Privacy Policy


Published: 1-4-2018
Updated: 11-9-2026

Kindship Privacy Policy — 11 September 2026


You deserve to know what happens to your information, who can see it, and what choices you have.


Whether you’re using our app, talking with our team or asking us to manage your NDIS plan, this policy explains how we handle your information. It also explains how to ask questions, update your details or tell us when something isn’t right.

1. Who this policy covers

This policy applies to:

  • Kindship Group Pty Ltd — ACN 648 460 646.
  • Kindship Pty Ltd — ACN 625 713 724.
  • Kindship Premium Services Pty Ltd — ACN 662 497 092.

When we say “Kindship”, “we”, “us” or “our”, we mean these organisations. Your service agreement or service information will identify which organisation provides your service. Kindship Pty Ltd operates the Kindship app.

This policy covers our work across plan management, the Family Pathways Program delivered by our team, and the Kindship app, including its self-service Family Pathways walkthrough.

It also covers customer and member support, our websites, enquiries, webinars, events, educational activities, newsletters and other communications. It applies to our dealings with staff, volunteers, job applicants and service providers too.

We handle personal information in line with the Privacy Act 1988 (Cth), the Australian Privacy Principles, and the other privacy, confidentiality and NDIS requirements that apply to our work.

Different services need different information. The self-service app keeps your detailed pathway answers on your device. Working directly with our team usually involves sharing information with us so we can provide your service and keep the records we need.

Section 7 explains the app’s particular arrangements.

This policy also covers information we still hold from earlier services. Updating this policy does not, by itself, give us permission to use that information for unrelated purposes.

2. What we mean by personal information

Personal information is information or an opinion about someone who is identified, or who could reasonably be identified.

Some personal information has extra protection under privacy law. This is called sensitive information. It includes information about health, disability, racial or ethnic origin, religious beliefs, sexual orientation and certain other matters.

For example, information about a child’s development, diagnosis or support needs may be sensitive information. Information about a parent’s or carer’s health and wellbeing may be sensitive too.

3. The information we collect

What we need depends on how you use Kindship. You won’t need to provide every type of information listed here.

We collect information that is reasonably necessary to provide your service or carry out our other lawful activities.

Your contact and identity details

These may include your name, contact details, address, communication preferences and, where needed, date of birth. We may also need information to confirm your identity or someone’s authority to act on your behalf.

Information about a participant, child or family

Depending on the service, we may collect information about disability, health, development, communication, sensory or mobility needs, and daily living.

This may include relevant reports, goals, family circumstances, support networks, existing services and difficulties accessing support.

Plan management information

We may collect NDIS numbers, plans, funding periods, budgets, support categories, invoices, receipts, provider details and service agreements.

We also collect the information needed to manage claims, payments and reimbursements, including bank details where relevant. Our records may include correspondence, compliance checks, payment decisions and requests for clarification.

Family Pathways information

When you work through Family Pathways with our team, we may collect information about your family’s circumstances, the supports you’re looking for, relevant eligibility requirements and your goals.

We may keep notes about your sessions, agreed actions, referrals and progress. Where relevant to a support you’re exploring, we may also need information about financial circumstances, residency or concession entitlements.

The self-service app works differently, as explained in section 7.

Support, events and communications

We may keep your enquiries, emails, chat messages, call notes, complaints, feedback and communication preferences.

For events and webinars, we may collect registration details, attendance information and accessibility requests. Section 10 explains how we handle recordings and transcripts.

Website and technical information

Our online services and their providers may receive information such as IP addresses, browser and device details, website activity and technical logs.

Information about people who work with us

For staff, volunteers, applicants and service providers, we may collect relevant qualifications, work history, references, screening results, right-to-work information, business details, insurance information and payment records.

Additional staff privacy notices and employment requirements may also apply.

4. How information reaches us

We usually collect information directly from you. This may happen through a form, service agreement, appointment, conversation, email, telephone call, online service or document you share.

Sometimes information comes from someone else, such as an authorised representative, nominee, parent, guardian, provider, professional or referring organisation. We may also receive information from the National Disability Insurance Agency (NDIA) or another organisation where we have the appropriate authority or another lawful basis.

We take reasonable steps to explain how we will handle your information when we collect it. Depending on the situation, we may do this through a service agreement, consent form or notice alongside the questions we ask.

Please only share information about someone else when you have appropriate authority or another lawful basis to do so.

If we receive information we didn’t ask for, we check whether we can lawfully keep it. Where we cannot, we take reasonable steps to delete it or remove identifying details, where lawful and reasonable.

5. Your choices and consent

You can ask why we need information, how we will use it and whether a question is optional.

Using Kindship or accepting our terms does not give us blanket permission to collect, use or share sensitive information.

