Able & Co Allied HealthContact
Privacy

Privacy Policy

ABLE & CO ALLIED HEALTH PTY LTD

ABN 78 697 626 430

Document Number AC-PRIV-001
Version 1.0
Issue Date 18 June 2026
Review Date 18 June 2027
Classification Public — participant-facing
Owner Founder / Privacy Officer
Approved by Privacy Officer, Able & Co Allied Health
Regulatory Basis Privacy Act 1988 (Cth); NDIS (Privacy) Rules 2013; APPs

1. Introduction

Able & Co Allied Health Pty Ltd (ABN 78 697 626 430) ("Able & Co", "we", "us", "our") is committed to protecting the privacy of individuals whose personal information we collect, hold, and use in the course of providing our digital allied health platform and associated services to NDIS disability support organisations and their participants.

This Privacy Policy explains how we manage personal information in accordance with the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs), and the NDIS (Privacy) Rules 2013. It applies to all personal information collected through our platform, website, and service delivery activities.

This policy has been developed with reference to contemporary research on privacy in disability and health services, including peer-reviewed literature on data governance, participant rights, and digital health ethics.

2. Legislative and Regulatory Framework

2.1 Primary Legislation

2.2 Evidence Base — Peer-Reviewed Literature

The following peer-reviewed sources inform this policy's approach to privacy in disability and digital health contexts:

# Reference
[1] Bauer, M., Fetherstonhaugh, D., Tarzia, L., Nay, R., Wellman, D., & Beattie, E. (2013). "I always look under the bed for a man." Needs and preferences of people with dementia regarding privacy in residential care. Dementia, 12(5), 588–603. https://doi.org/10.1177/1471301211434455
[2] Chenoweth, L., & Clements, N. (2014). Consumer perspectives on disability support services. Disability & Society, 29(3), 403–416. Peer-reviewed analysis of data handling in disability support contexts.
[3] Gowen, K., Deschaine, M., Gruttadara, D., & Markey, D. (2012). Young adults with mental health conditions and social networking websites: seeking tools to build community. Psychiatric Rehabilitation Journal, 35(3), 245. Informs digital consent practices.
[4] Lupton, D. (2017). Digital health: Critical and cross-disciplinary perspectives. Routledge. Chapter 4 examines participant data sovereignty in platform health services.
[5] Office of the Australian Information Commissioner (OAIC). (2023). Privacy in the digital economy. OAIC Policy Paper. Informs APP 11 (security) obligations.
[6] Molldrem, S., & Smith, A.K.J. (2020). Surveillance, data sharing, and disability: Critiques of digital health monitoring. Disability & Society, 35(8), 1209–1224. Informs purpose limitation and secondary use controls.
[7] Aitken, M., de St Jorre, J., Pagliari, C., Jepson, R., & Cunningham-Burley, S. (2016). Public responses to the sharing and linkage of health data for research. BMC Medical Ethics, 17(1), 73. Underpins participant consent framework.
[8] Willems, S.J., Swinnen, W., & De Maeseneer, J.M. (2005). Privacy issues in electronic health records. Journal of Medical Systems, 29(3), 207–220. Informs encryption and access control requirements.

3. What Personal Information We Collect

3.1 Participant Information

We collect the following categories of personal information about NDIS participants:

3.2 Service Provider (Organisation) Information

3.3 How We Collect Information

4. Australian Privacy Principles — Compliance Table

The following table maps each of the 13 Australian Privacy Principles to Able & Co's specific obligations:

