Privacy Policy - Maple Services

Privacy Policy

We respect your privacy and dignity. This policy explains how we collect, hold, use and disclose personal information, how you can access or correct it, and how to raise a privacy concern.

We aim to handle personal information openly, safely and only for purposes connected with our services, legal obligations and legitimate business operations. We take particular care with health, disability and other sensitive information.

Who this policy applies to

This policy applies to personal information handled by The Maple Group and the group service brand or entity with which you deal, including:

  • Maple Community Services (MCS), including Core, Short Term Accommodation and Supported Independent Living services;
  • The Behaviour Support People (TBSP), operating on behalf of Maple Community Services;
  • Sites Group (SITES);
  • Achora, including plan management services, support coordination services; and
  • other Maple Group businesses that adopt this policy.

In this policy, “we”, “us” and “our” refer to the relevant Maple Group entity and, where information is shared within the group for an authorised purpose, the Maple Group entities involved.

It applies to participants, prospective participants, nominees, guardians and representatives; family members and carers; workers, contractors, volunteers and job applicants; service providers and professional advisers; website and social media users; and other people who interact with us.

Our privacy obligations

We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). We also comply, where applicable, with:

  • the National Disability Insurance Scheme Act 2013 (Cth), NDIS Rules, NDIS Code of Conduct and NDIS Practice Standards;
  • the Notifiable Data Breaches scheme under the Privacy Act;
  • State and Territory health privacy laws, including the Health Records and Information Privacy Act 2002 (NSW) and the Health Records Act 2001 (Vic);
  • the Spam Act 2003 (Cth), Do Not Call Register Act 2006 (Cth) and other laws governing communications; and
  • record-keeping, safeguarding, workplace, taxation and other laws relevant to our services.

If a more protective legal requirement applies to particular information, we will follow that requirement.

What information we collect

The information we collect depends on your relationship with us and the services involved. It may include:

  • identity and contact details, date of birth, address, preferred language and communication needs;
  • NDIS number, plan details, funding arrangements, service agreements, budgets, claims, invoices and payment or bank details;
  • health, disability, medication, allergies, behaviour support, risk, safeguarding, incident and emergency information;
  • support goals, assessments, care and support plans, shift and case notes, progress reports, rosters and service delivery records;
  • information about family members, nominees, guardians, carers, advocates, support coordinators, plan managers and other providers;
  • government identifiers and information from the NDIA, NDIS Quality and Safeguards Commission and other government bodies;
  • photos, audio or video where separately authorised, including for service delivery, incident management or optional marketing;
  • correspondence, enquiries, feedback, complaints and records of interactions with us;
  • employment, contractor, volunteer, screening, qualification, payroll and work health and safety information; and
  • website and technology information such as IP address, device and browser data, cookies, analytics, form submissions and security logs.

Sensitive and health information

Sensitive information includes health and disability information, racial or ethnic origin, religious beliefs, sexual orientation or practices, criminal record and certain professional or association memberships. We collect sensitive information only where it is reasonably necessary for our functions and you consent, or where another legal exception permits or requires collection. Consent must be informed, voluntary, current and specific enough for the proposed handling.

How we collect information

Where reasonable and practicable, we collect personal information directly from you or your authorised representative. We may collect it through enquiries, referrals, intake and assessment, service agreements and consent forms, service delivery, NDIS portals, claims and invoices, phone calls, email, forms, our websites and social media, incident and complaint processes, recruitment and employment processes, and interactions with our workers.

With your consent, or where authorised or required by law, we may collect information from the NDIA, the NDIS Quality and Safeguards Commission, nominees and guardians, family members and carers, support coordinators and plan managers, health professionals, behaviour support practitioners, other providers, government agencies, referees, screening bodies and professional advisers.

If we receive unsolicited personal information, we will determine whether we could lawfully have collected it. If not, and if lawful and reasonable to do so, we will destroy or de-identify it.

