Legal

Terms of Service

The terms that govern access to and use of the Vorda platform by NDIS providers and their authorised users.

Important

The Platform is an assistive software tool. Customers remain responsible for their decisions, professional judgement and compliance with applicable law.

These Terms of Service govern access to and use of the Vorda platform by NDIS providers and their authorised users. Please read them carefully.

1. Agreement and acceptance

1.1 Parties

These Terms of Service (Terms) are an agreement between Vorda Pty Ltd (ABN 52 698 153 623) (Vorda, we, us or our) and the person or organisation identified as the customer in an Order Form or when an account is created (Customer, you or your).

1.2 Authority to accept

If you accept these Terms for an organisation, you represent that you have authority to bind that organisation. If you do not have that authority, you must not create an account, purchase a Subscription or use the Platform on its behalf.

1.3 When the agreement starts

The agreement starts on the earliest of the date you:

(a) accept an Order Form that refers to these Terms;

(b) click to accept these Terms;

(c) create or activate a paid account; or

(d) first use the Platform after being given notice that these Terms apply.

1.4 Documents forming the agreement

The agreement consists of:

(a) each Order Form accepted by the parties;

(b) the Data Processing Addendum in Schedule 1;

(c) these Terms; and

(d) any additional written terms expressly agreed by Vorda and the Customer.

If there is an inconsistency, the documents apply in the order listed above, except that Schedule 1 prevails for the processing and protection of personal information.

1.5 Privacy Policy

Our Privacy Policy explains how we handle personal information. It is a privacy notice and does not create contractual rights or obligations except where these Terms or Schedule 1 expressly say otherwise.

2. Definitions

In these Terms:

Applicable Law means any law, regulation, binding code, standard, court order or regulatory requirement that applies to a party, the Platform, Customer Data or the Customer’s activities, including the Privacy Act 1988 (Cth), the Australian Consumer Law, applicable State and Territory privacy and health-records laws, and applicable NDIS legislation, rules and standards.

App Store means the Apple App Store, Google Play or another authorised application marketplace through which a Vorda mobile application is distributed.

Authorised User means an individual whom the Customer authorises to access the Platform under the Customer’s account, including an administrator, manager, employee, contractor, support worker, participant or authorised representative.

Business Day means a day other than a Saturday, Sunday or public holiday in Australia.

Care Data means Customer Data relating to participants, workers, service delivery, health or disability, incidents, progress notes, restrictive practices, credentials, service agreements, rosters, timesheets, billing, correspondence or audit evidence.

Confidential Information has the meaning given in clause 15.

Customer Data means all data, records, documents, images, audio, content and personal information submitted to, stored in, transmitted through or generated for the Customer through the Platform, including Care Data and AI prompts and outputs. Customer Data does not include Usage Data.

Documentation means user guides, technical materials and instructions made available by Vorda for the Platform.

Fees means the fees payable for the Subscription as set out in an Order Form, at checkout or on the applicable pricing page.

Order Form means an order, proposal, online checkout, subscription confirmation or other document accepted by the parties that identifies the Subscription, Fees or other commercial terms.

Platform means Vorda’s websites, web applications, mobile applications, APIs, software features and related services made available under a Subscription.

Provider means the NDIS provider organisation that holds the Customer account.

Security Incident means a confirmed unauthorised access to, acquisition, use, alteration, loss or disclosure of Customer Data in Vorda’s possession or control. It does not include unsuccessful attempts or events that do not compromise Customer Data, such as blocked scans, failed login attempts or denial-of-service attempts that are successfully mitigated.

Subscription means the right to access and use the Platform under an Order Form or selected plan.

Subscription Term means the period for which the Customer has purchased or is entitled to use a Subscription.

Usage Data means technical, diagnostic, statistical and usage information about operation and use of the Platform that does not identify a participant or worker and does not disclose the Customer’s Confidential Information.

Vorda Materials means the Platform, Documentation, templates, software, workflows, designs, databases, models, taxonomies, reports, interfaces and other materials supplied or developed by Vorda, excluding Customer Data.

3. The Platform and licence

3.1 Subscription service

Subject to payment of the Fees and compliance with the agreement, Vorda grants the Customer a limited, non-exclusive, non-transferable and non-sublicensable right during the Subscription Term to access and use the Platform for the Customer’s internal NDIS compliance, workforce and operational purposes.

3.2 Authorised Users

The Customer may permit Authorised Users to use the Platform within the limits of its Subscription. The Customer is responsible for determining who should have access, assigning appropriate permissions, reviewing access regularly and promptly removing access when it is no longer required.

3.3 Documentation and updates

The Customer may use the Documentation solely to support its permitted use of the Platform. Vorda may provide updates, patches, new features and changes to the Platform from time to time in accordance with clause 26.

3.4 What Vorda is not

Vorda provides software tools. Vorda is not:

(a) an NDIS provider, approved quality auditor or government authority;

(b) a law firm, accounting practice, medical practice, clinical service or employment adviser;

(c) the Customer’s records manager, privacy officer, incident manager or compliance officer; or

(d) responsible for delivering supports, making clinical or safeguarding decisions, determining NDIS funding, authorising restrictive practices, submitting regulatory reports or deciding whether the Customer is compliant.

3.5 No certification or compliance guarantee

The Platform may assist the Customer to organise records, identify gaps and prepare evidence, but it does not certify or guarantee compliance, registration, audit outcomes, payment, funding, worker suitability or the accuracy of information supplied by third parties. The Customer remains responsible for its decisions, professional judgement and compliance with Applicable Law.

