Policies
Last updated
YOURKIND — Privacy Policy
1 Purpose of our policy
1.1
YourKind Pty Ltd ABN 31 663 959 448 (we, us or our) has adopted this Privacy Policy to ensure that we have standards in place to protect the Personal Information that we collect about individuals that is necessary and incidental to:
- Providing the system and services that we offer; and
- The normal day-to-day operations of our business.
1.2
This Privacy Policy follows the standards of the following, among others:
- The Australian Privacy Principles set by the Australian Government for the handling of Personal Information under the Privacy Act 1988 (Cth) (Privacy Act);
- The regulations and principles set by the European Union’s General Data Protection Regulation (GDPR) for the handling of Personal Data;
- the United Kingdom General Data Protection Regulation and the Data Protection Act 2018 (UK GDPR);
- the California Consumer Privacy Act as amended, and the comprehensive privacy laws of other United States jurisdictions;
- the Personal Data Protection Act 2012 (Singapore);
- the Personal Information Protection and Electronic Documents Act (Canada) and Quebec’s Law 25;
- the Swiss Federal Act on Data Protection; and
- UAE Federal Decree-Law No. 45 of 2021.
1.3
By publishing this Privacy Policy, we aim to make it easy for our customers and the public to understand what Personal Information we collect and store, why we do so, how we receive, obtain, store and/or use that information, and the rights of control an individual has with respect to their Personal Information in our possession.
2 Who and what this policy applies to
2.1
Our Privacy Policy deals with how we handle “personal information” and “personal data” as those terms are defined in the Privacy Act and the GDPR respectively, together with any equivalent term under any other privacy law that applies to us (Personal Information).
2.2
We handle Personal Information in our own right, and alongside the event organisers, venues and brands that sell through our platform (brands). The section of this Privacy Policy headed “YourKind and the brands” explains how we and each brand each use it.
2.3
Our Privacy Policy does not apply to information we collect about businesses or companies, however it does apply to information about the people in those businesses or companies which we store.
2.4
The Privacy Policy applies to all forms of information, physical and digital, whether collected or stored electronically or in hardcopy.
2.5
If, at any time, an individual provides Personal Information or other information about someone other than himself or herself, the individual warrants that they have that person’s consent to provide such information for the purpose specified.
2.6
We consider the protection of privacy of children very important. An individual must be at least 16 years old to create a YourKind account. Where an individual is under 16, a parent or guardian must create and manage the account on their behalf. We ask for date of birth at sign-up. If we learn that we hold Personal Information about a person under 16 without parental consent, we will delete it.
2.7
We do not use targeted advertising, profiling or behavioural marketing in relation to anyone under 18, and we never sell or share the Personal Information of anyone under 18.
2.8
A parent or guardian who believes that their child has given us information should contact us using the details at the end of this Privacy Policy, and we will delete it.
3 YourKind and the brands
3.1
We provide the platform through which brands sell tickets and memberships and communicate with their audiences. When an individual buys a ticket, subscribes to a brand, pre-registers for an event or completes a form, we collect their Personal Information and supply it to the relevant brand, in accordance with the consent given at the time.
3.2
We and each brand hold separate records of that Personal Information and each determine independently how those records are used. A brand holds information about an individual’s dealings with that brand only, and cannot access their dealings with any other brand. We hold information about an individual’s dealings across the platform, together with the information they provide to us directly through their YourKind account.
3.3
We determine what Personal Information is collected through the platform. A brand cannot alter the information collected at checkout or in the app, but may add its own questions to its checkout, and decides whether, when and what to send by way of marketing.
3.4
A brand’s use of Personal Information is governed by that brand’s own privacy policy. We are not responsible for what a brand does with Personal Information once we have supplied it. An individual who wishes to access, correct or delete the information a brand holds about them should contact that brand, and we will assist them to do so.
4 Consent to our use of Personal Information
4.1
By creating an account, buying a ticket, completing a form or otherwise using YourKind, an individual agrees that:
- We may collect and use their Personal Information as described in this Privacy Policy, and both we and the brand may hold and use separate records of it.
