Privacy Policy – Australia and New Zealand
Effective Date: 7 September 2026
Introduction
Welcome to the Global Mentors Group, trading as CMi Merryck ANZ Pty Ltd ACN 112 648 192 (CMi Merryck ANZ) Privacy Notice. This Privacy Notice explains how CMi Merryck ANZ collects, holds, uses and discloses personal information in connection with its business of facilitating mentoring relationships, including through our programs, platforms and related services.
CMi Merryck ANZ is part of Global Mentors Group headquartered in the United Kingdom and is a subsidiary of Global Mentors Group Limited, registered in Jersey (GMG). The GMG website at https://globalmentorsgroup.com (Website) is hosted and controlled by, Global Mentors Group Services Limited (GMGS), an associated entity registered in the United Kingdom. The Website includes a page about the business operated by CMi Merryck ANZ in Australia, and personal information submitted and collected through the Website may be shared with CMi Merryck ANZ for the purposes described in this Privacy Notice.
The terms:
- “the Company,” “we,” “us,” “our,” and “ours” refer to CMi Merryck ANZ; and
- “you,” “your,” and “yours” refer to the user or viewer of the Website or user of our Services.
We respect your right to privacy. This privacy notice explains how we collect, share and use personal information about you, and how you can exercise your privacy rights.
As an Australian company, we handle personal information in accordance with the Privacy Act 1988 (Cth), including the Australian Privacy Principles (Act), and other applicable Australian State and Commonwealth laws. Where we handle personal information about individuals outside Australia, other privacy and data protection laws may also apply and we will comply with those laws to the extent they apply to us.
This Privacy Notice applies to personal information collected by CMi Merryck ANZ in the conduct of its business and about Australian users of the Services. It also applies to personal information submitted through the CMi Merryck ANZ page or related forms on the Website to the extent that the information is collected, used or disclosed by CMi Merryck ANZ or shared with CMi Merryck ANZ by GMGS or another member of the GMG for the Services.
This Privacy Notice explains the categories of personal data we may collect about you, it also explains the purpose of processing your data and how we keep it safe.
We know that there’s a lot of information here, but we want you to be informed about your rights, and how we use data to provide you with the best possible service.
If you have any questions or concerns about our use of your personal information or this privacy notice, then please contact us using the details set out in the ‘How to Contact Us’ section.
The Website is hosted, operated and controlled by GMGS, not by CMi Merryck ANZ. This Privacy Notice explains how CMi Merryck ANZ handles personal information that it collects or that is shared with it through the Website for CMi Merryck ANZ’s Services. GMGS, Global Mentors Group Limited and other members of the GMG may also handle personal information collected through the Website for their own purposes or for group-level purposes, in accordance with the privacy notice or cookie notice applicable to the Website. The Website may also contain links to other websites. CMi Merryck ANZ has no control over how personal information is collected, stored or used by unrelated third-party websites, and you should review the privacy notices of those websites before providing personal information to them.
Information we may collect and hold
Personal information
We have set out below a number of different reasons for which we may collect and process your personal information and data.
Personal information is collected, held, used and disclosed only where reasonably necessary for, or directly related to, our functions and activities. The personal information we may collect depends on how you use our Services, whether you are a mentor, mentee, organisational customer, referee, employee, contractor, supplier or other business contact, and the type of relationship we have with you. It may include:
- name, contact details and date of birth;
- employment, education, professional experience and career interests;
- mentoring goals, preferences, availability, areas of expertise and program participation details;
- information contained in profiles, applications, surveys, feedback forms, communications and mentoring records;
- identity verification information where required for a program or customer requirement;
- billing, payment and account administration information;
- technical information about your use of the Website, platforms and Services, including device, log, cookie and usage information; and
- information provided by referees, program sponsors, organisational customers or other third parties involved in a mentoring program.
Sensitive information
We do not collect sensitive information unless it is reasonably necessary for, or directly related to, our functions and activities and we have your consent, or another exception under the Act applies.
