All terms & policies

Security & Data Handling Policy

Last updated: 1 June 2026

This Security & Data Handling Policy (Policy) forms part of the COMCA Master Terms & Conditions and applies to all data, systems, and warehouse operations used by COMCA. By using COMCA, you agree to this Policy.

1. Purpose of This Policy

This Policy outlines how COMCA:

  • protects user data
  • secures warehouse operations
  • manages access controls
  • handles system security
  • responds to incidents
  • complies with Australian privacy and data laws

2. Definitions

Terms defined in the COMCA Master Terms & Conditions have the same meaning in this Policy.

“Personal Information” has the meaning given in the Privacy Act 1988 (Cth).

“Systems” means COMCA’s website, platform, databases, warehouse software, and internal tools.

“Security Incident” means any unauthorised access, breach, or compromise of data or systems.

3. Data Collection & Use

3.1 COMCA collects only the data necessary to operate the platform, including:

  • account information
  • identity verification data (via Stripe Connect)
  • transaction data
  • warehouse intake data
  • communication logs
  • security logs

3.2 Data is used for:

  • providing Services
  • fraud prevention
  • compliance with law
  • platform optimisation
  • customer support

3.3 Data is handled in accordance with this Policy and the Australian Privacy Principles.

4. Data Storage & Protection

4.1 COMCA uses secure, access-controlled systems to store:

  • personal information
  • inventory data
  • transaction records
  • warehouse logs

4.2 Security measures include:

  • encryption in transit and at rest
  • access controls and role-based permissions
  • audit logs
  • secure backups
  • network monitoring
  • MFA for staff access

4.3 Only authorised staff may access sensitive data.

5. Warehouse Security

5.1 COMCA warehouses use:

  • restricted physical access
  • CCTV monitoring
  • alarm systems
  • staff access logs
  • secure storage systems

5.2 Warehouse footage is retained for a reasonable period but is not guaranteed to be available indefinitely.

5.3 Clients may not access the warehouse unless expressly authorised.

6. Access Controls

6.1 COMCA uses role-based access to ensure staff only access data required for their duties.

6.2 Access is revoked immediately upon termination of employment or contract.

6.3 Administrative access is restricted to authorised personnel.

7. System Security

7.1 COMCA employs:

  • firewalls
  • intrusion detection
  • rate limiting
  • bot protection
  • vulnerability scanning
  • secure coding practices

7.2 Users must not:

  • attempt to bypass security
  • probe or scan systems
  • use bots or scrapers without permission
  • upload malicious code

Violations may result in immediate suspension.

8. Incident Response

8.1 COMCA maintains an internal incident response process.

8.2 In the event of a Security Incident, COMCA will:

  • investigate promptly
  • contain and mitigate the issue
  • notify affected users where required by law
  • cooperate with regulators where applicable

8.3 Users must notify COMCA immediately if they suspect unauthorised access to their account.

9. Data Retention & Deletion

9.1 COMCA retains data only as long as necessary for:

  • legal compliance
  • operational requirements
  • fraud prevention
  • dispute resolution

9.2 Users may request deletion of personal information where permitted by law.

9.3 Warehouse footage, logs, and operational data may be deleted automatically after a retention period.

10. Third-Party Services

10.1 COMCA uses trusted third-party providers for:

  • payment processing (Stripe)
  • hosting and infrastructure
  • analytics
  • communication tools

10.2 Third-party providers must meet COMCA’s security standards.

10.3 COMCA does not store full payment card details.

11. User Responsibilities

Users must:

  • maintain secure passwords
  • enable MFA where available
  • keep account details up to date
  • notify COMCA of suspicious activity
  • comply with the Acceptable Use Policy

COMCA is not responsible for losses caused by compromised user accounts.

12. Prohibited Security-Related Conduct

Users must not:

  • attempt to access other users’ data
  • interfere with COMCA’s systems
  • bypass security controls
  • upload malware
  • use automated tools without permission
  • attempt to reverse engineer the platform

Violations may result in immediate termination.

13. Compliance With Law

COMCA complies with:

  • the Privacy Act 1988 (Cth)
  • Australian Consumer Law
  • applicable cybersecurity obligations
  • payment industry standards (via Stripe)

14. Changes to This Policy

COMCA may update this Policy by posting a new version on the website. Continued use of the Services constitutes acceptance.