fbpx

PRIVACY POLICY

This Privacy Policy details how Cockburn Ice Arena (‘The Rink’) protects your privacy and how we comply with the requirements of the Privacy Act 1988 and its 13 Australian Privacy Principles.

This policy also describes:

  • Who we collect information from;
  • The types of personal information collected and held by us;
  • How this information is collected and held;
  • The purposes for which your personal information is collected, held, used and disclosed;
  • How you can gain access to your personal information and seek its correction;
  • How you may complain or inquire about our collection, handling, use or disclosure of your personal information and how that complaint or inquiry will be handled; and
  • Whether we are likely to disclose your personal information to any overseas recipients.

Scope of Policy and Source of Obligation

In the course of Cockburn Ice Arena’s activities, we manage and protect personal information in accordance with the Privacy Act 1988 (Privacy Act) and the 13 Australian Privacy Principles (APPs).

Scope of policy

This policy outlines the circumstances in which we obtain personal information, how we use and disclose that information and how we manage requests to access and/or change that information.

What is personal information and how do we collect it?

Personal information is information or an opinion about an individual from which they can be reasonably identified. Depending on the circumstances, we may collect personal information from the individual in their capacity as an employee, private member, patron, contractor, stakeholder, job applicant, coach, spectator, visitor or others that come into contact with the Rink.

In the course of providing services, we may collect and hold:

Personal Information including names, addresses and other contact details; dates of birth; next of kin details; photographic images; attendance records and financial information.

Sensitive Information (particularly in relation to student records) including country of birth and health information

Health Information (particularly in relation to student records) includes disclosed medical information that may impact participation at our venue.

As part of our recruitment processes for employees, contractors and coaches, we may collect and hold:

Personal Information including names, addresses and other contact details, dates of birth, financial information, citizenship, employment references, regulatory accreditations and licences, photographs, directorships, and driver’s licence information.

Sensitive Information including government identifiers (such as TFN), nationality, country of birth, professional memberships, family court orders and criminal records.

Health Information (particularly in relation to e staff) including medical records, , immunisation details and psychological reports.

It is noted that employee records are not covered by the APPs where they relate to current or former employment relations between the Rink and the employee.

Collection of personal information

The collection of personal information depends on the circumstances in which Cockburn Ice Arena is collecting it. If it is reasonable and practical to do so, we collect personal information directly from the individual.

Solicited information

Cockburn Ice Arena has, where possible, attempted to standardise the collection of personal information by using specifically designed forms (e.g. an Enrolment Form or Health Information Disclosure Form). However, given the nature of our operations we also receive personal information by email, letters, via our website, over the telephone, in face-to-face meetings, through financial transactions and through surveillance activities such as the use of CCTV security cameras or email monitoring.

We may also collect personal information from other people (e.g. a third-party administrator, referees for prospective employees) or independent sources. However, we will only do so where it is not reasonable and practical to collect the personal information from the individual directly.

Information collected from our website

We may collect information based on how individuals use our website. We use ‘’cookies’’ and other data collection methods to collect information on website activity such as the number of visitors, the number of pages viewed and the internet advertisements which bring visitors to our website. This information is collected to analyse and improve our website, marketing campaigns and to record statistics on web traffic.  We do not use this information to personally identify individuals.

Unsolicited information

Cockburn Ice Arena may be provided with personal information without having sought it through our normal means of collection. This is known as “unsolicited information” and is often collected by:

  • Misdirected postal mail – Letters, Notes, Documents
  • Misdirected electronic mail – Emails, electronic messages
  • Employment applications sent to us that are not in response to an advertised vacancy
  • Additional information provided to us which was not requested.

Unsolicited information obtained by Cockburn Ice Arena will only be held, used and or disclosed if it is considered as personal information that could have been collected by normal means. If that unsolicited information could not have been collected by normal means, then we will destroy, permanently delete or de-identify the personal information as appropriate.

Collection and use of sensitive information

We only collect sensitive information if it is:

  • reasonably necessary for one or more of these functions or activities, and we have the individual’s consent
  • necessary to lessen or prevent a serious threat to life, health or safety
  • another permitted general situation
  • another permitted health situation.

We may share sensitive information to other entities in our organisation structure, but only if necessary for us to provide our products or services.

How do we use personal information?

Cockburn Ice Arena only uses personal information that is reasonably necessary for one or more of our functions or activities (the primary purpose) or for a related secondary purpose that would be reasonably expected by you, or for an activity or purpose to which you have consented.

