Privacy Policy
How we collect, use, and protect your personal information in accordance with the Australian Privacy Principles.
Last updated: June 2026
1. Introduction
The Only Support Coordination (referred to as "we," "our," or "us") is committed to protecting your privacy. We comply with the Australian Privacy Principles under the Privacy Act 1988 (Cth), the NDIS Code of Conduct, and NDIS Practice Standards as set out by the NDIS Quality and Safeguards Commission, and handle all personal information responsibly and with respect.
2. Personal Information We Collect
We collect only the information necessary to provide our services, which may include:
- Contact details (name, address, phone number, email address)
- NDIS-specific information including plan details and funding allocations
- Health and medical information (collected only with your consent)
- Payment and billing information
- Video and audio recordings of meetings conducted via Microsoft Teams, collected only with your prior consent
- Information provided through our AI-powered chatbot on the website portal
- Information relevant to the delivery of your support coordination services
We only collect information that is necessary for our services and will not collect more than is required.
3. How We Collect Information
Information may be collected through:
- Direct provision from you — in person, by phone, email, or via our website
- Third parties with your authorisation, such as health providers, family members, or other service providers
- Microsoft Teams video and audio recordings, with your prior consent
- Our AI-powered chatbot on the website portal, where you voluntarily provide information during a conversation
- Publicly available sources where permitted by law
4. How We Use Your Information
Your personal information is used to:
- Deliver support coordination services tailored to your needs
- Coordinate and manage third-party service providers on your behalf
- Communicate with you and your authorised representatives
- Meet our legal obligations and comply with NDIS regulations
- Improve the quality and delivery of our services
- Quality assurance, training, supervision, complaint resolution, risk management, and service improvement where recordings are involved
5. Disclosure to Third Parties
We may share your information with:
- Service providers involved in delivering your supports
- Medical and allied health professionals (with your consent)
- Government agencies, including the National Disability Insurance Agency (NDIA)
- Other parties you have authorised
In certain circumstances, we may be required to disclose personal information without your consent, including mandatory reporting obligations relating to child protection, incidents of violence, exploitation, neglect, abuse, or sexual misconduct as required under applicable law.
We take reasonable steps to ensure that all third parties we share information with are also compliant with their privacy obligations.
6. Storage and Security
Your information is stored in both electronic and physical formats using secure systems and appropriate safeguards. Electronic records are hosted on Australian servers via DreamIT Host. Multi-factor authentication (MFA) verification codes are delivered via SMTP2Go, which is hosted in Australia. General email communications are managed through Microsoft Exchange Online, hosted in Australian Microsoft data centres. Documents and files are stored in Microsoft SharePoint and OneDrive, with data at rest confirmed in Australian Microsoft data centres across Exchange Online, Teams, OneDrive, and SharePoint.
We take reasonable steps to protect your personal information from misuse, interference, loss, and unauthorised access, modification, or disclosure. Access to participant records is restricted to authorised staff only and is protected by multi-factor authentication (MFA).
We retain participant records for a minimum of 7 years in accordance with NDIS record-keeping requirements. When personal information is no longer needed beyond this period, we will take reasonable steps to destroy or de-identify it.
Microsoft Teams video recordings are stored securely and retained only for as long as necessary for the purpose for which they were recorded. Access is restricted to authorised staff only.
7. Data Breach Notification
In the event of an eligible data breach, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) as required under the Notifiable Data Breaches (NDB) scheme within 30 days of becoming aware of the breach. We maintain an internal incident response procedure to ensure prompt identification and management of any data security incidents.
8. Website Data and Cookies
Our website may collect non-personal data through cookies and analytics tools to improve user experience and website performance. No personally identifiable information is collected through cookies without your knowledge. You may disable cookies at any time through your browser settings without affecting your ability to access our services.
9. Meeting Recordings
We may record meetings conducted via Microsoft Teams with your prior consent. Recordings are used solely for quality assurance, training, supervision, complaint resolution, risk management, and service improvement purposes. All recordings are stored securely, accessed only by authorised personnel, and managed in accordance with the Privacy Act 1988 (Cth), Australian Privacy Principles, and NDIS requirements.
Participation in recording is voluntary. You may decline or withdraw consent at any time without affecting your access to services. Recordings will not be publicly shared and will only be disclosed where required by law or with your consent.
By providing consent, you acknowledge that you understand the purpose of the recording and agree to the collection, storage, and use of the recording for quality assurance and service improvement purposes.
10. Artificial Intelligence (AI) and Automated Tools
Our website portal includes an AI-powered chatbot to assist participants and staff with enquiries and service navigation. This chatbot may collect and process information you provide during the conversation to generate responses. No automated decisions that significantly affect your rights or entitlements are made solely by the AI without human review. You may choose not to use the chatbot and contact us directly at any time using the details in Section 14.
11. Accessing and Correcting Your Information
You have the right to request access to the personal information we hold about you, and to ask us to correct any information that is inaccurate, incomplete, or out of date. We will respond to all such requests within 30 days.
To make a request, please contact us using the details below.
12. Complaints
If you believe we have handled your personal information in a way that does not comply with the Australian Privacy Principles, please contact us in the first instance. We will investigate your complaint and respond within 30 days.
If you are unsatisfied with our response, you may escalate your complaint to the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au.
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal obligations. Any updates will take effect upon posting to our website. We encourage you to review this policy periodically.
14. Contact Us
If you have any questions about this Privacy Policy or the way we handle your personal information, please contact us:
- Email: connect@theonlysc.com.au
- Phone: 0406 969 689
- ABN: 46 664 734 605