Privacy Policy 2026

Privacy Policy 2026

PRIVACY POLICY

This Privacy Policy applies to information, including personal information, collected and used by GB Environmental Trading Pty Ltd t/as Greenbank Environmental (“GBE”).
 

1. Purpose

Greenbank Environmental Trading Pty Ltd ("Greenbank", "we", "our" or "us") is committed to protecting the privacy, confidentiality and security of personal information.

This Privacy Policy explains how Greenbank collects, uses, stores, discloses and protects personal information in accordance with the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs) and other applicable laws.

Greenbank recognises the importance of maintaining the trust and confidence of customers, consumers, contractors, suppliers and other stakeholders.

 

2. Scope

This Policy applies to personal information collected by Greenbank through:

  • websites;
  • email correspondence;
  • telephone communications;
  • mobile applications;
  • customer interactions;
  • products and services;
  • regulatory programs; and
  • business operations.

This Policy does not apply to employee records maintained in relation to current or former employees where exemptions under the Privacy Act 1988 (Cth) apply.

 

3. Information We Collect

Greenbank may collect personal information including:

  • name;
  • company name;
  • address;
  • telephone numbers;
  • email addresses;
  • IP addresses;
  • payment information;
  • customer and transaction records;
  • correspondence and communications;
  • records required for participation in environmental certificate schemes; and
  • information required to satisfy legal and regulatory obligations.

Where required, Greenbank may also collect information from authorised third parties and government agencies.

 

4. How Information Is Collected

Personal information may be collected through:

  • telephone conversations;
  • emails and correspondence;
  • websites and online forms;
  • customer enquiries;
  • mobile applications;
  • social media channels;
  • service providers;
  • regulatory bodies;
  • cookies and analytics tools; and
  • other lawful sources.

 

Greenbank will only collect personal information that is reasonably necessary for the conduct of its business activities.

 

5. Use of Personal Information

Greenbank may use personal information to:

  • provide products and services;
  • administer customer relationships;
  • process claims and transactions;
  • provide support and assistance;
  • comply with regulatory obligations;
  • improve business processes;
  • conduct internal audits;
  • prevent fraud or unlawful activity;
  • manage marketing activities were permitted by law; and
  • comply with legal obligations.

 

Where required by law, consent will be obtained before using personal information for direct marketing purposes.

 

6. Disclosure of Personal Information

Greenbank does not sell personal information.

Personal information may be disclosed to:

  • service providers;
  • payment processors;
  • professional advisers;
  • insurers;
  • auditors;
  • regulators and government agencies;
  • law enforcement agencies; and
  • third parties where disclosure is authorised or required by law.

 

Reasonable steps are taken to ensure third parties appropriately safeguard personal information.

 

7. Third-Party Service Providers

Greenbank may engage third-party service providers to support the delivery of its products and services.

Where third-party providers process personal information on behalf of Greenbank, reasonable steps are taken to ensure:

  • appropriate contractual arrangements are in place;
  • confidentiality obligations are maintained;
  • information is protected against misuse and unauthorised access;
  • personal information is used only for authorised purposes; and
  • applicable privacy and security obligations are met.

Greenbank periodically reviews critical suppliers and cloud service providers.

 

8. Overseas Disclosure

Some information may be processed or stored using cloud-based systems located outside Australia.

Where personal information is disclosed overseas, Greenbank takes reasonable steps to ensure that recipients maintain privacy protections substantially equivalent to those required under Australian law.

 

9. Cookies and Analytics

Greenbank's websites may use cookies and analytics technologies to:

  • improve website functionality;
  • understand website usage;
  • enhance user experience; and
  • support business improvement activities.

Users may configure browser settings to manage or disable cookies, although some website functionality may be affected.

 

10. Information Security

Greenbank is committed to protecting personal information from misuse, interference, loss, unauthorised access, modification or disclosure.

Security measures may include:

  • access controls;
  • password protection;
  • encryption;
  • multi-factor authentication;
  • backups;
  • system monitoring;
  • staff training;
  • secure storage arrangements; and
  • periodic security reviews.

 

11. Data Retention and Disposal

Greenbank retains personal information only for as long as necessary to:

  • provide services;
  • comply with legal obligations;
  • satisfy regulatory requirements;
  • resolve disputes; and
  • enforce contractual arrangements.

