top of page

PRIVACY POLICY

Calm In the Chaos

The Postpartum Hub PTY LTD

www.calminthechaos.com.au

Effective Date: 16 June 2025

 

1. INTRODUCTION AND COMMITMENT TO PRIVACY

The Postpartum Hub PTY LTD, trading as Calm In the Chaos ("we", "us", "our", or the "Company"), is committed to protecting the privacy and security of all personal information we collect, hold, use, and disclose in the course of providing our first aid, infant CPR, and childcare emergency response training services.

This Privacy Policy explains how we handle personal information in accordance with the Privacy Act 1988 (Cth) ("Privacy Act"), the Australian Privacy Principles ("APPs") contained in Schedule 1 to the Privacy Act, and the Privacy and Other Legislation Amendment Act 2024 (Cth) ("POLA 2024"), which received Royal Assent on 10 December 2024 and introduced the most significant reforms to Australia's privacy framework in over a decade.

We recognise that the personal information you provide to us, including sensitive health information, is important and personal. We treat all such information with the utmost care, confidentiality, and respect. By engaging with our services, website, or any Course, you consent to the collection, use, and handling of your personal information as described in this Privacy Policy.

This Policy applies to all individuals whose personal information we collect, including Course participants, website visitors, and persons who contact us by email, phone, or any other means. This Policy should be read in conjunction with our Terms and Conditions and Cookie Policy.

 

2. ABOUT US AND THIS POLICY

Calm In the Chaos is a Melbourne-based baby and child first aid education provider offering non-accredited first aid and emergency response training for parents, caregivers, grandparents, and members of the public in Victoria, Australia. Our services are delivered in-person and, in the future, via online and digital platforms.

We operate as a small business entity. While the Privacy Act 1988 (Cth) generally applies to organisations with an annual turnover exceeding AUD 3 million, we voluntarily comply with the Act and all thirteen (13) Australian Privacy Principles in recognition of the sensitive nature of the health information we collect from Course participants. We are also required to comply with the Act because we handle health information about individuals, which is classified as sensitive information under the Privacy Act.

We may update this Privacy Policy from time to time to reflect changes in our practices, applicable law, or technology. We will publish the updated Policy on our website and note the date it was last revised. We encourage you to review this Policy periodically. Your continued use of our services or website following any update constitutes your acceptance of the updated Policy.

 

3. WHAT IS PERSONAL INFORMATION AND SENSITIVE INFORMATION

Under the Privacy Act 1988 (Cth), personal information means information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether the information is true or not, and whether or not recorded in a material form. This broad definition captures a wide range of information about you.

Sensitive information is a specific subset of personal information that attracts a higher level of protection under the APPs. Under APP 3, we may only collect sensitive information with your consent or where required or authorised by law. Sensitive information relevant to our services includes:

  • health information, including information about your physical condition, injury, disability, or medical status;

  • information about pregnancy or post-natal status; and

  • information about food allergies or intolerances that may have implications for your health and safety.

Given that we collect health information from Course participants, we are subject to heightened obligations in relation to the collection, handling, storage, and disclosure of that information, and we take those obligations seriously.

 

4. WHAT PERSONAL INFORMATION WE COLLECT

We collect only the personal information that is reasonably necessary for the purposes of providing our Course Services and related business operations. The categories of personal information we collect include:

4.1 Identity and Contact Information

  • Full first and last name;

  • Email address; 

  • Phone number; and

  • Any other contact details you voluntarily provide to us.

4.2 Booking and Payment Information

  • Course selection and booking details;

  • Invoice and payment records (processed via our third-party invoicing platform); and

  • Communication records relating to your booking, transfer requests, or enquiries.

4.3 Sensitive Health Information

As part of the enrolment and Course check-in process, we collect the following sensitive health information for participant safety purposes:

  • Known food allergies or dietary requirements relevant to any food or beverages served at a Course;

  • Pregnancy or recent post-natal status that may affect safe participation in practical CPR training activities; and

  • Physical conditions, injuries, disabilities, or health concerns that may limit your ability to safely participate in any Course activity.

The provision of accurate health information is a condition of enrolment. If you choose not to provide us with required health information, the Company may, in its absolute discretion, be unable to accommodate your participation or may restrict your access to certain practical Course activities.

4.4 Technical and Website Information

When you visit our website, we may collect technical information, including your IP address, browser type, device type, and information about how you navigate and interact with our website. Please refer to our Cookie Policy for further detail.

