Privacy Policy
In plain words. We collect the personal and health information we need to support you safely and to meet our NDIS obligations. We only share it with the people involved in your care, the NDIS bodies we must report to, and the systems we use to run the service. Some of those systems are overseas, and we tell you which ones. You can see your information, ask us to fix it, and complain if you think we have got something wrong. Our phone line is answered by an AI receptionist called Paige and calls are recorded; you can ask for an unrecorded call-back instead. If you want this policy explained in a different way, in Easy Read, or in your language, ask us and we will arrange it.
1. Who we are and what this policy covers
This Privacy Policy explains how Complex Care Continuum (we, us, our), collects, holds, uses, discloses and protects personal information. We are a registered NDIS provider delivering complex care, high-intensity supports, community nursing, supported independent living, respite and hospital-discharge support to people across the Perth metropolitan area and the Peel region of Western Australia.
This policy applies to everyone whose personal information we handle, including NDIS participants, their families, carers, nominees and guardians; people who enquire about our services; hospital, health and coordination professionals who refer to us; our workers and job applicants; and visitors to our website. It applies however the information reaches us: in person, by phone, by email, through our website, or through another organisation.
Because we provide health services and hold health information, we are bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) regardless of our size. The small business exemption in that Act does not apply to us.
2. The laws and standards we work under
We handle personal information in accordance with the following. Where they overlap, we apply whichever gives you the greater protection.
- The Privacy Act 1988 (Cth), including the thirteen Australian Privacy Principles and the Notifiable Data Breaches scheme, as amended by the Privacy and Other Legislation Amendment Act 2024 (Cth).
- The National Disability Insurance Scheme Act 2013 (Cth) and the rules made under it, including the NDIS (Provider Registration and Practice Standards) Rules 2018, the NDIS Practice Standards and Quality Indicators (in particular the Privacy and Dignity and Independence and Informed Choice standards), the NDIS Code of Conduct, and the requirements of the NDIS Quality and Safeguards Commission on incident management, complaints, behaviour support and worker screening.
- The Surveillance Devices Act 1998 (WA), which governs the recording of private conversations, including telephone calls.
- The Privacy and Responsible Information Sharing Act 2024 (WA), to the extent we handle personal information on behalf of a Western Australian public entity under a contract that applies that Act to us.
- The Spam Act 2003 (Cth) and the Do Not Call Register Act 2006 (Cth) for any electronic or telephone marketing.
- Our own policies and procedures on privacy, records, incident management and safeguarding, which are available on request.
3. The kinds of personal information we collect
We collect only what we reasonably need for the purposes described in section 5. Depending on your relationship with us, this may include:
- Identity and contact details — name, date of birth, address, phone numbers, email, preferred language and communication needs, emergency contacts.
- NDIS information — NDIS number, plan details and dates, funded supports and budgets, plan manager and support coordinator details, service agreements, and the details of nominees or guardians.
- Health and disability information (sensitive information) — diagnoses, medications, allergies, clinical histories, hospital discharge summaries, care and nursing plans, mealtime and swallowing plans, behaviour support plans, restrictive practice authorisations, risk assessments, progress notes, incident records and information from treating practitioners.
- Other sensitive information where it is relevant to your support and you have consented — for example cultural background, religious observance or Aboriginal or Torres Strait Islander status where it affects how you want to be supported.
- Information about family, carers and other supporters — names, roles, contact details and the decisions they are authorised to make.
- Financial information — invoicing and claiming details, bank account details where we reimburse you or pay you, and payment records.
- Images and recordings — photographs or video only with your express consent and for a stated purpose; recordings and transcripts of telephone calls (see section 8); and website chat transcripts.
- Worker and applicant information — qualifications, NDIS Worker Screening Check results, references, right-to-work evidence, training records, rosters and payroll information.
- Website and technical information — see section 9.
4. How we collect personal information
Wherever practicable we collect personal information directly from you, or from the person you have authorised to speak for you. We also collect information from:
- hospitals, discharge planners, social workers and treating practitioners, when you are being referred to us or we are planning your transition home;
- the National Disability Insurance Agency, plan managers and support coordinators;
- your family, carers, nominees or guardians, where they are authorised to act for you or in an emergency;
- other providers involved in your support, with your consent;
- our telephone receptionist service, website forms and website chat; and
- publicly available sources, where it is reasonable to do so.
We collect sensitive information, including health information, only with your consent, or where the collection is required or authorised by law, or where a permitted health situation under the Privacy Act applies (for example, to lessen or prevent a serious threat to life, health or safety). We explain what we are collecting and why using the language, format and mode of communication you are most likely to understand, and we will arrange an interpreter, Easy Read material or an advocate on request.
If you provide us with personal information about another person, you must be authorised to do so and should make them aware of this policy.
