Privacy Policy

Clyroo is committed to protecting your privacy and personal information

Last Updated: July 27, 2026

1. Overview

Clyroo ("we," "our," or "us") is committed to protecting the privacy and security of personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

This policy applies to all personal information collected through our care management platform, website, and related services.

2. Information We Collect

2.1 Personal Information

We collect the following types of personal information:

2.2 Sensitive Information

We collect sensitive information only with consent or where permitted by law. This includes:

All sensitive information is handled in accordance with APP 3 (Collection of solicited personal information) and stored securely with restricted access.

2.3 How We Collect Information

We collect personal information through:

3. How We Use Your Information

3.1 Primary Purposes

We use personal information for:

3.2 Secondary Purposes

With appropriate consent or where permitted by law, we may use information for:

4. Disclosure of Personal Information

4.1 When We Share Information

We may disclose personal information to:

Recipient Purpose Legal Basis
Authorized staff within your organization Service delivery and care coordination Consent / Primary purpose
NDIS and government agencies Compliance reporting and funding claims Legal obligation
Healthcare providers Coordinated care and medical support Consent / Healthcare provision
Cloud hosting providers Data storage and platform operation Service provision
IT service providers Technical support and maintenance Service provision
Legal and regulatory authorities Compliance with legal obligations Legal requirement

4.2 Overseas Disclosure

We use cloud services that may store data on servers located overseas (including United States, Singapore). We ensure overseas recipients comply with privacy obligations equivalent to the APPs through:

4.3 We Will Never

5. Data Security

5.1 Security Measures

We implement comprehensive security measures including:

5.2 Data Breach Notification

In the event of a data breach likely to result in serious harm, we will:

  1. Notify the Office of the Australian Information Commissioner (OAIC) within 72 hours
  2. Notify affected individuals as soon as practicable
  3. Take immediate steps to contain the breach and prevent further unauthorized access
  4. Conduct a full investigation and implement remedial measures

6. Data Retention

6.1 Retention Periods

We retain personal information for:

6.2 Secure Disposal

When retention periods expire, we securely destroy or de-identify personal information using:

7. Your Rights

7.1 Access and Correction (APPs 12 & 13)

You have the right to:

We will respond to access requests within 30 days. In some cases, we may deny access where permitted by law (e.g., if it would unreasonably impact another person's privacy). We will provide written reasons for any denial.

7.2 Complaints (APP 1.4)

If you believe we have breached your privacy:

  1. Contact our Privacy Officer (details below)
  2. We will acknowledge your complaint within 7 days
  3. We will investigate and respond within 30 days
  4. If unsatisfied, you may complain to the OAIC (www.oaic.gov.au)

7.3 Withdrawal of Consent

Where we rely on consent, you may withdraw consent at any time. Note that withdrawal may impact our ability to provide services. We will explain any implications before processing your withdrawal.

8. Cookies and Tracking

8.1 What We Use

Our platform uses:

8.2 Your Control

You can control cookies through your browser settings. Note that disabling essential cookies may prevent platform access.

9. Third-Party Services

We use the following third-party services:

All third-party providers are required to protect your information consistent with this policy and applicable privacy laws.

10. Children's Privacy

When we collect information about children (under 18), we:

11. Changes to This Policy

We may update this policy to reflect changes in:

We will notify users of material changes by:

Continued use after notification constitutes acceptance of the updated policy.

12. Contact Us

Privacy Officer

Email: noreply@clyroo.com.au

Subject Line: "Privacy Inquiry" or "Privacy Complaint"


For access requests, corrections, complaints, or privacy questions, please contact our Privacy Officer.


Office of the Australian Information Commissioner (OAIC)

Website: www.oaic.gov.au

Phone: 1300 363 992


Compliance Statement: This Privacy Policy is designed to comply with the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs), the Notifiable Data Breaches (NDB) scheme, and relevant healthcare privacy obligations.