Privacy Policy
Ovarian Cancer Australia Privacy Policy
Ovarian Cancer Australia Limited (OCA, we, our, us) respects and is committed to protecting your privacy. OCA is required to comply with the Privacy Act 1988 (Cth) (Privacy Act), including the Australian Privacy Principles (APPs) contained in the Privacy Act, as well as applicable State and Territory based health records legislation.
This Privacy Policy (Policy) sets out how OCA collects, holds, uses, discloses, and keeps your information secure and correct, how to request access to and collection of the personal information we hold about you, and how to make a complaint.
This Policy does not apply to the personal information of our employees.
What is 'personal information'?
‘Personal information’ is any information or opinion about an identified individual or an individual who is reasonably identifiable, whether the information or opinion is true or not.
‘Sensitive information’ is a subset of personal information which includes information about your health, your membership of professional association, religious affiliations or beliefs, criminal record, and racial or ethnic origin.
Because of the nature of our organisation and the support services that we provide, the personal information we collect may include your health or other sensitive information.
What personal information do we collect?
The personal information we collect about you depends on your relationship with us and the nature of any support services that we are providing to you.
Donors and supporters
We may collect the following personal information about you if you are a donor or supporter:
your name and contact details (including email, telephone/mobile number and address);
payment information such as payment method (e.g., cheque, cash, credit card);
for credit card transactions made through secure third-party payment platforms (such as Payments2Us and Raisely), the last 4 digits of the credit card (which are saved for identity confirmation);
the expiry date of your credit card (when a credit card transaction is made);
the amount of your donation(s);
the date of donation(s) and any campaign they relate to; and
the details of any previous donations.
Your personal information is held in Salesforce, a PCI (Payment Card Industry) compliant cloud-based Customer Relationship Management (CRM) platform. We may also collect your personal information from you directly, or from third parties such as GoodCompany, GoFundraise, Benevity, Paypal, PayPal Giving Fund, My Cause, Give Now, GoFundraise, Good2Give & Grassrootz, if you register with them to raise money for OCA.
Job applicants and volunteers
Depending on whether you are a volunteer or a job applicant, we may collect the following personal information about you:
your name and contact details;
your qualifications and skills, past employment history, professional associations, professional registration and details of referees;
details of your previous volunteer work with us; and
a police check which may be required for some roles and volunteer positions.
Those we support
Depending on the nature of the support we are providing to you, we may collect the following personal information about you:
your name and contact details; and date of birth; and
details of your diagnosis including the type and stage of cancer, when you were diagnosed, your doctor’s name and where you are receiving treatment, family history, including where applicable, a summary of nursing, psychology and counselling support received.
Your information is held in Salesforce, a cloud-based CRM platform.
Users of Ovarian Cancer Australia's Facebook Support Groups
If you use our Ovarian Cancer Australia Private Facebook Support Group, or Facebook Support Group for Family, Carers and Friends, we may collect the following personal information about you:
name and contact details; and
posts you make (including any replies and comments).
Others
Depending on the nature of our interactions with you, we may collect the following personal information about you:
name and contact details;
date and stage of diagnosis;
health professional details;
details of the nature of your relationship with OCA; and
details of your enquiry or complaint.
Dealing with us anonymously or using a pseudonym
You may deal with us anonymously or by using a pseudonym, wherever it is lawful and practical to do so. Donors can choose to make donations anonymously; however, if you are paying by credit card, we will need to collect some personal information in order to be able to process your donation.
Website and cookies policy
Our website uses cookies to improve our website. Cookies are small files that store information on your computer, mobile phone, or another device. They enable the entity that put the cookie on your device to recognise you across different websites, services, devices and/or browsing sessions. The information that we collect via cookies is not personal information and we are not able to identify you from it. You can disable cookies through your internet browser, but if you do, our website may not work as intended for you.
How do we use and disclose your personal information?
How we use and disclose your personal information also depends on your relationship with us and the nature of any support services that we are providing to you.
Donors and supporters – we use your personal information for the purposes of processing your donation, financial reporting, and contacting you about our activities and events unless you have opted out of such communications. If you have chosen to make a public donation, then we may disclose your name and the amount of the donation on our website for as long as the fundraising campaign continues (which will vary by campaign). If you do not wish to have your information displayed, you can opt to make an anonymous donation. We do not share donor or supporter information with any third parties.
