Privacy Policy
1. Who we are
Guardian Desk (the “Service”, “we”, “us”) is operated by Guardian Desk Pty Ltd (Australian Company Number ACN 698 001 688). We provide a software-as-a-service platform for NDIS compliance, care management, billing and record-keeping. Our software, branding, documentation and related intellectual property are owned by Guardian Desk Pty Ltd.
Privacy contact:
privacy@guardiandesk.com.au
General support:
support@guardiandesk.com.au
Security incidents:
security@guardiandesk.com.au
2. Who this policy applies to
This policy applies to:
- Visitors to our public website and registration pages;
- Account owners, administrators and workers using the Guardian Desk provider application;
- Self-managed participants and their authorised users using the Self-Managed Edition;
- Individuals whose personal information is entered into the Service by a customer (for example NDIS participants and workers) — in those cases the customer organisation is usually the primary collector and we act on their instructions as a service provider.
3. Roles: controller and processor
Depending on the data:
- For your account, billing and support data, we generally act as the entity that collects and holds that information for our own business purposes.
- For participant, worker and compliance records you enter for your organisation, you (the customer) determine what is collected and why; we store and process that data on your behalf to provide the Service. You must meet your own obligations under the Privacy Act, the NDIS Practice Standards, and any participant consents or notices you are required to give.
4. What we collect
4.1 Account and organisation data
- Name, email, phone, role and authentication credentials (passwords are hashed; we do not store plaintext passwords);
- Organisation name, ABN/ACN, NDIS registration number, address and contact details;
- Subscription plan, billing status, invoices and payment references;
- Communications with support, change requests and onboarding applications.
4.2 NDIS participant data (entered by customers)
- Identity and contact details, date of birth, gender, state, nominees and emergency contacts;
- NDIS participant numbers, plan dates, plan-manager details, budgets and service agreements;
- Progress notes, incidents, risks, goals, consents and signed documents;
- Files uploaded to the document library or linked cloud storage.
4.3 Worker and compliance data
- Employment details, qualifications, screening numbers and expiry dates (WWCC, NDIS worker screening, police checks, first aid, CPR, etc.);
- Audit and compliance workflow status.
4.4 Technical and usage data
- IP address, browser, device type, pages viewed, session identifiers, timestamps;
- Security logs, failed logins, administrative actions and API activity where enabled;
- First-party analytics (page views, session length) to improve reliability and detect abuse — we do not sell this data.
4.5 Payments
Card payments are processed by Stripe (and optionally other gateways we enable). We receive transaction IDs, amounts, status and customer references — we do not store full card numbers or CVV.
4.6 AI and chat features
- Messages sent to in-app chat or AI assistants (e.g. Eden AI), including escalated support transcripts;
- Text you explicitly submit when you press an AI writing assist button (support notes, quick-note phrases, and similar fields).
AI writing features send only the text in that field to our AI writing assist provider for that request. Pressing the AI button is your agreement to that transfer. We do not automatically send participant files, invoices, or full records to AI providers, and we do not use your stored records to train third-party models. Avoid pasting unnecessary participant identifiers unless your organisation’s policies allow it.
4.7 Integrations you enable
If you connect third-party services, we process credentials and metadata needed to operate the integration, for example:
- Cloud storage (Dropbox, Microsoft OneDrive, Google Drive);
- Accounting (Xero, MYOB);
- Email (SMTP settings you configure).
Data sent to those services is also governed by their privacy policies.
4.8 Voluntary product feedback (opt-in)
If your organisation opts in to our product improvement program (Settings → Product improvement program), authorised users of the Guardian Desk provider application or Self-Managed Edition may submit bugs, improvements and suggestions. Participation is voluntary; account owners may opt in or out at any time, and the preference applies immediately to new submissions.
When a user submits feedback, we may collect:
- Type, title, description and optional steps to reproduce;
- Optional page or section context if the user provides it;
- Organisation identification — your company or tenancy name and internal company identifier;
- Worker identification — the submitter’s display name and worker account identifier;
- Application context — whether the report came from the Guardian Desk provider application or Self-Managed Edition.
