PRIVACY POLICY
Effective date: 1 August 2026
Version: 2.0
1. About this policy
The Sapphire Project (“Sapphire”, “we”, “us” or “our”).
We are committed to protecting personal information and handling it with care, transparency and respect.
This Privacy Policy explains how we collect, hold, use and disclose personal information through:
sapphireproject.com.au and its related pages;
The Sapphire Project’s events, initiatives and community activities;
Young Sapphires;
Sapphire Circle;
our online shop;
newsletters and other communications;
sponsorship, partnership and organisation submissions;
fundraising and donation-related activities;
social media and digital content; and
any other interaction you have with us.
Where the Privacy Act 1988 (Cth) applies to us, we comply with it and the Australian Privacy Principles. We also aim to apply the Australian Privacy Principles as our minimum privacy standard wherever reasonably practicable.
“Personal information” means information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether or not the information is true or recorded in a material form.
2. Who this policy applies to
This policy applies to supporters, donors, event attendees, customers, subscribers, volunteers, committee members, artists, partner organisations, sponsors, grant applicants, suppliers, contractors, Young Sapphires participants, parents and guardians, website visitors and other people who interact with us.
Some services linked from our website are operated by other organisations, including donation, ticketing, payment, social media, video and photographic gallery providers. Those organisations handle personal information under their own privacy policies.
3. The personal information we may collect
The personal information we collect depends on how you interact with us and may include:
Identity and contact information
Your name;
email address;
telephone or mobile number;
postal, billing or delivery address;
age or age range, where relevant;
organisation, school, employer or community affiliation;
position, title or role; and
parent, guardian or emergency contact information where appropriate.
Enquiries, submissions and relationship information
Information included in messages, enquiries and correspondence;
your reason for contacting us;
organisation names, websites and Australian Business Numbers;
sponsorship and partnership interests;
information about environmental organisations, initiatives and proposed projects;
project objectives, impact information and funding requirements;
survey responses, feedback and preferences;
records of our relationship and communications with you; and
testimonials, stories, artwork or other material you choose to submit.
Please do not provide personal information about beneficiaries, colleagues or other third parties unless it is necessary and you are authorised to do so. Wherever possible, project and impact information should be provided in a de-identified or aggregated form.
Event information
Registrations, invitations, RSVPs and attendance records;
ticketing or transaction confirmation;
guest information;
seating, dietary, accessibility or other participation requirements;
emergency or safety information where reasonably necessary;
event preferences and feedback; and
photographs, video, audio and other recordings made at events.
Donation information
Donations are processed by the Great Barrier Reef Foundation, GBRF USA Inc or another approved fundraising provider.
Where authorised, we may receive limited donor information such as:
Your name and contact details;
donation date and amount;
campaign or event associated with the donation;
receipt or acknowledgement status;
whether you wish to remain anonymous; and
your communication preferences.
We do not receive or store complete payment-card or bank-account details used to make a donation.
Shop and order information
When you purchase from our online shop, we may collect or receive:
Your name and contact details;
billing and delivery addresses;
products ordered;
order value and transaction confirmation;
delivery, fulfilment and tracking information;
gift messages or delivery instructions;
communications relating to the order; and
return, refund or customer-service information.
Complete payment-card information is generally collected directly by our ecommerce or payment provider and is not visible to or stored by Sapphire.
Young Sapphires information
Where required to operate Young Sapphires activities, we may collect:
A young person’s name, age or age range;
school or community affiliation;
contact information;
parent or guardian details and permissions;
activity registrations and participation records;
artwork, stories, ideas, photographs or recordings submitted with permission;
communication preferences; and
information necessary to support safety, accessibility and participation.
We limit the collection of information about children and young people to what is reasonably necessary for the relevant activity.
Applications and participation
If you apply to work, volunteer, serve on a committee or otherwise participate in Sapphire’s work, we may collect information about your experience, qualifications, interests, references and suitability for the role.
Technical and website information
When you use our website or digital services, we and our service providers may collect:
IP address;
browser and device information;
operating system;
cookie and similar technology identifiers;
pages viewed and links selected;
referring website;
date, time and duration of visits;
approximate location derived from an IP address;
interactions with emails or embedded content; and
security, diagnostic and error information.
Communication preferences
We may record whether you wish to receive newsletters, event invitations, fundraising communications, Young Sapphires updates or other information, together with your unsubscribe and consent preferences.
