Privacy Policy
CaravanWorks is a software application developed and maintained by Mythradon Pty Ltd
Date last updated: 12th January 2023
- About this Privacy Policy
- This Privacy Policy describes how Mythradon Pty Ltd ABN 35 644 344 409 of 470 St Kilda Road, Melbourne Victoria 3004 (we, us and our) manages personal information about our customers (including our resellers), individuals whose data is processed by or on their behalf and users of our Mythradon Customer Success Platform and the Mythradon website at https://mythradon.com/. All such individuals are referred to in this Privacy Policy as "data subjects".
- Mythradon is committed to upholding the highest privacy standards in all jurisdictions in which we operate. We adhere to all relevant privacy laws and regulations, including the Australian Privacy Act 1988, The United Kingdom General Data Protection Regulation (UK-GDPR) and the General Data Protection Regulation (GDPR). We take the protection of personal data seriously and strive to ensure that all personal data is collected, used, and shared in a transparent and compliant manner.
-
This Privacy Policy describes:
- The period for which we store personal information;
- A data subject's right to access, rectify or to request erasure of personal information;
- A data subject's right to withdraw consent to our collection and use of your personal information;
- A data subject's right to lodge a complaint with the Office of the Australian Information Commissioner (OAIC);
- Why we collect and process personal information, the types of personal information that we collect and process and who we disclose it to;
- Details of the security measures that we take to help protect personal information; and
- Other information about how we collect, use and disclose personal information.
- We are committed to complying with our privacy obligations in accordance with the Australian Privacy Principles contained in Schedule 1 to the Privacy Act 1988 (Cth).
- If we decide to change this Privacy Policy, we will post the updated version at https://mythradon.com/privacy and notify you of such updates to the email account notified by our data subjects to us. Our policy is to be completely transparent about our privacy practices.
- Our Platform
- We own and operate the Mythradon Customer Success Platform which provides customer relationship management functionality to business entities (Mythradon CSP) and the Mythradon website at https://mythradon.com/ (Mythradon Website) (together, the Mythradon Platform).
- We enter into contracts with our customers for their subscription to the Mythradon CSP. The Mythradon CSP provides customers with functionality that can be used by them to collect, process and disclose personal information about their end users and other data subjects. We may also appoint resellers who may enter into contracts for their distribution of access to the Mythradon CSP.
- Customer responsibility for data subject privacy
- Our customers (including our resellers and their authorised end users) are required to comply with all applicable privacy laws.
- We rely on our customers to obtain all relevant privacy consents and authorisations from data subjects required by law, in order for the personal information that is entered into the Mythradon CSP to be collected, disclosed and otherwise processed by us.
- We also rely on our customers to ensure that all personal information of their data subjects held by us is accurate, up to date, complete, relevant and not misleading.
- We encourage our customers to ensure that their data subjects are familiar with their privacy policies so that their data subjects understand how the relevant customer will collect, use and otherwise process personal information about them, via the Mythradon CSP or otherwise.
- The types of personal information we collect and hold about customers and data subjects
- The Mythradon Platform can be used to collect and hold the following types of personal information:
- Content entered into the Mythradon Platform about data subjects: All information, including personal information, that is entered into the Mythradon Platform is stored in systems managed by our customers and/or by us on their behalf. The types of personal information collected may include names, dates of birth, telephone numbers, mobile numbers, email addresses, job titles, bank account details, transaction data, postal addresses, residential and business addresses, as well as any other personal information entered into the Mythradon CSP by, about or on behalf of a data subject.
- Financial Information: We collect billing and payment details. Credit card details are not held by us, but are held by payment gateway providers that we use. Other than the last 4 digits of a credit card, all such credit card information is not accessible by us.
- Information required for the support, maintenance and security of the Mythradon Platform: In order to support and maintain the Mythradon CSP for a customer or to maintain the Mythradon Website, we collect and process end user information including device ID, device type, computer and connection information, statistics on page views, traffic to and from the Mythradon CSP, advertising data, IP addresses, email addresses, user access logs, usernames, hashed passwords, information included by customers in technical support tickets and error messages.
- The Mythradon Platform can be used to collect and hold the following types of personal information:
- How we collect personal information
- Our policy is to not collect personal information by means that are unfair or unreasonably intrusive in the circumstances.
- We collect personal information about data subjects in one or more of the following ways:
- when end users enter personal information into the Mythradon CSP;
- when it is transmitted to the Mythradon CSP via an API in accordance with our obligations to do so pursuant to a contract with a customer;
- when a customer provides personal information to us;
- when it is provided to us by third parties such as government agencies on behalf of a customer or pursuant to an agreement with a customer, for it to be entered into and/or processed by the Mythradon Platform;
- publicly available records and registries, online searches and any other third party data sources that voluntarily disclose it to us.
