Privacy policy
Version 1.2 (draft) · Last updated 12 August 2026
Draft — pending legal review
This privacy policy is a working draft prepared for review and has not yet been approved or adopted. It does not represent an accepted legal position of EnableCare360 or any provider organisation until this notice is removed.
What this says, in short
- EnableCare360 is an app your disability support provider uses to help look after you.
- We keep information about you, like your name, your NDIS number, and notes about your care and what helps you.
- We keep this information safe. Only your support workers and your provider can see it.
- The app has helpers powered by artificial intelligence (AI). To do their job, some of your information is sent to trusted companies overseas, including in the United States. Your voice recordings are the exception — they are sent to a speech-to-text company that processes them in Australia.
- The AI helpers only give suggestions. A real person always makes the decisions about your care.
- We do not sell your information. There are no ads and no tracking in the app.
- You can ask to see your information, fix it, or have it deleted. Just ask your provider, or email info@enablecare360.com.au.
Who we are
EnableCare360 is care-management software operated on behalf of registered National Disability Insurance Scheme (NDIS) support providers. Your provider is the organisation that gave you access to the app. Your provider decides how your information is used to deliver your supports and is responsible for your care records. EnableCare360 provides and maintains the software that stores and processes that information on your provider's behalf.
This policy explains what personal and sensitive information the app collects, how it is held, who it may be shared with (including overseas), and how you can access, correct or delete it. It applies to everyone who uses the app — NDIS participants and provider staff (support workers, coordinators and administrators).
If you have a question about your privacy, contact your provider organisation first, or email us at info@enablecare360.com.au.
Information we collect
The information held depends on whether you are a participant or a member of staff. The app collects and stores the following categories, which include sensitive information (health and disability information) as defined by the Privacy Act 1988:
- Participant identity and NDIS identifier — your first and last name, preferred name, email address, suburb and state, and your NDIS number. Your NDIS number, on its own, indicates that you are a participant in a disability-support scheme, so we treat it as sensitive information.
- Health and disability information — your communication preferences and style, your support ratio, your goals, care tags, and behavioural-support records describing "what helps" and "what harms" you.
- Care and support notes — free-text notes written by your support workers, including shift notes, handovers, daily check-ins and checklist responses. These can describe medication, behaviour and mental state.
- Crisis conversations and escalations — messages exchanged in the Crisis Assistant, triage categories, escalation actions (for example calling a support line or emergency services), and "Eight Minutes" co-regulation session outcomes. These may include mental-health and self-harm disclosures.
- Voice recordings and transcripts — audio you or a worker records for a voice note or during a crisis, and the text transcript produced from it.
- Behaviour and incident records — incident and behaviour details recorded on timesheets, along with hours, travel and odometer readings.
- Uploaded documents and photos — care plans, medical documents and other files, profile photos, and staff accreditations or clearances.
- Staff identity and credentials — for provider staff: name, email, phone number, role, and securely hashed passwords and one-time login codes.
- Sign-in and device information — a coarsened sign-in IP address (the precise address is not kept), sign-in times and sign-in count, recorded for security.
- Participant sign-in count — for participants, we record how many times you've signed in and when you first signed in — not IP addresses, device details or a record of individual sign-in events — so we can tell whether an account has been used.
- Scheduling and availability — shifts, rosters, availability windows and blockout reasons (which may reveal a staff member's health, for example a medical appointment).
- Messages and notifications — broadcasts and in-app notifications, which may reference a participant.
- Audit trail — an append-only history of changes made to key records (including the sensitive records above), recording who changed it, when, and a coarsened IP address it was changed from. The detail of what changed is kept for a limited retention period and then removed, after which the entry still shows that a change happened and who made it.
How we collect and hold your information
We collect information directly from you and from provider staff as they deliver and record your supports — when accounts are set up, when notes and records are entered, when voice notes are recorded, and when you use the app's features. Accounts are created by your provider; the app has no public sign-up.
The application and its main database run on Fly.io infrastructure in Sydney, Australia. Uploaded files and audio are stored in Tigris object storage, which is configured to select a storage region automatically and is not guaranteed to keep your files in Australia.
We take reasonable steps to protect your information, including encrypted connections (HTTPS), hashed passwords and login codes, role-based access controls, and access to files only through authenticated, permission-checked requests.
How long we keep it — an honest note
We currently retain your information for as long as your provider uses the app. When a record is "deleted" in the app it is generally hidden from everyday view (soft-deleted) rather than permanently erased, so it can still be restored if that was done in error. The audit trail's who/what/when record of a change is kept, but the detail of what changed is automatically removed from older audit entries after a set retention period (this window is still being finalised). If you ask us to permanently erase your information, your provider's admin can run a real erasure: your identifying details, care notes, voice recordings and uploaded documents are permanently removed, including from the audit trail. Some structural incident information may be kept where the law requires it, but with your identifying details stripped out — see Requesting account and data deletion below for what that covers.
