Skip to main content

Privacy Policy

How CCData Pty Limited collects, uses, stores and protects personal information under the Privacy Act 1988 (Cth) and the Australian Privacy Principles.

1. About this Privacy Policy

CCData Pty Limited (ABN 84 690 097 922) is committed to protecting your privacy and handling personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

This policy explains:

  • what personal information we collect,
  • how we collect it,
  • why we collect it and how we use it,
  • who we share it with,
  • how we keep it secure,
  • your rights to access and correct your information, and
  • how to contact us or make a complaint.

This Privacy Policy applies to personal information we hold in connection with our business, including information collected through our website (ccdata.com.au), our survey and data-processing services, and any other interaction you have with us.

2. About CCData

CCData has provided survey research and data-processing services to Australian businesses, government agencies, and not-for-profit organisations since 1990. Our core work involves:

  • designing and conducting surveys on behalf of our clients,
  • collecting and processing survey responses, and
  • analysing and reporting on data supplied by our clients.

We are primarily a business-to-business service provider. In most cases, we handle personal information as a service provider to our clients — the originating organisation (our client) remains the entity that holds the underlying customer or member relationship.

3. What personal information we collect

We collect different categories of personal information depending on how you interact with us.

3.1 From you, directly

When you contact us through our website, by phone, or by email, we may collect:

  • your name,
  • your business email address and phone number,
  • your organisation and role,
  • the content of your enquiry, and
  • any other information you choose to provide.

3.2 Through our website

Our website (ccdata.com.au) automatically collects limited technical information when you visit, including:

  • your IP address,
  • your browser type and version,
  • the pages you visit on our site, and
  • the date and time of your visit.

This information is collected via standard web server logs and via Google Analytics (see §10 for cookies and analytics).

3.3 In the course of providing services to our clients

When we conduct a survey or process data on behalf of a client, we may receive personal information about that client’s customers, members, donors, patients, or other contacts. This may include:

  • names and contact details,
  • demographic information,
  • responses to survey questions,
  • account or membership identifiers.

We do not collect or handle sensitive information (as defined in the Privacy Act 1988) — including health or medical information, racial or ethnic origin, religious or political beliefs, sexual orientation, or criminal record. Our survey and data-processing work is limited to standard customer-satisfaction, market-research, and similar non-sensitive information.

We receive this information from our client under a contract that sets out how the information is to be used, secured, retained, and returned or destroyed at the end of the project.

We do not directly recruit survey respondents from the general public. Where a survey involves contacting individuals directly, the underlying contact list is supplied by our client, who is responsible for ensuring those individuals have been notified of, or consented to, that use.

4. How we use personal information

We use personal information only for the purposes for which it was collected, and for related purposes that you would reasonably expect.

Specifically, we use personal information to:

  • respond to enquiries and provide quotes,
  • conduct surveys and collect responses on behalf of our clients,
  • process and analyse data supplied by our clients,
  • prepare reports and deliverables for our clients,
  • send service-related communications (e.g. project updates, account notices),
  • improve our website and services, and
  • meet our legal and regulatory obligations.

We do not use personal information for direct marketing without your consent, and we do not sell personal information to any third party.

5. Who we share it with

We may share personal information with:

  • The client who engaged us. Where we are conducting a survey or processing data on behalf of a client, the client receives the survey results, processed data, and reports.
  • Our service providers, including our cloud hosting, email infrastructure, and analytics providers (see §7 on cross-border disclosure). All service providers are bound by confidentiality and data-protection obligations.
  • Law enforcement and regulators, where we are required to disclose information by law or by court order.
  • Professional advisors (e.g. legal, accounting) under confidentiality obligations.

We do not sell, rent, or trade personal information to any third party for marketing purposes.

6. Anonymity and pseudonymity (APP 2)

Where it is lawful and practicable, you can deal with us anonymously or under a pseudonym — for example, when browsing our website or asking a general question.

We may need to identify you when:

  • you ask us to respond to an enquiry that requires us to contact you,
  • you participate in a survey where the design requires identifying respondents (we will tell you when this is the case), or
  • we are required by law to identify you.