Job applicants and volunteers – we use your personal information to process your job or volunteer application, and if you are a volunteer, for management and HR purposes. We do not disclose your personal information to any third parties without your consent. In the event of a job application, your information may be shared with OCA’s preferred recruitment agencies.
Those we support – we use your personal information to provide you with our services as a person affected by cancer or as a family member receiving support from OCA, as well as to ensure the consistent provision of our services. We do not disclose your personal information to any third parties. Patient information is never distributed. In the event of a medical or mental health emergency your personal information may be disclosed to relevant third parties to ensure you receive appropriate and timely support.
Users of Ovarian Cancer Australia’s Facebook Groups – you should be aware that, when using OCA’s Private Facebook Groups, your username and profile picture and any posts you make will be visible to the general public. Should you wish to protect your identity you should choose a username and profile picture that does not reveal your identity and should also keep in mind when posting that your posts will be viewable to the public.
Others – depending on the nature of your relationship with us, we may use your personal information to respond to your enquiry or complaint, provide you with our publications, send you surveys, or contact you with information regarding our activities, events or services.
We use some third-party service providers located overseas however all our data is hosted in Australia.
We may also disclose your personal information where required or authorised by or under an Australian law, or court or tribunal order, or where otherwise legally permitted.
Direct marketing
If you have asked to receive information from us about our activities and events, we may contact you via post, phone and/or email. You can opt-out of receiving such communications from us at any time by contacting us on 1300 660 334 / admin@ovariancancer.net.au or by going to the ‘Contact Us’ section of the OCA website.
How do we store your personal information and keep it secure?
We understand the importance of the personal information that we hold, and we take reasonable steps to protect that personal information from misuse, interference, and loss, and from unauthorised access, modification, or disclosure.
Your personal information may be stored in electronic format on Salesforce, a cloud-based PCI compliant database hosted in Australia. Access to Salesforce is restricted to those within our organisation who require it to carry out their role with OCA.
If you have completed a paper donation form and mailed it back to us, we will securely store the information for a period of one month for any queries, after which time it will be securely destroyed.
Health records
If the information that we hold about you forms part of a health or medical record that we hold as your health service provider, that information will be held for a period of at least seven (7) years from the last time we provided you with a health service, in accordance with the Victorian Health Records Act 2001 (Vic) or other applicable laws. If the health record is that of someone under the age of 18, that information will be held at least until that person turns 25.
How can you access your personal information?
If you wish to access personal information that we hold about you, please email support@ovariancancer.net.au. We will need to verify your identity before we can provide you with access. In some circumstances we can refuse access, for example, where providing you with access would unreasonably impact the privacy of others, or if we are required or authorised by law to deny access. If we refuse your access request, we will give you written notice of our decision, including our reasons (unless providing reasons would have an unreasonable impact on us or third parties) and how to complain if you are not satisfied with our decision.
Quality and correction of personal information
OCA takes reasonable steps to ensure that the personal information it collects about you is accurate, up-to-date, and complete, and also when using and disclosing it, that it is relevant for the purposes of the use or disclosure. If we are satisfied that any of the information should be corrected we will take reasonable steps to correct it.
If you believe that the personal information that we hold about you is inaccurate, incomplete, out-of-date, irrelevant, or misleading, please let us know by contacting us on admin@ovariancancer.net.au. There is no charge for making a correction request.
Privacy queries and complaints
If you have any questions about your privacy, or if you believe that OCA has not handled your personal information in accordance with this Policy or with applicable privacy laws, please contact our Privacy Officer at the details below and provide us with written details of your complaint:
The Privacy Officer
Ovarian Cancer Australia
Level 1, 210 Lonsdale Street
Melbourne VIC 3000
Phone: (03) 9289 9777
Email: admin@ovariancancer.net.au
We will investigate and respond to your complaint within a reasonable period, generally within 30 days. Sometimes we may need to request more information from you, and we may also propose a resolution to your complaint.
If you are not satisfied with our response, you can contact the OAIC (www.oaic.gov.au) or the regulator of health records legislation in your jurisdiction. In Victoria this is the Health Complaints Commissioner (https://hcc.vic.gov.au/).
Changes to our Policy
OCA may, from time to time, update or change this Policy to ensure that it reflects the acts and practices of our organisation as well as any changes in applicable law. Any changes to the Policy will take effect from the time that the amended Policy is posted on our website at https://ovariancancer.net.au/.
Last updated: 8 November 2024