MOBILE ASSETS PTY LTD
Effective as of 1 October 2021
Under the Act, “Personal Information” is defined as: “Information or an opinion about an identified individual, or an individual who is reasonably identifiable:
(a) whether the information or opinion is true or not; and?
(b) whether the information or opinion is recorded in a material form or not.”
Rush Gold is an Australian financial technology group that allows customers to own and transact gold digitally (Services).
Rush Gold provides its Services through the Rush Gold website at www.rush.gold and the Rush Gold mobile application, which is an investment, gifting & P2P payment app that allows customers to buy, sell, spend, send or pay with gold to anyone using their mobile phones (Rush Gold Platforms).
In making the Rush Gold Platforms available, we are sensitive to Individuals’ concerns about the safety of their Personal Information.
In essence, Rush Gold will typically only:
Rush Gold has developed our privacy framework to assist Individuals, and to comply with privacy legislation and regulations applicable to us and our management of your Personal Information.
Rush Gold collects Personal Information in one of three main ways:
(a) Directly from Individuals, when they interact with the Services or the Rush Gold Platforms;
(b) Passively from Individuals, when they interact with the Services or the Rush Gold Platforms; and
(c) From third parties in certain circumstances.
The specifics of Personal Information collected in each situation is discussed further below.
(a) Personal Information collected directly
Rush Gold collects Personal Information directly from Individuals unless it is unreasonable or impracticable to do so. When an Individual engages with the Rush Gold Platforms (including by accessing or using, creating an account with or completing an order to buy, sell, spend or send gold on the Rush Gold Platforms), the following types of Personal Information directly and consensually:
(b) Personal Information collected passively
As Individuals come into contact with, or otherwise interact with the Services or the Rush Gold Platforms, we may collect the following types of Personal Information:
(c) Personal Information collected from third parties
In certain circumstances, Rush Gold will collect Personal Information about Individuals from third parties. This includes parties to any buy, sell, spend or send gold transaction, credit reporting agencies, identity verification services, law enforcement agencies and other government entities. The types of Personal Information collected include:
Some of these third parties may collect Personal Information about you on our behalf for the purposes of providing services to us.
Rush Gold may collect information that is not Personal Information because it does not identify you or anyone else, or pseudo-anonymised data sets acquired from clients or other third parties. These data sets might contain Personal Information that is not immediately attributable to identifiable individuals, but may constitute Personal Information when combined with other information available to Rush Gold.
(d) What happens if Rush Gold can’t collect your personal information?
If you do not provide Rush Gold with the Personal Information described above, some or all of the following may happen:
Although Rush Gold collects Personal Information from Individuals in a number of circumstances, Rush Gold will only collect this information in order to provide and develop the Rush Gold Platforms and Services. Rush Gold collects Personal Information about Individuals so that it can perform its business activities and functions and provide the best possible quality of customer service. Here are the main ways we use Personal Information to achieve these objectives:
Rush Gold will use basic contact, enquiry and feedback in order to communicate with Individuals about their enquiries or feedback, interest in the Rush Gold Platforms or Services, to provide information about Individuals’ orders to buy, sell, spend or send gold and to store gold with vault providers, and for other administrative purposes related to the specific reason for which the Personal Information was collected.
If Individuals have consented, Rush Gold will also use these types of Personal Information to share relevant communications about Rush Gold and the Rush Gold Platforms.
Administration and Delivery of Services and Rush Gold Platforms
Rush Gold will use basic contact information and other organisational information (e.g. provided about an Individual by their organisation) to engage with Individuals effectively and efficiently in providing the Services and Rush Gold Platforms. Rush Gold will also use these types of information for administrative purposes (e.g. resetting account information or permissions as applicable).
In some cases, Rush Gold will use an Individual’s browser and IP address to enable the browser to pre-fill the Individual’s email address when they visit the Rush Gold website. The Individual’s browser may also store a token of the Individual’s current web session. Rush Gold may log IP addresses to analyse trends, administer the website, track users’ movements, determine users’ location and gather broad demographic information. Rush Gold collects, holds, uses and discloses Personal Information to provide Individuals with access to protected areas of the Rush Gold website, to assess the performance of the website and to conduct business processing functions including providing personal information to Rush Gold’s related bodies corporate, contractors, service providers or other third parties.
