– Privacy Notice – NR

We at Tabit Technologies Pty Ltd ABN 15 665 107 497 (“Tabit” “us“, “we“, or “our“) recognise and respect the importance of maintaining the privacy of our users, customers and their end users. If not otherwise defined herein, capitalized terms have the meaning given to them in the Terms of Service, available at  Terms of Service (“Terms“). Tabit has previously entered into an agreement with a Restaurant for management of ordering and service through Tabit’s proprietary System. This Privacy Notice describes the types of information we collect from you when use the System and the Services as an Employee of a Restaurant, including as a Managing Employee. This Privacy Notice also explains how we collect, process, transfer, store and disclose the information collected, as well as your ability to control certain uses of the collected information. These processes are established in compliance with the Australian Privacy Principles (“APPs“) contained within the Privacy Act 1988 (Cth) (“Privacy Act“). (“You“) means any adult user of the System and/or Services.

Tabit Technologies Pty Ltd ACN 665 107 497. and Tabit Technologies Ltd. serve as joint data controllers in respect of certain processing activities outlined in this Privacy Notice related to your use of our Services. Please contact us at privacy-au@tabit.cloud for further details regarding our arrangement as joint controllers. The registered office of Tabit Technologies Pty Ltd ACN 665 107 497. is at Level 11, 1 York Street, Sydney NSW 2000, and the registered office of Tabit Technologies Ltd. registered is at Derech HaPardes 31, Rishpon Israel and its registration number is 514759661.

In addition, the applicable Restaurant serves as a separate, independent controller with respect to Personal Information of its Managing Employees and Employees. If you are an Employee whose account is linked to more than one Restaurant, each Restaurant will serve as a separate, independent controller of your Personal Information.

Under the Privacy Act, “Personal Information” is defined as: “Information or an opinion about an identified individual, or an individual who is reasonably identifiable: (a) whether the information or opinion is true or not; and (b) whether the information or opinion is recorded in a material form or not.” This Privacy Notice details which Personal Information is collected by us in connection with provision of the Services.

Personal Information. This Privacy Notice details which Personal Information is collected by us in connection with provision of the System and Services.

Privacy Notice Key Points 

The key points listed below are presented in further detail throughout this Privacy Notice. You can click on the headers in this section in order to find out more information about any topic. These key points do not substitute the full Privacy Notice.

  • Personal Information We Collect, Uses and Legal Basis. We collect certain Personal Information that you provide to us including registration information, payment information, and contact information. We also collect certain Personal Information automatically when you use the App and/or Services. We use your Personal Information for various reasons, including to provide you with the App and/or Services, improve our Services, and to contact you with marketing offers. These processing activities are based on different legal basis including performance of a contract, legitimate interests, and your consent.
  • Sharing the Personal Information We Collect. We share the Personal Information we collect with our service providers and subcontractors who assist us in the operation of the System and process the information on our behalf and under our instructions, as well as with Restaurants, who act as independent separate controllers of the Personal Information.
  • International Transfer. Some of our service providers, subcontractors, business partners who have access to your Personal Information are located in countries other than your own. We will ensure that we have agreements in place with such parties that ensure the same level of privacy and data protection as set forth in this Privacy Notice.
  • Security. We implement measures aimed at protecting your Personal Information, but they do not provide absolute information security. Such measures include physical, electronic, and procedural safeguards (such as secure servers, firewalls, antivirus and SSL encryption), access control, and other internal security policies.
  • Your Rights. Subject to applicable law and in addition to other rights as set forth below, you may have a right to access, update, delete, and/or obtain a copy of the Personal Information we have collected about you. You also have the right to object at any time to processing your Personal Information for certain purposes, including, if relevant, marketing purposes.
  • Data Retention. We retain Personal Information for as long as necessary for the purposes set forth in this Privacy Notice. We consider a number of different factors when determining the appropriate retention periods.
  • Use of Cookies and Similar Technologies. We use cookies and similar technologies to help personalize your experience by helping save your settings and customizations across visits and providing you targeted content and advertisements. You can adjust your settings to determine which cookies are allowed, though this may affect the Services.
  • Children. We do not knowingly collect PersonalData from children under the age of sixteen (16).
  • Communications. We may send you e-mail or other messages about us or our Services. You always have the opportunity to opt-out of receiving future messages.
  • Changes to the Privacy Notice. We may change this Privacy Notice from time to time and shall notify you of such changes by indicating on the Site the Privacy Notice has been amended by publishing an updated Privacy Notice on the Site.
  • Comments and Questions. If you have any comments or questions about this Privacy Notice, or if you wish to exercise your legal rights with respect to your Personal Information, please contact us at privacy-au@tabit.cloud.