We do not automatically attach or transmit participant NDIS records, care notes, progress notes, incident reports, uploaded documents, invoices, financial records, bank or payment details, transaction histories, or other Customer Data with feedback submissions. We collect only what is needed to identify your organisation and the worker experiencing the issue, plus the feedback text you enter. Nothing else is sent unless a user deliberately enters additional text.
We use this information only to diagnose issues, prioritise improvements, notify your organisation when work is deployed, and improve the Service. You must not paste sensitive personal or financial information into feedback forms unless necessary and lawful.
You may opt out at any time in Settings. Opting out stops new submissions; previously submitted feedback may be retained in our internal tracker for audit and support purposes.
4.9 Location / GPS (support notes and optional clock-in)
Where a customer organisation enables Field GPS prompts in Guardian Desk Settings
(gps_prompt_enabled — labelled as collecting GPS for support notes), the provider application may request the
worker’s device location through the browser Geolocation API when they start or save a new support note,
and optionally when clocking in or out of a scheduled visit.
- Coordinates (latitude, longitude and approximate accuracy) may be stored on the support note or visit clock record for field accuracy, attendance evidence and compliance workflows chosen by that organisation;
- We do not continuously track workers; location is requested in connection with those discrete actions;
- If location permission is denied or unavailable, the worker may continue; the note or clock may record that GPS was unavailable;
- When the organisation leaves the setting off (default), Guardian Desk does not prompt the browser for location for these flows;
- The customer organisation decides whether to enable collection and remains responsible for informing workers and participants as required under applicable privacy and workplace laws.
Device GPS used for security or audit alerts on sign-in/sign-out (where collected) is handled similarly as technical metadata and is not sold or used for unrelated marketing.
5. How we collect information
- Directly from you when you register, complete forms, upload files or contact us;
- Automatically through cookies, logs and security systems when you use the Service;
- From the device browser Geolocation API when a customer organisation has enabled field GPS collection and a worker starts a support note or (where applicable) clocks a visit — see section 4.9;
- From your authorised users (workers) acting under your account;
- From payment processors and integration partners where you have connected them.
6. Why we use information
We use personal information to:
- Provide, operate, secure and improve the Service;
- Authenticate users, enforce access controls and prevent fraud or abuse;
- Generate documents, reports, invoices and compliance workflows you request;
- Bill subscriptions, send receipts and manage account status;
- Respond to enquiries, incidents and privacy requests;
- Attach optional GPS stamps to support notes and visit clocks when your organisation enables field GPS collection (section 4.9);
- Process voluntary product feedback when your organisation has opted in to the product improvement program (section 4.8);
- Comply with law, regulators, courts and lawful law-enforcement requests;
- Maintain backups, disaster recovery and audit trails.
We do not sell personal information. We do not use participant clinical records for unrelated direct marketing.
7. Disclosure to third parties
We disclose information only where necessary, including to:
7.1 Sub-processors and infrastructure
- Hosting and database providers (Australian data centres where practicable);
- Stripe and other payment providers;
- AI writing assist and chat providers (including Eden AI where enabled) used only when you press an AI writing assist button or use enabled chat features — we send the text you submit for that request, not your full database;
- Email delivery services;
- Telegram or similar channels for operational alerts (metadata and message content you trigger through support flows);
- Captcha providers on public forms.
These providers are engaged for defined purposes and must protect information consistent with this policy and applicable law.
7.2 Integrations you authorise
When you connect Xero, MYOB, Dropbox or other integrations, data flows to those systems under your control and their terms.
7.3 Legal and regulatory
We may disclose information where required or reasonably necessary, including to the OAIC, NDIS Quality and Safeguards Commission, courts, police or other regulators.
7.4 Business transfers
If we sell, merge or restructure the business, information may transfer to the successor subject to equivalent privacy protections. We will notify account owners of material changes.
8. Overseas disclosure (APP 8)
Primary storage is in Australia. Some sub-processors (payment, AI, email, cloud APIs) may process data in the United States, European Union, United Kingdom or other countries. Where we disclose to overseas recipients, we take reasonable steps to ensure APP 8 compliance, including contractual protections and assessing whether the recipient is subject to comparable privacy law or binding schemes.
