Privacy policy
ULTRA VIOLETTE’S COMMITMENT TO PRIVACY
Grace & Fire Pty Ltd (ACN 637 431 077) and Grace & Fire IP Pty Ltd (ACN 618 536 328) (as trustee for Grace & Fire IP Unit Trust) (together, “Ultra Violette Australia”) and Grace & Fire London Limited (Company no. 13459683) (“Ultra Violette UK”), Grace & Fire USA, Inc, trading as “Ultra Violette” and its subsidiaries and affiliates in Australia, the United Kingdom, the United States and Canada (collectively referred to as “Ultra Violette”) is a manufacturer and seller of new generation sunscreen.
We care about you and are committed to managing personal information in accordance with the relevant local privacy and data protection laws which apply to us (“Privacy Laws”), including:
|
Short name |
Reference |
|
Privacy Act |
· The Privacy Act 1988 (Cth) (including the Australian Privacy Principles) |
|
UK GDPR |
· The UK Data Protection Act 2018 and the UK GDPR, which incorporates the General Data Protection Regulation (EU) 2016/679 in the United Kingdom (UK) by virtue of section 3 of the UK European Union (Withdrawal) Act 2018 |
|
Canadian Privacy Law |
· The Personal Information Protection and Electronic Documents Act SC 2000, c 5 (Canada), the Personal Information Protection Act, SA 2003, c P-6.5 (Alberta), and the Personal Information Protection Act, SBC 2003, c 63 (British Columbia), and the Act respecting the protection of personal information in the private sector, CQLR c P-39.1 (Quebec) |
We understand the importance of being open and transparent with you in the way in which we collect, hold, store, use and disclose your personal information. Just like protecting your skin, we take protecting your privacy very seriously!
We strongly encourage you read this document, so that you understand and are comfortable with how we handle your personal information. If you have any questions about this document, or about our handling of your personal information, please contact us using the relevant contact details set out in section 17.
2. WHEN DOES THIS PRIVACY POLICY APPLY?
This Privacy Policy applies to all Ultra Violette websites, subsidiaries, affiliates and businesses, unless that website subsidiary, affiliate or business has adopted a separate privacy policy.
For clarity:
-
our obligations under the Privacy Act apply where and to the extent the Privacy Act applies;
-
our obligations under the UK GDPR apply where and to the extent the UK GDPR applies;
-
our obligations under Canadian Privacy Laws apply where and to the extent the Canadian Privacy Law applies; and
-
our obligations under any other applicable laws and regulations apply where and to the extent those laws and regulations apply.
Ultra Violette UK is the data controller for the purposes of the UK GDPR (as applicable).
3. ABOUT THIS PRIVACY POLICY AND WHEN IT APPLIES
This document sets out our policies for managing your personal information and is referred to as our Privacy Policy. It is divided into a number of sections and in addition to explaining how we manage personal information it also provides answers to commonly asked questions.
In this Privacy Policy, “we”, “us” and “our” refers to Ultra Violette and “you” and “your” refers to any individual about whom we collect personal information.
This Privacy Policy sets out how we collect, store, process, use and disclose personal information (including personal information we collect, and personal information submitted to us, whether offline or online). For example, this can include information we collect when:
-
you purchase products and services from us through our websites (including when checking out as a guest);
-
you sign up to receive our newsletter;
-
you join Vi’s VIP Room (our loyalty program), including by creating an online account with us, and other membership and loyalty programs we may make available; and
-
you interact with us (including when you visit our websites (such as https://ultraviolette.com.au/, https://ultraviolette.co.uk/ and https://ultraviolettespf.com), or contact and communicate with us via our social media channels (such as via Facebook, Instagram, TikTok, Pinterest, LinkedIn or X (formerly known as Twitter)), phone or online).
It also sets out your rights in respect of your personal information.
Other terms and conditions may apply to you such as:
-
the privacy terms and conditions contained in our Terms and Conditions (as applicable to you); and
-
any collection notices and privacy statements which may be provided to you at the time your personal information is collected (for example, when you apply for a job with us).
4. WHAT IS PERSONAL INFORMATION?
Personal information generally means any information or an opinion about an identified individual, or an individual who is reasonably identifiable. It does not include anonymised data (where the personal information is rendered in such a manner that you are no longer identifiable from it). For the purposes of this Privacy Policy, “personal information” has the meaning ascribed to that term or to “personal data” under the Privacy Laws which apply to you.
5. WHAT INFORMATION DO WE COLLECT ABOUT YOU AND HOW DO WE COLLECT THIS INFORMATION?
Normally we collect your personal information from you directly, however on occasion, we may also collect personal information about you from other people and organisations as permitted by Privacy Laws.
