Privacy notice (Supplier Portal)
Scope
This Privacy notice describes how Hawkesbury Motorcycles ("we", "us") handles personal information collected through the Hawkesbury Motorcycles Supplier Portal ("the Portal").
This notice is specific to the Portal. For the privacy notice covering our customer-facing services, see our main website.
What information we collect
From access requests
- Email address
- Supplier business name
- Reason for access (optional)
- Timestamp, source IP, user-agent
From Portal usage
- Pages visited
- Files downloaded
- Session lifecycle (creation, expiry, sign-out)
- Authentication events (success, failure, expiry)
- Source IP and user-agent on each request
Why we collect this information
| Purpose | Lawful basis |
|---|---|
| Authenticating Portal users and managing access | Legitimate interest; necessary for the supplier relationship |
| Evaluating supplier registrations | Steps necessary to enter into a contract; consent |
| Operational and commercial correspondence | Performance of the supplier contract; consent |
| Security monitoring, fraud prevention and incident response | Legitimate interest in protecting the Portal and its users |
| Audit and compliance | Legal obligation; legitimate interest |
Who has access
Inside Hawkesbury Motorcycles, access is limited to:
- The Supplier Operations team
- The security team (incident-related access only)
- Specific Hawkesbury Motorcycles contacts assigned to your supplier relationship (your buyer, finance contact, etc.)
Outside Hawkesbury Motorcycles, we use:
- Cloudflare for Portal hosting and content delivery (Australia)
- AWS Sydney for database and object storage
- An email-delivery service for transactional emails
- Standard observability tooling for security monitoring
None of these is used to enrich, profile or market to you.
Retention
| Information | Retention |
|---|---|
| Active supplier records | For the duration of the supplier relationship plus 7 years (financial records) |
| Declined registrations | 24 months (so we recognise re-submissions) |
| Access request logs | 12 months minimum |
| Authentication logs | 12 months minimum |
| Page-view and download logs | 12 months minimum |
| Security incident records | 7 years |
Your rights
You have the right to:
- Request access to the personal information we hold about you
- Request correction of inaccurate information
- Request deletion (subject to our retention obligations)
- Withdraw consent for non-essential processing
- Object to processing in certain circumstances
- Lodge a complaint with the OAIC if you believe we have breached the Privacy Act
To exercise any of these rights, contact privacy@hawkesbury.motorcycles.
Security
We protect your information using technical and organisational controls including encryption in transit and at rest, role-based access control, network segmentation, security monitoring and incident response. See Data handling for operational detail.
International transfers
Our primary data residency is Australia. Some operational tooling (transactional email delivery, observability) is provided by overseas vendors with appropriate contractual protections. We do not send your information outside Australia for marketing or analytics purposes.
Children
The Portal is intended for business users. We do not knowingly collect personal information from children.
Cookies
The Portal uses only essential cookies:
- A session cookie to maintain your signed-in state
- A CSRF protection cookie
We do not use analytics, marketing or third-party cookies.
Changes to this notice
This notice may be updated from time to time. Material changes will be notified to your Primary admin at least 14 days before taking effect.
Contact
Privacy enquiries: privacy@hawkesbury.motorcycles