Privacy policy.
This Privacy Policy applies to A. Gatt & K. Gatt, trading as Wiggle & Giggle Dance, referred to in this policy as “Wiggle & Giggle,” “we,” “us” or “our.”
This policy explains how we collect, use, store, protect and disclose personal and sensitive information when providing dance, movement, social, community participation, support and event services.
We are committed to respecting each person’s privacy, dignity, choice and control. We aim to handle personal information consistently with applicable Australian privacy laws, the NDIS Code of Conduct and relevant NDIS requirements.
1. Personal and Sensitive Information We May Collect
The information we collect depends on the services a person receives and may include:
name, date of birth, pronouns and contact details
address and emergency-contact details
parent, carer, guardian, nominee or representative details
communication methods and preferences
accessibility and participation requirements
disability, health and medical information
allergies, medications and emergency-response information
sensory, behavioural, emotional-regulation and support information
mobility, personal-care and transport requirements
cultural, language and communication preferences
service bookings and attendance records
payment, invoice and transaction information
feedback, complaints and incident information
photographs, video or audio recordings where consent has been provided
correspondence and other information provided to us.
When providing NDIS-funded services, we may also collect:
NDIS participant numbers
plan-management information
plan manager contact details
support coordinator contact details
nominee or authorised representative details
relevant NDIS goals
service agreements and consent forms
support plans and risk assessments
session notes, progress notes and service-delivery records
incident, complaint and safeguarding records
service dates, support item information and claim details
information reasonably required to prepare invoices or verify that a service was delivered.
We will only collect information that is reasonably necessary for our activities and services.
2. Sensitive Information and Consent
Health, disability, medical and support information may be considered sensitive information.
Where required, we collect sensitive information with the consent of the participant or their authorised representative. We only collect sensitive information that is reasonably necessary to provide safe, appropriate and individualised services, respond to emergencies, meet our legal responsibilities or protect a person’s health and safety.
Consent may be recorded through forms, service agreements, emails, written correspondence or other appropriate methods.
A person may withdraw their consent where lawful and practicable. Withdrawing consent may affect our ability to provide certain services safely or meet our legal responsibilities. We will explain any likely consequences before acting on a withdrawal of consent.
3. Children, Consent and Authorised Representatives
Where a participant is a child, we will usually obtain consent from their parent or legal guardian.
Where an adult participant has a guardian, nominee or other legally authorised representative, we may obtain consent or instructions from that person after taking reasonable steps to confirm their authority.
Wherever practicable, we will also communicate directly with the participant, involve them in decisions and respect their preferences, wishes, communication methods, dignity and right to choice and control.
We will not assume that a family member, friend or support worker has authority to access a participant’s information or make decisions on their behalf.
4. Why We Collect and Use Information
We may collect and use personal and sensitive information to:
process enquiries, registrations and bookings
learn about a participant’s interests, goals and support needs
provide safe and appropriate dance, social, community and support services
make reasonable adjustments
communicate with participants, families, carers and authorised representatives
prepare service agreements and support documentation
monitor attendance, participation and progress
maintain session notes and service-delivery records
manage risks, incidents, emergencies and safeguarding concerns
provide first aid or contact emergency services
prepare invoices and manage payments
verify NDIS-funded supports and respond to plan managers
respond to feedback and complaints
manage events, programs and membership communications
meet legal, insurance, taxation, audit and record-keeping responsibilities
improve our services, policies and procedures
send updates or promotional information where consent has been given.
We will not use personal information for an unrelated purpose unless the person has consented or the use is authorised or required by law.
5. How We Collect Information
We may collect information:
directly from the participant
from a parent, carer, guardian, nominee or authorised representative
through registration, consent, feedback and service-agreement forms
during conversations, assessments, sessions, events or service delivery
through our website, email, telephone, text message or social media
from a plan manager or support coordinator
from another provider or professional with appropriate consent or lawful authority
through payment, booking and accounting systems
when an incident, complaint or emergency occurs.
Where practicable, we will collect information directly from the person it relates to.
When information is provided by someone else, we may take reasonable steps to confirm their authority and ensure the participant is aware of the collection.
