This Privacy Policy, which is subject to the Privacy Act and APPs, regulates how we collect, use and disclose personal information.
Amendment. We may change, vary or modify all or part of this Privacy Policy at any time in our sole discretion. It is your responsibility to check this Privacy Policy periodically for changes. If we adopt a new Privacy Policy:
Purpose/Activity:
To process and deliver Products and Services to you including but not limited to – necessary –
Type of personal information:
Identity, Contact, Financial, Transaction, Client
Basis for use For :
Purpose/Activity:
To provide you with information about the Products and Services you requested and any other products and services you may be interested in
Type of personal information :
Identity, Contact, Client, Marketing and Communications
Basis for use :
Performance of a contract with you; Improvement of delivery of Products and Services to you
Purpose/Activity:
To personalise and customise your experiences with us
Type of personal information:
Identity, Contact, Client, Technical, Marketing and Communications, Profile
Basis for use:
Performance of Contract with you
Purpose/Activity :
To help us meet our warranty obligations
Type of personal information :
Identity, Contact, Client, Technical,
Basis for use :
Performance of a contract with you; Legal and regulatory requirement
Purpose/Activity :
To help us assess an application submitted by you or on your behalf in relation to your employment
Type of personal information :
Identity, Contact, Client, Technical, Profile, Financial
Basis for use
Purpose/Activity :
To help us review, manage and enhance our Products and Services and develop insights used in reports or other content developed by us
Type of personal information :
Identity, Contact, Client, Technical, Marketing and Communications, Profile
Basis for use :
Necessary for our legitimate interests (e.g. to study how our customers interact with and use our Products and Services, to develop our Products and Services, to grow our business, and to inform our marketing strategy)
Purpose/Activity :
To communicate with you, including by email, mobile and in-application notifications
Type of personal information :
Identity, Contact, Profile
Basis for use :
Performance of a contract with you; also necessary for our legitimate interests (e.g. to resolve any matters that require additional services or attention by us in relation to the Products or Services delivered to you)
Purpose/Activity :
To process payments and administer your account, including to send you account related reminders
Type of personal information :
Identity, Contact, Financial, Transaction, Client
Basis for use :
Legal and regulatory requirement, Necessary for our legitimate interests (e.g. to recover debts due to us)
Purpose/Activity :
To investigate any complaints about or made by you, or if we have reason to suspect you have breached any relevant terms
Type of personal information :
Identity, Contact, Financial, Transaction, Client
Basis for use :
Legal and regulatory requirement; also necessary for our legitimate interests (e.g. to ensure that we continue to deliver Products and Services in accordance with industry best-practice)
Purpose/Activity :
To do anything else as required or permitted by any law
Type of personal information :
Identity, Contact, Financial, Transaction, Client, Technical, Marketing and Communications, Profile
Basis for use:
Personal information we collect about you may include identification information such as your name, address, telephone number, date of birth, email address, mobile phone number, financial and payment information and such other information necessary or convenient for delivering our Products and Services. We also may collect additional information as part of our collection of Identity, Contact, Financial, Transaction, Technical, Marketing and Communications, Client and Profile information used for the Primary and Secondary Purposes.
Other information.
We may collect, and you consent to us collecting, information relating to you that is not personal information, such as data relating to your activity on our Platforms, including:
Sensitive information.
We will only collect, hold, use or disclose your sensitive information with your consent or if you volunteer your sensitive information to us. If we collect or hold your sensitive information in accordance with this clause, we may disclose such sensitive information to our Related Bodies Corporate. However neither us nor our Related Bodies Corporate may use or disclose your sensitive information to any Third Party except as required or permitted by law.
Your personal information may be collected:
Third party collection
If we collect any personal information about you from someone other than you, to the extent not already set out in this Privacy Policy, we will inform you of the fact that we will collect, or have collected, such information and the circumstances of that collection before, at or as soon as reasonably practicable after we collect such personal information.
