Broken Hill Distillery Policy

November 2019

1. Broken Hill Distillery is committed to respecting the privacy of
your personal information. This Privacy Policy explains how we deal with your
personal information that we collect, use, disclose or process.
2. We will update this Privacy Policy from time to time when we change how we
deal with personal information. We will post any changes to the Privacy Policy
on our website, and will endeavour to notify you when this occurs.
3. In addition to the provisions of this Privacy Policy, there may also be specific
and additional privacy and consent provisions that apply to certain collection
channels of personal information. Because those specific and additional
provisions also relate to your privacy protection, we recommend that you
review them wherever they appear. In the event of any inconsistency between
the provisions of this Privacy Policy and those other specific and additional
provisions, the specific and additional provisions will prevail.
Definition of personal information
4. Throughout this Privacy Policy, we use the term ‘personal information’ to refer
to information relating to an identified or identifiable natural person, including
information or an opinion about an identified individual, or an individual who is
reasonably identifiable, whether the information or opinion is true or not; and
whether the information or opinion is recorded in a material form or not. For
example, your full name, date of birth, address, mobile telephone number,
email address and credit card details are examples of information which may
constitute personal information. Personal information may also include
information we may collect about your individual preferences.
Problems, complaints or queries
5. If you have any questions about our Privacy Policy, or any problems or
complaints about how we have collected, used, stored, handled, disclosed
and/or processed your personal information, please contact our privacy officer
via one of the following channels:
For individuals in Australia:
Mail: Broken Hill Distillery, 400 Thomas St, Broken Hill, 2880
Please allow 30 days for this request to be processed. On receipt of your query,
problem or complaint a review will be conducted and findings will be communicated

to you where required. If you do not receive a satisfactory response to your query,
problem or complaint within 30 days, you may refer your query, problem or complaint
to the Office of the Australian Information Commissioner via the contact details listed
at, or, for individuals in the EU, to the
data protection supervisory authority in your country.

On what basis do we process your data?

Lawful basis of processing
7. Broken Hill Distillery will only collect, monitor, use, disclose, or process any personal
information about you with your consent (which we endeavour to obtain at the
same time as collecting your personal information) or if it is otherwise lawful to
do so. The only personal information collected by us is what has been
provided to or collected by us in accordance with this Privacy Policy or has
been provided to us lawfully by third parties. We will generally deal with your
personal information for the primary purposes set out in this Privacy Policy.
8. For individuals in the European Union, Broken Hill Distillery may also rely on the
lawful bases of contract and legitimate interest. That is, where you enter into a
contract with us, Broken Hill Distillery will process your personal information because
it is necessary for the performance of that contract with you. In some
circumstances, such as fraud prevention, Broken Hill Distillery may also have a
legitimate commercial interest in processing your personal information that is
not outweighed by your interests, rights and freedoms. Broken Hill Distillery may also
request your explicit consent to process your personal data from time to time
for various purposes.
9. Broken Hill Distillery also reserves the right to use, disclose or otherwise process any
personal information to satisfy any law, regulation or legal request, or in
relation to Broken Hill Distillery’s other legitimate interests such as where that
personal information is relevant to legal action relating to Broken Hill Distillery).
When and how do we collect personal information?
Collection channels
10. We (or our subcontractors) collect and combine personal information in a
number of ways through the following channels (each, a Collection Channel):
1. our online properties (here and after, each a “Website”), including:
1. our websites, including but not limited
2. any related Broken Hill Distillery website, social media page, internal
website, intranet and any Broken Hill Distillery mobile or tablet

2. our service providers acting on behalf of us (including but not limited to
Eventbrite and Pozible), or other legitimate third party sources;

3. physical and other ad-hoc channels of collecting personal information
in relation to events and the Broken Hill Distillery (such as through
paper forms or tablets); and
4. any other means through which an individual provides personal
information to Broken Hill Distillery,including either physically or electronically.

