Opening Statement

This Policy has been approved by the dplr Group Executive Team.

dplr Pty Ltd (ABN: 42 628 377 300), ORBIT Co Pty Ltd (ABN: 89 666 818 177), and Solar2Go Pty Ltd (ABN: 13 675 776 404), collectively referred to as dplr Group (the “Company”), respect the privacy of the people we work with and are committed to handling personal information responsibly, securely and in accordance with applicable privacy laws.

Intent

The intent of this Policy is to provide clear and practical information about how dplr Group collects, holds, uses, discloses and protects personal information.

The Company aims to collect only the information reasonably required for its business, employment and project activities, use that information for appropriate purposes, protect it from misuse or unauthorised access, and provide people with appropriate access to and control over their personal information.

Scope

This Policy applies to personal information handled by dplr Group in connection with its business and activities, including information relating to clients, prospective clients, staff, job applicants, contractors, suppliers, event attendees and participants, project stakeholders and members of the public.

It applies to information collected through Company workplaces, projects and events, business systems, communications, websites, social media and other online platforms.

Policy Actions

Personal & Sensitive Information

Personal information is information or an opinion about an identified individual, or an individual who is reasonably identifiable.

Depending on the nature of a person's interaction with us, dplr Group may collect information such as:

  • name and contact details;

  • employment, professional or business information;

  • job application, qualification and work history information;

  • payment, billing or financial information where required;

  • emergency contact details;

  • photographs, video or other recordings where an individual may be identifiable;

  • event registration or participation information;

  • online and website usage information; and

  • other information reasonably required to deliver Company services, projects or activities.

The Company may also collect sensitive information where reasonably necessary, including health, accessibility or dietary information, information about racial or ethnic origin, religious beliefs, sexual orientation, criminal history or other information classified as sensitive under applicable privacy law.

Sensitive information will only be collected and handled where there is an appropriate legal basis to do so, including consent where required.

How We Collect Personal Information

Where reasonably practicable, dplr Group collects personal information directly from the individual concerned.

Information may be collected when a person:

  • communicates with the Company by phone, email, online or in person;

  • submits an enquiry or completes a form;

  • engages the Company or requests information about its services;

  • applies for employment, casual work, contractor work or another engagement;

  • works on or participates in a Company project;

  • registers for or attends an event produced, managed or supported by the Company;

  • provides information about accessibility, dietary or other participation requirements;

  • interacts with Company websites or social media platforms; or

  • subscribes to communications or participates in surveys, competitions or similar activities.

The Company may also receive personal information from clients, venues, event partners, suppliers, recruitment providers, service providers, publicly available sources or other third parties where it is reasonable and lawful to do so.

Where practicable, individuals may interact with the Company anonymously or using a pseudonym. In some circumstances, however, dplr Group may be unable to provide a service, respond to a request or complete an activity without certain identifying information.

How We Use Personal Information

dplr Group may use personal information to:

  • provide, manage and improve its services, projects and events;

  • communicate with clients, staff, contractors, suppliers, attendees and other stakeholders;

  • manage event registrations, participation and accessibility requirements;

  • administer recruitment, workforce and contractor arrangements;

  • manage safety, security and emergency requirements;

  • process payments, accounts and business administration;

  • maintain business and project records;

  • manage enquiries, feedback and complaints;

  • comply with legal, regulatory, contractual and insurance requirements;

  • analyse and improve Company operations and online services; and

  • undertake marketing or business communications where permitted.

Personal information will not generally be used for an unrelated purpose unless the individual would reasonably expect that use, consent has been obtained, or the use is otherwise permitted or required by law.

Disclosure of Personal Information

dplr Group may disclose personal information where reasonably required for its business activities.

This may include disclosure between dplr Group entities and, where appropriate, to:

  • clients, venues, event partners and project stakeholders;

  • contractors, suppliers and service providers;

  • technology, cloud storage and IT providers;

  • payroll, accounting, workforce management and business system providers;

  • ticketing, registration or event service providers;

  • professional advisers, insurers and financial institutions;

  • government agencies, regulators or emergency services; and

  • other parties where authorised or required by law.

The Company will take reasonable steps to ensure that personal information is only disclosed where appropriate and that service providers handling personal information are expected to protect it appropriately.

