Privacy Policy
Thank you for accessing our Privacy Policy.
We are Autism Actually Speech & Communication (ABN 18 103 032 299), of PO Box 4227, Croydon Hills, Victoria, 3136, Australia. We are a private speech pathology practice under the ownership of Mx Shadia Hancock.
What is this policy about?
We are committed to protecting your privacy in your dealings with us.
This Privacy Policy explains how we manage the personal information we collect, use, and disclose. Privacy is a human right, and we respect the privacy of people with a disability. People with a disability have a right to privacy, including in relation to the collection, use and disclosure of information concerning them and the services they receive.
Like most private health businesses in VIC, we are bound by the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth), the Health Records Act 2001 (Vic), and the Privacy and Data Protection Act 2014 (Vic) (together, the Privacy Laws).
Amongst other things, this means we must:
-
respect and protect the privacy of everyone that receives support and services from us and our workers;
-
manage health information about any people we support and our workers in accordance with privacy laws related to the management of health information; and
-
have this Policy and provide you with this Notice about our privacy policy and procedures to help ensure we (and our workers) understand our obligations.
A portable document format (pdf) version of this policy is available, free of charge, by way of email upon request to our Privacy Officer.
When we refer to "clients" below, we mean former, current, and potential clients, including people who enquire about our services.
In this Policy, we explain:
-
the kinds of personal information that we collect and hold, including recorded audio and visual materials;
-
why we hold this information;
-
who will have access to this information;
-
how we ensure that information is secure;
-
how we use the information;
-
how you can access and amend information held about you; and
-
how to make a complaint if you feel that we have breached our privacy obligations to you.
How we handle your personal information
Our legal obligations
In order to provide you with the health care services you have requested, Autism Actually Speech & Communication (AAS&C) will need to collect and use your personal information. If you provide incomplete or inaccurate information to use, or withhold personal and health information from us, we may not be able to provide you with the services you are seeking.
The information we collect
Privacy is about more than simply meeting our legal obligations. It is also about the way we deliver our services to Neurodivergent and Disabled people. We will work hard to be aware of your privacy needs and preferences and will deliver our services in a way that maintains your personal dignity.
Without limiting what we mean by this commitment, we will:
-
explain and request your permission to perform procedures that involve physical touch or the invasion of your personal space;
-
provide services in a timely manner to prevent your embarrassment and discomfort, such as toilet breaks; and
-
consider your everyday personal needs, such as being able to shower or dress in a private or comfortable space.
We will only collect the information we need for the particular function or activity we are carrying out. We collect information from you that is necessary to provide you with speech pathology services and to manage our professional relationship with you. The information we collect includes your name, date of birth, address, health fund details, and information about your health history and family history. This information is required to assist us with diagnosis and providing therapy.
How we collect information
We will usually collect your health information directly from you, including via telephone, our website, pages on our social media sites, via our client questionnaires, written letters, reports, other documents, emails, interviews, and face-to-face interactions. Sometimes, we may need to collect information about you from a third party, such as a family member or another health service provider.
When we ask for your consent to use your personal information, we will ensure that consent is opt-in, affirmative and freely given. At any time, you can withdraw consent by contacting us to tell us that you are withdrawing your consent.
How we use information
We use your personal information for the purpose for which you gave the information to us. This includes providing speech pathology services to you, managing our relationship with you, and contacting you in relation to matters concerning your care. We may also use your information for other purposes permitted under the Privacy Act 1988.
Who do we collect personal information from?
We collect personal information from clients, or someone authorised to act on the behalf of clients (e.g. their parents, carers or guardians). Wherever practicable, we will ask for the information directly. However, we may need to contact others when relevant to a client’s circumstances (e.g. when working with clients who cannot communicate their needs without the assistance of others). In these cases, we will, when practicable, make you aware of the fact that we have collected this information and the circumstances of the collection.
When you give us information about other people, we rely on you to have obtained their prior consent and tell them of the types of third parties we may provide the information to and why.
Why do we collect personal information?
We collect personal information to deliver, review and improve the products and services that we provide. Generally, these services and products relate to your speech pathology support. If we didn’t collect this information, we wouldn’t be able to carry out our business or provide our products and services to you in accordance with the standards required by law, the NDIS Code, or our professional ethics requirements. If you do not provide the personal information that we request, we would not be able to carry out our business and provide our products or services to you.
