A note on sensitive information
Please do not send Care Data or other sensitive information through ordinary email. Contact us first so we can provide an appropriate secure method.
1. About this Privacy Policy
Vorda Pty Ltd (ABN 52 698 153 623) (Vorda, we, us or our) provides cloud-based compliance and operations software for National Disability Insurance Scheme (NDIS) providers through our websites, web applications and mobile applications (together, the Platform).
This Privacy Policy explains how Vorda collects, holds, uses, discloses, secures, retains and otherwise handles personal information. We seek to handle personal information consistently with the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs), the Notifiable Data Breaches scheme and other privacy laws that apply to us.
This Privacy Policy applies to:
- NDIS providers and other organisations that subscribe to, trial or enquire about the Platform (Providers);
- personnel and other authorised users who access the Platform through a Provider account (Authorised Users);
- participants, workers, nominees, guardians, family members, emergency contacts and other individuals whose information is entered into the Platform by a Provider; and
- visitors to our websites, prospective customers, business contacts and people who communicate with us.
A Provider generally controls why and how information about its participants, workers and related persons is entered into and used through the Platform. Vorda provides the technology and processes that information to provide the Platform and comply with Vorda’s own legal obligations. Depending on the circumstances, Vorda and the Provider may each have privacy obligations. Nothing in this policy limits Vorda’s obligations for personal information that Vorda collects, holds, uses or discloses.
The contractual allocation of privacy, security and data-handling responsibilities between Vorda and a Provider is also set out in Vorda’s customer terms, Data Processing Agreement and any applicable order form. This Privacy Policy is a statement of Vorda’s privacy practices and does not exclude or limit any right or remedy that cannot lawfully be excluded.
2. Key terms
In this policy:
Care Data means personal information entered into or generated through the Platform about participants, workers or other persons in connection with the delivery, administration, monitoring or documentation of NDIS supports. It includes health information and other sensitive information.
Customer Data means information, records, documents and content submitted to, stored in, generated through or exported from the Platform by or for a Provider. Customer Data includes Care Data.
personal information, sensitive information, health information and government-related identifier have the meanings given by applicable Australian privacy law.
3. Personal information we collect and hold
The kinds of personal information we collect and hold depend on how a person interacts with Vorda and how a Provider configures and uses the Platform.
3.1 Provider, account and business-contact information
We may collect:
- names, roles, employer or business details and Australian Business Numbers;
- business and personal contact details, including email addresses and telephone numbers;
- account credentials, authentication details, permissions and account-recovery information;
- subscription, billing, invoicing, transaction and payment-related information;
- enquiries, demo requests, customer-support communications, survey responses and feedback;
- contractual, procurement and due-diligence information; and
- professional information obtained from public business sources, referrals, events, professional networking services or lawful business-data sources.
Where a third-party payment processor is used, payment-card information may be collected directly by that processor. Vorda may receive a payment token, billing address, payment status and transaction details rather than complete card information.
3.2 Participant and related-person information entered by Providers
Depending on the features used, Providers may enter or upload information such as:
- names, contact details, dates of birth, addresses and preferred communication details;
- NDIS numbers and other identifiers;
- nominee, guardian, plan manager, support coordinator, family and emergency-contact details;
- service agreements, support plans, budgets, quotes, schedules, correspondence and consent records;
- progress notes, case notes, incident and complaint records, risk assessments and behaviour-support information;
- disability, diagnosis, health, medication, clinical, behavioural and support-needs information;
- photographs, videos, audio recordings, voice notes, transcripts, signatures and attachments;
- location and timestamps associated with shift check-in and check-out, where that feature is enabled;
- invoices, claims, time records, service-delivery records and audit evidence; and
- AI prompts, generated drafts, classifications, summaries, flags and user approvals.
3.3 Worker and workforce information entered by Providers
Providers may enter or upload information such as:
- identity and contact details;
- employment or engagement details, roles, availability and roster information;
- qualifications, licences, training, competencies and expiry dates;
- NDIS Worker Screening, Working with Children Check and other screening information;
- payroll, timesheet, leave, performance, incident and compliance records;
- emergency contacts and workplace documents; and
- device, sign-in, check-in and audit-log information connected with the worker’s use of the Platform.
