Prezzee Pty Ltd (ACN 602 963 422) (Prezzee or our or we) is in the business of providing an Online Platform enabling the purchase, redeeming, managing and storing of a variety of non-reloadable digital gift cards, codes and associated services as well as digital greeting cards (Services).
This Policy governs how Prezzee will process your Personal Information collected in connection with the Services.
This Policy also applies to Personal Information collected by Prezzee in connection with its website, social media accounts, applications, software and other technological means (Online Platforms), as well as in connection with any direct communication between you and Prezzee.
Prezzee uses third parties located both locally and overseas in addition to its own resources to provide these Services.
1.2. We are committed to protecting the privacy of everyone who uses our Online Platforms and/or our Services, for them to understand what Personal Information we collect and store, and why we do so, how we receive and/or obtain that information, the rights an individual has with respect to their Personal Information under our controllership, and with complying with the Australian Privacy Principles set out in the Privacy Act 1988 (Cth) (Privacy Act) and the General Data Protection Regulation (EU) 2016.679 (GDPR).
2. The Information We Collect
We may collect Personal Information that allows us to identify who an individual is and share Personal Information. The type of information we may collect includes:
2.1 Personal Information - We may collect personal details such as an individual’s name, location, date of birth and nationality allowing us to identify who the individual is;
2.2 Contact Information - We collect information such as an individual’s email address, telephone & fax number, Internet Protocol (IP) address, unique device identifiers, your mobile number, your device model and name, you operating system, your browser type third-party user names, residential, business and postal address and other information that allows us to contact the individual. We also collect other contact information (where you choose to import or upload that information) such as the names and phone numbers of your contacts from your address book or contact list, which we only use to help you quickly send digital greeting cards and digital gift cards to people you may know.
2.3 Financial Information - We collect financial information such as any bank or credit card details used to transact with us and other information that allows us to transact with the individual and/or provide them with our Services;
2.4 Statistical Information - We collect behavioural and statistical information about an individual and businesses in connection with the Services and/or the Online Platforms.
2.5 Geo-location information - We provide a geo-push notification feature to customers using a mobile app to send servicing messages and/or special offers from select retailers based on the close proximity of the customer to that retailer. The app requires access to the location services on the mobile device in order to utilize this feature and must be manually enabled by the customer firstly. Prezzee does not retain real time location data of the customer and does not use location services and data for any other purpose.
For users of the Prezzee Buzz service
The Prezzee Buzz service requires the processing of the following data elements, all of which we are required to collect in order for us to provide you with the service:
- Email address
- Gift card name, denomination, region
- Slack user IDs
- Slack workspace ID
- Slack token to call slack APIs
- Text content of recognition messages sent between employees
- Microsoft tenant ID
- Microsoft Teams ID
- Microsoft graph API access token to interact with Graph API
3. Why we collect Personal Information
3.1. We collect your personal information so that we can carry out the following actions:
a) to enable you to use our Online Platforms;
b) to provide our Services;
c) to communicate with you about our Services;
d) to communicate with you about marketing, offers and promotions which might interest you;
e) to provide you with information or advice;
f) to process payments by or to you in connection with our Services;
g) to create accounts, tax invoices or receipts;
h) to provide your personal information to third parties in order for them to supply the Services to you;
i) to consider and respond to complaints made by you.
j) to communicate with you about research opportunities relating to our products and services.
3.2. We may disclose additional purposes for collection of your personal information in collection statements at the point of collection.
4. How information is collected
Information is collected in association with your use of the Services, an enquiry about Prezzee or generally dealing with us directly or via our Online Platforms. If you are a digital greeting card or digital gift card recipient, from the person who purchased the digital gift card or sent you the digital greeting card.
