EchoTag Privacy Policy

Privacy Policy

LAST UPDATED: 8 September 2026

1. General

1.1 General

  1. This website (emeraldalarms.com.au) and the EchoTag mobile application (App) — which includes the EchoTag diagnostic feature — are owned and operated by K.P.S Australia Pty Ltd (ABN 60 639 243 520) (KPS, we, us or our).

  2. Emerald Alarms is a brand of KPS Australia Pty Ltd. Emerald Alarms Pty Ltd is a wholly owned subsidiary of KPS and is the entity that owns the Emerald Alarms brand, the EchoTag technology and all associated intellectual property. KPS is the entity responsible for the collection, use, storage, and disclosure of personal information under this policy.

  3. Your privacy is important to us and we are committed to protecting your personal information in accordance with the Australian Privacy Principles (APPs) set out in the Privacy Act 1988 (Cth) (Privacy Act).

  4. This policy outlines how and when we collect, use, share and store your personal information and applies to all personal information we collect through:

    1. our website (emeraldalarms.com.au) and the App (together, the Site); and

    2. our products and services, including your Connected Devices, EchoTag and our Cloud Services.

  5. By accessing or using the Site or any of our products or services, you acknowledge that you:

    1. have read and understood this policy; and

    2. agree that your access to, or use of, the Site or any of our products or services indicates your consent to this policy.

If you have any questions about this policy, you can contact us via: Privacy Officer, KPS Australia Pty Ltd (the home of Emerald Alarms) — service@kpsaustralia.com.au

1.2 Interpretation and relationship with Terms of Use

  1. Capitalised terms in this policy that are not defined in this policy have the same meaning given to them in the EchoTag App Terms of Use (Terms of Use), unless the context clearly requires otherwise.

  2. This policy should be read together with the Terms of Use. By using the App, the Site or any of our products or services, you are bound by both documents.

  3. To the extent of any inconsistency between this policy and the Terms of Use on a matter relating to the collection, use, storage, or disclosure of personal information, this policy prevails.

2. What personal information we collect

2.1 Two types of App user

  1. The App has two types of registered user, and the personal information we collect depends on which type of user you are:

  1. Business Partner — a licensed electrician or contractor who registers for their own account in the App in order to perform EchoTag diagnostic checks on Connected Devices at their customers' properties, in the course of their trade or business; and

  2. Home Owner — an individual who registers for their own account in the App in order to perform EchoTag diagnostic checks on Connected Devices at their own property.

See clause 2.3 (Business Partners) and clause 2.4 (Home Owners) below for what we collect for each.

2.2 General types of personal information

  1. Personal information is information or an opinion that relates to an identified individual, or an individual who is reasonably identifiable, whether or not the information is true or recorded in a material form.

  2. Emerald Alarms collects and uses personal information from Business Partners, Home Owners, other authorised users or visitors of the Site, and any other individual who interacts with us.

  3. To register and administer your Account (whether as a Business Partner or a Home Owner), we collect personal information which may include:

  1. your name, date of birth, address, phone number, email address and, for Business Partners, your business name and occupation;

  2. information about the products or services you enquire about, including how they are used;

  3. your shopping or browsing behaviour on the Site;

  4. your user name and password;

  5. Diagnostic Data associated with your Account (see clause 2.5); and

  6. any other information relating to you that you provide to us, including information you provide by email or telephone, or through surveys, competition forms, at special events and other promotional activities.

2.3 Business Partners — personal information

  1. If you register as a Business Partner, we collect your personal information (such as your name, business name, contact details, licence details (if provided) and login credentials) in order to create and administer your Business Partner Account.

  2. When you use EchoTag to perform a diagnostic check on a Connected Device at a property that is not your own, we collect:

  1. the Diagnostic Data generated by that check (see clause 2.5); and

  2. the address of the property at which the check was performed,

  1. but we do not collect the name, contact details or other personal information of that property's owner, occupant or resident as part of the check itself, unless that individual separately registers with us as a Home Owner or otherwise provides their personal information to us directly.

  2. We treat the property address referred to above as personal information and handle it in accordance with this policy, even though on its own it may not identify a specific individual.

