Introduction
Support Coordination Plus (SSTNBL PTY LTD) is committed to protecting the privacy and confidentiality of the personal and sensitive information we collect in providing Support Coordination services under the NDIS. This Policy explains our practices in relation to your data, and your rights under the Privacy Act 1988 (Cth) and NDIS requirements.
Scope
This Policy applies to all personal and sensitive information collected, held, used or disclosed by SSTNBL PTY LTD about:
- NDIS participants (and, where authorised, their nominees or guardians)
- Prospective participants and referrers
- Employees, contractors and volunteers who support our services
- Key Definitions
- Personal Information: Any information or opinion about an identified person or reasonably identifiable individual (e.g., name, contact details, NDIS number).
- Sensitive Information: A subset of personal information that is inherently sensitive, including health data, disability details, racial or ethnic origin, and criminal history.
- Use: To handle, process, analyze or otherwise operate on information for a permitted purpose.
- Disclosure: To share information with a third party outside SSTNBL PTY LTD.
Information We Collect
- From You
- Identity & Contact: Name, address, phone, email, date of birth, emergency contacts.
- NDIS Plan: Participant number, plan dates, funding categories and allocations, goals and budgets.
- Health & Support Needs: Disability type, medical history, risk assessments, allied health reports (where provided).
- Service Interactions: Case notes, session summaries, incident or complaint reports, consent forms.
- Automatically & Third Parties
- Website Analytics: Page visits, time on page, device IP address (non-identifying).
- Referrer Data: Information provided by referrers (e.g., Local Area Coordinators).
- Mandatory Checks: Worker Screening, Police and WWCC results (for staff only).
Purpose of Collection
We collect, hold and use your information to:
- Plan, coordinate and review your NDIS supports effectively.
- Communicate with you, your nominees, providers, the NDIA and other stakeholders.
- Meet our legal and regulatory obligations, including incident and complaints reporting to the NDIS Commission.
- Maintain staff compliance and training records.
- Conduct business administration, billing and auditing.
Sensitive Information
- We will only collect sensitive information with your consent or where required by law.
- Sensitive data is used strictly for service delivery, risk management and compliance purposes.
How We Collect Information
- Directly from you via intake forms, emails, phone calls or face-to-face meetings.
- With your consent from third parties (e.g., health professionals, allied providers).
- Automatically via our secure website (analytics cookies).
- Where legally authorised, from government agencies or the NDIS Commission.
Disclosure & Sharing
We will not disclose your information except:
- With Your Consent: e.g., to obtain allied health reports or liaise with other providers.
- Legal Requirements: e.g., mandatory incident reports to the NDIS Commission within required timeframes.
- Service Delivery Partners: e.g., when engaging contractors or auditors bound by confidentiality.
- Regulatory Bodies: e.g., in response to a lawful request by the NDIA, NDIS Commission, or other authorities.
Data Security & Storage
- Electronic: Encrypted storage, password-protected access, multi-factor authentication for critical systems.
- Physical: Locked cabinets for hard-copy files, secure office premises.
- Access Controls: Role-based permissions, audit logs of file access.
- Retention & Destruction: Information is retained only as required by law or business need, then securely destroyed or de-identified.
Your Rights
You have the right to:
- Access your personal information and request a copy.
- Request to Correct inaccuracies or incomplete data.
- Withdraw Consent to information sharing (subject to legal obligations).
- Object to direct marketing communications.
- Lodge a Privacy Complaint in accordance with our Complaints & Feedback Policy, or with the Office of the Australian Information Commissioner (OAIC).
Complaints & Queries
If you have any questions or concerns about our handling of your data, please contact us:
You may also escalate to:
Review & Changes
We will review this Policy at least annually or when privacy legislation or NDIS requirements change. The current version will always appear on our website.
Legislative and other References
- Privacy Act 1988 (Cth) & Australian Privacy Principles
- NDIS Act 2013 (Cth)
- NDIS Practice Standards & Quality Indicators
- NDIS Code of Conduct