This Privacy Policy identifies how We manage the Personal Information We collect, use, hold and disclose and how to contact Us if You have any queries. As a business, We comply with Australian legislation in relation to Privacy (including the Privacy Act 1988 (Cth) (Privacy Act)) and protect Your Personal Information in accordance with those laws as well as privacy laws that may apply in Your jurisdiction.
Occasionally, We may ask You for Personal Information about other people – for example, Your customers or other authorised representatives, to provide Our services. If You choose to disclose this information to us, You confirm that You have informed these parties that You are providing their Personal Information to Us for the purposes of providing Our products and services either directly or by providing such disclosure in Your own privacy policy.
Where lawful and practical, You have the right to remain anonymous or to make use of a pseudonym, however if You choose to remain anonymous or to use a pseudonym, We may not be able to provide You with access to some or all Our products or services.
Australian Privacy Principles means the Australian Privacy Principles as found in Schedule 1 of the Privacy Act.
Information means, collectively, Personal Information and Sensitive Information.
Personal Information means information relating to an individual, including an opinion, which may be provided to Us as part of its business requirements. Such information may personally identify an individual or make the persons identify reasonably apparent.
Privacy Act means the Privacy Act 1988 (Cth).
Privacy Law includes the Australian Privacy Principles as well as the Privacy Act.
Sensitive Information means information or an opinion about an individual’s racial or ethnic origin, political opinions, membership of a political association, religious beliefs, philosophical beliefs, membership of a trade union or other professional body, sexual preferences, criminal record or health information.
Relevant Circumstances means all circumstances where the employee records exemption under the Privacy Act does not apply, including Information:
We/Us/Our means any of Esri Australia and/or related companies (as that definition applies in the Australian Corporations Act 2001 (Cth)) and includes for example (but not exclusive to) Boustead Geospatial Technologies Sdn Bhd, Esri Australia Pty Ltd and Boustead Geospatial Technologies Pte Ltd.
You/Your means You as a Customer or employee (former, current or prospective) of Us, both in the singular and plural and as an individual and/or a legal entity under the Corporations legislation in Your jurisdiction.
We may collect the following types of Personal Information:
We will only collect Personal Information where that information is necessary for Us to perform one or more of Our functions or activities, where We are required to by law, or You have consented to Our collection of Your Personal Information from third parties – for example Your own representatives. If You choose to provide Us with Personal Information, You consent to the transfer and storage of such Personal Information on Our servers for as long as We consider necessary to fulfil the purpose for which it was collected, or as required by relevant laws, under this Privacy Policy and any other arrangements that apply between Us.
We may collect Personal Information from You through the following (amongst others):
We will generally collect Personal Information directly from You. We may also collect Personal Information from third parties (including third party data analytic service providers) and publicly available sources of information. We may use Personal Information supplied by You or a third party to source additional Personal Information from publicly available sources of information.
Some Personal Information (e.g. race, ethnicity, health information etc.) is Sensitive Information and requires a higher level of protection under the Privacy Law. We will only collect such Sensitive Information when We have Your express consent for Us to do so and the collection is reasonably necessary for Us to conduct Our functions or activities, or where the information is required or authorised by law.
When You apply for a job with Us We collect certain information from You (including Your name, contact details, working history and relevant records checks) from any recruitment consultant, Your previous employers and others who provide information to Us, to assist in Our decision should We make You an offer of employment or engage You under a contract. This Privacy Policy does not apply to acts and practices in relation to employee records of Our current and former employees, which are exempt from the Privacy Laws.
If You do not provide Your Personal Information, We may not be able to:
In addition to the general Personal Information referred to in this Privacy Policy, Personal Information collected in connection with the Relevant Circumstances may include:
Sensitive Information may be required to be collected in some circumstances. We will only collect Sensitive Information if it is necessary for business purposes and for the inherent requirements of the position.
All information collected will be used and disclosed by Us as outlined in this Privacy Policy. We take reasonable steps to ensure that Your Personal Information is held securely.
It is Our usual practice to collect Personal Information about You in the Relevant Circumstances:
Your Personal Information may be used to:
Unless authorised by the Privacy Act, Your Personal Information will not be used for any other purpose without Your consent.
