This policy explains how EzyBeef (we, us or our) collects, holds, uses, discloses and protects personal information and farm data when you use our websites, applications, products and support services (the Services).
1. Our commitments
We comply with applicable Australian laws relating to privacy, data protection and security, including applicable Victorian laws. Where the Privacy Act 1988 (Cth) and the Australian Privacy Principles apply to us, we will handle personal information in accordance with them.
We also align our farm-data practices with the principles of the National Farmers’ Federation’s Australian Farm Data Code. EzyBeef is not currently certified or accredited under the Code, and no endorsement by the National Farmers’ Federation is implied.
2. Information and data we collect
Depending on how you use EzyBeef, we may collect and hold:
- Account and contact information, such as your name, email address, telephone number, business or farm name and login details.
- Farm data entered, imported or generated through the Services, such as information about farms, properties, paddocks, mobs, livestock, identifiers, movements, treatments, weights, traits, performance, breeding and other farm operations.
- Authorised-user information, including staff, contractors, stock agents or advisers you invite and the access permissions you assign to them.
- Technical and usage information, such as device and browser type, IP address, dates and times of access, diagnostic information, security events and application logs.
- Communications, including support requests, feedback and other correspondence.
- Transaction information needed to administer subscriptions and payments. Payment card details may be handled directly by a payment provider and need not be stored by EzyBeef.
Please do not enter personal information about another person unless you are authorised to do so.
3. How we collect information
We generally collect information directly from you when you create an account, enter or import data, invite another user, contact us or use the Services. We may also receive information from people you authorise, connected services you choose to use, and our technology and service providers.
4. How we use information and farm data
We use information only for purposes connected with providing and operating EzyBeef, including to:
- create and administer accounts and subscriptions;
- store, process, display, import, export and back up data as directed by users;
- provide support and communicate about the Services;
- maintain security, prevent misuse, diagnose faults and improve reliability and functionality;
- meet legal, accounting and regulatory obligations; and
- send product or marketing communications where permitted by law, with an option to unsubscribe.
We do not sell individual farm data or personal information. We do not give another customer access to your individual farm data unless you or an authorised user directs us to do so.
We may use aggregated or de-identified information to understand and improve the Services, provided it is not reasonably capable of identifying an individual farm, farmer or business. We will not attempt to re-identify that information except where required or permitted by law, including to test whether de-identification is effective.
5. Your control of farm data
As between you and EzyBeef, you retain ownership of the farm data you provide. You give us the limited rights needed to host, back up, process and display that data and otherwise provide the Services.
You control who you invite to access your account and the permissions given to them. You are responsible for reviewing and removing access when it is no longer required.
You may request access to, correction of, export of, or deletion of your individual farm data and personal information. We will respond within a reasonable period and may need to verify your identity or authority. Some information may need to be retained where required by law, to resolve a dispute, protect the security and integrity of the Services, or remain temporarily in secure backups until those backups are overwritten in the ordinary cycle.
6. Storage and data location
EzyBeef’s customer farm data is stored using Amazon Web Services (AWS) infrastructure located in Australia.
We use Auth0 to provide account identity, authentication and login security. Auth0 may process information such as your name, email address, login identifier, IP address and authentication logs. Although our Auth0 service is configured for the Australian region, some authentication information may be processed, replicated, backed up or accessed outside Australia as part of Auth0’s security, support, redundancy and disaster-recovery arrangements.
EzyBeef does not intentionally provide Auth0 with livestock, paddock, mob, production or other operational farm data.
We may use other specialist providers for functions such as email delivery, payments, monitoring or customer support. We require providers to handle information only for the services they supply and to apply appropriate safeguards. Limited technical, security, billing or support information may be processed outside Australia where a supplier’s service necessarily involves overseas systems. Where applicable, we take reasonable steps to ensure overseas handling or disclosure of personal information complies with Australian privacy law.
7. When we disclose information
We may disclose information:
- to people you authorise, such as staff, contractors, agents or advisers;
- to contracted providers that help us deliver the Services, including AWS for application hosting and data storage;
- to Auth0 for identity management, account authentication, login security and related technical support;
- where required or authorised by law, court order or a lawful request from an authority;
- to protect the rights, safety, security or property of users, EzyBeef or others; or
- in connection with a business sale, merger or restructure, subject to appropriate confidentiality and data-protection arrangements.
If we are legally required to disclose identifiable farm data, we will notify the affected customer where we are legally permitted and it is reasonably practicable to do so.
8. Security, quality and availability
We take reasonable and prudent steps, consistent with known industry practices and proportionate to the nature of the data, to protect information against loss, interference, misuse and unauthorised access, modification, disclosure, damage or destruction. These steps include appropriate access controls, secure hosting, monitoring, backups and recovery procedures, software maintenance and testing.
We also take reasonable steps to keep personal information accurate, complete and up to date. You can help by keeping your account details current and reviewing data entered by you or your authorised users.
No online service or storage system can be guaranteed to be completely secure or continuously available. You should use a strong, unique password, protect access to your devices and promptly tell us if you suspect unauthorised access.
9. Data breaches
We maintain procedures for responding to suspected data breaches. We will investigate an incident, take reasonable steps to contain and remediate it, and notify affected users and the Office of the Australian Information Commissioner where required by the Notifiable Data Breaches scheme. Consistent with our Farm Data Code commitments, we will also notify an affected customer promptly of an attempted or actual unauthorised access to, damage to or destruction of their identifiable farm data where doing so is lawful and the risk is credible.
10. Retention and account closure
We retain information for as long as reasonably needed to provide the Services and meet our legal, security, dispute-resolution and record-keeping obligations. Following account closure or a valid deletion request, we will delete or de-identify information that we are not required to retain. Residual copies may remain in secure backups for a limited period and will not be restored except for disaster recovery, legal or security purposes.
Before closing an account, you should export any data you wish to keep. If EzyBeef permanently discontinues the Services, we will take reasonable steps to give customers an opportunity to retrieve their individual farm data before deletion, subject to operational and legal constraints.
11. Cookies and similar technologies
Our websites and applications may use cookies, local storage and similar technologies that are necessary for authentication, security, preferences, offline operation and service performance. Where we use optional analytics or marketing technologies, we will provide any notice or choice required by law.
12. Access, correction and complaints
You may contact us to ask what personal information we hold about you, request access or correction, make a farm-data enquiry, request an export or deletion, or make a privacy complaint. We may ask you to verify your identity and authority before acting.
Please contact us through the contact details published on ezybeef.com.au. We will acknowledge and investigate privacy complaints within a reasonable time. If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner.
13. Changes to this policy
We may update this policy when our Services, suppliers or legal obligations change. We will publish the current version on our website with its effective date. If a change materially affects how we use or share identifiable farm data, we will give affected customers reasonable notice and, where appropriate, seek consent or provide a reasonable way to discontinue the affected use without penalty.