Skip to main content
Legal

Privacy Policy

Last updated: 18 August 2026

In short

Keystone Community Care (ABN 48 691 121 525) (“Keystone”, “we”, “our”, “us”) collects only the personal information we need to respond to you, deliver NDIS supports, employ our workers and run our website. We handle it under the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs), the Privacy (Tax File Number) Rule 2015, the NDIS Practice Standards and the NDIS Code of Conduct. Identifying, financial and health details you give us through this website are encrypted at rest, access is limited to authorised Keystone staff and every access to sensitive fields is logged. We never sell personal information and we do not use it for direct marketing.

This policy explains what we collect, why, how it is stored and shared (including overseas), how long we keep it, and how you can access, correct or complain. It applies to our website, our forms, our AI chat assistant, our services and our workers.

1. What personal information we collect

Participants, families and people making enquiries

  • Contact and identity details: name, preferred name, pronouns, date of birth, address, phone, email, preferred way to be contacted, emergency contact and their relationship to you.
  • NDIS details: NDIS participant number, plan dates, plan management type (self, plan or NDIA managed), plan manager or support coordinator details.
  • Health and disability information (sensitive information): primary and secondary diagnosis, date of diagnosis, a description of your disability and support needs, communication supports you use, and your preferences for support workers.
  • Cultural information (sensitive information): country of birth, primary language, whether you need an interpreter, cultural background, and whether you identify as Aboriginal and/or Torres Strait Islander — collected only so we can match you with appropriate supports and workers.
  • Referrer details: if someone completes a form on your behalf, their name, relationship to you, phone and email.
  • Service records once you become a participant: service agreements, support plans, shift notes, incident and complaint records, invoices and payment records.

Employees and applicants

  • Full legal name, date of birth, gender, address, contact details, emergency contact, employment details (role, employment basis, start date).
  • Tax File Number (TFN) and TFN declaration answers (residency status, tax-free threshold, study or training loan), bank account details for salary payments, and superannuation fund, USI and member number.
  • Induction and training records (module completed, quiz answers, scores, certificate) and worker screening, qualification and compliance documents required under the NDIS Practice Standards.

Website visitors

  • Enquiry forms and eligibility checker: what you type into them (name, email, phone, message, eligibility answers).
  • AI chat assistant: your messages and the assistant’s replies, a random session identifier, and — for security and rate-limiting — your IP address and browser type. See section 6.
  • Website analytics: we run our own first-party analytics. They record the page path, the referring website (if any), the device type, which of our own buttons and links are used (for example tapping our phone number, opening the chat, or reaching a step in a form), and a one-way daily hash of your IP address and browser string. When you submit a form we also attach the page you first arrived on, the referring site and any campaign tags in the link you followed, so we can see which channels lead to enquiries. None of this stores your IP address, uses cookies, tracks you across other websites, or is shared with any advertising network. Staff and onboarding pages are excluded.
  • Cookies and local storage: a secure session cookie is set only when a Keystone staff member signs in to the admin area. Your accessibility widget preferences and the chat session identifier are stored in your own browser (local/session storage) and are never sent to us as such. We do not use advertising or third-party tracking cookies.

2. How we collect it — and information about other people

We collect information directly from you through our website forms, the chat assistant, phone, email, service agreements, consent forms and during service delivery. With your consent we may also receive information from your plan manager, support coordinator, family members, guardian or nominee, or health professionals.

If you give us information about someone else (for example, you are completing the intake form as a family member, carer, support coordinator or referrer), you confirm that you are that person’s parent or legal guardian, their NDIS nominee or plan nominee, or that you have their consent (or the consent of the person authorised to decide for them) to share it with us for the purposes in this policy. Our forms ask you to declare this. Where the participant is a child, decisions and consents are given by a parent or guardian; where a participant has a guardian or nominee, we deal with that person as the law requires.

Anonymity: you can browse the site and ask general questions in the chat assistant without identifying yourself, and you can phone us anonymously with general questions. We can’t assess eligibility, respond to a specific enquiry or deliver supports without knowing who you are.

Sensitive information (health, disability and cultural information) is collected only with your consent — you are asked for it explicitly in the intake form — or where the law requires or permits it. You can choose not to answer optional questions; we will tell you if something is needed to provide supports.

3. Why we collect and use it

  • Responding to you: answering enquiries, checking eligibility, arranging a call or intake.
  • Delivering supports: planning, rostering, matching you with suitable support workers, delivering and reviewing NDIS-funded supports, and keeping the records the NDIS Practice Standards require.
  • Administration: service agreements, invoicing you, your plan manager or the NDIA, and payment records.
  • Safety, quality and compliance: incident management, complaints handling, worker screening, audits, and reporting required by the NDIS Quality and Safeguards Commission and other laws.
  • Employment: employing and paying our workers, meeting tax, superannuation, Fair Work and NDIS worker obligations, and delivering induction and training.
  • Improving our website and services: aggregated analytics and de-identified chat topics.

