Sandcastles News

privacy policy

Sandcastles Children’s Hospice Privacy Policy, as of 24 April 2026

This privacy policy sets out our practices in relation to the collection use, storage and disclosure of personal information.

Sandcastles Children’s Hospice is a brand of PCHF Hospice Limited (ABN 11 667 723 300). In this policy, “we” means PCHF Hospice Limited.

We are bound by the Privacy Act 1988 (Cth) (the Privacy Act) as well as other applicable laws protecting privacy, including State and Territory health information legislation.

We may modify or update this privacy policy from time to time by publishing it on this website. We encourage individuals to check our website periodically to ensure that they are aware of our current Privacy Policy.

The below sets out what information we collect and why. We’ll only collect information we need, we’ll be clear about why we need it, and we’ll ask for your consent where the Privacy Act requires it. You can ask us to stop using your information for marketing or fundraising at any time.

Responsible persons and children’s data

We don’t knowingly collect information from children aged 16 or under without the consent of a parent or guardian.

The following responsible persons may be treated as being able to act on behalf of a patient within the Child & Adolescent Health Service of WA (CAHS) who is aged 16 or under for the purposes of this privacy policy and the collection, use and disclosure of personal information:

  • A guardian, parent, carer or other person responsible for the care of the patient;
  • Someone with a general power of attorney or a power of attorney which includes health-related power;
  • A person recognised under a law as responsible for any aspect of the care or welfare of the patient which is relevant to something we do or intend to do.

The personal information we collect and why we collect it

We collect personal information from you that is necessary for us to perform our functions. The types of personal information we collect, and the purposes of collecting that information are set out below:

What we collect

Why we collect it

Contact and identity details – name, phone number, address, email, date of birth

To communicate with you, acknowledge your support, send newsletters and updates, and respond to enquiries. Where we collect date of birth, we do so only to ensure that the person we are communicating with is over the age of 18.

Payment information – billing address, payment method, credit card or bank details

To process donations, issue tax receipts, and manage recurring giving

Donation and supporter history – records of gifts, event participation, volunteer activity, and communications between us

To recognise your support, tailor our communications, measure the effectiveness of our fundraising, and invite you to future activities

Sensitive information (with your consent) – health information, including any connection your family has to Perth Children’s Hospital or the former Princess Margaret Hospital for Children

To understand your connection to our cause and share relevant stories and appeals, where you’ve agreed to this

Patient information (with guardian or carer consent) – a patient’s name, age, medical condition, treatment, and history

To share patient stories for fundraising, awareness, and media purposes, only where consent has been given and on the terms agreed

Photographs and video – images of patients, families, donors, volunteers, and supporters at our events

To promote events, share stories with our community, and raise awareness of our work, with the consent of those involved

Grant application and reporting information – applicant contact details, project and financial details, and (where consent has been given) details of patients and families connected to the project

To assess funding applications, administer grants, and evaluate the outcomes and impact of funded projects

Employment and volunteer application information – work history, references, and screening records including criminal history and Working with Children Checks

To assess your suitability for a role with us and meet our child-safe obligations

Supplier and contractor information – names and contact details of individuals who work for our suppliers, contractors, and agents

To manage our day-to-day business operations and contractual relationships

 

Generally, we collect information directly from the relevant individual. Sometimes, we may need to collect information about an individual from third parties including parents, carers, guardians or other third party information sources. We will do this if the individual, or in the case of a patient, their guardian or carer, has consented for us to collect, use or disclose the information in this way, or where it is not reasonable or practical for us to collect this information directly from the individual.

How we use and disclose personal information

We use the personal information we collect to:

  • Process your donation and issue your tax receipt
  • Communicate with you about our work, our impact, upcoming appeals, and events – by phone, post, email, SMS, or other electronic means, in line with your preferences
  • Acknowledge and recognise your support, including through stewardship communications and donor recognition where you’ve agreed to this
  • Run events and fundraising activities, including registering participants, sharing event stories, and promoting future activities
  • Share patient and family stories that have been provided to us with consent, for fundraising, awareness, and media purposes
  • Assess and manage grant applications, fund projects, and evaluate their outcomes and impact
  • Recruit and manage staff and volunteers, including verifying eligibility to work with children and young people
  • Run our organisation, including managing suppliers and contractors, meeting our financial, audit, and reporting obligations, and improving how we work
  • Respond to your enquiries, requests, and complaints

You can ask us to stop contacting you for fundraising or marketing purposes at any time. Every email we send includes an unsubscribe link, and you can contact us directly using the details at the end of this policy.

Who we share your information with

We share your information only where it’s needed, and we require anyone we share it with to protect it to the same standard we do.

