SKOOT Community Access Privacy Policy
JNC Lilim Pty Ltd t/a SKOOT COMMUNITY ACCESS
PRIVACY AND INFORMATION MANAGEMENT POLICY
Version: 2.0
Approved: June 2026
Review Date: June 2027
Privacy at a Glance
SKOOT Community Access ("SKOOT", "we", "us", "our") respects your privacy and is committed to protecting your personal information.
We collect personal, sensitive and health information to provide disability support services, transport services, community access supports and related services under the National Disability Insurance Scheme (NDIS).
Information may be collected through our staff, website, telephone systems, the SKOOT Community Access App ("SKOOT CA App"), and other approved service delivery systems.
We only collect information that is necessary to deliver our services, meet legal obligations and maintain participant and worker safety.
We do not sell personal information.
1. Purpose
This Privacy and Information Management Policy explains how SKOOT Community Access collects, uses, stores, discloses and protects personal information.
This policy has been developed in accordance with:
- Privacy Act 1988 (Cth)
- Privacy Amendment (Enhancing Privacy Protection) Act 2012
- Australian Privacy Principles (APPs)
- National Disability Insurance Scheme Act 2013 (Cth)
- NDIS Practice Standards
- Notifiable Data Breaches Scheme
- Applicable State and Territory legislation
2. Scope
This policy applies to:
- Participants
- Nominees
- Guardians
- Family members
- Support Coordinators
- Plan Managers
- Website users
- SKOOT CA App users
- Support Partners
- Contractors
- Employees
- Volunteers
This policy applies to information collected through:
- Face-to-face interactions
- Telephone calls
- SMS messages
- Emails
- Website enquiries
- Social Media Page Enquiries
- The SKOOT CA App
- Third-party systems used by SKOOT
- Service delivery records
3. Information We Collect
Participant Information
We may collect:
- Full name
- Preferred name
- Date of birth
- Address
- Email address
- Phone numbers
- Emergency contact details
- NDIS number
- Funding information
- Nominee or guardian information
- Plan Manager details
- Support Coordinator details
Health and Support Information
We may collect:
- Disability information
- Support requirements
- Risk assessments
- Behaviour support information
- Mobility requirements
- Communication preferences
- Medical information relevant to service delivery
- Service notes
- Progress notes
- Incident reports
- Feedback and complaints
Support Partner Information
We may collect:
- Personal details
- Contact information
- Driver licence information
- NDIS Worker Screening Checks
- Working With Children Checks
- First Aid qualifications
- Training records
- Vehicle information
- Insurance documents
- Compliance records
- Shift attendance records
- Service delivery records
Financial Information
We may collect:
- Invoices
- Payment records
- Bank account information
- Refund records
- Subscription payment information
- Funding management records
4. The SKOOT Community Access App
SKOOT provides digital services through the SKOOT Community Access App.
The App is powered by third-party technology providers, to assist with:
- Booking management
- Rostering
- Participant records
- Support Partner records
- Shift management
- Timesheets
- Service notes
- Incident reporting
- Compliance management
- Communication
- Invoicing and billing
Participants and Support Partners may use the App to:
- View bookings
- Manage schedules
- Receive notifications
- Record service delivery
- Submit notes and reports
- Communicate with SKOOT
- Access service information
The App may request permission to access:
- GPS/location services
- Camera
- Microphone
- Device storage
- Push notifications
Some App features may not operate correctly if these permissions are disabled.
5. GPS Tracking, Location Services and Service Verification
To support participant safety, worker safety, compliance and service verification, SKOOT utilises GPS-enabled systems.
Location information may be collected when a Support Partner:
- Starts a shift
- Ends a shift
- Delivers transport supports
- Delivers community access supports
- Uses the SKOOT CA App during an active booking
Location information may include:
- GPS coordinates
- Arrival times
- Departure times
- Route information
- Travel distances
- Vehicle location during active supports
GPS information may be used to:
- Verify attendance
- Confirm service delivery
- Confirm transport routes
- Verify travel claims
- Investigate complaints
- Investigate incidents
- Resolve disputes
- Improve participant safety
- Meet NDIS compliance obligations
- Support invoicing processes
During active bookings, limited real-time location information may be visible to participants, authorised representatives and Support Partners where necessary to facilitate service delivery and improve safety.
By accepting services from SKOOT Community Access, participants acknowledge that GPS-enabled systems and electronic attendance verification may be utilised during service delivery.
6. Communications and AI-Assisted Services
SKOOT may communicate with participants, representatives and Support Partners through:
- Telephone
- SMS
- Push notifications
- Website contact forms
- The SKOOT CA App
- Automated communication systems
- AI-assisted communication systems
Communication records may be retained for:
- Quality assurance
- Training purposes
- Service improvement
- Complaint investigations
- Incident investigations
- Legal compliance
AI-assisted systems may be used to assist with booking enquiries, call routing, scheduling and customer support.