9. Cookies and similar technologies
We use:
- Essential cookies — session authentication, CSRF protection, security, and resuming a signed-in session after a browser refresh;
- Preference cookies / local storage — dark or light theme and other UI settings on this device;
- Session storage (technical) — short-lived device metadata such as a recent GPS reading used for optional field stamps or security context, only where the organisation or flow has enabled location collection;
- Analytics — first-party usage measurement (no third-party ad trackers by default).
On public pages and the Guardian Desk apps we show a cookie preferences banner so you can accept analytics or choose essential only. When this policy or the cookie categories change, we bump the consent version and ask you to choose again. You can block cookies in your browser; essential features (sign-in, security) may stop working. Public marketing pages may use privacy-friendly analytics as configured from time to time.
10. Security
We implement technical and organisational measures including TLS encryption in transit, access controls, role-based permissions per tenant, hashed passwords, encrypted storage of sensitive integration secrets where supported, logging of significant actions, and restricted administrative access. We adhere to practices drawn from ISO/IEC 27001, ISO/IEC 27701, and Australia’s Essential Eight to protect personal and operational data. See our Security page for a plain-language summary of controls. We do not claim ISO certification or Essential Eight accreditation.
No online system is perfectly secure. You must use strong passwords, limit worker access to what each role needs, and report suspected compromise immediately to security@guardiandesk.com.au.
11. Retention
- Active accounts: data retained while the subscription is active and as needed to provide the Service;
- NDIS-related records: customers are responsible for statutory minimum retention (often seven years for many compliance records). We retain tenant data after cancellation for a limited export window, then delete or anonymise unless law requires longer retention;
- Backups: may persist for a defined period before rotation;
- Server and security logs: typically up to 24 months unless needed for an investigation;
- AI / chat logs: de-identified or deleted on a rolling basis (e.g. within 30 days) where configured.
12. Keeping your personal information accurate
Providing reliable service depends on holding information that is correct and current. We take reasonable steps to ensure personal information we hold is accurate, complete, and up to date. If you believe any information we hold about you is wrong or outdated, please contact us as soon as practicable at privacy@guardiandesk.com.au so we can update our records and continue to serve you properly.
13. Access, correction and deletion
Under the APPs you may request access to or correction of personal information we hold about you. Contact privacy@guardiandesk.com.au. We will respond within 30 days where practicable.
Account owners can export much of their organisation’s data from the application. Requests relating to participant records held for a provider should usually be directed to that provider first.
Deletion requests are subject to legal retention obligations and active disputes. We may refuse access in limited circumstances permitted by the Privacy Act.
14. Notifiable data breaches
If we become aware of a data breach likely to result in serious harm, we will comply with the Notifiable Data Breaches scheme under the Privacy Act, including assessing the breach, notifying affected individuals and the OAIC where required, and taking steps to contain and remediate.
15. Marketing and communications
We may send service-related emails (billing, security, policy updates, maintenance). Promotional messages are sent only where permitted by law and, where required, with your consent. You can opt out of non-essential marketing via the unsubscribe link or by contacting us.
16. Children
The Service is not directed at children under 16 for self-registration. Participant records about minors are entered by authorised adults in a professional or guardian capacity.
17. Automated decision-making
AI features suggest text or answers; they do not make binding decisions about NDIS eligibility, funding or compliance. Humans remain responsible for records submitted to the NDIA or regulators.
18. Complaints
Contact us first at privacy@guardiandesk.com.au. If unresolved, you may complain to the Office of the Australian Information Commissioner (OAIC): oaic.gov.au or 1300 363 992.
19. Changes to this policy
We may update this policy for legal, technical or business changes. Material updates will be notified by email or in-app notice at least 14 days before taking effect where practicable. Continued use after the effective date constitutes acceptance of the updated policy.
20. Related documents
Your use of the Service is also governed by our Terms of Use. Onboarding and registration forms may include additional notices at collection.
21. Contact
Privacy: privacy@guardiandesk.com.au
Support: support@guardiandesk.com.au
Security: security@guardiandesk.com.au