Privacy Policy

Introduction

VANTIS respects privacy and handles personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). This policy explains how we collect, use, disclose, protect and manage personal information.

1. Collection of Personal Information

1.1. We collect only personal information reasonably necessary for our functions and services. This may include identity and contact details, referral relationships, service needs, funding-management information, correspondence and service-delivery records.

1.2. We may collect information through:

  • Referral, contact and service agreement request forms

  • Direct conversations and correspondence with participants, nominees, families and referrers

  • Records created while coordinating or delivering supports

  • Website cookies and analytics where enabled

1.3. We may collect health, disability or other sensitive information only where reasonably necessary and with consent or another lawful basis. Please do not send NDIS numbers or detailed records through public forms unless VANTIS requests them through a secure channel.

2. Use of Personal Information

2.1. We use personal information for purposes including:

  • Assessing referrals, suitability, capacity and service requests

  • Delivering, coordinating and documenting agreed supports

  • Communicating with participants, authorised representatives and relevant support partners

  • Managing service agreements, billing and legal or regulatory obligations

  • Improving service quality, safeguarding and website functionality

2.2. We use and disclose information for the purpose for which it was collected, a related purpose you would reasonably expect, with consent, or where authorised or required by law.

3. Disclosure of Personal Information

3.1. We may disclose personal information to:

  • Workers and service providers who need the information to perform authorised functions, including secure IT and hosting providers

  • A participant’s authorised representatives, support partners, regulators or authorities where consented, reasonably expected or required by law

3.2. We do not sell, rent or trade personal information for third-party marketing.

3.3. We require external service providers to handle information only for authorised purposes and with appropriate privacy and security safeguards.

We limit disclosures to information reasonably necessary for the authorised purpose.

4. Data Security

4.1. We take reasonable technical, physical and organisational steps to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure.

4.2. No method of storage or transmission is completely secure. Suspected data breaches are assessed and managed under applicable requirements, including the Notifiable Data Breaches scheme where relevant.

5. Cookies and Analytics

5.1. Our website may use necessary and analytics cookies to operate correctly and understand how visitors use the site.

5.2. You can manage cookies through your browser settings, although disabling some cookies may affect website functionality.

5.3. Where analytics tools are enabled, we use aggregated website-use information to understand performance and improve accessibility, content and user experience.

6. Access and Correction

6.1. You may request access to personal information we hold about you and ask us to correct information that is inaccurate, out of date, incomplete, irrelevant or misleading.

6.2. To request access or correction, contact us using the details below. We may need to verify your identity before acting on the request.

7. Retention of Information

7.1. We retain personal information only for as long as reasonably necessary for service delivery and our legal, professional and NDIS-related obligations.

7.2. When information is no longer required, we take reasonable steps to securely destroy or de-identify it.

8. Cross-Border Data Transfers

8.1. Some technology or service providers may store or process information outside Australia. Where an overseas disclosure occurs, we take reasonable steps required by the APPs to protect the information.

9. Complaints

9.1. If you believe VANTIS has mishandled personal information, please contact us using the details below so we can investigate and respond.

9.2. We will acknowledge and assess privacy complaints within a reasonable time. If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC).

10. Updates to this Policy

10.1. We may update this policy when our practices or legal obligations change. The current version will be published on this website.

Last updated: 8 September 2026.

11. Contact Us

If you have questions, wish to access or correct information, or want to make a privacy complaint, contact:

VANTIS | Email: admin@vantis.support