Privacy policy
Draft — not legal advice, not in force
This document was drafted to describe how the system actually works, so that a lawyer does not have to reverse-engineer it. It has not been reviewed by one, and it does not bind anybody.
Before it can be relied on:
- Review and settlement by an Australian privacy lawyer (DEVELOPMENT-PLAN.md V10).
- A decision on PR1 — whether Proofline is an APP entity at all — because the rest of the document is written as though it is.
- A decision on PR2 — whether region-pinned hosting with US-incorporated suppliers is a cross-border disclosure under APP 8.
- Confirmation of the sub-processor list at the point service actually begins; parts of the stack below are not deployed yet.
Proofline is compliance software for NDIS providers. Providers use it to hold evidence, record incidents and produce an audit pack. Almost everything in it is about someone else's participants, and that shapes every decision below.
Who this is between
The provider is the NDIS organisation using Proofline. The participants, workers and records in a provider's tenant belong to the provider and their obligations. Proofline holds that information to deliver the service and for no other purpose.
What is held
- Account information for the people who log in: name, work email, role, and their multi-factor enrolment.
- Participant records a provider enters or imports: name, NDIS number, plan dates, plan management, and whether the provider is recorded as their “my provider”.
- Documents a provider uploads as evidence. A provider chooses what these contain; policies and procedures are the intended use.
- Incident records, which by their nature may describe harm to an identified person, and which the NDIS Rules require be kept for seven years.
- An audit trail of every change: who, when, what changed. It is append-only and hash-chained, and cannot be edited or deleted — including by us.
Where it is held
Participant data is stored in Sydney, Australia and is not stored anywhere else. Database and object storage run in the ap-southeast-2 region. Application servers run in Australia. Content delivery uses Cloudflare, which never holds participant data at rest — Cloudflare's storage products have no Australian jurisdiction, so none of them is used for anything of the kind.
Who else processes it
| Supplier | Purpose | Status |
|---|---|---|
| Supabase | Database, authentication and file storage — Sydney region | In use |
| Fly.io | Application servers — Sydney region | In use |
| Cloudflare | Content delivery, and the bot check on the enquiry form. The bot check receives the IP address and browser characteristics of anyone who submits that form. It does not receive what they wrote. No participant data at rest. | In use |
| Amazon Web Services | Email notification, and document reading — Sydney region | Not yet in use |
What is deliberately not done
- No participant information is used to train any model, by us or by a supplier.
- Notification emails carry no participant information. They say something needs attention and link to the application. This is a design constraint, not a setting.
- Nothing is submitted to the NDIS Commission or the NDIA. There is no connection from this system to either.
- Nothing is sold, and nothing is shared for advertising.
How long it is kept
Incident records are kept for seven years, which the NDIS (Incident Management and Reportable Incidents) Rules 2018 require. The audit trail is permanent by construction. Other records are kept while a provider uses the service.
Access, correction and complaints
A participant's first point of contact is the provider who holds their record — the provider controls the data and can correct it directly. Where a request reaches us instead, we will refer it to that provider and assist them.
If something goes wrong
A data breach likely to result in serious harm is notifiable to affected individuals and to the Office of the Australian Information Commissioner under the Notifiable Data Breaches scheme. Providers would be told without delay so they can meet their own obligations, including any reportable-incident obligation of their own.