3.4 Technical, security and usage information
We may collect:
- IP address, device type, operating system, browser, app version and device identifiers;
- login history, session information, access logs, audit trails and security events;
- feature usage, navigation, configuration and interaction information;
- cookie and similar-technology information;
- diagnostic, error, crash, latency and performance information; and
- push-notification tokens and delivery status.
We use this information to operate, secure, troubleshoot, measure and improve the Platform.
3.5 Recruitment and personnel information
Where a person applies to work with Vorda or provides services to Vorda, we may collect information relevant to recruitment, engagement, identity, qualifications, references, screening, payroll and workplace administration. Separate notices or policies may also apply.
4. How we collect personal information
We may collect personal information:
- directly from an individual when they create an account, contact us, request a demo, use the Platform, attend an event, apply for a role or communicate with us;
- from a Provider or an Authorised User who enters, imports, records or uploads information;
- from an authorised nominee, guardian, representative, referrer or business contact;
- from connected services and integrations authorised by a Provider;
- automatically through the Platform, cookies, logs, SDKs and security tools; and
- from public business sources, professional directories, referrals and lawful third-party business-information sources.
Where reasonable and practicable, Vorda collects personal information directly from the individual concerned. In many cases involving Customer Data, direct collection by Vorda is not reasonable or practicable because Vorda receives the information from the Provider that has the direct relationship with the individual.
4.1 Anonymity and pseudonymity
A person may deal with Vorda anonymously or using a pseudonym where it is lawful and practicable, such as when making a general enquiry. Identification is required where Vorda needs to verify authority, create or secure an account, provide contracted services, process payments, investigate security matters or comply with law.
4.2 Unsolicited personal information
If Vorda receives personal information that it did not request, we will assess whether the information could lawfully have been collected. Where it could not have been collected and Vorda is not required or permitted to retain it, Vorda will take reasonable steps to destroy or de-identify it.
5. Provider and Authorised User responsibilities
Providers determine which Customer Data is entered into the Platform and who may access it. Providers and Authorised Users are responsible for:
- collecting, using and disclosing personal information lawfully;
- giving required privacy notices and obtaining valid consent or other authority where required;
- ensuring that Vorda is authorised to receive and process information submitted to the Platform;
- collecting only information that is reasonably necessary for the Provider’s functions and services;
- keeping Customer Data accurate, complete and current;
- configuring roles, permissions, workflows, retention settings and integrations appropriately;
- protecting login credentials and promptly removing access for personnel who no longer require it;
- complying with applicable employment, workplace-surveillance, health-record, NDIS and record-keeping obligations;
- responding to participant, worker and representative requests concerning Provider-controlled records; and
- reviewing and approving AI-generated content and automated flags before relying on them.
Vorda is not responsible for a Provider’s collection or handling of information before it is submitted to the Platform, a Provider’s independent use or disclosure of information exported from the Platform, or a Provider’s failure to meet its own legal obligations. This does not limit Vorda’s responsibility for Vorda’s own acts and practices.
Providers and users must not send Care Data or other sensitive information through ordinary email or other insecure channels unless Vorda has expressly requested it and provided an appropriate secure method.
6. Why we collect, hold, use and disclose personal information
Vorda may handle personal information to:
- establish, verify, administer and secure accounts;
- provide, host, configure, support, maintain and improve the Platform;
- enable rostering, compliance, incident, document, workflow, reporting, billing and related Platform functions;
- generate records, drafts, summaries, alerts, reminders, approvals and audit evidence requested by users;
- provide AI-assisted and automated features described in section 8;
- process subscriptions, invoices and payments;
- authenticate users, enforce permissions, prevent fraud and investigate misuse or security incidents;
- communicate about accounts, service changes, outages, support, security and contractual matters;
- conduct product analytics, quality assurance, testing and performance monitoring;
- manage customer relationships, demonstrations, events and lawful marketing;
- comply with legal, regulatory, insurance, audit, accounting and tax obligations;
- establish, exercise or defend legal claims and resolve disputes;
- facilitate an actual or proposed corporate transaction under appropriate confidentiality controls; and
- carry out another purpose with consent or as required or authorised by law.
