Privacy Policy for AusVanta Platform
Effective Date: 2 July 2026
Last Updated: 2 July 2026

  1. Introduction
    AusVanta Pty Ltd (ABN: 53691933632) ("AusVanta", "we", "us", "our") is committed to protecting the privacy and security of personal information entrusted to us. This Privacy Statement explains how we collect, use, disclose, and manage personal information in connection with the AusVanta NDIS Provider Management Platform ("the Platform").
    AusVanta operates as a Registered Training Organisation and software provider, delivering the Platform to NDIS registered providers and disability support organisations across Australia. We recognise that the personal information we handle includes sensitive data relating to NDIS participants, support workers, and organisational staff.
    This Privacy Statement is designed to comply with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) contained in Schedule 1 of that Act. We are also committed to meeting the privacy requirements under the National Disability Insurance Scheme Act 2013 (Cth) (NDIS Act) and the NDIS Practice Standards.
  2. Types of Personal Information We Collect
    2.1 Information We Collect From Organisation Administrators and Staff
    When organisations register to use the Platform and their staff use our services, we collect:
    Identity and Contact Information:
    ⦁ Full name
    ⦁ Email address
    ⦁ Phone number
    ⦁ Position/title
    ⦁ Business address
    Employment and Professional Information:
    ⦁ Employment status and role
    ⦁ Qualifications and certifications
    ⦁ NDIS Worker Screening Clearance number and expiry date
    ⦁ Police check details and expiry date
    ⦁ First aid certificate details
    ⦁ Working with Children Check details (where applicable)
    Account Information:
    ⦁ Username and encrypted password
    ⦁ Login timestamps and session data
    ⦁ IP addresses and device information
    ⦁ User preferences and settings
    2.2 Information We Collect About NDIS Participants
    Organisations using the Platform may enter information about NDIS participants receiving support services. This includes:
    Personal Details:
    ⦁ Full name
    ⦁ Date of birth
    ⦁ NDIS Number
    ⦁ Residential address and service locations
    ⦁ Gender
    ⦁ Cultural and linguistic background (optional)
    Support Information:
    ⦁ NDIS Support Plan details and documents
    ⦁ Care plans and goals
    ⦁ Service agreements
    ⦁ Funding management type (self-managed, plan-managed, NDIA-managed)
    Health and Disability Information (Sensitive Information):
    ⦁ Disability type and support needs
    ⦁ Health conditions and medical information
    ⦁ Medication details
    ⦁ Behavioural support requirements
    ⦁ Restrictive practices information (where applicable)
    Emergency and Contact Information:
    ⦁ Emergency contact names and phone numbers
    ⦁ Family member/carer contact details
    ⦁ Nominee or guardian details
    Service Delivery Records:
    ⦁ Shift records and attendance
    ⦁ Progress notes and observations
    ⦁ Incident reports
    ⦁ Photos and evidence of service delivery
    2.3 Sensitive Information
    We collect sensitive information only with consent and where it is reasonably necessary for our functions or activities. Sensitive information may include:
    ⦁ Health information about participants and workers
    ⦁ Disability information
    ⦁ Criminal history (Worker Screening Checks, Police Checks)
    ⦁ Biometric information (GPS location data for compliance verification)
    ⦁ Racial or ethnic origin (for cultural support planning)
    2.4 Information We Collect Automatically
    When you use the Platform, we automatically collect:
    ⦁ Device and browser information
    ⦁ IP address and geolocation data
    ⦁ Access logs and timestamps
    ⦁ Pages viewed and features used
    ⦁ Session duration and activity patterns
  3. How We Collect Personal Information
    3.1 Direct Collection
    We collect personal information directly from:
    ⦁ Organisation administrators during registration and onboarding
    ⦁ Staff members when they create their profiles
    ⦁ Support Workers when they clock in/out and complete shift activities
    ⦁ Participants (or their representatives) through service delivery processes
    ⦁ Users who contact us for support or enquiries
    3.2 Indirect Collection
    We may receive personal information from:
    ⦁ Authorised representatives or nominees acting on behalf of participants
    ⦁ Other organisations when a user transfers between providers
    ⦁ Third-party integrations (Xero, MYOB) when authorised
    ⦁ Publicly available sources (where permitted)
    ⦁ Law enforcement or regulatory bodies when required by law
    3.3 Collection Notices
    At or before the time of collection, we will take reasonable steps to provide a collection notice that explains:
    ⦁ Our identity and contact details
    ⦁ The purposes of collection
    ⦁ How the information will be used and disclosed
    ⦁ Whether disclosure is required or authorised by law
    ⦁ How to access and correct the information
  4. Purposes of Collection and Use
    We collect and use personal information for the following purposes:
    4.1 Platform Service Delivery
    ⦁ Creating and managing user accounts
    ⦁ Enabling access to Platform features
