Privacy Policy

We respect the trust you place in us when sharing your personal information and are committed to protecting your privacy and complying with our obligations under the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs) and other applicable privacy legislation.

As a charitable organisation, we hold personal information about diverse stakeholders including donors, beneficiaries of funded programs, staff, volunteers, service partners and members of the public. This information is essential for fulfilling our charitable purpose, maintaining relationships and meeting legal obligations.

This policy details what personal information we collect and hold, how that information will be collected, held and used, including how we protect and manage personal information.

What This Policy Covers

This policy covers all personal information held by the Foundation, regardless of format, including information about:

  • Donors and supporters
  • Beneficiaries of funded programs (where applicable)
  • Staff, prospective employees, and former employees
  • Volunteers and prospective volunteers
  • Board members and committee members
  • Service partners and their personnel
  • Suppliers, contractors and service providers
  • Event attendees and participants
  • Website visitors and subscribers
  • Members of the public who contact the Foundation

Our Privacy Commitment

Martin Youth Foundation is committed to handling personal information in a manner that:

  • Respects Individual Rights
  • Is Transparent and Accountable
  • Collects Only What Is Necessary
  • Uses Information Appropriately
  • Protects Information Security
  • Ensures Data Quality
  • Supports Access and Correction
  • Protects Vulnerable People

Personal Information We Collect

The Foundation collects different types of personal information depending on the nature of the relationship:

From Donors, Supporters, Subscribers, Event Attendees and other members of the public who contact us:

  • Name, title, and contact details (address, phone, email)
  • Donation history and payment information
  • Communication preferences
  • Relationship information (connections to the Foundation)
  • Survey responses and other information you might choose to share with us
  • Event attendance and engagement history

From Service Partners and Suppliers:

  • Business contact details
  • Banking and payment information
  • Contract and agreement records

From Program Beneficiaries:

  • Aggregated and de-identified data for reporting and evaluation
  • Case studies or testimonials (with explicit consent)
  • Consent records for any personal information shared

How We Collect Information

The Foundation collects personal information through:

  • Direct interactions with you (donations, enquiries, event registrations)
  • Online forms and website interactions
  • Telephone and email communications
  • Paper-based forms and correspondence
  • Third-party referrals (with appropriate consent or authority)
  • Service partner reports (de-identified or with consent)
  • Publicly available sources (for donor research)

Consent and Notification

When collecting personal information, we:

  • Inform individuals about the purpose of collection
  • Explain how the information will be used and disclosed
  • Identify types of third parties to whom information may be disclosed
  • Advise how individuals can access and correct their information
  • Provide contact details for privacy enquiries

This notification is provided through privacy statements on forms, our website privacy notice and verbal explanations where appropriate.

Sensitive Information

The Foundation generally does not collect sensitive information unless:

  • Required by law (e.g., working with children checks)
  • Necessary for the Foundation’s charitable purposes
  • The individual has provided explicit consent
  • The information is de-identified

Where sensitive information is collected, enhanced security measures apply.

Unsolicited Information

If the Foundation receives personal information it did not request (unsolicited information), we will:

  • Determine whether we could have collected it under APP 3
  • If yes, handle it in accordance with this policy
  • If no, destroy or de-identify the information as soon as practicable (unless legally required to retain it)

Use and Disclosure of Personal Information

The Foundation uses personal information for the primary purpose for which it was collected, including:

  • Processing and acknowledging donations
  • Maintaining donor relationships and stewardship
  • Delivering Foundation programs and services
  • Communicating about Foundation activities and impact
  • Conducting fundraising activities including appeals, campaigns and events
  • Undertaking analysis, modelling and research to inform our fundraising activities
  • Meeting legal and regulatory obligations

Personal information may be used for secondary purposes where:

  • The secondary purpose is related to the primary purpose (or directly related, in the case of sensitive information), and the individual would reasonably expect such use
  • The individual has consented
  • Permitted or required by law
  • Necessary to prevent a serious threat to health or safety
  • Required for enforcement activities by a law enforcement body

The Foundation may disclose personal information to third parties such as:

  • Service providers supporting Foundation operations (e.g. IT support, payment processors, mail houses)
  • Professional advisors (accountants, lawyers, auditors)
  • Government and regulatory bodies where required
  • Service partners (limited, de-identified information for reporting)
  • Other charities (only with donor consent)

All third-party disclosures are subject to appropriate confidentiality agreements and privacy safeguards.

