Legal

Privacy Policy

Last updated: 10 August 2026

1. About This Policy

Eyestar Consulting Pty Ltd (ABN 50 696 487 082) and Eyestar Resilience Pty Ltd (ABN 87 696 706 742) (together, "Eyestar", "we", "us", "our") are committed to protecting your personal information in accordance with the Privacy Act 1988 (Cth) ("Privacy Act") and the Australian Privacy Principles ("APPs") contained in Schedule 1 of that Act.

This Privacy Policy ("Policy") explains how we collect, use, disclose, store and protect personal information when you visit eyestar.com.au (the "Website") or engage our services. It also explains your rights in relation to that information.

By using our Website or providing us with your personal information, you consent to the collection, use and disclosure of your personal information in accordance with this Policy.

2. What Is Personal Information?

Under the Privacy Act, personal information means information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether the information or opinion is true or not, and whether it is recorded in a material form or not.

Sensitive information is a subset of personal information that includes health information, racial or ethnic origin, political opinions, religious beliefs, sexual orientation and criminal record. We treat sensitive information with a higher level of protection.

3. Information We Collect

3.1 Information you provide to us

We may collect the following personal information when you contact us, enquire about our services or engage us:

  • Full name
  • Email address
  • Phone number
  • Organisation or employer name and role
  • The content of messages or enquiries you send us
  • Information relevant to the services you are enquiring about (e.g. training requirements, team size, industry sector)

3.2 Sensitive information

We do not seek to collect sensitive information unless it is reasonably necessary for our services and you have consented to its collection, or its collection is required or authorised by law. If you voluntarily provide sensitive information (for example, information about a health condition relevant to a training program), we will handle it in accordance with APP 3 and this Policy.

3.3 Technical and usage data

When you visit our Website, we may automatically collect technical information including:

  • IP address and approximate geographic location
  • Browser type and version
  • Operating system
  • Pages visited and time spent on each page
  • Referring URL
  • Date and time of access

This data is collected via server logs and, where applicable, cookies (see Section 7). It is used in aggregate form to improve our Website and is not ordinarily used to identify individuals.

3.4 Information from third parties

We may receive personal information about you from third parties, such as referral partners or organisations that engage us to deliver training to their staff. Where this occurs, we will handle that information in accordance with this Policy.

4. How We Collect Personal Information

We collect personal information in the following ways:

  • Directly from you — when you complete our contact form, send us an email, call us, or engage our services.
  • Automatically — when you visit our Website, through server logs and cookies.
  • From third parties — where an organisation engages us to deliver services to their personnel, or where you are referred to us by a partner.

Where it is reasonable and practicable to do so, we collect personal information directly from you.

5. How We Use Your Information

We use personal information for the primary purpose for which it was collected, and for secondary purposes that are related to the primary purpose and that you would reasonably expect. These purposes include:

  • Responding to your enquiries and providing our services
  • Communicating with you about our programs, training and consulting services
  • Managing our relationship with you and any organisation you represent
  • Administering training programs, including issuing certifications
  • Improving our Website, services and business operations
  • Complying with our legal and regulatory obligations
  • Protecting the rights, property or safety of Eyestar, our clients or others

5.1 Direct marketing

We will not use your personal information for direct marketing without your consent. If you consent to receiving marketing communications, you may opt out at any time by contacting us at [email protected] or by using the unsubscribe mechanism in any marketing email we send you. We will action opt-out requests promptly and within a reasonable period.

6. Disclosure of Personal Information

We do not sell, rent or trade your personal information to third parties.

We may disclose your personal information to:

  • Service providers — third parties who assist us in operating our Website and delivering our services (e.g. hosting providers, email delivery services, payment processors), who are bound by confidentiality obligations and are not permitted to use your information for their own purposes.
  • Accreditation bodies — where required to issue or verify certifications (e.g. MHFA Australia, Driven, Suicide Prevention Australia, ACA, ICF).
  • Client organisations — where we are engaged by an organisation to deliver training to their staff, we may share relevant participant information with that organisation for program administration purposes.
  • Professional advisers — including lawyers, accountants and insurers, where necessary.
  • Regulatory and law enforcement bodies — where required or authorised by law.

6.1 Overseas disclosure

We do not routinely disclose personal information to overseas recipients. If we are required to disclose personal information to an overseas recipient (for example, to an international accreditation body), we will take reasonable steps to ensure the recipient handles the information in a manner consistent with the APPs, or we will obtain your consent before doing so, in accordance with APP 8.

