Privacy Policy
Last updated 28 September 2026
Contents
1. About this policy
1.1 This policy explains how Data Nebula Pty Ltd (ABN 63 684 548 598) ("we", "us") collects, uses, stores and discloses personal information in connection with CareHelm, our website at carehelm.com.au, and our free registration path checker (together, the "Service").
1.2 We're an Australian company. Contact details are in section 14.
1.3 We have chosen to handle personal information in line with the Australian Privacy Principles (APPs) in the Privacy Act 1988 (Cth), including the notifiable data breaches scheme.
1.4 Our approach in short:
- We collect as little personal information as we need.
- Your business data and files are stored in Google Cloud's Sydney region.
- CareHelm is not designed to hold participant health information, and we ask you not to upload it.
- We don't sell personal information, and we don't use your data to train AI models.
2. Two roles we play
2.1 Information about you as our customer or visitor. For example, your name, email, business details and billing information. We decide how this is used, and this policy applies directly.
2.2 Information you put into CareHelm about other people. For example, your staff's names, qualifications, certificate expiry dates and policy sign-off records. We hold and process this on your behalf to provide the Service, under our Data Processing Agreement. You (the provider) are responsible for telling those people how their information is handled and for having any consents needed. We use it only to provide the Service to you, and as this policy describes.
3. What we collect
| Category | Examples | From whom |
|---|---|---|
| Checker answers and contact details | First name, email, business name, the services you provide, team size, marketing and research-call preferences | You, when you use the checker |
| Account information | Name, email address, role, login records, multi-factor authentication settings | You and your Users |
| Business information | Business name, ABN, services, sites, registration groups, registration dates | You |
| Staff information (on your behalf) | Staff names, work email, mobile number (for SMS invites and sign-in codes), role, qualifications, training and certificates, NDIS Worker Screening Check number and expiry date, records of checking the clearance in the NDIS Worker Screening Database, risk-assessed role, orientation, induction and supervision records, policy sign-off records (including how the staff member confirmed their identity), and answers to policy questions | You or your staff |
| Participant file checklist (on your behalf) | A participant code you choose (for example "P-07") and which file items are in place. We ask you not to enter names or other details that identify a participant | You |
| Content and files | Your answers to the policy interview (typed or voice), policies you generate or edit, evidence files you upload, comments | You and your Users |
| Voice recordings | Audio you record when answering by voice | You and your Users |
| Billing information | Billing contact, business name, billing address, ABN, subscription and payment history. Card details are collected and held by Stripe, not by us. | You, Stripe |
| Communications | Emails and support messages you send us; interview notes and recordings (only with your permission) | You |
| Technical and usage information | IP address, device and browser type, pages and features used, error logs, security logs | Automatically, when you use the Service |
What we ask you not to give us: participant names, NDIS numbers, health information, case notes or incident details about identifiable participants. The Service doesn't need this to help you prepare for an audit. If you upload it anyway, we'll handle it securely as your data under section 2.2, but please remove it.
Sensitive information. Some staff information, such as screening check details, may be sensitive. We collect it only because you choose to use the Service to track it, and we handle it with the same protections as all your data.
Anonymity. You can read our website and guides without telling us who you are. To receive a checker report or use CareHelm, we need at least your email address.
4. Why we use it
| Purpose | Information used |
|---|---|
| Provide the checker and email you your report | Checker answers, name, email |
| Create and run your account, including sign-in and security | Account and technical information |
| Provide CareHelm features: gap assessment, policy drafting, evidence library, expiry reminders, audit pack export, staff sign-off | Business, staff, content and files |
| Generate draft content and suggestions with AI (see section 6) | Interview answers, voice recordings, uploaded files, business information |
| Send reminders and notifications by email or SMS | Email, mobile number, expiry dates |
| Bill you and issue tax invoices | Billing information |
| Provide support and respond to you | Communications, account information |
| Send marketing emails, only if you've agreed | Name, email, checker answers |
| Invite you to research calls, only if you've agreed | Name, email |
| Keep the Service secure, prevent fraud and misuse, fix problems | Technical, account and billing information |
| Improve the Service using de-identified, aggregated data | Usage information, de-identified |
| Meet legal obligations (for example tax records) | Billing information |
We don't use personal information for other purposes unless you'd reasonably expect it and it's related to the purposes above, you've agreed, or the law requires or allows it.
