Privacy Policy

Last updated: 14 August 2026

NDIS Compliance Hub ("we", "us", "our") is operated by Zivy Care and Services Pty Ltd (ABN: [ABN]). This Privacy Policy explains how we collect, use, disclose, and protect personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

This Policy applies to personal information we collect through the NDIS Compliance Hub platform, including information entered by NDIS provider organisations ("Organisations") about their staff, workers, and clients.

1. What Personal Information We Collect

We collect personal information that is necessary to provide our compliance management services. This includes:

Worker and Staff Information

  • Full name, date of birth, residential address, contact details (email, phone)
  • Employment details: position title, employment start date, qualifications
  • Criminal history check results (police clearances) — a sensitive information category under the Privacy Act
  • Health information: immunisation and vaccination records — also a sensitive information category
  • Working With Children Check, NDIS Worker Screening Check, and other regulatory screening results
  • Training records, certifications, and qualification documents
  • Identity verification documents (100-point ID check records)
  • Timesheet and shift data (if using rostering features)

User Account Information

  • Name, work email address, and role within the Organisation
  • Authentication credentials (passwords stored as one-way cryptographic hashes)
  • Two-factor authentication settings
  • IP addresses and session information for security and audit purposes

Organisation Information

  • Organisation name, ABN, and contact details
  • NDIS provider registration details
  • Integration credentials for connected HR and rostering platforms (encrypted at rest)

2. How We Collect Personal Information

We collect personal information:

  • Directly from Organisations — when an Organisation subscribes and enters worker or client data
  • From integrated platforms — via authorised connections to HR/rostering systems such as Deputy, Employment Hero, KeyPay, and Humanforce, where the Organisation has granted access
  • Automatically — system logs, IP addresses, and session data collected as part of platform security

3. Why We Collect and Use Personal Information

We collect and use personal information to:

  • Enable Organisations to track and manage NDIS compliance obligations for their staff
  • Calculate compliance scores and generate alerts for expiring credentials, screenings, and training
  • Generate compliance reports required for NDIS Commission audits and registration renewals
  • Maintain immutable audit logs of all compliance-relevant actions
  • Operate, maintain, and improve the platform
  • Respond to support requests and communicate with authorised users
  • Meet our own legal obligations, including security and data breach requirements under the Privacy Act

Sensitive information (criminal history and health information) is collected only because it is necessary for NDIS compliance — specifically, police clearance and immunisation status are mandatory components of NDIS Worker Screening requirements. We do not use this information for any other purpose.

4. Disclosure of Personal Information

We do not sell, rent, or trade personal information. We may disclose personal information to:

  • Authorised users within the Organisation — only users with appropriate roles can access worker data
  • Cloud infrastructure providers — data is stored on Amazon Web Services (AWS) infrastructure in Australia or the Asia-Pacific region
  • Sub-processors — third-party services used to operate the platform (e.g., email delivery, error monitoring), bound by confidentiality obligations
  • Law enforcement or regulators — where required by law, a court order, or to prevent serious harm
  • NDIS Commission — only where an Organisation is legally required to report and instructs us to do so

We do not disclose personal information to overseas recipients except where sub-processors operate systems outside Australia. Where this occurs, we take reasonable steps to ensure those recipients handle information in accordance with the APPs.

5. Data Security

We take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access. Our security measures include:

  • Encryption of data in transit (TLS 1.2+) and at rest (AES-256 on AWS S3)
  • Encrypted storage of all integration credentials
  • Role-based access control — users can only access data their role permits
  • Mandatory two-factor authentication for all platform users
  • Session security controls including absolute timeout (8 hours) and IP-change detection
  • Immutable audit logs recording all create, update, and delete actions
  • Regular dependency audits and security patching

6. Data Retention

Worker compliance records are retained for a minimum of seven (7) years from the date of creation, consistent with NDIS record-keeping requirements under the NDIS (Provider Registration and Practice Standards) Rules 2018. Documents are soft-deleted only — permanent deletion requires a written request during the Organisation's off-boarding process.

User account data is retained for the duration of the subscription and for 12 months following termination, after which it is deleted or de-identified.

7. Access and Correction

Under APP 12 and APP 13, individuals have the right to request access to personal information we hold about them, and to request correction of inaccurate or incomplete information.

Requests from workers regarding their own data should be directed to the Organisation that entered the data, as that Organisation is the primary data controller for worker records. We will assist Organisations in responding to such requests.

Requests from Organisation account holders regarding their own user account data can be made directly to us at the contact details below.

8. Cookies and Tracking

The platform uses session cookies (essential for authentication) and does not use third-party tracking or advertising cookies. No personal data is shared with advertising networks.

9. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be notified to Organisation administrators by email at least 14 days before taking effect. Continued use of the platform after the effective date constitutes acceptance of the updated Policy.

10. Contact and Complaints

For privacy enquiries or complaints, please contact our Privacy Officer:

Zivy Care and Services Pty Ltd
Email: privacy@ndiscompliancehub.com.au

We will acknowledge your complaint within 5 business days and endeavour to resolve it within 30 days. If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC).

This system assists with compliance tracking. Providers retain legal responsibility for meeting NDIS Commission requirements.