    ⦁ Processing time tracking and shift management
    ⦁ Generating billing and payroll exports
    ⦁ Providing technical support and training
    4.2 Compliance and Regulatory Requirements
    ⦁ Verifying NDIS Worker Screening Clearances
    ⦁ Maintaining certification expiry tracking
    ⦁ Recording and reporting incidents to the NDIS Commission
    ⦁ Generating compliance reports and audit trails
    ⦁ Responding to regulatory enquiries and audits
    4.3 Service Delivery to NDIS Participants
    ⦁ Managing participant profiles and care plans
    ⦁ Scheduling and coordinating support services
    ⦁ Recording service delivery and progress
    ⦁ Managing emergency contacts and safety information
    ⦁ Supporting quality and safeguarding activities
    4.4 Communication
    ⦁ Sending service-related notifications
    ⦁ Communicating about Platform updates and changes
    ⦁ Responding to enquiries and support requests
    ⦁ Sending marketing communications (with consent)
    4.5 Security and Fraud Prevention
    ⦁ Authenticating users and preventing unauthorised access
    ⦁ Detecting and investigating suspicious activity
    ⦁ Maintaining audit logs for security purposes
    ⦁ Responding to data breaches and incidents
    4.6 Business Improvement
    ⦁ Analysing Platform usage and performance
    ⦁ Developing new features and improvements
    ⦁ Conducting research and reporting (de-identified data only)
    ⦁ Training and quality assurance activities
  5. Disclosure of Personal Information
    We may disclose personal information to:
    5.1 Authorised Recipients Within Your Organisation
    ⦁ Staff members with appropriate role-based access
    ⦁ Managers and coordinators responsible for service delivery
    ⦁ Compliance officers for audit and reporting purposes
    ⦁ Finance staff for billing and payroll processing
    5.2 Third-Party Service Providers
    We engage third-party service providers to assist with our operations, including:
    ⦁ Cloud hosting and infrastructure providers
    ⦁ Payment processing services
    ⦁ Accounting software providers (Xero, MYOB) when you authorise integration
    ⦁ Email and communication services
    ⦁ Analytics and monitoring tools
    These providers are bound by contractual obligations to protect personal information and use it only for the purposes we specify.
    5.3 Regulatory Bodies and Law Enforcement
    We may disclose personal information when:
    ⦁ Required or authorised by law
    ⦁ Requested by the NDIS Quality and Safeguards Commission
    ⦁ Responding to valid legal processes (subpoenas, court orders)
    ⦁ Reporting notifiable data breaches to the OAIC
    ⦁ Preventing or investigating fraud or criminal activity
    5.4 Related to Business Transactions
    In the event of a merger, acquisition, or sale of assets, personal information may be transferred as part of that transaction, subject to confidentiality obligations.
    5.5 With Your Consent
    We may disclose personal information for other purposes with your express consent.
  6. Cross-Border Disclosure
    Personal information is primarily stored and processed in Australia. However, we may use cloud services that store data overseas, including:
    ⦁ United States (for certain cloud infrastructure and analytics)
    ⦁ Singapore and other Asia-Pacific regions (for redundancy and performance)
    Before disclosing personal information to an overseas recipient, we will:
    ⦁ Obtain your consent where required by APP 8
    ⦁ Ensure the overseas recipient is bound by equivalent privacy protections
    ⦁ Take reasonable steps to ensure the overseas recipient complies with the APPs
    We do not disclose sensitive participant information to overseas recipients without explicit consent.
  7. Data Security and Retention
    7.1 Security Measures
    We implement robust security measures to protect personal information, including:
    Technical Security:
    ⦁ Encryption of data in transit (TLS 1.3) and at rest (AES-256)
    ⦁ Secure httpOnly session cookies for authentication
    ⦁ Role-based access control and principle of least privilege
    ⦁ Regular security assessments and penetration testing
    ⦁ Intrusion detection and monitoring systems
    Organisational Security:
    ⦁ Staff training on privacy and security obligations
    ⦁ Background checks for staff with access to personal information
    ⦁ Confidentiality agreements with all staff and contractors
    ⦁ Documented security policies and procedures
    Physical Security:
    ⦁ Secure access controls for physical facilities
    ⦁ Secure destruction of physical records
    7.2 Data Retention
    We retain personal information for as long as necessary to:
    ⦁ Provide the Platform services
    ⦁ Meet legal and regulatory obligations (including NDIS requirements)
    ⦁ Respond to complaints or legal claims
    ⦁ Maintain audit trails required for compliance
    Specific Retention Periods:
    ⦁ Participant records: Retained for 7 years after last service or as required by NDIS
    ⦁ Staff records: Retained for 7 years after employment ends
    ⦁ Incident reports: Retained for 7 years minimum
    ⦁ Audit logs: Retained for 7 years
    ⦁ Financial records: Retained for 7 years per tax law requirements
    When information is no longer required, we securely destroy or de-identify it.
