Paul Ramsay Foundation Limited (ABN 32 623 132 472) (PRF) is committed to protecting the privacy of personal information and complying with applicable obligations under the Privacy Act 1988 (Cth) (Privacy Act).

This Privacy Notice explains why and how we collect, hold, use and disclose personal information, and what to do if you have questions or feedback. It operates as a collection notice for the purposes of the Australian Privacy Principles under the Privacy Act.

We may collect information from you when you visit our website, contact us, raise a query or complaint with us, sign up to one of our mailing lists, submit an expression of interest in relation to a PRF grant, express interest in a giving or investing opportunity, apply for a job with us, contract with us, work alongside us in supporting our partners, express an interest in supporting out work with funding or co-investment, or otherwise interact with us.

It is your choice how much personal information you provide to us, and you may choose to remain anonymous or use a pseudonym, where lawful and practicable. However, we might not be able to fulfil a request if you remain anonymous, use a pseudonym, or do not provide us with certain information.

Depending on the nature of our relationship and interactions with you, we may collect a range of personal information. This includes: your name, contact details (including your address, email address and phone number), date of birth, online activity on our website, support or interest in our work, details about your giving (e.g. history and preferences), interests and opinions, information about your roles, networks or memberships, expressions of interest or questions about PRF grants, communication preferences and records and/or notes of conversations in person or by phone, email or social media channels with our staff. On occasion, we may also collect sensitive information (as defined in the Privacy Act), to fulfil our compliance obligations to external regulators, or for internal and external reporting purposes. On occasion, where our donors and co-funders choose to voluntarily share information with us that is sensitive information under Australian privacy legislation (such as information about charitable interests and affiliations that may indicate religious beliefs or affiliations), we may record this information with permission to facilitate charitable giving in line with donor interests and to advance our charitable purpose of addressing disadvantage in Australia. By voluntarily providing this information, individuals consent to the collection, use, and storage of this sensitive information for these purposes. Individuals are not required to provide this information, and choosing not to do so will not affect their ability to interact with us.

We may also collect your personal information, including sensitive information, that we reasonably need for assurance purposes from third parties, such as third party service providers (including credit reporting or other checks where relevant), and from publicly available records.

The purposes for which we collect, hold, use and disclose personal information include: undertaking philanthropic and related activities; monitoring, analysing or improving our philanthropic activities; facilitating our recruitment processes; responding to your requests for information and other enquiries; managing our relationship or interactions with you and ensuring a complete and accurate record of your engagement with PRF; planning for and enabling future gifts and bequests; carrying out future planning and strategy work in relation to our philanthropic activities and the charitable sector, including through the use of analytics and artificial intelligence tools; evaluation and learning activities; enabling sector partners to access strategic insights in a responsible de-identified manner; and complying with our contractual, legal or regulatory obligations or exercising our legal rights.

How do we use and disclose personal information?

We may disclose your personal information for our charitable purposes, including for the purposes set out above, to our internal business units, related entities or affiliates, third parties who work with us, our representatives, agents or contractors (including for data storage or processing, printing, mailing, marketing, planning, research and goods or services development) or provide services to us, our advisors (including lawyers and accountants), insurers, auditors and financiers and other parties when required by law, such as law enforcement entities or regulators.

We may also make personal information available to our secure, internal artificial intelligence (AI) tools for the purposes of improving the efficiency, accuracy and quality of our operations, data analysis, and the purposes set out above more generally. These tools operate within PRF’s data environment and do not disclose information externally. We will not share your personal information except in accordance with this privacy notice, the Privacy Act or other applicable privacy laws, or otherwise as agreed by you.

Website and digital information

In general, you can browse our website without submitting your personal information to us. We collect metadata relating to website usage, including by using cookies, for the purpose of improving our communications activities. The types of information collected include your server address, domain name or IP address, the date, time and duration of the visit, the pages accessed, and documents downloaded, and other information.

When you interact with a PRF page or account on a social media platform, such as Facebook, Instagram, Twitter, LinkedIn or YouTube, or when you use your social media account or credentials to log in to our website, we may also collect the personal information that you make available to us on that page or through that account, including your account ID or “handle.”

We use Google Analytics on our website to collect information regarding how people use our site, including the types of web information described above. Google Analytics uses both first person and third-party cookies to record standard internet traffic information and the information is used by us to understand how people use our website.

We may also use other analytics services to understand how visitors reach our websites, including from social media platforms and email newsletters, usage patterns on our websites, and visitors’ social media profiles.

If you do not wish to receive any cookies you may set your browser to refuse cookies. However, this may impact on website functionality and the services provided to you.

Storage and security of information

PRF will take reasonable steps to ensure that all personal information or sensitive information we collect is held in a secure format and protected from loss and misuse, as well as unauthorised access, modification, disclosure, alteration, or destruction. The information may be held either in hard copy or electronically.

We will hold the information we collect on systems managed and maintained by us and/or our reputable third-party cloud storage service provider who may create a backup of our data and store that backup overseas.  Backups of the data may be held in the United States, Canada, Singapore, the UK or within the European Economic Area.

PRF will destroy or de-identify personal information in the course of carrying out routine corporate records reviews and management from time to time.  We will take reasonable steps and use appropriate techniques and processes in destroying information.

Access

People have a right to request access to personal or sensitive information held about them, and to request its correction. Requests to access to personal information or sensitive information held by PRF may be made by contacting the address below. If it is information that a person is entitled to access, we will endeavour to provide it to them in a suitable way (e.g. by email or mail).  We may charge a fee for compiling the requested information, if it is lawful for us to do so. Requests may also be made that we update or amend information we hold about a person; we will either amend the information, or make a record of the request, as appropriate.

Updates and feedback

We may amend this privacy notice from time to time, with or without notice to you. By providing personal information to us, you acknowledge and consent to any updates to this privacy notice, and agree that your personal information may be used for the purposes outlined in the most recent version of the notice. Questions or feedback about this notice may be directed to:

Privacy Officer

(02) 8582 4001

feedback@paulramsayfoundation.org.au

We commit to respond in a timely manner.

Version: February 2026