Skip to content

rxnet

Privacy Policy

Document
Broadstack Pty Ltd-PRIV-1
Version
202609
Cited by
D2 clause 14.1

Broadstack Pty Ltd Privacy Policy


1. ABOUT THIS POLICY

1.1 Purpose

This policy explains how Broadstack Pty Ltd (ABN 41 648 429 789) handles personal information. It covers the personal information the Provider collects for its own purposes, and the personal information a Customer places in the Provider's care when it uses rxnet.

1.2 Who this policy applies to

This policy applies to:

(a) a visitor to the Provider's website;

(b) a person who contacts the Provider;

(c) a Customer's personnel and Authorised Users;

(d) a supplier, a contractor and a job applicant; and

(e) an individual whose personal information a Customer places in rxnet, to the extent clause 2.3 describes.

1.3 The Provider's position under the Privacy Act

(a) An organisation with an annual turnover of $3 million or less is not an APP entity under the Privacy Act, unless an exception in section 6D or 6DA applies. See Source Register, entries S-01 and S-26.

(b) The Provider is a small business operator and is not currently an APP entity. The Provider holds no registration, accreditation or certification under the Privacy Act, and this policy does not claim one.

(c) The Provider applies the Australian Privacy Principles as a matter of policy, whether or not the Privacy Act obliges it to. Under clause 8.1 of the Master Subscription Agreement that undertaking is also a contractual obligation the Provider owes each Customer.

(d) If the Provider becomes an APP entity, this policy continues to apply and the Provider complies with the Privacy Act as well.

1.4 Relationship to a Customer agreement

(a) Where the Provider handles personal information under an agreement with a Customer, that agreement governs. If this policy is inconsistent with clause 8 of the Master Subscription Agreement, clause 8 of that agreement prevails for Customer Data. See the Terms of Service, clause 14.2.

(b) Nothing in this policy limits a right an individual has under the Privacy Act or another law.

1.5 Meaning of terms

In this policy:

APP means an Australian Privacy Principle in Schedule 1 to the Privacy Act. See Source Register, entry S-01.

Authorised User has the meaning given in the Master Subscription Agreement.

Customer means an organisation that has an agreement with the Provider for rxnet.

Customer Data has the meaning given in the Master Subscription Agreement.

Personal Information has the meaning given in section 6(1) of the Privacy Act. See Source Register, entry S-01.

Privacy Act means the Privacy Act 1988 (Cth), including the Australian Privacy Principles in Schedule 1. See Source Register, entry S-01.

Provider, the Provider, we, us and our mean Broadstack Pty Ltd.

Sensitive Information has the meaning given in section 6(1) of the Privacy Act. See Source Register, entry S-01.

you means the individual this policy applies to under clause 1.2.


2. THE TWO ROLES

2.1 Why the distinction matters

We handle Personal Information in two roles. This policy separates them, because your route to access, correction and complaint is different in each.

2.2 Personal Information we hold for our own purposes

This is Personal Information we collect and decide what to do with. It includes enquiries, Customer contacts, support records, supplier records, applicant records and website records. Clauses 3 to 14 apply to it in full.

2.3 Personal Information a Customer places in rxnet

(a) Customer Data may contain Personal Information about people who are not our customers. The Customer decides what Personal Information it places in rxnet and why.

(b) We handle that Personal Information only on the Customer's documented instructions, which are the terms of its agreement with us, unless the law requires us to do otherwise. See the Master Subscription Agreement, clause 8.2.

(c) We do not use Customer Data for our own purposes. We do not use it to train a computer model. We do not sell it.

(d) If you ask us to give you access to, or to correct, Personal Information in Customer Data, we refer your request to the Customer. Clause 10.5 explains what happens next.

(e) The Customer is responsible for telling you what it collects and why. Ask the Customer for its own privacy policy.


3. THE PERSONAL INFORMATION WE COLLECT AND HOLD

3.1 The kinds we collect

(a) Contact information. Name, business name, position, email address, postal address and telephone number.