Sensitive information includes information about a person’s racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, sexual orientation, criminal record, health information and biometric information.
In a mentoring context, you may choose to provide sensitive information in a profile, application, preference setting, communication or feedback response. You do not need to provide sensitive information unless we specifically request it or it is necessary for the relevant mentoring program.
If we request or handle sensitive information, we will only use and disclose it for the purpose for which it was collected or otherwise in accordance with applicable law.
Third Party Personal Information
You might also need to provide us information about other persons (e.g. a referee). If so, you represent that, if at any time you supply us with their personal information, you are authorised to do so and you agree to inform that person who we are, that we will use and disclose their personal information as set out in this policy, and that they can gain access to their personal information.
You further acknowledge and agree we may send that person a notice we have collected and hold that person’s personal information.
What are our personal information handling practices?
How is personal information collected?
We collect personal information via:
- forms, applications, profiles, surveys and program records;
- the Website, online forms, portals, noticeboards, email enquiries and postings made available through the Website hosted and controlled by GMGS;
- information shared with us by GMGS or another member of the GMG from the Website where relevant to CMi Merryck ANZ’s Services;
- other electronic and paper correspondence;
- telephone;
- face to face meetings; and
- our social media channels and accounts.
Collection of personal information from you
Where possible, we will collect your personal information directly from you, your authorised representative or third parties you have authorised us to contact such as a referee or previous employer.
There may be instances where we receive your personal information from third parties such as:
- GMGS or another member of the GMG, where personal information is submitted through the Website and is relevant to CMi Merryck ANZ’s Services;
- contracted service providers, who have collected your information on our behalf; or
- member organisations, program sponsors, organisational customers or social media operators who you have authorised to share your personal information with other third parties such as us.
If we receive your personal information from another party we will contact you, if we have enough information to do so and it is reasonable in the circumstances. Some exceptions to advising you may arise where:
- you have provided consent or reasonably expect the collection to occur;
- the collection is required or authorised by or under law;
- the collection is for the purposes of an investigation or personnel issues; or
- the collection is for the purposes of litigation or legal advice.
Automated Decision Making
We do not currently make decisions about individuals based solely on automated processing that significantly affects an individual’s rights or interests.
What are the purposes for collecting, holding, using and disclosing personal information?
We collect, hold, use and disclose personal information to operate our business, provide and improve our Services, facilitate mentoring relationships and programs, manage our relationships with individuals and organisational customers, comply with legal obligations and for related secondary purposes permitted by law.
Examples of how we may use personal information include:
- registering, verifying and administering user accounts and mentoring program participation;
- matching mentors and mentees, including by reference to interests, goals, experience, availability, location, preferred communication methods and program requirements;
- facilitating introductions, communications, scheduling, feedback, program management and reporting;
- supporting organisational customers, program sponsors and administrators, including providing aggregated or program-level reporting where appropriate;
- responding to enquiries, requests, complaints and support issues;
- client and business relationship management;
- complying with legislative and regulatory requirements;
- performing administrative functions, including billing, accounting, risk management, record keeping, archiving, systems development, data analysis, security monitoring and staff training;
- conducting market, service quality, user experience or customer satisfaction research;
- developing, improving and personalising the Website, platforms, programs and Services; and
- providing you with information about our Services, programs, events or related offerings where this is permitted by law and you have not opted out.
If we request personal information and you choose not to or you cannot provide us with that information, we may be unable to provide you with the relevant Services you have requested or need.
Direct Marketing
From time to time we will use the personal information we collect from you to inform you of products and services that we consider may be of interest to you.
If you elect to follow or link-in with any official CMi Merryck ANZ or corporate group web pages, or opt to follow or link-in with any employee or representative of CMi Merryck ANZ or its corporate group on LinkedIn, Twitter, Facebook or other social media or networking platform, CMi Merryck ANZ or its corporate group may infer that you are open to receiving direct marketing through those mediums.
