Privacy Policy

Last Updated: January 1, 2026

This Privacy Policy explains how CRYOTECH INDUSTRIES PTY LTD (Operator, we, us or our) collects, uses, discloses, and protects personal information in the course of providing our warehousing and fulfillment services and operating our online platform. We are committed to handling personal information in accordance with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). By engaging our Services or using our platform, the Client (you) consents to the practices described in this Policy.

1. Personal Information We Collect

Information from Clients (B2B)

We collect personal information that is necessary to provide our Services to business clients. This may include contact details of individuals at our Client's organization (such as names, business addresses, email addresses, and phone numbers of account managers or staff), billing and payment information (including bank details or credit card information for payments), and any communications you send to us. If you apply for a credit account, we may collect additional information such as trade references or credit history information.

Information about End-Customers

In providing fulfillment and shipping Services to our Clients, we also handle personal information about your end-customers (such as the consumers who purchase products from you). This typically includes names, delivery addresses, email addresses, and telephone numbers of customers to whom orders will be shipped, as well as order details necessary for fulfillment. We collect and use this information only as needed to perform the Services on your behalf. As the Client, you are responsible for ensuring that you have the right to provide this personal information to us for these purposes (for example, by obtaining customer consent or having a lawful basis under privacy laws).

Website and Platform Usage Information

When you use our online platform or website, we may collect technical information such as your IP address, browser type, device identifiers, and browsing actions. We may use cookies or similar technologies to enhance user experience (e.g. to keep you logged in, or track site usage analytics). This technical data may be considered personal information when linked to an individual. Our platform may also record actions taken (for instance, order submissions, inventory updates, etc.) along with user account information for audit and support purposes.

Sensitive Information

We do not generally seek to collect sensitive information (such as health, genetic, biometric, or information about racial or ethnic origin) in the course of our Services. We ask that you do not provide us with such information, and we will only collect sensitive information with consent or if otherwise permitted or required by law.

2. How We Use Personal Information

To Provide Services

We use personal information primarily to operate and deliver our Services to our Clients. This includes using contact information to communicate with you about account matters, orders, inventory, and shipments; using end-customer information (name, address, etc.) to pick, pack, and dispatch orders to those customers; generating shipping labels and sharing necessary details with carriers; processing returns and updating order status; and generally performing the logistics and fulfillment tasks requested by the Client. We will also use personal information to provide customer support, resolve issues, and answer inquiries related to the Services or platform.

Business Operations and Improvements

We may use personal data for our internal business operations and service improvements. For example, we might analyze aggregated usage patterns to improve our warehouse processes or software functionality. We may use contact information to send service-related announcements or updates about our terms or features. If you have given consent, we might also send newsletters or marketing communications about new services or offerings, but you can opt out of such marketing at any time. Any marketing communications will comply with applicable spam and privacy laws.

Payments and Finance

We use billing and financial information to invoice Clients and process payments for our Services. For instance, we might share your provided credit card or banking details with our secure payment processor for charging service fees (we do not store full card details ourselves but rely on compliant payment gateways). We also maintain transaction records for accounting, taxation, and auditing purposes as required by law.

Legal Compliance and Protection

We may use or disclose personal information as required to comply with laws, regulations, court orders or governmental requests (for example, under customs, import/export, or national security laws, we may need to provide shipment information to authorities). Additionally, if necessary, we will use personal information to enforce our agreements or protect our rights or the rights of others – for instance, to investigate or prevent fraud, security incidents, or other illegal or harmful activities.

3. Disclosure of Personal Information

Disclosure to Service Providers (Third Parties)

We may disclose personal information to third-party service providers and partners who assist us in providing the Services. This includes:

  • Carriers and Logistics Partners: We share necessary shipment details (such as recipient name, address, phone, and package contents) with courier companies, postal services, freight carriers, and customs brokers that transport or facilitate delivery of the Goods.
  • Technology Providers: We use third-party software and infrastructure, such as cloud hosting services, warehouse management systems, and integration platforms. Personal information may be stored in or pass through these systems in the course of business. For example, our online platform may be hosted on cloud servers or we may use an email service to send notifications. We take steps to ensure such providers protect personal data and use it only for our purposes.
  • Professional Advisors: On occasion, we might share relevant information with our professional advisors (such as lawyers, accountants, or auditors) on a need-to-know basis for advice or compliance purposes. For instance, if there is a dispute, we may provide information to our legal counsel.

Within Corporate Group

If the Operator is part of a group of related companies, we may share personal information with our related bodies corporate (such as parent or subsidiary companies) as needed to operate the business and the Services. All related entities are bound to maintain that information in accordance with this Policy and applicable privacy principles.

Legal Requirements and Safety

We may disclose personal information if required by law or legal process, or if we have a good-faith belief that such disclosure is reasonably necessary to: (a) comply with legal obligations or governmental requests; (b) enforce our contracts or policies; (c) address fraud, security or technical issues; or (d) protect the rights, property, or safety of our company, Clients, or others. If we receive a law enforcement request for personal data, we will attempt to redirect the request to the Client when feasible, or notify the Client unless legally prohibited.

