Privacy Policy
What we collect, why we collect it, who we share it with, and what you can do about it.
Review before publishing. This is Lionheart’s Privacy Statement brought up to date and put on the website. The wording is largely as approved in 2021; the additions are marked below. It should be checked by someone qualified before it goes live, and it needs a version number and review date.
Lionheart Inclusion, Training & Support Services is committed to protecting the privacy of an individual’s personal information. This sets out how we aim to protect the privacy of your personal information, your rights in relation to the personal information we manage, and the way we collect, use and disclose it.
In handling your personal information we comply with the Privacy Act 1988 (Cth) and the thirteen Australian Privacy Principles. Because we deliver disability and aged care supports, much of what we hold is health information, which the Act treats as sensitive information and protects more strictly.
We have policies and procedures in place to ensure that:
- personal information is managed in an open and transparent way
- the privacy of personal information of participants and staff is protected
- we collect and handle personal information fairly
- information we collect is used and disclosed for legally permitted purposes only
- we regulate access to and correction of personal information
- we maintain confidentiality through appropriate storage and security
What we collect
Personal information is collected to provide care and services. It may include your:
- name, address, telephone number and email address
- date of birth and gender
- advocate or emergency contact’s telephone number and email
- health information
- diversity status (ethnicity, lifestyle preferences)
- NDIS plan or Support at Home details, including dates and how your funding is managed
How we collect it
Your personal information may be collected from you, your family members or significant others, your advocate, or your doctor and other service providers.
We will collect personal information directly from you unless we have your consent to collect it from someone else, we are required or authorised by law to do so, or it is unreasonable or impractical to do so.
You can withdraw your consent at any time by contacting us, though you should be aware this may affect our capacity to provide services. If that is the case, we will tell you plainly.
Information you give us through this website
Added 2026 — this section did not exist in the 2021 statement.
Our referral form, meet-and-greet form and coordinator form are hosted by Snapforms, an Australian provider. What you type into them comes to us by email and is then stored with your other records.
The referral form asks for health information. Please only include what you are comfortable sharing at that stage — if you would rather tell us over the phone, call (07) 4910 8777.
Analytics, cookies and things loaded from other companies
We do not run analytics on this site. There is no Google Analytics, no advertising pixel and no similar tool of ours, so we cannot see who you are or which pages you looked at.
Some parts of the site are loaded from other companies. When that happens, your browser contacts them directly and they receive your IP address — we cannot prevent that and it is not something we see:
- Google Fonts — the typefaces, on every page.
- Google Maps — the map on our Contact page. Our address is always written out as text beside it, so you never need to load the map.
- Meta (Facebook) — our Facebook feed on the What we’re up to page. This one is worth being specific about, because Meta does use what it collects for its own purposes, including advertising, and it can do so whether or not you have a Facebook account.
Added August 2026 when the Facebook feed was added to the site.
The Facebook feed is on that one page and nowhere else, and it only loads if you scroll far enough down the page to reach it. Open the page and don’t scroll, and nothing is sent to Meta. No other page on this site — including every page about supports, nursing and counselling — loads anything from Facebook. That was a deliberate choice: which service pages you read is nobody’s business but yours.
If you would rather have nothing to do with it, don’t open that page, or read the same posts on Facebook directly, or ring us and ask what’s coming up.
Our booking page is hosted by Microsoft and our forms by Snapforms. Those receive only what you choose to type in and submit.
Why we collect it, and who we share it with
Personal information is collected to provide care and services. We may disclose your personal and health information, for that purpose, to:
- service providers who assist us in providing care and services, medical practitioners, and external health agencies such as the ambulance service and hospitals
- the National Disability Insurance Scheme and other relevant government organisations
- a person you have nominated as your advocate — a parent, child, sibling, spouse, relative, member of your household, guardian, enduring power of attorney, or emergency contact — provided they are at least 18 years of age
We may not use or disclose personal information for any other purpose unless you have consented; the purpose is related to providing care and services and you would reasonably expect the disclosure; we believe on reasonable grounds that it is necessary to prevent or lessen a serious and imminent threat to life, health or safety, or a serious threat to public health or safety; or we suspect unlawful activity and disclosure is required or authorised by law.
