Privacy Policy
Integrity Internal Audits ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and safeguard your information when you visit our website or use our consultancy services.
2. Collection of Personal Information
2.1 Types of Information Collected
The Firm collects personal information that is reasonably necessary to perform our core functions of NDIS compliance auditing and strategic advisory. This data includes:
Identity Data: Names and professional titles of key personnel.
Contact Data: Business email addresses and telephone numbers.
Governance and NDIS Data: NDIS Provider Numbers, registration status, audit history, and information regarding an organisation’s current governance and compliance posture.
2.2 Methods of Collection
In accordance with APP 3, we collect information only by lawful and fair means. Data is primarily gathered through interactions with our website and digital services, specifically:
- Online Booking System: Information submitted to schedule a "Complimentary 20-Minute NDIS Compliance Health Check" or "One-on-One NDIS Compliance Coaching" session.
- Enquiry Channels: Data provided via our website contact forms or direct email correspondence to our enquiries inbox.
- Professional Resources: Information provided when subscribing to regulatory updates or accessing the Firm’s curated library of compliance guides.
3. Use and Disclosure of Information
The Firm utilises personal information to facilitate a structured five-step "Engagement Process" designed to ensure quality and safety in participant supports. This includes:
Initial Consultation: Assessing current compliance posture via the NDIS Compliance Health Check.
Strategic Planning: Developing bespoke roadmaps for governance and internal audit readiness.
Compliance Audit: Evaluating registration, policies, and participant records against NDIS Practice Standards.
Reporting and Review: Delivering actionable recommendations and risk assessments.
Ongoing Support: Monitoring progress and maintaining high standards of care.
APP 6 Compliance
We use and disclose information for the primary purpose for which it was collected (APP 6). This includes communicating regulatory changes regarding the NDIS Code of Conduct and providing expert guidance. Information is only disclosed to third parties where required by Australian law or for the primary purpose of providing advisory services.
4. Data Storage and Security
4.1 Secure Storage and Sovereignty
Integrity Internal Audits Pty Ltd holds personal information in secure digital databases to protect against unauthorised access or interference (APP 11.1). Our primary data environments are:
Pipedrive: Our Customer Relationship Management (CRM) system.
Microsoft 365: Our productivity and cloud storage suite.
APP 8 (Cross-border Disclosure): As these are cloud-based services, data may be stored on servers located outside of Australia. By providing your information, you acknowledge the potential for cross-border data flows inherent in professional cloud computing environments.
4.2 Technical Safeguards
Network/Access
The Firm implements high-level technical security measures, including:
Network Firewalls: To monitor and restrict unauthorised incoming and outgoing traffic.
Stringent Access Controls: All databases are protected by multi-factor authentication and robust password protocols.
Personnel Oversight: Access to client data is limited strictly to authorised personnel required for service delivery.
4.3 Transmission Risks
While we maintain rigorous security protocols, the transmission of data over the internet contains inherent risks. Users provide information via our online platforms at their own risk.
4.4 Data Destruction
In compliance with APP 11.2, the Firm will take reasonable steps to destroy or de-identify personal information once it is no longer required for its primary purpose or to meet statutory record-keeping obligations.
5. Website Interactions and Cookies
5.1 Anonymous Browsing
Users may generally browse our website without the need to reveal their identity. Identification only becomes necessary when scheduling a Health Check or engaging in a coaching session.
5.2 Use of Cookies
We utilise cookies to optimise site performance and remember user preferences. These small data files are stored on your device and do not identify individual users personally.
5.3 Non-Identifiable Data
For statistical and improvement purposes, we collect non-identifiable data, including browser type, device information, and interaction patterns. This information helps us refine our service delivery to NDIS providers.
5.4 Management and Third-Party Links
Users can manage or disable cookies through their browser settings, though this may impact website functionality. Our website may contain links to external "regulatory resources" or "government guides." Integrity Internal Audits Pty Ltd is not responsible for the privacy practices of external third-party sites.
6. Access and Correction
Under APP 12 and 13, you have the right to request access to the personal information the Firm holds about you and to request corrections to ensure data accuracy.
If you have a concern regarding our handling of your personal information or believe a breach of the APPs has occurred, please contact us via the details in Section 7. We will investigate and respond within a reasonable timeframe.
If you are unsatisfied with our response, you may escalate your complaint to the Office of the Australian Information Commissioner (OAIC):
Website: www.oaic.gov.au
Phone: 1300 363 992
7. Contact Information
For all privacy-related enquiries, access requests, or complaints, please contact Integrity Internal Audits Pty Ltd:
Email: enquiries@iiaudits.com.au
Phone: 0451 938 853
This policy is reviewed periodically to ensure alignment with changes in Australian legislation and NDIS regulatory requirements.