Our commitment to privacy
The Resilience Box Pty Ltd (ACN 636 137 409) and its related companies in Australia (collectively referred to as The Resilience Box) are committed to managing personal information in accordance with the Australian Privacy Principles under the Privacy Act 1988 (Cth) and in accordance with other applicable privacy laws.
About The Resilience Box
The Resilience Box operates The Resilience Box® digital platform which provides tools to navigate life’s challenges both inside and outside of work, which you can use to strengthen your resilience and general wellbeing (the Platform). The Platform provides a wide range of DIY learning activities and enables you to make counselling and coaching appointments.
- What information does The Resilience Box collect about you?
The personal information that we collect from you will depend on the ways in which you engage with us and/or the Platform.
- Users of the Platform
When you register to use the Platform, we collect your name, work email and personal email addresses and phone number. When you use various tools or services which are made available on the Platform, such as completing activities, questionnaires and online assessments or schedule appointments with our psychologists, collected information may include sensitive information, for example, information about your wellbeing, mental health and health concerns. Other information which may be collected includes information recorded in your personal log.
- Corporate clients
When you enquire about our services on behalf of your company or when your company becomes a corporate client of The Resilience Box and you are the key contact, the types of personal information that we collect from you will vary depending on the circumstances of collection and the kind of service that you request from us. Collected information will typically include:
i) your name, e-mail address, postal address and other work-related contact details;
ii) information about your employer or the organisation that you represent;
iii) your professional details; and
iv) any additional personal information you provide to us, or authorise us to collect, as part of your interaction with us.
- Other individuals
We may collect personal information about other individuals who are not users of the Platform and/or corporate clients of The Resilience Box. This may include members of the public who participate in events we are involved with, individual service providers and contractors to The Resilience Box and other individuals who interact with us on a commercial basis.
The kinds of personal information we collect will depend on the capacity in which you are dealing with us. Generally, it would include your name, contact details and information regarding our interactions and transactions with you.
You can always decline to give The Resilience Box any personal information we request, but that may mean that we cannot provide you with some or all of the services you have requested. If you have any concerns about personal information we have requested, please let us know.
How and why does The Resilience Box collect and use your personal information?
The Resilience Box collects personal information which is reasonably necessary to carry out our business, to assess and manage the needs of users of the Platform and our clients and to provide services including the wide range of services made available via the Platform. We may also collect information to fulfil administrative functions associated with these services, for example billing, entering into contracts with you or third parties and managing client relationships.
The purposes for which we usually collect and use personal information depends on the nature of your interaction with us, but may include:
a) Users of the Platform
Your personal information will be used to:
- assist you to monitor and improve your wellbeing and resilience. When you complete various assessments or questionnaires on the Platform, for example, we will provide you with content which is tailored to your assessment responses;
- enable you to book and manage psychologist and/or coaching appointments you make using the Platform; and
- provide you with online training modules, as well as access to videos and fact sheets.
In order that we can provide you with our services, the Platform stores information it collects from users, such as search histories, online training which has been completed, assessments and reports, as well as details of appointments scheduled with our psychologist and/or coaches.
b) Corporate Clients and Suppliers
Your personal information will be used to administer and manage our relationship with your company.
c) Other Uses of Personal Information
Your personal information may also be used, for example, for the following purposes:
- responding to requests for information and other general inquiries;
- managing, planning, advertising and administering programs, events, competitions and promotions;
- to inform you about our services, including new content and features added to the Platform;
- to contact you about upcoming promotions and events in relation to your wellbeing that may interest you;
- for internal business and management processes; and
- responding to complaints.
The Resilience Box also collects and uses personal information for market research purposes and for service innovation. While no personal information of users of the Platform will be disclosed to their employers, de-identified and aggregated data, such as statistics, may be provided to our corporate clients and third parties from time to time.
The Resilience Box generally collects personal information directly from you. We may collect and update your personal information via the Platform, over the phone, by email, over the internet or in person.
We may also collect personal information about you from other sources, for example:
- your employer, if your employer has engaged us to make the Platform available to its workforce;
- our related companies; and
- third party suppliers and contractors who assist us to operate our business.
How does The Resilience Box disclose personal information?
- Users of the Platform
If you are a registered user of the Platform, we may disclose your personal information to third parties, such as service providers whom we have engaged to provide services on our behalf such as our consulting psychologists or as required by law. If you are an individual subscriber and we provide services to you, we may provide your personal information to our payment processors. Where we consider it necessary, we may disclose your personal information to an emergency service provider, such as an ambulance service, the police or fire brigade.
Where you provide consent, your personal and/or sensitive information may be disclosed to your treating psychologist or other health professional.
- Corporate clients
The purposes for which we may disclose your personal information will depend on the services we are providing you. For example, if you have engaged us to deliver a service, we may disclose information about you to service providers where this is relevant to our services.
- Disclosure to contractors and other service providers
The Resilience Box may disclose information to third parties we engage in order to provide our services, including contractors and service providers used for data processing, data analysis, client and user satisfaction surveys, information technology services and support, website maintenance/development, printing, archiving, mail-outs and market research. Information disclosed is limited to the information which is reasonably necessary for these third parties to perform their limited functions for us.
