Privacy Policy

This privacy policy notice applies to all products marketed and branded by Asiga Pty Ltd and it’s subsidiaries.

1. Introduction

This Privacy Policy (Privacy Policy or Policy) outlines how your information is collected, used and disclosed when you access or use our Website and Services. This information is collected, used and disclosed in accordance with the Privacy Act 1988 (Cth) (Privacy Act). This Privacy Policy is incorporated by reference into our Terms.  Any capitalised terms not defined in this Policy are defined in the Terms. You agree to comply with all Terms when accessing or using our Website and Services, including this Privacy Policy.

Our payment processing is handled by Stripe. The Stripe Privacy Policy applies in relation to any Personal Information collected, stored and processed on Stripe servers. We may also use this Personal Information for the purposes as set out in this Policy and in accordance with the terms  set out in this Policy.

Our services may also be powered by Auth0. The Auth0 Servers Privacy Policy applies in relation to any Personal Information collected, stored and processed on Stripe servers. We may also use this Personal Information for the purposes as set out in this Policy and in accordance with the terms set out in this Policy.

2. What information do we collect and how is it collected?

We collect limited Personal Information, as defined in the Privacy Act (including Sensitive Information as defined in the Privacy Act), when you access or use our Website and Services.

2.1 Personal Information provided by you

We collect information that you provide to us via use of our Website and Services as well as through any other means used to contact us. The kinds of Personal Information we collect include your contact information such as your name, birth date, email address, organisation, address and phone or mobile number.

We reserve the right to maintain, store and use any information or data where we reasonably believe that such action is required to comply with any legal or regulatory obligations, to prevent criminal or other unlawful activity whether immediate or in the future, or where we have a legitimate business reason to do so, including collection of amounts owed, resolving disputes, enforcing our Terms or for record keeping integrity.

2.2 Automatically collected Personal Information

We automatically record information from your device and its software when you access our Website and Services, including your IP address, browser and device type, internet service provider, mobile phone carrier, platform type, the website from which you came and the website to which you are going when you leave our Website, date and time stamp and cookies that may uniquely identify your browser or account.

When accessing our Website or Services using a mobile device, we may also receive and collect identification numbers  associated with your device, mobile carrier, device type and manufacturer, and, if enabled, geographical location data (including GPS). Please note that some of the information we collect, for example an IP address, can sometimes be used to approximate a device’s location.

2.3 Personal Information collected via cookies

Our Website may use small pieces of data called cookies to identify a user who engages with our Website and to compile records of a user’s history of engaging with our Website. Cookies are stored by a users’ browser while the user browses a website. Cookies do not usually contain information that personally identifies a person, but each time the user visits the website, the browser sends the cookie data back to the server to notify the system of the user’s previous activity. If you wish to disable cookies, you may do so through your browser settings, however, please be aware that if you choose to do this, some functionality of our Website will not be available to you.

The Stripe platform is governed by its own Cookie Policy. We bear no responsibility for how Stripe uses your data for cookies. If you are concerned with any use and storage of your data for cookies by Stripe, please contact Stripe Support directly.

2.3.1  Types of cookies we use

  • Essential cookies: required for the site to function (e.g. authentication, security, basic functionality).
  • Functional cookies: enhance user experience but not strictly required (e.g., remember language preference).
  • Analytics cookies: measure usage, errors, or performance (e.g., analyse how users use our website).
  • Marketing cookies: cross-site tracking, retargeting, or advertising (e.g., analyse a User’s usage of the Website to show marketing to him or her online).

2.3.2  Managing your cookie preferences

Cookie preference centre: allows you to accept or reject different types of cookies.

    • Browser settings: You may be able to refuse or disable cookies by adjusting your web browser settings. Because each web browser is different, please consult the instructions provided the web browser (typically in the “help” section).
    • Opt-out links: Some third-party services provide direct opt-out options.

 

Please note: Disabling certain cookies may affect how our services work. Essential cookies cannot be disabled as they’re necessary for basic functionality

2.3.3 Cookies & Tracking Technology

2.4 Personal Information collected via PostHog

We use PostHog, which allows us to anonymously track the use of our Website and Services by recording the number of users who have visited, the number of pages viewed, navigation patterns, what systems users have and the date and time of visits through cookies. This information is collected for statistical purposes only and cannot be used to identify you. We may use a range of services and functions offered by PostHog.

