Privacy Policy
Empower and Shine Pty Ltd | ABN 36 407 809 790 | NDIS 4050138437 | Cranbourne VIC 3977 | Last Updated: July 2026
1. Purpose of this Policy
Empower and Shine Pty Ltd (“Empower and Shine”, “we”, “us”, “our”) is committed to protecting the privacy, confidentiality, and security of all personal information we collect. As a registered NDIS provider built on family partnership and trust, we take our privacy obligations seriously.
This Privacy Policy explains how we collect, store, use, and disclose personal, sensitive, and health information in accordance with:
- Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs)
- National Disability Insurance Scheme Act 2013 (Cth) and the NDIS Practice Standards
- Health Records Act 2001 (Vic) — as we operate in Victoria
- NDIS Quality and Safeguards Commission requirements
- Other applicable Commonwealth and State legislation
By accessing our services, website, or communicating with us, you consent to the terms outlined in this Privacy Policy. We encourage you to read this policy carefully and contact us if you have any questions. This Privacy Policy works alongside our Terms and Conditions.
2. What Personal Information We Collect
We may collect the following types of personal information:
2.1 General Personal Information
- Full name and contact details (address, phone, email)
- Date of birth and age
- Residential address
- Emergency contact and next-of-kin details
- Gender, cultural identity, and language spoken
- NDIS participant number, plan details, and funding information
- Plan management type (self-managed, plan-managed, or NDIA-managed)
- Medicare number (where applicable)
2.2 Sensitive and Health Information
- Disability type and support needs
- Medical history, diagnoses, allergies, and medications
- Clinical reports, functional assessments, and behaviour support information
- GP, specialist, and allied health professional details
- Individualised achievement plans and progress records
- Incident reports and care notes
- Support needs, mobility, and safety assessments
- Photographs or videos (with your explicit consent)
2.3 Administrative and Service Data
- Service agreements and consent forms
- Shift notes, progress records, and case files
- Banking details (where required for billing or refunds)
- Invoices, billing, and payment history
- Records of phone, email, SMS, and in-person communications
2.4 Website and Digital Data
- IP address and browser/device information
- Website interactions and online form submissions
- Cookies and similar tracking technologies (where you have consented)
3. How We Collect Information
We collect personal information through the following means:
- Directly from you — in person, by phone, email, SMS, or through our website contact forms
- From your authorised representative — parent, guardian, nominee, plan manager, or family member acting on your behalf
- From health professionals and providers — GPs, occupational therapists, support coordinators, and other allied health practitioners (with your consent)
- From government agencies — the NDIA, NDIS Quality and Safeguards Commission, Medicare, Centrelink, or Services Australia (where authorised)
- From referral sources — healthcare providers, support coordinators, or other NDIS providers who refer you to our services
We only collect information that is reasonably necessary for us to deliver our services, meet our legal obligations, or improve your experience with Empower and Shine.
4. Why We Collect Your Information
We collect personal and health information for the following purposes:
- To provide premium Supported Independent Living (SIL), Respite, and Community Access services under your NDIS plan
- To assess your support needs, goals, and preferences for personalised service delivery
- To develop, implement, and review Individualised Achievement Plans and progress reports
- To communicate with you, your family, and your support network about your services
- To meet our legal, regulatory, and NDIS reporting obligations
- To coordinate services with other providers involved in your care (with your consent)
- To process payments, claims, and maintain financial records
- To maintain accurate records for compliance, auditing, and quality improvement
- To respond to feedback, complaints, and enquiries
- To ensure the safety and wellbeing of participants, staff, and visitors
- To improve our service delivery, quality standards, and participant experience
We will not use your information for any purpose unrelated to the above unless required or permitted by law.
5. How We Use Your Information
5.1 Service Delivery
Your personal and health information is used by our team to deliver safe, personalised, and high-quality supports. This includes creating support plans, coordinating shifts, communicating with your family, and tracking your progress toward achievement goals.
5.2 NDIS Claims and Payments
We use your NDIS plan information and participant details to claim payment for services delivered, in accordance with your chosen payment method (self-managed, plan-managed, or NDIA-managed) and the NDIS Pricing Arrangements.
