Proudly Australian-Owned and Operated
As a founding member of EAP in Australia, we are a not-for-profit organisation with over 30 years of experience, dedicated to supporting workplaces nationwide with expert wellbeing solutions.
Purpose-Driven
The profits from this rewarding work are
distributed to help those most in need.
EAP with a human touch
Our team of in-house clinicians and network of mental health professionals will make sure you and your people receive the very best mental health and wellbeing support.
Support For Everyone
We provide a wide range of services to support individuals, managers, leaders, teams, and your organisation as a whole.
Privacy & Legal
Privacy Policy
Access Programs Australia Ltd (ABN 81 068 235 398) and its related bodies corporate (we, our, us) recognise the importance of protecting the privacy and the rights of individuals in relation to their personal information. This document is our privacy policy and it tells you how we collect and manage your personal information.
We respect your rights to privacy under the Privacy Act 1988 (Cth) (Act) and we comply with all of the Act’s requirements in respect of the collection, management and disclosure of your personal information.
What is your personal information?
When used in this privacy policy, the term “personal information” has the meaning given to it in the Act. In general terms, it is any information that can be used to personally identify you. This may include your name, address, telephone number, email address and profession or occupation. If the information we collect personally identifies you, or you are reasonably identifiable from it, the information will be considered personal information.
What personal information do we collect and hold?
We may collect the following types of personal information:
- Name
- Mailing or street address;
- Email address;
- Telephone number;
- Age or birth date;
- Profession, occupation or job title;
- In relation to clients accessing services, information that is relevant to your current situation and which is of assistance in providing a professional counselling service;
- Details of the products and services you have purchased from us or which you have enquired about, together with any additional information necessary to deliver those products and services and to respond to your enquiries;
- Any additional information relating to you that you provide to us directly through our website or indirectly through use of our website, through our representatives or otherwise; and information relating to you obtained from cookies and similar tools as described below.
- We may also collect some information that is not personal information because it does not identify you or anyone else. For example, we may collect anonymous answers to surveys or aggregated information about how users use our website.
- How do we collect your personal information? We collect your personal information directly from you unless it is unreasonable or impracticable to do so. When collecting personal information from you, we may collect in ways including:
- Through your access and use of our website;
- During conversations between you and our representatives;
- When you complete an application or purchase products or services; or when clients use our products or services.
Cookies
In some cases we may also collect your personal information through the use of cookies. When you access our website, we may senda “cookie” (which is a small summary file containing a unique ID number) to your computer. This enables us to recognise your computer and greet you each time you visit our website without bothering you with a request to register. It also enables us to keep track of products or services you view so that, if you consent, we can send you news about those products or services. We also use cookies to measure traffic patterns, to determine which areas of our website have been visited. We use this to research our users’ habits so that we can improve our online products and services. If you do not wish to receive cookies, you can set your browser so that your computer does not accept them. Tracking technologies also used include beacons, tags, and scripts to collect and trackinformation and to improve and analyse our products and services.
We may log IP addresses (that is, the electronic addresses of computers connected to the internet) to analyse trends, administer the website, track users movements, and gather broad demographic information. What happens if we can’t collect your personal information?
If you do not provide us with the personal information described above, some or all of the following may happen:
- We may not be able to provide the requested products or services to you, either to the same standard or at all;
- We may not be able to provide you with information about products and services that you may want; or
- We may be unable to tailor the content of our website to your preferences and your experience of our website may not be as enjoyable or useful.
For what purposes do we collect, hold, use and disclose your personal information? We collect personal information about you so that we can perform our business activities and functions and to provide best possible service.
We collect, hold, use and disclose your personal information for the following purposes:
- To provide products and services to you and to send communications requested by you;
- To answer enquiries and provide information or advice about existing and new products or services;
- To provide you with access to protected areas of our website;
- To compile non-identifying statistical reports for the relevant host organisation regarding usage of our services (all reasonable steps will be taken by us to ensure that this information does not allow for the identification of any persons);
- To assess the performance of the website and to improve the operation of the website;
- To conduct business processing functions including providing personal information to our related bodies corporate, contractors, service providers or other third parties;
- For the administrative, marketing (including direct marketing to our corporate and employer customers as detailed below), planning, product or service development, quality control and research purposes of Access Programs Australia Ltd, its related bodies corporate, contractors or service providers;
- To provide your updated personal information to our related bodies corporate, contractors or service providers;
- To update our records and keep your contact details up to date;
- To process and respond to any complaint made by you; and
- To comply with any law, rule, regulation, lawful and binding determination, decision or direction of a regulator, or in co-operation with any governmental authority of any country. Your personal information will not be shared, sold, rented or disclosed other than as described in this Privacy Policy.
