Customer Retention Marketing Australia Pty Ltd

ACN 128 865 378

Privacy Policy

Date:13th August 2026

1. Introduction

Customer Retention Marketing Australia Pty Ltd (ACN 128 865 378) (“CRMA”, “we”, “us” or “our”) is committed to protecting the privacy of personal information we handle to engage in our functions and activities.

 

This Privacy Policy explains how we collect, hold, use and disclose personal information, and how to contact us if you have any queries about the way we manage your personal information. It has been prepared in accordance with the Privacy Act 1988 (Cth) (the “Act”) and the Australian Privacy Principles (“APPs”). This Policy does not apply to how we handle our past or current employee records. We handle those records in accordance with the obligations that apply to those records under other applicable laws.  

 

In handling personal information, we comply with the thirteen Australian Privacy Principles (APPs) in the Act except where the Act does not require this. The APPs regulate how to handle personal information throughout its life cycle, from collection to use and disclosure, storage, accessibility and disposal.

 

Personal information is information or an opinion, in any form and whether true or not, about an identified individual or an individual who is reasonably identifiable.

1. About us

CRMA provides customer retention marketing services to automotive dealerships and dealer groups (“Dealers”). We contact individuals who are existing customers of our Dealer clients, on behalf of those Dealers. We do this to facilitate existing services provided to those existing customers, or to promote new services, offers and campaigns to existing customers. The channels through which we contact these individuals  include email, SMS, telephone and direct mail.

 

CRMA does not generally collect personal information directly from individuals.  We receive personal information from our Dealer clients who have collected it in the course of their own customer relationships. We hold all personal information provided to us by a Dealer for and on behalf of that Dealer to perform our services for that Dealer.

2. Types of personal information we collect and hold

The types of personal information about an individual that we may collect (including from Dealers) and hold include:

Identity and contact information

•         full name, salutation and title

•         residential address (including suburb, state and postcode)

•         email address

•         mobile phone number and other telephone numbers (including landline and work)

Vehicle and service information

•         vehicle identification number (VIN), registration number, engine number

•         vehicle make, model, model year, variant, series, grade, class and type

•         body type, colour, fuel type and odometer reading

•         build/manufacture date, vehicle description, registration expiry and first registration date

•         service history (including service dates, service type, next service due, booking and appointment details, repair order numbers, job cards, adviser/technician details, operation codes, labour hours, service intervals and service reminders)

Warranty and contract information

•         warranty or contract number, start date and expiry date

•         warranty product name and provider

•         warranty cancellation details

•         account or contract numbers

Marketing and communication preferences

•         consent and opt-in status

•         communication channel preferences (e.g. email, SMS, telephone, mail)

•         contact preferences and privacy codes

•         unsubscribe status and reasons

•         campaign, offer and survey information

Other information

•         notes and comments

•         contact and follow-up dates

 

Sensitive information: Special rules apply under the Act (including the APPs) for collecting personal information which is sensitive information. Sensitive information includes health information and information about a person’s race, ethnic origin, political opinions, membership of political, professional or trade associations, religious or philosophical beliefs, sexual orientation or practices and criminal history. We do not generally collect sensitive information. If sensitive information is inadvertently provided to us by a Dealer, we will handle it in accordance with the requirements of the APPs.

3. How personal information is collected

CRMA does not generally collect personal information directly from individuals. The exception is where the individuals are our business contacts (for example, personnel of Dealers with whom we liaise).  

 

We generally receive personal information from our Dealer clients, who collect it in the course of their customer relationships (for example, when a customer purchases a vehicle, has a vehicle serviced, or otherwise interacts with the Dealer).

 

Personal information is typically provided to us by Dealers through:

•         emails;

•         secure data feeds from the dealer management systems (DMS);

•         encrypted file transfers; and

•         secure online portals.

 

In limited circumstances, we may also collect personal information:

•         directly from individuals who contact us (for example, to make a privacy request or complaint);

•         from publicly available sources; or

•         through our website (for example, IP address and device metadata collected via cookies or similar technologies).

