Privacy Policy
Last updated 23 August 2026
This Privacy Policy explains how CareCert Pty Ltd (“CareCert”, “we”, “us”) handles information when a registered NDIS provider organisation (“you”, “your organisation”) uses the CareCert platform. It is drafted with reference to the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), and will be finalised with a lawyer before go-live.
What we deliberately don't collect
CareCert is built not to hold participant data. We do not store participant names, NDIS numbers, health information, or care records. Participants are referenced only by provider-assigned codes that mean nothing outside your organisation. Free-text fields are screened for anything that looks like personal information before it is stored. If a feature would require participant data, we don’t build it.
Information we do collect
- Account details for your organisation’s users: name, work email, and authentication credentials (handled by our authentication provider — we never see your password).
- Organisation details: business name, ABN, registration groups, services provided, and compliance records (registers, incidents, evidence, policies) that you enter or upload.
- Billing details, processed by our payment provider (Stripe) — we do not store full card numbers.
- Usage and diagnostic data needed to operate and secure the service (see Analytics below).
How we use it
To provide the compliance copilot, registers, and audit-pack features you sign up for; to keep your organisation’s account secure; to send service-related communications (deadline alerts, rule-change notices); and to meet our own legal and accounting obligations. We do not sell your data.
Where information is stored
Application data is stored with Supabase in the Sydney (Australia) region. Where CareCert calls a third-party AI model to draft prose for you, any free text is screened by our PII-scrub step before it leaves our systems.
Analytics
We use Plausible Analytics, a privacy-first, cookie-free analytics service. It does not use cookies or track you across sites, and collects only aggregate, non-identifying usage statistics (pages viewed, referrers, device type).
Your rights
You can request access to, correction of, or deletion of your organisation’s account data by contacting us. We will confirm identity before actioning requests involving another user’s data.
Contact
Questions about this policy: privacy@carecert.example.com (draft contact — to be confirmed).