Privacy Policy
Last Updated: 19 October 2025
1. Introduction
Welcome to the WACMN Whirlpool Hub ("we", "our", "us"). We are committed to protecting your personal information and your right to privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform.
This policy complies with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth).
2. Information We Collect
2.1 Information You Provide to Us
When you register and use the Whirlpool Hub, we collect:
- Account Information: Username, email address, password (encrypted), full name
- Profile Information: Bio, about section, phone number, website, address
- Professional Information: Primary role, primary skills, representation name
- Interest Areas: Areas of interest, community groups, research areas, industry sectors, government areas, not-for-profits, NRM Group
- Geographic Information: Regions
- Participation Preferences: How you heard about us, areas you wish to participate in
- Social Media Links: Links to your social media profiles
- Communication Preferences: Newsletter subscription preferences, network ping opt-out preferences
- Content: Posts, comments, boards, events, images, documents, and other content you create or upload
2.2 Information Collected Automatically
When you use our platform, we automatically collect:
- Usage Data: Pages viewed, features used, time spent on the platform, click patterns
- Device Information: Browser type, operating system, device type, IP address
- Authentication Data: Login timestamps, session information
2.3 Information from Third Parties
- Google OAuth: If you sign in with Google, we receive your email address, name, and profile picture from Google
- Airtable Integration: We may sync certain user information with Airtable for data management purposes
3. How We Use Your Information
We use your personal information for the following purposes:
3.1 Platform Operations
- Creating and managing your account
- Authenticating your identity
- Providing access to boards, posts, events, and other platform features
- Enabling connections between users
- Facilitating communication between users (mentions, notifications)
3.2 Content Management
- Storing and displaying your profile information
- Managing boards you create or have access to
- Storing images and documents you upload
- Processing and displaying posts and comments
- Generating AI-powered board summaries (using OpenAI)
3.3 Communication
- Sending invitation emails for boards and the platform
- Sending notification emails (mentions, network pings)
- Sending newsletters (if you've opted in)
- Sending password reset emails
- Responding to your inquiries and support requests
4. How We Store and Protect Your Information
4.1 Data Storage
- Database: User data is stored in a secure PostgreSQL database
- File Storage: Images and documents are stored securely in Amazon S3 with private access controls
- Location: Data may be stored in servers located in Australia or overseas (including AWS regions)
4.2 Security Measures
We implement appropriate technical and organizational measures to protect your information:
- Passwords are encrypted using bcrypt hashing
- Secure HTTPS connections for all data transmission
- Access controls and authentication requirements
- Private file storage with presigned URLs for secure access
- Regular security monitoring and updates
5. How We Share Your Information
5.1 With Other Users
Based on your privacy settings and choices:
- Your profile information may be visible to other users
- Posts and content you create on public boards are visible to users with access to those boards
- Your connections and network information may be visible to other users
- Users can mention you in posts if your account settings allow it
5.2 With Service Providers
We share information with trusted third-party service providers:
- Amazon Web Services (AWS): For file storage (S3)
- Google: For OAuth authentication
- OpenAI: For generating AI-powered board summaries
- Email Service Provider (Resend): For sending transactional emails and notifications
- Airtable: For data synchronization (if applicable)
- Vercel: For hosting and analytics
6. Your Privacy Rights
You have the right to:
- Access your personal information
- Request correction of inaccurate information
- Update your profile information at any time through your account settings
- Opt out of newsletters and promotional emails
- Opt out of network ping notifications
- Control who can mention you in posts
- Make your boards private
- Request deletion of your account and associated personal information
7. Cross-Border Data Transfers
Your information may be transferred to and stored on servers located outside Australia, including the United States (AWS, Google, OpenAI, Vercel) and other AWS regions globally. When we transfer your personal information overseas, we take reasonable steps to ensure that the overseas recipient handles your information in a manner consistent with the Australian Privacy Principles. By using our service, you consent to these transfers.
8. Cookies and Tracking Technologies
We use cookies and similar technologies for:
- Authentication: To keep you logged in (session cookies)
- Preferences: To remember your settings
- Analytics: To understand how you use our platform (Vercel Analytics)
- Performance: To improve platform speed and reliability
9. Contact Information
If you have questions, concerns, or complaints about this Privacy Policy or our privacy practices, please contact us:
Email: [Your Contact Email]
Mail: [Your Business Address]
Phone: [Your Contact Phone Number]
10. Complaints Process
If you believe we have breached the Australian Privacy Principles:
- Contact Us First: Submit a complaint using the contact details above
- Investigation: We will investigate your complaint within 30 days
- Resolution: We will work with you to resolve the issue
- External Review: If you're not satisfied with our response, you can contact the Office of the Australian Information Commissioner (OAIC)
Office of the Australian Information Commissioner (OAIC)
Website: www.oaic.gov.au
Phone: 1300 363 992
Email: enquiries@oaic.gov.au
Mail: GPO Box 5218, Sydney NSW 2001
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by posting the new Privacy Policy on our platform and updating the "Last Updated" date. Your continued use of the platform after changes indicates your acceptance of the updated policy.
By using the WACMN Whirlpool Hub, you acknowledge that you have read and understood this Privacy Policy and consent to the collection, use, and disclosure of your personal information as described herein.