Privacy Policy

How Sewa Care Australia collects, uses, stores and discloses personal and sensitive information, including health information, under the Privacy Act 1988 (Cth).

Last updated

This document is under review. It accurately describes our current practices, but has not yet been reviewed by a legal practitioner. If anything here is unclear or appears wrong, pleasetell us — we would rather fix it than leave it.

Sewa Care Australia (“we”, “us”, “our”) is committed to protecting your privacy. This policy explains how we handle personal information, including the sensitive information and health information we necessarily collect in order to provide disability and aged care support.

We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

What information we collect

Through this website, when you submit a referral, assessment or careers form, we collect:

  • your name, email address, phone number and suburb
  • the type of support you are enquiring about and your funding type
  • for referrals made by a third party: the referrer’s role, the participant’s contact details, and whether the participant has consented to being contacted
  • any notes you choose to provide, which may include information about disability, health conditions or risk

In the course of providing services, we also collect information such as NDIS or Home Care Package details, care plans, progress notes, medication information, emergency contacts and incident records.

Information about your health or disability is sensitive information under the Privacy Act and attracts a higher level of protection. We only collect it where it is reasonably necessary to deliver your supports safely.

Why we collect it

  • To respond to your enquiry and arrange a consultation
  • To assess whether we can meet your support needs
  • To deliver, schedule and coordinate your supports safely
  • To meet our obligations as a registered NDIS provider, including under the NDIS Practice Standards and to the NDIS Quality and Safeguards Commission
  • To bill you, your plan manager or the relevant funding body
  • To meet record-keeping obligations under Australian law

Where a referral is made on behalf of someone else, we ask the referrer to confirm that the participant has consented to being contacted. We may contact the participant to confirm that consent directly.

You can withdraw consent at any time by contacting us. Withdrawing consent may affect our ability to provide supports.

Who we disclose information to

We do not sell your information. We do not disclose it for marketing.

We may disclose personal information to:

  • support workers and coordinators involved in delivering your supports
  • your plan manager, support coordinator or nominated representative, where you have authorised this
  • the NDIS Quality and Safeguards Commission or NDIA, where required
  • health practitioners or emergency services, where there is a serious and imminent threat to life, health or safety
  • our professional advisers, insurers and auditors
  • law enforcement or regulators, where required or authorised by law

Website form submissions and overseas disclosure

We want to be specific about this, because it is the part most privacy policies gloss over.

When you submit a form on this website:

  1. The submission is transmitted over an encrypted connection to a Cloudflare Worker. Cloudflare, Inc. is a United States company operating a global network with Australian edge locations. The Worker processes the submission in transit and does not store it.
  2. A spam check is performed using Cloudflare Turnstile.
  3. The submission is then emailed to our Zoho Mail mailbox. Zoho hosts our mail in its Australian data centre.

We do not store website form submissions in any database. They exist as email in an Australian-hosted mailbox and in our own care records.

Because Cloudflare is an overseas recipient, this is a cross-border disclosure under APP 8. We have designed the form flow specifically to minimise it: data is in transit only, is not retained by the processor, and is delivered to Australian-hosted storage.

If we begin using an additional email delivery provider (such as Resend, a United States company) for automatic acknowledgement emails, that will be reflected in this policy.

Analytics

This site uses Cloudflare Web Analytics, which is privacy-preserving and sets no cookies. It does not track you across sites and does not build a profile of you. This is why the site does not display a cookie consent banner — there are no tracking cookies to consent to.

Maps

Our contact and service area pages can display a Google Map.

The map does not load until you click “Show the map”. Until you do, nothing is requested from Google and Google receives nothing about your visit. This is deliberate: an automatically-loaded map would send every visitor’s IP address to Google and set Google’s cookies, whether or not they wanted a map.

If you do choose to load it, Google receives your IP address and may set cookies, under Google’s privacy policy. Google is a United States company, so this is a cross-border disclosure under APP 8 — which is precisely why it is your choice rather than ours.

The “Get directions” and “View a larger map” links are ordinary links. They load nothing until you follow them, at which point you are on Google’s own site.

How we store and protect information

  • Care records are held in access-controlled systems, available only to staff who need them
  • All staff are bound by confidentiality obligations
  • Every support worker holds a current National Police Clearance and has completed the NDIS Worker Orientation Module
  • Paper records, where they exist, are stored securely and destroyed securely

How long we keep it

We retain participant records for the periods required by the NDIS Practice Standards and applicable Australian law — generally a minimum of seven years from the last entry, and longer where a participant was a child at the time of service. Enquiries that do not proceed to service are destroyed when no longer needed.

Accessing and correcting your information

You have the right to ask what personal information we hold about you and to request access to it or correction of it. Contact us using the details below. We will respond within 30 days. If we refuse access we will tell you why in writing.

There is no charge for making a request.

Complaints

If you believe we have mishandled your personal information, please contact us first — see our feedback and complaints page. We will acknowledge your complaint within two business days.

If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner (OAIC):

Participants may also contact the NDIS Quality and Safeguards Commission on 1800 035 544.

Changes to this policy

We will update this policy when our practices change. The date at the top of this page reflects the most recent revision.

Questions about this page?

Contact us and we will explain anything that is not clear.