AMAPPAMAPP

Privacy policy

How AMAPP handles your information.

This policy explains what personal information AMAPP collects, why, who sees it, and what you can ask us to do with it. It is written in plain language on purpose. If anything is unclear, email info@amapp.org.au and a person will answer.

Last updated 11 September 2026. Applies to amapp.org.au and to the ways you deal with AMAPP described below.

The short version

Six things worth knowing.

  • The website itself collects almost nothing. It has no analytics, no advertising pixels and no tracking cookies.
  • The application forms on this site do not send anything to a server. They package your answers and documents into a file on your own device, and you email it to us yourself.
  • We only ask for what we need to run a professional association: to assess applications, keep a register of members and accredited practitioners, run events, and stay in touch.
  • We never sell personal information, and we do not share it with anyone for marketing.
  • Practitioners listed in the public directory choose what appears there, and can change or remove it at any time.
  • You can ask to see, correct or delete what we hold about you, and you can complain if you think we have got something wrong.

Who we are

AMAPP Limited.

The Australian Multidisciplinary Association for Psychedelic Practitioners is a registered charity, ACN 666 322 256, ABN 61 666 322 256. It is run by volunteers. AMAPP handles personal information in line with the Australian Privacy Principles in the Privacy Act 1988 (Cth). Where this policy and the law differ, the law applies.

Personal information means anything that identifies you or could reasonably be used to identify you: your name, contact details, professional registration numbers, the documents you send us, and so on.

What we collect

It depends on how you deal with us.

Most people only ever do one or two of these. Each card describes one way of dealing with AMAPP, what we collect when you do, and where it goes.

Visiting the website

Our hosting provider, Cloudflare, records the technical details of each request (your IP address, browser type, the page requested and the time) in its logs, as every web host does. We do not run analytics or advertising on this site and we do not build profiles of visitors.

The site sets one cookie of its own, called transitionCount, which only counts page transitions so the page animations behave. It identifies nobody and expires with your session.

Applying for membership

Your name, email, phone number, professional category, two referees and their contact details, your declarations, and any supporting documents you attach, such as a CV, qualification or, for the concession rate, proof of study or a concession card.

The application page does not upload anything. When you press Package, your browser builds a zip file on your device and shows you an email addressed to credentialing@amapp.org.au. Nothing reaches AMAPP until you send that email yourself. Once it arrives, it is stored in AMAPP's Google Workspace: the credentialing mailbox, a folder in Google Drive, and a row in the member register.

Applying for accreditation

Everything above, plus your qualifications and training history, the training and experience criteria you confirm, your professional registration body and number, an endorsement referee, and documents such as a training certificate, a reflective statement, and a professional development log. It travels and is stored the same way as a membership application.

Paying the application fee or subscription

The $50 application fee and the annual subscription are paid through Mighty Networks, which runs card payments through Stripe. AMAPP never sees or stores your card number. Mighty Networks and Stripe have their own privacy policies, which apply to the payment itself.

Being listed in the practitioner directory

The directory is public. If you are an accredited practitioner and you ask to be listed, we publish what you give us for that purpose: your name, professional title, practice location, a photograph, a biography, the languages you work in, your registration body and number, your accreditation status, and a website or booking link if you supply one.

You choose what goes in. You can update it or have the listing removed at any time by emailing credentialing@amapp.org.au. The public register at /database exists so that people can verify that a practitioner holds a current AMAPP credential.

Registering for an event

Event tickets are sold through Humanitix, which collects your name, email and payment details under its own privacy policy. AMAPP receives the registration list so we can send the joining details, run the session, and issue continuing professional development certificates where they apply.

Webinars are delivered over Zoom and are recorded. The recording may include the name, voice, image, comments and questions of anyone who takes part with their camera or microphone on, or who writes in the chat. Recordings are shared with members and may be published on AMAPP's YouTube channel. The ticket page for every recorded event says so, and explains how to attend without appearing in the recording. Supervision sessions are not recorded.

Joining the member community

Members join a private community hosted on Mighty Networks. What you post there is visible to other members. Mighty Networks holds your account under its own privacy policy.

Newsletters and email

Members and past attendees receive AMAPP's newsletter and event notices by email. We send these ourselves from AMAPP's Google Workspace, with recipients in blind copy so that nobody else sees your address. Every email tells you how to stop receiving them: reply and ask, and we take you off the list.

Submitting research or an enquiry

If you list a study on the research register, the study details and a contact name are published. If you write to us, request a speaker, or offer to volunteer, we keep your message and our reply so we can follow it up.

The TGA campaign page uses an embedded Google Form. Google sets its own cookies inside that form, and what you submit is held in AMAPP's Google account. The form explains how your submission may be used before you send it.

