How NDIS Growth collects, uses, stores, shares and protects your personal information, in line with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. Please read this together with our Terms & Conditions and Legal Disclaimer. Last updated 25 June 2026.
This Privacy Policy explains how NDIS Growth (we, us or our), based in Sydney, New South Wales, handles personal information collected through the website at ndisgrowth.com.au and in the course of providing our marketing services. We are an independent marketing agency for NDIS providers. We are committed to protecting your privacy and to handling personal information in accordance with the Privacy Act 1988 (Cth) (Privacy Act) and the thirteen Australian Privacy Principles (APPs).
By using this website, submitting an enquiry or form, downloading a resource, or otherwise providing personal information to us, you acknowledge that you have read and understood this policy and agree to your personal information being handled as described in it. If you do not agree, please do not provide personal information to us or use the interactive features of the site.
“Personal information” means information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether the information is true or not and whether recorded in a material form or not. This policy applies to personal information about individuals. Information about a company is not personal information, although the contact details of individuals at a business are.
The personal information we collect depends on how you interact with us. It may include:
You do not have to provide the personal information we request, but if you do not, we may be unable to respond to your enquiry, provide a resource, or deliver our services.
“Sensitive information” includes health information and information about race, political opinions, religious beliefs, sexual orientation and criminal record. We do not seek, and ask that you do not provide, sensitive information through this website. In particular, please do not include the health information, disability information, plan details, NDIS numbers or other personal details of NDIS participants in any enquiry, form or message. We provide marketing services to NDIS providers; we do not provide services to NDIS participants through this site and we do not require participant information to assist you. If you provide sensitive information to us without our request, you consent to us handling it in accordance with this policy, and we may take reasonable steps to securely delete it.
We collect personal information in a number of ways:
Wherever it is reasonable and practicable, we collect personal information directly from you. If we receive personal information about you that we did not solicit, we will deal with it in accordance with the APPs.
We and our service providers use cookies, pixels, tags, software development kits and similar technologies (together, cookies) to operate the site, remember your preferences, understand how the site is used, measure and improve our marketing, and recognise returning visitors. Cookies are small files stored on your device. We use the following broad categories:
The main categories of tool we use are:
The specific tools and providers we use may change from time to time without notice. You can find current opt-out and privacy controls in the settings and privacy policies of the relevant providers, and through your browser as described below.
You can control cookies through your browser settings, including blocking or deleting them, and most browsers let you refuse non-essential cookies. Some browsers also offer a “Do Not Track” or “Global Privacy Control” signal. Where our systems recognise such a signal we will seek to honour it, but there is no consistent industry standard for responding to these signals. If you disable cookies, some features of the site may not work as intended, and disabling analytics and marketing cookies will reduce the data those tools collect about you.
We collect, hold, use and disclose personal information for the following purposes:
We will only use or disclose your personal information for a secondary purpose where you would reasonably expect it and the secondary purpose is related (or, for sensitive information, directly related) to the primary purpose, where you have consented, or where the use or disclosure is otherwise permitted or required by law. We do not sell your personal information, and we do not use it for automated decision-making that produces a legal or similarly significant effect on you.
We may send you marketing communications, such as newsletters, guides, offers and updates, where you have requested them, where you are an existing contact and would reasonably expect to receive them, or where you have otherwise consented, in each case as permitted by the Privacy Act and the Spam Act 2003 (Cth). Every marketing email includes a functional unsubscribe facility, and you can opt out at any time by using that facility or by contacting us. We will action opt-out requests within a reasonable time. We do not use sensitive information for direct marketing, and we do not provide your personal information to third parties for their own direct marketing without your consent.
Where it is lawful and practicable, you have the option of dealing with us anonymously or using a pseudonym, for example when making a general enquiry. However, for many of our services and communications we will need your contact details, and we may not be able to assist you, or provide a requested resource, if you do not identify yourself.