In summary, we may collect your personal information when you:
-
you purchase products and services from us through our websites (including when checking out as a guest);
-
you sign up to receive our newsletter;
-
join Vi’s VIP Room loyalty program, including by creating an online account with us (or other membership or loyalty programs we may make available to you);
-
make a purchase or complete purchase orders for our products or services (via phone or electronically);
-
communicate with us during competitions, special events and promotions;
-
interact with us in person, via phone or online (including through our website or our social media channels), such as when you contact us to make an enquiry or give us feedback or when you submit a comment or other content for publishing on our websites or social media channels; or
-
apply for a position with us (including for work experience).
We may also:
-
receive personal information from another Ultra Violette entity (for example, to assist with providing our products to you or to administer the Vi’s VIP Room loyalty program); and
-
collect personal information from third parties (such as through acquisition of third party mailing lists and from organisations with whom we have an affiliation), to improve the personalisation of our offerings for you, and from our partners.
Summary of personal information we collect and how we collect this information
|
Type of personal information |
What this includes |
How do we collect this information? |
|
Personal information and contact details |
This may include your: · full name; · date of birth; · address; · email address; · phone number; and/or · loyalty membership ID with us (as appropriate).
This may also include contact details for your emergency contact. |
We may collect this information: · directly from you during conversations with our staff members (via phone or online); · when you sign up to receive our newsletter; · when you join Vi’s VIP Room loyalty program (including by creating an online account with us) or other membership or loyalty programs we may offer from time-to-time; · when you communicate with us during competitions, special events and promotions; · when you begin the process for making a purchase of our products or services (even if you do not complete making your purchase); · when you complete purchase orders for our products or services (by phone or electronically); · when you contact us via our online chat functionality, or via our social media channels; · if you apply for a position with us; · from our partners (for example, when you use our delivery service); and · when you otherwise interact with us on a commercial basis. |
|
Information about your purchases and use of Vi’s VIP Room loyalty program benefits |
This includes information about: · purchases you have made, such as what, how and when you make purchases (including the price of those purchases); · information regarding purchases which count towards your Vi’s VIP Room loyalty program account; and · your use of any Vi’s VIP Room loyalty program benefits (such as using a birthday reward towards any of your purchases). |
We may collect this information when you: · purchase our products or services online (without signing up to the Vi’s VIP loyalty program); and · are logged into / use your Vi’s VIP Room loyalty program account and you make a purchase of or complete purchase orders for our products or services online.
Note that if you checkout as a guest (i.e. without signing up to the Vi’s VIP Room loyalty program), we will still collect information about your purchases and attach these to your email address. This is so that if you do later sign up to the Vi’s VIP Room loyalty program, your past purchases will retrospectively be applied to your membership (for the purposes of affording you with the benefits provided under the Vi’s VIP Room loyalty program).
|
|
Workplace information |
This may include: · information relating to your work history; · information about your education and qualifications; · your working eligibility rights (including relevant Visa information); · your suitability for the role you are applying for; and · details about your referees. |
We may collect this information if you apply for a position with us (including if you are applying for work experience with us). |
|
Information collected during our interactions – this may include sensitive information regarding your health or racial or ethnic origin |
This includes details of your interactions with us, for example information you provide us when you make an enquiry or complaint or you submit a comment or other content to us.
Our products may be regulated by regulatory authorities in your jurisdiction.
In limited circumstances, this may include sensitive information (afforded additional protections under the Privacy Laws) regarding your health, such as information on any skin or other health issues you may experience in connection with your use of our products (and as part of this, we may collect information regarding your racial or ethnic origin, as it relates to these skin or health issues). |
We may collect this information: · when you call us or we call you; · when you use our online services (such as our websites or our social media channels), including to submit a comment or other content for publishing; · when you make an enquiry, provide feedback, or make a complaint (via phone, email or otherwise); and · in your responses to customer satisfaction, service development, quality control, research surveys and similar activities. |
|
Online and digital services information (including behavioural information) |
We may collect information from you electronically, which includes information such as your IP address, and details about your device. Depending on your location, we may obtain consent form you before collecting this information. Please see section 11 for further information on the digital information we collect. |
We may collect this information when you use our online services (such as https://ultraviolette.com.au/, https://ultraviolette.co.uk/ and https://ultraviolettespf.com, or our social media channels), via use of online behavioural technologies, such as cookies. Please see section 11 for further information on the digital information we collect. |
|
Call recording information |
This may include the voice recording, time, date, number and name of individuals on the call. |
We may collect this information in circumstances where we monitor and record our call with you, when we call you, or you call us. We will let you know if we are going to record call information. |
|
Publicly available online information |
We may collect information that is publicly available online, such as on online forums, websites, and social media channels (for example, information that relates to a complaint or information about your social media presence, for the purpose of identifying and contacting you regarding collaboration opportunities). |
We may collect this directly from the publicly available source (for example, on the online forum, website, or social media channel). |
In some cases you may provide us with personal information which relates to another person (for example, referring a friend to Vi’s VIP Room loyalty program, purchasing and sending a UV gift card to someone else or nominating a job referee). If you do so, you agree that you have received permission from these individuals for us to collect, use, and disclose, their personal information in accordance with this Privacy Policy. You should also let them know about our Privacy Policy (including the information in this Privacy Policy).
