Privacy Policy
How we collect, hold, use and disclose personal information at ClassActions.com.au.
Privacy enquiries: privacy@classactions.com.au
Plain-English summary
We collect only the information needed to operate ClassActions.com.au and the Australian Class Action Registry. Your contact details are kept separate and are not shared unless you choose to allow it or it is required to provide a service you request.
Class Actions Australia ABN 77 672 009 764 and associated entities (we, us or our) understand that protecting your personal information is important. This Privacy Policy sets out our commitment to protecting the privacy of personal information provided to us, or otherwise collected by us, when interacting with you. This Privacy Policy is intended to comply with the Privacy Act 1988 (Cth) and the Australian Privacy Principles.
The information we collect
Personal information is information or an opinion, whether true or not and whether recorded in a material form or not, about an individual who is identified or reasonably identifiable.
The types of personal information we may collect about you include:
- basic identifying and contact information, such as your name, email address, phone number, suburb or state;
- information you provide to us when you use our website, platform, forms, surveys, questionnaires, feedback tools, registrations, activities or events;
- information you provide in connection with a matter, enquiry, registration, class action, investigation, claim-related opportunity or similar process;
- information you provide regarding illness, injury, inability to work, hardship, eligibility or related circumstances;
- information submitted through website forms, enquiry forms and platform communications;
- your communication preferences and preferences for receiving updates or marketing communications;
- if we need to verify your identity because we are legally required to do so or because it is reasonably necessary for a service you request, identity-related information or documents you provide;
- if you access software, portals or websites we make available to you, details about your use of those systems, including your IP address, browser type, device information, usage logs, search queries and browsing behaviour, including through cookies, pixels and analytics tools;
- records of communications with us or through our systems; and
- any other personal information you voluntarily provide to us.
Sensitive information
Sensitive information is a type of personal information that is given a higher level of protection under privacy law. It may include information about your health, racial or ethnic origin, religious beliefs, political opinions, union memberships, sexual orientation, criminal record, or biometric information.
In the course of providing our services or operating our platform, we may collect or otherwise receive sensitive information where it is reasonably necessary, including through forms, questionnaires, supporting documents, communications, or information you provide to us.
We only collect, hold, use and disclose sensitive information:
- for the primary purpose for which it is collected;
- for a directly related secondary purpose where permitted by law;
- with your express consent where required by law; or
- where otherwise required or authorised by law.
How we collect personal information
We collect personal information in a variety of ways, including when you provide it directly to us, when you use our website or platform, from analytics, cookies and similar tracking technologies, from service providers, from publicly available sources, and from third parties where you have authorised this or where permitted by law.
Why we collect, hold, use and disclose personal information
We collect, hold, use and disclose your personal information to operate our website, platform and related systems; register your interest in matters; facilitate communications; respond to enquiries; administer records and user profiles; provide related services and platform functions; maintain security; improve services; send relevant updates; comply with legal and regulatory obligations; and where otherwise required or authorised by law.
Data minimisation and contact protections
We aim to collect only the information reasonably necessary for the relevant purpose, limit unnecessary exposure of direct contact details, store response data separately where reasonably practicable, and use controlled communication pathways where appropriate.
We do not disclose your direct contact details to third parties unless you authorise us to do so, disclosure is reasonably necessary to provide a service you requested, disclosure is reasonably necessary for the operation of a matter or platform function you have chosen to engage with, or disclosure is required or permitted by law.
Disclosure of personal information
We may disclose personal information to employees, contractors, associated entities, technology and cloud providers, CRM and communications providers, analytics and security providers, marketing providers, professional advisers, payment processors, platform participants, parties connected with a matter, courts, regulators, government agencies, authorised recipients, and other third parties where required or permitted by law.
Overseas disclosure
We may store personal information in Australia, but some service providers, technology providers or cloud systems may store, process or access personal information outside Australia. Where this occurs, we will take reasonable steps to ensure recipients do not breach the Australian Privacy Principles, consistent with our APP 8 obligations.
Your rights and controlling your personal information
Your choice
You do not have to provide personal information to us. However, if you do not provide requested information, this may affect our ability to provide some or all services or platform functions to you.
Access, correction and complaints
You may request access to personal information we hold about you, ask us to correct inaccurate, out-of-date, incomplete, irrelevant or misleading information, or make a complaint about how we have handled your personal information. We may need to verify your identity before responding.
Storage and security
We take reasonable steps to safeguard personal information from misuse, interference, loss, unauthorised access, modification and disclosure. These steps may include access controls, envelope encryption at rest using per-record keys protected by Google Cloud Key Management Service, encryption in transit using TLS, secure cloud infrastructure, role-based access restrictions, logging and monitoring, secure system design and administrative controls.
Cookies and analytics
We may use cookies, pixels, tags and similar technologies for security, diagnostics, analytics, service improvement, performance monitoring, marketing and user experience purposes. Where IP addresses are processed in connection with platform security or consent recording, we store only a one-way hash of the IP address and do not retain the raw IP address.
Use of Artificial Intelligence (AI)
We may use artificial intelligence and machine learning tools in connection with business operations, website, platform and services for analysis, drafting, summarising, improving services, automating certain processes, supporting workflows, quality assurance and support. AI tools may generate automated or assisted outputs which may not always be complete or accurate. You should not rely solely on AI-generated outputs for legal, medical, financial or other significant decisions.
Amendments
We may vary this Privacy Policy by publishing the amended Privacy Policy on our website or platform. We recommend that you check the website regularly to ensure you are aware of our current Privacy Policy.
Contact details
For any questions, notices, access requests, correction requests or privacy complaints, please contact us using the contact form or contact details available on our website or platform.
Related
Trust and legal documents
How personal information is handled
What information is collected and why
Rules for using the registry
How ClassActions.com.au works