4. Customer responsibilities

4.1 General responsibility

The Customer is responsible for its use of the Platform, its delivery of supports and services, and all decisions and actions taken using information or outputs from the Platform.

4.2 Legal authority and notices

The Customer must:

(a) have a lawful basis and all notices, consents, permissions and authorities required to collect, use, disclose and upload Customer Data;

(b) ensure any nominee, guardian, plan manager, supported decision-maker or representative has appropriate authority;

(c) provide all privacy, collection, monitoring and workplace-surveillance notices required by Applicable Law;

(d) comply with employment, workplace surveillance, health-records, disability, safeguarding and NDIS requirements applicable to its activities; and

(e) not instruct Vorda to process Customer Data unlawfully.

4.3 Accuracy and review

The Customer must take reasonable steps to ensure Customer Data is accurate, complete, current and appropriate for its intended purpose. The Customer must review and verify documents, alerts, calculations, mappings, templates, AI outputs and other Platform results before relying on them, sharing them or adding them to an official record.

4.4 Regulatory obligations

The Customer is solely responsible for:

(a) determining which NDIS Practice Standards, registration groups, reporting obligations and retention periods apply to it;

(b) notifying and reporting incidents, restrictive practices, worker matters, complaints or other events within required timeframes;

(c) obtaining professional advice where appropriate;

(d) maintaining service agreements, consents, authorisations, worker screening and other records required by Applicable Law; and

(e) ensuring that information submitted to government agencies, auditors, plan managers, participants or other third parties is accurate and authorised.

4.5 Location and workforce monitoring

If the Customer enables location capture, check-in verification, device permissions, activity logging or other workforce-monitoring features, the Customer is responsible for determining whether the feature is lawful and proportionate and for giving workers and other affected individuals any notice and obtaining any consent required by Applicable Law.

4.6 Record retention and business continuity

The Customer is responsible for setting its record-retention requirements, exporting records when reasonably required and maintaining any independent records or continuity arrangements necessary for its legal and operational obligations. Vorda does not determine the Customer’s statutory retention periods.

4.7 No emergency use

The Platform is not an emergency, crisis-response or clinical monitoring service. It must not be relied on to contact emergency services, prevent imminent harm or deliver time-critical clinical care.

5. Accounts and security

5.1 Account information

The Customer must provide accurate account and billing information and keep it current.

5.2 Credentials

Each Authorised User must use an individual account. Login credentials must not be shared. The Customer must use reasonable security practices, including strong passwords and multi-factor authentication where available.

5.3 Responsibility for account activity

The Customer is responsible for activity under its account to the extent caused by its Authorised Users, its systems or its failure to protect credentials. The Customer is not responsible for activity caused by Vorda’s breach of the agreement or a Security Incident within Vorda’s systems.

5.4 Unauthorised access

The Customer must notify Vorda promptly after becoming aware of suspected unauthorised account access, credential compromise or misuse of the Platform and must reasonably cooperate with Vorda’s response.

6. Acceptable use

6.1 Prohibited conduct

The Customer and its Authorised Users must not:

(a) use the Platform unlawfully or to infringe a person’s rights;

(b) submit Customer Data they are not authorised to provide;

(c) introduce malware or harmful code;

(d) attempt to bypass access controls, probe vulnerabilities or access another customer’s systems or data;

(e) interfere with the integrity, security, performance or availability of the Platform;

(f) reverse engineer, decompile, disassemble or seek to derive source code, except to the limited extent the restriction is prohibited by law;

(g) copy, frame, mirror, scrape or systematically extract the Platform or Vorda Materials;

(h) resell, lease, timeshare, sublicense or provide the Platform as a service bureau without Vorda’s written approval;

(i) remove proprietary notices;

(j) use the Platform or its outputs to develop or train a competing product or model, except using Customer Data that the Customer independently owns and has exported lawfully;

(k) conduct or publish benchmark, penetration or security testing without Vorda’s written approval; or

(l) use an AI feature as the sole basis for a decision that produces legal or similarly significant effects for an individual.

6.2 Reasonable limits

Vorda may apply reasonable technical limits to protect security, stability and fair use. If the Customer materially exceeds the limits of its Subscription, Vorda may require the Customer to reduce usage or move to an appropriate plan.

6.3 Investigation and suspension

Vorda may investigate suspected misuse and may suspend affected access where reasonably necessary to protect individuals, Customer Data, the Platform or other customers. Vorda will limit a suspension to the affected access where reasonably practicable and will give notice unless doing so would increase security or legal risk.

7. Customer Data, outputs and Usage Data

7.1 Customer ownership

As between the parties, the Customer retains all rights in Customer Data.

7.2 Licence to provide the Platform

The Customer grants Vorda and its approved subcontractors a non-exclusive right to host, copy, transmit, process, display and otherwise use Customer Data only as reasonably necessary to:

(a) provide, secure, maintain and support the Platform;

(b) follow the Customer’s documented instructions;

(c) prevent fraud, misuse and security threats;

(d) comply with Applicable Law; and

(e) exercise Vorda’s rights and perform its obligations under the agreement.

7.3 AI and generated outputs

As between the parties, the Customer owns its rights in outputs generated specifically for it from Customer Data, subject to Vorda’s ownership of the Platform, Vorda Materials and underlying tools. Outputs may not be unique, and similar outputs may be generated for others.

