Legal
Privacy Policy
impressaatelier.com/legal/privacy
Impressa Atelier Pty Ltd (ACN 695 833 704 / ABN 32 695 833 704) (we, us or our) is committed to protecting your privacy. We comply with the Privacy Act 1988 (Cth) (Privacy Act) and the Australian Privacy Principles (APPs), and, to the extent applicable to our processing of Personal Data, the EU General Data Protection Regulation (GDPR) and the United Kingdom General Data Protection Regulation (UK GDPR).
This Privacy Policy explains how we collect, hold, use, disclose, and otherwise Process Personal Data in connection with: (a) our marketing and information website at impressaatelier.com; (b) our business-to-business software-as-a-service platform operated under the Impressa Atelier brand (the Platform); and (c) Guest interactions with the Platform through the QR Code Interface, in which we act on behalf of the Subscriber.
This Privacy Policy is intended primarily for Subscribers, Subscriber Personnel, prospective Subscribers, and website visitors. Where Guests interact with the QR Code Interface, the relevant Subscriber is the Controller of the Guest’s Personal Data and the Subscriber’s own privacy notice will apply. This Privacy Policy explains our role in that scenario as a Processor acting on the Subscriber’s instructions.
OPERATIVE PROVISIONS
1. ABOUT THIS PRIVACY POLICY
- 1.1This Privacy Policy applies to all Personal Data we collect about you and that we otherwise Process in connection with the Website, the Platform, and the QR Code Interface.
- 1.2This Privacy Policy should be read together with our Website Terms of Use, Website Disclaimer, Cookie Policy, and (where you are a Subscriber or Subscriber Personnel) the SaaS Terms, including any Data Processing Addendum.
- 1.3We may update this Privacy Policy from time to time. Any changes will be posted on the Website with an updated effective date. Where the changes are material, we will use reasonable endeavours to notify you (and, where you are a Subscriber, the Subscriber) before the changes take effect.
2. DEFINITIONS AND INTERPRETATION
Definitions
In this Privacy Policy, the following definitions apply:
| Term | Meaning |
|---|---|
| APPs | means the Australian Privacy Principles set out in Schedule 1 to the Privacy Act. |
| Controller | has the meaning given to "controller" in the GDPR or "data controller" in the UK GDPR (being the natural or legal person which, alone or jointly with others, determines the purposes and means of processing of Personal Data). |
| Data Protection Laws | means, collectively, the Privacy Act, the GDPR, the UK GDPR, and any other privacy or data protection law that applies to our processing of Personal Data from time to time. |
| EEA | means the European Economic Area. |
| GDPR | means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (the General Data Protection Regulation). |
| Guest | means an individual who is a guest of a Subscriber and who interacts with the Platform through the QR Code Interface in order to request dry cleaning or laundry services from the Subscriber. |
| Guest Personal Data | means Personal Data of Guests that we Process on behalf of a Subscriber as a Processor under clause 8. |
| Personal Data | means Personal Information and includes "personal data" as defined in the GDPR and the UK GDPR. |
| Personal Information | has the meaning given in section 6 of the Privacy Act. |
| Platform | means the B2B software-as-a-service platform operated by us under the Impressa Atelier brand, together with any Subscriber Portal, integrations, APIs, and the QR Code Interface. |
| Privacy Act | means the Privacy Act 1988 (Cth) and any regulations or subordinate instruments made under it, as amended from time to time. |
| Privacy Policy | means this Privacy Policy, as amended from time to time. |
| Processor | has the meaning given to "processor" in the GDPR or "data processor" in the UK GDPR. |
| Process | means any operation or set of operations performed on Personal Data, whether or not by automated means, and includes "processing" as defined in the GDPR. |
| QR Code Interface | means the QR code-based web interface through which a Guest interacts with the Platform in order to request services from a Subscriber (no application download is required). |
| SaaS Terms | means the B2B SaaS Terms of Service (including any Data Processing Addendum forming part of it) entered into between us and a Subscriber that govern access to and use of the Platform. |
| Subscriber | means a hotel, accommodation provider, or other commercial entity that has entered into the SaaS Terms with us. |
| Subscriber Personnel | means the directors, officers, employees, contractors, and other authorised personnel of a Subscriber whose Personal Data we Process as a Controller in connection with the Subscriber relationship. |
| UK | means the United Kingdom. |
| UK GDPR | means the United Kingdom General Data Protection Regulation, being Regulation (EU) 2016/679 as it forms part of the law of England and Wales, Scotland, and Northern Ireland by virtue of section 3 of the European Union (Withdrawal) Act 2018. |
| Website | means the website located at impressaatelier.com, including all pages, subdomains, and content accessible through that address. |
Interpretation
In this Privacy Policy, unless the context otherwise requires:
- 2.1headings are for convenience only and do not affect interpretation;
- 2.2the singular includes the plural and vice versa;
- 2.3a reference to a person includes a corporation, partnership, joint venture, association, government body, or other entity;
- 2.4a reference to a statute, regulation, or other law includes all amendments, consolidations, and replacements;
- 2.5a reference to writing includes email; and
- 2.6where a word or expression is given a particular meaning, other parts of speech and grammatical forms of that word or expression have a corresponding meaning.
