Legal
Privacy Policy
Last updated: 31 August 2026
This policy is provided as general information about how Bethel Therapy handles personal information. It is not legal advice. Please have a qualified Australian legal practitioner review and tailor this document before you publish it.
Bethel Therapy (“we”, “us”, “our”) is committed to protecting the privacy and dignity of the people we support. We handle personal information in accordance with the Privacy Act 1988 (Cth) and the 13 Australian Privacy Principles (APPs), and in line with our obligations as a provider working within the National Disability Insurance Scheme (NDIS).
1. Scope of this policy
This policy applies to all personal information we collect through our services, our website, referrals, enquiries and job applications. It covers participants, their families, carers, nominees, referrers, contractors and applicants for employment.
2. Information we collect
Participant information
To deliver behaviour support and social counselling safely and effectively, we collect:
- Name, date of birth, contact details and address
- NDIS participant number, plan details and plan management arrangements
- Details of your nominee, guardian, family members and support network
- Health and disability information, diagnoses and clinical history
- Behaviour support needs, incident records and any regulated restrictive practices
- Assessments, progress notes, support plans and reports
- Cultural background, language and communication preferences
- Consent records and correspondence with you or your support network
Sensitive information
Health, disability, cultural and similar details are sensitive information under the Privacy Act and attract higher protection. We collect sensitive information only where it is reasonably necessary for our services and where you (or a person lawfully authorised to act for you) have consented, or where the law otherwise permits or requires it.
Referrer and enquiry information
Where a referral is made by a support coordinator, family member, health professional or other third party, we collect the referrer’s name, organisation and contact details along with the information they provide about the participant.
Job applicant information
If you submit an expression of interest through our Career page, we collect your name, contact details, professional role, qualifications, years of experience, area of interest, any message you provide and your CV. We use this information solely to assess your suitability for current or future roles.
Website information
Our website may collect limited technical information such as your IP address, browser type, pages visited and referring site. This is used to keep the site secure and to understand how it is used.
3. How we collect information
Wherever it is reasonable and practicable, we collect personal information directly from you. We may also collect it from your nominee or guardian, family members and carers, support coordinators, the National Disability Insurance Agency (NDIA), treating practitioners and allied health professionals, schools or day programs, and other service providers involved in your support — in each case with your consent or as otherwise permitted by law.
4. Why we collect, hold and use information
We use personal information to:
- Assess referrals and determine whether our services suit your needs
- Conduct functional behaviour assessments and develop behaviour support plans
- Provide social counselling and therapeutic support
- Coordinate care with your family, carers and other providers
- Meet our reporting obligations to the NDIS Quality and Safeguards Commission
- Record and review any regulated restrictive practices
- Manage appointments, billing, claiming and plan administration
- Respond to enquiries, feedback and complaints
- Improve the quality and safety of our services
- Meet our legal, insurance and record-keeping obligations
5. When we disclose information
We do not sell personal information. We may disclose it to:
- Your nominated family members, carers, guardian or nominee
- Your support coordinator, plan manager or the NDIA
- The NDIS Quality and Safeguards Commission, including for reportable incidents and restrictive practice reporting
- Treating practitioners and allied health professionals involved in your care
- Our professional advisers, insurers and secure IT service providers
- Any person or body where disclosure is required or authorised by Australian law, a court or a tribunal
We disclose only what is reasonably necessary for the purpose, and we require our service providers to protect your information to the same standard we apply.
Overseas disclosure
We aim to store personal information in Australia. Some secure IT or cloud services we rely on may store data overseas. Where that occurs, we take reasonable steps to ensure the recipient handles your information consistently with the Australian Privacy Principles.
6. Consent and supported decision-making
We seek informed consent before collecting or sharing your information, and we explain what we are asking in a way that suits your communication needs. Where a participant is supported in decision-making, we work with the participant and their nominee or guardian, and we continue to involve the participant in decisions about their own information to the greatest extent possible. You may withdraw consent at any time, though this may affect our ability to continue providing a service.
7. Storage, security and retention
Personal information is held in secure electronic systems with access limited to authorised personnel, and in securely stored physical records where these exist. We use access controls, authentication, encryption in transit and staff confidentiality obligations to protect your information.
We retain records for as long as required by law and by our professional and NDIS obligations. Health records are generally retained for at least seven years from the date of last service, and where the participant is a child, until they reach 25 years of age. When information is no longer needed and no legal obligation to retain it applies, we destroy or de-identify it securely.
If a data breach occurs that is likely to result in serious harm, we will respond in accordance with the Notifiable Data Breaches scheme, including notifying affected individuals and the Office of the Australian Information Commissioner (OAIC).
8. Accessing and correcting your information
You may request access to the personal information we hold about you, and ask us to correct anything inaccurate, out of date or incomplete. Please contact us using the details below. We will ask you to verify your identity and will respond within a reasonable period, usually within 30 days.
In limited circumstances we may refuse access — for example, where giving access would pose a serious threat to the life, health or safety of any person, or unreasonably affect another person’s privacy. If we refuse, we will explain why in writing and tell you how to complain.
9. Complaints
If you believe we have mishandled your personal information, please tell us. We take privacy complaints seriously and will acknowledge your complaint and work with you to resolve it.
Bethel Therapy
20 Keane Street, Currajong, Queensland 4812
Phone: 07-31797064
Email: admin@betheltherapy.com.au
If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au or on 1300 363 992.
Concerns about NDIS services may also be raised with the NDIS Quality and Safeguards Commission on 1800 035 544 or at ndiscommission.gov.au.
10. Changes to this policy
We may update this policy from time to time to reflect changes in our services or our legal obligations. The current version will always be available on this page, with the date it was last updated shown at the top.