Keaton Mills Modular (ABN 12 482 409 883)(“KMM”, “we”, “us”, “our”) respects your right to privacy and is committed to protecting personal information we collect, hold, use and disclose in the course of running our business.
This Privacy Policy explains how we comply with the Privacy Act 1988(Cth) (“Privacy Act”), the thirteen Australian Privacy Principles (“APPs”) and related Australian privacy law, and how you can exercise the rights those laws give you.
By providing personal information to us, or by continuing to use this website, you acknowledge that you have read and understood this Privacy Policy and consent to the practices described in it. If you do not agree, please do not provide personal information to us.
1Definitions
In this Privacy Policy, the following defined terms have the meanings set out below:
| Term | Meaning |
|---|---|
| APPs | The thirteen Australian Privacy Principles set out in Schedule 1 of the Privacy Act 1988 (Cth). |
| Personal information | Information or an opinion about an identified individual, or an individual who is reasonably identifiable, regardless of whether the information is true, recorded in material form, or held only digitally. |
| Sensitive information | A subset of personal information that includes information about an individual's racial or ethnic origin, political opinions, religious beliefs, sexual orientation, membership of professional or political associations, health, biometrics or criminal record. |
| Direct marketing | Communication of marketing information sent to you using your personal information, by any channel — including post, email, SMS, phone and social media. |
| Third party | A party other than you or us — for example, our suppliers, sub-contractors, certifiers, freight operators, hosting providers and government bodies. |
| OAIC | The Office of the Australian Information Commissioner — the federal regulator for privacy. |
2Scope of this policy
This Privacy Policy applies to:
- personal information we collect through our website at keatonmills.com and any sub-domains;
- information we collect from quote forms, reseller applications, consultation bookings and newsletter sign-ups;
- information we collect during the course of supplying, manufacturing, delivering, installing or warranting our products;
- information we collect from telephone calls, emails, SMS, social-media messages and in-person interactions with our team;
- any other information you provide to us in the course of dealing with us.
It does not apply to information we hold about our employees or contractors, which is governed by the employee-records exemption under section 7B of the Privacy Act.
3The information we collect
We collect personal information that is reasonably necessary for, or directly related to, one or more of our business functions or activities. The categories of personal information we typically collect are described in the sub-sections below.
3.1Contact and identification information
When you enquire, request a quote, sign a contract, register a warranty or otherwise interact with us, we typically collect:
- your full name, postal address and email address;
- one or more phone numbers and your preferred contact method;
- where you contact us through social media, the public identifier (username/handle) you use;
- where relevant, identification documents we are legally required to sight (for example, driver licence on signing a contract of sale).
3.2Project and site information
When you ask us to quote or build, we collect detail about the proposed project, including:
- the site address, lot/plan and local government area;
- site characteristics — access, slope, soil class, bushfire-attack level, services availability;
- the product, configuration, finish, add-on and budget range you are considering;
- any architectural drawings, geotechnical reports, photographs or correspondence you provide to us;
- your preferred timeline and any operational, accessibility or cultural-heritage constraints relevant to the project.
3.3Commercial information (B2B)
For reseller, distributor, broker, builder, developer and other business-to-business interactions, we may additionally collect:
- business name, ABN, ACN, registered office and trading addresses;
- the names, roles and contact details of the directors, owners or representatives we interact with;
- industry, target territory and the expected volume of units;
- where required by law, identity-verification information for anti-money-laundering and counter-terrorism financing compliance.
3.4Financial information
We collect limited financial information for the purposes of pricing, invoicing, payment processing and finance referrals. This typically includes:
- billing and remittance addresses;
- bank account or payment-card details required to process a transaction (we do not retain full card numbers; payments are processed by an accredited payment-services provider);
- where you ask us to refer you to a finance partner, basic information about your stated budget, employment or business situation — passed to the partner with your consent.
3.5Technical and website information
When you visit our website, our hosting and analytics providers automatically collect technical information, including:
- your IP address and approximate geo-location derived from it;
- the device type, operating system, browser, screen size and language;
- the referring URL, the pages you visit, the time spent and interactions with the page;
- error reports and performance traces necessary to keep the website running.
See section 8 for detail on cookies and similar technologies.
