Heide Museum of Modern Art Privacy Policy

Introduction

Heide Museum of Modern Art, 7 Templestowe Road, Bulleen, Victoria, 3105, Australia (Heide) is committed to the protection of your personal information in accordance with the National Privacy Principles set out in the Privacy Act 1988 (Cth) and the Information Privacy Act 2000 (Vic).

This Privacy Statement reflects our firm commitment to you. It sets out our policies in relation to the way we collect and handle information.

Heide collects two types of information. The first type is anonymous information. For instance, we may collect information to tell us that five hundred people download this Privacy Policy from the website this month, but we do not know their names, where they live or their date of birth - they are 'anonymous' to us. The second type of information that Heide collects is personal information.
‘Personal information’ is any information or opinion (recorded in any form) about a person, whether true or not, from which that person may be identified. Heide will collect personal information when you provide it to us, that lets us know the specifics of who you are, such as your name, email address, or postal address. With this information, Heide can provide a variety of personalised and enhanced services that are not available to anonymous users. We hope that you will find it beneficial to provide individually identifiable information about yourself to us
because it will make our services more valuable to you.

We collect anonymous and personal information from a variety of sources, such as when you:

• access our website, or
• voluntarily provide us with your personal information via email, telephone, post or online, or
• attend the gallery spaces located at 5 and 7 Templestowe Road in
Bulleen (the Museum).

We encourage you to read our Privacy Statement regularly as it may change from time to time.


How we collect and use personal information

General collection of personal information

We collect personal information from or about you in a variety of circumstances. For example, when you:

• apply for membership with the Museum
• apply for employment or to become a volunteer with the Museum
• buy a ticket to attend the Museum
• make a purchase from our retail shop
• complete a market research survey or customer feedback questionnaire
• request information from us (via email, telephone or post)
• make a donation to the Museum
• visit Heide’s website
• participate in the Museum’s exhibitions or education and public programs.


We collect different types of information for different reasons. For example, when you apply for membership with us, or request information from us, we collect contact details from you (which may include your name, email address, postal address, mobile phone number and/or other phone numbers) so that we can:

• contact you, or
• send information that you have requested.


We collect financial information (such as credit card details) from you in order to receive payment from you for donations, services or products that you order. We may also collect your birthday information (optional) for future use in various promotions.


We also collect information on an optional basis about your preferences (such as types of seminars or events you may be interested in attending) and other demographic and profile data (such as postcode, age range), so that we can tailor the information we provide to you according to your preferences. We sometimes provide this information to our sponsors and supporters on an aggregated basis (that is, without identifying any individual).

On occasion, we collect information about potential donors, sponsors or members from information that is publicly available (such as the Who's Who publication). We use this information to help us develop our donor, sponsorship and membership programs.

Sensitive information

Heide does not collect any information about your racial or ethnic origin, political opinions or membership, religious or philosophical beliefs, trade association or union membership, sexual preferences or criminal record, unless:

• you have given us specific consent to do so, or
• where we are required by law to do so, or
• it is necessary to prevent a serious and imminent threat to the life or health of a person, or
• it is necessary for the establishment, exercise or defence of a legal claim.

Collection of personal information via the Heide website

As a user or potential user of the Heide website, Heide may seek and collect information from you for marketing and internal reporting purposes. This Privacy Policy describes the manner in which Heide collects, holds and uses personal information via our website.

Heide will not collect any personal information about visitors to the website except when they knowingly provide it or as otherwise described below. For example, Heide will collect personal information from users to its website when they register to receive e-mail notifications or Heide e-bulletins.

Click stream data

Click stream data is information about the path that a user takes while using the web. Heide collects click stream data to measure and evaluate site use for statistical, marketing and reporting purposes and as a basis
for making ongoing site improvements for users. When you visit the Heide website, we record your visit and log information about your visit. Some
of the information we log includes:

• your server's address
• your top-level domain name (for example .com, .gov, .au, .uk, etc.)
• times and dates of visits to the site
• pages accessed and files downloaded
• your operating system
• the type of browser you are using; and
• the address of the site that has referred you to Heide.

We use this information to help us improve visitors’ online experience and the collection of this type of information is common on most websites. A summary form of this information is sometimes shared with our stakeholders. Heide does not
identify or record specific individual user details such as the names and addresses of users.

Cookies

Cookies are small text files that are transferred to a user's computer hard drive by a website for the purpose of storing information about a user's identity, browser type or website visiting patterns.

If you access the website, a cookie may be downloaded onto your computer's hard drive when you first log onto the website and if it is, it will be automatically deleted when you log out or close your web browser.

