Privacy policy
What we collect, where it is held, what we do and do not do with it, and how to get it back or have it deleted.
1. The short version. We collect the minimum needed to run the service, we hold it in Australia, encrypted, separated per customer, we sell nothing to anyone, we use your documents for nothing except showing them back to you, and you can export or delete everything at any time.
2. What we collect. Account details (name, email, practice name, password stored only as a salted hash). Billing details are held by our payment provider, not by us. The documents you upload, encrypted at rest with a key derived per customer. Ordinary technical logs (request paths and timings), which never contain document contents, document names or cookies.
3. About the people in your documents. Provider evidence commonly contains personal information about NDIS participants and workers — some of it sensitive, including health-related information. You, as the uploader, are the one with the relationship to those people and the legal obligations for that information; we hold it only on your instructions, as a storage and organisation service. We do not read it for any purpose except the classification you ask for, we do not use it for analytics or training, we do not disclose it to anyone except at your direction or where the law requires, and we delete it when you tell us to.
4. Where and how it is held. On servers located in Australia. Encrypted at rest, per-customer key derivation, per-customer directory separation enforced and tested. Transport encrypted. Access to production systems is limited to what operating the service requires. A copy of the encrypted store is kept away from the server so that a hardware failure does not take your material with it; it holds nothing the live store does not, in the same encrypted form, and clause 7 of the terms says what that means for deletion.
5. Data breaches. If a data breach occurs that is likely to result in serious harm, we will notify you and the Office of the Australian Information Commissioner in accordance with the Notifiable Data Breaches scheme, and we will tell you plainly what happened and what we are doing.
6. Your rights. Export everything, correct your account details, delete a client or your account, ask us what we hold. Contact: [SET AT GATE].
7. Commitment. We apply the Australian Privacy Principles to everything we hold, regardless of whether any small-business exemption might otherwise apply. [Whether an exemption applies to a business this size is a review item. We apply the principles either way, so the answer changes what we must do and not what we do.]