Sensitive information

Some of what we ask for is sensitive, and we treat it that way.

Both application forms ask whether you have ever been the subject of a formal complaint, regulatory finding, professional misconduct determination or criminal conviction relevant to professional practice. The accreditation form also invites, but does not require, practitioners who identify as Aboriginal or Torres Strait Islander to describe their connection to community and cultural healing practice. Proof of concession may reveal that you hold a government benefit.

We collect this only with your consent, only for assessing your application, and only the people assessing that application see it. A disclosure is discussed with you directly before any decision is made, and a prior finding does not by itself disqualify anyone. Sensitive information is never published, never shared with referees, and never used for any other purpose.

How we use it

Only for the reasons we collected it.

  • To assess applications for membership and accreditation, including contacting the referees you nominate.
  • To maintain the register of members and accredited practitioners, and the public directory for those who opt in.
  • To run events, send joining details, and issue certificates.
  • To send the newsletter and notices about AMAPP's activities to people who have joined or attended.
  • To answer your questions and follow up anything you have asked us to do.
  • To meet our obligations as a registered charity, such as keeping financial and governance records.

When we check an application, we may use an AI assistant to read the application and prepare a checklist and a draft reply for a person to review. The tool is provided by a company based in the United States under terms that prohibit it from using our data to train its models. A person always reads the application and makes the decision, and anything sensitive gets a human read first.

Who else sees it

The services we rely on, and nobody else.

AMAPP does not sell personal information or pass it to anyone for marketing. It is shared only with the services that store or process it for us, with the people you ask us to contact, and, if the law ever requires it, with a regulator or court.

ServiceWhat it does for AMAPPWhere it holds data
Google WorkspaceEmail, Drive folders for applications, and the member registerGoogle data centres, including outside Australia
CloudflareHosts this website and keeps request logsGlobal network, including outside Australia
Mighty Networks and StripeMember community, subscriptions and card paymentsUnited States
HumanitixEvent ticketing and registration listsAustralia
ZoomDelivers webinars and supervision sessions and records webinarsUnited States
YouTubePublishes webinar recordingsUnited States
Google FormsCollects submissions on the TGA campaign page onlyGoogle data centres
AI assistantHelps a person check applications and draft repliesUnited States

Because several of these providers are outside Australia, some of your information is held overseas. Each one is a large provider bound by its own published privacy commitments, and we use them under their standard terms. We do not otherwise send personal information overseas.

Referees you nominate are contacted and told that you have named them. They are not shown your application.

How long we keep it

As long as it is doing a job, then it goes.

  • Successful applications and member records are kept for as long as you are a member or hold a credential, and for seven years afterwards, which is how long a registered charity must keep its financial and governance records.
  • Unsuccessful or withdrawn applications are deleted twelve months after the decision.
  • Directory listings stay up until you ask for removal or your credential ends.
  • Event registration lists are kept for seven years alongside the certificate records they support.
  • Webinar recordings are educational material and are kept while they remain useful to members.
  • Enquiries are kept for two years after the last message.

When information is no longer needed, we delete it from our systems. Copies held by the services above are deleted under their own retention rules.

Security

How we look after it.

Applications and records live in AMAPP's Google Workspace, protected by two-factor authentication, and only the people who need them for the credentialing role can open them. The website is served over HTTPS. The application forms were designed so that your documents never sit on a web server at all. No system is perfectly secure, and if we ever became aware of a breach that was likely to cause you harm, we would tell you and, where required, the Office of the Australian Information Commissioner.

Your rights

What you can ask us to do.

  • See what we hold. Ask, and we will send you a copy of the personal information we have about you, normally within 30 days.
  • Correct it. If something is wrong or out of date, tell us and we will fix it.
  • Change or remove your directory listing. Email credentialing@amapp.org.au. Removal is usually done within a few days.
  • Stop emails. Reply to any AMAPP email and ask.
  • Withdraw consent. You can withdraw an application, or ask us to delete what you sent, at any time before a decision.
  • Complain. If you think we have mishandled your information, write to info@amapp.org.au with "Privacy" in the subject line. We will acknowledge it within a week and reply properly within 30 days. If you are not satisfied with our answer, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au.

Other things

Children, links, and changes.

Children. AMAPP's services are for practitioners, researchers and adults working in or interested in the field. The website is not directed at people under 18 and we do not knowingly collect information from them.

Other websites. This site links to other organisations, and to the services above. Their privacy practices are their own, and this policy does not cover them.

Changes. When we change this policy we update the date at the top. If a change matters to how we use information you have already given us, we will tell members by email.

Contact

Questions about this policy or about your information: info@amapp.org.au. For anything to do with an application or a directory listing: credentialing@amapp.org.au. Both inboxes are read by a person.