Please see this link for instructions on how to opt-out of any PostHog data tracking.

2.5 Third Party Payment Processor

We use third party payment processors and gateways (i.e. Stripe) to process payments made to us in the provision of our Services. All Personal Information, including any financial information such as credit card numbers, is collected and used directly by our third party payment processors and gateways as set out on our Website, whose use of your personal information is governed by their own terms and conditions and privacy policy.

We do not store or retain any sensitive financial/billing information (being credit card numbers, bank account details, etc.), obtained in connection with processing such payments.

2.6 Uploaded data

When you upload files or data to our services, we collect any personal information contained in those files. You decide what information to include and remain responsible for ensuring you have appropriate permissions to upload personal information. For EU users, this means you are the “data controller” and we are the “data processor” under GDPR.

This notice explains our security, storage, and processing practices for uploaded data. Your privacy policies govern individual rights and the legal basis for processing uploaded data.

3. For what purposes do we collect and use Personal Information?

3.1 Use of Personal Information

We collect your Personal Information as outlined in this Privacy Policy for the purposes described below:

  • For provision of the Services which shall include without limitation fulfilling your Orders;
  • For the upload, storage, and sharing of patient data and information;
  • For communication with you and to provide messaging and/or communications to you in association with the functions and features of the Website;
  • For communicating to you any announcements and updates, updated terms, conditions and policies, security alerts, technical notices, support and administrative messages;
  • For analysis, monitoring, development and improvement of our Website and Services, including other products or services;
  • For security purposes, including to protect the Website and our property from abuse, fraud, malicious, unauthorised access or potentially illegal activities, and to protect our rights, safety and property and that of our other users;
  • For sending marketing communications to you, including notifying you of promotional or advertising offers, contests and rewards, upcoming events and other news about products and services offered by us and use of our Website and Services;
  • To comply with relevant laws and regulations where applicable; and for the performance of other functions described at the time of collection or as consented to in relation to our Website and Services.

4. How do we store and protect your information?

4.1 Storage of Personal Information

We take reasonable steps to protect your Personal Information in accordance with this Privacy Policy. The Personal Information we collect from you is transferred and stored electronically via a secure SSL connection, in secured, password-protected servers located in Australia, USA & Europe.

You agree and consent to us storing your Personal Information on such servers.

4.2 Who can access your Personal Information?

Your Personal Information is accessible to our employees, contractors and our third-party service providers such as our Website host and technical support providers. We may also store your Personal Information in password-protected email databases for the purpose of sending out communications and marketing emails in accordance with this Privacy Policy.

Please note that no method of electronic transmission or storage is 100% secure and we cannot guarantee the absolute security of your Personal Information. Transmission of Personal Information over the Internet is at your own risk, and you should only enter, or instruct the entering of, Personal Information to the Website within a secure environment. It is your responsibility to ensure that you keep your Personal Information safe, including keeping your software up to date to prevent security breaches.

We reserve the right to maintain and store any information or data where, we reasonably believe, in our sole discretion, that such action is required to comply with any legal or regulatory obligations, to prevent criminal or other unlawful activity whether immediate or in the future, or where we have a legitimate business reason to do so, including collection of amounts owed, resolving disputes, enforcing our Terms or for record keeping integrity.

We destroy or de-identify your Personal Information when it is no longer needed for the purposes outlined in this Policy, subject to our legal obligations to retain certain records for longer periods under applicable laws. However, we may also be required to keep some of your personal information for specified periods of time, for example under certain laws relating to corporations, money laundering, and financial reporting legislation.

