Townsville Education Centre
A service of All Access Education Group Pty Ltd
ABN 36 656 199 665
Effective date: 8 September 2026
Last updated: 8 September 2026
Townsville Education Centre (“TEC”, “we”, “us” or “our”) is operated by All Access Education Group Pty Ltd.
We respect the privacy of our clients, participants, families, carers and other people who interact with our services.
We provide multidisciplinary health, allied health and related services, which may include:
Occupational Therapy;
Speech Pathology;
Psychology;
Physiotherapy;
Social Work;
assessments and reports;
telehealth;
multidisciplinary care;
parent and carer consultation;
school, home and community-based services; and
other related clinical and support services.
In providing these services, we routinely handle health information and other sensitive personal information.
We recognise that people need to be able to trust us with this information. We are committed to handling personal information respectfully, securely and transparently.
This Privacy Policy explains:
what personal information we collect and hold;
how and why we collect it;
how we use and disclose it;
how information may be shared within a multidisciplinary team;
how we handle information relating to children and people represented by another person;
how financial and funding information is handled;
how information is stored and protected;
how you can access or correct your information;
how you can make a privacy complaint; and
how we respond to privacy and data-security incidents.
We handle personal information in accordance with applicable Australian privacy and health-information requirements, including the:
Privacy Act 1988 (Cth);
Australian Privacy Principles;
Notifiable Data Breaches Scheme;
applicable health practitioner professional standards, codes and record-keeping obligations;
applicable NDIS requirements where we provide NDIS-funded supports; and
other Australian laws that regulate the collection, use, disclosure or retention of health and personal information.
Health information is sensitive information and receives a higher level of protection under Australian privacy law.
This Privacy Policy applies to personal information we collect about people including:
clients and patients;
NDIS participants;
children and young people;
parents and carers;
guardians and nominees;
authorised representatives;
family members;
referrers;
people making enquiries;
people attending our premises;
people communicating with us online;
third-party payers;
contractors and service providers; and
other people whose personal information we reasonably need to collect in connection with our services.
Separate privacy arrangements may apply to employee records and recruitment information where required by law.
Personal information is information or an opinion about an identified individual, or an individual who is reasonably identifiable.
Depending on our relationship with you, we may collect information such as:
your name;
date of birth;
address;
email address;
telephone number;
emergency contact details;
family and household information;
parent, guardian, nominee or representative details;
communication preferences;
school, childcare or education details;
referral details;
information about other professionals or services involved with you;
billing and payment information; and
correspondence between you and our service.
To safely and effectively provide health and allied health services, we may collect sensitive information including:
current and previous health conditions;
diagnoses;
disabilities;
developmental history;
medical history;
medications;
allergies;
mental health information;
behavioural information;
communication needs;
sensory needs;
mobility and physical functioning information;
social and family circumstances relevant to care;
assessment results;
clinical observations;
treatment plans;
goals;
progress information;
clinical notes;
reports;
recommendations;
photographs, audio or video where separately authorised;
information received from other treating professionals;
relevant school or educational information;
information concerning risks or safety needs; and
other information reasonably necessary to provide safe and appropriate care.
We only seek to collect sensitive information that is reasonably necessary for our functions and activities and where we have consent or another lawful basis to collect it.
Depending on how services are funded, we may collect information relating to:
NDIS participant numbers;
NDIS plan or funding periods;
Plan Managers;
Support Coordinators;
Medicare details;
DVA information;
private health or insurer information;
referrals;
third-party funding arrangements;
payer contact details;
invoices;
payments;
service dates;
service codes;
quantities;
funding balances where provided to us;
claims;
outstanding accounts; and
transaction information.
Where payment details are processed using an external secure payment provider, we may not hold the complete card information ourselves.
Financial authority does not, by itself, give a Plan Manager, insurer, funding organisation or other payer authority to receive full clinical notes or reports.
Unless otherwise authorised or permitted by law, we aim to provide third-party payers only the information reasonably required to process, verify or administer payment or funding.
Where practical, we collect information directly from you or from your authorised representative.
We may collect information when you:
make an enquiry;
complete an online intake form;
book an appointment;
attend an appointment;
speak with us by phone;
communicate with us by email, SMS or another communication platform;
provide documents;
participate in an assessment;
receive treatment;
complete questionnaires;
provide feedback;
make a complaint;
make a payment;
use our website; or
otherwise interact with our service.
