Privacy policy
PRIVACY POLICY
Last updated: 16 June 2022
VALD Pty Ltd (ABN 16 603 446 171)
This Privacy Policy applies to VALD Pty Ltd and its affiliates and related bodies corporate (including VALD Operations Limited, VALD Performance (Aust) Pty Ltd, VALD Performance (Intl) Pty Ltd and VALD Group Inc) (VALD, we, us, our) in relation to their operations. It explains how we handle personal information and comply with the requirements of applicable privacy laws and other related laws regulating the handling of personal information, including without limitation the General Data Protection Regulation EU 2016/269 (“GDPR“) and applicable EU Member State laws (Privacy Laws). For the purposes of EU data protection law, the data controller is VALD Pty Ltd. If you have further questions relating to this policy please contact Sam James at DPO@vald.com.
This Privacy Policy also serves as notification to individuals of the matters required to be notified on collection of their personal information.
We recognise the importance of your privacy, and that you have a right to control how your personal information is collected and used.
1. Collection of personal information
1.1 We collect personal information from clients (existing and prospective), as well as end users of the VALD websites, VALD software and applications (including the TeleHab platform, VALD Hub, or the software that interfaces with VALD’s products) (Apps) and individuals who engage with us via our social media accounts. We also collect personal information from suppliers, contractors, investors, shareholders, prospective employees, and consumers and other individuals who interact with us or our clients for various business and other purposes further listed in section 2.2 below. In this section 1, we explain the kinds of personal information which we usually collect and hold as well as how we collect this information.
1.2 The kinds of personal information VALD will collect and hold about you will depend on the circumstances in which that information is collected. It may include:
(a) contact details which may include your name, address, email and phone details;
(b) age or date of birth information;
(c) personal information that you include in any content that you enter into the VALD websites or the Apps, being any information relating to a natural person who can be identified, directly or indirectly, by reference to that information (e.g. name, identification number, location data, or one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identify of a person);
(d) information required for you to open a trading or subscription account with us or subscribe to any of the VALD websites or the Apps or to otherwise do business with us, including bank account details, and any other relevant financial information;
(e) your device/s ID, device type, geo-location information, dates and times of visits, computer and connection information including browser type and operating system, statistics on page views, traffic to and from the sites and referring website addresses, ad data, IP address, standard web log information including online usage, and any other information or online analytics regarding the use of the VALD websites and the Apps, unless you object to such processing pursuant to rights that exist under applicable Privacy Laws (including the GDPR);
(f) information regarding the use of the VALD websites and the Apps, including users’ IP addresses and the dates, the country from which the user accessed the websites and the Apps, times and durations of visits, referring website address and device location, unless you object to such processing pursuant to rights that exist under applicable Privacy Laws (including the GDPR);
(g) information on your dealings with VALD, including details of the products and services we have provided to you or that you have enquired about, including any additional information necessary to deliver those products and services and respond to your enquiries;
(h) behavioural information and information on personal lifestyle preferences and past behaviours;
(i) information regarding the use of the VALD websites and the Apps, including users’ IP addresses and the dates, the country from which the user accessed the websites and the Apps, times and durations of visits, referring website address and device location;
(j) any additional information relating to you that you provide to us directly through our websites or the Apps or indirectly through your use of our websites or the Apps or online presence or through other websites or accounts from which you permit us to collect information; and
(k) information you provide to us through customer surveys.
1.3 If you are a healthcare professional, we may collect additional personal information including:
(a) your medical specialty; and
(b) your clinical interests.
1.4 If you are a patient, we may collect additional personal information including:
(a) details of your healthcare professional; and
(b) information about your health, including medical conditions.
1.5 We usually collect personal information either directly from you, someone acting on your behalf, or from third parties through:
(a) your use of VALD websites and the Apps, including when you register or subscribe for an account, create a profile, post or otherwise submit content or via our use of website analytics;
(b) use of social media;
(c) information that you communicate to us including through correspondence, chats, and other social media applications, services or websites, email, telephone, SMS, third party apps and any other forms of communication sent or given to us electronically or in hard copy;
(d) interaction with our services, content and advertising;
(e) orders for products or services;
(f) third party service providers;
(g) requests for brochures, to join a mailing list or to be contacted for further information about our products or services;
(h) warranty claims;
(i) provision of customer service and support;
(j) our shareholder registry;
(k) responses to surveys or research conducted by us or on our behalf; and
(l) entries into competitions or trade promotions conducted by us or on our behalf.
1.6 If you do not provide us with the information we request, we may not be able to fulfill the applicable purpose of collection, such as to supply products or services to you or to assess your application for employment.