If you do not wish to receive direct marketing information you can tell us at any time by contacting us using the details set out in the ‘How to Contact Us’ section or using the unsubscribe function in the relevant electronic communication.
In addition to meeting privacy obligations we endeavour to comply with relevant anti-spam laws which may apply if we market directly to you.
Disclosure
We can, and usually will, disclose personal information where:
- you have consented to the disclosure;
- you would reasonably expect that your information will be disclosed; or
- the disclosure is authorised or required by or under law, including circumstances where we are under a contractual or lawful duty of care to disclose information.
We do not sell your personal information. We may disclose personal information where this is reasonably necessary for the purposes described in this Privacy Notice, where you have consented to the disclosure, where you would reasonably expect the disclosure and it is related to the purpose of collection, or where the disclosure is authorised or required by law.
Third Party Service Providers
We need to share your personal information and data with third parties to meet legal and regulatory obligations and provide our Services and fulfil our contractual promises to you. Whenever personal information or data is provided to these parties it remains our property and is only used for the specific purpose for which it is supplied, or a purpose related to that specific purpose as permitted under the Act or applicable law.
Examples of third parties to whom we may disclose personal information include:
- mentors, mentees and program participants, to the extent necessary to facilitate mentoring relationships and program participation;
- organisational customers, program sponsors and administrators, to the extent necessary to administer mentoring programs and provide reporting or support;
- IT, hosting, software, analytics, communications, identity verification, payment processing, support and security service providers;
- our professional advisers, insurers, auditors, agents, suppliers and contractors;
- regulatory bodies, government agencies, law enforcement bodies and courts;
- Global Mentors Group Limited, GMGS and other members of the GMG for group administration, governance, reporting, technology, security, service delivery, risk management, compliance, business support and other purposes described in this Privacy Notice;
- business partners or alliance organisations involved in delivering or promoting our Services, where permitted by law;
- any person to the extent necessary to carry out an instruction you give to us or to provide the Services you request; and
- your authorised representatives, referees or other third parties you ask us to contact.
Overseas Disclosure
We may disclose personal information to overseas recipients, including Global Mentors Group Limited, GMGS, other members of GMG and service providers or group entities that host, store or process data in the United Kingdom, Jersey, Ireland and other countries in Europe. These disclosures may occur because the Website is hosted and controlled by GMGS and for group administration, governance, reporting, technology, security, data hosting, service delivery, risk management, compliance, support and related business purposes.
Before disclosing personal information to an overseas recipient, we will take such steps as are reasonable in the circumstances to ensure that the recipient does not breach the Australian Privacy Principles in relation to that information, unless an exception under the Act applies. These steps may include due diligence, contractual privacy and security obligations, access controls, data transfer arrangements, monitoring and other safeguards. Where APP 8 applies, we may remain accountable under the Act for how an overseas recipient handles personal information we disclose to it.
If we materially change the countries to which personal information is likely to be disclosed, we will update this Privacy Notice. You may contact us for further information about overseas disclosures relevant to your personal information.
GDPR
Where the General Data Protection Regulation (EU) 2016/679 (EU GDPR) or the United Kingdom General Data Protection Regulation (UK GDPR) applies to our handling of personal data, this section applies in addition to the rest of this Privacy Notice. References in this section to the GDPR mean the EU GDPR and the UK GDPR, as applicable.
For GDPR purposes, CMi Merryck ANZ is generally the controller of personal data that it collects and uses for its own business purposes, including account administration, relationship management, marketing, service improvement, compliance and support. The Website is hosted and controlled by GMGS, which may be a separate controller for personal data collected through the Website for its own or group-level purposes. Global Mentors Group Limited and other members of the GMG may also act as separate controllers where they determine the purposes and means of processing for group-level purposes. In some mentoring programs, CMi Merryck ANZ may act as a processor for an organisational customer or program sponsor where it handles personal data on that customer’s documented instructions. Where CMi Merryck ANZ acts as a processor, the relevant customer’s privacy notice will usually provide further information about how that customer determines the purposes and means of processing.