6. WHAT HAPPENS IF YOU DON’T PROVIDE US WITH YOUR PERSONAL INFORMATION?
Most of the time, you will have the option of not providing your name, or using a fake name, when you deal with us (where it is lawful and practicable), but in general, some information about you is required in order for you to access certain parts of our products, services and website. This includes, for example, when you make a general enquiry.
In some circumstances, however, we may need your real name as it may not be practicable for us to deal with you anonymously or pseudonymously on an ongoing basis. For example, this includes when processing your order with us or when adding purchases to your Vi’s VIP Room loyalty program account.
This means that if we do not collect your personal information, we may not be able to provide you with the products and/or services you have asked for.
7. WHY DO WE COLLECT, STORE AND USE YOUR PERSONAL INFORMATION AND WHAT IS OUR LEGAL BASIS FOR THIS PROCESSING?
We collect personal information that is necessary to provide you with our products and services, and to carry out our business.
We may use and otherwise process your personal information for purposes which are incidental to the sale and promotion of our goods and services, or for other purposes to which you consent, which are within your reasonable expectation, or are otherwise permitted or required by law in such jurisdictions.
If Canadian Privacy Laws apply to you or if you are located in the United States
If Canadian Privacy Laws apply to you or if you are located in the United States, we will collect, use, and disclose your personal information for the purposes for which you have provided your consent or are otherwise permitted or required by law.
By accessing or using the Ultra Violette website, you confirm that you understand, accept, and consent to the collection, use, and disclosure of your personal information as described in this Privacy Policy. You may withdraw your consent to our collection, use, and disclosure of your personal information at any time by contacting us using the contact details provided in section 17. If you withdraw your consent to our collection, use, or disclosure of your personal information, we may not be able to provide you with certain products, services, features, or communications, including as are made available through our website.
If the UK GDPR applies to you
If the UK GDPR applies to you, we may process your personal data using the following legal bases:
-
performance of a contract: where we need to perform a contract which we are about to enter into or have entered into with you as a party or to take steps at your request before entering into such a contract;
-
legal obligation: the processing is necessary for us to comply with our legal obligations;
-
legitimate interests: the processing is necessary for our (or a third party’s) legitimate interests, provided that your fundamental rights do not override such interests; or
-
consent: you have given your express consent that we may process your information for these specific reasons.
If the UK GDPR applies to you and we process sensitive or special category personal data, for instance information regarding your health and racial or ethnic origins as mentioned above, we will also ensure we are permitted to do so under applicable Privacy Laws. We rely on the following conditions to do so:
-
we have your explicit consent; or
-
the processing is necessary for us to comply with our obligations as an employer; or
-
the processing is necessary to establish, exercise or defend legal claims.
We have indicated which of these conditions we rely on in relation to particular processing in the table below.
Where we have determined, acting reasonably and considering the circumstances, that we are able to rely on legitimate interests as the lawful basis on which to process your personal information, we have stated this below and set out our legitimate interests. We have reached this decision by carrying out a balancing exercise to make sure our legitimate interest does not override your privacy rights as an individual.
We use automated decision making and profiling in limited circumstances for the purposes set out above. However, such automated decision-making or profiling will never be used in circumstances where it may have a legal or similarly significant impact on you.
Purpose for processing and legal basis
The purpose for which we usually collect, store, and use (and otherwise process) your personal information depends on how you interact with us (for example, whether you are part of our Vi’s VIP Room loyalty program), but may include the purposes identified in the following table.
The legal basis of processing your personal information if you are located in (Quebec), Canada is your consent, unless an exception under Privacy Laws applies. Where you have provided consent, you have the right to withdraw it. If UK GDPR applies, the legal bases are provided in the following table
|
Type of personal information |
Purpose |
Explanation |
Legal bases for processing (UK GDPR) |
|
· Personal Information and contact details · Information about your purchases and use of Vi’s VIP Room loyalty program benefits · Information collected during our interactions · Online and digital services information, · Call recording information · Publicly available online information |
To provide you with our products or services when you are a customer |
We may collect, store and use your personal information to: · provide you with our products or services you have purchased online (including to provide a delivery service); · administer, manage and communicate with you about existing products or services we are providing to you; · manage our relationship with you.
