Privacy Policy
This Privacy Policy explains how Serendib Support Services collects, uses, discloses, stores, protects and manages personal and health information — for participants, families, carers, nominees, support coordinators and plan managers. Use the contents list to jump to any section, or read straight through.
Table of contents
- 1. About this Privacy Policy
- 2. Information we may collect
- 3. How we collect information
- 4. Remaining anonymous
- 5. Consent and informed choice
- 6. Changing or withdrawing consent
- 7. Photographs, audio and video
- 8. Why we use your information
- 9. Sharing your information
- 10. Disclosure without consent
- 11. Privacy and dignity during support delivery
- 12. Digital recordkeeping and Blueset
- 13. Access to Blueset records
- 14. Protecting information stored in Blueset
- 15. Other places where information may appear
- 16. Storage within Australia and overseas disclosure
- 17. Accuracy of information
- 18. General information security
- 19. Accessing your information
- 20. Correcting your information
- 21. Retaining and destroying records
- 22. Privacy and data breaches
- 23. Website information and cookies
- 24. Third-party websites
- 25. Making a privacy complaint
- 26. External complaint options
- 27. Contact us
- 28. Accessible versions
- 29. Changes to this Privacy Policy
1. About this Privacy Policy
Serendib Consultants Pty Ltd, trading as Serendib Support Services, respects your privacy, dignity and right to have control over your personal information.
This Privacy Policy explains how we collect, use, disclose, store, protect and manage personal and health information when you:
- enquire about our services;
- receive supports from us;
- communicate with our workers;
- visit our website;
- provide feedback or make a complaint; or
- otherwise interact with Serendib Support Services.
Our privacy practices are designed to comply with the NDIS Code of Conduct and align with the relevant NDIS Practice Standards concerning privacy, dignity, informed consent and information management.
We also handle personal and health information in accordance with applicable privacy legislation, including the Health Records Act 2001 (Vic) and, where applicable, the Privacy Act 1988 (Cth) and Australian Privacy Principles.
The Health Records Act applies to disability-service information handled in Victoria, including identifying personal information collected while providing disability services.
↑ Back to top2. Information we may collect
The information we collect will depend on the services you request or receive.
It may include:
- your name, date of birth, address and contact details;
- emergency-contact information;
- your NDIS participant number;
- relevant NDIS plan and funding information;
- information about whether your plan is self-managed or plan-managed;
- information about your disability, health, wellbeing and support needs;
- your goals, preferences, routines and support instructions;
- information about risks, allergies, medication or emergency requirements relevant to providing safe support;
- your cultural background, language, communication and accessibility preferences;
- details of your nominee, guardian, advocate, family member or authorised representative;
- contact details for your support coordinator, plan manager or other providers;
- intake documents, assessments, service agreements and consent records;
- support plans, risk assessments and safety documentation;
- progress notes, shift notes and records of supports provided;
- schedules, timesheets and attendance records;
- invoices, billing and payment information;
- incident, complaint and feedback records;
- correspondence and other communications with us;
- photographs, video or audio recordings where consent has been provided; and
- information submitted through our website, email, telephone or referral forms.
We only collect information that is reasonably necessary to respond to your enquiry, provide and manage your supports, operate our organisation or meet our legal and regulatory responsibilities.
↑ Back to top3. How we collect information
We may collect information directly from you through:
- enquiries and referral forms;
- intake and assessment processes;
- service agreements and consent forms;
- conversations, meetings, telephone calls and emails;
- the delivery of supports;
- shift notes and service records;
- complaints, feedback or incident processes; and
- our website.
With your consent, we may also receive relevant information from:
- your nominee, guardian or authorised representative;
- a family member, advocate or support person;
- your support coordinator;
- your plan manager;
- another NDIS provider;
- a health professional;
- the NDIA; or
- another person or organisation involved in your supports.
Where practical, we will collect information directly from you.
