Privacy Policy
1. Introduction
Cognify Digital Pty Ltd (ABN: 53691933632) ("Cognify Digital", "we", "us", "our") is committed to protecting the privacy and security of personal information entrusted to us. This Privacy Statement explains how we collect, use, disclose, and manage personal information in connection with the Cognify Digital NDIS Provider Management Platform ("the Platform").
Cognify Digital operates as a Registered Training Organisation and software provider, delivering the Platform to NDIS registered providers and disability support organisations across Australia. We recognise that the personal information we handle includes sensitive data relating to NDIS participants, support workers, and organisational staff.
This Privacy Statement is designed to comply with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) contained in Schedule 1 of that Act. We are also committed to meeting the privacy requirements under the National Disability Insurance Scheme Act 2013 (Cth) (NDIS Act) and the NDIS Practice Standards.
2. Types of Personal Information We Collect
2.1 Information We Collect From Organisation Administrators and Staff
When organisations register to use the Platform and their staff use our services, we collect:
Identity and Contact Information:
- Full name
- Email address
- Phone number
- Position/title
- Business address
Employment and Professional Information:
- Employment status and role
- Qualifications and certifications
- NDIS Worker Screening Clearance number and expiry date
- Police check details and expiry date
- First aid certificate details
- Working with Children Check details (where applicable)
Account Information:
- Username and encrypted password
- Login timestamps and session data
- IP addresses and device information
- User preferences and settings
2.2 Information We Collect About NDIS Participants
Organisations using the Platform may enter information about NDIS participants receiving support services. This includes:
Personal Details:
- Full name
- Date of birth
- NDIS Number
- Residential address and service locations
- Gender
- Cultural and linguistic background (optional)
Support Information:
- NDIS Support Plan details and documents
- Care plans and goals
- Service agreements
- Funding management type (self-managed, plan-managed, NDIA-managed)
Health and Disability Information (Sensitive Information):
- Disability type and support needs
- Health conditions and medical information
- Medication details
- Behavioural support requirements
- Restrictive practices information (where applicable)
Emergency and Contact Information:
- Emergency contact names and phone numbers
- Family member/carer contact details
- Nominee or guardian details
Service Delivery Records:
- Shift records and attendance
- Progress notes and observations
- Incident reports
- Photos and evidence of service delivery
2.3 Sensitive Information
We collect sensitive information only with consent and where it is reasonably necessary for our functions or activities. Sensitive information may include:
- Health information about participants and workers
- Disability information
- Criminal history (Worker Screening Checks, Police Checks)
- Biometric information (GPS location data for compliance verification)
- Racial or ethnic origin (for cultural support planning)
2.4 Information We Collect Automatically
When you use the Platform, we automatically collect:
- Device and browser information
- IP address and geolocation data
- Access logs and timestamps
- Pages viewed and features used
- Session duration and activity patterns
3. How We Collect Personal Information
3.1 Direct Collection
We collect personal information directly from:
- Organisation administrators during registration and onboarding
- Staff members when they create their profiles
- Support Workers when they clock in/out and complete shift activities
- Participants (or their representatives) through service delivery processes
- Users who contact us for support or enquiries
3.2 Indirect Collection
We may receive personal information from:
- Authorised representatives or nominees acting on behalf of participants
- Other organisations when a user transfers between providers
- Third-party integrations (Xero, MYOB) when authorised
- Publicly available sources (where permitted)
- Law enforcement or regulatory bodies when required by law
3.3 Collection Notices
At or before the time of collection, we will take reasonable steps to provide a collection notice that explains:
- Our identity and contact details
- The purposes of collection
- How the information will be used and disclosed
- Whether disclosure is required or authorised by law
- How to access and correct the information
4. Purposes of Collection and Use
We collect and use personal information for the following purposes:
4.1 Platform Service Delivery
- Creating and managing user accounts
- Enabling access to Platform features
- Processing time tracking and shift management
- Generating billing and payroll exports
- Providing technical support and training
4.2 Compliance and Regulatory Requirements
- Verifying NDIS Worker Screening Clearances
- Maintaining certification expiry tracking
- Recording and reporting incidents to the NDIS Commission
- Generating compliance reports and audit trails
- Responding to regulatory enquiries and audits
4.3 Service Delivery to NDIS Participants
- Managing participant profiles and care plans
- Scheduling and coordinating support services
- Recording service delivery and progress
- Managing emergency contacts and safety information
- Supporting quality and safeguarding activities
4.4 Communication
- Sending service-related notifications
- Communicating about Platform updates and changes
- Responding to enquiries and support requests
- Sending marketing communications (with consent)
4.5 Security and Fraud Prevention
- Authenticating users and preventing unauthorised access
- Detecting and investigating suspicious activity
- Maintaining audit logs for security purposes
- Responding to data breaches and incidents
4.6 Business Improvement
- Analysing Platform usage and performance
- Developing new features and improvements
- Conducting research and reporting (de-identified data only)
- Training and quality assurance activities
5. Disclosure of Personal Information
We may disclose personal information to:
5.1 Authorised Recipients Within Your Organisation
- Staff members with appropriate role-based access
- Managers and coordinators responsible for service delivery
- Compliance officers for audit and reporting purposes
- Finance staff for billing and payroll processing
5.2 Third-Party Service Providers
We engage third-party service providers to assist with our operations, including:
- Cloud hosting and infrastructure providers
- Payment processing services
- Accounting software providers (Xero, MYOB) when you authorise integration
- Email and communication services
- Analytics and monitoring tools
These providers are bound by contractual obligations to protect personal information and use it only for the purposes we specify.
