privacy policy

Effective date: 17 July 2020
Last updated: 20 July 2021

1. About this Privacy Policy

This Privacy Policy explains how LupoTek collects, holds, uses, discloses, protects and otherwise handles personal information.

In this Policy:

  • “LupoTek”, “we”, “us” and “our” refer to the Australian organisation operating under the LupoTek name and responsible for the website at www.lupotek.org;

  • “Site” means www.lupotek.org and any associated webpages, forms, portals, stores or digital properties operated by LupoTek;

  • “Services” includes the Site, research and development activities, programs, recruitment activities, partner and supplier engagements, expressions of interest, online accounts, store activities, communications and any products or services that LupoTek may make available; and

  • “personal information” means information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether or not the information is true or recorded in a material form.

Jurisdiction: Canberra, Australian Capital Territory, Australia.

This Policy is intended to reflect the requirements of the Privacy Act 1988 (Cth) and the Australian Privacy Principles, to the extent they apply to LupoTek. Other privacy or data-protection laws may apply to particular activities, individuals or jurisdictions.

Where LupoTek handles information for an enterprise, government, research or other customer under a written agreement, LupoTek may act as a service provider or data processor rather than determining the purposes for which the information is handled. In those circumstances, the relevant contract, privacy notice or data-processing terms may also apply.

This Policy describes LupoTek’s information-handling practices. It does not create a contract, warranty, guarantee or legally enforceable promise beyond any rights or obligations imposed by applicable law.

Nothing in this Policy excludes, restricts or modifies any right, remedy, guarantee or obligation that cannot lawfully be excluded, restricted or modified.

2. Scope of this Policy

This Policy applies when an individual:

  • visits or interacts with the Site;

  • contacts LupoTek by email, form, telephone, post, social media or another communication channel;

  • creates or uses an account or portal;

  • purchases or enquires about a product;

  • applies for employment, an internship, a placement or another opportunity;

  • submits an expression of interest, partnership proposal, supplier submission or capabilities statement;

  • participates in a meeting, event, research activity, evaluation, trial or program;

  • acts for a customer, supplier, adviser, partner, government body, research institution or other organisation;

  • enters into, or discusses, a commercial or professional relationship with LupoTek; or

  • otherwise provides personal information to LupoTek.

This Policy does not govern the independent privacy practices of third-party websites, platforms, payment providers, carriers or services that LupoTek does not control.

3. Personal information LupoTek may collect

The kinds of personal information collected depend on the nature of the interaction.

3.1 Identity and contact information

LupoTek may collect:

  • name;

  • title, role or position;

  • organisation or employer;

  • business or residential address;

  • email address;

  • telephone number;

  • country, state, territory or general location;

  • preferred contact method; and

  • signature or other identification information.

3.2 Organisational and professional information

LupoTek may collect information concerning:

  • employment history;

  • qualifications, licences and professional memberships;

  • technical experience and capabilities;

  • business responsibilities;

  • organisational affiliations;

  • professional interests;

  • project, research or industry experience;

  • supplier or contractor information;

  • references;

  • professional profiles and publicly available business information; and

  • authority to represent an organisation.

3.3 Recruitment and candidate information

Where an individual applies for employment, an internship, a placement, a contractor role or another opportunity, LupoTek may collect:

  • curriculum vitae or résumé information;

  • cover letters and application responses;

  • education and employment history;

  • portfolio materials, publications or work samples;

  • interview notes;

  • assessment and testing results;

  • referee details and references;

  • professional, academic or technical qualifications;

  • work rights, citizenship, residency or visa information;

  • availability and remuneration expectations;

  • identity-verification information;

  • information relevant to security, integrity or suitability checks;

  • information relevant to role-specific clearances or regulated work;

  • information concerning reasonable workplace or recruitment adjustments; and

  • other information reasonably relevant to the application.

Employment-related screening may include identity, qualification, reference, work-right, criminal-history, conflict, sanctions, security or other lawful checks where reasonably necessary for the relevant role.

Submitting an application does not guarantee an interview, offer, engagement, clearance, response or other outcome.

3.4 Account and access information

Where accounts, restricted portals or secure access facilities are available, LupoTek may collect:

  • username and account identifiers;

  • authentication records;

  • access permissions;

  • login dates and times;

  • password reset information;

  • multi-factor authentication information;

  • device and network information;

  • records of attempted or successful access; and

  • security, audit and activity logs.

LupoTek does not need to hold a user’s readable password where the relevant system stores passwords in another protected form.

