Effective 16th October 2025
1. Introduction
Bridge Disability Support (“Bridge”, “we”, “us”, or “our”) is committed to protecting the privacy and confidentiality of the personal and health information we collect and hold.
This Privacy Policy explains how we manage personal and health information in accordance with:
- The Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs)
- The Health Records and Information Privacy Act 2002 (NSW) (HRIP Act)
- The NDIS Code of Conduct and NDIS Practice Standards
This Policy applies to all clients, participants, families, carers, employees, contractors, suppliers, and website visitors. By engaging our services or using our website, you consent to the collection, use, and disclosure of personal information as described below.
2. Information We Collect
We collect personal information necessary to provide disability supports, manage our operations, and meet legal and funding requirements. This may include:
Personal Information
- Name, address, contact details, date of birth, gender
- NDIS participant number or plan details
- Next of kin, carers, or emergency contact details
- Payment or invoicing information
- Records of communication with us
Health and Sensitive Information
- Disability or medical diagnoses, assessments, and reports
- Support plans, therapy notes, medication details, risk or behaviour plans
- Cultural background, language, or interpreter requirements
Digital Information
- Website analytics (non-identifying data such as IP address, device type, and browser)
- Online form submissions and contact enquiries
Sensitive information (including health information) is only collected with consent or as permitted by law.
3. Purpose of Collection and Use
We collect, hold, and use personal and health information to:
- Assess eligibility for supports and deliver services
- Develop and review support and service plans
- Communicate with clients, families, carers, and other professionals
- Manage funding, billing, and NDIS reporting
- Fulfil legal, regulatory, and compliance obligations
- Conduct quality assurance, audits, and staff training
- Manage incidents, feedback, and complaints
- Safeguard participant health, safety, and wellbeing
We will not use your information for a secondary purpose unless you consent or we are otherwise permitted or required by law.
4. Disclosure of Personal Information
We may disclose personal or health information to:
- Employees, contractors, and authorised service providers who need it to perform their duties
- Other healthcare or support professionals involved in your care (with consent)
- The NDIS Quality and Safeguards Commission, NDIA, or government authorities where required
- Auditors, insurers, or funding bodies for compliance and reporting
- Emergency services where necessary to prevent harm
- IT or data-hosting providers (subject to confidentiality and security obligations)
We do not sell or trade personal information.
If information is stored or processed by third parties outside Australia, we take reasonable steps to ensure that those providers comply with Australian privacy standards and relevant cross-border data protections.
Permitted Use or Disclosure Without Consent
We may use or disclose personal or health information without consent when authorised or required by law, including:
- To prevent or lessen a serious threat to health, safety, or welfare
- Where there is suspected abuse, neglect, or risk of harm (including mandatory reporting)
- To comply with court orders, subpoenas, or legal obligations
- Where otherwise authorised under the Privacy Act or HRIP Act (NSW)
5. Data Security
We take all reasonable steps to protect personal and health information from misuse, loss, unauthorised access, modification, or disclosure. Measures include:
- Secure electronic and physical storage systems
- Password protection, encryption, and firewalls
- Restricted staff access on a “need to know” basis
- Confidentiality agreements and privacy training for all staff and contractors
If a data breach occurs that is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) in accordance with the Notifiable Data Breaches Scheme.
6. Privacy Risk Review and Impact Assessment
Bridge Disability Support undertakes Privacy Impact Assessments (PIAs) or equivalent risk reviews for new systems, projects, or processes that involve the collection or use of sensitive, high-risk, or large-scale personal information.
These reviews help identify and mitigate privacy risks before they affect participants or staff.
7. Access and Correction
You have the right to:
- Request access to personal or health information we hold about you
- Request correction of inaccurate or incomplete information
- Withdraw consent for certain uses of your information (where applicable)
Requests should be made in writing to our Privacy Officer. Proof of identity may be required.
If we are unable to grant access or make corrections, we will provide written reasons and outline options for external review.
8. Website and Cookies
Our website may use cookies or analytics tools to collect non-identifiable data that helps us improve functionality and user experience.
Cookies do not personally identify users. You can disable them in your browser settings, though this may affect site performance.
Our website may contain links to third-party sites. We are not responsible for the privacy practices or content of those websites.
9. Accessibility and Alternate Formats
We are committed to ensuring that this Privacy Policy and related information are accessible to all participants, including those with communication or language needs.
Upon request, we will provide this Policy in alternative formats such as Easy Read, large print, or audio, and arrange interpreter services where required.
10. Complaints
If you believe we have mishandled your personal information, please contact our Privacy Officer.
Step 1 – Internal complaint
Submit your complaint in writing. We will acknowledge receipt and investigate within 30 days.
Step 2 – External complaint
If you are not satisfied with our response, you may contact:
- NSW Information and Privacy Commission (IPC) – for issues under the HRIP Act
- Office of the Australian Information Commissioner (OAIC) – for issues under the Privacy Act 1988 (Cth)
We encourage you to allow us the opportunity to resolve the matter internally first.
11. Changes to This Policy
We may amend this Privacy Policy from time to time to reflect legal or operational updates. The latest version will always be available on our website.
Your continued use of our services after changes take effect constitutes acceptance of the updated policy.
12. Contact Us
Privacy Officer
Bridge Disability Support
Email: Hello@bridgeds.com.au
For questions, access or correction requests, or privacy complaints, please contact our Privacy Officer in writing.