Privacy
Your privacy matters to us. This page explains, in plain language, what information Ellira collects, why we collect it, who we may share it with, and the choices and rights you have. We handle personal information in line with the Privacy Act 1988 (Cth), the Australian Privacy Principles, and the Health Records Act 2001 (Vic).
Ellira Pty Ltd (ABN 96 688 683 301) is a mental health and disability support provider. Ellira is not yet a registered NDIS provider — we are working toward NDIS registration.
What we collect
We only collect what we need to support you well. Depending on the supports you receive, this can include:
- Your name, contact details, NDIS number and date of birth.
- Information about your goals, the supports you've had before, and what works for you.
- Sensitive information, where it's needed — including health, disability, medication, risk, emergency, family, cultural, communication and behaviour information.
- Notes from your support shifts ("progress notes"), and incident or complaint records if something goes wrong.
- Your Service Agreement, support plan and consent forms.
Some information is optional. We will never refuse you supports just because you chose not to provide optional information. If required information isn't provided, though, we may not be able to assess a request, deliver a support safely, or respond properly to a risk or concern.
Why we collect it
We collect information that is reasonably necessary to:
- Assess your request and confirm eligibility and funding.
- Plan and deliver your supports safely.
- Bill the NDIS or your plan manager.
- Communicate with the people you've approved.
- Manage safety, and respond to incidents or complaints.
- Meet our obligations as a provider of NDIS supports and keep required records.
Consent — and changing your mind
We usually ask for your consent before collecting sensitive information or sharing your information with other people or organisations. You can withdraw your consent at any time — just tell us.
There are limited times the law requires or allows us to use or share information without consent — for example, if you or someone else is at serious risk of harm, if we have mandatory reporting obligations, or if a subpoena, warrant or regulator's notice requires it. Where it's safe and appropriate, we will tell you what we're doing and why.
Who we may share information with
With your consent, and only where it's needed, we may share relevant information with:
- Your authorised representatives or nominees.
- Your plan manager or support coordinator.
- Health practitioners involved in your care.
- Emergency services.
- Regulators, auditors, insurers and legal advisers, where required for compliance, audit or legal purposes.
- Other providers involved in your supports.
We share only what is reasonably needed for the purpose.
How we store and protect your information
We store your records securely and limit access to workers who need the information for their role. We use physical, digital and operational safeguards — secure systems, controlled access, secure passwords and device handling, locked storage for any paper records, and secure disposal. We back up electronic records and take reasonable steps to protect your information from misuse, interference, loss, and unauthorised access, modification or disclosure.
Seeing and correcting your information
You can ask to see the information we hold about you, and ask us to correct it, at any time. We provide your records to you free of charge within 14 days — usually sooner. Just ask.
How long we keep records
We keep your records for 7 years after your services with us end, in line with privacy and NDIS requirements. After that, records are securely destroyed or de-identified when they're no longer needed and no longer required to be kept.
Overseas disclosure
We do not routinely send your information overseas. We would only do so with your consent, where the law requires or allows it, or after taking the privacy steps the law requires first.
If something goes wrong with your data
We take all reasonable steps to prevent data breaches. If we ever suspect a breach involving your personal information, we act immediately: we contain it, assess the risk of harm, and notify you and the Office of the Australian Information Commissioner where the Notifiable Data Breaches scheme requires it. We treat every breach as a critical incident and use what we learn to strengthen our security.
Privacy questions or complaints
If you have a question, or you think your privacy has been breached, please tell us first — we will fix what we can.
- Phone: 1300 487 996
- Email: hello@ellira.com.au
If you're not satisfied with our response, you can contact:
- Office of the Australian Information Commissioner (OAIC) — 1300 363 992 · oaic.gov.au
- Health Complaints Commissioner Victoria (for health information held in Victoria) — 1300 582 113