We may disclose Your Personal Information internally for the purposes of:
Our information technology systems may automatically permit access to Your Information within Our network of international and national related entities, contractors and service providers.
We take reasonable steps to ensure that these organisations are bound by confidentiality and privacy obligations in relation to the protection of Your Personal Information. These organisations may carry out activities including:
We may disclose Your Personal Information to overseas related entities or contractors, including related entities or contracts located in the areas where We have offices.
Where We have collected Personal Information about You either directly or by other means as set out above, We will notify You of the following as soon as practicable:
If We receive unsolicited Personal Information about or relating to You and We determine that such information could have been collected in the same manner if We had solicited the information, then We will treat it in the same way as solicited Personal Information under the Privacy Law. Otherwise if We determine that such information could not have been collected in the same manner as solicited Personal Information, and that information is not contained in a Commonwealth record, We will, if it is lawful and reasonable to do so, destroy the information or de-identify the information.
Where We store Your Personal Information depends largely on the purpose it was collected for but may include:
The data servers are password protected and login secured. However, by providing Personal Information to Us You consent to Your information being stored and processed on a data server or data servers (such as cloud services) owned by a third party or third parties that may be located outside of Your jurisdiction and which may not be subject to the Australian Privacy Principles.
We take reasonable steps to protect Your Personal Information from unauthorised access, loss, disclosure or modification under this Privacy Policy.
We regularly monitor all Our systems holding Personal Information, however, no data transmission over the internet can be guaranteed as one hundred per cent secure. We will take reasonable steps to maintain the security of and to prevent unauthorised access to or disclosure of Your Personal Information. However, We do not guarantee that unauthorised access to Your Personal Information will not occur, either during transmission of that information to Us or after We receive that information.
We only retain Your Personal Information for as long as is necessary for the purposes for which it was collected and We are required to keep it to comply with any laws. We will take such steps as are reasonable in the circumstances to destroy or de-identify Personal Information which We no longer need. These measures may vary depending on the Personal Information held.
We collect Personal Information primarily for the following purposes (the “Primary Purpose” of Personal Information collection):
If You subscribe to Our e-communications (e.g. newsletters, event updates etc.), We may send You direct updates about Our products and services, event invitations and for marketing purposes (including advising You of other products, services, promotional events, programs and special offers which may be of interest to You). These e-communications may be emails, SMS, etc under the Spam Act 2003 (Cth) (or other similar laws in Your jurisdiction) and the Privacy Laws. If You do not wish to remain a subscriber to Our mailing list, You can unsubscribe from any electronic communications by clicking the ‘unsubscribe’ button or by contacting Our marketing department.
We do not generally share Our customer lists on a commercial basis with third parties but if We did, We would only do so if We had the appropriate consent of the individual involved.
We may disclose Personal Information We collect from You:
If We use or disclose Your Personal Information for a Secondary Purpose other than the main reason for which it was originally collected, We will ensure that:
We will take reasonable steps to ensure that any contracts with third parties include requirements for those third parties to comply with the use and disclosure requirements of the Privacy Law.
In the unlikely event that We are required to disclose Personal Information to law enforcement agencies, government agencies or external advisors We will only do so under the Privacy Law or any other relevant legislation.
We take reasonable steps to ensure that each organisation that We disclose Your Personal Information to is committed to protecting Your privacy and complies with the Privacy Law.
By providing Your Personal Information to Us, You consent to Us transferring Your Personal Information to such other organisations.
Some of the service providers, related bodies corporate and other third parties We disclose Personal Information to are in countries outside of Your jurisdiction. Any overseas disclosure does not affect Our commitment to protecting Your Personal Information.
Where We send Your Personal Information outside of Our jurisdiction, We make sure that appropriate data handling and security arrangements are in place. You acknowledge that, by consenting to the disclosure of Your Personal Information to entities outside of Your jurisdiction We will no longer be required to take reasonable steps to ensure that the overseas recipient does not breach the applicable provisions of the Privacy Laws in relation to Your Personal Information.
When You provide such express consent, We will not be liable to You for any breach of the Privacy Principles by those overseas recipients. Further, the overseas recipient of Personal Information may be subject to a foreign law that could compel the disclosure of Personal Information to a third party, such as an overseas authority. In such case, We will not be responsible for that disclosure.