Detecting and preventing cookies
Many web surfers object to having files, like cookies, placed onto their hard drive without their permission. There are various things you can do to avoid cookies if you do not trust them, these include:
• Setting the browser cookie file to be Read Only. Whether you can do this or not may depend on what sort of Operating System (OS) or browser you are using. If you can do this then the cookies will only last for as long as your browser is running.
• Setting up your computer to delete the cookies file whenever you start your browser.
• Many browsers allow you to adjust settings so that you are notified when a cookie is to be written to your computer. However there may be instances where there are so many cookies that it becomes annoying to reject them all.
• Installing a software product which will reject or manage cookies for you, these include Cookie Crusher, Cookie Pal and Cookie Cruncher. You can perform an internet search to find them.

Web Beacons

Web beacons are images that originate from a third party site to track visitor activities. Heide does not currently use web beacons to track the visiting patterns of individuals accessing its website and no third party collects information from this website.

Protecting children and their privacy

Heide’s website is intended for use by people of all ages but please be aware that some exhibition content explores confronting themes and may show partial or full nudity. We ask that persons under the age of 18 have a parent or guardian supervise access to our site and verify any registration or data submission. We strongly encourage parents and guardians to talk to their children about their use of the Internet and the information they disclose to websites.

Links to other sites

The Heide website may contain links to other websites that are not operated or controlled by Heide. Heide takes reasonable care in linking websites, however any links are provided for convenience only and may not be current. Links to external websites do not constitute an endorsement or a recommendation of any material on those sites or of any third party products or services offered by, from or through those sites. This website privacy statement does not extend beyond the Heide website. Use of external links provided by this website is at your own risk. When linking to other sites, you should familiarise yourself with their
website privacy statements.

Other use and disclosure of information

Heide treats personal information that we collect from you in the same way that we treat our other confidential information. Heide will not sell to anyone, the information that we collect about you.

Heide will not disclose to a third party, the information which we collect about you, except where it is necessary to conduct our business (ie mail house or financial institution), and then only if the third party:

• first enters into appropriate confidentiality undertakings with us, or
• has a privacy policy, which is similar to ours.

Secondary use of information

We may use or disclose personal information which we collect from you for a purpose (the ‘secondary purpose’) which is different from the primary purpose of collection, if:

• the secondary purpose is related to the primary purpose, and
• you would reasonably expect us to so use or disclose such information.

For example, if we collect information about your attendance at a particular event, we may use that information to provide you with promotional materials about a similar event in the future. However, if we do this, we will always give you an opportunity to 'opt-out' (that is, to request not to receive any such promotional materials in the future).

We can also use or disclose personal information for a secondary purpose if it is permitted under the Information Privacy Principles (of the Information Privacy Act 2000). For example:

• where you have given us specific consent to do so, or
• where we are required by law to do so, or
• it is necessary to prevent a serious and imminent threat to the life or health of a person, or
• as a necessary part of an investigation of unlawful activity.

Marketing

Heide may use your personal information to provide you with promotional material about Heide or on any of the services offered by Heide. As noted above, if you do not wish to receive this type of promotional material Heide will always give you an opportunity to 'opt-out' or you can contact Heide whose details are listed below at any stage in the future so that Heide can remove your name from Heide's marketing lists.

Who we disclose personal information to

Other than as set out in this Privacy Policy or as authorised by you, Heide will not disclose any of your personal information to any other organisation unless the disclosure is required by law or is otherwise permitted by the National Privacy Principles.

In addition to disclosing your personal information to other users where authorised by you, Heide may disclose the information of users, including you, to its business partners, but only on terms requiring them to comply with this statement. If you do not wish to receive promotional information, you can contact Heide at any stage in the future so that your name can be removed.

Heide may also disclose your information to other persons in order to give effect to legally binding agreements between you and Heide. For example, if you have agreed to pay for a particular item, Heide may give your details to the provider so that they can bill you. Heide may also disclose your personal information to its website host and technology service providers in certain limited circumstances, for example, when the website experiences a technical problem, to ensure that it operates in an effective and secure manner. Otherwise, Heide will not disclose any of your personal information to any other organisation unless the disclosure is required by law or is otherwise permitted by the National Privacy Principles.

Your consent

Heide will only collect and use personal information with your consent and only within the limits of this Privacy Policy.

If you choose not to provide your personal information to Heide for the purposes set out in this Privacy Policy, it is possible that Heide will not be able to provide you with the requested product or service.

Updating, storage and security of personal information held by Heide

Heide aims to keep your personal information secure and up to date. Any personal information that is collected via the website or which is held on Heide's computer systems is protected by safeguards including physical, technical (firewalls, SSL encryptions etc) and procedural methods.
Heide does not collect sensitive or financial information about its users via its website. Personal information that is held by Heide in hard copy is stored securely on its premises
and is only disclosed or used for the purposes described in this Privacy Policy.

You can update your profile information in relation to receipt of Heide e-bulletins at any time by logging onto the website and following the appropriate links.