5.3 Regulatory Bodies and Law Enforcement
We may disclose personal information when:
- Required or authorised by law
- Requested by the NDIS Quality and Safeguards Commission
- Responding to valid legal processes (subpoenas, court orders)
- Reporting notifiable data breaches to the OAIC
- Preventing or investigating fraud or criminal activity
5.4 Related to Business Transactions
In the event of a merger, acquisition, or sale of assets, personal information may be transferred as part of that transaction, subject to confidentiality obligations.
5.5 With Your Consent
We may disclose personal information for other purposes with your express consent.
6. Cross-Border Disclosure
Personal information is primarily stored and processed in Australia. However, we may use cloud services that store data overseas, including:
- United States (for certain cloud infrastructure and analytics)
- Singapore and other Asia-Pacific regions (for redundancy and performance)
Before disclosing personal information to an overseas recipient, we will:
- Obtain your consent where required by APP 8
- Ensure the overseas recipient is bound by equivalent privacy protections
- Take reasonable steps to ensure the overseas recipient complies with the APPs
We do not disclose sensitive participant information to overseas recipients without explicit consent.
7. Data Security and Retention
7.1 Security Measures
We implement robust security measures to protect personal information, including:
Technical Security:
- Encryption of data in transit (TLS 1.3) and at rest (AES-256)
- Secure httpOnly session cookies for authentication
- Role-based access control and principle of least privilege
- Regular security assessments and penetration testing
- Intrusion detection and monitoring systems
Organisational Security:
- Staff training on privacy and security obligations
- Background checks for staff with access to personal information
- Confidentiality agreements with all staff and contractors
- Documented security policies and procedures
Physical Security:
- Secure access controls for physical facilities
- Secure destruction of physical records
7.2 Data Retention
We retain personal information for as long as necessary to:
- Provide the Platform services
- Meet legal and regulatory obligations (including NDIS requirements)
- Respond to complaints or legal claims
- Maintain audit trails required for compliance
Specific Retention Periods:
- Participant records: Retained for 7 years after last service or as required by NDIS
- Staff records: Retained for 7 years after employment ends
- Incident reports: Retained for 7 years minimum
- Audit logs: Retained for 7 years
- Financial records: Retained for 7 years per tax law requirements
When information is no longer required, we securely destroy or de-identify it.
7.3 Data Deletion Upon Request
When you request deletion of your data, we will:
- Delete or anonymise your personal information within 30 days
- Retain only information required by law (archived with restricted access)
- Notify third parties who may hold your information on our behalf
8. Access and Correction
8.1 Your Right to Access
Under the Privacy Act, you have the right to request access to personal information we hold about you. To make an access request:
- Submit a written request to our Privacy Officer (details below)
- Provide sufficient identification information
- Specify the information you are seeking
We will respond to your request within 30 days.
8.2 Fees
We may charge a reasonable fee for processing access requests to cover:
- Staff time required to locate and compile the information
- Costs of copying or reproducing records
We will advise you of any applicable fees before processing your request.
8.3 Correction of Information
You may request correction of personal information that is inaccurate, outdated, incomplete, irrelevant, or misleading. We will:
- Assess your request within 30 days
- Make corrections where appropriate
- Notify you of the outcome
- Add a statement to the record if we decline to make a correction
8.4 Access Through Platform
Users can access and update certain personal information directly through the Platform:
- Staff can view and edit their own profile information
- Participants (or their representatives) can request access through their provider organisation
- Administrators can manage organisational data within their tenant
9. Anonymity and Pseudonymity
Where it is lawful and practicable, individuals may deal with us anonymously or under a pseudonym. However, we may not be able to provide certain services without identifying information, such as:
- Creating a user account
- Processing NDIS claims
- Verifying worker clearances
We will inform you if anonymity or pseudonymity is not possible for a particular transaction.
10. Notifiable Data Breaches
10.1 Our Commitment
Cognify Digital is committed to preventing data breaches and responding swiftly if they occur. We have robust systems and processes in place to protect personal information from misuse, interference, loss, and unauthorised access, modification, or disclosure.