4. Sensitive information
Sensitive information includes information about health, disability, racial or ethnic origin, religious beliefs, sexual orientation, political opinions and certain other protected matters.
We collect sensitive information only where it is reasonably necessary for our activities and:
you have consented;
it is necessary to protect someone’s health or safety;
it is required or authorised by law; or
another lawful exception applies.
For example, we may collect dietary, accessibility or health information to support safe participation in an event. We may also receive information about First Nations identity or cultural affiliation where it is relevant to a project and provided with appropriate consent.
Please avoid including unnecessary sensitive information in free-text forms or emails.
5. How we collect information
We may collect personal information:
Directly from you through website forms, event registrations, purchases, emails, telephone conversations, surveys, applications and in-person interactions;
when you subscribe to a newsletter or mailing list;
when you attend or participate in an event;
when you interact with us on social media;
automatically through cookies, analytics and related technologies;
from a parent, guardian, school or authorised organisation;
from the Great Barrier Reef Foundation, GBRF USA Inc, ticketing providers, venues, partner organisations, payment providers, delivery providers or other service providers;
from someone who refers or introduces you, where they have authority to do so; and
from publicly available sources where lawful and reasonably expected.
Where required, we provide a shorter collection notice at or before the point of collection. That notice should be read together with this policy.
If we receive personal information that we did not request, we will consider whether we could lawfully have collected it. If not, we will take reasonable steps to destroy or de-identify it, where lawful and practicable.
6. Anonymity and pseudonyms
Where lawful and practicable, you may interact with us anonymously or using a pseudonym.
We may need your correct identity where it is necessary to process an order, arrange delivery, issue a receipt, administer an event, assess an application, protect participant safety or meet legal obligations.
7. If you do not provide information
You are not required to provide personal information to us. However, if required information is not provided, we may be unable to:
respond to an enquiry;
process an order or arrange delivery;
administer an event registration;
consider a partnership or organisation submission;
provide a requested service;
support safe participation in an activity; or
send communications you have requested.
8. How we use personal information
We may use personal information to:
respond to enquiries and communicate with you;
manage our relationship with supporters, partners, organisations, sponsors, artists and community members;
administer events, initiatives, programs and Young Sapphires activities;
assess sponsorship, partnership and organisation submissions;
process and fulfil shop orders;
coordinate delivery, returns, refunds and customer support;
support fundraising and donor acknowledgement activities;
provide impact reporting and updates;
manage newsletters, invitations and community communications;
create and publish event, impact and educational content where appropriate;
conduct surveys, research and program evaluation;
improve our website, events, communications and supporter experience;
maintain accurate records and communication preferences;
protect our community, systems, events and website from misuse, fraud or security threats;
manage volunteers, committee members, contractors and service providers;
comply with accounting, insurance, legal and regulatory obligations;
establish, exercise or defend legal claims; and
carry out another purpose disclosed when the information was collected or authorised by you.
We will not use personal information for an unrelated purpose unless you consent or the use is otherwise permitted or required by law.
9. Donations and the Great Barrier Reef Foundation
The Sapphire Project does not itself receive or hold funds from donations or ticket sales.
Donations and relevant fundraising transactions are administered through the Great Barrier Reef Foundation. The organisation processing the transaction is responsible for collecting payment information, issuing receipts and handling that information under its own privacy policy.
Where you have authorised it, or where otherwise lawful, Sapphire may receive limited information from the relevant fundraising provider for:
acknowledging your support;
administering an event or campaign;
maintaining accurate supporter records;
sending requested impact updates;
understanding fundraising outcomes; and
communicating with you in accordance with your preferences.
We do not use donor information for an unrelated purpose or provide it to another organisation for that organisation’s independent marketing without appropriate consent.
10. Online shop and payments
Our website, ecommerce and payment providers may collect and process payment information directly. Their privacy policies and terms apply to their handling of that information.
Sapphire generally receives only the information needed to confirm, fulfil and support an order.
We may disclose order information to:
payment and ecommerce providers;
artists or authorised fulfilment partners;
couriers and postal services;
technology and customer-support providers; and
professional advisers where reasonably necessary.
We retain transaction records for the periods required by applicable accounting, tax, consumer and other laws.
11. Events, photography and recordings
Photography, video and audio recording may take place at Sapphire events.
Where practicable, we provide notice through event information, registration materials or venue signage. Images and recordings may be used to document and communicate Sapphire’s work through:
our website;
social media;
event galleries;
newsletters;
impact reports;
media and public relations;
fundraising and partner communications;
educational material; and
Sapphire’s historical archive.
