Privacy Policy

Effective

05 May 2026

Updated

05 May 2026

1. Introduction

AuditDoc Pty Ltd (ABN 11 687 813 869) ("we", "us", "our", "AuditDoc") operates the AuditDoc platform, accessible at auditdoc.com.au and associated applications (the "Platform"). We are committed to protecting the privacy and security of personal information entrusted to us.
This Privacy Policy explains how we collect, hold, use, disclose and otherwise handle personal information in accordance with the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs), the Notifiable Data Breaches scheme, and our obligations under the NDIS Quality and Safeguards framework.
By creating an account, accessing or using the Platform, you acknowledge that you have read, understood and accept this Privacy Policy. If you do not accept it, you must not use the Platform.

2. Scope and Application

This Privacy Policy applies to all users of the Platform, including NDIS providers, auditors, registration consultants, team members, and any individual who accesses or interacts with the Platform or our website at auditdoc.com.au.
Data processor role: AuditDoc acts as a data processor on behalf of our clients (NDIS providers). Our clients are the data controllers responsible for the personal information of their NDIS participants, staff, and other individuals whose data they upload to the Platform. We process this data solely on our clients' instructions and in accordance with this Privacy Policy and our Terms and Conditions.
Where AuditDoc collects personal information directly from you (for example, when you sign up, contact us, or use our website), we act as the data controller for that information.

3. Information We Collect

3.1 Information you provide to us

Account information: name, email address, phone number, organisation name, ABN, role, and billing details (managed via Clerk).
Subscription and payment information: plan selection and payment method details (processed via Stripe — we do not store full credit card numbers on our systems).
Profile information: job title, professional qualifications, profile preferences.
Communications: messages, support requests, feedback, demo requests, and correspondence.
Marketing preferences: subscriptions to newsletters, blog updates, or product announcements.

3.2 Information uploaded by clients (Your Content)

Clients upload documents and data to the Platform as part of NDIS compliance and audit preparation. This may include:
Participant information: names, contact details, NDIS plan references, service agreements.
Staff and HR records: worker screening checks, training records, qualifications, contact details.
Compliance documents: policies, procedures, incident reports, risk assessments, audit evidence.
Health and sensitive information: where clients upload documents containing health-related data about NDIS participants.
We acknowledge that much of this data may constitute sensitive information under the Privacy Act, including health information. We treat all client-uploaded content with the highest level of care and apply technical, organisational and contractual safeguards to protect it.

3.3 Information collected automatically

Device and browser information: IP address, browser type, operating system, device identifiers.
Usage data: pages visited, features used, actions taken, timestamps (via Google Analytics GA4 and Vercel Analytics).
Error and performance data: application errors and metrics (via Sentry).
Cookies and similar technologies: see our Cookie Policy at auditdoc.com.au/cookies for full details.

3.4 Information from third parties

We may receive limited information about you from third parties such as referral partners, integration providers, or publicly available business sources (for example, ABN Lookup) to verify your identity or organisation.

4. How We Use Your Information

We collect and use personal information only for purposes reasonably necessary for, or directly related to, the operation of our business and the provision of the Platform:
Providing, maintaining, securing, and improving the Platform.
Authenticating users and managing access (via Clerk).
Processing subscriptions and payments (via Stripe).
Sending transactional communications such as invitations, account notifications, and service updates (via Resend).
Monitoring errors, performance and security (via Sentry).
Analysing usage to improve the Platform (via GA4 and Vercel Analytics).
Enabling AI-powered features (see Section 5).
Detecting, preventing and investigating misuse, fraud, or breaches of our Terms.
Responding to enquiries, support requests, and complaints.
Complying with legal obligations, including the Notifiable Data Breaches scheme, court orders, and regulatory requests.
With your consent, sending marketing communications about AuditDoc products, features, events, and educational NDIS content. You can opt out at any time using the unsubscribe link in any marketing email or by contacting us.
We do not use personal information for direct marketing without your express or reasonably implied consent, and we always provide a simple opt-out mechanism.

