Table of Contents
1. Overview
Clyroo ("we," "our," or "us") is committed to protecting the privacy and security of personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
This policy applies to all personal information collected through our care management platform, website, and related services.
2. Information We Collect
2.1 Personal Information
We collect the following types of personal information:
- Participant Information: Name, date of birth, address, contact details, NDIS plan details, goals, support needs, medical information, progress notes, and incident reports
- Staff Information: Name, contact details, qualifications, employment history, working with children checks, police checks, emergency contacts
- Account Information: Username, email address, password (encrypted), organization details
- Billing Information: Service hours, rates, invoicing details, payment information
- Usage Information: Log data, IP addresses, browser type, pages accessed, time stamps
- Communications: Messages, support tickets, email correspondence
2.2 Sensitive Information
We collect sensitive information only with consent or where permitted by law. This includes:
- Health information (medical conditions, medications, treatment plans)
- Disability information
- Information about support needs and goals
- Information required for NDIS service delivery
All sensitive information is handled in accordance with APP 3 (Collection of solicited personal information) and stored securely with restricted access.
2.3 How We Collect Information
We collect personal information through:
- Direct entry into our platform by authorized users
- Forms submitted through our website
- Email and phone communications
- Third-party integrations (with your consent)
- Automated collection via cookies and tracking technologies
3. How We Use Your Information
3.1 Primary Purposes
We use personal information for:
- Service Delivery: Managing participants, scheduling support, documenting progress, coordinating care
- NDIS Compliance: Meeting reporting requirements, maintaining audit trails, demonstrating compliance
- Billing: Generating invoices, processing claims, maintaining financial records
- Communication: Coordinating between staff, participants, families, and stakeholders
- Platform Operation: Providing access, maintaining security, improving functionality
- Legal Obligations: Complying with healthcare regulations, privacy laws, and legal requirements
3.2 Secondary Purposes
With appropriate consent or where permitted by law, we may use information for:
- Improving our services and platform features
- Analyzing usage patterns (in aggregated, de-identified form)
- Sending service updates and important notices
- Responding to inquiries and support requests
4. Disclosure of Personal Information
4.1 When We Share Information
We may disclose personal information to:
| Recipient | Purpose | Legal Basis |
|---|---|---|
| Authorized staff within your organization | Service delivery and care coordination | Consent / Primary purpose |
| NDIS and government agencies | Compliance reporting and funding claims | Legal obligation |
| Healthcare providers | Coordinated care and medical support | Consent / Healthcare provision |
| Cloud hosting providers | Data storage and platform operation | Service provision |
| IT service providers | Technical support and maintenance | Service provision |
| Legal and regulatory authorities | Compliance with legal obligations | Legal requirement |
4.2 Overseas Disclosure
We use cloud services that may store data on servers located overseas (including United States, Singapore). We ensure overseas recipients comply with privacy obligations equivalent to the APPs through:
- Contractual agreements requiring APP-equivalent protections
- Use of reputable cloud providers with strong privacy practices (Microsoft Azure, AWS)
- Encryption of data in transit and at rest
- Regular security assessments and compliance audits
4.3 We Will Never
- Sell your personal information to third parties
- Share information for marketing purposes without explicit consent
- Disclose sensitive information except as required by law or with consent
5. Data Security
5.1 Security Measures
We implement comprehensive security measures including:
- Encryption: SSL/TLS encryption for data in transit, AES-256 encryption for data at rest
- Access Controls: Role-based access, multi-factor authentication, regular access reviews
- Network Security: Firewalls, intrusion detection, regular security monitoring
- Staff Training: Regular privacy and security training for all personnel
- Audit Trails: Comprehensive logging of all data access and modifications
- Incident Response: Procedures for detecting, responding to, and reporting data breaches
- Regular Testing: Vulnerability assessments and penetration testing
5.2 Data Breach Notification
In the event of a data breach likely to result in serious harm, we will:
- Notify the Office of the Australian Information Commissioner (OAIC) within 72 hours
- Notify affected individuals as soon as practicable
- Take immediate steps to contain the breach and prevent further unauthorized access
- Conduct a full investigation and implement remedial measures
6. Data Retention
6.1 Retention Periods
We retain personal information for:
- Participant records: 7 years after service completion (healthcare records requirement)
- Staff records: 7 years after employment ends (Fair Work Act requirement)
- Financial records: 7 years (ATO requirement)
- Incident reports: 10 years (NDIS requirement)
- System logs: 2 years (security and audit purposes)
6.2 Secure Disposal
When retention periods expire, we securely destroy or de-identify personal information using:
- Secure deletion protocols for electronic data
- Irreversible de-identification where data is retained for statistical purposes
- Documented disposal procedures and verification
7. Your Rights
7.1 Access and Correction (APPs 12 & 13)
You have the right to:
- Access: Request a copy of your personal information we hold
- Correction: Request correction of inaccurate or incomplete information
- Explanation: Request information about how we handle your personal information
We will respond to access requests within 30 days. In some cases, we may deny access where permitted by law (e.g., if it would unreasonably impact another person's privacy). We will provide written reasons for any denial.
7.2 Complaints (APP 1.4)
If you believe we have breached your privacy:
- Contact our Privacy Officer (details below)
- We will acknowledge your complaint within 7 days
- We will investigate and respond within 30 days
- If unsatisfied, you may complain to the OAIC (www.oaic.gov.au)
7.3 Withdrawal of Consent
Where we rely on consent, you may withdraw consent at any time. Note that withdrawal may impact our ability to provide services. We will explain any implications before processing your withdrawal.
8. Cookies and Tracking
8.1 What We Use
Our platform uses:
- Essential cookies: Required for authentication and security
- Functional cookies: Remember preferences and settings
- Analytics cookies: Understand usage patterns (aggregated data only)
8.2 Your Control
You can control cookies through your browser settings. Note that disabling essential cookies may prevent platform access.
9. Third-Party Services
We use the following third-party services:
- Microsoft 365: Email communication (Microsoft Privacy Statement applies)
- Cloud Hosting: AWS/Azure for data storage (covered by data processing agreements)
- Xero: Accounting integration (with your explicit consent, Xero privacy policy applies)
All third-party providers are required to protect your information consistent with this policy and applicable privacy laws.
10. Children's Privacy
When we collect information about children (under 18), we:
- Obtain consent from parents/guardians where required
- Only collect information necessary for NDIS service delivery
- Apply heightened security and access restrictions
- Allow parents/guardians to access and correct their child's information
11. Changes to This Policy
We may update this policy to reflect changes in:
- Legal requirements
- Our practices
- Platform features
We will notify users of material changes by:
- Email notification to registered users
- Prominent notice on our website
- In-platform notifications
Continued use after notification constitutes acceptance of the updated policy.
12. Contact Us
Privacy Officer
Email: noreply@clyroo.com.au
Subject Line: "Privacy Inquiry" or "Privacy Complaint"
For access requests, corrections, complaints, or privacy questions, please contact our Privacy Officer.
Office of the Australian Information Commissioner (OAIC)
Website: www.oaic.gov.au
Phone: 1300 363 992
Compliance Statement: This Privacy Policy is designed to comply with the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs), the Notifiable Data Breaches (NDB) scheme, and relevant healthcare privacy obligations.