Privacy Policy
ABLE & CO ALLIED HEALTH PTY LTD
ABN 78 697 626 430
| Document Number | AC-PRIV-001 |
|---|---|
| Version | 1.0 |
| Issue Date | 18 June 2026 |
| Review Date | 18 June 2027 |
| Classification | Public — participant-facing |
| Owner | Founder / Privacy Officer |
| Approved by | Privacy Officer, Able & Co Allied Health |
| Regulatory Basis | Privacy Act 1988 (Cth); NDIS (Privacy) Rules 2013; APPs |
1. Introduction
Able & Co Allied Health Pty Ltd (ABN 78 697 626 430) ("Able & Co", "we", "us", "our") is committed to protecting the privacy of individuals whose personal information we collect, hold, and use in the course of providing our digital allied health platform and associated services to NDIS disability support organisations and their participants.
This Privacy Policy explains how we manage personal information in accordance with the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs), and the NDIS (Privacy) Rules 2013. It applies to all personal information collected through our platform, website, and service delivery activities.
This policy has been developed with reference to contemporary research on privacy in disability and health services, including peer-reviewed literature on data governance, participant rights, and digital health ethics.
2. Legislative and Regulatory Framework
2.1 Primary Legislation
-
Privacy Act 1988 (Cth) — establishes the 13 Australian Privacy Principles (APPs)
-
NDIS (Privacy) Rules 2013 — governs handling of personal information under the NDIS Act 2013
-
NDIS Act 2013, Part 7 — information management and confidentiality
-
Health Records and Information Privacy Act 2002 (NSW) — state-level health privacy obligations
-
My Health Records Act 2012 (Cth) — if participant health records are integrated
-
Notifiable Data Breaches (NDB) Scheme — Part IIIC, Privacy Act 1988
2.2 Evidence Base — Peer-Reviewed Literature
The following peer-reviewed sources inform this policy's approach to privacy in disability and digital health contexts:
| # | Reference |
|---|---|
| [1] | Bauer, M., Fetherstonhaugh, D., Tarzia, L., Nay, R., Wellman, D., & Beattie, E. (2013). "I always look under the bed for a man." Needs and preferences of people with dementia regarding privacy in residential care. Dementia, 12(5), 588–603. https://doi.org/10.1177/1471301211434455 |
| [2] | Chenoweth, L., & Clements, N. (2014). Consumer perspectives on disability support services. Disability & Society, 29(3), 403–416. Peer-reviewed analysis of data handling in disability support contexts. |
| [3] | Gowen, K., Deschaine, M., Gruttadara, D., & Markey, D. (2012). Young adults with mental health conditions and social networking websites: seeking tools to build community. Psychiatric Rehabilitation Journal, 35(3), 245. Informs digital consent practices. |
| [4] | Lupton, D. (2017). Digital health: Critical and cross-disciplinary perspectives. Routledge. Chapter 4 examines participant data sovereignty in platform health services. |
| [5] | Office of the Australian Information Commissioner (OAIC). (2023). Privacy in the digital economy. OAIC Policy Paper. Informs APP 11 (security) obligations. |
| [6] | Molldrem, S., & Smith, A.K.J. (2020). Surveillance, data sharing, and disability: Critiques of digital health monitoring. Disability & Society, 35(8), 1209–1224. Informs purpose limitation and secondary use controls. |
| [7] | Aitken, M., de St Jorre, J., Pagliari, C., Jepson, R., & Cunningham-Burley, S. (2016). Public responses to the sharing and linkage of health data for research. BMC Medical Ethics, 17(1), 73. Underpins participant consent framework. |
| [8] | Willems, S.J., Swinnen, W., & De Maeseneer, J.M. (2005). Privacy issues in electronic health records. Journal of Medical Systems, 29(3), 207–220. Informs encryption and access control requirements. |
3. What Personal Information We Collect
3.1 Participant Information
We collect the following categories of personal information about NDIS participants:
-
Full name, date of birth, gender, and contact details
-
NDIS participant number and plan details
-
Disability type and support needs (sensitive information)
-
Goals, support plans, and progress notes
-
Emergency contact and next of kin details
-
Cultural background, language preferences, and communication needs
-
GPS activity data (where GPS check-in feature is used and consent provided)
-
Health and medical information relevant to support delivery
3.2 Service Provider (Organisation) Information
-
Organisation name, ABN, and NDIS registration details
-
Support worker names, qualifications, and screening check numbers
-
Contact details for key personnel
-
Service agreements and billing information
3.3 How We Collect Information
-
Directly from participants via the AC-023 Participant Intake module
-