Personal Data We Collect, Uses and Legal Basis

Depending on your usage, we collect different types of data and we and any of our third-party sub-contractors and service providers use the data we collect for different purposes, as specified below. We will collect Personal Information only by lawful and fair means and not in an unreasonably intrusive way. It is your voluntary decision whether to provide us with certain Personal Information, but if you refuse to provide such Personal Information we may not be able to register you to the System and/or provide you with the Services or part thereof.

Account Data – When you register to use our System and/or receive related Services as a Managing Employee or, if you are an Employee, when you are registered to use the System by a Managing Employee, we collect Personal Information including your name, email address, phone number. If you wish, you may choose to upload a photo that will be associated with your account. We will also have information regarding the Restaurant(s) for which you work and your position within that/those Restaurant(s), as applicable.

How we use this data: (1) to provide you with the System and Services and to respond to your inquiries and requests and to contact and communicate with you; and (2) to prevent fraud, protect the security of and address any problems with the System. (3) If you are a Managing Employee and have requested that we do so, to provide you with informational newsletters and promotional materials related to the System and Services, including via email. For more information about our direct marketing activities and how you can control your preferences, please see the Direct Marketing section below.

Legal Basis: (1) We process this Personal Information for the purpose of providing the System and Services to you, which is considered performance of a contract with you, including responding to your inquiries and requests and providing customer support. (2) When we process your Personal Information for the purposes of preventing fraud, protecting the security of and/or addressing problems with the System and Services and/or, if you are a Managing Employee, for the purpose of providing you with informational newsletters and promotional materials relating to our Services, such processing is based on our legitimate interests.

Usage Information – When you use the System and Services, we collect information about your use of the System, which may include attendance records, such as the times when you sign in and out and other activities on the System.

How we use this data: We use this data to provide you with the System and Services.

Legal Basis: We process this Personal Information for the purpose of providing the System and Services to you, which is considered performance of a contract with you.

Facial Recognition/Special – Depending on the Restaurant for which you work, it may be possible to use certain facial recognition functionalities on the System and in order to do so, we will collect facial images. This is considered biometric data and may be subject to special protections under the Privacy Act in accordance with provisions relating to Sensitive Personal Information. We will only collect such data if you provide your explicit consent.

How we use this data: We use this Personal Information in order to provide facial recognition functionalities on the Systems and part of the Services we provide to the Restaurants and Employees, such as recognition of Employees for purposes of attendance records.

Legal Basis: We process this Personal Information based on your explicit consent. You may withdraw your consent by updating your preferences within your account or by contacting us at privacy-au@tabit.cloud. If you withdraw your consent by email, we will process your request as soon as reasonably possible, however it may take a few days for us to update our records before any opt out is effective.

Sensitive Data – With the exception of health data provided above, we will endeavour not to collect Sensitive Personal Information (as defined under the relevant Privacy Laws) from you. We ask that you do not send us, or do not disclose, any Sensitive Personal Information (such as information related to racial or ethnic origin, religion or other beliefs, criminal background or trade union membership) on or through the App or otherwise. If, contrary to this request, you do provide any Sensitive Personal Information, in doing so you consent to us collecting and handling that information in accordance with this Privacy Notice.

