Privacy Policy
Effective date: 30 September 2026
Livlly Technologies Pty Ltd (ABN 22 640 884 420), trading as Careable (“Careable”, “we”, “us”, “our”), is committed to protecting the privacy of the people we support and everyone who contacts us. This policy explains how we collect, hold, use and disclose personal information and health information, and your rights in relation to it.
Careable is a registered NDIS provider. Depending on the circumstances, Careable is regulated by the Privacy Act 1988 (Cth), including the Australian Privacy Principles (APPs); the Health Records Act 2001 (Vic); and the National Disability Insurance Scheme Act 2013 (Cth) and NDIS rules that apply to registered providers, including obligations relating to participant privacy, confidentiality and record-keeping. This policy should be read together with those obligations.
1. The information we collect
Careable collects personal information that is reasonably necessary to provide and coordinate disability supports and to respond to enquiries. Depending on your relationship with Careable, this may include:
- Contact and identity details— name, date of birth, phone number, email and postal address.
- Enquiry and referral details— the supports you are interested in, your relationship to the participant (for example, participant, family member, support coordinator, hospital team or advocate), and anything you choose to tell Careable in a form, email, phone call or live chat.
- NDIS-related details— NDIS number, plan information, funding categories and plan goals, where you choose to provide them so Careable can understand your situation and respond to a request for support.
- Support and service information— details about the supports Careable provides, service agreements, schedules, communications with you and others involved in your supports, and complaints or feedback you submit.
- Health and disability information (sensitive information)— information about disability, health conditions, psychosocial needs, functional capacity, hospital admissions, and related information that you or your representatives provide so Careable can assess, plan and deliver supports.
- Risk and safeguarding information— risk assessments, incident reports, and behaviour support plans authored by external specialists that Careable holds and implements when delivering supports, where relevant under the NDIS Practice Standards or other laws. Careable does not author behaviour support plans.
- Emergency and support contacts and communication needs— details of emergency contacts, nominees, guardians, your plan manager, support coordinators and other people you have authorised to act on your behalf or be involved in your supports, as well as interpreter or communication support needs you tell Careable about.
- Employment information— if you apply to work with Careable, information in your application, qualifications, screening checks and references.
- Website and technical information— see sections 7 and 8 below.
We collect sensitive information, including health and disability information, with your consent unless collection is required or authorised by law or another exception under applicable privacy law applies. We only collect sensitive information that is reasonably necessary to provide, coordinate or safely manage the supports you have requested.
2. How we collect it
We collect personal information directly from you where possible — through our website forms, by phone, email, live chat, in person, or through service agreements and support planning. We may also collect it from people you have authorised to act for you (such as a nominee, guardian, plan manager or support coordinator), from hospitals and health services involved in your care with your consent, and from the National Disability Insurance Agency (NDIA) where we are authorised to receive it.
If you provide information about someone else (for example, a family member or the person you support), please make sure you are authorised to do so and that they are aware of this policy.
3. Why we collect and use it
We collect and use personal information to:
- respond to enquiries and referrals, and assess whether we can provide the supports requested;
- plan, deliver, coordinate and review NDIS supports and services;
- prepare service agreements, rosters and support plans;
- communicate with you and the people involved in your supports;
- claim payment for supports from the NDIA, plan managers or self-managed participants;
- meet our obligations as a registered NDIS provider, including incident management, safeguarding, quality and audit requirements;
- manage feedback and complaints;
- recruit, screen and manage staff;
- operate, secure and improve our website and services; and
- comply with the law.
We do not use or disclose sensitive information for direct marketing.
4. Who we share it with
We share personal information only where needed to provide your supports or where the law requires or permits it. This may include:
- our staff and contractors who deliver or coordinate your supports;
- other people involved in your supports who you have authorised, such as your nominee, guardian, plan manager, support coordinator, allied health professionals or hospital discharge teams;
- the NDIA and the NDIS Quality and Safeguards Commission, where required;
- health services in an emergency;
- service providers who help us operate, such as our customer relationship management, rostering, payroll, email and website hosting providers, under agreements that require them to protect your information; and
- regulators, courts or law enforcement where required by law.
We do not sell personal information.
