Privacy Policy

Get Kollo Pty Ltd ACN 669 977 833 (“Kollo,” “our,” “us,” or “we”) respects your right to privacy and are committed to safeguarding the privacy of our customers and users.

This policy sets out how we collect and treat your Personal Information.

By accessing or using our website, you accept and agree to the practices this Privacy Policy describes. If you do not agree to any of the terms in this Privacy Policy, you should not use our website.

This Privacy Policy was last updated on 15 August 2024.

1. Changes to This Privacy Policy

We may update this Privacy Policy from time to time, including to reflect changes to our practices or for other operational, legal, or regulatory reasons. We will post the revised Privacy Policy on the Get Kollo Platform, update the “last updated” date, and take any other steps required by applicable law.

We encourage users to frequently check this page for any changes to stay informed about we handle personal information. You acknowledge and agree that it is your responsibility to review this privacy policy periodically and become aware of modifications.

Your continued use of the Get Kollo Platform following the posting of changes to this Privacy Policy will be deemed your acceptance of those changes.

2. Scope This Privacy Policy

This Privacy Policy covers how we process the Personal Information of our existing and perspective customers, end-users who use or request to use the Get Kollo Platform, visitors of our websites, applications, merchants, vendors, partners and those who participate in our promotions or events (“you” or “your”). It also describes your data protection rights, including your right to object to some of the processing activities we carry out.

We adhere to the Australian Privacy Principles established under the Privacy Act 1988 (Cth) and to the extent applicable, the EU General Data Protection Regulation (“GDPR”).

This Privacy Policy applies to all Personal Information that we collect, use, or disclose when providing our websites and services owned or operated by us, including in relation to the following http//:www.getkollo.com.

3. What is Personal Information?

Personal information refers to any information relating to an identified or identifiable natural person, i.e. one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person (“Personal Information”).

We do not collect information regarding your race, ethnicity, religious or philosophical beliefs, political beliefs, sexual orientation, genetic information, or information about your health.

4. How we Collect Personal Information

When you use the Get Kollo Platform, whether directly or through a third party website or mobile application, we may collect, store, and process various kinds of data, including Personal Information. The Personal Information that we may collect about you broadly falls into the following categories:

Information You Provide to us Directly

We collect the information you provide to us when you do things such as request, sign up for or use the Get Kollo Platform, register or update your account, respond to a job application or an email offer, participate in community forums, join us on social media, take part in competitions or events, contact us with questions or request support, or voluntarily interact with us in other ways.

This may include:

  • Basic contact details including your name, address, phone number, email.
  • Account information including your username, password, security questions.
  • Information from our interactions (such as when you use the Get Kollo Platform) including when you communicate with us via email, telephone, SMS, video conference, social media or chatbots.
  • Customer support information including the information you choose to include in communications with us.

Information We Collect Automatically

We automatically collect usage information when you browse or use the Get Kollo Platform to improve our services and enhance your user experience (for example, by personalising the content you see). To do this, we may use cookies, pixels and similar technologies (“Cookies”).

This may include information about how you use our digital properties (including the Get Kollo Platform, third-party websites, social media sites, apps and electronic communications) such as, what pages you looked at, what items you viewed and what links you clicked on, device information, browser information, information about your network connection, your IP address, marketing and cookie preferences, including any consents you have given us.

Information We Obtain from Third Parties

We may obtain information about you from third parties, including from vendors and service providers who may collect information on our behalf, such as:

  • Companies who support the Get Kollo Platform (e.g. Shopify, WooCommerce and other platforms)
  • Our payment processors, who collect payment information (e.g., bank account, credit or debit card information, billing address) to process your payment in order to fulfill your orders and provide you with products or services you have requested, in order to perform our contract with you.
  • When you visit the Get Kollo Platform, open or click on emails we send you, or interact with the Get Kollo Platform or advertisements, we, or third parties we work with, may automatically collect certain information using online tracking technologies such as pixels, web beacons, software developer kits, third-party libraries, and cookies.

Any information we obtain from third parties will be treated in accordance with this Privacy Policy. We are not responsible or liable for the accuracy of the information provided to us by third parties and are not responsible for any third party’s policies or practices. For more information, see the section below, Third Party Websites and Links.