3.6Sensitive information
We do not seek sensitive information from you in the ordinary course of our business. Where you choose to disclose sensitive information to us — for example, telling us about a disability or health requirement affecting the build — we will treat it with the same protections as all other personal information described in this policy and only use it for the purpose for which you provided it.
3.7Information about children
Our products and services are sold to adults. We do not knowingly market to or collect personal information from children under the age of 16. If you believe a child has provided us with personal information, please contact us and we will take reasonable steps to remove it.
4How we collect information
We collect personal information by lawful and fair means, generally directly from you. Specifically:
- through our website, when you submit a quote, reseller application, contact form or newsletter sign-up;
- by telephone, email, SMS, post or social-media message;
- at in-person meetings, factory tours and consultations;
- through the contract-of-sale and engineering-brief documents you sign with us;
- from publicly available sources (such as ABN Lookup, ASIC company extracts and your business website) when verifying a B2B counterparty;
- through our service providers, where they collect information on our behalf in accordance with this policy.
If we collect personal information about you from a third party, we will take reasonable steps to ensure that the collection complies with APP 3 and that you are made aware of the collection where the APPs require it.
5How we use personal information
We use personal information for the primary purpose for which it was collected and for related secondary purposes that you would reasonably expect, including:
- responding to your enquiry, preparing your quote and managing the contract;
- arranging engineering, drafting, certification, council lodgement, manufacturing, freight, crane, setup and warranty service;
- processing payments, refunds and any finance referrals you ask us to make;
- communicating with you about your project — including site coordination, scheduling, defect rectification and end-of-warranty notices;
- complying with our obligations under Australian Consumer Law, building law, the Privacy Act, taxation legislation and any other applicable law;
- maintaining our records, evidencing decisions, defending or pursuing legal claims, and resolving disputes;
- improving our website, product range, manufacturing, marketing and customer-service practices;
- with your consent (or where permitted by APP 7), sending direct marketing about our products, models, financing options and events.
5.1Direct marketing and your right to opt-out
Where we send you direct-marketing communications, every message will include a simple mechanism to opt-out — typically an “unsubscribe” link in the email footer, or a reply-STOP option for SMS.
You can also opt-out at any time by emailing sales@keatonmills.com with the subject line “Unsubscribe”. We will action your request within 30 days of receipt.
Opting-out of direct marketing does not affect transactional communications (for example, build-status updates, invoices, warranty notices) which we must continue to send to perform the contract.
6Who we disclose information to
We disclose personal information to third parties only where the disclosure is reasonably necessary to perform our business functions, where you have consented, or where the disclosure is required or authorised by law.
The principal categories of recipient are:
- Engineers and certifiers — registered structural engineers, private building certifiers, energy assessors, geotechnical surveyors and bushfire-attack-level assessors;
- Manufacturers and trade partners — factories, manufacturing partners, plumbers, electricians, fitters and finishers involved in producing or commissioning the building;
- Freight, crane and logistics providers — heavy-haulage operators, crane-hire providers, customs brokers, freight forwarders and pilot-vehicle operators;
- Government and regulatory bodies — local councils, building certifiers, the Australian Tax Office, the OAIC and similar authorities where required by law;
- Finance partners — only with your express consent, and only the information needed for a finance pre-assessment;
- Technology providers — hosting, email-delivery, analytics, payment-processing, CRM and helpdesk providers we use to operate the business;
- Advertising platforms — Meta Platforms (Facebook/Instagram) where you have given marketing consent — see Section 8 for the specific data shared and your ability to opt out;
- Professional advisers — our lawyers, auditors, insurance brokers and consultants, on a need-to-know basis;
- Successor entities — in the event of a sale of our business or a corporate restructure, to the buyer or successor entity on terms consistent with this policy.
7Overseas disclosure
Some of our technology providers store and process data in jurisdictions outside Australia. Typical recipient countries include:
- the United States (hosting, email-delivery and analytics providers);
- the European Union (some hosting and content-delivery providers);
- Singapore (some regional content-delivery infrastructure).
Where we disclose personal information overseas, we take reasonable steps under APP 8 to ensure the recipient handles the information in a way that is consistent with the APPs. This typically takes the form of contractual obligations imposed on the provider, including data-processing addenda and security commitments. A copy of those terms can be requested from sales@keatonmills.com.
