Your information
Privacy policy
Plain version: we collect what we need to provide your support, we do not sell it, and you can ask to see it or have it deleted at any time.
Last updated August 2026. Hope Harbour, ABN 63 677 813 384.
Who this covers
This policy covers Hope Harbour and everyone who works for us. We handle personal information under the Privacy Act 1988 (Cth) and the Australian Privacy Principles, and health information under the Health Records Act 2001 (Vic).
What we collect
Only what we need. That is usually:
- Identity and contact details: name, date of birth, address, phone, email, and the name of anyone who helps you make decisions
- NDIS details: your NDIS number, plan dates, plan management type, and the funded supports relevant to us
- Health and support information: your disability, support needs, medications, allergies, behaviour support plans, manual handling requirements, and anything else needed to support you safely
- Records of your support: shift notes, incident reports, and correspondence
- Payment information: invoices and claim records. We do not store your card details
- For job applicants: what you send us in your application, plus the results of the required checks
- Website information: see the section below
Health information is sensitive information under the Privacy Act. We only collect it with your consent, or where the law requires or permits it.
How we collect it
Mostly directly from you, in conversation or through the forms on this site. Sometimes from your support coordinator, plan manager, family, doctor or another provider, where you have agreed to that.
What we use it for
- Providing, planning and reviewing your support
- Matching you with suitable support workers
- Keeping you and our workers safe
- Claiming payment and meeting our record-keeping obligations
- Responding to complaints and reporting incidents where we are required to
- Improving how we work, using de-identified information
We will not use your information for marketing without asking you first, and you can say no or change your mind at any time.
Who we share it with
Only where you have agreed, or where the law requires it:
- Your support workers, limited to what they need to support you
- Your plan manager or the NDIA, to claim payment
- Your support coordinator, allied health providers or doctor, with your consent
- The NDIS Quality and Safeguards Commission, where we are required to report an incident
- Emergency services, where there is a serious and imminent risk
- Our software providers, who host our systems under contract
We never sell your information, and we never share it for advertising.
Where it is stored
In access-controlled systems with encryption in transit and at rest. Some of our software providers, including our website host and our email provider, store data on servers outside Australia. Where that happens we require contractual protections at least equivalent to the Australian Privacy Principles. Paper records are kept in locked storage.
How long we keep it
- Participant records: seven years after support ends, as NDIS record-keeping rules require. For a participant who was a child, until they turn 25
- Enquiries and referrals that do not proceed: 12 months
- Job applications: 12 months, then deleted
- Website analytics: we do not keep any (see below)
This website specifically
We have deliberately kept this simple.
- No tracking cookies, no advertising pixels, no analytics. There is no Google Analytics, no Meta pixel, and nothing following you around the internet. That is why you were not asked to accept cookies: there is nothing to accept.
- Your accessibility settings are stored in your own browser using local storage. They never leave your device and we cannot see them.
- Forms. When you submit the referral, contact or careers form, the information is emailed to our office and, if you gave an email address, a copy of the confirmation goes to you. Submissions pass through Netlify (hosting) and Resend (email delivery). We keep a short-lived record of your IP address to prevent automated abuse.
- Uploaded NDIS plans. If you attach a plan to a referral, the file travels straight through to our office inbox as an email attachment. It is not saved to the website, to Netlify, or to any storage service, and it is not attached to the confirmation that goes back to you, because the address on a form can contain a typo. Once it is in our inbox it is treated exactly like a plan you emailed us or handed over in person: stored in our participant records, and covered by the retention periods above. If a referral does not proceed, the file is deleted with the rest of the enquiry after 12 months.
- Fonts are served by Google Fonts, which means Google receives the request. If that concerns you, tell us and we will self-host them.
- Read aloud uses voices already on your device. No audio is sent anywhere.
- The dictionary sends only the single word you looked up to a free public dictionary API. Nothing else about you is sent.
- Translation opens the page in Google Translate in a new tab, at which point Google's privacy policy applies rather than ours.
Your rights
You can:
- Ask to see what we hold about you. We will provide it within 30 days, free, in a format you can use
- Ask us to correct anything wrong or out of date
- Ask us to delete information, where we are not legally required to keep it
- Withdraw consent to sharing, at any time
- Complain if you think we have mishandled your information
Email info@hopeharbour.com.au or call 0414 851 688. We can provide this policy or your records in Easy Read, large print or another language.
Complaints about privacy
Tell us first if you can: we will respond within 30 days. If you are not satisfied, the Office of the Australian Information Commissioner takes privacy complaints at 1300 363 992 or oaic.gov.au. For health records specifically, the Health Complaints Commissioner Victoria can be reached on 1300 582 113.
Data breaches
If a breach happens that is likely to cause you serious harm, we will tell you and the Office of the Australian Information Commissioner, as the Notifiable Data Breaches scheme requires.
Changes to this policy
If we change anything significant we will update the date at the top and, for current participants, tell you directly.