Personal information provided through these systems will be managed in accordance with this policy.
7. Photographs, Video and Audio
SKOOT may collect photographs, videos or recordings where appropriate consent has been provided.
This may include:
- Participant identification
- Incident reporting
- Service delivery requirements
- Promotional materials (with separate consent)
- Quality and training activities
The SKOOT CA App may offer speech-to-text functionality.
Where utilised:
- Audio may be processed to create written notes
- Transcribed notes may be stored within participant or worker records
- Audio recordings themselves may not be retained
8. How We Use Information
We use personal information to:
- Deliver supports and services
- Coordinate bookings
- Allocate Support Partners
- Facilitate transport services
- Manage participant safety
- Generate invoices
- Process payments
- Manage subscriptions
- Communicate with stakeholders
- Conduct quality improvement activities
- Investigate incidents and complaints
- Meet legal obligations
- Meet NDIS compliance requirements
We will not use personal information for unrelated purposes without consent unless authorised by law.
9. Sharing Information
Information may be shared with:
- Participants
- Nominees
- Guardians
- Support Partners
- Support Coordinators
- Plan Managers
- Allied health professionals (where authorised)
- Government agencies
- Regulatory bodies
- Professional advisers
Information may also be shared with technology providers that support SKOOT's operations, including providers responsible for:
- Service management systems
- Cloud storage
- Accounting systems
- Payment processing
- Communications platforms
- Mobile applications
Information is only disclosed where:
- Consent has been provided;
- Disclosure is necessary for service delivery; or
- Disclosure is required or authorised by law.
10. Information Security
SKOOT takes reasonable steps to protect information from misuse, interference, loss, unauthorised access, modification or disclosure.
Security measures include:
- Password-protected systems
- Multi-factor authentication
- Role-based access controls
- Encryption of sensitive information
- Secure cloud storage
- Audit logs
- Staff privacy training
- Secure disposal processes
Only authorised personnel may access information required to perform their role.
11. Storage and Retention of Records
Participant information is maintained in secure electronic systems and, where required, secure physical records.
Records may include:
- Participant files
- Service agreements
- Notes and assessments
- Incident reports
- Communications
- Invoices and payment records
- GPS and attendance records
Retention periods generally include:
- Participant records: minimum 7 years after service cessation
- Financial records: minimum 7 years
- Records relating to minors: until age 25 or 7 years after service cessation, whichever is longer
- Compliance records: as required by legislation
- GPS and attendance records: retained for operational, compliance and dispute resolution purposes
When records are no longer required, they will be securely destroyed or de-identified.
12. Access and Correction
Individuals may request access to their personal information or request corrections if information is inaccurate, incomplete or out of date.
Requests should be directed to:
The Directors
SKOOT Community Access
Email:
hq@skootca.com.au
Phone: 08 7118 8801
Identity verification may be required before information is released.
13. Data Breaches
Where a data breach is likely to result in serious harm, SKOOT will comply with the Notifiable Data Breaches Scheme.
This may include:
- Investigating the incident
- Containing the breach
- Notifying affected individuals
- Notifying the Office of the Australian Information Commissioner (OAIC)
- Taking corrective action
14. Website Cookies and Analytics
SKOOT websites may utilise cookies and analytics tools to:
- Improve website performance
- Monitor website functionality
- Improve user experience
- Understand website usage trends
Users may manage cookie settings through their browser.
15. Complaints
Privacy complaints may be submitted to:
The Directors
SKOOT Community Access
Email:
hq@skootca.com.au
Phone: 08 7118 8801
We aim to acknowledge complaints within seven (7) days and resolve them within thirty (30) days where possible.
If you are dissatisfied with our response, you may contact:
Office of the Australian Information Commissioner (OAIC)
Website:
www.oaic.gov.au
Phone: 1300 363 992
or
NDIS Quality and Safeguards Commission
Website:
www.ndiscommission.gov.au
16. Policy Review
This policy will be reviewed annually or sooner if required due to legislative, operational or technological changes.
Appendix 1 – Australian Privacy Principles (APPs)
SKOOT Community Access complies with the thirteen Australian Privacy Principles:
- Open and transparent management of personal information
- Anonymity and pseudonymity
- Collection of solicited personal information
- Dealing with unsolicited personal information
- Notification of collection
- Use or disclosure of personal information
- Direct marketing
- Cross-border disclosure
- Adoption, use or disclosure of government identifiers
- Quality of personal information
- Security of personal information
- Access to personal information
- Correction of personal information

