Damarco Enterprises Pty Ltd T/A St Anastasia's Care — Privacy Policy
Introduction
This Privacy Policy outlines the practices of Damarco Enterprises Pty Ltd (ABN 49 649 563 388) trading as St Anastasia's Care ("we", "our" or "the Company") with respect to information collected from users who access our website at www.stanastasiascare.com.au ("Site"), or who otherwise share personal information with us (collectively: "Users").
We provide disability support services under the National Disability Insurance Scheme (NDIS) and aged care services under the Support at Home program.
We are bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles ("APPs"), and, in relation to health information, by the Health Records and Information Privacy Act 2002 (NSW). This policy explains how we collect, hold, use and disclose personal information, and how you can access, correct or complain about our handling of it.
Grounds for data collection
Processing of your personal information (meaning any information which may potentially allow your identification by reasonable means; hereinafter "Personal Information") is carried out on the following grounds:
- Performance of our services and contractual obligations — to deliver care and support services to you or the person you care for, to administer service agreements, rosters, invoicing and payments, and to respond to your enquiries.
- Consent — where we collect sensitive information (including health information, disability, medication and treatment details, cultural or religious background, and criminal history for worker screening purposes), we do so with your consent, unless the law permits or requires otherwise. You may withdraw consent at any time by contacting us, though this may affect our ability to provide services safely.
- Compliance with legal and regulatory obligations — including our obligations under the Privacy Act 1988 (Cth), the National Disability Insurance Scheme Act 2013 (Cth) and the NDIS Practice Standards, the Aged Care Act 2024 (Cth), the Aged Care Rules 2025 (Cth) and the Aged Care Quality Standards, work health and safety laws, employment and taxation law, and mandatory reporting obligations.
- Our legitimate interests and permitted general situations — including protecting the health and safety of participants, clients and staff, preventing and investigating fraud or misconduct, maintaining quality and incident management systems, and establishing or defending legal claims.
When you use the Site, you consent to the collection, storage, use, disclosure and other uses of your Personal Information as described in this Privacy Policy.
We encourage our Users to read this Privacy Policy carefully and to use it to make informed decisions.
What information we collect
We collect two types of data and information from Users.
Non-personal Information. The first type is un-identified and non-identifiable information pertaining to a User, which may be made available or gathered via your use of the Site ("Non-personal Information"). We are not aware of the identity of a User from which the Non-personal Information was collected. This may include aggregated usage information and technical information transmitted by your device, including certain software and hardware information (e.g. the type of browser and operating system your device uses, language preference, access time, etc.) in order to enhance the functionality of our Site. We may also collect information about your activity on the Site (e.g. pages viewed, browsing, clicks, actions, etc.).
Personal Information. The second type is individually identifiable information — information that identifies an individual, or that may with reasonable effort identify an individual. Such information includes:
- Device information: We collect Personal Information from your device, including geolocation data, IP address, unique identifiers (e.g. MAC address and UUID) and other information relating to your activity through the Site.
- Enquiry and registration information: When you contact us or complete a form on our Site, we may ask you to provide details such as your full name, email address, postal address, telephone number, your relationship to the person requiring support, and the nature of your enquiry.
- Client and participant information: Where you become a client or participant (or where you are a family member, guardian, nominee or advocate of one), we collect information necessary to provide safe and appropriate care. This includes date of birth, gender, address and contact details, emergency contact details, next of kin, preferred language, cultural and religious background, and living arrangements.
- Health and other sensitive information: medical history and current conditions, disability and functional needs, medications, allergies, treating practitioners, care and support plans, behaviour support plans, risk assessments, progress and shift notes, and incident reports. We may also collect information about your cultural or religious background, ethnic origin, and sexual orientation where it is relevant to providing culturally safe and person-centred support.
- Government identifiers and funding information: NDIS participant number, My Aged Care client ID and Support at Home classification and budget details, Medicare number, Department of Veterans' Affairs number, Centrelink or pension details, private health insurance details, and plan or funding management arrangements. We collect these only where reasonably necessary and we do not use government identifiers as our own client reference numbers.
