POP International Holdings Pty Limited
Effective starting: 1 August 2021
POP International Holdings Pty Limited and its subsidiary companies and POPai Holdings Pty Limited and its subsidiary companies, collectively known as “POP” and our related entities (“POP”, “us”, “we” and “our”) are committed to protecting the privacy of our customers and users.
“POP Services” are all the products and services we may provide to you, including our websites, our online and offline insurance services and associated services.
Where our changes are material, we will try to notify you – this may be by way of an email or a notice on our websites, or an alert on the login screens for the POP Services that will appear for at least 30 days. We may not notify you if the way in which we use your personal information has not changed.
Why we collect your personal information
We collect your personal information to supply you with the POP Services and to further develop, enhance and safeguard those services. We may also use your personal information to:
If we do not collect this information from you, you might not be able to use the POP Services or create an account or profile with us, some of the functions comprising the POP Services might not be available to you, and/or we might not be able to communicate with you (including through marketing communications).
Other ways we use your information
What personal information do we collect?
The personal information we may collect includes information that you provide voluntarily to us, information that we collect automatically and information that we obtain from third party sources. This may include:
We may also process personal information incorporated in the content that users create, provide, post, host, upload, store, communicate or display when you use the POP Services (“User Content”). This may include sensitive information, such as personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person’s sex life or sexual orientation. Where we process personal information in content, we do so on behalf of our customers and users and it is their responsibility to have lawful grounds to use that personal information. We will not be responsible for obtaining consent for the use of any sensitive information that is incorporated in any user content.
How do we collect personal information?
We collect personal information in a number of ways, including:
How do we disclose personal information?
We may disclose the personal information we collect:
to related entities of POP Specialty Insurance Pty Limited for the purposes of performing the Services and operating our group’s business. A list of our group companies is set out below:
POPai Holdings Pty Ltd.
to a new owner or potential buyer of POP, where the ownership of all or substantially all of the POP business, or individual business units owned by POP, were to change. This information would be provided in order to allow the POP Services to continue to operate.
Some of the recipients described above, including our service providers, your team administrator, other users of the POP Services, any new owner of POP, and the SEC, are or may be located offshore.
We may disclose your personal information to third parties to allow them to market to you (including through direct marketing) if we have first obtained your consent or if we have other lawful grounds to do so.
Legal basis for processing personal information (EEA visitors only)
If you are a visitor from the European Economic Area, our legal basis for collecting and using the personal information described above will depend on the personal information concerned and the specific context in which we collect it.
However, we will normally collect personal information from you only where we have your consent to do so, where we need the personal information to perform a contract with you, or where the processing is in our legitimate interests and not overridden by your data protection interests or fundamental rights and freedoms. In some cases, we may also have a legal obligation to collect personal information from you or may otherwise need the personal information to protect your vital interests or those of another person (e.g. other users).
If we ask you to provide personal information to comply with a legal requirement or to perform a contact with you, we will make this clear at the relevant time and advise you whether the provision of your personal information is mandatory or not (as well as of the possible consequences if you do not provide your personal information).
Similarly, if we collect and use your personal information in reliance on our legitimate interests (or those of any third party), we will make clear to you at the relevant time what those legitimate interests are.
Most of the ways in which we use your personal data are based on our legitimate interests in:
When we rely on our legitimate interests as a lawful ground to process your personal information, we do so taking into account the potential impact on your privacy and we offer the right to object to or opt out from processing as described below in the “Your privacy rights” section below.
If you have questions about or need further information concerning the legal basis on which we collect and use your personal information, please contact us using the contact details provided under the “Contacting POP about Privacy” heading below.
Cookies and similar tracking technology
International data transfers
Your personal information may be transferred to, and processed in, countries other than the country in which you are resident. These countries may have privacy laws that are different to the laws of your country (and, in some cases, may not be as protective).
Specifically, our group companies and third party service providers and partners operate around the world and, in particular, in Australia, the United States of America, Amsterdam, Germany, Hong Kong, the United Kingdom and Vietnam. This means that when we collect your personal information we may process it in any of these countries.
We currently host our servers for the POP Services in Australia using a third party hosting provider (Google Cloud).
We retain personal information we collect from you where we have an ongoing legitimate business need to do so (for example, to continue providing access to the POP Services or to comply with applicable legal, tax or accounting requirements).
When we have no ongoing legitimate business need to process your personal information, we will either delete or anonymise it or, if this is not possible (for example, because your personal information has been stored in backup archives), then we will securely store your personal information and isolate it from any further processing until deletion is possible.
We only retain User Content for such time as permitted by our contracts with our customers or for such time as they instruct or permit us to do so.
Your privacy rights
You have the following privacy rights:
We respond to all requests we receive from individuals wishing to exercise their data protection rights in accordance with applicable privacy laws.
Please note that we do not offer any of the rights described above with respect to any personal information that is incorporated in any User Content. We process such content on behalf of our customers and if your personal information is contained in any such content, you should contact the customer on whose behalf we have stored the information.
In storing your personal information, we use a number of security and organisational measures and technologies to safeguard your personal information from unauthorised access, modification or disclosure and misuse, interference or loss. We have personnel tasked with protecting your information, developing new security features, and identifying and mitigating vulnerabilities. Our existing security measures include encryption, two-factor authentication, and notifications when new devices and apps are connected with your user account. We also have in place security measures and policies focused on restricting access to sensitive information to authorised personnel.
While we hold your information on a secured server behind a firewall and we encrypt data transfer using 256 bit SSL encryption, please be aware that there are inherent risks in transmitting information using the internet.
Contacting POP about Privacy
POP International Holdings Pty Ltd. and POPai Holdings Pty Ltd.
Level 29, Chifley Tower. 2 Chifley Square, Sydney NSW 2000
When you request that we access or correct your personal information, we will need to locate the relevant information, so it would assist us if you could supply as much supporting detail as possible. Where we refuse your access or correction request, we will comply with any requirements under applicable laws to notify you of our reasons for doing so and the mechanisms through which you may complain. Where we deny a request to correct information and where you make a request to us, we will comply with any applicable legal requirement to associate with the information a statement that it is inaccurate, out of date, incomplete, irrelevant or misleading.
We take your privacy complaints seriously. Where you inform us that you have a complaint about our handling of your personal information, we will contact you to let you know which of our team members will investigate your matter and the timeframe within which they will aim to respond to you.
If you’d like to have a chat with one of our team, please send us your name, email and phone number and we’ll get back you to as soon as possible