top of page
Image by jonakoh _

Privacy Policy

Privacy Policy

Buynetic Pty Ltd · Effective 2 August 2026 · Version 1.0

This Privacy Policy explains how Buynetic Pty Ltd (ABN 46 647 898 468, ACN 647 898 468), an Australian private company registered in New South Wales (“Buynetic”, “we”, “us”, “our”), collects, uses, discloses, stores and protects personal information.


Buynetic is a B2B sourcing and technology supply company. This policy applies to www.buynetic.com.au and our other websites, our bulk sourcing and procurement services, our dealings with customers and suppliers, the brands and products we own or operate, and any mobile or web applications, connected products and support services we make available (together, the “Services”).


We are bound by the Australian Privacy Principles (“APPs”) in the Privacy Act 1988 (Cth), and, where they apply to our handling of personal data, by the EU and UK General Data Protection Regulation and comparable laws in other markets we serve. Buynetic is the entity responsible for personal information handled under this policy — the “data controller” for GDPR purposes. 

Questions, requests or complaints: privacy@buynetic.com.au.


1. Summary

  • Most of what we hold is business contact information — the names, work emails, phone numbers and roles of people at our customers, suppliers and partners, together with the enquiries, quotes, orders and correspondence attached to them.

  • Some of our brands sell products with companion applications or connected features. Where a product collects information from the people who use it, that is covered here and, where the product needs it, by a supplementary notice published with that product.

  • We do not sell personal information and we do not disclose it to third parties for their own marketing.

  • We use it to do business with you — to quote, supply, deliver, invoice, support, and keep the required records.

  • You can ask us what we hold, have it corrected, ask for it to be deleted, opt out of marketing, or complain — see sections 12 and 13.

2. Whose information this policy covers

  • Customers and prospective customers — the individuals who enquire, request a quote, place an order or manage an account on behalf of a business.

  • Suppliers, vendors and partners — the individuals we deal with at manufacturers, distributors, freight forwarders, agents and service providers.

  • Website visitors — anyone who browses our websites or submits a form.

  • Users of our products and applications — people who use a product, app or connected device supplied under one of our brands, and people who contact us for support.

  • Job applicants and contractors — people who apply to work with us or who provide services to us.

Where you give us information about someone else — a colleague, a delivery contact, a referee — you confirm you are entitled to do so and that they have been told their details will be handled as described here.


3. Information we collect


3.1 Business and contact information

  • Name, job title, employer, work email address, work phone number and postal or delivery address.

  • The business you represent, its trading details, ABN or equivalent registration number, and its markets of interest.

  • Account credentials and preferences where you hold a login with us.

3.2 Enquiry, quote and order information

  • The content of enquiry and quote-request forms, including the market you selected, the volumes and specifications you need, and your project details.

  • Quotes, purchase orders, order history, delivery instructions, shipping and customs documentation, and returns or warranty claims.

  • Correspondence about a transaction, including email threads, call notes and meeting notes.

3.3 Payment and credit information

  • Billing contact details, invoicing and payment records, purchase order references and tax information.

  • Bank or remittance details where you pay by transfer, and payment status and history.

  • Where we extend credit, the information needed to assess and monitor it, including trade references and credit-reporting information obtained with your consent and handled in accordance with Part IIIA of the Privacy Act 1988 (Cth).

Where a payment is made by card, the card details are collected by and sent directly to our payment processor. We do not store full card numbers.

3.4 Supplier and due-diligence information

  • Contact and role details for individuals at our suppliers and their agents.

  • Compliance, certification, product-testing, quality and audit records, including information gathered for modern-slavery, sanctions and anti-bribery screening.

  • Contract and performance records.

3.5 Information from our products and applications

Some of the brands and products we operate include mobile or web applications, connected or cellular-enabled hardware, or online accounts. Where that is the case we may collect, depending on the product:

  • Account information — name, email address, password (stored only as a salted one-way hash), profile details and preferences.

  • Device and product information — serial numbers, hardware identifiers, SIM identifiers where a product is cellular-connected, firmware version, battery and connectivity status, settings and diagnostic telemetry.

  • Content you create or capture — files, images, video, readings, measurements and other data a product records and uploads to your account, together with its metadata.

  • Location information — the location of a product, where the product reports it or you set it, and your device’s location where a feature needs it and you have granted the permission. Location permissions can be declined and can be revoked at any time in your operating system settings.

  • Usage and technical information — app interactions, IP address, device and operating-system type, app version, session records, crash and error reports, and security events.

  • Notification information — push notification tokens and your notification preferences.

  • Subscription information — where a product carries a paid plan, the plan, its status, renewal dates and billing history.