5. AI-Powered Features

The Platform may include AI-powered features such as document classification, auto-tagging, audit-evidence suggestions, and compliance scoring. Where used:
AI processing is performed solely to deliver the requested functionality.
Our document classification feature uses Anthropic's Claude models, accessed via Amazon Web Services (AWS) infrastructure in the Sydney (ap-southeast-2) region. This processing occurs within Australia and does not involve cross-border transfer of Your Content.
Document content submitted for AI classification is not retained by the AI provider beyond what is required to return a classification result.
Your Content is not used to train general-purpose or third-party AI models.
Outputs are generated for your use within your account only and are stored within your workspace.
AI outputs are automated suggestions only — they are not professional, legal, or compliance advice and must be reviewed by qualified personnel before being relied upon.
If we introduce additional AI features that involve a new third-party AI provider, or any AI processing involving cross-border data transfer, we will update this Privacy Policy and notify affected clients before that processing takes place.

6. How We Share Your Information

We do not sell, rent or trade personal information. We share information only in the limited circumstances described below.

6.1 Service providers (sub-processors)

We engage trusted third-party providers who are contractually required to protect your information and use it only for the purposes we instruct:
Vercel (vercel.com) — application hosting, Sydney (syd1) region.
Supabase (supabase.com) — database and file storage, AWS ap-southeast-2 (Sydney).
Clerk (clerk.com) — authentication and session management.
Stripe (stripe.com) — payment processing.
Resend (resend.com) — transactional email.
Google Analytics GA4 — usage analytics.
Vercel Analytics — page-level analytics.
Sentry (sentry.io) — error monitoring.
Anthropic (anthropic.com) — AI-powered document classification, accessed via AWS ap-southeast-2 (Sydney).
A current list of sub-processors is maintained at auditdoc.com.au/subprocessors. We will provide reasonable advance notice of new sub-processors where they will materially affect the processing of personal information.

6.2 Auditor access

Where a client grants auditor access via the Platform, the relevant auditor may view workspace content shared with them. This access is controlled by the client. AuditDoc is not party to the audit engagement between client and auditor and does not endorse, verify or assume responsibility for the auditor's conduct, decisions or fees.

6.3 Referral and integration partners

Where you engage with a referral partner, registration consultant, document provider, or integration partner connected to AuditDoc (whether listed on our website or otherwise), we may share limited information necessary to facilitate that engagement. AuditDoc is not responsible for the privacy practices of such third parties — their handling of your information is governed by their own privacy policies. You should review those policies before engaging with them.

6.4 Legal and regulatory disclosures

In response to a lawful court order, subpoena, search warrant, or regulatory request.
To comply with our obligations under the Notifiable Data Breaches scheme.
To protect the rights, property, or safety of AuditDoc, our users, or the public.
To enforce our Terms and Conditions or investigate suspected breaches.
  • We may disclose personal information where required or permitted by law, including:

6.5 Business transfers

In the event of a merger, acquisition, restructure, or sale of all or substantially all of our assets, personal information may be transferred to the acquiring entity, subject to the same protections as set out in this Privacy Policy. We will notify affected users in advance where reasonably practicable.

7. Cross-Border Data Transfers

All primary client data (including Your Content) is stored in Australia (Sydney, AWS ap-southeast-2) via Supabase, with our application hosted on Vercel (Sydney syd1).
Some of our sub-processors may, in the course of providing their services, store or process limited operational data (such as authentication tokens, error logs, or email metadata) outside Australia, including in the United States. Where this occurs:
We assess the privacy practices of the relevant provider before engagement.
We rely on contractual safeguards consistent with Australian Privacy Principle 8 (cross-border disclosure).
We require providers to apply security and confidentiality standards substantially similar to those required under Australian privacy law.
By using the Platform, you acknowledge and consent to such limited cross-border processing for these operational purposes.

8. Data Storage and Security

We take the security of personal information seriously and apply reasonable technical and organisational measures to protect it from misuse, interference, loss, unauthorised access, modification or disclosure. These measures include:
Encryption in transit: TLS 1.2/1.3 across all traffic.
Encryption at rest: AES-256 for database and file storage.
Authentication: managed by Clerk with encrypted JWT tokens. We do not store passwords on our systems.
Role-based access controls and least-privilege principles for AuditDoc personnel.
Sentry configured to minimise the inclusion of personal data in error reports (PII scrubbing).
Regular review of security configurations, dependencies, and sub-processor practices.
No method of internet transmission or electronic storage is 100% secure. While we apply industry-accepted safeguards, we cannot guarantee absolute security. You are responsible for maintaining the confidentiality of your account credentials and for promptly notifying us of any unauthorised access.

