This Privacy Policy explains how COS Connect (ABN: 42 979 587 446) (“we”, “us” or “our”) collects, holds, uses, discloses and protects personal information.
We are committed to respecting the privacy, dignity and confidentiality of the people who interact with us. Depending on the nature of our services, this may include NDIS participants, people with disability, clients receiving health or allied health services, family members, carers, nominees, representatives, referrers, workers and other members of the community.
This Privacy Policy applies to personal information collected through our website and through our interactions with you, including by telephone, email, online forms, referral forms, appointments, service delivery and other communications.
Our privacy obligations
We manage personal information in accordance with applicable Australian privacy laws and regulatory requirements.
Depending on the nature of our organisation and the services we provide, these may include the Privacy Act 1988 (Cth), the Australian Privacy Principles, applicable state or territory health privacy and health records legislation, and relevant requirements applying to NDIS providers, healthcare providers and allied health professionals.
Where we are a registered NDIS provider, we also manage participant information in accordance with applicable NDIS legislation, rules and NDIS Practice Standards.
What is personal information?
Personal information is information or an opinion about an identified individual or an individual who is reasonably identifiable.
Some personal information is considered sensitive information and is subject to additional protections. Sensitive information can include health and disability information, racial or ethnic origin, religious beliefs, sexual orientation and other information classified as sensitive under Australian privacy law.
Health information is also a form of sensitive information.
What information may we collect?
The information we collect depends on your relationship with us and the services you are seeking or receiving.
We may collect:
Where relevant to the services we provide, we may also collect:
We may also collect government-related identifiers, such as an NDIS participant number, where it is reasonably necessary and lawful for us to do so. We do not use government-related identifiers as our own identifiers except where permitted by law.
If you apply for employment, contracting, volunteering or another role with us, we may also collect information relevant to that application, including your employment history, qualifications, references, licences, screening information and other information required to assess your suitability.
Sensitive and health information
We recognise that disability, health and clinical information can be highly sensitive.
We only collect sensitive information where it is reasonably necessary for our functions or activities and where we have your consent, unless collection without consent is permitted or required by law.
Where appropriate, we will explain why sensitive information is being collected and how it may be used or disclosed.
We aim to collect only the information reasonably necessary for the relevant purpose.
How we collect information
Where reasonable and practicable, we collect personal information directly from you.
We may collect information when you:
We may also receive personal information from another person or organisation where appropriate, including:
Where another person makes a referral or provides information about you, we will take reasonable steps, where required, to ensure you are aware that we have received the information and understand how it will be handled.
Why we collect and use personal information
We may collect, hold, use and disclose personal information to:
We will not use personal information for an unrelated purpose unless you have consented or the use is otherwise permitted or required by law.
Artificial intelligence and automated tools
We may use artificial intelligence, automation, transcription or similar digital tools to assist with administrative, communication, documentation or service-related tasks.
Where personal or sensitive information is processed using these tools, we take reasonable steps to ensure the technology is appropriate for its intended purpose and that information is handled in accordance with applicable privacy obligations.
This may include considering how information is collected, stored, processed and accessed, the privacy and security practices of technology providers and whether human oversight is appropriate.
Where consent is required for a particular use of personal or sensitive information, we will seek appropriate consent.
We do not rely solely on automated systems to make significant decisions about an individual where human review is appropriate or required.
Where a public-facing tool, such as an automated chatbot, uses artificial intelligence, we aim to make this clear to users where appropriate.
NDIS participant information
Where we provide NDIS supports or services, participant information will be managed with regard to applicable NDIS obligations.
Where required, participants will be informed about:
Where we are a registered NDIS provider, we maintain information-management practices appropriate to the nature, size and complexity of our organisation and the supports we provide.
Disclosure of personal information
We may disclose personal information where reasonably necessary for the purposes described in this Privacy Policy.
Depending on the circumstances, this may include disclosure to:
We take reasonable steps to limit disclosures to information necessary for the relevant purpose.
We may also disclose information with your consent.
Serious threats and emergencies
In limited circumstances, privacy laws permit information to be collected, used or disclosed without consent.
For example, this may occur where we reasonably believe it is necessary to lessen or prevent a serious threat to the life, health or safety of an individual or to public health or safety, or where disclosure is otherwise required or authorised by law.
