Our Privacy Policy
Lactalis Australia Privacy Policy April 2024
1. About This Policy
Lactalis Australia Pty Ltd (ABN 56 072 928 879) and its Associated Entities (as defined under the Corporations Act 2001 (Cth)) ('we', 'us', 'our') (Lactalis Australia) understands the importance of, and is committed to, protecting your personal information. We are bound by the Privacy Act 1988 (Cth) (Privacy Act) and must protect your personal information according to the Privacy Act, the relevant privacy laws in each state and territory and other applicable laws such as Spam Act 2007 (Cth) (Privacy Laws).
Please refer to our Credit Reporting Policy on our website for information on how we manage our credit information.
Purpose
The purpose of this Policy is to explain how we can collect, use, hold and disclose your personal information by:
Giving you a better and more complete understanding of the sort of personal information that Lactalis Australia holds, and the way we handle that information; and
Clearly communicating to you how we deal with personal information.
2. GDPR Compliance – for our Customers and Suppliers in the European UnionCo
From 25 May 2018, the General Data Protection Regulation (GDPR) regulates the processing of personal information under European Union (EU) law. The GDPR aims to protect the information relating to individuals in the EU and harmonise data protection laws across EU Member States. Our collection, use, disclosure and processing of your personal information is regulated by the GDPR if we offer or receive products or services to/ from you whilst you are located in the EU.
3. What is personal information
Personal information includes any information or opinion, about an identified individual, or individuals who can be reasonably identified from that information. The information or opinion will still be personal information whether it is true or not and regardless of whether we have kept a record of it.
Some examples of personal information may include your:
Name;
Mailing or residential address details;
Contact details such as telephone numbers, email address, social media platform user name;
Government issued identifiers such as tax file numbers, Medicare number, driver license number;
Bank account and credit card details;
Credit history and credit worthiness;
Employment history;
Photographs, video or audio recording; and
Sensitive information such as information relating to your health, biometric data, criminal history, racial or ethnic origin.
4. Information we collect about you
We only collect information about you that we reasonably need for our business functions and activities. Our functions and activities include:
Manufacturing and supplying dairy products and associated services;
Activities in support of those functions including administration, management, marketing, online and mobile marketing, IT, legal, security, customer support (including the Consumer Information Centre), finance (including credit control), e-commerce transactions, property management and human resources; and
Activities we plan for the future including new ways of communicating, new products and services, new business models and new businesses.
Generally we may collect the following personal information about you:
Your name;
Your contact details including residential or business address, telephone number and email address;
Bank account details and credit card details;
Your employment history (where relevant for recruitment purposes); and
Sensitive health information, including your vaccination status (if Lactalis Australia is required or authorised to collect by law),and where you or your business submit a credit application:
Certain other types of personal information (including information contained in a consumer or commercial credit report about you) including:
Information about your credit history, including information about your past experiences with us and other credit providers; he kinds of credit products that you have sought and obtained in the past;
Information about your consumer credit payments overdue for at least 60 days and for which collection action has started;
Advice that payments that were previously notified to a credit reporting body as overdue are no longer overdue;
Publicly available information about your credit worthiness; and/or
An opinion of a credit provider that you have committed a serious credit infringement in relation to credit provided by that credit provider.
We may also derive information about you from consumer or commercial credit reports about you, including:
Information which assists us to assess your suitability for credit; and/or
The likelihood of you being able to meet your commitments to us.
We may combine the personal information described above with other information about you, for example:
If your business or employer supplies us with products or services, or if your business or employer distributes or sells our products and services, we collect information about your trading with us (for example the products you buy or sell and credit card records), your trading history and account history;
If you apply for a position with us, we collect information to help us decide your application, which may include your date of birth, tax-file number, work history and similar details;
If you request information from us (for example about a competition) or register a complaint, we collect information about your request or complaint; and/or
If you buy products and services, we may collect information about your purchasing preferences and history. We record this information (personal information) in our database whilst we deal with you. We will remove this information from out database when we have no further need to keep a record of it, except if we are required to keep it by law (for example, for tax or for superannuation purposes).
5. How we collect information about you
How do we collect personal information?
Usually we collect personal information directly from you, whether in person, on the phone or electronically. For example, we may record your contact details when you call our call centre, when you fill out an application form (including a credit application), when you enter one of our competitions or promotions, or when you ask us to do something for you.
We may collect closed-circuit television (CCTV) surveillance footage of you, as we have CCTV surveillance systems operating in various locations within our sites and offices.
From time to time we may collect personal information about you from third parties or organisations. This may arise where you have given your consent to do so or where we notify you that we are collecting information in the application. For example:
We may engage a consultant or agent to collect information for us about people who may be interested in buying or selling our products and services, or about people from whom we may be interested in buying or selling products and services;
If you are an employee of one of our business partners (e.g. a supplier or distributor), we may be given your name and contact details by your employer;
If you enter a competition or promotion organised by us, we may be given your name and contact details by the agent or promoter organising the event;
If you make a credit application and also where you carry on business with us on credit terms, we may obtain information about you from credit reporting bodies and other credit providers;
Our service providers may provide us with your personal information from websites, social media sites, mobile, and other technology based sources; and/or
We also may collect information about you from publicly available sources, such as public registers.
