Legal

Privacy Policy

Last updated: 2 September 2026

Pinnacle Chapter Australia Pty Ltd
ABN 26 697 188 882

Our Commitment

Pinnacle Chapter Australia Pty Ltd ("Pinnacle Chapter", "we", "us" or "our") respects the privacy, dignity and confidentiality of the people and organisations who interact with us.

This Privacy Policy explains how we collect, hold, use, disclose and protect personal information in connection with:

  • our website and online enquiry channels;
  • initial enquiries and preliminary screening processes;
  • prospective, current and former clients;
  • individual, family, disability-related and advocacy-related enquiries;
  • governance, business consulting, advisory and project engagements;
  • referrals and professional collaboration;
  • contractors, consultants, suppliers and other service providers; and
  • complaints, incidents, records administration, risk management and compliance activities.

This Privacy Policy is a public statement of our privacy practices. It does not create a service engagement, contractual retainer or obligation to accept or continue an enquiry.

Specific collection notices, consent forms, service agreements or legal requirements may also apply to a particular matter.

1. Privacy Framework

Where the Privacy Act 1988 (Cth) applies to us, we intend to handle personal information consistently with that Act and the Australian Privacy Principles.

We also comply with other privacy, confidentiality, record-keeping, safeguarding and disclosure requirements that apply to our activities.

Some small businesses may be exempt from parts of the Privacy Act 1988 (Cth). Nothing in this Privacy Policy is intended to represent that a particular exemption does or does not apply. We may choose to follow the practices described in this Privacy Policy as a matter of governance, service quality and trust.

A copy of this Privacy Policy is available free of charge in an appropriate form upon request.

2. Information We Collect

The types of information we collect depend on the nature of the enquiry, relationship or service involved. We seek to collect only information reasonably necessary for our functions or activities.

We may collect:

Contact and Identity Information

  • name, preferred name and contact details;
  • postal address, email address and telephone number;
  • date of birth where relevant;
  • organisation, position, role and professional contact details;
  • communication and accessibility requirements;
  • representative, guardian, nominee or carer details where relevant; and
  • information reasonably required to verify identity or authority.

Enquiry and Service Information

  • the nature and background of an enquiry;
  • the assistance sought and desired outcomes;
  • relevant personal, family, professional or organisational circumstances;
  • current services or professionals;
  • relevant deadlines;
  • referral and stakeholder information;
  • communication and accessibility requirements;
  • information relevant to authority, conflicts, suitability, safeguarding or risk;
  • proposals, agreements, service records and correspondence;
  • invoices, payment status and account administration information; and
  • complaints, feedback, incidents and risk-management information.

Sensitive Information

Where reasonably necessary and permitted by law, we may collect sensitive information, including:

  • disability-related information;
  • support needs and accessibility requirements;
  • health information relevant to requested support;
  • advocacy-related information;
  • family or personal circumstances;
  • safeguarding concerns; and
  • other sensitive information volunteered or reasonably required for the matter.

We collect sensitive information only where it is reasonably necessary for our functions or activities and where the individual has consented when consent is required, or where collection is otherwise authorised or required by law.

Individuals should provide only sensitive information that is relevant and reasonably necessary for us to understand or assess an enquiry. Original documents or unnecessary health, disability, identity, family, financial, safeguarding or other sensitive information should not be provided unless requested.

Website and Technical Information

When a person uses our website or digital services, we may collect:

  • IP address;
  • browser and device information;
  • pages viewed;
  • dates and times of visits;
  • referring pages;
  • form submission metadata;
  • cookie identifiers; and
  • security and system logs.

3. Information About Other People

An enquiry or engagement may include information about family members, children, workers, clients, professionals, community members or other third parties.

A person providing information about another individual must have that individual's consent where consent is required, or otherwise have lawful authority or another valid legal basis to provide the information.

Only information that is relevant and reasonably necessary for the enquiry or engagement should be provided.

Providing information about another person does not, by itself:

  • establish authority to act for that person;
  • give instructions on that person's behalf;
  • make decisions for that person;
  • provide consent on that person's behalf; or
  • create an entitlement to receive confidential information about that person.

We may request evidence of consent, identity, parental responsibility, guardianship, representation or other authority before relying on information or instructions or communicating about another individual.