- Where they have opted to receive marketing, we may contact them about our own products and services, about the events and experiences of the brands that use our platform, and about the products and services of third parties. Where we send a message about a third party, we send it ourselves and do not disclose their contact details to that third party.
- We may track how they engage with the messages we send, including whether a message was opened, which links were clicked, and whether a purchase followed.
- Where a brand has enabled attendee lists for an event to which they have bought a ticket, their first name and profile picture may be shown as described in this Privacy Policy, unless they turn off the Discoverable setting in their profile.
- We may use information about how the platform is used to operate, secure, analyse and improve our products and services, and to create aggregated and de-identified information.
- If our business or its assets are sold or transferred, the Personal Information we hold may be transferred with it.
4.2
An individual may withdraw any consent given at any time, and may stop receiving marketing at any time, as described in this Privacy Policy. Withdrawing consent does not affect anything done before it was withdrawn.
5 The information we collect
5.1
Without limitation, the type of information we may collect includes:
- Identity Information. Name, date of birth or age, profile photo, and optionally gender (see the clause on sensitive information below);
- Contact Information. Email address and mobile number;
- Financial Information. Card details are entered directly into Stripe’s systems and are processed by Stripe, not stored by us. We hold the last four digits, card type, and records of transactions;
- Location Information. The individual’s city or suburb, which they enter themselves and can change at any time. We do not collect precise or continuous GPS location;
- Transaction and attendance Information. Tickets, add-ons and memberships purchased, price paid, promo codes used, refunds, and check-in and scan records;
- Engagement Information. Whether an email or SMS was delivered, opened or clicked, and whether it led to a purchase and its value;
- Loyalty Information. YourKind Credits earned and the individual’s tier;
- Technical Information. IP address, device type and operating system, browser, app version, and identifiers used for analytics and advertising measurement;
- Derived Information. Totals and summaries we calculate, such as lifetime spend, events attended and attendance frequency; and
- Information an individual sends us. We may collect any personal correspondence that an individual sends us, or that is sent to us by others about the individual’s activities. This includes messages sent to brands through our Inbox feature, support requests sent to us, and answers to questions a brand adds to its own checkout, which are stored against the event and not on the individual’s YourKind profile.
5.2
We may collect other Personal Information about an individual, which we will maintain in accordance with this Privacy Policy.
5.3
Sensitive information. We do not ask for sensitive or special category information — we do not collect race, ethnicity, religion, political views, health, sexual orientation or biometric data. Two exceptions apply.
- Gender. We ask for this once, when an individual first signs in to the app. It is optional and an individual may choose not to specify it. We use it, and we make it available to the brands whose events the individual attends, so that we and they can better understand our audiences and present experiences that are more likely to be relevant. We never sell it, and we never disclose it other than as described in this Privacy Policy. An individual may change or remove it at any time in their profile.
- Questionnaire answers. Brands write their own checkout questions and we do not control what they ask. Our Acceptable Use Policy prohibits brands from asking for information they are not legally entitled to collect. We do not profile individuals or build segments based on questionnaire answers.
5.4
Information about people at the brands that use YourKind. Where an individual works for a brand that uses our platform, we collect their name, email address, phone number, their role and permissions, their account login details, records of how they use the dashboard, billing and subscription information, records of their support conversations with us, and information about the brand’s payment account status provided to us by our payment provider. We use this information to provide and secure the platform, to manage the account, subscription and credits, to provide support, and to inform them about our products and services.
5.5
Information about how brands use YourKind. We collect and analyse information about the performance and use of our platform by the brands that sell through it, including the events they run, the tickets and memberships they sell, the revenue they generate, the campaigns they send and how those campaigns perform, and how their audiences grow and behave. We use this information to operate, secure and improve the platform, to provide brands with reporting and insights about their own performance, to produce aggregated benchmarks and industry reporting, and to promote our own products and services. Where we publish or promote results, we do so on an aggregated or anonymised basis, unless the brand concerned has given us permission to identify it.
