AustralTechnologies

Legal

Privacy policy

What we do with personal data, in two parts — because we sit in two different roles and most privacy policies blur them.

Version Pending: version — effective Pending: effective date

Section 01Two roles

As controller. For people who visit this site, book a demo, or write to us, we decide what happens to that data. Sections 2 to 10 cover it, and they are most of this page.

As processor. For the merchant records Austral reads to defend a dispute — your shoppers' orders, addresses and messages — the merchant is the controller and we act on their instructions. That relationship is governed by the contract and the data processing agreement, not by this page. Section 11 explains where to look instead.

If you are a shopper who has had a dispute defended using Austral, the company you bought from is the controller of your data, and your rights are exercised against them. We will help them answer you.

Section 02Who is the controller

Pending: registered entity name, registered in Pending: country under number Pending: registration number, at Pending: registered address.

For anything in this policy, write to Pending: privacy email address.

Pending: whether a data protection officer has been appointed, and their contact details

Section 03What we collect

Less than you might expect, because this site does very little.

  • Demo bookings. When you book a demo you give Calendly your name, email address and chosen time, along with anything you type into the booking form. We receive that booking.
  • Correspondence. If you email us, we have your email address and whatever you wrote.
  • Server logs. Our host records requests to this site, including IP address, timestamp, and the page requested. Pending: what the host logs, and for how long

We run no analytics, no advertising pixels, no session recording, no A/B testing tool and no tag manager. There is no newsletter and no signup form. We do not buy contact lists and we do not enrich the data we hold about you from third-party sources.

Section 04Why, and on what basis

  • To arrange and hold a demo — Article 6(1)(b) GDPR, steps taken at your request before entering a contract.
  • To answer correspondence — Article 6(1)(f), our legitimate interest in replying to people who write to us, which we consider your interests are unlikely to override given you started the conversation.
  • To keep the site running and secure — Article 6(1)(f), our legitimate interest in operating a website that works and is not being attacked.
  • To meet legal obligations — Article 6(1)(c), where accounting or tax law requires us to keep a record.

Section 05Cookies and this website

This site sets no cookies of its own. It runs no analytics, no advertising pixels, and no tracking of any kind. There is no consent banner because there is nothing to consent to.

The one third party involved is Calendly, which powers the "Get a demo" scheduler and sets its own cookies. Calendly's script is not loaded with the page. It is fetched when you click "Get a demo" and never before — so if you don't click it, nothing on this site talks to anyone but our own server, and no third-party cookie is set.

If you do click it, you are handed to Calendly, and Calendly's own privacy notice applies to what happens in that widget alongside this one.

Section 06Who else sees it

Our sub-processors, listed on the security page, which is kept current. Beyond them: professional advisers where we need advice, and authorities where the law requires it. We do not sell personal data and we do not share it for anyone else's marketing.

Section 07Transfers outside the EEA

Calendly is a US provider, so booking a demo involves a transfer to the United States. Pending: the transfer mechanism relied on: Standard Contractual Clauses, the EU-US Data Privacy Framework, or another safeguard, and the position for every other sub-processor

Section 08How long we keep it

Pending: retention period for demo bookings, for correspondence with people who did not become customers, and for server logs

Where law sets a minimum — accounting records, for instance — we keep it for that period and no longer.

Section 09Your rights

Under the GDPR you may ask us to:

  • confirm what we hold about you and give you a copy (Article 15);
  • correct it if it is wrong (Article 16);
  • delete it (Article 17);
  • restrict what we do with it (Article 18);
  • hand it to you or another provider in a portable format (Article 20); and
  • stop processing based on legitimate interest, including any direct marketing (Article 21).

Write to Pending: privacy email address. We will answer within one month, and tell you if we need longer and why. We will not charge you, and we will not make you justify the request.

Section 10Complaints

If you think we have got this wrong, tell us first — it is usually faster. You also have the right to complain to a supervisory authority, either in the country where you live or where you believe the problem occurred.

Pending: our lead supervisory authority

Section 11Merchant records

When Austral reads a merchant's orders, shipments and support threads in order to defend a dispute, the merchant decides what happens to that data and we follow their instructions. We are a processor and this policy does not describe that processing.

What governs it is the data processing agreement between us and that merchant: the scope of processing, the security measures, the sub-processors, breach notification, assistance with data subject requests, and deletion or return when the contract ends. The technical side of it is described on our security page, and the contractual side in our terms of service.

Section 12Changes

If we change this policy we will change the version and date at the top. Where a change materially affects how we handle data we already hold about you, we will tell you directly rather than expecting you to re-read the page.