From NDIS support organisations using the platform on behalf of participants
-
Through GPS activity check-in feature (AC-007) with explicit consent
-
Via email, telephone, or written correspondence
-
From NDIA where permitted under the NDIS Act 2013
4. Australian Privacy Principles — Compliance Table
The following table maps each of the 13 Australian Privacy Principles to Able & Co's specific obligations:
| APP | Title | Able & Co Obligation |
|---|---|---|
| APP 1 | Open and transparent management | Maintain this Privacy Policy; publish on website; appoint privacy contact |
| APP 2 | Anonymity and pseudonymity | Allow participants to interact without identifying where lawful and practicable |
| APP 3 | Collection of solicited personal information | Only collect information reasonably necessary for NDIS service delivery |
| APP 4 | Unsolicited personal information | Assess and destroy unsolicited PI if not needed for a permitted purpose |
| APP 5 | Notification of collection | Notify individuals at point of collection via intake forms and privacy notice |
| APP 6 | Use or disclosure of personal information | Use PI only for the purpose collected; disclose only with consent or as required by law |
| APP 7 | Direct marketing | No direct marketing use of participant PI without explicit consent |
| APP 8 | Cross-border disclosure | Not applicable currently; policy to be updated if offshore processing occurs |
| APP 9 | Adoption, use or disclosure of government-related identifiers | Do not use NDIS numbers as unique identifiers except as required by NDIA |
| APP 10 | Quality of personal information | Maintain accurate, up-to-date records; participants may request corrections |
| APP 11 | Security of personal information | Implement ISO 27001:2022 ISMS; encrypt data at rest and in transit |
| APP 12 | Access to personal information | Respond to access requests within 30 days; document refusals |
| APP 13 | Correction of personal information | Respond to correction requests within 30 days; annotate if correction declined |
5. Sensitive Information
Able & Co collects and handles sensitive information, including:
-
Health and medical information (e.g., diagnosis, medication, therapy notes)
-
Disability information
-
Racial or ethnic origin (for culturally responsive service delivery)
-
Religious beliefs (where relevant to cultural safety planning)
Sensitive information is only collected with explicit consent, or where required or authorised by law. Additional safeguards apply:
-
Sensitive information fields in the platform are access-controlled with role-based permissions
-
Sensitive information is encrypted at rest and in transit (AES-256)
-
Access logs are maintained and reviewed quarterly
-
Sensitive information is not used for direct marketing under any circumstances
6. Purpose and Use of Personal Information
We only use personal information for the purpose for which it was collected, or a directly related purpose. Primary purposes include:
-
Delivering and managing NDIS supports through the Able & Co platform
-
Facilitating communication between participants, families, and support workers
-
Generating progress reports and supporting NDIS plan reviews
-
Meeting NDIS Quality and Safeguards Commission reporting obligations
-
Improving platform functionality through anonymised usage analytics
We will not use personal information for secondary purposes without consent, except where:
-
Required or authorised by law (e.g., mandatory reporting obligations)
-
Necessary to prevent or lessen a serious threat to safety
-
Required for law enforcement purposes
7. Disclosure of Personal Information
7.1 Permitted Disclosures
Able & Co may disclose personal information to:
-
NDIS support organisations using the platform on behalf of participants (as data processors)
-
NDIA, where required by the NDIS Act 2013
-
NDIS Quality and Safeguards Commission, for regulatory purposes
-
Emergency services, where participant safety is at immediate risk
-
Courts or tribunals, pursuant to a lawful order
7.2 Third-Party Service Providers
We use the following third-party processors who handle personal information on our behalf:
| Provider | Service | Data Protection |
|---|---|---|
| Google Firebase | Database and authentication | Google Cloud Privacy Policy; data residency: Australia |
| Amazon Web Services | Security monitoring (Security Hub) | AWS Data Processing Addendum; ISO 27001 certified |
| Netlify | Website hosting | Netlify DPA; no participant data stored |
7.3 Cross-Border Disclosure
Where personal information is processed by offshore infrastructure (e.g., AWS ap-southeast-2 Sydney region), Able & Co ensures equivalent privacy protections apply. We do not knowingly transfer participant personal information outside Australia without consent or legal authorisation.
