Privacy Policy
Last updated: April 2025 · ANDICare Finance · Adelaide, South Australia
ANDICare Finance handles personal and financial information on behalf of NDIS providers. We take that responsibility seriously. This policy explains what we collect, why we collect it, and how we protect it.
1. Who we are
ANDICare Finance is a specialist financial services practice based in Adelaide, South Australia, providing accounting, invoicing, bookkeeping, payroll, cash flow management, and financial advisory services exclusively to NDIS disability support providers. ABN registration pending.
When you engage ANDICare Finance, we become a data processor acting on your behalf. All data we handle is governed by the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
2. What information we collect
We collect only the information necessary to deliver our services. This includes:
- Contact information — name, email address, phone number, business address
- Organisation details — ABN, NDIS registration number, bank account details for payroll and payments
- Employee information — names, Tax File Numbers, super fund details, leave balances (for payroll processing clients)
- NDIS participant information — first name, NDIS number, plan dates, support categories and budgets (for invoicing and budget mapping clients)
- Financial records — invoices, receipts, bank statements, payroll data provided by you for bookkeeping purposes
- Website enquiry information — name, email, message content submitted through our contact form
We do not collect sensitive personal information beyond what is required for NDIS financial services, and we never collect it speculatively.
3. How we use your information
Information is used solely for the purpose it was provided:
- Delivering the specific financial services you have engaged us to provide
- Communicating with you about your engagement — queries, reports, and updates
- Meeting our own legal obligations — tax, ATO reporting, professional compliance
- Improving the quality and efficiency of our services
We do not use your information for marketing to third parties, sell data to anyone, or use personal information for any purpose beyond what is reasonably expected for a financial services engagement.
4. How we store and protect your data
All data shared with ANDICare Finance is handled with care:
- Client documents are stored in encrypted cloud storage with access limited to ANDICare Finance personnel only
- Financial software access is protected by strong passwords and multi-factor authentication
- Sensitive documents (TFNs, bank details, NDIS participant information) are never transmitted via unencrypted email — we use secure file sharing methods
- Paper documents are not retained — all records are digitised and securely stored
- We do not store more data than necessary and review retention regularly
5. Who we share information with
ANDICare Finance does not sell, rent, or trade your information. We may share information only in these specific circumstances:
- The ATO — payroll data submitted via STP Phase 2, and any other legally required reporting
- Your superannuation funds — employer super contributions on behalf of your employees
- The NDIA — NDIS invoices and claiming on your behalf as your authorised representative
- Plan managers — invoices submitted on your behalf as directed by you
- Your tax agent or accountant — only when you explicitly direct us to share information
- Our cloud accounting software providers — Xero and/or MYOB, which have their own privacy policies and are bound by Australian privacy law
We will never share your information with any other third party without your explicit written consent.
6. NDIS participant information
ANDICare Finance understands that NDIS participant information is particularly sensitive. We handle participant data with the highest level of care:
- Participant information is used only for the financial services you have engaged us for — invoicing, budget mapping, and claiming
- We use first name and NDIS number only where possible — we do not retain full personal profiles of participants
- Participant data is never shared with any party other than those directly involved in the NDIS claiming and payment process
- Access to participant information within ANDICare Finance is restricted to personnel directly involved in your account
7. Your rights
Under the Australian Privacy Principles, you have the right to:
- Request access to the personal information we hold about you or your organisation
- Request correction of any inaccurate information we hold
- Request deletion of your information when our engagement ends (subject to our legal record-keeping obligations)
- Withdraw consent for us to hold or use specific information
- Make a complaint if you believe we have mishandled your information
To exercise any of these rights, contact us at human@finance.andicare.com.au. We will respond within 14 days.
8. Data retention
We retain financial records for the minimum period required by law — generally 7 years for tax and financial records under ATO requirements. When retention periods expire, records are securely deleted. Engagement data is retained for the duration of our working relationship and deleted within 90 days of formal engagement termination unless a longer period is legally required.
9. Website and contact form
When you submit our contact form, your name, email, and message are sent directly to human@finance.andicare.com.au. This information is used only to respond to your enquiry. If you do not proceed to engage our services, your enquiry information is not retained beyond 30 days.
Our website does not use tracking cookies, advertising pixels, or third-party analytics tools that share your data with external parties.
10. Changes to this policy
We may update this policy from time to time as our services evolve or as legal requirements change. The current version will always be available at this URL. For material changes, we will notify active clients directly.
11. Contact us
For any privacy-related questions, requests, or complaints:
ANDICare Finance
Adelaide, South Australia
Email: human@finance.andicare.com.au
If you are not satisfied with our response to a complaint, you may contact the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.