In addition, we may also collect, store and use your personal information to: · improve our products and services, and your experience with us; and/or · personalise your shopping experience with us by communicating with you about, displaying and promoting our products and services (including to let you know about other products and services you may be interested in based on information you have provided us with). |
· Necessary to comply with a legal obligation. · Performance of a contract. · Necessary to our legitimate interests: to provide our services to you and manage our relationship with you. · Consent. · Necessary to establish, exercise or defend legal claims.
To the extent that such personal data contains "special category personal data", then the processing of such data shall solely be on the basis of consent |
|
· Personal Information and contact details · Information about your purchases and use of Vi’s VIP Room loyalty program benefits |
To administer and manage the Vi’s VIP Room loyalty program |
We may collect, store and use your personal information to: · provide you with special offers and promotions (including your loyalty or member benefits or rewards, such as price discounts and vouchers); · provide you with the benefits of the Vi’s VIP Room loyalty program; · communicate with you about the Vi’s VIP Room loyalty program and promote our products and services (including to let you know about other products and services or promotions you may be interested in); · gather information about your purchases, including for data analytics activities (see ‘To conduct data analytics activities’ below in this table for further information); and · improve the Vi’s VIP Room loyalty program. |
· Performance of a contract. · Necessary to our legitimate interests: to manage and operate our loyalty program offering and develop our relationship with you. · Necessary to our legitimate interests: to promote our business and our products and services.. · Consent. · Our obligations as an employer |
|
Workplace information |
To manage your working relationship with us (including when you are a contractor) |
We may collect, store and use your personal information to assess your suitability for a position with us, and, if you successfully join us, to manage your working relationship with us.
We may collect, store and use your personal information for administration and management purposes (such as if you are a contractor). |
· Performance of a contract. · Necessary for legitimate interests: to assess applicants. · Necessary to our legitimate interests: to manage your employment or other engagement with us and handle any complaints or disciplinary action.
To the extent that such personal information contains "special category personal data", then the processing of such data shall solely be on the basis of complying with any duty imposed on us by an enactment to comply with our obligations as an employer |
|
· Personal Information and contact details · Publicly available online information |
To do business with you |
We may collect, store and use your personal information about you if you interact with us on a commercial basis (such as if you are a service provider, contractor or supplier to us), or you otherwise interact with us on a commercial basis (such as partnering with us to promote our products and services). |
· Performance of a contract. · Necessary to our legitimate interests: to maintain and develop further our business relationships with you. |
|
· Personal Information and contact details · Information about your purchases and use of Vi’s VIP Room loyalty program benefits · Information collected during our interactions · Online and digital services information · Call recording information · Publicly available online information |
To manage and improve our operations and business |
We may collect, store and use your personal information to: · manage fees and administer billing (including administration of third party payment arrangements) and debt recovery; · manage, monitor, plan and evaluate our products and services; · conduct safety and quality assurance and improvement activities, including quality control of our products, services and communications with you; · train staff (including sales staff); · test and maintain information technology systems; · investigate any incidents that may occur (both in relation to cyber security, as well as any health and safety incidents that may occur); · handle and respond to any complaints made; and/or · assist with product and service development, to test the effectiveness and customer satisfaction of our products and services, improve the way we provide products and services to you, and for other quality assurance and compliance purposes. |
· Necessary to comply with a legal obligation. · Performance of a contract. · Necessary for legitimate interests: to increase our knowledge and understanding of, and improve, our products and services. · Necessary to our legitimate interests: to develop our relationship with you and deal with complaints in a proper and efficient manner. · Necessary to our legitimate interests: to provide our products services to you and comply with our obligations under our contract with you. · Necessary to our legitimate interests: to ensure the ongoing, efficient and secure running of our websites and our business, including through maintaining information technology services, network, data security and fraud detection. |
|
· Information about your purchases and use of Vi’s VIP Room loyalty program benefits · Information collected during our interactions · Online and digital services information · Publicly available online information |
To create anonymised data for data analytics activities |
When permitted under Privacy laws, we may collect, store and use your personal information to create anonymised data sets (which is no longer personal information).
We use this anonymised data to assist with our business decisions, such as to: · help us in understanding trends in customer behaviour (such as the success of our products and services, and our different marketing campaigns (such as promotions)); · create look-a-like audiences for the purposes of providing targeted advertising to other customers; · improve the products and services we offer; and · develop new products and services that better meet our customers’ preferences and behaviours. |
· Necessary to our legitimate interests: to enable us to properly administer our websites. · Necessary to our legitimate interests: to assist us to grow our business and to decide on our marketing strategy. · Necessary to our legitimate interests: to increase our knowledge and understanding of, and improve, our products and services. |
|
· Personal Information and contact details · Information about your purchases and use of Vi’s VIP Room loyalty program benefits |
To assist with any business, share sale or corporate restructure |
We may collect, store and use your personal information for the purpose of facilitating or implementing a transfer or sale of all or part of our assets or business or if we undergo any other kind of corporate restructure, acquisition or sale. |
· Necessary to our legitimate interests: to manage responsibly the ongoing trading of the business as may be necessary or appropriate in the circumstances. |
8. WHO DO WE DISCLOSE YOUR PERSONAL INFORMATION TO AND WHY?
We may disclose your information with third parties:
-
for the reasons for which we collect, store and use that information (see above in section 7);
-
for other reasonable purposes explained at the time we collect your personal information; or
-
where we are otherwise allowed or required to do so under law.
