MyCareFinders

Privacy Policy

Your privacy matters to us. This policy explains how MyCareFinders handles your personal information, and sets out your rights under Australian privacy law. We have written it to meet and exceed the standards in the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

Last updated: 26 August 2026

We collect only what we need

We ask for the minimum information required to connect you with the right NDIS support, and nothing more.

Your data is protected

Information is encrypted in transit and at rest, and access is limited to authorised team members.

We are transparent

We explain in plain language what we collect, why, and exactly who it is shared with.

You stay in control

You can access, correct or delete your personal information, and opt out of marketing at any time.

1.About this policy & who we are

MyCareFinders is operated by Local Knowledge Pty Ltd (ABN 15 116 200 796). References to “MyCareFinders”, “we”, “us” or “our” in this policy mean Local Knowledge Pty Ltd. We operate the website at mycarefinders.com.au — an independent Australian directory that helps NDIS participants, their families, carers and support networks find registered disability support providers and Plan Managers, and connect with them. We also provide tools and services to the providers listed in our directory.

This Privacy Policy applies to all personal information we collect through our website, forms, email, phone and any related services. By using our website or submitting an enquiry, you agree to the handling of your information as described in this policy.

We are bound by the Privacy Act 1988 (Cth) and the 13 Australian Privacy Principles (APPs). Where a state or territory privacy or health-records law provides you with greater protection, we comply with that law as well.

MyCareFinders is an independent directory and referral service. We are not the NDIA, we are not the NDIS Quality and Safeguards Commission, and we do not manage your NDIS funds or plan budgets. We connect you with providers who deliver those services. MyMoney® and MyGoals® are registered trademarks, and Local Knowledge™ and MyCareFinders™ are trademarks, of Local Knowledge Pty Ltd.

2.Information we collect

The personal information we collect depends on how you interact with us. It may include:

Information you give us directly

  • Your name, email address and phone number.
  • Your suburb and postcode (so we can match you with local support).
  • The support type or topic you are enquiring about, and the days and times you prefer to be contacted.
  • Any notes, questions or details you choose to include in an enquiry, care request or message.
  • For providers: business name, ABN, NDIS registration details, contact details and account login credentials.

Sensitive information

Because we work in the disability sector, you may choose to tell us information that is “sensitive information” under the Privacy Act — for example, that you are an NDIS participant, or details about your disability or support needs. We only collect sensitive information with your consent and only where it is reasonably necessary to help connect you with appropriate support. Please only share what you are comfortable sharing.

Information we collect automatically

  • Device and browser type, and general location derived from your IP address.
  • Pages you view, links you click, and how you move through the site.
  • The page or campaign that referred you to us (including UTM tracking parameters).
  • Error logs and performance data used to keep the site working reliably.

3.Provider directory information

Our directory includes information about NDIS providers that is sourced from the publicly available NDIS Provider Register and other public sources, such as business name, registration status, registration groups, service types and public contact details.

If you are a provider and would like to claim, correct, update or remove your listing, you can do so at any time via our Remove Your Listing page or by contacting our Privacy Officer. We honour opt-out and removal requests promptly.

4.How we collect your information

We collect personal information:

  • Directly from you, when you complete a form, request a callback, submit a care request, send us an email, call us, or create a provider account.
  • Automatically, through cookies and analytics as you use our website (see the Cookies section below).
  • From publicly available sources, such as the NDIS Provider Register, for directory listings.

Where it is reasonable and practical to do so, we collect personal information directly from you. If someone submits your information on your behalf (for example, a family member or support coordinator), we rely on them having your authority to do so.

5.How we use your information

We use your personal information to:

  • Respond to your enquiry and connect you with a suitable NDIS provider or Plan Manager.
  • Contact you by phone or email about your enquiry, including at the times you told us you prefer.
  • Provide, maintain and improve our website, directory and services.
  • Personalise the support and information we show you.
  • Send you relevant updates or marketing where you have consented (you can opt out at any time).
  • Keep our services safe and secure, prevent fraud and misuse, and enforce our terms.
  • Comply with our legal obligations and respond to lawful requests.

We will only use your personal information for the purpose we collected it, for a directly related purpose you would reasonably expect, or where you have consented or the law permits or requires it.

6.When we share information

We never sell, rent or trade your personal information to third parties, and we never share it with third-party marketers, call centres or data brokers.

