Privacy Policy

Last updated: 9 September 2026

Referral and affiliate programme

Partner applications collect verified contact details, tax declarations, promotional channels and agreement acceptance. PayPal verifies payout details and delivers earnings. First-party referral cookies are optional and expire after 90 days; partners receive anonymous conversion references and campaign totals. Marketing consent is separate from account and payout notices.

Read the referral collection and tracking notice for the information shared with service providers, retention periods and your choices.

1. Introduction

CordoCare (operated by Equila Pty Ltd) (“CordoCare”, “we”, “us”, “our”) is committed to protecting the privacy of our users and the personal information of NDIS participants managed through our platform. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our practice management software or purchase from our digital document store.

We comply with the Australian Privacy Principles (APPs) contained in the Privacy Act 1988 (Cth) and relevant NDIS data protection requirements.

2. Information We Collect

We collect information that you voluntarily provide when using our platform, including:

  • Account information (name, email, organisation details)
  • Participant information entered by authorised users (names, NDIS numbers, contact details, plan information)
  • Case notes, invoices, service agreements, and other documents
  • Usage data and analytics
  • Payment and billing information (processed securely via Stripe)
  • Document-store order information, including buyer name, email, purchased products, consent choice, payment status and secure fulfilment records
  • Organisation identity, logo and colour choices supplied for optional document personalisation

3. How We Use Your Information

We use collected information to:

  • Provide and maintain our practice management platform
  • Process invoices and manage subscription billing
  • Process document pack orders, provide secure access and publish product updates
  • Complete requested branding and organisation setup
  • Generate AI-assisted reports and case notes at your direction
  • Send transactional communications (e.g., invoice notifications, appointment reminders)
  • Improve our services and develop new features
  • Comply with legal obligations

4. Data Security

We implement industry-standard security measures including:

  • Encryption of data in transit (TLS 1.3) and at rest (AES-256)
  • Managed cloud infrastructure with encryption and backups
  • Role-based access controls and tenant isolation
  • Regular security audits and penetration testing
  • Automated backups and disaster recovery procedures

5. Data Sharing

We do not sell personal information. We may share data with:

  • Third-party service providers who assist in operating our platform (hosting, payment processing, email delivery)
  • AI service providers when you use AI features, as described under AI processing below
  • Law enforcement or government agencies when required by law

AI processing

OpenAI processing is active for all CordoCare accounts. The production migration was confirmed live on 9 September 2026 at 3:26:07 pm Adelaide time (ACST, UTC+9:30). Built-in AI requests use the OpenAI API, not the consumer ChatGPT service, with no fallback to a previous AI provider.

This covers mAI, document extraction, drafting, case notes, reports, plan processing and audio transcription. Future built-in AI features, including any AI-assisted forecasting, must follow these same data-handling controls before release. This does not mean that a future feature is already available.

AI requests can include your instructions and relevant workspace information, such as participant details, case notes and selected document content. Review the information you include and your participant consent records before using these features. Manual participant entry and CSV imports are available without an AI request.

CordoCare uses the OpenAI API for its built-in AI features. OpenAI does not use API inputs or outputs to train or improve its models unless the customer explicitly opts in. CordoCare does not opt in to sharing your workspace content for that purpose. Our dedicated CordoCare Production project is excluded from the organisation's optional sharing of feedback, evaluation and fine-tuning data, and API inputs and outputs. The no-training protection covers participant information, document content, prompts and generated responses submitted through these built-in features. Section 4.2 of the OpenAI Services Agreement sets out these restrictions. The provider is disclosed here so you can understand who processes your information; the underlying model may change.

No training does not mean no retention. OpenAI normally retains abuse-monitoring logs, which may include prompts and responses, for up to 30 days. It may retain them longer where required by law or reasonably necessary to protect its services or others from harm. Temporary prompt caches may also be retained for up to 24 hours. CordoCare disables optional response storage for its AI requests, but this does not remove provider safety logs or temporary caches. We do not claim Zero Data Retention approval. See OpenAI's API data controls and retention documentation.

CordoCare still stores your workspace records, saved AI drafts and relevant audit records to provide the service, subject to this policy and your organisation's retention requirements. Changing AI provider does not delete information previously submitted to another provider or change the terms that applied to those requests.

AI processing may take place outside Australia. Hosting the CordoCare application in Australia does not establish that every AI request, log or backup remains in Australia. We do not offer an Australian-only AI processing guarantee. If you connect your own AI account or another external tool, that service's own terms and data settings apply to information you share with it. Contact privacy@cordocare.com before submitting information that requires additional restrictions.

6. Public Website Analytics and Cookies

CordoCare automatically uses Google Analytics and may use Vercel Web Analytics and Vercel Speed Insights on public marketing pages to understand which guidance and product journeys are useful, measure trial and contact intent, and monitor website performance. These tools do not operate on private application routes.

For public website analytics, we may collect the public page path without query parameters, broad campaign source information, browser and device information, interaction events such as a trial or contact action, and website performance measurements. We do not send contact-form entries, names, email addresses, phone numbers, participant information, workspace records or private application page addresses to these analytics tools.

Secure document-store pages that may contain an order token, download grant, Stripe session reference or buyer information do not load public website analytics. These pages are also configured not to be indexed by search engines.