4. How We Collect Information

We may collect personal information:

  • directly from an individual through website forms, email, telephone calls, meetings, interviews, correspondence, documents and service delivery;
  • from an authorised representative, parent, guardian, carer, advocate, nominee or family member;
  • from a referring organisation, service provider, professional adviser, government body, educational institution, health professional or other relevant source where authorised or permitted;
  • from publicly available sources where collection is lawful and relevant; and
  • through website forms, cookies, analytics, hosting, security monitoring and other digital systems.

If we receive unsolicited personal information, we will consider whether we could have collected it under applicable privacy requirements. Where appropriate and lawful, information that is not required may be securely destroyed or de-identified.

5. How We Use Information

We may collect, hold, use and disclose personal information to:

  • respond to an enquiry and communicate with the person or their representative;
  • understand the matter and identify the assistance being sought;
  • assess whether we may be able and suitable to assist;
  • conduct preliminary screening, identity or authority verification, conflict checks, safeguarding assessment, risk assessment and suitability review;
  • decide whether to offer an engagement;
  • prepare proposals or engagement documents where appropriate;
  • provide, administer, review, suspend or end services;
  • prepare service plans, records, reports or other agreed work;
  • coordinate authorised referrals and communication with third parties;
  • manage appointments, accounts, payments, insurance, complaints, incidents, disputes and legal claims;
  • support quality assurance, supervision, training, governance and service improvement;
  • maintain the safety, security and integrity of people, systems and operations; and
  • comply with legal, regulatory, contractual, safeguarding, reporting, audit and record-keeping obligations.

We may use or disclose personal information for the primary purpose for which it was collected, for a related secondary purpose where permitted, with consent, or as otherwise authorised or required by law.

6. Initial Enquiries and Preliminary Screening

Information submitted through an initial enquiry or preliminary screening process may be used to:

  • understand the assistance being sought;
  • communicate with the enquirer;
  • assess whether we may be able and suitable to assist;
  • conduct preliminary identity, authority, safeguarding, conflict, suitability and risk assessments;
  • determine whether an engagement may be offered; and
  • determine whether referral information may be appropriate.

No Engagement Created

Making an enquiry, completing or returning an initial enquiry or preliminary screening form, providing information, participating in preliminary discussions, receiving general information or undertaking pre-engagement screening does not create:

  • a client relationship;
  • a retainer;
  • an engagement;
  • a service agreement;
  • a contract;
  • a fiduciary relationship;
  • a duty to act; or
  • an obligation to provide services.

Discussion of possible services, options, scope, availability, fees, likely next steps or potential engagement arrangements during preliminary screening is exploratory only.

Nothing in the enquiry or preliminary screening process guarantees acceptance, availability, suitability, service provision or any particular outcome.

An engagement begins only when Pinnacle Chapter expressly confirms acceptance in writing and the applicable scope, fees and engagement terms have been agreed in writing.

Enquirers should not assume that Pinnacle Chapter has agreed to act, protect a legal position, meet a deadline, preserve a right, commence a process, contact another person or organisation, or take any other action unless Pinnacle Chapter expressly confirms that agreement in writing.

7. Disclosure of Information

Depending on the circumstances, we may disclose personal information to:

  • authorised personnel, contractors and representatives who require the information to perform their roles;
  • information technology, cybersecurity, cloud storage, website, communications and administrative providers;
  • accountants, auditors, insurers, legal advisers and other professional advisers;
  • payment, billing, document management and business support providers;
  • referral recipients, collaboration partners and other professionals where authorised or permitted;
  • courts, tribunals, law enforcement bodies, regulators, government agencies or statutory bodies where authorised or required; and
  • a prospective purchaser, successor or adviser in connection with a proposed business restructure or transaction, subject to appropriate confidentiality and legal controls.

We do not sell, rent or trade personal information.

8. Overseas Processing and Disclosure

Some technology, cloud, support or professional service providers may store, access or process information outside Australia.

The countries involved may vary according to the provider, service configuration, support arrangements and location of authorised users.

Before relying on a material overseas handling arrangement, we take steps that are reasonable in the circumstances to assess privacy and security considerations and address applicable legal requirements.

Current information about known overseas locations may be requested from the Privacy Officer.

