Becoming an NDIS provider? Get audit-ready in days, not months, with our proven system

PRIVACY POLICY

This Privacy Policy describes how Connect and Grow Pty Ltd (ABN 65 656 839 253) trading as Provider360, including www.provider360.com.au and the Provider Hub (the “Site”, “Provider360”, “we”, “us” or “our”), collects, uses, holds and discloses your Personal Information when you visit, contact us, or make a purchase from the Site.

We handle Personal Information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). This policy explains your rights and our obligations. By using the Site or our services, you agree to the handling of your Personal Information as described in this policy.

CONTACT

After reviewing this policy, if you have additional questions, want more information about our privacy practices, or would like to make a complaint, please contact us by email at info@provider360.com.au.

COLLECTING PERSONAL INFORMATION

When you visit the Site, we collect certain information about your device, your interaction with the Site, and the information necessary to process your purchases. We may also collect additional information if you contact us for customer support or to enquire about a quote for our products and/or services.

In this Privacy Policy, we refer to any information about an identifiable individual (including the information below) as “Personal Information”. See the list below for more information about what Personal Information we collect and why.

Device information
• Purpose of collection: to load the Site accurately for you and to perform analytics on Site usage to optimise our Site.
• Source of collection: collected automatically when you access our Site using cookies, log files, web beacons, tags, or pixels.
• Disclosure for a business purpose: shared with our analytics and advertising providers (for example, Meta and Google).
• Personal Information collected: version of web browser, IP address, time zone, cookie information, what sites or products you view, search terms, and how you interact with the Site.

Order information
• Purpose of collection: to provide products or services to you to fulfil our contract, to process your payment information, and provide you with invoices and/or order confirmations, communicate with you, screen our orders for potential risk or fraud, and, when in line with the preferences you have shared with us, provide you with information or advertising relating to our products or services.
• Source of collection: collected from you.
• Disclosure for a business purpose: shared with our payment processors, our email and customer relationship management (CRM) provider, and Meta.
• Disclosure to third parties: shared with third parties as authorised by you. For example, share with an NDIS Quality Auditor.
• Personal Information collected: name, billing address, home address, business address, payment information (including credit card numbers), email address, mobile number and phone number.

Customer support information
• Purpose of collection: To provide customer support.
• Source of collection: Collected from you.
• Disclosure for a business purpose: shared with our live chat, scheduling and email providers, or any contractor engaged by us.

Provider Hub account information
• Purpose of collection: to create and manage your Provider Hub account and give you access to the platform.
• Source of collection: collected from you.
• Personal Information collected: the username and password you use to access the Provider Hub. Passwords are stored in hashed form, not in plain text.
• How it is held: stored using a secure third-party database service.

SENSITIVE INFORMATION

Some information we may handle is “sensitive information” under the Privacy Act 1988 (Cth), including health information and information about a person’s disability. In delivering NDIS registration support, we may handle documents you provide that contain sensitive information about your workers or participants.

• We collect sensitive information only with your consent, or where we are otherwise permitted or required by law, and only for the purpose for which it is provided.
• You are responsible for obtaining any consents required from your workers or participants before providing us with documents that contain their personal or sensitive information, and for removing or de-identifying that information where it is not required.
• We treat sensitive information with additional care and only disclose it as described in this policy or as authorised by you.

ANONYMITY AND PSEUDONYMITY

Where it is lawful and practicable, you may deal with us anonymously or by using a pseudonym (for example, when making a general enquiry). This may not be possible where we need to verify your identity, communicate with you, or provide our products and services.

MINORS

The Site is not intended for individuals under the age of 18. We do not intentionally collect Personal Information from children. If you are the parent or guardian and believe your child has provided us with Personal Information, please contact us at the address above to request deletion.

