The Reframe Foundation
Privacy Policy
The Reframe Foundation Ltd (“we”, “us”, “our”) is committed to protecting the privacy and security of personal information in our possession. This Privacy Policy explains how we collect, use, disclose, store, and manage personal and sensitive information.
01 Introduction
We handle personal and sensitive information in accordance with:
- The Privacy Act 1988 (Cth), including the Notifiable Data Breaches scheme;
- The Information Privacy Act 2009 (Qld), for Queensland activities; and
- Any applicable state or territory health records legislation.
02 What Information We Collect
We may collect the following categories of personal information, depending on our interaction with you:
- Identity & contact details: name, address, email, phone number;
- Demographic data: date of birth, gender, language, cultural background;
- Professional details: employer, role, qualifications, areas of expertise;
- Financial & donation records: donation amounts, payment method, invoicing details;
- Service-related information: feedback, complaints, safeguarding incident reports;
- Health & sensitive data: health or therapeutic information, and Working With Children Check numbers, where required for safeguarding;
- Technical data: IP address, device and browser information, and usage statistics when you visit our website.
03 How We Use and Disclose Your Information
We will use personal information only for purposes directly related to our mission and operations, such as:
- Delivering programs, services, and resources;
- Processing donations, grants, sponsorships, and issuing receipts;
- Managing employment, contractor, and volunteer relationships;
- Responding to enquiries, complaints, or safeguarding concerns;
- Meeting our legal and regulatory obligations (e.g. ACNC and ASIC reporting);
- Communicating news, updates, and invitations to events or training; and
- Conducting research, evaluation, and quality improvement.
We will not sell, rent, or trade your personal information. We may disclose your information to:
- Service providers: third-party IT, payment, or event-management platforms, under strict confidentiality obligations;
- Regulators: ACNC, ASIC, ATO, or other government bodies when required by law;
- Professional advisers: legal, accounting, or audit firms for compliance purposes; and
- Safeguarding authorities: police, child protection, or health agencies where required under law.
04 Cross-Border Disclosure
We will not send personal information outside Australia unless:
- We have your consent;
- The recipient is subject to laws or binding arrangements offering similar privacy protections; or
- It is otherwise permitted by law.
05 Data Storage and Security
We take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access or disclosure. These include:
- Secure, access-controlled electronic systems;
- Encryption of sensitive data in transit and at rest;
- Regular security audits and staff training; and
- Physical security measures for any hard-copy records.
06 Notifiable Data Breaches
If a data breach occurs that is likely to result in serious harm to any individual, we will comply with our obligations under the Notifiable Data Breaches scheme by:
- Conducting a prompt assessment;
- Notifying affected individuals as soon as practicable; and
- Lodging a report with the Office of the Australian Information Commissioner (OAIC).
07 Access and Correction
You have the right to:
- Access the personal information we hold about you; and
- Request correction of any inaccurate information.
To do so, contact our Company Secretary (details below). We will respond within 30 days and, if we refuse access or correction, provide reasons and review options.
08 Retention and Disposal
We retain personal information only as long as necessary for the purpose it was collected, or as required by law. Once no longer needed, we will securely destroy or de-identify the information.
09 Complaints and Inquiries
If you believe we have breached this Privacy Policy or the Privacy Act, please contact us (details below). We will investigate and respond within 30 days. If you remain dissatisfied, you may lodge a complaint with the OAIC or the Queensland Office of the Information Commissioner (OIC).
10 Policy Review and Updates
This Privacy Policy will be reviewed by the Board at least annually or when legislative changes occur. The latest version will be published on our website.
11 Contact Details
Company Secretary
The Reframe Foundation Ltd
2/290 Boundary Street, Spring Hill, QLD 4000
Email: admin@reframe.org.au