Privacy Policy.

Last updated:
September 2026

Go back to homepage

Privacy Policy

Harmony Early Education Pty Ltd is committed to protecting personal information and handling it openly and responsibly. This Policy explains how we collect, hold, use and disclose personal information and how individuals may access, correct or complain about our handling of it.

Who this Policy applies to

This Policy applies to Harmony Early Education Pty Ltd ACN 615 934 033 and its wholly owned subsidiaries (Harmony, we, us or our). It applies to personal information we handle about children, parents, guardians, authorised nominees, family members, visitors, workers, employment candidates, contractors, suppliers, professional contacts and Website users.

This Policy is intended to satisfy the requirements of the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), to the extent they apply. Other laws and regulatory requirements may also govern particular records, including education and care, family assistance, employment, workplace surveillance, child safety, health and record-retention requirements.

Additional collection notices, consents and policies may apply to particular activities or technologies. They should be read together with this Policy. Where a more specific notice or policy applies, it will provide additional information about that activity.

Meaning of personal and sensitive information

Personal information is information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether or not the information is true and whether or not it is recorded in a material form.

Sensitive information includes health information and information or opinions about matters such as racial or ethnic origin, religious beliefs, sexual orientation, criminal record and biometric information used for automated biometric verification or identification. We only collect sensitive information where authorised by law, with consent where required, or where another legal exception applies.

Personal information we may collect

Children and families

  • names, dates of birth, addresses, contact details, family relationships and authorised nominee details;
  • enrolment, attendance, booking, waitlist and service history;
  • biometric identifiers or biometric templates used for centre access, security or authentication purposes where a parent, guardian or authorised individual elects to use a biometric access system;
  • identity, residency, Customer Reference Number, Child Care Subsidy and other government-related information where required;
  • health, medical, allergy, dietary, immunisation, disability, developmental, cultural, religious, behavioural and additional-needs information;
  • care plans, medication records, incident, injury, trauma, illness and emergency information;
  • learning observations, educational documentation, assessments, photographs, audio or video where authorised or otherwise permitted by law;
  • court orders, parenting arrangements, custody information and child-safety information;
  • billing, payment, debt and transaction information; and
  • communications, feedback, complaints and records of interactions with us.

Workers, candidates and contractors

  • identity and contact details, employment history, qualifications, registrations, licences and referee information;
  • right-to-work, visa, background-check, working-with-children and criminal-history information where lawful and required;
  • payroll, banking, superannuation, tax, leave and benefits information;
  • health, medical, injury, workers compensation, emergency-contact and workplace-adjustment information;
  • training, performance, conduct, investigation, safety, access and system-use records; and
  • information necessary to manage a supplier, contractor or professional relationship.

Website users and other contacts

  • name, contact details and information provided in enquiry, tour, recruitment, waitlist or other online forms;
  • device, browser, IP address, approximate location, referral source, page views, interactions and cookie identifiers;
  • marketing preferences and engagement with communications; and
  • visitor, event, access, incident or security information.

How we collect personal information

We generally collect personal information directly from the individual or, for a child, from a parent, guardian or authorised person. We may collect information:

  • when a person enquires, books a tour, joins a waitlist, enrols a child, attends a centre, uses a portal or application, makes a payment or communicates with us;
  • through forms, telephone calls, email, meetings, surveys, complaints, photographs, educational documentation, CCTV systems, access control systems (including biometric access systems where utilised) and centre records;
  • during recruitment, onboarding, employment, contracting or supplier administration;
  • from government agencies, regulators, schools, health professionals, emergency services, referees, screening providers, insurers, advisers, service providers and other authorised third parties;
  • from publicly available sources where lawful and relevant; and
  • automatically when a person uses our Website or digital services, including through cookies and similar technologies.

If we receive unsolicited personal information, we will determine whether we could lawfully have collected it. If not, we will destroy or de-identify it where lawful and reasonable to do so.

Why we collect, hold, use and disclose information

We may handle personal information for purposes including (without limitation):

  • providing education and care services and supporting children’s safety, wellbeing, development, inclusion and learning;
  • assessing enquiries, tours, waitlists, enrolments, bookings and service availability;
  • identifying and communicating with parents, guardians, authorised nominees, emergency contacts and other relevant persons;
  • meeting legal, regulatory, funding, quality, safeguarding, reporting and record-keeping obligations;
  • administering centre security, visitor management and access control systems;
  • administering Child Care Subsidy, government programs, fees, payments, refunds, debts and accounts;
  • managing incidents, emergencies, complaints, disputes, investigations, insurance and legal claims;
  • operating, securing, maintaining and improving centres, systems, Website and services;
  • recruiting, engaging and managing workers, contractors and suppliers;
  • conducting quality assurance, governance, audit, training, planning, research and service improvement, using de-identified information where reasonably practicable;
  • communicating with individuals and, with consent or where otherwise permitted, providing news, events and marketing; and
  • protecting the rights, safety and property of children, families, workers, Harmony and others.

We generally use and disclose personal information for the purpose for which it was collected. We may also use or disclose it for a related secondary purpose that an individual would reasonably expect, with consent, where required or authorised by law, or where another exception under privacy law applies.

If information is not provided

Individuals may choose not to provide requested information. However, we may be unable to respond to an enquiry, assess an application, enrol or safely care for a child, administer funding or payments, meet legal obligations, provide access to a service, or enter into or manage an employment or supplier relationship. Where practicable, we will explain the consequence at the time the information is requested.

