Privacy Policy

October 2021

Introduction

  1. R.T. LegacySpirit Distilling Co. Pty. Ltd. (LegacySpirit Co) is committed to respecting the privacy of your personal information. This Privacy Policy explains how we deal with your personal information that we collect, use, disclose or process.
  2. We will update this Privacy Policy from time to time when we change how we deal with personal information. We will post any changes to the Privacy Policy on our website, and will endeavour to notify you when this occurs.
  3. In addition to the provisions of this Privacy Policy, there may also be specific and additional privacy and consent provisions that apply to certain collection channels of personal information. Because those specific and additional provisions also relate to your privacy protection, we recommend that you review them wherever they appear. In the event of any inconsistency between the provisions of this Privacy Policy and those other specific and additional provisions, the specific and additional provisions will prevail.

Definition of personal information

  1. Throughout this Privacy Policy, we use the term ‘personal information’ to refer to information relating to an identified or identifiable natural person, including information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether the information or opinion is true or not; and whether the information or opinion is recorded in a material form or not. For example, your full name, date of birth, address, mobile telephone number, email address and credit card details are examples of information which may constitute personal information. Personal information may also include information we may collect about your individual preferences.

Problems, complaints or queries

  1. If you have any questions about our Privacy Policy, or any problems or complaints about how we have collected, used, stored, handled, disclosed and/or processed your personal information, please contact our privacy officer via one of the following channels:

For individuals in Australia:

Mail:
Privacy Officer
R.T. LegacySpirit Distilling Co. Pty. Ltd.
(Trading as Legacy Spirit Co)
PO Box 185
Altona, Victoria, Australia 3018

Email:

 

  1. Please allow 30 days for this request to be processed. On receipt of your query, problem or complaint a review will be conducted and findings will be communicated to you where required. If you do not receive a satisfactory response to your query, problem or complaint within 30 days, you may refer your query, problem or complaint to the Office of the Australian Information Commissioner via the contact details listed at www.oaic.gov.au/about-us/contact-us-page, or, for individuals in the EU, to the data protection supervisory authority in your country.

On what basis do we process your data?

Lawful basis of processing

  1. LegacySpirit Co will only collect, monitor, use, disclose, or process any personal information about you with your consent (which we endeavour to obtain at the same time as collecting your personal information) or if it is otherwise lawful to do so. The only personal information collected by us is what has been provided to or collected by us in accordance with this Privacy Policy or has been provided to us lawfully by third parties. We will generally deal with your personal information for the primary purposes set out in this Privacy Policy.
  2. For individuals in the European Union, LegacySpirit Co may also rely on the lawful bases of contract and legitimate interest. That is, where you enter into a contract with us, LegacySpirit Co will process your personal information because it is necessary for the performance of that contract with you. In some circumstances, such as fraud prevention, LegacySpirit Co may also have a legitimate commercial interest in processing your personal information that is not outweighed by your interests, rights and freedoms. LegacySpirit Co may also request your explicit consent to process your personal data from time to time for various purposes.
  3. LegacySpirit Co also reserves the right to use, disclose or otherwise process any personal information to satisfy any law, regulation or legal request, or in relation to LegacySpirit Co’s other legitimate interests such as where that personal information is relevant to legal action relating to LegacySpirit Co).

When and How do we collect Personal Information?

Collection channels

  1. We (or our subcontractors) collect and combine personal information in a number of ways through the following channels (each, a Collection Channel):
    1. our online properties (here and after, each a “Website”), including:
      1. our websites, including but not limited to www.legacyspiritco.com.au;
      2. any related LegacySpirit Co website, social media page, internal website, intranet and any LegacySpirit Co mobile or tablet applications;
    2. our service providers acting on behalf of us (including but not limited to Eventbrite and Pozible), or other legitimate third party sources;
    3. physical and other ad-hoc channels of collecting personal information in relation to events and the LegacySpirit Co distilleries (such as through paper forms or tablets); and
    4. any other means through which an individual provides personal information to LegacySpirit Co, including either physically or electronically.