- Financial information: billing address, bank account or payment details, invoices and payment history.
- Legal and authority information: guardianship or administration orders, powers of attorney, advance care directives, nominee arrangements and consent forms.
- Worker, contractor and applicant information: where you apply to work with us, we collect your résumé, employment and qualification history, referee details, right-to-work status, professional registrations, NDIS Worker Screening Check or Police Check results, Working with Children Check, driver licence and vehicle insurance details, immunisation status, bank and superannuation details, tax file number and emergency contacts.
- Feedback, complaints and communications: correspondence, call records, feedback, complaints and any information you provide when you interact with us.
If you do not provide the Personal Information we request, we may not be able to provide services to you, or the services we provide may be limited or unsafe.
Unsolicited information and anonymity
If we receive Personal Information we did not solicit and we could not have collected it under the APPs, we will destroy or de-identify it where lawful to do so. You may deal with us anonymously or under a pseudonym when making a general enquiry, but this will not be practicable where we are providing care services or where we are required by law to identify you.
How do we receive information about you?
We receive your Personal Information from various sources:
- When you voluntarily provide us your personal details in order to register on our Site or contact us;
- When you use or access our Site in connection with your use of our services;
- Directly from you, your family, guardian, nominee, advocate or authorised representative during intake, assessment and the course of service delivery;
- From referrers and funding bodies, including the National Disability Insurance Agency, My Aged Care, support coordinators, plan managers, hospitals, discharge planners and government departments;
- From your treating health practitioners, allied health providers and other service providers, with your consent;
- From referees, screening bodies and background-check providers, where you apply to work with us;
- From third party providers, services and public registers (for example, traffic analytics vendors).
We collect Personal Information about you from someone else only where you have consented, or where it is unreasonable or impracticable to collect it directly from you.
How we use the information we collect
We do not rent, sell, or share Users' information with third parties except as described in this Privacy Policy.
We may use the information for the following purposes:
- Delivering care and support — assessing your needs, developing and reviewing care and support plans, matching and rostering suitable support workers, and providing the services you have requested;
- Coordinating your care — communicating with your treating practitioners, allied health providers, family members, guardians, nominees and advocates, where authorised;
- Health and safety — responding to emergencies, managing clinical and behavioural risk, and recording and investigating incidents;
- Administration and billing — managing service agreements, claiming from the NDIA, My Aged Care, insurers or other funders, invoicing, and collecting payments;
- Communicating with you — sending notices regarding our services, providing technical information, and responding to any customer service issue you may have;
- Keeping you informed of our latest updates and services;
- Quality, compliance and improvement — quality assurance, auditing, accreditation, staff training and supervision, complaints handling, and meeting our reporting obligations to regulators including the NDIS Quality and Safeguards Commission and the Aged Care Quality and Safety Commission;
- Recruitment and workforce management — assessing applications, verifying screening clearances and qualifications, and managing employment;
- Marketing our services (see "Marketing" below);
- Conducting statistical and analytical work intended to improve the Site and our services;
- Meeting our legal obligations, including responding to subpoenas, coronial inquiries, mandatory reporting and regulatory requests.
In addition to the different uses listed above, we may transfer or disclose Personal Information to our subsidiaries, affiliated companies and subcontractors.
In addition to the purposes listed in this Privacy Policy, we may share Personal Information with our trusted third party providers, who may be located in different jurisdictions across the world, for any of the following purposes:
- Hosting and operating our Site;
- Providing client management, rostering, care planning and electronic records software;
- Providing you with our services, including a personalised display of our Site;
- Storing and processing information on our behalf (including cloud storage and backup providers);
- Processing payments and providing accounting, bookkeeping and payroll services;
- Conducting worker screening and background checks;
- Providing you with marketing offers and promotional materials related to our Site and services;
- Performing research, technical diagnostics or analytics;
- Providing legal, insurance, audit and professional advisory services.