Information initially received by email, telephone or through our website may be transferred to Blueset so that it forms part of your central participant record.
↑ Back to top4. Remaining anonymous
Where practical, you may make a general enquiry without giving us your full name or by using a preferred name.
However, we will usually need accurate identifying and contact information before we can:
- determine whether we can safely provide supports;
- prepare a service agreement;
- verify NDIS funding arrangements;
- communicate with your plan manager or support coordinator;
- maintain appropriate service records; or
- provide ongoing supports.
The Australian Privacy Principles provide for anonymity or the use of a pseudonym where this is practical, subject to limited exceptions.
↑ Back to top5. Consent and informed choice
Before collecting, using, retaining or disclosing participant information, we will explain, where relevant:
- what information is being requested;
- why we need it;
- how it will be used;
- who it may be shared with;
- how it will be stored;
- whether it may be disclosed without consent where required or authorised by law; and
- what may happen if the information is not provided.
We will provide this information using the language, communication method and terms you are most likely to understand.
You may ask for assistance from an advocate, interpreter, nominee, family member or other support person when making decisions about your information.
Where another person provides consent on your behalf, we may request evidence that the person is authorised to do so.
The NDIS information-management indicators address informed consent for the collection, use, retention and disclosure of participant information, as well as participant access to and correction of records.
↑ Back to top6. Changing or withdrawing consent
You may withdraw or amend your consent at any time by contacting us.
We will explain whether changing or withdrawing your consent may affect our ability to:
- provide a particular support;
- communicate with another person involved in your services;
- share information with your plan manager or support coordinator;
- respond safely during an emergency; or
- meet a legal or regulatory obligation.
You will not be treated unfairly because you have changed or withdrawn your consent.
However, we may be unable to continue a particular support where essential information is unavailable and the support cannot be provided safely, effectively or lawfully.
Withdrawal of consent will generally apply from the date it is received. It may not require the deletion of records that we are legally required or reasonably entitled to retain.
↑ Back to top7. Photographs, audio and video
We will obtain specific consent before taking or using identifiable photographs, audio recordings or video recordings, unless the recording is required or authorised by law.
Before requesting consent, we will explain:
- why the recording is being made;
- how it will be used;
- where it will be stored;
- who will have access to it;
- whether it will be shared or published; and
- how consent can be withdrawn or amended.
Consent to photographs, audio or video can be withdrawn for future use. Withdrawal may not always enable us to retrieve material that has already been lawfully published or provided to another person with your previous consent.
↑ Back to top8. Why we use your information
We may use your information to:
- respond to enquiries and referrals;
- determine whether we can provide suitable supports;
- understand your needs, goals, preferences and circumstances;
- prepare and manage your service agreement;
- plan, coordinate and provide supports;
- match you with suitable workers;
- communicate with you and your authorised representatives;
- provide workers with the information required to deliver safe and appropriate support;
- prepare schedules, timesheets and service records;
- prepare invoices and payment claims;
- communicate with your plan manager or support coordinator where authorised;
- manage risks, emergencies, incidents, complaints and feedback;
- monitor and improve the quality and safety of our services;
- meet insurance, accounting, auditing, legal and regulatory requirements;
- train, supervise and manage workers;
- maintain business and compliance records; and
- operate and secure our website and business systems.
We will not use participant information for a purpose unrelated to the reason it was collected unless:
- you have provided consent;
- the secondary use is directly related to the original purpose and you would reasonably expect it;
- the use is required or authorised by law; or
- another permitted exception applies.
We do not sell or rent participant information.
↑ Back to top9. Sharing your information
With your consent, we may disclose relevant information to:
- workers involved in providing your supports;
- your nominee, guardian, advocate or authorised representative;
- your support coordinator;
- your plan manager;
- another provider involved in your supports;
- health professionals;
- emergency services;
- the NDIA;
- insurers, auditors, accountants or legal advisers;
- Blueset and other technology providers used to operate our organisation; or
- another person or organisation you have authorised us to communicate with.
