CareHelm

Privacy Policy

Last updated 28 September 2026

Contents
  1. About this policy
  2. Two roles we play
  3. What we collect
  4. Why we use it
  5. Where it's stored and who gets it
  6. How we use AI
  7. Automated decisions
  8. How long we keep it
  9. How we protect it
  10. Your rights
  11. Data breaches
  12. Cookies and analytics
  13. Children
  14. Contact and complaints
  15. Changes

1. About this policy

1.1 This policy explains how Data Nebula Pty Ltd (ABN 63 684 548 598) ("we", "us") collects, uses, stores and discloses personal information in connection with CareHelm, our website at carehelm.com.au, and our free registration path checker (together, the "Service").

1.2 We're an Australian company. Contact details are in section 14.

1.3 We have chosen to handle personal information in line with the Australian Privacy Principles (APPs) in the Privacy Act 1988 (Cth), including the notifiable data breaches scheme.

1.4 Our approach in short:

  • We collect as little personal information as we need.
  • Your business data and files are stored in Google Cloud's Sydney region.
  • CareHelm is not designed to hold participant health information, and we ask you not to upload it.
  • We don't sell personal information, and we don't use your data to train AI models.

2. Two roles we play

2.1 Information about you as our customer or visitor. For example, your name, email, business details and billing information. We decide how this is used, and this policy applies directly.

2.2 Information you put into CareHelm about other people. For example, your staff's names, qualifications, certificate expiry dates and policy sign-off records. We hold and process this on your behalf to provide the Service, under our Data Processing Agreement. You (the provider) are responsible for telling those people how their information is handled and for having any consents needed. We use it only to provide the Service to you, and as this policy describes.

3. What we collect

CategoryExamplesFrom whom
Checker answers and contact detailsFirst name, email, business name, the services you provide, team size, marketing and research-call preferencesYou, when you use the checker
Account informationName, email address, role, login records, multi-factor authentication settingsYou and your Users
Business informationBusiness name, ABN, services, sites, registration groups, registration datesYou
Staff information (on your behalf)Staff names, work email, mobile number (for SMS invites and sign-in codes), role, qualifications, training and certificates, NDIS Worker Screening Check number and expiry date, records of checking the clearance in the NDIS Worker Screening Database, risk-assessed role, orientation, induction and supervision records, policy sign-off records (including how the staff member confirmed their identity), and answers to policy questionsYou or your staff
Participant file checklist (on your behalf)A participant code you choose (for example "P-07") and which file items are in place. We ask you not to enter names or other details that identify a participantYou
Content and filesYour answers to the policy interview (typed or voice), policies you generate or edit, evidence files you upload, commentsYou and your Users
Voice recordingsAudio you record when answering by voiceYou and your Users
Billing informationBilling contact, business name, billing address, ABN, subscription and payment history. Card details are collected and held by Stripe, not by us.You, Stripe
CommunicationsEmails and support messages you send us; interview notes and recordings (only with your permission)You
Technical and usage informationIP address, device and browser type, pages and features used, error logs, security logsAutomatically, when you use the Service

What we ask you not to give us: participant names, NDIS numbers, health information, case notes or incident details about identifiable participants. The Service doesn't need this to help you prepare for an audit. If you upload it anyway, we'll handle it securely as your data under section 2.2, but please remove it.

Sensitive information. Some staff information, such as screening check details, may be sensitive. We collect it only because you choose to use the Service to track it, and we handle it with the same protections as all your data.

Anonymity. You can read our website and guides without telling us who you are. To receive a checker report or use CareHelm, we need at least your email address.

4. Why we use it

PurposeInformation used
Provide the checker and email you your reportChecker answers, name, email
Create and run your account, including sign-in and securityAccount and technical information
Provide CareHelm features: gap assessment, policy drafting, evidence library, expiry reminders, audit pack export, staff sign-offBusiness, staff, content and files
Generate draft content and suggestions with AI (see section 6)Interview answers, voice recordings, uploaded files, business information
Send reminders and notifications by email or SMSEmail, mobile number, expiry dates
Bill you and issue tax invoicesBilling information
Provide support and respond to youCommunications, account information
Send marketing emails, only if you've agreedName, email, checker answers
Invite you to research calls, only if you've agreedName, email
Keep the Service secure, prevent fraud and misuse, fix problemsTechnical, account and billing information
Improve the Service using de-identified, aggregated dataUsage information, de-identified
Meet legal obligations (for example tax records)Billing information

We don't use personal information for other purposes unless you'd reasonably expect it and it's related to the purposes above, you've agreed, or the law requires or allows it.