Our primary uses of personal information include, but are not limited to:

  • Providing lessons, coaches and programs
  • Satisfying our legal obligations including our duty of care
  • Keeping stakeholders informed as to Ice Rink community matters through correspondence, newsletters and magazines
  • Marketing, promotional and fundraising activities
  • Supporting the activities of the mySKATE proshop
  • Supporting the activities of Cabin 401
  • Helping us to improve our day-to-day operations including training our staff
  • Systems development; developing new programs and services; undertaking planning, research and statistical analysis
  • Rink administration including for insurance purposes
  • The employment of staff

We will only use or disclose sensitive or health information for a secondary purpose if you would reasonably expect us to use or disclose the information and the secondary purpose is directly related to the primary purpose.

We may share personal information to related bodies corporate, but only if necessary for us to provide our services.

The Rink may disclose information about an individual to overseas recipients only when it is necessary, for example to facilitate a media enquiry. The Rink will not however send information about an individual outside of Australia without their consent.

Recurring Payments and Card Information

When card details are provided for recurring payments, they are securely stored and processed by Stripe, our chosen payment processor. Stripe adheres to the following strict security measures:

  1. Encryption 
    All transactions are processed using secure connections, with TLS encryption to protect data in transit. Stripe encrypts sensitive data both in transit and at rest. Stripe’s infrastructure for storing, decrypting, and transmitting primary account numbers (PANs), such as credit card numbers, runs in a separate hosting infrastructure, and doesn’t share any credentials with the rest of their services.All card numbers are encrypted at rest with AES-256. Decryption keys are stored on separate machines. Stripe tokenises PANs internally, isolating raw numbers from the rest of their infrastructure. None of Stripe’s internal servers and daemons are able to obtain plain text card numbers but can request that cards are sent to a service provider on a static allowlist. Stripe’s infrastructure for storing, decrypting, and transmitting card numbers runs in a separate hosting environment, and doesn’t share any credentials with Stripe’s primary services including their API and website. It’s not just PANs that are tokenised this way; they treat other sensitive data, such as bank account information, in a similar way.
  2. Access
    Cockburn Ice Arena does not have access to full card details. Only Stripe, the payment processor, has access to this information, and even within Stripe, access is restricted to authorized personnel only. A dedicated team manages CDV in an isolated Amazon Web Services (AWS) environment that’s separate from the rest of Stripe’s infrastructure. Access to this separate environment is restricted to a small number of specially trained engineers and access is reviewed quarterly.
  3. Liability
    Stripe is PCI-DSS Level 1 compliant, meaning they meet the highest standards of data security. In the event of any unauthorized access or misuse of card details, Stripe holds the primary responsibility for the security of the data they handle. Please refer to Stripe’s Service Agreement for more details on their liability and security practices.

Storage and Security of Personal Information

Cockburn Ice Arena stores Personal Information in a variety of formats including, but not limited to:

  • Databases
  • Hard copy files
  • Personal devices, including laptop computers an ipads; and
  • Third party storage providers such as cloud storage facilities.

Cockburn Ice Arena takes all reasonable steps to protect the personal information we hold from misuse, loss, unauthorised access, modification or disclosure.

These steps include, but are not limited to:

  • Restricting access and user privilege of information by staff depending on their role and responsibilities
  • Ensuring staff do not share personal passwords
  • Ensuring hard copy files are stored in lockable filing cabinets in lockable rooms. Staff access is subject to user privilege
  • Ensuring access to Cockburn Ice Arena’s premises are reasonably secured at all times
  • Implementing physical security measures around the Rink buildings and grounds to prevent break-ins
  • Ensuring our IT and cyber security systems, policies and procedures are implemented and up to date
  • Ensuring staff comply with internal policies and procedures when handling the information
  • Undertaking due diligence with respect to third party service providers who may have access to personal information, including customer identification providers and cloud service providers, to ensure as far as practicable that they are compliant with the APPs or a similar privacy regime; and
  • The destruction, deletion or de-identification of personal information we hold that is no longer needed or required to be retained by any other laws.

Our public website may contain links to other third-party websites outside of Cockburn Ice Arena. Cockburn Ice Arena is not responsible for the information stored, accessed, used or disclosed on such websites and we cannot comment on their privacy policies.

Responding to data breaches

Cockburn Ice Arena will take appropriate, prompt action if we have reasonable grounds to believe that a data breach may have or is suspected to have occurred. Depending on the type of data breach, this may include a review of our internal security procedures, taking remedial internal action, notifying affected individuals and the Office of the Australian Information Commissioner (OAIC).

If we are unable to notify individuals, we will publish a statement on our website and take reasonable steps to publicise the contents of this statement.