(b) Enquiry information. The content of an enquiry you send us, and our correspondence with you about it.

(c) Account information. The user name, email address and access rights of an Authorised User of rxnet, and the records of that person's sign in activity.

(d) Support information. The content of a support request, and the records we make while we work on it.

(e) Transaction information. Billing contact details, purchase orders, invoices and payment records. We do not store a full payment card number.

(f) Technical information. Internet protocol address, browser type, the page requested, and the date and time of the request, recorded in server and security logs.

(g) Supplier and contractor information. Contact details, and the records of an engagement.

(h) Applicant information. A curriculum vitae, work history, referee details, and the records of a recruitment process.

3.2 Sensitive Information

(a) We do not seek Sensitive Information, and rxnet is not designed to hold it.

(b) We collect Sensitive Information only with your consent, and only where it is reasonably necessary for one of our functions or activities. See Source Register, entry S-01, APP 3.3.

(c) A Customer may place Sensitive Information in Customer Data. Clause 2.3 applies to it.

3.3 Government related identifiers

We do not adopt a government related identifier as our own identifier for an individual. We do not use or disclose one except as APP 9 permits. See Source Register, entry S-01.

3.4 Children

rxnet is a business service. We do not direct our website or rxnet at children, and we do not knowingly collect Personal Information from a child.


4. HOW WE COLLECT PERSONAL INFORMATION

4.1 Directly from you

We collect most Personal Information directly from the individual: through the contact form on our website, by email, by telephone, at a meeting, and when an Authorised User uses rxnet.

4.2 From someone else

(a) We collect the contact details of a Customer's personnel from the Customer.

(b) We collect an applicant's details from a recruiter, or from a referee the applicant names.

(c) Where we collect Personal Information about you from someone else, we take reasonable steps to tell you the matters APP 5 lists, unless an exception in APP 5 applies. See Source Register, entry S-01.

4.3 Personal Information we did not ask for

If we receive Personal Information we did not ask for, we decide whether we could have collected it under APP 3. If we could not, and no law requires us to keep it, we destroy it or de-identify it as soon as practicable. See Source Register, entry S-01, APP 4.

4.4 Dealing with us anonymously

(a) You may ask a general question about our services without giving your name.

(b) We cannot provide rxnet, answer a support request, or invoice a Customer without knowing who we are dealing with. In those cases dealing with us anonymously, or under a pseudonym, is not practicable. See Source Register, entry S-01, APP 2.

4.5 Our website

(a) Our web server records the technical information clause 3.1(f) describes.

(b) The content delivery network that serves our website adds a measurement script to each page. It reports how the page performed. It sets no cookie and it stores nothing in your browser.

(c) The cookies, the browser storage and the measurement script used on our website and in the rxnet web interface are described in the Cookie Notice at https://broadstack.com.au/p/rxnet/l/cookies.

(d) Our contact form is operated by a third party form service. Clause 6.1 applies to it.


5. WHY WE COLLECT, HOLD, USE AND DISCLOSE PERSONAL INFORMATION

5.1 Our purposes

(a) to answer an enquiry and to give a quote;

(b) to enter into and perform an agreement with a Customer;

(c) to provide, operate, support and secure rxnet;

(d) to manage accounts, billing and collection;

(e) to detect, investigate and respond to a security incident, to misuse, and to fraud;

(f) to keep the business records the law requires us to keep;

(g) to manage our suppliers and contractors;

(h) to assess a job application; and

(i) to meet an obligation under an Australian law, or a binding request from a court, a regulator or a law enforcement agency.

5.2 Use for another purpose

We use or disclose Personal Information for a purpose other than the one we collected it for only where you would reasonably expect it and that purpose is related to the first, where you consent, or where APP 6 otherwise permits it. See Source Register, entry S-01.

5.3 Direct marketing

(a) We may send you information about our services where you are a business contact and you would reasonably expect it.