Some of the third parties we may disclose your information to include the following:
|
Types of personal information |
Recipient |
Explanation |
|
· Personal Information and contact details · Information about your purchases and use of Vi’s VIP Room loyalty program benefits · Information collected during our interactions · Online and digital services information · Publicly available online information |
Other Ultra Violette entities |
We may disclose your personal information to Ultra Violette entities.
For example: · when you are part of the Vi’s VIP Room loyalty program, we may disclose your personal information to the Ultra Violette entity responsible for administering the loyalty program to provide you with the rewards and benefits made available to you under the program; · we may disclose information about your purchases to other Ultra Violette entities, to better understand consumer behaviour in relation to the products and services we offer; · we may disclose your personal information to another Ultra Violette entity where that entity provides backend IT support and other corporate services to other Ultra Violette entities; · where it is necessary, for example you have entered into a promotion or competition operated by one Ultra Violette entity, however, another Ultra Violette entity is responsible for delivering all or some of the prize; and · for direct marketing purposes, for example we may disclose your personal information to another Ultra Violette entity so that the other Ultra Violette entity can serve targeted advertising which may be of interest to you.
|
|
· Personal Information and contact details · Information about your purchases and use of Vi’s VIP Room loyalty program benefits |
Our partners, suppliers and other entities we do business with |
We may disclose your personal information with our partners and other entities we do business with to assist in providing our products and services.
The kinds of third parties to whom we may disclose personal information to include delivery services providers, manufacturers, suppliers and distributors.
For example, our online store is hosted on Shopify Inc. They provide us with the online e-commerce platform that allows us to sell our goods and services to you. We will disclose personal information with Shopify for the purposes of providing our online store.
We will also disclose your personal information with Shopify to check if you have an account with Shop by Shopify. If the email address you use at the time of placing an order, or for your online shopping account or Vi’s VIP loyalty program membership, is also linked to a Shop by Shopify account, your information (including information regarding your purchases with us) may be used by Shopify to provide information on your purchase in your Shop account, if you choose to sign into your Shop account when prompted. |
|
· Personal Information and contact details, Information about your purchases and use of Vi’s VIP Room loyalty program benefits · Information collected during our interactions · Online and digital services information · Call recording information · Publicly available online information |
Our service providers and advisors |
We may disclose your personal information to a variety of our service providers to assist us with providing, promoting and managing our products and services. These may include our: · IT service providers and third party storage providers (such as Oracle, Celigo, Airwallex, AWS, NAB and Xero); · marketing and communications agencies; · data analysis organisations; and · professional advisors and consultants (such as legal, insurance and financial advisors). |
|
· Personal Information and contact details · Information about your purchases and use of Vi’s VIP Room loyalty program benefits · Workplace information |
Corporate restructure |
We may disclose your personal information with third parties, whether affiliated or unaffiliated, for the purpose of facilitating or implementing a transfer or sale of all or part of our assets or business or if we undergo any other kind of corporate restructure, acquisition or sale. In this context (or if such a sale, transfer, acquisition or corporate restructure is being contemplated by us), your personal information may be transferred to another entity. |
|
· Personal Information and contact details · Information about your purchases and use of Vi’s VIP Room loyalty program benefits · Information collected during our interactions · Call recording information |
Government and law enforcement agencies |
We may disclose your personal information with regulatory bodies, government agencies and law enforcement bodies to comply with our legislative or regulatory obligations (such as to assist with police investigations).
This may also include disclosing information regarding your health or other conditions you experience in connection with our products if required (noting our products may be regulated by regulatory authorities in your jurisdiction). |
9. DO WE DISCLOSE YOUR PERSONAL INFORMATION OVERSEAS?
Ultra Violette is a global organisation and works with customers, stockists, service providers and commercial interests across the globe.
It is likely that your personal information will be disclosed within our group of companies which operate in different jurisdictions around the world, including in countries such as the UK, Canada, Australia, the United States and to overseas recipients.
We generally collect your personal information in Australia or the jurisdiction in which the Ultra Violette entity you are dealing with is located (such as the UK, the U.S. or Canada). It is likely that we will disclose your personal information outside of the jurisdiction it was collected, such as with overseas recipients located in Israel, the United States of America, the United Kingdom, Switzerland and other countries within the European Economic Area. These recipients include our service providers who may handle, process or store your personal information on our behalf.