  3. You must not use the App or EchoTag to perform a diagnostic check at a property that is not your own unless you are authorised to do so (for example, as a licensed electrician or contractor engaged to carry out that work), and you remain responsible for complying with any obligations you have to the property's owner, occupant or resident in connection with that work.

2.4 Home Owners — personal information

  1. If you register as a Home Owner, we collect your personal information (such as your name, address, contact details and login credentials) in order to create and administer your Home Owner Account.

  2. When you use EchoTag to perform a diagnostic check on a Connected Device at your own property, we collect the resulting Diagnostic Data (see clause 2.5) and associate it with your Home Owner Account and property address.

2.5 Diagnostic Data

  1. Each Connected Device includes a proprietary diagnostic feature (EchoTag), which can be activated at any time using a button on the Connected Device. Where the App is open on your smartphone, the App receives and translates the resulting signal into status information about the Connected Device, such as chamber status and battery life (Diagnostic Data), and uploads it to our Cloud Services (hosted using AWS) for record-keeping.

  2. Diagnostic Data is personal information for the purposes of the Privacy Act and the APPs, and is collected, used, stored, disclosed and destroyed in accordance with this policy. Standard Diagnostic Data (chamber status, battery life, signal strength and similar operational data points) is not health information.

  3. The App only receives and processes Diagnostic Data when EchoTag is activated on a Connected Device and the App is open on the relevant smartphone. EchoTag does not remotely or continuously monitor any property.

2.6 How the App uses your phone's microphone

  1. To receive Diagnostic Data, the App uses your smartphone's microphone to listen for the machine-generated diagnostic tone emitted by a Connected Device when EchoTag is activated.

  2. EchoTag does not capture, use or store your voice, speech, conversations or any other human sound. The App only reads a machine-generated audio tone — it is not a recording device, is not used for biometric identification or voice verification of any kind, and does not otherwise process human speech.

  3. Your smartphone's operating system will ask you to grant microphone permission before the App can receive Diagnostic Data. You can review or withdraw this permission at any time in your device settings, noting that EchoTag, the App and the diagnostic function will not work without it.

2.7 Sensitive information

  1. Emerald Alarms does not seek to collect sensitive information (as defined by the Privacy Act) about you.

  2. However, if you choose to use a Safety Alarm Accessory (such as a strobe light or bed shaker) designed for people who are deaf or hard of hearing, and provide us with information about that use, that information may constitute sensitive information about you or another occupant of the relevant property. We will only collect, use or disclose that information for the purpose of providing, configuring or supporting the relevant accessory, and in accordance with the APPs and any consent you provide.

3. Collection

3.1 Methods of collection

  1. Emerald Alarms collects your personal information in several ways, including:

  1. through your use of our products or services (and our records of these);

  2. when you visit the Site or submit information through the Site, contact us, or complete any forms or documents for our products or services;

  3. when you participate in our surveys, competitions, promotions, questionnaires or other promotional activities;

  4. through your registration as a Business Partner or Home Owner in the App, or for our newsletter;

  5. when you interact with us on our social media, including through comments, posts or private messages;

  6. if you apply for a job opportunity with us;

  7. through the App, including the Diagnostic Data and permissions described in clauses 2.5 and 2.6;

  8. from third parties (which we discuss further in clause 3.3 of this policy); and

  9. from publicly available sources of information.

  1. The personal information we collect will track and enhance your use of the Site or our products or services, and assist us in providing a better service to you.

  2. Emerald Alarms will only collect personal information that is necessary for one or more of our functions or for a purpose outlined in this policy or otherwise disclosed to you.

  3. By providing your personal information to us, you acknowledge that you are authorised to provide such information to us.

3.2 Collection from you

  1. When we collect personal information directly from you, we will take reasonable steps to notify you (using a collection notice) at, before, or as soon as practicable after, the time of collection.

  2. As a collection notice is specific to a particular collection of personal information, it will provide more specific information about our information-handling practices than this policy.

  3. This policy is subject to any specific provisions contained in our collection notices and the terms and conditions of any offers, products and services. We therefore encourage you to read those provisions carefully.