Our lawful bases for processing personal data under the GDPR may include:
- the performance of a contract with you, or taking steps at your request before entering into a contract, including registering you for and providing mentoring-related Services;
- our legitimate interests, or those of our organisational customers, program sponsors or corporate group, including facilitating mentoring relationships, administering programs, improving Services, maintaining security, managing relationships, undertaking reporting, conducting analytics and operating our business, except where those interests are overridden by your interests or fundamental rights and freedoms;
- your consent, including where consent is required for direct marketing, optional profile information, cookies or similar technologies, or special category data;
- compliance with legal obligations to which we are subject; and
- establishing, exercising or defending legal claims.
Where we rely on legitimate interests, those interests include operating, administering and improving our mentoring services, supporting organisational mentoring programs, maintaining platform security, conducting business reporting and analytics, managing client and user relationships, and sharing information within our corporate group for governance, compliance, technology, security and business support purposes.
If we rely on consent, you may withdraw that consent at any time. Withdrawal of consent will not affect the lawfulness of processing based on consent before it was withdrawn.
Where the GDPR applies, you may have the right to request access to your personal data, correction of inaccurate personal data, erasure of personal data, restriction of processing, portability of personal data you have provided to us, and to object to processing based on legitimate interests or direct marketing. You may also have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal or similarly significant effects.
We will respond to GDPR rights requests within the time required by applicable law. We may ask you to verify your identity before responding and may refuse or limit a request where permitted by law, including where an exemption applies or the request is manifestly unfounded or excessive.
If we obtain personal data from a source other than you, we will provide privacy information within the time required by the GDPR, unless an exception applies. The categories of personal data and sources we may use are described elsewhere in this Privacy Notice, including information provided by organisational customers, program sponsors, referees, authorised representatives, service providers and other third parties involved in a mentoring program.
Personal data may be transferred between Australia, the United Kingdom, Ireland, countries in the European Economic Area and other countries where our corporate group, service providers or partners operate. Where required by the GDPR, we will ensure that appropriate safeguards are in place for international transfers, such as an adequacy decision, standard contractual clauses, the UK International Data Transfer Agreement or Addendum, or another lawful transfer mechanism.
European and UK privacy complaints
If the GDPR applies and you consider that we have not handled your personal data correctly, you may contact us using the details in the ‘How to Contact Us’ section. You also have the right to lodge a complaint with a competent supervisory authority in the EU Member State of your habitual residence, place of work or place of the alleged infringement, or with the UK Information Commissioner’s Office where the UK GDPR applies.
Where required by the GDPR, we will identify and publish details of any appointed data protection officer, EU representative or UK representative. If those details are not set out in this Privacy Notice, you may contact us using the details in the ‘How to Contact Us’ section.
You can contact the UK Information Commissioner’s Office through its website at ico.org.uk. If you are in the EU or EEA, details of EU supervisory authorities are available from the European Data Protection Board website.
Storage, data security and retention
Collected personal information is held securely in our electronic and paper recordkeeping systems and may be stored or processed by us, GMGS, Global Mentors Group Limited, other members of the GMG and our service providers in Australia, the United Kingdom, Jersey, Ireland and other countries in Europe. Personal information submitted through the Website may initially be stored or processed in systems controlled by GMGS before being shared with CMi Merryck ANZ where relevant to the Services.
We have controls in place to protect against interference with personal information by way of unauthorised access, misuse, loss, modification, or disclosure including in the following ways:
- access to information collected from individuals is limited to authorised persons with a need-to know;
- our internal network, electronic records management system, and databases are protected using firewall, intrusion detection and prevention, antivirus, user authentication complexity and other IT security technologies and protocols;
- web transactions are conducted in accordance with PCI DSS standards;
- our web services are vulnerability tested against intrusion;
- our premises are under 24-hour surveillance and access is via security passes only with all access (and attempted access) logged electronically;
- we regularly conduct system audits and staff training to ensure we adhere to our established protective and IT security compliance and best practices; and
- aftercare measures are taken to support the removal of access to personal information when no longer required.