    7.3 Data Deletion Upon Request
    When you request deletion of your data, we will:
    ⦁ Delete or anonymise your personal information within 30 days
    ⦁ Retain only information required by law (archived with restricted access)
    ⦁ Notify third parties who may hold your information on our behalf
  8. Access and Correction
    8.1 Your Right to Access
    Under the Privacy Act, you have the right to request access to personal information we hold about you. To make an access request:
  9. Submit a written request to our Privacy Officer (details below)
  10. Provide sufficient identification information
  11. Specify the information you are seeking
    We will respond to your request within 30 days.
    8.2 Fees
    We may charge a reasonable fee for processing access requests to cover:
    ⦁ Staff time required to locate and compile the information
    ⦁ Costs of copying or reproducing records
    We will advise you of any applicable fees before processing your request.
    8.3 Correction of Information
    You may request correction of personal information that is inaccurate, outdated, incomplete, irrelevant, or misleading. We will:
    ⦁ Assess your request within 30 days
    ⦁ Make corrections where appropriate
    ⦁ Notify you of the outcome
    ⦁ Add a statement to the record if we decline to make a correction
    8.4 Access Through Platform
    Users can access and update certain personal information directly through the Platform:
    ⦁ Staff can view and edit their own profile information
    ⦁ Participants (or their representatives) can request access through their provider organisation
    ⦁ Administrators can manage organisational data within their tenant
  12. Anonymity and Pseudonymity
    Where it is lawful and practicable, individuals may deal with us anonymously or under a pseudonym. However, we may not be able to provide certain services without identifying information, such as:
    ⦁ Creating a user account
    ⦁ Processing NDIS claims
    ⦁ Verifying worker clearances
    We will inform you if anonymity or pseudonymity is not possible for a particular transaction.
  13. Notifiable Data Breaches
    10.1 Our Commitment
    AusVanta is committed to preventing data breaches and responding swiftly if they occur. We have robust systems and processes in place to protect personal information from misuse, interference, loss, and unauthorised access, modification, or disclosure.
    10.2 Data Breach Response
    If we suspect a data breach has occurred, we will:
  14. Contain the breach – Take immediate steps to limit the spread and impact
  15. Assess the breach – Conduct an assessment within 30 days to determine severity
  16. Notify affected parties – If the breach is eligible for notification under the NDB scheme:
    ⦁ Notify the Office of the Australian Information Commissioner (OAIC)
    ⦁ Notify affected individuals with recommendations for protective action
  17. Review and improve – Conduct a post-incident review to prevent future breaches
    10.3 Notifiable Data Breach Scheme
    Under the NDB scheme, we are required to notify individuals and the OAIC when:
    ⦁ There is unauthorised access to, or disclosure of, personal information
    ⦁ This is likely to result in serious harm to affected individuals
    ⦁ We cannot prevent the serious harm through remedial action
  18. Direct Marketing
    We may use your personal information for direct marketing purposes only when:
    ⦁ We have your consent to do so
    ⦁ The marketing relates to services similar to those you have previously requested
    ⦁ You have not opted out of receiving marketing communications
    11.1 Opt-Out Rights
    You can opt out of marketing communications at any time by:
    ⦁ Clicking the "unsubscribe" link in marketing emails
    ⦁ Contacting us at privacy@ausvanta.com.au
    ⦁ Updating your communication preferences in your account settings
    We will process opt-out requests within 5 business days.
  19. Cookies and Tracking Technologies
    12.1 Cookies We Use
    We use cookies and similar technologies to:
    ⦁ Maintain your session and authenticate your login
    ⦁ Remember your preferences and settings
    ⦁ Analyse Platform usage and performance
    ⦁ Improve security and detect fraud
    12.2 Types of Cookies
    Cookie Type Purpose Duration
    Essential Session management, authentication Session
    Functional Preferences, settings Up to 12 months
    Analytics Usage analysis, performance monitoring Up to 24 months
    Security Fraud prevention, bot detection Session

12.3 Managing Cookies
You can manage cookie preferences through your browser settings. Note that disabling essential cookies may affect Platform functionality.