Information may be collected verbally, electronically or in writing.
Sometimes it is appropriate or necessary to collect information from another person or organisation.
Depending on the circumstances and your consent, this may include information from:
parents or carers;
guardians;
authorised representatives;
NDIS nominees;
Support Coordinators;
Plan Managers;
general practitioners;
paediatricians;
psychiatrists;
psychologists;
allied health professionals;
hospitals;
schools;
teachers;
childcare providers;
support workers;
government agencies;
insurers;
funding bodies; or
other people involved in your care.
We will only collect information from another source where it is reasonably necessary and lawful to do so.
We may collect, hold and use personal information for purposes including:
To:
understand your needs;
assess your health, development or functioning;
provide treatment;
establish goals;
plan services;
monitor progress;
make clinical recommendations;
provide reports;
provide telehealth;
coordinate multidisciplinary care;
make appropriate referrals; and
communicate with you about your care.
To:
identify health or safety risks;
understand allergies, medications or relevant medical conditions;
appropriately manage emergencies;
protect clients, staff and other people; and
respond where there are concerns about abuse, neglect, exploitation, violence or other serious risks.
To:
make and manage appointments;
contact you;
maintain client records;
manage waiting lists;
allocate clinicians;
provide customer service;
respond to enquiries; and
administer our practice.
To:
issue invoices;
receive payments;
process claims;
communicate with authorised Plan Managers or other payers;
administer Medicare, DVA, NDIS or other funding arrangements;
manage outstanding accounts; and
meet financial, taxation and audit requirements.
To:
supervise clinicians;
conduct appropriate clinical consultation;
review the quality and safety of services;
manage incidents;
investigate concerns or complaints;
maintain professional standards;
support staff training and development; and
improve our systems and services.
Where practicable, information used for broader business analysis or quality improvement will be de-identified or aggregated.
We may also use information where necessary to comply with:
legislation;
court or tribunal orders;
subpoenas;
regulatory requirements;
mandatory reporting obligations;
professional obligations;
insurance requirements;
funding requirements; or
other lawful obligations.
Consent is an important part of how we manage personal information.
Where consent is required, we aim to ensure that it is:
informed;
voluntary;
current;
specific to the purpose involved; and
provided by a person with capacity and authority to give that consent.
Consent may be written, electronic or verbal depending on the circumstances and applicable requirements.
Certain activities may require specific written or electronic consent.
For example:
sharing information with an external school or provider;
recording a clinical session;
using photographs or video for non-clinical purposes;
involving a student;
particular information-sharing arrangements; or
marketing involving sensitive information.
You may ask questions about a consent request before agreeing.
Where consent is relied upon, you may generally withdraw or change that consent by contacting us. Withdrawal does not affect actions that were lawfully taken before the consent was withdrawn.
There may be circumstances where we can or must use or disclose information without consent because this is required or authorised by law.
Many of our clients are children and young people.
We take particular care when handling information concerning children.
Depending on the child's age, maturity, capacity, circumstances and applicable law:
consent may be provided by a parent, legal guardian or another person with appropriate authority;
the child or young person may be able to provide their own consent;
we may seek the child's or young person's assent and involve them in decisions about their information; and
confidentiality considerations may change as a young person develops greater capacity to make their own healthcare decisions.
We aim to involve children and young people in decisions about their care and privacy in a way that is appropriate to their understanding and circumstances.
Where a person completes forms, communicates with us or provides consent on behalf of a client, we may collect information about:
their identity;
relationship to the client;
contact details; and
authority to act for the client.
We may request evidence of authority where appropriate.
This may be particularly important where there are:
parenting orders;
guardianship arrangements;
statutory orders;
family-law proceedings;
NDIS nominee arrangements; or
disputes regarding authority to access health information or make healthcare decisions.
We will consider applicable law and the rights, interests and safety of the client when responding to requests from parents or representatives.
Being a parent, family member or payer does not necessarily create an unrestricted right to access every part of a person's clinical record.
Townsville Education Centre operates as a multidisciplinary health and allied health service.
Where a client receives care from more than one TEC clinician, relevant information may need to be shared between members of the treating team to provide coordinated, safe and effective care.