We take reasonable steps to destroy or permanently de-identify personal information when it is no longer required for any purpose for which it may be used or disclosed, unless we are required or permitted by law to retain it.
The period for which we retain personal information depends on the nature of the information, the purpose for which it was collected, applicable legal, accounting and reporting requirements, and our legitimate business needs. Where it is not reasonable or practicable to destroy or permanently de-identify personal information in electronic form, we will take reasonable steps to prevent unauthorised or inadvertent access to it.
Remaining anonymous or using a pseudonym
You have the right to contact us anonymously or using a pseudonym unless there is a legal requirement that prevents this.
Where you wish to make an enquiry or give us feedback, you may have the option of not identifying yourself. For example, you may sign up for our news services using a pseudonymous email address.
You should be aware, however, that there may be instances where we cannot respond to you or properly investigate a complaint if you do not provide contact details or sufficient information.
Privacy Notice Updates
This policy may be updated from time to time including when the OAIC guidance material is revised or legislative amendments are made to the Act or other applicable laws.
Any updates will be posted on this Website at https://globalmentorsgroup.com/privacy-policy-australia-and-new-zealand and we encourage you to review our privacy notice from time to time when using our Services or visiting the Website.
Copy of this policy
If you wish to access this policy in hard copy it can be downloaded and printed from the Website or if you require an alternative format, please contact us.
We will provide the policy to you at no cost, together with hard copies or any documents referred to in this policy and maintained by us.
Access to and correction of personal information
How you may access and correct personal information we hold about you
You may request access to personal information we hold about you. We will provide you with access as requested, if it is reasonable and practicable to do so. There may be a moderate charge for us to provide access and there may be instances where we refuse your request such as:
- providing access would pose a serious and imminent threat to the life or health of any individual;
- providing access would have unreasonable impact on the privacy of other individuals;
- the request for access is frivolous or vexatious;
- the information sought relates to existing or anticipated legal proceedings between you and us and that information would not be accessible by the process of discovery in those proceedings;
- providing access would be unlawful;
- denying access is required or authorised by or under law; or
- providing access would be likely to prejudice an investigation of possible unlawful activity.
If we deny your request for access, we will, where permitted by law, provide you with reasons for that denial.
You may request corrections to any of your personal information that we hold to ensure the information is accurate, up to date, complete, relevant and not misleading.
Verifying Identity
We must be satisfied that you are seeking access to or correction of your own personal information. We may ask you to provide verification of your identity. This process is free of charge.
How to request access or correction
If you wish to access or correct personal information we hold about you please contact us. Details of how to contact us are in the ‘How to Contact Us’ section.
Complaints about privacy
If you wish to inquire or make a complaint about the way we have handled your personal information, you may contact us are in the ‘How to Contact Us’ section.
We are committed to quick and fair resolution of customer complaints and will ensure any privacy complaint is taken seriously. You will always be treated professionally and respectfully.
Complaints to the Office of the Australian Information Commissioner
If you are dissatisfied with the way we handle a privacy complaint, you may contact the Office of the Australian Information Commissioner (OAIC):
- Email: [email protected]
- Phone: 1300 363 992
- Write to: Office of the Australian Information Commissioner
GPO Box 5218
Sydney NSW 2001
You may also make a complaint directly to the Information Commissioner, however, the Commissioner may recommend you try to resolve the complaint with us first.
How to Contact Us
Privacy enquiries for CMi Merryck ANZ are managed by the GMG privacy team on behalf of Cmi Merryck ANZ.
Contact us if you want to:
- obtain access to your personal information held by us;
- request correction of your personal information held by us;
- make an enquiry or complaint about our compliance with the APPs; or
- ask any questions about our Privacy Notice.