Vorda may create and use aggregated or de-identified information for analytics, security, service improvement, benchmarking, research and business planning where individuals are not reasonably identifiable. Vorda does not attempt to re-identify information that has been properly de-identified except where permitted by law to test or verify de-identification and security.
7. Sensitive information and consent
Care Data may contain sensitive information, including health information, disability-related information, racial or ethnic information, criminal-record information, professional-association information and information about a person’s support needs or behaviour.
Vorda collects sensitive information only where reasonably necessary for the functions of the Platform and where the collection is permitted by law. Vorda requires Providers to ensure they are authorised to disclose sensitive information to Vorda and that Vorda is authorised to collect and process it, including by obtaining valid consent from the relevant individual or authorised representative where consent is required.
A participant or other individual who wishes to withdraw consent or change how Provider-controlled information is used should ordinarily contact the relevant Provider. Withdrawal of consent may affect the Provider’s ability to deliver services or use particular Platform functions, and does not require deletion where information must or may lawfully be retained.
8. Artificial intelligence and automated features
8.1 AI-assisted content
The Platform may use artificial intelligence to help Authorised Users draft, extract, classify, summarise, review or organise information. Examples include drafting a progress note, extracting information from an uploaded record, suggesting a document classification, identifying missing information, generating a compliance summary or assisting with audit preparation.
AI-generated content is assistive and may be incomplete, inaccurate or inappropriate for a particular person or circumstance. It is not legal, clinical, financial, employment or professional advice. Authorised Users must independently review, verify, edit and approve AI-generated content before relying on it or adding it to an official participant, worker, incident, financial or compliance record.
Where Care Data is submitted to an AI feature, Vorda processes the relevant input and output within Australia using Amazon Web Services infrastructure in Australian regions, currently including the Sydney region. Vorda configures Care Data processing to use in-region or Australia-only geographic inference and does not use global or non-Australian inference profiles for Care Data.
Vorda requires its AI service providers not to use Customer Data to train or improve general-purpose or third-party foundation models. Vorda does not use identifiable Customer Data to train or fine-tune a general-purpose AI model unless the relevant Provider has expressly agreed, Vorda has provided appropriate notice, and the use is permitted by law. Vorda may use appropriately de-identified or aggregated information to evaluate and improve Platform performance.
AI prompts, outputs, user edits and approvals may be retained as Customer Data, audit evidence or security records in accordance with the Provider’s settings, contractual requirements and section 17.
8.2 Automated flags, recommendations and decisions
The Platform may automatically generate reminders, expiry alerts, compliance flags, document classifications, risk indicators, audit-readiness scores, suggested actions and other recommendations using information such as credentials, dates, documents, incidents, service records, Provider-configured rules and user activity.
These outputs support decisions made by the Provider and its Authorised Users. Unless Vorda expressly states otherwise in an updated notice, the Platform does not independently make final decisions that determine a participant’s NDIS eligibility or entitlement, the provision or withdrawal of supports, a worker’s employment or disciplinary outcome, or another individual’s legal rights or significant interests. The Provider remains responsible for evaluating the output, considering relevant context and making the final decision.
If Vorda introduces automated decision-making that may significantly affect an individual’s rights or interests, Vorda will update this policy and provide any additional notice required by law before or when that functionality is introduced.
9. Disclosure of personal information
Vorda may disclose personal information to:
- hosting, storage, backup, security and infrastructure providers;
- authentication, email, communications, customer-support, analytics, error-monitoring and push-notification providers;
- payment processors, banks, accountants and billing providers;
- AI, document-processing and other technology subprocessors used to provide the Platform;
- professional advisers, auditors, insurers and financiers;
- a Provider’s authorised integrations and connected services;
- government agencies, courts, tribunals, regulators, law-enforcement bodies or other persons where required or authorised by law;
- persons involved in investigating or responding to suspected fraud, misuse, safety risks, security incidents or legal claims;
- a prospective purchaser, investor, successor or transaction adviser in connection with a proposed or completed sale, merger, financing, restructure or transfer of all or part of Vorda’s business, subject to appropriate confidentiality and legal safeguards; and
- another recipient with consent or at the direction of the relevant Provider or individual.