9. Data Retention and Backups

Account data: retained while the account is active and for 90 days post-cancellation, after which it is permanently deleted (subject to legal retention obligations).
Your Content: retained while subscribed. Exportable during the 90-day post-cancellation window via your account settings or by contacting us.
Backups: Supabase Pro 7-day rolling backups, plus nightly AWS backups with up to 1-year retention for disaster recovery purposes only.
Payment records: retained for the period required by Australian taxation and corporations law (generally 5–7 years).
Analytics: de-identified aggregated data may be retained indefinitely. Individual logs are deleted after 12 months.
Communications: support and enquiry correspondence retained for up to 5 years for service quality and legal purposes.

10. Marketing Communications

With your consent, we may send you marketing communications about AuditDoc products, features, NDIS regulatory updates, events, and educational content. Every marketing email contains a clear unsubscribe link. You can also opt out at any time by contacting contact@auditdoc.com.au.
Opting out of marketing will not affect transactional or account-related communications, which are necessary for us to provide the Platform.

11. Your Rights

Access: you can request access to the personal information we hold about you. We will respond within 30 days of receiving a verifiable request.
Correction: you can request correction of inaccurate, out-of-date, incomplete, irrelevant or misleading information, or update most details directly via your account settings.
Deletion: you can request deletion of your personal information, subject to legal and contractual retention obligations. Initiate via your account settings or by contacting us.
Data export: you can request an export of your information in a commonly used, machine-readable format.
Withdraw consent: where we rely on your consent, you can withdraw it at any time. Withdrawal does not affect the lawfulness of processing prior to withdrawal.
Anonymity and pseudonymity: where lawful and practicable, you may interact with us anonymously or under a pseudonym (note this is generally not practicable for paid Platform use).
To exercise any of these rights, contact us using the details in Section 16. We may need to verify your identity before acting on a request. We will not charge a fee for reasonable requests.

12. Cookies

We use cookies and similar technologies to operate the Platform, remember your preferences, analyse usage, and improve our services. Full details, including a list of specific cookies and their purposes, are set out in our Cookie Policy at auditdoc.com.au/cookies.
We do not use advertising or behavioural-tracking cookies.

13. Third-Party Links

The Platform and our website may contain links to third-party websites, services or resources (including sub-processors, partners, and educational resources). We are not responsible for the privacy practices, content, or availability of those third parties. You should review their privacy policies before providing any personal information.

14. Children's Privacy

The Platform is not directed at, or intended for use by, individuals under the age of 18. We do not knowingly collect personal information directly from children. Where NDIS participants who are minors are supported via our Platform, the relevant NDIS provider (our client, as data controller) is responsible for obtaining all required consents from parents, guardians, or legally authorised representatives in accordance with the Privacy Act and the NDIS Code of Conduct.

15. Notifiable Data Breaches

We comply with the Notifiable Data Breaches (NDB) scheme under Part IIIC of the Privacy Act 1988 (Cth). If we become aware of an eligible data breach — that is, unauthorised access to, disclosure of, or loss of personal information likely to result in serious harm — we will:
Promptly assess and contain the breach.
Notify the Office of the Australian Information Commissioner (OAIC) and affected individuals as soon as practicable, in accordance with the NDB scheme.
Where we are acting as a data processor, notify the relevant data controller (our client) without undue delay so they can meet their own notification obligations.
Clients remain responsible for assessing breaches involving Your Content where they are the data controller.

16. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes to our practices, sub-processors, or legal obligations. Material changes will be notified at least 14 days in advance via email or in-app notice. The "Last updated" date at the top of this document indicates when it was last revised. An archive of previous versions is available on request.
Continued use of the Platform after the effective date of an updated Privacy Policy constitutes acceptance of the updated terms.

17. Complaints

If you have a complaint about how we have handled your personal information, please contact us first using the details in Section 18. We will acknowledge your complaint within 7 days and aim to resolve it within 30 days.
If you are not satisfied with our response, you can lodge a complaint with the Office of the Australian Information Commissioner (OAIC):
Website: oaic.gov.au
Phone: 1300 363 992
Email: enquiries@oaic.gov.au

18. Contact Us

AuditDoc Pty Ltd
ABN: 11 687 813 869
PO Box 242, St Marys NSW 2760
Email: contact@auditdoc.com.au
We respond to privacy enquiries within 14 days.