Legal
Privacy Policy
This policy explains how we collect, hold, use and disclose personal information under the Privacy Act 1988 (Cth) and the Australian Privacy Principles.
- Effective
- TODO-LEGAL: effective date
- Last updated
- TODO-LEGAL: last updated date
Draft. This document is awaiting Australian legal review and still contains placeholder details. It is published for review, not yet for reliance.
1. About this policy
CoveyOS is operated by TODO-LEGAL: registered entity name (ABN TODO-LEGAL: ABN/ACN) (“CoveyOS”, “we”, “us” or “our”).
Care providers using CoveyOS are generally responsible for deciding what participant, client and workforce information is entered into the platform. We process that information on their behalf, subject to our agreements and applicable law.
2. Information we collect
Depending on how CoveyOS is used, we may collect and hold:
- identity and contact information, including names, dates of birth, addresses, email addresses and telephone numbers;
- account, authentication, organisation, role and permission information;
- employment information, qualifications, credentials, right-to-work details and staff review records;
- participant and client information, including NDIS numbers, Medicare details, funding arrangements and support contacts;
- sensitive information, including health, disability, medical, medication, behavioural, incident, religious and support-plan information;
- accommodation, property, room and residency information;
- rosters, timesheets, attendance records, service notes, mileage and expenses;
- GPS location and location accuracy when location-enabled clock-in features are used;
- forms, signatures, uploaded documents, photographs and free-text notes;
- financial, invoicing, payroll and accounting information;
- communications with us, support requests and feedback;
- AI assistant prompts, responses, approved actions and relevant organisational context;
- device, browser, security, session and kiosk information, including hashed device or network identifiers; and
- marketing enquiries, including organisation and contact details.
We seek to collect only information reasonably necessary for providing and securing the platform.
3. How we collect information
We may collect personal information:
- directly from individuals;
- from an organisation using CoveyOS;
- from authorised workers, representatives, guardians or support persons;
- through forms, uploads, support enquiries and platform activity;
- from connected services such as Xero or Google Maps, when enabled;
- automatically through authentication cookies, device information and security logs; and
- where authorised or required by law.
If information is not provided, some platform functions may be unavailable.
4. Purposes of collection and use
We collect, hold and use information to:
- provide, administer and improve CoveyOS;
- manage accounts, permissions and organisation access;
- support care, accommodation, workforce and compliance workflows;
- process forms, incidents, credentials, rosters, timesheets and records;
- provide location-enabled attendance functions;
- operate integrations requested by an organisation;
- provide the Pip AI assistant and carry out user-approved actions;
- communicate about accounts, support, security and service changes;
- detect fraud, misuse and security incidents;
- meet legal, regulatory, insurance and record-keeping obligations; and
- establish, exercise or defend legal claims.
Sensitive information is processed only where consent or another lawful basis permits it.
5. Artificial intelligence
CoveyOS includes an AI assistant called Pip. Information submitted to Pip may be combined with relevant organisational information and sent through Vercel AI Gateway to TODO-LEGAL: current AI provider for processing.
Pip may generate inaccurate or incomplete information. Users must review its output. Actions that change organisational records require explicit user approval, and Pip does not independently make decisions that determine an individual’s access to care, employment, accommodation, funding or legal rights.
We do not permit AI providers to use customer personal information to train general-purpose models unless this has been expressly agreed and lawfully authorised.
AI processing may occur in TODO-LEGAL: AI processing countries/regions. Organisations should avoid submitting personal or sensitive information that is unnecessary for the requested task.
6. Disclosure
We may disclose information:
- to authorised users within the relevant organisation;
- to service providers supporting hosting, authentication, storage, email, maps, accounting, security and AI processing;
- to professional advisers, auditors, insurers and regulators;
- where an organisation directs or authorises us to do so;
- where necessary to prevent a serious threat to health or safety; or
- where required or authorised by law.
Current service providers may include Supabase, Vercel, Resend, Google Maps Platform, Xero and TODO-LEGAL: current AI provider.
We do not sell personal information.
7. Overseas disclosures
Some service providers may process or store information outside Australia. Likely recipient locations include TODO-LEGAL: verified overseas recipient countries.
Before using an overseas provider, we take reasonable steps to assess its privacy and security practices and apply contractual, technical and organisational safeguards as appropriate.
8. Security
We use safeguards designed to protect information from misuse, interference, loss and unauthorised access, modification or disclosure. These include access controls, organisation-level data separation, encryption, audit controls and restricted storage.
No online system is completely secure. Organisations and users must protect their credentials and promptly report suspected unauthorised access.
9. Retention and deletion
We retain personal information only for as long as reasonably necessary for the purposes described in this policy or as required by law, contractual obligations and applicable NDIS, employment, health, taxation and corporate record-keeping requirements.
Retention periods include TODO-LEGAL: approved retention schedule.
When information is no longer required, we take reasonable steps to delete it, destroy it or permanently de-identify it. Some information may remain in secure backups or audit records until the applicable retention period expires.
10. Cookies and local storage
CoveyOS uses authentication and kiosk cookies needed to provide and secure the service. It also uses browser storage for functions such as interface preferences and temporary AI chat history.
We do not currently use third-party advertising cookies. If this changes, we will update this policy and implement any required consent controls.
11. Access and correction
Individuals may request access to, or correction of, personal information held about them.
Where information was entered by a care provider or employer, the request should usually be made to that organisation first. Requests may also be sent to TODO-LEGAL: privacy email.
We may need to verify identity. Access may be refused where permitted by law, in which case we will generally provide written reasons and available complaint options.
12. Privacy complaints
Privacy concerns should be sent to:
Privacy Officer
TODO-LEGAL: registered entity name
Email: TODO-LEGAL: privacy email
Address: TODO-LEGAL: postal address
Telephone: TODO-LEGAL: telephone
We will acknowledge a complaint promptly, investigate it fairly and aim to respond within 30 days.
If the response is unsatisfactory, a complaint may be made to the Office of the Australian Information Commissioner.
13. Data breaches
We investigate suspected privacy and security incidents. Where an eligible data breach is likely to result in serious harm, we will notify affected individuals and the OAIC in accordance with the Notifiable Data Breaches scheme.
14. Changes to this policy
We may update this policy when our practices, service providers or legal obligations change. The current version will be published on our website with its effective date.