SHARING PERSONAL INFORMATION

We share your Personal Information with service providers to help us provide our services and fulfil our contracts with you, as described above. For example:
• Provider Hub account access is managed by us. We store only the username and password you use to access the Provider Hub (with passwords held in hashed form) in a secure third-party database.
• We use payment processors (for example, GoCardless and Stripe) to process payments and instalment plans. We do not store full payment card details ourselves.
• We use a live chat provider to operate the chat on our Site, which may collect your name, email address and the messages you send us.
• We use a scheduling provider to manage bookings, which collects your name, email address and booking details.
• We use an email and customer relationship management (CRM) provider to send communications and manage our contacts.
• Where you authorise it, we may share relevant contact and business details with partners such as NDIS Approved Quality Auditors and insurers, solely to help facilitate your audit, compliance or a referral you have requested.
• We may share information with our professional advisors, IT, hosting and analytics providers, and contractors engaged by us, to operate our business.
• We may share your Personal Information to comply with applicable laws and regulations, to respond to a subpoena, search warrant or other lawful requests for information we receive, or to otherwise protect our rights.
• We also use this to retarget relevant advertisements that are personalised for you.

OVERSEAS DISCLOSURE

Some of our service providers and tools may store or process Personal Information outside Australia, including in the United States and Europe. These may include Meta, Google, our payment processors (such as GoCardless and Stripe), our email/CRM provider, our live chat provider and our scheduling provider. Where we disclose Personal Information to a recipient overseas, we take reasonable steps to ensure that it is handled in a manner consistent with the Australian Privacy Principles.

BEHAVIOURAL ADVERTISING

As described above, we use your Personal Information to provide you with targeted advertisements or marketing communications we believe may be of interest to you. For example:
• We use Google Analytics to help us understand how our customers use the Site. You can read more about how Google uses your Personal Information here: https://www.google.com/intl/en/policies/privacy/. You can also opt out of Google Analytics here: https://tools.google.com/dlpage/gaoptout.
• We share information about your use of the Site, your purchases, and your interaction with our ads on other websites with our advertising partners. We collect and share some of this information directly with our advertising partners, and in some cases, through the use of cookies or other similar technologies (which you may consent to, depending on your location).

For more information about how targeted advertising works, you can visit the Network Advertising Initiative’s (“NAI”) educational page at https://www.networkadvertising.org/understanding-online-advertising/how-does-it-work.

You can opt out of targeted advertising by:
• FACEBOOK – https://www.facebook.com/settings/?tab=ads
• GOOGLE – https://www.google.com/settings/ads/anonymous
• BING – https://advertise.bingads.microsoft.com/en-us/resources/policies/personalized-ads

Additionally, you can opt out of some of these services by visiting the Digital Advertising Alliance’s opt-out portal at: https://optout.aboutads.info/.

DIRECT MARKETING

We may send you marketing communications about our products, services, resources and offers where you have requested them or where it is otherwise permitted by law. You can opt out at any time by using the unsubscribe link in our emails or by contacting us at info@provider360.com.au. We do not use sensitive information for direct marketing without your consent.

USING PERSONAL INFORMATION

We use your personal information to provide our services to you, which include: offering products for sale, processing payments, fulfilment of your order, and keeping you up to date on new products, services, and offers.

LAWFUL BASIS

Pursuant to the Data Protection Laws and Regulations (“DPLR”), if you are a resident of Australia, we handle your personal information in compliance with the Privacy Act 1988 and the Privacy Regulation 2013.

DATA SECURITY

We take reasonable steps to protect Personal Information from misuse, interference and loss, and from unauthorised access, modification or disclosure. These steps include access controls, secure storage, use of reputable service providers, and limiting access to those who need it to perform their role. For example, passwords used to access the Provider Hub are stored in hashed form (not in plain text). While we take reasonable steps to protect your Personal Information, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.

RETENTION

When you place an order through the Site, we will retain your Personal Information for our records unless and until you ask us to erase this information. For more information on your right of erasure, please see the ‘Your rights’ section below. We may also retain Personal Information where we are required to do so by law, or where it is reasonably necessary for our legitimate business purposes (for example, record-keeping, dispute resolution and enforcing our agreements).

DATA BREACHES

We comply with the Notifiable Data Breaches scheme under the Privacy Act 1988 (Cth). If we become aware of an eligible data breach that is likely to result in serious harm to any individual whose Personal Information is involved, we will take reasonable steps to contain and assess the breach and will notify the affected individuals and the Office of the Australian Information Commissioner (OAIC) as required by law.