6 How information is collected
6.1
Most information will be collected in association with an individual’s use of our event ticketing, audience and marketing platform (YourKind), an enquiry about YourKind or generally dealing with us. However, we may also receive Personal Information from advertising and measurement partners, and from our business partners. In particular, information is likely to be collected as follows:
- Registrations/Subscriptions. When an individual registers or subscribes for a service, account, connection or other process whereby they enter Personal Information details in order to receive or access something, including a transaction;
- Ticket and membership purchases. When an individual buys a ticket, add-on or membership, whether online or in person at an event, and enters Personal Information details in order to complete the order;
- In-person sales. Where a brand sells a ticket at the door using our Box Office feature and captures the buyer’s name, email address and mobile number;
- Check-in. When a ticket is scanned at an event;
- Forms, pre-registrations and questionnaires. When an individual completes a form, registers interest in an event before tickets go on sale, or answers questions at checkout;
- The YourKind app. When an individual creates an account, completes a profile, sets a location, or changes settings;
- Imports by brands. Where a brand uploads contact details it has collected itself. The brand is responsible for having the right to provide that information and for having obtained valid consent for any marketing it then sends;
- Supply. When an individual supplies us with goods or services;
- Contact. When an individual contacts us in any way;
- Access. When an individual accesses us through the internet we may collect information using cookies and similar technologies or analytical services, as described in the section on cookies, pixels and tracking; and/or
- Email and message tracking. We use a small invisible image, called a pixel, that tells us whether a message was opened, and we add tags to links that tell us whether the recipient clicked.
6.2
As there are many circumstances in which we may collect information both electronically and physically, we will endeavour to ensure that an individual is always aware of when their Personal Information is being collected.
6.3
Where we obtain Personal Information without an individual’s knowledge (such as by accidental acquisition from a client) we will either delete/destroy the information, or inform the individual that we hold such information, in accordance with the Australian Privacy Principles and the GDPR.
7 Automated decisions
7.1
Some decisions on our platform are made by software without a person reviewing them.
- Fraud screening. Every payment is screened by Stripe Radar, an automated fraud detection system. It scores the transaction using information about the payment, the device and the purchase pattern, and may block a purchase. An individual whose purchase is blocked may contact us, and a person will review the decision. That individual may ask us to explain the decision, put their case, and ask for the decision to be reconsidered.
- YourKind Credits. An individual’s credits balance and loyalty tier are calculated automatically from their ticket purchases, which affects their entitlements under the programme. An individual may ask us to review their balance or tier.
7.2
We do not use automated decision-making to set prices, or decide who may attend an event.
8 When Personal Information is used & disclosed
8.1
In general, the primary principle is that we will not use any Personal Information other than for the purpose for which it was collected other than with the individual’s permission. The purpose of collection is determined by the circumstances in which the information was collected and/or submitted.
8.2
We will only process Personal Information when we can identify a lawful basis to do so. It is always our responsibility to ensure that we can demonstrate which lawful basis applies to the particular processing purpose.
8.3
The most common lawful bases relied upon are:
- Performance of a contract: to create and operate an individual’s account, process their order, deliver their ticket, admit them to an event, and operate YourKind Credits;
- Consent: we will only rely upon express, clear and informed consent. Any consent provided may specify and/or restrict the purpose and can be withdrawn at any time without penalty. We will keep a record of when and how we got consent from an individual. We rely on consent for all marketing, and for optional gender information.
- Legitimate interests: we will only rely upon an identifiable legitimate interest where we can demonstrate that the processing of Personal Information is necessary to achieve it by balancing it against the individual’s interests, rights and freedoms. We will keep a record of our legitimate interests’ assessments. The legitimate interests we rely on are: keeping the platform secure and free from fraud; understanding in aggregate how features are used so that we can improve them; and protecting our legal position. We also process Personal Information where we are under a legal obligation to do so, including to keep financial and tax records and to respond to lawful requests.
