Privacy Policy
Last updated: April 16, 2026
For parish governance and legal review
Last updated: 1 September 2026.
Sections Introduction to 10 reproduce the parish’s existing Privacy Policy. Section 11 is new and describes how this website handles information. This policy has not yet been reviewed or approved by the Parish Council or by a legal adviser, and nothing in it should be treated as legal advice or as a statement of compliance. Please direct review comments to the Church Secretary.
Introduction
Your privacy is important to us, that is why the Church is committed to maintaining an environment and processes that protect the privacy of individuals associated with our church to ensure that we uphold your trust. Our Privacy Policy has been developed using the Australian Privacy Principles (APP) as governed by the Privacy Act (1988) and covers how we collect, use, disclose and store your information.
For more information about the Privacy Act (1988) please refer to the Office of the Australian Information Commissioner’s website at oaic.gov.au.
1. Why we collect your personal information
We provide a range of Christian services and programs including face-to-face and online church services, kids’ and youth programs, specialised pastoral care as well as community and missions projects. Participation in our programs and activities requires us to collect some information from those who want to be involved with our church to enable us to communicate effectively and provide the requested services.
2. What is your personal information?
In general terms “personal information” has the meaning given to it in the Act. This is information that can be used to identify you and may include your name, address, telephone number, email address and profession or occupation. If this information identifies you, or you are reasonably identifiable from it, then it is considered personal information.
3. Personal information we collect and hold
The information that we collect from you will vary depending on the nature of your involvement and activities with which you choose to engage. We endeavour to only request information that is reasonably necessary for the activities you are seeking to be involved in. You are not required to provide the personal or sensitive information that we request, but if you choose not to provide it, it may hinder or prevent your involvement or inclusion in some activities and communications and the degree of pastoral support and care we can provide you with.
The information we collect may include:
- Personal details such as your title, name, date of birth and marital status.
- Contact details such as your mailing or street address, email address, mobile and home or work telephone numbers.
- Family details such as your spouse and dependants.
- Profession, occupation or job title.
- Details of services we have provided to you, or about which you have enquired.
- Any additional information relating to you that you provided to us directly through our representatives or otherwise.
- Information you provide to us through our activities and services, surveys or visits by Church representatives.
Some services (including other activities) of Saint Mary and Saint Marina Coptic Orthodox Church are recorded. Images of people attending or participating in the service (or other activity) may be used for promotional or other purposes. Through attending any service (or other activity) you agree to Saint Mary and Saint Marina Coptic Orthodox Church using your image in these circumstances.
In the interests of security and safety, and the comfort of the Church community, the church also operates video cameras within and around some Church premises and, as such, collects images of people attending the premises.
3.1 Sensitive personal information
Some personal information is considered sensitive information, and, at times, it may be necessary for us to collect such information including:
- On occasion, with your consent, health information where it is necessary for one or more of our functions or activities.
- Religious information such as spiritual milestones and denominational details.
- Country of origin and ethnic background.
- Professional and practice details.
- Personal credit card details.
- Passport details.
- Criminal record or Working with Children Check.
- Any idiosyncratic or personal information we obtain from you.
3.2 Anonymity and use of a pseudonym
In some instances, you will have the right to not identify yourself or to use a pseudonym when contacting us or participating in activities or obtaining services or assistance from us, unless we are authorised by law not to do so or it is impracticable for us to deal with individuals who have not identified themselves or have used a pseudonym. In such circumstances we will only obtain as much personal information as is necessary to provide you with the service or assistance you require. However, in some circumstances we may be limited in our ability to provide you with services or assistance without your personal information.
4. How is your personal information collected?
Personal information is collected directly from you unless it is unreasonable or impracticable to do so. Personal information may be collected in a number of ways including:
- The Church Registration Forms.
- During telephone conversations.
- Through your access and use of our website, email or social media.
- When you complete an application or purchase.
- During conversations (face to face contact) or via correspondence between you and our representatives.
- When you register for conferences or Church events which can involve third party service providers.
- When you complete our forms for the provision of services or to volunteer your services and assistance to the Church or its various organizations.
- When you complete a survey or make a submission.
- Voice or image recordings.
4.1 Collection of your information from third parties
Personal information may be collected from third parties such as credit reporting agencies, law enforcement agencies, other government entities and specialist agencies to assist the Church achieve its objectives. This collection from third parties may occur in circumstances such as recruitment when conducting a criminal record check or verifying a Working with Children Check.