Automatically Collected Data – When you use the System, we automatically collect information about your mobile device, including your operating system, IP address, device ID, as well as your usage history on the System.

How we use this data: (1) to review usage and operations, including in an aggregated non-specific analytical manner, develop new products or services and improve current content, products, and Services and to improve users’ experiences using the System and Services; (2) to prevent fraud, protect the security of our System and Services, and address any problems with the System and/or Services.

Legal Basis: We process this Personal Information for our legitimate interests to develop our products and Services, review usage, perform analytics, prevent fraud, for our recordkeeping and protection of our legal rights.

Additional Uses

Statistical Information

By analyzing all information we receive, including all information concerning users we may compile statistical information across a variety of platforms and users (“Statistical Information“). Statistical Information helps understand trends and customer needs so that new products and services can be considered and so that existing products and services can be tailored to customer desires. Statistical Information is anonymous and aggregated and we will not link Statistical Information to any Personal Information. We may share such Statistical Information with our partners, without restriction, on commercial terms that we can determine in our sole discretion.

Analytics

We and/or our service providers or subcontractors, use analytics tools (“Tools“), including “Google Analytics” to collect information about the use of the App and/or Services. Such Tools collect information such as how often users visit the App, what pages they visit when they do so, and what other sites and mobile applications they used prior to visiting the App. The Tools may collect certain Personal Data, and may link such Personal Data to specific information stored in our customer database. We use the information we get from the Tools to improve our Services. Google’s ability to use and share information collected by Google Analytics about your visits to this site is restricted by the Google Analytics Terms of Service located at http://www.google.com/analytics/terms/us.html and the Google Privacy Policy located at http://www.google.com/policies/privacy/. Without limiting anything else in this Privacy Notice, we and our service providers or subcontractors may also use de-identified transaction-related data for analytics to provide insights for those service providers, contractors and other contracting parties.

Direct Marketing

As described above, if you are a Managing Employee and have requested that we do so, we may use Personal Information to let you know about our products and Services that we believe will be of interest to you. We may contact you by email, SMS, or through other communication channels. In all cases, we will respect your preferences for how you would like us to manage marketing activity with respect to you. To protect privacy rights and to ensure you have control over how we manage marketing with you:

  • We will take steps to limit direct marketing to a reasonable and proportionate level and only send you communications which we believe may be of interest or relevance to you.
  • You can ask us to stop sending email marketing by following the “unsubscribe” link you will find on all the email marketing messages we send you. Alternatively you can contact us at privacy-au@tabit.cloud.

Legal Uses

We may use your Personal Information as required or permitted by any applicable law, for example, to comply with audit and other legal requirements.

Sharing the Personal Data We Collect

We share your information, including Personal Information, as follows:

Affiliates

We share information, including your Personal Information, with our affiliated companies, Tabit Technologies Inc and Tabit Technologies, Ltd. where this is necessary to provide you with our products and Services, and for the purpose of management of our business.

Service Providers, and Subcontractors

We also disclose information, including Personal Information we collect from and/or about you, to our trusted service providers and subcontractors, who have agreed to confidentiality restrictions and who use such information solely on our behalf in order to: (1) help us provide you with the App and/or Services; (2) aid in their understanding of how users are using our App and/or Services; (3) for the purpose of direct marketing (see above for more details). Without limiting anything else in this Privacy Notice, service providers or subcontractors may also use de-identified transaction-related data for developing, marketing, maintaining and/or improving our and our service providers and subcontractors products and services.

Such service providers and subcontractors provide us with IT and system administration services, payment services, data backup, security, and storage services, data analysis, and help us serve advertisements and provide other marketing services.

Data Controllers

When you use our System and/or Services, we also disclose your Personal Information to the applicable Restaurants, which act as an independent, separate controllers with respect to the collection of your Personal Information.

