Who we are

Our website address is: www.auswaybiotech.com.au

What personal data we collect and why we collect it

Effective as of 03 February 2021.

This Privacy Policy applies to the products, services, website(s) provided, mobile application(s) provided and/or the business conducted, by SkyCare Australia Pty Ltd and Ausway BioTech (collectively and individually referred to as “SKYCARE”, “we”, “our”, “us”) and explains how we handle Personal Information and comply with the requirements of Australia’s Privacy Act Privacy Act 1988 (Cth) (“Privacy Act”). SKYCARE takes the security and privacy of the Personal Information of its customers and users of its website(s) (such website(s) may be collectively or individually referred to as the “Site”) very seriously.

This Privacy Policy illustrates how we collect, use, disclose and/or process the Personal Information you have provided to us or that we possess about you, as well as to assist you in making an informed decision before providing us with any of your Personal Information. The term “Personal Information” refers to information that is connected to you as an identifiable individual, defined under the Privacy Act to mean any information or an opinion about an identified individual, or an individual who is reasonably identifiable whether the information or opinion is true or not (“Personal Information”). We may collect your name, address, telephone number, email address, date of birth, gender, credit card details, photographs, personal images, device ID, operating system or version, information about your purchases or preferences, and any other information collected by us where you are identified or identifiable.

If you, at any time, have any queries about this Privacy Policy or any other queries in relation to how we may manage, protect and/or process your Personal Information, please send an email addressed to ‘Data Protection Office’ to info@auswaybiotech.com.au.

This Privacy Policy is subject to Australian laws.

Collection of Personal Information

1.1 We may collect Personal Information from you through various means, including but not limited to instances when you: · provide your Personal Information through our Site for the purpose of registering for and creating an account; · participate in a promotion or other website features; · request for a product or services information or to receive any marketing, promotional or other types of communications; · provide your ratings and review of products as a customer; · make purchases through our retail store or Site; · make enquiries or comments through our Customer Department through info@auswaybiotech.com.au; and/or · interact with our sales staff or with us, including in store via sign-up pads.

1.2 In addition to the above, we may use the following technologies (elaborated below) to automatically collect information about your activities on the Site, as the case may be (each a “Mobile Technology”):

· Cookies · Flash Cookies · Web beacons, clear pixels, or pixel tags · Analytical tags · Web server logs · Geo-location technologies

Do refer to paragraph 9 of this Privacy Policy for more information about these Mobile Technologies and how they operate to collect information about you.

1.3 You have no obligation to provide any of the Personal Information requested by us. However, depending on circumstances, it may be the case that if you do not provide the requested Personal Information, we may not be able to provide you with certain products and services, or transact with you, that depend on the collection, use or disclosure of your Personal Information.

Children’s Privacy

2.1 We do not and do not intend to, transact through the Site directly with anyone we know to be under the age of 18. If you are under the age of 18, you should use the Site only with the involvement of a parent or guardian and should not submit any Personal Information to us. By providing any Personal Information to us, you declare that you are over the age of 18.

Purposes For Collection, Use, Disclosure And Processing Of Personal Information

3.1 SKYCARE will/may collect, use, disclose and/or process your Personal Information for one or more of the following purposes:

(a) administering, facilitating, processing and/or dealing in any matters relating to your use or access of the Site. Without limiting the generality of the foregoing, if you:

(i) gain access to or sign in to the Site, using your login credentials of a Social Networking Site, or (ii) use any features of a Social Networking Site such as its widgets, plug-ins and browser push notifications, made available to you on our Site,

it may result in information or your Personal Information being collected or shared between us and the third party. For example, if you use Facebook’s “Like” feature, Facebook may register the fact that you “liked” a product and may post that information on Facebook. (“Social Networking Site” refers to an online or digital platform owned or operated by a third party, that is used by people to build social networks or social relations, or to interact, with other people, such as but not limited to Facebook, Instagram, Twitter, TikTok). By your proceeding pursuant to (i) or (ii) above, you consent to such collection, use or disclosure of your Personal Information;

(b) monitoring, processing and/or tracking your use of the Site in order to provide you with a seamless experience, facilitating or administering your use of the Site, and/or to assist us in improving your experience in using the Site;

