Privacy Policy

1. Introduction

Cognify Digital Pty Ltd (ABN: 53691933632) ("Cognify Digital", "we", "us", "our") is committed to protecting the privacy and security of personal information entrusted to us. This Privacy Statement explains how we collect, use, disclose, and manage personal information in connection with the Cognify Digital NDIS Provider Management Platform ("the Platform").

Cognify Digital operates as a Registered Training Organisation and software provider, delivering the Platform to NDIS registered providers and disability support organisations across Australia. We recognise that the personal information we handle includes sensitive data relating to NDIS participants, support workers, and organisational staff.

This Privacy Statement is designed to comply with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) contained in Schedule 1 of that Act. We are also committed to meeting the privacy requirements under the National Disability Insurance Scheme Act 2013 (Cth) (NDIS Act) and the NDIS Practice Standards.

 

2. Types of Personal Information We Collect

2.1 Information We Collect From Organisation Administrators and Staff

When organisations register to use the Platform and their staff use our services, we collect:

Identity and Contact Information:

  • Full name
  • Email address
  • Phone number
  • Position/title
  • Business address

Employment and Professional Information:

  • Employment status and role
  • Qualifications and certifications
  • NDIS Worker Screening Clearance number and expiry date
  • Police check details and expiry date
  • First aid certificate details
  • Working with Children Check details (where applicable)

Account Information:

  • Username and encrypted password
  • Login timestamps and session data
  • IP addresses and device information
  • User preferences and settings

2.2 Information We Collect About NDIS Participants

Organisations using the Platform may enter information about NDIS participants receiving support services. This includes:

Personal Details:

  • Full name
  • Date of birth
  • NDIS Number
  • Residential address and service locations
  • Gender
  • Cultural and linguistic background (optional)

Support Information:

  • NDIS Support Plan details and documents
  • Care plans and goals
  • Service agreements
  • Funding management type (self-managed, plan-managed, NDIA-managed)

Health and Disability Information (Sensitive Information):

  • Disability type and support needs
  • Health conditions and medical information
  • Medication details
  • Behavioural support requirements
  • Restrictive practices information (where applicable)

Emergency and Contact Information:

  • Emergency contact names and phone numbers
  • Family member/carer contact details
  • Nominee or guardian details

Service Delivery Records:

  • Shift records and attendance
  • Progress notes and observations
  • Incident reports
  • Photos and evidence of service delivery

2.3 Sensitive Information

We collect sensitive information only with consent and where it is reasonably necessary for our functions or activities. Sensitive information may include:

  • Health information about participants and workers
  • Disability information
  • Criminal history (Worker Screening Checks, Police Checks)
  • Biometric information (GPS location data for compliance verification)
  • Racial or ethnic origin (for cultural support planning)

2.4 Information We Collect Automatically

When you use the Platform, we automatically collect:

  • Device and browser information
  • IP address and geolocation data
  • Access logs and timestamps
  • Pages viewed and features used
  • Session duration and activity patterns

 

3. How We Collect Personal Information

3.1 Direct Collection

We collect personal information directly from:

  • Organisation administrators during registration and onboarding
  • Staff members when they create their profiles
  • Support Workers when they clock in/out and complete shift activities
  • Participants (or their representatives) through service delivery processes
  • Users who contact us for support or enquiries

3.2 Indirect Collection

We may receive personal information from:

  • Authorised representatives or nominees acting on behalf of participants
  • Other organisations when a user transfers between providers
  • Third-party integrations (Xero, MYOB) when authorised
  • Publicly available sources (where permitted)
  • Law enforcement or regulatory bodies when required by law

3.3 Collection Notices

At or before the time of collection, we will take reasonable steps to provide a collection notice that explains:

  • Our identity and contact details
  • The purposes of collection
  • How the information will be used and disclosed
  • Whether disclosure is required or authorised by law
  • How to access and correct the information

 

4. Purposes of Collection and Use

We collect and use personal information for the following purposes:

4.1 Platform Service Delivery

  • Creating and managing user accounts
  • Enabling access to Platform features
  • Processing time tracking and shift management
  • Generating billing and payroll exports
  • Providing technical support and training

4.2 Compliance and Regulatory Requirements

  • Verifying NDIS Worker Screening Clearances
  • Maintaining certification expiry tracking
  • Recording and reporting incidents to the NDIS Commission
  • Generating compliance reports and audit trails
  • Responding to regulatory enquiries and audits

4.3 Service Delivery to NDIS Participants

  • Managing participant profiles and care plans
  • Scheduling and coordinating support services
  • Recording service delivery and progress
  • Managing emergency contacts and safety information
  • Supporting quality and safeguarding activities

4.4 Communication

  • Sending service-related notifications
  • Communicating about Platform updates and changes
  • Responding to enquiries and support requests
  • Sending marketing communications (with consent)

4.5 Security and Fraud Prevention

  • Authenticating users and preventing unauthorised access
  • Detecting and investigating suspicious activity
  • Maintaining audit logs for security purposes
  • Responding to data breaches and incidents

