Privacy policy
Effective date: 31 August 2026 Last updated: 31 August 2026
The short version
We are a family-owned Australian business selling hygiene dispensers and consumables, mostly to schools, councils, facility managers and hospitality operators. We take your privacy seriously. Here is what is true in plain language.
- What we collect: your name, contact details, delivery and billing address, payment details, the products you order, the organisation you work for, and your dealings with our team.
- Why we collect it: to send you your order, run your account, quote and invoice, answer your questions, support your warranty, and send you the emails you have signed up to receive.
- Who we share it with: the companies that help us run the shop and deliver your order, our fulfilment and freight partners, and, where you ask us to put you in touch with a distributor in your area, that distributor.
- What we do not do: we do not sell your information. We do not run a clinical service, we do not ask for health information, and we hold no medical records of any kind.
- Your rights: you can ask to see, change, or delete most information we hold about you. Email operations@fortressdispensers.com.au.
- If something goes wrong: tell us first. If we cannot sort it out, you can take it to the OAIC at oaic.gov.au.
The full policy below sits underneath this summary if you want the detail.
Who we are
Fortress Dispensers is owned and run by Australian First Aid Distributions Pty Ltd (ACN 153 377 185, ABN 54 153 377 185), trading as Fortress Dispensers, an Australian owned business based at 205 Murphy Street, East Bendigo VIC 3550. This policy covers the Fortress Dispensers website and the dealings described in it. Our other brands run their own websites with their own privacy policies.
When this policy says "we", "us" or "our", we mean Australian First Aid Distributions Pty Ltd (ACN 153 377 185, ABN 54 153 377 185), trading as Fortress Dispensers. When it says "you", we mean any person whose information we hold or who interacts with our website, our products or our team.
We are bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles. This policy operates on the basis that the Australian Privacy Principles apply to us in full, and we do not rely on any small-business exemption.
You can contact us about anything in this policy at:
- Email: operations@fortressdispensers.com.au
- Phone: 03 5443 2239
- Post: Australian First Aid Distributions Pty Ltd (ACN 153 377 185, ABN 54 153 377 185), trading as Fortress Dispensers, 205 Murphy Street, East Bendigo VIC 3550
Privacy at Fortress sits with a single named role we call the Privacy Contact. That role handles privacy enquiries and complaints, oversees access and correction requests, and leads our response if a data breach is suspected. We are a family business, so we do not carry a dedicated Privacy Officer in the large-corporate sense, but accountability for privacy is held at director level. You reach the Privacy Contact at operations@fortressdispensers.com.au.
What we collect
Different parts of your dealings with us involve different information. At each point where we collect information directly from you, we tell you who is collecting it and why, and this policy fills in the detail. Together, those notices and this policy are how we meet our obligation under Australian Privacy Principle 5. If you do not give us the information we need, such as delivery and contact details, we may not be able to fulfil your order.
When you browse our website without buying:
- Your IP address and approximate location at city or region level, through standard web analytics
- Your browser type, device type and operating system
- The pages you visit, the time you spend on them, and the site you came from
- Cookies and similar technologies that store small text files on your device
When you create an account:
- Your name, email address and phone number
- Your delivery and billing address
- The organisation you are ordering for, where you tell us
- Your account password, stored as a hashed value and never in plain text
When you place an order, online, over the phone or in our Bendigo store:
- The products you have bought, including quantities and variants
- Your delivery instructions and site access notes
- Your order history and invoice records
- Your payment confirmation. We do not see or store your full card number
When you contact our team:
- The content of your message, whether by email, phone, web form or our contact page
- Any photos or attachments you send, for example a photo of a damaged unit
- Records of how we resolved your enquiry, including returns, warranty claims and replacements
When you request a free trial, a quote or a distributor referral:
- Your name, role, organisation, email address and phone number
- The site or facility the enquiry relates to, and what you are looking for
When you register a dispenser under our lifetime warranty:
- Your contact details, the site address, the install date, and which units were installed
When you open a 30-day account:
- The contact person's name and role
- The organisation name, address and ABN
- Account, order-history and any credit-application details
When you sign up for our emails:
- Your email address and name
- Your engagement with the emails, being opens, clicks and unsubscribes
When you apply for a job with us:
- Your name and contact details, your resume, your work history and your references
- Reference or background checks only with your express consent given before the check
We do not collect more than this. We do not collect or hold health information, medical records or clinical notes of any kind, and nothing we sell requires them.