The Foundation will not:

  • Sell, rent, or trade personal information
  • Disclose donor information to other charities without consent
  • Share sensitive information about program beneficiaries without explicit consent and clear necessity
  • Provide personal information in response to informal requests without verification

Ensuring Accuracy

The Foundation takes reasonable steps to ensure that personal information is:

  • Accurate and not misleading
  • Complete for the purpose for which it is used
  • Up to date

We maintain data quality by:

  • Verifying information at the point of collection where possible
  • Providing opportunities for individuals to update their information
  • Regularly reviewing and cleansing databases
  • Training staff on accurate data entry
  • Encouraging individuals to notify us of changes

Individual Responsibility

Individuals are encouraged to ensure that the personal information they provide is accurate and complete, and to notify us of any changes.

Data Security

The Foundation implements appropriate physical, technical and administrative measures to protect personal information from:

  • Misuse, interference and loss
  • Unauthorised access, modification or disclosure
  • Accidental or unlawful destruction

Security Measures

Security measures are employed by the Foundation to protect personal information.

Physical Security:

  • Secure premises with controlled access
  • Locked storage for paper records containing personal information
  • Clear desk policies
  • Secure destruction of physical documents

Technical Security:

  • Password protection and access controls
  • Encryption of sensitive data
  • Secure networks and firewalls
  • Regular software updates and security patches
  • Secure cloud-based systems with appropriate provider agreements
  • Multi-factor authentication where appropriate

Administrative Security:

  • Access limited to personnel who need information for their role
  • Confidentiality agreements for staff, volunteers and contractors
  • Privacy and security training
  • Incident response procedures
  • Regular security reviews

Storage of Personal Information

Personal information is stored in Foundation systems including:

  • Customer Relationship Management (CRM) database
  • Financial and accounting systems
  • Email and collaboration platforms
  • Secure file storage

All systems are subject to the Foundation’s IT and Cyber Security Policy.

Your Right to Access

Individuals have the right to request access to the personal information the Foundation holds about them. This right is subject to limited exceptions under the Privacy Act.

Access requests should be made in writing to the Privacy Officer (CEO) at:

Email: [email protected]

Mail: Martin Youth Foundation, GPO Box 69, Sydney NSW 2001

Phone: 1300 951 009

The request should include sufficient detail to identify the individual and the information sought.

The Foundation will:

  • Respond to access requests within 30 days
  • Verify the identity of the requester before providing information
  • Provide access in the format requested, where reasonable and practicable
  • Not charge excessive fees for providing access

Access may be refused where:

  • Providing access would pose a serious threat to health or safety
  • Providing access would unreasonably impact the privacy of others
  • The request is frivolous or vexatious
  • Legal proceedings are underway and the information would be privileged
  • Providing access would prejudice enforcement activities
  • Denying access is required or authorised by law

If access is refused, the Foundation will provide written reasons (unless doing so would be unreasonable) and advise of complaint mechanisms.

Your Right to Correct

Individuals may request correction of personal information that is inaccurate, out-of-date, incomplete, irrelevant, or misleading.

Correction requests should be made in writing to the Privacy Officer, with sufficient detail to identify the information requiring correction and the correction requested.

The Foundation will:

  • Respond within 30 days to correction requests
  • Correct information where satisfied it is inaccurate, out-of-date, incomplete, irrelevant or misleading
  • Not charge for making corrections
  • Notify third parties of corrections where appropriate and practicable

If the Foundation refuses to correct information, we will provide written reasons and advise of complaint mechanisms. Individuals may request that a statement be associated with the information noting their view that it is inaccurate or incomplete.

Data Retention and Destruction

The Foundation retains personal information only for as long as necessary to:

  • Fulfil the purposes for which it was collected
  • Meet legal and regulatory requirements
  • Support legitimate business purposes

Data is held for varying retention periods depending on the type of information and in compliance with the relevant legislation.

