Legal
Privacy Policy
MortarCAPS Higher Learning Data Standard Limited handles personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). This page summarises how we collect, use, protect, and share that information; the formal Privacy Collection Notice sits alongside it.
Last reviewed:
Formal policy documents: This page is a plain-English summary. The board-approved Privacy Policy and Privacy Collection Notice are the authoritative documents and govern in case of any inconsistency.
Download the Privacy Policy (PDF) ↗ Download the Privacy Collection Notice (PDF) ↗ All policies
Who is responsible
MortarCAPS Higher Learning Data Standard Limited (ABN 21 684 569 864, ACN 684 569 864) is the data controller for personal information collected via this site and through our operations. We are a registered charity with the Australian Charities and Not-for-profits Commission (ACNC).
What information we collect
We collect information you give us directly — for example, when you contact us through this site, sign a licence agreement, attend a townhall or working group, or subscribe to our updates. This may include name, organisation, role, work email and phone, and any information you include in your messages to us.
How we use it
- To respond to enquiries and run our partner programmes.
- To run working groups, townhalls, and the standard's release process.
- To meet our regulatory and audit obligations as an Australian registered charity.
- To send relevant updates about the standard. You can opt out of these at any time.
Who we share it with
We do not sell personal information. We share it only with our service providers (hosting, email, accounting), our auditors, and, where relevant, peak bodies and partner institutions acting on a need-to-know basis. Anyone we share information with is bound by equivalent obligations of confidentiality and security.
Overseas disclosures
MortarCAPS operates across Australia, New Zealand and Canada. In line with Australian Privacy Principle 8, we may disclose personal information to overseas recipients — principally partner organisations, peak bodies and service providers in Canada. Where we do so, we take reasonable steps to ensure those recipients handle personal information consistently with the APPs. Some of our service providers (e.g. cloud hosting, email) may also process data in the United States or Europe under equivalent contractual protections.
How long we keep it
We retain personal information only for as long as it is needed for the purpose it was collected, or as required by law. Our full retention schedule is set out in the Data Governance & Retention Policy (PDF) ↗.
Security
We apply security controls proportionate to the sensitivity of the information we handle. Our information-security management system is developed in line with recognised industry standards. See our Information Security Policy (PDF) ↗.
If something goes wrong — data breach response
If a data breach is suspected or confirmed, we follow our Data Breach Response Plan (PDF) ↗. Where a breach is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) in accordance with the Notifiable Data Breaches (NDB) scheme under Part IIIC of the Privacy Act.
Your rights
You can ask us what personal information we hold about you, ask us to correct it, or ask us to delete it (subject to our legal obligations). Email hello@mortarcaps.org with your request and we will respond within a reasonable timeframe (usually 30 days).
Making a privacy complaint
If you believe we have handled your personal information contrary to the APPs, please tell us. Send your complaint in writing to hello@mortarcaps.org with "Privacy complaint" in the subject line. We will:
- Acknowledge your complaint within 5 business days.
- Investigate and provide a written response within 30 days.
- Work with you to resolve the concern.
If you are not satisfied with our response, you can escalate to the Office of the Australian Information Commissioner (OAIC) — oaic.gov.au or 1300 363 992.
Privacy contact
Our named Privacy Officer is Gemma Williams, Head of Operations. All privacy enquiries and complaints should be directed to her at hello@mortarcaps.org. Postal mail can be addressed to Privacy Officer, MortarCAPS Higher Learning Data Standard Limited, 368 Sussex St, Sydney NSW 2000, Australia.
Cookies and analytics
This site uses minimal first-party cookies strictly necessary for navigation and to remember display preferences. We do not use third-party advertising or profiling trackers. We do not currently run analytics; if we add privacy-respecting analytics in future, we will update this page first and give visitors clear notice.
Updates
We will publish material updates to this policy on this page with the new "last reviewed" date at the top.