8.4
We keep Personal Information for as long as we need it for the purposes described in this Privacy Policy. An individual’s YourKind account remains available to them, and the tickets, purchase history and credits associated with it remain accessible, for as long as that account is held. We therefore keep the information that supports an account for as long as the account exists. We keep transaction and financial records for as long as we are required to by tax, accounting and anti-money-laundering law. We keep a record of any opt-out for as long as we operate, so that we can continue to honour it. An individual may ask us at any time to delete their Personal Information, and we will do so in accordance with the section of this Privacy Policy on how to access, update and remove information, other than information we are required by law to keep. Where we no longer need to identify an individual, we may anonymise their Personal Information and continue to use it in aggregate form indefinitely.
8.5
We may create aggregated, statistical and de-identified information from the Personal Information we hold, including information about how events perform, how audiences behave and how our products are used. Once information has been aggregated or de-identified so that it no longer identifies an individual, it is no longer Personal Information, and we may use, retain and disclose it for any purpose, including to develop and improve our products, to produce insights, benchmarks and industry reports, and to publish and promote results in our own marketing, case studies and public reporting. We do not attempt to re-identify information we have de-identified.
8.6
If it is necessary for us to disclose an individual’s Personal Information to third parties in a manner compliant with the Australian Privacy Principles and the GDPR in the course of our business, we will inform the individual that we intend to do so, or have done so, as soon as practical.
8.7
Information is used to enable us to operate our business, especially as it relates to an individual. This may include:
- The provision of goods and services between an individual and us;
- Verifying an individual’s identity;
- Communicating with an individual about:
- Their relationship with us;
- Our goods and services;
- Our own marketing and promotions to customers and prospects;
- The events, experiences, products and services of the brands that use our platform, and of third parties, where we send those communications ourselves and do not disclose the individual’s contact details to them;
- Competitions, surveys and questionnaires;
- Investigating any complaints about or made by an individual, or if we have reason to suspect that an individual is in breach of any of our terms and conditions or that an individual is or has been otherwise engaged in any unlawful activity; and/or
- As required or permitted by any law (including the Privacy Act).
8.8
We and each brand may send marketing communications to an individual who has consented to receive them. Each brand determines the content and timing of its own marketing and is responsible for holding the consent on which it relies. Every marketing message identifies the sender and includes a means of unsubscribing. Communications necessary to provide the service, including tickets, order confirmations, event changes, cancellations, refunds and security notices, are not marketing, and we send these for as long as a ticket or an account is held. We send by email, SMS, push notification and, where an individual has agreed, WhatsApp.
8.9
The individual shall have the right to object at any time to the processing of their Personal Information for direct marketing purposes, which includes profiling to the extent that it is related to such direct marketing. Every marketing email and SMS we send contains a unique opt-out link that allows the recipient to stop receiving further marketing material. Transactional messages, such as tickets, order confirmations and event changes, do not carry an opt-out link because they are not marketing. An individual may also reply STOP to any SMS, or contact us using the details at the end of this Privacy Policy, and we will action the request without charge or penalty.
8.10
If an individual opts out of receiving promotional communications from us, we may still send them communications regarding their use of YourKind, including communications regarding their account or subscription.
8.11
There are some circumstances in which we must disclose an individual’s information:
- Where we reasonably believe that an individual may be engaged in fraudulent, deceptive or unlawful activity that a governmental authority should be made aware of;
- As required by any law (including the Privacy Act); and/or
- In order to sell our business (in that we may need to transfer Personal Information to a new owner).
8.12
If all or part of our business, or its assets, is sold, merged, restructured or otherwise transferred, and the Personal Information we hold is one of the assets transferred; the acquiring entity may continue to use that Personal Information in accordance with a privacy policy that is not materially less protective than this one. We will notify individuals if this happens.
9 Mobile numbers and SMS
9.1
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Mobile numbers and SMS opt-in data are not shared, sold, rented or transferred to third parties, affiliates or other organisations.
9.2
This applies without exception and sits above everything else in this Privacy Policy, including the sections on cookies, pixels and tracking and on who we share Personal Information with. Mobile numbers and SMS consent data are never included in any analytics, advertising, measurement or data-sharing arrangement of any kind.
9.3
Message frequency varies by brand and by event. Message and data rates may apply. Reply STOP to any message to unsubscribe, or HELP for assistance.