5. To whom your Personal Information is disclosed?

Your Personal Information may be disclosed to individuals and companies, for the purposes described in this Policy, as outlined below:

5.1 Asiga and Related Bodies Corporate
NameOwnerPurposeExpiry
_legacy_auth0,
is.authenticatedauth0
AsigaEssential: necessary to authenticate and maintain user authentication1 day after being set
auth0,
auth0_compat
AsigaEssential: necessary to authenticate and maintain user authentication as a fallback1 day after being set
i18nextAsigaFunctional: stores the User’s language preferenceEnd of the session
did, did_compatAsigaEssential: security of the Website, in particular for device identification helps prevent replay attacks by verifying the unique identity of a device trying to access a system.1 year after being set
ajs_anonymous_idAsigaFunctional: it identifies anonymous users across sessions to maintain continuity in analytics data, even if the user is not logged in or identified by a user ID.1 year after being set
_cfuvidCloudflarePerformance: it helps distinguish individual users who share the same IP address (if they share the same workplace). Without this cookie, all users sharing the same IP might be treated as a single user, which could lead to incorrect rate limiting or blocking.End of the session
_gaLaunchDarklyAnalytics: this is the main Google Analytics cookie used to uniquely identify users across multiple sessions and visits. It stores a unique client ID to distinguish one visitor from another over time.2 years after being set
gidLaunchDarklyAnalytics: this cookie also distinguishes users but is focused on tracking user behaviour within a single day or session. It helps understand how users interact with the site during a short timeframe.1 day after being set
_biz_uid,
_biz_flagsA
Bizible/OptimizelyAnalytics and marketing: it contains a unique user ID that identifies a user on the current domain. It helps Bizible/Optimizely associate user actions and preferences across sessions and websites to provide personalised marketing and analytics insights.1 year after being set
adroll_fpcAdRollAnalytics and marketing: it helps AdRoll identify visitors across multiple visits and devices to enable real-time bidding and deliver relevant, personalised advertisements based on users' browsing behaviour.1 year after being set
stripe_mid,StripeEssential: it is used to distinguish users and is essential for fraud prevention and secure payment processing on websites using Stripe. It helps identify unique visitors to prevent fraudulent transactions.1 year after being set
sentrysidSentryEssential: this cookie is related to session identification for Sentry’s error tracking and monitoring services. It helps associate user sessions with error reports and performance data.End of the session
Help Scout
(2fa_)
Help ScoutEssential: Tracks two-factor authentication status.30 minutes
Help Scout
(PHPSESSID)
Help ScoutEssential: Manages login session IDs, enabling multiple browser windows to stay logged in. End of the session
Help Scout
(mhash)
Help ScoutEssential: Provides a security token to maintain session integrity.30 days
Help Scout
(folder_sort):
Help ScoutEssential: Saves sorting preferences for a consistent user experience.1 day
Help Scout
(hs_tvar)
Help ScoutEssential: Supports A/B testing to improve functionality.1 year after being set
Mixpanel
(\mixpanel, mp\*):
Help ScoutFunctional: Tracks events to monitor user behavior.1 year after being set
HubSpot
(_hssc, hssrc,
_hstc, hubspotutk):
HubSpotOptional: Powers email marketing and analytics tools.End of session
ph_phc_xL7Hc32iizefWGeNzQ53gz6QEYcMDzSsZVJBnMQWWSUE_posthogPostHogAnalytics and product analytics: stores the user’s PostHog distinct_id, session and device identifiers, the user’s active and enabled feature-flag state, and PostHog configuration options (e.g. whether session recording is enabled). The segment of the cookie name is the Genira PostHog project key.365 days after being set

Your Personal Information may be accessed by us, including our directors, employees, officers and contractors.

You consent to us providing your Personal Information, including Sensitive Information to our Related Bodies Corporate (as defined in the Corporations Act 2001 (Cth)).

5.2 Parties required by law

Your Personal Information may be disclosed by us to any party to whom we are required by law to provide your Personal Information and to any party to whom disclosure is permitted under the Australian Privacy Principles, or where we reasonably believe that disclosure is required to comply with any court orders, subpoenas, or other legal process or investigation including by tax authorities, if such disclosure is required by law. 

Where possible and appropriate, we will notify you if we are required by law to disclose your Personal Information.

5.3 Direct marketing

You agree and expressly and indefinitely consent to us using or disclosing Personal Information (other than Sensitive Information) to keep you informed about our products and services and other products and services that we consider may be of interest to you.

For this purpose, disclosure may be made to our third-party service providers. We may communicate with you via phone, email, social media, or regular mail. If you have indicated a preference for a method of communication, we will endeavour to use that method wherever practical to do so.

You can opt-out of direct marketing communication activities undertaken by us at any time by clicking the “unsubscribe” or “opt-out” link on email communications from us.