Why we collect, use and disclose information

We collect, use and disclose personal information where reasonably necessary to:

  • assess enquiries, referrals, eligibility, risks and service suitability;
  • plan, provide, coordinate, monitor and improve safe, person-centred supports and services;
  • set up and administer service agreements, rosters, plans, budgets, bookings, claims, invoices, reimbursements and payments;
  • access and use NDIS portals where authorised, including to establish plan management services, check funding and process claims;
  • communicate with you and the people you authorise, and provide information in an accessible format;
  • work with the NDIA, NDIS Quality and Safeguards Commission, health professionals and other providers as authorised or required;
  • prepare, implement, review and lodge behaviour support plans, assessments and reports, including restrictive-practice and safeguarding requirements;
  • manage quality, audits, accreditation, complaints, incidents, investigations, risks, safety and regulatory reporting;
  • recruit, screen, engage, train and manage workers, contractors and volunteers;
  • operate, secure, analyse and improve our services, systems and websites; and
  • meet legal, regulatory, contractual, insurance, financial and governance obligations.

We may also use or disclose information for a related secondary purpose you would reasonably expect, where you have consented, or where otherwise permitted or required by law.

Consent, choice and authorised representatives

We seek consent when required, explain the purpose of collection, use or disclosure, and record the scope of consent. You may nominate the people or organisations with whom we may share information, such as other NDIS providers, the NDIA, family members, guardians, carers, representatives or medical practitioners.

You may withdraw or change consent at any time by contacting us. This will not affect handling that has already occurred lawfully. Withdrawing consent may limit the services we can safely or effectively provide, and we will explain any practical consequences.

We will take reasonable steps to confirm that a nominee, guardian, attorney, advocate or other representative has authority to act for you. Where a person cannot provide consent, we will work with the legally authorised decision-maker and involve the person as much as possible, consistent with their will, preferences and rights.

When we disclose information

Depending on the service and the permissions or laws that apply, we may disclose personal information to:

  • the people and organisations you authorise, including representatives, family, carers and advocates;
  • the NDIA, NDIS Quality and Safeguards Commission, Services Australia, State or Territory authorising bodies and other government agencies;
  • support coordinators, plan managers, health professionals, emergency services, behaviour support practitioners and other service providers;
  • independent auditors, quality and accreditation bodies, insurers, legal advisers, accountants and other professional advisers;
  • contractors and technology, records, communications, payment and security providers that support our operations and are required to protect the information; and
  • courts, tribunals, regulators, law-enforcement bodies or other parties where authorised or required by law.

We may disclose information without consent where the law permits or requires it, including to respond to a serious threat to life, health or safety; report or manage abuse, neglect, exploitation, violence, incidents or unauthorised restrictive practices; locate a missing person; take appropriate action regarding suspected unlawful activity or serious misconduct; establish, exercise or defend a legal claim; or comply with a court, tribunal, regulator or government requirement.

We do not sell personal information.

Audits and quality reviews

Participant records may be reviewed by authorised internal reviewers, approved quality auditors or regulators for quality, accreditation, safeguarding or compliance purposes. We limit access to what is reasonably necessary and require confidentiality and secure handling. We seek participant consent for audit access where required, while recognising that some access or disclosure may be authorised or required by law.

Overseas recipients

All personal information is stored in Australia, although we may, from time to time, disclose personal information to, or allow it to be accessed by, service providers or contractors located outside Australia. 

Overseas arrangements may be used to support certain business, administrative, technology, reporting, data processing or operational functions. The nature of the information involved will depend on the service being provided and will be limited to information reasonably necessary for that purpose.

Where personal information is disclosed outside Australia, we take reasonable steps appropriate to the circumstances to require that it is handled consistently with applicable Australian privacy requirements. These steps may include contractual, confidentiality, access, security and incident-management controls. We may remain accountable under the Privacy Act for the handling of personal information by an overseas recipient.

Websites, cookies and third-party platforms

Our websites may use essential cookies, security tools and analytics to operate the sites, remember preferences, understand use and improve content. Some pages may include links, embedded content or social media features provided by third parties. Those third parties may collect information under their own privacy policies. We encourage you to review their policies and browser or device settings.

We will assess any tracking technologies that may collect personal or sensitive information and use them only with appropriate transparency, controls and lawful authority.

