Privacy Policy

    SuggiCare (The Organisation) ABN: 63191 415 517

    Last Updated: 14 November 2025

    1. Governance and Openness (APP 1: Open and Transparent Management)

    1.1 Our Legal Obligation

    SuggiCare operates as an APP Entity under the Privacy Act 1988 (Cth). We are committed to managing personal information in an open and transparent manner, ensuring compliance with the Australian Privacy Principles (APPs) and all applicable state and territory laws. This policy details our specific practices concerning the collection, use, security, and disclosure of personal information, including data processed by Artificial Intelligence (AI) systems.

    1.2 Policy Availability and Privacy Officer

    This policy is maintained as up-to-date and is available free of charge on our primary digital channel.

    Privacy Officer Contact Details: info@suggicare.com

    2. Collection of Personal Information (APP 3 & 5)

    2.1 Types of Personal Information Collected

    SuggiCare collects personal information that is reasonably necessary for or directly related to our primary functions. This information includes, but is not limited to:

    • Identity and Contact Data: Name, date of birth, mailing and street address, email address, and telephone numbers.
    • Sensitive Information: As defined by the Privacy Act, this is collected only with explicit, informed consent and includes:
      • Criminal History: Results of Police Checks or Working with Children Checks.
      • Health Information: Conditions or medical history provided to ensure workplace safety or enable reasonable adjustments.
    • Operational Data: Skills, qualifications, training history, shift preferences, historical attendance records, and performance feedback.
    • Inferred Data (AI-Generated): Data derived or generated by our AI systems from existing personal information, such as inferred compatibility scores, reliability metrics, and suitability flags. This inferred data is considered personal information under the APPs and is subject to the same protections and access rights.

    2.2 Methods of Collection

    We collect personal information directly from you unless:

    • It is unreasonable or impracticable to do so.
    • It is provided by a third-party source (e.g., referees, government agencies for background checks).
    • It is generated automatically by our systems (e.g., website analytics, transaction logs, or AI inferences).

    3. Dealing with Personal Information (APP 4 & 6: Use or Disclosure)

    3.1 Primary Purposes of Use

    SuggiCare collects and uses personal information solely for the primary purpose for which it was collected, which includes:

    • Contractual and Program Delivery: To assess, place, manage, and support volunteers and staff.
    • Risk Mitigation and Compliance: To ensure legal and safety requirements are met, particularly concerning child protection and workplace health and safety.
    • Service Enhancement: To measure and improve the efficiency and quality of our programs and services.
    • Financial Administration: To process donations, issue receipts, and meet taxation and accounting requirements.

    3.2 Direct Marketing (APP 7)

    SuggiCare may use non-sensitive personal information (e.g., name and email) to send direct marketing communications regarding our charitable appeals, events, and opportunities. You may opt-out of receiving these communications at any time by following the unsubscribe link provided in the communication or by contacting the Privacy Officer.

    4. AI-Assisted Decision Governance (APP 1: Transparency & APPs 12/13: Rights)

    SuggiCare employs an AI-assisted Volunteer Management System (VMS) to optimise resource allocation. All outputs are AI-assisted and subject to human oversight; no material decision is fully automated.

    4.1 Transparency and Data Use for AI

    Non-Sensitive Use: The AI system is designed to use only non-sensitive personal and operational data for its algorithms.

    Model Training: When personal information is utilised to train, test, or refine the AI model, SuggiCare takes all reasonable steps to ensure the data is first de-identified and aggregated to remove any reasonable chance of individual identification.

    The AI system performs the following functions:

    • Intelligent Matching: Recommends best-fit roles based on skills and availability.
    • Predictive Scheduling: Forecasts optimal rosters and potential shift gaps.
    • Compliance Screening: Flags expiry dates for mandatory checks.

    4.2 Accountability and Human Review (AI Governance)

    SuggiCare maintains a duty of care to ensure that the AI system does not result in decisions that cause a significant and material effect on the rights or interests of any individual.

    • Human-in-the-Loop: All high-impact AI outputs (e.g., a "high-risk" flag, an inference suggesting non-suitability for a role) must be reviewed, contextualised, and approved by a trained human manager before any action is taken.
    • Bias Mitigation: We periodically conduct internal audits of the AI system's performance metrics against protected attributes to proactively identify and rectify algorithmic bias.

    4.3 Right to Explanation and Challenge

    If an individual believes a decision regarding their volunteer status, role allocation, or application outcome was unfairly influenced by an AI recommendation:

    • Process: They may request a human review of the decision by contacting the Privacy Officer within 14 days of the outcome.
    • Explanation: SuggiCare commits to providing a timely and clear explanation of the AI's input (the data it processed) and the human manager's reasoning for the final decision.

    5. Security and Data Integrity (APP 10 & 11)

    5.1 Quality of Personal Information

    We rely on the accuracy of the information provided by you and will take reasonable steps to ensure that the personal information we use and disclose is, having regard to the purpose of the use or disclosure, accurate, up-to-date, complete, and relevant.

    5.2 Security Measures

    SuggiCare takes all reasonable steps to protect the personal information we hold from misuse, interference, loss, and from unauthorised access, modification, or disclosure. This includes, but is not limited to:

    • Encryption: Implementing industry-standard encryption protocols for data both in transit (TLS) and at rest (AES-256).
    • Testing: Conducting regular vulnerability and penetration testing of our VMS and data infrastructure.
    • Access Management: Enforcing multi-factor authentication (MFA) and the principle of least privilege for staff access.
    • Data Breach Response: Maintaining a documented and tested Data Breach Response Plan in line with the Notifiable Data Breaches (NDB) scheme.

    6. Overseas Disclosure (APP 8: Cross-border Disclosure)

    6.1 Likely Overseas Recipients

    Your personal information is stored primarily within our cloud-based VMS. The cloud provider may utilise servers located outside of Australia.

    The likely countries where your data may be processed or held include The United States, Singapore, and Ireland.

    6.2 Transfer Mechanisms

    SuggiCare takes reasonable steps to ensure that any overseas recipient of your personal information adheres to principles substantially similar to the APPs, typically by requiring them to execute legally binding contracts (such as Standard Contractual Clauses or equivalent agreements) that mandate appropriate data protection standards.

    7. Access and Correction (APP 12 & 13)

    7.1 Access

    You have the right to request access to the personal information we hold about you. Requests must be submitted in writing to the Privacy Officer. We will respond within a reasonable period (typically 30 days) and will not charge a fee for the request itself, but may charge a reasonable administrative fee for the time and costs associated with locating and providing the information.

    7.2 Correction

    If you believe that any personal information we hold about you is inaccurate, out-of-date, incomplete, irrelevant, or misleading, you may request that we correct it. We will take reasonable steps to correct the information or, if we disagree with your request, we will take reasonable steps to associate a statement with the information that you believe it is inaccurate.

    8. Complaints Process

    If you believe SuggiCare has breached the Privacy Act or any APP, you may lodge a formal complaint with our Privacy Officer (Section 1.2).

    • Acknowledgement: We will acknowledge receipt of your written complaint within 7 business days.
    • Investigation: We will investigate your complaint promptly and confidentially, and aim to provide a written response addressing your concerns within 30 days.

    If you are not satisfied with the outcome of our investigation, you may refer your complaint to the Office of the Australian Information Commissioner (OAIC).

    OAIC Contact:

    Phone: 1300 363 992

    Website: https://www.oaic.gov.au/

    Mail: GPO Box 5218, Sydney NSW 2001

    You are offline. We will retry when you reconnect.