Effective date: 11 August 2026
Our commitment. Sky Ability respects every person's privacy, dignity, autonomy, choice, and control. We handle information in a way that supports safe, lawful, person-centred, and rights-based services.
1. About this policy
Sky Ability Pty Ltd (ABN 74 686 794 794), trading as Sky Ability, is committed to respecting privacy and handling personal information responsibly. We manage personal information in accordance with the Privacy Act 1988 (Cth), the Australian Privacy Principles, the Notifiable Data Breaches scheme, applicable health-records laws, NDIS requirements, and relevant professional obligations.
Health and disability information is sensitive information and is given additional protection. In Victoria, health information is also handled in accordance with the Health Records Act 2001 (Vic) and the Health Privacy Principles where applicable.
2. Personal information we collect
Depending on the service and your circumstances, we may collect:
- identity and contact details, including name, date of birth, address, telephone number, email address, pronouns, language, and communication preferences;
- details about a participant's representative, nominee, family members, carers, referrers, support coordinator, and other members of their care team;
- NDIS information, including participant number, plan dates, goals, funding, plan-management arrangements, service agreements, and claiming information;
- health, disability, developmental, psychological, behavioural, cultural, and other sensitive information relevant to assessment and service delivery;
- referrals, assessments, reports, Behaviour Support Plans, clinical notes, correspondence, consent records, risk and safety information, and service outcomes;
- appointment, billing, payment, and transaction information;
- feedback, complaints, incidents, safeguarding information, and quality-improvement records;
- employment or contractor application information; and
- technical website information such as device, browser, IP address, pages visited, and security logs.
Where relevant to Specialist Behaviour Support, this may include functional behaviour assessments, behaviours of concern, environmental and safeguarding information, Behaviour Support Plan implementation and monitoring information, consultation records, restrictive-practice information, authorisations, and incident records.
3. How we collect information
We collect information in several ways, including:
- directly from a participant during an enquiry, referral, assessment, appointment, or service;
- from a parent, guardian, nominee, authorised representative, family member, carer, support coordinator, referrer, or care-team member;
- through our website, email, telephone, secure Splose referral forms, telehealth systems, and practice-management systems;
- from reports, plans, records, observations, assessments, and information supplied by other professionals or organisations with appropriate authority; and
- where required or authorised by law.
If we receive personal information that we did not request, we assess whether we could lawfully have collected it. Where we are not required or permitted to retain it, we take reasonable steps to securely destroy or de-identify it.
You may make a general enquiry anonymously or using a pseudonym where this is lawful and practicable. We generally need accurate identifying information before we can accept a referral, verify authority, provide clinical or NDIS services, prepare reports, or process claims.
4. Why we collect, use, and hold information
We use personal information to:
- review referrals, determine service suitability, and respond to enquiries;
- provide, coordinate, monitor, and improve Behaviour Support, Psychology, Counselling, assessment, and reporting services;
- understand a participant's strengths, needs, circumstances, communication, risks, preferences, and goals;
- communicate with participants, authorised representatives, referrers, funders, and care teams;
- manage appointments, consent, service agreements, billing, payments, and NDIS claims;
- meet safeguarding, incident-management, record-keeping, professional, regulatory, insurance, and legal requirements;
- respond to feedback, complaints, access requests, and privacy enquiries;
- maintain the safety and security of our participants, workers, systems, and services; and
- recruit and manage workers and contractors.
Sky Ability does not rely solely on automated decision-making to make clinical decisions or decide whether a person will be accepted for a service. Appropriate professional and human review is used.
5. Consent and sensitive information
We collect sensitive information with consent where required, or where collection is otherwise permitted or required by law. Consent may be provided by the participant or a person legally authorised to act for them. We seek to involve participants in decisions in a way that reflects their capacity, rights, communication needs, preferences, and circumstances.
You may withdraw or change consent for future use or disclosure by contacting us. This may affect our ability to provide or coordinate a service. Withdrawal does not affect actions already taken with valid consent or information we must retain or use by law.
We presume adults can make their own decisions unless there is a lawful reason to conclude otherwise. We provide reasonable communication adjustments and support participants to involve an advocate, interpreter, or trusted person. A representative must have the participant's consent or lawful authority; NDIS nominee status does not automatically provide authority for every health or privacy decision.
When supporting a child or young person, we consider their age, maturity, decision-making capacity, participation rights, safety, applicable parenting or guardianship arrangements, and any relevant court orders. We involve them in privacy decisions as far as appropriate and lawful.
