CareLinc Privacy Policy
CareLinc is committed to respecting your privacy and protecting personal, health, and sensitive information in accordance with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth).
1. About CareLinc & Scope
CareLinc ("we", "us", or "our") provides a web-based care-management software platform designed for Australian care providers, NDIS registered and non-registered support services, aged care organisations, support workers, care coordinators, and clients/participants.
This Privacy Policy describes how we collect, hold, use, disclose, and safeguard personal information and sensitive health information when you access or use the CareLinc website, web application, custom admin views, client portals, worker portals, or e-commerce shop.
Legal Entity Notice: CareLinc Pty Ltd [REQUIRES BUSINESS CONFIRMATION] (ABN: [REQUIRES BUSINESS CONFIRMATION]).
2. Personal Information We Collect
We collect personal information that is reasonably necessary to provide care-management software functionality, process subscriptions, facilitate workforce rostering, and deliver e-commerce store products.
A. User & Account Credentials
Full name, email address, contact phone number, encrypted password hash, system role assignment (e.g. Super Admin, Provider Admin, Staff, Care Coordinator, Roster Manager, Care Worker, Client, Family Member, Supplier), and module access permissions.
B. Client & Participant Records
Name, date of birth, gender, home residential address, telephone, email, emergency contact details, primary language, interpreter requirements, cultural/diversity preferences, and authorized representative details (relationship, power of attorney notes).
C. Workforce & Employment Information
Care worker profile details, primary job title, employment classification (full-time, part-time, casual, contractor), department, skills, compliance certifications, office location, bank account details (BSB and account number), Tax File Number (TFN), and superannuation details [REQUIRES BUSINESS CONFIRMATION].
D. Operational & Service Delivery Information
Shift rosters, scheduled appointments, service requests, shift attendance timestamps, daily instructions, care team assignments, activity logs, and system audit trails.
E. Financial & E-Commerce Information
Quotes, invoices, service agreement funding types (NDIS, Aged Care, Private), billing addresses, e-commerce shop product orders, and delivery addresses.
3. Sensitive & Health Information
Because CareLinc operates as a care-management platform, the system processes sensitive information (including health and disability information) as defined under the Privacy Act 1988 (Cth).
Handling Sensitive Health Records
Sensitive information is collected and processed only with express consent, or where entered by authorized customer organisations and care workers in accordance with relevant care contracts and legal requirements.
Verified sensitive data modules in CareLinc include:
- Medical History & Health Summaries: Clinical medical history, health summaries, recorded allergies, and emergency medical protocols.
- Functional Ability Assessments: Standardized Barthel Index ADL scores (feeding, bathing, grooming, dressing, bowel, bladder, toilet, transfers, mobility, stairs) and Lawton IADL scores.
- Individualized Support Plans & Care Plans: Operational goals, support needs, assistive technology needs, daily morning/afternoon/evening routines, and emergency disaster plans.
- Progress Notes & Clinical Records: Care worker progress notes, shift logs, clinical observations, medication administration records, and incident reports.
- Risks & Alerts: Identified participant risks (e.g. falls risk, medication risk), likelihood, consequences, and risk mitigation strategies.
4. How We Collect Information
We collect personal information through several channels:
- Directly from You: When you register an account, complete online inquiry/intake forms, place an e-commerce shop order, or subscribe to newsletter updates.
- From Customer Care Provider Organisations: When care coordinators, administrators, or support workers input participant details, care plans, rosters, or progress notes into the platform.
- From Authorised Representatives: When family members, legal guardians, or holders of Power of Attorney provide details on behalf of a participant.
- Automated System Logging: Web server logs, audit logs, authentication session trackers, and error diagnostics collected when accessing the platform.
5. How We Hold & Protect Data
We implement technical and organizational security controls designed to safeguard personal and sensitive information against unauthorized access, modification, disclosure, or misuse.
Role-Based Access Control (RBAC)
Access to participant records, health summaries, and staff details is strictly restricted based on user system roles and account type permissions.
Data Encryption in Transit
All web communications, API requests, and user logins are encrypted in transit using industry-standard TLS (HTTPS) protocols.
