Legal

Privacy Policy

How African Professionals of Australia handles personal information. Effective 27 August 2026.

Effective date: 27 August 2026 Last updated: 27 August 2026

Who we are

African Professionals of Australia Limited (APA, we, us, our) is a not-for-profit company limited by guarantee, ABN 21 147 889 389. We are a national community of African professionals in Australia, with chapters in Western Australia, New South Wales, Victoria, Queensland, South Australia and Tasmania.

This policy explains how we handle your personal information when you use this website (www.apaau.com), become or remain a member, subscribe to our newsletter, or get in touch with us.

Personal information is any information that identifies you, or could reasonably identify you.

The privacy standard we follow

We handle your personal information in line with the Australian Privacy Principles (APPs) in the Privacy Act 1988 (Cth). We treat those principles as our standard because we think our members are entitled to it, and because they are the benchmark Australians expect.

We are also subject to the Spam Act 2003 (Cth), which governs the marketing emails we send.

You can use most of this site anonymously

You do not have to tell us who you are to read this website. You only need to give us personal information if you want to do something that requires it — join, subscribe, pay, or contact us.

Where it is lawful and practical, you can deal with us using a pseudonym. If you would prefer not to give us your name, tell us and we will do what we reasonably can.

What we collect, and why

When you simply browse the site

We collect standard technical information through our hosting and content-delivery providers and through Google Analytics: your IP address, approximate location derived from it, the pages you view, how long you stay, your device and browser type, and the site or search that referred you.

We use this to understand which pages are useful, to spot problems, and to keep the site running and secure. We use it to improve the site — not to build a profile of you as an individual.

When you subscribe to our newsletter

We collect your email address, and a marker recording where on the site you subscribed (our footer, a page sign-up band, or a blog post). When you subscribe we also record the date and time you consented and the IP address the subscription came from — this is our evidence that you asked to hear from us, which the Spam Act requires us to be able to show.

We use double opt-in. After you subscribe we email you a confirmation link. You are not on our list until you click it. Our email provider, MailerLite, records that confirmation, including the time, IP address and browser you used.

We use this to send you APA news, events and opportunities. You can unsubscribe from every email we send, at any time.

When you use our contact form

We collect your name, email address, the subject and the message you write. We use it to answer you and to keep a reasonable record of the enquiry.

Please don’t send us sensitive personal details through the contact form. If your enquiry needs them, say so and we’ll find a more appropriate way.

When you become a member

At sign-up we collect your first and last name, username, email address, a password, and your state or territory (which is required, because it tells us which chapter you belong to). You can also tell us your occupation and the areas you’re interested in — those are optional.

We use this to create and run your member account, to give you access to member benefits, to connect you with your chapter, and to contact you about your membership.

Your password is stored as a one-way encrypted value. We cannot see your password.

When you pay

Paid memberships are processed by Stripe. Your card details are entered on Stripe’s own secure checkout page and are sent directly to Stripe.

We never see, receive or store your card number. What comes back to us is the information we need to run your membership: your name and email, that a payment succeeded, your membership level, your renewal date, and a payment reference.

Stripe states that it is certified as a PCI Service Provider Level 1, the highest level of certification available in the payments industry. Stripe handles your payment information under its own privacy policy.

If you joined APA before this website

APA has run a members’ system for many years. When we moved to this website, we transferred the member records we already held so that existing members would not lose their membership, their payment history or their standing.

Those records may include your name, email address, phone number, postal address, country of origin, industry, profession, membership tier and the date you first paid. We did not transfer old passwords or one-time login codes — those were left behind, which is why long-standing members are asked to set a new password.

If you would like to see what we hold from that transfer, or have it corrected or removed, please ask (see “Getting access, and getting things fixed”).

When you watch an event recording

Our event recordings are hosted on YouTube or Vimeo, not on our own servers. Where a recording card shows a preview image, that image is loaded from YouTube, which means YouTube receives a request from your browser — including your IP address — even if you don’t click. If you play a recording, or if a video player is embedded in the page, YouTube or Vimeo may set their own cookies and collect information about you as though you had visited their site directly. That is governed by their privacy policies, not ours.

Sensitive information

Some information gets extra protection under Australian privacy law because misuse of it can cause real harm. That includes information about a person’s racial or ethnic origin.