This may include information concerning:
assessment;
diagnosis;
goals;
treatment;
risk;
progress;
recommendations; and
other information relevant to coordinated care.
Access to information is limited to people who require it for legitimate clinical, administrative, governance or other authorised purposes.
Where a client places particular restrictions on internal information sharing, we will consider those wishes and discuss whether the restriction affects our ability to safely or effectively provide multidisciplinary services.
Our clinicians may participate in professional supervision, peer consultation or case discussion as part of safe and effective professional practice.
Where client information is used for supervision or professional consultation, we aim to limit information to what is reasonably necessary for that purpose.
Supervisors and professionals involved in such consultation are expected to maintain appropriate confidentiality.
Where separate consent is required by professional standards or because of the nature of the arrangement, we will seek it.
With appropriate authority or consent, we may communicate with external people involved in a client's care or support.
These may include:
general practitioners;
paediatricians;
psychiatrists;
psychologists;
allied health practitioners;
hospitals;
schools;
childcare services;
Support Coordinators;
NDIS providers;
support workers;
community organisations;
government services; and
other people nominated by the client or their representative.
Where practical, our information-sharing consent process allows clients or representatives to specify:
who information may be shared with;
what type of information may be shared; and
the purpose of that communication.
We do not treat permission to communicate with one organisation as unlimited authority to disclose the entire clinical record.
For NDIS participants, information may be collected, used or disclosed for purposes including:
providing agreed NDIS supports;
service agreements;
maintaining a Schedule of Services;
invoicing;
working with a Plan Manager;
communicating with a Support Coordinator where authorised;
reporting;
responding to NDIA or NDIS Quality and Safeguards Commission requirements;
record keeping;
complaints;
incidents; and
other lawful NDIS provider obligations.
A Plan Manager's role in processing payment does not automatically authorise access to clinical notes, assessments or reports.
Clinical information will only be disclosed to a Plan Manager where appropriately authorised, reasonably necessary or otherwise permitted or required by law.
Where services are funded or subsidised by Medicare, DVA, an insurer, government agency, employer or another third party, we may provide information reasonably necessary for:
confirming eligibility;
processing a claim;
receiving payment;
verifying that a service occurred;
meeting funding requirements; or
complying with lawful audit requirements.
The amount and type of information disclosed will depend on the relevant program and applicable requirements.
Where a funding body seeks information beyond what is ordinarily required to administer payment, we will consider whether further consent or another lawful authority is required.
There are circumstances where Australian law permits or requires health information to be disclosed without consent.
Depending on the situation, these can include where disclosure:
is required or authorised by law;
is required by a court or tribunal;
is required under a subpoena or other lawful process;
is required under mandatory reporting legislation;
is necessary in responding to a serious threat to life, health or safety where the law permits disclosure;
is required to investigate or respond to certain incidents;
is required by an authorised regulator; or
otherwise falls within an exception permitted by Australian privacy law.
We will aim to disclose only information reasonably necessary for the relevant purpose.
We use third-party technology and professional service providers to operate our clinic.
Depending on our systems and the service involved, these may include providers of:
practice-management and electronic health-record systems;
secure online forms;
appointment booking;
telehealth;
SMS;
email;
document storage;
accounting;
invoicing;
payment processing;
IT support;
website hosting;
analytics;
cybersecurity;
professional advice; and
other administrative systems.
Our primary allied health practice-management system is Halaxy.
Halaxy is used for functions that may include:
patient records;
clinical notes;
appointments;
forms;
service agreements;
invoices;
funding information;
communications; and
telehealth.
We remain responsible for taking reasonable steps in the selection and management of service providers that handle personal information on our behalf.
Our core clinical practice data held in Halaxy for Australian users is stored in Australia.
However, some technology providers, integrations and subprocessors may process or have access to limited information outside Australia.
Depending on the systems and integrations being used, overseas recipients or service providers may be located in jurisdictions including the United States and countries within the European Union, as well as other jurisdictions disclosed by the relevant service provider from time to time.
Examples can include providers supporting:
cloud infrastructure;
communications;
payment processing;
accounting;
analytics;
email; and
software support.
Before disclosing personal information to an overseas recipient, where the Australian Privacy Principles require us to do so, we take reasonable steps in the circumstances to ensure that the information will be handled consistently with applicable Australian privacy obligations.