We review, on a regular and ongoing basis, Our collection and storage practices to ascertain how improvements to accuracy can be achieved.
You can request access to Your Personal Information held by Us in writing. We also require some proof of identification before releasing or correcting any Personal Information.
We may make reasonable changes for access to Information and may refuse to provide access to, or delete, Information where this is required or authorised by the Privacy Act or another law.
To assist Us to keep Our records up to date, You should ensure all Personal Information provided to Us is accurate and kept up to date. We take the accuracy of Your Personal Information seriously, if You are aware that the information, We hold relating to You is inaccurate, incorrect or out-of-date, please contact Our Privacy Officer.
We require employees to perform their duties in a manner consistent with Our legal responsibilities in relation to privacy.
We take all reasonable steps to ensure that paper and electronic records containing Personal Information are stored in facilities that are only accessible by people who have a genuine need to know.
We review, on a regular and ongoing basis, Our information security practices ascertaining how ongoing responsibilities can be achieved and maintained.
If You have a concern about the way We have dealt with Your Personal Information, please contact Our Privacy Officer.
We will seek to deal with privacy complaints as follows:
If You think We have not resolved Your concerns satisfactorily, You may wish to contact the Data Protection authority in Your jurisdiction for example if You are based in Australia, contact the Office of the Australian Information Commissioner.
We reserve the right in Our sole discretion to modify, amend, vary or update this Privacy Policy at any time without notice. If this is necessary, We will include the amended Privacy Policy on Our website to ensure You are kept up to date of how We manage Your Personal Information. We recommend You review the Privacy Policy regularly to ensure You are aware of any changes.
We take Your Privacy very seriously, to make it simpler for You to contact Us, We have centralised Our contact details, please contact Us by one of the following means:
The disclosures in this section apply only to European and UK residents and are intended to supplement the Privacy Policy with information required by European and UK law.
For these additional disclosures:
Cookies means text files placed on Your computer to collect standard internet log and visitor behaviour information. When You visit Our websites, We may collect information from You automatically through cookies or similar technology. For more information about how We use Cookies please refer to Our Australian Privacy Policy on Our website, You may also withdraw Your consent through the link at the bottom of Our Esri Australia website.
Information means, collectively, Personal Information and Sensitive Information.
Personal Information means any information relating to an identified or identifiable living individual, who can be identified, directly or indirectly in particular by reference to:-
Privacy Law includes the EU General Data Protection Regulation (GDPR) and where applicable UK legislation including the UK Privacy Act 2018 and any UK GDPR rules. The Australian Privacy Act may also apply, if You move jurisdictions and are based in Australia, please refer to Our Australian Privacy Policy on Our website.
Sensitive Information means information or an opinion about an individual’s racial or ethnic origin, political opinions, membership of a political association, religious beliefs, philosophical beliefs, membership of a professional or trade association, membership of a trade union, sexual preferences, criminal record or health information.
We/Us/Our means any of Esri Australia’s Group’s related companies (as that definition applies in the Australian Corporations Act 2001 (Cth)) and includes for example (but not exclusive to) Esri Malaysia, Esri Australia Pty Ltd and Boustead Geospatial Technologies Pte Ltd.
You/Your means You as the Customer, both in the singular and plural and as an individual and/or a legal entity under the Australian Corporations Act 2001.
We will only collect, hold, use and/or process (together "process") Your Personal Information where We are legally allowed to do so.
We will ensure that Your Personal Information is:
For Us, the lawful basis which We rely on will fall into one of the following:
There may be circumstances where We need to or are required to obtain and/or rely upon Your consent to process Your Personal Information. If this is the case We will give You:
We process Your Personal Information to enable You to buy or use Our products, services, training, or to send You, or allow You to access, Our marketing material. We only process Your Personal Information in accordance with the Privacy Law. Further information on these is set out below:
Example | Lawful Basis for Processing |
You are a customer | We will have entered a contract with You to provide You with products, services, content or training. |
You use Our website | To help inform You of Our products and services. Where We process Your Information, We will do so with Your consent. |
You apply for a job with Us | The legitimate interests for processing Information You provide Us is to facilitate Your employment application. |
If You are a supplier | We will have entered a contract with You for You to supply Us with products, goods or services. |
Depending on the circumstances for processing Personal Information, Personal Information We process will include for example: title/salutation; name; date of birth; address; country or location; employer; e-mail addresses; telephone numbers; IP address and information obtained from that address; Information We obtain from use of Cookies on Your computer.