Two things we hold can reveal ethnic origin:

  • the country of origin recorded for some long-standing members; and
  • the fact of APA membership itself, given who we are.

We treat both as sensitive information. That means:

  • we only collect it with your consent, and only where we genuinely need it;
  • we do not use it for anything except running APA and its programs;
  • we never disclose it to anyone outside the service providers listed below;
  • we never sell, rent, trade or share member lists with sponsors, partners or anyone else.

Country of origin is not required. You can ask us to remove it from your record at any time and it will not affect your membership.

We previously held a “country of origin” field on records migrated from our earlier website. It was not used for anything, and it is not collected when you join today. We deleted it from every record on 27 August 2026. We no longer hold it.

Cookies and similar technologies

Cookies are small files a website stores on your device. This site uses:

  • Essential cookies — set by WordPress and by our membership system so you can log in, stay logged in, and see member-only content. The site cannot work properly without these.
  • Analytics cookies — set by Google Analytics to measure how the site is used.

We do not use advertising cookies, and we do not allow third parties to track you across other websites for advertising.

Alongside page views, we ask Google Analytics to record four things you do on the site: starting a sign-up, completing a sign-up, subscribing to the newsletter, and opening a member resource. These are recorded as events, not tied to your name.

You can block or delete cookies in your browser settings. If you block essential cookies, you will not be able to log in.

We do not use a cookie consent banner. Australian privacy law does not require one, and we do not target advertising at people overseas. If that changes, we will add one and update this policy.

How we use your information

We use your personal information to:

  • set up and run your membership account and give you access to member areas;
  • take your membership payments and manage renewals and cancellations;
  • put you in touch with your state chapter;
  • send you the newsletter and event invitations you signed up for;
  • answer your enquiries;
  • understand how the website is used, and improve it;
  • keep proper financial and governance records as a not-for-profit company; and
  • meet our legal obligations.

We do not sell your personal information. We never have.

We will only use your information for a different purpose if you would reasonably expect it, if you agree, or if the law requires it.

Who we share your information with

We share personal information with a small number of service providers who help us run APA. Each of them may only use it to provide their service to us. We do not give any of them permission to use your information for their own marketing.

WhoWhat they receiveWhat they do with it
StripeYour name, email address, card details (entered directly with them), and your subscription and payment recordsTakes and manages membership payments
MailerLiteYour email address, first and last name, membership level and status, state/chapter, join date, renewal date, and an internal member IDSends our newsletter and membership emails, and manages subscriptions and unsubscribes
GoDaddyEverything stored on the website, because they host itHosts the website and its database
Google (Google Analytics)Your IP address, approximate location, pages viewed, device and browser, and the four site events listed aboveWebsite analytics
CloudflareYour IP address and the technical details of each requestDelivers the site quickly and helps block attacks and abuse

We may also disclose your personal information where the law requires or authorises it — for example, in response to a court order — or where we reasonably believe it is necessary to prevent a serious threat to someone’s life, health or safety.

Some of the software running on our own website — our forms plugin, membership plugin, SEO plugin, image optimiser and security plugin — runs on APA’s own server and does not send your information anywhere else.

Marketing emails, and how to stop them

Newsletter. We only send you the newsletter if you asked for it and confirmed it by clicking the link in our confirmation email. Every newsletter identifies APA as the sender and contains a working unsubscribe link. Unsubscribing takes one click and never requires you to log in or give us anything extra. We action unsubscribes promptly.

Membership emails. If you are a member, we will email you about your membership — welcome messages, receipts, renewals, changes to your account, and your chapter’s activities. These are part of the membership you signed up for and they are not marketing, so they are not covered by the newsletter unsubscribe. You can stop them by cancelling your membership, or by asking us.

If you unsubscribe, we keep a record of your email address on a suppression list. That is not us holding on to your details — it is the only reliable way to make sure we don’t accidentally email you again.

How we protect your information

We take these steps to keep your information safe:

  • the whole site runs over an encrypted HTTPS connection;
  • passwords are stored one-way encrypted, so nobody at APA can read them;
  • we run a security plugin that blocks repeated login attempts and filters malicious traffic, and two-factor authentication is available on accounts;
  • editing website code from inside the admin area is disabled, which closes a common attack route;
  • card payments are handled entirely by Stripe, so card numbers never reach our systems; and
  • access to member records is limited to the people who need it to do their APA role.