Heide’s website provides for communications with other users within the Heide Blog. Comments within the blog constitute communication between users that is stored on the Heide website.

Other personal information provided voluntarily by you in response to surveys, competitions etc is archived on a regular basis and treated as confidential information.

Testimonials, complaints and other feedback may be stored indefinitely.

Security of information

Heide will take all reasonable steps to protect the personal information that we hold from misuse and loss, and from unauthorised access, modification or disclosure.

The inherent nature of the internet means that the security of any transmission of information to us using the internet cannot be guaranteed.

However, once the information reaches our control it is protected by our computer network's firewall, which is designed to prevent unauthorised access to our computer network.

We also have systems in place within our organisation to ensure that personal information is handled in a way that is consistent with our Privacy Policy.

Your right to access and correct information

Integrity of information

We will take all reasonable steps to ensure that your personal information which we collect, use or disclose is accurate, complete and up to date.

Your right of access

You have the right to access personal information that Heide holds about you. If the information we hold about you is inaccurate, incomplete or out of date, you can ask us to modify our records.

If you request access to your personal information, we will grant your request unless providing you with access would unreasonably impact upon the privacy of others or is not otherwise permitted under the National Privacy Principles. If Heide refuses your request to access your personal information, it will provide you with reasons for this refusal.

A request for access can be done in any of the following ways:

T 03 9850 1500

email: info@heide.com.au

write to:

Heide Museum of Modern Art
7 Templestowe Road, Bulleen Victoria 3105

Freedom of information requests should be made in writing, describing the documents requested. An application fee of $22.70 is required and other charges may apply to Freedom of Information requests, to find out more please refer to Freedom of Information Online, Victoria. Charges other than the application fee may be waived if the request is a routine request or for access to a document related to the applicant's personal affairs. The application fee can be reduced or waived if the applicant would be caused hardship because he/she had to pay the fee.

Our right to refuse

We reserve the right to refuse your request if:
• you have not paid our prescribed fee for accessing the information, or
• we consider your request to be frivolous or vexatious, or
• to do so is likely to prejudice an investigation of possible unlawful activity, or
• to do so will be unlawful, or
• we are otherwise legally entitled to do so (whether under the Information Privacy
Principles, or generally by law).

Reasons for refusal

If we refuse your request to either access your personal information, or modify our records about you we will provide you with the reasons for our refusal.

Statement of claim

If you consider that the personal information which we hold about you is inaccurate, incomplete or out of date, and we refuse your request to modify our records, we will post a statement of your claim at the place where we hold your personal information.

Heide staff use of and access to personal information held by Heide

Heide employees and contractors may also be users of the website, and their employment may give them access to information not generally available to other users. Heide has taken all reasonable steps to prevent unauthorised access of its computer systems by Heide staff and requires that its employees and contractors comply with the Privacy Policy.

Copyright Policy

Copyright notice

This website contains copyright material, including but not limited to text, graphics, photographs, images, moving images, sound, illustrations and software (’content’).

All rights in the website and the content shall remain the exclusive property of Heide or its licensors.

No content displayed on this website may be reproduced, communicated, copied or altered without Heide’s express permission. Use and referral is only permitted for the purposes of research or study if full and proper attribution is given. For Indigenous works, this may include attribution of both the artist and community.

Unauthorised publication or reproduction and any commercial use or reproduction of any content or any part of this website is specifically prohibited.

If Heide grants permission to reproduce any content of part of the website, it is your responsibility to obtain permission from the copyright holders or their agents before using, reproducing or requesting an alteration to any content or any part of the website. Requests and enquiries concerning reproduction and rights should be directed to Heide.

Disclaimer

This Privacy Policy is subject to relevant legislation set out above. To the extent that this Privacy Policy provides for greater privacy protection than required by law, Heide will not be liable for any loss, liability, cost, expenses or damage arising as a result of it failing to meet that increased standard of privacy protection from under this Privacy Policy.

Heide operates this website for the purpose of disseminating information free of charge for the benefit of the public. Heide updates the information on the website regularly. In particular, details in the ‘What’s On’ section of the website are subject to change without prior notice.

However, Heide gives no express or implied warranties and makes no representations in relation to this website, its content or any software associated with this website. In particular, Heide does not warrant or represent that:
• the information provided on the website is accurate, complete, up to date or suitable for any purpose, or
• your access to the website will be continuous and uninterrupted

Heide and its officers, employees, agents and representatives will not be liable for any loss or damage (including consequential loss or damage) to any person, however caused (whether by negligence or otherwise) which may arise directly or indirectly in respect of any information, content or software provided on this website or otherwise in respect of this website.

Users should be aware that the World Wide Web is an insecure public network. As such, it gives rise to a potential risk that a user's transactions are being viewed, intercepted or modified by third parties or that files which the user downloads may contain computer viruses, disabling codes, worms or other devices or defects.