Privacy Policy
Homelander Pty Ltd | ABN 30 639 475 568 | NDIS Provider 4050124168
Version: 1.1 · Effective: 27 February 2026 · Last updated: 2 July 2026 · Review: Annual
Plain English: we collect only what we need to help you with SDA housing, we keep it safe in Australia, and we never sell it. Questions? Message us on WhatsApp or email ndis@homelander.com.au. Easy English version available on request.
1. Introduction
Homelander Pty Ltd ("Homelander," "we," "us," or "our") is committed to protecting the privacy of all individuals whose personal information we collect and hold. This policy explains how we handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). As a registered NDIS provider (Provider Number 4050124168), we also comply with the NDIS Quality and Safeguards Commission requirements for privacy and information handling.
2. What information we collect
Participants (SDA tenants): full name; contact details; NDIS participant number; date of birth; emergency contacts; support coordinator details; disability support needs (general); SDA design category eligibility; plan manager details; bank details (for bond refunds); communication records.
Landlords/investors: full name; contact details; bank account details; property ownership details; TFN (if provided); ABN (if applicable).
Support coordinators & partners: name and organisation; contact details; NDIS registration details.
Website visitors: IP address; browser/device type; pages visited; enquiry form submissions.
3. How we collect it
Directly from you (enquiries, applications, agreements, messages); from third parties (support coordinators, plan managers, NDIA — with your consent or legal authority); from our systems (website analytics, communication logs, NDIS portals); and from public sources (business registrations, property records, for verification). We will not collect personal information without your knowledge unless legally required or permitted.
4. How we use it
Primary purposes: service delivery (matching participants to properties, managing tenancies); NDIS compliance (claims, reporting, audits); financial operations (rent collection, landlord payments, reconciliation); communication; legal compliance and record keeping.
Secondary purposes: service improvement using de-identified data; marketing to participants only with explicit consent; marketing to investors on a legitimate-interest basis with opt-out.
We do NOT sell personal information, use participant data for marketing without explicit consent, or share data with third parties for their marketing.
5. How we store it
Data is held in encrypted systems on Australian servers (secure cloud database, Dropbox Business, Microsoft 365) with role-based access control, multi-factor authentication, automated security monitoring, and daily encrypted backups retained for 7 years. Our AI assistant (Susie) operates under strict governance rules with a full audit trail. We do not transfer personal information overseas except via cloud services with Australian data centres, or with your explicit consent for specific purposes.
6. Who can access it
Internal: the CEO (business operations) and our audited AI assistant (controlled operational access).
External disclosure only to: NDIA (claims, funding verification); NDIS Commission (compliance, audits, incidents); support coordinators (with your consent); plan managers (payment processing); contractors (limited maintenance information); legal/financial advisors; law enforcement where legally required. We will NOT disclose to marketing companies, data brokers, unrelated third parties, or overseas parties without consent.
7. Your rights
Access: ask to see the information we hold about you — we respond within 30 days. Correction: ask us to fix inaccurate, incomplete or outdated information. Deletion: ask us to delete information no longer needed (note: NDIS rules require us to keep records for 7 years after service ends). Complaint: contact us first at ndis@homelander.com.au; you can also go to the OAIC (oaic.gov.au, 1300 363 992) or the NDIS Quality and Safeguards Commission (ndiscommission.gov.au) at any time.
8. Participant-specific rights (NDIS)
Choice and control over who we share your information with; a support person present when discussing your information; Easy English formats on request; an advocate acting on your behalf; interpreter services if needed.
9. AI-assisted service delivery
We use an AI assistant (Susie) to help manage operations: drafting communications (human-approved before sending), administrative tasks, system monitoring, and service-improvement analysis. Your rights: ask whether AI was involved in any decision; significant decisions are always human-reviewed; you can request human-only handling (may affect response times); all AI actions are logged and auditable.
10. Cookies and websites
Our websites use essential cookies (site function — cannot disable), analytics cookies (can disable) and marketing cookies (can disable). Manage cookies in your browser settings.
11. Data retention
Participant records, financial records, contracts and communication logs: 7 years (NDIS and tax law). Website analytics: 2 years. Marketing consents: until withdrawn plus 1 year. After retention periods, data is securely destroyed.
12. Changes to this policy
Significant changes are communicated by email to affected individuals, on our website, and at service reviews. The "Last updated" date shows when changes were made.
13. Contact us
Privacy Officer: Tony Tadros
215/566 St Kilda Rd, Melbourne VIC 3004
Phone: 0400 425 620 · Email: ndis@homelander.com.au
For urgent privacy concerns include "PRIVACY URGENT" in the subject line.
Registered SDA Provider · No SIL · NDIS Quality & Safeguards Commission · Document control: v1.0 27 Feb 2026 initial; v1.1 2 Jul 2026 accessibility summary + WhatsApp contact added.