Sensitive information
We do not collect sensitive information as the Privacy Act defines it. We sell hygiene dispensers and consumables to organisations, and an order for a soap dispenser reveals nothing about the person who placed it. If information we did not ask for and do not need reaches us, we assess it and destroy or de-identify it.
Business, school and government account customers
Most of our customers are organisations: schools, councils, facility management companies, industrial sites and hospitality operators. For these accounts we collect the contact person's name and role, the organisation name and address, the ABN where relevant, and account, order-history and any credit-application details.
We use this information to set up and run the account, process and fulfil orders, invoice, and provide account support. Where a contact person has opted in, or would reasonably expect it in a business context, we may send relevant updates, and every message carries an opt-out.
Distributors and referrals
Fortress products are sold direct and through a national distributor network. Where you ask us to put you in touch with a distributor in your area, or where your enquiry is best served by one, we pass your name, contact details, organisation and what you are looking for to that distributor so they can contact you. We do this so your enquiry is handled by the people closest to you.
We tell you when we are doing this. If you would rather deal with us directly, say so and we will keep your enquiry in house. Distributors handle your information under their own privacy obligations, and we require them to use what we pass on only for your enquiry.
Warranty registration
We invite you to register a dispenser when you install it. Registration is not a condition of the warranty, and it exists so a later claim is faster because we already hold the install date and location.
Buying in our Bendigo store
If you buy from us in person at East Bendigo, we collect what we need to complete the sale and give you a receipt. If you ask for an invoice, an account or a delivery, we collect your contact and delivery details as well. Walk-in purchases that need nothing beyond a receipt leave us with no personal information at all.
Why we collect it
We collect your information to supply what you have ordered, to run your account, to answer your questions, to quote and invoice, to support warranty claims and replacements, to improve our products and our site, to send you marketing you have opted in to, and to meet our legal obligations. We do not use it for anything else without telling you.
Who we share it with
We share your information only with parties who help us run our business, and only the information they actually need. We do not sell your information.
Our e-commerce platform. Shopify hosts the store, your account, your orders and the checkout. It is based in Canada with data centres in several jurisdictions including the United States.
Our payment processor. Card payments are processed and tokenised by Shopify Payments, which also provides Shop Pay. We do not see or store your full card number.
Our fulfilment and freight partners. They receive your name, delivery address, phone number, site access notes and order details so they can pick, pack and deliver your order.
Order fulfilment and warehousing are handled within the Australian First Aid Distributions group.
Our distributors. Where a referral applies, as set out in the distributors section above.
Our email and marketing platform, and our analytics providers. We use Klaviyo for email and marketing, Google Analytics 4 for website analytics, and Shopify's own web pixels. We do not currently run advertising pixels from any other platform.
Our operational systems. We use a small set of business systems that may hold personal information while we run the business: our inventory system, our accounting software, our document and email storage, and our team-communications tools. These systems are located in Australia and overseas.
Our developer and freelancers. They may have access to our systems while doing development or support work, which can expose personal information in the course of that work. They are bound by confidentiality.
Our accountants, lawyers and other professional advisers, where they need limited access for advice or compliance work. They are bound by confidentiality.
Government and regulatory bodies, where we are legally required to disclose information.
We require all of these parties to handle your information securely and in line with their own privacy obligations and the Australian Privacy Principles, where applicable. We work to put written data-protection terms in place with the third parties that handle personal information for us. If we add new parties that handle your information, we will update this policy.
Where your information is stored
Some of your information is stored on servers in Australia, and some is stored overseas, mostly the United States and Canada.
Held in Australia: our customer service notes, our internal records, and our fulfilment and freight partner data.