YOUR RIGHTS

If you are a resident of Australia, you have the right to access the Personal Information we hold about you (also known as the ‘Right to Know’), to port it to a new service, and to ask that your Personal Information be corrected, updated, or erased. If you would like to exercise these rights, please contact us through the contact information above.

If you would like to designate an authorised agent to submit these requests on your behalf, please contact us at the address above.

We will respond to your request within a reasonable period. We may need to verify your identity before acting on a request, and in some cases we may be unable to provide access or erasure where the law allows or requires us to retain the information.

SAFE USE OF AI TOOLS

We may use internally operated tools and trusted third-party tools, including AI-assisted tools, to support product refinement, quality improvement, internal drafting support, workflow enhancement, internal analysis and service optimisation. We use these tools responsibly and in a way that protects your privacy, consistent with the Australian Privacy Principles and the OAIC’s guidance on the use of commercially available AI products.

• We do not enter your personal information, and in particular sensitive information, into publicly available (consumer) generative AI tools.
• Where we use AI-assisted tools that may process Personal Information, we select reputable providers, review their terms, and take reasonable steps to ensure that your information is not used to train their AI models or disclosed for unrelated purposes.
• Human oversight: AI outputs are reviewed by our team. We do not rely solely on AI to make decisions that have a significant effect on you, and a person remains responsible for our advice and deliverables.
• We take reasonable steps to protect the accuracy, security and confidentiality of any Personal Information involved when AI-assisted tools are used.
• Our use of these tools does not change our confidentiality obligations to you, and we will not use them in any way that compromises those obligations.

THIRD-PARTY LINKS

Our Site, communications and the Provider Hub (including the vetted partners directory) may contain links to websites and services operated by third parties. We are not responsible for the privacy practices or content of those third parties. We encourage you to review their privacy policies before providing them with your Personal Information.

COOKIES

A cookie is a small amount of information that’s downloaded to your computer or device when you visit our Site. We use a number of different cookies, including functional, performance, advertising, and social media or content cookies. Cookies make your browsing experience better by allowing the website to remember your actions and preferences (such as login and region selection). This means you don’t have to re-enter this information each time you return to the site or browse from one page to another. Cookies also provide information on how people use the website, for instance, whether it’s their first time visiting or if they are a frequent visitor.

We use the following cookies to optimise your experience on our Site and to provide our services.

The length of time that a cookie remains on your computer or mobile device depends on whether it is a “persistent” or “session” cookie. Session cookies last until you stop browsing, and persistent cookies last until they expire or are deleted. Most of the cookies we use are persistent and will expire between 30 minutes and two years from the date they are downloaded to your device.

You can control and manage cookies in various ways. Please keep in mind that removing or blocking cookies can negatively impact your user experience, and parts of our website may no longer be fully accessible.

Most browsers automatically accept cookies, but you can choose whether or not to accept cookies through your browser controls, often found in your browser’s “Tools” or “Preferences” menu. For more information on how to modify your browser settings or how to block, manage or filter cookies, can be found in your browser’s help file or through such sites as: www.allaboutcookies.org.

Additionally, please note that blocking cookies may not completely prevent how we share information with third parties, such as our advertising partners. To exercise your rights or opt out of certain uses of your information by these parties, please follow the instructions in the “Behavioural Advertising” section above.

DO NOT TRACK

Please note that because there is no consistent industry understanding of how to respond to “Do Not Track” signals, we do not alter our data collection and usage practices when we detect such a signal from your browser.

CHANGES

We may update this Privacy Policy from time to time in order to reflect, for example, changes to our practices or for other operational, legal, or regulatory reasons. The updated policy will be posted on the Site with a revised “Last updated” date.

COMPLAINTS

As noted above, if you would like to make a complaint, please contact us by email at info@provider360.com.au. We will acknowledge your complaint and respond within a reasonable period.

If you are not satisfied with our response to your complaint, you have the right to lodge your complaint with the relevant data protection authority. You can contact the Office of the Australian Information Commissioner (OAIC) here: https://www.oaic.gov.au/privacy/privacy-complaints/what-you-can-complain-about

Last updated: 4 June 2026

×

Thank you! Your message has been sent.