Email: [email protected]
Phone: +44 (0)207 823 0516
Write to: Data Protection Officer
Global Mentors Group Services Limited
Standbrook House, Floor 2,
2–5 Old Bond Street London, W1S 4PD
What we will do
We will acknowledge your requests or enquiries within 5 business days.
Provided you have given us your contact details we will endeavour to provide you with a written response within 30 calendar days after receiving your request by:
- providing access to documents;
- advising you of our decision to refuse access to or correction of documents; or
- advising you of any difficulties we have encountered in actioning your request, in which case we will provide you with an expected timeframe for finalising your request.
Electronic Data Collection
This section explains in more detail how information may be collected through the Website and related electronic transactions and communications. The Website is the GMG website hosted and controlled by GMGS. CMi Merryck ANZ has a page on that Website, and information submitted through that page or related online forms may be collected through GMGS’ website systems and shared with CMi Merryck ANZ where relevant to CMi Merryck ANZ’s Services.
It is important that you understand that there are risks associated with use of the internet and you should take all appropriate steps to protect your personal information.
Browsing
When an individual uses the Website, GMG’s’ website hosting, analytics or technology providers may make a record of the visit and log information such as:
- the individual’s server address;
- the individual’s top-level domain name (for example .com, .gov, .org, .au, etc);
- the pages the individual accessed, and documents downloaded;
- the previous site the individual visited; and
- the type of browser being used.
CMi Merryck ANZ does not control the Website hosting environment. CMi Merryck ANZ will not use Website browsing information to identify users or their browsing activities except where the information is shared with CMi Merryck ANZ for a legitimate business purpose described in this Privacy Notice, or where required or permitted by law.
Cookies
The Website may use cookies and similar technologies to operate the Website, support security and functionality, remember user preferences, understand how the Website and Services are used, and improve the user experience. Because the Website is hosted and controlled by GMGS, cookies and similar technologies on the Website may be set by GMGS, another member of the GMG or their service providers.
Some cookies are necessary for the Website to function. Others may help us analyse usage or personalise content. Cookies do not usually identify you by themselves, but they may be associated with information we hold about you if you register for or use our Services.
You can manage cookies through your browser settings. If you disable or delete cookies, parts of the Website or Services may not function properly.
Managing cookies
You can manage, block or delete cookies through your browser settings. The main browser providers publish instructions for doing this, including Google Chrome, Mozilla Firefox, Apple Safari and Microsoft Edge.
Where optional cookies or similar technologies require consent, consent may be managed through the cookie settings made available on the Website by GMGS or through your browser settings.
Third parties that provide services to GMGS, another member of the GMG or to us, such as analytics, hosting, security or embedded content providers, may also use cookies or similar technologies. Their use of those technologies is governed by their own privacy and cookie notices and the website privacy or cookie notice made available by GMGS.
Web Bugs
If we use web bugs we will display a clearly visible icon on the page. The icon will include the name of the company collecting information and will be labelled as a tracking device.
The Web bug will be linked to a page disclosing what data is collected, how it is used, and which companies receive the data.
Web visitors will be able to opt out of data collection by Web bugs. Web bugs will not be used to collect sensitive information.
Emails
Our technology systems log emails received and sent and may include voting and read and receipt notifications to enable tracking.
When your email address is received by us because you send us a message, the email address will only be used or disclosed for the purpose for which you have provided it and it will not be added to a mailing list or used or disclosed for any other purpose without your consent other than as may be permitted or required by law.
Call and message logs
Our telephone technology (systems and mobile phones) logs telephone calls and messages received and sent and enables call number display.
When your call number is received by us because you phone us or send us a message, the number will only be used or disclosed for the purpose for which you have provided it and it will not be added to a phone list or used or disclosed for any other purpose without your consent other than as may be permitted or required by law.
Your pathway to exceptional leadership