4.6 Business Improvement

  • Analysing Platform usage and performance
  • Developing new features and improvements
  • Conducting research and reporting (de-identified data only)
  • Training and quality assurance activities

 

5. Disclosure of Personal Information

We may disclose personal information to:

5.1 Authorised Recipients Within Your Organisation

  • Staff members with appropriate role-based access
  • Managers and coordinators responsible for service delivery
  • Compliance officers for audit and reporting purposes
  • Finance staff for billing and payroll processing

5.2 Third-Party Service Providers

We engage third-party service providers to assist with our operations, including:

  • Cloud hosting and infrastructure providers
  • Payment processing services
  • Accounting software providers (Xero, MYOB) when you authorise integration
  • Email and communication services
  • Analytics and monitoring tools

These providers are bound by contractual obligations to protect personal information and use it only for the purposes we specify.

5.3 Regulatory Bodies and Law Enforcement

We may disclose personal information when:

  • Required or authorised by law
  • Requested by the NDIS Quality and Safeguards Commission
  • Responding to valid legal processes (subpoenas, court orders)
  • Reporting notifiable data breaches to the OAIC
  • Preventing or investigating fraud or criminal activity

5.4 Related to Business Transactions

In the event of a merger, acquisition, or sale of assets, personal information may be transferred as part of that transaction, subject to confidentiality obligations.

5.5 With Your Consent

We may disclose personal information for other purposes with your express consent.

 

6. Cross-Border Disclosure

Personal information is primarily stored and processed in Australia. However, we may use cloud services that store data overseas, including:

  • United States (for certain cloud infrastructure and analytics)
  • Singapore and other Asia-Pacific regions (for redundancy and performance)

Before disclosing personal information to an overseas recipient, we will:

  • Obtain your consent where required by APP 8
  • Ensure the overseas recipient is bound by equivalent privacy protections
  • Take reasonable steps to ensure the overseas recipient complies with the APPs

We do not disclose sensitive participant information to overseas recipients without explicit consent.

 

7. Data Security and Retention

7.1 Security Measures

We implement robust security measures to protect personal information, including:

Technical Security:

  • Encryption of data in transit (TLS 1.3) and at rest (AES-256)
  • Secure httpOnly session cookies for authentication
  • Role-based access control and principle of least privilege
  • Regular security assessments and penetration testing
  • Intrusion detection and monitoring systems

Organisational Security:

  • Staff training on privacy and security obligations
  • Background checks for staff with access to personal information
  • Confidentiality agreements with all staff and contractors
  • Documented security policies and procedures

Physical Security:

  • Secure access controls for physical facilities
  • Secure destruction of physical records

7.2 Data Retention

We retain personal information for as long as necessary to:

  • Provide the Platform services
  • Meet legal and regulatory obligations (including NDIS requirements)
  • Respond to complaints or legal claims
  • Maintain audit trails required for compliance

Specific Retention Periods:

  • Participant records: Retained for 7 years after last service or as required by NDIS
  • Staff records: Retained for 7 years after employment ends
  • Incident reports: Retained for 7 years minimum
  • Audit logs: Retained for 7 years
  • Financial records: Retained for 7 years per tax law requirements

When information is no longer required, we securely destroy or de-identify it.

7.3 Data Deletion Upon Request

When you request deletion of your data, we will:

  • Delete or anonymise your personal information within 30 days
  • Retain only information required by law (archived with restricted access)
  • Notify third parties who may hold your information on our behalf

 

8. Access and Correction

8.1 Your Right to Access

Under the Privacy Act, you have the right to request access to personal information we hold about you. To make an access request:

  1. Submit a written request to our Privacy Officer (details below)
  2. Provide sufficient identification information
  3. Specify the information you are seeking

We will respond to your request within 30 days.

8.2 Fees

We may charge a reasonable fee for processing access requests to cover:

  • Staff time required to locate and compile the information
  • Costs of copying or reproducing records

We will advise you of any applicable fees before processing your request.

8.3 Correction of Information

You may request correction of personal information that is inaccurate, outdated, incomplete, irrelevant, or misleading. We will:

  • Assess your request within 30 days
  • Make corrections where appropriate
  • Notify you of the outcome
  • Add a statement to the record if we decline to make a correction

8.4 Access Through Platform

Users can access and update certain personal information directly through the Platform:

  • Staff can view and edit their own profile information
  • Participants (or their representatives) can request access through their provider organisation
  • Administrators can manage organisational data within their tenant

9. Anonymity and Pseudonymity

Where it is lawful and practicable, individuals may deal with us anonymously or under a pseudonym. However, we may not be able to provide certain services without identifying information, such as:

  • Creating a user account
  • Processing NDIS claims
  • Verifying worker clearances

We will inform you if anonymity or pseudonymity is not possible for a particular transaction.

 

10. Notifiable Data Breaches

10.1 Our Commitment

Cognify Digital is committed to preventing data breaches and responding swiftly if they occur. We have robust systems and processes in place to protect personal information from misuse, interference, loss, and unauthorised access, modification, or disclosure.