1.7 Where reasonable and practicable, we will collect personal information directly from you. If we collect information about you from someone else (for example, from someone who supplies goods or services to us), we will ensure you are aware that we have collected personal information about you and the circumstances of the collection and provide any additional disclosure required under applicable Privacy Laws (including the GDPR).
Sensitive Information (or special categories of personal information)
1.8 Given the nature of the VALD websites and the Apps, it is possible that there could be instances where we collect sensitive information or special categories of personal data (as defined under relevant Privacy Laws) such as:
(a) health information or data relating to health; and
(b) other sensitive information or special categories of personal data (as defined under relevant Privacy Laws), but only where you choose to disclose it to us via the VALD websites and the Apps.
1.9 Depending on the applicable Privacy Laws, we will only collect such information about you:
(a) with your consent (or explicit consent, if the GDPR applies); or
(b) where otherwise permitted by law.
2. Use and disclosure of personal information
2.1 We will only use and disclose your personal information in accordance with Privacy Laws and in accordance with this Privacy Policy.
2.2 Our main purposes for collecting, holding, using and disclosing personal information are the following:
(a) to supply products or services to our customers and end users of our websites and the Apps;
Legal basis: we need to process your personal information in order to perform our contractual obligations to you as our customer or end user in relation to the supply of products or services.
(b) to manage your account with us;
Legal basis: it is in our legitimate business interests to collect and process your personal information to enable us to deliver our products and related services to you, our customers, and to manage your account with VALD.
(c) to obtain products and services from our suppliers;
Legal basis: it is in our legitimate business interest to process minimal amounts of business contact information in order to conduct business with our third party suppliers.
(d) to respond to enquiries from existing or prospective customers seeking information about our products or services;
Legal basis: it is in our legitimate business interests to collect and process personal information to provide quality customer service and assistance to our valued customers (existing or prospective).
(e) to assess and process warranty claims;
Legal basis: it is in our legitimate business interests to process your personal information in order to assess and process warranty claims.
(f) to process and assess employment applications;
Legal basis: it is in VALD’s legitimate business interest to collect personal information relating to job applicants/candidates. This enables VALD to contact candidates and conduct other reasonable enquiries as part of the recruitment process.
(g) to enforce agreements between you and VALD;
Legal basis: we may process your personal data for the performance of an agreement between you and VALD (including enforcement of agreements).
(h) to undertake research and surveys and analyse statistical information including the disclosure of de-identified, aggregated statistics created using your personal information (including health data) to third parties if you have given VALD express consent, in writing, to do so;
Legal basis: it is in our legitimate business interests to collect and process personal information to monitor, evaluate and improve our products and service offerings and ensure they are tailored to our customers’ needs and preferences. Further, personal data can be shared with approved third parties in circumstances where you have provided express written consent for VALD to do so.
(i) to communicate updates or orders with you, including for competitions and trade promotions; and
Legal basis: we will only process your data in this way if you have provided consent and have not unsubscribed from receiving such information.
(j) to comply with applicable laws and with our policy requirements including in relation to occupational health and safety and environmental matters.
Legal basis: we may need to process your personal information in order to comply with applicable laws.
2.3 We will only use or disclose personal information for a purpose other than for which it was collected or a related purpose if you have consented to such different use or disclosure or to the extent that such use or disclosure is permitted by applicable law.
2.4 In carrying out our business, it may be necessary to share information about you with and between our related bodies corporate and organisations that provide services to us (eg, our alliance partners). We would not otherwise routinely disclose personal information to an organisation other than as set out in this Privacy Policy unless:
(a) required or permitted by law;
(b) we believe it is necessary to provide you with a product or service which you have requested;
(c) it is necessary to protect the rights, property or personal safety of any of our customers, any member of the public or our interests;
(d) the assets and operations of our business are transferred to another party as a going concern; or
(e) you have provided your consent.
3. Service providers
3.1 Like most large organisations, we use a range of service providers to help us maximise the quality and efficiency of our products and services and our business operations. This means that individuals and organisations outside of VALD, such as cloud and web hosting service providers, software as a service providers, providers of IT support services, providers of analytics and marketing support services and online payment system providers, will sometimes have access to or be disclosed personal information held by us and may only use it on behalf of us to facilitate our services, provide services on our behalf, perform service-related services or assist us in analysing how our service is used. We require our service providers to adhere to strict privacy guidelines which require the service providers not to keep this information, nor to use it or disclose it for any unauthorised purposes.
4. Disclosure of personal information outside the jurisdiction of collection
General disclosure
4.1 We may disclose personal information outside of the jurisdiction from which it was collected. In the conduct of our business, we transfer to, hold or access personal information from various countries including Australia, as well as the United States of America, the United Kingdom and countries in the European Economic Area. The privacy laws of those countries may not provide the same level of protection as the privacy laws of the country from which the personal information was collected. However, this does not change our commitments to safeguard your privacy and we will comply with all applicable laws relating to the cross-border data disclosure.
