We respect the integrity of the Privacy Act 1988 and seek to uphold its principles through the attentive care we give to the data provided to us.
Ammonite respects the privacy of all Ammonite people including clients, employees, business partners, contractors, online users, and all other stakeholders and is committed to safeguarding the personal information that is provided to us.
Purpose
The purpose of this privacy policy is to:
- clearly communicate the personal information handling practices of Ammonite
- enhance the transparency of Ammonite operations, and
- give individuals a better and more complete understanding of the sort of personal information that Ammonite holds, and the way we handle that information.
Scope
This policy and procedure applies to all Ammonite clients, employees, business partners, contractors, online users and all other Ammonite stakeholders.
The Privacy Act and this Privacy Policy do not apply to acts or practices which directly relate to employee records of Ammonite’s current and former employees.
Definitions
Online users refers to anyone that accesses the Ammonite software.
Personal information as defined by the Privacy Act 1988 (as amended) is information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether true or not, and whether recorded in a material form or not.
Sensitive information as defined by the Privacy Act 1988 (as amended) is information or opinion (that is also personal information) about an individual’s racial or ethnic origin, political opinions, membership of a political association, religious beliefs or affiliations, philosophical beliefs, membership of a professional or trade association, membership of a trade union, sexual preferences or practices or criminal record or health, genetic, biometric information or biometric templates, that is also personal information.
Our Personal Information Handling Practices
This section explains our general information handling practices across Ammonite including information about how we collect, use, disclose and store your personal information.
Our obligations under the Privacy Act
This Privacy Policy sets out how we comply with our obligations under the Privacy Act 1988 (Privacy Act). We are bound by the Australian Privacy Principles (APPs) in the Privacy Act which regulate how organisations may collect, use, disclose and store personal information, and how individuals may access and correct personal information held about them. We will obtain your consent as applicable prior to collecting, using and/or sharing your information. If you do not provide consent and/or withdraw your consent at a later date, we may not be able to provide the services you require.
Ammonite’s Clients and Users
Kind of information collected:
- contact details (name, address, email etc.)
- personal details including date of birth, gender
- information on qualifications/training
How the information is collected:
- online registration
- telephone
- during consultations/meetings/activities
- upload of client data
The purpose for which Ammonite uses the information:
- to provide Ammonite’s services
- to provide clients with the most appropriate services for their needs
- to comply with legal obligations
- to produce promotional materials
Ammonite Business Partners
Types of information collected:
- contact person’s name, the name of the organisation which employs the person, telephone number, fax number, street and postal address, email address and position title
- areas of interest by category and industry
- Australian Business Number (ABN)
How the information is collected:
- communications, email, flyers
- online registration
- telephone
The purpose for which Ammonite uses the information:
- to provide Ammonite services
- to pay for services
- to establish and manage partnerships
- to receive services from you or the organisation which employs you
- to manage Ammonite‘s relationship with the business partner
- to provide information about Ammonite‘s services
Ammonite People
(Employees, delegates, volunteers, and candidates for prospective employment)
Type of information collected:
- contact details (name, address, telephone numbers, email etc.)
- personal details including personal details of emergency contact person(s)
- date of birth
- country of birth, citizenship, residency and/or visa details
- details of current/previous employment or volunteer involvement
- skills and experience
- languages spoken and written
- qualifications, driver's licence details
- information and opinions from referees for prospective employees and candidates for volunteer work
- in some situations, it is necessary for Ammonite to collect or receive information about an individual’s health. In this circumstance, Ammonite will advise why the information is being collected and whether and to whom it will be released.
The purpose for which Ammonite uses the information:
- to provide Ammonite services
- to process an application to become a volunteer or employee of our organisation
- to assist with services whilst an individual is employed or engaged as a volunteer with Ammonite
- to provide feedback on performance as a volunteer or employee
- to meet legislative responsibilities to all volunteers and employees
- to obtain feedback from individuals about their experiences
- to assist Ammonite to review and improve its services to keep individuals informed about Ammonite developments and opportunities
- to provide information about Ammonite services
- to facilitate further involvement with Ammonite
Online Users
To the extent that this Privacy Policy applies to online privacy issues, it is to be read as forming part of the terms and conditions of use for the Ammonite website.
Type of information collected:
- contact details (name, address, telephone numbers, email etc.)