Active Information Collection
11. Personal information may be collected and combined via our Collection
Channels if you:
1. you purchase products either as a “guest” or a “member” through a
Collection Channel, or create an account with Broken Hill Distillery through a
Collection Channel;
2. subscribe to any newsletters, updates, alerts or news and media
releases, or request launch or event information or information about
our products or services or other information services as well as third
party products or services;
3. have previously provided us with personal information prior to this
Privacy Policy coming into effect, either directly from you personally or
via a third party;
4. complete and submit any forms or surveys provided to Broken Hill Distillery,
either physically or electronically;
5. conspicuously publish or provide on request your personal information
to Broken Hill Distillery;
6. contact us or our clients directly in person or via any medium including
mail, telephone, social media and commercial electronic messages
(SMS (Short Message Service), MMS (Multimedia Message Service),
IM (Instant Messaging) and email) including via the contact details
listed on a Website;
7. participate in any events, offers, promotions, competitions or marketing
8. interact with a Website for a specific purpose; or
9. interact with or browse a Website generally.
12. We also collect your information through other legitimate third party sources
including list brokers, social media organisations, and other data providers or
organisations that share data in circumstances where it is lawful and/or you
have given permission for them to do so.
13. We may collect personal information from you in a passive manner including
through the use of cookies and other tracking tools such as internet tags,
tracking pixels, web beacons and unique device identifiers. For further
information about the use of passive personal information collection, see
paragraph 35 below.
What kind of personal information does Broken Hill Distillery

14. We may collect personal information including:

1. your full name, contact details (such as your email address, phone
number, and contact preferences), location, and passwords you create
for the Broken Hill Distillery;
2. information about your preferences, interests, opinions, feedback and
experiences with our products or services. This information is collected
in order to tailor our communications to you and continuously improve
our products and services;
3. financial details, if you have provided them to us, such as your bank
account, credit card, Paypal or other online payment system details
(where you purchase any products or services from us);
4. When you visit the Broken Hill Distillery website, we may also collect personal
information about you in the following general categories:
1. usage and preference information: we collect information about
how you interact with the Broken Hill Distillery website, including the
pages you visit, your preferences and settings that you choose.
We may do this through the use of cookies and other similar
technologies that uniquely identify you;
2. device information: we may collect information about your
mobile device such as the hardware model, operating system,
preferred language, unique device identifier and mobile network;

 other information: we may also collect and log information such as your IP
address, access dates and times, browser type and pages visited when you
interact with a website.
1. any other personal information you provide directly to us. Where you provide
us with unsolicited personal information, we will retain this information where it
falls within our primary purposes for collection of personal information (as
stated in this Privacy Policy).
2. any other personal information requested or required by a Collection Channel.
Sensitive Information
15. We do not seek to collect sensitive information (or “special categories” of
information under the GDPR).
16. If we do collect sensitive information, we will only do so with your consent and
where you provide it to us directly. Where you provide us with any sensitive
information (including, but not limited to, information about your sexual
orientation, religious beliefs, medical and/or criminal history), we will only use
this information for the purposes stated at the time of collection and will only
share this information with our trusted third parties in the manner stated in this
Privacy Policy.
Consequences of not providing personal information
17. If you don’t provide us with personal information, we may be unable to provide
you with our goods and services or other content, information, upcoming opportunity,
promotion, event or product information.

For what purposes does Broken Hill Distillery collect, hold, use

and disclose personal information?

18. Personal information that Broken Hill Distillery collects will be used for the following
primary purposes:
Special offers, marketing and advertising
a. where you have provided your separate consent, to provide you with early access
to new releases, exclusive events, special offers, newsletters, events and
promotions either of Broken Hill Distillery or its trusted partners, and to otherwise market to
you (with direct marketing materials), via any medium including mail, telephone,
commercial electronic messages (such as SMS, MMS, instant messaging, email,
social media, mobile applications), or any other form of electronic, emerging, digital
or conventional communications channel.;
b. to provide you with relevant advertising;
Managing our relationship
c. to carry out any purchases you make and otherwise manage our commercial and
trading relationship with you including identifying you in our system and contacting
you, invoicing you correctly, sending you our products and to address your
expectations of us in respect of how we conduct our business;
d. to ensure that your personal information remains up-to-date and complete;
e. to provide you with information about your Broken Hill Distillery account, customer
account, transactions, content, services and products;
f. to fulfil obligations in respect of any contract between you and Broken Hill Distillery; to
render services related to our Broken Hill Distillery and customers (such as after sales
services and enquiries); to facilitate payments from you;
g. to contact you, including sending you any technical, administrative or legal notices
relevant to Broken Hill Distillery or the Broken Hill Distillery Websites;
h. to otherwise maintain our relationship with you;
Broken Hill Distillery’s Website
i. to maintain the functionality of the Broken Hill Distillery website, including the provision of
information to you relating to the content available on the website; to improve the
website and system administration;
Improving our offerings