Data transfers from the European Economic Area (“EEA”)
4.2 We will take all reasonable and necessary steps to ensure your personal information is treated securely and in accordance with this Privacy Policy and applicable Privacy Laws (including the GDPR, where applicable), and will not transfer personal information outside the EEA unless an appropriate safeguard is implemented (other than to a jurisdiction whose Privacy Laws have been deemed adequate by the European Commission), such as entering into the EU Standard Contractual Clauses (or equivalent measures) with the party outside the EEA receiving the personal information. You may obtain a copy of the appropriate safeguards implemented by us in relation to your personal information by contacting DPO@vald.com.
5. Direct marketing
5.1 Like most businesses, marketing is important to our business’ success. We therefore, from time to time, send marketing materials to current or prospective customers. We only do so in accordance with applicable laws (which may or may not require VALD to obtain your prior consent, depending on the country in which you are located and/or the applicable Privacy Laws).
5.2 If you are receiving promotional information from us and do not wish to receive this information any longer, please contact VALD directly at DPO@vald.com asking to be removed from our mailing lists, or use the unsubscribe facilities included in our marketing communications.
5.3 After you opt-out or update your marketing preferences, please allow us sufficient time to process your marketing preferences. Unless otherwise required to process your requests earlier by law, it may take up to 5 business days to process your opt out requests in relation to receipt of electronic marketing materials such as emails and SMS, and up to 30 days for all other marketing-related requests.
6. Our website and Apps privacy practices
6.1 We sometimes use cookie and similar tracking technology on VALD websites and the Apps to provide information and services to site visitors and improve your experience on our websites and the Apps. Cookies are pieces of information that a website transfers to your computer’s hard disk for record keeping purposes and are a necessary part of facilitating online transactions, and include standard internet log information and visitor behaviour information. Most web browsers are set to accept cookies. Cookies are useful to keep you signed in, remember your preferences, estimate our number of users and determine overall traffic patterns through our sites.
6.2 If you do not wish to receive any cookies you may set your browser to refuse cookies. This may mean you will not be able to take full advantage of the services on the websites and the Apps.
6.3 Google and other third parties collect data about traffic to this site. Google Analytics uses Cookies to monitor traffic to, and use of, the Websites. Google uses this information on our behalf to evaluate your Websites usage, to compile reports on the Websites activities, and to provide additional services connected with the Websites. We will not identify you to Google, and will not merge personal and non-personal information collected through this service. You can prevent the use of Google Analytics Cookies by adjusting the settings on your browser software, however, you may not be able to fully use all of the functions of the Websites if you do so. If you would like to prevent Google’s collection of data generated by your use of the Websites (including your IP address), please download and install a Browser Plugin available at https://tools.google.com/dlpage/gaoptout?hl=en. Alternatively, you can find out how Google Analytics uses data when you use our Websites, at www.google.com/policies/privacy/partners.
7. Links to other websites and other third party collections
7.1 Our websites and the Apps may contain links to third party websites or references to third party apps. These linked sites and apps are not under our control and we are not responsible for the content of those sites nor are those sites or apps subject to our Privacy Policy. Before disclosing your personal information on any other website or app we recommend that you examine the terms and conditions and Privacy Policy of the relevant site. VALD is not responsible for any practices on third party websites or apps that might breach your privacy.
7.2 You should also note that, if you are a patient, personal information you provide via the Apps will also be collected by your healthcare professional. Before disclosing your personal information we recommend that you examine the relevant healthcare practice’s Privacy Policy. VALD is not responsible for the privacy practices of your healthcare professional that might breach your privacy.
8. Accessing and correcting the information we keep about you
8.1 This section 8 applies unless the GDPR applies to processing of your personal information by VALD.
8.2 If at any time you want to know exactly what personal information we hold about you, you are welcome to request access to your record by contacting us at DPO@vald.com. We will make our file of your information available to you within a reasonable time from receipt of your request. We will only withhold access where permitted by law.
8.3 If at any time you wish to change personal information that we hold about you because it is inaccurate, incomplete or out of date, please contact us at DPO@vald.com. If you wish to have your personal information deleted, please let us know in the same manner as referred to above and we will take all reasonable steps to delete it unless we need to keep it for legal reasons. You should note that you may update certain content and account details directly within the VALD websites and the Apps.
8.4 We may charge a small fee to cover our costs of supplying the information. If we do not grant you access to your personal information or do not agree to correct your personal information, we will tell you why.
