1300 130 566 Join API Member Area Instagram Menu

API Qld Ltd Privacy Statement 

Australian Post-Tel Institute (Queensland) Ltd Privacy Statement

Updated 15 September 2026

This Privacy Statement explains how Australian Post-Tel Institute (Queensland) Ltd and its related entities collect, hold, use, disclose and protect personal information. For the purposes of this Privacy Statement, references to “API”, “we”, “our” and “the organisation” include:

Australian Post-Tel Institute (Queensland) Ltd
A.P.I. Promotions Pty Ltd
Canopy Dakabin Pty Ltd
Canopy Ormiston Pty Ltd
Canopy Community Ltd

API is committed to protecting the privacy, confidentiality and security of personal information. We maintain physical, electronic and procedural safeguards to protect personal information from misuse, interference, loss, unauthorised access, modification or disclosure.
API’s Privacy Policy and Procedure provides further information about:
•  how we collect and hold personal information
•  the purposes for which we collect, hold, use and disclose personal information
•  how individuals may access or correct their personal information
•  how privacy complaints may be made and managed.

API manages personal information in accordance with the Privacy Act 1988 (Cth), including the Australian Privacy Principles. This reflects API’s commitment to responsible, transparent and lawful information handling across its membership, community, early education, workforce, governance, property and administrative activities.

API has a long history of supporting members, children, families and communities. Protecting the privacy and individual rights of the people connected with our organisation remains central to the way we operate. This Privacy Statement is made available publicly and may be provided to any person on request.

1. Open and transparent management of personal information
API aims to manage personal information in an open and transparent way. We will take reasonable steps to ensure that individuals understand why their personal information is collected, how it may be used, who it may be disclosed to, and how it will be protected.

2. Anonymity and pseudonymity
Where lawful and practicable, individuals may choose not to identify themselves or may use a pseudonym when dealing with API.
In some circumstances, it will not be practicable for API to deal with an individual anonymously or pseudonymously. This may include where we need to confirm a person’s identity to provide services, manage membership or account records, enrol a child, comply with legal or regulatory obligations, respond to safety or safeguarding matters, process payments, manage employment records, or protect confidential or sensitive information.

3. Collection of personal information
API will only collect personal information where it is reasonably necessary for one or more of its functions or activities, or where collection is otherwise authorised or required by law.

Personal information may include names, addresses, email addresses, phone numbers, dates of birth, family or emergency contact details, membership details, employment information, payment or account information, service records, enrolment information, images, correspondence and other information relevant to API’s functions.

API may collect sensitive information where it is reasonably necessary and permitted by law. This may include health information, child safety or wellbeing information, cultural or language information, disability-related information, family circumstances, background check information, or other sensitive information required for early education, employment, safety, safeguarding, service delivery, legal or regulatory purposes.

Where reasonable and practicable, API will collect personal information directly from the individual. Information may also be collected from parents, guardians, authorised nominees, employees, contractors, service providers, regulators, government agencies, professional advisers, publicly available sources, digital systems, forms, websites, email, telephone, in-person interactions and other lawful sources.

4. Unsolicited personal information
If API receives personal information it did not request, we will assess whether the information could have been collected under the Australian Privacy Principles. If the information could not have been collected and is not required to be retained, API will take reasonable steps to destroy or de-identify the information where lawful and reasonable to do so.

5. Notification of collection
At or before the time personal information is collected, or as soon as practicable afterwards, API will take reasonable steps to notify individuals of relevant collection details. This may include the purpose of collection, the consequences if information is not provided, the usual disclosures of information, and how the individual may access, correct or complain about the handling of their personal information.

6. Use and disclosure of personal information
API will use or disclose personal information for the purpose for which it was collected, for a related purpose the individual would reasonably expect, with consent, or where authorised or required by law. API may use or disclose personal information for purposes including:
• delivering services and programs
• managing membership, community and engagement activities
• operating early education and care services
• managing child safety, safeguarding, health, wellbeing and incident obligations
• communicating with members, families, employees, contractors, suppliers and stakeholders
• managing payments, accounts, payroll and finance functions
• administering employment, contractor and volunteer arrangements
• managing governance, risk, compliance, audit, insurance and legal obligations
• maintaining records and organisational systems
• responding to complaints, incidents, inquiries, disputes, claims or regulatory matters
• improving services, systems, safety, quality and organisational performance.

