PRIVACY POLICY Introduction
Gippsland Care Services Pty Ltd ACN 169 870 222 (together “us”, “our” or “we”) are committed to protecting the privacy of your Personal Information.
This Privacy Policy tells you how we will handle your Personal Information in accordance with the Privacy Act 1988 (Cth) (“Privacy Act”) and the Australian Privacy Principles (“APPs”).
Please note that any information that is not Personal Information that we collect, process or otherwise use will not be governed by this Privacy Policy.
All capitalised terms in this Privacy Policy have the meaning given to that term in the Schedule “Definitions” unless the context requires otherwise.
1. When does this Privacy Policy apply to me? This Privacy Policy applies when you visit the Portal or use any of our Services. By visiting the Portal or by using any of our Services, you agree to the terms of this Privacy Policy. You should not access the Portal and/or use any of our Services if you do not agree with this Privacy Policy.
2. What Personal Information do we collect? We collect and use Personal Information from Users of the Portal, Users of any of our Services and visitors of the Portal. The specific type of Personal Information that we collect will depend on the reasons for, or circumstances of its collection and may include, but is not limited to, the following:
· User information: name, telephone and mobile number, email address, residential and postal address;
· Medical information: including medical information and reports from medical practitioners – all medical information is Sensitive Information;
· Payment and transactional information: banking, credit card or debit card details, billing information, Device information and Technical Usage Data; and
· Enquiries, communications and social media: information contained in any enquiry you submit to us regarding our Portal or any of our Services, communication content, metadata associated with communications and information about you shared by social media portals (if you communicate with us by way of a social media portal that we use).
We will only collect, hold, and use your Sensitive Information with your consent or otherwise in accordance with the Privacy Act.
If you do not allow us to collect all the Personal Information we reasonably request, we may not be able to deliver any of our Services to you.
3. How do we collect Personal Information? We may collect your Personal Information directly from you or in the course of our dealings with you. For example, we collect Personal Information from you or about you from:
· your use of any of our Services;· correspondence between you and us;· from external sources like My Aged Care and other governmental agencies who we provide care for;
· visits to and submissions you make on our Site;· your interactions with our electronic direct mail and/or emails from our marketing campaigns (such as clicks on links included in these emails); and
· registration and forms you may fill in for our marketing-related activities and events. In some instances, we may receive Personal Information about you from third parties, including our related entities, government agencies and regulatory authorities. We may also receive Personal Information about you from your authorised third parties and publicly available sources.
4. Why do we collect, hold and use Personal Information?
We collect, hold and use your Personal Information for the purposes of providing you with access and usage of the Portal and the Services, which include (without limitation):
· providing you with our Services; · ongoing client relationship management purposes;· offering, promoting, advertising, marketing and selling relevant and suitable Services to you;
· sending you relevant notifications, electronic direct mail, email marketing campaigns and/or newsletters;· any other purposes identified at the time of collecting your Personal Information;
· developing and improving our business and/or any of our Services;· for monitoring, research and analysis in relation to our business, the Portal and any of our Services;· involving you in market research, gauging customer satisfaction and seeking feedback;· performing and supplying any of our Services to you;· managing our relationship with you (including maintaining a User profile), communicating with you, identifying you when you contact us, responding to your enquiries and keeping records;· processing payments you have authorised;· complying with all of our legal obligations to you and to third parties (including, without limitation, any governmental authority.
· ensuring the security of our Services and maintaining back-ups of our database(s);· for our internal accounting and administration;· where we reasonably suspect that unlawful activity has been, is being or may be engaged in and the use or disclosure is a necessary part of our investigation or in reporting the matter to the relevant authorities;· in the preparation for, or conduct of, court proceedings or in an administrative or out-of-court procedure (or the implementation of orders of a court or tribunal or on behalf of an enforcement body);· for the purpose of obtaining or maintaining insurance coverage, managing risks, or obtaining professional advice; and
· where we reasonably believe that use or disclosure is necessary to lessen or prevent a serious, immediate threat to someone's health or safety or the public's health or safety. Where we wish to use or disclose your Personal Information for other purposes, we will obtain your consent.