Business Transfers

Your Personal Information may be disclosed to service providers, potential transactional partners, or other third parties in the context of, or during negotiations of, any merger, sale of company assets or acquisition (including in cases of liquidation) in such case, your Personal Information shall continue being subject to the provisions of this Privacy Notice.

Law Enforcement Related Disclosure

We may share your Personal Information with third parties: (i) if we believe in good faith that disclosure is appropriate to protect our or a third party’s rights, property or safety (including the enforcement of the Terms and this Privacy Notice); (ii) when required by law, regulation subpoena, court order or other law enforcement related issues, agencies and/or authorities; or (iii) as is necessary to comply with any legal and/or regulatory obligation.

International Transfer

We use subcontractors and service providers and have affiliates who are located in countries other than your own, such as the US and Israel, and send them information we receive (including Personal Information) (“Recipients“). We conduct such international transfers for the purposes described above. We will ensure that these third parties will be subject to written agreements ensuring the same level of privacy and data protection as set forth in this Privacy Notice and required by the APPs, including appropriate remedies in the event of the violation of your data protection rights in such third country. When entering into a transaction with us you consent to your personal information being disclosed or transferred to such Recipients and you acknowledge and agree that we have no obligation to take such steps as are reasonable in the circumstances to ensure that the information that is transferred or disclosed to the Recipients will be treated in a manner that is consistent with the APPs. You also agree that insofar as the law allows, we have no liability to you or anyone else for any breach by the Recipient of the APPs.

Whenever we transfer your Personal Information to third parties based outside of the European Economic Area (“EEA“), we ensure a similar degree of protection is afforded to it by ensuring at least one of the following safeguards is implemented:

  • We will only transfer your Personal Information to countries that have been deemed to provide an adequate level of protection for Personal Information by the European Commission.
  • Where we use certain service providers, we may use specific contracts approved by the European Commission which give Personal Information the same protection it has in the EEA.
  • Where we use service providers based in the US, we may transfer Personal Information to them if they have been certified by the EU-US Privacy Shield, which requires them to provide similar protection to Personal Information shared between the EU and the US or any other arrangement which has been approved by the European Commission or other body having jurisdiction to approve such arrangement.

Please contact us at privacy-au@tabit.cloud if you are an EU Individual and would like further information on the specific mechanism used by us when transferring your Personal Information out of the EEA.

Security

We have implemented and maintain appropriate technical and organization security measures, policies and procedures designed to reduce the risk of accidental destruction or loss, or the unauthorized disclosure or access to Personal Information appropriate to the nature of such data. The measures we take include:

Safeguards – The physical, electronic, and procedural safeguards we employ to protect your Personal Information include secure servers and SSL encryption of data.

Access Control – We dedicate efforts for a proper management of system entries and limit access only to authorized personnel on a need to know basis of least privilege rules, review permissions quarterly, and revoke access immediately after employee termination.

Internal Policies – We maintain and regularly review and update our privacy related and information security policies.

Personnel – We require new employees to sign non-disclosure agreements according to applicable law and industry customary practice.

Encryption – We encrypt the data in transit using secure SSL protocols.

Database Backup – Our databases are backed up on a periodic basis for certain data and are verified regularly. Backups are encrypted and stored within the production environment to preserve their confidentiality and integrity, are tested regularly to ensure availability, and are accessible only by authorized personnel.

However, no method of transmission over the Internet or method of electronic storage is 100% secure. Therefore, while we strive to use commercially acceptable means to protect your Personal Information, we cannot guarantee its absolute security. We will not be liable for any unauthorised access, modification or disclosure, or misuse of your Personal Information.

As the security of information depends in part on the security of the computer you use to communicate with us and the security you use to protect user IDs and passwords, please take appropriate measures to protect this information.

