The short version
We handle personal information carefully and respectfully. We only collect what we need to respond to enquiries, deliver and plan supports, keep people safe, meet our legal and NDIS obligations, and run our services.
- We use and share information only for those purposes, or where you agree, or where the law requires or allows it.
- We provide privacy and confidentiality information in the language, communication mode and terms most likely to be understood by the person receiving supports.
- You can ask to see or correct the information we hold about you. The steps are explained below.
- You can raise a privacy concern or complaint. It will be handled fairly, and raising it will not affect your support.
If you would like this information in another format or communication style, email sparkly@neurodivergentempowered.com or ask any team member.
Who holds your information
Your information is held by Neurodivergent Empowered (ABN 43 318 321 173, registered NDIS provider 4-K6GFD9R), which operates The Nest at Shop 3, 10 Leeding Terrace, Caloundra QLD 4551.
For any privacy question, request or concern, email sparkly@neurodivergentempowered.com and mark it "Privacy". You can also tell any team member, or book a call.
What this policy covers
This policy covers all of Neurodivergent Empowered's work, including:
- Interest Based Supports sessions at The Nest and in the community
- 1:1 supports, including therapy assistant supports
- counselling
- Specialist Behaviour Support
- psychosocial recovery coaching and support coordination
- carer and parent education sessions
- enquiries, referrals, bookings, feedback and complaints, our client portal, and this website.
It also applies to information about family members, representatives and other people involved in a participant's support.
What we collect
We only collect information that is reasonably necessary for our work. Depending on the service, this can include:
- contact and identity details: name, pronouns, date of birth, address, phone, email, and emergency contacts
- NDIS and funding information: NDIS number, plan details, how the plan is managed, plan manager or support coordinator details
- disability and health information: diagnoses, health, medication and safety information, communication and sensory preferences, and support needs
- support plans and reports: goals, assessments, behaviour support plans, risk assessments, and reports from other practitioners you share with us
- session records: session notes, attendance, progress and review information, and photos where you have consented
- consent records: what you have agreed to, and any limits or changes
- billing information: service agreements, invoices and payment records (card details are handled by our payment provider, not stored by us)
- communication records: emails, text messages, portal messages and phone notes
- feedback, complaints and incident records.
Much of this is sensitive information under privacy law. We only collect sensitive information with consent, or where the law requires or allows it.
If you do not provide information
You can choose not to give us some information. You can also contact us without giving your name, for example through the feedback form. If we do not have information we need, we may not be able to provide a service safely, contact you, or claim funding for it. We will tell you if that is the case.
How we collect it
- directly from you, through our forms, phone calls, emails, texts, the client portal and during sessions
- from your representatives, such as a parent, guardian, nominee or support person
- from referrers and other providers, such as support coordinators, recovery coaches, allied health practitioners, behaviour support practitioners or plan managers, where you have agreed or the law allows it
- from documents you give us, such as NDIS plans, assessments and reports
- from our own records of the supports we deliver.
How we hold and protect it
We keep records mainly in electronic systems, described under "Overseas" below. Our main record system is a secure database that our team accesses through our clinical record tool.
- Every team member has their own account and signs in with multi-factor authentication.
- Access is limited by role. Team members can only see what they need for their work, and specific records are blocked from team members who have a conflict of interest.
- Information is sent over encrypted connections.
- Access is removed when a team member leaves.
- If we use paper records, we keep them secure and dispose of them securely.
We keep records for at least as long as the law requires. NDIS provider records are generally kept for at least seven years. We do not delete clinical records. If a record is wrong, we correct it and keep a note of the change.
Why we use it
We use personal information to:
- respond to enquiries and referrals, and decide whether and how we can help
- plan, deliver and review supports, and write session notes and reports
- understand and manage risk and safety, including behaviour support safeguards
- communicate with you and the people you have authorised
- prepare service agreements, invoices and funding claims
- roster and supervise our team, and review the quality of our work
- manage feedback, complaints and incidents
- meet our legal, NDIS and audit obligations.
