Wesley Mission (Wesley Mission, we, us or our) understands that protecting your Personal Information is important. This Privacy Policy (Policy) sets out our commitment to protecting the privacy of Personal Information provided to us, or collected by us, when interacting with you and providing our services.
Please read this Policy carefully. If you provide Personal Information to us, we will collect, hold, use and disclose your Personal Information in accordance with this Policy and our obligations under Privacy Laws.
What this policy covers
This Policy explains how Wesley Mission collects, holds, uses and discloses Personal Information.
When we collect your information, we will usually provide a privacy collection notice with more specific details about that collection, including the purpose of the collection and who we may disclose this information to. These notices should be read together with this Policy and will apply to the particular circumstances in which your Personal Information is collected.
This Policy does not apply to information contained in Employee Records.
Application of Privacy Laws and APP Entity Status
Wesley Mission is an APP entity for the purposes of the Privacy Act 1988 (Cth) and complies with the Australian Privacy Principles (APPs).
Wesley Mission is also subject to, and complies with, applicable privacy and information handling laws including:
Definitions
Aged Care Act means the Aged Care Act 2024 (Cth), as amended from time to time.
Employee Records means a record of Personal Information relating to the employment of an employee.
Personal Information means information or an opinion about an identified person, or a person who is able to be reasonably identified from the information. Information does not have to be true or recorded in a material form to be considered Personal Information.
Privacy Act means the Privacy Act 1988 (Cth), as amended from time to time.
Sensitive Information means certain types of Personal Information that are afforded a higher level of protection under the Privacy Act, including information about an individual's ethnicity, race, political opinions, religious beliefs, health information, political association memberships, philosophical beliefs, professional or trade association membership, sexual orientation or practices, or criminal record.
Website means https://www.wesleymission.org.au.
Wesley Mission means:
- Wesley Community Services Limited ABN 42 164 655 145; and all businesses operated by Wesley Mission.
The Personal Information we collect
The types of Personal Information we may collect about you includes:
- Identity Data including your name, age, date of birth and photographic identification;
- Contact Data including your telephone number, address and email;
- Financial Data including information about your financial status and your social security status (if applicable) and bank account and payment card details;
- Transaction Data including details about payments between us in relation to products and services purchased and donations;
- Technical data which may include your internet protocol (IP) address, browser session and geo- location data, statistics on page views and sessions, device and network information;
- Interaction Data including information you provide to us when you participate in any interactive features, including appeals, surveys, contests, promotions, activities or events;
- Job Applicant Data including your professional history, visa information, authorisations or licences held, Working with Children Checks, National Disability Insurance Scheme Worker Screening clearance, National Police Check, where you apply for a role with us;
- Sensitive information including:
- where we provide services to you:
- identity data and health information, including individual or family medical history and healthcare preferences;
- racial or ethnic origin (so that we can provide culturally
appropriate care where possible); and - details of any support plan or treatment report provided to us;
- where you apply for a role with us:
- results of criminal records and NDIS screening checks; and
- your professional registrations and associations (where applicable);
- where you attend our events, we may ask for dietary requirements if we are arranging catering for you.
You have the option of not identifying yourself, or using a pseudonym, when interacting with us in some circumstances, for example, when making a general enquiry about our services. However, it is generally not practicable for us to interact with you anonymously or pseudonymously on an ongoing basis, for example, if you wish to make a more detailed enquiry about our services or become a client.
If we do not collect Personal Information about you, we may be unable to provide you with the information or services you have asked us to provide.
How we collect your Personal Information
We may collect Personal Information about you directly from you. We may also receive Personal information from third parties, including:
-
Commonwealth, State or Territory government agencies as well as independent agencies including the Aged Care Quality and Safety Commission;
- police agencies, e.g. to obtain your criminal history record;
- your medical practitioner or other healthcare professional;
- your authorised representative, registered supporter, independent aged care advocate, guardian or family members;
- our clients, when they provide information regarding details of their appointed attorney, guardian or other alternative decision makers and next of kin;
- service providers and individuals we engage to help us carry out our work, e.g. fundraising and telemarketing organisations; and
- recruiters, current and former employers, referees and academic institutions as part of an assessment of your suitability for any position you are applying for with us.
