Privacy Policy

Effective date: 1st day of December, 2023

www.suttongroup.net.au (the “Site”) is owned and operated by SUTTON ENGINEERING GROUP NSW
PTY LTD. SUTTON ENGINEERING GROUP NSW PTY LTD is the data controller and can be contacted at:

privacy@suttongroup.net.au
+61 02 9726 8600
25 Bent Street St Marys NSW 2760 Australia

SUTTON ENGINEERING GROUP NSW PTY LTD is committed to treating the personal information we
collect in accordance with the Australian Privacy Principles in the Privacy Act 1988 (Cth) (Privacy Act)
The purpose of this privacy policy (this “Privacy Policy”) is to inform users and visitors of our Site of
the following:

  1. The personal data we will collect;
  2. Use of collected data;
  3. Who has access to the data collected
  4. The rights of Site Users; and
  5. The Sites cookie policy

Overseas residents and overseas personal information transfer
If you are a resident of an overseas country (for example, a country in the European Union or the
United Kingdom), you may have additional or modified rights in relation to your personal
information in certain circumstances under GDPR, including deletion of your personal information or
receiving your personal information in a portable format.
To make a request to exercise any of these rights in relation to your personal information, please
contact our Privacy Officer / Data Protection Officer (details set out below) or via the contact us
form on our website.

Consent
By using our Site users agree that they consent to:

The conditions set out in this Privacy Policy.
When the legal basis for us processing your personal data is that you have provided your consent to
that processing, you may withdraw your consent at any time. If you withdraw your consent, it will
not make processing which we completed before you withdrew your consent unlawful.
You can withdraw your consent by Contacting the Data Protection Officer
privacy@suttongroup.net.au
+61 02 9726 8600
25 Bent Street St Marys NSW 2760 Australia

Personal Data We Collect
We only collect data that helps us achieve the purpose set out in this Privacy Policy. We will not
collect any additional data beyond the data listed below without notifying you first.

Data Collected Automatically
When you visit and use our Site, we may automatically collect and store the following information:

  1. IP address;
  2. Location;
  3. Hardware and software details;
  4. Clicked links; and
  5. Content viewed

Data Collected in a Non-Automatic Way

  • We may also collect the following data when you perform certain functions on our Site:
  • First and last name; and
  • Email address
  • This data may be collected using the following methods:
  • Contact Us Webform

How We Use Personal Data
Data collected on our Site will only be used for the purposes specified in this Privacy Policy or
indicated on the relevant pages of our Site. We will not use your data beyond what we disclose in
this Privacy Policy.
The data we collect automatically is used for the following purposes:

  • Google Analytics.

The data we collect when the user performs certain functions may be used for the following
purposes:

  • Communication.

Who We Share Personal Data With
Employees

We may disclose user data to any member of our organisation who reasonably needs access to user
data to achieve the purposes set out in this Privacy Policy.

  • Third Parties

We may share user data with the following third parties:

  • Google

We may share the following user data with third parties:

  • Links clicked while using site

We may share user data with third parties for the following purposes:

  • Statistics and Data Analysis

Third parties will not be able to access user data beyond what is reasonably necessary to achieve the
given purpose.

Other Disclosures
We will not sell or share your data with other third parties, except in the following cases:

a. If the law requires it;
b. If it is required for any legal proceeding;
c. To prove or protect our legal rights; and
d. To buyers or potential buyers of this company in the event that we seek to sell the
company.

If you follow hyperlinks from our Site to another Site, please note that we are not responsible for
and have no control over their privacy policies and practices.

How Long We Store Personal Data
We try to retain your personal information for only as long as is necessary for the purpose for which
that personal information was collected and to the extent permitted by applicable laws. When we
no longer need to use personal information, we will remove it from our systems and records and/or
take steps to anonymise it so you can no longer be identified from it.

How We Protect Your Personal Data
We use reasonable organisational, technical, and administrative measures and security safeguards
to collect and protect, as is reasonable in the circumstances, the personal information we hold from
misuse, loss, interference and/or unauthorised access, use, disclosure, or alteration of information
under our control. Where practicable, we implement measures to require organisations to whom
disclosure is made to comply with applicable data protection and privacy laws. If a third party is
given access to personal information, we take reasonable steps to ensure that the information is
held securely and used only for the purpose of providing the relevant service or activity.
Unfortunately, no data transmission over the internet or data storage system can be guaranteed to
be 100% secure. While we take all reasonable precautions to ensure that user data is secure and
that users are protected, there always remains the risk of harm. The Internet as a whole can be
insecure at times and therefore we are unable to guarantee the security of user data beyond what is
reasonably practical.

Children
We do not knowingly collect or use personal data from children under 16 years of age. If we learn
that we have collected personal data from a child under 16 years of age, the personal data will be
deleted as soon as possible. If a child under 16 years of age has provided us with personal data their
parent or guardian may contact our data protection officer.

How to Access, Modify, Delete, or Challenge the Data Collected
If you would like to know if we have collected your personal data, how we have used your personal
data, if we have disclosed your personal data and to who we disclosed your personal data, if you
would like your data to be deleted or modified in any way, or if you would like to exercise any of
your other rights under the GDPR, please contact our data protection officer here:

Data Protection Officer
privacy@suttongroup.net.au
+61 02 9726 8600
25 Bent Street St Marys NSW 2760 Australia

How to Opt-Out of Data Collection, Use or Disclosure
In addition to the method(s) described in the How to Access, Modify, Delete, or Challenge the Data
Collected section, we provide the following specific opt-out methods for the forms of collection, use,
or disclosure of your personal data specified below:

  • You can opt-out of the use of your personal data for marketing emails. You can opt-out by clicking “unsubscribe” on the bottom of any marketing email.

Cookie Policy
A cookie is a small file, stored on a user’s hard drive by a website. Its purpose is to collect data
relating to the user’s browsing habits. You can choose to be notified each time a cookie is
transmitted. You can also choose to disable cookies entirely in your internet browser, but this may
decrease the quality of your user experience.

a) Functional cookies – Functional cookies are used to remember the selections you make on
our Site so that your selections are saved for your next visits;
b) Analytical cookies – Analytical cookies allow us to improve the design and functionality of our
Site by collecting data on how you access our Site, for example data on the content you
access, how long you stay on our Site, etc; and
c) Third Party cookies – Third-party cookies are created by a website other than ours. We may
use third-party cookies to achieve the following purposes: Statistics and Analysis

Modifications
This Privacy Policy may be amended from time to time in order to maintain compliance with the law
and to reflect any changes to our data collection process. When we amend this Privacy Policy we will
update the “Effective Date” at the top of this Privacy Policy. We recommend that our users
periodically review our Privacy Policy to ensure that they are notified of any updates. If necessary,
we may notify users by email of changes to this Privacy Policy.

Complaints
If you have any complaints about how we process your personal data, please contact us through the
contact methods listed in the Contact Information section so that we can, where possible, resolve
the issue. If you feel we have not addressed your concern in a satisfactory manner you may contact
a supervisory authority. You also have the right to directly make a complaint to a supervisory
authority. You can lodge a complaint with a supervisory authority by contacting the Office of the
Australian Information Commissioner.

Contact Information
If you have any questions, concerns or complaints, you can contact our data protection officer, Data
Protection Officer, at:

privacy@suttongroup.net.au
+61 02 9726 8600
25 Bent Street St Marys NSW 2760 Australia