We use an automated drafting service to help prepare draft session notes and reports from what our team records. Notes and reports are reviewed by a team member before they are finalised. Short family session summaries may be sent to a family's client portal automatically once they have passed automated safety checks.
We do not sell personal information. We do not use it for marketing without your consent. We do not use photos, videos or stories about participants publicly without consent for that specific use.
Who receives it
We share only what is needed for the purpose. Depending on your supports, information may go to:
- our team members who deliver or supervise your supports
- people you have authorised, such as family members, representatives, support coordinators or other providers
- your plan manager, for invoices and payment
- the NDIA, for claims and plan reviews where relevant
- the NDIS Quality and Safeguards Commission and other regulators, for reportable incidents, complaints, audits and other legal requirements
- auditors, under controlled access and only for the evidence they need
- emergency services or others, where there is a serious risk to someone's life, health or safety, or where the law requires it
- service providers who run our systems, listed below. They handle information on our behalf to provide their service.
Overseas disclosure
Some of the services we use store or process information outside Australia. Information is likely to be held or processed in the following countries:
| Service | What it is used for | Where |
|---|---|---|
| Supabase | Our main records database, client portal and clinical record tool | Japan |
| Netlify | Hosting this website and our clinical record tool | United States |
| Twilio and SendGrid | Sending and receiving text messages, phone calls and email | United States |
| Google Workspace | Team email, calendars and online meetings | United States and other countries |
| Daily.co | Online video meetings | United States |
| Anthropic | The automated drafting service described above | United States |
| Stripe | Card and bank payments for self-managed and private invoices | United States |
| Xero and Hnry | Accounting and payment records | United States and New Zealand |
We choose established providers and use their security settings, but we cannot control how overseas laws apply to them. If you have questions about a particular service, contact us.
How to see or correct your information
- Ask us. Email sparkly@neurodivergentempowered.com, tell any team member, or ask through the client portal. A parent, guardian or authorised representative can ask on a participant's behalf.
- We check it is you. We confirm your identity, or your authority to act for someone, before releasing information.
- We respond within 30 days. We will give you access in the way you ask for where we reasonably can. There is no charge to make a request.
- If we limit access, we tell you why. Sometimes the law allows us to limit access, for example where it would affect someone else's privacy or create a serious safety risk. If so, we explain the reason in writing and tell you how to complain.
- Correction. If information is wrong, out of date or incomplete, we correct it and keep a note of the change. If we disagree with a correction, we tell you why, and you can ask us to attach your statement to the record.
How privacy complaints work
- Tell us. Email sparkly@neurodivergentempowered.com, use our Feedback & Complaints form, or tell any team member. You can have a trusted person or independent advocate help you.
- We acknowledge it within two business days, where you have given us contact details.
- A senior team member who was not involved considers it. We look at what happened, talk with you, and review our records and practices.
- We respond within 14 days with what we found, what we will do, and your review options. If it will take longer, we tell you why and keep you updated.
If you are not satisfied, you can contact the Office of the Australian Information Commissioner (OAIC): oaic.gov.au, phone 1300 363 992. The OAIC usually expects you to raise the complaint with us first.
You can also contact the NDIS Quality and Safeguards Commission at any time: 1800 035 544 (free call), or report an issue or make a complaint.
Raising a privacy concern will not affect your right to respectful support.
If something goes wrong
If information is lost, sent to the wrong person or accessed without authority, we act quickly to contain it and assess the risk of harm. If the breach is likely to cause serious harm, we notify the people affected and the OAIC, as the Notifiable Data Breaches scheme requires.
This website
This website does not use advertising or analytics tracking. Our website host keeps standard server logs. Information you enter into our forms goes to our records system so we can respond to you. Each form explains what it collects and why.
Changes to this policy
We review this policy when our systems, services or obligations change. The date at the top shows when it was last updated.