Privacy policy.

Our commitment to your privacy

Rose Bay Community Care respects your privacy and is committed to protecting the personal information entrusted to us.

This Privacy Policy explains how Rose Bay Community Care (referred to as we, us or our) collects, holds, uses and discloses personal information. It also explains how you can access or correct your information, ask a question or make a privacy complaint.

We handle personal information in accordance with the Privacy Act 1988 (Cth), the Australian Privacy Principles and other applicable health, disability, aged-care and record-keeping requirements.

This policy applies to clients and prospective clients, family members, carers, nominees, guardians, advocates and other representatives; referrers and service partners; employees, contractors, volunteers and applicants; and visitors to our website.

What information we collect

The information we collect depends on our relationship with you and the services or support being requested or provided. It may include:

  • Identity and contact information, such as your name, date of birth, address, telephone number, email address and preferred method of communication.

  • Representative and relationship information, including details of family members, carers, guardians, nominees, advocates, emergency contacts and other authorised representatives.

  • Health and care information, such as diagnoses, medical history, disability, medications, allergies, communication needs, support needs, risk assessments, care plans, clinical notes, incident information and information relevant to providing safe and effective care.

  • Sensitive information, which may include health information, disability information, racial or ethnic origin, cultural identity, religious beliefs, sexual orientation or other information where it is relevant to your care and we have consent or another lawful basis to collect it.

  • Funding and service information, including NDIS, aged-care, privately funded or other funding arrangements; plan, package or referral details; service agreements; claims; invoices and payment records.

  • Service and communication records, including enquiries, referrals, assessments, appointments, correspondence, feedback, compliments, complaints and records of services provided.

  • Safety, quality and compliance information, including incidents, hazards, restrictive practices where applicable, safeguarding concerns, investigations, audits and regulatory reporting.

  • Workforce information, such as employment history, qualifications, registrations, references, right-to-work information, screening clearances, training records and information supplied by applicants, employees and contractors.

  • Website and technical information, such as your IP address, device and browser information, pages visited and other information collected through cookies and similar technologies.

We aim to collect only the information reasonably necessary for our functions and activities. We generally collect sensitive information with your consent unless collection is otherwise permitted or required by law.

How we collect information

Where reasonable and practicable, we collect personal information directly from you. We may collect it when you:

  • contact us by telephone, email, through our website or in person;

  • complete a referral, feedback, complaint or other form;

  • meet with us or receive services from us;

  • enter into a service agreement or provide information needed for funding and billing;

  • apply to work with us; or

  • otherwise communicate or interact with our team.

With your consent, authority or where permitted by law, we may also collect information from:

  • a family member, carer, guardian, nominee, advocate or other representative;

  • a support coordinator, plan manager, referrer or funding body;

  • a health practitioner, hospital, allied health professional, community service or another care provider;

  • the National Disability Insurance Agency, My Aged Care, an aged-care provider or another government agency;

  • an employer, referee, screening body, registration authority or training provider; or

  • another person or organisation involved in your care, safety, funding or service delivery.

Our online referral and feedback forms are provided through Astalty. Information entered into those forms is transmitted to and stored within systems made available to us by Astalty. Astalty’s handling of information is also subject to its Privacy Policy.

If we receive personal information that we did not request, we will assess whether we could lawfully have collected it. If not, we will take reasonable steps to destroy or de-identify it, unless we are required by law to retain it.

Remaining anonymous or using a pseudonym

You may choose to deal with us anonymously or by using a pseudonym where this is lawful and practicable. However, we will generally need accurate identifying, contact and health information to assess a referral, arrange services, provide safe care, respond to a complaint or meet funding and regulatory requirements.

Why we collect and use information

We may collect, hold, use and disclose personal information to:

  • respond to enquiries and assess referrals;

  • determine whether we can safely and appropriately meet a person’s needs;

  • develop, deliver, coordinate, monitor and review care and support;

  • communicate with clients, families, representatives, referrers and other authorised people;

  • support medication management, clinical care, emergency responses and continuity of care;

  • prepare service agreements, rosters, care plans, reports and other service records;

  • administer NDIS, aged-care, private and other funding arrangements, including invoicing and claims;

  • manage feedback, compliments, complaints, incidents, risks and safeguarding concerns;

  • meet our legal, professional, contractual, insurance, audit and regulatory obligations;

  • recruit, screen, train, manage and support our workforce;

  • maintain and improve the quality, safety and accessibility of our services;

  • operate, secure and improve our website, systems and business; and

  • establish, exercise or defend legal claims.

We will not use health or other sensitive information for direct marketing without express consent.

If you do not provide information we reasonably require, we may be unable to assess your referral, provide or coordinate services, process funding, respond fully to an enquiry or complaint, or consider an application to work with us.

When we disclose information

We disclose personal information only where it is reasonably necessary for our functions, you have authorised it, or it is permitted or required by law.