9. Cookies, Analytics and Digital Services

We may use cookies, analytics, performance tools and security technologies to:

  • operate and protect the website;
  • understand website use;
  • improve functionality and performance;
  • maintain reliable digital services; and
  • support system administration and security.

These technologies may collect device, browser and website usage information.

Browser settings may allow cookies to be blocked or deleted. Blocking or deleting cookies may affect some website functions.

Do not use a website form for urgent, emergency or time-critical matters.

Website transmission and electronic storage cannot be guaranteed to be completely secure.

10. Direct Marketing

Where permitted by law, we may use contact details to send service updates, invitations, resources or other communications that may be relevant to the recipient.

We comply with applicable requirements under the Spam Act 2003 (Cth).

We provide a practical way to opt out of direct marketing communications and action opt-out requests within the period required by law.

Submitting an initial enquiry or preliminary screening form does not, by itself, constitute consent to receive direct marketing.

Operational, service, legal or account communications are not necessarily direct marketing and may continue where reasonably required for an existing relationship.

11. Government-Related Identifiers

We do not adopt, use or disclose a government-related identifier as our own identifier except where permitted by law.

Where a government-related identifier is reasonably required for an authorised process, we limit its handling to the relevant purpose and apply appropriate access and security controls.

12. Data Security

We take steps that are reasonable in the circumstances to protect personal information from misuse, interference, loss, unauthorised access, modification or disclosure.

Security measures may include:

  • role-based and need-to-know access controls;
  • password, multi-factor authentication, device, network and account security controls where available and appropriate;
  • secure cloud, document and communication systems;
  • confidentiality requirements for workers, contractors and service providers;
  • secure handling, transmission, backup and disposal practices;
  • incident reporting, monitoring, review and response procedures; and
  • training, governance oversight and periodic review of information-handling practices.

Individuals can assist by using secure communication channels, checking recipients, protecting account credentials and notifying us promptly if information may have been sent to the wrong person or otherwise compromised.

No method of electronic transmission or storage can be guaranteed to be completely secure.

13. Retention, Destruction and De-Identification

We retain personal information for as long as reasonably necessary for the purpose for which it was collected and to meet applicable:

  • legal;
  • contractual;
  • financial;
  • insurance;
  • governance;
  • safeguarding;
  • conflict-checking;
  • dispute-management; and
  • operational requirements.

Retention periods may differ according to the record type, people involved, nature of the service, statutory obligations, limitation periods, insurance conditions, litigation holds, complaints, investigations or ongoing risks.

When personal information is no longer required and there is no lawful reason to retain it, we take reasonable steps to securely destroy or de-identify it.

Backup, archive or system records may be removed through controlled lifecycle processes rather than immediately.

14. Access and Correction

An individual may request access to personal information we hold about the individual and may ask us to correct information believed to be inaccurate, out of date, incomplete, irrelevant or misleading.

Requests should be made in writing to the Privacy Officer and should include enough information to:

  • identify the person making the request;
  • confirm any authority to act for another person; and
  • locate the relevant records.

We may verify identity or authority before responding.

We respond within a reasonable period. Access may be refused or limited where permitted or required by law, including where access would:

  • unreasonably affect another person's privacy;
  • reveal confidential evaluative information;
  • prejudice an investigation or legal process; or
  • otherwise fall within a lawful exception.

Where required, we will provide reasons for refusing or limiting access.

If we do not agree to a requested correction, the individual may ask us to associate a statement with the relevant record where applicable.

15. Privacy Complaints

A person who believes we have mishandled personal information may make a complaint to the Privacy Officer using the contact details below.

A complaint should describe:

  • the concern;
  • relevant dates, people or communications;
  • the outcome sought; and
  • any supporting information.

We will acknowledge, assess and investigate the complaint as appropriate, communicate the outcome and identify any corrective action.

We aim to respond within a reasonable period, having regard to the complexity and circumstances of the complaint.

If the complainant is dissatisfied with our response, the complainant may be able to contact the Office of the Australian Information Commissioner or another regulator or external dispute-resolution body with jurisdiction.

Current contact information and eligibility requirements should be checked through the relevant regulator's official website.