Where information is no longer required, it will be securely destroyed, deleted or de-identified where practicable.

 

12. Notifiable Data Breaches

Greenbank maintains procedures for identifying and responding to actual or suspected data breaches.

Where a data breach is likely to result in serious harm, Greenbank will:

  • assess the incident;
  • take reasonable steps to contain the breach;
  • notify affected individuals where required; and
  • notify the Office of the Australian Information Commissioner (OAIC) in accordance with applicable legislation.

 

13. Access and Correction

Individuals may request access to personal information held by Greenbank and may request correction of inaccurate, incomplete or out-of-date information.

Requests should be directed to Greenbank using the contact details provided below.

 

14. Privacy Complaints

Greenbank is committed to resolving privacy complaints fairly and promptly.

Complaints regarding privacy or the handling of personal information may be submitted using the contact details below.

Greenbank will investigate complaints and endeavour to respond within a reasonable period.

 

15. External Review

If an individual is dissatisfied with Greenbank's response, they may contact:

Office of the Australian Information Commissioner (OAIC)

Website: www.oaic.gov.au

Telephone: 1300 363 992

 

16. Contact Details

Privacy Officer

Greenbank Environmental Trading Pty Ltd

PO Box 310
Mt Eliza VIC 3930

Emailinfo@green-bank.com.au

Website: www.green-bank.com.au

 

17. Identity Verification

Greenbank may be required to verify the identity of customers, contractors, installers, authorised representatives and other individuals in connection with the delivery of its products, services and regulatory obligations.

Identity verification may be undertaken using information provided by the individual or, where permitted by law, through authorised third-party verification services or government-issued identification documents.

Greenbank will only collect information reasonably necessary to:

  • verify identity;
  • prevent fraud or identity theft;
  • satisfy legislative and regulatory requirements;
  • administer government energy efficiency schemes; and
  • protect Greenbank, its customers and other stakeholders. 

Identity verification records will be managed in accordance with this Policy and Greenbank's information security requirements.

 

 

 

 

18. Regulatory Scheme Information

As an Accredited Certificate Provider and participant in various government energy efficiency and environmental programs, Greenbank may collect, use and disclose personal information where reasonably necessary to administer regulatory schemes.

This may include information required for:

  • Small-scale Renewable Energy Scheme (SRES);
  • Victorian Energy Upgrades (VEU);
  • Peak Demand Reduction Scheme (PDRS);
  • Battery Energy Storage System (BESS) programs;
  • Certificate creation and validation;
  • compliance audits;
  • regulatory reporting;
  • installer accreditation verification; and
  • other government programs administered from time to time. 

Personal information may be disclosed to regulators, government agencies, auditors and approved service providers where authorised or required by legislation or scheme rules.

 

19. Website Forms and Marketing Communications

Greenbank may collect personal information submitted through:

  • website enquiry forms;
  • quotation requests;
  • rebate applications;
  • customer support requests;
  • event registrations;
  • newsletter subscriptions; and
  • other online services. 

Where permitted by law, Greenbank may use contact information to provide updates regarding products, services, regulatory changes and promotional activities.

Individuals may opt out of receiving marketing communications at any time by using the unsubscribe facility included within electronic communications or by contacting Greenbank directly.

Greenbank will comply with applicable privacy and electronic communications legislation when undertaking direct marketing activities.

 

20. Automated Processing and Decision Support

Greenbank uses information systems and business applications to assist with the administration of customer records, compliance activities and regulatory programs.

These systems may be used to:

  • validate information;
  • identify incomplete or inconsistent records;
  • support compliance reviews;
  • assist claim processing;
  • monitor operational performance; and
  • improve service delivery. 

Where automated processing is used, appropriate oversight and review processes are maintained to ensure decisions affecting individuals are accurate, reasonable and consistent with legislative and regulatory requirements.

 

21. Policy Review 

This Policy may be amended from time to time to reflect changes in legislation, regulatory requirements and business practices.

Version 

Date

Change Description 

Author 

1.0

 

Initial Issue 

Compliance Manager 

Or contact your local Data Privacy Authority.

Strategy and customised solutions for the Renewable Energy Industry.

Call us now

1300 473 362