Secure Destruction

When personal information is no longer required, the Foundation will:

  • Securely destroy or permanently de-identify the information
  • Use appropriate destruction methods (e.g. cross-cut shredding, secure digital deletion)
  • Engage secure destruction services for large volumes or sensitive materials
  • Maintain destruction logs where appropriate

Third Parties

The Foundation engages third-party service providers who may access personal information on our behalf, including:

  • IT and cloud service providers
  • Payment processors and banking services
  • Mail houses and communication service providers
  • Event management platforms
  • Professional advisors

Before engaging service providers with access to personal information, the Foundation:

  • Assesses their privacy and security practices
  • Ensures contractual obligations to protect personal information
  • Requires compliance with Australian privacy laws or equivalent standards
  • Limits access to information necessary for the service

Service Partners

The Foundation funds services delivered by partner organisations. Service Partner relationships are governed by funding agreements that include:

  • Clear data handling responsibilities
  • De-identification requirements for reporting
  • Consent requirements for any personal information sharing
  • Confidentiality obligations

The Foundation does not receive identifiable personal information about individual program beneficiaries unless explicit consent has been obtained for specific purposes (such as testimonials or case studies).

Cross-Border Disclosure

The Foundation generally does not disclose personal information to overseas recipients. Our operations are based in Australia, and we use Australian-based service providers where possible.

Cross-border disclosure may occur in limited circumstances, such as:

  • Use of cloud services with overseas data storage, including in United Kingdom, United States and Singapore
  • Communication with international supporters or partners
  • Global payment processing networks

Before disclosing personal information overseas, the Foundation takes reasonable steps to ensure the overseas recipient:

  • Complies with the Australian Privacy Principles, or
  • Is bound by a substantially similar privacy regime, or
  • Has provided consent to handling under a less protective regime (after being informed of the implications)

Data Breach Management

The Foundation is committed to responding promptly and effectively to data breaches to minimise harm and maintain trust.

The Foundation’s data breach response follows our Incident and Breach Management Policy and includes:

Contain: Stop the breach, recover information, if possible, restrict access

Assess: Determine the nature and extent of the breach, identify affected individuals, assess the risk of harm

Notify: Where required, notify the OAIC and affected individuals

Prevent: Review and implement improvements to prevent recurrence

Special Considerations for Children and Vulnerable Young People

The Foundation funds programs supporting young Australians aged 12–25 experiencing drug and alcohol addiction. We recognise the heightened importance of protecting information about these individuals and apply enhanced protections and processes when handling such information.

The Foundation does not directly collect personal information from children. Where information about children or young people is received (such as in program reporting), it is subject to the highest level of protection and is handled in compliance with child safety frameworks.

Direct Marketing and Fundraising

As a charitable foundation, direct marketing (including fundraising campaigns, appeals and other communications) is essential to our mission. We are committed to conducting these activities responsibly and in compliance with privacy laws.

Our direct marketing activities comply with:

  • The Australian Privacy Principles (APP 7)
  • The Spam Act 2003 (electronic communications)
  • The Do Not Call Register Act 2006 (telemarketing)
  • The Charitable Fundraising Act 1991 (NSW) and equivalent state legislation

Consent and Opt-Out

The Foundation:

  • Provides a simple opt-out mechanism in all marketing communications
  • Honours opt-out requests promptly (within 5 business days for electronic, 30 days for mail)
  • Does not send electronic marketing without consent or an existing relationship
  • Maintains suppression lists to ensure preferences are respected

Your Privacy Choices

You may choose to:

  • Remain anonymous in public recognition (honour boards, reports)
  • Limit the types of communications you receive
  • Opt-out of all marketing while maintaining transactional communications
  • Request that your information not be used for donor research

We record and respect your preferences.

Privacy Complaints

The Foundation takes privacy complaints seriously and is committed to resolving them fairly and promptly.

Privacy complaints should be directed to the Privacy Officer (CEO):

Email: [email protected], please mark: Attn: PRIVACY OFFICER

Mail: Privacy Officer, Martin Youth Foundation, GPO Box 69, Sydney NSW 2001

Phone: 1300 951 009

Complaints should include:

  • Contact details of the complainant
  • Description of the privacy concern
  • Any relevant documents or evidence
  • Desired outcome (if known)

When a privacy complaint is received, the Foundation will:

  • Acknowledge receipt within 5 business days
  • Investigate the complaint thoroughly
  • Keep the complainant informed of progress
  • Provide a written response within 30 days (or advise of delays)
  • Implement corrective action where appropriate

If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner:

Website: www.oaic.gov.au

Phone: 1300 363 992

Mail: GPO Box 5218, Sydney NSW 2001

Join our community

Subscribe to our newsletter for stories of impact, upcoming events, and ways to get involved.

Name(Required)
This field is hidden when viewing the form
Privacy