7. Cross-border disclosure (APP 8)

Some of the service providers we rely on operate or store data outside Australia. We use these providers for categories of service such as website analytics, content delivery and security, and cloud hosting and email infrastructure. Our specific providers may change from time to time as we review and update our systems.

The countries to which personal information may be disclosed currently include the United States and other countries in which our service providers operate. Our primary hosting, email, and internal systems are located in Australia.

Where we disclose personal information to an overseas recipient, we take reasonable steps to ensure that the recipient handles the information in a way consistent with the Australian Privacy Principles.

8. Security (APP 11)

We take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access, modification, or disclosure. These steps include:

  • encrypted transmission of data (TLS/HTTPS) on our website and in our email systems,
  • access controls on our internal systems, with personal information accessible only to staff who need it for their work,
  • staff confidentiality obligations,
  • secure destruction of physical records when no longer required, and
  • secure deletion of digital records when no longer required.

We retain personal information only for as long as we need it for the purpose for which it was collected, or as required by law or by contract with our clients. At the end of a project, personal information held on behalf of a client is returned to the client or securely destroyed, as agreed with the client.

If you believe the security of your personal information has been compromised, please contact us immediately (see §14).

9. Access and correction (APPs 12 and 13)

You have the right to ask us:

  • to confirm whether we hold personal information about you,
  • to give you access to that information, and
  • to correct that information if it is inaccurate, out of date, incomplete, irrelevant, or misleading.

To make a request, please contact our Privacy Officer (see §14). We will:

  • acknowledge your request within 5 business days,
  • respond substantively within 30 days,
  • not charge you for making the request, although we may charge a reasonable cost for retrieving information from archives or third-party systems (we will tell you in advance if any charge will apply), and
  • explain in writing if we cannot give you access or make a requested correction.

Where the personal information was collected by us on behalf of a client, we may need to refer the request to that client, as they are the holder of the underlying relationship with you.

10. Cookies and web analytics

Our website uses cookies for two purposes:

  1. Essential cookies that are required for the site to function (e.g. session management). These cookies are always active.
  2. Analytics cookies that help us understand how visitors use the site. These are only set if you consent.

We use Google Analytics to collect aggregated, de-identified information about site traffic. You can opt out of Google Analytics tracking using the Google Analytics opt-out browser add-on, available at https://tools.google.com/dlpage/gaoptout.

Most browsers also allow you to refuse or delete cookies. Doing so may affect the functionality of our site.

11. Children

Our services are not directed at children, and our website is not designed to attract or be used by children.

CCData will not knowingly collect personal information from, or engage in survey work with, anyone under the age of 18. Our survey and data-processing work does not target minors. If you become aware that we have collected personal information about a person under 18, please contact us so we can remove it.

12. Direct marketing (APP 7)

We do not conduct direct marketing to individuals. Communications we send are limited to:

  • responses to enquiries you have made,
  • service-related communications relating to a project we are conducting for or with you, and
  • updates to existing clients about our services.

You can opt out of any non-essential communications at any time by contacting us.

13. Industry codes and standards

CCData is not currently a certified member of an external research industry code (e.g. AMSRS, AMSRO, ISO AS 20252). Where we conduct work that is governed by such a code on behalf of a member client, we follow the applicable code requirements in addition to the Privacy Act.

14. Complaints

If you have a complaint about how we have handled your personal information, please contact our Privacy Officer (see contact details below).

We will:

  • acknowledge your complaint within 5 business days,
  • investigate the complaint, and
  • respond to you substantively within 30 days.

If you are not satisfied with our response, you can lodge a complaint with the Office of the Australian Information Commissioner (OAIC):

15. Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in our practices or in the law. The current version is always available at ccdata.com.au/privacy-policy/. We will note the date of the last update at the bottom of the policy.

16. Contact us

Privacy Officer
CCData Pty Limited
ABN 84 690 097 922

Channel Details
Email [email protected]
Phone 1300 858 253 (Mon–Fri 9:00 AM – 5:00 PM AEST)
Address 593–595 Woodstock Ave, Glendenning NSW 2761

This Privacy Policy was last updated on 31 July 2026.