3.5 Store, order and transaction information

Where products may be purchased or ordered, LupoTek may collect:

  • billing and delivery details;

  • product selections;

  • order and transaction identifiers;

  • payment status;

  • purchase history;

  • delivery instructions;

  • carrier and tracking information;

  • refund, return and cancellation information;

  • customer-service correspondence; and

  • information necessary to detect suspected fraud or misuse.

Where a third-party payment provider is used, payment credentials may be collected directly by that provider. LupoTek may receive limited payment and transaction information, such as the payer’s name, transaction reference, payment status, amount and payment method.

LupoTek does not ordinarily require a customer to send full payment-card details through an ordinary email or public enquiry form.

3.6 Communications and submissions

LupoTek may collect:

  • correspondence;

  • enquiries and support requests;

  • meeting records;

  • feedback;

  • survey responses;

  • complaints;

  • submitted proposals;

  • expressions of interest;

  • capability statements;

  • investor, partner, supplier or contractor submissions;

  • attachments and supporting documents; and

  • other information voluntarily communicated to LupoTek.

Business information is not necessarily personal information. However, business documents may contain personal information about directors, officers, employees, contractors, advisers or other individuals.

3.7 Technical, device and usage information

When an individual accesses the Site or another LupoTek system, information may be recorded automatically, including:

  • internet protocol address;

  • browser type and version;

  • device type;

  • operating system;

  • language and time-zone settings;

  • approximate location derived from an IP address;

  • referring and exit pages;

  • pages, products or content viewed;

  • links selected;

  • dates, times and duration of visits;

  • session and interaction information;

  • cookie and similar-technology identifiers;

  • error, diagnostic and performance information;

  • network and security events; and

  • suspected malicious, automated or unauthorised activity.

3.8 Images, audio and event information

Where appropriate, LupoTek may collect photographs, video, audio, attendance records or meeting recordings in connection with:

  • events;

  • demonstrations;

  • interviews;

  • facilities;

  • meetings;

  • research activities;

  • security arrangements; or

  • authorised communications.

Additional notice or consent may be sought where required.

3.9 Sensitive information

Sensitive information may include information concerning health, disability, racial or ethnic origin, political opinions, religious beliefs, sexual orientation, biometric information, professional or trade association membership, or criminal history.

LupoTek may collect sensitive information where:

  • the individual has consented and the information is reasonably necessary for a function or activity;

  • collection is required or authorised by law;

  • collection is necessary to establish, exercise or defend a legal claim;

  • collection is reasonably necessary for recruitment adjustments, safety, security, vetting or role suitability;

  • a permitted general situation or other legal exception applies; or

  • the information is otherwise lawfully provided and handled.

Individuals should not provide sensitive information unless it is relevant and reasonably necessary.

3.10 Government-related identifiers

LupoTek may collect government-related identifiers, such as passport, visa, driver licence or other identity-document details, where reasonably necessary for lawful identity, eligibility, security, transaction or employment purposes.

LupoTek does not adopt a government-related identifier as its own identifier except where permitted by law.

3.11 Inferences and assessments

LupoTek may create or record information derived from other information, including:

  • security or fraud indicators;

  • application assessments;

  • suitability, risk or eligibility assessments;

  • inferred preferences;

  • engagement history;

  • technical or professional evaluations; and

  • internal classifications or recommendations.

Such information is handled as personal information where it relates to an identified or reasonably identifiable individual.

4. How personal information is collected

LupoTek may collect personal information:

  • directly from the individual;

  • through the Site, forms, portals, accounts or store;

  • through email, telephone, meetings, interviews or correspondence;

  • from an organisation the individual represents;

  • from referees, recruiters, educational institutions or previous employers;

  • from customers, partners, advisers, suppliers or contractors;

  • from identity, qualification, security, sanctions, fraud or background-check providers;

  • from payment, delivery, hosting, analytics or technology providers;

  • from government authorities, regulators or lawful records;

  • from public registers, professional directories, publications, websites or social media;

  • through cookies, pixels, logs and similar technologies; and

  • through observation of interactions with LupoTek’s systems, personnel, premises or activities.

LupoTek generally seeks to collect personal information directly from the individual where reasonable and practicable.

5. Unsolicited personal information

LupoTek may receive personal information that it did not request.

Where unsolicited personal information is received, LupoTek may assess whether it could lawfully have collected the information. Where it could not have been lawfully collected and no legal requirement to retain it applies, LupoTek may take reasonable steps to destroy or de-identify it.

