exemption applies, we apply the same procedure on a voluntary basis.
5. Your rights
- Access (APP 12) — request a copy of the personal information we hold about you.
- Correction (APP 13) — request correction of information that is inaccurate, out of date, incomplete, irrelevant, or misleading.
- Anonymity / pseudonymity (APP 2) — interact with us under a pseudonym where practicable; note that this is not practicable for a paid subscription because we must invoice you.
- Withdraw consent — for any processing we conduct on consent.
- Opt out of direct marketing (APP 7) — unsubscribe link in every marketing email; we honour it within five (5) business days.
We respond to access and correction requests within thirty (30) days, free of charge.
6. Complaints to the OAIC
If you are not satisfied with how we have handled your personal information or with our response to a request, you may complain to the Office of the Australian Information Commissioner — oaic.gov.au — including by submitting an online privacy complaint form. We ask that you contact us first so we have the opportunity to resolve the matter.
7. Contact
Email privacy@poigeo.app. Postal address: [Şirket — kuruluş aşamasında].