(b) Every commercial electronic message we send identifies us and contains a working unsubscribe facility. See Source Register, entry S-14.

(c) If you ask us to stop, we stop, and we do not charge you for it.

(d) We do not disclose Personal Information to another organisation for that organisation's direct marketing.


6. WHO WE DISCLOSE PERSONAL INFORMATION TO

6.1 Service providers

(a) We disclose Personal Information to the suppliers that help us run the business and the service. They include our hosting subcontractor, the operators of the facilities it uses, the content delivery and security network that serves our website, security monitoring providers, our form, email and file storage providers, and our accounting and payment providers.

(b) The subcontractors and third party services that handle Customer Data are listed in the register of subcontractors and third party services published in the Documentation at https://broadstack.com.au/p/rxnet/documentation.

(c) We require a supplier to handle Personal Information only for the purpose we engage it for.

6.2 Other disclosures

We disclose Personal Information:

(a) to a professional adviser, under a duty of confidence;

(b) where you consent;

(c) where an Australian law requires it, or a court, a regulator or a law enforcement agency makes a binding request; and

(d) to a buyer, or a proposed buyer, of our business or assets, under a duty of confidence.

6.3 A binding request for Customer Data

Where a binding request is for Customer Data, we notify the Customer before we disclose unless the law prohibits us from doing so, we disclose only the minimum data required, and we take reasonable steps to seek confidential treatment of the data. See the Master Subscription Agreement, clause 8.9.

6.4 What we do not do

We do not sell Personal Information. We do not trade in Personal Information. We do not disclose Personal Information to a data broker.


7. DISCLOSURE OUTSIDE AUSTRALIA

7.1 Where Customer Data is held

We store Customer Data, including backups and disaster recovery copies, only in Australia. We process Customer Data only in Australia, other than the transit clause 7.2 describes. See the Master Subscription Agreement, clause 8.4.

7.2 Edge transit

(a) We route public traffic to rxnet through a global content delivery and security network. Data contained in a request or a response may be received and decrypted outside Australia while it is in transit.

(b) This is a cross border disclosure for the purposes of APP 8. See Source Register, entry S-01.

(c) The limitation reaches data in transit within a request or a response, and any transient cache at the edge. It does not reach stored Customer Data, backups, database contents, or any person's access to data at rest.

(d) The edge network selects the point of presence that handles a request, and the routing can change without notice. We cannot state in advance which country will handle a request, so it is not practicable for us to list the countries where a recipient is likely to be located. See Source Register, entry S-01, APP 1.4(g).

7.3 Other overseas recipients of Customer Data

Apart from clause 7.2, we do not disclose Customer Data to an overseas recipient without the Customer's prior written consent, unless an Australian law requires it. See the Master Subscription Agreement, clause 8.4(d) and clause 8.4(f).

7.4 Personal Information we hold for our own purposes

(a) We use business software supplied by international vendors for email, file storage, accounting and customer communication. Personal Information we hold for our own purposes may be stored outside Australia, or accessed from outside Australia, by those vendors.

(b) The vendors, and the countries involved, are not yet listed here. We are compiling that list and we will publish it in this clause. Until we do, ask us for the current position using the contact details in clause 14.


8. HOW WE HOLD AND PROTECT PERSONAL INFORMATION

8.1 Security

(a) We take reasonable steps to protect Personal Information from misuse, interference and loss, and from unauthorised access, modification and disclosure. See Source Register, entry S-01, APP 11.1.

(b) We describe those controls in our security documentation. That document is not a term of any agreement. A Customer may ask us for a copy.

(c) We hold no certification under a security standard, and this policy does not claim one.

8.2 How long we keep it

(a) We keep Personal Information only for as long as we need it for a purpose in clause 5.1, or for as long as a law requires us to keep it.

(b) Where an Australian law sets a minimum retention period for a record, we keep the record for that period.

(c) When we no longer need Personal Information, and no law requires us to keep it, we destroy it or de-identify it. See Source Register, entry S-01, APP 11.2.