5. Will my Personal Information be disclosed to third parties?
We may need to disclose your Personal Information to third parties, including:
· to our related entities as necessary for the provision of any of our Services or to enable them to provide any of the service offerings that you have requested;
· to our third party provider of verification of identity services (in which case you will be asked to agree to the third party provider’s applicable privacy policy and other policies);
· to government agencies to enable relevant registrations, notifications and/or lodgements in connection with the Portal and/or our Services;
· to a person that you have authorised to use the Portal or any of our Services on your behalf;
· if you enable third party applications to be used in conjunction with the Portal and/or any of our Services, to those third party applications;
· to our partners, contractors, suppliers, subcontractors and service providers, including without limitation our suppliers of IT based solutions that assist us in providing any of our Services, distributors of direct marketing communications; marketing agencies, insurers and external business advisors;· in accordance with requirements or authorisations under applicable laws or to comply with our legal obligations; and
· to any other persons that you would reasonably expect us to disclose to for purposes contemplated by the Services or this Privacy Policy. We take reasonable steps to ensure that third party recipients are obliged to protect the privacy and security of your Personal Information and use it only for the purpose for which it is disclosed. These measures include use of industry-standard, physical procedural and technical security measures and encryption where appropriate. However, regardless of any security measures used, we cannot guarantee the absolute protection and security of any Personal Information stored with us or with any third parties.
6. How we hold and store Personal Information?
Your Personal Information is held and stored on paper, by electronic means (including by way of a third party client relationship management product or system) or both. We have physical, electronic and procedural safeguards in place for Personal Information and take reasonable steps (including by maintaining technical and organisational measures) to ensure that your Personal Information is protected from misuse, interference, loss and unauthorised access, modification and disclosure, including:· Data held and stored on paper is stored in secure premises. · Data held and stored electronically is protected by internal and external firewalls. We encrypt and/or pseudonymise data wherever possible. All access to electronic Data including databases requires password access that meets industry complexity standards.· Access to Personal Information is restricted to staff and contractors whose job description requires access. Our employees and contractors are contractually obliged to maintain the confidentiality of any Personal Information held by us. We also implement multi-factor authentication (MFA) safeguards wherever possible and appropriate.
· Data stored or archived off-Portal is contained within secure facilities. We also require our storage contractors to implement privacy safeguards.· We undertake regular Data backups, with the Data copied and backed up to multiple locations for redundancy purposes.· Our staff receive regular training on privacy and data protection procedures.
7. How long will my Personal Information be retained? We will retain your Personal Information only for as long it is required for any of the purposes set out in this Privacy Policy or for any other lawful purposes.
We will retain your Personal Information for the time periods required by law. We use secure methods to destroy, desensitise or de-identify your Personal Information when it is no longer needed or legally required to be retained. Paper records are sent for secure destruction. In some instances, paper records and original documents will be returned to you and/or relevant third parties. Electronic records may be archived to alternative storage and are subject to the procedural safeguards described above. Please refer to sections 8 and 9 below for the procedure to have your Personal Information deleted.
8. Will I be able to access and control my Personal Information? You have a right to request access to or correction of your Personal Information held by us. If you wish to access, correct or update any Personal Information that we hold about you, please contact us via the details below in section 14. We will respond to your request within 30 days of you making the request and give you access in the manner you requested unless it is unreasonable or impracticable for us to do so. Before we accept your request, we will need to use reasonable methods to verify your identity. There may be reasons why we cannot give you access to the information that you have requested, or we refuse to correct your personal information. In these instances, we will let you know these reasons in writing. To assist us to keep our records up to date, please notify us of any changes to your Personal Information.
9. Can I withdraw my consent to hold my Personal Information? You have a right to withdraw your consent to us using your Personal Information at any time. Please contact us via the details below if you would like to make such a request. We will process a request within one month. Please note that by withdrawing your consent, we may no longer be able to provide you with access to our Portal or Services. Please refer to section 8 above for the procedure to have your Personal Information deleted.
10. Will my Personal Information be transferred internationally? Disclosure to third parties overseas. Occasionally, we may be required to disclose your Personal Information to third parties outside of Australia in connection with the provision of Services or other purpose permitted by the Privacy Act. If we make such disclosure, we will take reasonable steps to ensure that those third parties, in whichever jurisdiction, adhere to the APPs.