Authority
If you provide us with the personal information of another individual, without limiting any other provision of this Privacy Policy, you acknowledge and agree that the other individual:
Unsolicited information
If we receive unsolicited personal information about you that we could not have collected in accordance with this Privacy Policy and the Privacy Act, we will, within a reasonable period, destroy or de-identify such information received.
Anonymity
If you would like to access any of our Products and Services on an anonymous or pseudonymous basis we will take reasonable steps to comply with your request, however:
Destruction
We will destroy or de-identify your personal information if:
and we are not required by law to retain your personal information.
Website and Google Analytics.
We have integrated Google Analytics into the Platforms (see http://www.google.com/analytics/ for details). We use Google Analytics Demographics and Interest Reports to obtain a more detailed understanding of our Platforms users and their potential needs. Data collected from such reports may be used to more accurately target marketing and advertising campaigns based on demographic information and more generally for the Primary Purposes and Secondary Purposes detailed in this Privacy Policy. We do not collect personal information about individuals by such methods; only aggregate data is collected and used for planning purposes.
Primary use
We will only use and disclose your personal information:
in accordance with this Privacy Policy and the Privacy Act.
Reasonable uses.
We will not use your personal information for any purpose for which you would not reasonably expect us to use your personal information.
Third parties.
We will not sell, trade, rent or licence your personal information to third parties.
Direct marketing
We will offer you a choice as to whether you want to receive direct marketing communications about services. If you choose not to receive these communications, we will not use your personal information for this purpose.
We will otherwise only use or disclose your personal information for the purposes of direct marketing if:
Opt-out.
You may opt out of receiving such communications by:
We may disclose personal information and you consent to us disclosing such personal information to:
Overseas disclosure.
We may in some circumstances send your personal information to overseas recipients to enable us provide our Products and Services to you. Overseas disclosure is made to the countries in which the products and services are booked, generally being within the South Pacific Region (including Fiji, Vanuatu, Cook Islands, Islands of Tahiti; French Polynesia, Samoa, Tonga, Niue and Micronesia).
Overseas recipients.
Overseas recipients that may handle or process your data include (but are not limited to) the server hosts of our email services, cloud storage services and the Platforms.
Reasonable protections.
If we send your personal information to overseas recipients, we will take reasonable measures to protect your personal information from misuse, interference, loss, unauthorised access or modification. However, you acknowledge and agree that if we disclose your personal information to overseas recipients, we are not obliged to take reasonable steps to ensure overseas recipients of your personal information comply with the Privacy Act and the APPs.
If we become aware that you are a citizen of, or are located within, the European Union at the time at which we collect personal information about you, or at the time at which we propose to transfer personal information about you overseas, we will take steps to ensure that we comply with Articles 45 to 49 of the European General Data Protection Regulation in relation to the transfer of your personal information overseas. However, you acknowledge that as we conduct our business from and predominantly within Australia, you are required to provide us with written notice of our need to comply with the General Data Protection Regulation in relation to your personal information if you wish for us to take steps that are not already set out in this Privacy Policy.
If you require access to your personal information, please contact us using our contact details set out at clause 11. You may be required to put your request in writing and provide proof of identity.
Exceptions
We are not obliged to allow access to your personal information if:
Response to access request.
If you make a request for access to personal information, we will:
Refusal of access.
If we refuse to give access to the personal information, we will give you a written notice that sets out at a minimum:
We request that you keep your personal information as current as possible. If you feel that information about you is not accurate or your details have or are about to change, you can contact us using our contact details set out at clause 11 and we will correct or update your personal information.
Response to correction request.
If you otherwise make a request for us to correct your personal information, we will:
Refusal to correct.
If we refuse a request to correct personal information, we will:
If you are a citizen of, or are located within, the European Union at the time at which we collect personal information about you, or at the time at which you make a relevant request, we will take steps to ensure that we comply with a request by you to restrict the use of your personal information pursuant to Article 18 of the European General Data Protection Regulation. You acknowledge that, depending on the nature of the restriction you request, we may be unable to provide you with some or all of our Products and Services (or any part of any Product or Service) if we comply with your request. In such circumstances, we will advise you of our inability to provide or continue to provide you with the relevant Products and Services, and if you confirm that you would like us to proceed with your request, we may terminate a relevant agreement or other document with you in relation to our Products and Services.
