Privacy Policy

Section 34 Co — NDIS Document Preparation Service

⚠ PRE-LEGAL-REVIEW DRAFT — pending compliance specialist review before final adoption

This policy has been prepared based on the Privacy Act 1988 (Cth), Australian Privacy Principles, and NSW Health Records and Information Privacy Act 2002, and reflects Section 34 Co's current privacy architecture. It must be reviewed by a privacy compliance specialist and approved before final publication. Items marked [VERIFY] require manual completion before this policy can be finalised.

Effective date: [VERIFY — pending compliance specialist review, est. June 2026]  |  Version: 2.0  |  Section 34 Co (ABN 92 721 361 463), Sydney NSW, Australia.  |  Supersedes: Version 1.0 published 29 April 2026.

1. About This Policy

This privacy policy explains how Section 34 Co (ABN 92 721 361 463) collects, holds, uses, discloses, and protects personal information when providing NDIS submission preparation services.

We are bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). Because we hold health information about NDIS participants, we are also bound by state health records legislation, including the Health Records and Information Privacy Act 2002 (NSW) where applicable to our operations.

This policy explains: what personal information we collect and why; how we use and disclose your information; how we store and protect your information; how long we keep your information; your rights, including access and correction; and how to make a complaint.

If you have questions about this policy or our handling of your information, contact us at hello@section34.com.au.

2. Who We Are

Section 34 Co provides NDIS submission preparation services to NDIS participants who self-manage or plan-manage their funding, and to support coordinators who outsource submission preparation work to us.

Important: We are not a registered NDIS provider. We do not deliver NDIS-funded supports. We prepare written submissions that participants (and their authorised representatives) provide to the NDIA, the NDIS Quality and Safeguards Commission, or the Administrative Review Tribunal (ART). Our role is document preparation. Decisions about what supports to request, whether to appeal, and how to instruct us remain with you or your authorised representative.

3. What Information We Collect

3.1 Identifying information

Your full name, date of birth, NDIS number, contact details (phone, email, postal address), and similar identifiers needed to prepare your submission.

3.2 Sensitive information — health and disability

Clinical assessments, medical reports, allied health reports, treatment histories, behavioural information, support needs documentation, and other information about your health or disability. This is sensitive information under the Privacy Act and requires your explicit consent to collect, use, and disclose.

3.3 Financial and legal information

Information about your NDIS plan budget, current and previous funding amounts, prior NDIA decisions, ART proceedings, legal correspondence, and quotes from service providers.

3.4 Information about third parties

Where your submission references clinicians, support workers, family members, advocates, or others, we may collect personal information about those people. We treat this information under the same protections.

3.5 Service usage information

Information about how you interact with our services, including your enquiries, intake form submissions, payment records, and engagement progress.

We only collect information that is reasonably necessary for, or directly related to, providing our services.

4. How We Collect Information

Wherever practical, we collect information directly from you.

5. Why We Collect Your Information

We collect your information to:

We will not use your information for any other purpose without your consent, unless an exception under the Privacy Act applies (for example, a legal obligation, or a serious threat to life, health, or safety).

6. Sensitive Information — Explicit Consent

Under the Australian Privacy Principles, we may only collect, use, or disclose your health and disability information with your explicit consent, unless a specific exception applies.

By engaging our services and providing health or disability information, you give us explicit consent to collect, use, and disclose that information for the purposes set out in this policy.

You can withdraw your consent at any time by contacting us at hello@section34.com.au. Withdrawing consent may mean we cannot continue to provide our services. We will explain the consequences before acting on a withdrawal of consent.

7. How We Use and Disclose Your Information

7.1 Use

We use your information to provide the services you have engaged us for, including document preparation, communication about your engagement, and verification of accuracy.

7.2 AI processing — with de-identification

Parts of our document preparation use AI language models. Before any of your information is sent to AI services, identifying information is removed through our de-identification system. AI services do not receive your real name, date of birth, NDIS number, address, or other direct identifiers.

AI providers contracted by us do not train AI models on your information.