More specifically, we need personal information (including health information) to provide clients with personalised evaluations, diagnoses, goal setting, and therapy sessions.
We also need this information:
-
for administrative purposes of managing our business;
-
when necessary, to fulfil our obligations under law, regulation, the NDIS Code and/or our professional ethics rules;
-
for billing management (either directly or through insurers or other compensation agencies);
-
for discussions between workers related to the care of clients;
-
for discussions and other communications, e.g. with your doctors, other health professionals, and others related to your care;
-
for discussions with insurers (including the NDIS and its agents);
-
for any insurance or compensation or other claims or litigation (including threatened litigation); and
-
for security and workplace safety purposes, e.g. to monitor the safety of participants, workers and others.
From time to time, we may use personal information (but not sensitive health information) to provide you with news or offers about our products or services that may be of interest to you. We will ensure that your consent to receive this type of communication from us is opt-in, affirmative and freely given. These products and services will be related to our services described above and will be products and services that we believe will be relevant to you. You have a right, at any time, to tell us that you don’t want to receive this type of material.
Can people access our products and services anonymously?
No. Due to the nature of our services and products, we cannot offer them to people who wish to be anonymous, wish to use a pseudonym or who do not provide us with enough information to properly identify them for the purposes of providing services and products.
Can you access and correct your health information?
We take reasonable steps to ensure that personal information we collect about or from you is accurate, complete, up-to-date and relevant whenever it is used, collected or disclosed.
Subject to the recognised exceptions to access for organisations contained in the Australian Privacy Principles (APP12.3), you have a right to access your information if you wish (subject to any privilege or legal restrictions); and, if it is reasonable and practicable to do so, we will give you access to the information in the manner requested by you. By law, we may charge you a reasonable fee to cover the cost of retrieving and processing the information.
If you believe personal information that we hold about you is inaccurate, out-of-date, incomplete or misleading, we will, on receipt of your request, take steps that are reasonable in the circumstances to correct the information.
Who will see our have access to your personal information?
Your information may be seen or used by people working for or on behalf of us and other service providers including (without limitation):
-
our directors and owners;
-
our professional workers (employed or contracted);
-
our administrative staff (employed or contracted);
-
our third-party professional advisors and service providers, including (without limitation) our lawyers, bookkeepers, accountants, auditors, tax consultants, actuaries, management consultants and IT service providers (including software-as-a-service providers);
-
Medicare, private health insurance providers, our insurers and reinsurers; and
-
the National Disability Insurance Agency and its agents.
We will not rent, sell, trade or otherwise disclose to any other third parties any personal information about you without your consent, or unless we are required to by law (including pursuant to a court or tribunal order), or where a permitted general situation (including a permitted health situation) exists within the meaning of the Privacy Act 1988 (Cth), or if we reasonably believe disclosure is necessary for enforcement-related activities.
Security of your personal information and data retention
We know that you are concerned about your personal information – especially your health information. We will use reasonable endeavours to prevent unauthorised access to, modification of, disclosure, misuse, or loss of that information, except as required by law (e.g. under mandatory reporting laws, and our obligations to report incidences of violence, exploitation, neglect and abuse, and sexual misconduct to the NDIS Quality and Safeguards Commission and the police).
Our directors and staff have reviewed the requirements of the Privacy Laws and our third-party service providers are aware that they are required to comply with the requirements of the Privacy Act 1988 (Cth).
We have data protection measures in place when we store personal information electronically, including password-locked computers. Our hard copy health records are stored in a locked filing cabinet accessible to authorised staff only.
If we no longer need personal information about you for any purpose described above, then we will take reasonable steps to destroy the information or to ensure that such information is de-identified. This obligation is subject to an important exception – we may be required to retain some information (e.g. health, financial or tax records) to comply with our statutory and other legal obligations.
What happens if personal information is disclosed outside Australia?
Given the increasing globalisation of electronic information systems and the businesses of service providers, it is likely that personal information may be disclosed to a person or entity outside Australia (e.g. to a third-party technology-related service provider managed outside Australia). For the same reason, it is not practicable to specify the countries in which such recipients may be located.
If your personal information is disclosed by us to an overseas recipient (e.g. to an insurer or IT-service provider), we will take reasonable steps in the circumstances to ensure the overseas recipient does not breach the Australian Privacy Principles in relation to the information.