Active Information Collection

  1. Personal information may be collected and combined via our Collection Channels if you:
    1. you purchase products either as a “guest” or a “member” through a Collection Channel, or create an account with LegacySpirit Co through a Collection Channel;
    2. subscribe to any newsletters, updates, alerts or news and media releases, or request launch or event information or information about our products or services or other information services as well as third party products or services;
    3. have previously provided us with personal information prior to this Privacy Policy coming into effect, either directly from you personally or via a third party;
    4. complete and submit any forms or surveys provided to LegacySpirit Co, either physically or electronically;
    5. conspicuously publish or provide on request your personal information to LegacySpirit Co;
    6. contact us or our clients directly in person or via any medium including mail, telephone, social media and commercial electronic messages (SMS (Short Message Service), MMS (Multimedia Message Service), IM (Instant Messaging) and email) including via the contact details listed on a Website;
    7. participate in any events, offers, promotions, competitions or marketing activities;
    8. interact with a Website for a specific purpose; or
    9. interact with or browse a Website generally.
  2. We also collect your information through other legitimate third party sources including list brokers, social media organisations, and other data providers or organisations that share data in circumstances where it is lawful and/or you have given permission for them to do so.
  3. We may collect personal information from you in a passive manner including through the use of cookies and other tracking tools such as internet tags, tracking pixels, web beacons and unique device identifiers. For further information about the use of passive personal information collection, see paragraph 35 below.

What kind of Personal Information DO we collect?

  1. We may collect personal information including:
    1. your full name, contact details (such as your email address, phone number, and contact preferences), location, and passwords you create for the LegacySpirit Co website;
    2. information about your preferences, interests, opinions, feedback and experiences with our products or services. This information is collected in order to tailor our communications to you and continuously improve our products and services;
    3. financial details, if you have provided them to us, such as your bank account, credit card, Paypal or other online payment system details (where you purchase any products or services from us);
    4. When you visit the LegacySpirit Co website, we may also collect personal information about you in the following general categories:
      1. usage and preference information: we collect information about how you interact with the LegacySpirit Co website, including the pages you visit, your preferences and settings that you choose. We may do this through the use of cookies and other similar technologies that uniquely identify you;
      2. device information: we may collect information about your mobile device such as the hardware model, operating system, preferred language, unique device identifier and mobile network; and
  • other information: we may also collect and log information such as your IP address, access dates and times, browser type and pages visited when you interact with a website.
  1. any other personal information you provide directly to us. Where you provide us with unsolicited personal information, we will retain this information where it falls within our primary purposes for collection of personal information (as stated in this Privacy Policy).
  2. any other personal information requested or required by a Collection Channel.

Sensitive Information

  1. We do not seek to collect sensitive information (or “special categories” of information under the GDPR).
  2. If we do collect sensitive information, we will only do so with your consent and where you provide it to us directly. Where you provide us with any sensitive information (including, but not limited to, information about your sexual orientation, religious beliefs, medical and/or criminal history), we will only use this information for the purposes stated at the time of collection and will only share this information with our trusted third parties in the manner stated in this Privacy Policy.

Consequences of not providing personal information

17. If you don’t provide us with personal information, we may be unable to provide you with our goods and services or other content, information, upcoming opportunity, promotion, event or product information.

For what purposes do we collect, hold, use and disclose personal information?
18. Personal information that LegacySpirit Co collects will be used for the following primary purposes:

Special offers, marketing and advertising

a. where you have provided your separate consent, to provide you with early access to new releases, exclusive events, special offers, newsletters, events and promotions either of LegacySpirit Co or its trusted partners, and to otherwise market to you (with direct marketing materials), via any medium including mail, telephone, commercial electronic messages (such as SMS, MMS, instant messaging, email, social media, mobile applications), or any other form of electronic, emerging, digital or conventional communications channel.;

b. to provide you with relevant advertising;

