Terms
How SendNet handles your personal data in accordance with the General Data Protection Regulation (GDPR).
Last updated: 19-08-2026
SendNet, a trading name of SendNet Australia Pty Ltd ("SendNet", "we", "us" or "our"), attaches great importance to the protection of your personal data. In this privacy statement we explain transparently which personal data we collect, for what purpose, on what legal basis, how long we retain it, who we share it with and what rights you have. We process personal data in accordance with the General Data Protection Regulation (Regulation (EU) 2016/679, hereinafter: "GDPR"), the Dutch GDPR Implementation Act and other applicable laws and regulations. We recommend reading this statement carefully.
The controller within the meaning of the GDPR is:
For any questions, requests or complaints about the processing of your personal data you can contact us using the details above.
In this privacy statement we use the definitions set out in Article 4 GDPR. In particular:
We process personal data of the following categories of data subjects, among others:
Depending on the service and your relationship with us, we may process the following (categories of) personal data:
In principle we do not process special categories of personal data (such as data on health, religion or political opinion) and ask you not to provide it to us, unless there is a legal obligation or necessity exists.
We process your personal data only for specified, explicit and legitimate purposes. Each purpose has a legal basis under Article 6 GDPR:
| Purpose | Legal basis (Art. 6 GDPR) |
|---|---|
| Performing the contract: processing, packing, shipping and delivering shipments and providing track & trace | Necessary for the performance of the contract (Art. 6(1)(b)) |
| Preparing, sending and administering invoices | Legal obligation (Art. 6(1)(c)) and performance of contract (b) |
| Customer contact, support and handling of enquiries and complaints | Performance of contract (b) and legitimate interest (f) |
| Security, fraud prevention and improvement of our services and website | Legitimate interest (Art. 6(1)(f)) |
| Meeting statutory retention and disclosure obligations | Legal obligation (Art. 6(1)(c)) |
| Sending commercial communications (where applicable) | Consent (Art. 6(1)(a)) or legitimate interest (f) |
Where we rely on a legitimate interest, we have balanced our interests against your rights and freedoms. You have the right to object to processing on this basis (see clause 11).
We disclose your personal data to third parties only insofar as necessary for the performance of our services or to comply with a legal obligation. This may involve:
With parties that process personal data on our instructions (processors) we conclude a data processing agreement setting out appropriate technical and organisational measures, confidentiality and security, in accordance with Article 28 GDPR. We never sell your personal data to third parties.
We aim to process your personal data within the EEA. If personal data is nonetheless processed outside the EEA , we do so only where an adequate level of protection is guaranteed, for example on the basis of an adequacy decision by the European Commission or by concluding the Commission's Standard Contractual Clauses, supplemented by any necessary additional measures.
We do not retain your personal data longer than necessary for the purposes for which it was collected, unless a longer retention period is legally required or permitted. As a guide we apply, among others:
Once the retention period has expired, personal data is deleted or anonymised.
We take appropriate technical and organisational measures to protect your personal data against loss, misuse, unauthorised access, unwanted disclosure and unauthorised alteration. This includes access controls, encryption where appropriate, logical separation of data, and limiting access to personal data to staff for whom it is necessary. In the unlikely event of a data breach, we act in accordance with our legal obligations, including notifying the Office of the Australian Information Commissioner (OAIC) and affected individuals where the Notifiable Data Breaches scheme requires it.
Our website may use cookies and similar technologies. Cookies are small text files that are placed on your device when you visit the website. We distinguish between:
You can set your browser to refuse or delete cookies. Disabling certain cookies may affect how the website works.
Under the GDPR you have the following rights in relation to your personal data:
You can submit a request to exercise your rights via sales@send-net.com. To verify your identity we may ask for additional information. In principle we respond within one month of your request; this period may be extended by two months for complex or numerous requests, in which case we will inform you.
We do not take decisions based solely on automated processing (including profiling) that that have legal effects for you or otherwise significantly affect you, without human intervention.
Our services and website are not directed at minors. We do not knowingly collect personal data from people under 16 without the consent of a parent or legal guardian. If you believe we have processed data without that consent, please contact us so we can delete it.
If you believe we are not handling your personal data carefully, we ask you to raise this with us first. You also have the right to lodge a complaint with the supervisory authority, the Office of the Australian Information Commissioner (www.oaic.gov.au).
We may amend this privacy statement from time to time, for example in response to changes in laws and regulations or our services. The most current version is always available on this page. For significant changes, we will make reasonable efforts to inform you appropriately.
If you have questions or comments about this privacy statement or about how we handle personal data ? Please contact us at sales@send-net.com or by post: SendNet Australia Pty Ltd, 159 Studley Ct, DERRIMUT VIC 3026, Australia.