Disclosure of personal information

We may disclose personal information where reasonably necessary to:

  • Harmony group entities and personnel who require it for their responsibilities;
  • parents, guardians, authorised nominees, emergency contacts and health professionals involved in a child’s care;
  • Australian Government, State or Territory agencies, education and care regulators, child-protection bodies, law enforcement, emergency services and courts or tribunals;
  • Child Care Subsidy and other funding or program administrators;
  • banks, payment processors, credit-reporting bodies and debt-collection providers where applicable;
  • insurers, brokers, auditors, lawyers and other professional advisers;
  • IT, cloud, hosting, communications, records-management, learning, recruitment, payroll, screening, security, maintenance and other service providers;
  • a purchaser, investor, financier or adviser in connection with a proposed or completed business or corporate transaction, subject to appropriate confidentiality arrangements; and
  • any other person with consent or as required or authorised by law.

We take reasonable steps to require service providers to protect personal information and use it only for authorised purposes.

Overseas disclosures and storage

Some service providers may store or process personal information outside Australia or permit support personnel located overseas to access it. The countries involved may vary according to the provider and service in use.

Where APP 8 applies, we take reasonable steps in the circumstances to ensure that an overseas recipient does not breach the APPs, unless an exception applies. More specific information about likely overseas locations may be provided in a collection notice or on request where reasonably available.

Website cookies, analytics and digital advertising

Our Website may use cookies, pixels, tags, local storage and similar technologies. These technologies may be used to:

  • operate the Website and remember preferences;
  • maintain security and diagnose technical issues;
  • understand Website traffic, usage and performance;
  • measure enquiries, tours, applications and campaign effectiveness; and
  • where enabled and permitted, personalise or measure advertising across websites and platforms.

Information collected may include IP address, device and browser information, general location, referral source, pages visited, actions taken and identifiers assigned by us or a provider. Providers may combine information collected through our Website with information from other services in accordance with their own privacy policies.

You can manage non-essential cookies using any cookie controls available on the Website and may also adjust your browser or device settings. Blocking some cookies may affect Website functionality. You may also change advertising preferences through the settings offered by relevant platforms.

Direct marketing

We may use contact details to send information about Harmony services, events, centres or opportunities where the individual has consented or where otherwise permitted by law. Individuals may opt out at any time by using the unsubscribe function in the communication or contacting us. We will action an opt-out request within a reasonable period.

Government-related identifiers

We may collect government-related identifiers where required or authorised, including for Child Care Subsidy, taxation, employment, screening and regulatory purposes. We do not use or disclose government-related identifiers as our own identifier except where permitted by law.

Security and retention

We take reasonable steps to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure. Measures may include access controls, authentication, security monitoring, physical protections, confidentiality obligations, staff training, vendor controls, backup and recovery arrangements, and secure disposal practices.

No storage or transmission method is completely secure. If we become aware of a suspected privacy or security incident, we will assess and respond to it in accordance with our incident-response processes and legal obligations.

We retain personal information for as long as reasonably needed for the purposes described in this Policy and to meet legal, regulatory, funding, employment, insurance, dispute-management and record-keeping requirements. When information is no longer required and we are legally permitted to do so, we take reasonable steps to destroy it securely or de-identify it.

Data breaches

We maintain processes for responding to actual or suspected data breaches. This may include containing the incident, assessing the circumstances and likely harm, taking remedial action, preserving evidence and reviewing controls.

Where the Notifiable Data Breaches scheme applies and an eligible data breach has occurred, we will notify affected individuals and the Office of the Australian Information Commissioner as required by the Privacy Act.

Quality and correction

We take reasonable steps to ensure that personal information we use or disclose is accurate, up to date, complete and relevant. Individuals should tell us if their information changes or appears incorrect. We may need to verify identity and the requested correction before changing a record.

Access to personal information

An individual may request access to personal information we hold about them. A parent, guardian or other representative may request information for another person where authorised or otherwise permitted by law.

We may ask for proof of identity and authority. We will respond within a reasonable period and may provide access in an appropriate form. We may refuse or limit access where permitted by law, including where access would unreasonably affect another person’s privacy, reveal commercially sensitive evaluative information, prejudice an investigation or legal proceeding, or be otherwise unlawful. If access is refused, we will generally provide written reasons and available complaint avenues.

We do not ordinarily charge for making an access request. We may charge a reasonable amount for providing access where permitted and will advise of any proposed charge in advance.

Privacy complaints

A privacy concern or complaint should be sent to our Privacy Officer using the contact details below. Please describe the issue and provide relevant details and documents. We may ask for further information and proof of identity.

We will acknowledge and investigate the complaint and aim to provide a response within a reasonable period. If the complainant is not satisfied, they may contact the Office of the Australian Information Commissioner. Information about making a privacy complaint is available at oaic.gov.au.

Anonymity and pseudonymity

Where lawful and practicable, individuals may interact with us anonymously or using a pseudonym, for example when making a general enquiry. This option may not be available where identity is required by law or where it is impracticable for us to provide the relevant service without identifying the individual.

Third-party websites and services

Our Website and communications may link to third-party websites, portals or services. Harmony is not responsible for the privacy practices of independent third parties. Individuals should review the privacy information provided by those third parties before providing personal information.

Changes to this Policy

We may update this Policy when our information-handling practices, technologies or legal obligations change. The current version will be published on our Website and will take effect from the date shown at the beginning of the Policy.

Contact us

Privacy Officer

Contact Your Local Harmony Centre

Talk with our educators about how we can assist your child transition from home to Harmony each morning and book your tour today.

Book a Tour

Early education, beautifully composed .

Early education, beautifully composed .

Early education, beautifully composed .

Early education, beautifully composed .

Early education, beautifully composed .

Early education, beautifully composed .