We may share your information with:

  • Service providers and contractors who help us operate, including payment processors, IT and cloud hosting providers, CRM and email platforms, mailing houses, grant management platforms, and analytics providers
  • Professional advisors such as auditors, lawyers, and accountants
  • Government agencies and regulators where we are required or authorised by law, including the Australian Taxation Office for receipting purposes
  • Patient families where we are discussing a story they have agreed to share, or third parties helping to promote a fundraising activity that involves their story
  • A successor organisation in the event of a merger, restructure, or transfer of our activities

Sending information overseas. Some of our service providers store or process information outside Australia, including in the United States and the European Union. Where this happens, we take reasonable steps to ensure your information is handled consistently with the Australian Privacy Principles.

The security of your personal information

We take the security of your information seriously and use a range of measures to protect it, including:

  • Access controls, so only staff and contractors who need your information to do their job can see it
  • Encryption of information in transit between your device and our systems
  • Staff training on privacy and information handling
  • Secure disposal of information we no longer need

No system is completely secure, and we can’t guarantee absolute security, but we work to protect your information using current good practice.

If we experience a data breach that is likely to cause you serious harm, we will notify you and the Office of the Australian Information Commissioner in line with the Notifiable Data Breaches scheme.

We keep your information only for as long as we need it for the purposes set out in this policy, or for as long as we’re required to by law (for example, donation records for tax and audit purposes). When we no longer need it, we securely delete or de-identify it.

Cookies

Our website uses cookies and similar technologies to help it work properly, understand how visitors use it, and improve the experience we offer. Cookies are small files placed on your device when you visit a website.

We use three categories of cookies:

  • Strictly necessary cookies make the website work, for example remembering items in your online store cart or keeping you logged in. The website won’t function properly without these.
  • Analytics cookies, including Google Analytics, help us understand how people use our website so we can improve it. These collect information in an aggregated form.
  • Marketing cookies, including Google Ads, allow us to show relevant ads to people who have visited our website. These are set by third parties.

You can control cookies through your browser settings, including blocking cookies or deleting existing ones. Blocking some cookies may affect how parts of the website work.

You can also opt out of Google’s advertising and analytics cookies directly:

Accessing and correcting your personal information

Generally, you have the right to access the personal information we hold about you. We will handle requests for access to personal information in accordance with the Privacy Act. To request access to your personal information, please contact us using the contact details at the end of this privacy policy.

When you request access, we may need to take measures to verify your identity. If you would like a copy of the personal information that we hold about you, in order to verify your identity, please send the request to us in writing, by mail to the address set out at the end of this privacy policy.

In some cases, we may need time to consider and respond to your request for access. If we need time to consider your request, we will acknowledge your request within 14 days and respond within 30 days after your request is made.

If for any reason we refuse to give you access to your personal information, or we do not give you access in the manner in which you have requested, we will provide you with a written notice giving you the reasons for our refusal (unless it would be unreasonable for us to do so).

If you believe that your personal information held by us is inaccurate, incomplete or out of date, you may request that we correct that information. In most cases, we will amend any inaccurate, incomplete or out of date information. If we are not able to correct your personal information in the way requested by you, we will notify you of our reasons for refusing your request (unless it would be unreasonable for us to do so) and let you know how you may make a complaint about our decision, should you wish to do so.

Direct marketing and electronic messages

We send fundraising appeals, event invitations, newsletters, and other communications to people who have supported us or asked to hear from us. We do this by post, phone, email, and SMS.

When we send commercial electronic messages (emails and SMS) we comply with the Spam Act 2003 (Cth). That means:

  • We only send these messages where you’ve consented to receive them, either expressly (for example, by ticking a box) or because of an existing relationship with us (for example, you’ve donated recently)
  • We always identify ourselves as the sender
  • Every email and SMS includes a clear way to unsubscribe

You can opt out of our marketing and fundraising communications at any time. Use the unsubscribe link in any email, reply STOP to an SMS, or contact us using the details at the end of this policy. We’ll action your request promptly. Opting out of marketing won’t affect transactional messages such as donation receipts or event confirmations.

Making a complaint

You may make a complaint about our handling of your personal information, including if you think we have breached the Privacy Act, by contacting us in writing, by mail, email to the address set out at the end of this privacy policy.

We will generally acknowledge your request within 14 days and respond within 30 days after your request is made or let you know what the next steps are for resolving your complaint. If we are not able to resolve your complaint, you may wish to contact the Office of the Australian Information Commissioner at the details set out below, which will be able to provide you with information about your other options.

What to do if you want to access your personal information or make a complaint

If you would like to access your personal information held by us or wish to make a complaint about the way we have collected, used, held or disclosed your personal information, please contact us as follows:

Phone: (08) 6456 5550

Email: privacy@pchf.org.au

Writing: Chief Executive Officer, The Perth Children’s Hospital Foundation, Perth Children’s Hospital, 15 Hospital Avenue, Nedlands WA 6009

If you want to obtain additional information about your privacy rights and how you can enforce them, you can visit the website of the Office of the Australian Information Commissioner at https://www.oaic.gov.au