We may also disclose information to:
- the National Disability Insurance Agency, the NDIS Quality and Safeguards Commission, the Department of Health, Disability and Ageing, the Aged Care Quality and Safety Commission, My Aged Care, Services Australia and other funding or regulatory bodies;
- hospitals, ambulance services, doctors and other health providers involved in your care, including in an emergency;
- your family members, guardian, nominee, advocate or other authorised representative;
- police, courts, tribunals and public guardianship or trustee bodies where required or authorised by law.
We may also disclose information if we have a good faith belief that disclosure is helpful or reasonably necessary to: (i) comply with any applicable law, regulation, legal process or governmental request; (ii) enforce our policies (including our Agreement), including investigations of potential violations; (iii) investigate, detect, prevent, or take action regarding illegal activities or other wrongdoing, suspected fraud or security issues; (iv) establish or exercise our rights or defend against legal claims; (v) prevent harm to the rights, property or safety of us, our users, yourself or any third party; or (vi) collaborate with law enforcement agencies, or where we find it necessary in order to enforce intellectual property or other legal rights.
Your rights
You may request to:
- Receive confirmation as to whether or not personal information concerning you is being processed, and access your stored personal information, together with supplementary information;
- Receive a copy of personal information you directly volunteer to us in a structured, commonly used and machine-readable format;
- Request correction of personal information that is in our control that is inaccurate, out of date, incomplete, irrelevant or misleading;
- Request erasure of your personal information, where we are not required by law to retain it;
- Object to the processing of your personal information by us, or withdraw a consent you have given;
- Request that we restrict processing of your personal information;
- Opt out of receiving direct marketing communications from us;
- Lodge a complaint with us or with a supervisory authority.
However, please note that these rights are not absolute, and may be subject to our own legitimate interests and to regulatory requirements. In particular, we are required by law to retain certain care, clinical and financial records for minimum periods, and we may refuse access where an exception in APP 12 applies (for example, where access would pose a serious threat to the life, health or safety of any individual, or would unreasonably affect another person's privacy). If we refuse a request, we will tell you why in writing and explain how you can complain.
We will normally respond to a request for access or correction within 30 days. We do not charge for making a request, but we may charge a reasonable fee for giving access.
Complaints
If you believe we have breached the Australian Privacy Principles or mishandled your personal information, please contact our Privacy Officer using the details below.
We will acknowledge your complaint within 5 business days and aim to resolve it within 30 days.
If you are not satisfied with our response, you can contact:
- Office of the Australian Information Commissioner (OAIC) — GPO Box 5218, Sydney NSW 2001 · 1300 363 992 · enquiries@oaic.gov.au · www.oaic.gov.au
- NSW Information and Privacy Commission (for health information in NSW) — 1800 472 679 · ipcinfo@ipc.nsw.gov.au
- NDIS Quality and Safeguards Commission — 1800 035 544 · www.ndiscommission.gov.au
- Aged Care Quality and Safety Commission — 1800 951 822 · www.agedcarequality.gov.au
Contact — Privacy Officer
If you wish to exercise any of the rights above, make a complaint, or receive more information, please contact our Privacy Officer:
- Privacy Officer: Natasha Stevanovski, Managing Director
- Email: privacy@stanastasiascare.com
- Phone: 1300 055 918
- Post: Suite 122, Shop 1, 130 Oyster Bay Road, Oyster Bay NSW 2225
Retention
We will retain your personal information for as long as necessary to provide our services, and as necessary to comply with our legal obligations, resolve disputes, and enforce our policies. Retention periods will be determined taking into account the type of information collected and the purpose for which it was collected, bearing in mind the requirements applicable to the situation and the need to destroy outdated, unused information at the earliest reasonable time.
