Your information, your rights
Privacy in plain language
We collect only the information reasonably needed to provide safe, professional and person-centred services. We explain why information is needed, seek consent where required, restrict access and support each person to exercise choice and control.
1. Who we are and what this policy covers
Sky Ability Pty Ltd (ABN 74 686 794 794), trading as Sky Ability, provides Specialist Behaviour Support, Psychology, Counselling and related services. This policy applies to people who use or enquire about our services, participants, their authorised representatives and care teams, referrers, website visitors, job applicants, workers and contractors.
We handle personal information in accordance with the Privacy Act 1988 (Cth), the Australian Privacy Principles, the Notifiable Data Breaches scheme, applicable health-records laws, NDIS requirements and relevant professional obligations. In Victoria, this includes the Health Records Act 2001 (Vic) and the Health Privacy Principles where they apply.
This policy describes our general information-handling practices. It is not a service agreement and does not limit any right or obligation that applies under law.
Our privacy commitments
- Respect privacy, dignity, autonomy and supported decision-making.
- Explain what we collect, why it is needed and how it may be shared.
- Use information only for lawful and relevant purposes.
- Keep records accurate, current, confidential and appropriately secure.
- Enable access, correction and privacy complaints as required by law.
2. Information we collect and hold
The information we need depends on the service and the person's circumstances. It may include:
Identity and contact
Name, date of birth, address, telephone number, email address, pronouns, language, communication preferences and details of authorised representatives or care-team members.
NDIS and administration
Participant number, plan dates, goals, funding and plan-management arrangements, service agreements, appointments, invoices, payments and claiming information.
Health and service information
Health, disability, developmental, psychological, behavioural, cultural and other sensitive information, together with referrals, assessments, reports, clinical notes, correspondence, risks, safety information and outcomes.
Quality, safety and operations
Consent records, feedback, complaints, incidents, safeguarding and quality records, job or contractor applications, and limited website or security information.
For Specialist Behaviour Support, records may also include functional assessments, behaviours of concern, environmental information, Behaviour Support Plans, consultation and implementation records, restrictive-practice information, authorisations and relevant incident records.
3. How we collect information
We usually collect information:
- directly from the person during an enquiry, referral, assessment, appointment or service;
- from a parent, guardian, nominee, authorised representative, referrer, support coordinator or care-team member;
- through telephone, email, our website, Splose forms, telehealth and practice-management systems;
- from reports, plans, observations and records supplied by professionals or organisations with appropriate authority; or
- where collection is required or authorised by law.
If we receive information that we did not request, we assess whether we may lawfully retain it. If not, and where lawful, we securely destroy or de-identify it.
A person may make a general enquiry anonymously or using a pseudonym where practical and lawful. We normally need accurate identifying information before accepting a referral, confirming authority, providing clinical or NDIS services, preparing reports or processing claims.
4. Why we use information
We collect, hold, use and disclose information to:
- respond to enquiries, review referrals and assess whether a service is suitable;
- assess needs and provide, coordinate, monitor and improve services;
- prepare clinical records, assessments, plans, reports and recommendations;
- communicate with the person, their authorised representatives, referrers, funders and care team;
- manage consent, appointments, service agreements, billing, payments and NDIS claims;
- manage risks, incidents, safeguarding, complaints, quality and service continuity;
- meet legal, regulatory, professional, insurance, audit and record-keeping requirements; and
- recruit, manage and support workers and contractors.
5. Consent, choice and supported decision-making
We seek informed consent where required before collecting, using, retaining or disclosing sensitive information, including assessments and identifiable audio or visual recordings. Consent may be given by the participant or a person with lawful authority to act for them.
A person may withdraw or change consent for future handling of their information by contacting us. We explain any likely effect this may have on our ability to provide or coordinate a service. A change does not affect action already taken with valid consent or information we are required to retain or use by law.
We presume adults can make their own decisions unless there is a lawful basis to determine otherwise. We offer reasonable communication adjustments and support a person to involve an advocate, interpreter or trusted person. NDIS nominee status does not automatically provide authority for every health or privacy decision.