For identifiable portraits, interviews, testimonials and content focused on a particular person, we will seek appropriate permission where required.
If you do not wish to be photographed or recorded, please contact us before the event or notify a member of the event team. We will take reasonable steps to respect your preference, although we cannot guarantee that a person will be excluded from every incidental crowd or background image.
If you later withdraw permission, we will consider the request and, where reasonably practicable, stop future use or remove the material from channels we control. We may not be able to retrieve printed material, archival records or content already shared or republished by third parties.
Additional protections apply to images and recordings of children and young people.
12. Children and Young Sapphires
For this policy, a child or young person is someone under 18 years of age.
When handling information about children and young people, we seek to:
act in their best interests;
provide clear and age-appropriate explanations;
collect only the information reasonably necessary;
use the information only for the activity or purpose explained;
maintain appropriate safety and access controls;
avoid collecting precise location, financial or government-identifier information unless genuinely necessary;
avoid behavioural advertising or commercial profiling using children’s information;
avoid selling or renting children’s personal information;
provide appropriate ways to ask questions, correct information or request deletion; and
involve a parent, guardian or authorised school representative where appropriate.
A young person may provide consent where they have sufficient understanding and capacity to make an informed decision. Where that is not reasonably clear, or where the nature of the activity requires it, we will seek consent from a parent or guardian.
We may communicate directly with a young person who has requested Young Sapphires information where it is appropriate and lawful. Depending on the young person’s age and the nature of the activity, we may involve or copy a parent, guardian, school or other authorised adult.
We will not publish an identifiable child’s photograph, recording, artwork or personal story without the appropriate permission.
A young person, parent or guardian may contact us to request access, correction, withdrawal of consent or deletion. We will consider the young person’s capacity, wishes, safety, privacy and best interests when responding.
We will continue to review these practices as Australia’s Children’s Online Privacy Code and other child-safety and privacy requirements develop.
13. Newsletters and direct marketing
With your consent or where otherwise permitted by law, we may send:
newsletters and impact updates;
event invitations;
fundraising communications;
information about Sapphire Circle or Young Sapphires;
shop or product updates; and
other information reasonably connected with Sapphire’s work.
You can unsubscribe at any time using the link in an email or by contacting us. We will process unsubscribe requests promptly and within the period required by law.
Unsubscribing from marketing does not prevent us from sending necessary service messages, such as an order confirmation, event update, safety notice or response to an enquiry.
We do not sell or rent mailing lists. We do not provide personal information to another organisation for its independent direct marketing without express consent.
Where required by law and reasonably practicable, we will tell you the source from which we obtained information used for direct marketing.
14. Cookies, analytics and embedded content
Our website and service providers may use cookies, pixels and similar technologies for:
website functionality and security;
remembering preferences;
understanding website traffic and performance;
diagnosing errors;
measuring engagement with communications; and
displaying embedded video, photographic galleries or social media content.
Third-party content—such as videos, social media posts, payment pages or photographic galleries—may allow the relevant provider to collect information about your device and interaction.
You can control many cookies through your browser settings and, where available, our cookie preference tools. Blocking some cookies may affect website functionality.
We do not knowingly use children’s personal information for targeted behavioural advertising.
15. When we disclose personal information
We may disclose personal information where reasonably necessary to:
the Great Barrier Reef Foundation, GBRF USA Inc or an approved fundraising provider;
website hosting, form, ecommerce, email, cloud-storage, analytics, cybersecurity and IT providers;
payment processors;
event registration and ticketing providers;
venues, event producers, photographers and videographers;
artists, fulfilment partners, couriers and postal services;
partner organisations, schools or community organisations involved in an activity;
accountants, auditors, lawyers, insurers and other professional advisers;
regulators, courts, law-enforcement agencies and government bodies;
a party involved in a proposed restructure, transfer or combination of our operations; and
another party where you have consented or disclosure is required or authorised by law.
We take reasonable steps to limit disclosures to the information needed for the relevant purpose.
16. Overseas disclosure and processing
Some service providers and recipients may be located outside Australia.
At the date of this policy, overseas recipients are likely to be located in:
the United States; and
Singapore.
Cloud, email, content-delivery, security, social media and other technology providers may also process information through facilities in additional countries.
Where practicable, we will identify relevant countries in this policy, in a collection notice or through the relevant provider’s privacy information.