We may also process other Personal Information about You when needed to provide data, software, products, services or other Information that You requested. We will make You aware of what Personal Information We are processing at the time of when We obtain it.
We do not process any Sensitive Information about You. You should not provide Us with any Sensitive Information. Any Sensitive Information provided to Us will be deleted.
We will never sell Your Information to a third party.
We will only share Your Information with a third party or transfer Your data outside of the EU if We need to. Where We do this We will comply with all Our legal obligations and We ensure that there are adequate protections in place to protect Your Information.
If We need Your consent We will:
You will be able to easily withdraw Your consent in the same way in which You gave it.
Where We rely on a different lawful basis, such as 'legitimate interests' or 'contractual', We will do so only to the extent permitted by such lawful basis.
Organisations that We may share Your Personal Information with include:
In all cases We will only keep Your Personal Information for as long as We have a lawful basis for processing it.
Where You enter a contract and/or place an order, We will keep Your Information for the duration of the contract and/or order, and thereafter for such period as We are permitted by law (to comply with financial legislation), or for so long as is necessary for the establishment, exercise or defence of legal claims.
Where You have made a general or specific enquiry but have not entered a contract or placed an order with Us, We will keep Your Information until that enquiry is resolved.
Where You have expressly consented to and/or subscribed to marketing, newsletters, events Information or to any other form of communication, We will keep Your Information only whilst Your consent and/or subscription is valid.
Where We no longer need Your Information and no longer have a basis for keeping it, We will delete it within 12 months.
We place a great deal of importance on the security of all Personal Information. We have in place appropriate technical and security measures which are reviewed routinely. Our approach to Information security is validated by Esri Australia’s externally audited certification to ISO 27001, which the rest of the group aims to align with.
We respect and place significant importance on Your rights. We would like to make sure You are fully aware of all Your data protection rights.
In summary, Your rights include the right to:
If You wish to object or to withdraw consent, You may contact Us though one of the methods detailed below in the 'Contact us' section. In addition, where We have sent You a marketing email, We will have provided an 'unsubscribe' or 'set Your preferences' which You can use to stop any future marketing communications.
Should You wish to report a concern or if You feel that We have not addressed Your concern in a satisfactory manner, You may contact the Information Commissioner's Office.
The disclosures in this section apply only to Californian residents and are intended to supplement the Privacy Policy with information required by California law.
The table below describes the categories of personal information We collected in the past 12 months, the purposes for which We may collect and disclose this information, the categories of recipients of disclosures made for business purposes in the past 12 months, and the categories of recipients of disclosures made in the past 12 months.
Category of Information | Purpose(s) for Collecting & Disclosing | Recipients of Disclosures for Business Purposes | Recipients of “Sales” or “Sharing” |
Identifiers, such as name, email address, unique identifiers associated with user or user account, IP Address |
|
| Third Party Advertising Providers |
Commercial information, such as purchase details, transaction records, billing information, billing address, payment card details |
|
| -NA- |
Internet or other electronic network activity information, such as information about Your usage of the Services, pseudonymous IDs, clickstream data, device and connection information, browser information, crash data, referring/exit URLs, IP Address |
|
| -NA- |
Visual information, such as photos or avatars, with Your consent, recordings of Your attendance at Our events |
|
| -NA- |
Professional or employment information, such as job title, company name, company domain |
|
| -NA- |
Geolocation data, such as Your approximate location, IP address, time zone |
|
| Third Party Advertising Providers |
Inferences (drawn about You based on other personal information we collect), such as preferences, interests, user behaviour data |
|
| Third Party Advertising Providers |
Sensitive personal information, such as login credentials and passwords |
|
| -NA- |
If You are a Californian resident, You have the right to:
We will not discriminate against You because You exercised one of Your rights under Californian law. You have the right of no retaliation following opt out or an exercise of any of Your rights.
If You wish to contact Us to exercise any of the above rights, please see Our contact details below.
We take Your Privacy very seriously, to make it simpler for You to contact Us, We have centralised Our contact details, please contact Us by one of the following means:
Stay in the loop with all the latest news, user case studies, and information on upcoming events.