We do not use your personal information for direct marketing and we will not add you to any marketing list without your express consent. Government identifiers (your NDIS number, a worker’s TFN) are used only for the purposes for which they were issued and never as our own identifier for you.

4. AI chat assistant

The chat on our website is an AI assistant, and it tells you so at the start of every conversation. It answers general questions about our supports and how to get started. It has no access to your NDIS plan, health records or anything you have not typed into the conversation. When you use it we store your messages, the replies, a random session identifier, and your IP address and browser type (for security and rate limits).

Your messages are sent to a third-party large language model provider (xAI, hosted in the United States) to generate a reply. Please do not enter health details, NDIS numbers or other sensitive information into the chat — use the secure forms or call us instead. Conversations are deleted automatically after 90 days, or 180 days if you asked for a callback so we can follow up. Callback requests (name, phone or email, and the conversation summary) are handled like any other enquiry. Keystone staff can review conversations to improve the assistant and to identify common questions.

The assistant also has an optional voice mode. If you choose to start a voice conversation, your browser will ask for microphone access, and the audio of what you say is streamed to the same provider (xAI) to hold the conversation — we do not keep the audio itself. A text transcript of the conversation is stored and deleted on the same schedule as typed chats. Voice mode is entirely optional: everything it does can also be done by typing, on the phone, or through our forms.

5. Employees, applicants and Tax File Numbers

When you complete our onboarding form (which is available only through a secure, personal invitation link) we collect the information needed to employ you and enrol you in payroll. It is collected under the Taxation Administration Act 1953 (Cth), the Superannuation Guarantee (Administration) Act 1992 (Cth) and the Fair Work Act 2009 (Cth), and — for worker screening and training records — the National Disability Insurance Scheme Act 2013 (Cth) and the NDIS Practice Standards.

Your TFN is handled in accordance with the Privacy (Tax File Number) Rule 2015: it is optional to provide (if you don’t, tax is withheld at the highest marginal rate), it is used only for tax and superannuation purposes, it is disclosed only to the ATO (through Single Touch Payroll), our payroll system and your superannuation fund, it is never used to identify you in our own systems, and it is securely destroyed when it is no longer required by law.

Your TFN, bank account details, superannuation membership details, date of birth, address and contact details are encrypted at rest. In our admin system they are masked by default; a staff member must deliberately “reveal” a sensitive field, and every reveal is recorded in an audit log with who and when. Payroll details are transferred to Xero (see section 7) so we can pay you and report to the ATO.

Induction and training records (including your quiz answers, scores and certificate) are kept as evidence of worker competency required by the NDIS Practice Standards.

6. How we store and protect it

  • Encryption: personal identifiers, contact details, dates of birth, NDIS numbers, health and cultural information, TFNs, bank and superannuation details are encrypted at rest (AES-256-GCM) with a key that is not stored with the data. All traffic to our website is encrypted in transit (HTTPS).
  • Access: only authorised Keystone staff can access the admin system, using single-use login codes sent to our staff address, with sessions that expire. Sensitive fields are masked until deliberately revealed, and views, reveals, changes and deletions are written to an audit trail.
  • Hosting: our website and database are hosted on commercial cloud infrastructure with the database located in an Australian (Sydney) region. Backups are encrypted.
  • Physical records are kept in locked storage with restricted access and are securely destroyed when no longer required.
  • Staff are trained in privacy, confidentiality and the NDIS Code of Conduct.
  • Data breaches: we have a data breach response plan. If a data breach is likely to result in serious harm we will notify the affected people and the Office of the Australian Information Commissioner (OAIC) as required by the Notifiable Data Breaches scheme, and the NDIS Commission where required.

7. Who we share it with, including overseas

We disclose personal information only for the purposes above, with your consent, or where the law requires or permits it — for example to:

  • NDIS parties: your plan manager, support coordinator, the NDIA and the NDIS Quality and Safeguards Commission, for service delivery, funding, reporting and safeguarding.
  • Health and other providers involved in your supports, with your consent.
  • Your emergency contact, guardian or nominee in an emergency or where they are authorised to act for you.
  • Regulators, courts and law enforcement where the law requires.
  • Our service providers listed below, who may only use the information to provide their service to us.