We will never contact a third party without written and clear consent & instruction from the participant or their authorised representative.
6. How We Use Your Information
We use your information to:
Manage class bookings and participation
Ensure the safety, wellbeing, and support of all participants
Communicate with you about classes, events, and updates
Share photos/videos on social media or our website (only with your consent)
Meet our legal obligations and manage risk
7. If Information Is Not Provided
People may choose not to provide certain personal information.
However, we may be unable to provide a requested service, process an NDIS invoice, make necessary adjustments or safely respond to a person’s support needs if essential information is not provided.
We will explain why information is requested and what may happen if it is not provided.
8. Anonymous Enquiries
Where practicable, people may make a general enquiry without identifying themselves or may use a preferred name or pseudonym.
Identification may be required when it is necessary to provide a booked service, manage safety, process payment, meet record-keeping obligations or comply with the law.
9. When We May Share Information
We will not sell or rent personal information.
We may share relevant information with the following people or organisations where the participant or their authorised representative has consented, where it is reasonably necessary to provide the service, or where disclosure is authorised or required by law:
workers, contractors and authorised volunteers
parents, guardians, nominees and authorised representatives
plan managers
support coordinators
the National Disability Insurance Agency
the NDIS Quality and Safeguards Commission
other service providers or health professionals involved in the person’s support
emergency services and health practitioners
venue operators where limited information is required for safety or accessibility
insurers, auditors, accountants, legal advisers and professional consultants
payment, accounting, booking, form, email and technology-service providers
government departments, courts, tribunals, law-enforcement agencies or regulatory authorities.
We will only disclose the information reasonably necessary for the relevant purpose.
We may disclose information without consent where required or authorised by law, including where necessary to respond to a serious threat to a person’s life, health or safety, report suspected abuse, neglect, exploitation or violence, or comply with a lawful request.
10. Access by Workers, Contractors and Volunteers
Access to personal information is limited to owners, workers, contractors and authorised volunteers who require the information to perform their role safely and appropriately.
Information is provided on a need-to-know basis.
Workers, contractors and volunteers must follow our privacy, confidentiality, information-management and professional-boundary requirements. Volunteers will not be given general access to participant files or records unless access is necessary for their authorised role.
11. Service Providers and Digital Systems
We may use third-party providers to help manage:
online forms
bookings and registrations
website hosting
email and electronic communication
accounting and invoicing
electronic payments
cloud storage
document management
customer and participant records
marketing and social-media communications.
These providers may collect or process information on our behalf. We take reasonable steps to use reputable providers and limit the information shared with them to what is necessary for the service they provide.
12. Overseas Storage and Processing
Some technology, website, form, payment, accounting, email, social-media or cloud-service providers may store or process information using systems or personnel located outside Australia.
The countries involved may vary depending on the provider and its current storage and processing arrangements.
Where overseas storage or processing may occur, we take reasonable steps appropriate to our circumstances to use reputable providers and protect the information being handled.
People may contact us for further information about the main third-party providers we use.
13. How We Protect Information
We take reasonable steps to protect personal and sensitive information from misuse, interference, loss, unauthorised access, modification and disclosure.
Depending on the type of information, these steps may include:
password-protected accounts and devices
multi-factor authentication where available
restricted access to electronic files
secure storage of paper records
confidentiality requirements for workers and volunteers
limiting information to people who need it for their role
secure transfer and disposal practices
reviewing account permissions and access
maintaining backups where appropriate
staff induction and privacy training
responding promptly to suspected privacy or security breaches.
No storage or communication method can be guaranteed to be completely secure. We will act promptly if we become aware that information may have been lost, misused or accessed without authority.
14. Privacy and Data Breaches
A privacy or data breach may occur when personal information is lost, accessed, changed, used or disclosed without authority.
If we become aware of a suspected breach, we will take reasonable steps to:
contain the breach
protect affected individuals from further harm
investigate what happened
assess the type and seriousness of the information involved
correct weaknesses in our systems or practices
document our response
notify affected individuals where appropriate
notify the Office of the Australian Information Commissioner or another authority where legally required.
People should contact us promptly if they believe personal information has been lost, incorrectly disclosed or accessed without permission.