In relation to all personal information, we will take all reasonable steps to:
Obligation to notify.
Please contact us immediately if you become aware of or suspect any misuse or loss of your personal information.
We are required to comply with the Notifiable Data Breaches scheme under Part IIIC of the Privacy Act.
Investigation and assessment.
If we become aware that a Data Breach in respect of personal information held by us may have occurred, we will:
If we become aware that there has been an eligible data breach in respect of personal information held by us, and the personal information relates to you or you are at risk from the eligible data breach, we will ensure that either we, or a relevant APP entity that is the subject of the same eligible data breach:
If you have a complaint about how we collect, use, disclose, manage or protect your personal information, or consider that we have breached the Privacy Act or APPs, please contact us using our contact details below. We will respond to your complaint within 14 days of receiving the complaint.
Response and resolution.
Once the complaint has been received, we may resolve the matter in a number of ways:
Notice of decision.
After investigating the complaint, we will give you a written notice about our decision.
You are free to lodge a complaint directly with the OAIC online, by mail, fax or email. For more information please visit the OAIC website at www.oaic.gov.au.
Please forward all correspondence in respect of this Privacy Policy to:
61 Cabarita Road Concord NSW 2137 Australia P: 1300991751 E: admin @ hideawayholidays.com.au
Personal pronouns:
Except where the context otherwise provides or requires:
APPs
means any of the Australian Privacy Principles set out in Schedule 1 of the Privacy Act.
Client information
includes information about how you use the Products and Services or our website, as well as personal information which can include Identity, Contact, Financial, Transaction and Profile information of you and/or your family members, beneficiaries, employees or employers, or other third persons about whom we need to collect personal informationby law, or under the terms of a contract we have with you.
Contact information
includes billing address, postal address, email address and telephone numbers (these details may relate to your work or to you personally, depending on the nature of our relationship with you or the company that you work for).
Data Breach
means unauthorised access, modification, use, disclosure, loss, or other misuse of personal information held by us.
Financial information
includes bank account and other payment method details.
Identity information
includes first name, maiden name, last name, username or similar identifier, marital status, title, date of birth, gender, your job function, your employer or department.
Marketing and Communications information
includes your preferences in receiving marketing from us and your communication preferences. This may include information about events to which you or your colleagues are invited, and your personal information and preferences to the extent that this information is relevant to organising and managing those events (for example, your dietary requirements).
Platforms
means all or any of the relevant platforms, electronic interfaces (including the Products) and websites that are owned, provided and/or operated from time to time by us (including but not limited to the Website), regardless of how those websites are accessed by users (including via the internet, mobile phone, mobile applications or any other device or other means).
Primary and Secondary Purposes
means the primary and secondary purposes stated at clause 2.1.
Privacy Act
means the Privacy Act 1988 (Cth) as amended from time to time.
Privacy Policy
means this privacy policy as amended from time to time.
Profile information
includes your username and password, your interests, preferences, feedback, survey responses and all other information you provide through your use of the Products or Services, or otherwise through your contact or correspondence with us.
Products
means any products offered by us from time to time, including a collection of products and services packaged by us where components may be provided by various suppliers to an aggregate offering (e.g. all inclusive products, luxury products, adults only, budget products).
Services
means the construction of holiday packages for travel over land, air and sea including elements such as airfares, accommodation, transfers and tours.
Technical information
includes (as relevant):
Transaction information
includes details about payments to and from you and other associated information.
Website
means http://www.hideawayholidays.com.au and http://www.hideawayholidays.net.au and all relevant sub-domains.
Get in Contact
Request a callGet exclusive access to discounts and deals - Enter your email address, subscribe to our mailing list and earn a $50 voucher to use against your first booking!
Please select type for search