Privacy Policy
How The Only Support Coordination collects, uses, stores and protects your information.
Updated August 2026 | ABN 46 664 734 605
1. Introduction
The Only Support Coordination (referred to as "we", "our", or "us") is committed to protecting your privacy.
We comply with the Australian Privacy Principles under the Privacy Act 1988 (Cth), the NDIS Code of Conduct, and NDIS Practice Standards as set out by the NDIS Quality and Safeguards Commission.
We handle all personal information responsibly and with respect.
2. Personal Information We Collect
We may collect information that is necessary to provide our services, including:
- Name, address, phone number, email and date of birth
- NDIS participant number and plan details
- Information about supports, needs, goals and preferences
- Health or disability-related information where required
- Guardian, nominee, representative or support contact details
- Information provided through referrals, intake forms, service agreements, consent forms, feedback forms and complaints
- Communication records, service notes and documents needed to coordinate supports
We only collect information that is reasonably necessary for our work.
3. How We Collect Information
We may collect information through:
- Direct provision from you, in person, by phone, email, or via our website
- Referral forms and intake forms
- Your authorised nominee, guardian or representative
- NDIS providers, allied health professionals, plan managers or support people, where consent has been provided
- Our secure digital systems, including the participant portal
4. How We Use Your Information
We use personal information to:
- Process referrals and intake forms
- Provide support coordination and related services
- Communicate with you and your authorised supports
- Prepare and manage service agreements, consent forms and documents
- Coordinate with approved providers and supports
- Meet NDIS, legal, audit, safeguarding and compliance requirements
- Respond to feedback, complaints, incidents or requests for information
- Improve our services and internal processes
5. Disclosure to Third Parties
We do not sell or misuse your personal information.
We may share information only when required to provide supports, meet our obligations, or where consent or legal authority allows it.
5.1 Disclosure with consent
Where appropriate, we may share information with:
- The NDIA
- Plan managers
- Support providers
- Allied health professionals
- Guardians, nominees, representatives or family members authorised by you
- External service providers who support our operations, such as secure IT, document storage or email systems
5.2 Disclosure where required without consent
We may disclose information without consent where required or authorised by law, including where there is a serious risk to safety, where mandatory reporting applies, or where required by a regulator, court, tribunal or government authority.
6. Storage and Security
We store information using secure systems and take reasonable steps to protect it from misuse, interference, loss, unauthorised access, modification or disclosure.
Security measures may include:
- Secure digital storage
- Access controls
- Password and authentication protections
- Audit logs
- Staff confidentiality obligations
- Secure disposal practices
Access to participant information is limited to authorised staff or contractors who need it for their role.
7. Data Breach Notification
If a data breach occurs that is likely to result in serious harm, we will act in accordance with the Notifiable Data Breaches Scheme.
This may include notifying affected individuals and the Office of the Australian Information Commissioner.
8. Website Data and Cookies
Our website may collect limited technical information, such as browser type, device information, pages visited, and general website usage.
This helps us improve website accessibility, security and functionality.
We do not use website cookies to collect unnecessary sensitive NDIS or health information.
9. Meeting Recordings
We will not record meetings, calls or video sessions without informing participants and obtaining consent where required.
If a meeting is recorded, we will explain why and how the recording will be stored, used and protected.
10. Artificial Intelligence (AI) and Automated Tools
We may use approved technology, automation or AI tools to support administration, document handling, internal workflow, communication assistance, service planning, and quality improvement.
AI or automated tools must not replace human judgement in participant-related decisions.
We do not use AI to make final decisions about eligibility, service suitability, risk, safeguarding, funding, participant outcomes, or support needs.
Where AI or automation is used, it is subject to privacy, access, security and staff oversight controls.
11. Accessing, Correcting, and Withdrawing
You may request access to your personal information or ask us to correct information that is inaccurate, outdated, incomplete or misleading.
You may also withdraw consent where consent is the basis for using or sharing your information.
Withdrawing consent may affect our ability to provide some services, and we will explain this clearly if it applies.
12. Complaints
If you have concerns about how your information has been handled, please contact us first so we can try to resolve the matter.
You may also contact the Office of the Australian Information Commissioner at www.oaic.gov.au.
13. Changes to This Policy
We may update this Privacy Policy from time to time.
The latest version will be published on our website.
14. Accessible Formats
If you need this policy in another format or need help understanding it, please contact us.
We can provide support in a way that works best for you.
15. Contact Us
If you have questions about privacy, consent or your information, please contact:
- The Only Support Coordination
- Privacy Officer Email: connect@theonlysc.com.au
- Phone: 0406 969 689