3. OUR ROLE UNDER DATA PROTECTION LAW
- 3.1We act in different roles under the Data Protection Laws depending on the Personal Data concerned.
-
3.2We are a Controller in respect of:
- (a)Personal Data of website visitors (including prospective Subscribers) collected through the Website;
- (b)Personal Data of Subscriber Personnel (such as directors, finance and IT contacts, and authorised users of the Subscriber Portal) that we collect and Process in order to manage the Subscriber relationship, including contracting, billing, support, and account administration; and
- (c)Personal Data of our personnel, contractors, suppliers, and other third parties with whom we deal in the ordinary course of operating our business.
- 3.3We are a Processor in respect of Guest Personal Data. When Guests interact with the QR Code Interface, the Subscriber is the Controller of the Guest’s Personal Data and we Process Guest Personal Data on the Subscriber’s behalf for the purpose of providing the Platform to the Subscriber. Our role, responsibilities, and the terms on which we Process Guest Personal Data are set out in the SaaS Terms (including the Data Processing Addendum). Guests should refer to the relevant Subscriber’s privacy notice for information about the Subscriber’s own Processing.
- 3.4Where we Process Personal Data in our capacity as a Controller, the remainder of this Privacy Policy describes our practices. Where we Process Guest Personal Data as a Processor, we will only do so on documented instructions from the relevant Subscriber and otherwise in accordance with the SaaS Terms and applicable Data Protection Laws.
4. PERSONAL DATA WE COLLECT AS CONTROLLER
- 4.1The categories of Personal Data we collect as Controller depend on how you interact with the Website and the Platform.
-
4.2Website visitor information includes:
- (a)contact details you submit through the Website (for example, name, business email address, telephone number, and the company you represent), where you complete a contact form, request a demo, sign up for marketing communications, or otherwise contact us;
- (b)the content of communications you send to us through the Website, by email, or through other channels; and
- (c)technical, device, and usage data collected automatically through cookies and similar technologies, as described in our Cookie Policy.
-
4.3Subscriber Personnel information includes:
- (a)contracting and onboarding information, including names, position titles, business contact details, billing contact details, and signatory details of authorised representatives of each Subscriber;
- (b)account and access information for users of the Subscriber Portal, including username, role, authentication credentials, single sign-on identifiers (where applicable), and audit logs;
- (c)records of communications, support tickets, and feedback exchanged between Subscriber Personnel and us; and
- (d)financial information, including bank account or card details (held by our payment processor on our behalf), invoice history, and tax identifiers.
- 4.4Other Personal Data that we Process as Controller includes information about our own personnel, contractors, suppliers, professional advisors, and other counterparties in connection with the operation of our business.
- 4.5We do not generally seek to collect Personal Data of a sensitive nature as Controller. Where you submit any such information voluntarily, we Process it only to the extent reasonably necessary for the relevant purpose and consistent with the Data Protection Laws.