16. Data Breaches

Actual or suspected data breaches should be reported promptly to the Privacy Officer.

We take reasonable steps to:

  • contain the incident;
  • preserve relevant evidence;
  • assess the information and people affected;
  • reduce potential harm;
  • investigate the cause;
  • determine whether notification is required;
  • document decisions; and
  • implement corrective action.

Where the Notifiable Data Breaches scheme or another notification obligation applies, we assess the incident and notify affected individuals and the relevant regulator as required by law.

Notification decisions are based on the verified facts and applicable legal requirements at the time.

17. Children, Young People and Safeguarding

Where an enquiry, engagement or service involves a child or young person, we seek to promote the individual's safety, dignity, wellbeing, participation and best interests, having regard to the individual's age, circumstances, capacity, communication needs and applicable legal requirements.

Information relating to children and young people may be particularly sensitive. We take reasonable steps to ensure personal information is collected, used, disclosed and stored appropriately and proportionately for the purpose for which it is required.

Where appropriate, we may collect information from or communicate with:

  • parents;
  • legal guardians;
  • carers;
  • advocates;
  • nominees;
  • authorised representatives; and
  • other individuals lawfully acting on behalf of a person.

We may request evidence of parental responsibility, authority, guardianship, representation, consent or other legal authority before relying on instructions, information or decisions provided by another person.

Providing information about another individual does not, by itself, establish parental responsibility, guardianship, decision-making authority, consent authority or an entitlement to receive confidential information about that person.

Privacy and confidentiality may be limited where we reasonably believe:

  • a child or young person may be at risk of harm;
  • a person may be experiencing abuse, neglect, exploitation, coercion or serious violence;
  • there is a serious threat to a person's life, health, safety or welfare;
  • a safeguarding concern requires reporting, escalation, intervention or protective action; or
  • disclosure is otherwise authorised, permitted or required by law.

Where appropriate, relevant information may be disclosed to:

  • child protection authorities;
  • government agencies;
  • law enforcement bodies;
  • emergency services;
  • safeguarding bodies;
  • regulators;
  • courts or tribunals; or
  • other persons or organisations lawfully involved in managing the concern.

Any disclosure will generally be limited to information reasonably necessary for the safeguarding, protective, welfare, safety, investigative or legal purpose.

18. Limits of Privacy and Confidentiality

While we are committed to protecting personal information and maintaining confidentiality wherever reasonably possible, privacy and confidentiality cannot be guaranteed in all circumstances.

Privacy and confidentiality may be limited where:

  • disclosure is authorised by the individual or a lawful representative;
  • disclosure is reasonably necessary to provide services or administer an engagement;
  • disclosure is required to prevent or lessen a serious threat to health, safety or welfare;
  • disclosure is necessary to investigate, respond to or manage safeguarding concerns, complaints, incidents or unlawful conduct;
  • disclosure is authorised or required by law; or
  • we receive a lawful request, notice, warrant, order or direction from a court, tribunal, regulator, government agency or law enforcement body.

Where disclosure is required or authorised, we seek to disclose only the information reasonably necessary in the circumstances and take reasonable steps to protect privacy to the extent practicable.

19. Anonymity and Pseudonyms

Where practicable and lawful, a person may make an enquiry anonymously or use a pseudonym.

We may require a person's identity or contact details where identification is required by law, verification is necessary or it is impracticable to assess or provide the requested service without identifying the person.

20. Changes to This Policy

We may amend this Privacy Policy to reflect changes in law, guidance, services, technology, systems or business practices.

The current public version will state its effective date.

Material changes will be communicated where reasonably appropriate.

Continued use of the website does not replace any consent that must be obtained under applicable law.

21. Contact Us

Privacy Officer

Pinnacle Chapter Australia Pty Ltd
PO Box 45
Junee NSW 2663

Email: [email protected]
Phone: 0485 908 507
Website: pinnaclechapter.com.au

By submitting an enquiry through this website, you acknowledge that Pinnacle Chapter Australia Pty Ltd may collect and handle personal information in accordance with this Privacy Policy. Submission of an enquiry does not create a client relationship or guarantee that an engagement will be offered. Please provide only information that is relevant and reasonably necessary for us to understand your enquiry. Do not use the website form for urgent, emergency or time-critical matters.