Privacy Policy
1. INTRODUCTION
This Privacy Policy (Policy) explains how Opening Doors Foundation Ltd (ODF) collects and handles your Personal Information.
ODF is committed to protecting your privacy. Establishing a trusting relationship with our users is central to our work practices. Privacy Legislation means, as applicable, the Privacy Act 1988 (Cth, Australia) or supplements, Australian state or territory privacy laws, or any legislation that replaces those laws.
In this Policy, Personal Information or Personal Data has the same meaning as in the Privacy Legislation
2. PURPOSE
The purpose of this document is to provide a framework for ODF in dealing with privacy considerations.
We apply this Policy to all individuals and entities who interact with ODF. This includes (but is not limited to) agents, contractors, subcontractors, employees, representatives, users of our services, and volunteers.
We may update this Policy from time to time in accordance with legislative or operational changes. If you would like us to send you a copy, or you have comments or questions regarding this Policy, please contact us. Our contact details and method for contacting us are provided in clause 3.11.
3. POLICY
3.1 Types of information we collect
The type of information that we collect and hold depends on the nature of a person’s involvement with us and the services we provide on their behalf.
We only collect your Personal Information where it is reasonably necessary for us to pursue one or more of our functions or activities, or where the law requires us to collect it.
Depending on the reason for collecting it, the Personal Information we collect may include (but is not limited to):
Your name and contact details.
Your date of birth.
Copies of identification documentation.
Banking details if you are purchasing a service through us.
Social security and pension eligibility for the purpose of determining your financial status and eligibility for accommodation.
Other financial information which may be used to determine eligibility for accommodation and your position on our waiting lists.
Centrelink Customer Reference Numbers and personal information if you wish to pay through deductions from your Centrelink payments.
National Disability Insurance Scheme Participant number and personal information if you are applying for NDIS Specialist Disability Accommodation.
Personal Information contained in forms or applications.
Personal Information contained in queries, or feedback about our services.
Usage data (which may include your IP address, the pages you have accessed on our websites, websites that referred you to our sites, information about the device you are using, and your wider geographic location).
In some circumstances, we collect Sensitive Information, which requires a higher level of protection under the Privacy Legislation. We consciously limit how much Sensitive Information we collect, and we only collect it when we have your consent and the collection is reasonably necessary for us to pursue one or more of our functions or activities. In this Policy, Sensitive Information (or Special Category Data) has the same meaning as in the Privacy Legislation.
Sensitive information includes:
Health information.
Personal and social preferences.
Religious or faith beliefs.
Racial or ethnic origin.
Gender.
Genetic and biometric information.
Data, video, images and audio from monitoring devices (e.g. CCTV, personal care alarms).
3.2 How we collect information
We ask you for Personal Information when it is reasonably necessary for the activities and services in which you are seeking ODF to provide. ODF will only collect information which the organisation requires for its primary function, and for such other secondary purposes that are related to the primary purpose of collection and would reasonably be expected, or to which you have consented.
We will only collect your Personal Information by lawful and fair means, including by telephone, by letter, by email, through forms on our websites or through websites we trust, and from monitoring devices (e.g. CCTV, personal care alarms).
ODF will usually collect information directly from you. We generally obtain consent from you to collect Personal Information. Consent may be provided in writing, or may be provided orally, or may be implied through a person’s conduct.
Sometimes we may need to solicit information from a third party. We will only do this if you have consented for us to collect this information in this way or where it is not reasonable or practicable to collect the information directly from you. Other ways we may gather data about you could include obtaining information from:
Your family members;
Your appointed representatives (e.g. enduring guardian);
Health care providers and professionals or other professional experts.
Agents, contractors or subcontractors.
Employees, users of ODF’s services, and volunteers.
Statutory authorities or government departments.
Publicly held information including public registers or websites.
We collect user data through log files and cookies. In some cases, you can block or delete cookies and still use our services, although if you do, you will be asked for your email address and password every time you log into an account you hold with us.
You are not required to provide the Personal Information and/or Sensitive Information we request. However, if you choose not to provide it, we may not be able to service your needs (see also clause 3.5. How we store and handle your data).
You are free to browse our websites anonymously. However, when you are registering for one of our services, we will require you to register an account using your name or a pseudonym and provide a valid email address. It is impractical for us to manage and provide support if we cannot match you to your account.
3.3 How we deal with unsolicited information
If we receive your Personal Information from you or a third party without having asked for it, and we determine we do not have a need for it, we will destroy or deidentify the information as soon as practicable, so long as it is lawful and reasonable to do so.
3.4 How we use your personal information
We use your Personal Information for a range of purposes, including:
Providing you with our services.
Improving our services through quality-improvement activities.
Providing you with information, news, offers and surveys.
Helping you to access the most appropriate information and tools associated with our websites.
Providing you with support if you need technical assistance.
Processing payments, including donations.