Information about newsletters and updates
If you have signed up or otherwise agreed to receive newsletters, emails, or other update services from us, we will use you contact data (including your name and email) to provide those services to you. We tailor information provided to you and we will look at user statistics and preferences. These activities are for marketing and business development purposes.
Information about webinars, seminars and courses
We may offer webinars, seminars and training courses on a range of topics to you and others in the course of our business relationship with them. These are part of our business and business development efforts. If you sign up to a seminar, webinar, or course, we will process your registration data (including your name and email address) to administer access and to prepare and present the webinar, seminar or course (as the case may be). We will also use your registration data for the purposes of our business development.
Information about social media plug-ins
To improve the quality of our services to clients, our website includes social media plug-ins of the large social media networks, including Facebook, LinkedIn, Threads, and YouTube. Upon opening a website on which a social media plug-in is embedded, the social network provider will collect and process information on your visit to our website for its own business purposes. This is not initiated or controlled by us, but is a built-in feature of most social media plug-ins. For further information about these plug-ins and privacy, refer to the social media platform’s privacy policy.
Complaints and asserting your privacy rights
If you believe your privacy has been prejudiced by something we have done or failed to do, you have a legal right to lodge a complaint. If you make a complaint to us, our Privacy Officer will treat it very seriously and will apply our Complaints Management and Resolution System Policy.
To do so, you can contact our Privacy Officer, Shadia Hancock, either by phone, email, or in writing. We will respond to you in writing within 15 days of receiving your complaint.
A breach of your privacy may constitute a breach of the NDIS Code. In this situation, you or anyone can make a complaint to us, or to the NDIS. As suggested in the NDIS Code, we encourage you to contact us first, to see if we can resolve the matter directly.
You also have the right to lodge a complaint with the Office of the Australian Information Commissioner, who is the competent supervisory authority.
A breach of privacy by a professional who works for us (e.g. a health care worker) may also be a breach of their professional code of conduct or code of ethics.
As noted above, you have several statutory rights under privacy laws, including rights to information, access, rectification and the withdrawal of your consent to the collection and use of personal information. If you wish to assert any of these rights, please contact our Privacy Officer using the contact details included above.
How we handle your personal information when you visit our website
This Privacy Policy applies to your use of our website and the use of any of the facilities on our website.
How we collect your information
When you use our website, we do not attempt to identify you as an individual user, and we will not collect personal information about you unless you specifically provide this to us.
Sometimes, we may collect your personal information if you choose to provide this to us via an online form or by email, for example, if you:
• submit a general enquiry via our contacts page;
• register to receive email updates; or
• send a written complaint or enquiry to our Privacy Officer.
When you use our website, our Internet Service Provider (ISP) may record and log for statistical purposes the following information about your visit:
• your computer address;
• your top level name (for example, .com., gov., .org, .au etc.);
• the date and time of your visit;
• the pages and documents you access during your visit; and
• the browser you are using.
Our website management agent may use statistical data collected by our ISP to evaluate the effectiveness of our website.
Cookies
Our websites use cookies to enable, optimise and analyse site operations, as well as to provide content and to allow you to connect to social media. Cookies are small text files that are stored on your computer’s browser directory or program data subfolders when you visit our website. They are stored on your computer for the duration of your visit or for when you re-visit our website later. They allow our website to store or access information from your browser about you, your settings, or your device. They are uses mainly to ensure our website works well and, as a rule, do not contain information that could identity you directly. You can find out more about cookies via: www.allaboutcookies.org.
When you first click on our website, you will get a message that says something like:
“This website uses cookies to enable, optimise and analyse site operations, as well as to provide personalised content and to allow you to connect to social media. By clicking “I agree” you consent to the use of cookies for non-essential functions and the related use of personal data.”
Want more information?
If you have any questions about this Policy or this Notice or have any concerns about the personal information you or others have given us about you, please contact us at info@autismactually.com.au.
More information on the Privacy Act 1988 (Cth) can be found on the website of the Office of the Australian Information Commissioner: https://www.oaic.gov.au/
This Policy and Notice are in addition to, and do not relieve, remove or replace our rights and responsibilities under applicable laws. If there is a conflict between this Policy and this Notice, on the one hand, and an applicable law, on the other hand, the law shall prevail to the extent of any conflict.
Last updated: 3 September 2026.
