Privacy Policy

Privacy Policy

Travel Buddy Adventures is committed to protecting the personal and health information of guests, families and workers, and to being transparent about what we collect and why. This policy is drawn directly from our internal Policies and Procedures Manual, so it reflects exactly how we actually handle information, not just what sounds good on a website.

What personal information we collect

We collect only what we need to provide safe, appropriate support:

  • Name, date of birth, address, phone and email
  • NDIS number, plan dates and funding details
  • Health information: diagnoses, medication, allergies, seizure or behaviour support plans, mobility and transfer needs
  • Emergency contacts, nominee, guardian or advocate details
  • Communication preferences, cultural and dietary needs
  • Photographs and video, where consent has been given
  • Records of supports delivered, progress notes, incidents and complaints

How we collect, use and share it

How we collect it

Wherever possible, directly from the guest. We may also collect from a family member, carer, nominee, guardian, support coordinator, or a health professional, but only with consent, or where the law requires or permits it, or where it is unreasonable or impractical to collect it directly.

Consent

We explain what we are collecting and why, in a form the guest can understand. Consent is recorded, and a guest can withdraw it at any time by telling us.

Photographs and video are separate. Consent to receive supports is not consent to appear in our marketing. Photography consent is asked for separately, recorded separately, and can be withdrawn at any time without affecting supports.

Who we share it with

We share only what is necessary, and only with:

Your support team

Our workers supporting that guest, on a need-to-know basis, not as general knowledge.

Family, carer or advocate

The guest's nominated family member, carer, nominee or advocate.

Health & emergency services

Health professionals and emergency services where needed for the guest's care or safety.

Plan manager / support coordinator

For billing and planning.

NDIA and NDIS Commission

Where required by law.

We do not sell or disclose guest information for marketing. We do not disclose to overseas recipients.

The systems we use

Guest records, rosters and progress notes are held in our CRM system. Financial records are held in accounting software. Each system is access-controlled, and access is granted by role and removed the day a worker leaves.

How we store and protect it

  • Electronic records are held in secure, access-controlled systems. Access is limited to workers who need it.
  • Paper records are stored securely and are never left in vehicles or unattended.
  • Workers do not discuss guests in public places, on social media, or with anyone outside the support team.
  • Devices used for work are password protected.
  • Access is removed as soon as a worker leaves.

Keeping our systems secure

  • Strong, unique passwords and multi-factor authentication where the system supports it.
  • Devices are password protected and locked when unattended.
  • Guest information is not sent to personal email addresses.
  • Access is reviewed periodically and removed promptly when no longer needed.

Retention

Records are kept for the periods required under the NDIS Rules and other applicable law (a minimum of seven years for guest records) and destroyed securely when no longer required.

If information is lost or exposed

Any suspected breach, such as a lost phone, a misdirected email or an unauthorised access, is reported to the Director immediately. We contain it, assess the risk of serious harm, and where the Notifiable Data Breaches scheme applies, notify the affected people and the Office of the Australian Information Commissioner.

1

Contain

Report to the Director immediately. Change passwords, revoke access, recover or remotely wipe the device.

2

Assess

Identify what information was involved, whose, and whether serious harm is likely.

3

Notify

Where serious harm is likely, notify affected individuals and the Office of the Australian Information Commissioner as required under the Notifiable Data Breaches scheme.

4

Review

Identify how it happened and change the practice or system that allowed it.

Breaches are also recorded as incidents under our Incident Management policy.

Accessing and correcting your information

A guest can ask to see the information we hold about them, and to have it corrected if it is wrong. Ask us in writing, and we will respond within a reasonable period, usually within seven days. We may ask for proof of identity.

Photos and social media

Photos are only ever taken on Travel Buddy Adventures' own devices or accounts, and only where written photography consent is recorded for that guest. They're transferred off any temporary storage and deleted promptly.

  • A guest may decline to be photographed at any time, whatever consent is on file, and that is respected immediately.
  • Photos are never posted by workers to personal social media.

Privacy complaints

If you're concerned about how we've handled your personal information, please contact us using the details above. See our Complaints & Feedback page for how we handle concerns.

If you're not satisfied with our response, you can contact the Office of the Australian Information Commissioner (OAIC) on 1300 363 992, or oaic.gov.au.

NEED HELP? REACH OUT!

If anything on this page is unclear, or you'd like it in another format, please get in touch. We're happy to talk it through.