Proofline

Data processing terms

Draft — not legal advice, not in force

This document was drafted to describe how the system actually works, so that a lawyer does not have to reverse-engineer it. It has not been reviewed by one, and it does not bind anybody.

Before it can be relied on:

  • Review and settlement by an Australian lawyer (DEVELOPMENT-PLAN.md V10).
  • A decision on DP1 — what legal shape this document should take at all.
  • Resolution of PR2 on the privacy policy: if region-pinned hosting with US-incorporated suppliers is a cross-border disclosure, the APP 8 position has to appear in these terms too.
  • Liability, indemnity, insurance and termination are absent entirely. They are commercial positions, not drafting gaps.

1. What this covers

These terms describe how Proofline handles information a provider puts into it: participant records, evidence documents, incident records, worker details, and the audit trail generated by using the service.

2. The provider stays responsible

The provider decides what goes in, who may see it, and what it is used for. Proofline holds it to deliver the service and for nothing else. Nothing in these terms moves a provider's obligations under the NDIS Act, the NDIS Practice Standards, or privacy law onto us — and nothing in the product does either.

Specifically: Proofline does not submit anything to the NDIS Commission or the NDIA. Where the product works out that a notification is due, that is a calculation offered to a person. Lodging it, and lodging it in time, remains the provider's obligation.

3. Where the data goes

Participant data is stored in Sydney and is not stored outside Australia. The current list of suppliers is on the privacy policy, and that list is the authoritative one — it is maintained as the system changes.

4. Security

5. People

Access to production data is limited to those who need it to operate the service. Support access to a provider's tenant is not routine and leaves an audit record like any other access.

6. Sub-contracting and breach

Suppliers are engaged only where they are needed to run the service, and are held to obligations no weaker than these. If a breach affecting a provider's data occurs, we will tell that provider without undue delay, with what is known, so they can meet their own obligations — which may include a reportable incident of their own.

7. Retention and return

A provider can export everything they hold at any time, as an audit pack, without asking us. That is deliberate: the ability to leave should not depend on our cooperation.

8. What is not in this document

Liability, indemnities, insurance, service levels, notice periods and termination rights are absent. That is not an oversight to be tidied up later: they are commercial positions, and inventing them here would create expectations nobody has agreed to.

Privacy policy · Pricing