- when it is voluntarily disclosed to us (such as via telephone, surveys, e-mail and online forms).
- How we use customer and data subject personal information
- We use customer and data subject personal information for the following purposes:
- to deliver software services for the purposes of fulfilling our obligations under our customer contracts;
- by hosting personal information on our servers that may incorporate personal information;
- in the course of providing support services (when receiving technical support calls or when accepting enquiries, requests or orders for new services);
- when employing staff and engaging contractors and when interviewing staff and contractors;
- through the use of cookies on the Mythradon Website;
- when processing orders for our products and services; and
- in order to identify members when contacted with questions or concerns regarding our products and services;
- We use customer and data subject personal information for the following purposes:
- Analytics data
- We also collect information about the Mythradon Platform end users known as analytics data including user location, the type of device accessing our platforms, the amount of time an end user spends on the Mythradon Platform and in which parts of it, and the path navigated through it. However, all such information is de-identified data and not collected in a form that could reasonably be expected to identify an individual. In any event, we only use analytics data for the following purposes:
- to help us review, enhance and improve the Mythradon Platform (for statistical or research purposes); and
- to develop case studies and marketing material without identifying any end users.
- We use analytics and cookie tracking on the Mythradon Website.
- We also collect information about the Mythradon Platform end users known as analytics data including user location, the type of device accessing our platforms, the amount of time an end user spends on the Mythradon Platform and in which parts of it, and the path navigated through it. However, all such information is de-identified data and not collected in a form that could reasonably be expected to identify an individual. In any event, we only use analytics data for the following purposes:
- How we hold and secure personal information
- We hold and store personal information that we collect in our offices, computer systems and third party owned and operated hosting facilities for a period of 7 years following the termination of any contract with a customer for information collected using the Mythradon CSP. For personal information not collected using the Mythradon CSP, we will hold and store such personal information for a period of 7 years following the date that we first collected the information. In particular:
- We hold data collected via the Mythradon CSP in hosting facilities operated by reputable hosting providers;
- personal information that is provided to us via email is held on our servers or those of our cloud-based email providers;
- we use third party owned cloud-based marketing platform providers to hold personal information about current and prospective customers;
- personal information is held on computers and other electronic devices in our offices and at the premises of our personnel;
- we hold personal information that is provided to us in hard copy in files on our business premises.
- We take reasonable steps to protect personal information that we hold using such security safeguards as are reasonable in the circumstances to take against loss, unauthorised access, modification and disclosure and other misuse and to implement technical and organisational measures to ensure a level of protection appropriate to the risk of accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal information transmitted, stored or otherwise processed by us.
- We:
- ensure all staff and contractors are aware of their information security responsibilities and that they are appropriately trained to meet those responsibilities;
- use SSL encryption on our systems;
- implement anti-virus and security controls for email and other applicable computer software and systems;
- have data backup archiving, data breach response plans and disaster recovery processes in place;
- implement passwords and access control procedures into our computer systems;
- perform audit tracking of personal detail read/updates;
- maintain other electronic (e-security) measures for the purposes of securing personal information, such as passwords, anti-virus management and firewalls
- maintain physical security measures in our buildings and offices
- ensure that data centres that we engage:
- undertake server security hardening services;
- employ strict security policies and visitor access management;
- keep entry points to a minimum to ensure full visibility of those entering the facility;
- use surveillance cameras and security barriers to keep unwanted intruders out;
- operate a strict access policy for all those on-site;
- implements DDoS prevention systems and 24/7 network monitoring;
- have extensive data backup and restoration facilities;
- implement two-factor authentication Access Control Systems in place to protect data from employee negligence or malicious activities; and
- incorporate a digital Visitor Management Solution to provide full visibility and accountability for any third party contractors or visitors who may require ad hoc access.
- with respect to personal information that we no longer require or where we are otherwise required to destroy it under applicable law, we ensure that such personal information is securely destroyed.