Because technology providers and their infrastructure can change, clients may contact us for further information about current overseas data-processing arrangements.
We take reasonable technical, physical and organisational steps to protect personal information from:
misuse;
interference;
loss;
unauthorised access;
unauthorised modification; and
unauthorised disclosure.
Depending on the system and information involved, safeguards may include:
secure healthcare practice-management systems;
role-based user access;
authentication controls;
restricted staff permissions;
secure passwords;
encryption;
secure payment processing;
device security;
system backups;
access logging;
staff confidentiality obligations;
staff privacy and security training;
physical security;
policies and procedures; and
processes for responding to privacy or security incidents.
No electronic or physical information system can be guaranteed to be completely secure.
We therefore regularly consider privacy and security risks and update our practices where appropriate.
We may communicate with clients using email, SMS, online forms, telehealth platforms and other electronic systems.
Electronic communication can carry privacy risks.
We take reasonable steps to use appropriate systems and avoid including unnecessary sensitive information in communications.
Clients should tell us if they have particular communication requirements or do not want particular types of information sent by email or SMS.
We may need to verify identity before responding to a request involving sensitive information.
Where telehealth is clinically appropriate, we may provide services using secure telehealth technology.
Personal and health information used during telehealth is managed in accordance with this policy.
Unless there is a specific clinical reason and appropriate consent has been obtained, telehealth sessions are not intentionally recorded by Townsville Education Centre.
Clients should participate from a location where they are comfortable with the level of privacy available to them.
We will not use identifiable photographs, audio or video of a client for advertising, social media, promotional material or other non-clinical purposes without appropriate consent.
Where audio, video or another form of recording is proposed for a clinical purpose, such as assessment, supervision, transcription or documentation, we will explain the intended purpose and obtain consent where required.
A person may ordinarily decline optional photography, promotional recording or student involvement without affecting their access to clinical care.
We may use digital tools to assist with aspects of clinical or administrative work, such as:
documentation;
transcription;
scheduling;
billing;
communications;
drafting;
information organisation; or
other administrative functions.
Where an artificial intelligence or transcription tool processes identifiable health information, we will consider the privacy, security, professional and consent requirements applying to that use.
Use of assistive technology does not remove the treating professional's responsibility for clinical judgement, accuracy or appropriate review of the clinical record.
Townsville Education Centre does not currently intend to rely solely on automated computer systems to make decisions that significantly affect a person's access to healthcare or other significant rights or interests.
If we introduce automated decision-making that is subject to additional privacy requirements, this policy will be updated accordingly.
When you visit our website or interact with our online services, certain technical information may be collected automatically.
This can include:
IP address;
browser type;
device type;
pages viewed;
time and date of access;
referring website;
website interactions; and
cookies or similar technologies.
We may use this information to:
operate our website;
maintain security;
understand website usage;
improve our services; and
measure the effectiveness of communications or advertising.
Where third-party analytics, advertising or social-media technologies are used, those providers may also collect information in accordance with their own privacy practices.
You may be able to manage cookies through your browser or device settings.
Receiving healthcare or allied health services from Townsville Education Centre does not automatically mean that a person has agreed to receive marketing communications.
Where appropriate, we seek separate consent for marketing communications.
Marketing may include information about:
clinic services;
new programs;
workshops;
educational services;
school-holiday activities;
events; or
other services offered by All Access Education Group Pty Ltd.
A person can unsubscribe or ask us to stop sending marketing communications at any time.
We will not use sensitive health information for direct marketing unless permitted by law and appropriate consent has been obtained.
Opting out of marketing does not affect access to clinical services.
Administrative communications such as appointment reminders, invoices, service updates or information necessary to provide care are not considered marketing communications.
We take reasonable steps to ensure the personal information we hold is accurate, complete, relevant and up to date where required.
We ask clients and representatives to tell us when important information changes, including:
contact details;
emergency contacts;
guardianship arrangements;
funding arrangements;
Plan Managers;
medications;
diagnoses;
relevant health information; or
other information that may affect the safe delivery of services.
You may request access to personal information we hold about you.
Requests should be made to our Privacy Officer using the contact details at the end of this policy.
We may need to verify your identity or authority before releasing information.
Depending on the request, we may provide access through:
a copy of the record;
access to particular documents;
an explanation of information;
another appropriate method; or
access through an authorised representative.