Data quality, security and storage

We take reasonable steps to keep personal information accurate, up to date, complete and relevant, having regard to how it is used or disclosed. Please tell us if your details change.

We use physical, technical and organisational safeguards appropriate to the nature and sensitivity of the information. These may include role-based and need-to-know access, confidentiality obligations, worker training, authentication and access controls, encryption where appropriate, secure paper storage, system monitoring, backups, vendor due diligence and incident-response processes.

No system is completely secure. If you send information electronically, there are risks outside our control. Please contact us if you need a more suitable or accessible communication method.

Retention and disposal

We retain personal information only for as long as needed for the purpose for which it was collected and to meet legal, regulatory, insurance and operational requirements. Different records have different retention periods. For example, NDIS incident and complaint records may need to be retained for at least seven years, and longer periods may apply to health, employment, taxation, child-related or legal records.

When information is no longer required and we are not legally required to retain it, we take reasonable steps to securely destroy it or de-identify it. De-identified information may be retained for quality improvement, analysis and reporting where individuals are not reasonably identifiable.

Accessing and correcting your information

You may ask for access to personal information we hold about you and ask us to correct information you believe is inaccurate, out of date, incomplete, irrelevant or misleading. You may also ask us to notify another organisation of a correction where required by law.

We may need to verify your identity and authority before responding. We will respond within a reasonable period, usually within 30 days, or within any shorter period required by applicable law. We generally do not charge for making a request. If a lawful access charge is permitted, we will explain it first and it will not be excessive.

In limited circumstances, the law may permit or require us to refuse access or correction. If we refuse, we will provide written reasons where required, explain available complaint options and, for a correction request, allow you to ask us to associate a statement with the record.

Privacy complaints

You may contact our Privacy Officer if you have a question, want to make a request, or believe we have mishandled personal information. Complaints may be made without fear of disadvantage and you may use an advocate or representative.

We will acknowledge a complaint promptly, investigate it fairly, keep you informed where appropriate and aim to provide an outcome within 30 days. If we need more time, we will explain why and provide an updated timeframe.

If you are not satisfied, you may complain to the Office of the Australian Information Commissioner (OAIC). The OAIC generally expects you to raise the matter with us first and allow 30 days for a response. Depending on the information and location, you may also contact the relevant State or Territory health privacy or complaints regulator. Concerns about the quality or safety of NDIS supports may also be raised with the NDIS Quality and Safeguards Commission.

Data breaches

We have a data breach response process. If personal information is lost, accessed or disclosed without authorisation, we will act promptly to contain the incident, assess the risks and take remedial action.

Where we suspect an eligible data breach, we will conduct a reasonable and expeditious assessment and take reasonable steps to complete it within 30 days. If a breach is likely to result in serious harm and remedial action has not removed that likelihood, we will notify affected individuals and the OAIC as soon as practicable, and any other regulator where required.

Automated decision-making

We do not currently use computer programs to substantially and directly make decisions that significantly affect a person’s rights or interests using their personal information. We may use AI-enabled tools to streamline administrative and operational processes; however, these tools do not independently make decisions that significantly affect a person’s rights or interests. If this practice changes, we will update this policy to explain the kinds of decisions made and the kinds of personal information used, in accordance with applicable law.

Contact us

  • Privacy Officer – The Maple Group
  • Phone: 1800 780 964
  • Email: [email protected]
  • Post: Suite 5.17, 5 Celebration Drive, Bella Vista NSW 2153

You may also use the usual contact details for the service brand with which you deal:

Service

Phone

Email

Maple Community Services

1800 780 964

[email protected]

The Behaviour Support People

1800 780 964

[email protected]

Sites Group

1800 780 980

[email protected]

Achora

1800 780 108

[email protected]

External contacts

  • Office of the Australian Information Commissioner: oaic.gov.au | 1300 363 992
  • NDIS Quality and Safeguards Commission: ndiscommission.gov.au | 1800 035 544

Note

Date updated: June 2023

Date updated: April 2024

Date updated: April 2026

Date updated: August 2026

The Maple Group reserves the right to modify this policy in whole or in part, at any time.