(c) assessing and processing your request for the purchase of and/or subscription to our products and/or services;

(d) registering you as a customer of SKYCARE and/or to deal with, process and/or administer the account that you may open with us, including to facilitate your transactions or activities on the Site, or your transactions or activities with us;

(e) administering, facilitating, processing and/or dealing with your relationship with us, any transactions or activities carried out by you on the Site or at our retail stores. This includes processing your application, orders and payment transactions; implementing transactions and the supply of products and/or services to you that you have requested. Without limiting the generality of the foregoing, should you make a purchase to be delivered to a third party recipient, you consent to us disclosing Personal Information that identifies you, to the said third party recipient (such as but not limited to your name). Further, you acknowledge and agree that delivery of your purchase could involve disclosure of certain Personal Information about you to bring about delivery of the same such as your name and contact details, which may be disclosed on the cover of the parcel, on an envelope or a delivery related document, as the case may be, which could be seen by third parties who view such parcel, envelope or said document;

(f) carrying out your instructions or responding to any enquiry given by (or purported to be given by) you or on your behalf including responding to your customer service enquiries and complaints; or responding to or dealing with your interactions with us;

(g) contacting you or communicating with you via phone/voice call, text message and/or fax message, email and/or postal mail for the purposes of administering and/or managing your use of the Site, and/or account with us, your relationship with us or any transactions made by you with us. You acknowledge and agree that such communication by us could be by way of the mailing of correspondence, documents or notices to you, which could involve disclosure of certain Personal Information about you to bring about delivery of the same as well as on the external cover of envelopes/mail packages;

(h) providing services to you as our account holder, as our customer, as a member of our loyalty program(s) or when requested by you; dealing with or administering your participation in contests, gamification, social events organized by us;

(i) sharing or disclosing (at our discretion) your suggestions, comments, feedback or content (including audio, video etc.) (collectively “Feedback”) that you provide through Social Networking Sites, to the Site or to us (including at the retail stores), with other users of the Site or with the public, for publicity and/or promotion purposes with a view to marketing or showcasing the business of SkyCare, and/or to acquiring customers, and/or for the purpose of providing the public with your Feedback which may be useful for the public’s purchasing decision or for the public’s information or otherwise. This includes us disclosing your name together with your Feedback. Without limiting the generality of the foregoing, in the above regard, your Feedback and name may/will be published or shared by us on public media platforms such as the newspaper, the Internet, in our (including our affiliates’) annual reports (if any) etc., and/or incorporated as part of SkyCare’s marketing collaterals/materials or corporate video to be disclosed to the public, and you hereby consent to the same. Do not provide us with Feedback if you do not wish for such Feedback to be disclosed to the public. If you wish to give us your Feedback without it being disclosed to the public, please separately email our Customer Department at info@auswaybiotech.com.au and head the subject of your email with the word “Confidential”;

(j) where you have provided your consent to us, whether such consent was obtained through the Site, the retail store(s) or otherwise or communication platform as we so choose, at our discretion, such as but not limited to as part of SkyCare’s marketing collaterals/materials or corporate video.

(k) carrying out due diligence or other screening activities (including background checks) in accordance with legal or regulatory obligations (whether Australia or foreign country/region) applicable to us or our affiliates/associated companies, the requirements or guidelines of governmental authorities (whether Australia or foreign country/region) which we determine are applicable to us or our affiliates/associated companies, and/or our risk management procedures that may be required by law (whether Australia or foreign country/region) or that may have been put in place by us or our affiliates/associated companies;

(l) to prevent or investigate any fraud, unlawful activity or omission or misconduct, whether or not there is any suspicion of the aforementioned; dealing with and/or investigating complaints;

(m) complying with or as required by any applicable law, court order, order of a regulatory body, governmental or regulatory requirements of any jurisdiction applicable to us or our affiliates/associated companies, including meeting the requirements to make disclosure under the requirements of any law binding on us or our affiliates/associated companies, and/or for the purposes of any guidelines issued by regulatory or other authorities (whether of Australia or foreign country/region), with which we or our affiliates/associated companies are expected to comply;

