Privacy Policy

This Privacy Policy explains how coRise, operated independently by its founder ("coRise", "we", "us"), based in Melbourne, Victoria, Australia, handles personal information when you visit our websites (corise.me and corisehq.com), apply for or hold a coRise membership, or contact us.

We aim to handle personal information consistently with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles. Where we offer services to people in other regions, we also take into account widely recognised data-protection principles such as those in the EU/UK GDPR. This document is a plain-language summary and is not legal advice.

1. Who is responsible for your data

The data controller is coRise, operated independently by its founder, based in Melbourne, Victoria, Australia. We do not publish a street address; for privacy enquiries, contact [email protected].

2. Information we collect

We do not intentionally collect special-category / sensitive information, and we ask that you do not send it to us through registration fields.

3. Why we use your information (purposes)

Depending on the applicable law, our legal bases include performance of our membership agreement with you, your consent (for optional profile data and marketing), our legitimate interests in running and securing a trusted community, and compliance with law.

4. Service providers we use

We share personal information with a small number of vendors that process it on our behalf, under contract and only for the purposes above. By category, these currently include:

This list may change as our stack evolves; we will keep this section current. We do not sell personal information.

5. International transfers

Our providers may store or process data outside Australia, including in the United States and other countries. Where we transfer personal information overseas, we take reasonable steps to ensure it is handled consistently with this policy and applicable law, for example through the provider's contractual commitments and recognised transfer mechanisms. Contact us if you would like more detail on a specific provider.

6. How long we keep it

We keep membership records for as long as you hold a membership and for a reasonable period afterwards to meet legal, accounting, and dispute-resolution needs, then delete or de-identify them. Verification and security logs are kept only for a short period appropriate to their purpose. Marketing preference records are kept while relevant to show the basis of your consent or opt-out.

7. How we protect your information

We use technical and organisational measures appropriate to the risk, including encryption in transit, access controls, limiting who can see member data, and abuse / rate-limiting protections on our endpoints. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we become aware of a data breach that is likely to cause serious harm, we will notify affected individuals and the relevant regulator as required by law.

8. Marketing communications

Membership does not depend on receiving marketing. We send non-essential updates (such as newsletters or event invitations) only if you have opted in with the separate, unticked checkbox at registration or elsewhere. You can withdraw consent at any time using the unsubscribe link in those emails or by contacting [email protected]. We will still send you essential service messages related to your membership.

9. Your rights and choices

You can ask us to:

To make a request, email [email protected]. We may need to verify your identity. We aim to respond within the timeframe required by applicable law.

10. Complaints

If you are concerned about how we have handled your personal information, contact us first at [email protected] so we can try to resolve it. You may also complain to the Office of the Australian Information Commissioner (oaic.gov.au) or, if you are in another jurisdiction, to your local data-protection authority.

11. Children

coRise is intended for adults. It is not directed at children, and we do not knowingly collect their personal information. If you believe a child has provided us data, contact us and we will delete it.

12. Changes to this policy

We may update this policy from time to time. We will change the "last updated" date above and, for material changes, take reasonable steps to notify members.