Dingo Privacy Policy

Version 2.0 · Effective 7 September 2026

Applies to Dingo Mining Pty Ltd ABN 76 154 370 706 and Dingo Software Pty Ltd ABN 20 053 730 331.

1. Who we are

This policy is jointly issued by Dingo Mining Pty Ltd ABN 76 154 370 706 and Dingo Software Pty Ltd ABN 20 053 730 331, which provides asset health services, condition intelligence and program support.

In this policy, “DINGO”, “we”, “us” and “our” mean both companies. Each company is separately responsible for the personal information it handles; neither is responsible for the other’s handling of personal information.

For the purposes of the European Union General Data Protection Regulation (EU GDPR), the relevant DINGO company is the controller of the personal information described in section 5, and acts as a processor on behalf of its business customers for the personal information described in section 8.

We are committed to protecting your privacy and to handling your personal information openly, lawfully and securely.

2. What this policy covers

This policy explains how we handle personal information about:

  • visitors to our websites;
  • representatives, employees and contractors of our customers, prospective customers, suppliers and partners;
  • users of the Dingo Trakka® software and our other products and services;
  • people who contact us, attend our events, or respond to our surveys; and
  • job applicants.

It does not change the terms of any written agreement between DINGO and a business customer. Where a customer agreement contains data protection terms, those terms prevail over this policy to the extent of any inconsistency.

3. What personal information we collect

The information we collect depends on how you interact with us. It may include:

  • Identity and contact details — name, job title, employer, business address, email address and telephone number.
  • Account information — username, authentication credentials, role and permission settings, and the sites and assets you are authorised to access.
  • Records of our dealings with you — correspondence, support tickets, meeting and call notes, training records and site induction records.
  • Usage and technical information — IP address, device and browser type, operating system, language settings, pages and features used, dates and times of access, referring URL, and diagnostic and error logs.
  • Site attendance and safety information — where our personnel attend a customer site, records relating to inductions, safety training and site access.
  • Information you choose to give us — survey and feedback responses, event registrations, and information in job applications.

We do not seek to collect sensitive information (as defined in the Privacy Act 1988 (Cth)) or special category data (as defined in the EU GDPR), and we ask that you do not provide it to us unless we have specifically requested it. Where we do need it — for example, health or medical information required for a site induction — we collect it only with your consent or as otherwise permitted by law.

4. How we collect personal information

We collect personal information:

  • directly from you, when you contact us, order or use our products and services, register for an event, complete a form, or apply for a job;
  • from your employer or the organisation you represent, where it provides your details so that we can provide products and services to it;
  • automatically, through your use of our websites, software and mobile applications;
  • from publicly available sources, including professional networking platforms, which have their own privacy policies; and
  • from third parties who are lawfully entitled to disclose it to us, including referral partners, recruitment agencies and commercially available business databases.

Where we collect your personal information from someone other than you, we take reasonable steps to ensure you are made aware of this policy.

If you choose not to provide information we request, we may be unable to provide you with our products or services, or with all of their features, or to respond to your enquiry.

5. Why we use personal information, and our legal bases

We use personal information for the purposes set out below. For individuals in the European Economic Area and Switzerland, the table also identifies our legal basis under Article 6 of the EU GDPR.

Purpose Legal basis (EU)
Providing, administering and supporting our products and services, including managing user accounts and access Performance of a contract, or our legitimate interests in providing services to the organisation you represent
Verifying identity and authority when you deal with us Performance of a contract; legitimate interests in preventing unauthorised access
Responding to your enquiries, requests, concerns and complaints Performance of a contract; legitimate interests in responding to you
Invoicing, payment processing and credit management Performance of a contract; compliance with a legal obligation
Securing, monitoring, maintaining, troubleshooting and improving our products, services and websites Legitimate interests in operating a secure and reliable service
Developing new products, services and features, and conducting analytics and research (see section 6) Legitimate interests in developing our business, and only using anonymised data where practicable
Sending you service communications, including administrative and security notices Performance of a contract; compliance with a legal obligation
Marketing our products and services (see section 14) Consent, or legitimate interests in marketing to existing business contacts, in each case subject to your right to opt out
Managing our relationships with suppliers, partners and prospective customers Legitimate interests in managing our business relationships
Recruitment and assessing job applications Steps preparatory to a contract; legitimate interests in assessing candidates; consent where required
Complying with legal, regulatory, tax, audit and record-keeping obligations, and responding to lawful requests from authorities Compliance with a legal obligation
Establishing, exercising or defending legal claims, and managing disputes and insurance matters Legitimate interests in protecting our legal position; establishment, exercise or defence of legal claims
A corporate transaction, such as a sale, merger or reorganisation of our business Legitimate interests in conducting the transaction