Overseas processing. Personal Information may be processed in countries other than Australia, where our Data hosting provider’s servers are located. These countries may have laws different to what you’re used to. Where we process your Personal Information in another country, we put safeguards in place to ensure your Personal Information remains protected in accordance with this Privacy Policy.
11. Will I have the opportunity to provide feedback? From time to time, you may have the option to participate in surveys or provide feedback intended to improve any of our Services which may involve providing additional Personal Information. Your participation in such activities is subject to your consent.
12. What direct marketing will be undertaken? We may use and disclose your Personal Information for the purpose of direct marketing to you by way of a direct mail, email, SMS, MMS, targeted digital advertising or any other means of marketing communication, where:· you have consented to us doing so; or· it is otherwise permitted by law.
You may opt out of direct marketing communications at any time by contacting us or by using opt-out facilities set out in the direct marketing communications.
13. Will this Privacy Policy change? We may update our Privacy Policy from time to time by either notifying you of a change to our Privacy Policy and providing you with the updated Privacy Policy or publishing a new version on our Portal. Our Privacy Policy was last updated on 31 October 2024. By continuing to use our website or otherwise continuing to deal with us, you accept this Privacy Policy as it applies from time to time.
14. Who do I contact if I have a complaint? We have procedures in place for dealing with complaints and concerns about our practices in relation to the Privacy Act, the APPs, and any alleged breach of this Privacy Policy. We will respond to your complaint in accordance with the relevant provisions of the APPs. For further information, please contact us using the details below.
78, Albert Street, Warragul Email: admin@gippslandcareservices.com.au
Phone: 0429 650 196
If you are not satisfied with our response to your complaint, or you consider that we may have breached the APPs or the Privacy Act, a complaint may be made to the Office of the Australian Information Commissioner (OAIC). The OAIC can be contacted by telephone using contact details below or by using the contact details on the OAIC website.
Office of the Australian Information Commissioner
Phone: 1300 363 992
Teletypewriter (TTY): 133 677 then ask for 1300 363 992.
Speak and Listen users: 1300 555 727 then ask for 1300 363 992
15. Schedule - Definitions
"Data" means any data inputted by you or with your authority through the use of the Services and includes, without limitation, data owned or supplied by you or data which may otherwise be generated, compiled, arranged or developed by you in using the Services pursuant to these Terms of Use.
“Device” means any type of device including a computer, mobile phone, tablet or console that meets the minimum specifications required to access to the Portal and/or use any of our Services.
“Device Information” means Data that can be automatically collected from any device used to access the Portal and/or any of our Services, including your Device type, your Device’s network connections, your Device’s name, your Device’s IP address, information about your Device’s web browser and the internet connection used to access the Portal or any of our Services, Geolocation Information, information about apps downloaded to your Device and biometric Data (such as Touch ID/Fingerprint).
“Geolocation Information” means information that identifies your location by using longitude and latitude coordinates obtained through GPS, Wi-Fi or cell Portal triangulation.
“Portal’ means the cloud-based software and Site owned and operated by us.
“Personal Information” means information or an opinion (including information or an opinion forming part of a database), whether true or not, and whether recorded in a material form or not, about an individual whose identity is apparent, or can reasonably be ascertained;
“Sensitive Information” means: (a) Personal Information that is also information about an individual’s racial or ethnic origin, political opinions, membership of a political association, philosophical beliefs, religious beliefs or affiliations, membership of a professional or trade association, membership of a trade union, sexual orientation or practices, or criminal record; (b) health information (as defined in section 6FA of the Privacy Act) about an individual; (c) genetic information about an individual that is not otherwise health information (as defined in section 6FA of the Privacy Act); (d) biometric information that is to be used for the purpose of automated biometric verification or biometric identification; or (e) biometric templates.
"Services" means any and all services provided by us from time to time.
“Site” means the website operating from the domain at “https://www.gippslandcareservices.com.au” or such other domains used by us from time to time for access to this site or any other sites or provision of any of our Services.
“Technical Usage Data” means information we collect from your Device that you use to access the Portal or any of our Services such as what you have searched for and viewed on the Portal, the length of your visit and the way you use any of our Services, including your IP address, statistics regarding how pages are loaded or viewed, the website you viewed before coming to the Portal and other usage and browsing information collected through cookies.
“User” means a user of the Portal and/or any of our Services, as the context requires.