PRIVACY & DATA PROTECTION POLICY FOR GLWS SURVEY & WEBSITE
At EEK & SENSE, we are tenacious and rigorous in our approach to delivering best-in-class products and services. We always try to be fair, honest and ethical in everything we do. We’re collaborative and community-oriented in supporting our clients. This also means being committed to achieving the data security and privacy standards clients would expect from us. This website and the EEK & SENSE business is operated by E.E.K. & SENSE Pty Ltd ACN 606 086 793, an Australian company.
EEK & SENSE keep confidential all information we collect directly. We only use the information for the purpose stated at the point of collection or as otherwise set out in this Policy. We seek your specific permission for any additional use. You may choose to have this information removed at any time. We never barter, trade or sell access to your information.
This Policy describes the types of information, including personal information, collected and processed 1) through the GLWS survey 2) directly through GLWS websites and 3) indirectly by GLWS websites. It also describes how EEK & SENSE treats such information.
Information collected by the GLWS survey
The GLWS survey is a wellbeing survey delivered via the internet, owned and operated by EEK & SENSE. The survey and reporting system is hosted on a platform which is developed, owned and maintained by Kendall Want Associates.
A client/coach accredited in the use of GLWS may have ordered and arranged the purchase of the GLWS survey for you, and may have provided EEK & SENSE with your personal information sufficient to email you a confidential log-in to access and complete the GLWS survey.
What information is collected when completing the GLWS?
The GLWS survey collects your responses to questions regarding your evaluation of your personal and workplace wellbeing, some of which might be considered to be of a sensitive, personal nature. We also ask how you identify yourself in relation to a range of demographic variables (including name, gender, email, income, age, seniority, relationship status, country of residence). This data is collected only after obtaining your affirmative express consent, as below.
What is this information used for?
Your evaluations of your personal and workplace wellbeing are collected to provide you with a Personal Wellbeing Report, which will be provided to your GLWS accredited coach to debrief with you. We might also use your data and aggregate this with other peoples’ data, to create a GLWS Team or Group Report, but if this happens, it will be anonymised – no names or identifiers attached.
Your demographic variables (except for your name) are collected for research purposes only and will not appear in your Personal Wellbeing Report or be made available to your coach. Again, for research analyses, we would aggregate your data with that of many other respondents and this would be anonymised.
Who will see my information?
Access to your data and responses to the survey is strictly limited to specific individuals within EEK & SENSE and to GLWS accredited users who are trained to respect user privacy. The access given to these individuals is restricted to their need for such information for business purposes.
The survey system creates your GLWS Personal Wellbeing Report automatically and this is then saved by EEK & SENSE as a password protected PDF. We provide a link to this document to your GLWS accredited coach for them to access and download the Report before sharing this with you in your debrief session. All GLWS accredited coaches sign Terms and Conditions of Use which mandate that GLWS Personal Wellbeing Reports are not shared with anyone other than the individual respondent. Your employing organisation is not provided with a copy of your Report by EEK & SENSE or by your GLWS Accredited coach.
After completion of the survey and debrief of your GLWS Personal Wellbeing Report from your GLWS accredited coach, you may choose to share your survey results. If you do so, you are responsible for any loss or damage resulting from the disclosure including any costs or liability we incur, and we may claim them back from you. If you do not want your personal information shared in this way, please do not provide your GLWS information to your network or anywhere else, and please take steps to keep your Report secure for yourself.
Giving your informed consent for data collection, processing and sharing
Completing the GLWS is voluntary and this should be your free choice without any sense of obligation to complete the survey. You can choose not to proceed at any point. EEK & SENSE will provide you (the survey respondent) with information about the purpose and process for your survey completion, as part of the survey’s introduction and to obtain your explicit informed consent prior to commencing the survey.
Even after you have given your consent, you can withdraw this at any time and request to have your responses erased. You may also choose ‘Not Answered’ as your response to any or all questions as you proceed through the survey.
After completion of the GLWS survey, you can contact us immediately by emailing firstname.lastname@example.org to opt-out of the processing of your results or sharing of your confidential Report with your accredited GLWS coach.