5. Where it's stored and who gets it

5.1 Main storage in Sydney. Your account data, business data, staff information, content and files are stored in Google Cloud's Sydney region (australia-southeast1), using Firebase Cloud Firestore, Cloud Storage for Firebase and Cloud Functions. Backups are also stored in Australia.

5.2 Service providers ("sub-processors"). We use these providers to run the Service. Each receives only what it needs.

ProviderWhat it does for usInformation involvedWhere it processes data
Google Cloud / Firebase (Firestore, Cloud Storage, Cloud Functions)Database, file storage, application serversAll account, business, staff, content and file dataAustralia (Sydney)
Google Cloud Vertex AIGenerates draft text, transcribes voice, reads documentsInterview answers, voice recordings, uploaded files, business informationAustralia (Sydney)
Google Firebase AuthenticationSign-in (email links, multi-factor authentication)Email address, phone number (if used for MFA or SMS sign-in), IP address, device information, login timesUnited States
StripePayments, subscriptions, tax invoices, fraud checksBilling contact, business name, billing address, ABN, payment card details (held by Stripe), IP addressUnited States and other countries where Stripe operates
ResendSending emails (reports, reminders, notifications, marketing if agreed)Name, email address, email contentUnited States
TwilioSending SMS invitations and reminders (if you use them)Mobile number, message contentUnited States and other countries where Twilio operates
Firebase Hosting (Google)Hosting our public website and checker pagesIP address, pages visitedglobal CDN, origin in Australia
Google Analytics (Google LLC)Usage statistics for the website and app (section 12)Pages and features used, device and browser type, approximate location, a random browser ID. Organisations appear only as a one-way codeOutside Australia, including the United States
Google Calendar appointment schedulesScheduling research callsName, email, chosen timeUnited States

5.3 Overseas disclosure (APP 8). As shown above, some information goes overseas, mainly to the United States. This includes sign-in data (Firebase Authentication), payments (Stripe), email and SMS delivery (Resend, Twilio) and usage statistics (Google Analytics). Before we use an overseas provider, we take reasonable steps to make sure it protects personal information consistently with the APPs, including by using providers with contractual data protection terms and security certifications.

5.4 Other disclosures. We may also disclose personal information:

  • to professional advisers (such as our accountant) where needed;
  • if you signed up through a referral partner (such as your bookkeeper or accountant), to that partner: only your business name, plan and subscription status, so we can pay their referral fee;
  • to a buyer of our business, under confidentiality, if we sell the business or the Service (we'll tell you first);
  • where required or authorised by law, such as a court order; or
  • with your consent.

5.5 We don't sell personal information and we don't share it with advertisers.

6. How we use AI

6.1 CareHelm uses AI (Google's Gemini models through Vertex AI, run in the Sydney region) to:

  • turn voice answers into text;
  • draft policy and procedure sections from your interview answers and our templates;
  • explain standards in plain English and ask follow-up questions in the gap assessment;
  • suggest where an uploaded file belongs and read expiry dates from certificates.

The free checker suggests registration groups from your description with keyword matching in your browser. It doesn't use AI and doesn't send the description to us.

6.2 You're in control. AI output is a suggestion. You confirm or change every classification and expiry date, and every generated policy section stays a draft until you approve it.

6.3 What we send to the AI model. Only the content needed for the task. We design prompts so that participant identities are not needed, and we warn you if something you type looks like personal information about a participant.

6.4 No training. Under Google Cloud's terms, Google doesn't use the content we send to Vertex AI to train its models. We don't use your data to train AI models either.

7. Automated decisions

7.1 From 10 December 2026, Australian privacy law requires us to tell you when we use a computer program, using personal information, to make decisions that could reasonably be expected to significantly affect your rights or interests.

7.2 Decisions made solely by automated processes:

DecisionPersonal information usedEffectWhat you can do
Changing your account to read-only when a trial ends without a subscriptionAccount and subscription statusYou can view and export, but not editSubscribe at any time; contact us if you think it's wrong
Changing your account to read-only when a payment remains unpaid 14 days after noticeBilling and payment statusAs aboveUpdate payment details; contact us
Stripe's fraud screening (Stripe Radar) declining a payment it assesses as high-riskPayment card details, billing address, IP address, device informationThe payment may not go throughContact us and we'll look at other ways to pay
Blocking sign-in after repeated failed attempts or suspicious activityLogin records, IP address, device informationTemporary lock-outWait and retry, or contact us

7.3 Decisions where automated processes do something substantial but a person decides:

  • AI suggestions of registration groups, evidence categories and expiry dates. You confirm them before they take effect.
  • AI-drafted policy content. You approve each section.
  • Coverage percentages and "what to do next" lists, calculated by fixed rules from your answers.