10.2 Data Breach Response

If we suspect a data breach has occurred, we will:

  1. Contain the breach – Take immediate steps to limit the spread and impact
  2. Assess the breach – Conduct an assessment within 30 days to determine severity
  3. Notify affected parties – If the breach is eligible for notification under the NDB scheme:
  • Notify the Office of the Australian Information Commissioner (OAIC)
  • Notify affected individuals with recommendations for protective action
  1. Review and improve – Conduct a post-incident review to prevent future breaches

10.3 Notifiable Data Breach Scheme

Under the NDB scheme, we are required to notify individuals and the OAIC when:

  • There is unauthorised access to, or disclosure of, personal information
  • This is likely to result in serious harm to affected individuals
  • We cannot prevent the serious harm through remedial action

 

11. Direct Marketing

We may use your personal information for direct marketing purposes only when:

  • We have your consent to do so
  • The marketing relates to services similar to those you have previously requested
  • You have not opted out of receiving marketing communications

11.1 Opt-Out Rights

You can opt out of marketing communications at any time by:

  • Clicking the "unsubscribe" link in marketing emails
  • Contacting us at [email protected] 
  • Updating your communication preferences in your account settings

We will process opt-out requests within 5 business days.

 

12. Cookies and Tracking Technologies

12.1 Cookies We Use

We use cookies and similar technologies to:

  • Maintain your session and authenticate your login
  • Remember your preferences and settings
  • Analyse Platform usage and performance
  • Improve security and detect fraud

12.2 Types of Cookies

Cookie Type Purpose Duration
Essential Session management, authentication Session
Functional Preferences, settings Up to 12 months
Analytics Usage analysis, performance monitoring Up to 24 months
Security Fraud prevention, bot detection Session

 

12.3 Managing Cookies

You can manage cookie preferences through your browser settings. Note that disabling essential cookies may affect Platform functionality.

 

13. Artificial Intelligence (AI) Transparency

Cognify Digital may use AI-assisted features to enhance Platform capabilities, including:

  • AI-powered search and information retrieval (RAG with citations)
  • Note drafting assistance (optional feature)
  • Compliance form completion assistance
  • Risk signal detection for missing evidence or anomalies

13.1 AI Data Handling

When AI features are used:

  • Your data is processed securely and not used to train third-party AI models without consent
  • AI outputs are clearly identified and may be reviewed before finalisation
  • You can opt out of AI-assisted features in your organisation settings

13.2 Human Oversight

AI features are designed to assist, not replace, human decision-making. All AI-generated outputs should be reviewed by authorised staff before use.

 

14. Children's Privacy

The Cognify Digital Platform is not designed for use by children under 18 years of age. If we become aware that we have collected personal information from a child without parental consent, we will take steps to delete that information.

Where participants under 18 receive NDIS supports, information about them is managed by their parent, guardian, or authorised representative in accordance with this Privacy Statement.

 

15. Changes to This Privacy Statement

We may update this Privacy Statement from time to time to reflect:

  • Changes in our information handling practices
  • New features or services
  • Changes in legal or regulatory requirements
  • Industry best practices

When we make material changes, we will:

  • Publish the updated Privacy Statement on our website
  • Notify registered users by email
  • Update the "Last Updated" date at the top of this document

We encourage you to review this Privacy Statement periodically.

 

16. Complaints and Enquiries

16.1 Contacting Us

If you have questions, concerns, or complaints about our privacy practices, please contact our Privacy Officer:

Cognify Digital Pty Ltd

Attention: Privacy Officer

16.2 Complaints Process

We take privacy complaints seriously and will:

  1. Acknowledge your complaint within 5 business days
  2. Investigate and respond within 30 days
  3. Provide a written response explaining our findings and any remedial actions

16.3 External Review

If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC):

  • Website:oaic.gov.au
  • Phone: 1300 363 992
  • Post: GPO Box 5218, Sydney NSW 2001

 

17. Definitions

Term Definition
**APP** Australian Privacy Principle
**Collection** Gathering, acquiring, or obtaining personal information
**Consent** Express or implied agreement to the collection, use, or disclosure of personal information
**Data Breach** Unauthorised access to, disclosure of, or loss of personal information
**NDIS** National Disability Insurance Scheme
**NDB Scheme** Notifiable Data Breaches scheme under Part IIIC of the Privacy Act
**Personal Information** Information or an opinion about an identified individual, or an individual who is reasonably identifiable
**Sensitive Information** Personal information including health information, racial or ethnic origin, political opinions, religious beliefs, sexual orientation, criminal record, and biometric information
**Tenant** An organisation's isolated environment within the Cognify Digital Platform
**Use** Access, consultation, processing, or handling of personal information

 

 

18. Contact Information

Cognify Digital Pty Ltd

ABN: 53691933632

Registered Office:

Suite 17, 89-97 Jones Street, Ultimo, NSW 2007

Privacy Officer:

Email: [email protected] 

Phone: +61 468 167 862

Data Protection Enquiries:

Email: [email protected] 

This Privacy Statement is compliant with the Privacy Act 1988 (Cth) and the Australian Privacy Principles.