Why we use your information
- To deliver, coordinate and record your NDIS supports and care.
- To help support workers respond to crises and keep you safe.
- To roster staff, manage shifts and record time and incidents.
- To communicate with you, including one-time login codes and notifications.
- To keep the app secure and to detect and investigate misuse.
- To meet your provider's record-keeping, quality and compliance obligations.
AI assistants
The app includes AI features: a Crisis Assistant that helps workers and participants respond to distress, automatic end-of-shift summaries, and speech-to-text transcription of voice notes. To provide these features, relevant personal and sensitive information — such as a participant's name, "what helps"/"what harms" records, care notes and crisis messages — is sent to the third-party AI providers listed below for processing. Voice audio is sent only to Deepgram, our speech-to-text provider, whose Australian-region service processes it onshore; it is never sent to any other AI provider.
AI outputs support human decisions; they do not replace them. Summaries and suggestions produced by AI are drafts and prompts for a qualified person to review. A support worker, coordinator or clinician always remains responsible for decisions about your care.
Who we share it with, and overseas disclosures
Inside the app, your information is available to the staff of your provider organisation who need it to deliver your supports. We do not sell your information and we do not disclose it for advertising.
To run the app's features we use the service providers below. Some are located overseas, which means your information — including health and sensitive information — is disclosed outside Australia, mainly to the United States. Voice audio is the exception: it is sent to Deepgram's Australian region, so it is processed onshore rather than crossing the border, and every request opts that clip out of Deepgram's Model Improvement Program. We want to be clear and honest: this onshore routing and per-request opt-out are technical settings, not a signed agreement — we do not currently have signed zero-retention or "no-training" agreements in place with any of our AI providers, and each provider keeps data according to its own policies.
| Provider | Location | What is shared and why |
|---|---|---|
| Anthropic (Claude) | United States | Powers the Crisis Assistant and shift summaries. Receives participant name and behavioural-support context, crisis conversation messages, and recent care notes and handovers. |
| Deepgram | Australia (api.au.deepgram.com) | Converts voice recordings to text (speech-to-text). Receives the raw audio, which is processed in Deepgram's Australian region, not overseas, with every request set to opt that clip out of Deepgram's Model Improvement Program. Operational metadata and billing for this processing are handled by Deepgram in the United States, per Deepgram's own documentation. |
| Resend | United States | Delivers our emails. Receives your email address, name, and one-time login codes, magic-link sign-in links and password-reset links. |
| Tigris / Fly.io | Region not guaranteed to be Australia | Stores uploaded files and audio recordings. The storage region is selected automatically and may be outside Australia. |
We may also disclose information where required or authorised by law, or to protect the life, health or safety of a person.
No advertising, analytics or tracking
The app contains no advertising, no analytics SDKs and no third-party tracking technologies. We do not build advertising profiles and we do not track you across other apps or websites.
Accessing and correcting your information
You have the right to ask for a copy of the personal information we hold about you, and to ask us to correct it if it is wrong or out of date. To make a request, contact your provider organisation, or email info@enablecare360.com.au. We will respond within 30 days. There is normally no charge to make a request.
Requesting account and data deletion
You can ask us to delete your account and the personal information associated with it. Here is how:
- Contact your provider organisation and ask them to delete your account, or
- Email info@enablecare360.com.au from the email address on your account, with the subject "Delete my account".
- Tell us your name and, if you are a participant, the provider organisation you are with, so we can find the right records.
We will acknowledge your request and action it within 30 days. Your provider's admin runs a real erasure in the app: your name, NDIS number, contact details, care notes, voice recordings and uploaded documents are permanently removed, together with every audit-trail entry that names you — this is irreversible. Some incident information (for example, a crisis event or its escalation) may be kept where NDIS record-keeping obligations require it, but with your identifying details stripped out first. We will tell you if anything must be kept in that de-identified form and why.
Complaints
If you think we have mishandled your personal information, please tell us first so we can put it right. Contact your provider organisation, or email info@enablecare360.com.au. We will investigate and respond within 30 days.
If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner (OAIC): oaic.gov.au, or by phone on 1300 363 992.
Data breaches
We are covered by the Notifiable Data Breaches scheme under the Privacy Act 1988. If a data breach is likely to result in serious harm to you and we cannot prevent that harm, we will notify you and the Office of the Australian Information Commissioner as soon as practicable, and explain what happened and what you can do in response.
Changes to this policy
We may update this policy from time to time. The version number and date at the top of this page show when it last changed. The current version always lives at this page.
EnableCare360 · info@enablecare360.com.au