Privacy Policy

Introduction

This document sets out the privacy policy of CAREVICINITY PTY LTD ACN 656 800 690 (referred to in this privacy policy as 'we', 'us', or 'our').

We take our privacy obligations seriously and we've created this privacy policy to explain how we store, maintain, use and disclose personal information to ensure we comply with the Privacy Act 1988 (Cth) (Privacy Act), the 13 Australian Privacy Principles (APP), and all applicable state and territory privacy legislation.

This Privacy Policy applies to all personal information collected by us, including sensitive information such as health information.

By providing personal information (including sensitive information) to us, you consent to our storage, maintenance, use and disclosing of personal information in accordance with this privacy policy.

We may change this privacy policy from time to time by posting an updated copy on our website and we encourage you to check our website regularly to ensure that you are aware of our most current privacy policy. Material changes to this Privacy Policy will be notified to affected individuals where practicable.

Our Principles

We are committed to:

Types of Personal Information We Collect

The personal information we collect may include the following:

We collect information about individuals of all ages, including children and people with cognitive or communication difficulties. If you are providing information on behalf of a minor or person without capacity, you must have appropriate authority to do so.

How Personal Information Is Collected

We will collect your personal information in a lawful and fair way. We will only collect your personal information where you have consented to it, or otherwise in accordance with the law. Where information is collected for secondary purposes, we will take reasonable steps to ensure you are aware of those purposes.

Direct Collection

We may collect personal information where you:

Anonymity and Pseudonymity

You may interact with us anonymously (without providing identifying information) or under a pseudonym in the following circumstances:

However, anonymity and pseudonymity are not practicable where:

In these circumstances, we will clearly explain why identifying information is required before collection.

Collection from Third Parties

Where practicable, we collect personal information directly from you. However, we may collect information about you from:

When collecting any information from third parties, we will:

Providing Information for Someone Else

If you are providing personal or sensitive information on behalf of someone else you must, and you represent to us that you:

This clause will apply where you are:

We reserve the right to request evidence of your consent or authority before proceeding with service delivery.

Where information is provided for a minor (under 18 years), the parent or legal guardian must provide consent. If we determine the minor has capacity to understand privacy matters, we may require direct consent from the minor as well.

Unsolicited Personal Information

We may receive personal information that we did not solicit (e.g., misdirected emails, over-shared documents, information sent without authorisation, incorrect referrals).

When we receive unsolicited information, we will:

We will not use unsolicited information for purposes beyond what we would have been authorised to collect it for.

Website and Cookies

We may also collect personal information from you when you use or access our website or our social media pages. This may be done through use of web analytics tools, 'cookies' or other similar tracking technologies that allow us to track and analyse your website usage. Cookies are small files that store information on your computer, mobile phone or other device and enable and allow the creator of the cookie to identify when you visit different websites. If you do not wish information to be stored as a cookie, you can disable cookies in your web browser.

Use of Your Personal Information

Primary Purposes

We collect and use personal information for the following primary purposes:

Secondary Purposes

We may also use your personal information for:

If we intend to use or disclose personal information for a purpose that is not directly related to our primary purpose and that you would not reasonably expect, we will (where practicable):

The following secondary purposes are purposes we expect a likelihood of occurring:

Sensitive Information Restricted Uses

Sensitive information is used only for the primary purposes listed in the Sensitive Information section below.

We do not use sensitive information for direct marketing or commercial purposes.

We do not use sensitive information to make automated decisions that significantly affect you (such as eligibility decisions) without appropriate human review.

How We Disclose Your Personal Information

We may disclose your personal information to:

We may also disclose personal information to third party contractors as required for us to provide our goods and services to you, such as cloud-service providers, IT professionals, marketing agencies and debt collection agencies.

We take care to work with such third parties who we believe maintain an acceptable standard of data security and require them not to use your personal information for any purpose except for those activities we have asked them to perform on our behalf. Before we disclose your personal information to any third-party service providers we:

We may provide personal information to government agencies (NDIA, DVA, and other regulatory bodies) where:

We may disclose personal information without your consent:

We do not sell, lease, or trade personal information to third parties or provide personal information to marketing companies, data brokers, or advertising networks.

Disclosures are made only where necessary for service delivery, legal compliance or with your express consent.

Storage, Security and Data Retention

Storage

All personal information we collect is stored on servers located in Australia.

Where cloud service providers operate overseas disaster recovery sites, we have contractual safeguards to:

Security

We implement comprehensive security measures to protect personal information from:

Data Retention

We retain personal information only for as long as it is needed for the purposes for which it was collected or as required by law, as follows:

After the retention period expires, we will:

Destruction and De-identification

We implement secure destruction procedures for personal information that is no longer required including:

Sensitive Information

We recognise that health information, including disability information, mental health information, and information about medical conditions, is sensitive information under the Privacy Act and requires special protection.

Collection of Sensitive Information

We may collect sensitive information about you during the course of providing you our goods and services. We will only collect this sensitive information where you consent to such collection and either directly provide us with this information or it is provided by a referring health care provider.

Types of Sensitive Information We Collect

The sensitive information we collect may include the following:

How We Use Your Sensitive Information

Your sensitive information will only be used for our primary purposes listed in this privacy policy or for the purpose of:

How We Disclose Your Sensitive Information

Your sensitive information will only be disclosed for or to:

We do not disclose sensitive information to marketing third parties or for commercial purposes.

If disclosure is necessary for health and safety reasons (e.g., to prevent serious harm), we may disclose without your consent but will document and notify you where reasonable.

All staff handling sensitive information must acknowledge their obligations under this Privacy Policy and the Privacy Act.