7.4 Usage Data and de-identified information

Vorda may collect and use Usage Data to operate, secure, analyse and improve the Platform and to produce aggregated statistics. Vorda may use information derived from Customer Data only where it has been de-identified so that no individual or Customer is reasonably identifiable, and Vorda must not attempt to re-identify it.

7.5 Customer warranties about data

The Customer represents and warrants that its provision of Customer Data and Vorda’s processing of it in accordance with the agreement will not breach Applicable Law, confidentiality obligations or third-party rights.

8. Privacy and data processing

8.1 Data Processing Addendum

Schedule 1 applies to Vorda’s processing of personal information contained in Customer Data.

8.2 Customer’s role

The Customer determines why and how Customer Data is collected and used in its business. The Customer remains responsible for its privacy notices, consents, instructions, data quality, access permissions and responses to individuals and regulators, except to the extent the agreement expressly assigns a responsibility to Vorda.

8.3 Vorda’s role

Vorda processes personal information in Customer Data to provide the Platform and in accordance with the agreement, the Customer’s lawful instructions and Applicable Law. Depending on the circumstances, both parties may have direct obligations under privacy law, and nothing in the agreement excludes those obligations.

8.4 Government and legal requests

If Vorda receives a legally binding request for Customer Data, Vorda may disclose the minimum information reasonably required. Where legally permitted and practicable, Vorda will notify the Customer before disclosure.

9. Data location, security and incidents

9.1 Australian hosting of Care Data

Vorda will host the primary production data stores and production backups containing Care Data in Australia. Where Vorda’s AI features process Care Data, Vorda will configure those features to process that Care Data in Australia. This commitment does not apply to:

(a) operational, account, billing, support, email, analytics, diagnostic or push-notification data described in the Privacy Policy;

(b) transfers initiated or authorised by the Customer through an integration, export, email, download or sharing feature;

(c) access or disclosure required by Australian law; or

(d) information that has been de-identified so that no individual or Customer is reasonably identifiable.

9.2 Security measures

Vorda will maintain reasonable technical and organisational measures appropriate to the nature of Customer Data and the risks of processing, including access controls, encryption in transit and at rest, logging, backup arrangements, vulnerability management and incident-response procedures.

9.3 No absolute security

No internet-based service can be guaranteed to be uninterrupted or completely secure. Vorda does not warrant that all threats, vulnerabilities or unauthorised access can be prevented, but this does not reduce Vorda’s obligation to maintain the measures required by clause 9.2 and Schedule 1.

9.4 Security Incident notification

Vorda will notify the Customer without undue delay after becoming aware of a Security Incident affecting Customer Data and will provide information and reasonable cooperation available to Vorda to assist the Customer to assess and respond to the incident. Notification is not an admission of fault or liability.

9.5 Customer security responsibilities

The Customer is responsible for security within its own systems, devices, networks and accounts, including user access, endpoint security, exports and information shared outside the Platform. The Customer must not include Care Data in ordinary email or general support requests unless Vorda requests it through an approved secure process.

10. Artificial intelligence features

10.1 Assistive features only

AI features are designed to assist with drafting, summarising, extraction, classification, quality checks and similar tasks. They do not replace professional judgement, human review or the Customer’s statutory responsibilities.

10.2 Output limitations

AI outputs may be inaccurate, incomplete, inconsistent, biased or unsuitable for a particular purpose. The Customer must review source materials and independently verify an output before relying on it.

10.3 Restricted uses

The Customer must not use AI outputs as the sole basis for:

(a) a clinical diagnosis, treatment or medication decision;

(b) an emergency or safeguarding decision;

(c) authorising or implementing a restrictive practice;

(d) deciding whether to hire, dismiss, discipline or exclude a worker;

(e) determining a participant’s legal rights, eligibility or access to supports; or

(f) submitting information to a regulator or auditor without human verification.

10.4 Responsibility for final records

A user who approves, edits, exports, signs or submits an AI-assisted record is responsible for the final record and for ensuring that it is accurate, lawful and appropriate.

10.5 Training restriction

Vorda will not permit an AI subprocessor to use Customer Data to train a general-purpose model for that provider’s or another person’s benefit unless the Customer has expressly opted in in writing.

10.6 Model and feature changes

AI models and features may change as technology, law and provider availability evolve. Vorda may modify, limit or withdraw an AI feature where reasonably necessary for safety, accuracy, security, legal compliance or service availability.

11. Third-party services

11.1 Customer-directed integrations

The Customer may choose to connect the Platform to third-party services. By enabling an integration, the Customer authorises Vorda to exchange the data necessary to operate it.

11.2 Separate terms

Third-party services are governed by their own terms and privacy practices. Vorda does not control and is not responsible for a third-party service, its availability, acts, omissions, security or changes.

11.3 Integration changes

Vorda may suspend or discontinue an integration if the third party changes or withdraws access, the integration creates security or legal risk, or continued support is not commercially reasonable. Where practicable, Vorda will provide notice.

12. Fees, billing and taxes

12.1 Fees

The Customer must pay the Fees stated in the applicable Order Form or checkout. Unless stated otherwise, Fees are in Australian dollars and exclude GST.

12.2 GST

If GST is payable on a taxable supply, the Customer must pay the GST amount in addition to the Fees after receiving a valid tax invoice.

12.3 Billing and renewal

Subscriptions are billed in advance on the selected monthly or annual cycle and automatically renew for successive periods of the same length unless cancelled before the renewal date. The Customer authorises Vorda or its payment processor to charge the nominated payment method.

