Privacy Policy

Introduction

In this policy, Leasexpress, we, our or us refers to Lease Express Pty Ltd ACN 098 169 665, trading as Leasexpress and Xpress Salary Packaging.

Personal Information is any information about you where your identity is apparent, or can reasonably be ascertained, and may include Sensitive Information (defined below).

Sensitive Information is information or an opinion about a person’s racial or ethnic origin, political opinions, membership of a political association, religious beliefs or affiliations, philosophical beliefs, sexual preferences, health or medical information or criminal records.

What this Policy is about

This Policy explains the key measures we have taken to implement the requirements of the Privacy Act 1988 (Act), the Australian Privacy Principles and where applicable, other data protection laws such as the European Union General Data Protection Regulations (GDPR). This Privacy Policy outlines the Personal Information collection practices utilised by Leasexpress, how that information is collected, used and disclosed and your rights in relation to your Personal Information.

This Policy covers Personal Information collected directly from individuals, but also Personal Information which may be provided by your where Leasexpress manages a corporate fleet on behalf of your employer (Employer).

We endorse fair information handling practices and uses of information in compliance with our obligations under the privacy laws in force in Australia from time to time. Any information provided, including identification of individuals, will be used only for the purpose(s) intended and where the intention includes confidentiality, information will be treated as such unless otherwise required by law.

This Policy represents the default position that Leasexpress will take in its treatment of Personal Information. Leasexpress will treat all Personal Information in a manner consistent with this Policy unless you have provided your express consent otherwise.

If there is any inconsistency between the Act and this Policy, this Policy shall be read and interpreted to comply with the Act.

Other Policies and Terms and Conditions

Your use of our website is also subject to our Terms and Conditions. The Terms and Conditions for your use of our Website may be found here: Leasexpress Terms ›

Leasexpress also collects, holds and uses credit information about you in accordance with Part IIIA of the Privacy Act 1988 (Cth) and the Privacy (Credit Reporting) Code 2014 (Cth). Our Credit Reporting Policy explains how Leasexpress manages your credit information and may be found here: Credit Reporting Policy ›

Collection of Personal Information

Leasexpress collects the following Personal Information:

Personal Information and Sensitive Information will be typically collected when provided directly to Leasexpress by you:

Our Website automatically collects anonymous usage data about visitors, including the URL that the visitor came from, the browser being used and the IP address. This data is utilised to improve the services of Leasexpress and does not include any personally identifying information.

Leasexpress also reserves the right to collect anonymous usage data through other websites and online systems in order to provide its customers with a better user experience. This data does not include any personally identifying information.

'Cookies' are alphanumeric identifiers that are stored by the web browser on a computer's hard-drive that enable our system to recognise a visitor to our Website. This helps Leasexpress to track basic visitor information for the purposes of optimising the design of our systems and marketing activities.

Most web browsers automatically accept cookies and this function can be disabled by changing the browser settings of the user.

Please note that the Website contains links to other websites which are not hosted or operated by Leasexpress. Leasexpress is not responsible for the privacy policies of such other websites and you should independently review the privacy policies on such websites.

Use of Personal Information

Leasexpress uses Personal Information in the following ways:

We may also use Personal Information we collect for related purposes such as:

We do not pass on any Personal Information to a third party except in accordance with this Policy.

As a user of Leasexpress's products or services, you may occasionally receive email, promotional material or other updates from us about new information, briefings or products or services being offered by Leasexpress or any of its related companies or business partners, along with newsletters and any noteworthy changes to the Website. You may always unsubscribe and opt out from receiving these promotional/marketing update messages.

Disclosure of Personal Information

Other than disclosure to service providers (explained below) or as required by law (for example, disclosure to various Government departments or to Courts), our policy is that we do not give Personal Information to other organisations unless we have disclosed the use in this Policy or you have expressly consented for us to do so.

Upon the collection of Personal Information by us, we will request that you provide consent for us to disclose Personal Information to your immediate family, including children (above the age of 18) or spouse. Where you give this consent, you will be required to provide us with the full names of such immediate family members. Such information will be treated in accordance with this Policy.