5. How and Why We Collect Personal Information

We must have a legal basis to process your Personal Information and we explain these bases below. We also explain the purposes for which we process your Personal Information, the processing operations we carry out, and the categories of information we use for each purpose.

Where we collect Personal Information, we’ll only process it in the following circumstances:

  • Where we have your consent. In certain cases, we ask for your consent to use your Personal Information. If when we need to ask for your consent, we will explain the situations where we use your Personal information and the purposes for which your Personal Information will be used.
  • In accordance with a legal obligation. We are required to comply with relevant legal and regulatory obligations. If we ask you to provide Personal Information to comply with a legal requirement, we will make this clear at the relevant time and advise you whether the provision of your Personal Information is mandatory or not (as well as the possible consequences if you do not provide your Personal Information).
  • Where we have legitimate interests. We can process your Personal Information when this is necessary for us (or a third party) to achieve a business purpose, so long as they’re in accordance with your rights.

If we collect and use your Personal Information in reliance on our legitimate interests (or those of any third party), this interest will normally be to provide and improve the Get Kollo Platform, respond to your inquiries, and support requests, and communicate with you about our products and services, and for any other purpose with your consent. We may have other legitimate interests, and if appropriate, we will make clear to you at the relevant time what those legitimate interests are.

If you have questions about or need further information concerning the legal basis on which we collect and use your Personal Information, please contact us using the contact details provided under the “Contact Us” heading below.

6. How We Share Your Personal Information

Other than disclosure to service providers and merchants (explained below) or as required by law, we do not give Personal Information to third parties unless we have disclosed the use in this Privacy Policy, or you have expressly consented for us to do so.

We may disclose your Personal Information as follows:

  • With affiliates, contractors, service providers, and other third parties we use to support our business on a need-to-know basis to allow the provision of the Get Kollo Platform to you or as requested by you;
  • To a buyer or other successor in the event of a merger, divestiture, restructuring, reorganisation, dissolution or other sale or transfer of some or all of our assets, whether as a going concern or as part of bankruptcy, liquidation, or similar proceeding, in which Personal Information held by us about the Get Kollo Platform users is among the assets transferred;
  • To enforce any agreement, including any applicable terms of service;
  • To establish or exercise our right to defend against legal claims;
  • To law enforcement and other government authorities such as legislatures, courts, agencies and litigants if we reasonably believe that such action is necessary to: (a) comply with the law and the reasonable requests of governmental authorities; (b) comply with legal process; (c) respond to requests from public or government authorities, including public or government authorities outside your country of residence; (d) protect the security or integrity of the Services’ information systems; and/or (e) exercise or protect our rights, privacy, safety or those of affiliates, clients, you or others; and
  • If we reasonably believe disclosure is necessary or appropriate to protect the rights, property, or safety of Get Kollo or others.

7. Third Party Websites and Links

The Get Kollo Platform may provide links to websites or other online platforms operated by third parties. If you follow links to sites not affiliated or controlled by us, you should review their privacy and security policies and other terms and conditions. We do not guarantee and are not responsible for the privacy or security of such sites, including the accuracy, completeness, or reliability of information found on these sites. Information you provide on public or semi-public venues, including information you share on third-party social networking platforms may also be viewable by other users of the Get Kollo Platform and/or users of those third-party platforms without limitation as to its use by us or by a third party. Our inclusion of such links does not, by itself, imply any endorsement of the content on such platforms or of their owners or operators, except as disclosed on the Get Kollo Platform.

8. Marketing Communication and Preferences (Consent)

In some cases, we may send you direct marketing based on our legitimate interests or where you have provided us with explicit consent. These communications may be sent in various forms, including mail, social media, SMS, or email.

You have an absolute right to opt out of direct marketing at any time. You can do this by following the instructions in the communication within the electronic message we send to you, or by contacting us via email at support@getkollo.com.

We will never share your mobile telephone number or SMS opt-in consent status with these third parties to use for their own marketing purposes without your explicit consent.

We may still send you important notices relating to your account, operational activities, and technical updates, even after you have opted out of receiving marketing communications.