10 Sending information overseas
10.1
Personal Information is stored in Australia. Our servers and database are hosted in Amazon Web Services’ Sydney region (ap-southeast-2).
10.2
Some of our service providers process Personal Information outside Australia, as set out in the section headed “Who we share Personal Information with” — principally in the United States and Ireland.
10.3
Where we transfer Personal Information out of the country in which an individual is located, and the law of that country requires a transfer safeguard, we put an appropriate safeguard in place. The data processing terms of the service providers we use are incorporated into our agreements with them and include the standard contractual clauses approved for transfers from the European Economic Area, the United Kingdom and Switzerland. Where we receive Personal Information from a person or business in the European Economic Area, the United Kingdom or Switzerland, we put the applicable standard contractual clauses in place with them. Australia has not been the subject of an adequacy decision by the European Commission. An individual may ask us which safeguard applies to a particular transfer.
10.4
For individuals in Australia, we take reasonable steps to ensure that any overseas recipient handles Personal Information consistently with the Australian Privacy Principles, and we remain accountable for their handling of it.
11 Opting “in” or “out”
11.1
An individual may opt to not have us collect and/or process their Personal Information. This may prevent us from offering them some or all of our services and may terminate their access to some or all of the services they access with or through us. They will be aware of this when:
- Opt In. Where relevant, the individual will have the right to choose to have information collected and/or receive information from us (for clarity, consent must involve an unambiguous positive action to opt in); or
- Opt Out. Where relevant, the individual will have the right to choose to exclude himself or herself from some or all collection of information and/or receiving information from us.
11.2
We action opt-outs immediately, and in any case within 5 business days in Australia and 10 business days in the United States and Canada. We keep a minimal record of each opt-out — the email address or mobile number in suppressed form — so that we can continue to honour it. That record is the one data point we cannot delete on request, because deleting it would cause the messages to resume.
11.3
If an individual believes that they have received information from us that they did not opt in or out to receive, they should contact us using the details at the end of this Privacy Policy.
12 Cookies, pixels and tracking
12.1
We and our partners use cookies and similar technologies on our websites, event pages and in our emails.
12.2
On our sites and event pages we use cookies that are strictly necessary to make the site work and, where an individual consents, cookies and pixels for analytics and advertising measurement, including the Meta Pixel and server-side conversion tracking. Server-side tracking is not exempt from consent and we treat it in the same way.
12.3
In emails and messages we track engagement. In email we use a small invisible image, called a pixel, that tells us whether a message was opened. In every email, SMS and message we send, the links are unique to the recipient, so that we can see whether they clicked, what they did afterwards, and whether they went on to make a purchase and for how much. For SMS we also record whether the message was delivered. We use this to report campaign performance to the brands whose messages the recipient receives, to attribute purchases to campaigns, and to improve our service.
12.4
By using our platform and by agreeing to receive messages from us or from a brand, an individual consents to this tracking. An individual who would prefer that we did not track their engagement with the messages we send may contact us using the details at the end of this Privacy Policy, and we will action that request within a reasonable time.
13 The safety & security of Personal Information
13.1
We have appointed a Privacy Officer to oversee the management of this Privacy Policy and compliance with the Australian Privacy Principles, the Privacy Act and the GDPR. This officer may have other duties within our business and also be assisted by internal and external professionals and advisors.
13.2
We will take all reasonable precautions to protect an individual’s Personal Information from unauthorised access. This includes appropriately securing our physical facilities and electronic networks.
13.3
We use encryption in transit and at rest, access controls limiting who on our team can see what, and logging and monitoring of our systems. Despite this, the security of online transactions and the security of communications sent by electronic means or by post cannot be guaranteed. Each individual that provides information to us via the internet or by post does so at their own risk. We cannot accept responsibility for misuse or loss of, or unauthorised access to, Personal Information where the security of information is not within our control.
13.4
We are not responsible for the privacy or security practices of any third party (including third parties that we are permitted to disclose an individual’s Personal Information to in accordance with this policy or any applicable laws), unless otherwise required by the Privacy Act and the GDPR. The collection and use of an individual’s information by such third parties may be subject to separate privacy and security policies.