4.2 Unsolicited collection of personal or sensitive information
At times we may discover personal or sensitive information about you from a third party (e.g. a parent registering a child’s friend for an activity or program). If it is not information that is necessary for conducting Saint Mary and Saint Marina Coptic Orthodox Church activities, we will take steps to destroy or de-identify the information if it is lawful and reasonable to do so. We will make all legally required and reasonable attempts to advise you of the information we hold. Attendance at any of our programs or activities will be considered implied consent for us to hold any personal or sensitive information required for the program or activity.
4.3 Cookies
Access to our public website is anonymous, except for any area where you login with your own account or enter your personal details.
Our website may contain links to third party websites. Our privacy policy does not apply to other websites and we encourage you to read the privacy policy of any website you link to from ours.
Current position for this website. This website does not use analytics or advertising trackers, and it does not set any cookie of its own when you simply browse the public pages. Cookies are set only if you sign in to the website as a member of staff or a volunteer. Google reCAPTCHA and the embedded Google Map may set their own cookies when those components load. See section 11 for the detail.
4.4 Identifiers
We hold Working with Children Check Numbers as required by law. We also collect passport information for people participating in short term mission trips.
5. Security and holding of your information
We take all reasonable steps to protect the personal and sensitive information we hold from interference, misuse, loss, unauthorised access, modification or disclosure.
Our IT systems are password protected and only authorised personnel are permitted to access your data. Where we use cloud storage, we take reasonable steps to ensure that the providers we use have privacy policies in place that comply with Australian Privacy regulations and principles.
We will permanently de-identify or securely destroy personal information once there is no longer a legal or other need for us to retain it.
Care will be taken to ensure the integrity of information contained in files. Personal opinions will not be reflected as facts.
We will take reasonable steps to ensure your information is relevant, accurate, complete and up to date. We regularly provide opportunity for you to update your details.
6. How we use your information
We will only use personal information for the primary purpose for which it is collected. In most cases, the purpose will relate to the spiritual, pastoral, social, educational and administrative functions of the Church. Those functions include maintaining personal information for the purpose of providing pastoral care within our congregation, and for the promotion of activities and functions associated with the church.
We collect personal information from members of our congregation and visitors to our church for a variety of pastoral reasons so that we can perform our activities and functions and to provide the best possible quality of service for the following purposes:
- To provide services to you and send communications to you.
- Answer enquiries and provide information or advice on existing and new services.
- To update our records and keep your contact details up to date.
- To enable the development and promotion of other activities and services and to improve our general ability to assist Church attendees and the wider community.
- For the immediate reason for which you have provided it to us (for example, to enable us to process your request, registration or travel documentation).
6.1 Direct marketing
At times we will use your personal information to directly communicate with you about topics which we think may interest you, and would benefit you, such as church events. This communication will generally be in the form of email or text message. You will always have the ability to opt out of these communications, unless the communication is required for your involvement in a specific event, ministry or other area in which you have chosen to participate.
7. Disclosure of your information
At times we may need to make your personal and sensitive information available in order to provide pastoral services or manage certain aspects of our ministries and programs, or because it is a legal requirement. Disclosure of your information will only be made in accordance to the provisions and exclusions of the Australian Privacy Principles. Disclosure of your information will occur for the following reasons:
The provision of pastoral care or administration of church ministries and programs. We provide personal information to Church staff and lay leadership who have agreed to a confidentiality statement, as related to the area of ministry in which the staff member or lay leader is involved. It is reasonable to expect that pastoral care cannot be done thoroughly without the use of lay leaders, and therefore the information collected may be disclosed for purposes of pastoral care.
Access to these files by persons other than those who created the file should only occur in cases where pastoral care is being provided by another authorised staff member and the information contained in the file is necessary for effective pastoral care.
Care will be exercised when sending group emails to ensure email addresses are not provided unless authorised by the owners. To ensure privacy the “BCC” field will be used, as people whose names are in the “BCC” field cannot be seen by other recipients.
When there is reasonable need to provide contact details of church members to other church members who are involved in a team ministry together, pastors or staff may disclose those details.
The disclosure is required or authorised by law or court order, and it does not breach the Australian Privacy Principles and the recipient of the information is subject to provisions of protecting such information substantially similar to those of the Australian Privacy Principles.