7.3 Disclosure

We disclose your information only to:

We do not sell your information. We do not use it for direct marketing.

8. Third-Party Services

We use the following third-party services to operate our business. These providers have limited access to information necessary to perform their services:

All third-party services are bound by their own privacy policies and security obligations. We do not transfer your identified personal information to providers located outside Australia.

9. Storage and Security

9.1 Where your information is stored

We store your information on encrypted servers located in Australia (Sydney). Backups are also stored encrypted and within Australia.

9.2 How we protect your information

While we take reasonable steps to protect your information, no electronic storage is completely secure.

9.3 Data breaches

If a data breach occurs that is likely to result in serious harm, we will notify you and the Office of the Australian Information Commissioner (OAIC) as required under the Notifiable Data Breaches scheme (Part IIIC of the Privacy Act).

10. How Long We Keep Your Information

10.1 Retention periods

We retain your information for the periods required by Australian law:

These retention periods reflect our obligations under the Privacy Act and state health records legislation, including section 25 of the Health Records and Information Privacy Act 2002 (NSW).

10.2 Storage during retention

Throughout the retention period, your information is held in encrypted storage with access restricted to authorised personnel.

10.3 Destruction

After the retention period ends, we securely destroy your information. We keep a record of the destruction, including the name of the individual to whom the information related, the period covered, and the date of destruction, as required by section 25(2) of the Health Records and Information Privacy Act 2002 (NSW).

10.4 Earlier deletion

If you ask us to delete your information before the retention period ends, we will comply unless we are legally required to retain it. Where we are legally required to retain information, we will explain why.

11. Your Rights

11.1 Access

You can ask to access the personal information we hold about you. We will respond within 30 days. Where the law permits, we may charge a reasonable fee for access; we will tell you any costs before proceeding.

11.2 Correction

You can ask us to correct information that is inaccurate, out of date, incomplete, irrelevant, or misleading. We will respond within 30 days.

11.3 Anonymity and pseudonymity

For general enquiries about our services, you can deal with us anonymously or under a pseudonym. For actual document preparation services, we need your real information because the submissions we prepare require accurate identification.

11.4 Withdrawing consent

You can withdraw consent for the collection, use, or disclosure of your sensitive information at any time. This may mean we cannot continue to provide our services.

11.5 Deletion

You can ask us to delete your information. We will comply unless we are legally required to retain it.

To exercise any of these rights, contact us at hello@section34.com.au.

12. Complaints

12.1 First, contact us

Email hello@section34.com.au with details of your concern. We will acknowledge your complaint within seven (7) days and respond substantively within thirty (30) days.

12.2 Office of the Australian Information Commissioner

If you are not satisfied with our response, you can complain to the OAIC:

12.3 State health complaints bodies

For complaints specifically about how we handle health information, you may also contact your state health complaints body:

12.4 NDIS Quality and Safeguards Commission

For complaints about NDIS-related conduct, you can also contact the NDIS Quality and Safeguards Commission at ndiscommission.gov.au or 1800 035 544.

13. Cross-Border Disclosure

We do not disclose your identified personal information to recipients outside Australia. De-identified content processed by AI services may be processed on servers outside Australia; this content does not contain personal identifiers and cannot reasonably be used to identify you.

14. Government Identifiers

We collect your NDIS number because it is necessary to prepare your submission. We do not adopt government identifiers (such as your NDIS number, Medicare number, or tax file number) as our own identifiers for you. We use government identifiers only for the purpose for which they were issued.

15. Changes to This Policy

We may update this policy from time to time. When we make material changes, we will publish the updated policy at section34.com.au/privacy.html with an updated version number and effective date. We may also notify existing clients of material changes by email.

16. Contact

Section 34 Co
Email: hello@section34.com.au
Website: section34.com.au

Version2.0
Effective date[VERIFY — pending compliance specialist review, est. June 2026]
Approved bySection 34 Co
Next review date12 months from effective date
SupersedesVersion 1.0 published 29 April 2026