Your privacy in plain English
- We only ask for information we need to support you.
- We keep it safe and private.
- We only share it with people in your care team, and we ask you first. The only exceptions are when the law says we must, or someone is in danger.
- We never sell your information.
- You can ask to see your information or fix it at any time. It is free.
- If you are unhappy, tell us. You can also complain to the privacy regulator.
01About this policy
Care Hub Australia Pty Ltd (ABN [to be confirmed]) ("Care Hub", "we", "us") is an NDIS provider based at 78 North Street, Hadfield VIC 3046, delivering support work, allied health and home modifications across metropolitan Melbourne and Greater Western Sydney.
This policy applies to information about NDIS participants, their families, carers, guardians and nominees, support coordinators, plan managers and health professionals who refer to us, job applicants and staff, and anyone who contacts us or uses our website.
02Laws we follow
- The Privacy Act 1988 (Cth) and the 13 Australian Privacy Principles (APPs)
- The Health Records Act 2001 (Vic) and its Health Privacy Principles
- The Health Records and Information Privacy Act 2002 (NSW) and its Health Privacy Principles
- The National Disability Insurance Scheme Act 2013 (Cth), the NDIS Code of Conduct and the NDIS Practice Standards
03What we collect
We only collect information that is reasonably necessary to provide, coordinate and improve our supports. Depending on who you are, this may include:
| Type | Examples |
|---|---|
| Personal details | Name, date of birth, address, phone, email, preferred language, emergency contacts, and details of guardians, nominees or representatives. |
| NDIS details | NDIS number, plan dates, plan goals, funded supports and how your plan is managed (NDIA-managed, plan-managed or self-managed). |
| Health and disability information | Disability, diagnoses, medical history, medications, allergies, therapy and assessment reports, behaviour support plans, risk assessments and progress notes. This is sensitive information and receives extra protection. |
| Cultural and personal preferences | Cultural background, religion, communication needs and routines, collected only so we can match the right workers and deliver respectful support. |
| Service and billing records | Service agreements, rosters, case notes, invoices and incident records. |
| Job applicants and staff | Resumes, qualifications, references, NDIS Worker Screening Check and Working with Children Check details. |
| Website enquiries | Information you enter into our contact, referral or call-back forms. |
We do not collect credit card or bank account numbers through our website.
04How we collect it
Wherever possible we collect information directly from you, in person, by phone, by email or through our website. With your consent, we may also receive information from your representative or family, your support coordinator or plan manager, the NDIA, and treating health professionals such as your GP, paediatrician or specialist.
You can make a general enquiry without giving your name. However, we cannot provide supports anonymously, because NDIS rules require us to identify the people we support.
05Why we use it
- To plan, deliver and coordinate your supports, and to match you with suitable workers and clinicians
- To write and review your support plan and monthly progress notes against your NDIS goals
- To claim payment from the NDIA or your plan manager, or to invoice you if you self-manage
- To keep you and our staff safe, including risk assessments and incident management
- To meet our legal and NDIS obligations, including audits, complaints and reportable incidents
- To improve the quality of our services
- To assess job applications and manage our workforce
We do not sell or rent personal information, and we do not use it for marketing unrelated to your supports without your consent.
06Who we share it with
We share information only for the purposes above, and only as much as is needed:
- The NDIA, to claim payment for NDIA-managed supports and where the NDIS requires it
- Your plan manager and support coordinator, for invoicing and coordinating your supports
- Other providers and health professionals in your care team, with your consent
- Your nominee, guardian or representative, where they are authorised to act for you
- The NDIS Quality and Safeguards Commission, for reportable incidents, complaints and audits
- Auditors, insurers and IT or software providers who handle information on our behalf under confidentiality obligations
- Police, emergency services or other authorities where there is a serious threat to someone's life, health or safety, or where the law requires or authorises it
Overseas disclosure
We do not intentionally send personal information overseas. Some of our software providers may store data on servers outside Australia; where this happens we take reasonable steps under APP 8 to make sure the information is protected to Australian standards.
07Consent
We explain how we will use and share your information when you start with us, and record your consent in your service agreement. You can change or withdraw your consent at any time by telling your coordinator. If you withdraw consent, we will explain whether that affects the supports we can provide.
Support coordinators and health professionals who refer someone to us must have that person's (or their representative's) consent before sharing their details.
08Storage, security & retention
We store information in secure, access-controlled systems. Staff can see only what they need for their role, accounts are protected with strong passwords and multi-factor authentication, and paper records are kept locked and minimised. Every staff member signs a confidentiality agreement and completes privacy training.
We keep health records for at least 7 years after the last service we provide. For people who were under 18 when the information was collected, we keep it until they turn 25, whichever is later, as required by Victorian and NSW health records laws. After that, we securely destroy or de-identify it.
09Accessing & correcting your information
You can ask to see the information we hold about you, or ask us to correct anything that is wrong, out of date or incomplete. Contact our Privacy Officer using the details below. We will respond within 30 days. There is no charge to make a request.
In limited cases the law allows us to refuse access, for example if it would pose a serious threat to someone's safety. If we refuse, we will tell you why in writing and how to complain.
10Data breaches
If personal information is lost or accessed without authorisation, we act quickly to contain it and assess the risk. Where a breach is likely to cause serious harm, we will notify you and the Office of the Australian Information Commissioner under the Notifiable Data Breaches scheme.
11Our website
Information you submit through our forms is used only to respond to your enquiry or referral. Our website may use cookies and analytics tools that collect anonymous information such as pages visited and device type, to help us improve the site. You can block cookies in your browser settings; the site will still work.
Accessibility settings you choose on our website (such as text size or Easy Read) are stored only in your own browser.
12Complaints
If you are unhappy with how we have handled your information, please contact our Privacy Officer first. We will acknowledge your complaint within 2 business days and aim to resolve it within 30 days. Making a complaint will never affect the supports you receive.
If you are not satisfied with our response, you can contact:
13Contact us
Need an interpreter? Call us and we will arrange one through TIS National at no cost. This policy is available in Easy Read and other formats on request.
We may update this policy from time to time. The latest version will always be on this page.