9. Cookies

Like many websites, we use Cookies on the Get Kollo Platform. We use Cookies to power and improve the Get Kollo Platform (including to remember your actions and preferences), to run analytics and better understand user interaction with the Get Kollo Platform (in our legitimate interests to administer, improve and optimise the Get Kollo Platform). We may also permit third parties and services providers to use Cookies on the Get Kollo Platform to better tailor the services, products and advertising on the Get Kollo Platform.

Most browsers automatically accept Cookies by default, but you can choose to set your browser to remove or reject Cookies through your browser controls. Please keep in mind that removing or blocking Cookies can negatively impact your user experience and may cause some of the Get Kollo Platform, including certain features and general functionality, to work incorrectly or no longer be available. Additionally, blocking Cookies may not completely prevent how we share information with third parties such as our advertising partners.

10. Your Data Rights and Choices.

You have the following rights in relation to your Personal Information:

  • Right to object: You have a right to ask us to consider any valid objections which you have to our use of your Personal Information where we process your Personal Information on the basis of our or a third party’s legitimate interest.
  • Right of access: All data that you have provided to us is accessible through the Get Kollo Platform. You can request a copy of all Personal Information you have provided us through the Get Kollo Platform or by sending us an email from the email address you use for your Get Kollo account. We can only give you the data we hold ourselves. Any data that a partner holds about you is with that partner. You should request access to that data directly with them. We will help you where we can.
  • Right to data portability: You have a right to ask us to provide your Personal Information to a third-party provider of services.
  • Right to rectification: You can control your data through the Get Kollo Platform. Where you cannot change this data through the Get Kollo Platform, you have the right to ask us to rectify inaccurate or incomplete Personal Information which we have about you.
  • Right to erasure: You have the right to ask us to erase your Personal Information. You can close your Get Kollo account by emailing us at support@getkollo.com, or by using the appropriate feature in the Get Kollo Platform, when available. We will then anonymise and archive all data we have about you 12 months later (we keep this data for 12 months in case of any subsequent queries and for audit requirements, unless you ask us to delete it as soon as possible following closure which you can do by sending us an email at support@getkollo.com). Be aware that the partners you have used may still have data about you. You will need to contact them directly in order for them to delete this data.
  • Right to restrict use of your Personal Information: You have a right to ask us to restrict the way that we process your Personal Information in certain specific circumstances. We will also pass your request onto other recipients of your Personal Information unless that is impossible or involves disproportionate effort.

If you wish to exercise any of the rights set out above, please email us at support@getkollo.com. We aim to respond to all legitimate requests within one month. Occasionally it may take us longer than a month if your request is particularly complex or you have made a number of requests. In this case, we will notify you and keep you updated.

11. Where We Store Your Personal Information

All Personal Information collected is stored on secure servers in Australia and other data centres worldwide. By using the Get Kollo Platform, you are consenting to the transfer of your Personal Information to other jurisdictions that may have different privacy laws and regulations than your jurisdiction.

We retain your Personal Information for as long as you maintain an open account with us of as otherwise necessary to provide you with the Get Kollo Platform. In some cases, we retain Personal Information for longer, if doing so is necessary to comply with our legal obligations, resolve disputes or collect fees owed, or is otherwise permitted or required by applicable law, rule, regulation, or contract. We may further retain information in an anonymous or aggregated form where that information would not identify you personally.

12. Protecting Your Personal Data

We take the protection of your Personal Information seriously, however, please be aware that no security measures are perfect or impenetrable, and we cannot guarantee “perfect security”. In addition, any information you send to us may not be secure while in transit. We recommend that you do not use unsecure channels to communicate sensitive or confidential information to us.

How long we retain your Personal Information depends on different factors, such as whether we need the information to maintain your account, to provide the Get Kollo Platform, comply with legal obligations, resolve disputes, or enforce other applicable contracts and policies.