The service providers we use, and where they process information:

  • Xero (payroll and accounting) — employee onboarding details including name, date of birth, address, contact details, TFN or exemption, tax declaration answers, bank account and superannuation details, for payroll, PAYG and Single Touch Payroll reporting. Xero stores data outside Australia (primarily the United States); see Xero’s privacy notice.
  • Resend (email delivery, United States) — the addresses and content of the emails we send you (enquiry confirmations, invitation and induction links, login codes) and internal notifications to our staff.
  • xAI (AI chat assistant, United States) — chat messages, to generate replies. We instruct the assistant not to ask for sensitive information and we ask you not to enter it.
  • Google Maps Platform (United States) or Photon / OpenStreetMap (Germany) — the address text you type into an address field, to offer suggestions. Only the characters you type are sent; your name is not.
  • Vercel (website hosting; requests may be handled in Australia or the United States) and Neon (database, Sydney region) — infrastructure on which our website and database run.
  • Cloudflare R2 (file storage, Asia-Pacific region) — copies of compliance documents that staff choose to upload during onboarding (for example a Worker Screening clearance or First Aid certificate). Files are stored privately and can only be opened by our administrator, and each access is logged.
  • Synthesia / YouTube (United Kingdom / United States) — the training video embedded on the staff induction page loads from these providers, which see the viewer’s IP address and browser as any website does.
  • Meta (Instagram) — our home page shows our own recent Instagram posts. Nothing about you is sent to Meta by viewing them.

Because some of these providers process information outside Australia (mainly the United States, and Germany for address suggestions), APP 8 applies. Before using an overseas provider we take reasonable steps to ensure it protects information to a standard consistent with the APPs — through its contract, security certifications and privacy commitments — and we limit what is sent to the minimum needed. Health, NDIS, TFN and banking details are never sent to the chat or address-lookup providers.

We do not sell, rent or trade personal information.

8. How long we keep it

  • Participant and service records: at least 7 years after our supports to you end, as required by the NDIS Practice Standards.
  • Employee records (including pay, tax, super and training records): at least 7 years after employment ends, as required by the Fair Work Act and tax law. TFNs are destroyed once no longer required.
  • Onboarding forms that do not lead to employment (for example, withdrawn or duplicate submissions the admin deletes) are permanently purged 30 days after deletion.
  • Website enquiries, eligibility checks and chat callback requests that do not become a service relationship: 24 months.
  • AI chat conversations: 90 days (180 days with a callback request).
  • Invitation and induction links: disabled once used, expired or revoked and purged after 180 days.
  • Website analytics: 24 months (pseudonymous, aggregated).
  • Audit logs of access to personal information are kept for the life of the record they relate to.

When information is no longer needed we delete it permanently or securely destroy it. Automatic deletion of chat, enquiry, analytics and purged-onboarding data runs on a schedule; the remaining records are reviewed under our records management procedure.

9. Access, correction and your other rights

You may at any time:

  • Ask for access to the personal information we hold about you (APP 12). We will respond within 30 days and there is no charge for a reasonable request. We may need to verify your identity, and in limited cases the law allows us to refuse or redact — we will tell you why in writing.
  • Ask us to correct information that is inaccurate, out of date, incomplete or misleading (APP 13). We will correct it or, if we disagree, attach a statement from you to the record.
  • Withdraw a consent you have given (this may limit the supports we can provide, and we may still have to keep records the law requires).
  • Ask us to delete information we are not required to keep.
  • Use an advocate, interpreter or nominee to do any of these for you.

Contact our Privacy Officer using the details at the end of this policy. Employees can access their own onboarding details by asking for a correction link.

10. Privacy complaints

If you think we have mishandled your personal information, please tell us. You will not be disadvantaged for complaining. We will:

  1. acknowledge your complaint within 5 business days and tell you who is handling it;
  2. investigate, keeping you informed;
  3. give you a written response within 30 days (or explain why we need longer and when to expect it); and
  4. fix what went wrong and tell you what we changed.

You can also complain at any time — you don’t have to wait for us — to the Office of the Australian Information Commissioner (OAIC), oaic.gov.au, 1300 363 992, or to the NDIS Quality and Safeguards Commission, ndiscommission.gov.au, 1800 035 544. Our full complaints process, including interpreters and advocates, is on our Complaints & Feedback page.

11. Changes to this policy

We review this policy at least annually and whenever our practices, providers or the law change. The current version is always at keystonecommunitycare.com.au/privacy-policy with the date it was last updated. Significant changes will be highlighted on the page and, for participants and employees, communicated directly.

12. Contact our Privacy Officer

Heidi GriffithsDirector & Privacy Officer
Keystone Community Care (ABN 48 691 121 525)
Email: admin@keystonecommunitycare.com.au
Phone: 0403 886 293
Brisbane & Gold Coast, Queensland

We can provide this policy in Easy Read, large print or audio, or explain it over the phone or through an interpreter — see our Accessibility Statement.