5. Why we collect, hold, use and disclose personal information
The primary purpose is to assess, plan, deliver, coordinate and review your supports safely and in line with your NDIS plan. Related purposes for which you would reasonably expect us to use your information include:
- rostering and briefing the workers who support you, so that they know your needs before they arrive;
- clinical oversight by our nurses, including medication, wound, continence, mealtime and high-intensity supports;
- responding to emergencies and communicating with hospitals, ambulance and treating practitioners;
- claiming payment from the NDIA, plan managers or self-managed participants, and keeping the financial records the NDIS requires;
- meeting our obligations to the NDIS Quality and Safeguards Commission, including reportable incident notifications, behaviour support and restrictive practice reporting, complaints management and audits;
- quality assurance, internal audit, training and continuous improvement, using de-identified information wherever possible;
- managing our workforce, including screening, supervision and workplace safety;
- handling enquiries, feedback and complaints, and defending or exercising our legal rights; and
- complying with the law, including mandatory reporting obligations and lawful requests from regulators, courts and law enforcement.
We do not use or disclose your information for any other purpose unless you consent, you would reasonably expect it, or the law requires or permits it.
6. Who we share personal information with
We share personal information only with those who need it for the purposes above, and only the information they need. Recipients may include:
- Your care team and supporters — the workers and nurses rostered to you; your GP, specialists, allied health professionals, hospitals and pharmacies; your support coordinator and plan manager; and your family, carers, nominees or guardians, in line with the decisions you have made about who may know what.
- NDIS bodies — the National Disability Insurance Agency and the NDIS Quality and Safeguards Commission, as required by the NDIS Act and rules.
- Other government bodies — where required by law, including WA Health entities where we provide services under contract, the Department of Communities, guardianship and administration bodies, police and courts.
- Our service providers — the organisations that provide our telephone reception, telephony, email, document storage, rostering, accounting, website hosting and IT support. They are permitted to handle your information only for our purposes and under confidentiality obligations. The main ones are listed in section 7.
- Professional advisers and insurers — our lawyers, accountants, auditors and insurers, where necessary.
- A purchaser or successor of our business, in which case we will tell you and this policy will continue to apply until you are told otherwise.
We do not sell personal information, and we do not share it with third parties for their own marketing.
7. Overseas disclosure and the systems we use
Most of your information is stored in Australia. Some of the systems that run our service are operated by companies based overseas, and information may be transferred to, or accessed from, the countries where those companies operate. Under APP 8 we take reasonable steps to ensure those recipients handle your information in a way that is consistent with the APPs, including through contractual terms and by limiting what they receive. The systems that matter for privacy are:
- Telephone reception (Retell AI, United States). Our phone line is answered by an AI receptionist, Paige. Call audio, transcripts and the summary of each call are processed and stored on Retell’s infrastructure in the United States. See section 8.
- Telephony (Twilio, United States). Calls to and from our business number are routed through Twilio, which may process call metadata in the United States.
- Microsoft 365 (Microsoft). Email, documents, enquiry records and our participant files are held in Microsoft 365. We keep our tenancy in Australian data regions where the service allows.
- Website hosting and content delivery (Hostinger) and the fonts and location service described in section 9, which may process technical information outside Australia.
By providing your information to us, including by calling our phone line after being told the call is recorded, you consent to these disclosures. If you would prefer that your information not be handled by an overseas system, tell us and we will discuss what is possible; in most cases we can take your details on an unrecorded line and record them directly in our Australian systems.
8. Telephone calls, our AI receptionist, and automated systems
Recording. Calls to (08) 9515 8000 are recorded. Under the Surveillance Devices Act 1998 (WA), a private conversation may only be recorded with the consent of all principal parties, so Paige tells every caller at the start of the call that it is being recorded. By continuing with the call you consent to the recording. If you do not want to be recorded, tell Paige or ask for a team member to call you back on a line that is not recorded, or contact us by email. Recordings and transcripts are used to make sure your enquiry is handled accurately, to brief the team member who calls you back, for staff training and quality review, and to investigate any complaint or incident. They are kept for 12 months and then deleted, unless they are needed for a complaint, incident or legal matter, in which case they are kept until that matter is closed.
What Paige does. Paige collects your name, contact details and the reason for your call, answers general questions about our services using information from this website, and either transfers you to a team member or arranges a call-back. Paige is instructed not to guess, not to give clinical advice, and not to confirm or deny whether any person is a participant. Every enquiry is reviewed by a person; Paige does not decide whether we can support you, what supports you receive, or anything else that could significantly affect your rights or interests. Those decisions are made by our team.
Automated decision-making. We do not use computer programs to make decisions that could reasonably be expected to significantly affect your rights or interests. If that changes, we will update this policy to describe the kinds of decisions involved and the information used, as the Privacy Act requires.