Where a product handles information not described here, or handles it differently, a supplementary privacy notice is published with that product and prevails over this policy to the extent of any inconsistency. Where a product is sold under a brand we operate, Buynetic is the entity responsible for that information.

3.6 Website information, cookies and analytics

We and our providers collect the following when you use our websites:

  • Strictly necessary cookies — session, security and form-integrity cookies. The site does not work without them.

  • Preference storage — your interface and language choices.

  • Security services — bot and abuse detection on forms and logins.

  • Analytics — aggregate measurement of which pages are visited and where visitors encounter problems, so we can improve the site.

  • Server logs — IP address, browser and device type, referring page, pages viewed, and timestamps.

You can block or delete cookies in your browser settings; blocking strictly necessary cookies will prevent parts of the site from working. Where the law requires consent for non-essential cookies, we ask for it before setting them, and you can withdraw it at any time.


3.7 Recruitment information

If you apply to work with us we collect your application, CV, work history, qualifications, right-to-work status, referee comments and interview notes, and any assessment results.


3.8 Information we do not seek


We do not seek sensitive information as defined by the Privacy Act 1988 (Cth), or special-category data under the GDPR — health, biometric, racial or ethnic origin, political opinions, religious beliefs, union membership, sexual orientation or criminal record — except where it is genuinely necessary, permitted by law, and you have consented. Please do not send it to us unsolicited. We do not use facial recognition, and we do not buy personal information from data brokers or list vendors.


4. How we collect information

  • Directly from you — when you complete a form, email or call us, request a quote, place an order, register an account, set up a product, or apply for a role.

  • Automatically — from your browser when you visit our websites, and from a product or application when it connects to our systems.

  • From your organisation — when a colleague nominates you as a contact, an approver or a delivery recipient.

  • From third parties — from suppliers, freight forwarders and customs agents in connection with an order; from payment providers and, with consent, credit reporting bodies; from publicly available sources such as company registers and business directories; and from recruiters and referees you have nominated.

Where we collect your information from someone other than you, we take reasonable steps to make you aware of it, as APP 5 requires.


5. Why we use information, and our lawful bases


For individuals in the European Economic Area and the United Kingdom, the GDPR lawful basis for each purpose is noted in brackets.

  • Responding to enquiries and preparing quotes. (Steps at your request prior to entering a contract; legitimate interests.)

  • Supplying goods and services — accepting and fulfilling orders, arranging manufacture, freight, customs clearance and delivery, and handling returns, warranty and after-sales matters. (Performance of a contract.)

  • Operating our products, applications and accounts — providing the features a product offers, delivering content to your account, keeping connected products working, and supporting you. (Performance of a contract.)

  • Billing and credit — invoicing, collecting payment, assessing and managing credit, and recovering debts. (Performance of a contract; legitimate interests; legal obligation.)

  • Supplier management and due diligence — onboarding, quality and compliance verification, and sanctions, anti-bribery and modern-slavery screening. (Legitimate interests; legal obligation.)

  • Support and communications — answering questions, sending transactional and service messages, and keeping a record of what was resolved. (Performance of a contract; legitimate interests.)

  • Security and fraud prevention — authenticating users, detecting and blocking abuse of our sites, products and accounts, and investigating incidents. (Legitimate interests; legal obligation.)

  • Improving our Services — understanding in aggregate how our sites and products are used, diagnosing faults, and planning our range and capacity. (Legitimate interests.)

  • Marketing — sending business communications about our markets, products and offers to people who have not opted out. (Consent, or legitimate interests where permitted.)

  • Legal and regulatory compliance — meeting tax, customs, consumer, product-safety, export-control and corporate obligations, responding to lawful requests, and establishing, exercising or defending legal claims. (Legal obligation; legitimate interests.)

  • Recruitment — assessing applications and managing engagement. (Steps prior to a contract; legitimate interests.)

Where we rely on legitimate interests, we have weighed our interest against your rights and concluded it does not override them. You may object at any time — see section 12.


6. Direct marketing


We may send you information about our markets, products and offers where you are an existing or prospective business contact and you have not opted out. Every marketing message identifies us and includes a working unsubscribe facility, consistent with the Spam Act 2003 (Cth) and, where applicable, the ePrivacy rules and the CAN-SPAM Act.


Unsubscribing stops marketing only. We will still send the messages needed to run a transaction or an account — order confirmations, delivery notices, invoices, security alerts, product-safety notices and changes to these terms.

You can opt out at any time by using the unsubscribe link or by writing to privacy@buynetic.com.au. We keep a suppression record so we can honour your request permanently. We do not sell or rent our contact lists.


7. When we disclose information


We do not sell personal information. We disclose it only as follows:

  • To suppliers and manufacturers — the contact, specification and delivery details needed to produce and ship your order.

