PRIVACY POLICY

1. Introduction

1.1.  This is the official Privacy Policy of DURRANI.

1.2.  DURRANI is committed to providing quality services and products and recognise that your personal information is important to you. This Privacy Policy outlines our ongoing commitment and obligations to you regarding how we manage your personal information.

1.3.  DURRANI is bound by the Australian Privacy Principles (APPs) contained in the Australian Privacy Act 1988 (Act). The APPs set clear standards regarding the way in which we collect, use, disclose, store and secure your Personal Information. A copy of the APPs may be obtained from the website of the Office of the Australian Information Commissioner.

1.4.  With respect to customers residing in California, DURRANI also complies with the California Consumer Privacy Act of 2008 (CCPA). The CCPA requires DURRANI to indicate what, how and why a business collects information, why the information may be shared or sold and how a customer can control the information collected and used.

1.5.  Except where indicated to apply to customers in particular locations or governed by a particular law, each clause of this policy applies to all DURRANI customers.

1.6.  This policy explains:

(a)  dealing with DURRANI regarding your Personal Information;

(b)  the types of Personal Information DURRANI collects;

(c)  how DURRANI collects, stores, uses and discloses your Personal Information;

(d)  your rights to access and correct Personal Information held by DURRANI; and

(e)  how you make a complaint about our handling of personal information.

1.7.  This policy relates only to the personal information management practices of DURRANI and not any related companies, contractors or suppliers. This policy does not relate to personal information held about current or former employees of DURRANI.

1.8.  By visiting our website, using any of our services or otherwise providing us with your personal information, you agree to your personal information being handled as set out in this Privacy Policy.

1.9.  If you exercise any of your rights under the CCPA or other privacy law, DURRANI will not deny you goods or services, charge you a different price or rate or provide a different quality good or service except where that information is required to provide the good or service.

1.10.  DURRANI may change this privacy policy at any time by posting the revised privacy policy on DURRANI’s website, indicating its effective date.

  1. Dealing with DURRANI

Generally, you can deal with DURRANI without identifying yourself but in certain circumstances, DURRANI will ask you to provide personal information because:

(a) it is required by law;

(b) it is required by DURRANI policies; or

(c) it would be impracticable to deal with you anonymously,

such as where you order goods online, where you trade-in products, where goods are returned for repair, where you purchase goods to be delivered or installed, where you enter one of our competitions or when you submit a request, enquiry, complaint, consumer guarantee or warranty claim.

  1. Types of Personal Information We Collect

3.1.  Personal information means information which identifies you as an individual or from which your identity can be reasonably ascertained, regardless of the form of the information and whether or not it is true.

3.2.  Sensitive information means information or opinions about an individual’s racial or ethnic origins, political opinions, political affiliations, religious or philosophical beliefs, trade union membership, criminal record or health information.

3.3.  The kinds of personal information we collect or which we may hold about you varies depending on the purpose for collection. The personal information we have collected within the last 12 months include:

(a)  your name;

(b)  your address;

(c)  your date of birth;

(d)  your telephone number(s);

(e)  your e-mail address;

(f)  payment information;

(g)  financial information such as your bank account details;

(h)  transaction information;

(i)  delivery information and any information needed for customs clearance;

(j)  your user name and password;

(k)  information contained on identification documents (such as driving licences) and, in some specific cases, copies of such identification documents, where we require these to verify your identity;

(l)  information on how you use our products and services; and

(m)  location data, including your Internet Protocol (“IP”) address, server address, domain name and information on your browsing activity when visiting one of our websites.

3.4.  DURRANI website is for a general audience and not directed at children under 16. DURRANI does not intend to collect information about children under 16 in a manner which is not permitted by the US Children’s Privacy Protection Act. If you are a parent or guardian of a child in the US and believe such information has been collected, please contact the privacy officer so that we may remove such information to comply with the US Children’s Privacy Protection Act.

  1. How We Collect & Hold Personal Information

4.1.  Personal information may be collected in many ways, including interviews, correspondence, telephone, facsimile, email, via DURRANI’s website: https://www.durrani.com.au, other publicly available sources or cookies.

4.2.  This may occur when you:

(a)  order goods or services from us;

(b)  set up an account with us or add information to your account;

(c) purchase certain products or warranties from us;

(d)  request for a refund or exchange of a product;

(e)  subscribe to a subscription service, our mailing lists, SMS notification list or those of certain partners of ours;

(f)  enter competitions or promotions that we run;

(g)  provide us your details for customer care purposes;

(h)  browse one of our websites;

(i)  submit an enquiry;

(j)  complete surveys or provide online feedback or product reviews; and

(k)  publicly comment about us on social media sites.

