DRAFT FOR LEGAL AND GOVERNANCE REVIEW — NOT AN APPROVED OR FINAL PRIVACY POLICY
About this draft
This draft describes personal-information handling visible in the Foundation’s current local website snapshot. It must be reviewed against the Foundation’s approved practices, contracts, retention requirements and Australian legal obligations before publication as a final policy.
Who this website relates to
This website is operated for 52 Degree Foundation Limited. Final privacy contact details, responsible officer details and any approved complaints route remain to be confirmed.
Information the website may collect
Depending on the service used, the website may collect:
- names, email addresses, phone numbers, postal addresses and enquiry content;
- donor identity, donation amount, payment method and receipt information through GiveWP;
- grant and scholarship application information through WPForms, including information about children, parents or carers, schools, organisations and referees;
- child date of birth, gender identity, residency, language, school and Aboriginal or Torres Strait Islander heritage where requested by an application;
- sensitive information about disability, diagnosis, long-term health conditions, disadvantage, financial hardship, NDIS participation and household circumstances;
- financial evidence and supporting documents, including quotes, professional or school letters and, in some scholarship workflows, ATO Income Statements or Centrelink Statements;
- technical and usage information such as IP address, device/browser data, pages viewed, referral information and interaction events;
- live-chat messages and related technical information if Tawk.to chat is used.
Application forms in the audited local snapshot are currently inactive. This draft does not authorise or announce their reopening.
Children and sensitive information
The Foundation’s programmes may involve information about children and young people and information that may be sensitive. Collection must be limited to information genuinely required for an approved programme. Parent, carer or other authority, notice and consent requirements are pending legal and safeguarding review. Do not use the general contact channel to send medical, identity, income or other sensitive supporting documents.
Why information may be used
Subject to approved programme and legal requirements, information may be used to respond to enquiries; receive and assess grant or scholarship applications; verify eligibility and supporting evidence; communicate with applicants, carers, organisations or referees; administer donations and receipts; maintain security and records; investigate misuse; improve website performance; and meet applicable governance, accounting or legal requirements.
Systems and providers identified in the website
- WordPress provides the website and administrative platform.
- WPForms is installed for contact, grant and scholarship forms and can store submissions and uploaded documents in the WordPress database and uploads area. It is inactive in the audited local snapshot.
- GiveWP is installed for donation and fundraising records. The audited local setup is test-mode, USD and manual/offline only; no live payment gateway is represented by this draft.
- Google Analytics 4 is loaded using Google tag `G-FH4L7Q25H7` and may receive website usage and device information.
- Tawk.to chat code is loaded and may receive chat and technical usage information.
- Website hosting, email delivery and backup providers may hold or transmit website records, but the approved provider list, locations and contracts were not established in this audit.
Use of a software product does not by itself establish the legal role, storage location or approved disclosure terms of its vendor. Those matters require confirmation.
Disclosure and overseas handling
Information may be disclosed only where required for an approved Foundation function, to authorised personnel and approved service providers, or where required by law. Google Analytics and Tawk.to are third-party services and may process information outside Australia. Hosting, email, backup, payment and other provider locations remain unverified and must be confirmed before final approval.
Storage, security and access
Website records may be stored in the WordPress database, web-hosting storage, form upload directories, email notifications and backups. The audit did not prove private-file access controls, role separation, retention deletion, breach handling or provider safeguards. These controls must be approved and tested before sensitive application collection is reopened.
Retention
Retention periods are unresolved. The Foundation must approve and publish appropriate retention and deletion rules for enquiries, applications, unsuccessful applications, supporting documents, donor records, analytics, chat records, logs and backups. Information should not be promised as deleted or retained for a particular period until those rules and system capabilities are confirmed.
Access, correction and privacy complaints
The verified identity-checking process, privacy contact, access/correction workflow, response timeframes and external complaint information are pending governance and legal approval. General contact details are available on the Contact page. The Feedback & Complaints page is also a governance placeholder and is not yet an approved complaints process.
Changes and approval
This draft must be updated when approved forms, providers, payment services, retention rules, safeguarding controls or legal requirements change. A final effective date and approval authority must be added only after formal review.