Privacy Policy
Privacy Policy
Travel Buddy Adventures is committed to protecting the personal and health information of guests, families and workers, and to being transparent about what we collect and why. This policy is drawn directly from our internal Policies and Procedures Manual, so it reflects exactly how we actually handle information, not just what sounds good on a website.
What personal information we collect
We collect only what we need to provide safe, appropriate support:
- Name, date of birth, address, phone and email
- NDIS number, plan dates and funding details
- Health information: diagnoses, medication, allergies, seizure or behaviour support plans, mobility and transfer needs
- Emergency contacts, nominee, guardian or advocate details
- Communication preferences, cultural and dietary needs
- Photographs and video, where consent has been given
- Records of supports delivered, progress notes, incidents and complaints
How we collect, use and share it
How we collect it
Wherever possible, directly from the guest. We may also collect from a family member, carer, nominee, guardian, support coordinator, or a health professional, but only with consent, or where the law requires or permits it, or where it is unreasonable or impractical to collect it directly.
Consent
We explain what we are collecting and why, in a form the guest can understand. Consent is recorded, and a guest can withdraw it at any time by telling us.
Photographs and video are separate. Consent to receive supports is not consent to appear in our marketing. Photography consent is asked for separately, recorded separately, and can be withdrawn at any time without affecting supports.
Who we share it with
We share only what is necessary, and only with:
Your support team
Our workers supporting that guest, on a need-to-know basis, not as general knowledge.
Family, carer or advocate
The guest's nominated family member, carer, nominee or advocate.
Health & emergency services
Health professionals and emergency services where needed for the guest's care or safety.
Plan manager / support coordinator
For billing and planning.
NDIA and NDIS Commission
Where required by law.
We do not sell or disclose guest information for marketing. We do not disclose to overseas recipients.
The systems we use
Guest records, rosters and progress notes are held in our CRM system. Financial records are held in accounting software. Each system is access-controlled, and access is granted by role and removed the day a worker leaves.
How we store and protect it
- Electronic records are held in secure, access-controlled systems. Access is limited to workers who need it.
- Paper records are stored securely and are never left in vehicles or unattended.
- Workers do not discuss guests in public places, on social media, or with anyone outside the support team.
- Devices used for work are password protected.
- Access is removed as soon as a worker leaves.
Keeping our systems secure
- Strong, unique passwords and multi-factor authentication where the system supports it.
- Devices are password protected and locked when unattended.
- Guest information is not sent to personal email addresses.
- Access is reviewed periodically and removed promptly when no longer needed.
Retention
Records are kept for the periods required under the NDIS Rules and other applicable law (a minimum of seven years for guest records) and destroyed securely when no longer required.
If information is lost or exposed
Any suspected breach, such as a lost phone, a misdirected email or an unauthorised access, is reported to the Director immediately. We contain it, assess the risk of serious harm, and where the Notifiable Data Breaches scheme applies, notify the affected people and the Office of the Australian Information Commissioner.
Contain
Report to the Director immediately. Change passwords, revoke access, recover or remotely wipe the device.
Assess
Identify what information was involved, whose, and whether serious harm is likely.
Notify
Where serious harm is likely, notify affected individuals and the Office of the Australian Information Commissioner as required under the Notifiable Data Breaches scheme.
Review
Identify how it happened and change the practice or system that allowed it.
Breaches are also recorded as incidents under our Incident Management policy.
Accessing and correcting your information
A guest can ask to see the information we hold about them, and to have it corrected if it is wrong. Ask us in writing, and we will respond within a reasonable period, usually within seven days. We may ask for proof of identity.
Photos and social media
Photos are only ever taken on Travel Buddy Adventures' own devices or accounts, and only where written photography consent is recorded for that guest. They're transferred off any temporary storage and deleted promptly.
- A guest may decline to be photographed at any time, whatever consent is on file, and that is respected immediately.
- Photos are never posted by workers to personal social media.
Privacy complaints
If you're concerned about how we've handled your personal information, please contact us using the details above. See our Complaints & Feedback page for how we handle concerns.
If you're not satisfied with our response, you can contact the Office of the Australian Information Commissioner (OAIC) on 1300 363 992, or oaic.gov.au.
Travel Buddy Adventures · ABN 87 678 587 490
Drawn from our Policies and Procedures Manual (Privacy, Consent and Confidentiality · Information Management and Data Breach · Mobile Phone, Photography and Social Media) · Version 1.0 · Approved August 2026
NEED HELP? REACH OUT!
If anything on this page is unclear, or you'd like it in another format, please get in touch. We're happy to talk it through.