4.3.  DURRANI generally collects your personal information directly from you. However, DURRANI also holds information, collected incidentally, concerning individuals who work for companies or organisations that have a business relationship with DURRANI.

4.4.  If you do not provide us with the information we request or if we cannot collect this information from other sources, we may not be able to provide you with our services.

4.5.  If you visit DURRANI’s websites, including https://www.durrani.com.au (“Websites”), our system may record information such as the date and time of your visit to the Websites, the pages accessed and any information downloaded for statistical and reporting purposes, website administration, security and maintenance and to direct you to material on our Websites that we believe will be of interest to you.

4.6.  Our Websites use “cookies”, which are small text files that we transfer to your computer’s hard drive through your web browser to enable our systems to recognise your browser and your log-in status and record non-personal information such as the date, time, frequency or duration of your visit, or the pages accessed, IP address, etc. Any such information will be aggregated and not linked to particular individuals.

4.7.  Users can easily erase cookies from their hard-drive, block all cookies, or receive a warning before a cookie is stored. Some features of our website may be unavailable if cookies are erased, blocked or disabled. Additionally, you can exercise choices regarding Google Analytics cookies by downloading the Google Analytics Opt-out Browser Add- on.

4.8.  While we take great care to protect your personal information on our website, no data transmission over the internet is guaranteed to be 100% secure and we cannot warrant the security of any information that you send to us or receive from us online, particularly by email.

4.9.  DURRANI holds personal information in a number of ways, including on our information technology systems and servers operated by third parties who provide services to us in connection with our business and by securely storing hard copy documents on which personal information is contained, at our various premises and potentially using third party document management and archiving services.

  1. Why We Collect, Hold & Use Personal Information

5.1. Generally, you have no obligation to provide any personal information requested by us. However, if you choose not to do so where we require this information, we may not be able to provide you with the goods and services that you want or deal with a request, enquiry or complaint that you have.

5.2.  DURRANI collects, holds, uses and discloses personal information for the purposes for which it was provided to us, a related purpose or as permitted or required by law. These may be for a number of purposes, including:

(a)  providing you with products/services you have purchased;

(b)  verifying your identity;

(c)  dealing with requests, enquiries, complaints, consumer guarantee or warranty claims, and other customer care related activities;

(d)  marketing products and services;

(e)  providing advice on products;

(f)  developing and improving products and services, such as Google Analytics;

(g)  in connection with any loyalty or reward programmes/competitions;

(h)  the operation and administration of accounts or subscriptions with us;

(i)  payment, refund or exchange processing;

(j)  carrying out certain checks, such as fraud or theft prevention processes;

(k)  quality assurance, IT security and operations, and training purposes;

(l)  personnel management, including recruitment;

(m)  interacting with companies or organisations with whom DURRANI has a business relationship;

(n)  reconciling payments due to DURRANI from suppliers in relation to goods or services provided to you by those suppliers;

(o)  purposes relating to any third party acquisition or potential acquisition of an interest in DURRANI or its assets;

(p)  complying with our obligations under agreements with third parties; and

(q)  carrying out any activity in connection with a legal, governmental or regulatory requirement that we have to comply with, or in connection with legal proceedings, crime or fraud prevention, detection or prosecution;

5.3.  DURRANI may use your personal information to promote and market products and services to you, including through methods such as email and SMS. When you create an account with DURRANI, your details may be added to DURRANI’s marketing database to receive product related information.

5.4.  Your personal information will not be used for such marketing purposes where you have opted out of receiving such communications. You may opt-out of receiving marketing materials by unsubscribing form our marketing database, either by clicking unsubscribe on the email, SMS “STOP” in response to an SMS or emailing DURRANI.

5.5.  If you provided personal information as part of a job application with DURRANI, we will hold, use and disclose that information solely for the purpose of considering your application. If it is necessary for DURRANI disclose personal information to third parties to verify the accuracy of that information, we will only disclose such information as is necessary in the circumstances.

5.6.  DURRANI website may contain content from or links to other websites, platforms or services unaffiliated with DURRANI. Conversely, you may interact with our website from another website or platform, for example social media websites. Those third parties may have different privacy policies to DURRANI and information collected and stored by these third parties remains subject to the third party’s policies.

  1. Why We Disclose Personal Information

6.1. DURRANI will not sell, rent or otherwise disclose personal information for profit. DURRANI may disclose or receive personal information or documents about you, including to/from:

(a) organisations that provide services to us in connection with our business, such as:

(i)  customer support;

(ii)  payment processing;

(iii)  administration;

(iv)  data storage;

(v)  website hosting;

(vi)  research;

(vii)  mail and delivery;

(b)  affiliates for internal business purposes;

(c)  manufacturers or distributors;

(viii) distribution and logistics; (ix) marketing;
(x) auditing and banking; (xi) financial and legal;

(xii) debt collection; and
(xiii) security or technical services.