j. to better understand and meet your needs and interests, to enable us to improve
the nature of the goods and services we provide and to more accurately market our
goods and services, and research our customers;
k. to obtain opinions or comments about products and/or services and to conduct
other research and development;
l. to record statistical or de-identified data for analysis including marketing analysis;
m. to conduct market research including identifying likeminded individuals;
n. to share personal information with our group companies and their related bodies
corporate and agents, and other trusted third parties in the manner described in this
Privacy Policy;
o. for any further purposes stated in a particular Collection Channel;
p. where explicitly notified to you, to undertake recruitment for Broken Hill Distillery;
q. to manage your employment with Broken Hill Distillery (if applicable);
r. any other purpose as may be deemed reasonably necessary by Broken Hill Distillery in
the circumstances;
s. as needed to satisfy any law, regulation or legal request, to protect the rights or
property of Broken Hill Distillery, any member of the Broken Hill Distillery group, or any member of
the public, to protect the integrity of the Broken Hill Distillery website, to fulfill your requests,
or to cooperate in any law enforcement investigation or an investigation on a matter
of public safety.
Contact by Broken Hill Distillery
19. Broken Hill Distillery does not send advertising or marketing information without
obtaining prior consent, for example the consent contained within this Privacy
Policy. If you receive communications from Broken Hill Distillery which you do not
wish to receive, you may remove your name from the database either by
using the functional unsubscribe facility (if the communication is via
commercial electronic message) or by contacting Broken Hill Distillery’s Privacy
Officer as described above. Please allow 30 days for this request to be
20. Despite removing your name from the database from receiving future
advertising and marketing information, Broken Hill Distillery may send you non-
commercial “Administrative Emails”. Administrative Emails relate to a
Broken Hill Distillery user account and may include administrative and transaction
confirmations, requests and inquiries or information about a particular
Broken Hill Distillery user account. If you do not wish to receive such
communications from Broken Hill Distillery, you may remove your name from the

database by contacting Broken Hill Distillery’s Privacy Officer. Please allow 30 days
for this request to be processed.
Automated decision-making
21. Broken Hill Distillery does not make decisions that produce significant effects on you
which are solely based on automated decision making.
How do we share your personal information?
22. Solely for the purposes described above, personal information may be shared
with the entities below including their directors, servants and agents and
related bodies corporate:
1. our marketing and email sending partners;
2. technical service providers, such as mail carriers, hosting providers, IT
companies and communications agencies;
3. other trusted service providers; and
4. Broken Hill Distillery group companies (if applicable).
23. These recipients may be engaged by Broken Hill Distillery to perform a variety of
functions, such as legal and accounting services, data storage, support
services, conducting market research, processing credit card payments,
assisting with promotions and providing technical services for our websites.
These companies may have access to personal information if needed to
perform such functions. Your credit card details are only used to facilitate your
purchase. They are not used for any other purpose and will never be supplied
to a third party other than Broken Hill Distillery or our relevant service provider. If you
are a business we trade with, we may disclose your information to debt
recovery agents or credit reporting bodies if necessary.
24. Some of the recipients of your personal information may be located overseas.
Broken Hill Distillery employees, data processors and other trusted third parties are
obliged to respect the confidentiality of any personal information held by
Broken Hill Distillery. However, security of communications over the Internet cannot
be guaranteed, and therefore absolute assurance that information will be
secure at all times cannot be given. Broken Hill Distillery will not be held responsible
for events arising from unauthorised access to personal information except to
the extent required by the relevant privacy laws.
25. The recipients of your personal information are located in countries including
Australia, the United Kingdom and the United States.
26. For individuals in the EU, please note that the recipients of your personal
information may be located in countries in which the privacy or data protection
laws differ from those of the European Union, and which are not the subject of
an adequacy decision by the European Commission. For recipients of your
personal information in Australia, appropriate or suitable safeguards over your
personal data have been put in place by virtue of our compliance with the
standard data protection contract clauses approved by the European
Commission. Please contact our Privacy Officer for more information.