10.2 Data Breach Response
If we suspect a data breach has occurred, we will:
- Contain the breach – Take immediate steps to limit the spread and impact
- Assess the breach – Conduct an assessment within 30 days to determine severity
- Notify affected parties – If the breach is eligible for notification under the NDB scheme:
- Notify the Office of the Australian Information Commissioner (OAIC)
- Notify affected individuals with recommendations for protective action
- Review and improve – Conduct a post-incident review to prevent future breaches
10.3 Notifiable Data Breach Scheme
Under the NDB scheme, we are required to notify individuals and the OAIC when:
- There is unauthorised access to, or disclosure of, personal information
- This is likely to result in serious harm to affected individuals
- We cannot prevent the serious harm through remedial action
11. Direct Marketing
We may use your personal information for direct marketing purposes only when:
- We have your consent to do so
- The marketing relates to services similar to those you have previously requested
- You have not opted out of receiving marketing communications
11.1 Opt-Out Rights
You can opt out of marketing communications at any time by:
- Clicking the "unsubscribe" link in marketing emails
- Contacting us at [email protected]
- Updating your communication preferences in your account settings
We will process opt-out requests within 5 business days.
12. Cookies and Tracking Technologies
12.1 Cookies We Use
We use cookies and similar technologies to:
- Maintain your session and authenticate your login
- Remember your preferences and settings
- Analyse Platform usage and performance
- Improve security and detect fraud
12.2 Types of Cookies
| Cookie Type | Purpose | Duration |
| Essential | Session management, authentication | Session |
| Functional | Preferences, settings | Up to 12 months |
| Analytics | Usage analysis, performance monitoring | Up to 24 months |
| Security | Fraud prevention, bot detection | Session |
12.3 Managing Cookies
You can manage cookie preferences through your browser settings. Note that disabling essential cookies may affect Platform functionality.
13. Artificial Intelligence (AI) Transparency
Cognify Digital may use AI-assisted features to enhance Platform capabilities, including:
- AI-powered search and information retrieval (RAG with citations)
- Note drafting assistance (optional feature)
- Compliance form completion assistance
- Risk signal detection for missing evidence or anomalies
13.1 AI Data Handling
When AI features are used:
- Your data is processed securely and not used to train third-party AI models without consent
- AI outputs are clearly identified and may be reviewed before finalisation
- You can opt out of AI-assisted features in your organisation settings
13.2 Human Oversight
AI features are designed to assist, not replace, human decision-making. All AI-generated outputs should be reviewed by authorised staff before use.
14. Children's Privacy
The Cognify Digital Platform is not designed for use by children under 18 years of age. If we become aware that we have collected personal information from a child without parental consent, we will take steps to delete that information.
Where participants under 18 receive NDIS supports, information about them is managed by their parent, guardian, or authorised representative in accordance with this Privacy Statement.
15. Changes to This Privacy Statement
We may update this Privacy Statement from time to time to reflect:
- Changes in our information handling practices
- New features or services
- Changes in legal or regulatory requirements
- Industry best practices
When we make material changes, we will:
- Publish the updated Privacy Statement on our website
- Notify registered users by email
- Update the "Last Updated" date at the top of this document
We encourage you to review this Privacy Statement periodically.
16. Complaints and Enquiries
16.1 Contacting Us
If you have questions, concerns, or complaints about our privacy practices, please contact our Privacy Officer:
Cognify Digital Pty Ltd
Attention: Privacy Officer
- Email: [email protected]
- Phone: +61468167862
- Post: Suite 17, 89-97 Jones Street, Ultimo, NSW 2007
16.2 Complaints Process
We take privacy complaints seriously and will:
- Acknowledge your complaint within 5 business days
- Investigate and respond within 30 days
- Provide a written response explaining our findings and any remedial actions
16.3 External Review
If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC):
- Website:oaic.gov.au
- Phone: 1300 363 992
- Post: GPO Box 5218, Sydney NSW 2001
17. Definitions
| Term | Definition |
| **APP** | Australian Privacy Principle |
| **Collection** | Gathering, acquiring, or obtaining personal information |
| **Consent** | Express or implied agreement to the collection, use, or disclosure of personal information |
| **Data Breach** | Unauthorised access to, disclosure of, or loss of personal information |
| **NDIS** | National Disability Insurance Scheme |
| **NDB Scheme** | Notifiable Data Breaches scheme under Part IIIC of the Privacy Act |
| **Personal Information** | Information or an opinion about an identified individual, or an individual who is reasonably identifiable |
| **Sensitive Information** | Personal information including health information, racial or ethnic origin, political opinions, religious beliefs, sexual orientation, criminal record, and biometric information |
| **Tenant** | An organisation's isolated environment within the Cognify Digital Platform |
| **Use** | Access, consultation, processing, or handling of personal information |
18. Contact Information
Cognify Digital Pty Ltd
ABN: 53691933632
Registered Office:
Suite 17, 89-97 Jones Street, Ultimo, NSW 2007
Privacy Officer:
Email: [email protected]
Phone: +61 468 167 862
Data Protection Enquiries:
Email: [email protected]
This Privacy Statement is compliant with the Privacy Act 1988 (Cth) and the Australian Privacy Principles.