Taitung Australia Pty Ltd β€” Legal

Privacy Policy

Effective date: 1 July 2026 Last updated: 1 July 2026 ACN 101 496 646
βœ‰︎ privacy@taitung.com.au

1.Introduction

This Privacy Policy describes how Taitung Australia Pty Ltd (ACN 101 496 646, “we,” “us,” “our,” or “Taitung”) collects, uses, discloses, and otherwise handles personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

This policy applies to all Taitung digital services and platforms, including but not limited to:

  • TAITIME (employee time-tracking kiosk at taitime.web.app)
  • TAICREDIT (customer credit application at credit.taitung.com.au)
  • TaiOrder (wholesale ordering portal)
  • TAIPULSE (management dashboard)
  • Sales365 (internal sales CRM)
  • TAIBOARDS (team kanban board)
  • Taitung Logistics (dispatch and delivery management)
  • Visitor sign-in kiosk (visitor.taitung.com.au)
  • ImportWatch and other internal tools
  • Main website (taitung.com.au)

Our registered office is located at:

Taitung Australia Pty Ltd
355 Newbridge Road
Moorebank NSW 2170

2.Personal Information We Collect

2.1 Information You Provide Directly

  • Account Registration: name, email address, phone number, job title, company details
  • Credit Applications: full name, date of birth, ACN/ABN, business structure, financial information, driver's license details, personal guarantor information, contact details
  • Employee Time Tracking: employee name, employee ID, GPS location (for geofence compliance), shift data, attendance records
  • Orders and Transactions: billing address, delivery address, product preferences, purchase history, payment information
  • Contact and Support: correspondence with our team, including inquiries, feedback, and complaints
  • Visitor Sign-In: visitor name, company, purpose of visit, host name, photo (biosecurity acknowledgement)

2.2 Information Collected Automatically

  • Device Information: device type, operating system, browser type, IP address, device identifiers
  • Usage Data: pages visited, time spent on features, clicks, interactions, error logs
  • Location Data: GPS coordinates (where explicitly enabled for geofence features)
  • Cookies and Similar Technologies: session identifiers, user preferences, authentication tokens
  • Server Logs: access logs, authentication attempts, system performance data

2.3 Information from Third Parties

  • eSuite ERP System: customer records, order history, payment status, inventory data (via secure API integration)
  • Google Workspace: email metadata, calendar events (for sales and operations features)
  • ABR (Australian Business Register): business entity information for credit applications
  • Payment Processors: transaction history, payment status, dispute records
  • Government Databases: where authorised for know-your-customer verification (ABN/ACN lookups)

2.4 Sensitive Information

We collect sensitive information only where necessary for specific functions:

  • Driver's license numbers (TAICREDIT for identity verification)
  • GPS location data (TAITIME for employee geofencing)
  • Biometric data: none collected
  • Health information: not collected except where voluntarily disclosed in support requests
  • Financial information: collected only for credit assessment (TAICREDIT)

3.How We Use Personal Information

3.1 Service Delivery

  • Enabling account access and authentication
  • Processing orders, deliveries, and customer transactions
  • Managing employee time tracking and payroll integration
  • Providing customer credit assessments and credit facility management
  • Delivering dispatch, logistics, and visitor management services
  • Supporting customer and employee service requests

3.2 Business Operations

  • Managing internal communication and collaboration (TAIBOARDS, email, calendar)
  • Analysing sales performance and pipeline management (Sales365)
  • Integrating with eSuite ERP for order fulfillment and inventory management
  • Generating business intelligence reports and dashboards (TAIPULSE)
  • Monitoring system performance and security

3.3 Compliance and Legal

  • Verifying identity and eligibility for credit facilities
  • Complying with Australian taxation and payroll legislation
  • Meeting biosecurity and food handling regulations
  • Responding to legal obligations, court orders, or regulatory enquiries
  • Maintaining audit trails and records retention

3.4 Marketing and Communication

  • Sending transactional notifications (order confirmations, delivery updates, system alerts)
  • Sending promotional communications (only where consent is provided or existing customer relationship exists)
  • Updating you on product availability, pricing, or service changes
  • Conducting customer feedback surveys (with consent)

3.5 Improvement and Analytics

  • Analysing usage patterns to improve service functionality
  • Identifying and fixing technical issues and security vulnerabilities
  • Developing new features and services
  • Training machine learning models on anonymised data only

4.Data Storage and Infrastructure

4.1 Firebase Cloud Infrastructure

All Taitung digital services are hosted on Google Firebase (Cloud Firestore, Realtime Database, Cloud Functions, Cloud Storage) with data residency in australia-southeast1 (Sydney).