9How we secure information
We take reasonable steps to protect the personal information we hold from misuse, interference, loss and unauthorised access, modification or disclosure. Those measures include:
- Transport security: our website is served over HTTPS and configured with HTTP Strict Transport Security and a strong Content-Security-Policy header.
- Access control: access to internal systems is restricted to authorised personnel on a need-to-know basis, with multi-factor authentication enforced on all administrative accounts.
- Encryption at rest: data stored with our cloud providers is encrypted at rest by default.
- Vendor due-diligence: we review the security posture of new technology providers before adoption and re-review at material renewals.
- Retention limits: we do not retain personal information for longer than necessary (see section 10).
No internet transmission or storage system is perfectly secure. If you have a specific security concern about a piece of information we hold, contact us at sales@keatonmills.com.
10Retention periods
We retain personal information only for as long as it is necessary for the purpose for which it was collected, or as required by law. Typical retention periods are:
| Category | Indicative retention |
|---|---|
| Quote enquiries that do not progress | 24 months from last contact |
| Contract documents, project records and warranty registrations | Life of the structural warranty + 7 years |
| Tax invoices, payment records and financial documents | 7 years (per ATO record-keeping requirements) |
| Reseller and B2B records | 7 years after end of trading relationship |
| Marketing-list subscribers | Until you unsubscribe |
| Website analytics events | 14 months (aggregated only) |
At the end of the relevant period, personal information is either destroyed or de-identified so it can no longer be associated with you.
11Data breach response
We maintain an internal data-breach response plan. In the event of a known or suspected breach involving personal information, we will:
- contain the breach and assess its scope within 24 hours of becoming aware of it;
- determine whether the breach is likely to result in serious harm and is therefore notifiable under Part IIIC of the Privacy Act (the Notifiable Data Breaches scheme);
- where notification is required, notify the OAIC and each affected individual as soon as practicable, with the information required by section 26WL of the Privacy Act;
- review and update our security controls to prevent recurrence.
12Accessing, correcting and deleting your information
You have the right under the APPs to:
- Access a copy of the personal information we hold about you (APP 12);
- Correct information that is inaccurate, out of date, incomplete, irrelevant or misleading (APP 13);
- Opt-out of direct marketing as set out in section 5.1;
- Withdraw consent for a particular use of your information where the use is consent-based;
- Request deletion of information we are not required by law to retain.
To exercise any of these rights, email sales@keatonmills.com. We will acknowledge your request within five business days and respond substantively within 30 days. There is no fee for a routine access or correction request; if your request is unusually voluminous or complex, we may agree a reasonable cost-recovery fee with you in advance.
If we deny an access or correction request, we will give you written reasons and tell you how to complain (see section 14).
13Anonymity and pseudonymity
Wherever it is lawful and practicable, you have the option of dealing with us anonymously or using a pseudonym (APP 2). This is not always possible — for example, we cannot supply or warrant a building anonymously — but for early-stage research enquiries you are welcome to call without identifying yourself.
14Complaints
If you believe we have handled your personal information in a way that breaches the Privacy Act or this policy, please complain to us first. Send your complaint to sales@keatonmills.com with as much detail as you can — what happened, when, who was involved and what outcome you would like.
We will:
- acknowledge your complaint within five business days;
- investigate and respond substantively within thirty days;
- tell you what we have done and how we have addressed your concern.
If you are not satisfied with our response, you may refer the matter to the Office of the Australian Information Commissioner at oaic.gov.au or by calling 1300 363 992.
15Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in law, business practice, or the technology we use. The current version is always available at keatonmills.com/privacy with the “last updated” date shown below the title.
For material changes — for example, where we begin handling a new category of information, or where a new overseas recipient is involved — we will provide a notice on the website at least thirty days before the change takes effect, and where appropriate, contact you directly.
16Contact us
Privacy questions, access requests, correction requests and complaints can be sent to:
Privacy Officer
Keaton Mills Modular
ABN 12 482 409 883
Email: sales@keatonmills.com
Phone: 0410 112 685
See also our Terms & Conditions and Warranty for related contractual terms.