Vorda does not sell Care Data or other personal information. Vorda does not disclose Care Data to third parties for their own advertising or independent marketing purposes.
When a Provider enables a third-party integration, information selected by the Provider may be disclosed to and handled by that third party under the Provider’s agreement with that third party and the third party’s privacy practices. Providers should assess an integration before enabling it. Vorda is not responsible for a third party’s independent acts after information has been disclosed at the Provider’s direction, except to the extent required by law.
10. Data location and overseas handling
10.1 Care Data
Vorda stores and processes Care Data in Australia, including production databases, document storage and backups. AI processing of Care Data is also restricted to AWS infrastructure in Australia as described in section 8.
Routine production access to Care Data by Vorda personnel is restricted to authorised personnel located in Australia and is subject to role-based access, least-privilege controls, confidentiality obligations and audit logging.
10.2 Operational and account information
Some account, billing, communications, authentication, diagnostic, analytics, error-monitoring and push-notification information may be processed by service providers located in or operating from countries outside Australia. The countries in which overseas recipients are currently likely to be located include the United States and Ireland.
Vorda configures its systems to minimise the inclusion of Care Data in overseas operational services and does not intentionally send Care Data to those services. Care Data may nevertheless be included if a Provider or user places it in an ordinary email, support message or another channel not designed for Care Data. Users should contact Vorda before sending sensitive material so an appropriate secure method can be provided.
Where Vorda discloses personal information to an overseas recipient, Vorda takes reasonable steps required by applicable law to ensure that the recipient handles the information consistently with applicable Australian privacy requirements. Overseas recipients may also be subject to foreign laws that require disclosure of information to public authorities.
A current list of Vorda’s material subprocessors and their principal processing locations is available from the Privacy Officer on request.
11. Government-related identifiers
Customer Data may include NDIS numbers and other government-related identifiers. Vorda does not adopt an NDIS number or another government-related identifier as Vorda’s own identifier for an individual.
Vorda uses or discloses government-related identifiers only where reasonably necessary for authorised Platform functions, to verify identity, administer NDIS-related records or integrations, meet obligations to an Australian government body, or as otherwise required or authorised by law.
12. Direct marketing and service communications
Vorda may use business-contact information to send information about the Platform, product updates, events, resources and offers where permitted by law. A person can opt out of marketing communications by using the unsubscribe facility or contacting Vorda.
Vorda may retain limited contact information on a suppression list so that an opt-out request can be respected. Opting out of marketing does not prevent Vorda from sending operational, contractual, security, billing or service messages that are reasonably necessary for an account or service.
Vorda does not use Care Data for direct marketing.
13. Cookies, analytics and online technologies
Vorda uses cookies and similar technologies to:
- authenticate users and maintain sessions;
- remember preferences and settings;
- secure the Platform and detect suspicious activity;
- understand website and Platform usage;
- diagnose errors and measure performance; and
- improve the Platform and customer experience.
Users can control cookies through browser or device settings. Disabling essential cookies may prevent parts of the Platform from operating correctly.
Vorda uses limited analytics and does not use Care Data to track individuals across unrelated third-party websites or applications for advertising. If Vorda materially changes its tracking or advertising practices, Vorda will update this policy and obtain any consent required by law or platform rules.
14. Mobile applications and device permissions
14.1 Camera, photos, files and microphone
With device permission, a Vorda mobile application may access the camera, photos, files or microphone when a user activates a feature that requires that access, such as capturing a document, uploading an incident photograph, attaching a receipt or recording a voice note. Permissions can be changed through device settings, although disabling a permission may prevent the related function from working.
Vorda does not activate the microphone for continuous listening or record audio in the background for these functions.
14.2 Shift location
Where a Provider enables location-based check-in or check-out and the user grants permission, the Platform records the location at the time the user initiates check-in or check-out. Vorda does not use that feature for continuous or background location tracking.