3.3 Collection from an authorised representative

  1. When we collect your personal information from your authorised representative, we will take reasonable steps to make sure you are aware of the collection.

  2. If you provide us with personal information about another individual (as their authorised representative), we rely on you to:

inform them that you are providing their personal information to us; and

advise them that they can contact us for further information.

  1. You must take reasonable steps to ensure the individual is aware of, and consents to, the matters outlined in this policy, including that their personal information is being collected, the purposes for which that information is being collected, the intended recipients of that information, the individual's right to access that information, and who we are and how to contact us.

  2. Upon our request, you must also assist us with any requests by the individual to access or update the personal information you have collected from them and provided to us.

  3. This clause 3.3 does not apply to a Business Partner performing an EchoTag diagnostic check on a Connected Device at a property that is not their own — that scenario, and what is and is not collected about the property's occupant, is instead governed by clause 2.3.

4. How we use your personal information

4.1 Purposes of use and disclosure

  1. Emerald Alarms only uses and discloses your personal information for the purposes for which it is collected.

  2. In particular, we use your personal information to:

  1. provide you with our products or services, or the Site;

  2. enable Business Partners to perform and record EchoTag diagnostic checks at customer properties, and Home Owners to perform and record EchoTag diagnostic checks at their own property, including the diagnostic and safety-alert functions of EchoTag and the App;

  3. improve, develop and manage our products, services and the Site;

  4. operate, maintain, test and upgrade our systems; and

  5. notify you of opportunities we think you might be interested in, including new product or service offerings.

  1. We may also use your personal information:

  1. to customise the advertising and content on our Site;

  2. to provide information that we think may interest or benefit you, including information about the Site, offers, competitions, promotions, events and surveys;

  3. to verify your identity;

  4. to perform research and analysis about our products, services and the Site;

  5. to comply with regulatory or other legal requirements;

  6. for any purpose to which you have consented; and

  7. for any other purpose notified to you at the time of collection.

  1. In the event of a merger, acquisition or sale of the whole or part of our business or assets, we reserve the right to transfer your personal information as part of the transaction, without your consent or notice to you.

4.2 Disclosure to third parties

  1. We may provide your personal information to:

  1. our employees, related entities, business partners, contractors, suppliers and agents from time to time for the purpose of delivering, providing and administering our products, services or Site; and

  2. third party service providers for the purpose of performing functions on our behalf, but those service providers may not process or use such information for any other purpose. Examples of these third-party service providers include, but are not limited to, our Cloud Services provider (currently AWS, or any successor or alternative cloud infrastructure provider we engage from time to time), marketing automation platforms, marketing and analysis organisations, web developers, internet service providers, customer service providers, customer support specialists, research and data analysis firms, external business advisors (including auditors and lawyers) and our insurer,

(collectively, Authorised Affiliates).

  1. When we disclose your personal information to any of our Authorised Affiliates, we will ensure that they undertake to protect your privacy. These Authorised Affiliates are not permitted to use the information for any purpose other than the purpose for which they have been given access without your express consent.

  2. Our Authorised Affiliates may also provide us with personal information collected from you. If you disclose personal information to an Authorised Affiliate, we rely on you to provide the Authorised Affiliate with consent for us to collect, store, use and disclose your personal information.

  3. We may also disclose any personal information we consider necessary to comply with any applicable law, regulation, legal process, governmental request or industry code or standard.

4.3 Overseas disclosure

  1. Diagnostic Data and other personal information collected via the App is stored using our Cloud Services, currently provided by AWS, in [Sydney, Australia (ap-southeast-2) — to be confirmed and stated precisely before publication; see EchoTag_App_AWS_Website_Suggestions.docx, Section 3].

  2. Our Authorised Affiliates may be located in or outside Australia, in [countries to be listed specifically — to be confirmed].

  3. Before we disclose your personal information overseas, we will take reasonable steps to ensure that our overseas Authorised Affiliate:

treats your personal information securely; and

complies with the relevant APPs.

  1. By accessing or using our products, services or Site, or providing your personal information to us, you consent to the transfer of your personal information to our overseas Authorised Affiliates on the terms set out in this clause 4.3.

