Privacy Policy
Effective Date: June 1, 2026
At Advanced Pallet Management ABN: 37 151 260 093, we provide advanced pallet account auditing, reconciliation, and equipment management services. To successfully execute these services, optimize your pooling accounts, and eliminate financial discrepancies, we must process complex commercial, logistic, and transactional datasets.
This document serves as our Privacy Policy and Data Protection Agreement. It dictates how we handle your business data and personal information in absolute alignment with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth) and relevant state-based operational frameworks within New South Wales (NSW).
1. Scope of Data Collection
We collect and process data strictly required to deliver our hire pallet account management service. This data is broadly categorized into two streams:
A. Commercial & Operational Data (Proprietary Business Information)
- Authorized Portal Access: Delegated user credentials, access tokens, and API permissions for your hire pallet portal accounts (including CHEP Portfolio, Loscam Online, or alternative pooling environments).
- Financial & Transactional Records: Hire pallet invoices, correction vouchers, declaration logs, delayed-transfer notices, and monthly reconciliation statements.
- Internal Logistics Analytics: Bulk inbound/outbound physical movement files, bills of lading, gatehouse registers, shipping manifests, and electronic data interchange (EDI) strings.
B. Personal Information (Regulated under the Privacy Act 1988)
While our primary target is equipment asset metrics, the data you supply inherently contains personal information under Australian law. This includes:
- Names, electronic signatures, and identity data of delivery drivers, warehouse staff, and receiving clerks on transfer dockets or manifests.
- Contact details, corporate email addresses, and direct phone numbers of your internal staff, suppliers, and trading partner agents.
- Digital audit trails linking specific employees to transactions or modifications made inside the pallet portals.
2. Permitted Grounds for Collection and Use
We collect, hold, and process this data solely for purposes directly related to our primary business functions under APP 3. Specifically, we use this information to:
- Verify the legitimacy of equipment balances and reconcile physical inventories against hire invoices.
- Identify, escalate, and formally dispute erroneous or unauthorized pallet transfers.
- Enforce correct days-on-hire calculations to minimize exposure to unmitigated hire fees.
- Provide algorithmic insights, variance notifications, and predictive data mapping to optimize supply chain pipelines.
Data Integrity Directive: We do not engage in data monetization. We will never sell, lease, trade, or profiles-for-profit your operational data or personal information to third-party brokers or external marketers.
3. Data Protection and Security
We maintain rigorous technological and physical controls to meet our statutory obligations to protect data from misuse, interference, loss, and unauthorized modification (APP 11):
- Cryptographic Controls: All data sets are encrypted while in transit across networks utilizing Transport Layer Security (TLS) and protected at-rest using advanced AES-256 standard encryption.
- Vaulted Access Separation: Customer portal credentials and API keys are completely isolated from standard operational databases and stored inside specialized, cryptographically secure password vault architectures.
- Data Minimization: We isolate and parse only the specific data fields required to run calculations. Extraneous underlying metadata within your order files is bypassed wherever technically feasible.
4. Strict Non-Disclosure and Shielding of Internal Data
We enforce a strict wall of separation between your proprietary internal analytics and the equipment hire pooling providers.
- Zero Sharing of Internal Logs: We will never share, expose, or provide access to your internal logistics data, bulk inbound/outbound physical movement files, shipping manifests, bills of lading, or internal invoices with hire equipment pooling providers (such as CHEP or Loscam).
- Administrative Interaction Only: Our interactions with your hire equipment pooling providers are strictly limited to providing administrative instructions, processing authorized transfers, and executing formal balance disputes through your management portals. Your internal source data remains completely shielded from them at all times.
- Secure Infrastructure Subprocessors: Internal data is stored and processed utilizing tier-one cloud data infrastructure providers (such as AWS or Google Cloud).
- Cross-Border Provisions (APP 8): We prioritize local hosting within Australian-based sovereign data centers. If a subprocessor utilizes servers located outside of Australia, we enforce binding contractual clauses ensuring the recipient treats such data in strict compliance with the APPs.
- Statutory Mandates: We will disclose data if compelled by law, court order, or formal subpoena issued by an Australian judicial body.
5. Automated Decision-Making Transparency
In compliance with the Automated Decision-Making (ADM) transparency mandates under Australian law:
- Our hire pallet account management services utilize automated scripts, validation loops, and matching algorithms to flag processing errors, identify double-bookings, and trace equipment leakage.
- These automated systems are diagnostic and advisory. Critical commercial decisions—such as submitting formal balance disputes or resetting liability dates—are subjected to manual human validation before execution.
6. Access, Correction, and Data Control Rights
Under APP 12 and 13, individuals whose personal information is held within our ecosystems possess clear, legal pathways to manage their data:
- Access Requests: You or your personnel may formally request a copy of the personal information we hold. We will process and fulfill these requests within 30 days without fee, unless the request is legally vexatious or structurally unreasonable.
- Correction Procedures: If you establish that the personal info we hold is outdated, incomplete, or inaccurate, we will take immediate steps to update our operational records.
- Data Portability and Deletion: Upon the formal termination of our service agreement, we will securely purge or anonymize your historical movement logs, invoices, and portal access credentials within 60 days, subject to mandatory statutory tax or financial archiving retention laws.
7. Notifiable Data Breaches (NDB) Compliance
We maintain a documented Data Breach Response Plan in absolute compliance with Part IIIC of the Privacy Act 1988 (Cth). In the event of an "eligible data breach"—where data is accessed or disclosed without authorization, and is likely to cause serious harm to any individual:
- We will immediately isolate affected databases and limit systemic exposure.
- We will execute an expedited, thorough forensic assessment.
- If an eligible breach is confirmed, we will systematically notify all affected individuals and compile a formal statement to the Office of the Australian Information Commissioner (OAIC) detailing the mitigation parameters.
8. Limitations of Liability and Commercial Disclaimers
This policy strictly defines and limits our legal exposure arising from the handling of complex supply chain datasets:
- Third-Party Platform Actions: We act as an independent account manager utilizing external software portals. We hold no liability for system vulnerabilities, data breaches, database corruption, processing outages, or unilateral adjustments originating directly inside third-party pooling provider software systems.
- Source Data Reliance: Our reconciliation engine depends entirely on the authenticity and precision of the data files (invoices, manifests, and EDI logs) you provide. We accept zero liability for financial losses, back-billing penalties, or failed corrections resulting from inaccurate, altered, or fraudulent source data provided by your business or your trading partners.
- Cap on Statutory & Commercial Damages: To the maximum extent permitted under the Competition and Consumer Act 2010 (Cth) and NSW civil liability statutes, our liability for any single data event or commercial discrepancy is strictly limited to the total fees paid by you to us in the 12 months immediately preceding the event. We are not liable for speculative indirect costs, lost enterprise profits, or consequential supply chain damages.
9. Contact and Grievance Resolutions
If you have a question regarding this policy, wish to execute your rights to access data, or intend to file a formal complaint regarding a potential breach of the APPs, please contact our Privacy Officer:
Attention: Privacy & Data Compliance Officer
Advanced Pallet Management
Email: Eamon@advancedpalletmanagement.com.au