Held overseas: our e-commerce platform data, payment data with our payment processor, email and engagement data, and analytics and advertising data. Where our developer or freelancers work outside Australia, their access to our systems can involve a cross-border disclosure to the countries they are based in.
What this means for you, in plain language. Overseas storage is normal for any business using modern cloud services. Data held overseas may be subject to the laws of that country, which can differ from Australian law. We remain accountable to you under Australian law, through Australian Privacy Principle 8 and section 16C of the Privacy Act, for how overseas recipients handle it, and your rights to access, correct and delete do not change.
How we manage the cross-border risk. Australian Privacy Principle 8 requires us to take reasonable steps to ensure overseas recipients handle your information consistently with the Australian Privacy Principles. We take those steps, including through the data-protection commitments in our service agreements. If a recipient breaches those terms we remain accountable to you under section 16C, and we deal with the breach through our incident-response process.
Cookies, tracking and analytics
When you visit our website we use cookies and similar technologies. Cookies are small text files stored on your device that help the site work and help us understand how you use it.
Strictly necessary cookies keep your cart, your login and your checkout working. The site cannot operate without them.
Analytics cookies collect aggregated and pseudonymous information about how you use the site, such as which pages you visit and where you came from. Marketing cookies remember that you have visited so we can show you relevant Fortress ads on advertising platforms.
You can manage cookies through your browser controls at any time, and you can opt out of Google Analytics through the Google Analytics opt-out browser add-on at tools.google.com/dlpage/gaoptout. If you block cookies, parts of the site may stop working properly.
Marketing communications
We only send you marketing if you have opted in. You can unsubscribe at any time using the link at the bottom of every email, or by emailing operations@fortressdispensers.com.au.
Order-related emails about your orders, deliveries and account changes are sent regardless of marketing opt-in. They are not marketing, they are part of the service you have bought, and you keep receiving them if you unsubscribe from marketing.
Where you are a business contact, we may send relevant updates in a business context, and every message carries an opt-out.
Our email marketing complies with the Spam Act 2003 (Cth): we send it with consent, we identify ourselves, and every message has a working unsubscribe. We do not currently run SMS or telephone marketing. If we add either, we will seek opt-in first and comply with the Spam Act and the Do Not Call Register Act 2006 (Cth).
How we keep your information secure
We take reasonable steps to protect your information from misuse, interference, loss, and unauthorised access, modification or disclosure. Australian privacy law expects both technical and organisational measures, and we maintain both.
Technical measures:
- Encrypted connections across our website and account portal
- Account passwords stored as hashed values, not in plain text
- Payment information handled and tokenised by our payment processor, with no full card details stored by us
- Access controls so information is reachable only by those who need it
- Backups, managed through our hosting and platform providers
Organisational measures:
- Access control on a least-privilege basis, reviewed when team members change roles
- Privacy awareness for team members who handle customer information
- Vendor selection with privacy in mind, and written data-protection terms where we can put them in place
- An incident-response process that engages our Privacy Contact for any suspected unauthorised access, loss or disclosure
- Privacy management as a standing responsibility of our Privacy Contact, reporting to our director
We destroy or de-identify personal information once we no longer need it, subject to legal retention requirements. No system is perfectly secure. If we discover a breach that affects your information, we will notify you and the OAIC in line with the Notifiable Data Breaches scheme.
Notifiable Data Breaches
Under Part IIIC of the Privacy Act we must notify affected individuals and the OAIC if there is unauthorised access to, disclosure of, or loss of personal information we hold, where this is likely to result in serious harm and we have not prevented that harm through remedial action.
If we suspect a breach, we begin assessment promptly, complete it within the 30 days permitted under section 26WH of the Privacy Act, and work to complete it sooner where the facts allow. Our assessment covers who is affected, what information was involved, what harm could result, and what remedial action is possible.
If we determine a breach is eligible, we prepare a statement and notify the OAIC as soon as practicable, then notify affected customers as soon as practicable after that. We do not wait out the 30-day window once we have formed that view. We explain what happened, what information was involved, what we are doing about it, what you can do to protect yourself, and who to contact with questions.