13.5
If an individual suspects any misuse or loss of, or unauthorised access to, their Personal Information, they should let us know immediately.
13.6
We are not liable for any loss, damage or claim arising out of another person’s use of the Personal Information where we were authorised to provide that person with the Personal Information.
13.7
Where there is a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Information, then:
- We will immediately establish the likelihood and severity of the resulting risk to wider rights and freedoms of natural persons;
- If we determine there is a risk from the security breach, then we will immediately notify the relevant supervisory authority and provide all relevant information on the particular breach, and by no later than 72 hours after having first become aware of the breach;
- If we determine there is a high risk from the security breach (a higher threshold than set for notifying supervisory authorities), we will immediately notify the affected individuals and provide all relevant information on the particular breach without undue delay.
13.8
We will comply with the Notifiable Data Breaches scheme under the Privacy Act, and with the notification requirements of any other law that applies, including Singapore’s three-day requirement where 500 or more individuals are affected.
13.9
We will document the facts relating to any security breach, its effects and the remedial action taken, and investigate the cause of the breach and how to prevent similar situations in the future.
14 Who we share Personal Information with
14.1
With brands. The brand whose event an individual attends receives their name, contact details, ticket and order information, attendance record, that brand’s own questionnaire responses, their city or suburb, and their profile picture if one has been added. A brand sees an individual’s activity with that brand only.
14.2
With other users of the platform. Where a brand has enabled attendee lists for its event, an individual’s first name and profile picture are shown to other users on the event page and in the YourKind app. No other information is shown and the list does not allow anyone to contact them. By buying a ticket to such an event an individual consents to that disclosure, and may prevent it at any time by turning off the Discoverable setting in their profile.
14.3
With our service providers. We use a small number of providers to run the platform. Each is bound by contract to protect Personal Information and to use it only on our instructions. They fall into the following categories: cloud hosting and database services, located in Australia; payment processing and fraud screening, located in Australia, Ireland and the United States; email and SMS delivery, located in Australia and the United States; and customer support and help centre software, located in the United States. We will tell a brand who our providers are on request.
14.4
With advertising and measurement partners. Where an individual consents, we share limited information about actions they take, such as viewing an event page or completing a purchase, with advertising and measurement partners so that brands can understand which of their advertising works. These partners are not acting on our instructions and determine for themselves how they use that information, so their own privacy policies apply in addition to this one. Where an individual does not consent, we do not share this information.
14.5
We do not sell Personal Information.
15 How to access, update and/or remove information
15.1
Users of YourKind may update their Personal Information from within their account or profile at any time to ensure it is accurate and complete.
15.2
Subject to the Australian Privacy Principles and the GDPR, an individual has the right to request from us the Personal Information that we have about them, and we have an obligation to provide them with such information as soon as practicable, and by no later than 28 days of receiving the written request. The individual is free to retain and reuse their Personal Information for their own purposes. We may be required to transmit the Personal Information directly to another organisation if this is technically feasible. We will not charge a fee for providing this information.
15.3
If an individual cannot update their own information, we will correct any errors in the Personal Information we hold about an individual within 28 days of receiving written notice from them about those errors, or two months where the request for rectification is complex.
15.4
In addition to access and correction, an individual may object to our use of their Personal Information, ask us to restrict it, withdraw any consent given, ask us to stop marketing at any time, and receive their Personal Information in a portable format. An individual may appoint another person to make a request on their behalf, and we will ask for proof of that person’s authority. We will never treat an individual differently for exercising a privacy right.
15.5
If we refuse a request, an individual may appeal by replying to our decision or by contacting us with “Appeal” in the subject line. We will respond within 45 days and will explain how to contact the relevant regulator if the individual remains unsatisfied.
15.6
It is an individual’s responsibility to provide us with accurate and truthful Personal Information. We cannot be liable for any information that is provided to us that is incorrect.
15.7
Where a request to access Personal Information is manifestly unfounded, excessive and/or repetitive, we may refuse to respond or charge an individual a reasonable fee for our costs incurred in meeting any of their requests to disclose the Personal Information we hold about them. Where we refuse to respond to a request, we will explain why to the individual, informing them of their right to complain to the supervisory authority and to a judicial remedy without undue delay and at the latest within 28 days.