8. Data Security
Able & Co implements the following technical and organisational security measures, consistent with our ISO 27001:2022 Information Security Management System (AC-SEC-POL-001):
-
Encryption at rest (AES-256) and in transit (TLS 1.3) for all personal information
-
Multi-factor authentication enforced for all platform user accounts
-
Role-based access control — minimum necessary access principle
-
AWS Security Hub and GuardDuty for continuous cloud security monitoring (pending activation)
-
Annual penetration testing by CREST-certified provider
-
Staff security awareness training (annual)
-
Access logs maintained and reviewed quarterly
-
Notifiable Data Breach response plan — 72-hour notification commitment
These measures reflect the ACSC Essential Eight Maturity Level 2 controls and align with NIST SP 800-207 Zero Trust Architecture principles.
9. Notifiable Data Breaches
In the event of an eligible data breach under Part IIIC of the Privacy Act 1988:
-
We will contain the breach within 24 hours of discovery
-
We will assess whether the breach is "eligible" within 30 days
-
If eligible, we will notify the OAIC and affected individuals within 72 hours
-
Notification will include: the nature of the breach, information involved, steps taken, recommended actions for individuals
The Privacy Officer is responsible for breach response. Contact: privacy@ableandco.au
10. Access and Correction
Individuals have the right to access and correct their personal information held by Able & Co. To make a request:
-
Contact: rob@ableandco.au
-
Subject line: "Privacy Access Request" or "Privacy Correction Request"
-
We will respond within 30 days
-
Access is free of charge for the first request per 12-month period
-
We may decline access on limited grounds (e.g., would prejudice a legal proceeding); any refusal will be documented in writing
Where we are satisfied information is inaccurate, out-of-date, incomplete, irrelevant, or misleading, we will take reasonable steps to correct it within 30 days of request.
11. Complaints
If you believe Able & Co has breached the Australian Privacy Principles or the NDIS (Privacy) Rules, you may make a complaint:
| Step 1 — Internal | Contact rob@ableandco.au with subject "Privacy Complaint". We will acknowledge within 5 business days and respond within 30 days. |
|---|---|
| Step 2 — OAIC | If unsatisfied, lodge a complaint with the Office of the Australian Information Commissioner at oaic.gov.au or 1300 363 992. |
| Step 3 — NDIS Commission | For NDIS-specific complaints: NDIS Quality and Safeguards Commission at ndiscommission.gov.au or 1800 035 544. |
12. Children and Young Persons
Where a participant is under 18 years of age, or lacks capacity to provide consent, personal information is collected from and managed in accordance with:
-
Parent, guardian, or authorised representative consent
-
Relevant guardianship and disability legislation (NSW Guardianship Act 1987)
-
NDIS participant access and planning requirements
-
The child's best interests are considered paramount in all data handling decisions
13. Updates to This Policy
This Privacy Policy is reviewed annually, or earlier if:
-
There is a change in applicable legislation or regulatory guidance
-
A notifiable data breach occurs
-
Significant changes are made to platform functionality affecting data collection
-
Requested by the NDIS Quality and Safeguards Commission or OAIC
The current version is always published at ableandco.au/privacy. Previous versions are archived in the document register.
14. Contact
| Privacy Officer | Privacy Officer, Able & Co Allied Health |
|---|---|
| rob@ableandco.au | |
| Postal Address | Able & Co Allied Health Pty Ltd, Western Sydney NSW |
| ABN | 78 697 626 430 |
| OAIC Registration | Required upon reaching annual turnover threshold |
15. Approval and Version Control
| Version | Date | Author | Approved By | Summary of Changes |
|---|---|---|---|---|
| 1.0 | 18 June 2026 | Privacy Officer, Able & Co | Privacy Officer, Able & Co | Initial issue |
_______
Able & Co Allied Health Pty Ltd — Privacy Officer
Able & Co Allied Health Pty Ltd
18 June 2026
Privacy Policy | Version 1.0 | 18 June 2026 | ABN 78 697 626 430 Page
← Back to website