Hello Sunday Morning Privacy Statement

    1. Introduction

    Hello Sunday Morning (ABN 82 145 512 125) is a not-for-profit organisation that supports people to change their relationship with alcohol. We are committed to protecting your personal and sensitive information in accordance with the Privacy Act 1988 (Cth) (including amendments introduced under the Privacy and Other Legislation Amendment Act 2024), the Australian Privacy Principles (APPs), and where applicable, the Health Records Act 2001 (Vic).

    This policy explains how we collect, use, disclose, store, and secure personal information across all our services including Daybreak, Hello Change, Drink Tracker, My Drink Check, our newsletter and donor activities.

    2. What We Collect

    We may collect the following types of personal information:

    Donors and Supporters

    • Full name, contact details, and billing information
    • Donation history and communications

    Service Users

    • Registration details (e.g. name, email)
    • Program usage data (e.g. app activity, journal entries)
    • Survey and feedback responses
    • Sensitive health data (e.g. wellbeing scores, alcohol consumption)

    Staff, Volunteers, Board Members

    • Employment history and qualifications
    • Contact information and identity documentation

    We may also collect device information (e.g. IP address, geo-location, web log data) when you interact with our website.

    3. Sensitive Information

    We only collect sensitive information, such as health data or demographic characteristics, with your consent or where legally required. This includes information gathered for research, program evaluation, or service delivery.

    You can interact anonymously or using a pseudonym; however, this may limit our ability to respond or provide certain services.

    4. How We Collect Information

    We collect information:

    • Directly from you (e.g. sign-up forms, surveys, emails, donations)
    • Automatically through cookies and website analytics
    • Via third-party platforms (e.g. Qualtrics, Stripe, Google Analytics)

    We also implement strict controls to prevent the re-identification of de-identified data by ensuring that no identifiable markers are retained, access to datasets is restricted and data is only shared in aggregated or anonymised formats.

    5. Use of Personal Information

    We use personal information to:

    • Deliver our services and improve user experience
    • Communicate with you about updates, programs, or campaigns
    • Process and acknowledge donations
    • Conduct research and evaluations (de-identified data only unless consented)
    • Meet legal and funding obligations

    You can opt out of communications at any time.

    6. Disclosure to Third Parties

    We do not sell personal information. We may share your information with:

    • Approved contractors and providers supporting our IT, payroll, marketing or research services
    • Government agencies where required by law
    • Ethics-approved research partners (de-identified unless consented)

    All external parties are contractually required to maintain privacy safeguards.

    7. Overseas Disclosure

    Some third-party services we use (e.g. Qualtrics, Stripe) may store or process information outside Australia. Where this occurs, we:

    • Select vendors with equivalent data protection standards
    • Ensure contractual privacy protections are in place
    • Limit personal data exported and restrict access to authorised personnel

    8. Storage and Security

    We take reasonable steps to ensure your information is safe:

    • Data is encrypted in transit and at rest
    • Stored in secure servers located in Australia or equivalent jurisdictions
    • Access limited to staff on a need-to-know basis

    Personal data is retained only for as long as necessary and is securely destroyed or de-identified when no longer needed. Users will be notified in advance and where applicable, given an opportunity to download or transfer their data.

    When retiring a system, Hello Sunday Morning will take reasonable steps to migrate data to a new system where feasible, ensuring continuity and accessibility while maintaining security and privacy standards.

    9. Access, Correction and Transparency

    You can request access to or correction of your personal data by emailing info@hellosundaymorning.org. We will verify your identity and respond within 30 days.

    Under current legislation, you can also request information about how your data has been handled or used.

    10. Research and Evaluation

    We use de-identified data to evaluate the impact of our services. You may be invited to participate in surveys, interviews or studies. Participation is voluntary and opt-in. All research is reviewed by an independent ethics committee.

    11. Complaints and Enquiries

    If you have a privacy concern:

    If you are unsatisfied with our response you can contact:

    • Office of the Australian Information Commissioner (OAIC) – oaic.gov.au
    • Office of the Victorian Information Commissioner (OVIC) – ovic.vic.gov.au (if applicable)

    12. Related Policies

    • Partnering with Consumers Policy
    • Complaints Policy
    • Research and Evaluation Policy

    This policy is aligned with IPP 5 and is available in alternative formats upon request. For more information or assistance, please email privacy@hellosundaymorning.org.

    This policy applies from 1st April 2025.