You can ask at any time to have a look at the data you have given us in the GLWS survey, and if you feel there are any inaccuracies in this, we will rectify any actual inaccuracies or press delete – your choice.
We will obtain your additional explicit (opt in) consent if any information you provide as part of the GLWS survey is to be (i) disclosed to a third party for any purpose other than those expressly set out in this Policy; or (ii) used for a purpose other than those for which it was originally collected or subsequently authorised by you through the exercise of opt-in choice. We are not required to obtain affirmative express consent (opt-in) with respect to personal information where the processing, use or disclosure is expressly permitted by applicable privacy law which may include where it is (a) in your vital interests and it is not feasible to obtain your consent; (b) necessary for the establishment of legal claims or defences; (c) required to provide medical care or diagnosis and it is not feasible to obtain your consent; (d) necessary to carry out our obligations in the field of employment law; or (e) comprises information that is manifestly made public by you.
Direct collection of information from GLWS websites
When contacting us, responding to a call for action from us, registering or setting up an account on a GLWS website or providing feedback to us, you may provide personal information including your name, e-mail address, company name and your phone number. If you choose to purchase any products, services, access codes or other items for sale by GLWS or EEK & SENSE, you may be asked to provide payment details and your full address for billing purposes.
As a customer/user, we will use your personal information for the following purposes:
- To provide you with the products and services you request.
- To communicate with you about your account or transactions with us and send you information about features on our sites or changes to our policies.
- To provide support including product updates, product development and other similar communications.
- To notify you about new product releases and service developments, and to advertise GLWS’s products, services and events in accordance with this Policy.
If the client/user relationship between us is terminated, we will cease to use your personal information. However, we may be obliged to store your personal information due to statutory retention requirements.
If you have consented to receiving e-mail communications from us but wish to discontinue this service, you may request to do so at any time by contacting us, or by unsubscribing from the email communication itself.
Information collected indirectly by GLWS websites
When you visit a GLWS website, our server makes a record of your visit and logs the following information (referred to as Tracking Data) including your server IP address, your top-level domain name (for example .com, .au, .net etc), date and time of your visit to our site, the pages you accessed, the documents you downloaded, the previous site you visited and the type of browser you used.
We collect this data to facilitate website and system administration, including monitoring to prevent security breaches and enhancement of the website to meet users’ needs.
To obtain this Tracking Data, we use third-party web analytics providers (Google Analytics) who use “cookies”. Cookies are text files placed on your computer, to help us analyse how users use GLWS websites. The information generated by the cookie about your use of GLWS websites, including your IP address, will be transmitted to and stored by Google Analytics servers. On behalf of EEK & SENSE, Google Analytics will use this information for evaluating your use of GLWS websites, compiling reports on website activity and providing other services relating to website activity. They will not associate your IP address with any other data held by them. Only designated administrators of the GLWS websites can access the information gathered by Google Analytics. The information is used only for administrative and planning purposes to meet the needs of our users, such as to improve the content of the site and to customise the content and/or layout of the site for individuals or groups of users.
We will not attempt to identify users or their browsing activities unless legally required to do so, such as in the event of an investigation e.g. where a law enforcement agency exercises a warrant to inspect our server’s logs.
We operate in Australia
Our Head Office is located in Australia so your information may be transferred to, processed or stored in Australia, or other locations globally.
The processing, storing and securing of the online GLWS survey data is undertaken by Kendall Want Associates, a third-party hosting service provider (our ‘data processor’). This includes the personal information and responses submitted by respondents to create their GLWS Personal Wellbeing Report. Our data processor processes and stores all the GLWS personal data in Australia.
We also use the following third party service providers:
From time to time, we may share personal information with vendors or agents working on our behalf for the purposes described in this Policy. For example, we may hire companies to assist with protecting and securing our systems or services, or to assist with analysing aggregated data trends.
We will obtain your consent before sharing your personal information with any third party for any purpose not disclosed in this Policy which is materially different from the purpose for which it was initially collected or subsequently authorised by you. An exception to this will be where we are required to respond to lawful requests by public authorities, including to meet national security or law enforcement requirements.