For more information, see our Cookie Policy.

  1. Artificial Intelligence (AI) Transparency
    AusVanta may use AI-assisted features to enhance Platform capabilities, including:
    ⦁ AI-powered search and information retrieval (RAG with citations)
    ⦁ Note drafting assistance (optional feature)
    ⦁ Compliance form completion assistance
    ⦁ Risk signal detection for missing evidence or anomalies
    13.1 AI Data Handling
    When AI features are used:
    ⦁ Your data is processed securely and not used to train third-party AI models without consent
    ⦁ AI outputs are clearly identified and may be reviewed before finalisation
    ⦁ You can opt out of AI-assisted features in your organisation settings
    13.2 Human Oversight
    AI features are designed to assist, not replace, human decision-making. All AI-generated outputs should be reviewed by authorised staff before use.
  2. Children's Privacy
    The AusVanta Platform is not designed for use by children under 18 years of age. If we become aware that we have collected personal information from a child without parental consent, we will take steps to delete that information.
    Where participants under 18 receive NDIS supports, information about them is managed by their parent, guardian, or authorised representative in accordance with this Privacy Statement.
  3. Changes to This Privacy Statement
    We may update this Privacy Statement from time to time to reflect:
    ⦁ Changes in our information handling practices
    ⦁ New features or services
    ⦁ Changes in legal or regulatory requirements
    ⦁ Industry best practices
    When we make material changes, we will:
    ⦁ Publish the updated Privacy Statement on our website
    ⦁ Notify registered users by email
    ⦁ Update the "Last Updated" date at the top of this document
    We encourage you to review this Privacy Statement periodically.
  4. Complaints and Enquiries
    16.1 Contacting Us
    If you have questions, concerns, or complaints about our privacy practices, please contact our Privacy Officer:
    AusVanta Pty Ltd
    Attention: Privacy Officer
    ⦁ Email: privacy@ausvanta.com.au
    ⦁ Phone: +61468167862
    ⦁ Post:Suite 17, 89-97 Jones Street, Ultimo, NSW 2007
    16.2 Complaints Process
    We take privacy complaints seriously and will:
  5. Acknowledge your complaint within 5 business days
  6. Investigate and respond within 30 days
  7. Provide a written response explaining our findings and any remedial actions
    16.3 External Review
    If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC):
    ⦁ Website: www.oaic.gov.au
    ⦁ Phone: 1300 363 992
    ⦁ Post: GPO Box 5218, Sydney NSW 2001
  8. Definitions
    Term Definition
    APP Australian Privacy Principle
    Collection Gathering, acquiring, or obtaining personal information
    Consent Express or implied agreement to the collection, use, or disclosure of personal information
    Data Breach Unauthorised access to, disclosure of, or loss of personal information
    NDIS National Disability Insurance Scheme
    NDB Scheme Notifiable Data Breaches scheme under Part IIIC of the Privacy Act
    Personal Information Information or an opinion about an identified individual, or an individual who is reasonably identifiable
    Sensitive Information Personal information including health information, racial or ethnic origin, political opinions, religious beliefs, sexual orientation, criminal record, and biometric information
    Tenant An organisation's isolated environment within the AusVanta Platform
    Use Access, consultation, processing, or handling of personal information

 

  1. Contact Information
    AusVanta Pty Ltd
    ABN: 53691933632
    Registered Office:
    Suite 17, 89-97 Jones Street, Ultimo, NSW 2007
    Privacy Officer:
    Email: privacy@ausvanta.com.au
    Phone: +61468167862
    Data Protection Enquiries:
    Email: dataprotection@ausvanta.com.au
  2. Related Policies
    This Privacy Statement should be read in conjunction with:
    ⦁ AusVanta Terms and Conditions
    ⦁ AusVanta Acceptable Use Policy
    ⦁ AusVanta Cookie Policy
    ⦁ AusVanta Data Processing Agreement
    ⦁ AusVanta Service Level Agreement
    ────────────────────────────────────────────────────────────────────────────────
    Document Control
    Version Date Author Changes
    1.0 2 July 2026 AusVanta Legal & Compliance Initial release

────────────────────────────────────────────────────────────────────────────────
This Privacy Statement is compliant with the Privacy Act 1988 (Cth) and the Australian Privacy Principles.