Under applicable laws and regulations, we will keep records containing client personal data, service agreements, communications and anything else as required. In particular:
- Health information is retained for at least 7 years from the date of last service. Where the individual was under 18 at the time of last service, it is retained until they turn 25, as required by the Health Records and Information Privacy Act 2002 (NSW).
- NDIS records are retained for at least 7 years from the date the record was made, as required under the NDIS Practice Standards.
- Aged care and Support at Home records are retained for at least 7 years, as required under the Aged Care Act 2024 (Cth) and the Aged Care Rules 2025 (Cth).
- Financial and taxation records are retained for at least 7 years.
- Employment records are retained for at least 7 years after the end of employment.
Where we no longer need your Personal Information and are not required by law to retain it, we will destroy it or de-identify it securely.
We may rectify, replenish or remove incomplete or inaccurate information at any time and at our own discretion.
Cookies
We and our trusted partners use cookies and other technologies in our related services, including when you visit our Site or access our services.
A "cookie" is a small piece of information that a website assigns to your device while you are viewing a website. Cookies are helpful and can be used for various purposes, including allowing you to navigate between pages efficiently, enabling automatic activation of certain features, remembering your preferences and making the interaction between you and our services quicker and easier. Cookies are also used to compile statistical data on your use of our services.
The Site uses the following types of cookies:
a. Session cookies, which are stored only temporarily during a browsing session in order to allow normal use of the system, and are deleted from your device when the browser is closed;
b. Persistent cookies, which are read only by the Site, saved on your computer for a fixed period, and are not deleted when the browser is closed. Such cookies are used where we need to know who you are for repeat visits — for example, to store your preferences for the next sign-in;
c. Third party cookies, which are set by other online services that run content on the page you are viewing — for example, by third party analytics companies who monitor and analyse our web access.
Cookies do not contain any information that personally identifies you, but Personal Information that we store about you may be linked, by us, to the information stored in and obtained from cookies. You may remove cookies by following the instructions in your device preferences; however, if you choose to disable cookies, some features of our Site may not operate properly and your online experience may be limited.
We also use a tool called "Google Analytics" to collect information about your use of the Site. Google Analytics collects information such as how often users access the Site and what pages they visit. We use the information we get from Google Analytics only to improve our Site and services. Google Analytics collects the IP address assigned to you on the date you visit the Site, rather than your name or other identifying information. We do not combine the information collected through Google Analytics with personally identifiable information. Google's ability to use and share information collected by Google Analytics about your visits to this Site is restricted by the Google Analytics Terms of Use and the Google Privacy Policy.
Third party collection of information
Our policy only addresses the use and disclosure of information we collect from you. To the extent you disclose your information to other parties or sites throughout the internet, different rules may apply to their use or disclosure of the information you disclose to them. Accordingly, we encourage you to read the terms and conditions and privacy policy of each third party to whom you choose to disclose information.
This Privacy Policy does not apply to the practices of companies that we do not own or control, or to individuals whom we do not employ or manage, including any of the third parties to which we may disclose information as set forth in this Privacy Policy.
How do we safeguard your information?
We take great care in implementing and maintaining the security of the Site and your information. We employ industry standard procedures and policies to ensure the safety of the information we collect and retain, and to prevent unauthorised access to or use of that information. Our measures include:
- storing electronic records in access-controlled systems protected by encryption in transit and at rest, individual user accounts, strong password requirements and multi-factor authentication;
- restricting access to Personal Information to staff who need it to perform their role, on a least-privilege basis;
- requiring all staff, students and contractors to sign confidentiality agreements and complete privacy and information-security training on induction and periodically thereafter;
- storing paper records in locked cabinets in secured premises;
- maintaining firewalls, anti-malware protection, patching and regular backups;
- reviewing and removing access promptly when a worker's role changes or ends;
- requiring third party providers to comply with security requirements consistent with this Privacy Policy and the Privacy Act 1988 (Cth);
- securely destroying or de-identifying records that are no longer required.