 

To the extent required by the Act:

•         we will not collect personal information about you unless that information is reasonably necessary for one or more of our functions or activities; and

•         we will collect personal information only by lawful and fair means.

 

When we collect personal information directly from you, we will take reasonable steps at or before the time of collection (or, if that is not practicable, as soon as practicable after that time) to ensure that you are aware of certain key matters, such as the purposes for which we are collecting the information, the organisations (or types of organisations) to which we would normally disclose information of that kind, the fact that you are able to access the information and how to contact us.

4. Purposes of collection, use and disclosure

We use and disclose personal information for the following purposes:

 

•         providing customer retention marketing services to Dealers, including contacting individuals on behalf of Dealers by email, SMS, telephone or direct mail to promote Dealer services, offers and campaigns;

•         managing marketing campaigns, communications and distribution lists on behalf of Dealers;

•         data analysis and segmentation to assist Dealers in identifying relevant customer audiences;

•         de-identifying personal information and using that de-identified data to generate insights for Dealers as well as CRMA and its related bodies corporate, in relation to current or proposed business operations;

•         maintaining and updating Dealer customer databases;

•         contacting Dealer personnel in relation to any of the above functions;

•         responding to privacy-related requests, enquiries or complaints from individuals;

•         complying with, and assisting Dealers to comply with, applicable laws;

•         managing our internal business operations, including record-keeping, reporting and quality assurance;

•         disclosing personal information to our related bodies corporate for the purposes of those related bodies corporate performing services in their own right, or on our behalf, for the relevant Dealer; and

•         any other purpose related to the provision of our services that the relevant individual or Dealer would reasonably expect.

 

We will not use or disclose personal information for a secondary purpose unless that secondary purpose is related to the primary purpose of collection and the individual would reasonably expect such use or disclosure, or we are otherwise permitted or required to do so by law.

5. Disclosure back to Dealers and to third party suppliers

We may disclose personal information to:

 

•         Dealers: We disclose personal information back to the Dealer that provided it (for example, campaign results, updated contact details or opt-out notifications).

•         Technology and platform providers: We engage third-party service providers to facilitate the transmission, delivery and management of communications on behalf of Dealers. These may include email service platforms, SMS gateway providers, telephony platforms and direct mail service providers.

•         Professional advisers: We may disclose personal information to our legal, accounting and other professional advisers for the purposes of obtaining professional advice.

•         Regulatory bodies and law enforcement: We may disclose personal information where required or authorised by law, including to regulators or law enforcement agencies.

•         Related bodies corporate: We may disclose personal information to any of our related bodies corporate (within the meaning of section 9 of the Corporations Act 2001 (Cth)) for the purposes of performing services to the Dealer who provided us with that personal information or on whose behalf we collected that personal information. Any such related body corporate that receives personal information from us will handle it in accordance with this Privacy Policy and the APPs.

 

We do not sell personal information to any third party. We will not disclose personal information to a third party unless it is reasonably necessary for the provision of our services, or we are otherwise permitted or required to do so by law.

 

All third-party service providers engaged by CRMA are required to be bound by appropriate confidentiality and privacy obligations consistent with the APPs.

6. Cross-border disclosure

Some of the third-party technology providers we engage may store data on, or operate from, servers located outside Australia. Where personal information is disclosed to an overseas recipient, we will take reasonable steps to ensure that the overseas recipient does not breach the APPs in relation to that information. It is not practicable for us to specify where those computer servers are based.

 

This obligation will not apply if:

•         we reasonably believe that the recipient of the information is subject to legal obligations that have the effect of protecting the information in a way that, overall, is at least substantially similar to protection under the APPs and there are mechanisms that you can access to enforce that protection;

•         you give us consent to disclose your personal information to an overseas recipient, expressly or by implication, after you are expressly informed by us that if you consent we will not be required to take reasonable steps to ensure that the overseas recipient does not breach the APPs in relation to the information; or

•         we are legally authorised to do so.

7. Direct marketing and opting out

To the extent only that CRMA sends commercial electronic messages (including emails and SMS messages) or makes telemarketing calls on behalf of Dealers, the Dealers as well as CRMA are required to comply with the Act and other specific laws depending on the channel of communication. 

