Zipline Cloud Pty Ltd trading as Pendula Solutions ACN 613 136 824 (referred to in this document as we, us or our) are committed to protecting the personal information we collect from you.
Subject to exceptions, the Privacy Act 1988 (Cth) (Privacy Act) and the Australian Privacy Principles (APPs) govern the handling of personal information in Australia. If you are located in or are a citizen of the European Union, you may have additional rights under the European Union General Data Protection Regulation (GDPR). This document sets out how we will manage your personal information.
We provide intelligent, omni-channel communications solutions that are optimised to integrate with various software platforms. As such, we engage with personal information in two capacities. First, as a primary collector (or ‘data controller’ in privacy-speak), for instance if you are our customer or if you visit our website. Second, as a service provider to other organisations who are the primary collector (or ‘data processor’ in privacy-speak).
Our relationship with you is very different in those two circumstances. In the first, we have collected information from you to maintain your relationship with us. But in the second, we are given limited access (usually via an Application Programming Interface, or ‘API’) to information that sits in other platforms (like Salesforce and Zuora) so that our customers can use our communications solutions to engage with you. We treat those situations differently.
In this privacy policy, when we talk about the first relationship, we call you our ‘customer’, and when we talk about the second relationship, we call you our ‘customer’s customer’.
If you are our customer, we may collect and hold personal information about you, that is, information that can identify you, and is relevant to providing you with the services you are seeking. In particular, we may collect:
If you are our customer’s customer, we may access or receive certain of your personal information as necessary to provide our communications services. For instance, we may be given your mobile telephone number in order to be able to send you an SMS and the contents of that SMS (e.g. appointment bookings).
We also receive access to the information you include in your communications with our customers (for instance, if you respond to an SMS sent by our platform on behalf of our customer).
The personal information that we collect and hold about you depends on your interaction with us.
If you are our customer, we will generally collect, use and hold your personal information if it is reasonably necessary for or directly related to the performance of our functions and activities and for the purposes of:
If you are our customer’s customer, we process your information for the purposes of providing our messaging services to our customer. Typically, this means we use your information for the purpose of sending you messages, analysing the contents of your messages to determine the most appropriate response, and delivering your messages to our customer.
We have set out below, in a table format, a description of all the ways we plan to use your personal information, and which of the legal bases we rely on to do so. We have also identified what our legitimate interests are where appropriate.
Purpose/Activity
Type of data
Lawful basis for processing including basis of legitimate interest
To register you as a new customer
(a) Identity
(b) Contact
Performance of a contract with you
To process and deliver your order including:
(a) Manage payments, fees and charges
(b) Collect and recover money owed to us
(a) Identity
(b) Contact
(c) Financial
(d) Transaction
(e) Marketing and Communications
(a) Performance of a contract with you
(b) Necessary for our legitimate interests (to recover debts due to us)
To manage our relationship with you which will include:
(a) Notifying you about changes to our terms, our offerings or privacy policy
(b) Asking you to leave a review or take a survey
(a) Identity
(b) Contact
(c) Profile
(d) Marketing and Communications
(a) Performance of a contract with you
(b) Necessary to comply with a legal obligation
(c) Necessary for our legitimate interests (to keep our records updated and to study how customers use our products/services)
To enable you to complete a survey
(a) Identity
(b) Contact
(c) Profile
(d) Usage
(e) Marketing and Communications
(a) Performance of a contract with you
(b) Necessary for our legitimate interests (to study how customers use our products/services, to develop them and grow our business)
To administer and protect our business, service offerings and this website (including troubleshooting, data analysis, testing, system maintenance, support, reporting and hosting of data)
(a) Identity
(b) Contact
(c) Technical
(a) Necessary for our legitimate interests (for running our business, provision of administration and IT services, network security, to prevent fraud and in the context of a business reorganisation or group restructuring exercise)
(b) Necessary to comply with a legal obligation
To use data analytics to improve our website, products/services, marketing, customer relationships and experiences
(a) Technical
(b) Usage
Necessary for our legitimate interests (to define types of customers for our products and services, to keep our website updated and relevant, to develop our business and to inform our marketing strategy)
To make suggestions and recommendations to you about goods or services that may be of interest to you
(a) Identity
(b) Contact
(c) Technical
(d) Usage
(e) Profile
(f) Marketing and Communications
Necessary for our legitimate interests (to develop our products/services and grow our business)
If you are our customer, personal information will generally be collected directly from you through the use of any of our standard forms, over the internet, via email, through a telephone conversation with you, or in person. There may, however, be some instances where personal information about you will be collected indirectly because it is unreasonable or impractical to collect personal information directly from you. We will usually notify you about these instances in advance, or where that is not possible, as soon as reasonably practicable after the information has been collected.
If you are our customer’s customer, we receive your personal information through an API that connects to our customer’s customer relationship management system, or similar platform that holds your information. We do not notify you of this collection directly, because it is not practicable for us to do so. In the circumstances of our relationship with you, we rely on our customer to notify you that they may use services like ours and that personal information may be disclosed to us. We take reasonable steps to ensure they are aware of and comply with this obligation.
If the personal information you provide to us is incomplete or inaccurate, we may be unable to provide you, or someone else you know, with the services you, or they, are seeking.
If you are our customer’s customer, you separately control your privacy settings with our customers, through your direct relationship with them. If you do not provide your information to them, they may not be able to provide their services to you.
If you access our website, we may collect additional personal information about you in the form of your IP address and domain name.
