1.Who this applies to

This policy applies to personal information we handle about: visitors to our website; customers and prospective customers of Provider Scale OS and our growth services; Authorised Users who access the Platform; and individuals whose information our customers upload to the Platform (such as participants and workers). "Personal information" means information about an identified or reasonably identifiable individual, and includes sensitive information such as health information.

2.Our role & your role

There are two different situations to understand:

You own your data. As between you and us, you retain ownership of all Customer Data you upload to or create in the Platform. We do not claim ownership of it. We handle it only as described in this policy and our Terms of Service, and we do not use it for our own commercial purposes beyond providing and improving the Platform and the services you request.

3.Information we collect

4.How we collect it

We collect personal information: directly from you (when you register, use the Platform, contact us, or engage our services); automatically (through cookies, analytics and server logs when you use our website or Platform); from your Authorised Users; and occasionally from third parties such as referrers or publicly available sources. Customer Data is collected from you when you or your Authorised Users upload it.

Where it is reasonable and practicable, we collect personal information directly from the individual concerned. Where you provide us information about other people, we rely on you to have collected it lawfully and to have made those people aware of how it may be handled.

5.How we use it

We use personal information to:

We handle sensitive information (including health information) only where it is reasonably necessary to provide the Platform or services to you, with consent where required, or where otherwise permitted by law.

Artificial intelligence. We will not use your personal information or Customer Data to train, fine-tune or develop artificial intelligence or machine-learning models for use outside your own account without your consent. Where you choose to use an AI-assisted feature in the Platform, we process the relevant information only to provide that feature to you. We may use information that has been aggregated and de-identified (so that it does not identify you, any individual or any participant) to maintain and improve our services.

6.When we disclose it

We may disclose personal information to:

7.Supabase & cloud storage

Provider Scale OS is built on third-party cloud infrastructure. We use Supabase (which provides database, authentication and storage services) together with related hosting, email and security providers to store and process data. These providers maintain their own security and privacy programs and are engaged under terms requiring them to protect the data they process for us.

Depending on the configuration of these services, data may be stored and processed in Australia and/or in other countries where our infrastructure providers operate. See clause 9 for how we handle overseas disclosure.

8.Our access for support & services

Our personnel may access Customer Data and account information where reasonably necessary to provide technical support, troubleshooting, maintenance, security, data migrations, onboarding and training, and to deliver consulting, growth, marketing, automation or other services you request. If you engage us for growth or consulting services, you authorise us to access the data reasonably required to deliver them.

How we control staff access. Access to Customer Data is restricted to authorised personnel and contractors who need it for one of the purposes above. We apply role-based access controls so that staff can only reach the data relevant to their role, require individual login credentials and (where appropriate) multi-factor authentication, and bind our personnel and contractors to confidentiality obligations. Access is used only for the relevant purpose, may be logged, and is removed when a person no longer needs it or leaves. We do not browse, use or disclose your Customer Data for any purpose other than those described in this policy and our Terms of Service.

9.Overseas disclosure

Some of our Sub-processors may store or process data on servers located outside Australia. Where we disclose personal information to an overseas recipient, we take reasonable steps to ensure it is handled consistently with the APPs, including by using reputable providers that offer appropriate contractual and security protections. By using the Platform, you acknowledge that your information (and Customer Data you upload) may be stored or processed overseas. If you require your data to be kept within Australia, contact us before uploading sensitive information so we can discuss available options.

10.How we protect it

We take reasonable technical and organisational steps to protect personal information from misuse, interference, loss, and unauthorised access, modification or disclosure. These include access controls, authentication, encryption in transit, role-based permissions, and use of reputable infrastructure providers.

No system can be guaranteed to be completely secure, and we cannot promise that the Platform will be free from every security risk. You also play an important role in security: keep your credentials confidential, manage your Authorised Users' access, and use secure devices.

11.How long we keep it

We keep personal information for as long as needed to provide the Platform and services, and to meet our legal, accounting and record-keeping obligations. We retain Customer Data while your account is active. After your account closes, we may keep it for a limited period to allow export and recovery, after which we take reasonable steps to delete or de-identify it, except where we are required to retain it by law. Backups are kept for a limited period for resilience.

12.Marketing & communications

We may send you service messages (such as security, billing and account notices) that are necessary for your use of the Platform. We may also send marketing communications about our products and services where the law allows. Every marketing message includes a way to unsubscribe, and you can opt out at any time by using that link or contacting us. We handle marketing in accordance with the Spam Act 2003 (Cth). Opting out of marketing does not stop essential service messages.

13.Cookies & analytics

Our website and Platform use cookies and similar technologies to keep you signed in, remember preferences, measure performance and improve our services. We may use analytics and advertising tools, which may include Google and Meta (Facebook) products, to understand website usage and the effectiveness of our marketing. These tools may set their own cookies and collect information subject to their own privacy policies. You can control cookies through your browser settings, though some features may not work properly if cookies are disabled.

14.Sensitive & participant information

Because Provider Scale OS is used by NDIS providers, Customer Data often includes sensitive information, including the health information of participants, and information about workers. When you upload this information, you confirm that you are authorised to do so and that you have met your own privacy obligations to those individuals. We process it on your behalf to provide the Platform and the services you request. If an individual asks us about information that a provider has uploaded, we will generally refer them to that provider, who is responsible for that information.

15.Accessing & correcting your information

You can access and update much of your account information directly in the Platform. You may also ask us to give you access to the personal information we hold about you, or to correct it if it is inaccurate, out of date, incomplete or misleading. We will respond within a reasonable time. In limited circumstances we may decline a request (for example where the law allows us to), and if so we will explain why. We may need to verify your identity first. There is generally no charge to make a request, though a reasonable cost may apply for substantial access requests.

If your request relates to information that an NDIS provider uploaded about you, please contact that provider, as they are responsible for that Customer Data.

16.Data breaches

We maintain procedures to detect and respond to data breaches. If a breach involving personal information is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) as required by the Notifiable Data Breaches scheme, and we will cooperate reasonably with affected customers.

17.Changes to this policy

We may update this policy from time to time to reflect changes in our practices or the law. The current version is always published on our website with the "last updated" date shown above. Where changes are material, we will take reasonable steps to notify you.

18.Complaints & contact

If you have a question, request or complaint about how we handle personal information, please contact us first so we can try to resolve it:

Privacy Officer, Enrichment Care Pty Ltd (trading as Provider Scale)
Level 1, 457-459 Elizabeth Street, Surry Hills NSW 2010
Email: admin@providerscale.com.au
Phone: 0470 627 565

We will acknowledge your complaint and respond within a reasonable time. If you are not satisfied with our response, you can contact the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au or on 1300 363 992.

↑ Back to top