DailyCore Trust & Legal Center

Legal, Privacy & Compliance

Clear, transparent, and legally binding commitments safeguarding healthcare providers, participants, and support staff under Australian law.

NDIS & Privacy Act 1988 CompliantUpdated: September 2026

DailyCore Privacy Policy

Effective Date: 1 September 2026 | Last Reviewed: September 2026 | Version: 2.4

Key Summary: DailyCore is a healthcare and workforce management SaaS platform designed for Australian NDIS, Aged Care, and Disability Support providers. We collect and process personal and sensitive health data solely to facilitate rosters, care plans, shift verification, clinical notes, and billing on behalf of authorized service providers. All data remains encrypted within Australian sovereign cloud infrastructure.

1. Introduction & Statutory Framework

DailyCore Australia ("DailyCore", "we", "our", or "us") is committed to protecting the privacy and confidentiality of individuals who interact with our platform, including care providers ("Subscribers"), support workers, healthcare professionals, care coordinators, and service participants ("Clients" or "Participants").

This Privacy Policy sets out how we collect, hold, use, disclose, and protect personal and sensitive information in strict compliance with:

  • The Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs);
  • The National Disability Insurance Scheme Act 2013 (Cth) and the NDIS Quality and Safeguards Commission Rules;
  • The Aged Care Act 1997 (Cth) and applicable Quality Standards;
  • State and Territory Health Records Legislation (including the Health Records Act 2001 (Vic), Health Records and Information Privacy Act 2002 (NSW), and equivalent statutes).

2. Information We Collect

Depending on your role and relationship with DailyCore, we collect different categories of data:

A. Provider & Administrative Account Information

  • Organization details: Business name, Australian Business Number (ABN), NDIS Provider Registration Number, billing contact information.
  • Authorized user profiles: Full name, official email address, phone number, and administrative role designations.

B. Support Worker & Staff Information

  • Identity & Contact: Full name, home address, mobile phone number, emergency contacts, profile photo.
  • Compliance & Credentials: Working With Children Check (WWCC) numbers and expiry dates, National Police Check certificates, NDIS Worker Screening Check credentials, CPR/First Aid certifications, driver's license details, and visa verification data.
  • Operational Records: Rostered shifts, timesheets, break tracking, mileage logs, expense reimbursement claims, and staff digital signatures.
  • Geolocation Records: Precise GPS latitude and longitude coordinates captured strictly at the instant of shift "Clock-In" and "Clock-Out" to verify attendance at designated service locations. Continuous background tracking is never conducted.

C. Participant / Client Sensitive Health Data

Sensitive health information is only stored on DailyCore at the direction of the authorized care provider with participant or guardian consent.

  • Demographics: Participant name, date of birth, residential address, primary language, emergency and next-of-kin contacts.
  • NDIS / Funding Data: NDIS Participant Number, support funding categories, price book assignments, and plan management contacts.
  • Care & Clinical Documentation: Comprehensive Care Plans, developmental goals, risk alerts (e.g., choking risks, fall hazards, allergies), behavioral support plans, and Medication Administration Records (MAR).
  • Shift Notes & Incident Reports: Shift progress notes entered by support workers, attached shift photos (e.g., wound progression or activity evidence), adverse incident logs, and participant/guardian digital verification signatures.

3. How We Use Collected Information

DailyCore collects and uses information exclusively for legitimate care delivery and management operations, including:

  • Roster & Service Delivery: Matching support workers to participants, publishing schedules, and sending push notifications for shift changes.
  • Clinical Continuity & Safety: Ensuring support staff have immediate, on-site access to necessary care plans, medication regimens, and behavioral precautions.
  • Time, Attendance & Billing: Generating accurate timesheets, reconciling GPS clock-in verification, and creating compliant NDIS bulk claim invoices.
  • Compliance & Statutory Reporting: Assisting providers in meeting mandatory auditing standards required by the NDIS Quality and Safeguards Commission.
  • Incident Management: Logging and triaging incidents, injuries, or restrictive practices for prompt escalation.
  • Platform Maintenance & Security: Authenticating users, debugging errors, monitoring system health, and preventing fraudulent access.

4. Information Sharing & Disclosure

We do not sell, rent, or trade personal or health data. Data is disclosed only in the following regulated circumstances:

  • Within the Care Provider Team: Support workers and administrators assigned to a participant can view relevant care instructions, emergency protocols, and notes.
  • Participant & Family Portal: Authorized participants and nominated family representatives can review their own schedules and progress documentation.
  • Legal & Regulatory Authorities: Where compelled by law, court order, or formal request from the NDIS Quality and Safeguards Commission, the NDIA, Coroners Court, or emergency medical responders.
  • Sub-Processors & Infrastructure Providers: Highly vetted cloud infrastructure partners (such as Australian-based AWS and Google Cloud data centers) who operate under strict Data Processing Agreements.

Australian Sovereign Hosting: All primary databases and backup repositories housing sensitive health data are hosted physically within data centers located in Australia (Sydney and Melbourne regions), satisfying sovereign healthcare data residency guidelines.

5. Data Security & Storage

We deploy bank-grade technical and organizational safeguards to ensure data integrity and confidentiality:

  • Encryption: Data in transit is protected using Transport Layer Security (TLS 1.3). Data at rest in databases, backups, and attachments is encrypted using AES-256.
  • Role-Based Access Control (RBAC): Granular permissions enforce the Principle of Least Privilege, preventing unauthorized staff from viewing sensitive clinical records.
  • Offline Mobile Security: Shifts and progress notes cached locally on support worker devices for offline operation are stored in encrypted SQLite/AsyncStorage vaults and purged upon logout.
  • Audit Trails: Immutable audit logs track record creation, modifications, clock events, and note views for forensic compliance.

6. Data Retention & Archival

In accordance with Australian medical record regulations, participant health documentation and incident reports are retained for a minimum of 7 years from the date of creation (or until a minor participant reaches the age of 25).

Upon contract termination by a care provider, an export window is provided to download all organization records, following which inactive accounts are securely decommissioned and purged in accordance with our data sanitization procedures.

7. Data Breach Response

DailyCore maintains a documented Data Breach Incident Response Plan. In the event of an eligible data breach that is likely to result in serious harm, we will immediately contain the incident, notify affected providers and individuals, and notify the Office of the Australian Information Commissioner (OAIC) in accordance with Part IIIC of the Privacy Act 1988.

8. Your Rights & Complaints

Under Australian Privacy Principles 12 and 13, you have the right to request access to personal information held about you and request corrections if inaccurate.

If you are a participant whose information was entered by a care provider using DailyCore, we encourage you to contact your service provider directly, as they are the primary data controller. You may also contact our Privacy Officer directly.

If you are unsatisfied with our response, you may lodge a formal complaint with the Office of the Australian Information Commissioner (OAIC):

  • OAIC Website: www.oaic.gov.au
  • Phone: 1300 363 992
  • Post: GPO Box 5218, Sydney NSW 2001

9. Contact Our Privacy Officer

For privacy inquiries, data access requests, or regulatory questions regarding our compliance framework:

Privacy Officer, DailyCore Technologies Australia

Email: privacy@dailycore.com.au

Legal & Compliance: legal@dailycore.com.au

Address: Level 14, 385 Bourke Street, Melbourne VIC 3000, Australia