We use lawful and fair means to collect your information. We will collect personal information about you from another person or from a publicly available source only if it is unreasonable or impracticable to collect it directly from you, and we will take reasonable steps to inform you that we have collected your personal information. Those reasonable steps may include informing you through this statement. Unsolicited information
If we receive personal information about you that we have not requested, and if we determine that we could not have lawfully collected that information under Privacy Laws if we had requested it, we will destroy or de-identify the information, if it is lawful and reasonable to do so.
6. Do I have to provide you with my personal information?
You can choose to deal with us anonymously (without giving us your name and contact details) or by using a pseudonym (a name that does not include your real name, for example an email address or a user name that you use in an online forum (nickname)).
If you choose to deal with us anonymously or using a nickname, we can give you general information about our products and services, you may be able to buy certain products and services from us, and you may be able to participate in any online forum we provide, but there are some things we may not be able to do, for example:
If you do not give us your personal information we cannot give you information about or open or close an account (if you are a supplier or distributor), may not be able to deal with a complaint you may have or deliver a product to you at an address. You cannot enter into one of our competitions or promotions anonymously or using a nickname; and
If you do not give us your personal information we cannot assess your suitability for a role with Lactalis Australia.
You can deal with us using a nickname together with your real name and contact details. If you choose to deal with us in this way, we may collect your personal information together with your nickname. When you identify yourself to us using your nickname only, we can deal with you only as set out above. We may ask you to provide proof of your identity if you use a nickname.
7. Why we collect personal information about you (purpose of collection)
The main reasons we collect, use, hold and disclose personal information is to help run our business. This includes:
Administration of our business dealings with you;
Assessment and processing of credit applications made by you or your business, establish, provide and administer your credit account, processing payment, and collect overdue payments development of insights and analysis to improve in the delivery of products and services;
Administration of any competitions or marketing activities that we undertake;
For compliance with legislation and regulations (including public health orders) such as Safe Food Queensland;
For the purpose of considering you for a potential employment opportunity with Lactalis Australia;
Investigating any unlawful activities and security breaches, controlling access to our sites and offices and detecting and responding to emergencies; and
Monitoring employee performance and conduct and ensuring compliance with company policies and procedures.
We also collect your personal information for certain secondary purposes that are related to the primary purposes outlined above (or directly related where sensitive information is concerned). Secondary purposes may include so that we can run our business efficiently, for example, our advisors can provide us with customer research, or so that we can use technology to automate our business and to understand how our business is performing, to allow us to operate efficiently and to lower costs by outsourcing services (such as collecting or paying money). Other secondary purposes may include so that we can sell or transfer our business or merge with another business.
8. Disclosure
Who do we disclose your personal information to?
We may share your personal information with our subsidiary companies. We do not use or disclose your personal information for a purpose other than:
A purpose set out in this privacy policy (primary or secondary purpose above);
A purpose you would reasonably expect;
A purpose required or permitted by law; and/or
A purpose otherwise disclosed to you to which you have consented.
Depending on the circumstances, we may disclose your personal information to other people or organisations outside of Lactalis Australia including:
Service providers, including management, IT, security, legal, accounting, research, credit, marketing, insurers, financial institutions, debt collection agencies and others;
Other credit providers, to assist them with assessing a credit application they have with you, or to ensure that the information about you that we handle is correct;
Credit reporting bodies in order to obtain credit reports and also for the purpose of dealing with defaults on your credit account and serious credit infringements;
Our related companies, and companies that we may merge with or who may acquire ownership of us;
Government, regulatory and law enforcement authorities, where we are required to or permitted to by law; and/or
Your employer, if you are an employee of a supplier or distributor.
We take reasonable steps to ensure that these organisations are bound by confidentiality and privacy obligations with respect to the protection of your personal information. Disclosure overseas
Lactalis Australia is part of the Lactalis Group, a French family owned business, and consequently we may disclose your personal information to our parent companies in France or Italy.
We also may disclose your personal information to an overseas service provider, for example a cloud data centre or a customer information call centre.
If it is not practicable or reasonable for us to gain your consent to disclose your personal information to an overseas service provider, we will take reasonable steps to notify you of the specific countries where we disclose your personal information.
When we do disclose and / or store personal information overseas, we will take reasonable steps to ensure that the overseas services provider protects that information by complying with security measures and is bound by privacy and confidentiality obligations to us.
9. Access to your personal information
You may request access to the personal information that we hold about you by using the contact details provided below. We will deal with your request for such access within a reasonable time. If we refuse access, we will provide you with a written notice which sets out the reasons for the refusal and the relevant provisions of the Privacy Act that we rely on to refuse access.
We may recover reasonable costs in relation to a request for access to personal information.
Accuracy and correction
We take reasonable steps to make sure that the personal information we collect is accurate, up-to-date and complete. We take reasonable steps to make sure that the personal information we use or disclose is accurate, up-to-date, complete and relevant. Where we believe that the personal information we hold is inaccurate, out-of-date, incomplete, irrelevant or misleading, we will take reasonable steps to correct that information.