Managing our relationship

c. to carry out any purchases you make and otherwise manage our commercial and trading relationship with you including identifying you in our system and contacting you, invoicing you correctly, sending you our products and to address your expectations of us in respect of how we conduct our business;

d. to ensure that your personal information remains up-to-date and complete;

e. to provide you with information about your LegacySpirit Co account, customer account, transactions, content, services and products;

f. to fulfil obligations in respect of any contract between you and LegacySpirit Co; to render services related to our LegacySpirit Co and customers (such as after sales services and enquiries); to facilitate payments from you;

g. to contact you, including sending you any technical, administrative or legal notices relevant to LegacySpirit Co or the LegacySpirit Co Websites;

h. to otherwise maintain our relationship with you;

LegacySpirit Co’s Website

i. to maintain the functionality of the LegacySpirit Co website, including the provision of information to you relating to the content available on the website; to improve the website and system administration;

Improving our offerings

j. to better understand and meet your needs and interests, to enable us to improve the nature of the goods and services we provide and to more accurately market our goods and services, and research our customers;

k. to obtain opinions or comments about products and/or services and to conduct other research and development;

l. to record statistical or de-identified data for analysis including marketing analysis;

m. to conduct market research including identifying likeminded individuals;

Miscellaneous

n. to share personal information with our group companies and their related bodies corporate and agents, and other trusted third parties in the manner described in this Privacy Policy;

o. for any further purposes stated in a particular Collection Channel;

p. where explicitly notified to you, to undertake recruitment for LegacySpirit Co;

q. to manage your employment with LegacySpirit Co (if applicable);

r. any other purpose as may be deemed reasonably necessary by LegacySpirit Co in the circumstances;

s. as needed to satisfy any law, regulation or legal request, to protect the rights or property of LegacySpirit Co, any member of the LegacySpirit Co group, or any member of the public, to protect the integrity of the LegacySpirit Co website, to fulfill your requests, or to cooperate in any law enforcement investigation or an investigation on a matter of public safety.

Contact by LegacySpirit Co

  1. LegacySpirit Co does not send advertising or marketing information without obtaining prior consent, for example the consent contained within this Privacy Policy. If you receive communications from LegacySpirit Co which you do not wish to receive, you may remove your name from the database either by using the functional unsubscribe facility (if the communication is via commercial electronic message) or by contacting LegacySpirit Co’s Privacy Officer as described above. Please allow 30 days for this request to be processed.
  2. Despite removing your name from the database from receiving future advertising and marketing information, LegacySpirit Co may send you non-commercial “Administrative Emails”. Administrative Emails relate to a LegacySpirit Co user account and may include administrative and transaction confirmations, requests and inquiries or information about a particular LegacySpirit Co user account. If you do not wish to receive such communications from LegacySpirit Co, you may remove your name from the database by contacting LegacySpirit Co’s Privacy Officer. Please allow 30 days for this request to be processed.

Automated decision-making

  1. LegacySpirit Co does not make decisions that produce significant effects on you which are solely based on automated decision making.
How do we share your personal information?
  1. Solely for the purposes described above, personal information may be shared with the entities below including their directors, servants and agents and related bodies corporate:
    1. our marketing and email sending partners;
    2. technical service providers, such as mail carriers, hosting providers, IT companies and communications agencies;
    3. other trusted service providers; and
    4. LegacySpirit Co group companies (if applicable).
  2. These recipients may be engaged by LegacySpirit Co to perform a variety of functions, such as legal and accounting services, data storage, support services, conducting market research, processing credit card payments, assisting with promotions and providing technical services for our websites. These companies may have access to personal information if needed to perform such functions. Your credit card details are only used to facilitate your purchase. They are not used for any other purpose and will never be supplied to a third party other than LegacySpirit Co or our relevant service provider. If you are a business we trade with, we may disclose your information to debt recovery agents or credit reporting bodies if necessary.
  3. Some of the recipients of your personal information may be located overseas. LegacySpirit Co employees, data processors and other trusted third parties are obliged to respect the confidentiality of any personal information held by LegacySpirit Co. However, security of communications over the Internet cannot be guaranteed, and therefore absolute assurance that information will be secure at all times cannot be given. LegacySpirit Co will not be held responsible for events arising from unauthorised access to personal information except to the extent required by the relevant privacy laws.
  4. The recipients of your personal information are located in countries including Australia, the United Kingdom and the United States.
  5. For individuals in the EU, please note that the recipients of your personal information may be located in countries in which the privacy or data protection laws differ from those of the European Union, and which are not the subject of an adequacy decision by the European Commission. For recipients of your personal information in Australia, appropriate or suitable safeguards over your personal data have been put in place by virtue of our compliance with the standard data protection contract clauses approved by the European Commission. Please contact our Privacy Officer for more information.