CordoCare does not use this website analytics data for advertising or to build advertising audiences. You can block third-party analytics scripts through your browser's privacy or content-blocking settings without affecting your ability to use the public website or the CordoCare application.

Google and Vercel may process analytics information using infrastructure outside Australia, including in the United States, under their applicable data-protection terms. CordoCare configures Google Analytics event-level retention for no longer than 14 months and keeps advertising storage, Google signals and personalisation disabled.

7. Google Calendar Data

If you choose to connect Google Calendar, CordoCare requests access only to the calendar permissions needed to provide calendar synchronisation. This allows CordoCare to use a calendar you select, create and update CordoCare events in that calendar, import events you place there as private CordoCare internal events, sync later edits and removals, remove events created through CordoCare, and check availability to help prevent scheduling conflicts. Events from unrelated calendars are used only to calculate busy times and are not imported into CordoCare. CordoCare does not use Google Calendar data for advertising, profiling, or training AI models.

Google authorisation tokens are encrypted and stored securely so the connection can operate until you disconnect it. Calendar data is processed only to provide the features you request and is not sold or shared with advertisers. Limited information may be processed by our contracted infrastructure providers solely to operate and secure CordoCare, subject to confidentiality and data-protection obligations.

You can disconnect Google Calendar from CordoCare at any time. You can also revoke CordoCare's access from your Google Account. Disconnecting stops future synchronisation and deletes the stored Google authorisation tokens. You may request deletion of associated CordoCare account data using the process in section 9 below.

CordoCare's use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements.

8. Our Commitment to Your Data Privacy

Workspace access follows organisation membership, role and participant assignment rules. Membership of another business does not grant access to your workspace. An organisation owner or administrator can approve a named support operator for a limited period in Settings > Security, choose read-only or read/write access and confirm their express consent using a code sent to their account email. Access remains blocked until confirmation and can be revoked at any time. Organisation owners and administrators receive an in-app alert and an email notification when consent is confirmed and when support first enters under that approval. Approved in-app support requests are recorded in the organisation audit log.

This approval controls in-app support sessions. It does not remove the privileged access required to administer hosting, databases and backups. The application audit log is not a complete record of infrastructure access. Contact privacy@cordocare.com for information about authorised personnel and infrastructure access records.

We do not claim current ISO 27001 or ISO 27701 certification. If you need specific assurance evidence or have questions about our data handling, contact privacy@cordocare.com.

9. Document Store Fulfilment, Personalisation and Consent

Stripe processes payment-card details. CordoCare receives the identifiers and status needed to reconcile the transaction but does not store full payment-card details. We use one-way hashed access tokens for secure order-library links and record downloads needed to protect entitlements and investigate access issues.

Branding files and organisation information are stored privately and used only to provide the requested personalisation, corrections and eligible rebuilds during the update period. Do not upload participant, worker or unrelated sensitive information for branding.

Marketing consent is optional, unticked by default and recorded separately from the purchase. Declining marketing does not affect checkout, receipt, fulfilment, security or service messages. We send document-store promotional email only after a buyer separately opts in and we record that choice. Every promotional email includes a clear unsubscribe method, and a buyer can withdraw consent at any time by using that method or contacting privacy@cordocare.com.

10. Data Retention

We retain your data for as long as your account is active or as needed to provide services. After your subscription ends (cancellation, expiry, or non-payment), your organisation's data stays in place. We do not run an automated purge on a fixed timetable, and we do not send automated deletion reminder emails. You can resubscribe at any time and your workspace will be exactly as you left it.

You can ask us to delete your organisation's data at any time by emailing keanu@cordocare.com from an email address on the account. We confirm the request in writing before acting on it. Once actioned, the organisation record and everything linked to it, including participant records, case notes, documents, invoices, AI chat history, audit logs and user accounts, is removed from our live systems. This deletion is irreversible. Encrypted backups taken before the deletion date roll off on our hosting provider's normal backup cycle rather than being individually erased.

Please note that NDIS providers have their own record-keeping obligations. Export the records you are required to keep before you close your account or request deletion.

For document-store purchases, our retention approach is:

  • Secure library access, hashed access-token records and operational download logs are retained for the 12-month access period. Access-token and download-log records are then deleted or de-identified within 90 days unless an active security investigation, dispute or legal obligation requires longer retention.
  • Branding uploads and personalisation working files are retained only while we provide personalisation, corrections and eligible rebuilds during the 12-month update period, then deleted within 30 days unless you request earlier deletion or we must preserve a specific file for a dispute or legal requirement.
  • Order, payment reconciliation and recorded marketing-consent evidence may be kept after access ends where reasonably required for Australian tax and accounting records, chargebacks, consumer claims, fraud prevention or other legal obligations. We delete or de-identify these records when those purposes no longer apply.

11. Your Rights

Under the Privacy Act, you have the right to:

  • Access your personal information
  • Request correction of inaccurate information
  • Request deletion of your information (subject to legal retention requirements)
  • Lodge a complaint with the Office of the Australian Information Commissioner (OAIC)

12. Contact Us

For privacy-related enquiries, contact our Privacy Officer:

Email: privacy@cordocare.com
CordoCare (operated by Equila Pty Ltd), Adelaide, South Australia