In the event that we must discuss your Personal Information with you or have your consent to disclose Personal Information to an immediate family member, we will require a minimum of 3 data points (for example, Name, Car Registration, Driver’s birth date) from you or your family member to ensure any disclosure of Personal Information is in accordance with this Policy and only to those in respect you have provided consent.

Leasexpress uses specific systems to collect and store data, including Catch-e and Macquarie Group. All data stored using these specific providers is governed by each provider’s privacy policy, the Privacy Act, GDPR and any other relevant law.

The parties we may share Personal Information with are employees, subcontractors, suppliers and affiliates of Leasexpress on a need to know basis to allow the provision of services to you as requested by you. Access to Personal Information by these people is subject to such people protecting your Personal Information to at least the degree set out in this Policy, and such access will be revoked within a reasonable timeframe of access no longer being required.

Occasionally, Leasexpress might also use Personal Information for other purposes or share Personal Information with another organisation because:

When we share information with other organisations and service providers as set out above, we do so in accordance with this Policy. To the extent that these organisations and service providers gain access to Personal Information, their use is governed by their own privacy policies, the Privacy Act, GDPR and any other relevant law.

Confidentiality and Data Security

All Personal Information collected is stored on secure Australian and offshore servers.

We take all reasonable steps to manage data stored on our servers to ensure data security and to prevent the loss, misuse or alteration of Personal Information. Notwithstanding the above, Leasexpress is not responsible for any third-party access to Personal Information as a result of:

Leasexpress is also not responsible for any losses, expenses, damages and costs, including legal fees, resulting from such third-party access.

If we have reasonable grounds to believe that your Personal Information that we hold may be subject to unauthorised access or disclosure (eligible data breach), we will investigate and assess the suspected eligible data breach to determine whether the eligible data breach is likely to result in serious harm to you (Notifiable Data Breach). If a Notifiable Data Breach occurs, then we will notify you and the Australian Information Commissioner as soon as practicable after we become aware of the Notifiable Data Breach in accordance with our obligations under the Act. We will comply in every way with our obligations under Part IIIC – “notification of eligible data breaches” of the Act.

Retention and Disposal of Personal Information

We will retain Personal Information for as long as is required for us to fulfil the purposes for which the Personal Information was collected, including where applicable to provide you with our services and to comply with legal requirements.

If we no longer require Personal Information for any purpose, including legal purposes, we will take reasonable steps to securely destroy or permanently de-identify the Personal Information.

Personal Information is backed up frequently and tested regularly in line with Leasexpress’s standard backup procedures. Personal Information that has been deleted may therefore persist within backups for a period of time after which it falls outside the backup rotation.

Access to Personal Information

You can access the Personal Information held about you at any time by contacting our Privacy Officer.

We will always endeavour to meet requests for access. However, in some circumstances we may decline a request for access. This includes the following circumstances:

If we decline a request for access, we will provide reasons for our decision when we respond to the request.

We reserve the right to charge you a reasonable fee for access to your Personal Information. These charges will be limited to the cost of recouping our expenses for providing you with your Personal Information, such as document retrieval, photocopying, labour and delivery.

Despite anything contained in this Policy to the contrary, if the Freedom of Information Act 1982 applies to a person on whose behalf we hold Personal Information, the access and correction requirements in the Act operate alongside and do not replace other informal or legal procedures by which an individual can be provided access to, or correction of, their Personal Information.

Changing or deleting Personal Information
Contact Information and Changes to Privacy Policy

If you have any further queries relating to Leasexpress’s Privacy Policy, please contact our Privacy Officer. If Leasexpress becomes aware of any ongoing concerns or problems with your Personal Information, we will take these issues seriously and work to address these concerns.

If you have a complaint in relation to the way your Personal Information has been handled by Leasexpress, the complaint should be made in writing to our Privacy Officer in the first instance. Leasexpress will investigate the complaint and prepare a response to you in writing within a reasonable period of time.

Our Privacy Officer can be contacted by:
Phone: (03) 9670 4840
Email: privacy@leasexpress.com.au

From time to time, our policies will be reviewed and may be revised. Leasexpress reserves the right to change this Policy at any time.