Non-identifiable information may be provided to research organisations if such information will benefit the provision of church services and programs.
A Priest is to consult with their colleagues if asked by a congregation member to reach out to the third party. Such a consultation will be for the purpose of identifying the appropriateness of the contact and identifying what information, if any, can be provided to the third party to avoid breach of privacy.
7.1 Public prayer
Due to the often-sensitive nature of prayer requests, and taking into consideration the dire need often represented by a prayer request, we have endeavoured to implement a process which will protect the privacy of individuals and yet still allow those in our Church to be prayed for should they desire it. Names may only be used in public prayer if consent is first gained from the person who is the subject of the prayer request.
These guidelines will apply to all prayer within the Church that could be considered public, including any prayer requests submitted to the Intercessory Prayer Group.
7.2 Cross-border disclosure of personal information
In order for you to participate in a short-term mission trip we will provide personal, and sensitive information including passport details and relevant medical information including vaccination details, to our missions’ partners for the provision of travel and visa applications. This information may also be provided to third party government and travel agencies as is necessary for your trip.
No personal information will be sent without the individual’s consent, and only in the manner that the individual prescribes.
7.3 Safeguards
Your personal information will not be shared, sold, rented or disclosed other than in accordance with this privacy policy.
We do not give, sell, rent or loan any identifiable information regarding members and adherents to any person or organisation without the consent of the person involved.
We do not provide your personal information to other organisations for the purposes of direct marketing.
7.4 Breach of privacy
You need to be aware that confidentiality can be legally breached by issues relating to subpoenas or mandatory reporting. Over and above subpoenas and mandatory reporting, a decision to breach confidentiality may also be taken in the following situations:
- Suspected abuse and neglect.
- Actual or possible overdose situations.
- Where an individual issues substantive threats of intended violence or harm either to themselves or to others.
Apart from the above, confidentiality will be regarded as a sacred trust by any Priest. Such breaches of confidentiality will be made only after the Priest has consulted with their supervisor or professional associate.
In response to any subpoena, only the material specifically requested will be provided, in whatever form it may be held. Legal advice is recommended. Released material must only be delivered to official individuals (e.g. to the Clerk of the Court) and an official receipt obtained.
8. Access to personal information
You have every right to access your personal and sensitive information, subject to exceptions allowed by the law. There may be instances where we cannot grant your access request, for example where:
- Granting you access would have an unreasonable impact upon someone else’s privacy.
- Any other reason consistent with the Privacy Act.
8.1 Correction of information
If you believe that personal information we hold is incorrect, incomplete or inaccurate, then you may request us to amend it by contacting us via the contact details below. We will consider whether the information requires amendment. If we do not agree that there are grounds for amendment, then we will add a note to the personal information stating that you disagree with it.
9. Questions and complaints
If you have any further questions about our Privacy Policy, please contact our Church Secretary. If you have concerns about our Privacy Policy, or if you need to make a complaint about a possible breach of this policy, please contact our Church Secretary.
You can reach us through our contact page, by email at info@stmaryandstmarina.com.au, or by post at 363 Ninth Avenue, Llandilo NSW 2747.
10. Policy review
This policy will be reviewed every 5 years or as required by legislative change.
11. This website and its online services
This section describes what this website actually does. It was written by reference to the website’s own source code and is limited to practices that are in place. Where something is not automated, that is stated plainly rather than implied.
11.1 Contact form
Our contact form collects your name, your email address, your telephone number if you choose to give one, and your message. Your enquiry is saved to the website before any notification email is attempted, so that a mail failure cannot lose it. Each enquiry is given a reference number. A notification is emailed to the parish office so that someone can respond to you.
11.2 Suggestions and complaints form
This form records the type of submission, a category, a subject line and your message. You may submit it anonymously. If you choose to give your name, email address, telephone number or a preferred method of contact, those details are stored with the submission so that we can reply.
The notification email sent to the parish office contains only the submission type, the category and the subject line, together with a link that requires a login. Your message and your contact details are never copied into that email. They are read only by signing in to the website.
Submissions that our spam protection scores as low confidence are held for a person to review rather than being published.