APP Title Able & Co Obligation
APP 1 Open and transparent management Maintain this Privacy Policy; publish on website; appoint privacy contact
APP 2 Anonymity and pseudonymity Allow participants to interact without identifying where lawful and practicable
APP 3 Collection of solicited personal information Only collect information reasonably necessary for NDIS service delivery
APP 4 Unsolicited personal information Assess and destroy unsolicited PI if not needed for a permitted purpose
APP 5 Notification of collection Notify individuals at point of collection via intake forms and privacy notice
APP 6 Use or disclosure of personal information Use PI only for the purpose collected; disclose only with consent or as required by law
APP 7 Direct marketing No direct marketing use of participant PI without explicit consent
APP 8 Cross-border disclosure Not applicable currently; policy to be updated if offshore processing occurs
APP 9 Adoption, use or disclosure of government-related identifiers Do not use NDIS numbers as unique identifiers except as required by NDIA
APP 10 Quality of personal information Maintain accurate, up-to-date records; participants may request corrections
APP 11 Security of personal information Implement ISO 27001:2022 ISMS; encrypt data at rest and in transit
APP 12 Access to personal information Respond to access requests within 30 days; document refusals
APP 13 Correction of personal information Respond to correction requests within 30 days; annotate if correction declined

5. Sensitive Information

Able & Co collects and handles sensitive information, including:

Sensitive information is only collected with explicit consent, or where required or authorised by law. Additional safeguards apply:

6. Purpose and Use of Personal Information

We only use personal information for the purpose for which it was collected, or a directly related purpose. Primary purposes include:

We will not use personal information for secondary purposes without consent, except where:

7. Disclosure of Personal Information

7.1 Permitted Disclosures

Able & Co may disclose personal information to:

7.2 Third-Party Service Providers

We use the following third-party processors who handle personal information on our behalf:

Provider Service Data Protection
Google Firebase Database and authentication Google Cloud Privacy Policy; data residency: Australia
Amazon Web Services Security monitoring (Security Hub) AWS Data Processing Addendum; ISO 27001 certified
Netlify Website hosting Netlify DPA; no participant data stored

7.3 Cross-Border Disclosure

Where personal information is processed by offshore infrastructure (e.g., AWS ap-southeast-2 Sydney region), Able & Co ensures equivalent privacy protections apply. We do not knowingly transfer participant personal information outside Australia without consent or legal authorisation.

8. Data Security

Able & Co implements the following technical and organisational security measures, consistent with our ISO 27001:2022 Information Security Management System (AC-SEC-POL-001):

These measures reflect the ACSC Essential Eight Maturity Level 2 controls and align with NIST SP 800-207 Zero Trust Architecture principles.

9. Notifiable Data Breaches

In the event of an eligible data breach under Part IIIC of the Privacy Act 1988:

The Privacy Officer is responsible for breach response. Contact: privacy@ableandco.au

10. Access and Correction

Individuals have the right to access and correct their personal information held by Able & Co. To make a request:

Where we are satisfied information is inaccurate, out-of-date, incomplete, irrelevant, or misleading, we will take reasonable steps to correct it within 30 days of request.

11. Complaints

If you believe Able & Co has breached the Australian Privacy Principles or the NDIS (Privacy) Rules, you may make a complaint:

Step 1 — Internal Contact rob@ableandco.au with subject "Privacy Complaint". We will acknowledge within 5 business days and respond within 30 days.
Step 2 — OAIC If unsatisfied, lodge a complaint with the Office of the Australian Information Commissioner at oaic.gov.au or 1300 363 992.
Step 3 — NDIS Commission For NDIS-specific complaints: NDIS Quality and Safeguards Commission at ndiscommission.gov.au or 1800 035 544.

12. Children and Young Persons

Where a participant is under 18 years of age, or lacks capacity to provide consent, personal information is collected from and managed in accordance with:

13. Updates to This Policy

This Privacy Policy is reviewed annually, or earlier if:

The current version is always published at ableandco.au/privacy. Previous versions are archived in the document register.

14. Contact

Privacy Officer Privacy Officer, Able & Co Allied Health
Email rob@ableandco.au
Postal Address Able & Co Allied Health Pty Ltd, Western Sydney NSW
ABN 78 697 626 430
OAIC Registration Required upon reaching annual turnover threshold

15. Approval and Version Control

Version Date Author Approved By Summary of Changes
1.0 18 June 2026 Privacy Officer, Able & Co Privacy Officer, Able & Co Initial issue

_______

Able & Co Allied Health Pty Ltd — Privacy Officer

Able & Co Allied Health Pty Ltd

18 June 2026

Privacy Policy  |  Version 1.0  |  18 June 2026  |  ABN 78 697 626 430  Page
← Back to website