5. Overseas disclosure
Our primary client and enquiry records are stored in Australia. Our Zoho customer relationship management and live-chat records are hosted in Sydney, Australia.
Some technology providers we use to operate our email, website hosting, analytics, security and communications systems may process personal information outside Australia. Depending on the service used, this may include the United States and other countries in which those providers or their approved subcontractors operate.
Before disclosing personal information to an overseas recipient, we take reasonable steps to ensure the recipient handles it in a way consistent with the Australian Privacy Principles, unless an exception under privacy law applies.
6. Website forms and enquiries
When you submit a form on our website, we collect the information you enter and send it securely to our customer relationship management system so our team can respond. We do not ask for NDIS numbers or health details in our public website forms; if you choose to include them in a free-text field, we will handle them as sensitive information under this policy.
7. Cookies and analytics
Our website uses Google Analytics 4 to understand how visitors use the site — for example, which pages are visited and how people arrive at the site. This uses cookies and collects technical information such as your approximate location, device type and pages viewed. We configure our website so that names, email addresses, phone numbers, NDIS numbers and health information are not intentionally sent to Google Analytics, and we do not intentionally link analytics information to information submitted through our website forms. You can opt out using the Google Analytics opt-out browser add-on or by disabling cookies in your browser.
8. Live chat
If you use the live chat on our website, your conversation and basic technical details are processed by Zoho SalesIQ so we can respond. Chat transcripts are kept in our customer relationship management system in the same way as an email enquiry. Please do not enter health information, NDIS numbers, plan details or other sensitive information in live chat. If you need to discuss sensitive information, call us on 1300 332 433 or ask us to arrange a suitable and secure way to contact you.
9. How we store and protect your information
We take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access, modification or disclosure. These include multi-factor authentication and access controls on our systems, encryption of data in transit, restricting access to authorised personnel, staff training, and written agreements with our service providers.
If a data breach occurs that is likely to result in serious harm, we will respond in line with the Notifiable Data Breaches scheme under the Privacy Act 1988, which may include notifying affected individuals and the Office of the Australian Information Commissioner (OAIC).
10. Accessing and correcting your information
You can ask to access the personal information we hold about you, or ask us to correct it, by contacting us (see Contact us). There is no charge for making a request.
We will acknowledge your request and take reasonable steps to verify your identity and your authority to make it. We aim to respond within 30 calendar days.
If we refuse access or correction, or cannot provide access in the form requested, we will give you written reasons and explain how you can complain. If we correct information and you ask us to, we will take reasonable steps to notify relevant third parties to whom we previously gave that information, unless this is impracticable or unlawful.
11. How long we keep information
We keep personal information for as long as it is needed for the purposes described in this policy and to meet our legal, regulatory, financial, safeguarding and audit obligations.
- Health and support records are generally retained for at least seven years after the last health service or support-related record and, if health information was collected while the person was a child, until at least the time they turn 25, or longer where required or reasonably necessary.
- Complaint records are retained for at least seven years from the date the record is made, in line with the NDIS (Complaints Management and Resolution) Rules 2018.
- Enquiries that do not lead to services are generally retained for up to two years, unless a longer period is required for a complaint, legal matter, safeguarding issue, consent record or another legal obligation.
When information is no longer required, we securely destroy or de-identify it, unless we are legally required or permitted to retain it.
12. Privacy complaints
If you have a concern about how we have handled your personal information, please contact us using the details below and mark your message “Attention: Privacy”. We will acknowledge your complaint within 2 business days and aim to respond within 30 calendar days. If we need more time, we will tell you why and when you can expect a response.
We will investigate your complaint, keep your information confidential, and provide a written outcome where appropriate. If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au or on 1300 363 992.
For complaints about your supports or our service, see our Feedback & Complaints page.
13. Changes to this policy
We may update this policy from time to time. The current version, with its effective date, will always be available on this page.
14. Contact us
Careable (Livlly Technologies Pty Ltd, ABN 22 640 884 420)
104/12 Ormond Boulevard, Bundoora VIC 3083
1300 332 433 · cx@careable.com.au
Please mark privacy requests “Attention: Privacy” so they reach the right person.