5. Where it's stored and who gets it
5.1 Main storage in Sydney. Your account data, business data, staff information, content and files are stored in Google Cloud's Sydney region (australia-southeast1), using Firebase Cloud Firestore, Cloud Storage for Firebase and Cloud Functions. Backups are also stored in Australia.
5.2 Service providers ("sub-processors"). We use these providers to run the Service. Each receives only what it needs.
| Provider | What it does for us | Information involved | Where it processes data |
|---|---|---|---|
| Google Cloud / Firebase (Firestore, Cloud Storage, Cloud Functions) | Database, file storage, application servers | All account, business, staff, content and file data | Australia (Sydney) |
| Google Cloud Vertex AI | Generates draft text, transcribes voice, reads documents | Interview answers, voice recordings, uploaded files, business information | Australia (Sydney) |
| Google Firebase Authentication | Sign-in (email links, multi-factor authentication) | Email address, phone number (if used for MFA or SMS sign-in), IP address, device information, login times | United States |
| Stripe | Payments, subscriptions, tax invoices, fraud checks | Billing contact, business name, billing address, ABN, payment card details (held by Stripe), IP address | United States and other countries where Stripe operates |
| Resend | Sending emails (reports, reminders, notifications, marketing if agreed) | Name, email address, email content | United States |
| Twilio | Sending SMS invitations and reminders (if you use them) | Mobile number, message content | United States and other countries where Twilio operates |
| Firebase Hosting (Google) | Hosting our public website and checker pages | IP address, pages visited | global CDN, origin in Australia |
| Google Analytics (Google LLC) | Usage statistics for the website and app (section 12) | Pages and features used, device and browser type, approximate location, a random browser ID. Organisations appear only as a one-way code | Outside Australia, including the United States |
| Google Calendar appointment schedules | Scheduling research calls | Name, email, chosen time | United States |
5.3 Overseas disclosure (APP 8). As shown above, some information goes overseas, mainly to the United States. This includes sign-in data (Firebase Authentication), payments (Stripe), email and SMS delivery (Resend, Twilio) and usage statistics (Google Analytics). Before we use an overseas provider, we take reasonable steps to make sure it protects personal information consistently with the APPs, including by using providers with contractual data protection terms and security certifications.
5.4 Other disclosures. We may also disclose personal information:
- to professional advisers (such as our accountant) where needed;
- if you signed up through a referral partner (such as your bookkeeper or accountant), to that partner: only your business name, plan and subscription status, so we can pay their referral fee;
- to a buyer of our business, under confidentiality, if we sell the business or the Service (we'll tell you first);
- where required or authorised by law, such as a court order; or
- with your consent.
5.5 We don't sell personal information and we don't share it with advertisers.
6. How we use AI
6.1 CareHelm uses AI (Google's Gemini models through Vertex AI, run in the Sydney region) to:
- turn voice answers into text;
- draft policy and procedure sections from your interview answers and our templates;
- explain standards in plain English and ask follow-up questions in the gap assessment;
- suggest where an uploaded file belongs and read expiry dates from certificates.
The free checker suggests registration groups from your description with keyword matching in your browser. It doesn't use AI and doesn't send the description to us.
6.2 You're in control. AI output is a suggestion. You confirm or change every classification and expiry date, and every generated policy section stays a draft until you approve it.
6.3 What we send to the AI model. Only the content needed for the task. We design prompts so that participant identities are not needed, and we warn you if something you type looks like personal information about a participant.
6.4 No training. Under Google Cloud's terms, Google doesn't use the content we send to Vertex AI to train its models. We don't use your data to train AI models either.
7. Automated decisions
7.1 From 10 December 2026, Australian privacy law requires us to tell you when we use a computer program, using personal information, to make decisions that could reasonably be expected to significantly affect your rights or interests.
7.2 Decisions made solely by automated processes:
| Decision | Personal information used | Effect | What you can do |
|---|---|---|---|
| Changing your account to read-only when a trial ends without a subscription | Account and subscription status | You can view and export, but not edit | Subscribe at any time; contact us if you think it's wrong |
| Changing your account to read-only when a payment remains unpaid 14 days after notice | Billing and payment status | As above | Update payment details; contact us |
| Stripe's fraud screening (Stripe Radar) declining a payment it assesses as high-risk | Payment card details, billing address, IP address, device information | The payment may not go through | Contact us and we'll look at other ways to pay |
| Blocking sign-in after repeated failed attempts or suspicious activity | Login records, IP address, device information | Temporary lock-out | Wait and retry, or contact us |
7.3 Decisions where automated processes do something substantial but a person decides:
- AI suggestions of registration groups, evidence categories and expiry dates. You confirm them before they take effect.