Where Australian privacy law requires it, we take reasonable steps appropriate to the circumstances to ensure overseas recipients handle personal information consistently with the Australian Privacy Principles. However, privacy protections and legal remedies may differ between countries.
You may contact us if you would like further information about likely overseas disclosures relevant to your interaction with Sapphire.
17. Data security
We take reasonable technical, administrative and physical measures to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure.
These measures may include:
access controls and authentication;
secure and reputable service providers;
encryption in transit where supported;
limiting access to people who need the information;
confidentiality expectations for team members and service providers;
system maintenance, backups and security monitoring;
secure disposal practices; and
incident-response procedures.
No website, email system or data-storage service can be guaranteed to be completely secure. You should take care when sending personal information online and avoid sending unnecessary sensitive information by ordinary email or free-text forms.
18. Retention and deletion
We retain personal information only for as long as reasonably necessary for the purpose for which it was collected, including to:
provide services and administer relationships;
fulfil orders and resolve enquiries;
maintain event, donor and organisational records;
meet accounting, tax, insurance, contractual and legal requirements;
resolve disputes and protect legal rights;
maintain a record of communication preferences; and
preserve appropriate historical and impact records.
Retention periods vary depending on the type and sensitivity of the information.
When personal information is no longer required, we take reasonable steps to destroy or de-identify it, unless we are required or authorised to retain it.
We may retain a limited suppression record after an unsubscribe request to ensure that the person is not added back to a marketing list.
Approved photographs, publications and historically significant records may be kept for longer as part of Sapphire’s archive. Information about children and young people will be reviewed particularly carefully and removed when it is no longer reasonably necessary.
Deleted information may remain in secure backups for a limited period until those backups are overwritten in the ordinary course of business.
19. Data breaches
We maintain procedures for responding to suspected privacy and data-security incidents.
If an incident occurs, we will take reasonable steps to:
contain the incident;
assess what happened and what information was affected;
reduce the risk of harm;
remedy identified weaknesses; and
notify affected individuals, the Office of the Australian Information Commissioner or another regulator where required by law.
20. Access, correction, withdrawal and deletion requests
You may contact us to:
request access to personal information we hold about you;
ask us to correct information that is inaccurate, incomplete, out of date, irrelevant or misleading;
withdraw consent for a future use;
change communication preferences; or
request deletion or de-identification of information that is no longer required.
We may ask you to verify your identity before acting on a request.
We do not charge for making an access or correction request. If the law permits us to charge a reasonable cost for providing access, we will explain that cost before proceeding.
We will respond within a reasonable period. In some circumstances, the law may permit or require us to refuse access, correction or deletion. If this occurs, we will provide written reasons where required and explain available complaint options.
Withdrawing consent does not affect uses or disclosures that occurred lawfully before the withdrawal, and we may retain information where required or authorised by law.
Where a request concerns a young person, we will consider the young person’s capacity, privacy, wishes and best interests, as well as the authority of the person making the request.
21. Privacy complaints
If you believe we have mishandled personal information, please contact our Privacy Officer using the details below and include:
your name and contact details;
a description of your concern;
relevant dates or communications; and
the outcome you are seeking.
We will acknowledge and investigate the complaint and aim to provide a substantive response within 30 days. If additional time is required, we will explain why and provide an updated timeframe.
If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner:
Website: https://www.oaic.gov.au/privacy/privacy-complaints
You may also have the right to contact another privacy, consumer or regulatory authority depending on where you live.
22. Third-party websites and social media
Our website may link to external donation pages, ticketing services, shops, photographic galleries, video platforms, social media accounts and partner websites.
We are not responsible for the privacy practices of those third parties. We encourage you to review the applicable privacy policy before providing personal information.
When you engage with Sapphire through a social media platform, both Sapphire and the platform may receive information about your interaction.
23. Automated decision-making
We do not currently use personal information to make solely automated decisions that could reasonably be expected to significantly affect an individual’s rights or interests.
If this changes, we will update this policy before or when required to explain the relevant personal information, computer programs and types of decisions involved.
24. Changes to this policy
We may update this policy to reflect changes in our activities, technology, service providers or legal obligations.
The current version will be published on our website with its effective date. Where a change is material, we may also provide notice through our website or direct communications where appropriate.
25. Contact us
For privacy enquiries, requests or complaints, contact: Privacy Officer / The Sapphire Project
Please use the contact form.