5. HOW WE COLLECT PERSONAL DATA AS CONTROLLER
-
5.1We collect Personal Data as Controller:
- (a)directly from you, when you visit the Website, contact us, request a demo or trial, enter into or perform under the SaaS Terms, or otherwise interact with us;
- (b)automatically, through cookies, analytics tools, and similar technologies, as further described in our Cookie Policy; and
- (c)from third parties, including marketing and lead generation providers, publicly available business directories, professional networks (where permitted by applicable law), single sign-on providers, payment processors, identity verification providers, and integration partners.
- 5.2Where it is reasonable and practicable to do so, we will collect Personal Data directly from you. We will not collect Personal Data by unlawful or unfair means.
- 5.3At or before the time we collect Personal Data from you, we will take reasonable steps to provide the information required by APP 5 (where the Privacy Act applies) and Articles 13 and 14 of the GDPR or UK GDPR (where they apply), either directly or by reference to this Privacy Policy.
6. PURPOSES AND LAWFUL BASES FOR PROCESSING
-
6.1We use Personal Data that we hold as Controller for the following primary purposes:
- (a)responding to enquiries and demo or trial requests, providing information about the Platform, and managing prospective Subscriber relationships;
- (b)entering into and performing the SaaS Terms with Subscribers, including provisioning, billing, support, and account administration;
- (c)operating, maintaining, securing, and improving the Website, the Platform, and our business systems;
- (d)communicating with Subscriber Personnel about service-related matters (such as outages, scheduled maintenance, feature changes, and security incidents);
- (e)sending marketing and promotional communications about our products and services to prospective Subscribers and existing Subscriber Personnel, where you have consented or where we are otherwise permitted to do so by law;
- (f)conducting analytics, research, and product development to understand and improve the Platform;
- (g)detecting, preventing, and responding to fraud, security incidents, and breaches of the SaaS Terms or applicable law; and
- (h)complying with our legal, regulatory, accounting, audit, and tax obligations, enforcing our terms, and protecting our rights and the rights of others.
-
6.2Lawful bases (GDPR and UK GDPR). Where the GDPR or UK GDPR applies, we Process Personal Data on one or more of the following lawful bases:
- (a)Contract (Article 6(1)(b)): to enter into and perform the SaaS Terms with a Subscriber, and to take steps requested by you prior to entering into the SaaS Terms;
- (b)Legitimate interests (Article 6(1)(f)): to operate, secure, and improve the Website, the Platform, and our business; to manage prospective Subscriber relationships and B2B marketing where consent is not required; to detect and prevent fraud and security incidents; and to defend or exercise legal claims, in each case subject to our balancing of those interests against your rights and freedoms;
- (c)Consent (Article 6(1)(a)): for marketing communications where the relevant law requires consent, and for non-essential cookies as described in our Cookie Policy. You may withdraw your consent at any time without affecting the lawfulness of Processing carried out before the withdrawal; and
- (d)Legal obligation (Article 6(1)(c)): to comply with our legal, regulatory, accounting, audit, and tax obligations.
- 6.3Where we Process Guest Personal Data as a Processor on behalf of a Subscriber, the lawful basis for that Processing is the Subscriber’s responsibility as Controller, and we Process the Guest Personal Data only on the Subscriber’s documented instructions under the SaaS Terms.
7. DISCLOSURE OF PERSONAL DATA
-
7.1We may disclose Personal Data that we hold as Controller to the following categories of recipients for the purposes described in clause 6:
- (a)Service providers: third party providers who perform services on our behalf, including cloud hosting, infrastructure, payment processing, customer relationship management, support and ticketing, marketing and analytics, identity and single sign-on, and security monitoring;
- (b)Integration partners: third party providers whose services Subscribers ask us to integrate with the Platform (for example, property management systems, payment processors, and laundry operations partners);
- (c)Group entities: other entities within the Purple TIC Enterprises group, where necessary to provide and support the Platform;
- (d)Professional advisors: our lawyers, accountants, auditors, and insurers, where necessary for the provision of their services;
- (e)Law enforcement and regulators: government authorities, law enforcement agencies, courts, tribunals, data protection authorities, or other regulators, where required or authorised by law, or to protect our legal rights and the rights of others; and
- (f)Business transfers: a potential buyer, transferee, investor, or merger partner in the event of a sale, merger, restructure, or other transfer of all or part of our business or assets.