Communicating important service-related announcements, changes to our services or policies, or password notifications.
Providing you with information about your account and newsletters you have signed up to receive.
Answering inquiries and resolving complaints.
Complying with directions from authorities or legislative requirements.
Screening for or preventing potentially fraudulent, illegal or abusive activity.
Storing your data so it is available for your future use of our services.
We may also collect, hold, use and disclose Personal Information for purposes:
Which we explained at the time of collection
Which are required by law.
For which you have provided your consent.
Which are necessary for maintaining the reliability and security of Infrastructure and services.
We only use or disclose your Personal Information for the above purposes, or for purposes that you consent to, or for other related purposes that you would reasonably anticipate.
To the extent you submit content to public areas of our websites (for example, on a public online forum), it will be available to the public and we may reuse or republish it. If you request that such content be removed, we will do our best to promptly remove it.
If you have any concerns about us using your Personal Information in any of these ways, please notify us immediately.
3.5 How we store and handle your data
We hold Personal Information in several ways, including in electronic databases, email contact lists, and in paper files held in secure offices.
We take reasonable steps to:
- Make sure that the Personal Information is accurate, up to date and complete, and (in the case of use and disclosure) relevant.
- Protect the Personal Information from misuse, interference, loss, unauthorised access, destruction, modification or disclosure.
- Destroy or permanently de-identify Personal Information that is no longer needed. (However, we will keep information for a longer period where necessary to comply with contractual, regulatory or legal requirements.)
Any Personal Information we provide to you through your online account(s) with ODF is password-protected.
- You must not reveal or share your password with anyone.
- We will never ask for your password, either verbally or through phone or email contact (whether initiated by you or us).
3.6 Accessing and correcting your Personal Information
If you would like to:
- confirm that we hold your Personal Information,
- access your Personal Information or
- correct your Personal Information.
You can request this by using the contact details in clause 3.11.
We will respond to your request within a reasonable period and within any timeframe specified by the Privacy Legislation. You may make an urgent request to access or correct your Personal Information, which should include the reasons for the urgency.
Prior to allowing access to your Personal Information, we may ask you to take steps to verify your identity.
We will allow you to access your Personal Information unless there is a sound reason not to, including where:
- Giving access would have an unreasonable impact on the privacy of others.
- We reasonably consider that your request for access is frivolous or vexatious.
- It is not permitted under the applicable privacy legislation.
If we refuse to give you access to your information, we will give you a notice setting out our reasons.
If you believe that information we hold about you is incorrect or out of date, please contact us and we will take all reasonable steps to amend the information in line with your request.
If the information has been collected on behalf of others (refer to clause 3.3. How we deal with unsolicited information), we may direct you to contact the relevant party to initiate your request
3.7 Third party service providers
ODF uses some third-party service providers (sub-processors) in order to support our websites and operations. These third-party service providers can include foreign entities that operate in an overseas jurisdiction.
We select reputable third-party service providers on the basis of their published privacy policies.
By using our services and interacting with ODF, you acknowledge that third party service providers that are foreign entities may not be required to protect your Personal Information in a way that provides comparable safeguards as those provided in the Privacy Legislation.
Any questions related to our use of third-party service providers can be directed to us via the contact details in clause 3.11.
3.8 Direct marketing
We only use your Personal Information to let you know about our products or services where we have your consent, or where we are otherwise permitted by law to do so. We may contact you for these purposes in a variety of ways, including by mail, email, SMS or telephone.
We do not sell your Personal Information to any third party for the purposes of direct marketing.
Where you have consented to receiving marketing communications from us, your consent remains current until you advise us otherwise. You can opt out at any time, by:
- Contacting us as set out in clause 3.11.
- Advising us if you receive a marketing call that you no longer wish to receive.
- Using the unsubscribe facility that we include in our electronic messages (such as emails and sms).
We do not use your Sensitive Information for the purposes of direct marketing.
3.9 Notification of a data breach
If we become aware of unauthorised access to or loss of your Personal Information, we will promptly:
- Notify you.
- Investigate the cause.
- Do our best to remedy any consequences.
- Tell you what steps we have taken to prevent a reoccurrence.
Unauthorised access to or unauthorised disclosure of personal information, or a loss of personal information, are handled in accordance with the relevant authority as follows: oaic.gov.au/privacy/notifiable-data-breaches
3.10 Complaints
If you have a complaint about how we collect or handle your Personal Information, please contact us using the contact details in clause 3.11. We treat any claims of privacy breaches seriously and will do our best to respond to your complaint within seven days of receiving it.
If you are unhappy with our response, you can refer your complaint to the Office of the Australian Information Commissioner in Australia.
3.11 Contact details
You can contact us by:
- Phone – Call us on 02 69257255
- Email to info@odf.org.au
- Writing a letter to us at:
Opening Doors Foundation Ltd
PO Box 7225
Wagga Wagga NSW 2650