Workers will only be given information that is relevant to their role and reasonably necessary to provide or manage your supports.
Where we use contractors or external service providers, we take reasonable steps to ensure that information is handled securely and confidentially.
↑ Back to top10. Disclosure without consent
There may be circumstances where information can or must be disclosed without your consent.
These may include where disclosure is reasonably necessary to:
- respond to a serious or immediate threat to someone's health or safety;
- contact emergency services;
- report or respond to suspected abuse, neglect, exploitation or violence;
- comply with incident or reportable-incident obligations;
- investigate suspected fraud or unlawful conduct;
- comply with a court order, warrant, subpoena or other lawful requirement;
- respond to a lawful request from the NDIS Quality and Safeguards Commission, the NDIA or another regulator;
- establish, exercise or defend a legal claim; or
- comply with another legal obligation.
Where legally permitted and appropriate, we will explain the disclosure to you.
We will limit the information disclosed to what is reasonably necessary for the relevant purpose.
↑ Back to top11. Privacy and dignity during support delivery
Privacy is not limited to written or electronic records.
Our workers are expected to respect your privacy and dignity while providing supports in your home and community.
This includes:
- asking permission before entering private spaces;
- respecting your home, belongings and personal boundaries;
- protecting your privacy during personal or sensitive activities;
- speaking about private matters discreetly;
- not discussing your information with unauthorised people;
- not accessing your belongings without permission;
- not taking photographs or recordings without consent;
- respecting your relationships, identity, culture, values and choices; and
- providing support in a way that preserves your dignity, independence and right to make decisions.
The NDIS Code of Conduct requires NDIS providers and workers to respect the privacy of people with disability.
↑ Back to top12. Digital recordkeeping and Blueset
Serendib Support Services uses Blueset as its primary system for storing and managing participant and service records.
The central or authoritative version of participant records is maintained in Blueset.
Information stored in Blueset may include:
- participant names and contact information;
- NDIS participant and funding-management details;
- emergency contacts and authorised representatives;
- intake forms and consent records;
- service agreements;
- support plans, goals and preferences;
- risk assessments and safety information;
- relevant health, disability or emergency information;
- schedules, bookings and rosters;
- timesheets and attendance records;
- progress notes and shift notes;
- records of supports delivered;
- incident, complaint and feedback records;
- invoices and payment information; and
- other documents required to provide, manage and review supports.
Blueset provides tools for scheduling, invoicing, administration, client records, notes and documentation. Blueset also publicly describes its note storage as secure and Australian based.
Serendib Support Services remains responsible for the way participant information is entered into, accessed through and managed within Blueset.
↑ Back to top13. Access to Blueset records
Access to information stored in Blueset is limited to authorised people who require the information to perform their duties.
Depending on their role, authorised users may include:
- management;
- administration personnel;
- workers providing your supports;
- contractors performing an authorised business function; and
- Blueset personnel who require access to operate, maintain or support the platform.
Workers must only access information that is relevant to their role.
Workers must not access, view, copy, download, alter or disclose participant information:
- for personal reasons;
- out of curiosity;
- after their access is no longer required;
- for an unauthorised purpose; or
- for the benefit of another person or organisation.
Access may be removed when a worker leaves the organisation, changes roles or no longer requires participant information.
↑ Back to top14. Protecting information stored in Blueset
We take reasonable steps to protect participant information stored in Blueset.
These steps may include:
- requiring individual user accounts;
- using passwords and available account-security features;
- limiting access according to a person's role;
- not sharing login credentials;
- reviewing who has access to participant records;
- removing access when it is no longer required;
- training workers in privacy and confidentiality;
- keeping devices used to access Blueset secure;
- correcting inaccurate or outdated records;
- responding to suspected unauthorised access; and
- following secure retention and disposal processes.
Workers must not save participant information to personal devices or accounts unless this is authorised, necessary and appropriately protected.
