WEBSITE AND DATA COLLECTION PRIVACY POLICY
This Privacy Policy applies to all personal information collected by Small Business Network (we, us or our) via the website located at www.smallbusinessnetwork.org.au (Website).
1. What information do we collect?
The kind of Personal Information that we collect from you will depend on how you use the website. The Personal Information which we collect and hold about you may include:
We collect some or all of the following personal information from website users and program participants: full name, email address, phone number, business name, ABN/ACN, postal address, business location and region, industry sector, business size and structure, program enrolment details, attendance records, business advisory session notes, payment and billing information, website usage data including IP addresses and cookies, communication preferences, and any other information voluntarily provided through our online programs or advisory services.
2. Types of information
The Privacy Act 1998 (Cth) (Privacy Act) defines types of information, including Personal Information and Sensitive Information.
Personal Information means information or an opinion about an identified individual or an individual who is reasonably identifiable:
- (a) whether the information or opinion is true or not; and
- (b) whether the information or opinion is recorded in a material form or not.
If the information does not disclose your identity or enable your identity to be ascertained, it will in most cases not be classified as “Personal Information” and will not be subject to this privacy policy.
Sensitive Information is defined in the Privacy Act as including information or opinion about such things as an individual's racial or ethnic origin, political opinions, membership of a political association, religious or philosophical beliefs, membership of a trade union or other professional body, criminal record or health information.
Sensitive Information will be used by us only:
- (a) for the primary purpose for which it was obtained;
- (b) for a secondary purpose that is directly related to the primary purpose; and
- (c) with your consent or where required or authorised by law.
3. How we collect your Personal Information
- (a) We may collect Personal Information from you whenever you input such information into the Website, related app or provide it to Us in any other way.
- (b) We may also collect cookies from your computer which enable us to tell when you use the Website and also to help customise your Website experience. As a general rule, however, it is not possible to identify you personally from our use of cookies.
- (c) We generally don’t collect Sensitive Information, but when we do, we will comply with the preceding paragraph.
- (d) Where Sensitive Information is inadvertently collected during business advisory sessions, we will promptly identify and segregate such information, obtain your explicit written consent before any use or disclosure, apply enhanced access controls and stricter retention limits, and notify you immediately in the event of any unauthorised access or breach.
- (e) Where reasonable and practicable we collect your Personal Information from you only. However, sometimes we may be given information from a third party, in cases like this we will take steps to make you aware of the information that was provided by a third party.
4. Purpose of collection
- (a) We collect Personal Information to provide you with the best service experience possible on the Website and keep in touch with you about developments in our business.
- (b) We customarily only disclose Personal Information to our service providers who assist us in operating the Website. Your Personal Information may also be exposed from time to time to maintenance and support personnel acting in the normal course of their duties.
- (c) We require all service providers who handle Personal Information to execute Data Processing Agreements that incorporate Privacy Act compliance obligations, confidentiality requirements, and security standards equivalent to our own. We maintain audit rights to verify compliance, require incident notification within [HOURS] of detection, and ensure appropriate liability allocation through indemnification provisions for third-party breaches.
- (d) We will not disclose your Personal Information to overseas recipients unless we have obtained your express consent or are satisfied that the recipient is subject to substantially similar privacy protections as those under Australian law. Where overseas disclosure is necessary for service delivery, we ensure appropriate cross-border data transfer mechanisms are in place, including standard contractual clauses and verification of adequate data protection frameworks in the recipient jurisdiction.
- (e) By using our Website, you consent to the receipt of direct marketing material. We will only use your Personal Information for this purpose if we have collected such information direct from you, and if it is material of a type which you would reasonably expect to receive from use. We do not use sensitive Personal Information in direct marketing activity. Our direct marketing material will include a simple means by which you can request not to receive further communications of this nature, such as an unsubscribe button link.
5. Security, Access and correction
- (a) We store your Personal Information in a way that reasonably protects it from unauthorised access, misuse, modification or disclosure. When we no longer require your Personal Information for the purpose for which we obtained in, we will take reasonable steps to destroy and anonymise or de-identify it. Most of the Personal Information that is stored in our client files and records will be kept for a maximum of years to fulfill our record keeping obligations.
- (b) The Australian Privacy Principles:
- permit you to obtain access to the Personal Information we hold about you in certain circumstances (Australian Privacy Principle 12); and
- allow you to correct inaccurate Personal Information subject to certain exceptions (Australian Privacy Principle 13).
- (c) Where you would like to obtain such access, please contact us in writing on the contact details set out at the bottom of this privacy policy.
- (d) We will retain Personal Information for [7] years for client files and business advisory records to fulfill our record-keeping obligations under applicable tax and corporate governance legislation, and for [2] years for website analytics and general enquiry data. Personal Information subject to legal holds, ongoing disputes, or regulatory investigations will be retained until such matters are resolved, after which standard retention periods will apply.
- (e) We will conduct periodic reviews of stored Personal Information at least annually to identify and securely dispose of data that has exceeded its retention period, unless retention is required for legal proceedings, regulatory investigations, or ongoing disputes. You will be notified in writing if your Personal Information is subject to extended retention due to such circumstances.
- (f) We implement industry-standard security measures to protect your Personal Information, including encryption for data in transit and at rest, role-based access controls limiting employee access to necessary information, multi-factor authentication for administrative access, regular security assessments and penetration testing, and comprehensive audit logs of data access and modifications. We maintain a documented information security policy addressing physical, technical, and organisational safeguards aligned with the Australian Government Information Security Manual (ISM) standards, and have established incident response procedures to address any data breaches in accordance with our notification obligations under the Privacy Act.
6. Complaint procedure
If you have a complaint concerning the manner in which we maintain the privacy of your Personal Information, please contact us as on the contact details set out below in Section 8 of this policy. All complaints will be considered by the Chief Executive Officer and we may seek further information from you to clarify your concerns. If we agree that your complaint is well founded, we will, in consultation with you, take appropriate steps to rectify the problem. If you remain dissatisfied with the outcome, you may refer the matter to the Office of the Australian Information Commissioner.
7. Overseas transfer
Your Personal Information will not be disclosed to recipients outside Australia unless you expressly request us to do so. If you request us to transfer your Personal Information to an overseas recipient, the overseas recipient will not be required to comply with the Australian Privacy Principles and we will not be liable for any mishandling of your information in such circumstances.
8. How to contact us about privacy
If you have any queries, or if you seek access to your Personal Information, or if you have a complaint about our privacy practices, you can contact us through: support@smallbusinessnetwork.org.au.
9. Complaint handling timeframes and process
We will acknowledge your complaint within [5] business days of receipt. We will investigate and provide a written response within [30] days, including our findings and any remedial action taken. If your complaint requires extended investigation, we will provide interim updates every [14] days. If you remain dissatisfied after receiving our response, you may request escalation to our senior management team within [14] days, and we will provide a final determination within a further [15] days before you refer the matter to the Office of the Australian Information Commissioner.
10. Data breach notification procedures
We maintain documented procedures for detecting, investigating, and responding to data breaches. Upon discovery of an eligible data breach likely to result in serious harm, we will notify affected individuals without unreasonable delay, typically within [30] days. Notifications will include the nature of the breach, types of personal information involved, steps individuals should take to protect themselves, and contact details for further information. We will simultaneously notify the Office of the Australian Information Commissioner if the breach is likely to result in serious harm to any individual.