15.8
We may be required to delete or remove all Personal Information we have on an individual upon request in the following circumstances:
- Where the Personal Information is no longer necessary in relation to the purpose for which it was originally collected and/or processed;
- When the individual withdraws consent;
- When the individual objects to the processing and there is no overriding legitimate interest for continuing the processing;
- The processing of the Personal Information was otherwise in breach of the GDPR;
- The Personal Information has to be erased in order to comply with a legal obligation; and/or
- The Personal Information is in relation to a child.
15.9
We may refuse to delete or remove all Personal Information we have on an individual where the Personal Information was processed for the following reasons:
- To exercise the right of freedom of expression and information;
- To comply with a legal obligation for the performance of a public interest task or exercise of official authority;
- For public health purposes in the public interest;
- Archiving purposes in the public interest, scientific research historical research or statistical purposes; or
- The exercise or defence of legal claims.
16 Complaints and disputes
16.1
If an individual has a complaint about our handling of their Personal Information, they should address their complaint in writing to the details below.
16.2
We will acknowledge a complaint within 30 days, investigate it, and inform the individual of the outcome.
16.3
If we have a dispute regarding an individual’s Personal Information, we both should first attempt to resolve the issue directly between us.
16.4
If we become aware of any unauthorised access to an individual’s Personal Information we will inform them at the earliest practical opportunity once we have established what was accessed and how it was accessed.
17 Regional information
17.1
Europe, the United Kingdom and Switzerland. An individual in the European Economic Area may complain to the supervisory authority in their country of residence, their place of work, or the place where the issue occurred. An individual in the United Kingdom may complain to the Information Commissioner’s Office at ico.org.uk. An individual in Switzerland may complain to the Federal Data Protection and Information Commissioner.
17.2
United States. We do not sell Personal Information. Where a United States privacy law applies to us, an individual may have the right to know what we hold about them, to have it deleted or corrected, and to appeal a decision we make about their request, by contacting us using the details at the end of this Privacy Policy.
17.3
Australia. We handle Personal Information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. An individual may complain to us first and, if unsatisfied, to the Office of the Australian Information Commissioner at oaic.gov.au.
17.4
Canada. Our Privacy Officer can be contacted at privacy@yourkind.io. An individual in Quebec may ask for the Personal Information used in any automated decision about them, the reasons for it and the principal factors involved, and may ask for a person to review that decision. An individual in Quebec may also ask us to cease using technology that identifies, locates or profiles them. We carry out a privacy impact assessment before transferring Personal Information outside Quebec. Complaints may be made to the Commission d’accès à l’information.
17.5
Singapore. Our Privacy Officer can be reached at privacy@yourkind.io during Singapore business hours.
17.6
United Arab Emirates. An individual may access, correct and port their Personal Information, object to direct marketing and to automated decisions, and ask us to restrict processing.
18 Contacting individuals
From time to time, we may send an individual important notices, such as changes to our terms, conditions and policies. Where such information is materially important to the individual’s interaction with us, they may not opt out of receiving these communications.
19 Contacting us
19.1
All correspondence with regards to privacy should be addressed to:
Privacy Officer
YourKind Pty Ltd
privacy@yourkind.io
19.2
An individual may contact the Privacy Officer via email in the first instance. Our postal address is 1/1 Jamison St, Sydney NSW 2000, Australia.
20 Additions to this policy
20.1
This policy is effective from 1 July 2024 and was last updated on 1 July 2026. If we decide to change this Privacy Policy, we will post the changes on our webpage at https://www.yourkind.io/policies/privacy. If a change is material we will notify individuals by email or in the app before it takes effect. Please refer back to this Privacy Policy to review any amendments. Previous versions are available on request.
20.2
We may do things in addition to what is stated in this Privacy Policy to comply with the Australian Privacy Principles and the GDPR, and nothing in this Privacy Policy shall deem us to have not complied with the Australian Privacy Principles and the GDPR.
Contact
For general enquiries, please contact our team.