↑ Back to top15. Other places where information may appear
Although Blueset is our primary participant-record system, limited information may also be temporarily held or transmitted through:
- business email;
- website enquiry forms;
- telephone messages;
- invoices sent to plan managers or participants;
- documents supplied by participants or other providers;
- accounting, banking or insurance systems;
- devices used by authorised workers; or
- records required to be supplied to government bodies, regulators or professional advisers.
Where relevant information is received outside Blueset, we may transfer it to Blueset so that the participant record remains complete and current.
We take reasonable steps to limit duplicate copies and protect information wherever it is held.
↑ Back to top16. Storage within Australia and overseas disclosure
Blueset publicly states that it provides secure, Australian-based note storage. On the information currently available to us, participant records stored through Blueset are not generally expected to be stored outside Australia.
Serendib Support Services does not generally intend to disclose participant information directly to overseas recipients.
However, cloud and technology providers may use supporting services, contractors or technical infrastructure that can change over time. If we become aware that participant information is likely to be disclosed to or accessible by an overseas recipient, we will:
- assess the privacy and security implications;
- take reasonable steps to protect the information;
- identify the relevant countries where practical;
- notify affected participants where required; and
- update this Privacy Policy.
Where the Australian Privacy Principles apply, a privacy policy must address likely overseas disclosures and identify the countries involved where practical.
↑ Back to top17. Accuracy of information
We take reasonable steps to ensure participant information is:
- accurate;
- current;
- complete;
- relevant; and
- recorded promptly.
You should tell us when your:
- contact information changes;
- emergency contacts change;
- support needs or risks change;
- health or safety information changes;
- nominee or representative changes;
- NDIS funding arrangements change; or
- preferences or circumstances change.
We may periodically ask you to review or confirm important information.
↑ Back to top18. General information security
In addition to the protections applied to Blueset, we take reasonable administrative, physical and technical steps to protect information from:
- loss;
- misuse;
- interference;
- unauthorised access;
- unauthorised disclosure;
- alteration; and
- destruction.
Depending on how information is held, safeguards may include:
- password-protected devices and systems;
- access restrictions;
- secure cloud storage;
- locked storage for paper documents;
- confidentiality requirements for workers and contractors;
- privacy and information-management training;
- secure transfer methods;
- secure disposal and deletion procedures; and
- processes for responding to suspected privacy or data breaches.
No electronic system is completely secure. However, we review our systems and practices and take reasonable steps to reduce privacy and security risks.
↑ Back to top19. Accessing your information
You may request access to the personal or health information we hold about you.
You may ask to:
- view your records;
- receive a copy of your records;
- have information explained to you;
- receive the information in an accessible format where reasonably possible; or
- have information transferred to another provider with your authority.
We may ask you to verify your identity or authority before providing access.
We will respond within a reasonable period.
Access may be limited or refused where permitted or required by law. Where this occurs, we will explain the reason unless we are legally prevented from doing so.
The Health Records Act applies to disability-service information in Victoria and provides rights concerning access to health information.
↑ Back to top20. Correcting your information
You may ask us to correct information that you believe is:
- inaccurate;
- incomplete;
- misleading;
- irrelevant; or
- out of date.
Where appropriate, we will:
- correct the information;
- add a note or statement explaining the correction;
- notify relevant people or organisations that previously received incorrect information; or
- record your request if we do not agree that the original information should be changed.
Some service records, such as contemporaneous progress notes, may need to remain as originally recorded. In these circumstances, a correction, clarification or participant statement may be added without deleting the original record.
↑ Back to top21. Retaining and destroying records
We retain records for as long as reasonably necessary to:
- provide and review supports;
- maintain an accurate history of services delivered;
- meet NDIS and legal recordkeeping requirements;
- manage complaints, incidents or claims;
- satisfy taxation, insurance, employment and contractual obligations; and
- protect the lawful interests of participants and Serendib Support Services.