(n) complying with or as required by any request or direction of any governmental authority (whether Australia or foreign country/region) which we are expected to comply with; or responding to requests for information from public agencies, ministries, statutory boards or other similar authorities (including but not limited to the Australian Border Force and Australian State or Territory Ministries of Health). For the avoidance of doubt, this means that we may/will disclose your Personal Information to such parties upon their request or direction;

(o) conducting research (including customer research), surveys, market surveys, analysis and/or development activities (including but not limited to data analytics, surveys and/or profiling) to improve our services and facilities, or to improve our understanding of your interests, concerns and preferences, in order to enhance any continued interaction between yourself and us connected or in relation to the Site, or improve any of our products or services. You consent to receiving surveys or requests for a face to face interview survey, by way of email or postal mail;

(p) storing, hosting, backing up (whether for disaster recovery or otherwise) of your Personal Information, whether within or outside Australia;

(q) facilitating, dealing with and/or administering external audit(s) or internal audit(s) of the business of SKYCARE or that of its affiliates/related corporations;

(r) for marketing purpose and in this regard, we would be providing you with marketing, advertising and promotional information, materials and/or documents relating to products, contests, services and/or events (including those of third party organisations whom SKYCARE may collaborate with) that SKYCARE (including its affiliates/related corporations) or such third party organisations may be selling, marketing, offering, organizing, involved in or promoting, whether such products, services and/or events exist now or are created in the future. You consent to receive such marketing, advertising and promotional information, materials and/or documents by way of postal mail, electronic transmission to your email address(es), voice calls, text messages, faxes, push notifications or harnessing other technologies (such as geo-location technology) or other technologies on your computers, and/or through other modes of communication, in compliance with Australian laws. You may opt out of this or withdraw from this at any time by sending an email to info@auswaybiotech.com.au.

For the avoidance of doubt, this subparagraph is without prejudice to subparagraph (o) above for which you have hereby consented to us contacting you for a survey, which you may subsequently opt out of by sending the Data Protection Office notice;

(s) dealing with and/or facilitating a business asset transaction or a potential business assert transaction, where such transaction involves SKYCARE as a participant or involves only a related corporation or affiliated company of SKYCARE as a participant or involves SKYCARE and/or any one or more of SKYCARE’s related corporations or affiliated companies as participant(s), and there may be other third party organisations who are participants in such transaction. “business asset transaction” means the purchase, sale, lease, merger or amalgamation or any other acquisition, disposal or financing of an organisation or a portion of an organisation or of any of the business or assets of an organisation;

(t) to implement and maintain our information technology systems, including to store and process Personal Information in computer databases and servers located within and outside Australia;

(u) de-identification of your Personal Information. In this regard, you acknowledge that Personal Information that has been de-identified is no longer Personal Information and the requirements of the Privacy Act would no longer apply to such data;

(v) record-keeping purposes and producing statistics and research for internal and/or statutory reporting and/or record-keeping requirements, of SKYCARE or of its affiliates/related corporations; and

(w) SKYCARE or SKYCARE’s parent corporation’s reporting purposes including but not limited to reporting on SKYCARE’s business performance (“SKYCARE Group Companies” means SKYCARE, its affiliates, related corporations and associated companies globally);

(the purposes set out in this paragraph 3.1 above shall be collectively referred to as the “Purposes”).

3.2 For the avoidance of doubt, you acknowledge and consent to SKYCARE sharing de-identified information such as but not limited to in the following circumstances. For the further avoidance of doubt, the Privacy Act does not apply to de-identified information that does not identify an individual and the Privacy Act does not provide you with a right to object to an organisation handling or processing de-identified information:

(a) Aggregate information. We may share de-identified aggregate information about our customers with advertisers and marketing partners;

(b) Behavioural-based advertising. A third party may use technology to collect de-identified information about your use of Site so that they can provide advertising about products and services tailored to your interest. That advertising may appear either when you are using the Site, or using the Internet or your mobile device to visit other websites.