Where we rely on legitimate interests, we have assessed that our interests do not override your rights and freedoms. You may ask us for information about that assessment using the contact details in section 19.

Where we rely on your consent, you may withdraw it at any time. Withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal.

6. Artificial intelligence, machine learning and analytics

We use data generated through our products and services to improve them, to build new features, and to develop analytics and machine learning models — for example, models that help predict equipment failure and recommend maintenance actions.

We do not use personal information to train our artificial intelligence or machine learning models. Before data is used for model development, training, testing or improvement, or for benchmarking or aggregated reporting made available to other customers, we anonymise it so that no individual is identified or reasonably identifiable. Removing names alone is not treated as sufficient.

Once data has been anonymised in this way it is no longer personal information, and this policy does not apply to it. We may retain and use anonymised and aggregated data indefinitely.

We do not sell personal information, and we do not make personal information available to third parties for those third parties’ own artificial intelligence training purposes.

7. Automated decision-making

Our software uses automated processing to analyse equipment condition data and to generate condition assessments, alerts and maintenance recommendations. These outputs relate to machines and equipment, not to people.

We do not use automated processing to make decisions about individuals that produce legal effects for them or otherwise significantly affect them, and we do not carry out profiling of that kind. Accordingly:

  • Article 22 of the EU GDPR (automated individual decision-making) does not apply to our processing; and
  • for the purposes of Australian Privacy Principle 1.7, we do not arrange for a computer program to use personal information to make, or to do a thing that is substantially and directly related to making, a decision that could reasonably be expected to significantly affect the rights or interests of an individual.

If this changes, we will update this policy to describe the personal information used, the kinds of decisions made, and how those decisions are made.

8. Personal information in customer systems

Our business customers decide what information they enter into, or connect to, the Dingo Trakka® software. That information is principally about equipment, but it may include personal information about the customer’s personnel and contractors — for example, the name of the person who recorded an inspection or approved a work order.

For that information, the customer is the controller (and, under Australian law, the entity that determines the purposes of collection) and DINGO acts as a processor on the customer’s behalf. We handle it only on the customer’s documented instructions and in accordance with our agreement with that customer, which includes the data processing terms required by Article 28(3) of the EU GDPR.

If you are an employee or contractor of one of our customers and you want to access, correct or delete personal information held in that customer’s Trakka account, please contact your employer in the first instance. If you contact us directly, we will refer you to the customer and let them know, unless the law requires or allows us to respond ourselves.

9. Who we disclose personal information to

We may disclose personal information to:

  • the other DINGO company, and our related entities;
  • your representatives and advisers, and others you have authorised to deal with us on your behalf;
  • our employees, contractors and personnel who need the information to do their work;
  • service providers who support our business, including cloud hosting and infrastructure providers, software and IT support providers, communications and email providers, analytics providers, payment and banking providers, and professional advisers;
  • laboratories, original equipment manufacturers and other third parties that provide condition data interfaces, where required to deliver the service;
  • a prospective purchaser of all or part of our business or shares, or of a related entity;
  • government agencies, regulators, courts and law enforcement, where authorised or required by law; and
  • any other party you have authorised, or as notified to you at the time of collection.

We require our service providers to protect personal information, to use it only for the purposes for which we engaged them, and to comply with obligations no less protective than those in this policy. A current list of the categories of provider that process personal information on behalf of our business customers is available to those customers on request.