 

5. HOW WE COLLECT PERSONAL INFORMATION

We collect personal information in the following ways:

  • directly from you when you complete a Course booking or enquiry form;

  • directly from you when you correspond with us by email, phone, or any other communication channel;

  • directly from you when you provide health disclosure information at the time of enrolment or Course check-in;

  • from our website, including through cookies and similar technologies, as described in our Cookie Policy; and

  • where applicable, from a parent or legal guardian booking on behalf of a minor participant.

We will always collect personal information directly from you unless it is unreasonable or impracticable to do so, or unless you have consented to collection from a third party.

We will only collect personal information by lawful and fair means and in a manner that is not unreasonably intrusive. We will not collect personal information by covert means or by deception.

 

6. PURPOSE OF COLLECTION: WHY WE COLLECT YOUR INFORMATION

We collect personal information for the following primary purposes:

  • to process your Course booking and enrolment;

  • to issue invoices and receive payment for Course fees;

  • to communicate with you about your booking, including confirmations, reminders, and updates;

  • to ensure your health and safety during Course participation;

  • to accommodate health disclosures and adapt Course delivery where appropriate and practicable;

  • to seek emergency medical assistance on your behalf if required during a Course;

  • to comply with our legal and regulatory obligations; and

  • to maintain records of Participant attendance and communications.

We may also collect and use your personal information for related secondary purposes that you would reasonably expect, including:

  • to improve our Course content, delivery, and services;

  • to respond to enquiries, complaints, and feedback;

  • to send you information about future Courses or promotions, where you have consented to receive such communications; and

  • to defend, resolve, or manage any legal claim or dispute.

We will not use or disclose your personal information for any purpose other than those described in this Privacy Policy, unless required or authorised by law or with your express consent.

 

7. HOW WE HOLD AND SECURE YOUR INFORMATION

We take reasonable and proportionate steps to protect the personal information we hold from misuse, interference, loss, unauthorised access, modification, and disclosure. Our security measures include:

  • storing personal information in password-protected digital systems with restricted access;

  • implementing appropriate physical security measures for any paper-based records;

  • limiting access to personal information to those staff members and contractors who require it for legitimate business purposes;

  • using reputable third-party platforms and service providers that maintain appropriate security standards; and

  • taking reasonable steps to delete or de-identify personal information that is no longer required for any legitimate purpose.

Health information is classified as sensitive information under the Privacy Act and is afforded the highest level of protection within our systems. Health disclosures provided at Course check-in are held securely and are accessible only to the relevant Course instructor and Company management on a need-to-know basis.

While we take all reasonable steps to protect your personal information, we cannot guarantee the absolute security of data transmitted via the internet or stored on any digital system. In the event of a data breach that is likely to result in serious harm to any affected individual, we will comply with our obligations under the Notifiable Data Breaches (NDB) scheme under Part IIIC of the Privacy Act, including notifying affected individuals and the Office of the Australian Information Commissioner (OAIC) as required.

 

8. HOW LONG WE KEEP YOUR INFORMATION

We retain personal information only for as long as it is necessary for the purposes for which it was collected, or as required or permitted by law. Our general data retention practices are as follows:

  • booking and payment records are retained for a minimum of seven (7) years for taxation and financial reporting purposes;

  • health information collected at Course check-in is retained only for the duration of the Course and is securely deleted or destroyed within a reasonable period following the Course's conclusion, unless the information is required in connection with a safety incident or legal claim;

  • email and communication records are retained for a reasonable period following your last engagement with us and then securely deleted; and

  • where required by law to retain information for a specified period, we will comply with that requirement.

When personal information is no longer required, we will take reasonable steps to destroy or de-identify it in a secure manner.

 

9. DISCLOSURE OF YOUR INFORMATION TO THIRD PARTIES

We do not sell, rent, or trade your personal information to any third party under any circumstances.

We may disclose your personal information to third parties only in the following circumstances:

  • to emergency services (including ambulance and hospital services) in the event of a medical emergency during a Course;

  • to our third-party invoicing or payment platform for the purpose of processing your Course booking and payment;

  • to professional advisers, including lawyers, accountants, and insurers, where necessary for the operation of our business or the resolution of a legal matter;

  • to government authorities, regulators, law enforcement agencies, or courts, where required or authorised by law; and

  • to any person with your express consent.

We will not disclose your health information to any third party without your express consent, except in circumstances involving an emergency medical situation or where required by law.

Where we engage third-party service providers to assist us in delivering our services, we take reasonable steps to ensure that those providers handle your personal information in accordance with the APPs and our privacy standards.

 

10. CROSS-BORDER DISCLOSURE

We do not currently transfer personal information to recipients located outside Australia. All personal data is stored and processed within Australia.

