Techwave Pty Ltd (ABN 13 644 894 397) (“Techwave”, “we”, “us”, “our”) is committed to handling your personal information openly, fairly and securely. This policy explains what information we collect, how we use it, who we share it with, and the rights you have. It applies across our entire group of business units.
Scope and our business units
This is the Techwave Group Privacy Policy. It applies to all personal information we handle through any of our business units, including:
- Techwave Store — our online and direct-channel store for telecom, networking and RF equipment (store.techwave.com.au)
- waveMail — our AI-driven email marketing platform (wavemail.com.au)
- waveSuite — our forthcoming AI-driven integrated business platform (wavesuite.com.au)
- Techwave IT — our IT and digital services arm (website development, e-commerce, web applications, digital transformation, digital marketing)
- ACMA & EESS Affairs — our regulatory affairs and compliance representation services
- Our main corporate website at techwave.com.au
Some business units may publish a supplementary privacy notice covering matters specific to that unit — for example, additional detail on how a particular platform handles its data, or terms that apply only to that unit’s subscribers. Where a unit-specific notice exists, this group policy still applies. The unit-specific notice adds to it; it does not replace it. If there is any inconsistency between a unit-specific notice and this group policy on matters covered here (such as your rights, complaints, or how we handle a data breach), this group policy prevails.
What information we collect
We only collect information we genuinely need for the purposes set out in this policy. Depending on which of our business units you interact with, the information we collect may include:
Identity information
- Your name (and the name of the business or organisation you represent, if applicable)
- Your role or job title where you are interacting with us in a business capacity
- Identifiers contained on identification documents, where we need to verify your identity for a specific purpose (such as opening a credit account or, for ACMA & EESS work, confirming an authorised representative). We collect the minimum information necessary and do not retain copies unless we are required to
Contact information
- Email address, telephone number(s) and postal/delivery address
- Your preferred communication channel
Account and transaction information
- Account credentials (usernames, hashed passwords — we do not store passwords in plain text)
- Orders, purchases, subscriptions, services engaged, support requests and the history of our dealings with you
- Payment information necessary to process a transaction. Card numbers and full payment details are processed by our payment processors and are not stored on our systems
Technical information
- IP address, device type, browser type and version, operating system, screen size
- Pages viewed, time spent, links clicked, referring URL and search queries on our sites
- Cookie and tag identifiers (see the Cookies section below)
Communications and content you provide
- The content of enquiries, support requests, feedback, survey responses and product reviews
- Records of calls, emails and chats with our team, where we keep them for service quality and dispute resolution purposes
- For waveMail and waveSuite customers, the data you process through our platforms in the course of using them (handled in accordance with the relevant unit-specific terms and notices)
Information you choose to share
- Personal preferences, areas of interest, and any other information you provide voluntarily (for example, when subscribing to a particular topic)
- Public social media interactions where you tag or message us
You generally do not have to provide personal information to us, but if you choose not to provide information we need for a particular purpose, we may not be able to provide you with the relevant product, service or response. We will tell you at the point of collection if information is mandatory for what you are asking us to do.
How we collect it
We collect personal information in several ways:
Directly from you when you place an order, create an account, subscribe to a service, fill in a contact form, attend a meeting or webinar, sign up to a newsletter, apply for a job, or otherwise engage with us.
Automatically through our websites and platforms when you visit or interact with them, through cookies, server logs, and similar technologies. See the Cookies section below for what we collect this way and how to control it.
From third parties in limited circumstances, including:
- From your colleagues or organisation, if you are introduced to us in a business capacity
- From referees you have nominated, if you are applying for a job with us
- From service providers we use to verify identity, process payments, or detect fraud
- From publicly available sources, where we are conducting research or due diligence in connection with a business relationship
Where we collect information about you from a third party, we will, where practicable, let you know that we have done so.