Unsolicited submissions may be screened, isolated, deleted, returned or referred for security or legal review where appropriate.

6. Purposes for which personal information may be used

LupoTek may collect, hold, use or disclose personal information for purposes including:

  • operating, administering, maintaining and securing the Site and Services;

  • responding to enquiries and communications;

  • evaluating partnership, supplier, research, customer or engagement proposals;

  • assessing applications for employment, internships, placements or other opportunities;

  • conducting lawful identity, reference, qualification, eligibility, security or background checks;

  • establishing and managing accounts and access permissions;

  • authenticating users and monitoring system access;

  • processing orders, payments, deliveries, returns or refunds;

  • providing information requested by an individual;

  • managing relationships with customers, suppliers, advisers, contractors and partners;

  • administering projects, research, programs, trials, events and engagements;

  • maintaining business, operational, legal and financial records;

  • preventing, detecting, investigating or responding to suspected fraud, cyber incidents, misuse, misconduct or unlawful activity;

  • protecting individuals, systems, intellectual property, facilities, assets and confidential information;

  • conducting audits, reviews, testing, analytics and quality assurance;

  • improving the functionality, accessibility, performance and security of the Site and Services;

  • managing insurance, risk, disputes and legal claims;

  • undertaking due diligence, restructuring or corporate transactions;

  • communicating operational, administrative, safety or security information;

  • sending permitted marketing or engagement communications;

  • complying with laws, court orders, regulatory requirements and lawful government requests; and

  • exercising or protecting LupoTek’s lawful rights and interests.

Personal information may also be used for a secondary purpose where:

  • the individual has consented;

  • the individual would reasonably expect the secondary use and it is related to the original purpose, or directly related in the case of sensitive information;

  • the use is required or authorised by law; or

  • another lawful exception applies.

7. Consequences of not providing information

Individuals may decline to provide requested personal information unless its provision is required by law or contract.

Depending on the circumstances, not providing requested information may mean that LupoTek is unable to:

  • respond to an enquiry;

  • verify identity or authority;

  • provide access to a system or facility;

  • assess an application or submission;

  • process an order or delivery;

  • carry out required due diligence;

  • establish or manage a relationship;

  • meet legal, security or contractual requirements; or

  • provide a requested product, service or opportunity.

8. Anonymity and pseudonymity

Where lawful and practicable, individuals may interact with LupoTek anonymously or by using a pseudonym.

Identification may be required where it is impracticable to deal anonymously, including for:

  • orders and deliveries;

  • payments and refunds;

  • employment applications;

  • account access;

  • identity, security or eligibility checks;

  • contractual matters;

  • legal or regulatory requirements; and

  • substantive partnership, supplier or commercial engagements.

9. Cookies and similar technologies

The Site may use cookies and similar technologies to support:

  • core site operation;

  • navigation and session management;

  • account and security functions;

  • shopping and transaction functions;

  • user preferences;

  • traffic and performance measurement;

  • analytics;

  • error detection;

  • fraud and abuse prevention; and

  • permitted personalisation or marketing.

Cookies may be:

  • strictly necessary, where required for the Site or a requested function to operate;

  • functional, where used to remember settings or improve features;

  • analytics or performance cookies, where used to understand site usage and performance; or

  • advertising or marketing cookies, where used for permitted communications, measurement or personalisation.

Where required by applicable law, non-essential cookies are used subject to the relevant consent settings.

Cookie preferences may be managed through any preference tool made available on the Site and, in many cases, through browser or device settings.

Blocking cookies may affect the operation or availability of some Site functions.

Third-party services may set or receive their own cookies or identifiers. Their handling of information is governed by their own terms and privacy notices.

10. Direct marketing and communications

LupoTek may use contact information to communicate about:

  • relevant programs, products, activities or events;

  • research or industry developments;

  • engagement opportunities;

  • store information;

  • organisational announcements; or

  • other matters reasonably connected with an existing relationship or enquiry.

Commercial electronic messages are sent only where permitted by applicable law.

Where required, communications include an unsubscribe or opt-out method. An individual may also request that direct-marketing communications stop by contacting LupoTek.

An opt-out does not prevent LupoTek from sending non-marketing communications that are reasonably necessary for an account, transaction, existing relationship.

LupoTek may retain limited suppression information to record and respect an opt-out request.