Your Rights – How to Access and Limit Our Use of Certain Personal Information

Subject to certain exemptions, and in some cases dependent upon the processing activity we are undertaking, you have certain rights in relation to the Personal Information that we or other controllers hold about you, as detailed below. For any requests to exercise such rights with respect to information held by other controllers, please contact the applicable controller directly. If you wish for us to notify all joint or independent controllers, please specify that request when you contact us in order to exercise any of your rights. We will investigate and attempt to resolve complaints and disputes and make every reasonable effort to honour your wish to exercise your rights as quickly as possible and in any event, within the timescales provided by applicable data protection laws. We reserve the right to ask for reasonable evidence to verify your identity before we provide you with any information and/or comply with any of your requests, as detailed below:

  • Right of Access. You have a right to know what Personal Information we collect about you and, in some cases, to have such Personal Information communicated to you. Subject to applicable law, we may charge you with a fee. Please note that we may not be able to provide you with all the information you request and in such case, we will endeavour to explain to you why.
  • Right to Data Portability. If the processing is based on your consent or performance of a contract with you and processing is being carried out by automated means, you may be entitled to (request that we) provide you or another party with a copy of the Personal Information you provided to us in a structured, commonly-used, and machine-readable format.
  • Right to Correct Personal Data. Subject to the limitations in applicable law, you may request that we update, complete, correct or delete inaccurate, incomplete, or outdated Personal Information.
  • Deletion of Personal Data (“Right to Be Forgotten”). You have a right to request that we delete your Personal Information if either: (i) it is no longer needed for the purpose for which it was collected, (ii) our processing was based on your consent and you have withdrawn your consent, (iii) you have successfully exercised your Right to Object (see below), (iv) processing was unlawful, or (iv) we are required to erase it for compliance with a legal obligation. We cannot restore information once it has been deleted. We may retain certain Personal Information (including following your request to delete) for audit and record-keeping purposes, or as otherwise permitted and/or required under applicable law.
  • Right to Restrict Processing:You can ask us to limit the processing of your Personal Information if either: (i) you have contested its accuracy and wish us to limit processing until this is verified; (ii) the processing is unlawful, but you do not wish us to erase the Personal Information; (iii) it is no longer needed for the purposes for which it was collected, but we still need it to establish, exercise, or defend of a legal claim; (iv) you have exercised your Right to Object (below) and we are in the process of verifying our legitimate grounds for processing. We may continue to use your Personal Information after a restriction request under certain circumstances.
  • Direct Marketing Opt Out. You can change your mind at any time about your election to receive marketing communications from us and/or having your Personal Information processed for direct marketing purposes. If you do, please notify us by contacting us at privacy-au@tabit.cloud. We will process your request as soon as reasonably possible, however it may take a few days for us to update our records before any opt out is effective.
  • Right to Object. You can object to any processing of your Personal Information which has our legitimate interests as its legal basis, if you believe your fundamental rights and freedoms outweigh our legitimate interests. If you raise an objection, we have an opportunity to demonstrate that we have compelling legitimate interests which override your rights and freedoms.
  • Withdrawal of Consent. You may withdraw your consent in connection with any processing of your Personal Information based on a previously granted consent. This will not affect the lawfulness of any processing prior to such withdrawal.
  • Right to Lodge a Complaint with Your Local Supervisory Authority. You may have the right to submit a complaint to the relevant supervisory data protection authority if you have any concerns about how we are processing your Personal Information, though we ask that as a courtesy you please attempt to resolve any issues with us first.

Data Retention

Subject to applicable law, we retain Personal Information as necessary for the purposes set forth above. We may delete information from our systems without notice to you once we deem it is no longer necessary for these purposes. Retention by any of our processors may vary in accordance with the processor’s retention policy.