When supporting a child or young person, we consider their age, maturity, decision-making capacity, participation rights, safety, parenting or guardianship arrangements and any relevant court orders. We involve them in privacy decisions as far as appropriate and lawful.
6. When we share information
We share information with consent, for the purpose for which it was collected, for a related purpose a person would reasonably expect where permitted, or when required or authorised by law. Depending on the service, recipients may include:
- authorised representatives, family members, carers, support coordinators, schools, health practitioners and other care-team members;
- the NDIA, the NDIS Quality and Safeguards Commission, plan managers, funding bodies and relevant government agencies;
- practice-management, secure-form, telehealth, payment, accounting, document, email and IT service providers;
- professional advisers, auditors, insurers, accreditation bodies and regulators; and
- courts, tribunals, emergency services, law-enforcement or safeguarding authorities where legally permitted or required.
Information may be disclosed without consent where the law allows or requires it, including to respond to a serious threat to life, health or safety; mandatory reporting; reportable incidents; safeguarding concerns; a lawful court order; or another legal obligation. We disclose only what is reasonably necessary.
Psychology and Counselling information is treated as highly sensitive. If a service involves more than one person, such as a family or joint session, we explain the practical limits of confidentiality and record access before the service begins where practicable.
Workers and service providers may access information only to the extent required for their role or another lawful purpose.
7. Systems, storage and overseas processing
We use third-party systems to operate our practice, including Splose for referral forms and practice management, as well as email, telehealth, document, accounting, payment and IT services. Information may be held in electronic systems and, where necessary, physical records.
Some technology providers or their support providers may process personal or technical information outside Australia, including in the United States. Where Australian Privacy Principle 8 applies, we take the steps required by that principle unless an exception applies.
8. Security and retention
We take reasonable steps required by applicable privacy and NDIS obligations to protect information from misuse, interference, loss, unauthorised access, modification and disclosure. No storage or transmission method is completely risk-free.
We retain records for the periods required by privacy, health-records, NDIS, taxation, employment, insurance and professional obligations. When information is no longer needed and may lawfully be disposed of, we take reasonable steps to securely destroy or de-identify it.
9. Access, correction and transfer
A person may ask to access personal information we hold about them or request correction of information that is inaccurate, out of date, incomplete, irrelevant or misleading. A person may also ask us to record a statement if we do not make a requested correction.
Requests may be made by email or telephone. We may need to verify identity and authority before responding. Access can be limited only where an applicable law permits or requires it. We respond within the period required by law or, if no period applies, within a reasonable time. We explain any refusal and available review or complaint options where required. A lawful access charge may apply.
10. Recordings, website and communications
We obtain specific consent before using an identifiable photograph, recording, testimonial or personal story for marketing, education, social media or publicity. Declining marketing consent does not affect access to services. A recording made for assessment or service delivery is treated as sensitive information and requires consent or another lawful basis.
Our website may collect limited technical information needed for operation, security and performance. Third-party forms or links also operate under the provider's privacy practices. General email is not the best place for detailed health or disability information; please use the relevant referral form when providing participant information.
11. Data breaches
We assess suspected privacy or security incidents and take reasonable steps to contain them and reduce possible harm. If a breach is likely to result in serious harm and the Notifiable Data Breaches scheme applies, we notify affected people and the Office of the Australian Information Commissioner. We also notify other regulators where required.
12. Privacy questions, access requests and complaints
Contact the Sky Ability Privacy Officer if you have a question, want to access or correct information, change consent, or make a privacy complaint. You do not need to use a particular form.
Please provide enough information for us to understand and investigate the issue. We handle complaints in accordance with applicable privacy and NDIS complaints requirements and respond within a reasonable time.
If you are not satisfied with our response, you may contact:
- Office of the Australian Information Commissioner for a privacy complaint;
- NDIS Quality and Safeguards Commission for an NDIS service complaint;
- Health Complaints Commissioner Victoria for a Victorian health-service or health-records complaint; or
- Office of the Health Ombudsman Queensland for a Queensland health-service complaint.
13. Accessible formats and policy updates
Contact us if you need help understanding this policy or require information in an accessible format. Requests are considered in accordance with applicable accessibility and NDIS obligations.
We review this policy when our services, systems or obligations change. The current version and effective date are published on this page.