The Provider is responsible for determining whether the feature is appropriate, giving notices, consulting where required and complying with employment, workplace-surveillance and other applicable laws. Disabling location may prevent use of location-dependent check-in or check-out functions.
14.3 Device biometrics
Where a user enables Face ID, Touch ID or another device biometric to unlock the application, authentication is performed by the device operating system. Vorda does not receive or store the user’s biometric template.
14.4 Push notifications and diagnostics
The Platform may use a device token to deliver reminders, approvals, alerts and security messages. Vorda seeks to minimise sensitive content in push notifications, but users should consider device lock-screen settings where other people may be able to view notifications.
Mobile applications may collect app version, device and diagnostic information, crash information and performance data. The disclosures made in the Apple App Privacy information and Google Play Data Safety information are intended to be consistent with this policy.
15. Data quality
Vorda takes reasonable steps to ensure that personal information it collects directly is accurate, current, complete and relevant for its purposes. For Customer Data, Vorda generally relies on the Provider and Authorised Users to enter, review and maintain accurate information.
Vorda does not independently verify the factual accuracy, clinical appropriateness, legal sufficiency or completeness of Customer Data, uploaded documents, AI-generated content or Provider decisions. Providers must correct inaccurate information and ensure that decisions are not made solely from incomplete or unverified Platform outputs.
16. Security
Vorda takes reasonable technical and organisational steps designed to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure. These steps may include:
- encryption in transit and at rest;
- role-based and least-privilege access controls;
- authentication and session controls;
- network, infrastructure and application security measures;
- logging, monitoring and audit trails;
- secure development, testing and change-management practices;
- vulnerability management and incident-response processes;
- backups and disaster-recovery arrangements;
- personnel confidentiality, security awareness and access reviews; and
- vendor due diligence and contractual privacy and security requirements.
Providers and Authorised Users also have security responsibilities. They must maintain secure devices and networks, protect credentials, use appropriate access permissions and promptly notify Vorda of suspected unauthorised access or credential compromise.
No internet transmission, software platform or storage system is completely secure. Vorda does not guarantee that unauthorised access, loss or other incidents will never occur. Nothing in this section limits Vorda’s obligation to take reasonable steps required by law.
17. Data breaches
Vorda maintains processes for identifying, containing, assessing, investigating, remediating and documenting suspected data breaches.
Where Vorda has reasonable grounds to suspect that an eligible data breach may have occurred and the Notifiable Data Breaches scheme applies, Vorda will conduct a reasonable and expeditious assessment and take reasonable steps to complete that assessment within 30 days after becoming aware of the suspected breach.
Where Vorda has reasonable grounds to believe that an eligible data breach has occurred, Vorda will notify the Office of the Australian Information Commissioner and affected individuals as soon as practicable, unless an exception applies.
Where an incident involves Customer Data, Vorda will notify the relevant Provider promptly and provide information reasonably available to Vorda to assist the Provider to assess and meet its own legal, contractual and regulatory obligations. Depending on the circumstances, an incident may also engage a Provider’s obligations under the NDIS incident-management or reportable-incident framework. The Provider remains responsible for notifications and actions arising from its delivery of supports, except where Vorda has a separate legal obligation.
18. Retention, account closure and deletion
18.1 General retention approach
Vorda retains personal information only for as long as reasonably necessary for the purposes for which it was collected, to provide and secure the Platform, to comply with a Provider’s lawful instructions, to meet legal and regulatory obligations, or to establish, exercise or defend legal claims.
Retention periods vary according to the information, account status, contractual arrangements, Provider instructions and applicable law. For example:
- subscription, billing, accounting, tax and contractual records may be retained for the periods required by law and legitimate business needs;
- security, access and audit logs may be retained for security, investigation, compliance and dispute-resolution purposes;
- marketing information may be retained until it is no longer required, subject to maintaining suppression records;
- support and complaint records may be retained while a matter is active and for a reasonable period afterwards; and
- Customer Data is retained during the Provider’s subscription and afterwards as required for export, transition, backup expiry, dispute resolution, Provider instructions and applicable law.
