Privacy Policy
Last Updated: August 2026
Introduction
This Privacy Policy outlines the ways in which LAN10 PTY LIMITED ACN 655 708 277 ("we", "us", or "our"), as the Data Controller, collects, uses, maintains, and discloses information, including potentially sensitive information, collected from users (each, a User) of our Platform. This policy applies to all services offered by LAN10 (including through the application known as LAN10 Vault) and it is in compliance with (where relevant) the Privacy Act 1988 (Cth), Australia's Privacy Principles, and other applicable privacy laws of Australia as well as the General Data Protection Regulation of the European Union (GDPR).
By accessing or using our services, Users agree to the collection and use of information in accordance with this policy. We are committed to protecting the privacy and security of our Users' information and to being transparent about the ways in which that information is used.
Scope and Consent
This Privacy Policy applies to all personal data collected, processed, or held by the Data Controller in relation to the services offered. By accessing or using the services, the User consents to the collection, use, disclosure, and processing of their personal data in accordance with this Privacy Policy.
Users have the right to access, correct, or delete their personal data held by the Data Controller. Requests for access, correction, or deletion should be directed to the contact details provided in this Privacy Policy.
By continuing to use the services, Users affirm their understanding and acceptance of the terms outlined in this Privacy Policy, including any updates or amendments made from time to time. The Data Controller reserves the right to modify this Privacy Policy at any time, with changes taking effect immediately upon posting to the service's website.
Information Collection
This Privacy Policy outlines the types of information that is collected and recorded by LAN10 (the Data Controller) and how we use it. This policy applies to all Users of our services, regardless of their location.
By accessing or using our services, Users consent to the collection, use, and sharing of their personal information as described in this Privacy Policy. The types of information we may collect include, but are not limited to:
- Personal Information (e.g., name, email address, phone number, address)
- Browser and Device Information (e.g., type of device, web browser version, IP address)
- Usage Data (e.g., pages visited, interaction with content, access times)
- Location Data (e.g., GPS-based or IP-based location information)
We collect information through various means, including but not limited to, direct interactions with our Users, use of cookies and other tracking technologies, and from third parties. Mobile phone numbers are never obtained from third parties; they are provided by the account holder only.
Biometric Authentication
LAN10 uses the biometric authentication built into the User's device, such as Face ID and Touch ID on iOS, or fingerprint and face unlock on Android, to protect access to the LAN10 Vault and LAN10 Auth applications.
Biometric verification is performed entirely by the device operating system. Biometric data never leaves the User's device and is not accessible to LAN10 or to the LAN10 applications. LAN10 does not collect, receive, transmit, process or store biometric data of any kind, and no biometric data is held in our cloud storage or on our servers.
Use of Information
The Data Controller shall use the personal data collected from Users in accordance with the Privacy Principles set out in the Privacy Act 1988 (Cth), and any other applicable privacy legislation or guidelines in Australia. The purposes for which personal and sensitive data may be used include, but are not limited to:
- Providing and managing access to our services;
- Improving and personalizing our services;
- Communicating with Users regarding their use of our services, including any updates or changes;
- Conducting research and analysis to enhance and protect our services;
- Complying with legal and regulatory obligations;
- Protecting the rights, property, or safety of LAN10, our Users, or others.
Any use of personal data beyond these stated purposes will be subject to the additional consent of the User, unless otherwise required or permitted by law.
Legal Basis for Processing under the GDPR
Under the GDPR, we rely on the following legal bases for processing personal and sensitive data:
- The User has given explicit consent to the processing of their data;
- Processing is necessary for the performance of a contract;
- Processing is necessary to comply with a legal obligation;
- Processing is necessary for the legitimate interests pursued by the Data Controller, except where overridden by the interests or fundamental rights and freedoms of the User.
Information Sharing and Disclosure
LAN10, herein referred to as the "Data Controller", commits to maintaining the confidentiality and security of the personal data of its Users. The Data Controller will not share, sell, rent, or trade personal data with third parties except as disclosed within this policy. The circumstances under which personal data may be disclosed to third parties are as follows:
- In response to a legal process or to comply with the law, such as in response to a court order or a subpoena.
- To protect the rights, property, or safety of the Data Controller, its Users, or the public as required or permitted by law.
- In the event of a merger, acquisition, reorganization, bankruptcy, or other similar event, personal data may be part of the transferred assets.
- With the User's consent, for purposes not listed above.
Any third parties with whom personal data is shared are required to protect the data in a manner that is consistent with this policy and are prohibited from using the data for any purpose other than those specified by the Data Controller.
SMS Messaging and Mobile Numbers
LAN10 sends one-time passcodes by SMS to verify a User's identity when they register an account, sign in, confirm a mobile number, or approve a sensitive action. Mobile numbers used for this purpose are entered by the account holder within their own account, for their own use.
Message frequency varies and depends on the User's account activity. Messages are sent only when the User initiates an action that requires verification. Message and data rates may apply.
Mobile phone numbers and SMS consent are not shared with, sold to, rented to, or otherwise disclosed to any third party or affiliate for marketing or promotional purposes. Mobile numbers are disclosed only to our SMS delivery provider, and solely for the purpose of transmitting the passcode. This paragraph applies despite any other provision of this Privacy Policy, including the section headed Information Sharing and Disclosure.
Users may reply STOP to any message to opt out, or HELP for assistance. Because SMS verification is a required security feature of a LAN10 account, opting out prevents passcode delivery until the User opts back in by replying START.