For example, we may disclose your personal information with service providers who assist us with storing our data on secure data storage servers, or with improving our products and services (by analysing sales information and trends, and conducting customer satisfaction enquiries).
We only ever disclose your personal information outside of the jurisdiction your personal information was collected where we are permitted to do so under Privacy Laws.
Since your personal information may be collected, used or disclosed outside of your jurisdiction of residence as described in this Privacy Policy, your personal information may potentially be accessible to law enforcement and national security authorities of another jurisdiction where local laws provide for a different level of protection for personal information. In certain circumstances, courts, law enforcement agencies, regulatory agencies, or security agencies in those other countries may be entitled to access your personal information.
If the UK GDPR applies to you
Whenever we transfer personal information outside of the UK, we ensure at least one of the following safeguards is implemented:
-
we will only transfer your personal information to countries that have been deemed to provide an adequate level of protection for personal information by the UK Government); or
-
we may enter into standard contractual clauses (or equivalent measures) with the third party located outside of the UK.
Please contact us using the details set out in section 17 to request further details.
10. DO WE USE OR DISCLOSE YOUR PERSONAL INFORMATION FOR DIRECT MARKETING?
When you provide your personal information to Ultra Violette, we may use that personal information to send you direct marketing communications to keep you informed about products and services offered by Ultra Violette and carefully selected partners which we think might be of interest to you based on your interactions with us.
For example, when you sign up to receive our newsletter or join the Vi’s VIP Room loyalty program, we may send you direct marketing communications and information about our products and services that we consider may be of interest to you (such as special offers and promotions offered under the Vi’s VIP Room loyalty program), or as otherwise allowed under applicable Privacy Laws.
We may communicate with you (and send these electronic messages and tailored advertising) through various channels (which may vary depending on your details provided), such as via email, SMS, telephone, push notifications or social media (including through targeted advertisements on certain websites and social media channels).
We will only send these communications in accordance with applicable privacy and marketing laws and only where you have not opted out from receiving that channel of communication from us (see below at “Important points regarding opting out”).
How can you opt out?
You are always in control of the direct marketing communications which you receive and can opt out at any time. You can opt out by following the relevant opt out or unsubscribe instructions in the relevant communication (such as email or SMS message).
You can also contact us using the details set out in section 17 to tell us you would like to stop receiving direct marketing communications from us.
For cookies which use your personal information for direct marketing (such as targeted advertising) you can only opt out by adjusting your device setting and online privacy settings (for advertising on certain websites and social media channels).
For more information about cookies, including how to opt out of targeted advertising, see our Cookie Policy.
Important points regarding opting out
Opting-out is channel specific, which means that if you receive SMS and email marketing messages from us and you opt-out of receiving our SMS marketing messages, you will still receive our email marketing messages (and you will need to separately opt-out of receiving our email marketing messages if you wish to opt-out of receiving these communications).
· Importantly, regardless of whether you opt out from receiving any or all direct marketing communications, we will still communicate with you if we are required by law to provide you with information, or in relation to the services or products we are providing you with (for example, in relation to delivery information for products, sending you an invoice in relation to a transaction or providing you with any vouchers you have earnt through the Vi’s VIP Room loyalty program).
If you are located in the Province of Quebec, how can you opt-in?
If you are located in the Province of Quebec, the cookies that are able to identify, localise or profile you, are turned off by default. To benefit of the functionalities of our website that allow us to identify, localise or profile you, you need to turn them on by accepting all cookies from our cookie banner or to select the desired cookies in our Quebec Cookies Center.
11. HOW DO WE INTERACT WITH YOU VIA THE INTERNET?
Third party links and sites
When you use our websites or receive communications from us, links to websites which belong to other third parties may be included (and are provided for your convenience). You should make your own enquiries as to the privacy policies of these parties. We are not responsible for information on, or the privacy practices of, any third party websites.
In addition, when you make online payments using our websites, we do not collect your credit card or banking details. This is because online payments are handled by third party payment providers such as PayPal, Afterpay, Klarna and Shop Pay (powered by Shopify) (as applicable) – please use these links to see details of their privacy and security policies before making online payments. As with all third-party providers, we are not a party to any agreement between you and the third-party payment provider, and we do not control their privacy or data security policies.
Website use and cookies
You may visit our websites without identifying yourself. If you identify yourself (for example, by creating an online account or making an enquiry), any personal information you provide to us will be managed in accordance with this Privacy Policy.
Our websites also use cookies (and we disclose personal information we collect between Ultra Violette entities). A “cookie” is a small file stored on your computer's browser, which assists in managing customised settings of the website and delivering content. We may collect certain information such as your device type, browser type, “click-through” information, IP address, pages you have accessed on our websites and on third party websites. Depending on the circumstances, this may or may not be personal information.