If this changes in the future (for example, if we adopt international cloud-based platforms or expand our services internationally), we will update this Privacy Policy accordingly and take all steps required under APP 8 to ensure that overseas recipients handle your information in a manner consistent with the APPs.

 

11. MARKETING COMMUNICATIONS AND OPT-OUT

We may use your name and email address to send you information about upcoming Courses, promotions, new services, or related educational content that we consider may be of interest to you, but only where you have expressly consented to receive such communications or where we are otherwise permitted by law.

You may withdraw your consent to receive marketing communications at any time by contacting us at the details below or by clicking the unsubscribe link in any marketing email we send to you. Following your opt-out request, we will remove you from our marketing list within a reasonable period. Please note that opting out of marketing communications will not affect our ability to send you transactional communications related to your Course booking.

We will not use your health information or any other sensitive information for marketing purposes without your express consent.

 

12. COOKIES AND WEBSITE TRACKING

Our website (www.calminthechaos.com.au) may use cookies and similar tracking technologies to collect technical information about website visitors. This information may constitute personal information where it is reasonably capable of identifying an individual.

For full details of how we use cookies on our website, what types of cookies we use, and how you can manage your cookie preferences, please refer to our Cookie Policy, available on our website.

Where cookies or tracking technologies collect personal information, we handle that information in accordance with this Privacy Policy and the APPs.

 

13. CONSENT TO COLLECTION OF SENSITIVE INFORMATION

Because we collect sensitive health information from Course Participants, we are required under APP 3.3 of the Privacy Act to obtain your consent before collecting such information, unless another ground under the Privacy Act applies.

By completing the health disclosure section of our enrolment process, or by verbally providing health information to our Course instructor at check-in, you provide your express consent to the Company collecting, holding, using, and disclosing your sensitive health information for the purposes set out in this Privacy Policy, including:

  • ensuring your safety and the safety of other Course participants during practical activities;

  • adapting Course delivery to accommodate your health disclosure;

  • facilitating emergency medical assistance if required during a Course; and

  • maintaining records for safety and incident management purposes.

You have the right to withdraw your consent to the collection and use of your sensitive health information at any time by contacting us in writing. Withdrawal of consent may affect our ability to safely deliver Course Services to you.

 

14. YOUR RIGHTS: ACCESS TO YOUR PERSONAL INFORMATION

Under APP 12 of the Privacy Act, you have the right to request access to personal information we hold about you. To make an access request, please contact us in writing at the contact details below, clearly identifying the information you wish to access.

We will respond to access requests within a reasonable period, and in any event within 30 days of receiving your request. We will provide access in the format requested by you, where it is reasonable and practicable for us to do so. In certain limited circumstances prescribed by the Privacy Act, we may refuse access to some or all of the information requested, in which case we will provide you with written reasons for the refusal.

We do not charge a fee for making an access request, but we may charge a reasonable fee for the cost of retrieving, compiling, and providing access to the information.

 

15. YOUR RIGHTS: CORRECTION OF YOUR PERSONAL INFORMATION

Under APP 13, you have the right to request that we correct any personal information we hold about you that is inaccurate, out of date, incomplete, irrelevant, or misleading. To make a correction request, please contact us in writing at the details below.

We will take reasonable steps to correct your personal information within 30 days of receiving your request. If we do not agree that correction is required, we will notify you in writing and provide reasons. You may then request that we associate a statement with your information noting that you believe it is inaccurate, out of date, incomplete, or misleading.

 

16. NOTIFIABLE DATA BREACHES

We are committed to complying with the Notifiable Data Breaches (NDB) scheme under Part IIIC of the Privacy Act 1988 (Cth). In the event of an eligible data breach, being a breach that is likely to result in serious harm to any individual whose information is involved, we will:

  • take immediate steps to contain the breach and assess its scope;

  • notify the Office of the Australian Information Commissioner (OAIC) as soon as practicable; and

  • notify each individual whose information is involved in the breach (or whose information is likely to be involved) as soon as practicable, providing details of the breach and the steps affected individuals should take to protect themselves.

Given that we hold sensitive health information, we take our obligations under the NDB scheme seriously and have implemented appropriate procedures for identifying, assessing, and responding to data breaches in a timely manner.

 

17. PRIVACY AND OTHER LEGISLATION AMENDMENT ACT 2024

The Privacy and Other Legislation Amendment Act 2024 (Cth) ("POLA 2024"), which received Royal Assent on 10 December 2024, introduced significant reforms to Australia's privacy framework. Relevant aspects of these reforms that affect our operations include:

  • the introduction of a statutory tort for serious invasions of privacy, enabling individuals to seek compensation in certain circumstances;

  • the introduction of new criminal offences relating to doxxing (malicious release of personal information online);

  • enhanced transparency requirements in relation to automated decision-making (applicable from December 2026); and

  • strengthened enforcement powers for the OAIC, including the ability to conduct audits and issue civil penalty notices.