Privacy laws require us to ensure that our hosting service provider and any other third-party service providers we use comply with applicable privacy laws unless you agree otherwise.
Information security & data breach notifications
We understand and fully endorse the need for user privacy, and we maintain appropriate security procedures to protect your information from loss, misuse and unauthorized access, disclosure, alteration and destruction, taking into due account the risks involved in the processing and the nature of the personal information. We have appointed an internal Privacy Administrator to monitor privacy practices.
We will comply with all applicable mandatory data breach notification laws.
Remember that e-mail sent over the Internet is not secure, and could be intercepted without your knowledge. EEK & SENSE has other methods of receiving information such as normal mail, phone and secure document transfer and you may prefer to use one of these methods when contacting us.
Compliance and Cooperation with Regulatory Authorities
At EEK & SENSE we have undertaken to comply with the European Parliament and Council’s General Data Protection Regulation (GDPR), effective from 25th May 2018 as the most stringent law, globally, regulating how companies protect citizens’ personal data.
Options for limiting use of your personal information
You have the right to access the personal information that we hold about you. You may object to the use or processing of your personal information or withdraw consent to use your personal information at any time.
You may also ask us to correct, update, delete or otherwise modify that information where it is inaccurate, or has been processed in violation of applicable privacy laws. We may decline to do so where we have to keep the information for legitimate business or legal purposes or we do not agree with your requested amendments (in which case, we will include a note with your personal information that you have requested it to be amended). When updating your personal information, we may ask you to verify your identity before we can act upon your request.
We may reject access or correction requests that are unreasonably repetitive, require disproportionate technical effort (for example, developing a new system or fundamentally changing an existing practice), risk the privacy of others, or would be extremely impractical (for instance, requests concerning information residing on backup systems). We will respond to access requests within a reasonable time period in a reasonable manner and readily intelligible form. We may charge a fee that is not excessive to cover the costs of providing access, and we may set a reasonable limit on the number of times within a given period in which access requests from a particular individual will be met.
Questions & Concerns
If you have any questions or if you want to update, delete or change any personal information we hold, or you have a concern about the way in which we have handled a privacy matter, please use our contact form to send us a message or email to email@example.com
We will investigate and attempt to resolve in a prompt manner any concerns and disputes regarding use and disclosure of personal information in accordance with this Policy. If you are an Australian resident, privacy complaints may also be made directly to the office of the Australian Information Commissioner through its website located at www.oaic.gov.au/privacy/privacy-complaints.
Changes to this Policy
We may change this Policy at any time and from time to time. The most recent version of the Policy is reflected by the version date located at the bottom of this Policy. All updates and amendments are effective immediately upon notice, which we may give by any means, including but not limited to, by posting a revised version of this Policy or other notice on the Website. We encourage you to review this Policy often to stay informed of changes that may affect you, as your continued use of the Website signifies your continuing consent to be bound by this Policy. Our electronically or otherwise properly stored copies of this Policy are each deemed to be the true, complete, valid, authentic and enforceable copy of the version of this Policy which were in effect on each respective date you visited the Website.
Acknowledging all of the above, by providing us with information (including personal information), using GLWS products or services or registering to use GLWS products or services, you:
(a) consent to us disclosing and transferring personal information, data and information (including the categories of personal information listed in this Policy) to our hosting service provider and any other third party provider for the purpose of allowing them to host all data necessary to support the GLWS product or service you use and for us to provide, and facilitate payment for, the information and services accessible via GLWS products or services;
(b) consent to us, our hosting service provider and any other third-party service providers transmitting, maintaining and storing personal information, data and information (including the categories of personal information listed in this Policy) between and on servers located outside of Australia; and
(c) agree that the requirement under privacy laws (if applicable) for us to ensure that our hosting service provider and any other third-party service providers we may engage from time to time comply with applicable privacy laws in respect of personal information, data and information you provide (including the categories of personal information listed in this Policy) does not apply.
26 February 2018