We only share your personal information in these limited situations:

  • NDIS providers and Plan Managers: where you ask us to connect you, we share the details needed for that provider to contact you and help with your enquiry.
  • Service partners: trusted suppliers who help us operate, such as secure cloud hosting, database, email delivery and analytics providers. They may only use your information to provide services to us, under contract and strict confidentiality.
  • Legal and safety reasons: where required or authorised by law, a court or regulator, or where necessary to protect the safety of a person or the public.
  • Business transfer: if our business is restructured, merged or transferred, information may be disclosed to the new owner under equivalent privacy protections.

7.Marketing & communications

We may send you helpful updates, guides or offers where you have opted in or where the law allows. Every marketing email includes an easy unsubscribe link, and we honour unsubscribe requests promptly, consistent with the Spam Act 2003 (Cth).

Some messages are transactional — for example, confirming we received your enquiry. These are not marketing and are necessary to respond to your request. You can opt out of marketing at any time by using the unsubscribe link or emailing us.

8.Cookies & analytics

We use cookies and similar technologies to keep the site working, remember your preferences, understand how the site is used, and improve it. Some cookies are essential; others help us measure and improve performance.

We may use analytics tools (such as privacy-respecting website analytics) to understand aggregate usage patterns. You can control or delete cookies through your browser settings. Disabling some cookies may affect how the site works.

9.Artificial intelligence tools

We use artificial intelligence tools to help us respond to enquiries, summarise information, and improve the support we provide (for example, our AI guide and internal enquiry-handling tools). Where AI is used to process the content of an enquiry, we take steps to limit the personal information involved and to keep it secure.

AI assists our team — a real person is responsible for the support and communications you receive. We do not use your personal information to train publicly available third-party AI models.

10.Overseas disclosure

We aim to store and process personal information in Australia. Some of our trusted service partners (for example, cloud infrastructure or software providers) may store or process data on servers located overseas. Where this happens, we take reasonable steps to ensure those partners handle your information consistently with the Australian Privacy Principles, under appropriate contractual protections.

11.How we keep information secure

We take the security of your information seriously and use layered safeguards, including:

  • Encryption of data in transit (TLS/SSL) and encryption of stored data.
  • Role-based access controls, so staff only see the information they need.
  • Secure, reputable cloud hosting with monitoring and regular backups.
  • Staff obligations of confidentiality and ongoing security awareness.
  • Regular review of our systems and access.

No method of transmission or storage is completely secure, but we work continually to protect your information and to respond quickly if an issue arises.

12.Data breach response

We maintain a data breach response plan. If a data breach occurs that is likely to result in serious harm to any individual, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) as required under the Notifiable Data Breaches scheme, and take steps to contain and remediate the breach.

13.How long we keep information

We keep personal information only for as long as we need it for the purposes described in this policy, to resolve your enquiry, to meet our legal and record-keeping obligations, or for a reasonable period afterwards in case you return to us. When information is no longer needed, we securely delete or de-identify it.

14.Your rights & choices

Under Australian privacy law, you have the right to:

  • Access the personal information we hold about you.
  • Correct information that is inaccurate, incomplete or out of date.
  • Request deletion of your information, subject to our legal obligations.
  • Opt out of marketing communications at any time.
  • Ask how we handle your information and raise a concern or complaint.
  • Deal with us anonymously or by pseudonym where it is lawful and practical.

To exercise any of these rights, email [email protected]. We may need to verify your identity first. There is normally no charge, and we aim to respond within 5 business days and to resolve access requests within 30 days.

15.Children & vulnerable people

We understand many of the people we help are participants, families and carers, and that some are vulnerable. We handle all personal information with care and respect. Our website is intended to be used by adults; where information about a young person or a person with reduced capacity is provided, we rely on a parent, guardian or authorised representative providing it with proper authority.

17.Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in our practices or the law. The “last updated” date at the top shows when it was last revised. We encourage you to review it periodically. Significant changes will be made clear on this page.

18.Complaints & how to contact us

If you have a question, concern or complaint about how we handle your personal information, please contact our Privacy Officer first so we can try to resolve it:

We will acknowledge your complaint and aim to respond within a reasonable time. If you are not satisfied with our response, you can contact the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au or on 1300 363 992.

Questions or requests

If you have any questions about this document, or you want to access, correct or delete your personal information, contact our Privacy Officer at [email protected]. For general enquiries, email [email protected]. We aim to respond within 5 business days.