Website chat. The chat window on our website is also operated by Paige. Chat transcripts are handled in the same way as call transcripts.
9. Our website
- Enquiry forms and chat. Information you enter is sent to us by email and recorded in our enquiry list so that we can respond.
- Approximate location. To show the nearest service area on our homepage, our website sends your device’s network (IP) address to a location service (geojs.io) which returns an approximate city or suburb. No precise device location is requested and nothing is stored beyond your visit.
- Cookies and analytics. Our website uses functional cookies needed for it to work and may use analytics cookies to understand how the site is used. You can control cookies through your browser settings.
- Fonts and content delivery. Fonts are loaded from Google Fonts and the site is delivered through a content delivery network, each of which receives standard technical information such as your IP address and browser type.
- Links. Our site links to other websites, including the NDIS and the NDIS Commission. We are not responsible for their privacy practices.
10. How we keep information secure
We take reasonable steps to protect personal information from misuse, interference, loss, unauthorised access, modification and disclosure. Those steps include role-based access so that workers see only the information they need for the people they support; multi-factor authentication on our systems; encryption of information in transit; secure disposal of paper records; NDIS Worker Screening Checks and confidentiality obligations for all workers; privacy and safeguarding training; and a data breach response plan. No method of storage or transmission is completely secure, and we cannot guarantee absolute security, but we review our practices regularly and act quickly on any weakness we find.
11. Data breaches
If we become aware of a data breach that is likely to result in serious harm to you, we will contain it, assess it, and notify you and the Office of the Australian Information Commissioner as the Notifiable Data Breaches scheme requires. We will tell you what happened, what information was involved, what we are doing about it, and what you can do to protect yourself. Where a breach involves information we hold for a Western Australian public entity, we will also meet any notification obligations under the Privacy and Responsible Information Sharing Act 2024 (WA).
12. How long we keep information
We keep participant records, including records of the supports we delivered, incident records and complaints, for at least seven years after the last support or the participant turning 25, whichever is later, as the NDIS rules and our clinical obligations require. Financial records are kept for seven years. Worker records are kept for seven years after employment ends. Call recordings and chat transcripts are kept for the period stated in section 8. Enquiries that do not lead to a service are kept for two years. When information is no longer needed and we are not required to keep it, we destroy it securely or de-identify it.
13. Your rights: access, correction, anonymity and choice
Access. You may ask to see the personal information we hold about you. We will respond within 30 days and usually provide access free of charge; where a request is large or complex we may charge a reasonable fee for the cost of retrieval and copying, and we will tell you before we do. In limited cases the law allows or requires us to refuse access, for example where giving access would pose a serious threat to someone’s safety; if so, we will tell you why in writing and how you can complain.
Correction. If information we hold is inaccurate, out of date, incomplete, irrelevant or misleading, we will correct it. If we do not agree that it needs correcting, we will tell you why and, at your request, attach a statement to the record noting your view.
Supported decision-making. You have the right to make decisions about your own information and to have support to do so. We will explain things in the way that works best for you, and we recognise the role of nominees, guardians and administrators appointed under law, and of advocates you choose. Where a participant is under 18, we deal with their parent or guardian while giving weight to the young person’s own views as their maturity allows.
Anonymity. You may enquire anonymously or under a pseudonym. We cannot provide NDIS-funded supports without knowing who you are.
Direct marketing. We send marketing, newsletters or service updates only with your consent, and every message will include a simple way to opt out. You may also opt out by contacting us.
Government identifiers. We use your NDIS number only for NDIS purposes and never as our own way of identifying you.
Withdrawing consent. You may withdraw consent to a use or disclosure at any time. Doing so will not affect anything done before you withdrew it, and we will tell you if it means we can no longer provide a support safely.
14. Questions and complaints
Please contact our Privacy Officer if you have a question, a request for access or correction, or a complaint about how we have handled your information:
Privacy Officer, Complex Care Continuum
7/1 Tonkin Place, Girrawheen WA 6064
Phone (08) 9515 8000 (answered 24 hours; ask for the Privacy Officer or an unrecorded call-back)
Email info@complexcarecontinuum.com.au with “Privacy” in the subject line
We will acknowledge a complaint within two business days, investigate it, and respond in writing within 30 days. You will not be disadvantaged in any way for making a complaint, and you may have an advocate or support person involved at every step.
If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (oaic.gov.au, 1300 363 992) or, for matters connected with NDIS supports, to the NDIS Quality and Safeguards Commission (ndiscommission.gov.au, 1800 035 544). If the matter concerns information we hold for a Western Australian public entity, you may also contact the WA Information Commissioner.
15. Changes to this policy
We review this policy at least annually and whenever the law or our systems change. The current version is always available on this website, and we will tell current participants about significant changes directly and in the format that suits them. Earlier versions are available on request.