(d) How long we keep Customer Data after an agreement ends is governed by that agreement. See the Master Subscription Agreement, clause 17.

8.3 Data breaches

(a) We investigate a suspected data breach and we take steps to contain it.

(b) Where a data breach affects Customer Data, we notify the Customer without undue delay, and within the period our agreement with that Customer sets. See the Master Subscription Agreement, clause 8.6.

(c) Where Part IIIC of the Privacy Act applies to a data breach and the breach is likely to result in serious harm to an individual, we notify the individual and the Office of the Australian Information Commissioner as Part IIIC requires. See Source Register, entry S-01.

(d) Where a breach affects Customer Data, we and the Customer co-operate to assess whether an eligible data breach has occurred.


9. AUTOMATED DECISIONS

9.1 Our position

(a) We do not use a computer program to make a decision about you, or to do a thing that is substantially and directly related to making a decision about you, where that decision could reasonably be expected to significantly affect your rights or interests.

(b) rxnet applies automated rules to the signals a Customer sends it, and it can act on those rules. The Customer configures those rules, and the rules act on events rather than on people. A decision about an individual is the Customer's decision, not ours.

9.2 The requirement that starts on 10 December 2026

(a) From 10 December 2026, APP 1.7 to APP 1.9 require an APP entity to state in its privacy policy the kinds of Personal Information a computer program uses to make a decision of the kind clause 9.1(a) describes, and the kinds of decision made. Schedule 1, Part 15 of the Privacy and Other Legislation Amendment Act 2024 (Cth) inserts that requirement. See Source Register, entry S-35.

(b) We are not an APP entity, so APP 1.7 does not bind us. If our practice changes, we state the matters APP 1.7 lists in this clause, whether or not we are an APP entity at that time.


10. ACCESS AND CORRECTION

10.1 Asking for access

You may ask us for the Personal Information we hold about you. Use the contact details in clause 14. We may ask you to verify your identity before we answer.

10.2 How we answer

(a) We answer within 30 days after we receive the request.

(b) We give access in the form you ask for, where it is reasonable to do so.

(c) We do not charge you for making a request. We may charge for giving access. A charge is not excessive and does not apply to the request itself. See Source Register, entry S-01, APP 12.

10.3 Asking for a correction

If you believe the Personal Information we hold about you is inaccurate, out of date, incomplete, irrelevant or misleading, ask us to correct it. We correct it, or we tell you why we have not. See Source Register, entry S-01, APP 13.

10.4 If we refuse

(a) If we refuse access or correction, we tell you in writing, we give our reasons, and we tell you how to complain.

(b) If we refuse a correction, you may ask us to associate a statement with the record saying that the information is inaccurate, out of date, incomplete, irrelevant or misleading. We take reasonable steps to do so.

10.5 A request about Customer Data

(a) Where your request is about Personal Information in Customer Data, we refer it to the Customer and we do not answer it directly, unless the law requires us to. See the Master Subscription Agreement, clause 8.8.

(b) We tell you that we have referred the request.

(c) We give the Customer reasonable assistance to answer it.


11. COMPLAINTS

11.1 Complain to us first

Send a complaint to info@broadstack.com.au, or to the postal address in clause 14. Tell us what happened, and tell us what you would like us to do.

11.2 How we deal with a complaint

(a) We acknowledge your complaint within 5 Business Days.

(b) We investigate it. We may ask you for more information.

(c) We give you a written answer within 30 days after we receive the complaint. If we need longer, we tell you why, and we tell you when to expect our answer.

11.3 If you are not satisfied

(a) The Office of the Australian Information Commissioner handles privacy complaints about APP entities. We are not currently an APP entity, as clause 1.3 states, so the Commissioner may decide that it cannot consider a complaint about us. See Source Register, entry S-36.

(b) You may still contact the Commissioner for information about your privacy rights.