We are actively monitoring the implementation of these reforms and further expected amendments to the Privacy Act and will update our practices and this Privacy Policy as required.

 

18. ANONYMITY AND PSEUDONYMITY

Under APP 2, wherever it is lawful and practicable for you to interact with us without providing your personal information, we will give you the option to do so anonymously or using a pseudonym.

However, we note that for the purposes of booking and attending a Course, particularly where health information is required for your safety, it is generally not practicable for us to deal with you on an anonymous basis. Anonymous or pseudonymous enquiries are welcome for general information requests.

 

19. UNSOLICITED PERSONAL INFORMATION

If we receive personal information about you that we did not solicit, we will assess whether we could have collected that information under the APPs if we had solicited it. If we determine that we could not have collected it, we will take reasonable steps to destroy or de-identify that information as soon as practicable.

 

20. DIRECT MARKETING

We will only use or disclose personal information for direct marketing purposes where:

  • the information was collected directly from you in the course of your engagement with our services;

  • you have not opted out of receiving marketing communications; and

  • we always provide a simple means for you to opt out of receiving further marketing materials.

We will never use sensitive information for direct marketing purposes without your express consent. We will not disclose your personal information to third parties for their direct marketing purposes under any circumstances.

 

21. CHILDREN'S PRIVACY

Our Courses are designed for adults. Where a parent or legal guardian enrols on behalf of a minor participant (with our express written consent), the parent or guardian is responsible for providing accurate and complete information on behalf of the minor and for ensuring the minor's participation is appropriate.

We do not knowingly collect personal information directly from individuals under the age of 18 without the express consent and oversight of their parent or legal guardian. In keeping with the POLA 2024 reforms' enhanced focus on children's online privacy, we take a conservative approach to handling any information that relates to a child.

 

22. THIRD-PARTY LINKS AND PLATFORMS

Our website may contain links to third-party websites or services. We are not responsible for the privacy practices of those third parties. We encourage you to review the privacy policies of any third-party website or service you access via our website.

The Company's invoicing and payment processes may involve third-party platforms. We take reasonable steps to ensure these platforms maintain appropriate privacy and security standards, but we are not responsible for their privacy practices beyond our contractual arrangements with them.

 

23. COMPLAINTS ABOUT PRIVACY

If you believe we have mishandled your personal information or failed to comply with the Privacy Act or the APPs, you have the right to make a complaint to us. To lodge a complaint, please contact us in writing at the details below, clearly stating:

  • your name and contact details;

  • a detailed description of your complaint; and

  • how you would like the matter resolved.

We will acknowledge your complaint within five (5) business days and will endeavour to investigate and resolve the matter within 30 days. If you are not satisfied with our response, or if we do not respond within a reasonable period, you have the right to escalate your complaint to the Office of the Australian Information Commissioner (OAIC):

 

OAIC Website: www.oaic.gov.au

OAIC Phone: 1300 363 992

OAIC Post: GPO Box 5218, Sydney NSW 2001

 

24. GOVERNING LAW

This Privacy Policy is governed by and construed in accordance with the laws of the Commonwealth of Australia, and the laws of the State of Victoria. Any dispute arising in connection with this Privacy Policy will be subject to the exclusive jurisdiction of the courts of Victoria and the Federal Court of Australia.

This Privacy Policy is prepared in accordance with and reflects the requirements of the Privacy Act 1988 (Cth) as amended, the Australian Privacy Principles, the Privacy and Other Legislation Amendment Act 2024 (Cth), and all other applicable Commonwealth and Victorian legislation.

 

25. CONTACT US

For any questions, requests, or concerns relating to this Privacy Policy or the handling of your personal information, please contact us:

 

Calm In the Chaos / The Postpartum Hub PTY LTD

Website: www.calminthechaos.com.au

Email: hello@calminthechaos.com.au

Phone: 0420 529 870

 

We are committed to handling all privacy enquiries and complaints promptly, fairly, and in accordance with our legal obligations.

 

Last updated: 16 June 2025. This Privacy Policy is reviewed annually or as required by changes in applicable law or our business practices.

Book a session

Ready to feel more confident in an emergency?

Fill in the form below with your preferred date, time and session option or to ask any questions - I’d love to help you find the option that suits you & your family best.

  • White Instagram Icon

© 2026 by Calm In The Chaos

bottom of page