top of page

Privacy Policy

Introduction

This Privacy Policy (Policy) explains how Keystone Commons collects and handles your Personal Information.  Keystone Commons is committed to protecting your privacy. Establishing a trusting relationship with our users is central to our work practices.


Privacy Legislation means, as applicable, the Privacy Act 1988 (Cth, Australia) or supplements, Australian state or territory privacy laws, or any legislation that replaces those laws. In this Policy, Personal Information or Personal Data has the same meaning as in the Privacy Legislation.

 

1.Purpose
1.1 The purpose of this document is to provide a framework for Keystone Commons in dealing with privacy considerations.
1.2 We apply this Policy to all individuals and entities who interact with for Keystone Commons. This includes (but is not limited to) agents, contractors, subcontractors, employees, representatives, users of Our Community’s services, and volunteers.
1.3 We may update this Policy from time to time in accordance with legislative or operational changes. If you would like us to send you a copy or you have comments or questions regarding this Policy, please contact us using the details provided in clause 12.


2. Types of information we collect

2.1 The type of information that we collect and hold depends on the nature of a person’s involvement with us.

2.2 We only collect your Personal Information where it is reasonably necessary for us to pursue one or more of our functions or activities, or where the law requires us to collect it.

2.3 Depending on the reason for collecting it, the Personal Information we collect may include (but is not limited to):

(a) your name and contact details;

(b) copies of identification documentation;

(c) payment information and banking details if you are purchasing a product through us;

(d) Personal Information contained in forms or applications;

(e) Personal Information contained in queries, or feedback about our services;

(f) usage data (which may include your IP address, the pages you have clicked through on our websites, websites that referred you to our sites, information about the device you are using, and your wider geographic location).

2.4 In some circumstances, we collect Sensitive Information, which requires a higher level of protection under the Privacy Legislation. We consciously limit how much Sensitive Information we collect, and we only collect it when we have your consent and the collection is reasonably necessary for us to pursue one or more of our functions or activities. In this Policy, Sensitive Information (or Special Category Data) has the same meaning as in the Privacy Legislation.

 

3. How we collect information

3.1 We ask you for Personal Information when it is reasonably necessary for the activities in which you are seeking to be involved.

3.2 We will only collect your Personal Information by lawful and fair means, including by telephone, by letter, by email, through forms on our websites or through websites we trust.

3.3 Normally, we collect your Personal Information directly from you (or the relevant individual), unless it is unreasonable or impracticable to do so.

3.4 Subject to clause 3.2:

(a) We may collect Personal Information from agents, contractors,

subcontractors, employees, representatives, users of [Name of Oerganisation]’s

services, and volunteers.

(b) On occasion, we may collect Personal Information from a third party. For example, Personal Information may be provided by third party websites (refer to clause 9).

(c) We collect user data through log files and cookies.

(i) In some cases you can block or delete cookies and still use our services, although if you do, you will be asked for your email address and password every time you log into an account you hold with us.

3.5 We generally obtain consent from the owner of Personal Information to collect their Personal Information. Consent may be provided in writing, or may be provided orally, or may be implied through a person’s conduct.

3.6 You are not required to provide the Personal Information and/or Sensitive Information we request. However, if you choose not to provide it, we may not be able to service your needs (see also clause 6).

You are free to browse our websites anonymously. However, when you are registering for one of our services, we require you to register an account using your name or a pseudonym and provide a valid email address. It is impractical for us to manage and provide support if we cannot match you to your account.

Receipts (especially tax receipts) may be invalid unless accurate information, including your real name, is provided.

 

4. How we deal with unsolicited Personal Information

4.1 If we receive your Personal Information from you or a third party without having asked for it, and we determine we do not have a need for it, we will destroy or deidentify the information as soon as practicable, so long as it is lawful and reasonable to do so

 

5. How we use your Personal Information

5.1 We use your Personal Information for a range of purposes, including:

(a) providing you with our services;

(b) improving our services through quality-improvement activities;

(c) providing you with information, news, offers and surveys;

(e) helping you to access the most appropriate information and tools  associated with our websites;

(f) providing you with support if you need technical assistance;

(g) processing payments, including donations;

(h) communicating important service-related announcements, changes to  our services or policies, or password notifications;

(i) providing you with information about your account and newsletters you  have signed up to receive;

(j) answering inquiries and resolving complaints;

(k) complying with directions from authorities or legislative requirements;

(l) screening for or preventing potentially fraudulent, illegal or abusive activity;

(m) storing your data so it is available for your future use of our services.

5.2 We may also collect, hold, use and disclose Personal Information for purposes:

(a) which we explained at the time of collection; or

(b) which are required by law; or

(c) for which you have provided your consent; or

(d) which are necessary for maintaining the reliability and security of

infrastructure and services.