Our website uses cookies. The main purpose of cookies is to identify users and to prepare customised web pages for them. Cookies do not identify you personally, but they may link back to a database record about you. We use cookies to monitor usage of our website and to create a personal record of when you visit our website and what pages you view so that we may serve you more effectively.
Our website may contain links to other websites. We are not responsible for the privacy practices of linked websites and linked websites are not subject to our privacy policies and procedures.
We will only use your personal information when the law allows us to. If you are our customer, generally we only use or disclose personal information about you for the purposes for which it was collected (as set out above). We may disclose personal information about you to:
and these service providers may not be required to comply with our privacy policy;
If you are our customer’s customer, we only use your personal information as necessary to perform our services for our customer. We do not separately process your personal information for our own purposes unless you are separately our customer.
We may run anonymised analytics on data that is transmitted through our services, but this does not identify you and is not personal information.
We are not likely to disclose your personal information overseas, except as permitted by the Privacy Act, unless we otherwise advise you in writing.
We strive to provide you with choices regarding certain personal information uses, particularly around marketing and advertising.
We may use your personal information to form a view on what we think you may want or need, or what may be of interest to you. This is how we decide which products, services and offers may be relevant for you (we call this marketing).
You may receive marketing communications from us if you have requested information from us or purchased services from us and you have not opted out of receiving that marketing.
We will get your express opt-in consent before we share your personal information with any third party for marketing purposes.
You can ask us or third parties to stop sending you marketing messages at any time by following the opt-out links on any marketing message sent to you or by contacting us at any time.
Where you opt out of receiving these marketing messages, this will not apply to personal information provided to us as a result of a service purchase, warranty registration, product/service experience or other transactions.
We are not likely to disclose your personal information overseas, except as permitted by the Privacy Act or, if applicable the GDPR, unless we otherwise advise you in writing. If we do transfer your personal information overseas, we ensure a similar degree of protection is afforded to it as set out in this privacy policy or otherwise required by law.
We store your personal information in different ways, including in paper and in electronic form. The security of your personal information is important to us. We take all reasonable measures to ensure that your personal information is stored safely to protect it from interference, misuse, loss, unauthorised access, modification or disclosure, including electronic and physical security measures. In addition, we limit access to your personal information to those employees, agents, contractors and other third parties who have a business need to know. They will only process your personal information on our instructions and they are subject to a duty of confidentiality.
We have put in place procedures to deal with any suspected personal information breach and will notify you and any applicable regulator of a breach where we are legally required to do so.
We will only retain your personal information for as long as reasonably necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, regulatory, tax, accounting or reporting requirements. We may retain your personal information for a longer period in the event of a complaint or if we reasonably believe there is a prospect of litigation in respect to our relationship with you.
To determine the appropriate retention period for personal information, we consider the amount, nature and sensitivity of the personal information, the potential risk of harm from unauthorised use or disclosure of your personal information, the purposes for which we process your personal information and whether we can achieve those purposes through other means, and the applicable legal, regulatory, tax, accounting or other requirements.
Where we anonymise your personal information (so that it can no longer be associated with you) for research or statistical purposes, we may use this information indefinitely without further notice to you.
You may access the personal information we hold about you, upon making a written request. We will respond to your request within a reasonable period. We may charge you a reasonable fee for processing your request (but not for making the request for access).
We may decline a request for access to personal information in circumstances prescribed by the Privacy Act or, if applicable the GDPR, and if we do, we will give you a written notice that sets out the reasons for the refusal (unless it would be unreasonable to provide those reasons).
If, upon receiving access to your personal information or at any other time, you believe the personal information we hold about you is inaccurate, incomplete or out of date, please notify us immediately. We will take reasonable steps to correct the information so that it is accurate, complete and up to date.
If we refuse to correct your personal information, we will give you a written notice that sets out our reasons for our refusal (unless it would be unreasonable to provide those reasons), including details of the mechanisms available to you to make a complaint.
If your personal information is governed by the GDPR, you may have additional rights as set out below:
d.
Request the transfer of your personal information to you or to a third party. We will provide to you, or a third party you have chosen, your personal information in a structured, commonly used, machine-readable format. Note that this right only applies to automated information which you initially provided consent for us to use or where we used the information to perform a contract with you.
e.
Withdraw consent at any time where we are relying on consent to process your personal information. However, this will not affect the lawfulness of any processing carried out before you withdraw your consent. If you withdraw your consent, we may not be able to provide certain products or services to you. We will advise you if this is the case at the time you withdraw your consent.
If you wish to make a complaint about a breach of the Privacy Act, the APPs, the GDPR or a privacy code that applies to us, please contact us using the details below and we will take reasonable steps to investigate the complaint and respond to you.
If you have any queries or concerns about our privacy policy or the way we handle your personal information, please contact our privacy officer at:
Street address: Level 1, 355 Crown Street Surry Hills NSW 2010
Email address: privacy@pendula.com
Website: www.pendula.com
For more information about privacy in general, you can visit the Office of the Information Commissioner’s website at www.oaic.gov.au.
If you wish to make a complaint about the collection, use or disclosure of your personal information, please contact our privacy officer, and we will work with you to resolve the issue.
If after this process you are not satisfied with our response, you can submit a complaint to the Office of the Information Commissioner. To lodge a complaint, visit the ‘Complaints’ section of the Information Commissioner’s website, located at www.oaic.gov.au/privacy/privacy-complaints to obtain the relevant complaint forms, or contact the Information Commissioner’s office.
We are not required to appoint a Data Protection Officer under the GDPR but, if you are located in or are a citizen of the European Union you may have certain additional rights to make a complaint to the privacy regulator in your home state.