Personal information may also be shared between related companies of The Resilience Box, located in Australia.
Third parties to whom we have disclosed your personal information may contact you directly to let you know they have collected your personal information and to give you information about their privacy policies.
- Disclosure for administration and management
The Resilience Box will also use and disclose personal information for a range of administrative, management and operational purposes. This includes:
i) administering billing and payments and debt recovery;
ii) planning, managing, monitoring and evaluating our services;
iii) quality improvement activities;
iv) statistical analysis and reporting using aggregated and de-identified data;
v) training staff, contractors and other workers;
vi) risk management and management of legal liabilities and claims (for example, liaising with insurers and legal representatives);
vii) responding to enquiries and complaints regarding our services;
viii) obtaining advice from consultants and other professional advisers; and
ix) responding to subpoenas and other legal orders and obligations.
- Other uses and disclosures
- Users of the Platform
Does The Resilience Box disclose your personal information overseas?
Personal information is not disclosed routinely to overseas recipients, except for a limited range of personal information (names and contact details) which is disclosed to our USA-based provider of customer relationship management software.
How does The Resilience Box interact with you via the internet?
You can use the settings in your browser to control how your browser deals with cookies. However, in doing so, you may be unable to access certain pages or content on our website.
The Resilience Box’s website may contain links to third-party websites. We are not responsible for the content or privacy practices of websites that are linked to our website.
Can you deal with The Resilience Box anonymously?
The Resilience Box will provide individuals with the opportunity of remaining anonymous or using a pseudonym in their dealings with us where it is lawful and practicable (for example, when making a general enquiry). Generally, it is not practicable for us to deal with individuals anonymously or pseudonymously on an ongoing basis. If we do not collect personal information about you, you may be unable to utilise the Platform, our services or participate in our events, programs or activities that we may manage or deliver.
How does The Resilience Box hold information?We take reasonable steps to protect your personal information from misuse, interference and loss and from unauthorised access, modification or disclosure.
Personal information may be collected in paper-based documents and converted to electronic form for use or storage (with the original paper-based documents either archived or securely destroyed).
The Resilience Box maintains physical security over paper and electronic data stores, such as through locks and security systems at our premises. We also maintain computer and network security, for example, we use firewalls (security measures for the internet) and other security systems such as user identifiers and passwords to control access to our computer systems, as well as double encryption. Our IT systems comply with relevant security standards. Only authorized personnel are permitted to access these systems. Individual login credentials are encrypted.
Digital data, including personal information collected via the Platform, is stored in the Cloud in Australia.
We take steps to destroy or de-identify information that we no longer require.
Does The Resilience Box use or disclose your personal information for direct marketing?The Resilience Box may use or disclose your personal information for the purpose of informing you about our services, including new content and features added to the Platform. We may also contact you about upcoming promotions and events in relation to your wellbeing that may interest you.
If you do not want to receive direct marketing communications, you can opt-out at any time by contacting us using the contact details below. If you opt-out of receiving marketing material from us, we may still contact you in relation to our ongoing relationship with you.
We do not send your personal information to third parties for direct marketing purposes.
How can you access or seek correction of your personal information?You are entitled to access your personal information held by The Resilience Box on request. To request access to your personal information, please contact our Privacy Officer using the contact details set out below.
You will not be charged for making a request to access your personal information but you may be charged for the reasonable time and expense incurred in compiling information in response to your request.
We will take reasonable steps to ensure that the personal information we collect, use or disclose is accurate, complete and up-to-date. You can help us to do this by letting us know if you notice errors or discrepancies in information we hold about you and letting us know if your personal details change.
However, if you consider any personal information we hold about you is inaccurate, out-of-date, incomplete, irrelevant or misleading, you are entitled to request correction of the information. After receiving a request from you, we will take reasonable steps to correct your information. Alternatively, you may be able to update your contact information, for example, by logging into your account on the Platform.
We may decline your request to access or correct your personal information in certain circumstances in accordance with the Australian Privacy Principles. If we do refuse your request, we will provide you with a reason for our decision and, in the case of a request for correction, we will include a statement with your personal information about the requested correction.
You may make a complaint about privacy to the Privacy Officer using the contact details set out below.
The Privacy Officer will first consider your complaint to determine whether there are simple or immediate steps which can be taken to resolve the complaint.
Your complaint will then be investigated. We may ask you to provide further information about your complaint and the outcome you are seeking. We will then typically gather relevant facts, locate and review relevant documents and speak with individuals involved.
In most cases, we will investigate and respond to a complaint within a reasonable time, usually within 30 days of receipt of the complaint. If the matter is more complex or our investigation may take longer, we will let you know.
If you are not satisfied with our response to your complaint, or you consider that The Resilience Box may have breached the Australian Privacy Principles or the Privacy Act, you may make a complaint to the Office of the Australian Information Commissioner. The Office of the Australian Information Commissioner can be contacted by telephone on 1300 363 992 or by using the contact details on the website www.oaic.gov.au.
How can you contact The Resilience Box?
Our contact details are:
The Privacy Officer
The Resilience Box Pty Ltd
PO Box Q197
Queen Victoria Building NSW 1230