5.4 Other third parties

We may share your Personal Information with third parties, if it is reasonably related to the provision of our Services. The third parties that we may share your Personal Information with includes delivery partners, consultants, contractors, credit agencies, debt collection agencies and other service providers that perform services on our behalf.

Such services we procure may include fulfilling our Orders, identifying and disseminating advertisements, enforcement of our Terms, providing fraud detection and prevention services, processing payments or providing analytics services. We may also share your Personal Information with our business partners who offer goods or services to you jointly with us (for example, contests or promotions). We may share your Personal Information where we have reason to believe that doing so is necessary to identify, contact or bring legal action against anyone damaging, injuring, or interfering (intentionally or unintentionally) with our rights or property, users, or anyone else who could be harmed by such activities.

We may also share your Personal Information with third parties with your consent in a separate agreement, in connection with any company transaction (such as a merger, sale of assets or shares, reorganisation, financing, change of control or acquisition of all or a portion of our business by another company or third party) or in the event of bankruptcy, dissolution, divestiture or any related or similar proceedings.

Note that we reserve the right to share your Personal Information with other third parties where, in our sole discretion, it is required to:
(a) investigate and defend ourselves against any third party claims or allegations;
(b) protect against harm to the rights, property or safety of us, our users or the public as required or permitted by law; and
(c) detect, prevent or otherwise address criminal (including fraud or stalking), security or technical issues.

5.5 Overseas disclosure

Please note that some of the parties listed above to whom your Personal Information may be disclosed, may be located overseas, including countries such as Australia. We use reasonable steps to ensure that these parties are either governed by substantially similar, accessible and enforceable laws to the Australian Privacy Principles or adhere to the Australian Privacy Principles, however to the maximum extent permitted by law, we are not liable for the privacy practices of such parties.

Please note that the transfer of your Personal Information to such overseas parties may pose risks to the security of your Personal Information as these countries may not have been issued with an adequacy decision as set out in the GDPR (if applicable) or have appropriate safeguards in place, however by providing your Personal Information to us, you acknowledge and consent to disclosure of Personal Information to such overseas recipients.

6. Third party websites and social media

Our Website may, from time to time, contain links to and from websites which are owned or operated by other parties. You acknowledge and agree that we have no control over, and shall not be liable for, the privacy practices or content of these third party websites and we do not make any representation about the privacy practices of, any third-party websites, whether or not linked from or transferred from our Website. You are responsible for checking the privacy policy of any such third party websites and applications so that you can be informed of how they will handle Personal Information.

We run pages on a number of social media platforms, including Facebook, Instagram, X (formerly Twitter), LinkedIn, YouTube and TikTok (Social Media Platforms). By accessing, interacting with and using our social media pages, you agree to the terms and privacy policy of those Social Media Platforms. You acknowledge and agree that these Social Media Platforms may collect your information and that the privacy practices of those Social Media Platforms are not controlled by us and that we hold no responsibility for such privacy practices.

Social Media Platforms also allow public access to your public social media profile, which may include your username, age range, country/language, list of friends or other information that you make publicly available, and you understand that such information may therefore be accessible by us if you interact with its social media pages.

We may from time to time, have access to statistics regarding the number of views, navigation patterns, posts that you like, comment on or share and any user interactions with our social media pages and may use such information for the purpose of its marketing and promotion strategies.

7. How can you access or update your Personal Information?

At any time, you may request access to Personal Information we hold about you. We may refuse to provide access if the law requires us to do so, in which case we will provide reasons for our decision as required by law.

We take reasonable steps to keep your Personal Information accurate, complete and up to date. If, at any time, you discover that information held about you is incorrect, you may contact us to have the information deleted or corrected.

You may request access to the information we hold about you, or request that we delete, update or correct any Personal Information we hold about you, by setting out your request in writing and sending it to us in accordance with paragraph 10.
We will process your request as soon as reasonably practicable, provided we are not otherwise prevented from doing so on legal grounds. If we are unable to meet your request, we will let you know why.

8. How can you make a complaint about our privacy practices?

You may submit a written complaint about how we handle your Personal Information to our Privacy Officer via the details below.

If you are not satisfied with our handling of your complaint or we have not replied to you within a reasonable period of time, then you are entitled to make a complaint to the Office of the Australian Information Commissioner or, if you are in the EU, a data protection authority or supervisory authority.

