This policy explains how and when your personal information and other data is collected, used, disclosed, and otherwise handled by the Rottnest Island Authority.
By using our websites and/or providing your personal information to us by any other means, you consent to us handling your personal information in accordance with this policy.
Collection of personal information
We may collect personal information about you during your dealings with us (e.g. when you make an accommodation or tour booking, or when you make and enquiry).
We only collect personal information necessary for our business function, which may include:
• Providing you with Island access, accommodation, or tourism services,
• Answering your queries,
• Arranging and paying for activities or services on your behalf (e.g. Island tours),
• Providing, administering, improving, and personalising our products and services,
• Data analysis, business consulting, auditing, archiving, printing, delivery, and mailing services,
• Administering a promotion or survey, and
• Fraud prevention and credit checks.
We collect most personal information directly from you by way of written forms, our website, by phone, in person, by our representatives, and other correspondence (such as emails and messaging services).
We may also collect personal information about you from third parties, including booking agents and tourist information centres.
If we are unable to collect the personal information we require, or the information provided is incorrect or incomplete, this may affect our ability to provide products or services to you.
Personal information collected by RIA will only be:
• Collected by lawful and fair means,
• Used for lawful purposes, and
• Collected with your consent.
Types of personal information
The specific types of personal information collected and used by Rottnest Island Authority varies according to the purpose for collection, in general this information includes, but is not limited to:
- Residential address / Postal address
- Email address
- Telephone number(s)
- Boat registration
- Credit card details*
Please note: Credit card details are NOT stored on the Rottnest Island Authority website servers. Transactions are processed through our merchant gateway.
Email and Feedback Information
If you subscribe to any services on the Rottnest Island Authority website or provide any comments or feedback via email, then your email address and other personal information you may provide will be maintained on our mailing lists.
Your email address is confidential. When you email us:
• We will record your email address,
• We will only use your email address for the purpose for which you provided it,
• We will not use your email address for any other purpose, and
• We will not disclose it to another party without your consent (though from time to time we may disclose your personal information to a party acting on behalf of Rottnest Island Authority).
Any email correspondence sent to us will be treated as a public record and will be retained as required by the Western Australian State Records Act 2000 and other relevant regulations.
Use and disclosure of personal information
We will use and disclose your personal information for the purposes for which we collected it, and/or for other related purposes that you would reasonably expect. Generally, these purposes include, but are not limited to:
• processing accommodation, products and services, and activity bookings, and to facilitate other transactions relating to those arrangements,
• providing you with marketing information about the goods and services offered by Rottnest Island Authority and third parties, such as Island businesses,
• maintaining a relationship with you as a customer or subscriber to our mailing lists,
• surveys and other market research to assist us in assessing and improving our services, and
• where required for administrative purposes and all other purposes reasonably associated with our business.
By providing us with your personal information, you consent to us using your personal information for the above purposes. You agree that we may send you such information by post or by electronic means (including email and SMS). You can opt-out of marketing and promotional communications at any time using an opt-out mechanism in one of our communications, or by contacting us directly.
Apart from the above instances, we may also use and disclose your personal information with your consent and as otherwise required at law.
We may disclose your personal information to third-party contractors and service providers, including third parties that are located outside of Australia, for the purposes outlined above. Where we do disclose your personal information outside Australia, the countries in which such recipients are likely to be located are the United States of America, the United Kingdom, Europe, India, and Japan.
The Rottnest Island Authority will take reasonable steps to ensure that the overseas recipient does not breach the Australian Privacy Principles.
Accuracy and security
The Rottnest Island Authority will take reasonable steps to:
• ensure that the personal information we collect, use, hold, and disclose is accurate, complete, up-to-date, and relevant for the purpose of its use or disclosure,
• protect personal information from misuse, interference, loss, unauthorised access, modification, or disclosure, and
• destroy or permanently de-identify personal information, which is no longer required, unless the information is contained in a Commonwealth or State record or the Rottnest Island Authority is legally required to retain the information.
How we protect the information we collect
Personal information is held in both electronic and hard copy records, which are stored securely at our facilities or by contracted partners. We take reasonable steps to securely store your personal information to ensure it is protected from unauthorised access, modification, and disclosure, and from other types of misuse, interference, and loss.
We will take reasonable steps to destroy or permanently de-identify your personal information when we no longer require it for any purpose for which it was collected. We may retain your personal information for as long as necessary to comply with any applicable law, for insurance and corporate governance purposes, for the prevention of fraud and to resolve disputes. Your personal information may also be retained in our IT system back-up records.
Online transactions are supported by secure server technology. The technology we use encrypts your personal financial information before it is transmitted over the Internet. You can only transact on our website using a browser that supports secure server technology.
Access and correction
You have the right to both ask:
• for access to personal information that we hold about you
• that we correct personal information we hold about you.
If you ask, we must give you access to your personal information, and take reasonable steps to correct it if we consider it is incorrect, unless there is a law that allows or requires us not to.
Any such requests must be made in writing to Rottnest Island Authority to our Privacy Officer via the email address firstname.lastname@example.org.
The Rottnest Island Authority will respond to written requests within twenty-eight (28) days of the receipt of the request at our offices.
Following the commencement of the Privacy Amendment (Notifiable Data Breaches) Act 2017, the Rottnest Island Authority will take reasonable steps to notify individuals impacted by eligible data breaches (as defined under the Privacy Act), as soon as possible after it becomes aware of the breach.
Some websites accessed via links from the Rottnest Island website may collect personally identifiable information about you when you access or utilise those links. When you leave Rottnest Island Authority’s website you are no longer protected by its privacy provisions.
Collection of Statistical information
Browsing any website generates a trail of the pages that are visited. When you visit our websites, a record of your visit is kept for statistical and research purposes. Our servers may record the following information:
• Server (IP) address and top-level domain name,
• Date and time of the visit,
• Pages accessed and documents downloaded,
• Previous site visited;
• Type of browser used; and
• Selected statistical information (operating system, transfer speed, etc.).
The Rottnest Island Authority examines this information to make its sites more useful to visitors.
No attempt will be made to identify visitors or their browsing activities except in the unlikely event of an investigation, or the need to determine details related to a security breach or other inappropriate activity.
Analytics & Cookies
A cookie is a piece of data sent from a website and stored in a user’s web browser while a user is browsing a website. When the user browses the same website in the future, the data stored in the cookie can be retrieved by the website to notify the website of the user’s previous activity. We use this data to monitor the effectiveness of our websites and to help improve site functionality and the quality of our content.
Cookies have no way of disclosing your name or any personal information. Most browsers can be set to accept or reject cookies. You can choose to adjust your browser to reject cookies or to notify you when they are being used.
We undertake to investigate and respond to any such complaint within twenty-eight (28) days of its receipt at our offices.
Amendments to policy
Privacy Act 1988 (Cth)
Australian Privacy Principles