12.4 Cancellation

The Customer may cancel renewal at any time through the available account or billing controls or by contacting Vorda. Cancellation takes effect at the end of the current paid Subscription Term unless Applicable Law requires otherwise.

12.5 Failed payments

If an undisputed amount remains unpaid after its due date, Vorda may provide notice and suspend paid features if payment is not made within 7 days after that notice. Vorda may recover reasonable external collection costs actually incurred in recovering overdue undisputed amounts.

12.6 Billing disputes

The Customer must notify Vorda of a billing dispute promptly and provide reasonable details. The parties will work in good faith to resolve it. This clause does not limit rights that cannot be excluded by law.

12.7 Fee changes

Vorda may change Fees for a future renewal by giving at least 30 days’ notice. A Fee change will not apply during a prepaid Subscription Term. If the Customer does not agree, it may cancel before renewal without penalty.

12.8 Refunds

Except as required by Applicable Law, stated in an Order Form or expressly provided in these Terms, Fees are non-refundable. If Vorda terminates a paid Subscription for convenience or the Customer terminates for Vorda’s uncured material breach, Vorda will refund prepaid Fees for the unused portion of the affected Subscription Term.

12.9 App Store purchases

If a Subscription is purchased through an App Store, billing, renewal, cancellation and refunds are also subject to that App Store’s rules, and the Customer must manage the purchase through the relevant App Store account where required.

13. Trials, free plans and beta features

13.1 Trials and free plans

Vorda may offer a trial or free plan subject to stated limits. Unless required by law, Vorda may modify or end a trial or free plan on reasonable notice.

13.2 Beta features

A beta, preview, experimental or early-access feature may be incomplete, change materially or be withdrawn. The Customer must not rely on a beta feature for time-critical, clinical, safeguarding or statutory reporting functions unless Vorda expressly states that the feature is production-ready for that purpose.

13.3 Liability for free services

To the maximum extent permitted by law, Vorda’s aggregate liability arising from a free plan, trial or beta feature is limited to AUD 100, except for liability that cannot lawfully be limited.

14. Support, maintenance and availability

14.1 Support

Vorda will provide support in accordance with the Customer’s plan and any service description or Order Form.

14.2 Availability

Vorda will use commercially reasonable efforts to keep the Platform available. No service-level commitment or service credit applies unless expressly stated in an Order Form or separate service-level agreement.

14.3 Maintenance

Vorda may carry out scheduled and emergency maintenance. Vorda will use reasonable efforts to give advance notice of scheduled maintenance expected to cause material disruption.

14.4 Backups and restoration

Vorda maintains backup and disaster-recovery arrangements appropriate to the Platform. Backups are intended for service recovery and are not a substitute for the Customer’s own record-retention and export responsibilities.

15. Confidentiality

15.1 Confidential Information

A party’s Confidential Information is information disclosed by or on behalf of that party that is marked confidential or that a reasonable person would understand to be confidential, including Customer Data, security information, pricing, product plans, technical information and business information. Vorda’s Confidential Information includes the non-public aspects of the Platform and Vorda Materials.

15.2 Obligations

The receiving party must:

(a) use the disclosing party’s Confidential Information only to perform or exercise rights under the agreement;

(b) protect it using at least reasonable care;

(c) disclose it only to personnel, professional advisers and subcontractors who need to know it and are subject to confidentiality obligations; and

(d) not disclose it to any other person without consent, except as permitted by this clause.

15.3 Exclusions

Confidential Information does not include information the receiving party can demonstrate:

(a) is or becomes public without breach of the agreement;

(b) was lawfully known without restriction before disclosure;

(c) is received lawfully from a third party without confidentiality restriction; or

(d) is independently developed without use of the disclosing party’s Confidential Information.

15.4 Required disclosure

A receiving party may disclose Confidential Information where required by law, court order or regulator. Where legally permitted, it must give reasonable advance notice and disclose only what is required.

15.5 Injunctive relief

A breach of this clause may cause harm that damages alone cannot adequately remedy. A party may seek urgent injunctive or equitable relief in addition to other remedies.

16. Intellectual property

16.1 Vorda ownership

Vorda and its licensors own all rights in the Vorda Materials, including improvements, modifications and derivative works, whether developed independently or in response to feedback.

16.2 Restrictions

Except as expressly permitted, no right to Vorda Materials is transferred to the Customer. The Customer must not use Vorda’s name, logo or trade marks without written permission.

16.3 Feedback

If the Customer provides feedback or suggestions, it grants Vorda a perpetual, irrevocable, worldwide, royalty-free right to use them without restriction or obligation, provided Vorda does not identify the Customer publicly without consent.

17. Intellectual-property claims

17.1 Vorda protection

Subject to this clause, Vorda will defend the Customer against a third-party claim that the Customer’s authorised use of the unmodified Platform infringes an Australian patent, copyright or registered trade mark, and will pay damages finally awarded or settlement amounts approved by Vorda.

17.2 Conditions

Vorda’s obligation applies only if the Customer:

(a) promptly gives written notice of the claim;

(b) gives Vorda sole control of the defence and settlement, except that Vorda may not settle by admitting fault by the Customer or imposing non-monetary obligations on it without consent; and

(c) provides reasonable cooperation at Vorda’s cost.

17.3 Exclusions

Vorda has no obligation to the extent a claim arises from:

(a) Customer Data;

(b) use contrary to the agreement or Documentation;

(c) modification not made by Vorda;

(d) combination with an item not supplied or approved by Vorda, where the claim would not otherwise arise;

(e) continued use after Vorda provides a non-infringing alternative or requires use to stop; or

(f) a free, trial or beta feature.