- 7.2Before disclosing Personal Data to a service provider or other third party, we take reasonable steps to ensure that the third party is contractually obliged to handle the Personal Data in accordance with the Data Protection Laws and this Privacy Policy, and only uses the Personal Data for the specified purposes.
- 7.3We do not sell Personal Data.
8. OUR ROLE AS PROCESSOR OF GUEST PERSONAL DATA
- 8.1When Guests interact with the QR Code Interface to request services from a Subscriber, we Process the resulting Guest Personal Data only as a Processor acting on behalf of, and on the documented instructions of, the relevant Subscriber. The Subscriber is the Controller of the Guest Personal Data.
-
8.2Our obligations as a Processor in respect of Guest Personal Data are set out in the SaaS Terms and any Data Processing Addendum forming part of them, and include obligations to:
- (a)Process the Guest Personal Data only on the Subscriber’s documented instructions;
- (b)ensure that personnel authorised to Process the Guest Personal Data are under appropriate confidentiality obligations;
- (c)implement appropriate technical and organisational measures to protect the Guest Personal Data;
- (d)engage sub-processors only on terms that are consistent with our obligations under the SaaS Terms, and notify the Subscriber of changes to sub-processors as required by the SaaS Terms;
- (e)reasonably assist the Subscriber in responding to data subject requests, in complying with Articles 32-36 of the GDPR or UK GDPR, and in conducting data protection impact assessments where required;
- (f)notify the Subscriber without undue delay if we become aware of a personal data breach affecting the Guest Personal Data; and
- (g)at the Subscriber’s option, delete or return all Guest Personal Data at the end of the relevant Subscriber relationship, except to the extent applicable law requires storage of the Guest Personal Data.
- 8.3Guests with questions about the collection or use of their Personal Data should contact the relevant Subscriber. Where we receive an enquiry or request from a Guest directly, we will (where appropriate) refer the Guest to the Subscriber or pass the request to the Subscriber for action.
9. INTERNATIONAL TRANSFERS OF PERSONAL DATA
-
9.1We are based in Australia. Our service providers and sub-processors are located in Australia and in other jurisdictions, including the United States, the United Kingdom, the EEA, and other countries depending on the service in question. Where we transfer Personal Data outside the country in which it was collected, we put in place safeguards intended to protect the Personal Data, including:
- (a)For transfers subject to the GDPR or UK GDPR out of the EEA or the UK: the European Commission’s Standard Contractual Clauses (and, for UK transfers, the UK International Data Transfer Addendum or UK IDTA), an adequacy decision (where one applies to the destination country), or another lawful transfer mechanism under Article 46 of the GDPR or UK GDPR;
- (b)For transfers subject to the Privacy Act out of Australia: reasonable steps consistent with our obligations under APP 8, including contractual commitments that bind the overseas recipient to handle the Personal Information in accordance with the APPs; and
- (c)appropriate supplementary measures (for example, encryption in transit and at rest, access controls, and pseudonymisation) where the destination jurisdiction does not provide equivalent protection.
- 9.2By using the Website or the Platform (and, where you are a Subscriber, by entering into the SaaS Terms), you acknowledge that Personal Data may be transferred to and Processed in countries other than the country in which you are located.
10. DATA RETENTION
- 10.1We retain Personal Data only for as long as is reasonably necessary to fulfil the purposes for which it was collected, including to satisfy any legal, regulatory, accounting, or reporting requirements, or to resolve disputes and enforce our agreements.
- 10.2To determine the appropriate retention period, we consider the amount, nature, and sensitivity of the Personal Data, the potential risk of harm from unauthorised use or disclosure, the purposes for which we Process the Personal Data, whether we can achieve those purposes through other means, and applicable legal requirements.