7. Cookies and Tracking Technologies

Our Website may use cookies and similar tracking technologies to improve your browsing experience and analyse site traffic. A cookie is a small text file stored on your device by your browser.

We may use the following types of cookies:

  • Essential cookies — necessary for the Website to function correctly.
  • Analytics cookies — used to understand how visitors interact with the Website (e.g. pages visited, time on site). This data is collected in aggregate and is not used to identify individuals.

You can disable or delete cookies through your browser settings. Disabling cookies may affect the functionality of some parts of the Website. Most browsers allow you to refuse cookies or to be notified when a cookie is set.

We do not use cookies to collect sensitive information or to track your activity across third-party websites.

8. Data Quality and Accuracy

We take reasonable steps to ensure that the personal information we collect, use and disclose is accurate, up-to-date, complete and relevant, having regard to the purpose for which it is used (APP 10). If you believe that information we hold about you is inaccurate, out-of-date, incomplete, irrelevant or misleading, please contact us so we can correct it.

9. Data Security

We take reasonable steps to protect personal information from misuse, interference, loss, unauthorised access, modification or disclosure (APP 11). Our security measures include:

  • HTTPS encryption for all data transmitted via our Website
  • Access controls limiting who within our organisation can access personal information
  • Secure storage of records containing personal information
  • Confidentiality obligations on staff and contractors who handle personal information

When personal information is no longer needed for any purpose for which it may be used or disclosed, and we are not required by law to retain it, we will take reasonable steps to destroy or de-identify it.

While we take reasonable precautions, no data transmission over the internet or electronic storage system is completely secure. We cannot guarantee the absolute security of information you transmit to us.

10. Data Retention

We retain personal information for as long as necessary to fulfil the purposes for which it was collected, including to satisfy any legal, accounting or reporting requirements. The retention period will depend on the nature of the information and the purpose for which it is held. When personal information is no longer required, we will destroy or de-identify it in a secure manner.

11. Your Rights — Access and Correction

Under APP 12, you have the right to request access to the personal information we hold about you. Under APP 13, you have the right to request that we correct personal information that is inaccurate, out-of-date, incomplete, irrelevant or misleading.

To make an access or correction request, please contact us in writing at [email protected]. We will respond within 30 days of receiving your request. We may ask you to verify your identity before processing your request.

We will not charge a fee for making an access request, but we may charge a reasonable fee to cover the cost of providing access where the request is complex or requires significant resources.

If we refuse your access or correction request, we will provide you with written reasons for the refusal and information about how to complain about the refusal.

12. Anonymity and Pseudonymity

Where lawful and practicable, we will give you the option of not identifying yourself or using a pseudonym when interacting with us (APP 2). However, in most cases we will need to identify you to provide our services effectively. If you choose not to provide your personal information, we may be unable to respond to your enquiry or provide our services.

13. Notifiable Data Breaches

We are subject to the Notifiable Data Breaches (NDB) scheme under Part IIIC of the Privacy Act. If we become aware of a data breach that is likely to result in serious harm to any individual whose personal information is involved, we will notify the affected individuals and the Office of the Australian Information Commissioner (OAIC) as required by law.

14. Complaints

If you believe we have breached the APPs or otherwise mishandled your personal information, please contact our Privacy Officer in the first instance:

Privacy Officer
Eyestar Consulting Pty Ltd
Office 21 — L1 / 135 High Street, Fremantle WA 6160
[email protected]

We will acknowledge your complaint within 5 business days and aim to resolve it within 30 days. If you are not satisfied with our response, or if we fail to respond within a reasonable time, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC):

Office of the Australian Information Commissioner
GPO Box 5218, Sydney NSW 2001
Phone: 1300 363 992
oaic.gov.au/privacy/privacy-complaints

15. Changes to This Policy

We may update this Policy from time to time to reflect changes in our practices, technology or legal obligations. The current version, with its effective date, will always be available at eyestar.com.au/privacy. We encourage you to review this Policy periodically. Where changes are material, we will take reasonable steps to notify you.

Continued use of our Website after the effective date of any changes constitutes your acceptance of the updated Policy.

16. Contact Us

For any questions, concerns or requests relating to this Policy or our handling of your personal information, please contact:

Privacy Officer
Eyestar Consulting Pty Ltd
Office 21 — L1 / 135 High Street, Fremantle WA 6160
[email protected]