No website can promise perfect security. If something goes wrong, we will act on it.

Access to member records is limited to APA officers who need it for their role — the National Executive, our website administrator, and each Chapter President for members in their own chapter. Everyone with access uses an individual account, not a shared login.

If something goes wrong — data breaches

If personal information we hold is lost, or accessed or disclosed without authorisation, we will assess what happened quickly.

Where a breach is likely to cause serious harm to you, we will tell you and the Office of the Australian Information Commissioner as soon as we reasonably can, and explain what happened, what information was involved, and what you should do about it.

How long we keep your information

We keep personal information only as long as we genuinely need it, and then we destroy it or remove anything that identifies you.

These are the periods we work to:

InformationHow long we keep itWhy
Payment and financial records7 years after the transactionWe are required to keep financial records for seven years under the Corporations Act 2001.
Your member account, while you are a memberFor as long as your membership continuesWe need it to provide your membership.
Your member account after your membership lapses2 years, then we delete or de-identify itSo you can rejoin without losing your history, without us holding lapsed records indefinitely.
Newsletter subscriptionUntil you unsubscribeYou control this one.
Record that you unsubscribedIndefinitelyWe keep a suppression list so we can honour your unsubscribe and never email you again by mistake.
Contact form messages12 monthsLong enough to handle your enquiry and any follow-up.
Website analytics14 monthsThe retention period we have set in Google Analytics.

Getting access, and getting things fixed

You can:

  • See what we hold about you. Ask us and we’ll give you a copy. There is normally no charge. If there is an unusual cost, we’ll tell you before we do anything.
  • Correct it. If something is wrong, out of date or incomplete, tell us and we’ll fix it. Members can update most details themselves in their account.
  • Remove optional details. Occupation, interests, phone, postal address and country of origin are not needed to be a member. Ask and we’ll remove them.
  • Unsubscribe from the newsletter, any time.
  • Ask us to delete your information. We will do so unless we are required to keep it — for example, payment records we must retain by law.

We’ll respond within 30 days

There are limited situations where we may not be able to give you access — for example, where doing so would reveal someone else’s personal information. If that happens we’ll explain why in writing and tell you what you can do next.

Complaints

If you think we’ve mishandled your personal information, please tell us. We would much rather hear about it and fix it.

Privacy complaints are handled by our Privacy Officer, a responsibility held by APA’s National Digital Strategist. We publish the role rather than an individual’s name, so that this policy stays accurate when the person in the role changes.

Write to us at hello@apaau.com with “Privacy” in the subject line, or by post at writing to us by email. If you would prefer to write to us by post, contact us first and we will give you a postal address.

We’ll acknowledge your complaint, look into it, and write back to you within 30 days

If you’re not happy with how we handle it, you can take your complaint to the Office of the Australian Information Commissioner:

  • Web: www.oaic.gov.au/privacy/privacy-complaints
  • Phone: 1300 363 992
  • Post: GPO Box 5218, Sydney NSW 2001

If you are outside Australia

APA is an Australian organisation and this website is intended for people in Australia. We don’t target our services at people in other countries.

If you’re overseas and a member or subscriber, the rights described in this policy — access, correction, deletion, unsubscribing — are offered to you on the same terms as everyone else. Just ask.

Your information will be handled in Australia, and in some cases by the service providers we use, which operate outside Australia.

Children

APA is a professional community for adults. We don’t offer membership to children and we don’t knowingly collect personal information from anyone under 18. If you believe a child has given us personal information, contact us and we’ll delete it.

Changes to this policy

We’ll update this policy when our practices change or the law does. The current version is always on this page, with the date at the top. If we make a significant change, we’ll tell members by email.

Contact us

African Professionals of Australia Limited ABN 21 147 889 389 Email: hello@apaau.com Web: www.apaau.com Attention: Privacy Officer (National Digital Strategist) Post: Available on request — email us and we will provide it

A copy of this policy is available free of charge. If you need it in another format, ask us and we’ll do our best to help.