You may request that we correct your personal information that we hold by contacting us by using the contact details provided above. We will take reasonable steps to correct the information to ensure that it is accurate, up-to-date, complete, relevant and not misleading.
We will deal with your request to correct your personal information within a reasonable time. If we do not agree with the corrections you have requested, we are not obliged to alter your personal information accordingly. However, where we refuse to correct any personal information as requested by you, we will give you a written notice which sets out the reasons for our refusal.
10. Security
We hold your personal information in paper-based and electronic files. We will take reasonable steps to ensure that your personal information which is kept in our files is protected from:
Misuse, interference and loss; and
Unauthorised access, modification or disclosure.
This means that, in respect of our paper-based files, we maintain various security systems on our premises, and in respect of electronic files, we (or our service providers) maintain secure electronic network systems. When we no longer require your personal information (including when we are no longer required by law to keep records relating to you), we ensure that it is destroyed or de-identified.
Website
This section explains how we handle personal information collected from our websites (including social media site and mobile site if relevant). If you have any questions or concerns about transmitting your personal information via the internet, you may contact us using the contact details provided above, as there are other ways for you to provide us with your personal information.
Visiting our website
If you access an unsecured part of our websites, that is, a public page that does not require you to log on, we (or our service providers) will collect information about your visit, such as:
The time and date of the visit;
Any information or documentation that you download;
Your browser type; and
Your server address
Cookies
A "cookie" is a small text file which is placed on your internet browser and which we access each time you visit our website. When you visit the secured pages of our website (ie pages that you have to provide login details to access) we use cookies for security and personalisation purposes. When you visit the unsecured pages of our website (ie public pages that you can access without providing login details) we use cookies to obtain information about how our website is being used.
You may change the settings on your browser to reject cookies, however doing so will prevent you from accessing the secured pages of our website.
When we receive emails, we will retain the content of the email and our response to you where we consider it necessary to do so. Your email address will only be used or disclosed for the purpose for which is was provided. It will not be added to any mailing lists or used for any other purpose without your consent.
Security
We make reasonable efforts to ensure that appropriate security measures are used on our website to protect your personal information. Any data containing personal information which we transmit via the internet is encrypted. However, we cannot guarantee that any information transmitted via the internet by us, or yourself, is entirely secure. You use our website at your own risk.
Links on our website
Our website may contain links to third party websites. We advise that the terms of this privacy policy do not apply to external websites. If you wish to find out how any third parties handle your personal information, you will need to obtain a copy of their privacy policy.
11. Marketing
We may use your personal information, including your contact details, to provide you with information about products and services, including those of third parties, which we consider may be of interest to you. But we will not do so if you tell us not to. When we market products and services to you, we will comply with applicable Privacy Laws to obtain your consent if required.
We may also provide your details to other organisations for specific marketing purposes. You may opt out at any time if you no longer wish to receive marketing information. In order to do so, you will need to request that we no longer send marketing materials to you or disclose your information to other organisations for marketing purposes. You can make this request by using the contact details provided above, or by "unsubscribing" from email marketing messages.
12. Notifiable Data Breaches
From February 2018, the Privacy Act includes a Notifiable Data Breaches (NDB) scheme which requires us to notify you and the Office of the Australian Information Commissioner (OAIC) of certain data breaches and recommend steps you can take to limit the impacts of a breach.
The NDB scheme requires us to notify about a data breach that is likely to result in serious harm to affected individuals. There are exceptions where notification is not required. For example where we have taken appropriate remedial action that removes the risk of any serious harm to individuals.
If we believe that there has been a data breach that impacts your personal information and creates a likely or serious harm, we will notify you and the OAIC as soon as practicable and keep you informed about the nature of the breach, the steps that we are taking and what you can do to reduce the impacts on your privacy. If you believe that any of the personal information we hold has been impacted by a data breach, you can contact us, using the details below.
13. Resolving concerns and complaints
If you have any questions, concerns or complaints about this privacy policy, or about how your personal information is being handled by us or a contracted service provider please contact our Privacy Officer using the contact details provided below:
Privacy Officer: 1800 676 961
Email: Legal@au.lactalis.com
Once a complaint has been lodged, the Privacy Officer will acknowledge receipt of your complaint, and we will let you know if we need any further information from you to resolve your complaint.
We aim to resolve complaints as quickly as possible. We strive to resolve complaints within 10 business days but some complaints may take longer to resolve. If your complaint is taking longer, we will let you know what is happening and when you can expect a response.
Under the Privacy Act you may also lodge a complaint with the Office of the Australian Information Commissioner by telephone: 1300 363 992 or email: enquiries@oaic.gov.au.
Please note that the OAIC requires any complaint must first be made by respondent organisation. The law also allows 30 days for the respondent organisation to deal with a complaint before a person may make a complaint to the OAIC.
14. Changes to the Privacy Policy
We may change the way we handle personal information from time to time. If we do so, we will update this Privacy Policy. An up to date version of this policy is available at any time at lactalis.com.au.