Data Quality and Accuracy

We take reasonable steps to ensure that personal information we hold is:

We regularly review and update personal information in our possession.

We take reasonable steps to correct information that we become aware is inaccurate.

Where we receive updated information from you, other service providers, or government agencies, we will promptly update our records.

You are responsible for ensuring that information you provide to us is accurate and complete.

If you believe we hold inaccurate, incomplete, or misleading information about you, you should notify us immediately and we will investigate your concerns and take corrective action where appropriate.

Individual Rights and Access to Personal Information

Right to Access

You have the right to request access to personal information we hold about you.

To request access, please contact us using the details provided in the Contact Us section, including:

We may require you to:

We will respond to your access request within a reasonable timeframe (generally 30 days, or as required by law).

We will provide information in the form you request (electronic or hard copy) where practicable.

We will provide reasons in writing if we refuse access, including information about our complaint process.

Limitations on Access

We may refuse access where:

We will provide written reasons and complaint information if access is refused.

Right to Correction

You have the right to request that we correct personal information that is inaccurate, incomplete, or misleading.

To request correction, please contact us with:

We will take reasonable steps to correct information within a reasonable timeframe (generally 30 days).

We will notify you when information has been corrected.

If we do not make the requested correction, we will provide written reasons.

Right to Request Alternative Form of Access

You may request information be provided in alternative formats (large print, audio, electronic, etc.).

We will accommodate reasonable requests where practicable.

We may charge a reasonable fee for providing information in alternative formats.

Representatives

You may authorise a representative (family member, carer, advocate, lawyer) to request access to your information.

We may require written evidence of the representative's authority.

We will verify the representative's authority before providing information.

De-identified Information

Where we de-identify information (by removing personal identifiers so that the person cannot be re-identified), we may:

We will not seek to re-identify de-identified information without explicit consent.

We may release de-identified written documentation, case studies, or statistical reports, including:

Any de-identified information will be kept separate from identified personal information to prevent re-identification.

Eligible Data Breaches and Notification

Definition of an Eligible Data Breach

An eligible data breach occurs when there is an unauthorised disclosure or loss of personal information where it is likely that serious harm could result to any individual.

Our Data Breach Response

We will implement procedures to:

Our Eligible Data Breach Management Plan sets out our procedures in detail.

What We Will Do If a Data Breach Occurs

Where an eligible data breach occurs, we will:

Breach Notification Content

All breach notifications will include:

We will not delay notification to verify or investigate matters unless it is essential to do so.

Record of Breaches

We maintain a register of all data breaches (eligible and non-eligible).

The register documents include:

Marketing

We may send you marketing communications and promotional materials to inform you about our services, events, and special offers.

Compliance with the Spam Act

We comply with the Spam Act 2003 (Cth) in all marketing communications.

We will only send marketing communications via email, SMS, social media, phone, or mail where:

We will not send marketing to individuals who have opted out.

All email marketing messages will include clear information about how to unsubscribe.

Opting Out of Marketing

You can opt out of receiving marketing communications at any time:

We will process unsubscribe requests as soon as possible, though there may be a brief delay as we update our systems.

Opting out of marketing does not affect our ability to send you administrative or transactional messages.

Marketing to Vulnerable People

We take care not to engage in marketing or promotions that target vulnerable people or that could be misleading.

We do not engage in aggressive or deceptive marketing practices.

Any marketing materials will clearly identify them as such and include our contact information.

Links

External Links

Our website may contain links to external websites and social media platforms.

We are not responsible for the privacy practices of linked websites.

When you follow external links, you leave our website and enter another organisation's privacy environment.

We recommend you review the privacy policies of external websites before providing information.

Links do not constitute endorsement of those websites or their privacy practices.

Social Media

We maintain profiles on social media platforms (Facebook, LinkedIn, etc.).

When you interact with us through social media:

We will not collect personal information from social media profiles except where you have made that information publicly available and you interact with our profile.

We recommend adjusting your social media privacy settings to control what information is visible.

Complaints

Making a Complaint

If you have a concern about how we handle your personal information or believe we have breached the Privacy Act or an Australian Privacy Principle, you may lodge a complaint.

To lodge a complaint, please contact us using the details in the Contact Us section, including:

We will acknowledge receipt of your complaint within 2 business days.

Our Complaint Process

We will investigate your complaint promptly and in a fair and impartial manner.

We will provide you with a response within 30 days of receiving your complaint.

If we cannot resolve the complaint within 30 days, we will notify you and provide a timeframe for resolution.

We will keep you informed of the progress.

Our response will include:

We will not take adverse action or discriminate against you for lodging a complaint.

Escalation to Privacy Commissioner

If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (OAIC) via the following details:

Office of the Australian Information Commissioner

The OAIC will assess your complaint and may investigate our privacy practices.

The OAIC can compel us to take remedial action if they find we have breached privacy law.

Complaint Record

We maintain a record of all privacy complaints, including:

We use complaints to identify systemic privacy issues and improve our practices.

Children's Privacy and Young People

Information About Children

We may collect personal information about children (under 18 years) where we provide services to them.

Before collecting sensitive information about a child, we obtain consent from:

We take age-appropriate steps to explain our privacy practices to children.

We do not engage in direct marketing to children.

Capacity and Consent

We assess whether a child has capacity to understand privacy and consent to collection.

Where a child has capacity, we may accept their consent in addition to parental consent.

Where a child lacks capacity, we rely on parental or guardian consent.

Contact Us

For further information about our privacy policy or practices, or to access or correct your personal information, or make a complaint, please contact us using the details set out below:

Our privacy policy was last updated on 5 December 2025.