We do not sell your information, and we do not use it for marketing.
Overseas disclosure
Updated 2026 — the 2021 statement said simply that nothing went overseas. That was written before we used cloud software, so it needed to be more precise.
We do not send your care records, health information or anything you tell us overseas, and we do not give any overseas organisation information about you to use for its own purposes.
Like most Australian businesses, we use established software to run Lionheart: Microsoft 365 and SharePoint for records and email, Employment Hero for employment records, and DCIQ for incidents and feedback. These providers handle information only on our instructions and only for our purposes — they are not free to use it for their own. Some large providers operate data centres in more than one country.
Made more precise in August 2026, when the Facebook feed was added. The paragraph below is the one exception to the statement above, and we would rather spell it out than leave a promise that isn’t quite true.
The one exception is browsing this website. The What we’re up to page shows our Facebook feed, and if you scroll down to it your browser contacts Meta, which is based in the United States. Meta receives your IP address and does use it for its own purposes. That is a disclosure to an overseas recipient, so we name it here rather than rely on the general statement above. It happens on that page only, only if you scroll to the feed, and it involves nothing you have told us — no name, no contact details, no health information.
If you want to know where your own information is stored, ask our Privacy Officer and we will tell you.
Keeping it safe
We take all reasonable steps to ensure the personal information we hold is protected against misuse, loss, unauthorised access, modification or disclosure. We hold personal information in both hard copy and electronic form, in secure databases on secure premises and on secure cloud-based technology, accessible only by authorised staff.
Seeing what we hold, and correcting it
Under the Privacy Act you have a right to access the personal information we hold about you. If at any time you would like to see it, or to correct it, contact our Privacy Officer using the details below.
To obtain access you will need to provide proof of identity. We will take all reasonable steps to provide access within seven days of your request. There is no charge.
Added 2026 — correction was not covered in the 2021 statement.
If you tell us something we hold is wrong, out of date or misleading, we will correct it. If we disagree, we will tell you why in writing and note your view on the record.
Employees and volunteers
Records of current and past employees relating to the employment relationship are managed in accordance with workplace laws. Privacy laws may apply to employee personal information where it is used for something unrelated to the employment relationship. Personal information we hold about volunteers is managed in accordance with the Privacy Act.
If something goes wrong with your information
If your personal information is lost, stolen, or subject to unauthorised access or disclosure, we implement our Management of Data Breach Policy and Procedure.
Added 2026 — the notification obligation was not covered in the 2021 statement.
Where a breach is likely to cause you serious harm, we are required under the Notifiable Data Breaches scheme to tell you and to notify the Office of the Australian Information Commissioner. We will tell you what happened, what information was involved, and what you can do about it.
Complaints about privacy
Complaints about privacy can be lodged through our complaints process. At all times, privacy complaints will:
- be treated seriously
- be dealt with as promptly as possible
- be dealt with confidentially
- not affect your existing services or arrangements with us
You will be told the outcome once the investigation is complete.
Added 2026 — the external escalation path is required by APP 1.4(e) and was missing.
If you are not satisfied with how we handle it, you can complain to the Office of the Australian Information Commissioner on 1300 363 992 or at oaic.gov.au. You do not need our permission, and you can go to them at any time.
For complaints about our services rather than your privacy, see Contact, or contact the NDIS Quality and Safeguards Commission on 1800 035 544.
Our Privacy Officer
Added 2026 — the 2021 statement said “contact us” without giving any details, which meant nobody could actually exercise these rights.
Brett Muggeridge
DIRECTOR AND PRIVACY OFFICER
2/2 Boowan Court, Callemondah QLD 4680
brett@lionheart.care
(07) 4910 8777
Write to Brett about anything to do with your personal information — seeing what we hold, correcting it, or making a privacy complaint. If you would rather not put it in writing, ring the office and ask for him.
Version 2.1 · Issued 7 August 2026 · Next review due August 2027
Supersedes Version 2.0 of 5 August 2026 and Lionheart’s Privacy Statement of September 2021. Reviewed at least annually, and whenever our systems or the law change.
Changed in 2.1: the Facebook feed was added to the website, so the third-party and overseas disclosure sections now name Meta specifically.
Owner: Brett Muggeridge, Privacy Officer.