- We hold and store personal information that we collect in our offices, computer systems and third party owned and operated hosting facilities for a period of 7 years following the termination of any contract with a customer for information collected using the Mythradon CSP. For personal information not collected using the Mythradon CSP, we will hold and store such personal information for a period of 7 years following the date that we first collected the information. In particular:
- Disclosure of personal information
- We only disclose customer and data subject personal information that we collect to third parties as follows:
- where required under a contract with a customer, we will transmit data subject personal information to third parties on behalf of the customer. For example, the Mythradon CSP includes functionality that enables data subject personal information to be transmitted to third party systems. Customers may be able to effect those transfers using the Mythradon CSP or may instruct us to otherwise do so on their behalf;
- to our resellers where necessary for us or them to determine or calculate the amount of any commission that is payable by us to them;
- in order to host databases that are integrated into the Mythradon CSP, we engage reputable hosting providers who host those databases on our behalf;
- when performing contracts we may outsource certain obligations to third party contractors such as professional service providers in accordance with our contractual rights. Professional services carried out by them may require access to customer and data subject personal information;
- when providing information to our legal, accounting or financial advisors/representatives or insurers, or to our debt collectors for debt collection purposes or when we need to obtain their advice, or where we require their representation in relation to a legal dispute;
- where a person provides written consent to the disclosure of their personal information;
- where it is brought to our attention that specific personal information needs to be disclosed to protect the safety or vital interests of any person;
- to avoid prejudice to the maintenance of the law by any public sector agency, including the prevention, detection, investigation, prosecution, and punishment of offences;
- for the enforcement of a law imposing a pecuniary penalty;
- for the conduct of proceedings before any court or tribunal (being proceedings that have been commenced or are reasonably in contemplation); or
- where required by law.
- Customers who use the Mythradon CSP to disclose personal information about data subjects to third parties are expected to only do so where permissible under applicable law.
- We only disclose customer and data subject personal information that we collect to third parties as follows:
- Third party websites
- The Mythradon CSP may include links to third party websites. Our linking to those websites does not mean that we endorse or recommend them. We do not warrant or represent that any third-party website operator complies with applicable data protection laws. Customers and data subjects should consider the privacy policies of any relevant third-party website prior to sending personal information to them.
-
Interacting with us without disclosing personal information
- If a person does not provide us with their personal information, they can only have limited interaction with us. For example, a person can browse our public facing website without providing us with personal information such as the pages that generally describe the services that we make available. However, when an organisation enters into a contract with us, or a person registers an end user account on the Mythradon CSP, or a person submits an enquiry to us, we need to collect personal information for identification purposes, so that we can provide our services, and for the other purposes described in this Privacy Policy.
- Any person has the option of not identifying themselves when contacting us to enquire about our services.
- For security purposes, only end users who identify themselves accurately and truthfully when opening any account on any of the Mythradon CSP, may login to and access the functionality provided by the Mythradon CSP.
-
Offshore disclosure
- We may disclose personal information to our offshore service providers and personnel who assist us with providing our services and to assist us with the operation of our businesses generally. We will take reasonable steps to ensure that such overseas recipients do not breach the Australian Privacy Principles, GDPR or UK-GDPR in relation to personal information.
-
How to access and correct personal information held by us
- End users who have accounts on the Mythradon CSP can access personal information on their account at any time, by logging into their accounts or by contacting the customer who provided them with access to the Mythradon CSP. Once an account is deleted, we may still be required to retain the data in accordance with our contract with the customer or by law.
- Data subjects who wish to make enquiries about the personal information held by them on the Mythradon CSP should contact the customer who provided them with access to the Mythradon CSP, or who uploaded their personal information into the Mythradon CSP in the first instance.
- Our customers can access their personal information and make copies of such information via the Mythradon CSP portal. We will handle all requests for access to personal information in accordance with our statutory obligations. We may require payment of a reasonable fee of $250 (or any other reasonable fee determined by us) by any person who requires Mythradon to provide a copy of their personal information that we hold, except where such a fee would be contrary to applicable law. Our customers have the right to request correction or deletion of their personal data.
-
Incident Management for Privacy Incidents
- We take the privacy of our customers seriously and have implemented procedures for managing and responding to any incidents that may compromise the privacy of our users. If we become aware of a privacy incident, we will promptly assess the nature and scope of the incident and determine the appropriate course of action. This may include:
- Notifying affected users and any relevant regulatory authorities, as required by law;
- Taking steps to secure any compromised systems or data;
- Conducting a thorough investigation to determine the root cause of the incident;
- Implementing corrective actions to prevent similar incidents from occurring in the future.
- We take the privacy of our customers seriously and have implemented procedures for managing and responding to any incidents that may compromise the privacy of our users. If we become aware of a privacy incident, we will promptly assess the nature and scope of the incident and determine the appropriate course of action. This may include:
-
Our contact details
- Any person who wishes to contact us for any reason regarding our privacy practices or the personal information that we hold about them, or make a privacy complaint, may contact us using the following details: Mythradon Pty Ltd
- We will use our best endeavours to resolve any privacy complaint with the complainant within a reasonable time frame given the circumstances. This may include working with the complainant on a collaborative basis or otherwise resolving the complaint.
- If the complainant is not satisfied with the outcome of a complaint or they wish to make a complaint about a breach of the Australian Privacy Principles, they may refer the complaint to the Office of the Australian Information Commissioner who can be contacted using the following details:
Telephone: 1300 363 992
Email: enquiries@oaic.gov.au
Address: GPO Box 5218, Sydney NSW 2001