When information is no longer required, we will take reasonable steps to securely destroy it or permanently remove identifying information, unless it must be retained by law.
Information may remain in secure backups for a limited period until those backups are overwritten or securely deleted.
↑ Back to top22. Privacy and data breaches
A privacy or data breach may occur where personal information is:
- accessed without authority;
- disclosed to the wrong person;
- lost;
- stolen;
- altered without authority; or
- made unavailable because of a security incident.
If we become aware of a suspected breach, we will take reasonable steps to:
- contain the breach;
- investigate what occurred;
- identify the information and people affected;
- reduce the risk of harm;
- preserve relevant evidence;
- correct weaknesses in our systems; and
- notify affected people, Blueset and relevant authorities where required.
Where the Privacy Act applies, affected individuals and the OAIC must be notified of an eligible data breach that is likely to result in serious harm and cannot be adequately remedied.
Privacy breaches involving health information may also be reported to the Victorian Health Complaints Commissioner where appropriate.
↑ Back to top23. Website information and cookies
When you visit our website, our website or hosting provider may automatically record limited technical information, including:
- your internet protocol address;
- browser and device type;
- pages visited;
- the date and time of access;
- referring website information; and
- website-performance or security information.
This information may be used to:
- maintain website security;
- identify technical problems;
- prevent misuse;
- understand general website usage; and
- improve the website.
Where our website uses cookies, you may be able to disable or delete them through your browser settings. Disabling cookies may affect how some website features operate.
Information submitted through a website contact form may be received by email before relevant details are transferred into Blueset.
↑ Back to top24. Third-party websites
Our website may contain links to third-party websites.
Serendib Support Services is not responsible for the privacy, security or content practices of an external website. You should review the privacy policy of any external website before providing personal information.
↑ Back to top25. Making a privacy complaint
You may contact us if you:
- have a question about this Privacy Policy;
- believe your information has been handled incorrectly;
- want to access or correct your information;
- want to change or withdraw your consent; or
- wish to make a privacy complaint.
You may make a complaint personally or with help from an advocate, interpreter, family member, nominee or support person.
Making a complaint will not affect your right to receive safe, respectful and appropriate supports.
We will:
- acknowledge your complaint;
- treat it fairly and confidentially;
- investigate where necessary;
- keep you informed about its progress;
- provide an outcome or response within a reasonable period; and
- explain any action taken.
Where possible, privacy complaints should first be raised with Serendib Support Services so that we have an opportunity to respond and resolve the concern.
↑ Back to top26. External complaint options
You may also contact an appropriate external body.
NDIS Quality and Safeguards Commission
The NDIS Commission receives complaints and concerns about supports and services provided by NDIS providers and workers.
Telephone: 1800 035 544
TTY: 133 677
Interpreters and National Relay Service assistance are available.
Victorian Health Complaints Commissioner
The Health Complaints Commissioner can receive complaints about the handling of health records and health information in Victoria.
Telephone: 1300 582 113
Office of the Australian Information Commissioner
Where the Privacy Act applies, you may make a privacy complaint to the OAIC after first giving us an opportunity to respond.
Telephone: 1300 363 992
27. Contact us
Serendib Consultants Pty Ltd
ABN 16 615 727 029
Melbourne, Victoria
Email: info@serendibsupportservices.com.au
Please mark privacy-related correspondence for the attention of the Privacy Officer.
28. Accessible versions
You may ask for this Privacy Policy or an explanation of our privacy practices in a format that is easier for you to understand.
Where reasonably possible, we can communicate using:
- plain language;
- your preferred communication method;
- an interpreter;
- an advocate or support person; or
- another accessible format.
29. Changes to this Privacy Policy
We may update this Privacy Policy when:
- our services change;
- our information systems change;
- Blueset's services or storage arrangements change;
- privacy or NDIS requirements change; or
- we identify improvements that should be made.
The current version will be published on our website with the date it was last updated.