11.3 Spam protection (Google reCAPTCHA)
Our public forms are protected by Google reCAPTCHA v3. It does not ask you to solve a puzzle. It does mean that your interaction with the form, and your IP address, are sent to Google, and that Google’s Privacy Policy and Terms of Service apply to that processing.
Because our newsletter sign-up appears at the foot of every page, we deliberately do not load reCAPTCHA when you are simply reading the site. It is fetched from Google only once you start filling in a form. If you never use a form, your visit involves no request to Google for this purpose.
On our own side we record only the outcome (accepted, held for review, or rejected) and a rounded confidence band. We do not store the reCAPTCHA token, and we do not store your IP address in readable form.
11.4 What we log
The website keeps a short activity log for security and troubleshooting. It records the kind of event, not the content of your message. Where we need to recognise repeat activity from the same visitor in order to apply rate limits, the IP address is stored as a one-way hash rather than as an address we can read back.
For newsletter sign-ups we keep a shortened form of the IP address (a prefix only) and a one-way hash of the browser identifier, as evidence of when and how consent was given.
11.5 Email sent by the website
Email from this website is sent through our mail provider over an authenticated, encrypted connection. SPF, DKIM and DMARC are configured for our domain so that recipients can verify that a message really came from us. Mailbox credentials are held in server configuration, are never stored in the website database, and are never displayed in the administration screens.
11.6 Church communications: consent, preferences and unsubscribing
If you subscribe to church communications we store the name you give, your email address, your telephone number if you provide one, your preferred language, and a record of which channels you have consented to and when that consent was given and confirmed.
We use confirmed opt-in, and there is a single sign-up form on this website. Whichever page you use it from, your address is recorded as pending and nothing is sent to you except one confirmation message. You become a subscriber only when you click the link in that message. If you never click it, you never hear from us again, and the pending record is not used for anything.
Confirmation links can be used once and expire. Every message we send includes a link to a preferences page where you can change which communications you receive, and a link to unsubscribe.
When you unsubscribe, your address is added to a suppression list in hashed form. This is deliberate: it means the unsubscribe continues to be honoured even if your details are later re-imported from another source.
Consent records are kept as an append-only history, so that we can always show when and how a person opted in or out.
WhatsApp and social media channels are present in the system but are not in live use, and no messages are sent to them.
11.7 Parish operations records
The website also holds private parish administration records: a servants directory, contractors and trades, maintenance tasks, inventory, and Parish Council meetings and minutes. None of this is publicly accessible. It requires a login, and it is not reachable by guessing a web address.
Access is controlled by role. Viewing a servant’s contact details and internal notes requires a specific permission that is separate from ordinary access, so a volunteer with a limited role cannot see them. Accounts can be protected with two-factor authentication and recovery codes. Changes are written to an audit log that records who made them.
11.8 Photographs
Photographs shown in our gallery are stored in the website’s media library. Section 3 above explains the position on images taken at church services and activities. If you would like a photograph of yourself removed, please contact us and we will remove it.
11.9 Retention, access and deletion
We want to be accurate about what is automated and what is not.
- Parish operations records. The website supports a formal request to export, or to erase, the personal information held about a person in these records. The erasure removes contact details, free text notes and the link to any login. It deliberately does not delete maintenance history, stock movements or audit entries, because those are the parish’s own operational and security records. What is kept, and why, is reported when the request is carried out.
- Contact enquiries and suggestions and complaints. A retention period can be set in the website settings. There is no automatic deletion. Removing these records is a manual action taken by an administrator.
- Communications and consent records. Subscriber records are marked as deleted rather than erased, and consent history is append-only by design, so that we can continue to demonstrate that consent was properly obtained and withdrawn.
If you would like to know what we hold about you, to have it corrected, or to ask us to delete it, please contact the Church Secretary using the details in section 9. Section 8 explains the circumstances in which we may not be able to grant a request.
11.10 Donations
This website does not process payments and does not collect card or bank details. Our donations page publishes the parish’s bank account details so that you can make a transfer yourself through your own bank, and gives an email address for requesting a receipt.
11.11 Third party content and hosting
The website is hosted, and our email is provided, by Hostinger. Some pages embed a Google Map showing the location of the church, and our forms load Google reCAPTCHA. Those components are provided by Google and are subject to Google’s own privacy terms. Our pages also link to our social media profiles; those are separate services with their own privacy policies.
We do not use website analytics, advertising networks or tracking pixels.