17.4 Remedies

If a claim is made or likely, Vorda may procure continued use, modify or replace the affected feature, or terminate the affected Subscription and refund prepaid Fees for its unused portion. This clause states the Customer’s exclusive contractual remedy for third-party intellectual-property infringement, subject to rights that cannot be excluded by law.

18. Term, suspension and termination

18.1 Subscription Term

The Subscription Term is stated in the Order Form or selected at checkout and renews under clause 12 unless cancelled.

18.2 Termination for breach

Either party may terminate the affected agreement by written notice if the other party materially breaches it and does not remedy the breach within 30 days after receiving notice. If the breach cannot reasonably be remedied, termination may be immediate.

18.3 Insolvency

Either party may terminate immediately if the other becomes insolvent, enters liquidation or administration, ceases business or is subject to an equivalent event, except where termination is prohibited by law.

18.4 Suspension

Vorda may suspend access to the extent reasonably necessary if:

(a) payment remains overdue after the process in clause 12.5;

(b) the Customer materially breaches clause 6;

(c) access creates a material security, privacy, legal or safeguarding risk;

(d) suspension is required by law or a regulator; or

(e) a third-party provider necessary for the Platform suspends Vorda’s access.

Where practicable, Vorda will give notice, explain the reason and allow the Customer to remedy the issue. Vorda will restore access promptly after the issue is resolved.

18.5 Discontinuation by Vorda

Vorda may discontinue the Platform or a material paid service by giving at least 60 days’ notice. If this occurs during a prepaid Subscription Term and no reasonably equivalent service is offered, the Customer may terminate and receive a pro-rata refund of prepaid Fees for the unused period.

18.6 Effect of termination

Termination does not affect accrued rights or payment obligations. Clauses intended by their nature to survive will survive, including clauses 7, 8, 15, 16, 17, 19, 20, 21, 22, 23, 25 and 28.

19. Data export, return and deletion

19.1 Export during the Subscription

The Customer may use available export features during the Subscription Term. The Customer should not wait until termination to export records required for legal, audit or continuity purposes.

19.2 Post-termination access

Unless access is suspended for unlawful conduct or a serious security risk, Vorda will make Customer Data available for export for 30 days after the effective termination date. Continued use of the Platform during this period is not permitted except for export and account administration.

19.3 Deletion

After the export period, Vorda may delete Customer Data from active systems. Residual copies may remain temporarily in secure backups and logs until deleted or overwritten through ordinary retention cycles. Vorda may retain information where required by law, to establish or defend legal claims, to prevent fraud or security threats, or as otherwise described in the Privacy Policy and Schedule 1.

19.4 Customer responsibility

The Customer is responsible for exporting and retaining records it is legally required to keep. Vorda is not responsible for a failure to export Customer Data before deletion where Vorda provided the export period required by this clause.

19.5 Assistance

Additional migration, custom export or restoration services may be available for a reasonable fee agreed in advance.

20. Warranties and disclaimers

20.1 Mutual authority

Each party warrants that it has authority to enter into and perform the agreement.

20.2 Vorda warranty

Vorda warrants that it will provide paid services with due care and skill as required by Applicable Law.

20.3 Exclusions

Subject to clause 21, and to the maximum extent permitted by law, Vorda does not warrant that:

(a) the Platform will be uninterrupted, error-free or immune from security threats;

(b) every defect will be corrected;

(c) information, templates, alerts, calculations, mappings, integrations or AI outputs will be complete, current or suitable for every Customer;

(d) use of the Platform will result in registration, compliance, funding, payment, audit success or any particular business outcome; or

(e) third-party services will remain available or unchanged.

20.4 Reliance on Customer and third-party information

Vorda is not responsible for errors or outcomes caused by inaccurate, incomplete, outdated or unauthorised Customer Data, Customer instructions, third-party data or a failure to review Platform outputs.

21. Australian Consumer Law and non-excludable rights

21.1 Preserved rights

Nothing in the agreement excludes, restricts or modifies a guarantee, right, condition or remedy that cannot lawfully be excluded or limited, including under the Australian Consumer Law (Non-Excludable Right).

21.2 Business-acquired services

Where a Non-Excludable Right applies to services not ordinarily acquired for personal, domestic or household use or consumption, and it is fair and reasonable to do so, Vorda’s liability is limited, at Vorda’s option, to resupplying the affected services or paying the reasonable cost of having them resupplied.

21.3 No misleading exclusion

The exclusions and limitations in the agreement apply only to the extent permitted by law and must not be read as representing that a Non-Excludable Right does not apply.

22. Liability

22.1 Excluded loss

Subject to clause 21 and to the maximum extent permitted by law, neither party is liable to the other for:

(a) indirect, special or consequential loss; or

(b) loss of profit, revenue, anticipated savings, opportunity, goodwill or reputation,

whether arising in contract, tort (including negligence), statute or otherwise, even if advised that the loss was possible.

This exclusion does not apply to amounts payable to a third party under an indemnity in the agreement or to loss that cannot lawfully be excluded.

22.2 Specific Vorda exclusions

Subject to clause 21, Vorda is not liable to the extent loss arises from:

(a) the Customer’s delivery of NDIS supports or services;

(b) the Customer’s regulatory, clinical, employment, safeguarding, funding or business decisions;

(c) Customer Data, Customer instructions or unauthorised account access caused by the Customer;

(d) failure to review or verify an AI output or other Platform result;

(e) a third-party service, App Store, telecommunications network or Customer-controlled system;

(f) use contrary to the agreement, Documentation or Vorda’s reasonable instructions; or

(g) failure to export records in accordance with clause 19.