10. International transfers

DINGO operates internationally. Personal information may be stored in, transferred to, or accessed from countries other than the country in which it was collected. At the date of this policy, our related entities and service providers are located in Australia, Finland, the United States of America, Brazil, Chile, Colombia, Ecuador, Panama, Peru, Bolivia, Venezuela, Mexico, India, Indonesia and South Africa. This list will change as our network of entities and providers changes.

Transfers from the EEA and Switzerland

Where we transfer personal information out of the European Economic Area or Switzerland to a country that has not been recognised as providing an adequate level of protection, we rely on an appropriate safeguard, being:

  • the Standard Contractual Clauses approved by the European Commission in Implementing Decision (EU) 2021/914; and
  • for transfers from Switzerland, the Standard Contractual Clauses as recognised by the Swiss Federal Data Protection and Information Commissioner.

We also carry out transfer risk assessments and apply supplementary technical and organisational measures where required. You may request a copy of the relevant safeguard, with commercial terms redacted, using the contact details in section 19.

Transfers from Australia

Before disclosing personal information to an overseas recipient, we take reasonable steps to ensure that the recipient does not breach the Australian Privacy Principles, as required by Australian Privacy Principle 8. We do not rely on your consent as the basis for overseas disclosure.

11. Security

We implement technical and organisational measures appropriate to the risk, which include:

  • encryption of data in transit and at rest;
  • role-based access controls, authentication requirements and least-privilege access;
  • network firewalls, intrusion detection, logging and monitoring;
  • restricted physical access to our premises and to the facilities of our hosting providers;
  • backup, resilience and disaster recovery arrangements;
  • supplier security assessment before engagement; and
  • privacy and security training for our personnel, and confidentiality obligations in their contracts.

We maintain a data breach response plan. Where a data breach is likely to result in serious harm, we will notify the Office of the Australian Information Commissioner and affected individuals as required by Part IIIC of the Privacy Act 1988 (Cth). Where the EU GDPR applies and we are a controller, we will notify the relevant supervisory authority within 72 hours of becoming aware of a notifiable breach, and affected individuals where required. Where we act as a processor for a business customer, we will notify that customer without undue delay in accordance with our agreement with them.

No system can be completely secure. You also play an important part in keeping your information safe by protecting your account credentials and notifying us promptly of any suspected unauthorised access.

12. How long we keep personal information

We keep personal information only for as long as we need it for the purpose for which it was collected, or for as long as the law requires. Our general retention periods are:

Category Retention period
Customer account and user records For the term of the agreement, then 24 months after it ends
Data held in the Trakka platform on behalf of a customer As directed by that customer under its agreement, including a 30-day export window after termination
Contracts, invoices and financial records 7 years, as required by Australian tax and corporations law
Correspondence and support records 2 years from the last interaction
Website and system logs 12 months
Marketing contact records Until you opt out, and then only as needed to honour your opt-out
Unsuccessful job applications 6 months, unless you ask us to keep them longer
Anonymised and aggregated data Indefinitely (no longer personal information)

At the end of the applicable period we destroy or de-identify the information, unless we are required to retain it in connection with a legal claim, investigation or legal obligation.

13. Your rights

Subject to the applicable law, you may:

  • Access the personal information we hold about you, and ask for a copy;
  • Correct information that is inaccurate, out of date, incomplete, irrelevant or misleading;
  • Erase information where it is no longer needed for the purpose for which it was collected, or where you validly withdraw consent and no other basis applies;
  • Restrict or object to our processing, including objecting to processing based on legitimate interests and to direct marketing;
  • Receive a portable copy of information you provided to us, in a structured, commonly used, machine-readable format, and ask us to transmit it to another organisation where technically feasible;
  • Withdraw consent at any time where we rely on consent; and
  • Complain to us or to a data protection authority (see section 18).

To exercise a right, contact us using the details in section 19. We may need to verify your identity. We will respond within a reasonable time and, where the EU GDPR applies, within one month, which we may extend by two further months for complex requests by telling you why.

We provide one copy of your personal information free of charge. If a request is for additional copies, or is manifestly unfounded, excessive or repetitive, we may charge a reasonable fee or decline it, and we will explain why. There may also be cases where we cannot comply — for example, where doing so would affect the privacy or rights of others, breach confidentiality, or conflict with a legal obligation. We will tell you the reasons.