At a high level, cookies can be used for a variety of reasons, such as to personalise your browsing experience (for example, by remembering your preferences and recognising you as a repeat visitor to our websites), and to track statistics about the usage of our website. This allows us to better understand our users and improve the layout and functionality of our websites.
Except If you are located in the Province of Quebec in Canada, if you do not wish to receive any cookies (other than those that are strictly necessary) you can use the settings in your browser to control how your browser deals with cookies. However, in doing so, you may be unable to access certain pages or content on our websites. If you are located in the Province of Quebec, as provided in section 10, some of the cookies we use will already be turned off by default
Please see our separate Cookie Policy for further information about what cookies we use and information we collect online and through digital services.
12. HOW DO WE STORE AND PROTECT YOUR PERSONAL INFORMATION?
We are committed to protecting your personal information, and ensuring that we securely store any personal information we collect (and in accordance with applicable Privacy Laws). We may hold your personal information in hard copy (paper) or electronic form.
We take all reasonable steps to ensure that any personal information we collect, use or disclose is accurate, complete, up-to-date and stored, transmitted or otherwise processed in a secure environment protected from misuse, interference, destruction, and loss, and from unauthorised access, modification or disclosure.
Security and storage of personal information
|
Form |
Explanation |
|
Paper-based files |
We store personal information in paper-based files in secure storage (generally at our head office). Personal information may be collected in paper-based documents and converted to electronic form for use or storage (with the original paper-based documents either archived or securely destroyed).
We maintain physical security measures to ensure that personal information in paper-based files is protected, such as physical locks and security systems at our premises. |
|
Electronic records |
We store electronic records in secure databases, using trusted third party storage providers based in Israel, the United States of America, the United Kingdom, Switzerland and other countries within the European Economic Area. We also maintain physical security measures in relation to storage of our electronic records (such as through locks and security systems at our electronic data stores).
Using technical methods, we also maintain computer and network security. For example, we use firewalls (security measures for the internet) and other security systems such as user identifiers and passwords to control access to our computer systems. |
|
Our websites (including for making payments) |
Our websites use encryption or other technologies to ensure that your personal information is securely transmitted via the internet (including to protect any payments you make).
We encourage you to exercise care when sending your personal information via the internet (for example, when communicating with us online, we ask that you do not include your full account or card details). |
How long do we keep your personal information?
We will only keep your personal information that we store for as long as is necessary to fulfill the purposes for which the personal information was collected, as set out in this Privacy Policy or as required to comply with any applicable legal obligations.
When deciding what the correct time is to retain your personal information for we take account of:
· legal and regulatory requirements and guidance;
· limitation periods that apply in respect of taking legal action;
· our ability to defend ourselves against legal claims and complaints;
· good practice; and
· the operational requirements of our business.
When we no longer require your personal information (and when permitted by and in accordance with any applicable laws), we will take steps to delete, destroy or anonymise that information.
13. HOW CAN YOU ACCESS OR SEEK CORRECTION OF YOUR PERSONAL INFORMATION?
You are entitled to request access to any of your personal information that we have. Computerised personal information will be communicated in the form of a written and intelligible transcript.
If you are handicapped, reasonable accommodation will be provided on request to enable you to exercise you right of access. To make such a request, please contact us using the relevant contact details set out below in section 17.
If you are located in the Province of Quebec in Canada, unless doing so raises serious practical difficulties, computerised personal information collected from you and not created or inferred using personal information concerning you, will, at your request, be communicated to you in a structured, commonly used technology format. The information will also be communicated, at your request, to any person or body authorised by law to collect such information. To make such a request, please contact us using the relevant contact details set out below in section 17.
We will take reasonable steps to ensure that the personal information we collect, use or disclose is accurate, complete and up-to-date. You can help us to do this by letting us know if you notice errors or discrepancies in information we hold about you and by informing us of any change in your personal details (for example, if your email or postal addresses change).
If you consider any personal information we have about you is inaccurate, out-of-date, incomplete, irrelevant or misleading, you are also entitled to request correction of the information (again, please contact us). After receiving a request from you, we will take reasonable steps to correct your information.
We may decline your request to access or correct your information in certain circumstances in accordance with the applicable Privacy Laws. If we do refuse your request, we will provide you with a reason for our decision. In addition, in the case we refuse your request for correction, we will include a statement about your request with the personal information we store.
14. HOW CAN YOU MAKE A COMPLAINT ABOUT THE HANDLING OF YOUR PERSONAL INFORMATION?
If you have any questions or concerns about this Privacy Policy or how we have handled your personal information, you may contact us at any time using the relevant contact details set out below in section 17.