Data Retention and Deletion
In compliance with the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs) and the GDPR, the Data Controller will retain the personal and sensitive data of Users for the minimum period required by the legislation and no longer than is necessary for the purposes for which the data is processed. Personal data may be held for longer periods insofar as the personal data will be processed solely for archiving purposes in the public interest, scientific or historical research purposes, or statistical purposes, in accordance with the GDPR and subject to implementation of the appropriate technical and organisational measures required by the GDPR to safeguard the rights and freedoms of the User.
Upon the expiration of the data retention period, or when a User requests deletion of their personal data in accordance with their rights under the Privacy Act 1988 (Cth), the Data Controller shall ensure that the personal data are erased without undue delay. The Data Controller shall also take reasonable steps to ensure that any third parties to whom the personal data have been disclosed are informed of the erasure request, unless this proves impossible or involves disproportionate effort.
Exceptions to the deletion of personal data may apply where the retention of personal data is necessary for:
- Complying with a legal obligation which requires processing by Australian law to which the Data Controller is subject or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Data Controller;
- The establishment, exercise, or defence of legal claims;
- Archival purposes in the public interest, scientific or historical research purposes, or statistical purposes in accordance with Article 89(1) of the GDPR, in so far as the right to erasure is likely to render impossible or seriously impair the achievement of the objectives of that processing.
Rights of Individuals
In compliance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), Users have the following rights regarding their personal data:
- Right to Access: Users have the right to request access to their personal data held by the Data Controller. The Data Controller shall provide a copy of the personal data in a commonly used electronic format, unless an exception applies.
- Right to Correction: Users have the right to request the correction of their personal data if it is inaccurate, incomplete, or out-of-date.
- Right to Erasure: Users may request the erasure of their personal data under certain conditions, such as when the data is no longer necessary for the purpose for which it was collected.
- Right to Restrict Processing: Users have the right to request a restriction on the processing of their personal data under certain circumstances, such as when the accuracy of the data is contested.
- Right to Data Portability: Users have the right to receive their personal data in a structured, commonly used, and machine-readable format and have the right to transmit those data to another controller without hindrance from the Data Controller.
- Right to Object: Users have the right to object to the processing of their personal data on grounds relating to their particular situation, at any time, to processing of personal data concerning them, including profiling.
- Right to Complain: Users have the right to lodge a complaint with the Australian Information Commissioner if they believe their privacy rights have been violated.
All requests related to the above rights should be made in writing to the Data Controller. The Data Controller will respond to such requests within a reasonable timeframe and in accordance with applicable laws.
Data Security
In compliance with applicable data protection laws and regulations, the Data Controller commits to implementing and maintaining comprehensive data security measures to protect the personal data of Users against unauthorized access, alteration, disclosure, or destruction. These security measures include, but are not limited to, the use of encryption technologies, secure data storage facilities, and regular security assessments conducted by qualified personnel.
The Data Controller will promptly notify Users and relevant regulatory authorities of any data breaches that result in a risk to the rights and freedoms of Users, in accordance with the requirements of applicable laws. The notification will include all necessary information about the nature of the breach, the categories and approximate number of data subjects affected, and the measures taken or proposed to be taken by the Data Controller to address the breach.
Users have the right to inquire about the security measures in place for the protection of their personal data and to request information on any data breaches that may affect them. The Data Controller will provide this information in a timely and transparent manner, as required by law.
International Data Transfers
In compliance with applicable Australian privacy laws, the Data Controller may transfer personal data collected from Users to countries outside of Australia. Such transfers will only occur if necessary for the provision of the services offered by LAN10, and will be conducted in a manner that ensures the protection of the User's personal data.
Before transferring personal data internationally, the Data Controller will:
- Assess the level of data protection offered by the receiving country, ensuring it is adequate and comparable to the protections afforded under Australian law.
- Implement appropriate safeguards to protect the personal data during its transfer and subsequent processing. This may include entering into data transfer agreements or adopting other legal mechanisms recognized by Australian privacy laws.
- Inform Users about the international transfer of their personal data, including details about the countries to which the data is transferred and the safeguards in place to protect their data.
By using the services offered by LAN10, Users consent to the transfer of their personal data under the conditions outlined above. Users have the right to withdraw their consent at any time, subject to legal or contractual restrictions and reasonable notice.
Privacy Impact Assessments
We undertake Privacy Impact Assessments (PIAs) for high-risk processing activities to evaluate and mitigate any potential risks to Users' privacy.
Children's Privacy
Our services are not directed to individuals under the age of 18 without proper parental approval or configurations accessed via LAN10 Vault Admin Access. We do not knowingly collect personal data from children without verifiable parental consent. If we become aware that we have collected data from a child without such consent, we will take steps to delete the information promptly.
Changes to the Privacy Policy
The Data Controller reserves the right to update or modify this Privacy Policy at any time and from time to time without prior notice. Please review this policy periodically, and especially before you provide any personal data. Your continued use of the services offered by the Data Controller after any changes or revisions to this Privacy Policy shall indicate your agreement with the terms of such revised Privacy Policy.
Contact Information
If you have any questions or concerns regarding this Privacy Policy or the handling of your personal information, please contact our Data Controller at our Email: info@lan10.com.au
We are committed to working with you to obtain a fair resolution of any complaint or concern about privacy. If, however, you believe that we have not been able to assist with your complaint or concern, you have the right to make a complaint to the Office of the Australian Information Commissioner (OAIC), or to the relevant supervisory authority in the European Union.