5. When Personal Information is used and disclosed
5.2. Our use of Personal Information may include, but is not limited to:
a) Processing and completing transactions relating to the Online Platform,
b) If you purchase a digital gift card, we will disclose your Personal Information to the retailer/s that you (or the digital gift card recipient) selects;
c) Requesting feedback in regards to your use of the Online Platform, its products or other companies, and other news and promotions we think will be of interest to you;
d) Responding to your emails, questions, comments, requests and complaints so as to provide customer service;
e) To monitor and analyse Online Platform usage and trends;
f) To perform analytics and to increase the Online Platform’s functionality, market profile and user friendliness;
g) Investigating and preventing fraudulent transactions and other illegal activities;
h) To send notifications regarding important changes to the Online Platform;
i) Use for the purpose for which the information was collected; and
j) To send you confirmations, updates, security alerts, additional information about our products and services and support, and otherwise assist with your use of the Online Platform.
5.4. Subject to clauses 9 and 15, we will not sell or otherwise provide or share an individual’s Personal Information to unrelated third parties unless:
a) you consent to the sharing of your Personal Information; and/or
b) in connection with, or during negotiations of any merger, sale, financing or acquisition of Prezzee assets where this information may be disclosed or transferred as one of Prezzee’s business assets.
5.5. There are some circumstances in which we must disclose an individual’s information:
a) where we reasonably believe that an individual may be engaged in fraudulent, deceptive or unlawful activity that a governmental authority should be made aware of;
c) as required by any law (including the Privacy Act and GDPR); and/or
d) in order to sell our business (in that we may need to transfer Personal Information to a new owner).
6. Sensitive Information
6.1. Sensitive information (sometimes referred to as “special category data” is information about you that reveals your racial or ethnic origin, political opinions, religious or philosophical beliefs or affiliations, membership of a professional or trade association, membership of a trade union, details of health, disability, sexual orientation or criminal record.
6.2. It is our policy to only collect your sensitive information where it is reasonably necessary for our functions or activities and either you have consented, or we are required or authorised under law to do so.
7. Opting “IN” or “OUT”
7.2. An individual may opt to not have us collect their Personal Information (for example by unsubscribing to any marketing emails received). This may prevent us from offering them some or all of our services and may terminate their access to some or all of the services they access with or through us.
7.3. If an individual believes that they have received information from us that they opted out of receiving, they should contact us on the contact details set out in clause 16.
8.1. When you make a purchase, register to hold an account with Prezzee or receive a Gift Card, we may send you commercial electronic messages and tailored advertising if you consent to let us do so. We may send you these messages via various channels and media (including by email, SMS, phone or mobile push notification), where you have not opted out of receiving such electronic messages.
8.2. You can opt out of receiving commercial electronic messages, by:
i) Using the unsubscribe facility in any commercial electronic message; or
ii) For mobile device-based push notifications or in-app notifications, by adjusting your device settings.
8.2.1. Opting out of receiving commercial electronic messages from one specific channel (such as email) will not withdraw your consent to receive messages by other channels, such as text message.
8.2.2. Regardless of whether you opt-out of any or all commercial electronic messages, you will still receive information we are required by law to provide to you or service-based communications.
9. De-Identified Information
9.1. We may use your Personal Information in de-identified form (de-identification being a process by which a collection of data or information is altered to remove or obscure personal identifiers and personal information) to assist us in running our business. We may also provide, including by way of sale, de-identified information in aggregated form, to third parties.
9.2. When your Personal Information is included in de-identified, aggregated data, it is not possible to identify you or anything about you from that data.
We may use temporary (session) cookies or permanent cookies when you access our Online Platforms and/or Services. This allows us to recognise your browser and track the web pages you have visited. Some of these cookies also help improve your user experience on our websites, assist with navigation and your ability to provide feedback and assist with our promotional and marketing efforts. You can switch off cookies by adjusting the settings on your web browser.
11. The Safety and Security of Personal Information
11.1. We may hold your personal information in either electronic or hard copy form.
11.2. If you provide information to us electronically we retain this information in our computer systems and databases. If you provide information to us in hard copy (paper) this information is normally retained in our files and a copy is made to our electronic files.
11.3. We use industry standard security measures to safeguard and protect your information.
11.4. We may disclose your personal information to third parties and service providers located overseas in connection with any purpose, including to overseas cloud computing hosts. We take appropriate regulatory steps to ensure that the overseas recipients of your personal information do not breach the privacy obligations relating to your personal information.