  2. If you do not wish to receive information from any of our Authorised Affiliates, please contact us.

4.4 Disclaimer

  1. We will not disclose your personal information to any third party (other than our Authorised Affiliates) without your written consent, unless:

  1. we are otherwise required by law;

  2. we are permitted to under this policy; or

  3. such disclosure is, in our opinion, reasonably necessary to protect our rights or property, avoid injury to any person or ensure the proper functioning of the Site.

  1. This policy only covers the use and disclosure of information we collect from you. The use of your personal information by any third party is governed by their privacy policies and is not within our control.

4.5 Automated decision-making

  1. The App generates Diagnostic Data reports based on the signal received from a Connected Device. These reports are produced automatically by the App's decoding process.

  2. The Diagnostic Data reports generated by the App are informational outputs intended to assist users (including Business Partners and compliance companies) in assessing the status of a Connected Device. They do not constitute a compliance certification or professional determination, and any decision made on the basis of a Diagnostic Data report remains the responsibility of the user. We do not use automated processes to make decisions about individuals that have legal or similarly significant effects on them.

5. Storage security

5.1 Protecting your personal information

  1. Emerald Alarms takes reasonable steps in the circumstances to keep your personal information safe. We use a combination of technical, administrative, and physical controls to protect and maintain the security of your personal information, including encryption of Diagnostic Data in transit and at rest. We also use SSL/TLS encryption when transmitting Diagnostic Data and other personal information.

  2. Our officers, employees, agents and third-party contractors are expected to observe the confidentiality of your personal information.

  3. Wherever possible, we procure that Authorised Affiliates who have access to your personal information take reasonable steps to:

  1. protect and maintain the security of your personal information; and

  2. comply with the relevant APPs when accessing and using your personal information.

5.2 No guarantee

  1. The transmission of information via the internet is not completely secure. While we do our best to protect your personal information, we cannot guarantee the security of any personal information transmitted through the Site.

  2. You provide your personal information to us at your own risk and we are not responsible for any unauthorised access to, and disclosure of, your personal information.

5.3 Destruction of personal information

  1. We retain personal information (including Diagnostic Data) for as long as it is needed for the purpose for which is was collected, or as required or permitted by law.Diagnostic Data associated with a Business Partner Account or Home Owner Account is generally retained for a period of 7 years from the date of the relevant EchoTag diagnostic check, after which it will be destroyed or de-identified.

  2. Account information (name, contact details, login credentials) is retained for the duration of your Account and for a reasonable period after Account closure to allow us to respond to any queries or complains, after which it will be destroyed or de-identified.

  3. Where personal information is de-identified, it may be retained and used by us for analytical, testing, and improvement purposes.

5.4 Suspected data security

  1. We have a comprehensive data breach notification policy and response plan (Response Plan), which outlines the steps our personnel are required to take in the event of a data breach. This allows us to identify and deal with a data breach quickly to mitigate any harm that may result.

  2. As part of the Response Plan, we will notify you, and where required, the Office of the Australian Information Commissioner (OAIC), in accordance with the Notifiable Data Breaches scheme under the Privacy Act, as soon as practicable if we:

  1. discover or suspect that your personal information has been lost, accessed by, or disclosed to, any unauthorised person or in any unauthorised manner;

  2. believe that you are likely to suffer serious harm as a result; and

  3. are unable to prevent the likely risk of harm.

  1. If you would like more information about our Response Plan, please contact us.

5.5 Data security for the App, EchoTag and Cloud Services

  1. In addition to our Response Plan, the App, EchoTag, your Connected Devices and our Cloud Services (including AWS) include the following data security measures to protect Diagnostic Data and any other personal information we collect:

  1. encryption of data in transit and at rest;

  2. data masking and access controls;

  3. data erasure and retention controls;

  4. data resilience and backup; and

  5. secure transmission (SSL/TLS) between the App and our Cloud Services.

6. Direct Marketing

  1. Emerald Alarms may use your personal information to send you information, including about our product and service offerings, where you have provided your consent (expressly or impliedly) for us to do so or we are permitted to do so by law.