We do not sell or rent personal information. We disclose personal information only as described in this policy, including to:
Some of our service providers, and their sub-processors, store or process personal information on servers located outside Australia. The countries involved depend on the providers we use at the time and may change, but are likely to include the United States and other countries in which our service providers or their sub-processors operate. Before disclosing personal information overseas, we take steps that are reasonable in the circumstances to ensure the overseas recipient handles your information in a way consistent with the APPs, including by relying on the recipient’s contractual commitments, certifications and security measures. By providing your personal information to us, you acknowledge these overseas disclosures. Where required, we will seek your consent. You also acknowledge that, if you consent to an overseas disclosure and the recipient handles your information in breach of the APPs, the requirement under APP 8.1 to take reasonable steps will not apply.
We hold personal information in electronic systems operated by us and by our service providers, which are protected by access controls and other security measures. We take steps that are reasonable in the circumstances to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure, including through access restrictions, use of reputable providers, and staff confidentiality obligations. However, no method of transmission over the internet, or method of electronic storage, is completely secure. While we strive to protect your personal information, we cannot guarantee its absolute security, and any transmission of information to us is at your own risk.
We maintain procedures to detect, assess, contain and respond to data security incidents. If a data breach involving your personal information occurs that is likely to result in serious harm, we will respond in accordance with the Notifiable Data Breaches scheme under Part IIIC of the Privacy Act, including notifying affected individuals and the Office of the Australian Information Commissioner where required.
We retain personal information only for as long as it is reasonably necessary for the purposes set out in this policy, to provide our services, to maintain business records, and to meet our legal, accounting, tax and regulatory obligations, after which we take reasonable steps to destroy or de-identify it. The retention period varies depending on the type of information and the purpose for which it is held; for example, enquiry and customer records are generally kept for the duration of our relationship and for a period afterwards consistent with our legal obligations and legitimate business needs.
You may request access to the personal information we hold about you, and ask us to correct it if it is inaccurate, out of date, incomplete, irrelevant or misleading, at any time by contacting us using the details below. We will respond within a reasonable period (generally within 30 days). We may need to verify your identity before acting on your request. There is no fee to make a request, although we may charge a reasonable fee for giving access in some circumstances (we will tell you in advance). In limited circumstances we may decline a request, for example where the law permits or requires us to, or where giving access would have an unreasonable impact on the privacy of others; if we refuse, we will give you reasons in writing and tell you how to complain.
We do not adopt, use or disclose a government related identifier (such as a tax file number, Medicare number or NDIS number) as our own identifier of an individual, except as permitted by the Privacy Act.
The website may contain links to, and content or tools from, third-party websites and services. We are not responsible for the privacy practices or content of those third parties. We encourage you to read the privacy policies of any third-party website or service before providing your personal information to them. This policy applies only to information collected by us.
This website and our services are directed at users in Australia, and our handling of personal information is governed by Australian law. If you access the site from outside Australia, you do so on your own initiative and are responsible for compliance with local laws, and you consent to your information being collected, transferred to and processed in Australia and the other countries described in this policy, which may have different data-protection laws to your country.
If you have a concern or complaint about how we have handled your personal information, please contact us first using the details below, with enough detail for us to investigate. We will acknowledge your complaint, investigate it, and respond within a reasonable period (generally within 30 days). If you are not satisfied with our response, you may refer your complaint to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au or on 1300 363 992.
We may update this policy from time to time to reflect changes in our practices, our tools, or our legal obligations. The current version is always available on this page, with the “last updated” date shown above. Material changes will take effect when the updated policy is published, and your continued use of the site after that constitutes acceptance of the updated policy. We encourage you to review this page periodically.
For any privacy question, request or complaint, or to contact our privacy contact, please email hello@ndisgrowth.com.au or call us on 02 8424 7597.
A specialist reviews your visibility against the providers competing in your catchment, and sends a written growth plan within two business days. You keep it either way.