We generally need your consent before collecting sensitive information. We also need to make sure it is reasonably necessary for our work. A legal exception may apply in some circumstances, but information being useful does not, on its own, remove the need for consent.

Where we need consent, we explain what you’re agreeing to.

You can decline optional requests or contact us to withdraw consent for future handling. We will explain whether this affects a service we can provide. Withdrawing consent does not undo earlier lawful handling or remove information we must keep by law.

You can make general enquiries without giving your name where practical. Some services, including plan management, require us to confirm your identity and authority.

When someone acts on another person’s behalf

Children and people with disability have their own privacy rights. We do not assume that a person cannot make privacy decisions because they have a disability.

When a representative acts for someone else, we check their authority and the limits of their role.

For children, we consider their understanding and ability to make the particular privacy decision. Where appropriate, we seek consent from a parent or another legally authorised representative.

6. How we use information to support you

We use personal information to provide the services you request, communicate with you, keep appropriate records and meet our obligations.

For plan management, this includes getting your service set up, checking authority, processing invoices and reimbursements, checking claims, tracking budgets and arranging payments. It also includes communicating with you, your authorised representatives, providers and the NDIA.

For Family Pathways delivered by our team, we use information to understand your circumstances, explore available supports, prepare action plans and documents, assist with referrals and applications, and follow up on agreed actions.

Unlike the self-service app, working through Family Pathways with our team involves sharing information with Kindship and keeping service records.

For customer and member support, we use information to answer questions, investigate problems, keep track of conversations and resolve complaints.

We also use relevant information to manage events, subscriptions, workers and suppliers; protect our systems; investigate suspected fraud or misuse; meet legal and audit requirements; and understand how we can improve our services.

We use information for the purpose it was collected, or another purpose allowed by law. Where a new use needs your consent, we ask for it. Changing this policy is not a substitute for that consent.

7. Your information in the Kindship app

This section applies to the self-service Family Pathways walkthrough at kindship.app.

It does not describe what happens when you separately contact our team, send us a document or use a service delivered by our staff.

Your detailed answers stay in your browser

You do not need an account to use the walkthrough. It does not ask for your name or email address.

Your detailed answers about your child’s name, sex, age, development and support needs are processed and saved in your device browser. This lets the app build your pathway and lets you come back to it later.

Kindship does not receive a copy of those detailed answers. The limited usage measurements, technical information and feedback described below are handled separately.

The app does not separately encrypt its browser storage. Someone with access to your device or browser profile may be able to see your saved answers, so please keep this in mind on a shared device.

You can clear your answers through the app’s clear-data page at /clear, or by clearing the website’s data in your browser settings.

Clearing your browser data does not delete documents you have already downloaded or copies you have shared.

Finding your local office

The app uses information available on your device to match your suburb or postcode with local services. Your entered suburb and postcode are not sent to Kindship for this matching.


The app may request office information for the relevant partner organisation. That request identifies the organisation, rather than your entered suburb or postcode.

Creating and sharing your pathway document

Your device creates the pathway document you download. Kindship does not receive a copy just because you create or download it.

You decide whether to keep it, print it or share it with someone supporting your family.

If you later send the document to our team, we handle the information in it under the relevant parts of this policy.

Understanding how the app is being used

The app sends limited measurements that contribute to daily totals. These help us understand where the app is useful, where people get stuck and how many families the program is reaching.

These measurements include:

  • Steps reached, where visits end, pathways shown, viewed and selected, broad visit-duration bands and satisfaction scores.
  • Categories of technical faults, the step affected and whether local office information was available.
  • Totals based on state, broad location type, number of children and optional family-characteristic selections.

Some optional family characteristics concern sensitive matters, such as cultural background or LGBTQIA+ identity.

These measurements are designed to produce overall statistics, not individual family profiles. They do not include your detailed developmental answers.

Reports hide small counts, including zero counts, to reduce the risk of identifying a family. A hidden number is still included in the underlying aggregate count.

We do not use your locally stored pathway answers for advertising.

Feedback you choose to share

When you press Share feedback, the note you write is sent to Kindship and stored in our database in Sydney, Australia.

Please leave out names, contact details and other identifying information unless they are needed to explain the issue. Anything you include in the note becomes information we receive.

Our team reads feedback to understand problems and improve the app. We do not include these notes in reports to program funders.

App feedback notes are scheduled for deletion after 12 months. If information is separately kept as part of a formal complaint or another record we need to retain, the retention rules for that record apply.

Technical information needed to run the app

Our hosting, database and other technical providers may receive information needed to operate and protect the app. This can include IP addresses, request details and technical logs.

Some technical information may be handled overseas.

Keeping detailed pathway answers on your device does not mean that every interaction with the website is free of personal information. The technical providers involved in running it may still receive information such as your IP address.

