Skip to main content

Privacy Policy


1. Introduction


We value your trust so it’s important to us that we are transparent about how we use information from and about you. This Privacy Policy explains how and why we collect and handle personal information about you.


We are committed to making your experiences with us better, easier and more enjoyable. The information (including, in some cases, personal information) that we gather from your interactions with us helps us to better understand and influence how we:


  • shape our services to meet your changing needs and expectations;


  • support our customers to help them deliver an improved offering to you.



We will update this Privacy Policy to explain changes in our information handling practices from time to time. Please keep an eye on our website for updates. 


Please contact our privacy team using the contact details provided at the end of this policy if you, or a person you assist, would like:


  • further information about our handling of personal information; or


  • the information in this Privacy Policy explained to them or provided in a different format.



Who are we?


Hyper Galaxy Pty Ltd ('Hyper Galaxy', 'we', 'our') is a leading IT infrastructure company which owns, develops and manages IT infrastructure across Australia. Hyper Galaxy is made up of Hyper Galaxy Pty Ltd ABN 63 681 083 705.



Who is this Privacy Policy for?


This Privacy Policy describes how we collect and handle the personal information of our customers, digital services users, service providers and job applicants.


Personal information generally refers to information which identifies you or from which you are reasonably identifiable. This can include your name, address, phone number, email address, date of birth, as well as in some circumstances photos and videos of you.



We generally collect personal information from you so that we can:


  • provide you with our services or obtain services from you;


  • operate our digital services, including through the use of apps (which you may download), device/website/app tracking and the logging of security, health and safety incidents;


  • respond to complaints, queries, feedback and disputes;


  • tailor our digital offerings to your activities, preferences and needs; and


  • conduct market research to obtain your feedback on your experiences with us.



If you contact us in person, via our websites or apps or by phone, email, letter or other communication, we collect your personal information so that we can provide you with an appropriate response, address any complaints, queries or feedback which you raise and maintain records of our communications. We also monitor your communications with us for security, dispute resolution and training purposes.


We collect sensitive information, such as:


  • health information, where required, for managing compliance with our health and safety obligations and responding to health and safety risks and incidents


  • criminal offence details as part of employment screening and where individuals have committed, or are suspected of, criminal offences at our locations.


We also directly or through our service providers de-identify and aggregate information for the purpose of conducting visitor behavioural analytics to better understand and report on the experiences, demographics and interests of our users, including the locations, app features and website pages that are most popular with our users and customers.



2. Digital Services and App Users


When you access our WiFi or electronic communications ('Digital Services'), the kinds of information (including, in some cases, personal information) which we may collect both directly and through our service providers include:


  • your name, month and year of birth, gender, postcode, country of residence, email and mobile number;


  • your location information, including dates, times and locations from which you access our Digital Services 


  • additional information, such as your photos and posts when you share this information with us through our social media pages, mobile applications or websites; and


  • data about your use of these services including information about what parts of these services you access, what type of device you use to access them, your IP address, your device ID, the dates and times at which you use these services and usage data collected through certain website and application monitoring tools.


We also collect information about your usage of our Digital Services by using cookie files and other tracking technology in, and in relation to, our Digital Services. Tracking technologies can be used for a variety of purposes, such as:


  • system administration and to manage site security and store information about the type of browser and type of device being used.


You can accept or reject cookies by changing the relevant settings associated with your browser.  However, if you decline cookies, you may be unable to access some parts of our websites.


We also collect information relating to other unique identifiers such as Flash cookies (also known as local stored objects), IP addresses and device identifiers that help us understand device and browser interactions, and activity on our websites and in our centres.


You can unsubscribe from our email and SMS marketing by following the steps specified in any communications we send to you.  You can turn off targeted ad features in third party platforms by following the relevant third party platform provider's instructions, for example by turning off Personalized Ads in Google.



We and our service providers offer WiFi services if you choose join the Wifi System.


We collect from your use of our WiFi:


  • MAC address, device ID, IP address assigned to the device, type of device and type of web browser you are using;


  • the dates, times and locations from which you access our WiFi


  • the websites which you access using our WiFi


We use this information in combination with other information which we collect to improve our services as well as:


  • manage the security of our networks; and


  • to identify, or assist law enforcement or government bodies in identifying, persons that are suspected of committing offences or who are being monitored for public health and safety management purposes;


  • when permitted or required by law



3. Service Providers


If you or a company which you work for provides goods or services to us, we collect personal information in order to manage our relationship with you, including for the purposes of registering your visits to our locations as well as managing onboarding, health and safety checks and compliance processes which apply to our service providers.


The kinds of personal information which we collect from you if you are service provider personnel may include:


  • name, address, date of birth, contact details and employment screening results (including reference, background, criminal record and eligibility to work checks);


  • insurance details as well as information on licences, permits and  qualifications which you possess;


  • information about your financial standing and business experience;


  • health and safety screening results from your onboarding/site questionnaire responses.


We collect this personal information directly from you and from others, such as your representatives, referees, current and previous employers, professional and trade associations as well as law enforcement agencies, employment screening providers and publicly available sources such as LinkedIn.



4. Job Applicants


If you apply to work with us, we collect the information which we require to consider your application for employment, consider and contact you about other positions and manage our employment relationship with you if you are successful in becoming a member of our team.


The kinds of personal information which we collect when you apply for employment with us includes:


  • your name, address, date of birth and contact details;


  • work experience, qualifications, employment history and resume;


  • tax file number and bank account details; and


  • employment screening results (including reference, background, criminal record and eligibility to work checks).


We collect this information directly from you as well as from others, such as our representatives, referees, academic institutions, current and previous employers, professional and trade associations as well as law enforcement agencies and publicly available sources such as LinkedIn.