4.2 Data Security Measures

  • Encryption in transit: TLS 1.3 or higher for all data transfers
  • Encryption at rest: Google-managed encryption keys (default) with option for customer-managed encryption keys
  • Access controls: Google Sign-In (restricted to @taitung.com.au domain) and role-based access control (RBAC)
  • Firewall rules: Cloud Armor and VPC security configurations
  • Audit logging: Firebase Security Logs and Google Cloud Audit Logs retained for minimum 90 days

4.3 Backup and Disaster Recovery

  • Automated daily backups to geographically redundant Google Cloud Storage
  • 30-day backup retention policy
  • Tested recovery procedures documented and maintained by Taitung

4.4 Third-Party Data Integrations

  • eSuite ERP: API-to-API integration via secure Cloud Functions proxy with CORS restrictions
  • ABR Lookup: Direct API calls with read-only access; no data stored locally
  • Google Workspace: OAuth 2.0 authenticated access with scoped permissions
  • Payment processors: PCI DSS compliant third-party processors; no raw payment card data stored

5.International Data Transfers

While Taitung's primary data residency is australia-southeast1, the following exceptions apply:

  • Google Firebase infrastructure may replicate metadata and backups to other Google Cloud regions for disaster recovery
  • Google Workspace data is subject to Google's global infrastructure policies
  • Third-party integrations (eSuite, ABR, payment processors) may process data outside Australia

We ensure all transfers comply with Australian Privacy Principle 1.2 by:

  • Obtaining explicit consent where required
  • Using service providers that have contractual commitments to APPs compliance
  • Conducting Privacy Impact Assessments for third-party integrations

6.Your Privacy Rights

Under the Privacy Act 1988 (Cth), you have the following rights:

6.1a Right of Access (APP 12.1)

  • You may request access to personal information we hold about you
  • Requests should be in writing to privacy@taitung.com.au
  • We will respond within 30 days (extendable to 60 days for complex requests)
  • A reasonable fee may apply for providing access (capped at actual costs)

6.1b Right to Correct (APP 13)

  • You may request we correct personal information that is inaccurate, incomplete, or outdated
  • We will update records within 30 days or provide written explanation
  • No fee applies for correction requests

6.1c Right to Erasure

  • You may request deletion of personal information, subject to legal retention obligations
  • Deletion requests are assessed for business and legal requirements
  • Some data may be anonymised instead of deleted to preserve business records

6.1d Right to Complain (APP 1.2A)

  • You may lodge a complaint with Taitung: privacy@taitung.com.au
  • You may also lodge a complaint with the Office of the Australian Information Commissioner (OAIC)
  • Complaints will be investigated and responded to within 30 days

6.2 Exercising Your Rights

All requests should be directed to:

Email: privacy@taitung.com.au
Mail: Taitung Australia Pty Ltd, 355 Newbridge Road, Moorebank NSW 2170

7.Cookies and Tracking Technologies

7.1 Cookie Types

We use cookies and similar technologies for the following purposes:

  • Session Management: maintaining login state and user authentication
  • Preferences: remembering language selection (English/Traditional Chinese) and interface preferences
  • Analytics: Google Analytics (anonymised)
  • Functionality: enabling drag-and-drop (SortableJS) and interactive features

7.2 Cookie Management

  • Essential Cookies: required for core functionality (cannot be disabled)
  • Analytics Cookies: optional; can be disabled via browser settings
  • Marketing Cookies: none deployed by default

7.3 Managing Cookies

  • Most browsers allow users to refuse cookies or alert when cookies are being set
  • Disabling cookies may impair service functionality
  • Clear your browser cookies and cache to remove stored identifiers

7.4 Third-Party Analytics

  • Google Analytics is deployed with anonymised IP settings
  • No personally identifiable information is sent to Google Analytics by default
  • Users can opt-out via Google Analytics opt-out browser add-on

8.Data Retention

Personal information is retained for the following periods:

8.1a Employee Data (TAITIME)

  • Active employment: duration of employment
  • Post-employment: 7 years (for payroll audit and FairWork compliance)
  • Geolocation logs: 30 days active, then archived