- non-personal information e.g. visitor navigation and statistics
- server address, browser type, date and time of visit
- personal information
The purpose for which Ammonite uses the information:
- to analyse website usage and make improvements to the website
- Ammonite does not match the personal information collected with the non-personal information
Additional Information
The website may from time to time contain links to other websites. Ammonite stresses that when an online user accesses a website that is not the Ammonite website, it may have a different privacy policy. To verify how that website collects and uses information, the user should check that particular website’s policy.
How We Collect Information
Where possible, we collect your personal and sensitive information directly from you. We collect information through various means, including telephone and in-person interviews, appointments, forms and questionnaires. If you feel that the information that we are requesting, either on our forms or in our discussions with you, is not information that you wish to provide, please feel free to raise this with us.
In some situations, we may also obtain personal information about you from a third-party source. If we collect information about you in this way, we will take reasonable steps to contact you and ensure that you are aware of the purposes for which we are collecting your personal information and the organisations to which we may disclose your information, subject to any exceptions under the Act.
Use and disclosure of Personal Information
We only use personal information for the purposes for which it was given to us, or for purposes that are related to one of our functions or activities.
For the purposes referred to in this Privacy Policy (discussed above under ‘Collection of Personal and Sensitive Information), we may also disclose your personal information to other external organisations including:
- Government departments/agencies that provide funding for Ammonite services
- Contractors who manage some of the services we offer to you. Steps are taken to ensure they comply with the APPs when they handle personal information and are authorised only to use personal information in order to provide the services or to perform the functions required by Ammonite;
- Other regulatory bodies, such as Workplace Health and Safety Qld
- Referees and former employers of Ammonite employees and volunteers, and candidates for Ammonite employee and volunteer positions; and
- Our professional advisors, including our accountants, auditors and lawyers.
Except as set out above, Ammonite will not disclose an individual’s personal information to a third party unless one of the following applies:
- the individual has consented
- the individual would reasonably expect us to use or give that information for another purpose related to the purpose for which it was collected (or in the case of sensitive information – directly related to the purpose for which it was collected)
- it is otherwise required or authorised by law
- it will prevent or lessen a serious threat to somebody’s life, health or safety or to public health or safety
- it is reasonably necessary for us to take appropriate action in relation to suspected unlawful activity, or misconduct of a serious nature that relates to our functions or activities
- it is reasonably necessary to assist in locating a missing person
- it is reasonably necessary to establish, exercise or defend a claim at law
- it is reasonably necessary for a confidential dispute resolution process
- it is necessary for the management, funding or monitoring of a health service relevant to public health or public safety
- it is necessary for research or the compilation or analysis of statistics relevant to public health or public safety
- it is reasonably necessary for the enforcement of a law conducted by an enforcement body.
We do not send personal information out of Australia. If we are required to send information overseas we will take measures to protect your personal information. We will protect your personal information either by ensuring that the country of destination has similar protections in relation to privacy or that we enter into contractual arrangements with the recipient of your personal information that safeguards your privacy.
Security of Personal and Sensitive Information
Ammonite takes reasonable steps to protect the personal and sensitive information we hold against misuse, interference, loss, unauthorised access, modification and disclosure.
These steps include password protection for accessing our online systems, securing paper files in locked cabinets and physical access restrictions. Only authorised personnel are permitted to access these details.
When the personal information is no longer required, it is destroyed in a secure manner, or deleted according to legislative requirements.
Viewing, amending and deleting personal information
An individual may request that Ammonite disclose, amend, or delete their personal information by contacting
In the first instance, Ammonite will generally provide a summary of the information held about the individual. It will be assumed (unless told otherwise) that the request relates to current records. These current records will include personal information which is included in Ammonite databases, and which may be used on a day-to-day basis.
We will provide access by allowing you to inspect, take notes or printouts of personal information that we hold about you. If personal information (for example, your name and address details) is duplicated across different databases, Ammonite will generally provide one printout of this information, rather than multiple printouts.
We will take all reasonable steps to provide access or the information requested within 14 days of your request. In situations where the request is complicated or requires access to a large volume of information, we will take all reasonable steps to provide access to the information requested within 30 days.
Ammonite may charge you reasonable fees to reimburse us for the cost we incur relating to your request for access to information.
If an individual is able to establish that personal information Ammonite holds about her/him is not accurate, complete or up to date, Ammonite will take reasonable steps to correct our records.