8. How we use AI-enabled tools

We use software with artificial intelligence, or AI, features in some administrative work, including invoice processing. AI features in workplace software may also help our team work with emails and documents.

When these features process an invoice, email or document, they may also process personal or sensitive information contained in it. Depending on the tool, this may involve the software provider processing information, not just a Kindship team member reading it.

Our privacy responsibilities still apply. Information must be handled for the relevant service purpose or another lawful purpose. Our team’s access must stay within their authorised duties.

This policy does not give blanket permission to use your information for unrelated AI training or other new purposes.

You can ask us how AI is used in a service you receive, raise a concern or request review or correction of personal information we hold. This includes information produced by an automated tool.

Before introducing materially different information handling, we will provide further information and seek consent where required.

9. Newsletters and other marketing

We may send newsletters, promotional invitations and other marketing where we have the consent required by law.

Using a service, attending an event or reading this policy does not automatically sign you up for every Kindship marketing activity.

You can unsubscribe using the instructions in a message or by contacting us. We action electronic marketing unsubscribe requests within five working days.

There is no charge, and you do not need to create an account.

You may still receive essential, non-promotional messages about a service you use, such as appointment details, payment enquiries or important service changes.

We do not use sensitive information for direct marketing without the consent required by law.

Choosing not to receive optional marketing does not affect your entitlement to an agreed service.

10. Webinars, events and group activities

When you register for an event or webinar, we may use your details to manage attendance, send access instructions, accommodate accessibility needs and share associated materials.

In group activities, other people may see your display name, hear what you say or read messages you share. Please consider what you’re comfortable sharing, especially about a child or another person.

Before recording or transcribing a call, webinar or session, we explain what is being recorded and how it will be used. We obtain consent where required.

You can contact us about participation options if you do not wish to appear in a recording.

We ask for separate permission before using identifiable participant stories, photographs, recordings or testimonials for public promotion.

Taking part in a group does not give us general permission to share your private service records or health information with other members.

11. Websites, cookies and external platforms

Outside the app arrangements described in section 7, our websites and communications may use cookies and similar technologies to help them work, measure usage and understand engagement.

Depending on the technology, this may include IP addresses, browser and device details, pages visited, referral information, email openings and link interactions. Some of this may be personal information.

You can manage cookies in your browser settings and through any privacy controls available on the website. Turning some technologies off may affect how a website works.

When you follow an external link or give information directly to another organisation, its privacy arrangements also apply. This includes social media platforms.

Please avoid sharing private participant or family information in public comments.

12. Who may receive your information

We share information where there is an appropriate service-related or other lawful basis. We limit what we share to what is needed.

Depending on your service and the circumstances, this may include:

  • People and organisations supporting our work, such as authorised workers and providers of email, document storage, customer support, invoicing, payment, hosting, security and AI-enabled software.
  • People involved in your supports, such as authorised representatives, chosen providers, professionals, referral organisations and the NDIA.
  • Organisations involved in legal, regulatory or professional matters, such as auditors, advisers, insurers, regulators, government agencies, courts and other authorities.

For plan management, we obtain written consent from the participant or an appropriately authorised representative before disclosing information to third parties, unless disclosure is required or authorised by law.

Relevant permissions may be recorded in a service agreement or a separate consent form.

There are limited circumstances where the law allows or requires sharing without consent. These may include particular reporting duties, valid legal demands or serious threats to health or safety. We check that the relevant legal requirements are met.

We do not sell personal information.

Audits and program reporting

Records may be reviewed as part of lawful audits and compliance activities. Where an audit interview or feedback activity is optional, we explain that choice.

Where practical, we use overall statistics or appropriately de-identified information to evaluate programs and report to funders.

If identifiable information is required, we explain what information is involved, who will receive it and why. We establish the necessary consent or other lawful basis.

Removing someone’s name does not always make information anonymous. We also consider whether other details, or the context, could reasonably identify them.

13. How information is handled across Kindship

Being part of the same group does not mean everyone at Kindship can see everyone’s information.

Kindship Plan Management receives agreed corporate services from Kindship Pty Ltd under a services agreement. Authorised personnel may access the information needed to carry out that work, subject to the agreement, confidentiality obligations and privacy requirements.

Access is based on a person’s role and limited to what they need to do their work.

Workers must not use participant information outside their role or the agreed service arrangements without separate authority or another lawful basis.

Using more than one Kindship service does not automatically give us permission to share all your information between those services.

Where conflicts of interest arise, we explain them and support your choice. Choosing to leave one service must not result in a penalty or an inappropriate impact on your other supports.

14. Where information is stored and accessed

We use electronic business systems and contracted providers to store and process information. Where information is stored or accessed depends on the system and service.

The self-service app’s database is in Sydney, Australia.