  • To freight forwarders, carriers, warehouses and customs brokers — the consignee, address and documentation details needed to move and clear goods.

  • To payment, banking and credit providers — to process payment, assess credit, and recover unpaid amounts.

  • To our service providers — the categories listed in section 8, each under contract, only on our instructions, and only to the extent needed.

  • Within our group — to related bodies corporate and to the brands we operate, for the purposes described in this policy.

  • To professional advisers — auditors, lawyers, insurers and accountants, under a duty of confidentiality.

  • For legal reasons — where required or authorised by law, including in response to a subpoena, court order, warrant, customs or tax requirement, or other lawful request by a public authority; to enforce our terms; or where we reasonably believe disclosure is necessary to prevent serious and imminent harm, or to investigate suspected unlawful activity. We assess each request, require it to be lawful and specific, and notify you unless legally prohibited.

  • In a business transaction — to a counterparty and its advisers in a merger, acquisition, restructure or sale of assets, subject to confidentiality. If a business changes hands, we will tell affected individuals before their personal information becomes subject to a different privacy policy.

8. Service providers


We engage providers in the following categories, each under written terms requiring appropriate security and restricting them to our instructions, consistent with APP 8 and, where relevant, Article 28 of the GDPR:

  • Cloud hosting, object storage and content delivery.

  • Email delivery, messaging and customer-relationship management.

  • Payment processing, invoicing and accounting.

  • Freight, logistics, warehousing and customs.

  • Product testing, inspection and certification.

  • Website analytics and security, including bot and abuse detection.

  • Push notification delivery and mapping services, for products with app or connected features.

  • IT support, security monitoring and business software.

  • Recruitment and background checking, where relevant to a role.

We will identify the specific providers relevant to your information on request to privacy@buynetic.com.au.


9. Overseas storage and international transfers


We operate from Australia and source internationally. Personal information may be stored or accessed in, or disclosed to recipients in, countries including the United States, the United Kingdom, the European Union, Singapore, Hong Kong, mainland China, India and the United Arab Emirates — the markets in which our suppliers, manufacturing partners, logistics providers and technology providers operate.


Before disclosing personal information overseas, we take reasonable steps under APP 8 to ensure the recipient handles it consistently with the Australian Privacy Principles. For transfers of personal data out of the European Economic Area or the United Kingdom, we rely on the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum, together with the safeguards in section 10, and we assess the destination country where the law requires it.

You may ask us for more detail about the safeguards applying to a particular transfer.


10. How we protect information

  • Traffic between your browser or device and our systems is encrypted in transit using TLS. Data at rest in our systems is encrypted.

  • Passwords, where we hold them, are stored only as salted one-way hashes using a modern, deliberately slow algorithm.

  • Access is granted on a least-privilege basis, requires multi-factor authentication, and is logged and reviewed.

  • We segregate environments, patch our systems, monitor for unusual activity, and keep audit trails of administrative and security-relevant actions.

  • Our staff are bound by confidentiality obligations and are trained on handling personal information.

  • We destroy or de-identify personal information when it is no longer needed for any purpose for which it may be used or disclosed, as APP 11.2 requires.

No system is perfectly secure. If you hold an account with us, use a strong unique password, enable multi-factor authentication where offered, and tell us immediately at privacy@buynetic.com.au if you suspect it has been compromised.


Data breaches. If an eligible data breach occurs that is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner as the Notifiable Data Breaches scheme requires. Where the GDPR applies, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, and affected individuals where the risk is high.


11. How long we keep information


We keep personal information only as long as we need it for the purposes in this policy, or as the law requires.

  • Enquiries that do not become orders — up to 24 months, so we can pick up a conversation you resume.

  • Customer and supplier records — for the life of the relationship, plus seven years.

  • Transaction, tax, customs and accounting records — seven years after the transaction, as Australian law requires.

  • Product and application accounts — while the account is open. On deletion, personal information is deleted or irreversibly de-identified within 30 days, other than records we must keep by law.

  • Content stored in a product account — until you delete it or the applicable retention limit is reached; purged from storage, including backups, within 90 days of deletion.

  • Support correspondence — three years after the matter is closed.

  • Security and audit logs — up to 24 months. Technical and diagnostic logs — typically 30 to 90 days.

  • Unsuccessful job applications — 12 months, unless you ask us to keep them on file.

  • Marketing suppression records — indefinitely, because we must remember that you opted out.

12. Your rights and how to exercise them

Subject to the exceptions in the Privacy Act 1988 (Cth) and other applicable law, you may ask us to:

  • confirm whether we hold personal information about you, and give you access to it;

  • correct information that is inaccurate, out of date, incomplete, irrelevant or misleading;

  • delete or de-identify information we no longer need;

  • provide your information in a portable, machine-readable format, or transmit it to another provider where technically feasible;

  • restrict or object to a particular use, including any use we base on legitimate interests, and any direct marketing;

  • withdraw a consent you previously gave, without affecting processing already carried out; or

  • tell you where we obtained your information.