Anonymity and pseudonyms
Where lawful and practicable, you may choose to interact with us anonymously or using a pseudonym.
However, there may be circumstances where we need to know your identity to provide services, process an NDIS referral, maintain appropriate records, meet legal requirements or protect your safety or the safety of others.
Technology and overseas storage
We may use third-party technology, communications, cloud-storage, artificial intelligence, automation, software and other service providers in operating our organisation.
Some providers may store or process information using infrastructure located outside Australia.
Where Australian privacy law applies to an overseas disclosure of personal information, we will take reasonable steps required by law in relation to that disclosure.
The location of technology infrastructure can change from time to time as service providers update their systems and operations.
Website, cookies and analytics
Our website may use cookies and similar technologies to operate correctly, remember preferences, understand website usage, improve functionality and monitor performance.
Information collected through these technologies may include:
Some website services may be provided by third parties, such as analytics, website hosting, embedded content, maps, forms, chat tools or other digital services.
You can usually manage or disable cookies through your browser settings. Disabling certain cookies may affect website functionality.
Direct marketing
We may send information about our services where permitted by law.
We will comply with applicable privacy and spam requirements when sending commercial electronic messages.
Where consent is required, we will seek appropriate consent before sending marketing communications.
You can ask us to stop sending marketing communications at any time using the unsubscribe method provided or by contacting us.
We do not use sensitive information for direct marketing unless this is permitted by law and appropriate consent has been obtained where required.
Security of personal information
We take reasonable steps to protect personal information from misuse, interference, loss, unauthorised access, modification and disclosure.
Depending on the circumstances, these measures may include:
No method of electronic transmission or storage can be guaranteed to be completely secure. We therefore continually consider appropriate safeguards having regard to the nature and sensitivity of the information we hold.
Retention and disposal
We retain personal information for as long as reasonably necessary for the purpose for which it was collected and to satisfy applicable legal, regulatory, professional, insurance, funding and record-keeping obligations.
Retention periods may differ depending on the type of information and the services provided.
When information is no longer required to be retained, we take reasonable steps to securely destroy or de-identify it where required by law.
Data breaches
We maintain processes for responding to actual or suspected data breaches.
Where the Notifiable Data Breaches scheme or another applicable notification requirement applies, we will assess the incident and notify affected individuals and the relevant regulator where required by law.
Accessing your information
You may request access to personal information we hold about you.
We will respond to access requests in accordance with applicable law.
In some circumstances, access may be limited or refused where permitted by law. If this occurs, we will generally explain the reason unless we are legally prevented from doing so.
We may need to verify your identity before providing access to personal information.
Correcting your information
We take reasonable steps to ensure personal information we hold is accurate, current, complete and relevant.
You can contact us if you believe information we hold about you is inaccurate, out of date, incomplete, irrelevant or misleading.
Where required, we will take reasonable steps to correct the information.
Consent and withdrawal of consent
Where we rely on your consent to collect, use or disclose information, you may ask to withdraw or amend that consent.
There may be circumstances where withdrawing consent affects our ability to provide particular services.
Withdrawal of consent does not necessarily require us to delete information that we are legally required or permitted to retain.
Privacy complaints
If you have concerns about how we have handled your personal information, please contact us using the contact details published on our website.
We will take reasonable steps to:
If your privacy complaint is not resolved to your satisfaction and the Privacy Act applies, you may be entitled to make a complaint to the Office of the Australian Information Commissioner.
Where a complaint relates to NDIS supports or services, you may also have the right to contact the NDIS Quality and Safeguards Commission.
Depending on the services involved, other state or territory health complaints bodies, professional regulators or oversight organisations may also be available.
Third-party websites
Our website may contain links to websites operated by other organisations.
We are not responsible for the privacy practices, content or security of third-party websites. We recommend reviewing the privacy policies of those websites before providing personal information.
Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes to our practices, services, technology or legal obligations.
The current version will be published on our website.
Contacting us
If you have questions about this Privacy Policy, wish to request access to or correction of your information, want to withdraw a consent, or wish to make a privacy complaint, please contact us using the contact details published on our website.
If you need help understanding this Privacy Policy or would like information provided in another format, please contact us.