How do we hold, and how long do we hold your personal Information?

Security

  1. LegacySpirit Co takes appropriate security measures to keep personal information secure and to prevent unauthorised access, disclosure, modification or destruction of personal information. LegacySpirit Co, its employees and its subcontractors are obliged to respect the confidentiality of any personal information held by LegacySpirit Co.
  2. LegacySpirit Co also takes reasonable steps to keep personal information accurate, up to date, complete and relevant. LegacySpirit Co takes reasonable steps to ensure only those necessary have access to your personal information. Personal information is stored on secure servers that are protected in controlled facilities. This service may be performed on our behalf and data may be hosted by our selected data storage providers. In some cases these facilities may be overseas, as described above. LegacySpirit Co retains your information only for as long as necessary for the purposes listed in this Privacy Policy.

Your Privacy Rights

  1. You have a number of rights under the Australian Privacy Law and the GDPR. These include:
    1. (access) to request access to your personal information from us, in a commonly used electronic format. On a case by case basis, LegacySpirit Co may determine that it is not legally required to give an individual access to personal information, in which case LegacySpirit Co will provide you with a written notice of its refusal to provide access;
    2. (correction) to request that we correct your personal information;
    3. (withdrawing consent) to withdraw your consent for us to use your personal information. Please note that you can also opt-out of online marketing communications at any time by using the unsubscribe feature in each electronic commercial message;
    4. (transparency) to be informed generally about the collection and use of your personal data, including where we intend to further process your personal data for additional purposes other than as discussed above; and
    5. (complaint) to complain about a breach of the Australian Privacy Principles.
    6. (deletion) you may also request that we delete your personal information, and all reasonable steps to delete the information will be made, except where it is required for legal reasons. Deletion of information may result in LegacySpirit Co and its service providers or partners being unable to facilitate or provide you with information about certain transactions (including the uploading, access to, and receipt of content on a Website), other product content, or services information, upcoming promotion, competition or event information, and/or provide certain content, goods or services. Unless required by applicable law, we are not responsible for removing your personal information from the lists of any third party who has previously been provided your information in accordance with this policy.
  2. If you are an individual in the EU, you have additional rights under the GDPR that you can exercise against the “controller” of your data. Where we are the controller of your data, your rights include:
    1. (access) to request that we transfer your personal information to another service provider of your choosing;
    2. (erasure) to request that we erase your personal data. All reasonable steps to delete the information will be made, except where it is required for legal reasons. Deletion of information may result in us being unable to facilitate or provide you with information about certain services (including the uploading, access to, and receipt of content on a website or the LegacySpirit Co Application, and purchase transactions undertaken on a website);
    3. (objection and restriction) in some circumstances, to object to the use of your personal data by us and request that we restrict our use of your personal information; and
    4. (complaint) to lodge a complaint in relation to our processing of your personal data with a data protection supervisory authority under the GDPR.
  3. To exercise these rights, please contact us at the contact details listed at the beginning of this Privacy Policy. Please allow for a reasonable amount of time for us to process your request, which will generally be up to 30 days.