We may disclose your personal information:
Which relates to a client including their health information if:
- You have provided written approval of informed consent for access to your own case notes;
- The information is health information and the use or disclosure is necessary for research, or the compilation or analysis of statistics, relevant to public health or public safety, and:
- It is impractical to seek your consent before the use or disclosure and we reasonably believe the use or disclosure is necessary to lessen or prevent a serious threat to the life, health or safety of any individual, or to public health or safety;
- The use or disclosure is conducted in accordance with guidelines approved under section 95A of the Act; or
- The use or disclosure is required or authorised by law. to our employees, related bodies corporate, contractors or service providers for the purposes of operation of our website or our business, fulfilling requests by you, and to otherwise provide products and services to you including, without limitation, web hosting providers, IT systems administrators, couriers, payment processors, data entry service providers, electronic network administrators, debt collectors, and professional advisors such as accountants, solicitors, business advisors and consultants; to suppliers and other third parties with whom we have commercial relationships, for business, marketing, and related purposes; and to any organisation for any authorised purpose with your express consent. Direct marketing materials We may send direct marketing communications and information about our products and services to our corporate and employer customers that we consider may be of interest, however we will not send direct marketing to clients who use our products or services. These communications may be sent in various forms, including mail, SMS, fax and email, in accordance with applicable marketing laws, such as the Spam Act 2003 (Cth). You consent to us sending you those direct marketing communications by any of those methods. If you indicate a preference for a method of communication, we will endeavour to use that method whenever practical to do so. In addition, at any time you may opt-out of receiving marketing communications from us by contacting us (see the details below) or by using opt-out facilities provided in the marketing communications and we will then ensure that your name is removed from our mailing list.
We do not provide your personal information to other organisations for the purposes of direct marketing.
How can you access and correct your personal information?
You may request access to any personal information we hold about you at any time by contacting us (see the details below). Where we hold information that you are entitled to access, we will try to provide you with suitable means of accessing it (for example, by mailing
or emailing it to you). We may charge you a fee to cover our administrative and other reasonable costs in providing the information to you. We will not charge for simply making the request and will not charge for making any corrections to your personal information.
There may be instances where we cannot grant you access to the personal information we hold. For example, we may need to refuse access if granting access would interfere with the privacy of others or if it would result in a breach of confidentiality. If that happens, we will give you written reasons for any refusal.
If you believe that personal information we hold about you is incorrect, incomplete or inaccurate, then you may request us to amend it. We will consider if the information requires amendment. If we do not agree that there are grounds for amendment then we will add a note to the personal information stating that you disagree with it.
What is the process for complaining about a breach of privacy?
If you believe that your privacy has been breached, please contact our Privacy Officer using the contact information below and provide details of the incident so that we can investigate it.
We request that complaints about breaches of privacy be made in writing, so we can be sure about the details of the complaint. Our Privacy Officer deals with privacy complaints and any complaints should be directed to our Privacy Officer using the contact details below. We will attempt to confirm as appropriate and necessary with you your understanding of the conduct relevant to the complaint
and what you expect as an outcome. We will inform you whether we will conduct an investigation, the name, title, and contact details of the investigating officer and the estimated completion date for the investigation process.
After we have completed our enquiries, we will contact you, usually in writing, to advise the outcome and invite a response to our conclusions about the complaint. If we receive a response from you, we will assess it and advise if we have changed our view.
If you are not satisfied with the way your privacy-related complaint is handled by us, you may refer your complaint to the Office of the Australian Information Commissioner (OAIC). Details of how to lodge a complaint with the OAIC may be found at www.oaic.gov.au or
by calling 1300 363 992.
Do we disclose your personal information to anyone outside Australia?
-
No, we don’t disclose personal information to recipients overseas Security
- We take reasonable steps to ensure your personal information is protected from misuse and loss and from unauthorised access, modification or disclosure. We may hold your information in either electronic or hard copy form. Personal information is destroyed or de-identified when no longer needed.