15. Photography, Video and Audio
We will seek consent before using identifiable photographs, video or audio recordings for advertising, promotional, educational or social-media purposes.
Consent for photography or recording is separate from consent to participate in our services.
A participant or their authorised representative may decline photography or recording without losing access to our services.
Consent may be withdrawn for future photography, recording or publication by contacting us. Withdrawal will apply from the time it is received and may not allow us to retrieve or remove material that has already been lawfully printed, distributed, published or shared by others.
We will take reasonable steps to remove material from platforms we control where practicable.
16.Marketing and Service Communications
We may send essential communications about bookings, service changes, cancellations, safety matters, payments or other services a person has requested.
With consent, we may also send newsletters, program announcements, event information and promotional messages.
A person may unsubscribe from promotional communications at any time by using the unsubscribe option provided or contacting us.
Unsubscribing from promotional messages will not prevent us from sending essential communications about a current booking, service, agreement, payment or safety matter.
We will not use health or disability information to target promotional communications without appropriate consent.
17. Accuracy and Correction of Information
We take reasonable steps to ensure that the personal information we hold is accurate, complete, relevant and up to date.
Participants and authorised representatives should tell us when contact details, emergency information, support needs, health information or other relevant circumstances change.
A person may ask us to correct information they believe is inaccurate, incomplete, out of date, irrelevant or misleading.
We will respond within a reasonable period and will not charge for making a correction request.
Where we cannot make the requested correction, we will explain why and, where appropriate, allow a statement to be added to the record noting that the information is disputed.
18. Accessing Personal Information
A person may request access to personal information we hold about them.
A parent, guardian, nominee or representative may request access where they have lawful authority to act for the participant.
Before providing access, we may ask for proof of identity and authority.
We will respond within a reasonable period. Access may be provided through a copy of the records, a summary or another suitable format.
In limited circumstances, we may refuse or restrict access where authorised by law, including where providing access would unreasonably affect another person’s privacy or create a serious risk to someone’s health or safety. If access is refused, we will explain the reason where lawful to do so.
We will not charge for making an access request.
You may request access to the personal information we hold about you, or ask us to correct it, at any time by contacting us at:
📧 Accounts@wigglegiggledance.com.au
📞 0480 572 164
19. Record Retention and Secure Destruction
We retain personal information only for as long as it is reasonably required to:
provide services
maintain appropriate participant and service records
respond to complaints, incidents or legal claims
meet NDIS, taxation, insurance, contractual and legal obligations
protect the rights and interests of participants and Wiggle & Giggle.
Different records may need to be kept for different periods.
When information is no longer required and we are legally permitted to dispose of it, we will take reasonable steps to securely destroy, delete or de-identify it.
Paper records may be securely shredded, and electronic records may be securely deleted or made inaccessible.
20. Privacy Complaints
A person may contact us if they:
have a question about this Privacy Policy
want to access or correct their information
believe their information has been handled incorrectly
believe their privacy has been breached
are concerned about how information has been collected, stored, used or disclosed.
Privacy complaints can be made verbally or in writing. We will:
listen to and acknowledge the complaint
treat the person respectfully
protect them from adverse treatment for making a complaint
investigate the concern fairly
keep the person informed where appropriate
provide an outcome or response within a reasonable period
take corrective action where required.
Privacy enquiries and complaints can be sent to:
Wiggle & Giggle Dance
Email: Accounts@wigglegiggledance.com.au
If a person is not satisfied with our response to a privacy complaint, they may contact the Office of the Australian Information Commissioner.
If the complaint relates to NDIS supports or services, the person may also contact the NDIS Quality and Safeguards Commission.
Making a complaint will not negatively affect a person’s access to our services.
21. Changes to This Privacy Policy
We may update this Privacy Policy when our services, systems, legal obligations or information-handling practices change.
The most current version will be available on our website. A printed copy or an alternative accessible format can be provided on request.
Where significant changes affect how we use or disclose existing personal information, we will take reasonable steps to notify affected people and seek further consent where required.
Effective date: 15 June 2026
Version: 2.0
Review date: June 2027