11.5. We are not responsible for the privacy or security practices of any third party, including retailers and third parties that we are permitted to disclose an individual’s Personal Information to in accordance with this policy or any applicable laws. The collection and use of an individual’s information by such third parties may be subject to separate privacy and security policies.
11.6. If an individual suspects any misuse or loss of, or unauthorised access to, their Personal Information, they should let us know immediately.
11.7. Where we become aware of any breach to our security systems that breaches or is likely to result in a breach of your rights or freedoms with respect to your Personal Information, we will notify you and any supervisory authority as required.
12. How to access and/or update information
12.1 If you would like us to update or amend your personal information, please contact us on the contact details set out in clause 16 and we will make the requested amendments.
12.2. We may ask you to verify your identity to ensure that personal information we hold is not improperly accessed.
13. Connecting via Social Networks
13.1. You can log-in to the service by signing into social networks such as Facebook or an Open ID provider. Providers such as Facebook provide the option of posting and sharing information with others within your social network. If you stop using the network from which you signed in to use the Service, you agree that we will still retain the personally identifiable information from the social network that you provided us access to in accordance with this policy.
14. Deleting your Account or Personal Data
You have the right to delete your account or request the deletion of your personal data, subject to certain exceptions. Prezzee gives you the ability to permanently delete your account or personal data at any time.
14.1. What happens when I delete my account or personal data?
When your account and/or personal data is deleted, it is permanent, and the information cannot be restored or reactivated. This means that:
a) If you want to continue to use your Gift Cards, you must print them before you delete your account.
b) we may not be able to assist you if you require customer service, including if you lose your Gift Card or experience issues with your Gift Card.
14.2. How long will it take to delete my account or personal data?
When a request to delete your account or personal data has been received, we will delete (and direct our third party service providers to delete) your account and personal data unless we are required to retain that information for regulatory or compliance purposes. Some personal data may be retained by Prezzee or our third party service providers after an account deletion request to enable Prezzee (or our third party service providers) to:
a) Maintain a record that an account deletion request was made and actioned;
b) Comply with applicable laws and legal obligations, including anti-money laundering and counter-terrorism financing laws;
c) Comply with internal security, fraud and anti-money laundering policies;
d) Detect security incidents, or protect against malicious, deceptive, fraudulent, or illegal activities;
e) Cooperate with investigations or directions from law enforcement or regulators; or
f) Make other internal and lawful uses of that information that are compatible with the context in which you provided it;
g) Make other internal and lawful uses of that information that are compatible with the context in which you provided it.
While most account or personal data deletion requests will be actioned within ten days, it may take up to 35 days for all personal data to be deleted.
16. Direct Marketing
16.1. We and/or our carefully selected third party business providers may contact you with direct marketing communications and information about the Services or other products and services offered by us via telephone, email, SMS, or regular mail.
16.2. If you have indicated a preference for a method of communication, we will endeavour to use that method wherever practical to do so.
16.3. You may opt out of receiving marketing communications at any time by responding via the channel in which you received the marketing communication, or by contacting us on the contact details set out in clause 16. You can unsubscribe from emails by clicking the unsubscribe link on the footer of the email communication you have received.
17. Complaints and Disputes
17.1. If an individual needs to contact us or has a complaint about our handling of their Personal Information, they should address their communication in writing to the details below:
Level 3, 9 Castlereagh street
SYDNEY NSW 2000
17.2. If we have a dispute regarding an individual’s Personal Information, we both must first attempt to resolve the issue directly between us.
17.3. If we become aware of any unauthorised access to an individual’s Personal Information we will inform them and any supervisory authority as required, at the earliest practical opportunity once we have established what was accessed and how it was accessed.
18.1. If you are:
a) a resident of the UK or European Economic Area accessing our Online Platforms or receiving our Services in Australia; or
b) accessing our Online Platforms or receiving our Services from within the UK or European Economit Area,
then in addition to our obligations under the Privacy Act, Prezzee is required to comply with the UK/EU GDPR (GDPR) with respect to your Personal Information.
19. Additions to this Policy
Version Date: September 2023