8.1b Customer Data

  • Active customer accounts: duration of commercial relationship + 3 years
  • Inactive accounts: 3 years from last transaction
  • Credit assessment data: 7 years (for credit risk management and disputes)

8.1c Transaction Data

  • Order records, invoices, delivery logs: 7 years (for tax and audit purposes)
  • Payment records: 7 years (for GST and taxation compliance)

8.1d System and Security Logs

  • Authentication logs: 90 days
  • Error logs and audit trails: 30 days
  • Backup data: 30 days

8.1e Visitor Sign-In Data

  • Visitor records: 12 months
  • Photos: 12 months (deleted after biosecurity clearance period)

8.2 Legal Hold

Data subject to legal proceedings, disputes, or regulatory investigations may be retained beyond standard retention periods. Users will be notified where retention is extended due to legal hold.

9.Security and Data Breach Response

9.1 Security Measures

  • All data in transit is encrypted using TLS 1.3 or higher
  • Data at rest is encrypted using Google-managed or customer-managed encryption keys
  • Access is restricted via Google Sign-In (taitung.com.au domain) and RBAC
  • Multi-factor authentication is available and recommended for all users
  • Regular security assessments and penetration testing are conducted

9.2 Data Breach Notification

In the event of a data breach that poses a serious risk to individuals:

  • We will notify affected individuals within 30 days of discovering the breach
  • Notification will include details of the breach, data involved, and recommended actions
  • We will notify the Office of the Australian Information Commissioner (OAIC) where required
  • A public notice will be published on our website if a large-scale breach occurs

9.3 Incident Response

  • All security incidents are logged and investigated
  • Affected systems are isolated and remediated
  • Post-incident reviews are conducted to prevent recurrence

10.Third-Party Services and Integrations

10.1 Google Cloud Platform (Firebase)

  • Data is processed by Google LLC under Data Processing Addendum (DPA) terms
  • Google's Privacy Policy applies: policies.google.com/privacy
  • Data residency is australia-southeast1

10.2 eSuite ERP Integration

  • Customer and order data is exchanged via Cloud Functions proxy
  • eSuite operates under separate privacy terms; see eSuite privacy policy
  • No data is cached; all queries are real-time via API

10.3 Google Workspace

  • Employee email and calendar data is subject to Google Workspace terms
  • Data is encrypted by Google in transit and at rest
  • Taitung maintains access controls via OAuth 2.0 scoped permissions

10.4 Payment Processors

  • Payment processing is handled by PCI DSS compliant third parties (PayPal, Stripe, Square, etc.)
  • No raw credit card data is stored by Taitung
  • Payment processors' privacy policies apply to transaction data

10.5 ABR (Australian Business Register)

  • ABN/ACN lookups are performed via official ABR API
  • No ABR data is stored locally; only lookup results are cached temporarily
  • ABR terms of use apply: abr.business.gov.au

11.Marketing and Communications

11.1 Promotional Communications

  • Existing customers may receive promotional email about Taitung products and services
  • New contacts require explicit opt-in consent to receive promotional communications
  • All marketing emails include an unsubscribe link compliant with the Spam Act 2003 (Cth)

11.2 Transactional Communications

  • We will send order confirmations, delivery updates, payment reminders, and system alerts
  • These are sent based on service usage and legal obligations (cannot be opted out)

11.3 Email Preferences

  • Users can update communication preferences in their account settings
  • Unsubscribe requests are processed within 10 business days

12.Children's Privacy

  • Taitung's services are not designed for children under 18 years old
  • We do not knowingly collect personal information from children
  • If we become aware that a child has provided personal information, we will delete it and notify the child's parent or guardian

13.Changes to This Privacy Policy

  • We may update this policy from time to time to reflect changes in privacy practices, legal requirements, or technology
  • We will notify users of material changes via email to registered accounts or by posting a notice on our website
  • Continued use of services following notification constitutes acceptance of the updated policy
  • The “Last Updated” date at the top of this policy reflects the most recent revision

14.Contact Us

For privacy enquiries, requests, or complaints, contact:

Taitung Australia Pty Ltd

Email: privacy@taitung.com.au

Mail: 355 Newbridge Road, Moorebank NSW 2170, Australia

Phone: 02 9821 2088

Office Hours: Monday–Friday, 9:00 AM – 5:00 PM AEDT

For complaints to the Australian Information Commissioner:

Office of the Australian Information Commissioner (OAIC)

Phone: 1300 363 992

Email: enquiries@oaic.gov.au

Website: www.oaic.gov.au