5.3 Communication
We use your contact information to keep you informed about your services, appointments, progress updates, and any changes to our policies or arrangements. We may also send you information about our services where you have opted in to receive such communications.
5.4 Quality and Compliance
We use information to conduct quality assurance activities, internal audits, and continuous improvement initiatives. De-identified data may be used for service evaluation and reporting purposes.
6. Disclosure of Information
6.1 Who We May Share Information With
We may disclose your personal information to the following parties:
- Our staff and support workers — who directly deliver services to you, on a need-to-know basis
- Your family, guardian, nominee, or authorised representative — as directed by you
- Healthcare providers — GPs, occupational therapists, allied health professionals, and hospitals involved in your care (with your consent)
- The National Disability Insurance Agency (NDIA) — for the purpose of NDIS plan management, payment claims, and compliance reporting
- The NDIS Quality and Safeguards Commission — for incident reporting, complaints handling, and regulatory compliance
- Other service providers — involved in coordinating your supports (with your consent)
- Professional advisers — including lawyers, auditors, and insurers, where reasonably required
- Government agencies — where required or authorised by law, including Medicare, Centrelink, and emergency services
- IT and administrative service providers — who assist us with secure data storage, communications, and business operations
6.2 When We Will Not Share Your Information
We will not:
- Sell, rent, or trade your personal information to any third party
- Use your information for marketing or commercial gain beyond our direct services
- Share your information without your consent unless required or permitted by law
6.3 Disclosure Without Consent
We may disclose your information without your consent where:
- Required or authorised by law (e.g., court order, statutory obligation)
- Necessary to lessen or prevent a serious threat to the life, health, or safety of any individual
- Required for the investigation of unlawful activity or serious misconduct
- Forming part of a mandatory reportable incident or complaints process under the NDIS Commission
6.4 Overseas Disclosure
We primarily store and process data within Australia. We do not routinely disclose personal information to overseas recipients. Where third-party service providers may store data on servers located overseas, we take reasonable steps to ensure they comply with obligations equivalent to the Australian Privacy Principles.
7. Data Storage and Security
7.1 How We Store Your Information
Your information may be stored in:
- Secure digital systems, including encrypted cloud-based platforms compliant with Australian privacy requirements
- NDIS-compliant record management software
- Locked physical files (where applicable)
7.2 Security Measures
We implement a combination of technical, physical, and administrative safeguards, including:
- Password-protected systems with multi-factor authentication
- Encrypted devices and secure network infrastructure
- Staff confidentiality agreements and regular privacy training
- Role-based access controls limiting staff access to information on a need-to-know basis
- Secure disposal or de-identification of records when no longer required
- Regular review of our data handling practices
While we strive to protect your personal information, no method of transmission or storage is 100% secure. We will notify you and the relevant authorities if a data breach occurs that is likely to result in serious harm.
7.3 Data Breach Notification
In accordance with the Privacy Act 1988 (Cth) and the Notifiable Data Breaches (NDB) scheme, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) in the event of a data breach that is likely to result in serious harm.
8. Data Retention
We retain your personal information for as long as necessary to fulfil the purposes outlined in this Privacy Policy or as required by law. Specifically:
- NDIS service records — retained for a minimum of 7 years after the last service date, as required by the NDIS Quality and Safeguards Commission
- Health information — retained for 7 years from the date of last service (or until the participant turns 25 if younger than 18, whichever is later), in accordance with Victorian health records legislation
- Financial records — retained for 7 years as required by the Corporations Act 2001 (Cth)
When personal information is no longer needed, we take reasonable steps to destroy or de-identify it securely.
9. Your Privacy Rights
Under the Australian Privacy Principles, you have the following rights:
9.1 Access to Your Information
You have the right to request access to the personal information we hold about you. We will respond to your request within a reasonable timeframe (usually within 30 days). We may refuse access in certain circumstances permitted by law, and where we do, we will explain our reasons in writing.
9.2 Correction of Your Information
You have the right to request correction of any personal information we hold that is inaccurate, incomplete, misleading, or out of date. Please contact us promptly if your details change so we can keep our records up to date.
9.3 Withdrawal of Consent
You may withdraw your consent for us to collect, use, or disclose your personal information at any time, subject to legal or contractual obligations. Please note that withdrawing consent may affect our ability to provide services to you.