Access will be denied if:
- the request does not relate to the personal information of the person making the request;
- providing access would pose a serious threat to the life, health or safety of a person or to public health or public safety;
- providing access would create an unreasonable impact on the privacy of others;
- the request is frivolous and vexatious;
- the request relates to existing or anticipated legal proceedings;
- providing access would prejudice negotiations with the individual making the request;
- access would be unlawful;
- denial of access is authorised or required by law;
- access would prejudice law enforcement activities;
- access would prejudice an action in relation to suspected unlawful activity, or misconduct of a serious nature relating to the functions or activities of Ammonite
- access discloses a commercially sensitive decision making process or information; or
- any other reason that is provided for in the APP or in the Privacy Act.
If we deny your request we will set our reasons for the decision in writing to you. Any dispute in relation to the decision will be dealt with in accordance with the complaints procedure set out below.
Complaints Procedure
If you have provided us with personal and sensitive information, or we have collected and hold your personal and sensitive information, you have a right to make a complaint and have it investigated and dealt with under this complaints procedure.
If you have a complaint about Ammonite privacy practices or our handling of your personal and sensitive information please contact your relevant service provider (details of which are set out at the end of this document).
All complaints will be logged on our database.
A privacy complaint relates to any concern that you may have regarding Ammonite privacy practices or our handling of your personal and sensitive information. This could include matters such as how your information is collected or stored, how your information is used or disclosed or how access is provided to your personal and sensitive information.
The goal of this policy is to achieve an effective resolution of your complaint within a reasonable timeframe, usually 30 days or as soon as practicable.
However, in some cases, particularly if the matter is complex, the resolution may take longer.
Once the complaint has been made, we will try to resolve the matter in a number of ways such as:
- Request for further information: We may request further information from you. You should be prepared to provide us with as much information as possible, including details of any relevant dates and documentation. This will enable us to investigate the complaint and determine an appropriate solution. All details provided will be kept confidential.
- Discuss options: We will discuss options for resolution with you and if you have suggestions about how the matter might be resolved you should raise these with your service provider.
- Investigation: Where necessary, the complaint will be investigated. We will try to do so within a reasonable time frame. It may be necessary to contact others in order to proceed with the investigation. This may be necessary in order to progress your complaint.
- Conduct of our employees: If your complaint involves the conduct of our employees we will raise the matter with the employee concerned and seek their comments and input in the resolution of the complaint.
- The complaint is substantiated: If your complaint is found to be substantiated, you will be informed of this finding. We will then take appropriate agreed steps to resolve the complaint, address your concerns and prevent the problem from recurring.
- If the complaint is not substantiated, or cannot be resolved to your satisfaction, but this Privacy Policy has been followed, Ammonite may decide to refer the issue to an appropriate intermediary. For example, this may mean an appropriately qualified lawyer or an agreed third party, to act as a mediator.
- At the conclusion of the complaint, if you are still not satisfied with the outcome you are free to take your complaint to the Office of the Australian Information Commissioner at www.oaic.gov.au.
We will keep a record of your complaint and the outcome.
We are unable to deal with anonymous complaints. This is because we are unable to investigate and follow up on such complaints. However, in the event that an anonymous complaint is received, we will note the issues raised and, where appropriate, try and investigate and resolve them appropriately.
Notice of Data Breach
We adhere to the APA legislation regarding eligible data breaches, which we determine to be under the following circumstances:
- there is unauthorised access to, or unauthorised disclosure of, the information;
AND - a reasonable person would conclude that the access or disclosure would be likely to result in serious harm to any of the individuals to whom the information relates;
OR
- unauthorised access to, or unauthorised disclosure of, the information is likely to occur;
AND - assuming that unauthorised access to, or unauthorised disclosure of, the information was to occur, a reasonable person would conclude that the access or disclosure would be likely to result in serious harm to any of the individuals to whom the information relates
In the event of an eligible data breach, we will comply fully with the notification requirements set out in the APA legislation.
Changes to this Privacy Policy
Ammonite reserves the right to review, amend and/or update this policy from time to time.
We aim to comply with the APPs and other privacy requirements required to be observed under State or Commonwealth Government contracts.
If further privacy legislation and/or self-regulatory codes are introduced or our Privacy Policy is updated, we will summarise any substantial modifications or enhancements in this section of our Privacy Policy.
How to contact us
Individuals can obtain further information in relation to this privacy policy, or provide any comments, by contacting us:
email:
phone: 1300 851 504