11. Disclosure of personal information

LupoTek may disclose personal information to:

  • entities or personnel involved in operating LupoTek activities;

  • authorised employees, officers, contractors and consultants;

  • website, cloud, hosting, communications and technology providers;

  • payment and transaction providers;

  • delivery, logistics and fulfilment providers;

  • analytics, cybersecurity, identity, fraud-prevention and support providers;

  • recruitment, assessment, reference and background-check providers;

  • insurers, auditors, accountants, lawyers and other professional advisers;

  • research institutions, project partners, customers or counterparties where relevant;

  • government bodies, law-enforcement agencies, courts and regulators;

  • parties involved in investigating suspected fraud, cyber incidents, threats or unlawful conduct;

  • actual or prospective parties to a merger, acquisition, financing, restructure, transfer or sale;

  • an organisation represented by the individual;

  • other parties authorised by the individual; and

  • other recipients where disclosure is required or authorised by law.

Access is limited where reasonably practicable to recipients who require the information for an authorised purpose.

Service providers may process personal information on LupoTek’s behalf or may independently handle information under their own privacy obligations.

LupoTek may disclose information without notice where notice is prohibited, impracticable, would prejudice an investigation, or is not required by law.

12. Overseas storage and disclosure

LupoTek operates from Australia but may use providers, advisers, contractors, carriers, counterparties or systems located outside Australia.

Personal information may therefore be stored in, accessed from or disclosed to overseas locations.

Depending on the service and interaction, likely locations may include:

  • Australia;

  • the United States of America;

  • the United Kingdom;

  • member states of the European Union or European Economic Area;

  • New Zealand;

  • Singapore; and

  • the country in which an individual, service provider, carrier, adviser, customer or counterparty is located.

Technology-provider locations and data-routing arrangements may change over time. It may not be practicable to identify every country in advance. Individuals may contact LupoTek for available information concerning the likely location of relevant recipients.

Where Australian Privacy Principle 8 or another cross-border requirement applies, LupoTek takes such steps as are reasonable in the circumstances before disclosing personal information overseas.

Those steps may include:

  • assessing the recipient and purpose;

  • limiting the information disclosed;

  • using contractual privacy and security terms;

  • applying access restrictions;

  • using recognised transfer terms where required; and

  • relying on another lawful cross-border mechanism.

Privacy laws and enforcement arrangements differ between countries. LupoTek does not represent or guarantee that an overseas jurisdiction provides protections identical to those available in Australia.

13. Automated tools and decision assistance

LupoTek may use computer programs, algorithms, artificial intelligence systems or other automated tools to assist with:

  • cybersecurity monitoring;

  • authentication and access control;

  • spam, malware and abuse detection;

  • fraud and transaction screening;

  • content and submission screening;

  • account or system-risk assessment;

  • recruitment administration or candidate triage;

  • partner, supplier or engagement assessments;

  • document classification;

  • service routing;

  • analytics; and

  • operational decision support.

Personal information used by these tools may include:

  • identity and contact information;

  • account and authentication information;

  • technical, device and usage information;

  • transaction information;

  • communications and submissions;

  • application and professional information;

  • identity, eligibility and verification information;

  • security and fraud indicators; and

  • information derived from those categories.

Automated tools may produce flags, rankings, classifications, recommendations, alerts, restrictions or referrals for further review.

Depending on the activity, an assisted or automated process may affect:

  • access to an account, portal, system or facility;

  • the progression of an application;

  • a transaction or order;

  • security controls;

  • eligibility for an opportunity; or

  • whether a matter is referred for further assessment.

The degree of human involvement depends on the nature, risk and context of the decision.

Where applicable law requires additional information, review rights, safeguards or notification concerning automated decision-making, LupoTek may provide that information in this Policy, a collection notice or another relevant notice.

Nothing in this section represents that a particular system is currently deployed or that any decision will be made in a particular manner.

14. Security of personal information

LupoTek takes reasonable technical, organisational and physical steps, having regard to the circumstances, to protect personal information from:

  • misuse;

  • interference;

  • loss;

  • unauthorised access;

  • unauthorised modification; and

  • unauthorised disclosure.

Measures may include:

  • access controls;

  • authentication;

  • encryption where appropriate;

  • network and endpoint protections;

  • logging and monitoring;

  • secure configuration;

  • vendor assessment;

  • confidentiality obligations;

  • personnel controls;

  • backup and recovery arrangements;

  • incident-response procedures;

  • information-handling restrictions; and

  • secure destruction or de-identification practices.