14. Marketing and your choices

We may send you information about our products, services, events and insights, and occasionally about offerings from our partners that we think will interest you. We send electronic marketing only where we have your consent or another basis permitted by the Spam Act 2003 (Cth) and, in the EEA, by applicable electronic marketing rules.

You can opt out at any time using the unsubscribe link in any marketing message, or by contacting us. Opting out of marketing does not stop service communications, such as administrative and security notices relating to your account.

15. Cookies and website analytics

Our websites use cookies and similar technologies to operate the site, remember your preferences, measure how the site is used and improve it. We use third-party analytics and marketing services, which may include Google services, HubSpot and similar providers; those providers have their own privacy policies.

Cookies that are not strictly necessary are set only where you have consented through our cookie banner. You can change or withdraw your cookie preferences at any time through the banner or your browser settings. Blocking some cookies may affect how the site works.

Our websites may link to other websites. We are not responsible for the privacy practices or content of those websites, and we encourage you to read their privacy policies.

16. Children

Our products and services are provided to businesses and are not directed at children. We do not knowingly collect personal information from anyone under 16. If you believe we have, please contact us and we will delete it.

17. Additional information for specific regions

 

European Economic Area and Switzerland

DINGO has an establishment in Finland, through which we sell to and service customers in the European Union. The GDPR applies to us directly in respect of processing carried out in the context of that establishment, and we are therefore not required to designate a representative in the Union under Article 27 of the EU GDPR.

Our lead supervisory authority is the Office of the Data Protection Ombudsman of Finland (Tietosuojavaltuutetun toimisto). You may also complain to the supervisory authority of the country where you live or work.

We have not appointed a data protection officer under Article 37 of the EU GDPR, having assessed that we are not required to do so. Privacy matters are handled by our Privacy Officer, whose contact details are in section 19.

Australia

We are bound by the Australian Privacy Principles in the Privacy Act 1988 (Cth). You may ask us to deal with you anonymously or under a pseudonym where it is lawful and practicable for us to do so.

California

We do not sell or share personal information as those terms are defined in the California Consumer Privacy Act, and we do not use or disclose sensitive personal information for purposes requiring an opt-out right. California residents may exercise rights of access, correction, deletion and portability, and will not be discriminated against for doing so.

Brazil

Where the Lei Geral de Proteção de Dados applies, you have rights of confirmation, access, correction, anonymisation, blocking, deletion, portability, information about sharing, and information about the consequences of refusing consent.

South Africa, Canada and other jurisdictions

Where the Protection of Personal Information Act 2013 (South Africa), the Personal Information Protection and Electronic Documents Act (Canada) or another data protection law applies to our handling of your personal information, we comply with that law and you may exercise the rights it gives you by contacting us.

If you are unsure which law applies to you, contact us and we will tell you.

18. Complaints

 

If you have a concern about how we have handled your personal information, please contact our Privacy Officer using the details in section 19. Please include your contact details and a clear description of your concern. We will acknowledge your complaint and respond within a reasonable time, and within 30 days where the Privacy Act 1988 (Cth) applies.

If you are not satisfied with our response, you may complain to a data protection authority, including:

  • Australia — Office of the Australian Information Commissioner, oaic.gov.au
  • Finland (our lead supervisory authority) — Office of the Data Protection Ombudsman, tietosuoja.fi
  • Elsewhere in the European Economic Area — the supervisory authority of the country where you live or work, or where the alleged infringement occurred
  • Other countries — the data protection authority in your jurisdiction

19. Contact us

DINGO Privacy Officer. Email: help@dingo.com. Post: 16 MacGregor Street, Wilston, Queensland 4051, Australia.

Please tell us which DINGO company your enquiry relates to if you know, and we will direct it appropriately.

20. Changes to this policy

We may update this policy from time to time to reflect changes to our practices or to comply with new laws. The current version is always available on our website. Where a change is significant, we will take reasonable steps to notify you in advance, for example by email or by a notice on our website or in the software.

Where you have a written agreement with us that incorporates this policy, the version that applies to that agreement is governed by the terms of that agreement.