- AI-drafted policy content. You approve each section.
- Coverage percentages and "what to do next" lists, calculated by fixed rules from your answers.
These relate to your business's compliance preparation. They don't decide anything about your participants, and we don't use them to make decisions about your staff.
7.4 We don't make decisions about individuals' eligibility, employment or access to NDIS supports.
8. How long we keep it
| Information | How long |
|---|---|
| Checker leads (no account) | 24 months after your last interaction with us, then deleted |
| Trial accounts that don't subscribe | 12 months after the trial ends. We email you 30 days before deletion |
| Customer accounts | For your subscription, then a 90-day export period, then deleted within 30 days (backups expire within a further 35 days), unless you choose an archive option or the law requires us to keep it |
| Billing and tax records | At least 5 years, as required by Australian tax law |
| Interview recordings (research calls) | Deleted within 90 days; written notes kept without contact details after 24 months |
| Security logs | Up to 12 months |
| Marketing unsubscribe list | Kept indefinitely so we don't contact you again |
When we no longer need personal information, we delete it or de-identify it.
9. How we protect it
- Encryption in transit (TLS) and at rest (Google Cloud default encryption).
- Separation between customer organisations, enforced by database security rules.
- Role-based access (Owner, Admin, Staff). Staff can't see other staff members' evidence or billing.
- Multi-factor authentication required for Owners and Admins.
- Access logs for administrative actions and file access.
- Only authorised Data Nebula personnel can access production systems, and only when needed for support or security.
- Daily backups stored in Australia.
- A written data breach response plan (section 11).
No system is perfectly secure, but we take reasonable steps to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure.
10. Your rights
10.1 Access and correction. You can see and update most of your information in your account settings. You can also ask us for a copy of the personal information we hold about you, or ask us to correct it, by emailing privacy@carehelm.com.au. We'll respond within 30 days. There's no charge. If we refuse, we'll tell you why in writing and how to complain.
10.2 Staff of our customers. If you're a staff member of one of our customers and want to access or correct information your employer put into CareHelm, please contact your employer first. We'll help them respond. You can also contact us.
10.3 Marketing. We send marketing emails only if you've agreed. Every marketing email has an unsubscribe link, and we action unsubscribe requests within 5 business days. You'll still receive essential account emails (such as billing notices and security alerts).
10.4 Deleting your account. Owners can close the account from settings or by emailing us. Section 8 explains what happens next.
11. Data breaches
11.1 If we suspect a data breach, we act immediately to contain it and assess it. We aim to complete our assessment as quickly as possible, and within 30 days at most.
11.2 If a breach is likely to result in serious harm to anyone (an "eligible data breach"), we will notify the affected individuals and the Office of the Australian Information Commissioner (OAIC) as soon as practicable, as required by the notifiable data breaches scheme.
11.3 If a breach affects data you put into CareHelm about your staff, we'll also notify you (the customer) promptly, as set out in our Data Processing Agreement, so you can meet any obligations you have.
12. Cookies and analytics
12.1 We use essential cookies and local storage to keep you signed in and to make the Service work. We don't use advertising cookies.
12.2 Google Analytics. Our website and the CareHelm app use Google Analytics, a service of Google LLC, to count visits and see which features are used. Google Analytics sets cookies and stores this data on Google's servers outside Australia, including in the United States.
12.3 What we send. We send no personal or health information to Google Analytics: no names, email addresses, answers you type, or participant or staff details. Your organisation appears only as a one-way code that can't be turned back into its name. We have turned off Google's advertising features and Google signals.
12.4 Opting out. You can install the Google Analytics Opt-out Browser Add-on, block cookies in your browser, or use a content blocker. The Service works the same without it.
13. Children
The Service is for businesses and adults. It's not intended for people under 18, and we don't knowingly collect their information.
14. Contact and complaints
Privacy contact: privacy@carehelm.com.au
Post: Data Nebula Pty Ltd (ABN 63 684 548 598), Sydney NSW 2008
If you have a concern about how we've handled your personal information, please email us with details. We'll acknowledge your complaint within 5 business days and aim to respond in full within 30 days.
If you're not satisfied with our response, you can complain to the Office of the Australian Information Commissioner (OAIC): www.oaic.gov.au, phone 1300 363 992.