Other information may be stored, processed or accessed outside Australia through software providers, technical infrastructure or authorised overseas personnel.

Relevant overseas locations include the United States and European Union.

An Australian database location does not necessarily mean every part of a service operates only in Australia. Technical logs, support access and other processing may happen elsewhere.

When we disclose personal information overseas, we take the reasonable steps required by Australian privacy law to protect it. This includes appropriate contractual, access and security arrangements.

Accepting this policy does not waive your protections under Australian privacy law.

The app’s arrangements for detailed answers stored on your device remain as described in section 7.

15. How long we keep information

We keep personal information for as long as we need it for a permitted purpose. This includes providing services and meeting legal, NDIS, accounting, audit and dispute-related requirements.

Different records may need to be kept for different periods.

Ending a service does not always mean we can immediately delete every record. Where we still need to keep information, we continue to protect it.

When we no longer need information for a permitted purpose, we take reasonable steps to destroy it or de-identify it, unless the law requires us to retain it.

The app’s saved answers and feedback have the particular arrangements explained in section 7.

You can ask us how long we keep a particular type of record.

16. How we protect information

We take reasonable steps to protect information from misuse, interference, loss, and unauthorised access, changes or sharing.

Our safeguards include access based on job responsibilities, permission reviews, confidentiality requirements, secure storage and sharing, device and password controls, multi-factor authentication where available, and appropriate disposal processes.

Our team must only access information for authorised work. They must check recipients before sharing information, keep confidential discussions private and promptly report suspected breaches.

No system can remove every security risk. For the self-service app, the shared-device considerations in section 7 are especially important.

When something goes wrong

If we become aware of a suspected privacy breach, we act to contain it, work out what happened, assess the information and risks involved, and take corrective action. We keep a record of our response.

Where the law requires notification, we notify the Office of the Australian Information Commissioner and affected people. We also explain relevant steps people can take to protect themselves.

Not every incident requires notification, but every suspected breach needs to be assessed.

17. Seeing, correcting or deleting your information

You can contact us to ask for access to personal information we hold about you, ask us to correct it, or request its deletion.

We may need to confirm your identity or authority before releasing or changing information. We keep those checks proportionate to the information involved.

We respond within a reasonable time, generally within 30 calendar days. If we need longer, we explain why and when you can expect a response.

There is no charge to make an access or correction request, or to have information corrected. If a reasonable charge for providing access is permitted and proposed, we explain it beforehand.

If we refuse access or a correction, we give you written reasons and explain your complaint options, subject to any legal restrictions.

If we disagree about a correction, you can ask us to attach a statement recording your position. Where applicable, you can also ask us to tell relevant recipients that information has been corrected.

We consider deletion requests alongside our ongoing purposes and legal obligations. Where we must keep information, we explain why.

Information in the app

We cannot retrieve, change or delete answers that are held only in your browser. You can manage these directly on your device.

If you ask us to find or remove a feedback note, we may need enough of its wording to locate it. Where a note has no identifying details, we may not otherwise be able to tell which one is yours.

18. When you have a privacy concern

Please tell us if you think we have mishandled information or have not followed this policy.


You do not need to work through the process alone. You can use a representative, advocate or support person.

We aim to acknowledge your complaint within two business days and resolve it within ten business days where possible. We aim to provide a written response within 30 calendar days of receiving your complaint.

If we need more time, we explain why and give you an expected response date.

Our response will explain what we found, what action we are taking and what you can do if you remain concerned.

Making a complaint will not, by itself, affect your access to services.

Taking your concern further

If you are unhappy with our response, or we have not responded within 30 days, you can complain to the Office of the Australian Information Commissioner (OAIC).

The OAIC generally expects you to raise your complaint with us first. You do not need our permission to contact it.

OAIC
Website: oaic.gov.au
Phone: 1300 363 992
Post: GPO Box 5288, Sydney NSW 2001

For concerns about privacy, rights, or the quality and safety of NDIS services, you can also contact the NDIS Quality and Safeguards Commission.

Website: ndiscommission.gov.au
Phone: 1800 035 544

19. Changes to this policy

We review this policy when our services, systems, information handling or legal obligations change.

The current version will be available on our website with its update date. We provide additional notice of significant changes where appropriate or required.

An updated policy does not replace consent where consent is required. It also does not automatically give us permission to use previously collected information in new ways.

You can ask for this policy in another format or contact us to talk through any part of it.

20. Contact us

For privacy questions, requests or complaints, please contact our team.

Email: hello@kindship.com.au
Member support: members@kindship.com.au
Phone: 1300 057 084

Post:
Privacy Enquiries
Kindship
Suite 17, Stone & Chalk Startup Hub
Lot Fourteen, North Terrace
Adelaide SA 5000