How do we hold, and long do we hold your personal


27. Broken Hill Distillery takes appropriate security measures to keep personal
information secure and to prevent unauthorised access, disclosure,
modification or destruction of personal information. Broken Hill Distillery, its
employees and its subcontractors are obliged to respect the confidentiality of
any personal information held by Broken Hill Distillery.
28. Broken Hill Distillery also takes reasonable steps to keep personal information
accurate, up to date, complete and relevant. Broken Hill Distillery takes reasonable
steps to ensure only those necessary have access to your personal
information. Personal information is stored on secure servers that are
protected in controlled facilities. This service may be performed on our behalf
and data may be hosted by our selected data storage providers. In some
cases these facilities may be overseas, as described above. Broken Hill Distillery
retains your information only for as long as necessary for the purposes listed
in this Privacy Policy.

Your privacy rights

29. You have a number of rights under the Australian Privacy Law and the GDPR.
These include:
1. (access) to request access to your personal information from us, in a
commonly used electronic format. On a case by case basis, Broken Hill Distillery may determine that it is not legally required to give an individual
access to personal information, in which case Broken Hill Distillery will provide
you with a written notice of its refusal to provide access;
2. (correction) to request that we correct your personal information;
3. (withdrawing consent) to withdraw your consent for us to use your
personal information. Please note that you can also opt-out of online
marketing communications at any time by using the unsubscribe
feature in each electronic commercial message;
4. (transparency) to be informed generally about the collection and use of
your personal data, including where we intend to further process your
personal data for additional purposes other than as discussed above;
5. (complaint) to complain about a breach of the Australian Privacy
6. (deletion) you may also request that we delete your personal
information, and all reasonable steps to delete the information will be
made, except where it is required for legal reasons. Deletion of
information may result in Broken Hill Distillery and its service providers or
partners being unable to facilitate or provide you with information about
certain transactions (including the uploading, access to, and receipt of
content on a Website), other product content, or services information,
upcoming promotion, competition or event information, and/or provide
certain content, goods or services. Unless required by applicable law,

we are not responsible for removing your personal information from the
lists of any third party who has previously been provided your
information in accordance with this policy.

30. If you are an individual in the EU, you have additional rights under the GDPR
that you can exercise against the “controller” of your data. Where we are the
controller of your data, your rights include:
1. (access) to request that we transfer your personal information to
another service provider of your choosing;
2. (erasure) to request that we erase your personal data. All reasonable
steps to delete the information will be made, except where it is required
for legal reasons. Deletion of information may result in us being unable
to facilitate or provide you with information about certain services
(including the uploading, access to, and receipt of content on a website
or the Broken Hill Distillery Application, and purchase transactions undertaken
on a website);
3. (objection and restriction) in some circumstances, to object to the use
of your personal data by us and request that we restrict our use of your
personal information; and
4. (complaint) to lodge a complaint in relation to our processing of your
personal data with a data protection supervisory authority under the

31. To exercise these rights, please contact us at the contact details listed at the
beginning of this Privacy Policy. Please allow for a reasonable amount of time
for us to process your request, which will generally be up to 30 days.


Anonymity and Pseudonymity
32. Where practicable, Broken Hill Distillery will allow you to deal with us on an
anonymous or pseudonymous basis. If this is practicable, our collection
channels will only seek information in this way. However, where it is not
practicable for the purposes for which information is collected, we will seek
the personal information identified above. It will not be practicable to deal with
you on an anonymous or pseudonymous basis when we wish to send you
direct marketing materials or need to provide you with goods or services
requested by you.
Sale of the company
33. If Broken Hill Distillery merges with, or is acquired by, another company, or sells all
or a portion of its assets, your personal information may be disclosed to our
advisers and any prospective purchaser’s adviser, and may be among the
assets transferred. However, personal information will always remain subject
to this Privacy Policy.