Sharing and Disclosure of Personal Information

4.1 SKYCARE may/will need to disclose your Personal Information to third parties, whether located within or outside Australia, for one or more of the above Purposes, as such third parties, would be processing your Personal Information for one or more of the above Purposes. In this regard, you hereby acknowledge, agree and consent that we are permitted to disclose your Personal Information to such third parties (whether located within or outside Australia) for one or more of the above Purposes and for the said third parties to subsequently collect, use, disclose and/or process your Personal Information for one or more of the above Purposes. Without limiting the generality of the foregoing or of paragraph 3, such third parties include :

(a) our related corporations and affiliates either in Australia or overseas including the countries/regions listed in Appendix A to this Privacy Policy;

(b) any of our agents, contractors or third party service providers that process or will be processing your Personal Information on our behalf or otherwise, including but not limited to those which provide administrative or other services to us such as mailing houses, call centres, telecommunication companies, logistics companies, information technology companies and data centres;

(c) our business partners;

(d) any actual or proposed assignee or transferee of the business of SKYCARE, or a merged entity in the event SKYCARE is merged to create the said merged entity;

(e) any other person to whom such disclosure is required by law or regulatory requirement or pursuant to a court order;

(f) third parties to whom disclosure by SKYCARE is for one or more of the Purposes and such third parties would in turn be collecting and processing your Personal Information for one or more of the Purposes.

4.2 We will provide our preferred service providers with the information they need to perform their services and work with them to respect and protect your Personal Information. We require our service providers to adhere to strict privacy guidelines and not to use your Personal Information for unauthorised purposes.

4.3 Where your Personal Information is to be transferred out of Australia, we will comply with the Privacy Act in doing so. This includes taking reasonable steps to ascertain that the overseas recipient organisation of the Personal Information will not breach the Privacy Act in relation to the Personal Information.

Provision Of Third Party Personal Information By You

5.1 Should you provide SKYCARE with Personal Information of individual(s) other than yourself, you represent and warrant to SKYCARE and you hereby confirm that :

(a) prior to disclosing such Personal Information to us, you would have and had obtained consent from the individuals whose Personal Information are being disclosed to us, to:

(i) permit you to disclose the individuals’ Personal Information to SKYCARE for the Purposes; and

(ii) permit SKYCARE to collect, use, disclose and/or process the individuals’ Personal Information for the Purposes, as set out in paragraph 3 above;

(b) any Personal Information of individuals that you disclose to us is accurate; and

(c) you are validly acting on behalf of such individuals and that you have the authority of such individuals to provide their Personal Information to SKYCARE and for SKYCARE to collect, use, disclose and process such Personal Information for the Purposes.

Request For Access And/ Or Correction Of Personal Information

6.1 You may request to access and/or correct your Personal Information currently in our possession or control by submitting a written request to us. We will need enough information from you in order to ascertain your identity as well as the nature of your request, to deal with your request. Please submit your written request to info@auswaybiotech.com.au.

6.2 For a request to access Personal Information, once we have sufficient information from you to deal with the request, we will seek to provide you with the relevant Personal Information within 30 days. Where we are unable to respond to you within the said 30 days, we will notify you of the soonest possible time within which we can provide you with the information requested. The Privacy Act exempts certain types of Personal Information from being subject to your access request.

6.3 For a request to correct Personal Information, once we have sufficient information from you to deal with the request, we will deal with your request in compliance with the Privacy Act, including correct your Personal Information within 30 days. Where we are unable to do so within the said 30 days, we will notify you of the soonest practicable time within which we can make the correction. Note that the Privacy Act exempts certain types of Personal Information from being subject to your correction request as well as provides for situation(s) when correction need not be made by us despite your request.

Request To Withdraw Consent

7.1 You may withdraw your consent for the collection, use and/or disclosure of your Personal Information in our possession or under our control by submitting your request to info@auswaybiotech.com.au.

7.2 We will process your request within a reasonable time from such a request for withdrawal of consent being made, and will subsequently not collect, use and/or disclose your Personal Information in the manner stated in your request, unless Australian laws allow us to.

7.3 However, your withdrawal of consent could result in certain legal consequences arising from such withdrawal. In this regard, depending on the extent of your withdrawal of consent for us to process your Personal Information, it may mean that we may not be able to fulfill the transaction you have entered into with us or continue with your relationship with us, or send you information that you have requested, as examples depending on the circumstances.

Protecting and Managing Your Personal Information

8.1 We will take all reasonable steps to ensure your Personal Information is kept confidential and secure, and to take appropriate technical and organizational measures to prevent unlawful or accidental destruction, accidental loss, unauthorized disclosure or access or other unlawful forms of processing. We will not rent, trade, distribute or sell any Personal Information that you give us to any third party unless we receive your prior consent or applicable law permits the same.