Security measures are selected according to factors including the sensitivity of the information, the relevant systems, foreseeable risks, available technology, legal requirements and reasonable implementation costs.

No website, transmission, storage system or security control is completely secure. LupoTek does not guarantee:

  • absolute security;

  • uninterrupted availability;

  • error-free systems;

  • prevention of every cyber incident;

  • successful delivery of every communication; or

  • recovery of every item of information.

Individuals are responsible for taking reasonable precautions when providing information, maintaining account credentials and using their own devices and networks.

15. Data incidents and notification

LupoTek may investigate suspected loss, unauthorised access, unauthorised disclosure or other compromise of personal information.

Depending on the circumstances, LupoTek may:

  • contain the incident;

  • preserve relevant evidence;

  • investigate the cause and scope;

  • assess the risk of harm;

  • take remediation measures;

  • engage advisers or specialist providers;

  • notify affected parties; and

  • notify regulators, law enforcement or other authorities.

Where the Notifiable Data Breaches scheme or another law applies, LupoTek makes notifications required by that law.

Not every security incident constitutes an eligible or legally notifiable data breach.

16. Retention and disposal

LupoTek retains personal information for as long as reasonably necessary for the purpose for which it was collected or for a related lawful purpose.

Retention periods may depend on:

  • the nature and sensitivity of the information;

  • the relevant relationship or activity;

  • security and operational requirements;

  • contractual requirements;

  • taxation, accounting, employment and corporate record obligations;

  • limitation periods;

  • disputes or anticipated legal proceedings;

  • regulatory, audit or insurance requirements;

  • fraud, misconduct or incident investigations; and

  • the need to preserve suppression, consent or access records.

Where personal information is no longer required and retention is not required or authorised by law, LupoTek may take reasonable steps to destroy or de-identify it.

Deletion from active systems may not immediately remove information from backups, logs, archives, legal holds or systems in which deletion is not reasonably practicable. Such information may remain protected and inaccessible for ordinary operational use until it is overwritten or otherwise removed.

De-identification reduces identification risk but may not eliminate every theoretical possibility of re-identification.

17. Access to personal information

An individual may request access to personal information that LupoTek holds about them.

A request should provide sufficient information to allow LupoTek to:

  • identify the individual;

  • locate the relevant information; and

  • understand the scope of the request.

LupoTek may require reasonable identity verification before providing access.

Access may be provided by:

  • supplying a copy;

  • allowing inspection;

  • providing a summary;

  • explaining the information; or

  • another appropriate method.

Access may be refused or limited where permitted or required by law, including where access would:

  • unreasonably affect another person’s privacy;

  • reveal confidential or commercially sensitive information;

  • reveal security-sensitive information;

  • prejudice an investigation;

  • be unlawful;

  • expose evaluative material in a manner protected by law;

  • pose a serious threat to life, health or safety; or

  • fall within another lawful exception.

Where required, LupoTek provides reasons for refusing access and information about available complaint mechanisms.

A reasonable charge may apply where permitted by law, but no charge applies merely for making an access request.

18. Correction and quality

LupoTek takes reasonable steps in the circumstances to maintain personal information that is accurate, up to date, complete, relevant and not misleading for the purpose for which it is used.

An individual may request correction of personal information held about them.

Where appropriate, LupoTek may:

  • correct or update the information;

  • add a statement requested by the individual;

  • notify relevant third parties of a correction; or

  • record a dispute concerning the accuracy of the information.

LupoTek may decline a correction request where permitted by law. Where required, reasons and available complaint options are provided.

19. Privacy enquiries and complaints

An individual who has a privacy question, concern or complaint may contact:

Privacy Contact
LupoTek
Canberra, Australian Capital Territory, Australia
Email: legal@lupotek.org

The communication should include:

  • the individual’s name and contact details;

  • a description of the issue;

  • relevant dates or interactions;

  • the information or conduct concerned; and

  • the outcome sought.

LupoTek may request additional information or identity verification where reasonably necessary.

Privacy complaints may be assessed by an appropriate person who was not directly responsible for the conduct complained about, where reasonably practicable.

LupoTek may:

  • acknowledge the complaint;

  • investigate the relevant circumstances;

  • consult relevant personnel or service providers;

  • request further information;

  • provide an outcome or explanation; and

  • take corrective or other action where appropriate.

Complaints are addressed within any period required by applicable law and otherwise within a reasonable period having regard to their nature and complexity.