Why we collect and use it
We use personal information for purposes connected with our business, including to:
- Provide the products, services and platforms you have ordered, subscribed to or asked us about
- Communicate with you about your account, your orders, your services and your support requests
- Operate, secure and improve our websites, platforms and services
- Process payments and refunds, manage credit accounts where applicable, and reconcile transactions
- Maintain records, conduct internal reporting, accounting, auditing and analytics
- Develop new products and services, and understand how our existing ones are used
- Send you marketing communications you have asked to receive, and tell you about new things we are doing that we think will interest you (see the Marketing section)
- Protect against fraud, security incidents, abuse and other unlawful activity
- Comply with our legal obligations, respond to lawful requests from authorities, and exercise or defend legal rights
- Manage business changes such as mergers, acquisitions, restructures or asset transfers
If we want to use your personal information for a materially new purpose, we will tell you and, where required, ask for your consent.
Who we share it with
We do not sell personal information. We share it only where it is necessary for one of the purposes above, and only with parties who have appropriate confidentiality and security obligations. The categories of recipient are:
Service providers and contractors who help us operate the business, including:
- Payment processors
- Hosting, infrastructure and cloud providers
- Email, SMS, customer messaging and helpdesk platforms
- Accounting, auditing, banking and legal advisors
- Analytics, advertising and marketing platforms (used in the manner described in the Cookies section)
- Identity verification and fraud prevention providers
- Delivery, logistics and installation providers (for Techwave Store orders)
- Manufacturers, distributors and authorised repairers (for warranty, repair or recall purposes)
Business partners where you have engaged with a Techwave service that involves a partner (for example, a finance partner you have chosen to apply for credit with). We will tell you about these arrangements when they apply.
Authorities and regulators, including law enforcement, government agencies and regulators (such as the ACMA, the Office of the Australian Information Commissioner, or the Australian Taxation Office), where required or permitted by law. For our ACMA & EESS Affairs work, we routinely interact with the ACMA on behalf of Responsible Suppliers; the relevant unit-specific notice gives more detail.
Acquirers and successors, in connection with an actual or potential corporate transaction (such as a sale, merger, or restructure) affecting Techwave or any of its business units. Recipients in this context are bound by confidentiality.
Other parties with your consent, or where you have specifically asked us to share information with them.
Overseas transfers
Some of the service providers and platforms we use are located outside Australia. This means personal information we hold may be transferred to, stored or processed in countries including the United States, the United Kingdom, the European Union and New Zealand, depending on the provider concerned.
Where we transfer personal information overseas:
- We choose providers with strong security and privacy practices, and we review them periodically
- We put contractual terms in place that require the recipient to handle personal information consistently with this policy and applicable laws
- For information about visitors from the EU and UK, we rely on appropriate transfer mechanisms (such as Standard Contractual Clauses) where applicable — see the EU and UK section
You can ask us for more detail about how we protect information transferred overseas at any time — see the Contact section.
Automated processing and AI
We use automated tools and AI-based systems in some parts of our business. Examples include:
- Spam filtering and abuse detection on our forms and inboxes
- Fraud screening on online orders and account creation
- Analytics and personalisation that select what content or recommendations to show you on our sites
- Drafting and suggestion features in our customer service and marketing tools, including the AI features we offer in waveMail and (when launched) waveSuite
Where these systems influence decisions that affect you in a significant way — such as whether to fulfil an order, extend credit, or accept a service application — a human is involved in making the final decision. We do not currently make decisions about individuals using AI alone.
If you have questions about how we have used automated processing in a particular interaction, or you would like to ask us to review a decision that involved automated processing, contact us using the details in the Contact section.
We will update this section as our use of AI evolves. We treat the careful, transparent use of AI as a core part of how we earn customer trust — not an afterthought.
How long we keep your information
We do not keep personal information for longer than we need to. The retention period depends on the type of information and the purpose:
- Account and transaction records are kept for the life of your account and for a period afterwards to meet our tax, accounting and warranty obligations (typically seven years from the relevant transaction, in line with Australian record-keeping requirements)
- Marketing preferences and unsubscribe records are kept for as long as needed to honour your choices
- Customer service correspondence is kept for a reasonable period to handle follow-up issues and improve service quality, after which it is deleted or de-identified
- Job applicant information is kept for the duration of the recruitment process and, where you consent, for a limited period afterwards in case of future opportunities
- Website and analytics logs are kept for shorter periods, typically measured in months
When we no longer need personal information, we securely delete it or de-identify it so it can no longer be associated with you.