6. When we disclose information
We disclose personal information only for the purpose for which it was collected, for a related purpose that would reasonably be expected where permitted, with consent, or where required or authorised by law. Recipients may include:
- authorised representatives, family members, carers, support coordinators, schools, health practitioners, allied-health providers, and other care-team members;
- the NDIA, NDIS Quality and Safeguards Commission, plan managers, funding bodies, and other relevant government agencies;
- technology, practice-management, secure-form, telehealth, payment, accounting, document-storage, email, and IT-support providers that assist us to operate;
- professional advisers, auditors, insurers, accreditation bodies, and regulators;
- courts, tribunals, law-enforcement bodies, emergency services, or safeguarding authorities where required or authorised; and
- another person or organisation where disclosure is necessary to lessen or prevent a serious threat and is permitted by law.
We do not sell or rent personal information. Workers and service providers are expected to protect confidentiality and access only the information needed for their role.
7. Psychology and Counselling confidentiality
Psychology and Counselling information is treated as highly sensitive. It is ordinarily disclosed only with consent, for a directly related purpose that would reasonably be expected in providing care, or where disclosure is required or authorised by law. This may include responding to a serious threat to life, health, or safety; mandatory reporting; safeguarding or reportable-incident obligations; a valid court order; or another legal duty.
If a service involves more than one person, such as a family or joint session, we explain the practical limits of confidentiality and access to records before the service begins where practicable.
8. Service providers and overseas processing
We use third-party systems to operate our practice, including Splose for secure referral forms and practice management. Core clinical information for Australian Splose workspaces is represented by Splose as being stored in Australia. Third-party providers maintain their own privacy, security, and subprocessor arrangements, which may change.
We do not generally send clinical records overseas. Some website, email, communications, support, or cloud providers may process limited personal or technical information outside Australia, including in the United States or other locations identified in their privacy notices. Where Australian Privacy Principle 8 applies, we take reasonable steps to ensure that overseas handling is consistent with applicable privacy requirements, unless an exception applies.
9. Storage, security, and retention
Information may be held in secure electronic practice-management, email, document, accounting, communications, and backup systems. We use safeguards appropriate to the nature of the information, including access controls, authentication, role-based permissions, secure transmission, system monitoring, backups, confidentiality obligations, and staff training where appropriate.
No method of storage or transmission is completely risk-free. We retain records for the periods required by privacy, health-records, NDIS, taxation, employment, insurance, and professional requirements. When information is no longer required and may lawfully be disposed of, we take reasonable steps to securely destroy or de-identify it.
10. Photographs, recordings, testimonials, and marketing
We ordinarily obtain specific consent before using an identifiable participant photograph, audio or video recording, testimonial, or personal story for marketing, social media, education, or publicity. Declining this consent will not affect access to our services.
Recordings made for assessment, service delivery, supervision, or another professional purpose are handled as sensitive information and require consent or another lawful basis. Consent for service delivery does not automatically mean consent for marketing.
11. Website, email, and third-party links
Our website may collect standard technical information needed for operation, security, and performance. Embedded Splose forms and links to third-party websites are governed by those providers' privacy practices as well as our obligations when we receive the information.
The general contact form prepares an email in your own email application. Please do not include detailed clinical, disability, or health information in a general email. Use the relevant secure referral form for participant information.
12. Accessing or correcting information
You may request access to personal information we hold about you or ask us to correct information that is inaccurate, out of date, incomplete, irrelevant, or misleading. We may need to verify your identity and authority before responding. Access may be limited where an exception under applicable law applies.
We will respond within the period required by applicable law or, where no period is specified, within a reasonable time. We will tell you if a lawful fee applies before proceeding and explain any refusal or limitation where required.
13. Data breaches
We take suspected privacy and security incidents seriously. We assess and respond to incidents and take reasonable steps to contain and reduce harm. Where an eligible data breach is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme. We will notify other regulators where required.
14. Privacy questions and complaints
Contact the Sky Ability Privacy Officer at info@skyability.com.au or 0452 145 887 if you have a privacy question, wish to make a complaint, or want to request access or correction. Please provide enough information for us to understand and investigate the issue. We will treat complaints respectfully and respond within a reasonable time. We aim to acknowledge a privacy complaint within five business days and provide an outcome within 30 calendar days, or explain why additional time is required.
If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner. Depending on the subject and location of the complaint, you may also contact the NDIS Quality and Safeguards Commission or the relevant health-complaints body.
15. Accessible formats and changes to this policy
This policy is available in alternative formats on request, including plain-language, Easy Read, large-print, translated, or assistive-technology-compatible formats. Please contact us to discuss an appropriate format.
We may update this policy when our services, systems, or legal and professional obligations change. The current version and effective date will be published on this page.
