Privacy Policy
1. Purpose and Applicability
This Policy applies to all the employees and users of the Gaia Resources information security management system, including temporary users, visitors and sub-contractors with limited or unlimited access to Gaia Resources services (including infrastructure, products, information, data or systems). Any person to whom this document applies must comply with the policies described in this document.
2. Exclusions
External providers and clients may be provided this document to indicate the standard of security that is required. Appropriate due diligence in establishing security provisions for external or third party providers is covered under the External Supplier Management Policy GAIA-POL-017.
3. Policy Statement
3.1 Objective
This Policy outlines Gaia Resources has ongoing obligations to you in respect of how we manage your Personal Information
We have adopted the Australian Privacy Principles (APPs) contained in the Privacy Act 1988 (Cth) (Privacy Act). The APPs govern the way in which we collect, use, disclose, store, secure and dispose of your Personal Information.
A copy of the Australian Privacy Principles may be obtained from the website of The Office of the Australian Information Commissioner at OAIC .
3.2 Contents
3.2.1 What is Personal Information and why do we collect it?
Personal Information is information or an opinion that identifies an individual. Examples of Personal Information we collect include:
- Names;
- Addresses;
- Email addresses;
- Phone numbers].
This Personal Information is obtained in many ways [including:
- Job applications;
- Interviews;
- Correspondence;
- Telephone;
- Email;
- Through our website (including contact forms, account registrations and online enquiries);
- Your use of our website and services;
- Social media platforms;
- Cookies and similar tracking technologies;
- Surveys and questionnaires;
- Events;
- Media and publications;
- Other publicly available sources; and
- Third parties
We collect your Personal Information for the primary purpose of providing our services to you. We may also use your Personal Information for secondary purposes closely related to the primary purpose, in circumstances where you would reasonably expect such use or disclosure.
When we collect Personal Information we will, where appropriate and where possible, explain to you why we are collecting the information and how we plan to use it.
3.2.2 Sensitive Information
Sensitive information is defined in the Privacy Act to include information or opinion about such things as an individual's racial or ethnic origin, political opinions, membership of a political association, religious or philosophical beliefs, membership of a trade union or other professional body, criminal record or health information.
Sensitive information will be used by us only:
- For the primary purpose for which it was obtained;
- For a secondary purpose that is directly related to the primary purpose;
- With your consent; or where required or authorised by law.
3.2.3 Third Parties
Where reasonable and practicable to do so, we will collect your Personal Information only from you. However, in some circumstances we may be provided with information by third parties. In such a case we will take reasonable steps to ensure that you are made aware of the information provided to us by the third party.
3.2.4 Disclosure of Personal Information
Your Personal Information may be disclosed in a number of circumstances including the following:
- Third parties where you consent to the use or disclosure; and
- Where required or authorised by law.
3.2.5 Security of Personal Information
Your Personal Information is stored in a manner that reasonably protects it from misuse and loss and from unauthorised access, modification or disclosure.
Your Personal Information is stored and handled using a combination of technical, physical and organisational safeguards, including:
- Personal Information is stored on secure servers and systems protected by firewalls.
- There are role-based access controls so that access is limited to authorised personnel only.
- Access to systems containing Personal Information is protected by unique user credentials, strong passwords, and, where available, multi-factor authentication.
- Physical records (if any) are stored in secure premises with controlled access, and paper files are kept in locked cabinets or secure storage areas.
- Personnel are trained on privacy and information-security requirements and are required to handle Personal Information in accordance with confidentiality and data-protection obligations.
- Where Personal Information is handled by service providers or stored using third-party systems, reasonable steps are taken to ensure those providers maintain appropriate security and confidentiality measures.
- Systems are regularly maintained, updated and monitored to reduce the risk of unauthorised access, data loss or misuse
When your personal information is no longer needed for the purpose for which it was obtained, we will take reasonable steps to destroy or permanently de-identify your personal information. However, most of the personal information is or will be stored in client files which will be kept by us for a minimum of 7 years as per Fair Work Australia 2009 legislation.
During the internal People and Culture teams annual audit, any personal information for clients or employees older than 7 years will be archived or deleted. The decision to either archive or delete will be made by the CEO.
3.2.6 Access to your Personal Information
You may access the Personal Information we hold about you and to update and/or correct it, subject to certain exceptions. If you wish to access your Personal Information, please contact us in writing.
In order to protect your Personal Information we may require identification from you before releasing the requested information.
3.2.7 Maintaining the quality of your Personal Information
It is an important to us that your Personal Information is up to date. We will take reasonable steps to make sure that your Personal Information is accurate, complete and up-to-date.
If you find that the information we have is not up to date or is inaccurate, please advise us as soon as practicable so we can update our records and ensure we can continue to provide quality services to you.
3.2.8 Policy Updates
This Policy may change from time to time and is available.
3.2.9 Privacy Policy Complaints and Enquiries
If you have any queries or complaints about our Privacy Policy please contact [email protected].