Miscellaneous

Anonymity and Pseudonymity

  1. Where practicable, LegacySpirit Co will allow you to deal with us on an anonymous or pseudonymous basis. If this is practicable, our collection channels will only seek information in this way. However, where it is not practicable for the purposes for which information is collected, we will seek the personal information identified above. It will not be practicable to deal with you on an anonymous or pseudonymous basis when we wish to send you direct marketing materials or need to provide you with goods or services requested by you.Sale of the company
  2. If LegacySpirit Co merges with, or is acquired by, another company, or sells all or a portion of its assets, your personal information may be disclosed to our advisers and any prospective purchaser’s adviser, and may be among the assets transferred. However, personal information will always remain subject to this Privacy Policy.Children
  3. The collection of personal information is neither intended for, nor directed to, persons who are under the age of eighteen (18) years old. Personal information will not be knowingly collected about any person who is known by LegacySpirit Co to be under the age of eighteen (18).Passive Information Collection
  4. As with many commercial websites (and mobile and tablet applications), we may also collect information which tells us about visitors to our websites. For example, we may collect information about the date, time and duration of visits and which pages of a website are most commonly accessed. This information is generally not linked to the identity of visitors, except where a website is accessed via links in an email we have sent or where we are able to uniquely identify the device or user accessing a website. By accessing a website via links in an email we have sent and/or by accessing a website generally including when you are logged into an account, you consent to the collection of such information where it is personal information.
  5. As you navigate through our websites, certain information can be passively collected (that is, gathered without you actively providing the information) using various technologies, such as Unique Device Identifiers (UDI), cookies, Internet tags or web beacons, and navigational data collection (log files, server logs, clickstream). In certain circumstances, this information may be considered anonymous information or personal information under the Privacy Act 1988 (Cth) and the GDPR, dependent on the device used and the method by which an individual connects to the Internet. Your Internet browser automatically transmits to the website you are browsing some of this anonymous information or personal information, such as the URL of the website you just came from, the Internet Protocol (IP) address, the UDI (if applicable) and the browser version your device is currently using. Our websites may also collect anonymous information or personal information from your device through cookies and Internet tags or web beacons. You may set your browser to notify you when a cookie is sent or to refuse cookies altogether, but certain features of a website might not work without cookies and this may limit the services provided by a website. Cookies and other technical methods may involve the transmission of information either directly to us or to another party authorised by us to collect information on our behalf.
  6. Our websites may use and combine such passively collected anonymous information or personal information and/or information from various third party sources, including as described above, and may combine this anonymous information or personal information with other personal information collected from you to provide better service to website visitors and users, customise a website based on your preferences, compile and analyse statistics and trends, provide you with relevant advertising when you visit a website or a third party website, and otherwise administer and improve a website for your use. We may combine your visitor session information or other information collected through tracking technologies with personally identifiable information from time to time in order to understand and measure your online experiences and to determine what products, promotions and services are likely to be of interest to you. By accessing a website, you consent to information about you being collected, compiled and used in this way.
  7. For more information about cookies and how you can opt out, you can visit www.youronlinechoices.com.au/.LegacySpirit Co and other websites
  8. Our websites may, from time to time, contain links to the websites of other organisations which may be of interest to you. Their inclusion cannot be taken to imply any endorsement or validation by us of the content of the third party website. Linked websites are responsible for their own privacy practices and you should check those websites for their respective privacy statements. LegacySpirit Co is not responsible, nor does it accept any liability, for the conduct of companies linked to our websites.
  9. We may use third party advertisements on our Websites. All third party advertising, if paid for, is paid for by the relevant third party advertisers and are not recommendations or endorsements by LegacySpirit Co or any of its affiliates. LegacySpirit Co is not responsible for the content (including representations) of any third party advertisement on a website. Cookies may be associated with these advertisements to enable the advertiser to track the number of anonymous users responding to the campaign. We do not have access to or control of cookies placed by third parties.

User submissions

  1. LegacySpirit Co may provide areas on a Website where you can upload user-generated content, post or provide information about yourself, communicate with other users, provide reviews for content, products and/or services or interact with or vote on particular content. This information may be shared with others and may be publicly posted on our Websites, including without limitation, other social media platforms and other public forums in which you choose to participate. This information may become publicly available and may be read, collected and used by others outside of our Websites. LegacySpirit Co is not responsible for the conduct of others who may read, collect and use this information.