9.4 Anonymity and Pseudonymity
Where practicable, you may interact with us anonymously or using a pseudonym. However, due to the nature of our NDIS services and our legal obligations, it is generally not possible to provide services without collecting your personal information.
9.5 Complaints
You have the right to lodge a complaint if you believe your privacy has been breached. See Section 13 for details.
9.6 How to Exercise Your Rights
To exercise any of the above rights, please contact our Privacy Officer using the details in Section 15. We will not charge you for making a request, although we may charge a reasonable fee for providing access to complex or voluminous records.
10. Cookies and Website Data
10.1 Website Analytics
Our website at empowerandshine.com.au may collect basic browsing information through cookies and similar technologies for:
- Website analytics and performance improvement
- User experience enhancement
- Processing online form submissions and enquiries
10.2 Managing Cookies
You may disable cookies through your browser settings. However, please note that some features of the website may not function properly as a result.
10.3 Third-Party Links
Our website may contain links to third-party websites, including social media platforms and external resources (e.g., NDIS website, Facebook, Instagram). We are not responsible for the privacy practices of those third parties, and we encourage you to review their privacy policies before engaging with them.
11. Direct Marketing
We may use your contact information to send you information about our services, service updates, or community events that we believe may be of interest to you. You can opt out of receiving marketing communications at any time by:
- Using the unsubscribe link in our emails
- Contacting us directly using the details in Section 15
We will not use sensitive information for direct marketing purposes without your explicit consent.
12. Mandatory Notifications
As a registered NDIS provider, Empower and Shine is required to comply with the NDIS (Incident Management and Reportable Incidents) Rules 2018. In certain circumstances, we may be required to report information about incidents affecting your safety, health, or wellbeing to the NDIS Quality and Safeguards Commission. This may include the disclosure of personal or health information as part of mandatory reporting obligations.
Where possible, we will discuss any mandatory reporting with you before information is disclosed.
13. Complaints and Dispute Resolution
13.1 Our Commitment
If you believe we have breached your privacy or mishandled your personal information, please contact us immediately. We take all privacy concerns seriously and are committed to resolving them promptly, fairly, and confidentially.
As a family-run provider, Mohan and Karaaj Vig (Founders) are personally involved in resolving any concerns raised by the families we support.
13.2 How to Make a Privacy Complaint
To lodge a privacy complaint, please contact our Privacy Officer:
- Email: support@empowerandshine.com.au
- Phone: 0449 121 812
- In Person: Speak with any Empower and Shine team member
- Mail: 7 Ferndown Drive, Cranbourne VIC 3977
We will acknowledge your complaint within 2 business days and work to resolve it within a reasonable timeframe. You will not be victimised or suffer negative treatment for making a complaint.
13.3 External Complaint Options
If you are not satisfied with our response to your privacy concern, you may escalate to:
- Office of the Australian Information Commissioner (OAIC)
Phone: 1300 363 992 | Website: www.oaic.gov.au | Email: enquiries@oaic.gov.au
Address: GPO Box 5218, Sydney NSW 2001 - NDIS Quality and Safeguards Commission
Phone: 1800 035 544 | Website: www.ndiscommission.gov.au - Health Complaints Commissioner (Victoria)
Phone: 1300 582 113 | Website: www.hcc.vic.gov.au
14. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or operational needs. Updated versions will be published on our website at empowerandshine.com.au with an updated “Last Updated” date.
Where significant changes are made that affect how we handle your personal information, we will notify you directly. We encourage you to review this policy periodically.
15. Contact Information
If you have any questions about this Privacy Policy, wish to access or correct your personal information, or would like a copy of this policy in an alternative format (e.g., hard copy, large print), please contact us:
- Business Name: Empower and Shine Pty Ltd
- ABN: 36 407 809 790
- NDIS Provider Number: 4050138437
- Website: empowerandshine.com.au
- Address: 7 Ferndown Drive, Cranbourne VIC 3977
- Phone: 0449 121 812
- Email: support@empowerandshine.com.au
- Privacy Officer: Mohan Vig (Founder)
Commitment Statement: At Empower and Shine, your privacy matters to us. As a family-run premium NDIS provider, we treat your personal information with the same care and respect we would want for our own family. We are always here to discuss any questions or concerns you may have.