The OAIC's guidance on the scheme is at oaic.gov.au/notifiabledatabreaches.
How long we keep your information
We keep your information only as long as we need it for the purposes in this policy, or as long as the law requires.
| Category | How long we keep it | |---|---| | Active account information | While your account is active | | Account profile data after account closure | 24 months from closure, then deleted | | Order and transaction records, required for tax and consumer law | 7 years from the date of transaction | | Customer service correspondence | 3 years from the last interaction | | Business and government account records | While the account is active, then per tax and consumer-law obligations | | Warranty registration and claim records | For the working life of the registered unit, because the warranty runs with the dispenser | | Marketing email subscription data | While you remain subscribed, plus 30 days after unsubscribe | | Aggregated and pseudonymous analytics data | 26 months | | Backup and archive data | Up to 90 days after live deletion | | Unsuccessful job applicant data | 12 months from the recruitment decision |
Once a retention period ends, the data is deleted or de-identified. Where a legal obligation such as an active dispute or a regulatory request requires us to keep specific information longer, we keep it only as long as that obligation requires.
Your rights and how to exercise them
Under the Privacy Act 1988 and the Australian Privacy Principles, you have the right to:
Access your information. You can ask what we hold about you. The law requires a response within a reasonable period, and our service commitment is 30 days. There is no fee. Email operations@fortressdispensers.com.au with the subject line "Privacy access request".
Correct your information. If something we hold is wrong, tell us and we will fix it. You can also correct most account details yourself from your account page. We take reasonable steps of our own to keep records accurate, including prompting you to confirm delivery details at checkout and processing bounces and unsubscribes.
Request a statement of disagreement. If you think we hold information that is incorrect, out of date, incomplete, irrelevant or misleading, and we do not agree to correct it, you can ask us to attach a statement of your view to the record. This is your right under Australian Privacy Principle 13.
Withdraw consent for marketing. Unsubscribe from any marketing email, or email us to opt out of all marketing.
Request deletion. You can ask us to delete information we hold. We will delete it where we can. Some categories cannot be deleted, such as transaction records we are legally required to retain, and we will explain why we have kept them. Email operations@fortressdispensers.com.au with the subject line "Privacy deletion request".
For all of the above we prefer email so there is a written record. If you would rather call, our number is 03 5443 2239.
Children
Fortress Dispensers sells to organisations and is not aimed at children as users of our website. We do not market to children, we do not knowingly collect information directly from people under 18, and we do not knowingly accept account registrations from people under 18. Our dispensers are installed in places children use, including schools, but the account and the order are made by an adult on the organisation's behalf.
If you become aware that a child has provided us with information without an adult's authorisation, contact operations@fortressdispensers.com.au and we will delete it.
Job applicants
If you apply for a role with us, your application is fully covered by the Privacy Act. The Act's exemption for employee records does not apply to job applicants. We collect your application, resume, work history and references, and tell you why at the point of collection. We carry out reference or background checks only with your express consent given before the check, and we keep unsuccessful applicants' information for the period set out above and then delete it.
How to make a complaint
If you think we have handled your information incorrectly, please tell us first. We would rather fix it than have you escalate. You do not have to tell us first before going to a regulator, and you can go straight to the OAIC if you prefer.
Step 1. Email operations@fortressdispensers.com.au with the subject line "Privacy complaint". Tell us what you think happened, when, and what you would like us to do.
Step 2. We will acknowledge your complaint within 5 business days and respond within 30 days. If we need longer, we will tell you why and keep you updated.
Step 3. If you are not satisfied with our response, you can lodge a complaint with the Office of the Australian Information Commissioner:
- Online: oaic.gov.au/privacy/privacy-complaints
- Phone: 1300 363 992
- Post: GPO Box 5288, Sydney NSW 2001
Changes to this policy
We may update this policy to reflect changes in our practices or our legal obligations. The current version is always the one published on this page, with the effective date at the top. Where a change is significant, we will tell you.
Australian First Aid Distributions Pty Ltd (ACN 153 377 185, ABN 54 153 377 185), trading as Fortress Dispensers.