- 10.3In respect of Guest Personal Data Processed as a Processor, retention is determined by the Subscriber as Controller, subject to the SaaS Terms. We will not retain Guest Personal Data after the end of the relevant Subscriber relationship except in accordance with the Subscriber’s instructions or as required by law.
- 10.4When Personal Data is no longer required, we will take reasonable steps to destroy or de-identify it in accordance with our information handling procedures (consistent with APP 11.2 and Article 17 of the GDPR or UK GDPR, as applicable). Where de-identification is used, the de-identified information may be retained for analytical and research purposes.
11. DATA SECURITY
-
11.1We take appropriate technical and organisational measures, having regard to the state of the art, the nature, scope, and purposes of the Processing, and the risk to data subjects, to protect Personal Data from unauthorised or unlawful Processing and against accidental loss, destruction, damage, alteration, or disclosure (consistent with our obligations under APP 11.1 and Article 32 of the GDPR or UK GDPR, as applicable). These measures include:
- (a)encryption of Personal Data in transit and, where appropriate, at rest;
- (b)access controls (including role-based access, multi-factor authentication, and least-privilege principles);
- (c)logging, monitoring, and alerting for suspicious activity;
- (d)regular security assessments and testing of our systems and processes;
- (e)staff training on privacy, security, and data handling obligations; and
- (f)incident response procedures for investigating and responding to actual or suspected personal data breaches.
- 11.2While we take reasonable steps to protect Personal Data, no method of transmission over the internet or method of electronic storage is completely secure. We cannot guarantee the absolute security of Personal Data.
- 11.3Breach notification. We will notify the OAIC and affected individuals of any "eligible data breach" in accordance with Part IIIC of the Privacy Act (the Notifiable Data Breaches scheme). Where the GDPR or UK GDPR applies, we will notify the relevant supervisory authority and (where required) the affected data subjects in accordance with Articles 33 and 34 of the GDPR or UK GDPR. In respect of Guest Personal Data Processed as a Processor, we will notify the Subscriber without undue delay in accordance with the SaaS Terms.
12. YOUR RIGHTS AS A DATA SUBJECT
-
12.1Subject to applicable Data Protection Laws and the conditions set out in them, you may have the following rights in respect of Personal Data we Process about you as Controller:
- (a)Access: to be informed about, and to obtain a copy of, the Personal Data we hold about you (APP 12; Article 15 of the GDPR or UK GDPR);
- (b)Correction or rectification: to have inaccurate, out-of-date, incomplete, irrelevant, or misleading Personal Data corrected (APP 13; Article 16 of the GDPR or UK GDPR);
- (c)Erasure / deletion: in certain circumstances, to have your Personal Data deleted (Article 17 of the GDPR or UK GDPR);
- (d)Restriction: in certain circumstances, to restrict our Processing of your Personal Data (Article 18 of the GDPR or UK GDPR);
- (e)Portability: in certain circumstances, to receive your Personal Data in a structured, commonly used, and machine-readable format and to transmit that data to another Controller (Article 20 of the GDPR or UK GDPR);
- (f)Objection: to object to our Processing of your Personal Data where we rely on legitimate interests, including for direct marketing (Article 21 of the GDPR or UK GDPR);
- (g)Withdraw consent: where we rely on your consent, to withdraw that consent at any time without affecting the lawfulness of Processing carried out before the withdrawal;
- (h)Not be subject to automated decision-making: in certain circumstances, not to be subject to a decision based solely on automated Processing, including profiling, which produces legal or similarly significant effects concerning you (Article 22 of the GDPR or UK GDPR); and
- (i)Lodge a complaint: with us, with the OAIC, or with a relevant data protection or supervisory authority (see clause 17).
- 12.2To exercise any of these rights, please contact us using the details in clause 17. We may require you to verify your identity before actioning your request. We will respond within the timeframes required by the applicable Data Protection Laws (and, in any event, within 30 days where the Privacy Act applies, or within one month where the GDPR or UK GDPR applies, subject to permitted extensions).
