Privacy Policy

Your Privacy

Ashton’s Place Ltd (ABN 91 629 813 261) is committed to protecting your privacy. This Privacy Policy explains how we collect, hold, use, disclose, store, retain and protect your personal information. In this Privacy Policy, “us”, “we” or “our” means Ashton’s Place Ltd and its related bodies corporate (as that term is defined in the Corporations Act 2001 (Cth)). It applies to your dealings with us, including your use of our website and any application or platform we operate that refers to this Privacy Policy.

In handling personal information we are bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles.[1] Because we provide supports and services to people with disability and to children, much of the information we handle is sensitive information, including health information, which is given a higher level of protection under that Act.[2]

Your Consent

Some of the information we handle is sensitive information, including but not limited to health, cultural, and disability information, which the Privacy Act protects more strictly. We collect sensitive information only where it is reasonably necessary for our functions and activities, and either:

  • you, or your guardian, nominee or authorised representative, have consented to the collection; or
  • the collection is otherwise permitted under the Privacy Act, for example where it is required or authorised by law, or where the information is necessary to provide a health service to you and is collected consistently with our professional confidentiality obligations.

We seek your consent to collect, use and disclose your personal information when you enrol or begin services with us, through our Consent to Collect, Use and Disclose Personal Information Form. Where you are a child, or have a guardian, nominee or authorised representative, that person may give or withdraw consent on your behalf. You may withdraw your consent at any time, although this may affect our ability to provide services to you.

What is Personal Information?

The Privacy Act 1988 (Cth) defines personal information as information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether or not the information or opinion is true, and whether or not it is recorded in a material form.[3] If information does not identify you, and you cannot reasonably be identified from it, it is generally not personal information and is not subject to this Privacy Policy.

What Information We Collect

The personal information we collect and hold about you may include your name, gender, contact details (address, telephone numbers and email address), date of birth, bank account and payment details, custody or parenting arrangements, and any images or recordings captured by surveillance cameras we operate at our premises.

Where you are, or are applying to become, a participant, the information we collect may also include your former name, NDIS number, date and place of birth, Medicare number, immunisation status, dietary requirements, languages spoken, treating practitioner details, medical conditions, and disability and support needs.

How We Collect Information

We generally collect personal information directly from you, through our standard forms, in writing, by email, by telephone or in person. We may also collect it from a guardian, nominee or authorised representative, and, with your consent or as authorised by law, from treating practitioners, support coordinators and other providers involved in your supports.

We may collect personal information when you contact us through our website or any social media channel we operate. We also collect cookies, which help us understand how our website is used; as a general rule you cannot be identified personally from our use of cookies. Where we operate surveillance cameras at our premises, images and recordings may be captured for the safety and security of participants, visitors and staff.

Purpose of Collection and Use of Personal Information

We collect, hold, use and disclose personal information for purposes connected with providing our supports and services, and advocating for the wellbeing, protection and development of the people we support. These purposes include:

  • providing, coordinating and reviewing NDIS supports, therapy and related services;
  • assessing needs, and planning, documenting and reviewing supports and participant progress;
  • processing payments and claiming from funders;
  • communicating with you about our services, activities and events;
  • conducting quality assurance, service evaluation and research, in a way that does not identify individuals wherever practicable;
  • monitoring the safety and security of participants, visitors and staff, including through any surveillance cameras we operate;
  • carrying out internal functions such as administration, training, accounting, audit and information technology;
  • complying with our legal obligations and reporting to funders and government agencies; and
  • any other purpose explained at the time of collection, or required or authorised by law.

Where we use de-identified information for research, service evaluation or quality assurance, you may contact us if you do not wish your de-identified data to be used in this way.

Direct Marketing

We may use your contact details to tell you about our services, activities and events, by mail, email, telephone, SMS or other electronic means, in accordance with the Spam Act 2003 (Cth) and the Privacy Act 1988 (Cth).[4] Every marketing communication will include a simple way to opt out, and we will stop sending them if you ask.

