This Privacy Policy explains how Australian Health & Nutrition Association Limited trading as Sanitarium Health Food Company and its related entities (‘Sanitarium’, ‘we’, ‘us’ or ‘our’), collects, uses, holds and discloses personal information. This policy applies to personal information we collect in connection with our business activities, including our dealings with employees, job applicants, customers, consumers, business partners and suppliers, and through our websites and digital platforms. We manage personal information in accordance with the Privacy Act 1988 (Cth), the Australian Privacy Principles, and other applicable privacy laws.
We collect personal information in a range of ways, depending on how you interact with us. This includes:
We only collect personal information where it is reasonably necessary for our functions and activities and as permitted by law. We only collect health and other sensitive information with your consent or where otherwise permitted by law.
If we collect personal information about you indirectly (that is, from someone other than you), we will take reasonable steps, as soon as reasonably practicable, to make you aware of that collection unless an exception applies under applicable law. This will include, where required, telling you that we have collected the information, why we collected it, who we may disclose it to, our contact details, any law that authorises or requires the collection, and how you can access or request correction of your information.
The table below provides further detail about the types of information we collect, how we collect it, and why.
Type of personal information | Examples | How we collect this information | Why we collect this information |
Contact details |
|
|
|
Identity Information |
|
|
|
Social media/ profile information |
|
|
|
Customer and consumer information |
|
|
|
Website, digital activity and analytics information |
|
|
|
Marketing and communications information |
|
|
|
Business Representatives |
|
|
|
Recruitment and employment-related information |
|
|
|
Employment and workplace information |
|
|
|
Health, safety and wellbeing information |
|
|
|
Other sensitive information |
|
| We only collect information about religious beliefs where it is reasonably necessary for our functions and activities, with your consent or otherwise as permitted by law, including:
|
Payment and financial information |
|
|
|
Account login and credential information |
|
|
|
Customer insights, interactions and content | Demographic and preference information
Customer communications and interactions
Consumer-generated content
|
|
|
Fraud, security and identity verification information |
|
|
|
Information relating to corporate transactions |
|
|
|
We may disclose personal information to third parties who support our business activities or where required or permitted by law. This may include:
Some of these recipients may be located outside Australia, including in jurisdictions where our service providers operate.
We take reasonable steps to ensure that third parties handle personal information in accordance with applicable privacy laws.
Where we collect personal information about you indirectly, we will take reasonable steps to notify you of that collection and these disclosures in accordance with applicable law.
The table above provides further detail about the types of personal information we disclose and the purposes for which it is disclosed.
We may disclose personal information to overseas recipients where this is reasonably necessary for our functions and activities. This may include disclosure to:
These recipients may be located in countries where our service providers and, in some cases, our related entities or affiliates (where applicable), operate, including:
It is not always practicable to specify the exact location of every service provider we use from time to time.
Where we disclose personal information to overseas recipients, we take reasonable steps to ensure that those recipients handle personal information in accordance with applicable privacy laws.
Where we collect personal information about you indirectly, we will take reasonable steps to notify you of these disclosures in accordance with applicable law.
We may use your personal information to send you marketing communications about our products, services or activities.
You can opt out of receiving marketing communications from us at any time by:
We will take reasonable steps to give effect to your request as soon as practicable.
We take reasonable steps to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure. These steps include:
We hold personal information to support our business operations, including maintaining records, managing relationships, complying with legal and regulatory requirements, and as otherwise described in this policy.
We may store personal information in electronic systems (including cloud-based systems) and, in some cases, in paper records. These systems may be operated by us or by third-party service providers that store and process personal information on our behalf.
Our systems and service providers may be located in Australia and overseas, including in countries referred to in the “Disclosure of personal information overseas” section of this policy.
While we take reasonable steps to protect personal information, no method of transmission over the internet or electronic storage is completely secure.
We retain personal information only for as long as it is reasonably necessary for our business activities or as required by law.
The length of time we keep personal information will depend on the purpose for which it was collected, including:
When personal information is no longer required, we take reasonable steps to:
We use cookies and similar technologies on our websites and digital platforms to collect information about how you use them. Cookies are small text files that are stored on your device when you visit a website. We use cookies and similar technologies to:
This may include information such as your IP address, browser type, the pages you visit and the time and duration of your visit. We may also use third-party service providers to assist us with these activities, including providers of:
These providers may collect or receive information about your interactions with our websites and online content. You can manage or disable cookies through your browser settings. If you choose to disable cookies, some parts of our websites or services may not function properly.
Our websites may contain links to third-party websites.
If you follow these links, you leave our website. We are not responsible for the privacy practices of those websites and encourage you to review their privacy policies.
You have the right to request access to the personal information we hold about you and to request that it be corrected if it is inaccurate, out of date, incomplete, irrelevant or misleading. To request access to, or correction of, your personal information, please contact us:
Attention: Privacy Officer
Email: privacy@sanitarium.com.au (please use the subject line “Privacy”)
Telephone: 1800 673 392
Postal address: 1 Sanitarium Drive, Berkeley Vale NSW Australia 2261
Please include:
We will:
In some circumstances, we may refuse access or correction requests where permitted by law. If this happens, we will provide you with our reasons (unless we are not required to do so) and information about how you can make a complaint.
Where it is lawful and practicable to do so, you may choose not to identify yourself or to use a pseudonym when dealing with us.
In many cases, we may need to collect personal information to provide our services, manage employment or workplace matters, or comply with legal obligations.
If you believe that we have not complied with applicable privacy laws (including the Australian Privacy Principles) or a registered binding privacy code, you can make a complaint by contacting us using the details set out above. Please include:
We take privacy complaints seriously and will respond in a timely manner. When we receive a complaint, we will:
We will aim to respond to you within 30 days of receiving your complaint.
If your complaint relates to our service providers or third parties, we may need to consult with them as part of our investigation.
If you are not satisfied with our response, you may contact an external dispute resolution body (if available) or the relevant privacy regulator, the Office of the Australian Information Commissioner (https://www.oaic.gov.au/).
We may update this Privacy Policy from time to time. The updated version will be available on our website. We encourage you to review this policy periodically.
Last updated: June 2026