Overseas Storage & Disclosure

Some cloud, technology and service providers used by dplr Group, including Google Workspace and, where required, Dropbox, may store, process or access personal information outside Australia.

Depending on the provider, service and account configuration, personal information may be stored or processed in the United States and other locations internationally.

Where personal information is disclosed to an overseas recipient, the Company will take reasonable steps as required by applicable privacy law to ensure the information is appropriately protected.

Website & Online Data Collection

When a person visits or interacts with a dplr Group website, the Company may automatically collect information about that interaction, including:

  • IP address;

  • browser and device information;

  • date and time of access;

  • pages viewed and links used;

  • referring website information; and

  • other technical or usage information.

The Company may use cookies and similar technologies to operate its websites, remember preferences, understand how visitors use the websites and improve website functionality and performance.

Users can generally control or disable cookies through their browser settings. Disabling some cookies may affect the functionality or performance of parts of the website.

dplr Group may use website analytics or other third-party digital services to understand website traffic and user behaviour. Information collected through these services may be processed by the relevant provider in accordance with its own privacy practices.

Where a person voluntarily provides personal information through an online enquiry form, registration form, mailing list or other website function, that information will be handled in accordance with this Policy and any additional privacy notice provided at the point of collection.

The Company's websites or online communications may contain links to third-party websites. dplr Group is not responsible for the privacy practices of those third parties and encourages users to review their privacy information when visiting external websites.

Direct Marketing

Where permitted by law, dplr Group may use personal information to communicate relevant information about its services, projects, events or activities.

Individuals may opt out of direct marketing communications at any time using the unsubscribe option provided or by contacting the Company.

The Company will comply with applicable privacy and electronic marketing requirements when sending direct marketing communications.

Children & Young People

Where dplr Group collects personal information relating to children or young people through events, projects or other activities, the Company will take additional care in how that information is collected, used, disclosed and secured.

Appropriate consent or authorisation will be obtained where required, having regard to the circumstances and applicable Company child safety requirements.

Security of Personal Information

dplr Group will take reasonable steps to protect personal information from misuse, interference, loss, unauthorised access, modification or disclosure.

Measures may include appropriate physical, administrative and technological safeguards, access controls, secure business systems, staff awareness and limiting access to personal information to people who reasonably require it for their work.

Staff are expected to handle personal information responsibly and in accordance with relevant Company policies and procedures.

Retention & Disposal

Personal information will be retained only for as long as reasonably required for the purpose for which it was collected, for legitimate business purposes, or as required by law.

Where personal information is no longer required and the Company is not legally required to retain it, reasonable steps will be taken to securely destroy or de-identify it.

Data Breaches

Suspected or actual loss, unauthorised access, disclosure or misuse of personal information must be reported promptly within the Company so that appropriate action can be taken.

dplr Group will assess and respond to data breaches in accordance with applicable privacy requirements and will notify affected individuals and the Office of the Australian Information Commissioner where required under the Notifiable Data Breaches scheme.

Access & Correction

Individuals may request access to, or correction of, personal information held by dplr Group. The Company may verify the identity of the person making the request before responding.

Requests will be handled within a reasonable period in accordance with applicable privacy law. Access may be limited or refused where permitted by law.

Requests should be made using the contact details below.

Privacy Enquiries & Complaints

If you have a question, request or complaint about how dplr Group handles your personal information, please contact:

dplr Group
4 Hordern Place, Camperdown NSW 2050
Email: hello [at] dplr.com.au
Websites: www.dplr.com.au | www.orbit.company | www.solar2go.com.au 

The Company will consider privacy complaints fairly, promptly and sensitively and may request further information where reasonably required to investigate the matter.

If a person is not satisfied with the Company's response, they may be entitled to lodge a complaint with the Office of the Australian Information Commissioner (OAIC).

Breaches of this Policy 

Any staff member who breaches this Policy may be subject to disciplinary action, having regard to the nature and seriousness of the breach and the circumstances involved. Disciplinary action may include termination of employment or engagement where appropriate. Serious or reportable privacy breaches may also result in notification to affected individuals, regulators or other relevant authorities where required.

Closing Statement

dplr Group is committed to managing personal information responsibly, transparently and securely. The Company will regularly review its privacy practices and this Policy to ensure they remain appropriate to its operations and applicable privacy requirements.