Opting out

If you do not wish to receive marketing communications from a Dealer for whom we send or make marketing communications, you may opt out at any time by:

•         using the unsubscribe link or facility included in any commercial electronic message you receive;

•         replying “STOP” to any SMS message you receive;

•         advising the maker of a telemarketing call that you revoke your consent to receiving telemarketing calls;

•         advising the relevant Dealer directly that you wish to opt out of marketing communications.

 

Depending on the communication channel and the context of your opt-out, the opt-out will be actioned by us (and we are required to inform the Dealer) or by the Dealer (who is required to inform us).  If you have any concerns about continuing to receive communications after opting out, please contact the Dealer for whom that communication was sent.

8. Data quality and security

We take reasonable steps to ensure that the personal information we hold is accurate, up-to-date, complete and relevant, having regard to the purpose for which it is held.

 

We also take reasonable steps to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure. The measures we take include:

 

•         storing data securely using encryption and access controls;

•         restricting access to personal information to authorised personnel only;

•         maintaining appropriate technical and organisational security measures;

•         ensuring that third-party service providers are bound by appropriate confidentiality and security obligations; and

•         destroying or de-identifying personal information that is no longer needed for any purpose permitted by the Act (including upon written request by the relevant Dealer, except to the extent retention is required for compliance purposes).

9. Access and correction

Under APPs 12 and 13, you have the right to request access to, and correction of, the personal information we hold about you.

 

Because CRMA receives personal information from Dealers (rather than collecting it directly from individuals), we may in some cases direct you to the relevant Dealer to make your access or correction request, as the Dealer is likely to hold a more complete record.

 

If you would like to request access to or correction of personal information we hold about you, please contact us using the details set out in section 15 below. We will respond to your request within a reasonable period (and in any event within 30 days). If we refuse to provide access or make a correction, we will give you written reasons for our decision and information about how you may complain.

10. Complaints

If you have a complaint about how we have handled your personal information, please contact us using the details set out in section 15 below. We will:

 

•         acknowledge your complaint as soon as practicable;

•         investigate your complaint; and

•         provide you with a written response within 30 days of receiving the complaint.

 

If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner:

 

•         Online: www.oaic.gov.au

•         Phone: 1300 363 992

•         Post: GPO Box 5218, Sydney NSW 2001

11. Notifiable data breaches

If there is a loss, or unauthorised access or disclosure of your personal information that is likely to result in serious harm to you, we will investigate and notify you and the Australian Information Commissioner as soon as practicable, in accordance with the Act.

12. Automated decisions

This section of the policy applies if:

•         we have arranged for a computer program to make, or do a thing that is substantially and directly related to making, a decision; and

•         the decision could reasonably be expected to significantly affect the rights or interests of an individual; and

•         personal information about the individual is used in the operation of the computer program to make the decision or do the thing that is substantially and directly related to making the decision.

If the above applies, we will update this policy to include information about:

•         the kinds of personal information used in the operation of such computer programs; and

•         the kinds of such decisions made solely by the operation of such computer programs; and

•         the kinds of such decisions for which a thing, that is substantially and directly related to making the decision, is done by the operation of such computer programs.

13. Website

When you use our website, we may collect information about your web browser, device, and browsing activity through the use of cookies and similar technologies. We use this information for website optimisation purposes only. We do not use this information to identify you. 

14. Changes to this policy

We may update or amend this Privacy Policy from time to time to reflect changes in our practices, technology or legal requirements. The current version of this policy will be published on our website at www.crma.com.au. We encourage you to review this policy periodically.

 

15. Contact us

If you have any questions about this Privacy Policy, or wish to make a privacy request or complaint, you can contact us as follows:

 

Privacy Officer

Customer Retention Marketing Australia Pty Ltd

Suite 920, 401 Docklands Drive

Docklands VIC 3008

 

Phone: (03) 9670 8308

Email: enquiry.form@crma.com.au

Website: www.crma.com.au