18.2 NDIS records
Providers may be required or expected to retain particular NDIS records for significant periods. Certain NDIS incident and complaint records must generally be kept for at least seven years, and NDIS Commission guidance recommends retaining participant records for a minimum of seven years after service provision. Other periods may apply depending on the Provider, record type, participant, service and applicable Commonwealth, State or Territory law.
The Provider is responsible for determining the legally appropriate retention period for Customer Data it controls and for configuring or instructing Vorda accordingly. Vorda may decline or delay deletion where retention is required or permitted by law, contract, a legal hold, an investigation or the Provider’s lawful instructions.
18.3 Account closure and deletion requests
A Provider account owner may request account closure through available Platform settings or by contacting Vorda. Where account creation is available through a Vorda mobile application, Vorda provides an in-app pathway to initiate account deletion in accordance with applicable app-store requirements.
Closing an Authorised User’s login does not necessarily delete records created by that user because those records may form part of the Provider’s Customer Data, audit trail or legal records.
Deletion is not absolute. Vorda may retain information where reasonably necessary or permitted for legal compliance, security, fraud prevention, billing, taxation, audit, dispute resolution, enforcement of agreements, backup integrity or the rights of another person. Data in backups may remain until it is overwritten under Vorda’s normal backup cycle and will not be restored except for disaster recovery or another legitimate operational purpose.
When personal information is no longer required and Vorda is not required or permitted to retain it, Vorda takes reasonable steps to destroy or de-identify it. Properly de-identified or aggregated information may be retained.
19. Access and correction
An individual may request access to, or correction of, personal information held by Vorda. Vorda may require reasonable identity and authority verification before acting on a request.
Where information forms part of Customer Data controlled by a Provider, the individual should ordinarily contact that Provider. Vorda may refer the request to the Provider or assist the Provider to respond. A nominee, guardian or other representative must establish appropriate authority.
Vorda will respond within a reasonable period and generally aims to respond within 30 calendar days. Access or correction may be refused or limited where an exception under applicable law applies. If Vorda refuses a request, Vorda will generally provide written reasons and information about how to complain, unless it would be unreasonable or unlawful to do so.
20. Privacy complaints
A person may submit a privacy question or complaint to Vorda’s Privacy Officer using the contact details in section 23. Please provide sufficient detail for Vorda to understand and investigate the matter, but do not send Care Data through ordinary email unless Vorda has provided a secure method.
Vorda generally aims to acknowledge a complaint within seven days and provide a substantive response within 30 calendar days. A longer period may be required where the matter is complex, involves a Provider or third party, requires identity verification or depends on information outside Vorda’s control. Vorda will communicate where additional time is reasonably required.
If a person is not satisfied with Vorda’s response, they may contact the Office of the Australian Information Commissioner at www.oaic.gov.au or on 1300 363 992. Other regulators or complaint bodies may also have jurisdiction depending on the circumstances.
21. Children and young people
The Platform is provided to organisations and their authorised personnel and is not directed to children for independent consumer use. A Provider may use the Platform to hold information about a participant who is a child or young person where the Provider is authorised to do so.
The Provider is responsible for obtaining consent or other authority from a parent, guardian, nominee or the young person where required, respecting the young person’s capacity and rights, and applying any additional legal or policy safeguards relevant to children and young people.
22. Changes to this policy
Vorda may update this Privacy Policy to reflect changes to law, regulatory guidance, technology, vendors or Platform functions. The current version will be published on Vorda’s website and made available through the Platform with its effective date.
Where a change materially affects how personal information is handled, Vorda will take reasonable steps to provide additional notice through the Platform, by email or by another appropriate method before or when the change takes effect.
23. Contact Vorda
Privacy Officer Vorda Pty Ltd ABN 52 698 153 623 Unit 8, 20 Macmillan Avenue Mawson Lakes SA 5095 Australia Email: info@vorda.com.au Website: www.vorda.com.au
Alternative and accessible formats of this policy, including an Easy Read summary where reasonably available, may be requested from the Privacy Officer.
Need help?
Contact our Privacy Officer
For a privacy question, complaint, or to request an accessible format of this policy, please get in touch.
Email the Privacy Officer