9. Amendments

We reserve the right to amend this Privacy Policy from time to time with reasonable notice to you. While we endeavour to notify you as soon as reasonably possible of any changes to our Policies by email or by a notice on our Website, it is your responsibility to keep up to date with any changes or amendments by checking this page prior to using our Website and Services.

This page contains our most accurate and up to date version of our Privacy Policy.

10. Contact us

All requests for access or corrections to your Personal Information and complaints should be directed to our Privacy Officer. If submitting a complaint, please provide our Privacy Officer with full details of your complaint and any supporting documentation:

  • by contact form at https://www.asiga.com.
  • by e-mail at info@asiga.com or
  • by letter to The Privacy Officer, 2/19-21 Bourke Rd, Alexandria NSW 2015.

If you are not satisfied with our handling of your complaint or we have not replied to you within a reasonable period of time, then you are entitled to make a complaint to the Office of the Australian Information Commissioner.

11. Data Protection

Personal Information
Asiga Processes Uploaded Data, such as 3D scans and STL files, on behalf of and in accordance with the Users’ instructions. Users are responsible for ensuring that any sharing of Personal Information with Asiga is in compliance with applicable privacy and data protection laws.

In relation to Uploaded Data from the EU, Asiga is a processor in accordance with the General Data Protection Regulation, and Users are the controllers. Asiga Processes such Uploaded Data in accordance with module two of the standard contractual clauses adopted by the European Commission on 4 June 2021 (C(2021) 3972 final) (as amended) (“SCCs”), which are deemed incorporated by reference into these Terms and completed as follows:

  • Clause 7: option not selected.
  • Clause 9(a): option 2 and the notice period should be read as five
    business days.
  • Clause 11: option not selected.
  • Clause 13: the data exporter is established in an EU Member State.
  • Clause 17: option 2.
  • Clause 18: the EU Member State in which the data exporter is established.
  •  Annex I:
    • A. Asiga is the data importer and Users are the data exporters.
    • B. The Personal Information is transferred in accordance with these Terms.
  • Annex II: Asiga will comply with the security measures mentioned in Section 9 of the Privacy Notice.
  • Annex III: See section 3(1) of the Terms.

 

In relation to Users in Switzerland, the SCCs mentioned in paragraph 2 apply with the following amendments:

  • The GDPR standard applies to all transfers of Uploaded Data.
  • References to the GDPR are to be understood as references to Swiss Federal Act on Data Protection dated 25 September 2020 (“revFADP”), as amended.
  • Regarding the supervisory authority:
    • A. where the transfer of Personal Information is exclusively subject to the revFADP: the competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner (“FDPIC”);
    • or B. where the transfer of Personal Information is subject to both the GDPR and the revFADP: the competent supervisory authority is the FDPIC for transfers governed by the revFADP, and the competent EU supervisory authority for transfers of Personal Information governed by the GDPR.
  • Regarding the applicable law for contractual claims under Clause 17 of the SCCs:
    • A. Where the transfer of Personal Information is exclusively subject to the revFADP: Swiss law; or
    • B. Where the transfer of Personal Information is subject to both the GDPR and the revFADP: law of the data exporter.
  • Place of jurisdiction for actions between the parties pursuant to Clause 18(b) of the SCCs:
    • A. where the transfer of Personal Information is exclusively subject to the revFADP: Swiss courts; 
    • or B. where the transfer of Personal Information is subject to both the GDPR and the revFADP: jurisdiction of the data exporter.
  •  In the context of jurisdiction for claims arising out of the SCCs, the term “Member State” shall not be interpreted in such a way as to exclude data
    subjects in Switzerland from the possibility of suing for their rights in their place of habitual residence (Switzerland).

 

In relation to Users in the UK, the SCCs mentioned in paragraph 2 apply amended in accordance with International Data Transfer Addendum to the EU Commission SCCs of 21 March 2022, adopted pursuant to S119A(1) Data Protection Act 2018,as amended.

  • Asiga Processes User Data, such as account credentials and log data, as necessary to provide the Services in accordance with these Terms and as otherwise mentioned in the Privacy Notice.
  • Capitalised terms in this clause shall have the meaning ascribed to them in the Key terms section of the Asiga services privacy notice.