This document declares the undertakings by MBSCA in relation to its handling of Your Data.
MBSCA undertakes to collect Your Data by means that are:
- legal; and
If you visit MBSCA website, your web-browser automatically discloses, and MBSCA web-server automatically logs, the following information: the date and time, the IP address from which you issued the request, the type of browser and operating system you are using, the URL of any page that referred you to the page, the URL you requested, and whether your request was successful. This data may or may not be sufficient to identify you.
Any additional data that you provide, e.g. in a web-form, may also be logged. This data may or may not be sufficient to identify you.
Any additional data that your web-browser automatically provides may also be logged. This will be the case, for example, if your browser has previously been requested to store data on your computer in 'cookies' and submits them each time you request a web-page within a particular domain (such as ThisCompany.com). This data may or may not be sufficient to identify you.
If you disclose personal data to MBSCA in conjunction with an identifier such as your name or your credit-card details, MBSCA will collect Your Data. Moreover, any data that becomes available to MBSCA through any of the means described in the preceding paragraphs may be able to be associated with that identifier, and hence become Your Data.
Subject to the qualifications immediately below, MBSCA undertakes to collect Your Data from you and not from other parties. This undertaking is qualified as follows:
- where MBSCA reasonably considers that the protection of its financial interests requires that it gather MBSCA from other sources, or from additional sources. This applies in particular where MBSCA has a lending exposure to you, and seeks information about your creditworthiness;
- where MBSCA reasonably considers that its capability to deliver quality services to you will be materially enhanced by gathering MBSCA from other sources. This applies in particular to consumer profile data.
- Where MBSCA collects Your Data from sources other than you, it undertakes:
- to do so only by legal means;
- to do so only with your Consent; and
- to declare to you what sources it uses, and under what circumstances.
- MBSCA undertakes to declare the purpose of collection in a manner which is clear and meaningful, and to avoid vague, highly inclusive statements such as 'to support our operations'.
MBSCA undertakes to store Your Data in a manner that ensures security against unauthorised access, alteration or deletion, at a level commensurate with its sensitivity.
MBSCA undertakes to store Your Data only in jurisdictions where data protections are at least equivalent to those required under the OECD Guidelines.
MBSCA undertakes to transmit Your Data in a manner that ensures security against unauthorised access, alteration or deletion, at a level commensurate with its sensitivity.
MBSCA undertakes to implement appropriate measures to ensure security of Your Data against inappropriate behaviour by MBSCA committee. These include:
- training for staff in relation to privacy;
- access control, to limit access to Your Data to those staff and contractors who have legitimate reasons to access it;
- particularly in the case of sensitive data, audit trails of accesses, including the identities of staff and contractors accessing the data;
- reminders to staff and contractors from time to time about the importance of data privacy, and the consequences of inappropriate behaviour;
- declaration of appropriately strong sanctions that are to be applied in the event of inappropriate behaviour
- clear communication of policies and sanctions; and
- processes to audit, to investigate and to impose sanctions.
- Data Use
- Use refers to the application of Your Data by any part of MBSCA, or any staff-member or contractor of MBSCA in the course of their work.
MBSCA undertakes to use Your Data only for:
- the purposes for which it was collected;
- such other purposes as are subsequently agreed between MBSCA and You;
- such additional purposes as may be required by law. In these circumstances, MBSCA will take any reasonable steps available to it to communicate to You that the use has occurred, unless it is precluded from doing so by law; and
- such additional purposes as are authorised by law (in particular to protect MBSCA interests, e.g. if it believes on reasonable grounds that You have failed to fulfil your undertakings to MBSCA or have committed a breach of the criminal law).
- MBSCA undertakes to use MBSCA only if it has demonstrable relevance to the particular use to which it is being put.
MBSCA undertakes to use MBSCA in such a manner as to take into account the possibility that it is not of sufficient quality for the purpose, e.g. because it is inaccurate, out-of-date, incomplete, or out-of-context.
Disclosure refers to making MBSCA available to any party other than MBSCA and You. The term disclosure may include many different conditions of data transfer, including selling, renting, trading, sharing and giving.
MBSCA undertakes to disclose Your Data only under the following circumstances:
- in the course of business being conducted between You and MBSCA, where disclosure is necessary to a contractor, such as a transport company. Where Your Data is disclosed in this way, MBSCA undertakes to exercise control over MBSCA contractors to ensure that their actions are compliant with these Terms;
- in other circumstances that are directly implied by the purpose agreed between You and MBSCA at the time of data collection or subsequently. Where Your Data is disclosed in this way, MBSCA undertakes to exercise control over MBSCA contractors to ensure that their actions are compliant with these Terms;
- with your consent, or at your request;
- where required by law, such as a provision of a statute, or a court order such as a search warrant or subpoena. In these circumstances, MBSCA will take any reasonable steps available to it to communicate to You that the disclosure has occurred, unless it is precluded from doing so by law;
- where permitted by law (e.g. the reporting of suspected breach of the criminal law to a law enforcement agency; and in an emergency, where MBSCA believes on reasonable grounds that the disclosure of MBSCA will materially assist in the protection of the life of health of some person), provided that MBSCA will apply due diligence to ensure that the exercise of the permission is justifiable.
- In all cases, MBSCA undertakes to disclose only such of Your Data as is necessary in the particular circumstances.
Data Retention and Destruction
Subject to the qualifications immediately below, MBSCA undertakes:
- to retain Your Data only as long as is consistent with its purpose; and
- to destroy Your Data when its purpose has expired, and to do so in such a manner that Your Data is not subsequently capable of being recovered.
This undertaking is qualified as follows:
Your Data may be retained in MBSCA logs, backups and audit trails within short-term retention cycles that are devised to protect the company's operations. In such cases, Your Data will be destroyed in accordance with those cycles;
Your Data may be retained beyond the expiry of its purpose if that is required by law, such as a provision of a statute, or a court order such as a search warrant or subpoena, or a warning by a law enforcement agency that delivery of a court order is imminent. In these circumstances, MBSCA:
will take any reasonable steps available to it to communicate to You that Your Data is being retained, unless it is precluded from doing so by law; and
will only retain Your Data while that provision is current, and will then destroy Your Data;
Your Data may be retained beyond the expiry of its purpose if it is authorised by law (in particular to protect MBSCA interests, e.g. if it believes on reasonable grounds that You have failed to fulfil your undertakings to MBSCA or have committed a breach of the criminal law). In these circumstances, MBSCA will only retain Your Data while that situation is current, and will then destroy Your Data.
MBSCA means Melbourne Boston Sister Cities Association
Your Data means data that is capable of being associated with you, whether or not it includes an explicit identifier such as your name or customer number. In particular, it encompasses all data that ThisCompany is capable of correlating with you, using such means as server-logs and cookie-contents.
Your Data does not refer to data that can no longer be associated with you. This includes aggregated data that does not and cannot identify the individuals whose data are included in the aggregation.
Consent means your concurrence with an action to be taken by MBSCA. Consent may be express or implicit, but in either case must be informed and freely-given