Privacy Policy

Green Summit Pty Ltd trading as Good Plan Management

ABN 16 696 359 770 · NDIS Provider Registration 4053607738

Version 1 – September 2026

Managing your plan means holding information about your disability, your money and the people around you. This page says exactly what we hold, who sees it, and what you can do about it. Our Service Terms cover the rest of how we work with you.

1. About this policy

This policy explains how Good Plan Management ("we", "us") handles your personal information. We are Green Summit Pty Ltd trading as Good Plan Management, ABN 16 696 359 770, a registered NDIS plan manager (provider registration 4053607738).

We are bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles. As an NDIS provider we also handle information under the National Disability Insurance Scheme Act 2013 and the rules made under it.

It covers everyone we hold information about: participants whose plans we manage, their nominees, guardians and other authorised representatives, support coordinators, provider contacts, and people who contact us through our website.

If we change this policy we will publish the new version here with a new version line. If a change materially affects how we handle information about participants we manage, we will email them before it takes effect.

2. What we collect

For a participant whose plan we manage, we typically hold:

  • identity and contact details – name, date of birth, address, email, phone number
  • NDIS details – your NDIS number, plan dates, plan budgets and funding categories, plan management type, and your service bookings
  • the people around you – your nominee, guardian, support coordinator, family or carers where you have told us about them, and what each of them is authorised to do
  • financial details – your bank account details where we reimburse you directly, provider invoices and receipts, claims we have made to the NDIA, and payments in and out
  • records of our dealings – emails, calls, notes, your Service Agreement and any consent you have given or withdrawn, and complaints or incidents.

Sensitive information

Information about your disability, and health information contained in the invoices and reports we receive from your providers, is "sensitive information" and gets extra protection under the Privacy Act. We collect it only where it is reasonably necessary to manage your plan, and we only do so with your consent or where the law allows it.

Providers and support coordinators

For providers and support coordinators we hold business contact details, ABN and banking details for payment, and records of invoices, claims and correspondence.

Our website

If you fill in a form on our website we collect what you type into it. Our website and portal also record standard technical information such as your IP address and browser type, which we use to keep the service secure and working.

3. How we collect it

Wherever we reasonably can, we collect information about you from you – on our sign-up form, in your Service Agreement, or when you talk to us.

We also collect information from other people, because plan management does not work otherwise:

  • from the NDIA, through the myplace provider portal – your plan, its budgets, and what has been claimed against it
  • from your providers – invoices, receipts and service records
  • from your support coordinator, nominee, guardian or family, where they are acting for you or you have asked them to deal with us
  • from anyone who signs you up on your behalf, such as a plan nominee completing our form for you.

If we receive information about you that we did not ask for and do not need, we destroy or de-identify it where the law allows.

4. Why we collect and use it

We use your information to:

  • manage the plan-managed funding in your NDIS plan – check invoices, submit claims to the NDIA, and pay providers or reimburse you
  • keep your records and give you statements showing how your budgets are being spent
  • tell you about likely overspend, underspend or claims that may not comply with your plan
  • contact you, and the people you have authorised, about your plan and our services
  • run and secure our systems, including detecting and preventing fraud or duplicate payments
  • handle complaints and incidents, and improve how we work
  • meet our obligations under the NDIS Act, the NDIS Practice Standards, tax and financial-records law, and any other law that applies to us.

We do not sell your information, and we do not use it for marketing by third parties.

Automated processing

We use software, including automated tools, to read the invoices sent to us and to draft the matching NDIS claim. A person reviews anything the software is unsure about, and no payment is made without our staff and, where your Service Agreement requires it, your own approval. Decisions about your supports are made by people, not by software.

5. Who we share it with

We share only what is reasonably necessary, and only with:

  • the NDIA – claims, payment requests and plan information, which is how your providers get paid
  • the NDIS Quality and Safeguards Commission – where we are required to report an incident or respond to a complaint
  • your providers – enough to pay their invoice and resolve questions about it
  • your support coordinator, nominee, guardian or other authorised representative – to the extent you have consented in your Service Agreement, or told us since
  • another plan manager – if you transfer to or from us and ask us to hand over your records
  • our service providers – the companies that host our software, send our email, store our documents and support our systems, under contracts that restrict what they may do with it
  • our professional advisers, auditors and insurers, where reasonably necessary
  • courts, tribunals and regulators, where required or authorised by law.

You can limit or withdraw your consent at any time, verbally or in writing. If you do not want us to deal with a particular person or organisation, tell us and we will not. Withdrawing consent may limit what we can do for you, and we will tell you if that is the case.

6. Information sent overseas

Our own application servers and our main database are located in Australia (Sydney).

Some of the service providers we rely on are based overseas, or use infrastructure overseas, and may store or process your information there. This is most likely to involve the United States, and covers things like sending our email, monitoring errors in our software, serving our website, and the automated reading of invoice documents.

Before we disclose your information to an overseas recipient we take reasonable steps to ensure they handle it in a way consistent with the Australian Privacy Principles, including through the contracts we hold with them.

7. How we keep it safe

We take reasonable steps to protect your information from misuse, interference and loss, and from unauthorised access, modification or disclosure. That includes encrypted connections and storage, access controls so staff can only reach the records they need, audit logging of changes to your records, and background checks and training for our people.

No system is perfectly secure. If a data breach happens that is likely to cause you serious harm, we will notify you and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme.

8. How long we keep it

We keep participant records for at least seven years after our services to you end. That is what the NDIS Practice Standards and financial-records law require of us, and it also means we can answer questions about a claim long after it was paid.

After that, we destroy or de-identify information we no longer need, unless we are required to keep it for longer.

9. Seeing and correcting your information

You can see the information we hold about you, and you can ask us to correct anything that is wrong. Much of it is already visible to you in our participant portal – your plan, your budgets, and every invoice and claim we have handled.

For anything else, ask us on (02) 4263 0663 or hello@goodplanmanagement.com.au. We will confirm who you are, respond within 30 days, and we do not charge for making a request. If we cannot give you access or make a correction, we will tell you why in writing and how to have that reviewed.

You can deal with us anonymously or under a pseudonym for general enquiries. We cannot manage an NDIS plan anonymously – the NDIA requires us to identify the participant we are claiming for.

10. Complaints about privacy

If you think we have mishandled your personal information, tell us on (02) 4263 0663 or hello@goodplanmanagement.com.au. You can make a complaint yourself or with the help of an advocate, nominee, family member, carer or other support person.

  • We will acknowledge your complaint promptly and investigate it fairly.
  • We aim to respond within 30 days, and we will tell you why if we need longer.
  • You will never be disadvantaged or have your services affected because you complained.

If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner on 1300 363 992 or at oaic.gov.au. If your complaint is about our conduct as an NDIS provider rather than about privacy, you can also complain to the NDIS Quality and Safeguards Commission on 1800 035 544 or at ndiscommission.gov.au.

11. Contact us

Privacy questions, access requests and complaints all go to the same place: hello@goodplanmanagement.com.au, or (02) 4263 0663 Monday to Friday, 9am to 5pm Sydney time.