(d)  third parties including our repairs system administrator, the manufacturer of the goods and authorised repairers;

(e)  law enforcement agencies or where required to do so by law, such as compliance with court orders or a subpoena;

(f)  parties involved in any third party acquisition or potential acquisition of an interest in DURRANI or its assets;

(g)  our insurers or insurance brokers; and

(h)  to other third parties where you have specifically consented to the disclosure of information to these third parties.

6.2.  In the event that DURRANI discloses personal information to a third party, DURRANI will take commercially reasonable steps to bind such third parties to appropriate levels of confidentiality but DURRANI cannot be responsible for the third party’s failure to comply with its confidentiality requirements.

6.3.  DURRANI is likely to disclose personal information it collects and holds about you to third parties who are not in Australia (such as third parties located in the United States of America) for one or more the purposes set out in this policy. These jurisdictions may have less protective privacy and data protections laws your jurisdiction.

6.4.  Any sensitive information collected will only be used for the primary purpose for which it was collected, a directly related secondary purpose, where you consent or where required to be disclosed by law.

  1. Accessing & Correcting Your Personal Information

7.1. If you request in writing to the Privacy Officer, DURRANI will, within 45 days, provide access to your personal information that we hold, the sources of such information, the purpose of such information being held and how certain types of information are shared with or sold to third parties, except in certain circumstances set out in:

(a) the Privacy Act 1988 (Cth) for Australian residents; or

(b) the CCPA for Californian residents,

as may be relevant to your jurisdiction.

7.2.  You have the right to direct DURRANI to not sell your personal information.

7.3.  DURRANI will require proof of identity and payment of an administration fee for providing access to your personal information.

7.4.  With respect to residents of California, the CCPA specifically provides that you can request DURRANI to disclose to you, with respect to information collected or use of your personal information in the preceding 12 months:

(a)  categories of personal information DURRANI collected, the purpose of collection and their sources;

(b)  the categories of third parties to whom the personal information was shared; and

(c)  if we sold or disclosed your personal information for a business purpose.

7.5.  You may also request DURRANI to correct your personal information held by DURRANI provided that DURRANI is satisfied that it is reasonable to ensure that the personal information is accurate, up-to-date, complete, relevant and not misleading, taking into account the purpose for which the personal information is held.

7.6.  You have the right to the erasure of personal data concerning you by DURRANI, unless:

(a)  for Australian residents, processing is necessary for exercising the right of freedom of expression and information, for compliance with a legal obligation, for reasons of public interest or for the establishment, exercise or defence of legal claims;

(b)  for Californian residents, the information is necessary to complete the transaction or business contract for which the personal information was collected, detect security incidents, exercise free speech or any other right provided by law, comply with the California Electronic Communications Privacy Act, comply with our legal obligations or other internal uses that are consistent with the purpose you provided the personal information.

7.7.  DURRANI shall notify any of its own service providers or contractors to delete personal information about the consumer collected, used, processed or retained by the service provider or the contractor unless this proves impossible or involves disproportionate effort.

  1. Complaints and Queries

8.1. DURRANI has a Privacy Officer to oversee the protection of your personal data. If you have any questions about this privacy policy or are concerned that the way DURRANI collects, holds, uses or discloses your personal information may be in breach of the APPs, CCPA or any other privacy law, please send the details of your complaint or request by email, addressed to:

The Privacy Officer
DURRANI
support@durrani.com.au

8.2.  Such query, complaint or request must provide sufficient information to verify your identity and provide sufficient details for DURRANI to understand and respond.

8.3.  You can only make 2 requests for access or data portability in any 12-month period. For data portability requests, we shall endeavour to provide your personal information in a readily useable form.

8.4.  After receiving a complaint, DURRANI will consider whether further information is required from you to properly consider and investigate the complaint, and may request such information from you. DURRANI will then conduct internal discussions with the relevant business units involved in the collection, holding, use or disclosure of your personal information and evaluate whether we believe there was a breach of relevant privacy laws and notify you of the result within 45 days. We may inform you that we require up to an additional 90 days in some circumstances.

8.5.  If the conclusion of our investigation is that our collection, holding, use or disclosure of your personal information was in breach of any privacy laws, we will take steps to remedy the breach as soon as reasonably practicable.

8.6.  If you are an Australian resident and not satisfied with our response to your complaint, you are entitled to make a complaint to the Office of the Australian Information Commissioner under the Privacy Act 1988 (Cth). Information is available from www.oaic.gov.au.

8.7.  If you are a Californian resident and not satisfied with our response to your complaint, you are entitled to make a complaint to the Office of the Attorney General of the State of California. Information is available from https://oag.ca.gov/contact/general-comment- question-or-complaint-form.