How we protect your information
We take protecting personal information seriously and have practical measures in place to do so:
- Encryption in transit: connections to our websites and platforms use HTTPS (TLS) by default
- Access controls: only staff and contractors who need access for their role can see personal information, and access is logged
- Authentication: we use strong authentication including multi-factor authentication for administrative access to systems holding personal information
- Provider review: we evaluate the security practices of the service providers we use and contractually require them to maintain appropriate standards
- Staff training: our team is trained on privacy and security, and on this policy
- Patching and monitoring: we keep our systems up to date and monitor for security incidents
No system can be made completely secure, and we cannot guarantee against every possible incident — but if an incident does occur we will respond promptly as set out below.
Data breach response
If personal information we hold is involved in a data breach that is likely to result in serious harm, we will:
- Contain the breach and limit any further compromise as quickly as we can
- Assess what information is affected and who is affected
- Notify affected individuals so they can take protective steps
- Notify the Office of the Australian Information Commissioner (OAIC) as required under the Notifiable Data Breaches scheme, even though we comply with the scheme voluntarily
- Cooperate with any other regulator with jurisdiction (for example, a State or Territory privacy regulator, or an overseas authority for international visitors)
Affected individuals will be notified by the means we have on file for them, with a clear description of what happened, what information was involved, what we are doing about it, and what they can do to protect themselves.
Your rights
You have a number of rights over your personal information, and we make these easy to exercise.
Access — you can ask for a copy of the personal information we hold about you. We will respond within 30 days. We do not charge for routine access requests, but for requests that involve substantial work (for example, recovering archived records going back many years) we may charge reasonable cost recovery, and will tell you the estimated cost before doing the work.
Correction — if information we hold about you is inaccurate, out of date, incomplete, irrelevant or misleading, you can ask us to correct it. If we agree, we will correct it promptly; if we disagree, we will explain why and you can ask us to attach a note to the record reflecting your view.
Marketing opt-out — you can withdraw consent for marketing communications at any time. See the Marketing section for how.
Withdraw consent — where we rely on your consent for a particular use, you can withdraw it. We will stop the relevant processing as soon as we reasonably can. Withdrawing consent does not affect anything we did with the information before you withdrew it.
Complain — if you think we have mishandled your personal information, you can complain to us, and to the OAIC. See the Complaints section.
For visitors from the EU and UK, additional rights apply — see the EU and UK section.
To exercise any of these rights, contact us using the details in the Contact section. We will ask for enough information to confirm your identity before acting on the request.
Marketing communications
We send marketing communications only to people who have actively chosen to receive them. When you create an account or fill in a form, you can tick a box to opt in to marketing communications — the box is not pre-ticked. We will not subscribe you to marketing communications just because you have purchased something or signed up for an account.
If you have opted in, we may send you information about:
- New products, services and platform features
- Offers, promotions and events
- Spotlight articles and other content we publish
- Updates relevant to the business units or topics you have indicated an interest in
Each marketing email and SMS we send includes a clear way to unsubscribe — typically an unsubscribe link in emails and a reply STOP option for SMS. Unsubscribing applies immediately. You will still receive non-marketing service communications (such as order confirmations, account notifications, and security alerts) because they are necessary for the service.
If you have opted in to marketing, we may use anonymised or hashed identifiers to show you relevant ads on third-party platforms such as Meta and Google. You can opt out of this without unsubscribing from our direct communications by contacting us, or by adjusting your ad settings on those platforms.