(c) Our undertaking in clause 1.3(c) is also a contractual obligation we owe each Customer under clause 8.1 of the Master Subscription Agreement. A Customer may enforce it under that agreement.


12. COOKIES AND ANALYTICS

The cookies, the browser storage and the page measurement used on our website and in the rxnet web interface are described in the Cookie Notice at https://broadstack.com.au/p/rxnet/l/cookies. See the Terms of Service, clause 14.3.


13. CHANGES TO THIS POLICY

13.1 We may change this policy

The current version is published at https://broadstack.com.au/p/rxnet/l/privacy.

13.2 Each version is identified

Each version carries a version number and the date it took effect. The header table at the top of this document states both.

13.3 Review

We review this policy at least every 12 months.

13.4 A change does not reduce your rights

A change to this policy does not reduce a right you have under the Privacy Act or another law.


14. HOW TO CONTACT US

Field Detail
Entity Broadstack Pty Ltd, ABN 41 648 429 789
Privacy contact info@broadstack.com.au
Post 8 Binney Rd, Kings Park, NSW, 2148, Australia
Telephone (+612) 8881 1480

We give a copy of this policy free of charge, and in the form you ask for where it is reasonable to do so. See Source Register, entry S-01, APP 1.5 and APP 1.6.


ANNEXURE A — SOURCE REGISTER

Every legal instrument and external document referenced in this document is listed below. Each entry was verified on 16 September 2026. Entries S-01, S-14 and S-26 are in Annexure A to the Master Subscription Agreement or the Terms of Service and are repeated here because this document is published on its own.

ID Source Citation Reference
S-01 Privacy Act 1988 (Cth), including the Australian Privacy Principles (Schedule 1), Part IIIC (Notifiable Data Breaches), and Schedule 2 (statutory tort for serious invasions of privacy, commenced 10 June 2025). Verified 16 September 2026 at compilation C2026C00227, 4 June 2026 Privacy Act 1988 (Cth) https://www.legislation.gov.au/C2004A03712/latest
S-14 Requirement that a commercial electronic message identify the sender and contain a functional unsubscribe facility, and the prohibition on sending an unsolicited commercial electronic message. Verified 16 September 2026 Spam Act 2003 (Cth) https://www.legislation.gov.au/C2004A01214/latest
S-26 Small business operator exemption. An organisation with annual turnover of $3 million or less is not an APP entity, unless an exception applies. Exceptions include providing a health service, trading in personal information, being a credit reporting body, contracting with the Australian Government, holding Consumer Data Right accreditation, handling tax file numbers, and opting in under section 6EA. Verified 16 September 2026: section 6D remains in the Act at compilation C2026C00227, 4 June 2026 Privacy Act 1988 (Cth) ss 6D, 6DA, 6EA https://www.legislation.gov.au/C2004A03712/latest
S-35 Automated decision transparency for privacy policies, inserting Australian Privacy Principles 1.7 to 1.9. Schedule 1, Part 15, "Automated decisions and privacy policies". Act No. 128 of 2024, verified 16 September 2026. The commencement date of 10 December 2026 is taken from the Commissioner's guidance at entry S-37, not from section 2 of the Act, which could not be retrieved Privacy and Other Legislation Amendment Act 2024 (Cth) sch 1 pt 15 https://www.legislation.gov.au/C2024A00128/latest
S-36 The Commissioner's privacy complaint process, and the requirement to complain to the organisation first. Verified 16 September 2026 Office of the Australian Information Commissioner, "Privacy complaints" https://www.oaic.gov.au/privacy/privacy-complaints
S-37 The matters an APP privacy policy must contain under APP 1.4, and the commencement date of the APP 1.7 to 1.9 automated decision requirements. Verified 16 September 2026 Office of the Australian Information Commissioner, Australian Privacy Principles guidelines, Chapter 1 https://www.oaic.gov.au/privacy/australian-privacy-principles/australian-privacy-principles-guidelines/chapter-1-app-1-open-and-transparent-management-of-personal-information

END OF PRIVACY POLICY