Business Transfers

If we undergo a business transaction such as a merger, acquisition by another company, or sale of all or part of our assets, personal information may be among the assets transferred. We will ensure that any successor entity is bound by terms substantially similar to this Privacy Policy in how it handles personal information, or we will obtain your consent if required by law.

No Sale of Personal Data

We do not sell or rent personal information to third parties for their marketing purposes. We will not disclose our Clients' or their customers' personal data to unrelated third parties for those third parties' own direct marketing without consent.

4. Cross-Border Data Transfers

In general, we prefer to store personal information on servers located in Australia. However, some of our service providers or systems may be located or use servers in other countries (for example, cloud hosting or email services may operate from the United States, the European Union, or other jurisdictions). Also, when fulfilling international orders, we necessarily transfer shipping data to carriers or customs authorities in destination countries. Therefore, personal information may be transferred outside of Australia. In all such cases, we will take reasonable steps to ensure the overseas recipients handle the information in a manner consistent with the APPs (for instance, by relying on providers certified under relevant privacy frameworks, or by contractually requiring safeguarding of data). By providing us with personal information or using our Services, you consent to any such cross-border transfers, understanding that overseas jurisdictions may have different data protection standards. If you would like to know more about where your data may be stored or transferred, please contact us.

5. Data Security

We take data security seriously and implement reasonable measures to protect personal information from misuse, interference, loss, and unauthorized access, modification or disclosure. These measures include physical security controls at our warehouses and offices (e.g., restricted access to facilities), technical protections (such as password-restricted systems, SSL encryption for data in transit, firewalls, and regular security audits of our platform), and organizational policies (like staff training on privacy and security, and limiting access to personal data to personnel who need it for their job duties). While we strive to use commercially acceptable means to protect your personal information, no method of transmission over the Internet or method of electronic storage is 100% secure. Therefore, we cannot guarantee absolute security. In the event of a data breach that is likely to result in serious harm, we will notify affected individuals and authorities as required under the Privacy Act's Notifiable Data Breach scheme.

6. Data Retention

We retain personal information only for as long as it is needed for the purposes described in this Policy or to comply with legal or business obligations. For example, we may retain transactional and shipment records (which include personal information) for several years to meet tax, accounting, and audit requirements. We may also retain certain basic contact information to facilitate any re-engagement or to inform you of services if you have so consented. When personal information is no longer required, we will take reasonable steps to securely destroy or de-identify it, unless retention is required by law.

7. Access and Correction

You have rights to access the personal information we hold about you and to request correction of any inaccuracies, subject to some exceptions allowed by law. If you wish to access or correct your personal information, please contact us using the details in Section 9. We may need to verify your identity before releasing information. We will respond to access or correction requests within a reasonable period and, where lawful, provide the information or make the correction as requested. If we refuse access or correction (for instance, if granting access would infringe someone else's privacy, or we are entitled to charge a fee and you do not agree), we will provide written reasons for the refusal and outline how you can complain about the decision.

8. Client Obligations (Privacy of Others)

If you are our Client, you may receive personal information in the course of using our Services (for example, through our platform you might see a carrier's tracking contact or an end-customer's details for an order). You agree to keep such information confidential and to use it only for the legitimate purposes for which it was provided (for instance, to handle that specific order or return). You must not use any personal information obtained through our Service for your own unrelated purposes (including marketing to individuals) unless you have obtained their consent or have another legal basis. You also agree to comply with applicable privacy laws in relation to any personal data you collect or access in using our Services, including providing necessary notices or obtaining consents from your customers for us to process their data as described in this Policy. We will not be responsible for any consequences arising from your failure to meet these obligations.

9. Inquiries and Privacy Complaints

Contacting Us

If you have any questions, concerns or requests regarding this Privacy Policy or how your personal information is handled, please contact our Privacy Officer at:

Email: info@cryologix.com.au
Mail: Privacy Officer, CRYOTECH INDUSTRIES Pty Ltd (ABN 69 682 955 291), registered in Australia

Complaints

We take privacy complaints seriously and will investigate any complaint we receive. If you believe we have breached this Privacy Policy or the APPs in our handling of your personal information, please contact us in writing using the details above. Include your name and contact details and describe the issue in detail. We will acknowledge your complaint and endeavor to respond with the outcome of our investigation within 30 days. If you are not satisfied with our response, you may escalate the complaint to the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au or by phone at 1300 363 992. We invite you to work with us first to resolve the issue before contacting the OAIC.

10. Updates to this Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, services or legal obligations. When we do, we will post the revised Policy on our website and update the "Last Updated" date at the top. If the changes are significant, we may also notify our Clients via email or through the platform. We encourage you to review this Policy periodically to stay informed about how we are protecting personal information. Your continued use of our Services or platform after any update to the Policy will constitute your acceptance of the changes, to the extent permitted by law.

This Privacy Policy is intended to provide a clear and comprehensive explanation of our personal information handling practices. If you require any further information or clarification, please do not hesitate to contact us.