We may collect Personal Information about you in a variety of ways, including:
- face-to-face, over the phone, email, on social media, or otherwise online;
- when you fill out any of our forms, such as a contact enquiry, event registration or sign up to our newsletters, or respond to surveys;
- when you use our Website;
- CCTV installed at our premises or community housing properties; and
- from third parties as set out in this Policy.
How we collect, hold, use and disclose Personal Information
We may collect, use, hold and disclose your Personal Information to:
- assess whether we can take you on as a client, including checking eligibility for aged care or other service entitlements;
- manage our relationship with you as a client or supplier, including registering event attendance, assessing applications, managing appointments, providing services, preparing care plans, and communicating with your healthcare providers;
- enter into contracts or funding arrangements for services or accommodation;
- deliver training and courses;
- run fundraising activities, accept donations and issue receipts;
- liaise with providers you authorise, or those we engage to support your care;
- respond to your support requests or other enquiries (including via our Website);
- communicate with your authorised representative and nominated contacts where needed;
- maintain internal records and handle administration, invoicing and billing;
- conduct analytics, market research and business development to improve our services, systems and social media platforms;
- carry out quality assurance, evaluation, and staff training, and to manage staff workloads, performance and career development;
- undertake advertising and marketing;
- assess your application if you apply for a role with us;
- comply with our legal obligations and exercise our legal rights; and
- otherwise with your consent or where the law permits or requires it.
We are committed to embedding privacy into the design of our programs, services, systems and business processes. Before implementing a new project, program technology, system or business process or initiative that involves the collection, use, disclosure or handling of Personal Information, we will consider whether a privacy impact assessment (PIA) should be undertaken.
A PIA is used to identify privacy risks, assess compliance with applicable Privacy Laws, and implement measure to eliminate or reduce risks before the initiative proceeds. We will periodically review completed PIA’s where there are significant changes to the initiative.
Unsolicited Personal Information
If we receive Personal Information about you that we have not requested (unsolicited information), we will determine whether we could have lawfully collected that information under the Privacy Laws.
If we determine that the information could have been lawfully collected, we will handle it in accordance with this Policy. If we determine that we could not have lawfully collected the information, we will take reasonable steps to destroy or de-identify the information as soon as practicable, unless it is unlawful or unreasonable to do so.
Use of Government-Related Identifiers
We may collect and use government-related identifiers (such as Medicare numbers, Centrelink reference numbers, or other government-issued identifiers) where reasonably necessary to:
- verify your identity;
- administer or deliver services;
- comply with legal obligations or funding requirements; or
- interact with government agencies.
We will not:
- use a government-related identifier as our own identifier of you; or
- disclose such identifiers, unless permitted or required by law, or reasonably necessary for our functions or activities.
How we share your Personal Information
We may disclose Personal Information to third parties for any of the purposes set out in this Policy, where we have your consent, or where permitted or required by law. Subject to law, we may disclose Personal Information to:
- any government agency or body with whom we have a contract as part of providing services to you;
- any of our related entities involved in providing services to you or managing receipt of donations;
- any of our other service providers including IT service providers, data storage, web-hosting, server providers, data analytics providers and marketing service providers;
- professional advisors, bankers, auditors, our insurers and insurance brokers;
- payment systems operators or processors;
- our existing or potential agents or business partners;
- your legally authorised representative or other nominated individuals, such
as family members; - sponsors or promoters of any promotions or competition we run;
- if we undergo or propose to undergo a corporate restructure or reorganisation or if we merge with, or are acquired by, another company, or sell all or a portion of our assets, your Personal Information may be disclosed to our advisers and other parties involved in the transaction and may be among the assets transferred to the new purchaser, transferee or successor;
- courts, tribunals, regulatory authorities and law enforcement officers, as required or authorised by law, including in connection with any actual or prospective legal proceedings, or in order to establish, exercise or defend our legal rights; and
- comply with our mandatory reporting obligations, for child protection purposes and for information exchange between prescribed bodies under Chapter 16A of the Children and Young Persons (Care and Protection) Act 1998 (NSW).