8.2 We will put in place reasonable security arrangements to ensure that your Personal Information is adequately protected and secured. Appropriate security arrangements will be taken to prevent any unauthorized access, collection, use, disclosure, copying, modification, leakage, loss, damage and/or alteration of your Personal Information. However, we cannot assume responsibility for any unauthorized use of your Personal Information by third parties which are wholly attributable to factors beyond our control.

8.3 We will take reasonable efforts to ensure that your Personal Information is accurate and complete, if your Personal Information is likely to be used by us to make a decision that affects you, or disclosed to another organisation. However, this means that you must also update us of any changes in your Personal Information that you had initially provided us with. We will not be responsible for relying on inaccurate or incomplete Personal Information arising from you not updating us of any changes in your Personal Information that you had initially provided us with.

8.4 We will also put in place measures such that your Personal Information in our possession or under our control is destroyed and/or de-identified as soon as it is reasonable to assume that (i) the purpose for which that Personal Information was collected is no longer being served by the retention of such Personal Information; and (ii) retention is no longer necessary for any other legal or business purposes.

Cookies and Mobile Technology

9.1 Cookies. For users of the Site, please note that SKYCARE may deposit “cookies” in your computer or your mobile device in order to identify you. Cookies are small data text files that are sent from a server computer during a browsing session. Cookies are typically stored on the computer’s hard drive and are used by web-sites to simulate a continuous connection to the site. Security measures have been employed to prevent unauthorized access to visitor data. However, visitors acknowledge that SKYCARE does not control the transfer of data over telecommunication facilities including the Internet. Therefore, to the extent permitted by law, SKYCARE will not be responsible for any breach of security or the unauthorized disclosure or use of any such data on the Internet, through no fault of SKYCARE. Not all cookies collect Personal Information and you may configure your browser to reject cookies. However, this may mean you may not be able to take full advantage of the services or features on the Site. Where the data collected by such cookies constitute your Personal Information, such Personal Information is being collected, used or disclosed for one or more of the Purposes. By continuing to use the Site, you are agreeing to the use of cookies on the Site. However, please note that we have no control over the cookies used by third parties.

9.2 Flash Cookies. “Flash Cookies” (also called Local Shared Objects or “LSOs”) are data files similar to cookies, except that they can store more complex data. Flash Cookies are used to remember settings, preferences, and usage, particularly for video, interactive gaming, and other similar services.

9.3 Web Beacons. Web beacons are small graphic images on a web page or in an e-mail that can be used for such things as recording the pages and advertisements clicked on by users, or tracking the performance of e-mail marketing campaigns.

9.4 Analytics Tags. We use analytical tags to analyse what our clients like to do and the effectiveness of our features and advertising. They can also help us customize your browsing and shopping experience. We may use information collected through analytical tags or tracked links in combination with your Personal Information. We may also combine Personal Information you provide to us with other Personal Information (such as purchase history and demographic information). We often work with other companies to help us track, collect and analyse this information but they are prohibited from using this information for any other purpose.

9.5 Web Server Logs. Web server logs are records of activity created by the mobile device or computer that delivers the webpages you request to your browser. For example, a web server log may record the search term you entered or the link you clicked to bring you the webpage. The Web server log also may record information about your browser, such as your IP address and the cookies set on your browser by the server.

9.6 Geo-Location Technologies. Geo-location technology refers to technologies that permit us to determine your country/region. We may ask you to manually provide country/region information (like your postal code), or to enable your mobile device to send us precise country/region information.

Registration Information

Our Site contains areas where you can submit information to us (such as our registration service), and we also have features (such as cookies and performance tracking technology) that automatically collect information from the visitors to our Site. During the registration process, you must provide us with a password, your name, address and a valid email address, etc. It is your responsibility to keep your password strictly confidential.

Changes to this Privacy Policy

Our privacy practices will be continuously assessed against new technologies, business practices and our customers’ needs. As we update and diversify our services, our Privacy Policy may evolve. SKYCARE reserves the right to change its Privacy Policy at any time and notify you by posting an updated version of the policy on the Site. Please check the Site or send your request by email to info@auswaybiotech.com.au if you would like to receive the latest updated Privacy Policy.