Write to privacy@buynetic.com.au. We will acknowledge promptly and respond within 30 days. We may need to verify your identity first, and we may need to keep information the law requires us to retain. If we refuse a request, we will tell you why in writing and explain how to complain. We do not charge for making a request, and we will not treat you differently for making one.


Where a product or application offers self-service controls — profile editing, notification preferences, data export, or account deletion — you can use those directly without contacting us.

You may also deal with us anonymously or under a pseudonym where it is lawful and practicable to do so, though we usually cannot supply goods or process an order without identifying details.


13. Complaints

If you are unhappy with how we have handled your personal information, tell us first at privacy@buynetic.com.au with “Privacy complaint” in the subject line. We will investigate and respond in writing within 30 days. 


If you are not satisfied with our response, you can complain to a regulator:

  • Australia — Office of the Australian Information Commissioner, oaic.gov.au, GPO Box 5218, Sydney NSW 2001, telephone 1300 363 992.

  • European Economic Area — your national data protection supervisory authority.

  • United Kingdom — the Information Commissioner’s Office, ico.org.uk.

14. If you are in the European Economic Area or the United Kingdom


Buynetic Pty Ltd is the controller of your personal data. Our lawful bases are in section 5, our transfer safeguards in section 9, and our retention periods in section 11.


In addition to the rights in section 12, you have the right to lodge a complaint with your supervisory authority, and the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects. We do not make such decisions solely by automated means; credit, supply and compliance decisions involve human judgement.


We do not currently have an establishment in the European Union or the United Kingdom. Where Article 27 of the GDPR requires it, we will appoint a representative and publish their details here.

15. If you are in California or another US state with a privacy law

This section applies to residents of California under the California Consumer Privacy Act as amended by the CPRA, and, as relevant, residents of other US states with comparable laws.


Categories of personal information collected in the last 12 months: identifiers (name, work email, phone, account ID, IP address, device identifiers); customer records (business and billing contact details, payment records); commercial information (enquiries, quotes, orders and purchase history); internet or network activity (site and application interactions, diagnostic logs); geolocation data (product location, and device location where a product feature needs it and you permit it); professional or employment information (job title, employer, and, for applicants, work history); visual or other content collected by a product where the product captures it; and inferences drawn from that content by product features. Sources, purposes and disclosures are described in sections 3, 4, 5, 7 and 8.


We have not sold personal information, and we have not shared personal information for cross-context behavioural advertising, in the preceding 12 months, and we do not do so now. We do not knowingly sell or share the personal information of consumers under 16 years of age.


Sensitive personal information. We collect account credentials, and precise geolocation only in the product circumstances described in section 3.5. We use these solely to provide and secure the Services and never to infer characteristics about you, so no right to limit their use applies.


Your rights to know, access, correct, delete, obtain a portable copy, opt out of sale or sharing, limit the use of sensitive personal information, and be free from discrimination for exercising any of them are honoured through section 12. You may use an authorised agent, in which case we will ask for proof of authorisation.


16. Children


Our Services are directed to businesses and to adults. We do not knowingly collect personal information from anyone under 16, or, in the United States, from a child under 13 within the meaning of the Children’s Online Privacy Protection Act. If we learn we have collected such information without verified parental consent, we will delete it promptly. Contact privacy@buynetic.com.au if you believe a child has provided us with personal information.


17. Third-party sites and services


Our sites, products and applications may link to or integrate services we do not control, including app stores, payment providers, mapping services, carriers and supplier portals. This policy does not apply to them, and we are not responsible for their content or privacy practices. Read their policies before providing them with your information.


18. Changes to this policy


We may update this policy as our business changes or as the law requires. The version published on this page is the current one, and the effective date is shown at the top. If a change is material — a new purpose, a new category of recipient, or a new category of information — we will give reasonable advance notice by email, by a notice on our sites or in the relevant application, or both, before it takes effect, and we will seek consent where the law requires it. Continuing to use the Services after the effective date means you accept the updated policy.


19. Contact us


Buynetic Pty Ltd ABN 46 647 898 468 · ACN 647 898 468 Suite 3A16, Level 14, 275 Little Alfred Street North Sydney NSW 2060, Australia

Privacy and data requests: privacy@buynetic.com.au Legal and contractual matters: legal@buynetic.com.au General enquiries: info@buynetic.com.au Web: www.buynetic.com.au


We are happy to provide this policy in an alternative accessible format on request.

bottom of page