Data breaches. We maintain a data breach response plan. If we suspectan eligible data breach that is likely to result in serious harm, we will investigate, contain it, and notify affected individuals and the Office of the Australian Information Commissioner as required under the Notifiable Data Breaches scheme.
Although we take reasonable steps to safeguard information, we cannot be responsible for the acts of those who gain unauthorised access to or abuse our Site, and we make no warranty, express, implied or otherwise, that we will prevent such access.
Overseas disclosure of data
We use a number of third party software providers to operate our business. Some of these store or process Personal Information on servers located outside Australia — principally in the United States, and in the case of our accounting software, New Zealand. Our providers are large international technology companies that may also operate data centres in other countries.
The main systems we use, and where information held in them is stored, are:
ShiftCare - Client management, care plans, progress notes and rostering / Australia
Google Workspace (including Gmail)Email - calendars and documents / United States and other countries in which Google operates data centres
Dropbox - File and document storage / United States
Xero - Accounting, invoicing and payroll / United States and New Zealand
GoDaddy and Duda - Website hosting and website builder / United States
Google Analytics - Website analytics / United States and other countries in which Google operates data centres
Our client care records — including care plans, progress notes and health information — are held in ShiftCare, which stores data in Australia.
Before disclosing Personal Information overseas, we take reasonable steps to ensure the recipient does not breach the Australian Privacy Principles, including by putting contractual protections in place with each provider.
If you would like more detail about any of these providers, please contact our Privacy Officer.
Where we disclose data to recipients in the European Economic Area, or transfer the data of individuals in the EEA, we will do so only to countries recognised by the European Commission as providing an adequate level of data protection, or under legal agreements ensuring an adequate level of data protection.
Marketing
We may use your Personal Information — such as your name, email address and telephone number — ourselves, or through our third party subcontractors, for the purpose of providing you with promotional materials concerning our services which we believe may interest you.
Out of respect for your right to privacy, we provide you within such marketing materials with a means to decline receiving further marketing offers from us. If you unsubscribe, we will remove your email address or telephone number from our marketing distribution lists. You can also opt out at any time by contacting us using the details in this policy. We do not sell or disclose your personal information to third parties for the purpose of direct marketing by those third parties.
Please note that even if you have unsubscribed from receiving marketing emails from us, we may send you other types of important email communications without offering you the opportunity to opt out of receiving them. These may include customer service announcements, service and rostering notifications, or administrative notices.
Corporate transaction
We may share information in the event of a corporate transaction (e.g. sale of a substantial part of our business, merger, consolidation or asset sale). In the event of the above, the transferee or acquiring company will assume the rights and obligations described in this Privacy Policy.
Minors
We understand the importance of protecting children's privacy, especially in an online environment. The Site is not designed for or directed at children. Under no circumstances will we allow use of our services by minors without prior consent or authorisation by a parent or legal guardian. We do not knowingly collect Personal Information from minors via the Site.
Where we provide services to a person under 18, we collect and handle their Personal Information with the consent of a parent or legal guardian, and we take into account the young person's capacity to make their own decisions where appropriate.
If a parent or guardian becomes aware that their child has provided us with Personal Information without their consent, they should contact us at privacy@stanastasiascare.com.
Updates or amendments to this Privacy Policy
We reserve the right to periodically amend or revise this Privacy Policy; material changes will be effective immediately upon display of the revised Privacy Policy. The last revision will be reflected in the "Last modified" section below. Your continued use of the Site, following notification of such amendments on our website, constitutes your acknowledgment and consent to those amendments and your agreement to be bound by their terms.
How to contact us
If you have any general questions about the Site, or about the information we collect about you and how we use it, you can contact us:
Damarco Enterprises Pty Ltd T/A St Anastasia's Care ABN: 49 649 563 388
Suite 122, Shop 1, 130 Oyster Bay Road, Oyster Bay NSW 2225
Phone: 1300 055 918
Email: privacy@stanastasiascare.com
Web: www.stanastasiascare.com.au
Last modified: 12 August 2026