Problems, queries or complaints

12.1 If you have any queries relating to our Privacy Policy, or if you wish to request for access to or correction of your Personal Information or to withdraw your consent, please contact or send your request to our Data Protection Office by email to info@auswaybiotech.com.au.

12.2 You may also contact us at the details above if you have a complaint about a possible breach of Australian privacy law. We will investigate your complaint and will use reasonable endeavours to respond to you in writing as soon as possible.

General

13.1 Your consent that is given pursuant to this Privacy Policy is additional to and does not supersede any other consents that you provided to SKYCARE with regard to processing of your Personal Information.

13.2 For the avoidance of doubt, in the event that Australian law permits an organisation such as us to collect, use or disclose your Personal Information without your consent, such permission granted by the law shall continue to apply. APPENDIX A

COUNTRIES/REGIONS IN WHICH OVERSEAS RECIPIENTS ARE LIKELY TO BE LOCATED

Aruba; Australia; Austria; Bahrain; Barbados; Belgium; Bermuda; Brazil; Canada; Chile; China; Colombia; Czech Republic; Denmark; Dominican Republic; Finland; France; Germany; Greece; Guam; Hong Kong SAR; Hungary; India; Indonesia; Ireland; Israel; Italy; Japan; Kazakhstan; Kuwait; Lebanon; Luxembourg; Macau SAR; Malaysia; Mexico; Mongolia; Morocco; Netherlands; New Zealand; Norway; Panama; Philippines; Poland; Portugal; Qatar; Romania; Russian Federation; Saipan; Saudi Arabia; Singapore; South Africa; South Korea; Spain; Sweden; Switzerland; Taiwan; Thailand; Turkey; Ukraine; United Arab Emirates; United Kingdom; Uruguay; United States of America; Vietnam.

Comments

When visitors leave comments on the site we collect the data shown in the comments form, and also the visitor’s IP address and browser user agent string to help spam detection.

An anonymized string created from your email address (also called a hash) may be provided to the Gravatar service to see if you are using it. The Gravatar service privacy policy is available here: https://automattic.com/privacy/. After approval of your comment, your profile picture is visible to the public in the context of your comment.

Media

If you upload images to the website, you should avoid uploading images with embedded location data (EXIF GPS) included. Visitors to the website can download and extract any location data from images on the website.

Cookies

If you leave a comment on our site you may opt-in to saving your name, email address and website in cookies. These are for your convenience so that you do not have to fill in your details again when you leave another comment. These cookies will last for one year.

If you visit our login page, we will set a temporary cookie to determine if your browser accepts cookies. This cookie contains no personal data and is discarded when you close your browser.

When you log in, we will also set up several cookies to save your login information and your screen display choices. Login cookies last for two days, and screen options cookies last for a year. If you select “Remember Me”, your login will persist for two weeks. If you log out of your account, the login cookies will be removed.

If you edit or publish an article, an additional cookie will be saved in your browser. This cookie includes no personal data and simply indicates the post ID of the article you just edited. It expires after 1 day.

Embedded content from other websites

Articles on this site may include embedded content (e.g. videos, images, articles, etc.). Embedded content from other websites behaves in the exact same way as if the visitor has visited the other website.

These websites may collect data about you, use cookies, embed additional third-party tracking, and monitor your interaction with that embedded content, including tracking your interaction with the embedded content if you have an account and are logged in to that website.

Analytics

Who we share your data with

If you request a password reset, your IP address will be included in the reset email.

How long we retain your data

If you leave a comment, the comment and its metadata are retained indefinitely. This is so we can recognize and approve any follow-up comments automatically instead of holding them in a moderation queue.

For users that register on our website (if any), we also store the personal information they provide in their user profile. All users can see, edit, or delete their personal information at any time (except they cannot change their username). Website administrators can also see and edit that information.

What rights you have over your data

If you have an account on this site, or have left comments, you can request to receive an exported file of the personal data we hold about you, including any data you have provided to us. You can also request that we erase any personal data we hold about you. This does not include any data we are obliged to keep for administrative, legal, or security purposes.