Rush Gold may also use Individuals’ Personal Information to provide Individuals’ updated Personal Information to Rush Gold’s related bodies corporate, contractors or service providers, to update Rush Gold’s records and keep Individuals’ contact details up to date, and to comply with any law, rule, regulation, lawful and binding determination, decision or direction of a regulator, or in co-operation with any governmental authority of any country.
Ensuring User safety
Rush Gold will use any type of information collected to prevent and address risks to all Individuals. For example, Rush Gold will use information to investigate suspicious or threatening activity.
Research and development
Rush Gold is constantly working to not only maintain and improve its Services and the RushGold Platforms, but to develop new ones. Rush Gold will use Personal Information for planning, product or service development, quality control and research purposes of Rush Gold, its contractors or service providers. Personal Information is used to develop, test and improve the Rush Gold Platforms and Services by providing us with an overview of how the Rush Gold Platforms are being used, any shortcomings the Rush Gold Platforms or Services may have, and subsequently to highlight the best means of improving experiences for all Individuals.
Rush Gold’s preference will be to de-identify these types information first, and then use it for this purpose in conjunction with de-identified browser and device information.
Where Individuals have consented, or subject to law, Rush Gold will use basic contact, enquiry and organisational information to provide Individuals with relevant marketing materials and information about Rush Gold’s products and services that Rush Gold considers may be of interest to Individuals.
These communications may be sent in various forms, including mail, SMS, fax and email, in accordance with applicable marketing laws, such as the Spam Act 2003 (Cth). Individuals consent to Rush Gold sending them those direct marketing communications by any of those methods. If an Individual indicates a preference for a method of communication, Rush Gold will endeavour to use that method whenever practical to do so.
Individuals can opt out of receiving marketing communications by using the opt-out functionality provided in each marketing communication (e.g. by clicking “unsubscribe” at the bottom of an email) or by contacting Rush Gold using the contact details provided below. Rush Gold will ensure that the Individual is removed from Rush Gold’s mailing list. Rush Gold does not provide Individuals’ Personal Information to other organisations for the purposes of direct marketing.
Generally, Rush Gold does not disclose Personal Information to any third parties except:
In the case of disclosing Personal Information to an organisation for an authorised purpose or to Individuals’ organisations, Rush Gold will seek the explicit consent of the Individual before disclosing their information. Rush Gold may combine any information that Rush Gold collects from Individuals with information collected by any of Rush Gold’s related bodies corporate.
Sometimes, subject to relevant law, we may disclose Individuals’ Personal Information to agents of Individuals, or their organisations, that are overseas. As with disclosures to third party service providers, overseas disclosures are always made once Rush Gold has taken all reasonable steps to determine the information will be treated as at least as favourably under the Act and other applicable privacy laws.
Rush Gold’s general approach
Rush Gold takes reasonable steps to ensure Individuals’ Personal Information is protected from misuse and loss and from unauthorised access, modification or disclosure. Rush Gold may hold Individuals’ information in either electronic or hard copy form.
Rush Gold will keep your Personal Information confidential and not sell or knowingly divulge Individual information to any external third parties, unless:
Rush Gold seeks the informed and voluntary consent of Individuals whenever it collects their information, or as soon as possible after.
Individuals can always refuse or revoke this consent, but sometimes this will affect Rush Gold’s ability to provide them with the Rush Gold Platforms. Rush Gold will advise Individuals if this is the case.
Personal Information is destroyed or de-identified when no longer needed. De-identified information refers to information that cannot reasonably be used to identify a particular Individual. De-identified information that can identify individuals only if it is combined with another, separate piece of information is referred to as pseudonymised information.
Where possible Rush Gold will aim to collect, store and use anonymised information as a first preference, and if not, then pseudonymised information. However, sometimes it will be impractical for Individuals’ information to be de-identified or treated in this way, and in this case, Rush Gold will continue to use and hold the information in a personally identifiable state. For example, if Rush Gold needs to reply to an Individual’s enquiry we will have to use the contact information provided.
Rush Gold is committed to information security. We will use all reasonable endeavours to keep the Personal Information we collect, hold and use in a secure environment. To this end we have implemented technical, organisational and physical security measures that are designed to protect Personal Information, and to respond appropriately if it is ever breached.
