Sureplan Friendly Society Ltd ACN 087 649 456 (referred to in this document as we, us or our) recognises that your privacy is very important and we are committed to protecting the personal information we collect from you. The Privacy Act 1988 (Cth) (Privacy Act) and the Australian Privacy Principles (APPs) set out in the Privacy Act govern the way in which we must manage your personal information. This Privacy Policy (Policy) sets out how we collect, use, disclose and otherwise manage personal information about you.
By providing personal information to us, an individual consents to us collecting, holding, using and disclosing its personal information in accordance with this Policy.
Types of information collected
Under the Privacy Act, personal information means information or an opinion about an identified individual, or an individual who is reasonably identifiable:
(a) whether the information or opinion is true or not; and
(b) whether the information or opinion is recorded in a material form or not.
The kinds of information we typically collect include name, address, date of birth, age, contact details like phone numbers and email addresses, financial information and employment information to process your premium payments, health information as well as electronic information from your use of our website (see further below).
Sureplan will not sell your personal information to any third party.
Sensitive information
Except as otherwise permitted by law, we only collect sensitive information about you, such as medical and health information, if you consent to the collection of the information and if the information is reasonably necessary for the performance of our functions or activities, as set out below.
Purpose for which we collect, use and disclose personal information
The personal information that we collect and hold about you, depends on your interaction with us.
Generally, we will collect, use, disclose, and hold your personal information for the purposes of:
a. assessing your application for membership (if applicable);
b. facilitating the delivery of any Sureplan products or services;
c. communicating with you in the event that your application is accepted;
d. providing you with details regarding Sureplan products and services;
e. assessing any claims that you make;
f. making moneys payable by one of our funds in the event of a member’s death available to the person nominated to receive those moneys on behalf of the member’s estate to cover funeral expenses;
g. communicating with the nominee under your policy;
h. using financial or employment details to carry out authorised payment of premiums or contributions, confirmation of new memberships to the signing agent and processing benefit claims;
i. marketing and promotional activities;
j. providing you with information about other services that we, our related entities and other organisations that we have affiliations with, offer that may be of interest to you;
k. facilitating our internal business operations, including the fulfilment of any legal requirements;
l. monitoring, auditing, analysing and evaluating our products and services and customer needs with a view to developing new or improved services; and
m. dealing with any complaints or enquiries.
In some instances, Sureplan may ask for personal details in order to comply with relevant legislation, including the Life Insurance Act 1995, the Corporations Act 2001, or taxation laws to process your application, or provide you with Sureplan’s high standard of service.
We will hold personal information for as long as needed to meet our legal obligations and until we no longer need the information for any purpose for which the information may be used or disclosed under the APPs.
Without limiting any disclosures permitted by relevant laws, we generally disclose personal information about you to:
a. beneficiaries or nominees of any policy you purchase or hold with us;
b. our related entities to facilitate our and their internal business processes;
c. service providers and agents, who assist us in operating our business, and these service providers may not be required to comply with our Policy; and
d. our related entities and other organisations with whom we have affiliations so that those organisations may provide you with information about services and various promotions.
In some circumstances, the law may permit or require us to use or disclose personal information for other purposes.
Method of collection
Personal information will generally be collected directly from you when you engage with us through the use of any of our standard forms, over the internet, via email, or through a telephone conversation. There may, however, be some instances where personal information about you will be collected indirectly because it is unreasonable or impractical to collect personal information directly from you. For example, by applying for cover, you consent to Sureplan collecting (from third parties including hospitals, other health care providers and funeral homes) sensitive information about you and using it to consider your application for insurance, assessing any claims made by you, and any other related purposes.
We will usually notify you about these instances in advance, or where that is not possible, as soon as reasonably practicable after the information has been collected. Your personal information may also be provided to us as part of an application of a family member, friend or other person, for instance when you are the beneficiary of a Sureplan product held by a member.
Failure to provide information or consent
If the personal information you provide to us is incomplete or inaccurate or your consent is not given to certain actions being undertaken Sureplan, we may be unable to provide you, or someone else you know, with the services or products you, or they, are seeking.
Internet users
If you access our website, we may collect additional personal information about you in the form of your IP address. Our website uses cookies. The main purpose of cookies is to prepare customised web pages for users. Without additional personal information, cookies do not identify you personally, but they may link back to a database record about you. We use cookies to monitor usage of our website and to create a personal record of when you visit our website and what pages you view so that we may serve you more effectively.
Our website may contain links to other websites. We are not responsible for the privacy practices of linked websites and linked websites are not subject to our privacy policies and procedures.
We hold and store your personal information in different ways, including in paper and in electronic form. The security of your personal information is important to us. We take all reasonable measures to ensure that your personal information is stored safely to protect it from misuse, loss, unauthorised access, modification or disclosure, including electronic and physical security measures.
Your personal information will be stored in servers located in Australia. We do not currently disclose personal information to overseas recipients and are unlikely to disclose your personal information to overseas recipients.
Our information technology systems, which are password and access-level protected, may only be accessed by our authorised employees and contractors who require access. Some personal information is held in hard copy such as files created when a claim or complaint is made, which are accessible to our claims and complaint-handling employees, their managers and any organisation which is contracted by us to store and secure that information. Other hard copy personal information may be held for internal purposes and administration of our business.
You have a right to request access to the personal information we hold about you, and may do so by making a written request. We will try to acknowledge your request within 14 days of receipt. Where we provide you with access to your requested person information, we will try to do so within 30 days. We may charge you a reasonable fee for providing access to your personal information (but not for making a request for access).We may decline a request for access to personal information in circumstances prescribed by the Privacy Act and if we do, we will provide you with a written notice that sets out the reasons for the refusal (unless it would be unreasonable to provide those reasons).
You have a right to request correction of your personal information. If, upon receiving access to your personal information or at any other time, you believe the personal information we hold about you is inaccurate, incomplete or out of date, please notify us immediately (see Complaints and Feedback below). We will take reasonable steps to correct the information so that it is accurate, complete and up to date.
If we refuse to correct your personal information, we will provide you with a written notice that sets out the reason for our refusal (unless it would be unreasonable to provide those reasons) together with information about the mechanisms available to you to make a complaint within 30 days of receiving your request for correction.
Sureplan may request that any request for correction be made in writing and signed. It is imperative that members advise Sureplan of changes to theirs or their nominee’s details promptly.
If you wish to make a complaint about a breach of the Privacy Act, APPs or a privacy code that applies to us, please contact us as set out below and we will take reasonable steps to investigate the complaint and respond to you within a reasonable time. If you are not happy with our response, you may complain directly to the Office of the Australian Information Commissioner (OAIC) (see below).
If you have any queries or concerns about our PrivacyPolicy or the way we handle your personal information, please contact our privacy officer at:
Street address: Ground Floor, 133 Leichhardt St, Spring Hill Qld 4000
Email address: [email protected]
Telephone: 1800 817 105 or 07 3833 3333
Facsimile: 07 3833 3338
For more information about privacy in general, you can visit the OAIC website at www.oaic.gov.au.
The Notifiable Data Breaches (NDB) scheme under Part IIIC of the Privacy Act establishes requirements for entities in responding to data breaches. Entities have data breach notification obligations when a data breach is likely to result in serious harm to any individuals whose personal information is involved in the breach.
We have procedures in place to ensure compliance with the NDB scheme.