There are circumstances under the Privacy Act or other applicable law where access may be refused or limited.
If we refuse access or provide only partial access, we will explain the reason where required and tell you about available complaint mechanisms.
Any charge associated with providing access will be limited to what is permitted by law and will be discussed with you before being incurred.
Where someone requests records on behalf of another person, we will consider:
the identity of the requester;
their legal authority;
the client's capacity;
the client's wishes where relevant;
applicable parenting, guardianship or statutory arrangements;
privacy obligations;
professional responsibilities; and
the client's safety and best interests where legally relevant.
We may ask for documentation establishing authority before releasing information.
If you believe personal information we hold is incorrect, incomplete, out of date, irrelevant or misleading, you may ask us to correct it.
We will consider the request and take reasonable steps as required by law.
Clinical records may not always be altered by deleting the original entry. Where professional or legal record-keeping requirements apply, a correction, clarification or addendum may instead be added to preserve the integrity of the clinical record.
If we decline a correction request, we will explain our decision where required and advise you of available complaint options.
We retain health and personal information for as long as reasonably necessary to:
provide services;
maintain appropriate continuity of care;
meet legal requirements;
comply with professional record-keeping standards;
comply with funding or contractual requirements;
respond to complaints or claims; and
otherwise meet lawful business requirements.
Different retention requirements may apply depending on:
the profession;
the age of the client;
the type of record;
the funding arrangement; and
applicable legal or professional requirements.
When information is no longer required to be retained, we take reasonable steps to securely destroy it or de-identify it where required.
We take privacy and data-security incidents seriously.
If we become aware of suspected:
loss of information;
unauthorised access;
unauthorised disclosure;
cyberattack;
compromised account;
incorrect recipient disclosure; or
another privacy or security incident,
we will assess and respond to the incident.
This may include:
containing the incident;
investigating what occurred;
assessing the information involved;
taking remedial action;
reviewing affected systems or procedures;
determining the risk of harm to individuals; and
taking steps to reduce the risk of recurrence.
Where a data breach meets the requirements of the Notifiable Data Breaches Scheme, we will notify affected individuals and the Office of the Australian Information Commissioner as required by law.
Where practical and lawful, people may interact with us anonymously or using a pseudonym for general enquiries.
However, it is generally not practical for us to provide clinical services, maintain health records, process funding or submit claims without knowing the client's identity.
If you have a question or concern about how we have handled your personal information, we encourage you to contact us.
Please provide enough information for us to understand and investigate the concern.
We will:
take the complaint seriously;
acknowledge and investigate it appropriately;
seek further information where necessary;
aim to respond within a reasonable period; and
explain the outcome.
Making a privacy complaint will not affect your right to receive respectful and appropriate health services.
If you are not satisfied with our response, you may be able to make a complaint to the Office of the Australian Information Commissioner (OAIC).
Depending on the nature of the issue, you may also have the right to contact the:
Office of the Health Ombudsman Queensland; or
NDIS Quality and Safeguards Commission.
If we receive a request for personal information from police, a regulator, court, tribunal, government agency or another authority, we will consider whether there is lawful authority to disclose the requested information.
We do not treat the existence of a request alone as unlimited authority to provide a complete clinical record.
Where appropriate, we may seek clarification, professional advice or legal advice before releasing information.
We may update this Privacy Policy from time to time to reflect changes in:
our services;
technology;
information-handling practices;
legislation;
regulatory guidance;
funding arrangements; or
professional requirements.
The current version will be available at:
https://www.allaccesseducation.com.au/tec/privacy-policy
We aim to review this policy at least annually and whenever there is a significant change to how we handle personal information.
For privacy enquiries, requests for access or correction, withdrawal or amendment of consent, or privacy complaints, please contact:
Privacy Officer
Townsville Education Centre
All Access Education Group Pty Ltd
ABN: 36 656 199 665
Email: admin@allaccesseducation.com.au
Phone: 0491 761 487
Address: 1/62 Keane Street, Currajong QLD 4812
Website: allaccesseducation.com.au
Our full Privacy Policy is available at:
https://www.allaccesseducation.com.au/tec/privacy-policy
If you require this Privacy Policy in another accessible format, please contact us and we will take reasonable steps to assist.