In some circumstances, we may store your Personal Information for longer periods of time, for instance where we are required to do so in accordance with legal, regulatory, tax, audit, accounting requirements and so that we have an accurate record of your dealings with us in the event of any complaints or challenges, or if we reasonably believe there is a prospect of litigation relating to your Personal Information or dealings. To determine the appropriate retention period, we consider the amount, nature, and sensitivity of the Personal Information, the potential risk of harm from unauthorised use or disclosure of your Personal Information, the purposes for which we process your Personal Information, and whether those purposes can be achieved through other means, as well as applicable legal requirements.

Please contact us at privacy-au@tabit.cloud if you would like details regarding the retention periods for different types of your Personal Information.

Cookies and Similar Technologies

We use cookies and similar technologies, such as local storage, for a number of reasons, including to help personalize your experience. Third parties through which we provide the Services and/or our business partners may be placing and reading cookies on your browser.

What are Cookies?

A cookie is a small piece of text that is sent to a user’s browser or device. The browser provides this piece of text to the device of the originating user when this user returns.

  • A “session cookie” is temporary and will remain on your device until you leave the App.
  • A “persistent” cookie may be used to help save your settings and customizations across visits. It will remain on your device until you delete it.
  • First-party cookies are placed by us, while third-party cookies may be placed by a third party. We use both first- and third-party cookies.
  • We may use the terms “cookies” to refer to all technologies that we may use to store data in your browser or device or that collect information or help us identify you in the manner described above, such as local storage.

How We Use Cookies

We use cookies and similar technologies for a number of reasons, as specified below.

The specific names and types of the cookies, web beacons, and other similar technologies we use may change from time to time. However, the cookies we use generally fall into one of the following categories:

Type of Cookie

Why We Use These Cookies

Necessary

These cookies are necessary in order to allow the System to work correctly. They enable you to access the System, move around, and access different services, features, and tools. Examples include remembering previous actions (e.g. entered text) when navigating back to a page in the same session. These cookies cannot be disabled.

Functionality

These cookies remember your settings and preferences and the choices you make (such as language or regional preferences) in order to help us personalize your experience and offer you enhanced functionality and content.

Performance

These cookies can help us collect information to help us understand how you use our System, for example whether you have viewed messages or specific pages and how long you spent on each page. This helps us improve the performance of our System.

Analytics

These cookies collect information regarding your activity on our App to help us learn more about which features are popular with our users and how our App can be improved.

How to Adjust Your Preferences

Most Web browsers are initially configured to accept cookies, but you can change this setting so your browser either refuses all cookies or informs you when a cookie is being sent. In addition, you are free to delete any existing cookies at any time. Please note that some features of the Services may not function properly when cookies are disabled or removed. For example, if you delete cookies that store your account information or preferences, you will be required to input these each time you visit.

By changing your device settings, you can prevent your device’s ad identifier being used for interest-based advertising, or you can reset your device’s ad identifier. Typically, you can find the ad identifier settings under “privacy” or “ads” in your device’s settings, although settings may vary from device to device. Adjusting your preferences as described in this section herein does not mean you will no longer receive advertisements, it only means the advertisements that you do see will be less relevant to your interests.

Third Party Cookies

  • Google Analytics

Communications

We reserve the right to send you service-related communications, including service announcements and administrative messages, without offering you the opportunity to opt out of receiving them. Should you not wish to receive such communications, you may terminate your account.

Children

We do not knowingly collect Personal Information from children under the age of sixteen (16). In the event that you become aware that an individual under the age of sixteen (16) has enrolled without parental permission, please advise us immediately.

Changes to the Privacy Notice

We may update this Privacy Notice from time to time to keep it up to date with legal requirements and the way we operate our business, and we will place any updates on this webpage Please come back to this page every now and then to make sure you are familiar with the latest version. If we make fundamental changes to this Privacy Notice, we will seek to inform you by notice on our App or per email.

Comments and Questions

If you have any comments or questions about this Privacy Notice or if you wish to exercise any of your legal rights as set out herein, please contact us at privacy-au@tabit.cloud.

Last updated: 

27/04/2025

Revision:

5