1. About This Policy
1.1 Who we are
Property Investment Professionals of Australia Ltd (ABN 21 093 872 051) (“PIPA”, “we”, “us”, “our”) is the peak not-for-profit industry body for property investment professionals in Australia. We provide membership services, the Qualified Property Investment Adviser (QPIA) accreditation program, professional development courses, events, industry advocacy, and research.
1.2 Purpose of this policy
This policy explains in plain language what personal information we collect, why we collect it, how we keep it safe, who we share it with, and what rights you have. We are committed to protecting your privacy and handling your personal information responsibly.
1.3 Legal framework
We handle your personal information in accordance with the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs), and the Privacy and Other Legislation Amendment Act 2024 (Cth).
1.4 Scope
This policy applies to all personal information collected through our websites (www.pipa.asn.au and www.education.pipa.asn.au), email communications, telephone enquiries, event registrations, membership applications, course enrolments, social media interactions, and any other dealings with us.
2. What Personal Information We Collect
The types of personal information we collect depend on how you interact with us.
2.1 Information you provide to us
When you apply for membership, enrol in a course, register for an event, or contact us, we may collect:
- your name, email address, telephone number, and postal address;
- your business or employer name, ABN, and professional role;
- your professional qualifications, licence numbers, and accreditation status;
- payment and billing information (processed securely by our third-party payment provider and not stored on our servers);
- your professional experience, training history, and references (for accreditation applications);
- dietary requirements or accessibility needs (for events);
- survey responses and feedback;
- social media handles (where you share them with us); and
- any other information you include in correspondence with us.
2.2 Information we collect automatically
When you visit our website, we automatically collect certain technical information, including:
- your IP address and approximate geographic location;
- your browser type, operating system, and device information;
- the pages you visit, the time spent on each page, and the referring website; and
- cookie and pixel data (see Section 10).
2.3 Information from third parties
We may receive personal information about you from third parties, including:
- professional licensing and regulatory bodies, to verify your qualifications or licence status;
- payment processors, to confirm transaction status; and
- event co-hosts or industry partners, where you have consented to your information being shared with us.
2.4 Sensitive information
We do not generally collect sensitive information (as defined in the Privacy Act 1988). If we ever need to collect sensitive information, we will obtain your consent unless we are required or authorised by law to collect it.
2.5 Anonymity and pseudonymity
Where practicable, you may deal with us without identifying yourself or by using a pseudonym. However, if you do not provide the personal information we request, we may not be able to provide you with our services, process your membership application, or enrol you in a course.
3. How We Collect Your Information
We collect personal information directly from you wherever reasonably practicable. This includes when you:
- apply for or renew your PIPA membership;
- enrol in the QPIA accreditation program or other courses;
- register for events, webinars, or conferences;
- subscribe to our newsletters, publications, or industry updates;
- submit enquiries, feedback, or complaints;
- participate in surveys or research;
- interact with us on social media; or
- visit our website.
Where it is unreasonable or impracticable to collect information directly from you, we may collect it from the third-party sources described in Section 2.3. We will take reasonable steps to notify you of such collection as soon as practicable.
If you provide us with personal information about another person (for example, a colleague’s contact details for an event registration), you must ensure that person is aware of and consents to the disclosure, and you must direct them to this privacy policy.
3.1 Unsolicited personal information
If we receive personal information that we did not request, we will determine within a reasonable period whether we could have collected it under the APPs. If we determine that we could not have collected it, and the information is not contained in a Commonwealth record, we will destroy or de-identify it as soon as practicable, provided it is lawful and reasonable to do so.
4. Why We Collect and How We Use Your Information
We only collect personal information that is reasonably necessary for our functions and activities as a not-for-profit industry body. We use your information for the following purposes:
4.1 Membership and accreditation
Processing and managing membership applications, renewals, and records; administering the QPIA accreditation program; verifying professional qualifications and licence status; maintaining the PIPA member directory (see Section 4.7); and communicating with you about your membership or accreditation.
4.2 Course delivery and education
Enrolling you in courses, delivering course content through our education platform, tracking your progress and assessment outcomes, issuing certificates and accreditation, and providing student support.
4.3 Events
Registering you for events, managing event logistics, catering to dietary or accessibility requirements, and issuing tickets, confirmations, or post-event materials.
4.4 Communications
Responding to your enquiries, providing customer and member support, sending administrative notices related to your membership, enrolment, or event registration, and issuing receipts and payment confirmations.
4.5 Marketing
Sending newsletters, industry updates, and promotional material about our services, courses, and events. We only send marketing communications where you have opted in or where we have an existing membership or service relationship with you and the communication relates to similar services. You can opt out at any time (see Section 4.6).
4.6 Opting out of marketing
You can opt out of marketing communications at any time by:
- clicking the unsubscribe link in any marketing email;
- replying STOP to any SMS; or
- contacting us using the details in Section 14.
We will action your request promptly. Opting out of marketing does not affect transactional or administrative communications related to your membership, course enrolment, or event registration.
