Privacy Policy
The Privacy Policy explains how Tunstall will collect, hold, and disclose personal and sensitive information that is compliant with:
Australian Privacy Principles (APPs) set out in the Privacy Act 1988 (Cth)
Information Privacy Principles (IPPs) set out in the Privacy Act 2020 (NZ)
Tunstall is committed to protecting privacy and being open and transparent, in how they manage information.
Information Tunstall Collects and Purpose
Tunstall only collects information when it is relevant to providing services or is required by law.
The type of information that we typically collect includes:
- Client - name, date of birth, personal and emergency contact information, health and medical information, health fund, and payment details.
- Contractor/Supplier - business contact details, ABN, and payment details.
- Website – IP address and domain name.
Tunstall will only collect sensitive and health information under the following circumstances:
- Consent has been provided.
- Collection is authorised or required by law.
- Collection is otherwise allowed under the Privacy Acts and associated Privacy Principles.
How Tunstall Collects and Manages Personal Information
Tunstall collects personal information through various means including paper and electronic forms (for example service agreements), online portals, written correspondence, face to face, social networking channels and over the phone discussions. If it is reasonable and practical to do so, Tunstall will collect personal information directly from the individual or their authorised representatives.
Additionally, Tunstall collects location data from our devices’ GPS (if applicable), as well as other locating technology like Wi-Fi, Bluetooth, and cellular towers. Location Data collected from devices will only be used when it is directly relevant to the features and services provided by Tunstall.
From time to time there may be circumstances where personal information is collected indirectly because it is unreasonable or impractical to collect this directly. In instances where this has occurred Tunstall will take reasonable steps to inform the individuals why the information was collected and how it will be handled.
Handling personal information, refers to when Tunstall retains control of the information. Secondary use or disclosure is only permitted when an individual has given consent or a legal or privacy exception applies.
Anonymity and Pseudonymity
Individuals engaging with Tunstall have the option of not identifying themselves or using a pseudonym (made-up name) when it is lawful and practicable to do so – for example, where an individual wants to make an anonymous complaint. However, in certain circumstances this might not be feasible, and Tunstall will be unable to provide services without being able to identify individuals.
If required information is not provided or incomplete, then Tunstall will be unable to provide services or complete employment engagement.
Personal Information Storage and Security
Tunstall have implemented security policies and measures to protect the personal information that they have. Personal information is stored in a variety of formats including though not limited to:
- Electronically in databases.
- Hard copy files.
- Tunstall issued devices, including laptop computers and mobile phones.
- Third party storage providers such as cloud storage facilities for backups, emails, and SharePoint. All are in Australia.
Reasonable steps are implemented to protect against misuse, interference, and loss, as well as from unauthorised access, modification, or disclosure. These steps include:
- Monitoring systems access, so that only those who need to access the information can using authenticated credentials.
- Ensuring secure building access.
- Auditing of storage and data security including compliance with ISO 27001
- Ensure destruction, deletion or de-identification of personal information we hold that is no longer required to be retained by archiving legislation.
- Staff training and annual policy acknowledgment.
Data Breaches
Tunstall will take appropriate, prompt action including reporting to the Office of the Australian Information Commissioner (OAIC) or for New Zealand the Office of The Privacy Commissioner (OPC) if an eligible data breach occurs and personal information Tunstall holds is subjected to unauthorised modification, loss, use, or disclosure.
If there is a suspected data breach an assessment will be undertaken to determine if it is an eligible data breach within 72 hours and where confirmed it will be reported to the relevant authority.
Tunstall will activate a breach response plan that includes containing the breach, assessing the risk, and implementing mitigation strategies. All actions will be documented. Impacted individuals will be notified if the assessment determines that the breach is likely to cause serious harm.
Disclosure of Personal Information Overseas
Tunstall endeavours to only disclose information within Australia or New Zealand while providing services or employment.
Specific to Australia; NDIS clients are advised of the following, and consent is gained through the Client Service Agreement:
A copy of an individual client record is held for business continuity purposes by Tunstall’s New Zealand Customer Care Centre. Tunstall assures you that your confidential personal information will only be used for the purpose for which you have provided it.
In the event of an overseas disclosure Tunstall will comply with applicable privacy laws, including the Australian Privacy Principles (APP 8) and the New Zealand Information Privacy Principles (IPPs).
Website and Social Media
Tunstall website and social media pages may (at times) contain links to other third-party websites. Tunstall is not responsible for information stored, accessed, used, or disclosed on these third-party websites.
Tunstall use social networking services such as X (Twitter), LinkedIn and YouTube to communicate about our services. Tunstall is not responsible for the privacy practices of social networking sites, as these sites have their own privacy policies.
Complaints and Feedback
If it is believed that Tunstall have used personal information in a way that is not consistent with this policy or the privacy laws, a complaint can be made by:
- Contacting us at AU-TUN-Privacy@tunstall.com or
- Contacting us via your account manager
Tunstall will investigate as per their Complaints and Feedback Policy and advise the outcome.
If after this process, the complainant is not satisfied, a complaint can be submitted to:
- Australia - Office of the Information Commissioner at http://www.oaic.gov.au/privacy/privacy-complaints For more general information www.oaic.gov.au
- New Zealand – Office of the Privacy Commissioner Office of the Privacy Commissioner | Complain to the Privacy Commissioner For more general information https://privacy.org.nz/
For more information about privacy in general, you can visit the Office of the Information Commissioner’s website at www.oaic.gov.au.
How to Access and Correct Information
Tunstall will take all reasonable steps to ensure that personal information held by Tunstall, that is used and disclosed is accurate, complete, and up to date, including at the time of using or disclosing the information.
Individuals have the right to access and request corrections to personal information if they think the information is inaccurate, out-of-date, incomplete, irrelevant, or misleading. All requests must be in writing forwarded to AU-TUN-Privacy@tunstall.com
In some circumstances, Tunstall may decline access to or correction of personal information – for example, where access is unlawful under a secrecy provision in legislation, or where the personal information held is an opinion and not an objective fact. If the request is declined written notice will be provided that sets out the reason for refusal.