Your privacy choices
Hummingbird Intercoms Pty Ltd (ABN 75 651 091 057; ACN 651 091 057) operates Humi and uses the Humi Networks brand. This page explains how to make a privacy or personal-data request concerning the Humi App, website, portals, support service or a Humi payment or remittance service.
These choices do not limit any right available under the Privacy Act 1988 (Cth), the Australian Privacy Principles or another applicable law. Our Privacy Policy explains our overall handling practices.
1. Requests you can make
You can ask Humi to:
- confirm whether we hold personal information about you and describe the main categories;
- give you access to personal information we hold about you;
- correct information that is inaccurate, out of date, incomplete, irrelevant or misleading;
- delete or irreversibly de-identify information that is no longer needed and is not subject to a lawful retention requirement;
- close your Humi account and process account-associated data under our Account and Data Deletion procedure;
- withdraw an optional consent or unsubscribe from optional marketing;
- ask how information was collected, used, disclosed or handled overseas;
- raise a privacy concern or ask us to review a privacy decision; or
- request a copy of a current or archived privacy notice that applies to you.
Australia does not provide an unlimited right to erase every record. Identity, AML/CTF, transaction, recipient, security, audit, complaint and legal records may need to be kept even after an account is closed. We will explain any applicable limit rather than treating a deletion request as ignored.
2. How to submit a request
The fastest method is the Humi Support Centre privacy form. The form produces a reference number immediately. You can also contact:
- Privacy, access, correction and complaints: compliance@humi.au
- Account closure and deletion: account@humi.au
- General assistance: support@humi.au
- Post: Hummingbird Intercoms Pty Ltd, 25 Lime Street, Sydney NSW 2000, Australia
To help us locate the correct record, provide your name, the email address associated with Humi, the type of request, the information or period concerned and the outcome you seek. Include a transfer or existing ticket reference if relevant, but do not put a full bank-account number, identity-document number, password, one-time code, transaction PIN or identity-document image in the form or an unrequested email.
3. Identity and authority checks
We must protect personal information from unauthorised access and alteration. Before releasing, correcting or deleting account-specific information, we may verify control of the registered email or App account and ask questions that a person with legitimate authority should be able to answer. If higher-risk evidence is needed, we will provide an approved channel and explain why it is necessary.
An authorised representative may make a request for you. We may ask for written authority, evidence of the representative’s identity and, where practicable, confirmation directly from you. A parent, guardian, attorney, executor or other legal representative may need to provide evidence of their authority. We will minimise the evidence retained after the authority check.
4. What happens next
- Reference and acknowledgement. An online submission creates a ticket reference immediately. We aim to acknowledge an ordinary email, postal or referred request within one business day.
- Scope check. We confirm the request, relevant account or service, date range and preferred response format.
- Verification. We perform a proportionate identity or authority check before exposing or changing information.
- Search and review. We search relevant systems and review results for another person’s privacy, legal privilege, security and mandatory-retention restrictions.
- Response. We provide access or make the correction or deletion, or explain what we cannot do and why.
- Follow-through. Where appropriate, we notify a relevant service provider or transaction participant of a correction or deletion instruction and record completion.
We respond within a reasonable period and generally aim to complete an ordinary verified request within 30 calendar days. A complex request, a large volume of records, information involving other people, an active investigation or a need to obtain archived records may take longer. If so, we will explain the reason and expected next step.
5. Access requests
Access may be provided through a secure electronic copy, a summary, an opportunity to inspect the record, or another method that reasonably meets your needs and protects others. Tell us if you need an accessible format or language assistance.
We ordinarily do not charge for making an access request. If the law permits a reasonable charge for giving access, for example because a request requires substantial retrieval or preparation, we will explain the amount and basis before proceeding. We will not charge for correcting our records.
We may need to redact information about another person, confidential security controls, legally privileged material or information whose disclosure would be unlawful or likely to prejudice fraud prevention or an investigation. Where reasonable, we will provide the remaining information or a useful explanation instead of refusing the entire request.
6. Correction requests
Tell us what is incorrect, why it is incorrect and what the correct information should be. Supporting evidence may be helpful for a legal name, date of birth, address, identity record, recipient detail or transaction annotation, but we will request it through a suitable channel.
If we correct information that was previously disclosed, we will take reasonable steps to notify relevant recipients where required or appropriate. If we do not agree that a correction should be made, we will explain why and, where the law requires or permits, associate a statement of your position with the record.
Some transaction records must remain an accurate historical record and cannot simply be overwritten. In that case, we may preserve the original entry and add a correction, explanation or linked adjustment.
7. Deletion and account closure
For full account closure, use the in-App Account closure control or the public Account deletion form. You can make the web request without reinstalling Humi. The Account and Data Deletion page explains verification, session revocation, open-transfer review, expected timing and retained records.
For deletion of a particular item rather than the whole account, describe that item in a privacy request. We will delete or de-identify it where it is no longer needed and no law, investigation, security purpose, dispute or legal hold requires retention. Many KYC, AML/CTF and transaction records are generally retained for seven years, with the starting event determined by the record type and applicable law.
8. Consent and communications choices
You can withdraw an optional consent by contacting compliance@humi.au. Withdrawal does not make earlier lawful handling invalid. If information is necessary to verify identity, prevent fraud, perform a transfer or meet a legal obligation, withdrawing consent may mean we cannot open or continue an account or provide the requested feature.
You can unsubscribe from optional marketing using the method in the message or by contacting support. Humi may still send security alerts, transaction notices, complaint communications, legal notices and other non-marketing messages needed to administer an account or service.
Face ID, Touch ID or passcode authentication used to unlock an existing Humi App session is controlled by your Apple device. Apple performs that check locally. Humi does not receive the Face ID template from Apple.
9. If we cannot fully grant a request
We may refuse or limit access, correction or deletion where permitted or required by law. Reasons can include:
- we cannot reasonably verify the requester’s identity or authority;
- the request would unreasonably affect another person’s privacy;
- the record is subject to legal privilege, a court process, regulatory restriction or mandatory retention;
- access would create a serious security, fraud, safety or investigation risk;
- the request is frivolous, vexatious or would require disclosure that is unlawful; or
- the information has already been securely destroyed or irreversibly de-identified.
Unless prohibited by law, we will give written reasons, identify the part of the request affected and explain how to complain. We will consider whether a redacted copy, summary, annotation or another practical alternative can be provided.
10. Privacy complaints and review
If your concern is about how Humi collected, used, disclosed, secured, retained or responded to a request for personal information, select Privacy or personal-data request in the Support Centre or email compliance@humi.au. State what happened and the outcome you seek. The process is free.
We will investigate the matter fairly and provide a reasoned response. Our Complaints and Disputes page explains acknowledgement, assistance and review arrangements.
If you remain dissatisfied with the handling of a privacy complaint, you may contact the Office of the Australian Information Commissioner. Current information is available at oaic.gov.au/privacy/privacy-complaints.
Quote the Humi ticket or deletion reference in follow-up communications. Do not send passwords, verification codes, transaction PINs, full bank details or identity-document images through ordinary email or the support form.