4.7 Member directory
PIPA operates a publicly accessible member directory on our website (“Find a Member”) to connect consumers with accredited property investment professionals. If you are a PIPA member, your name, business name, location, and accreditation status may be displayed in the directory. You may opt out of the public directory at any time by contacting us. Information displayed in the public directory may be cached by search engines, and we cannot control third-party caching after removal.
4.8 Industry research, advocacy, and analytics
Analysing aggregated and de-identified data to produce industry research and reports, inform policy submissions, understand membership trends, and improve our services. Individual members are not identified in published research or reports without their consent.
4.9 Website improvement
Analysing how visitors use our website to improve its functionality, content, and user experience.
4.10 Legal and regulatory compliance
Meeting our obligations under applicable laws, including tax record-keeping, responding to lawful requests from regulators or courts, and complying with regulatory requirements.
5. Automated Tools and Artificial Intelligence
We may use automated tools or artificial intelligence to support our operations. This may include:
- analysing website traffic and user behaviour to improve our services;
- filtering and managing enquiries and communications;
- assisting with content creation and administrative tasks; and
- detecting and preventing fraudulent or unauthorised activity on our website.
We do not use automated tools to make decisions about you that have a significant effect on your rights or interests without human review. If you have concerns about how an automated tool has been used in relation to your personal information, please contact us and we will have a person review the matter.
5.1 Automated decision-making transparency (from 10 December 2026)
In accordance with APPs 1.7, 1.8, and 1.9 introduced by the Privacy and Other Legislation Amendment Act 2024, from 10 December 2026 we will disclose in this policy:
- the kinds of personal information used in any substantially automated decision that could reasonably be expected to significantly affect an individual’s rights or interests; and
- the kinds of decisions made using such automated processes.
As at the date of this policy, PIPA does not make substantially automated decisions that significantly affect individual rights or interests. We will update this section if that changes.
6. Cross-Border Disclosure of Personal Information
6.1 Philippines-based service providers
PIPA engages service providers based in the Philippines who assist with administrative, operational, and member support functions. These service providers may access your personal information, including your name, contact details, membership status, and correspondence.
6.2 Our obligations under APP 8
Before disclosing your personal information to an overseas recipient, we take reasonable steps to ensure the overseas recipient handles your information consistently with the APPs. These steps include:
- binding contractual obligations requiring the overseas recipient to handle personal information in accordance with the APPs;
- implementing access controls so that overseas personnel can only access the personal information necessary for their specific role;
- ongoing monitoring and supervision of overseas service providers, including regular compliance reviews;
- requiring the use of secure, encrypted systems for accessing and transmitting personal information; and
- restricting the overseas recipient from further disclosing personal information without our authorisation.
6.3 Other countries
We may also disclose personal information to service providers located in other countries where those providers support our technology platforms (for example, cloud hosting, email marketing, analytics, or payment processing). Where this occurs, we take reasonable steps to ensure those providers are bound by obligations consistent with the APPs through contractual arrangements or the provider’s certified privacy frameworks.
6.4 Countries of disclosure
The countries to which we currently disclose, or may disclose, personal information include the Philippines, the United States, and any other countries in which our technology service providers operate servers or support functions. We will update this section if additional countries are added.
7. Who We Share Your Information With
We do not sell, rent, or trade your personal information.
We may share your personal information with the following categories of recipients, only to the extent necessary for the purposes described in this policy:
- payment processors, to process membership fees, course fees, and event payments securely;
- our website hosting and technology providers, to operate and maintain our websites and systems;
- our learning management system provider, to deliver course content and track enrolment;
- email and communications platforms, to send you correspondence and marketing (where you have opted in);
- analytics providers, to understand website usage in aggregated form;
- event venues and co-hosts, to manage event logistics (limited to the information necessary for that purpose);
- professional regulatory bodies, where verification of qualifications or accreditation status is required;
- our professional advisers, including lawyers, accountants, and auditors, where necessary for PIPA’s operations;
- overseas service providers, as described in Section 6; and
- any person or body where we are required or authorised by Australian law to do so.
Each of these recipients is required to handle your personal information securely and only for the specific purpose for which it was shared. Our contracts with third-party service providers prohibit them from using your personal information for any other purpose.
7.1 Government-related identifiers
Where we collect government-related identifiers (such as licence numbers or ABNs), we will only use or disclose them as required or authorised by law, or for the purpose of verifying your identity or professional qualifications.
7.2 Change of control
If PIPA undergoes a merger, restructure, or transfer of operations, your personal information may be transferred to the successor entity under a confidentiality agreement. We will notify you of any such transfer and your options regarding your personal information.
