1.2 The privacy of our Platform users is of the upmost importance to us. We have a strict log-free policy which ensures that none of your activity or connection data whilst using the Arresti VPN Applications will be stored in our system (Log-Free Policy).
2.1 We comply with the Privacy Act 1988 (Cth) (Privacy Act) and the Australian Privacy Principles (APPs), which regulate how we may collect, use, disclose and store personal information. ‘Personal information’ is information or an opinion about you (whether true or not) that identifies you or from which your identity is reasonably identifiable. It does not include data where the identity has been removed and it is not possible to connect the data to the individual.
4. What personal information do we collect?
4.1 We collect limited personal information that we reasonably need for our business functions and activities, which primarily involve providing our Platform to our subscribers. In line with our Log-Free Policy, we will not store any of your activity or connection data whilst using the Arresti VPN Applications.
4.2 The personal information that we will collect from you will only be the information that you provide to us directly, such as your email address when you create an account on our Platform, any personal information (including your name and email address) you send us when making an enquiry or complaint or any data you otherwise explicitly permit for us to collect.
5. How we collect information about you
5.1 The personal information we collect about users of our Platform is very limited. We will generally only collect personal information that you provide to us directly, such as:
- when you subscribe to our Platform we will collect your email address so that we can set up your account and administer our dealings with you;
- when you provide us with personal information when communicating with us via telephone, email, or the Platform;
- when you send us an enquiry through our Website that contains your personal information; or
- when you explicitly permit us to track your interactions with our Website.
5.2 We delegate the processing of payments to use a trusted third party gateway, such as Stripe, to process payments for your use of the Platform. We will not access, collect or store your credit card or payment details.
5.3 If we collect personal information about you from a third party we will, where appropriate, request that the third party take reasonable steps to inform you that we are holding such information, how we will use and disclose it, and that you may contact us to gain access to and correct and update the information.
6. Unsolicited information
7. Do you have to provide us with your personal information?
7.1 You can deal with us anonymously (without giving us your name and contact details) or by using a pseudonym in some circumstances. We will generally not ask for identifying details unless we need those details in order to assist with your enquiry or respond to your request.
7.2 If you choose to deal with us anonymously or by using a nickname, there are some things we cannot do. For example, we may not be able to give you information about your dealings with us as a customer, supplier, or potential employee, or deal with a complaint. To create an account on our Platform, you will need to provide us with your email address.
8. Purpose for handling your personal information
8.1 As a general rule, we only process personal information for purposes that would be considered relevant and reasonable in the circumstances. We may collect, hold, use and disclose your personal information for the purposes of:
- providing the Platform and its functionality to you;
- administering our dealings with you, including sending you renewal reminders, invoices, and marketing materials (if you opt in);
- communicating with you and providing you with relevant information;
- improve our product and service offering; and
- otherwise managing our business.
8.2 The legal basis for collecting and using personal information will depend on the specific circumstances in which it is collected. However we will collect personal information from you as follows:
- Consent: where you have given consent to Arresti VPN’s use of the personal information for one or more purposes;
- Legal obligation: where we need to use your personal information to comply with a legal obligation (e.g. to defend and exercise legal claims).
8.4 We may also use your personal information for activities in support of our primary business functions such as processing payments, administration, employment, management, marketing, contracting, IT, legal and customer support.
9. Who do we disclose your personal information to?
9.1 We will not share, sell or trade your personal information with any entity or person, except as set out in this policy or as permitted by the Privacy Act.
9.2 We may disclose your personal information to:
- to our employees, contractors, and related entities, which provide support for our operations and services to you;
- our service providers, including providers of accounting, auditing, legal, banking, payment, debt collection, delivery, data processing, data analysis, document management and technology services; and
- government agencies for reporting and compliance purposes.
9.3 If we disclose information to a third party, we generally require that the third party protect your information to the same extent that we do.
10. Protection of your personal information
10.1 We will hold personal information as either secure physical records, electronically on our intranet system, in cloud storage, and in some cases, records on third party servers, which may be located overseas. We maintain appropriate physical, procedural and technical security for our office and information storage facilities to prevent loss, misuse, unauthorised access, disclosure, or modification of personal information.
10.2 We have put in place procedures to deal with personal information breaches and will notify you and any applicable regulator of a breach where we are legally required to do so. We will destroy or de-identify your personal information once it is no longer needed for a valid purpose or required to be kept by law.
11. Direct Marketing
11.1 Like most businesses, marketing is important to our continued success. We may use personal information (such as the email address provided by you when you created an account) to provide you with information about our products and services that we consider may be of interest to you. You will have the option to opt in to receiving marketing information from us when creating your User Account.
11.2 You may opt out at any time if you no longer wish to receive marketing information from us. You can do this by contacting our Privacy Officer or by using the ‘unsubscribe’ function included in our marketing emails.
12.1 We may track your cookies when using our Website, but only if you opt-in when prompted to do so.
13. Overseas disclosures
14. Other privacy rights
14.1 Subject to certain limitations and restrictions (e.g. depending on circumstances such as where you reside) you may have the right to exercise additional rights in relation to your personal information. These may include the right to:
- request erasure of your personal information;
- object to processing of your personal information;
- request restriction of processing of your personal information;
- transfer your personal information (i.e. the right to data portability);
- not be subject to automatic decision making; and
- withdraw consent.
15. Accessing and correcting your personal information
15.1 You may contact our Privacy Officer using the contact details below to request access to, or a correction of, the personal information that we hold about you. We will deal with your request within a reasonable time. On the rare occasion that we refuse access, we will provide you with a written notice setting out the reasons for the refusal and the relevant provisions of the Privacy Act that we rely on to refuse access. We will also provide you with avenues to complain about our refusal to provide you with access to the information.
15.2 We are not obliged to correct any of your personal information if we do not agree that it requires correction. If we refuse a correction request, we will provide you with a written notice with our reasons for refusing. We may recover reasonable costs in relation to a request for access to personal information.
16. Information retention
18. Resolving personal information concerns
Arresti VPN Pty Ltd
Address: 1/3 Harvton Street
Stafford QLD 4053
Phone: 1300 240 829
18.2 We take all complaints seriously and will respond to your complaint within a reasonable period. You may also lodge a complaint with the Office of the Australian Information Commissioner by telephone: 1300 363 992 or by submitting an online enquiry form via the following link: https://forms.business.gov.au/smartforms/servlet/SmartForm.html?formCode=APC_ENQ&tmFormVersion.