5. Further Information and Your Rights


From whom do we collect your personal information?

We may collect your personal information directly from you or from third parties, such as:


  • our service providers;


  • our related entities;


  • our joint venture partners; and


  • from public registers.


We also collect information which does not identify you from third parties, such as from data businesses and public sources, such as Census data.


We may share your personal information with third parties, including:


  • our service providers who assist us with:


  • developments, technology services, marketing, communications, research and analytics;


  • business advisory services (including recruitment, legal, accounting and audit);


  •  utilities, and security services;


  • call centre, contract management and administrative services, including mailing, delivery and archiving services; and


  • insurance, banking, payment processing and debt collection services;


  • with other users of our websites, apps or social media channels where you have chosen to share your personal information with those users through your use of that service;


  • with brokers, agents and advisers and persons acting on your behalf for example, a custodian, asset consultant or person who holds a power of attorney;


  • with our related entities, joint venture partners for whom we provide services as well as to prospective buyers of our business;


  • with regulatory bodies, governmental agencies, law enforcement bodies or courts where necessary in order to report actual or suspected offences, illegal or fraudulent activity to police or other enforcement agencies as well as to meet our legal and regulatory obligations, including in order to respond to warrants and other lawful information requests from courts as well as protect our lawful interests; and


  • as otherwise permitted or required by law.



Overseas disclosures


Generally, we use systems and services in Australia, however some of our investment activity and service providers are located overseas.


Some of our technology service providers also provide services, for example, hosting of our data in countries outside of Australia.


How do we store and protect your personal information?

We store personal information both electronically and in hard copy form, both at our premises and with the assistance of our service providers, including several cloud service providers. We have a number of security controls which we apply in relation to our people, processes and technology including:


  • internal data handling processes;


  • access controls; and


  • reasonable IT network security measures such as intrusion detection systems and protective security software applications.


However, no data transmission or storage on the internet can be guaranteed as completely secure.  While we strive to protect our data and are continually reviewing our security systems to improve them, we cannot ensure and do not warrant the absolute security of the data we collect.


Data breach response


Please notify us immediately if you become aware of any misuse, interference or loss or any unauthorised access, modification or disclosure of personal information held by us ('Data Breach') or any other security incident affecting data held by us using the contact details provided at the end of this policy.


If we become aware of a Data Breach, we will promptly investigate the incident, and take reasonable steps to contain and remedy the breach.  To help you maintain the security of your personal information, we will take steps to notify you as soon as practicable if we believe that the Data Breach would likely result in serious harm to you.  Where possible, we will provide you with recommendations on the steps that you can take in response to the breach.


After investigating a Data Breach, we may disclose information to the Office of the Australian Information Commissioner and to law enforcement agencies about the incident in order to comply with our reporting obligations under the Privacy Act, and to enable the Office of the Australian Information Commissioner and law enforcement agencies to assess and investigate the incident.


How can you seek access, correction or updates to the personal information which we hold about you?


If you are a customer, service provider or job applicant, you can seek access, correction or updates to personal information which we hold about you by contacting our privacy team using the details provided at the end of this policy.


There is no fee charged by Hyper Galaxy for accessing your information. We endeavour to respond to your access request within 30 days of receiving the request. Before we give you access to information, we will need to confirm you are appropriately authorised to access the information, which may include an identity verification process. In certain circumstances we are allowed to deny your access request or limit the access we provide. For example, we may not provide you with access to records which contain the personal information of others.


It is also important that we have your correct details, such as your current address and telephone number. You can ask us to correct any inaccurate information we hold or have provided to others by contacting us. If the information that is corrected is information we have provided to others, you can ask us to notify them of the correction. We don’t charge a fee for these requests. If we’re able to correct your information, we’ll inform you when the process is complete. If we disagree with the request to correct, we’ll let you know in writing and include our reasons. You may ask us to add a note of your correction request to the information we hold about you.


How can I make a complaint?


If you have a concern or complaint about our handling of your personal information, please contact our Privacy Officer using the details provided at the end of this policy. We’ll review your situation and work towards resolving it within a reasonable timeframe.


We acknowledge every complaint we receive, provide contact details of the investigating officer and keep you updated on the progress we’re making towards investigating the complaint.


Usually, it takes only a few days to investigate a complaint. However, if we’re unable to provide a final response within 30 days we’ll contact you to explain why and discuss an appropriate timeframe to investigate the complaint.


If you’re not satisfied with our handling of your matter, please let us know using the contact details below so we can ensure that you are given the benefit of our complaint processes.


If you are still not satisfied with the response, you can contact the Office of the Australian Information Commissioner by:


Post

Office of the Australian Information Commissioner

GPO Box 5218

Sydney NSW 2001


 1300 363 992


oaic.gov.au


How can I contact the Hyper Galaxy privacy team?

For privacy related queries, access or correction requests, or complaints, please contact our Privacy Officer at:


Email:

privacy@hypergalaxy.com.au


Phone:

+61 419 035 845 Monday to Friday between 9.00am and 5.00pm Melbourne time


Post:

Privacy Officer

Hyper Galaxy

PO Box 247

South Yarra VIC 3141


How can I get further information about privacy?


For more information about privacy generally, you can also refer to the website for the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au or contact the OAIC using the contact details provided in the “How can I make a complaint?” section above.


6. Contact us


For any enquiries please contact our Privacy Officer.


Email:

privacy@hypergalaxy.com.au


Phone:

+61 419 035 845


Post:

Privacy Officer

Hyper Galaxy

PO Box 247

South Yarra VIC 3141