22.3 Liability cap

Subject to clauses 21 and 22.4, each party’s total aggregate liability arising out of or in connection with the agreement is limited to the greater of:

(a) the Fees paid or payable by the Customer for the affected Subscription in the 12 months immediately before the first event giving rise to liability; and

(b) AUD 10,000.

All related events and claims are treated as a single claim for the purpose of this cap.

22.4 Matters not subject to the cap

The cap in clause 22.3 does not apply to:

(a) liability that cannot lawfully be limited;

(b) fraud or wilful misconduct;

(c) death or personal injury caused by negligence;

(d) the Customer’s obligation to pay Fees;

(e) the Customer’s infringement or misuse of Vorda’s intellectual property; or

(f) a party’s liability under an indemnity, except that Vorda’s liability under clause 17 remains subject to the cap in clause 22.3.

22.5 Mitigation and contribution

A party claiming loss must take reasonable steps to mitigate it. Liability will be reduced to the extent the other party or a third party caused or contributed to the loss.

23. Customer indemnity

23.1 Indemnified claims

The Customer indemnifies Vorda, its officers and personnel against third-party claims, regulatory demands, damages, penalties, liabilities and reasonable external legal costs to the extent arising from:

(a) Customer Data or an allegation that Vorda’s authorised processing of Customer Data infringes rights or breaches law;

(b) the Customer’s NDIS services, clinical or safeguarding decisions, restrictive-practice activities, employment practices or dealings with participants, workers, regulators, auditors or third parties;

(c) the Customer’s failure to obtain required consent, authority or provide required notice;

(d) the Customer’s unlawful use of location, monitoring or workforce features;

(e) the Customer’s breach of clause 6; or

(f) fraud, wilful misconduct or unlawful conduct by the Customer or an Authorised User.

23.2 Exclusion

The indemnity does not apply to the extent the claim was caused by Vorda’s breach of the agreement, negligence, fraud or wilful misconduct.

23.3 Procedure

Vorda must give prompt notice of an indemnified claim, allow the Customer reasonable control of the defence and settlement, and provide reasonable cooperation at the Customer’s cost. The Customer must not settle a claim in a way that admits fault by Vorda, imposes non-monetary obligations on Vorda or fails to release Vorda without Vorda’s consent, not to be unreasonably withheld.

24. Force majeure

24.1 Events beyond reasonable control

Neither party is liable for delay or failure to perform caused by an event beyond its reasonable control, including natural disaster, fire, epidemic, war, civil unrest, government action, utility or telecommunications failure, or widespread failure of third-party cloud or App Store infrastructure.

24.2 Limits

This clause does not excuse payment obligations and does not apply to the extent an event could reasonably have been prevented by compliance with a party’s security, business-continuity or disaster-recovery obligations.

24.3 Extended event

If a force majeure event materially prevents the paid Platform from being provided for more than 30 consecutive days, either party may terminate the affected Subscription. Vorda will refund prepaid Fees for the unused period after termination.

25. Dispute resolution

25.1 Notice and negotiation

Before starting court proceedings, a party must give written notice describing the dispute. A senior representative of each party must meet or confer in good faith within 10 Business Days to try to resolve it.

25.2 Mediation

If the dispute is not resolved within 20 Business Days after notice, either party may refer it to mediation in Adelaide, South Australia, administered by the Resolution Institute under its mediation rules. The parties will share the mediator’s fees equally and bear their own costs.

25.3 Exceptions

This clause does not prevent a party from seeking urgent interlocutory or injunctive relief, recovering an undisputed debt or exercising a right of suspension or termination.

26. Changes to the Platform and Terms

26.1 Platform changes

Vorda may improve, update or change the Platform. During a paid Subscription Term, Vorda will not intentionally remove a core paid feature without providing a reasonably equivalent alternative or the termination and refund option in clause 18.5, unless the change is required urgently for law, safety or security.

26.2 Changes to Terms

Vorda may update these Terms by giving at least 30 days’ notice of a material change. If a change materially and adversely affects the Customer, the Customer may terminate the affected Subscription before the change takes effect and receive a pro-rata refund of prepaid Fees for the unused period.

26.3 Urgent changes

Vorda may make a change on shorter notice where reasonably necessary to comply with law, address a security threat or prevent material harm. Vorda will explain the change as soon as reasonably practicable.

26.4 Non-material changes

Vorda may make non-material, clarifying or administrative changes by posting the updated Terms with a revised effective date.

27. Mobile applications and App Stores

27.1 Additional store terms

Use of a mobile application is also subject to the applicable App Store’s mandatory terms. If a mandatory App Store term conflicts with the agreement, it prevails only to the extent required.

27.2 Apple-specific terms

For an application obtained through Apple:

(a) the agreement is between the Customer or user and Vorda, not Apple;

(b) Vorda, not Apple, is responsible for the application, its support and claims relating to it, subject to the agreement and Applicable Law;

(c) Apple has no obligation to provide maintenance or support;

(d) to the extent required by Apple’s terms, Apple and its subsidiaries are third-party beneficiaries and may enforce the applicable mobile-app terms; and

(e) the user represents that they are not prohibited from receiving or using the application under applicable trade-sanctions or restricted-party laws.

27.3 Store purchases

Where an App Store controls payment, cancellation or refunds, the Customer must use the processes provided by that App Store, without limiting Non-Excludable Rights.