9. Your rights (GDPR)
9.1 If the GDPR applies to processing of your personal information by VALD, you have the right to:
(a) Access. You have the right to request a copy of the personal information we are processing about you, which we will provide back to you in electronic form. For your own privacy and security, in our discretion we may require you to prove your identity before providing the requested information. If you require multiple copies of your personal information, we may charge a reasonable administration fee.
(b) Rectification. You have the right to have incomplete or inaccurate personal information that we process about you corrected.
(c) Deletion. You have the right to request that we delete personal information that we process about you, except we are not obligated to do so if we need to retain such information in order to comply with a legal obligation or to establish, exercise or defend legal claims.
(d) Restriction. You have the right to restrict our processing of your personal information where you believe such information to be inaccurate, our processing is unlawful or that we no longer need to process such information for a particular purpose, but where we are not able to delete the information due to a legal or other obligation or because you do not wish for us to delete it.
(e) Portability. You have the right to obtain personal information we hold about you, in a structured, electronic format, and to transmit such information to another data controller, where this is (a) personal information which you have provided to us, and (b) if we are processing that information on the basis of your consent (such as for direct marketing communications) or to perform a contract with you.
(f) Objection. Where the legal justification for our processing of your personal information is our legitimate interest, you have the right to object to such processing on grounds relating to your particular situation. We will abide by your request unless we have compelling legitimate grounds for the processing which override your interests and rights, or if we need to continue to process the information for the establishment, exercise or defence of a legal claim.
(g) Withdrawing Consent. If you have consented to our processing of your personal data, you have the right to withdraw your consent at any time, free of charge. This includes cases where you wish to opt out from marketing messages that you receive from us (see Section 5 above).
9.2 You can make any of these requests in relation to your personal data by sending the request to our Data Protection Officer by email at DPO@vald.com.
10. Storage and security of your personal information
10.1 We will endeavour to implement appropriate technical and organisational measures to keep secure any information which we hold about you, and to keep this information accurate, up to date and complete, and to ensure a level of security appropriate to any risks which may be associated with the processing activities outlined in this Privacy Policy.
10.2 Your information is stored on secure servers that are protected in controlled facilities. These are third party data storage services, including cloud service providers.
10.3 We require our personnel to respect the confidentiality of any personal information held by us.
10.4 We take all reasonable physical, administrative, and technological precautions to store and transmit data securely. For example, personal data is encrypted and held with reputable data storage providers. Other measures include:
(a) computer firewall protection; and
(b) computer maintenance to prevent unauthorised access.
10.5 In addition to technological measures, VALD also places access controls on its employees and other partners. Our employees are subject to contractual confidentiality obligations that are consistent with this Privacy Policy. Despite these measures, VALD cannot guarantee that the information described in this Privacy Policy will be completely secure.
11. Retention of personal information
11.1 We will retain and process your personal data only for as long as is necessary for the purposes for which the information is collected. In addition, we will retain and use your personal data to the extent necessary to comply with our legal obligations and exercise our legal rights (for example, if we are required to retain your data to comply with applicable laws), resolve disputes and enforce our legal agreements and policies.
11.2 When we no longer need to use your personal information or retain it pursuant to legal obligations in order to exercise our legal rights, we will remove it from our systems and records or take steps to anonymise it so that you can no longer be identified from it in accordance with relevant Privacy Laws.
12. Contacting Us
12.1 If you have any concerns or complaints about how we handle your personal information, or if you have any questions about this policy, please contact us at DPO@vald.com or at the address below:
Data Protection Officer
VALD Pty Ltd
115 Breakfast Creek Road
Newstead QLD 4006
Australia
12.2 In most cases we will ask that you put your request in writing to us. We will investigate your complaint and will use reasonable endeavours to respond to you in writing within 30 days of receiving the written complaint. If we fail to respond to your complaint or if you are dissatisfied with the response that you receive from us, you should be aware that you might also have the right to make a complaint to the applicable privacy authorities.
12.3 In Australia, this is the Office of the Australian Information Commissioner (www.oaic.gov.au) or, potentially in some instances, your applicable State or Territory privacy commissioner with regard to handling of health information.
12.4 If you are located in the EU and the GDPR applies to the processing of your personal data, you also have the right to lodge a complaint with a supervisory authority. A list of supervisory authorities for all EU Member States is available here (https://edpb.europa.eu/about-edpb/board/members_en).
13. Future changes
13.1 We operate in a dynamic business environment. Over time, aspects of our business may change as we respond to changing market conditions. This may require our policies to be reviewed and revised. We reserve the right to change this Privacy Policy at any time and notify you by posting an updated version of the policy on the VALD websites and the Apps. If at any point we decide to use personal information in a manner materially different from that stated at the time it was collected we will notify users by email or via a prominent notice on our website.