LEGAL

Privacy Policy

Last updated: 3 October 2026

This policy explains how Care Collaborator Pty Ltd (ABN 79 630 027 824) handles personal information. It covers our website, carecollaborator.com.au, and the Care Collaborator portal, app.carecollaborator.com.au. In this policy, "we", "us" and "our" mean Care Collaborator Pty Ltd.

We handle personal information in line with the Privacy Act 1988 (Cth) and the Australian Privacy Principles.

Who we collect information about

  • Website visitors who send us an enquiry, book a demo or sign up for our newsletter.
  • Provider staff who use the portal, such as care partners, managers and administrators.
  • Participants (people receiving care) and their representatives, whose details providers enter into the portal.
  • Suppliers and their staff, whose details providers record in the portal.

Our website

What we collect

  • Enquiry form: your name, company, phone number, email address, the type of enquiry, your message, and whether you want our newsletter.
  • Demo bookings: when you book a demo, the booking calendar (Calendly) collects your name, email address, the time you choose and any answers you give.
  • Onboarding Score and ROI calculator: your answers are worked out in your browser. We do not receive or store them.
  • Article read counts: we count how many times each article is read. We do not store who read it. Your IP address is used for a short time to stop repeated counting, and then discarded.

Cookies

Our website does not use advertising or tracking cookies. When you open the demo booking calendar, Calendly may set its own cookies. See Calendly's privacy notice for details.

How we use it

We use website information to reply to your enquiry, arrange and run your demo, and send you our newsletter if you asked for it. You can unsubscribe from the newsletter at any time using the link in each email, or by contacting us.

The Care Collaborator portal

Our role

Care providers use the portal to onboard participants, prepare budgets and agreements, and collect signatures. When a provider enters participant information, we handle it on the provider's behalf. The provider is responsible for how it collects and uses that information. If you are a participant or a representative, please contact your provider first about your information. We will help them respond.

What the portal holds

  • Provider staff: name, email address, phone number, role, the provider you work for, and sign-in and activity records (including IP address and browser details).
  • Participants: name, date of birth, gender, contact details, address, care program (for example Support at Home or NDIS), NDIS reference number, funding and budget details, agreements, signatures, documents, and notes.
  • Sensitive information: notes and risk alerts about a participant can include health information, for example dementia, falls risk, allergies or medications. Providers enter this so care can be delivered safely.
  • Representatives: name, contact details, and their role, for example guardian, attorney, nominee or emergency contact.
  • Suppliers: business name, ABN, contact details, and staff details such as position and check expiry dates.
  • Signing records: when someone signs an agreement, we record the signer's name, email address, IP address, browser details and the time.

How it is used

We use portal information only to provide the portal to providers: running the service, generating agreements and PDFs, sending signing links and notifications, supporting providers, keeping the service secure, and meeting legal obligations. We do not sell personal information and we do not use participant information for our own marketing.

Where information is stored

Portal data, including files, is stored in Australia, in Amazon Web Services (Sydney) and MongoDB Atlas (Sydney). Website enquiries are stored in Australia (Sydney).

Who we share it with

We share personal information only with service providers who help us run the website and portal, and only as needed:

  • Hosting and databases: Amazon Web Services, MongoDB Atlas, Supabase and Vercel.
  • Email delivery: SendGrid sends portal emails, such as invitations, signing links and reminders.
  • Electronic signatures: our e-signature service sends agreements for signing and returns the signed copy.
  • Demo bookings: Calendly.
  • Integrations a provider turns on: if a provider connects the portal to another system, such as their care management software, we send information to that system at the provider's direction.

Some of these providers may store or process information outside Australia, including in the United States. When this happens, we take reasonable steps to make sure the information is protected in line with the Australian Privacy Principles.

We may also disclose information when the law requires it.

How we protect it

We use encrypted connections, role-based access controls, hashed passwords, activity logging, and encrypted file storage. No system is completely secure, so we also review and improve our security over time. If a data breach is likely to cause serious harm, we will notify affected people and the Office of the Australian Information Commissioner (OAIC) as the law requires.

How long we keep it

We keep personal information only as long as we need it for the purposes above, or as long as the law requires. Portal records are kept while the provider uses the portal. When information is no longer needed, we take reasonable steps to delete it or remove details that identify people.

Access, correction and complaints

You can ask to see or correct the personal information we hold about you. For portal records about participants, please contact your provider first.

To make a request or a complaint, contact us:

We aim to respond within 30 days. If you are not satisfied with our response, you can contact the Office of the Australian Information Commissioner at oaic.gov.au.

Changes to this policy

We may update this policy. The latest version is always on this page, with the date it was last updated.