To ensure the security and integrity of your data, we have implemented the following measures:

  • Encryption: We encrypt Personal Information appropriately and use proper technical and organisational measures across the business. This includes encrypting your data backups to prevent unauthorised access.
  • Environment Separation: We maintain strict separation between test and production data environments. This prevents Personal Information from leaking into less secure environments and minimises the risk of exposure.
  • Data Loss Prevention: We have implemented a comprehensive data loss prevention strategy. This strategy includes a combination of technical controls, policies, and standards that protect against the possibility of unauthorised extraction or loss of Personal Information.
  • Staff Access Limitations: We limit staff access to protected customer data to authorised personnel who require access for legitimate business purposes. Access is granted on a need-to-know basis, minimising the risk of improper access, exfiltration, or processing of Personal Information.
  • Strong Passwords: We require all staff accounts to have strong passwords, which often include a minimum length and a mixture of numbers, letters, and special characters. This helps ensure the security of staff accounts and protects against unauthorised access.
  • Access Logs: We keep an access log to protected customer data, recording details of any interactions with the data. This allows us to maintain an audit trail of activity related to data access and helps assess the effectiveness of our security controls.
  • Security Incident Response: We have implemented a security incident response policy to ensure we respond appropriately to security incidents and data breaches. This policy includes incident severity scales, defined roles and responsibilities, escalation paths, evidence collection procedures, and required actions to mitigate and resolve security incidents.

Additionally, all third-party interactions with the Get Kollo Platform are made through a secure socket layer (“SSL”), which establishes an encrypted link between our web server and your browser. We have written contracts with each of those third-party processors that contain safeguards for your information.

Please be aware that while we implement these measures to protect your Personal Information, no security measure is completely foolproof. We continuously evaluate and update our security practices to ensure we maintain the highest level of data protection.

If you have any concerns about the protection of your Personal Information, or would like more information about our data security practices, please contact us using the details provided in this Privacy Policy. We encrypt Personal Information appropriately and use proper technical and organisational measures across the business.

13. International Users

Please note that we may transfer, store, and process your Personal Information outside the country you live in, including the United States. Your Personal Information is also processed by staff and third-party service providers and partners in these countries.

If we transfer your Personal Information out of Europe, we will rely on recognised transfer mechanisms like the European Commission’s Standard Contractual Clauses, or any equivalent contracts issued by the relevant competent authority of the United Kingdom, as relevant, unless the data transfer is to a country that has been determined to provide an adequate level of protection.

If you are an individual residing in the European Union, you have certain rights as to how your Personal Information is obtained and used. To the extent applicable, we comply with your rights as to how your Personal Information is used and controlled as an individual residing in the European Union.Except as otherwise provided in the GDPR, you have the following rights:

  • to be informed how your Personal Information is being used;
  • access your Personal Information (we will provide you with a free copy of it);
  • to correct your Personal Information if it is inaccurate or incomplete;
  • to delete your Personal Information (also known as "the right to be forgotten");
  • to restrict processing of your Personal Information;
  • to retain and reuse your Personal Information for your own purposes;
  • to object to your Personal Information being used; and
  • to object against automated decision making and profiling.

Please contact us at any time to exercise your rights under the GDPR at the contact details in this Privacy Policy. We may ask you to verify your identity before acting on any of your requests.

14. Our contact details

You may request access to or correction of your Personal Information in our custody or control, by writing to the address below, attention Compliance Officer. Your right to access or correct your Personal Information is subject to applicable legal restrictions. We may take reasonable steps to verify your identity before granting access or making corrections.

If you have any questions about this Privacy Policy, or our personal information handling practices generally, please contact us at:

Get Kollo Pty Ltd c/o 388 George Street, Sydney NSW 2000, Australia

Email: support@getkollo.com

15. Complaints to the Office of the Australian Information Commissioner (OAIC)

If you think we have breached the Privacy Act, or you wish to make a complaint about the way we have handled your personal information, you can contact us using the details set out below. Please include your name, email address and/or telephone number and clearly describe your complaint. We will acknowledge your complaint and respond to you regarding your complaint within a reasonable period of time. If you think that we have failed to resolve the complaint satisfactorily, then we encourage you to contact us to explain why, or you may raise your complaint with the Office of the Australian Information Commissioner (“OAIC”) using any of the following contact details or the privacy complaint form on the AIC website.

Phone: 1300 363 992

Email: enquiries@oaic.gov.au

Mail: GPO Box 5218, Sydney NSW 2001