If an individual is not satisfied with the outcome, they may be entitled to complain to the Office of the Australian Information Commissioner, or another regulator or dispute-resolution body with jurisdiction.

A regulator may expect the individual to raise the matter with LupoTek before accepting a complaint.

If the published email address is temporarily unavailable, an individual may use the current general contact method displayed on the Site.

20. Rights under overseas privacy laws

Individuals located outside Australia may have additional rights under laws applicable to their circumstances.

Depending on the relevant law, these may include rights to:

  • access personal information;

  • correct inaccurate information;

  • request deletion;

  • restrict processing;

  • object to certain processing;

  • withdraw consent;

  • receive portable data;

  • object to direct marketing;

  • complain to a local supervisory authority; or

  • obtain information concerning certain automated decisions.

These rights are not absolute and may be subject to legal exceptions.

LupoTek assesses requests under the law that applies to the relevant processing activity. The inclusion of this section does not represent that every overseas privacy law applies to LupoTek or every interaction with the Site.

Where processing is based on consent under an applicable law, withdrawal of consent does not affect processing lawfully undertaken before withdrawal.

21. Children and persons under 18

The Site and Services are intended primarily for adults and organisations.

LupoTek does not knowingly seek to collect personal information from children through ordinary website, recruitment, partnership or commercial interactions.

A person under 18 should not:

  • create an account;

  • submit an employment application;

  • make a purchase;

  • submit a partnership or investment enquiry; or

  • provide personal information

unless legally permitted and, where required, authorised by a parent or legal guardian.

If LupoTek becomes aware that personal information has been provided by a child in circumstances where it should not have been collected, LupoTek may take reasonable steps to delete, restrict or otherwise lawfully handle it.

22. Confidential, classified and restricted information

Public website forms, ordinary email and store functions must not be treated as secure channels for classified, export-controlled, operationally sensitive or otherwise restricted information.

Unless LupoTek has expressly authorised a specific secure channel in writing, individuals must not submit:

  • classified government information;

  • national-security information;

  • controlled technical data;

  • export-controlled information;

  • security credentials;

  • vulnerability details capable of enabling misuse;

  • private encryption keys;

  • passwords;

  • full payment-card credentials;

  • sensitive operational information;

  • personal information about another person without authority; or

  • information subject to confidentiality obligations that prohibit its disclosure.

A confidentiality statement placed on an unsolicited submission does not, by itself, create a confidentiality agreement or other obligation.

Formal confidentiality obligations apply only where established by law or an authorised written agreement.

LupoTek may isolate, delete, return, report or otherwise handle unsolicited restricted information as reasonably necessary for security, legal or operational purposes.

23. Third-party websites and services

The Site may contain links to third-party websites, platforms, social media pages, payment services, carriers or other resources.

LupoTek does not control the privacy, security, availability or content practices of independent third parties and does not make representations or guarantees concerning them.

Individuals should review the applicable third-party privacy policy before providing information.

The inclusion of a link does not necessarily indicate endorsement, affiliation or responsibility.

24. Changes to this Policy

LupoTek may amend this Policy to reflect changes in:

  • law;

  • regulatory guidance;

  • technology;

  • security practices;

  • Site functionality;

  • service providers;

  • organisational structure; or

  • business and operational activities.

The current version is published on the Site with its effective date or last-updated date.

Changes take effect when published or on a later date stated in the updated Policy.

Where required by law, additional notice or consent may be provided.

Continued use of the Site does not waive rights conferred by applicable privacy law and is not treated as consent where express consent is legally required.

25. Governing law and jurisdiction

This Policy and LupoTek’s handling of personal information are subject to applicable laws of the Commonwealth of Australia and the Australian Capital Territory.

To the extent that this Policy is construed as having contractual or other legal effect, it is governed by the laws applying in the Australian Capital Territory, Australia.

Subject to any mandatory right to complain to a regulator, tribunal or court elsewhere, proceedings concerning this Policy may be brought before a court or tribunal with jurisdiction in the Australian Capital Territory.

Nothing in this section:

  • excludes the application of a mandatory law;

  • prevents a complaint to the Office of the Australian Information Commissioner or another competent regulator;

  • limits a non-excludable statutory right; or

  • represents that Australian law is the only law that may apply to a particular individual or activity.

26. Contact LupoTek

Questions, requests or complaints concerning this Policy or LupoTek’s handling of personal information may be directed to:

Privacy Contact
LupoTek
Canberra, Australian Capital Territory, Australia
Email: legal@lupotek.org