- As our website is linked to the internet, and the internet is inherently insecure, we cannot provide any assurance regarding the security of transmission of information you communicate to us online. We also cannot guarantee that the information you supply will not be intercepted while being transmitted over the internet. Accordingly, any personal information or other information which you transmit to us online is transmitted at your own risk.
Links
Our website may contain links to other websites operated by third parties. We make no representations or warranties in relation to the privacy practices of any third party website and we are not responsible for the privacy policies or the content of any third party website. Third party websites are responsible for informing you about their own privacy practices.
Calendar integration (for providers only)
The AccessEAP Professional Hub allows providers to connect a calendar so that availability and bookings stay in sync. Connecting a calendar is optional, the Professional Hub can be used without it, and you can disconnect at any time.
If you connect your Google Calendar, AccessEAP accesses your calendar data through Google’s APIs in order to read your existing events to determine when you are unavailable, and to create and remove events in your calendar when sessions are booked or cancelled. When a session is rescheduled we remove the original event and create a replacement. For Google we use the Google Calendar API with the permission calendar.events, and userinfo.email to read your primary Google Account email address so we can show you which account is connected.
If you connect a Microsoft Outlook or Microsoft 365 calendar, we access your calendar data through the Microsoft Graph API for the same purposes, using the permissions Calendars.Read, Calendars.ReadWrite, User.Read and offline_access. User.Read reads your basic account profile, including your name and email address, so we can show you which account is connected. We access only the calendar event data required to operate these features, together with that basic profile information. We do not access your emails, contacts, files or any other data in your Google or Microsoft account. We store only what is needed to work out when you are free: the start and end time of each busy period, the event identifier supplied by your calendar provider, which provider the entry came from, the email address of the connected account, and the time of the last successful sync. We do not store event titles, descriptions, notes, locations, attachments, organisers or attendees. We synchronise a window running from one day back to 30 days ahead, and refresh it approximately every 10 minutes.
Calendar data is held in our secure Microsoft Azure environment located in Australia. It is encrypted in transit using TLS 1.2 or higher and encrypted at rest using AES-256 encryption. The OAuth refresh token issued by your calendar provider is held in Azure Key Vault and can be retrieved only by the Professional Hub application itself. Short-lived access tokens are requested as needed and are never stored. Tokens are never displayed to users and are not available to support staff through the application. Access to the systems holding calendar data is restricted to authorised personnel on a least privilege basis, requires multi-factor authentication, and is logged.
We use calendar data only to manage your availability and your AccessEAP session bookings. We do not sell your Google user data and we do not use it for advertising or profiling. We do not use Google user data obtained through Google Workspace APIs, including the Google Calendar API, to develop, improve or train generalised or non-personalised artificial intelligence or machine learning models, and we do not transfer Google user data to third parties for that purpose. We do not transfer calendar data to others except to the service providers who operate the Professional Hub on our behalf, where necessary for security purposes, or where required by law. Your calendar data is not read by any person except where necessary for security purposes, to comply with applicable law, or where you have given us express permission in order to resolve a support issue.
We retain calendar data only for as long as your calendar connection remains active. You can disconnect your calendar at any time from within the Professional Hub. When you disconnect your calendar, we immediately revoke our access with your calendar provider, so the credential can no longer be used, and delete your stored availability data. The revoked credential is removed from our key store at the same time and is permanently erased within 90 days. You can also withdraw our access directly with your provider at any time, which takes effect immediately: for Google, through your Google Account permissions page at https://myaccount.google.com/permissions; for Microsoft 365 or Outlook, through your Microsoft account privacy settings, or by asking your Microsoft 365 administrator.
AccessEAP’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Contacting us
If you have any questions about this privacy policy, any concerns or a complaint regarding the treatment of your privacy or a possible breach of your privacy, please use the contact link on our website or contact our Privacy Officer using the details set out below.
We will treat your requests or complaints confidentially. Our representative will contact you within a reasonable time after receipt of your complaint to discuss your concerns and outline options regarding how they may be resolved. We will aim to ensure that your complaint is resolved in timely and appropriate manner.
Please contact our Privacy Officer at:
Privacy Officer AccessEAP Post: Level 8, 75 Castlereagh St. Sydney, NSW Tel: 1800 818 728 Email: privacy.officer@accessEAP.com.au
Changes to our privacy policy
We may change this privacy policy from time to time. Any updated versions of this privacy policy will be posted on our website. Please review it regularly.
This privacy policy was last updated in September 2026.