  2. We may send this information to you via the communication channels specified at the time you provide your consent. These communication channels may include mail, email, SMS telephone, social media or by customising online content and displaying advertising on our Site.

  3. These communications may continue, even after you stop using our products or services.

  4. You can opt out of receiving these communications by:

  1. contacting us; or

  2. using the unsubscribe function in the email or SMS.

7. Links to other sites from our Site

  1. Our Site may contain hyperlinks or banner advertising to or from third-party websites.

  2. We do not endorse any of these third parties, their products or services, or the content on these websites.

  3. These websites are not subject to our privacy standards, policies and procedures. Therefore, we recommend that you make your own enquiries about their privacy practices.

  4. We are in no way responsible for the privacy practices or content of these third-party websites.

8. Cookies

  1. We may collect information when you access and use our Site by utilising features and technologies of your internet browser, including cookies, beacons, tags, scripts and similar technologies. A cookie is a piece of data that enables us to track and target your preferences.

  2. The type of information we collect may include statistical information, details of your operating system, location, your internet protocol (IP) address, the date and time of your visit, the pages you have accessed, the links which you have clicked and the type of browser that you were using.

  3. We may use cookies, beacons, tags, scripts and similar technologies to:

  1. enable us to identify you as a return user and personalise and enhance your experience and use of our Site; and

  2. help us improve our service to you when you access our Site and to ensure that our Site remains easy to use and navigate.

  1. Most browsers are initially set up to accept cookies. However, you can reset your browser to refuse all cookies or warn you before accepting cookies.

  2. If you reject our cookies or similar technologies, you may still use the Site but may only have limited functionality of the Site.

  3. We may also use your IP address to analyse trends, administer the Site and other websites we operate, and track traffic patterns and gather demographic information.

9. Your rights

Subject to certain exceptions, you have the right to:

Your rights What does it mean?
Right to access and correction

• We will use our reasonable endeavours to keep your personal information accurate, up-to-date and complete.

• You have the right to access any personal information we hold about you, subject to some exceptions provided by law.

• You can access, or request that we correct, your personal information by writing to us. We may require proof of identity.

• If we do not allow you to access any part of your personal information, we will tell you why in writing.

• We will not charge you for requesting access to your personal information but may charge you for our reasonable costs in supplying you with access to this information.

Right to object You have the right to object to the collection, use or disclosure of your personal information.
Right to erasure You have the right to request that we erase your information in certain situations. We will consider your request seriously and in accordance with APP 11.2
Complaint to the OAIC If you are not satisfied with our response to a privacy complaint, you have the right to complain to the OAIC. See clause 14 for details.

10. Anonymity

Where possible, we will allow you to interact with us anonymously. In certain circumstances however, we will ask you to provide personal information in situations where it would be impracticable to deal with you anonymously or it is required by law to do so.

11. Consent

  1. You acknowledge and agree that we, our Authorised Affiliates and each of their officers, employees, agents and contractors are permitted to collect, store, use and disclose your personal information in accordance with this policy and the Privacy Act.

  2. Diagnostic Data collected through the App will not be sold to third parties, and will only be shared with Authorised Affiliates in accordance with clause 4.2, or otherwise with your consent or as required by law.

12. Changes to the policy

  1. We may change this policy from time to time at our sole discretion.

  2. Any revised policy will be posted on our Site and effective from the time of posting.

  3. Your continued use of our products, services or the Site following the posting of any revised policy indicates your acceptance of the changes to the policy.

  4. You should regularly check and read the policy.

13. Further information

Further information about Australian privacy law is available from the Office of the Australian Information Commissioner's website at www.oaic.gov.au.

14. Complaint

  1. If you have any issues about this policy or the way we handle your personal information, please contact us using the details in clause 1(e) and provide full details of your complaint and any supporting documentation.

  2. At all times, privacy complaints:

  1. will be treated seriously;

  2. will be dealt with promptly;

  3. will be dealt with in a confidential manner; and

  4. will not affect your existing obligations or your commercial arrangements with us.

  1. Our Privacy Officer will endeavour to:

  1. respond to you within 10 business days; and

  2. investigate and attempt to resolve your concerns within 30 business days or any longer period necessary and notified to you by our Privacy Officer.