Legal

Privacy Policy

Last updated 26 June 2026

Introduction

SquareOne Solutions (“SquareOne”, “we”, “our” or “us”) is committed to protecting the privacy and confidentiality of the personal information entrusted to us. As an independent advisory practice providing consultancy, governance, quality assurance, regulatory, education and leadership services to the aged care sector, we recognise the importance of maintaining the trust and confidence of our clients and stakeholders.

This Privacy Policy explains how we collect, hold, use, disclose and protect personal information obtained through our website, during the provision of professional services, and through our business operations.

SquareOne complies with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) in managing personal information.

Our Privacy Commitment

Protecting the privacy of our clients, business partners, employees, contractors and website users is fundamental to the way we operate.

We are committed to:

  • Collecting only the personal information reasonably necessary to provide our services.
  • Using personal information fairly, lawfully and transparently.
  • Protecting information against unauthorised access, loss, misuse or disclosure.
  • Maintaining appropriate administrative, technical and physical safeguards.
  • Respecting confidentiality obligations associated with consultancy engagements.
  • Continually reviewing our privacy and information security practices.

Scope

This Privacy Policy applies to personal information collected by SquareOne from:

  • Clients and prospective clients.
  • Representatives of aged care providers.
  • Board Directors and Committee members.
  • Employees and contractors of client organisations.
  • Visitors to our website.
  • Individuals who contact or otherwise engage with SquareOne.

Definitions

Personal Information means information or an opinion about an identified individual, or an individual who is reasonably identifiable.

Sensitive Informationincludes information relating to an individual’s health, racial or ethnic origin, religious beliefs, political opinions, sexual orientation, criminal record or other information classified as sensitive under the Privacy Act 1988 (Cth).

Australian Privacy Principles (APPs) means the Australian Privacy Principles contained within the Privacy Act 1988 (Cth).

Client means any organisation or individual engaging SquareOne to provide consultancy or advisory services.

Information We Collect

The type of information we collect depends on the nature of our engagement and our relationship with you.

Clients and Business Contacts

We may collect:

  • Names.
  • Position titles.
  • Organisation details.
  • Business addresses.
  • Telephone numbers.
  • Email addresses.
  • Correspondence.
  • Meeting notes.
  • Information relevant to the provision of our services.

Consultancy Engagements

During the course of providing consultancy or advisory services, we may have access to information supplied by our clients, including:

  • Governance documentation.
  • Quality management systems.
  • Clinical governance frameworks.
  • Audit findings.
  • Policies and procedures.
  • Risk registers.
  • Quality indicator data.
  • Workforce information.
  • AN-ACC documentation.
  • Board and Committee papers.
  • Clinical records where necessary for the agreed scope of work.
  • Other operational or organisational information relevant to the engagement.

Where clinical or resident information is accessed, this occurs only where necessary to deliver the agreed services and in accordance with contractual, legislative and confidentiality obligations.

How We Collect Information

Personal information may be collected:

  • Directly from you when you contact us or engage our services.
  • Through meetings, telephone conversations and correspondence.
  • Via email communications.
  • Through our website enquiry forms.
  • During consultancy, audit or advisory engagements.
  • From client organisations where authorised or required for the engagement.
  • From publicly available sources where relevant to our services.
  • From third parties where consent has been obtained or where otherwise permitted by law.

Why We Collect Information

We collect personal information to enable us to:

  • Provide professional consultancy and advisory services.
  • Undertake governance, quality assurance and regulatory reviews.
  • Prepare reports and recommendations.
  • Provide Board advisory services.
  • Deliver education, coaching and workforce capability development.
  • Undertake AN-ACC advisory and clinical funding reviews.
  • Communicate with clients and stakeholders.
  • Respond to enquiries.
  • Administer our business operations.
  • Comply with contractual, legal and regulatory obligations.
  • Improve the quality of our services.

We will only collect information that is reasonably necessary for these purposes.

Use of Personal Information

SquareOne uses personal information only for purposes connected with the services we provide or where otherwise authorised or required by law.

Personal information may be used to:

  • Perform consultancy engagements.
  • Develop reports, recommendations and advisory documents.
  • Communicate with clients regarding projects.
  • Coordinate meetings and education sessions.
  • Manage contractual relationships.
  • Maintain business records.
  • Improve our website and services.
  • Conduct internal quality assurance activities.
  • Comply with professional, legal and regulatory obligations.
  • Send information about our services where appropriate and permitted.

Where artificial intelligence (AI) or other technology-assisted tools are used to support document preparation, analysis or administrative activities, appropriate steps are taken to protect confidential information and ensure compliance with applicable privacy obligations.

Disclosure of Personal Information

SquareOne respects the confidentiality of information entrusted to us and does not sell, rent or trade personal information.

Personal information may be disclosed:

  • To the client organisation that engaged SquareOne.
  • To authorised representatives of the client.
  • To professional advisers, insurers or auditors.
  • To trusted third-party service providers supporting our business operations.
  • Where required or authorised by law.
  • Where authorised by the individual concerned.
  • Where disclosure is necessary to prevent or lessen a serious threat to life, health or safety.

Where third-party service providers assist us in delivering our services, they are expected to maintain appropriate privacy and confidentiality standards.

SquareOne does not routinely disclose personal information outside Australia.

Storage and Security

SquareOne takes reasonable steps to protect personal information against misuse, interference, loss, unauthorised access, modification and disclosure.

Personal information may be stored electronically or in hard copy and is protected through a combination of administrative, technical and physical security measures appropriate to the nature of the information.

Our security measures may include:

  • Secure cloud-based systems.
  • Encrypted data transmission where appropriate.
  • Password-protected devices and user accounts.
  • Role-based access controls.
  • Multi-factor authentication.
  • Anti-malware and endpoint protection software.
  • Regular software updates and security patching.
  • Secure storage of physical records.

Access to personal information is limited to individuals who require the information to perform their professional responsibilities.

Although every reasonable effort is made to protect information held by SquareOne, no method of electronic transmission or storage can be guaranteed to be completely secure. Individuals providing information electronically acknowledge the inherent risks associated with internet communications.

Personal information is retained only for as long as necessary to fulfil the purposes for which it was collected, meet contractual obligations, or satisfy legal and regulatory requirements. When information is no longer required, it is securely destroyed or permanently de-identified where appropriate.

Privacy Enquiries

If you have any questions regarding this Privacy Policy or how SquareOne manages personal information, please contact:

Privacy Officer, SquareOne
Email: jc@squareoneau.com

SquareOne Solutions · ABN 29 884 881 248 · Melbourne VIC 3000