API may disclose personal information to related entities, employees, contractors, professional advisers, insurers, auditors, legal advisers, information technology providers, payment processors, software providers, government agencies, regulators, law enforcement bodies, health or emergency services, and other third parties where required for lawful organisational purposes.

7. Direct marketing and communications
API may use personal information to communicate with individuals about services, programs, events, opportunities, updates or information that may be relevant to them, where permitted by law.
API will provide a simple means for individuals to opt out of direct marketing communications where required. API will not use or disclose sensitive information for direct marketing unless permitted by law.

8. Third-party service providers and overseas storage or processing
API uses third-party service providers to support its operations. These may include providers of information technology systems, cloud storage, email and communication platforms, finance and payroll systems, early education management systems, customer relationship management systems, website services, analytics tools, cyber security services, professional services and other administrative or operational platforms.
Some third-party providers may store, process, back up or access information outside Australia. The countries in which information may be stored or accessed can vary depending on the provider, their systems, subcontractors and hosting arrangements.
Where API uses third-party services that may involve overseas storage, access or processing, API will take reasonable steps to assess and manage privacy, confidentiality and information security risks. This may include considering contractual protections, access controls, security standards, provider due diligence, data handling practices and whether the disclosure or transfer is permitted under applicable privacy laws.

9. Government related identifiers
API will not adopt a government related identifier, such as a Medicare number, tax file number, Centrelink reference number or other government identifier, as its own identifier of an individual unless permitted or required by law.

API may collect, use or disclose government related identifiers where required for lawful purposes, such as employment, taxation, childcare subsidy, regulatory, background checking, safety or service delivery obligations.

10. Quality of personal information
API will take reasonable steps to ensure that personal information it collects, uses or discloses is accurate, up to date, complete and relevant, having regard to the purpose for which the information is held.

Individuals are encouraged to notify API if their personal information changes or if they believe information held by API is inaccurate, incomplete, out of date, irrelevant or misleading.

11. Security of personal information
API will take reasonable steps to protect personal information from misuse, interference, loss, unauthorised access, modification or disclosure.
Security measures may include access controls, secure storage, password protection, system permissions, restricted access files, staff training, confidentiality obligations, secure disposal practices, cyber security controls, supplier management and recordkeeping procedures.

API will retain personal information for as long as required for legal, regulatory, operational, insurance, audit, safeguarding, employment, child safety, governance or business purposes. When personal information is no longer required, API will take reasonable steps to destroy or de-identify it where lawful and appropriate.

12. Access to personal information
Individuals may request access to personal information API holds about them. API will respond to access requests within a reasonable period and in accordance with applicable legal requirements.

In some circumstances, API may be unable to provide access to some or all information, including where access would unreasonably affect the privacy of others, prejudice an investigation, create a safety risk, breach confidentiality, reveal commercially sensitive information, or where another legal exception applies.

13. Correction of personal information
Individuals may request correction of personal information held by API. API will take reasonable steps to correct information where it is satisfied that the information is inaccurate, out of date, incomplete, irrelevant or misleading.

Where API does not agree to make a requested correction, API will provide reasons where appropriate and may allow the individual to request that a statement be associated with the information.

14. Cookies and website technologies
API may use cookies and similar technologies on its websites and digital platforms. These technologies may be used to support website functionality, improve user experience, understand how people use our sites, maintain security, remember preferences and provide content that may be relevant to users.
Individuals can manage cookies through their browser settings, although some website features may not function properly if cookies are disabled.

15. Privacy complaints and inquiries
Individuals may contact API if they have a question about how their personal information is collected, held, used or disclosed, or if they wish to make a privacy complaint.

API will take privacy complaints seriously and will respond within a reasonable period. Where appropriate, API may seek further information, investigate the matter, provide an outcome and identify any corrective action required.

Privacy inquiries or complaints may be directed to:
Australian Post-Tel Institute (Queensland) Ltd
Phone: 07 3005 6666
Email: api@apiqld.com.au
Business hours: 9:00am to 5:00pm AEST, Monday to Friday, excluding public holidays.