About this policy
This policy explains how OZI HYGIENE & PACKAGING PTY LTD (ABN 80 639 900 520), trading as OZI Hygiene & Packaging (“we”, “us”, “our”), handles personal information. It covers this website, our customer portal at portal.ozihp.com.au, the emails we send, and the information we hold to supply and invoice our customers.
We handle personal information in line with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. Personal information is information about an identified individual, or an individual who is reasonably identifiable.
In short: we collect what we need to quote, supply, deliver and invoice your business. We do not sell personal information, this website does not use cookies or analytics, and you can ask to see or correct what we hold about you at any time.
What we collect
Most of our customers are businesses. The personal information we hold is usually about the people who work in them.
When you send an enquiry
Your name, business name, email address, phone number if you give it, the range you are interested in, and your message.
When you open or hold an account
- Contact names, roles, email addresses and phone numbers for the people we deal with, including who should receive invoices.
- Business details such as trading name, ABN or ACN, billing and delivery addresses, delivery instructions and opening hours.
- Your order history, invoices, statements, payments received and account balance.
- Your customer portal sign-in email. Your password is stored only as a one-way hash, so nobody at OZI Hygiene & Packaging can read it.
When you apply for a trade credit account
The information on your credit application. Depending on the application, this can include details about directors, owners or guarantors and trade references. If we intend to obtain a credit report about an individual, we will tell you and ask for consent first.
When you use our website or portal
Our servers keep standard technical logs: IP address, browser type, the page requested and the time. We use these to keep the services running and secure, not to profile visitors.
What we do not collect
We do not ask for sensitive information such as health information, and we do not ask for or store credit or debit card numbers on this website or in the customer portal.
How we collect it
We collect personal information:
- directly from you, when you fill in a form, place an order, call us, email us or use the customer portal;
- from the business you work for, when it gives us your details as a contact on its account; and
- from third parties you have authorised, such as the trade references on a credit application.
You can make a general enquiry without telling us who you are, or by using a pseudonym. We cannot open an account, supply goods on credit or deliver an order without knowing who we are dealing with.
How we use it
We use personal information to:
- answer enquiries and prepare quotes;
- set up and manage customer accounts and portal access;
- process, pick, deliver and invoice orders, and send order confirmations, invoices and statements;
- assess applications for trade credit and manage accounts on credit, including following up overdue amounts;
- keep our systems secure, including resetting passwords and investigating misuse;
- keep the business records Australian law requires us to keep; and
- tell you about products or changes that are relevant to your account, if you have agreed to hear from us.
We do not use personal information for any other purpose unless you agree, you would reasonably expect it, or the law requires or permits it.
Cookies and browser storage
This website does not set cookies and does not use analytics, advertising or tracking tools.
The customer portalstores a sign-in token in your browser’s local storage so you stay signed in between pages. It is used only to identify your session to our server. Signing out removes it, and clearing your browser data has the same effect.
If we add analytics or any other tracking in future, this section will say so before it goes live.
Who we share it with
We share personal information only where it is needed to run the business:
- with the service providers listed in the next section, who store or process it on our behalf;
- with couriers and delivery contractors, limited to what they need to deliver an order;
- with our accountants, auditors, insurers and legal advisers; and
- where the law requires or authorises it, such as to a court or a government agency.
We do not sell, rent or trade personal information, and we do not give it to anyone for their own marketing.
Service providers and overseas storage
Our website, customer portal and order management system are hosted in Sydney. Some of the services we rely on store or process information outside Australia:
| Provider | What it does for us | Where |
|---|---|---|
| DigitalOcean | Hosts this website, the customer portal and our order management system | Sydney, Australia |
| Backblaze | Stores our nightly database backups | United States |
| Resend | Delivers the emails we send, such as invoices, statements, order confirmations and password resets | United States |
| Google Workspace | Hosts our business email inbox | Google data centres, which may include the United States |
| Xero | Our accounting system, which issues invoices and records payments | Xero data centres, which may include the United States |
We choose providers that publish their own security and privacy commitments, and we take reasonable steps to make sure they handle personal information consistently with the Australian Privacy Principles. We will update this list if the providers we use change.
Emails we send
Most of the email we send is part of supplying you: order confirmations, invoices, statements, portal invitations and password resets. These go to the contacts on your account and do not carry an unsubscribe link, because they are part of the service rather than marketing.
We send marketing email only to people who have agreed to receive it. Every marketing email identifies us and includes a way to unsubscribe, as the Spam Act 2003 (Cth) requires, and we act on an unsubscribe request within five business days.
How we protect it
- Everything travels over encrypted connections (HTTPS).
- Passwords are stored as one-way hashes, never in readable form.
- Staff access to our systems is by individual account, and each account can reach only the parts of the system that person’s role needs.
- Our database is backed up every night, so information is not lost if a server fails.
No system is perfectly secure. If a data breach is likely to result in serious harm to anyone, we will notify the people affected and the Office of the Australian Information Commissioner as the Notifiable Data Breaches scheme requires.
How long we keep it
We keep account, order and invoice records for as long as you are a customer and afterwards for as long as the law requires: at least five years under Australian tax law, and up to seven years for financial records.
Enquiries that do not lead to an account are kept only as long as we need them to follow up. When we no longer need personal information and are not required to keep it, we delete it or make it anonymous.
Accessing and correcting your information
You can ask for a copy of the personal information we hold about you, or ask us to correct it, at any time. Account customers can update many of their own details in the customer portal.
Contact us using the details at the end of this page. We will confirm who you are, and respond within 30 days. There is no charge to make a request. If we cannot give you access or make a correction, we will tell you why in writing.
Complaints
If you think we have mishandled your personal information, please tell us first using the contact details below, with enough detail for us to look into it. We will acknowledge your complaint promptly and aim to resolve it within 30 days.
If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au or on 1300 363 992.
Changes to this policy
We will update this policy when the way we handle personal information changes. The date at the top of the page shows when it last changed. If a change is significant, we will also tell account customers by email. This policy should be read with our terms of trade and website terms of use.