Depending on the circumstances, we may disclose information to:

  • your authorised family members, carers, guardians, nominees, advocates or other representatives;

  • our employees, nurses, support workers, contractors and other members of your care team who need the information to perform their roles;

  • health practitioners, hospitals, emergency services, pharmacies, allied health professionals and other care or support providers;

  • support coordinators, plan managers, funding bodies, aged-care partners and government agencies involved in arranging, funding or monitoring services;

  • the NDIS Quality and Safeguards Commission, Aged Care Quality and Safety Commission and other regulators or oversight bodies;

  • professional advisers and service providers, including our insurers, auditors, accountants and legal advisers;

  • technology and administration providers that support our operations, including Astalty, Squarespace, email, telecommunications, cloud storage, document management and IT-security providers; and

  • law enforcement bodies, courts, tribunals or other parties where disclosure is required or authorised by law, or is necessary to lessen or prevent a serious threat to life, health or safety.

Where appropriate, we require service providers to protect information and use it only for the services they provide to us.

We do not sell personal information.

Overseas storage and disclosure

Astalty states that its processing operations are performed in Australia and that it uses reasonable endeavours to store information in Australia. Other technology providers used for our website, communications or business systems may store or process information outside Australia, including in the United States and other countries in which those providers or their subcontractors operate.

Where personal information may be disclosed overseas, we take reasonable steps, where required, to ensure it is handled in accordance with applicable Australian privacy requirements. The locations used by service providers may change from time to time, and their own privacy policies provide further information about their data-handling practices.

How we protect information

We may hold personal information electronically and, where necessary, in hard-copy records. We take reasonable steps to protect it from misuse, interference, loss and unauthorised access, modification or disclosure.

These measures may include:

  • access controls and role-based permissions;

  • password protection and multi-factor authentication where available;

  • secure systems, networks and storage;

  • staff confidentiality obligations, privacy training and supervision;

  • policies and procedures governing information handling;

  • secure disposal and de-identification practices; and

  • monitoring, incident response and data-breach procedures.

No method of electronic transmission or storage is completely secure. If a data breach occurs, we will act promptly to contain and assess it and will notify affected individuals and the Office of the Australian Information Commissioner where required under the Notifiable Data Breaches scheme.

How long we retain information

We retain personal information only for as long as it is reasonably required for the purpose for which it was collected, to provide continuity of care, and to meet applicable legal, professional, funding, insurance and record-keeping obligations.

When information is no longer required and we are not legally required to retain it, we take reasonable steps to securely destroy or permanently de-identify it.

Website, cookies and external links

Our website is hosted by Squarespace and may use cookies and similar technologies needed to operate securely, remember preferences and understand website use. Depending on the settings enabled, this may include information such as IP address, browser type, device information, pages visited and the time of access.

You can control or delete cookies through your browser settings. Disabling some cookies may affect how the website functions.

Our website may contain links to external websites or services, including Astalty and social-media platforms. Those third parties have their own privacy practices, and we encourage you to review their privacy policies. We are not responsible for the content or privacy practices of external websites.

Accessing and correcting your information

You may ask to access the personal information we hold about you or request that it be corrected if you believe it is inaccurate, out of date, incomplete, irrelevant or misleading.

Please contact our Privacy Officer using the details below. We may need to verify your identity and authority before providing access or making a correction. If another person makes a request for you, we may ask for evidence that they are authorised to act on your behalf.

We will respond within a reasonable period and generally aim to do so within 30 days. We will not charge you for making a request or correcting your information. We may charge reasonable costs for providing access where permitted by law, but we will discuss this with you first.

In some circumstances, the law permits us to refuse access or correction. If this occurs, we will provide written reasons where required and explain how you can make a complaint. If we do not agree that information should be corrected, you may ask us to associate a statement with the record noting your position.

Privacy questions and complaints

If you have a question or concern about privacy, or believe we have mishandled your personal information, please contact our Privacy Officer:

Privacy Officer
Rose Bay Community Care
7/353 Beaconsfield Terrace
Brighton QLD 4017
Email: hello@rosebaycommunitycare.com.au
Phone: 0423 377 734

Please provide enough information for us to understand and investigate your concern. We will acknowledge your complaint as soon as practicable, investigate it fairly and aim to respond within 30 days. If we need more time, we will explain why and provide an expected response date.

If you are not satisfied with our response, or we have not responded within a reasonable period, you may contact the Office of the Australian Information Commissioner:

Office of the Australian Information Commissioner
Website: www.oaic.gov.au
Phone: 1300 363 992
Post: GPO Box 5218, Sydney NSW 2001

Depending on the subject of your concern, you may also have the right to contact the NDIS Quality and Safeguards Commission, the Aged Care Quality and Safety Commission or another relevant regulator.

Changes to this policy

We may update this Privacy Policy when our services, systems or legal obligations change. The current version will be published on our website and identified by the date shown at the beginning of the policy.