- 12.3Where you are a Guest, requests about your Personal Data should generally be directed to the relevant Subscriber, who is the Controller of your Personal Data. Where we receive your request directly, we will, where appropriate, forward it to the Subscriber for action.
13. DIRECT MARKETING
- 13.1We may use the Personal Data of prospective Subscribers and existing Subscriber Personnel (including business contact details) to send direct marketing communications about our products, services, events, and content, where you have consented or where we are otherwise permitted to do so under the Privacy Act, the Spam Act 2003 (Cth), the GDPR, the UK GDPR, the EU ePrivacy Directive (as implemented in the relevant member state), and the UK Privacy and Electronic Communications Regulations.
-
13.2You may opt out of receiving direct marketing communications from us at any time by:
- (a)using the unsubscribe link included in each marketing email;
- (b)updating your communication preferences in your account or contacting your account manager; or
- (c)contacting us using the details in clause 17.
- 13.3If you opt out of direct marketing communications, we will continue to send you service-related communications that are necessary for us to provide the Platform and our services.
14. COOKIES AND TRACKING TECHNOLOGIES
- 14.1We use cookies and similar tracking technologies on the Website and the Subscriber Portal. For detailed information about the cookies we use, the purposes for which we use them, and how you can manage your cookie preferences, please refer to our Cookie Policy, available at impressaatelier.com/legal/cookies.
15. THIRD PARTY LINKS
- 15.1The Website and the Platform may contain links to third party websites, services, or applications that are not operated or controlled by us (including integration partners, payment processors, and social media platforms). This Privacy Policy does not apply to those third party services, and we are not responsible for their privacy practices.
- 15.2We encourage you to review the privacy policies of any third party service before providing your Personal Data to them.
16. CHILDREN'S PRIVACY
- 16.1The Website, the Platform, and the QR Code Interface are intended for use by adults. We do not knowingly collect Personal Data directly from children. Where a Subscriber permits a Guest who is a minor to use the QR Code Interface, the relevant Subscriber is responsible, as Controller, for ensuring that any required parental or guardian consent is in place and that any age-appropriate protections apply.
17. CONTACT US AND COMPLAINTS
- 17.1If you have any questions about this Privacy Policy, wish to exercise any of your rights, or wish to make a complaint about how we Process Personal Data, please contact our privacy team at support@impressaatelier.com or by writing to Impressa Atelier Pty Ltd, Attn: Privacy Officer, Level 10, 369 Royal Parade, Parkville, VIC 3052 Australia.
- 17.2Where you have specific data protection enquiries (including data subject requests under the GDPR or UK GDPR), you may also contact support@impressaatelier.com.
- 17.3We will aim to resolve your complaint within 30 days of receipt. If we need more time, we will let you know the reason for the delay and the expected timeframe for resolution.
-
17.4If you are not satisfied with our response, or if you consider that we have not handled your complaint appropriately, you may refer your complaint to a competent privacy or data protection authority, including:
- (a)Australia: the Office of the Australian Information Commissioner (www.oaic.gov.au; 1300 363 992; GPO Box 5218, Sydney NSW 2001);
- (b)EU / EEA: the data protection supervisory authority in your country of residence, place of work, or place of the alleged infringement (a list is published by the European Data Protection Board); and
- (c)United Kingdom: the Information Commissioner’s Office (www.ico.org.uk).
18. EU AND UK REPRESENTATIVES
- 18.1Where required by Article 27 of the GDPR or UK GDPR (because we offer goods or services to, or monitor the behaviour of, individuals in the EU or the UK), we will appoint a representative in the EU and/or the UK. Details of any such representative will be provided here when appointed:
19. CHANGES TO THIS PRIVACY POLICY
- 19.1We reserve the right to amend this Privacy Policy at any time. Any changes will be effective when we post the revised Privacy Policy on the Website with an updated effective date.
- 19.2Where the changes are material, we will use reasonable endeavours to notify Subscribers and, where appropriate, other affected data subjects by email or by posting a prominent notice on the Website before the changes take effect.