2. Definitions
"Canopy", "Canopy DLM", "we", "us", "our" means PhoneCycle Pty Ltd (ABN 71 152 085 295), trading as Canopy DLM, and includes our employees, contractors, sub-contractors and agents. Our registered business name is Canopy DLM. "Canopy" is our brand name, used across our website, marketing and in this Policy, and any reference to "Canopy" is a reference to Canopy DLM / PhoneCycle Pty Ltd (ABN 71 152 085 295).
"You, your" means the individual whose personal information we collect, hold, use or disclose, including customers, website visitors, job applicants, and other individuals we deal with in the course of our business.
"Goods / Devices" means mobile phones, smartphones, tablets, laptops, desktops, all-in-one computers and related accessories including batteries, chargers and peripherals, consistent with the meaning given in our Terms and Conditions.
"Personal Information" means information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether true or not, and whether recorded in a material form or not.
"Sensitive Information" means Personal Information about an individual's racial or ethnic origin, political opinions or associations, religious or philosophical beliefs, professional or trade association or trade union membership, sexual orientation or practices, criminal record, or health, genetic or biometric information.
"APPs" means the Australian Privacy Principles set out in the Privacy Act 1988 (Cth).
"OAIC" means the Office of the Australian Information Commissioner, Australia's independent privacy regulator.
"Notifiable Data Breach" has the meaning given in the Privacy Act 1988 (Cth).
We collect Personal Information that is reasonably necessary for our business functions and activities, including our DEPLOY, REPAIR and RECOVER services (as described in our Terms and Conditions). This may include your name, contact details, date of birth, payment and billing details, employment or business details, and records of your dealings with us.
We may also collect additional information you provide when you give us feedback or make an enquiry; provide details about your personal or business affairs, for example as part of a corporate device collection or buyback arrangement; update your marketing or communication preferences; respond to a survey or promotion; provide financial or payment details; or contact our customer support or account management team.
Goods provided to us for repair, buyback, refurbishment, recovery or recycling may contain Personal Information belonging to you or third parties, including photos, contacts, accounts or files. Clause 8 (Data Security, Retention and Device Data) explains how we handle this.
4. How We Collect Personal Information
We collect Personal Information in a variety of ways, including when you interact with us electronically or in person, when you access our website, when you use a Service, or when Goods are provided to us for collection, repair, grading, buyback or recycling.
Where reasonably practicable, we collect Personal Information directly from you. We may also receive Personal Information from third parties, including MSP or enterprise customers submitting Goods on your behalf, referral partners, or publicly available sources. Where we do, we protect it in the same way as information collected directly, as set out in this Policy.
5. How We Use and Disclose Personal Information
We use and disclose Personal Information for the primary purpose for which it was collected, and for related secondary purposes you would reasonably expect, including:
3. Personal Information We Collect
- providing, managing and improving our DEPLOY, REPAIR and RECOVER services;
- billing, invoicing and account management;
- business planning and service development;
- providing information about promotions or new services; and
- personalising your experience of our website based on your preferences and prior interactions.
We will not use Personal Information without taking reasonable steps to ensure it is accurate, complete and up to date.
We may disclose Personal Information to trusted third parties who help us deliver our Services, such as IT and data hosting providers, payment processors, logistics and courier providers, or professional advisers, where that disclosure is for a related secondary purpose that has been notified to you or is within your reasonable expectations. We take reasonable steps to ensure our contracts with these providers require them to handle Personal Information consistently with the APPs.
We may disclose Personal Information to law enforcement agencies, government agencies, courts or external advisers where permitted or required by law, or to avoid an imminent threat to a person's life, health or safety, or to public safety.
Except as set out in this clause, we will not disclose Personal Information unless it is for the primary purpose of collection, a related secondary purpose, or we have your consent.
6. Direct Marketing
Where we direct market to you, we will clearly notify you of your right to opt out; provide a simple opt-out mechanism in every communication you have not already opted out of; and respect your opt-out request, other than to confirm it or where we are separately required to contact you, for example about an active order or Service.
7. Overseas Disclosure
Some of the third-party providers we use to operate our business and website, including cloud hosting, email, customer relationship management and payment processing providers, may store or process Personal Information on servers located outside Australia. Where this occurs, we take reasonable steps to ensure the overseas recipient handles Personal Information consistently with the APPs, or we obtain your consent to the disclosure.
8. Data Security, Retention and Device Data
We take reasonable steps to protect the Personal Information we hold from misuse, interference, loss, and unauthorised access, modification or disclosure. Personal Information is generally held in electronic databases, some of which may be managed on our behalf by third-party data storage providers.
We require our employees and contractors to handle Personal Information consistently with our privacy obligations, and restrict access to those with a genuine business need.
We only keep Personal Information for as long as it is reasonably needed for the purpose it was collected, or as required by law, including our tax and corporate record-keeping obligations, after which we securely destroy, permanently de-identify, or return it.
Goods provided to us for repair, buyback, refurbishment, recovery or recycling are sanitised in accordance with clause 7 (Data Responsibility Before Sanitisation) of our Terms and Conditions: we use certified data erasure tools in line with industry standards and issue a Data Clearance Certificate, and where Goods cannot be digitally sanitised, we route the relevant storage media to our approved e-waste recycling partners for physical destruction.
9. Data Breaches
If we experience a data breach involving Personal Information that is likely to result in serious harm, we will investigate and, where required under the Notifiable Data Breaches scheme in the Privacy Act, notify affected individuals and the OAIC as soon as practicable.
10. Cookies and Website Analytics
Our website may use cookies and similar tracking technologies, including web analytics tools to understand how visitors use our website and to improve your experience. You can disable cookies through your browser settings, though this may affect how our website functions.
11. Access and Correction
You may request access to the Personal Information we hold about you, and ask us to correct it, in accordance with the Privacy Act. To make a request, contact us using the details in clause 15 (Contact Us). We will respond within 30 days, and will only refuse a request where permitted under the Privacy Act, in which case we will explain our reasons.
12. Complaints
If you believe we have breached the APPs or mishandled your Personal Information, contact us using the details in clause 15 (Contact Us). We will acknowledge your complaint within 7 days and aim to resolve it within 30 days.
If you are not satisfied with our response, you may lodge a complaint with the OAIC at www.oaic.gov.au or by phone on 1300 363 992.
13. Anonymity and Pseudonymity
Where lawful and practicable, you may deal with us anonymously or under a pseudonym. We will not require you to provide Personal Information unless it is reasonably necessary to respond to your enquiry or provide a Service. We may invite you to voluntarily provide Personal Information, for example as part of a competition or questionnaire.
14. Changes to this Policy
We may update this Policy from time to time to reflect changes to our practices, our Services, or the law. The version published on our website at the relevant time applies. We recommend reviewing this Policy periodically.
15. Contact Us
Canopy (PhoneCycle Pty Ltd, ABN 71 152 085 295) operates from Ringwood, Victoria. For privacy-related questions, requests or complaints, contact us via the details published on our website, or lodge a complaint with the OAIC as set out in clause 12 (Complaints).