When information collected or used by Rush Gold is stored by third party service providers, Rush Gold takes reasonable steps to ensure these third parties use industry standard security measures that meet the level of information security Rush Gold owes Individuals.
As part of our privacy framework, we endeavour to routinely review these security procedures and consider the appropriateness of new technologies and methods.
As the Rush Gold website is linked to the internet, and the internet is inherently insecure, Rush Gold cannot provide any assurance regarding the security of transmission of information Individuals communicate to us online. Rush Gold also cannot guarantee that the information Individuals supply will not be intercepted while being transmitted over the internet. Accordingly, any personal information or other information which you transmit to us online is transmitted at your own risk.
The Rush Gold website may contain links to other websites operated by third parties. Rush Gold makes no representations or warranties in relation to the privacy practices of any third party website and Rush Gold is not responsible for the privacy policies or the content of any third party website. Third party websites are responsible for informing Individuals about their own privacy practices.
In the circumstances where Rush Gold suffers a data breach that contains Personal Information, we will take all necessary steps to comply with the Notifiable Data Breach Scheme outlined under the Act This means we will immediately make an objective assessment of whether a breach of Personal Information is likely to result in serious harm to Individuals, and if this is the case, endeavour to notify the affected Individual(s) and the Australian Information Commissioner.
If an Individual believes that their privacy has been breached, please contact us using the contact information below and provide details of the incident so that we can investigate it. Rush Gold requests that complaints about breaches of privacy be made in writing, so we can be sure about the details of the complaint. Rush Gold will attempt to confirm as appropriate and necessary with you your understanding of the conduct relevant to the complaint and what you expect as an outcome. We will inform you whether we will conduct an investigation, the name, title, and contact details of the investigating officer and the estimated completion date for the investigation process. After Rush Gold has completed its enquiries, we will contact you, usually in writing, to advise the outcome and invite a response to our conclusions about the complaint. If we receive a response from you, we will assess it and advise if we have changed our view.
Rush Gold retains Personal Information until it is no longer needed to provide or develop the Rush Gold Platforms. When the Personal Information is no longer required, Rush Gold will destroy or de-identify the Personal Information.
However, Rush Gold will retain:
Accessing and ensuring the accuracy of Personal Information
Rush Gold takes reasonable steps to ensure that the Personal Information we collect and hold is accurate, up to date and complete.
Individuals have a right to access and request the correction of any of Personal Information we hold about them at any time. Any such requests should be made by directly contacting us at the details set out below. Rush Gold will grant access to the extent required or authorised by the Act and applicable laws, and will take all reasonable steps to correct the relevant Personal Information where appropriate. Rush Gold may charge Individuals a fee to cover our administrative and other reasonable costs in providing the information to you. Rush Gold will not charge for simply making the request and will not charge for making any corrections to your Personal Information.
There may be circumstances in which Rush Gold cannot provide Individuals with access to information. We will advise you of these reasons if this is the case. For example, Rush Gold may need to refuse access if granting access would interfere with the privacy of others or if it would result in a breach of confidentiality. If that happens, Rush Gold will give the Individual written reasons for any refusal.
If an Individual believes that Personal Information Rush Gold holds about the Individual is incorrect, incomplete or inaccurate, then the Individual may amend it themselves online or request Rush Gold to amend it. Rush Gold will consider if the information requires amendment. If Rush Gold does not agree that there are grounds for amendment then Rush Gold will add a note to the Personal Information stating that the Individual disagrees with it.
Contacting Rush Gold
The Privacy Officer will contact you within a reasonable time after receipt of your complaint to discuss your concerns and outline options regarding how they may be resolved. Rush Gold will aim to ensure that your complaint is resolved in a timely and appropriate manner. Rush Gold will contact you if we require any additional information from you and will notify you in writing (which includes electronic communication via email) of the relevant determination. If you are not satisfied with the determination you can contact us to discuss your concerns or complain to the Australian Privacy Commissioner via www.oaic.gov.au.
Mobile Assets Pty Ltd
Suite 2003, Level 20, 109 Pitt Street, SYDNEY NSW 2000
Tel: 1800 183424