28. General

28.1 Notices

A notice under the agreement must be in writing. Notices to Vorda must be sent to contact@vorda.com.au. Vorda may send notices to the account owner’s registered email address or through a prominent in-Platform notice. A notice by email is taken received on the next Business Day after sending unless the sender receives an automated delivery-failure notice.

28.2 Assignment

The Customer may not assign the agreement without Vorda’s prior written consent, which must not be unreasonably withheld. Vorda may assign the agreement to a related body corporate or in connection with a merger, reorganisation, financing or sale of all or substantially all of the relevant business or assets, provided the assignee assumes Vorda’s obligations.

28.3 Subcontractors

Vorda may use subcontractors to perform the agreement. Vorda remains responsible for their performance to the extent required by the agreement and Schedule 1.

28.4 Relationship

The parties are independent contractors. The agreement does not create a partnership, employment, agency, fiduciary or franchise relationship.

28.5 Third-party rights

Except for the persons expressly protected by clauses 17, 23 and 27, no person who is not a party has a right to enforce the agreement.

28.6 Severability

If a provision is invalid or unenforceable, it will be read down to the minimum extent necessary, and if it cannot be read down it will be severed without affecting the remainder.

28.7 Waiver

A waiver must be in writing and applies only to the specific instance. Delay or failure to exercise a right is not a waiver.

28.8 Entire agreement

The agreement is the entire agreement about its subject matter and replaces prior representations and agreements, but does not exclude liability for fraud or misleading or deceptive conduct that cannot lawfully be excluded.

28.9 Electronic agreement

The agreement may be accepted electronically and in counterparts. Electronic records and signatures may be used to evidence acceptance.

28.10 Governing law

The agreement is governed by the laws of South Australia and the Commonwealth of Australia. Subject to clause 25, the parties submit to the non-exclusive jurisdiction of the courts of South Australia and courts entitled to hear appeals from them.

28.11 Interpretation

Headings are for convenience only. “Including” means “including without limitation”. A reference to legislation includes amendments and replacements. If an obligation is due on a non-Business Day, it is due on the next Business Day.

29. Contact

Vorda Pty Ltd ABN 52 698 153 623 Unit 8, 20 Macmillan Avenue Mawson Lakes SA 5095 Australia Email: info@vorda.com.au Website: www.vorda.com.au

SCHEDULE 1 — DATA PROCESSING ADDENDUM

1. Purpose and scope

1.1 Application

This Data Processing Addendum (DPA) applies where Vorda processes personal information contained in Customer Data to provide the Platform.

1.2 Relationship to privacy law

Australian privacy law does not always use the terms “controller” and “processor”. For clarity, the Customer determines the purposes for which Customer Data is collected and used in its operations, and Vorda processes Customer Data to provide the Platform and follow the Customer’s lawful instructions. Each party must comply with the privacy obligations directly applicable to it.

1.3 Processing details

The subject matter, nature and purpose of processing are the hosting, storage, retrieval, transmission, organisation, analysis, generation, support, security, backup, deletion and other processing necessary to provide the Platform. Processing continues for the Subscription Term and the deletion period in clause 19.

The types of personal information may include identity and contact information, NDIS numbers, health and disability information, service records, incident and behaviour-support information, worker credentials and screening information, employment information, location check-in information, photographs, audio, correspondence, billing records and other information submitted by the Customer.

Individuals may include participants, nominees, guardians, supported decision-makers, family members, workers, contractors, Customer personnel and other contacts.

2. Customer instructions and responsibilities

2.1 Documented instructions

Vorda will process personal information in Customer Data only:

(a) to provide, secure and support the Platform;

(b) as documented in the agreement, the Customer’s configuration and use of the Platform, and other lawful written instructions accepted by Vorda; or

(c) as required by Applicable Law.

2.2 Unlawful instructions

If Vorda reasonably believes an instruction breaches Applicable Law, it may suspend the affected processing and notify the Customer, unless prohibited by law. The parties will work in good faith to find a lawful alternative.

2.3 Customer responsibility

The Customer is responsible for:

(a) the lawfulness, fairness and transparency of its processing;

(b) providing required collection notices and privacy information;

(c) obtaining consent or another lawful authority where required;

(d) ensuring instructions are lawful and Customer Data is adequate, relevant and limited to what is reasonably necessary;

(e) responding to individuals and regulators, except for assistance Vorda must provide under this DPA; and

(f) determining retention periods and deletion instructions.

3. Vorda obligations

Vorda will:

(a) process Customer Data in accordance with clause 2.1;

(b) ensure personnel authorised to process Customer Data are subject to confidentiality obligations;

(c) implement and maintain the security measures described in Appendix A;

(d) provide reasonable assistance under clauses 7 and 8;

(e) notify the Customer of a Security Incident under clause 6;

(f) maintain appropriate records of its processing and security activities; and

(g) not sell Customer Data or disclose it to third parties for their own advertising or marketing.

4. Subprocessors

4.1 General authorisation

The Customer authorises Vorda to use subprocessors to provide hosting, infrastructure, authentication, communications, support, monitoring, analytics, payments, AI processing and other Platform functions.

4.2 Safeguards

Before a subprocessor processes personal information in Customer Data, Vorda will impose written data-protection and confidentiality obligations appropriate to the services and information involved.

4.3 Responsibility

Vorda remains responsible for a subprocessor’s performance of Vorda’s obligations under this DPA to the same extent as if Vorda performed them itself, subject to the liability provisions of the agreement.

