top of page

Privacy statement

This statement explains how the Digital Health Standards Council of Australasia (DHSCA) handles your personal information. It applies to www.dhsca.com.au and to any email you send us through the website.

 

DHSCA is operated by DHSCA Pty Ltd and the trustee for the Shearwater Family Trust, ABN 65 697 609 804. In this statement, "we", "us" and "our" mean DHSCA.

We follow the Australian Privacy Principles in the Privacy Act 1988 (Cth). You can read the Australian Privacy Principles on the website of the Office of the Australian Information Commissioner at www.oaic.gov.au.  Other applicable privacy laws include the Health Records and Information Privacy Act 2002 (NSW) and other laws which protect the privacy of personal information (including health information) in New South Wales. 

The short version:

  • We are serious about privacy. This includes ensuring that any information you trust us to hold is kept private and only for the purposes of providing a service to you.

  • By deliberate design, we only ever collect the minimal amount of information that lets us provide a service to you.

  • We never sell, rent, trade or share your personal information with a third party for that party’s own use.

  • You can opt out at any time. Every email we send has an unsubscribe link.

  • You can ask us what we hold about you. We tell you, and we correct it or delete it if you ask.

  • One email address reaches a DHSCA representative who can act on all of this.

 

We only collect the minimum

We only collect information that we need to give you a service. We do not collect information because it might be useful later. If we can answer you without a specific piece of information or data, we do not ask for it - ever.

The website collects personal information in two places.

 

The enquiry form. We collect your name, your email address and the content of your message. Your organisation and phone number is optional. We use these details to contact you and answer your request to us. 

The mailing list. We collect your email address, and your name if you give it. We use these details to send you the updates that you asked for.

 

We do not ask you for health information. We do not ask you for any other sensitive information as the Privacy Act defines it. Please do not send us health information or sensitive information through the website. If you send it to us, we protect it under this statement and we delete it once due diligence is performed to contact you regarding its submission to us.

 

We do not use advertising cookies. We do not use tracking cookies. We do not build a profile of you from the pages that you read.

You can read the website without giving us any personal information.

 

We do not share your information

We never sell your personal information. We never rent it. We never trade it. We never give it to a data broker, an advertising network, a marketing company or a partner organisation. Your personal information is not ours to sell, and we never engage in that practice. 

There are only two situations where your information leaves DHSCA.

  • You tell us to. For example, you ask us to introduce you to another organisation. We act only on your instruction, and only for what you asked.

  • The law requires it. A court order, a subpoena or a lawful request from a regulator can compel us to disclose information. We tell you when this happens, unless the law stops us from doing it. 

 

We do not send your personal information overseas for our own purposes. The only exception is the supplier arrangement below.

 

The suppliers that run our website and our email hosting

We use a small number of suppliers to host the website and to send email. They hold your information only so that the service works. Our contracts and their terms stop them from using your information for their own purposes. They are not permitted to sell it or to share it.

 

Our website host is wix.com, and our email platform is Microsoft Outlook, integrated via Wix and MailChimp for automated responses.

 

We only choose suppliers that store data in Australia. In future instances where we need data to be exchanged overseas, we check that it protects the information to a standard that meets the Australian Privacy Principles, and we commit to updating our clients via a declaration, and on this website. 

How to opt out

You can stop hearing from us at any time. You have three ways to do it.

  • Select the unsubscribe link at the bottom of any email that we send. This takes effect straight away.

  • Email us at contact@dhsca.org.au and ask us to remove you. We will remove you as soon as possible, and always within five business days.

  • Write to us at the postal address at the end of this statement.

 

You do not have to give us a reason. If you opt out of the mailing list, we keep only the record that we need to make sure that we do not contact you again.

If you send us an enquiry, we do not add you to the mailing list. You join the mailing list only when you ask to join it.

How to see what we hold

Send an email to contact@dhsca.org.au and ask for a copy of your information. We reply within 30 days.

We do not charge a fee for this. We ask you for proof of identity first, so that we do not give your information to somebody else.

 

You can also ask us to:

  • correct information that is wrong or out of date;

  • delete information that we hold about you; or

  • explain where a piece of information came from.

 

We delete your information when you ask, unless the law requires us to keep it. If we cannot delete something, we tell you which record it is and why we must keep it.

 

How we keep your information safe

We store your information in systems that need a password and multi factor authentication. Only the people who need the information can open it. Our team is small, and the list of people with access is short. Subcontractors are never given access to your information, unless you agree to it being shared for the purpose of delivering you a service. 

We delete information when we no longer need it. We delete enquiry records 24 months after we close the enquiry. We keep mailing list records until you unsubscribe.

 

If a data breach puts you at risk of serious harm, we tell you and we tell the Office of the Australian Information Commissioner. We follow the Notifiable Data Breaches scheme in the Privacy Act.

Links to other websites

Our website links to other websites. We do not control those websites, and this statement does not apply to them. Read the privacy statement of a website before you give it your information.

Changes to this statement

We update this statement when our practice changes. The current version is always on our website. The version number and the effective date are at the top of this page. We do not apply a change to information that we already hold in a way that reduces your rights.

 

Contact us

One person is accountable for privacy at DHSCA. Contact them with a question, a request or a complaint.

Who: Chris Boyd-Skinner, CEO and Privacy Officer

Contact: ceo@dhsca.org.au

 

If you are not satisfied

Tell us first. We investigate your complaint and we reply as quickly as possible, and always within 30 days. We tell you what we found and what we did.

 

If our answer does not satisfy you, we encourage you to complain by sharing your experience to the Office of the Australian Information Commissioner.

  • Website: www.oaic.gov.au

  • Phone: 1300 363 992

  • Post: GPO Box 5218, Sydney NSW 2001

bottom of page