Disclosing your Personal Information overseas
We generally do not disclose Personal Information of clients of government-funded services overseas. However, some Personal Information may be disclosed to or accessed by overseas recipients if necessary, including:
- cloud hosting providers;
- IT and system support providers;
- payment processing services; and
- data analytics or software service providers.
These recipients are typically located in countries including:
- New Zealand;
- United States of America;
-
Canada; and
-
European Union Member States.
Where overseas disclosure occurs, we will take reasonable steps to ensure that:
- the recipient complies with Privacy Laws or equivalent protections;
- due diligence will be undertaken;
- a security assessment is performed;
- supplier assurance controls are applied;
- contractual safeguards are in place (including privacy and security obligations);only the minimum necessary information is disclosed; and risks associated with cross-border disclosure are managed appropriately.
Securing your Personal Information
We hold Personal Information in paper-based and electronic records systems. Personal Information may be collected in paper-based documents and converted to electronic form for storage (with the original paper-based documents either archived or securely destroyed).Information complies with Privacy Laws and internal policies.
Information held in paper-based form is generally securely stored at the Wesley Mission office from which you receive our services or our head office in Sydney or in the case of archived records, at a local external storage facility under a commercial contract with security, retention, destruction and data protection provisions. We use physical security and other measures to protect Personal Information from misuse, interference and loss; and from unauthorised access, modification and disclosure.
Information held in electronic form is generally held on servers of contracted cloud service providers adhering to reasonable practice data security standards. We use physical security, password protection and other measures to protect Personal Information from misuse, interference and loss; and from unauthorised access, modification and disclosure.
We maintain an Information Security Management System (ISMS) aligned to ISO/IEC 27001 and implement technical, physical, people and organisational controls designed to protect Personal Information. We also implement governance, training and access control measures to ensure that staff only access Personal Information where necessary for their role, and that all handling of Personal Information complies with Privacy Laws and internal policies.
Retention and Destruction of Personal Information
We retain Personal Information to:
- fulfil the purposes for which it was collected;
- comply with legal, regulatory, funding and contractual obligations; and
- resolve disputes or enforce agreements.
Retention periods vary depending on the nature of the information and applicable legal requirements. When Personal Information is no longer required, Wesley Mission will take reasonable steps to:
- securely destroy the information; or
- de-identify the information so that it can no longer be used to identify an individual.
Destruction processes include secure disposal of paper records and permanent deletion or de-identification of electronic records.
Credit Card Payment Information
We may obtain credit card payment information in providing services to clients or when processing donations. Payment card information is kept confidential and secure and Wesley Mission complies with the Payment Card Industry Data Security Standard.
Analytics and marketing
We may use analytics and advertising tools to understand how people use our Website, improve our services and deliver more relevant marketing. These tools may collect technical and usage information about your interactions with our online services.
You can adjust your advertising or analytics preferences at any time using the opt-out options provided by major platforms (such as Google or Meta) or by using the unsubscribe or opt-out links in our communications.
Artificial intelligence
We do not use or disclose Personal Information on public AI platforms, or to train large language models.
We may use secure, private AI tools provided under contract (e.g., Microsoft platforms. AlayaCare) to help deliver our services, and these tools process Personal Information only in accordance with our privacy and security requirements. We will undertake a PIA before using any approved private AI tools, human oversight will be maintained and the provider will be required to comply with contractual safeguards to protect Personal Information.