This Privacy Policy was last updated in November 2019.


Credit Reporting Policy

Overview

Leasexpress, a trading name of Lease Express Pty Ltd ACN 098 169 665, collects, holds and uses credit information about you in accordance with Part IIIA of the Privacy Act 1988 (Cth) (Act) and the Privacy (Credit Reporting) Code 2014 (Cth) (Code).

This Credit Reporting Policy explains how Leasexpress manages your credit information and is to be read in conjunction with Leasexpress' Privacy Policy (Privacy Policy).

What is credit information?

Pursuant to the Act and the Code, credit information includes any of the following information:

identification information about you;

What information does Leasexpress collect and how this information is collected

Leasexpress collects credit information that you provide directly to Leasexpress through the methods set out in our Privacy Policy.

How does Leasexpress hold this credit information?

Once collected, Leasexpress holds credit information in accordance with the Act and the Code. To protect the credit information held by Leasexpress, it is stored on secure servers in Australia.

Leasexpress takes all reasonable steps to manage data stored on these servers to ensure data security and to prevent loss, misuse, or alteration.

How does Leasexpress use this credit information?

Leasexpress will only disclose your credit information in accordance with our Privacy Policy.

Leasexpress uses your credit information to provide that information to financiers as part of submitting credit applications for approval of your financial arrangements.

Leasexpress does not pass on any credit information to a third party for the purposes of direct marketing.

Access to credit information

You may request access to your credit information (Access Request). To make an Access Request, please contact Leasexpress using the contact details at the bottom of this Credit Reporting Policy.

If you make an Access Request, Leasexpress will provide you with access to your credit information unless the access falls within a relevant exception under the Act.

In order to provide you with access to your credit information, you will need to provide sufficient identifying information to Leasexpress as Leasexpress must be able to verify your identity and protect the security of the information.

Leasexpress will respond to your Access Request no more than 10 days after it has been made.

Generally, Leasexpress will not charge you for access to your credit information. However, in some circumstances, Leasexpress may charge a reasonable administrative fee to cover the costs of granting access to your credit information.

Your right to request a correction to the credit information Leasexpress holds about you

If you believe that the credit information that Leasexpress holds about you is inaccurate, out-of-date, incomplete, irrelevant or misleading, you may request a correction to that information (Correction Request). To make a Correction Request, please contact Leasexpress using the contact details at the bottom of this Credit Reporting Policy.

If you make a Correction Request, Leasexpress will respond to your request within 30 days (or such longer period as you may agree).

If Leasexpress is satisfied that the information is inaccurate, out-of-date, incomplete, irrelevant or misleading, Leasexpress will correct that information and inform you and each credit provider or credit reporting body to which Leasexpress has previously disclosed that information that your credit information has been corrected, unless it is impracticable or unlawful to do so.

Victim of fraud

If you believe on reasonable grounds that you have been or are likely to be a victim of fraud, you may request that Leasexpress commence a 21 day ban period in which Leasexpress will refrain from using or disclosing your credit information without your express written consent.

Complaints

If you wish to make a complaint about the way Leasexpress manages your credit information, please contact Leasexpress using the contact details at the bottom of this Credit Reporting Policy.

Leasexpress will acknowledge your complaint in writing within 7 days of the complaint being made and set out how Leasexpress will deal with your complaint. Your compliant will then be investigated. In investigating your complaint, it may be necessary for Leasexpress to consult with other credit reporting bodies or credit providers to which Leasexpress has already disclosed your credit information.

A decision will be made in relation to your complaint and you will be provided written notice of the decision within 30 days of the complaint being made (or such longer period as you may agree).

Contact

Our Privacy Officer can be contacted by:
Phone: (03) 9670 4840
Email: privacy@leasexpress.com.au

Changes to Credit Reporting Policy

From time to time, our policies will be reviewed and may be revised. Leasexpress reserves the right to change this Credit Reporting Policy at any time.

This Credit Reporting Policy was last updated in February 2024..