4.4 Changes

Vorda will maintain a current list of material subprocessors on its website or make it available on request. Vorda will provide reasonable advance notice of a new material subprocessor where the change materially affects processing of Care Data. The Customer may raise a reasonable, documented privacy or security objection. The parties will work in good faith to resolve it. If no reasonable solution is available, the Customer may terminate the affected service and receive a pro-rata refund of prepaid Fees for the unused period.

5. Data location and overseas disclosures

5.1 Care Data

Vorda will comply with the Australian hosting commitment in clause 9.1 of the Terms.

5.2 Other information

Operational and account information may be processed in other countries as disclosed in the Privacy Policy. Where Vorda discloses personal information to an overseas recipient, Vorda will take the steps required of it under Applicable Law.

5.3 Customer-directed transfers

The Customer is responsible for transfers it initiates or authorises through integrations, exports, downloads, emails or sharing features.

6. Security Incidents

6.1 Notification

Vorda will notify the Customer without undue delay after becoming aware of a Security Incident affecting Customer Data.

6.2 Information

To the extent reasonably available, Vorda’s notice or follow-up information will describe:

(a) the nature of the Security Incident;

(b) the categories of information and individuals affected;

(c) likely consequences known to Vorda;

(d) containment and remediation measures taken or proposed; and

(e) a contact point for coordination.

Information may be provided progressively as the investigation continues.

6.3 Response

Vorda will take reasonable steps to contain, investigate and remediate the Security Incident and will reasonably cooperate with the Customer’s assessment and legally required notifications.

6.4 Responsibility for notifications

The Customer is responsible for determining whether it must notify individuals, the OAIC, the NDIS Quality and Safeguards Commission or another regulator, except where Vorda has a direct legal notification obligation. The parties will coordinate to avoid inconsistent or misleading notifications.

7. Individual rights and regulatory assistance

7.1 Requests received by Vorda

If Vorda receives a request from an individual concerning personal information controlled by the Customer, Vorda may direct the individual to the Customer unless Vorda is legally required to respond directly.

7.2 Assistance

Taking into account the nature of processing and information available to Vorda, Vorda will provide reasonable assistance to help the Customer respond to requests for access, correction, deletion or complaints and to conduct privacy-impact or breach assessments required by Applicable Law.

7.3 Additional work

Where assistance requires material custom work beyond standard Platform functionality and is not caused by Vorda’s breach, Vorda may charge reasonable fees agreed in advance.

8. Audits and information

8.1 Compliance information

On reasonable request, Vorda will provide information reasonably necessary to demonstrate compliance with this DPA, which may include relevant policies, summaries, certifications or independent assurance reports available to Vorda.

8.2 Audit

If the information under clause 8.1 is insufficient to address a substantiated material concern, the Customer may request an audit no more than once in any 12-month period, unless required by a regulator or following a Security Incident. An audit must:

(a) be conducted on reasonable notice during business hours;

(b) avoid disruption to Vorda and other customers;

(c) protect confidential and security-sensitive information;

(d) be conducted by an independent auditor bound by confidentiality; and

(e) be at the Customer’s cost unless the audit identifies Vorda’s material breach of this DPA.

The audit must not include access to another customer’s data, penetration testing or disclosure of information that would create a security risk.

9. Return and deletion

Vorda will make Customer Data available for export and delete or retain it in accordance with clause 19 of the Terms and the Privacy Policy. If Applicable Law requires Vorda to retain information, Vorda will protect it and process it only for the legally required purpose.

10. Government access requests

Where legally permitted, Vorda will notify the Customer of a compulsory request by a government authority for Customer Data. Vorda will assess the validity of the request and disclose only information it is legally required to disclose.

11. Precedence and liability

If this DPA conflicts with the Terms on the processing or protection of personal information, this DPA prevails. Liability arising under this DPA is subject to clause 22 of the Terms.

APPENDIX A — SECURITY MEASURES

Vorda will maintain a security program appropriate to the nature of the Platform, the sensitivity of Care Data and the risks of processing. Measures may evolve as technology and threats change, but will include controls addressing the following areas:

Access control: role-based and least-privilege access, individual accounts, privileged-access controls and periodic access review.

Authentication: secure authentication controls and multi-factor authentication for privileged or administrative access where appropriate.

Encryption: encryption of Customer Data in transit using industry-standard transport encryption and encryption at rest for production systems and backups.

Hosting and network security: logically segregated environments, network controls and secure configuration of cloud infrastructure.

Logging and monitoring: logging of relevant administrative and security events, monitoring for suspicious activity and protection of logs against unauthorised alteration.

Secure development: code review, dependency and vulnerability management, separation of development and production environments, and change-management practices appropriate to the risk of a change.

Vulnerability management: risk-based identification, assessment and remediation of material vulnerabilities, including security updates and testing.

Backups and resilience: regular backups, protected backup access and disaster-recovery and business-continuity procedures proportionate to the service.

Incident response: documented procedures for identifying, containing, investigating, remediating and communicating Security Incidents.

Personnel security: confidentiality obligations, security awareness and access limited to personnel with a legitimate business need.

Subprocessor management: reasonable due diligence and contractual security and confidentiality requirements for subprocessors handling Customer Data.

Data lifecycle: controls for retention, export, deletion and secure disposal in accordance with the agreement and applicable retention requirements.

Questions about these Terms?

Get in touch with Vorda

Contact us for questions about your subscription, these Terms, or the Data Processing Addendum.

Contact Vorda