These relate to your business's compliance preparation. They don't decide anything about your participants, and we don't use them to make decisions about your staff.

7.4 We don't make decisions about individuals' eligibility, employment or access to NDIS supports.

8. How long we keep it

InformationHow long
Checker leads (no account)24 months after your last interaction with us, then deleted
Trial accounts that don't subscribe12 months after the trial ends. We email you 30 days before deletion
Customer accountsFor your subscription, then a 90-day export period, then deleted within 30 days (backups expire within a further 35 days), unless you choose an archive option or the law requires us to keep it
Billing and tax recordsAt least 5 years, as required by Australian tax law
Interview recordings (research calls)Deleted within 90 days; written notes kept without contact details after 24 months
Security logsUp to 12 months
Marketing unsubscribe listKept indefinitely so we don't contact you again

When we no longer need personal information, we delete it or de-identify it.

9. How we protect it

  • Encryption in transit (TLS) and at rest (Google Cloud default encryption).
  • Separation between customer organisations, enforced by database security rules.
  • Role-based access (Owner, Admin, Staff). Staff can't see other staff members' evidence or billing.
  • Multi-factor authentication required for Owners and Admins.
  • Access logs for administrative actions and file access.
  • Only authorised Data Nebula personnel can access production systems, and only when needed for support or security.
  • Daily backups stored in Australia.
  • A written data breach response plan (section 11).

No system is perfectly secure, but we take reasonable steps to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure.

10. Your rights

10.1 Access and correction. You can see and update most of your information in your account settings. You can also ask us for a copy of the personal information we hold about you, or ask us to correct it, by emailing privacy@carehelm.com.au. We'll respond within 30 days. There's no charge. If we refuse, we'll tell you why in writing and how to complain.

10.2 Staff of our customers. If you're a staff member of one of our customers and want to access or correct information your employer put into CareHelm, please contact your employer first. We'll help them respond. You can also contact us.

10.3 Marketing. We send marketing emails only if you've agreed. Every marketing email has an unsubscribe link, and we action unsubscribe requests within 5 business days. You'll still receive essential account emails (such as billing notices and security alerts).

10.4 Deleting your account. Owners can close the account from settings or by emailing us. Section 8 explains what happens next.

11. Data breaches

11.1 If we suspect a data breach, we act immediately to contain it and assess it. We aim to complete our assessment as quickly as possible, and within 30 days at most.

11.2 If a breach is likely to result in serious harm to anyone (an "eligible data breach"), we will notify the affected individuals and the Office of the Australian Information Commissioner (OAIC) as soon as practicable, as required by the notifiable data breaches scheme.

11.3 If a breach affects data you put into CareHelm about your staff, we'll also notify you (the customer) promptly, as set out in our Data Processing Agreement, so you can meet any obligations you have.

12. Cookies and analytics

12.1 We use essential cookies and local storage to keep you signed in and to make the Service work. We don't use advertising cookies.

12.2 Google Analytics. Our website and the CareHelm app use Google Analytics, a service of Google LLC, to count visits and see which features are used. Google Analytics sets cookies and stores this data on Google's servers outside Australia, including in the United States.

12.3 What we send. We send no personal or health information to Google Analytics: no names, email addresses, answers you type, or participant or staff details. Your organisation appears only as a one-way code that can't be turned back into its name. We have turned off Google's advertising features and Google signals.

12.4 Opting out. You can install the Google Analytics Opt-out Browser Add-on, block cookies in your browser, or use a content blocker. The Service works the same without it.

13. Children

The Service is for businesses and adults. It's not intended for people under 18, and we don't knowingly collect their information.

14. Contact and complaints

Privacy contact: privacy@carehelm.com.au
Post: Data Nebula Pty Ltd (ABN 63 684 548 598), Sydney NSW 2008

If you have a concern about how we've handled your personal information, please email us with details. We'll acknowledge your complaint within 5 business days and aim to respond in full within 30 days.

If you're not satisfied with our response, you can complain to the Office of the Australian Information Commissioner (OAIC): www.oaic.gov.au, phone 1300 363 992.

15. Changes