5.3 We only use or disclose your Personal Information for the above purposes, or for purposes that you consent to, or for other related purposes that you would  reasonably anticipate.

5.4 To the extent you submit content to public areas of our websites (for example, on a public online forum), it will be available to the public and we may reuse or  republish it. If you request that such content be removed, we will do our best to  promptly remove it.

5.5 If you have any concerns about us using your Personal Information in any of these ways, please notify us immediately.

 

6. How we store and handle your data

6.1 We hold Personal Information in a number of ways, including in electronic databases, email contact lists, and in paper files held in secure offices.

6.2 We take reasonable steps to:

(a) make sure that the Personal Information is accurate, up to date and  complete, and (in the case of use and disclosure) relevant;

(b) protect the Personal Information from misuse, interference, loss,  unauthorised access, destruction, modification or disclosure;

(c) destroy or permanently de-identify Personal Information that is no  longer needed. (However, we will keep information for a longer period  where necessary to comply with contractual, regulatory or legal  requirements.)

6.3 Any Personal Information we provide to you through your online account(s) with Keystone Commons is password-protected.

(a) You must not reveal or share your password with anyone.

(b) We will never ask for your password, either verbally or through phone or email contact (whether initiated by you or us)


7. Accessing and correcting your Personal Information

7.1 If you would like:

(a) confirmation that we hold your Personal Information;

(b) to access your Personal Information; or

(c) to correct your Personal Information

you can request this by using the contact details in clause 12.

7.2 We will respond to your request within a reasonable period and within any timeframe specified by the Privacy Legislation. You may make an urgent request to access or correct your Personal Information, which should include the reasons  for the urgency.

7.3 Prior to allowing access to your Personal Information, we may ask you to take steps to verify your identity.

7.4 We will allow you to access your Personal Information unless there is a sound reason not to, including where:

(a) giving access would have an unreasonable impact on the privacy of

others; or

(b) we reasonably consider that your request for access is frivolous or

vexatious; or

(c) it is not permitted under the applicable Privacy Legislation.

7.5 If we refuse to give you access to your information, we will give you a notice setting out our reasons.

7.6 If you believe that information we hold about you is incorrect or out of date, please contact us and we will take all reasonable steps to amend the information in line with your request.

7.7 If the information has been collected on behalf of others (refer to clause 4), we may direct you to contact the relevant party to initiate your request.

 

8. Third party service providers

8.1 Keystone Commons uses some third party service providers (sub-processors) in order to support our websites and operations. These third party service providers can include foreign entities that operate in an overseas jurisdiction.

(a) We select reputable third party service providers on the basis of their published privacy policies.

(b) By using our services and interacting with The Commons, you acknowledge that third party service providers that are foreign entities may not be required to protect your Personal Information in a way that provides comparable safeguards as those provided in the Privacy Legislation.

8.2 Any questions related to our use of third party service providers can be directed to us via the contact details in clause 12.

 

9. Direct marketing

9.1 We only use your Personal Information to let you know about our products or services where we have your consent, or where we are otherwise permitted by law to do so. We may contact you for these purposes in a variety of ways, including by mail, email, SMS or telephone.

9.2 We do not sell your Personal Information to any third party for the purposes of direct marketing.

Where you have consented to receiving marketing communications from us,  your consent remains current until you advise us otherwise. You can opt out at any time, by:

(a) contacting us as set out in clause 12;

(b) advising us if you receive a marketing call that you no longer wish to receive; or

(c) using the unsubscribe facility that we include in our electronic messages (such as emails and SMS).

9.3 We do not use your Sensitive Information (refer to clause 2.4) for the purposes of direct marketing

 

10. Notification of a data breach

10.1 If we become aware of unauthorised access to or loss of your Personal  Information, we will promptly:

(a) notify you;

(b) investigate the cause;

(c) do our best to remedy any consequences; and

(d) tell you what steps we have taken to prevent a reoccurrence.

10.2 Unauthorised access to or unauthorised disclosure of personal information, or a loss of personal information, are handled in accordance with the relevant authority as follows: oaic.gov.au/privacy/notifiable-data-breaches


11. Complaints

11.1 If you have a complaint about how we collect or handle your Personal  Information, please contact us using the contact details in clause 12. We treat any  claims of privacy breaches seriously and will do our best to respond to your complaint within seven days of receiving it.

11.2 If you are unhappy with our response, you can refer your complaint to the Office of the Australian Information Commissioner in Australia or the Office of the Privacy Commissioner in New Zealand


12. How you can contact us

12.1 Please contact us if you have any queries about the Personal Information that we hold about you or the way we handle it.

Our contact details are set out below:

(a) Call us on 0409 559 577 or

(b) Email us on privacy[at]keystonecommons.org.au

(c) Send a letter to us at:

Attention: Privacy Officer Keystone Commons,  2/290 Boundary StreetSpring Hill QLD4000

bottom of page