Automated Decision Making
In certain situations, we use computer programs to make decisions that could significantly affect your rights or interests, or to carry out steps that are closely and directly involved in reaching those decisions. This is called Automated Decision Making under the Privacy Act.
The Automated Decision Making Table sets out:
-
the kinds of decisions that may involve Automated Decision Making;
-
how the computer program is involved - whether it makes the decision entirely on its own, or plays a significant and direct part in the progress alongside human input; and
-
the kinds of Personal Information used.
Your rights in relation to your Personal Information
Access to and Correction of your Personal Information
You have the right to request access to and correction of Personal Information we hold about you. We will:
- acknowledge your request promptly; and
- respond within a reasonable period, usually within 30 days of receiving the request.
We may extend this timeframe, where permitted by law (for example, if the request is complex), and will notify you if this occurs.
Refusal
In some circumstances it may not be possible to action your access or correction request, for example where:
- giving access would unreasonably impact the privacy of other individuals;
- the information relates to existing or anticipated legal proceedings;
- we are legally prohibited from providing access or making the correction; or
- we are otherwise permitted or required to refuse the request under Privacy Laws.
If we refuse your access or correction request we will provide you with written reasons for this decision.
Notifiable Data Breach
If a data breach occurs that affects Personal Information we hold, we will respond in accordance with our notifiable data breach response plan. Where an eligible data breach has occurred, we will comply with our notification obligations under the Privacy Laws, including providing affected individuals with information about the breach, the Personal Information involved, the steps we have taken in response, and recommendations for protecting themselves from potential harm.
To learn more about limiting ad tracking using this identifier, visit the settings menu on your device. To find out how Google uses data when you use third party websites or applications, please see here.
Whistleblowing reports
We are committed to protecting the privacy and confidentiality of individuals who make, are the subject of, or are otherwise involved in a whistleblower report. When managing a whistleblower complaint or disclosure, we may collect, use and disclose Personal Information as reasonably necessary to:
- receive, assess and investigate the disclosure;
- protect the identity and confidentiality of eligible whistleblowers, where required by law;
- obtain legal, regulatory or professional advice;
- comply with our legal obligations under applicable whistleblower, employment, corporate, privacy and other laws;
- take appropriate action in response to the matters raised; and
- establish, exercise or defend legal claims.
Personal Information relating to a whistleblower matter will only be disclosed on a need-to-know basis and, where required by law, with appropriate safeguards to protect confidentiality. Disclosure may be made to investigators, legal advisers, auditors, regulators, law enforcement agencies or other persons authorised or required by law. Personal Information may also be stored in a third-party whistleblower case management system or platform to manage any report.
Where applicable, we will handle whistleblower information in accordance with the whistleblower protections contained in the Corporations Act 2001 (Cth), the Taxation Administration Act 1953 (Cth), and any other applicable legislation. Nothing in this Privacy Policy limits or affects any statutory protections available to eligible whistleblowers.
Third party websites
Our Website may contain links to third party websites. We do not have any control over those websites and we are not responsible for the protection and privacy of any Personal Information which you provide whilst visiting those websites. Those websites are not governed by this Privacy Policy.
Complaints
If you are not satisfied with our handling of your Personal Information or you believe we have breached our obligations under Privacy Laws, you can complain in writing to the Privacy Officer listed below. We will respond to you within 30 days.
If you are not satisfied with the handling of our response to your complaint you may also make a complaint to the Office of the Australian Information Commissioner by telephone 1300 363 992 or online.
Contact us
If you have any questions about this Policy or about how we handle Personal information, our contact details are:
The Privacy Officer
Wesley Mission
PO Box A5555
Sydney South NSW 1235
E: PrivacyOfficer@wesleymission.org.au
P: (02) 9263 5421
Changes to this Policy
We may update or change this Policy at any time. We recommend you check our Website regularly to stay up to date with our current Privacy Policy.
Privacy Policy was approved on 14 September 2026.