Disclosure of personal information

Personal information is used for the purposes for which it was given to Cockburn Ice Arena or for purposes which are directly related to one or more of our functions or activities.

Personal information may be disclosed to government agencies, other members, patrons, other rinks, recipients of rink publications, coaches and visiting coaches, our services providers, contractors, business partners, related entities and other recipients from time to time, if the individual:

  • Has given consent; or
  • Would reasonably expect the personal information to be disclosed in that manner.

Cockburn Ice Arena may disclose personal information without consent or in a manner which an individual would reasonably expect if:

  • We are required to do so by law
  • The disclosure will lessen or prevent a serious threat to the life, health or safety of an individual or to public safety
  • Another permitted general situation applies
  • Disclosure is reasonably necessary for a law enforcement related activity; or
  • Another permitted health situation exists.

Disclosure of your personal information to overseas recipients

Personal information about an individual may be disclosed to an overseas organisation in the course of providing our services, for example when storing information with a “cloud service provider” which stores data outside of Australia.

We will however take all reasonable steps not to disclose an individual’s personal information to overseas recipients unless:

  • We have the individual’s consent (which may be implied)
  • We have satisfied ourselves that the overseas recipient is compliant with the APPs, or a similar privacy regime
  • We form the opinion that the disclosure will lessen or prevent a serious threat to the life, health or safety of an individual or to public safety; or
  • we are taking appropriate action in relation to suspected unlawful activity or serious misconduct.

Personal information of members under 18

The Privacy Act does not differentiate between adults and children and does not specify an age after which individuals can make their own decisions with respect to their personal information.

At Cockburn Ice Arena we take a common sense approach to dealing with an underage member’s personal information and generally will refer any requests for personal information to a underage member’s parent/guardian.  We will treat notices provided to parents/guardians as notices provided to the underage member and we will treat consents provided by parents/guardians as consents provided by an underage member.

We are however cognisant of the fact that children do have rights under the Privacy Act, and that in certain circumstances (especially when dealing with teenage members and especially when dealing with sensitive information), it will be appropriate to seek and obtain consents directly from underage members. We also acknowledge that there may be occasions where an underage member may give or withhold consent with respect to the use of their personal information independently from their parents/guardian.

There may also be occasions where parents/guardians are denied access to information with respect to their children, because to provide such information would have an unreasonable impact on the privacy of others or result in a breach of the The Rink’s duty of care to the underage member.

The quality of personal information

We take all reasonable steps to ensure the personal information we hold, use and disclose is accurate, complete and up-to-date, including at the time of using or disclosing the information.

If Cockburn Ice Arena becomes aware that the Personal Information is incorrect or out of date, we will take reasonable steps to rectify the incorrect or out of date information.

Access and correction of personal information

You may submit a request to us to access the personal information we hold, or request that we change the personal information. Upon receiving such a request, we will take steps to verify your identity before granting access or correcting the information.

If we reject the request, you will be notified accordingly. Where appropriate, we will provide the reason/s for our decision. If the rejection relates to a request to change personal information, an individual may make a statement about the requested change and we will attach this to their record.

Complaints

You can make a complaint about how Cockburn Ice Arena manages personal information, including a breach of the APPs by notifying us in writing as soon as possible.  We will respond to the complaint within a reasonable time (usually no longer than 30 days) and we make seek further information in order to provide a full and complete response.

Cockburn Ice Arena does not charge a fee for the handling of complaints.

If you are not satisfied with our response, you may refer the complaint to the Office of the Australian Information Commissioner (OAIC). A complaint can be made using the OAIC online Privacy Complaint form or by mail, fax or email.

A referral to OAIC should be a last resort once all other avenues of resolution have been exhausted.

How to contact us

Cockburn Ice Arena can be contacted about this Privacy Policy or about the collection and handling of personal information generally by contacting the Privacy Officer by:

Email: Attention – Privacy Officer  reception@cockburnicearena.com.au

T: +61 8 9411 0300

Or by writing to the Privacy Officer, Cockburn Ice Arena, 401 Progress Drive, Bibra Lake WA 6163.

If practical, you can contact us anonymously (i.e. without identifying yourself) or by using a pseudonym. However, if you choose not to identify yourself, we may not be able to give you the information or provide the assistance you might otherwise receive if it is not practical to do so.

Changes to our privacy and information handling practices

This Privacy Policy is subject to change at any time. The Policy is reviewed regularly and any changes are updated on our website accordingly.

 

This Privacy Policy was last reviewed: August 2024

0
1Cart2Delivery & Payment3Complete Order
    0
    Your Cart
    Your cart is emptyReturn to Shop