Cookies and similar technologies
Like most websites, our sites use cookies, pixels and similar technologies. We use them in the following categories:
- Strictly necessary — cookies needed for the site to work (such as keeping you logged in, holding your shopping cart, and protecting against fraud). These cannot be disabled because the site will not work properly without them
- Functional — cookies that remember your preferences (such as language, region, and accessibility choices) to give you a better experience
- Analytics — cookies that help us understand how people use our sites so we can improve them. We use providers such as Google Analytics for this
- Marketing — cookies and pixels used to measure the effectiveness of our marketing and, for people who have opted in, to show relevant ads on third-party platforms
Where required, we will ask for your consent before setting non-essential cookies, and you can change your preferences at any time through the cookie preferences link in our website footer. You can also control cookies through your browser settings — most browsers let you block cookies, delete existing ones, or be alerted before a cookie is stored. Blocking cookies may affect how parts of our sites work.
Some of our sites also use web push notifications. You can choose to allow or block these the first time you visit a site that uses them, and you can change your choice at any time in your browser’s notification settings.
Children’s information
Our products and services are designed for businesses and adults. We do not knowingly collect personal information from anyone under 16 years of age. If you believe we hold information about a person under 16, please contact us and we will delete it.
If you apply for a job with us
If you apply for a role with Techwave, we collect personal information necessary to assess your application — typically your CV, contact details, employment and education history, and the information you choose to provide in your cover letter or interviews.
We use that information solely for recruitment purposes. We may contact your nominated referees, and we may do background or right-to-work checks where they are relevant to the role; we will tell you before we do. We do not share applicant information with anyone outside Techwave except as needed for the recruitment process (for example, with a background-checking provider you have consented to).
If your application is unsuccessful and you have not asked us to keep your details on file, we will delete your information within a reasonable period.
Visitors from the EU and UK
If you are located in the European Economic Area or the United Kingdom, your local data protection laws (the EU GDPR and the UK GDPR) give you additional rights and place additional obligations on us. We honour those rights:
- Lawful basis: we process your personal information on the basis of your consent, to perform a contract with you, to comply with a legal obligation, or for our legitimate interests (such as operating and improving our business), depending on the situation
- Right to erasure: you can ask us to delete personal information we hold about you, subject to limits where we are legally required to retain it
- Right to portability: where we process your information by automated means based on consent or contract, you can ask to receive a copy in a structured, machine-readable format, or for us to send it to another controller where technically feasible
- Right to restrict or object: you can ask us to restrict processing in certain circumstances, or object to processing based on legitimate interests
- Right to withdraw consent: where we rely on your consent, you can withdraw it at any time
- Right to complain to your supervisory authority: you can lodge a complaint with the data protection authority in your country
By using our services from the EU or UK, you understand that your personal information will be transferred to Australia, and that Australia is not formally recognised by the European Commission as offering an adequate level of data protection. We rely on appropriate safeguards (such as the European Commission’s Standard Contractual Clauses) for such transfers and have committed in this policy to handle your information consistently with the rights described above. You can ask us for more detail on the safeguards we use.
Complaints
If you have a concern about how we have handled your personal information, please raise it with us first. We take privacy complaints seriously and we want a chance to put things right.
To make a complaint, contact us at [email protected] with enough detail for us to understand the issue. We will acknowledge your complaint within five business days, investigate it, and respond with the outcome within 30 days. If your complaint is complex and needs more time, we will keep you updated.
If you are not satisfied with our response, you can take the matter to the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au, even though we comply with the Privacy Act voluntarily. EU and UK visitors can also lodge a complaint with their relevant supervisory authority.
Changes to this policy
We may update this policy from time to time — for example, when we change how we use information, add new business units, or update our practices to reflect changes in the law or in industry best practice.
When we make material changes, we will update the effective date at the top of this policy, increment the version number, and (where practical) notify people who have an active account or subscription with us before the changes take effect. Continued use of our services after the effective date means you have accepted the updated policy.
Earlier versions of this policy are available on request.
Contact us
For any privacy enquiry, including to exercise any of the rights in the Your rights section, to ask a question, or to make a complaint:
Email: [email protected]
Post:
Privacy Enquiries
Techwave Pty Ltd
Level 9, 123 Epping Rd
Macquarie Park NSW 2113
Australia
Techwave Pty Ltd · ABN 13 644 894 397