34. The collection of personal information is neither intended for, nor directed to,
persons who are under the age of eighteen (18) years old. Personal
information will not be knowingly collected about any person who is known by
Broken Hill Distillery to be under the age of eighteen (18).
Passive Information Collection
35. As with many commercial websites (and mobile and tablet applications), we
may also collect information which tells us about visitors to our websites. For
example, we may collect information about the date, time and duration of
visits and which pages of a website are most commonly accessed. This
information is generally not linked to the identity of visitors, except where a
website is accessed via links in an email we have sent or where we are able
to uniquely identify the device or user accessing a website. By accessing a
website via links in an email we have sent and/or by accessing a website
generally including when you are logged into an account, you consent to the
collection of such information where it is personal information.
36. As you navigate through our websites, certain information can be passively
collected (that is, gathered without you actively providing the information)
using various technologies, such as Unique Device Identifiers (UDI), cookies,
Internet tags or web beacons, and navigational data collection (log files,
server logs, clickstream). In certain circumstances, this information may be
considered anonymous information or personal information under the Privacy
Act 1988 (Cth) and the GDPR, dependent on the device used and the method
by which an individual connects to the Internet. Your Internet browser
automatically transmits to the website you are browsing some of this
anonymous information or personal information, such as the URL of the
website you just came from, the Internet Protocol (IP) address, the UDI (if
applicable) and the browser version your device is currently using. Our
websites may also collect anonymous information or personal information
from your device through cookies and Internet tags or web beacons. You may
set your browser to notify you when a cookie is sent or to refuse cookies
altogether, but certain features of a website might not work without cookies
and this may limit the services provided by a website. Cookies and other
technical methods may involve the transmission of information either directly
to us or to another party authorised by us to collect information on our behalf.
37. Our websites may use and combine such passively collected anonymous
information or personal information and/or information from various third party
sources, including as described above, and may combine this anonymous
information or personal information with other personal information collected
from you to provide better service to website visitors and users, customise a
website based on your preferences, compile and analyse statistics and
trends, provide you with relevant advertising when you visit a website or a
third party website, and otherwise administer and improve a website for your
use. We may combine your visitor session information or other information
collected through tracking technologies with personally identifiable information
from time to time in order to understand and measure your online experiences
and to determine what products, promotions and services are likely to be of

interest to you. By accessing a website, you consent to information about you
being collected, compiled and used in this way.
38. For more information about cookies and how you can opt out, you can
Broken Hill Distillery and other websites
39. Our websites may, from time to time, contain links to the websites of other
organisations which may be of interest to you. Their inclusion cannot be taken
to imply any endorsement or validation by us of the content of the third party
website. Linked websites are responsible for their own privacy practices and
you should check those websites for their respective privacy statements.
Broken Hill Distillery is not responsible, nor does it accept any liability, for the
conduct of companies linked to our websites.
40. We may use third party advertisements on our Websites. All third party
advertising, if paid for, is paid for by the relevant third party advertisers and
are not recommendations or endorsements by Broken Hill Distillery or any of its
affiliates. Broken Hill Distillery is not responsible for the content (including
representations) of any third party advertisement on a website. Cookies may
be associated with these advertisements to enable the advertiser to track the
number of anonymous users responding to the campaign. We do not have
access to or control of cookies placed by third parties.
User submissions
41. Broken Hill Distillery may provide areas on a Website where you can upload user-
generated content, post or provide information about yourself, communicate
with other users, provide reviews for content, products and/or services or
interact with or vote on particular content. This information may be shared
with others and may be publicly posted on our Websites, including without
limitation, other social media platforms and other public forums in which you
choose to participate. This information may become publicly available and
may be read, collected and used by others outside of our Websites. Broken Hill Distillery is not responsible for the conduct of others who may read, collect and use
this information.

Are you 18 or older? This website requires you to be 18 years of age or older. Please verify your age to view the content, or click "Exit" to leave.