Please also contact us if you have a complaint about privacy. If you make a complaint about privacy, the following will occur:
|
No. |
Step |
|
1. |
We will first consider your complaint to determine whether there are simple or immediate steps which can be taken to resolve the complaint. |
|
2. |
If your complaint requires more detailed consideration or investigation: · we will acknowledge receipt of your complaint within a week and endeavour to complete our investigation into your complaint promptly; and · we may ask you to provide further information about your complaint and the outcome you are seeking. |
|
3. |
We will then typically gather relevant facts, locate and review relevant documents and speak with the individuals involved. |
|
4. |
In most cases, we will respond to your complaint within 30 business days from when we receive your complaint. If the matter is more complex or our investigation may take longer, we will let you know. |
If you are not satisfied with our response to your complaint, or you believe that we have breached applicable laws and regulations with regards to the handling of your personal information, you may be able to file a complaint with a regulator / local data protection authority in your jurisdiction.
|
Jurisdiction |
Contact |
|
Australia |
If you are located in Australia, you may make a complaint to the Office of the Australian Information Commissioner (OAIC).
The OAIC can be contacted by telephone on 1300 363 992, or you can fill out this form to make a complaint about our handling of your personal information. Full contact details for the Office of the Australian Information Commissioner can be found online at www.oaic.gov.au. |
|
UK |
If you are located in UK, the UK GDPR gives you the right to lodge a complaint with the Information Commissioner’s Office who may be contacted at https://ico.org.uk/concerns/. |
|
Canada |
If you are located in Canada, you may make a complaint to the Office of the Privacy Commissioner of Canada (OPC). The OPC can be contacted by telephone at 1-800-282-1376, or you can fill out this form to make a complaint about our handling of your personal information. More information for the OPC can be found online at https://www.priv.gc.ca/en/report-a-concern/file-a-formal-privacy-complaint/file-a-complaint-about-a-business/. In addition, you may make a complaint to the following provincial privacy regulators if you reside in that province: · British Columbia – Office of the Information & Privacy Commissioner for British Columbia (OIPC); |
Please contact us using the relevant contact details set out below in section 17 if you have any questions about how you can contact your local data protection authority.
15. YOUR LEGAL RIGHTS IF THE UK GDPR APPLIES TO YOU
If the UK GDPR applies you, you have the following rights in relation to your personal information (where applicable):
· Access: you have the right to request a copy of any personal information we hold about you, in a structured, commonly used and machine-readable format.
· Rectification: you have the right to the rectification of your personal information, if you consider that it is incomplete or inaccurate.
· Deletion: you have the right to request that we delete certain personal information that we process about you, except we are not obliged to do so if we need to retain such personal information in order to comply with a legal obligation or to establish, exercise or defend legal claims.
· Restriction: you have the right to request restriction to our processing of your personal information in certain circumstances.
· Portability: you have the right to ask us to transfer a copy of certain personal information to you or to another service provider or third party where technically feasible.
· Objection: you have the right to object to your personal information being processed for a particular purpose (including direct marketing) or to request that we stop processing your information. You also have the right to object to certain decisions being taken by automated means which produce legal effects concerning you or similarly significantly affect you.
· Complaint: As noted above, if you are unhappy with our treatment of your personal information, and you have contacted us as set out below, you have the right to lodge a complaint with the local data protection authority.
When you exercise any of these rights we will respond within a reasonable period and in any event within one month (in compliance with the UK GDPR). Please note that in some circumstances we have the right to extend the period within which we respond to your rights request by up to two months
If you have consented to our processing of your personal information, you have the right to withdraw, at any time, any consent that you have previously given to us for use of your personal information. In certain circumstances even if you withdraw your consent we may still be able to process your personal information if required or permitted by law or for the purpose of exercising or defending our legal rights or meeting our legal and regulatory obligations. Please note that some of these rights may not always apply, as there are sometimes requirements and exemptions which may mean we need to keep processing the personal information or not disclose it, or other times when the rights may not apply at all
To make a request to exercise any of these rights (where applicable) in relation to your personal information, please contact us using the relevant contact details set out below in section 17.
16. HOW ARE CHANGES ARE MADE TO THIS PRIVACY POLICY?
We may make changes to this Privacy Policy, with or without notice to you. However, where we make a material change to the Privacy Policy, we will provide notice to you (including by updating our websites, and, where appropriate, notifying you directly). We recommend you visit this Privacy Policy regularly to keep you up to date with any changes we make.
17. HOW CAN YOU CONTACT US?
You can contact us using the details below:
|
|
ULTRA VIOLETTE (Privacy Officer) |
|||||
|
|
Australia |
UK |
Canada |
United States |
Elsewhere |
|
|
|
||||||
|
Postal address |
19 Dover street Cremorne, VIC, Australia, 3141 |
19 Dover street Cremorne, VIC, Australia, 3141 |
19 Dover street Cremorne, VIC, Australia, 3141 |
19 Dover street Cremorne, VIC, Australia, 3141 |
19 Dover street Cremorne, VIC, Australia, 3141 |
|