Disclosure of Information

We disclose personal information only for the purpose for which it was collected, for a related secondary purpose you would reasonably expect, or as required or authorised by law.[5] We may disclose personal information about you to:

  • government and regulatory bodies, including the National Disability Insurance Agency, the NDIS Quality and Safeguards Commission, Services Australia (Medicare) and the Australian Taxation Office;
  • your guardian, nominee, authorised representatives and advocates;
  • child protection or family support agencies where we reasonably believe a child is at risk of significant harm;
  • our funders;
  • the police, courts, tribunals and the NDIS Commission or other authorities, to comply with compulsory notices or our legal obligations;
  • financial institutions, for payment processing;
  • our contracted service providers, including our practice-management and information technology providers, invoicing, communications, auditors and legal advisers;
  • referees whose details are provided to us by job applicants; and
  • a purchaser of our assets and operations, where purchased as a going concern.

We do not otherwise disclose personal information to a third party without your consent, unless required or authorised by law.

Overseas Disclosure

We use a practice-management platform, Splose, to hold and manage participant and client records. Splose stores Australian users’ data in Australia. Some information may nonetheless be disclosed to, stored by, or accessed by service providers located overseas, including in the United States, the United Kingdom and the European Union, for example for payment processing and certain software services.[6] Where we disclose personal information overseas, we take steps that are reasonable in the circumstances to ensure the overseas recipient handles it consistently with the Australian Privacy Principles, and we remain accountable for that information.

Storage, Security and Data Breaches

We take steps that are reasonable in the circumstances, including technical and organisational measures, to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure.[7] Records are held in secure electronic systems, including Splose, and, where held in hard copy, in secure cabinets or rooms.

If we experience a data breach that is likely to result in serious harm, we will respond in accordance with the Notifiable Data Breaches scheme, including notifying affected individuals and the Office of the Australian Information Commissioner where required.[8]

Information Retention

We retain and dispose of personal information in accordance with our legal obligations, including the NDIS Practice Standards and applicable record-keeping laws.[9] As a general rule:

  • records collected while the individual was an adult are kept for at least seven years after the last occasion on which we provided a service to that individual;
  • records collected while the individual was a child are kept until the individual turns 25 years of age;
  • records relating to child safety may be kept for longer where required.

We destroy or de-identify personal information securely once it is no longer needed for any purpose permitted by law.[10]

Access and Correction

You may ask to access the personal information we hold about you, and to have it corrected if it is inaccurate, out of date, incomplete, irrelevant or misleading.[11] We ask that you make your request in writing to our Privacy Officer, using the contact details below. We may ask you to verify your identity before we act on a request, so that your information is properly protected. Where an individual is a child or has an authorised representative, that representative may make a request on their behalf.

In limited circumstances set out in the Privacy Act 1988 (Cth), we may decline access or correction, for example where doing so would pose a risk to the life, health or safety of a person, or would unreasonably affect the privacy of others. If we decline, we will tell you why and how you may complain.

Our Website

If you access our website, we may collect additional information such as your IP address or domain name for statistical purposes. Our website may contain links to other websites; we are not responsible for the privacy practices of linked websites. We will not publish information about participants, families or staff on our website or social media channels without the written consent of that person or their authorised representative.

Amendments to this Privacy Policy

We may update this Privacy Policy from time to time. The current version is available on our website, and we encourage you to review it periodically.

Complaints

If you believe we have breached the Australian Privacy Principles, or otherwise mishandled your personal information, please contact our Privacy Officer using the details below. We will acknowledge your complaint and take reasonable steps to investigate and respond to you. If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner.[12]

Contact us

Privacy Officer, Ashton’s Place Ltd.
Email: info@ashtonsplace.com.au.
Telephone: 07 5690 2735.

Related Policies, Forms & Procedures policies, forms and procedures

Related Policies

  • Dignity Policy;
  • Confidentiality Policy;
  • Information Management Policy;

[1] Privacy Act 1988 (Cth) sch 1 (Australian Privacy Principles).
[2] Privacy Act 1988 (Cth) s 6(1).
[3] Privacy Act 1988 (Cth) s 6(1).
[4] Privacy Act 1988 (Cth) sch 1 APP 7.
[5] Privacy Act 1988 (Cth) sch 1 APP 6.
[6] Privacy Act 1988 (Cth) sch 1 APP 1.4(f), (g); APP 8.
[7] Privacy Act 1988 (Cth) sch 1 APP 11.
[8] Privacy Act 1988 (Cth) pt IIIC.
[9] National Disability Insurance Scheme (Provider Registration and Practice Standards) Rules 2018 (Cth).
[10] Privacy Act 1988 (Cth) sch 1 APP 11.2.
[11] Privacy Act 1988 (Cth) sch 1 APPs 12, 13.
[12] Privacy Act 1988 (Cth) s 36.