8. Keeping Your Information Safe
We take reasonable steps to protect your personal information from misuse, interference, loss, unauthorised access, modification, and disclosure. Our security measures include:
- encrypting data transmitted between your browser and our website using SSL/TLS;
- restricting access to personal information to authorised personnel on a need-to-know basis;
- using secure, encrypted storage for sensitive data;
- implementing access controls, including multi-factor authentication where appropriate;
- monitoring and supervising overseas service providers with access to personal information;
- conducting regular security reviews and assessments;
- training all staff and contractors (including overseas service providers) on their privacy and data security obligations; and
- maintaining strict access protocols for overseas personnel, including activity logging and periodic audits.
Payment information is processed by our third-party payment provider and is not stored on our servers.
No system is completely secure. While we take all reasonable precautions, we cannot guarantee the absolute security of your personal information.
9. How Long We Keep Your Information
We retain your personal information only for as long as necessary to fulfil the purposes for which it was collected, or as required by law. As a general guide:
- membership records: for the duration of your membership, plus 7 years after your membership ends (for legal and regulatory purposes);
- QPIA accreditation records: indefinitely, as a permanent record of professional qualification;
- course enrolment and completion records: 7 years after course completion;
- payment and financial records: 7 years (as required by Australian tax law);
- event registration records: 3 years after the event;
- marketing preferences: until you unsubscribe, plus 12 months;
- support and enquiry correspondence: 3 years after resolution;
- website analytics data: 26 months; and
- cookie consent records: 12 months.
When your personal information is no longer required, we securely delete or de-identify it in accordance with our data retention procedures.
10. Cookies
Cookies are small text files stored on your device when you visit our website. They help our website function correctly and allow us to understand how visitors use it.
10.1 Essential cookies
These are necessary for the website to function, including maintaining your login session, processing payments, and ensuring website security. They are always active.
10.2 Analytics cookies
These help us understand how visitors interact with our website, including which pages are visited most frequently and how users navigate the site. You can opt out of these cookies.
10.3 Marketing cookies
These are used to deliver relevant advertisements and measure the effectiveness of campaigns through third-party platforms. You can opt out of these cookies.
10.4 Preference cookies
These remember your settings and choices to personalise your experience. You can opt out of these cookies.
10.5 Managing cookies
When you first visit our website, a cookie consent banner allows you to accept or decline non-essential cookies. You can also manage cookies at any time through your browser settings. Disabling certain cookies may affect the functionality of our website.
11. Notifiable Data Breaches
In the event of a data breach that is likely to result in serious harm to any individual whose personal information is involved, we will:
- take immediate steps to contain the breach and mitigate any harm;
- conduct an assessment to determine whether the breach is likely to result in serious harm;
- notify the Office of the Australian Information Commissioner (OAIC) as soon as practicable; and
- notify affected individuals, providing a description of the breach, the types of information involved, and recommended steps to protect themselves.
This is in accordance with the Notifiable Data Breaches scheme under Part IIIC of the Privacy Act 1988.
12. Children’s Privacy
Our services are directed at property investment professionals and are not intended for individuals under 18 years of age. We do not knowingly collect personal information from children.
If we become aware that we have collected personal information from a person under 18 without appropriate parental or guardian consent, we will take steps to delete that information as soon as practicable.
If you are a parent or guardian and believe a child has provided personal information to us, please contact us immediately using the details in Section 14.
We will comply with the Children’s Online Privacy Code when it takes effect, as required under the Privacy and Other Legislation Amendment Act 2024.
13. Your Rights
Under the Privacy Act 1988 and the Australian Privacy Principles, you have the right to:
- request access to the personal information we hold about you (APP 12);
- request correction of any personal information that is inaccurate, out of date, incomplete, irrelevant, or misleading (APP 13);
- request deletion of your personal information, where we are not required by law to retain it;
- withdraw your consent to the collection or use of your personal information, where consent was the basis for collection;
- opt out of receiving marketing communications;
- opt out of the public member directory; and
- make a complaint if you believe we have breached the APPs or mishandled your personal information.
To exercise any of these rights, contact us using the details in Section 14. We will acknowledge your request within 5 business days and respond substantively within 30 days.
13.1 Right to take legal action
Since 10 June 2025, the Privacy and Other Legislation Amendment Act 2024 provides individuals with the right to take legal action for serious invasions of privacy. PIPA takes this obligation seriously and encourages you to contact us first so we can work to resolve any concerns directly.
14. Complaints and Contact
If you have any questions about this policy, wish to exercise your privacy rights, or wish to make a complaint about how we have handled your personal information, please contact us:
Privacy Officer Property Investment Professionals of Australia Ltd Level 3, 478 George Street Sydney NSW 2000
Phone: 02 7205 0700 Email: [email protected]
We aim to acknowledge your enquiry within 5 business days and to resolve any complaint within 30 days.
If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC):
Website: www.oaic.gov.au Phone: 1300 363 992
15. Changes to This Policy
We may update this policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make changes, we will update the “Last updated” date at the top of this policy and post a notice on our website.
Where a change materially affects how we handle your personal information, we will take reasonable steps to notify you directly, including by email where practicable.
We encourage you to review this policy periodically.