Secure Database Storage
Application data is stored in relational PostgreSQL database infrastructure managed with isolated user credentials and password hashing.
Audit Trails & System Logging
Key administrative actions, data edits, and shift notes generate audit logs to maintain transparency and operational accountability.
* Note: While we enforce stringent access controls, no internet-based software platform can guarantee 100% security against all potential security risks.
6. Purposes for Using Information
We use personal information for the following primary purposes:
- Providing care-management software functionality, including care plan drafting, functional assessment scoring, rostering, and progress note logging.
- Facilitating workforce scheduling, carer availability tracking, and shift assignment.
- Processing e-commerce store orders, managing invoices, quotes, and billing.
- Communicating transactional service notifications, shift reminders, and password reset links via email or SMS.
- Improving application performance, monitoring system stability via Sentry, and troubleshooting technical errors.
- Complying with applicable Australian legal, regulatory, health, and reporting obligations.
7. Disclosure of Personal Information
We disclose personal information only in limited circumstances:
- To Customer Care Provider Organisations: Support workers, care coordinators, and administrators within the organization managing your care.
- To Verified Subprocessors & Service Providers: Third-party technology infrastructure providers assisting with hosting, database storage, email delivery, SMS, and analytics (see Section 9).
- To Emergency Services & Health Professionals: Where necessary to prevent or lessen a serious and imminent threat to life, health, or safety.
- As Required by Law: Where mandated by Australian court orders, statutory bodies, or law enforcement authorities.
8. Care Providers vs Platform Operator
CareLinc operates primarily as a SaaS technology provider. Where a care provider organisation (such as an NDIS service provider or aged care provider) uses CareLinc to manage participant care, that organisation remains responsible for ensuring appropriate participant notices, authorisations, and consents are obtained under Australian privacy law.
9. Third-Party Subprocessors
We engage verified third-party technology subprocessors to deliver core application infrastructure. Each service provider is bound by confidentiality and data protection obligations:
| Provider | Purpose | Data Handled | Location / Overseas |
|---|---|---|---|
| Amazon Web Services (AWS S3) | Cloud Object Storage for uploaded attachments, care documents, media, and compliance evidence. | Uploaded document files, media assets, attachments. | Asia Pacific (Sydney, Australia) region [REQUIRES BUSINESS CONFIRMATION] (No (if Sydney region confirmed) [REQUIRES BUSINESS CONFIRMATION]) |
| PostgreSQL Database Infrastructure | Primary relational database for core application records, user credentials, client profiles, care plans, shift logs, and billing data. | All application data tables. | Australia / Cloud Database Infrastructure [REQUIRES BUSINESS CONFIRMATION] (Pending host region confirmation [REQUIRES BUSINESS CONFIRMATION]) |
| Resend | Transactional email delivery service (e.g. welcome emails, password resets, system alerts). | Recipient email address, name, email message body contents. | United States [REQUIRES BUSINESS CONFIRMATION] (Yes (United States) [REQUIRES BUSINESS CONFIRMATION]) |
| ClickSend | SMS transactional messaging service for shift notifications, emergency alerts, and verification codes. | Recipient mobile phone number, SMS message content. | Australia [REQUIRES BUSINESS CONFIRMATION] (No [REQUIRES BUSINESS CONFIRMATION]) |
| Zoho CRM | Customer Relationship Management integration for managing business inquiries, leads, and organizational accounts. | Lead contact details, organization details, communications. | Australia / Global Data Centers [REQUIRES BUSINESS CONFIRMATION] (Possible depending on Zoho data center region [REQUIRES BUSINESS CONFIRMATION]) |
| Beehiiv | Newsletter and marketing update subscription service. | Subscriber email address, subscription status. | United States [REQUIRES BUSINESS CONFIRMATION] (Yes (United States) [REQUIRES BUSINESS CONFIRMATION]) |
| Sentry | Application error tracking, crash monitoring, and performance diagnostics. | Error stack traces, browser metadata, IP address (scrubbed), page URLs. | United States [REQUIRES BUSINESS CONFIRMATION] (Yes (United States) [REQUIRES BUSINESS CONFIRMATION]) |
| AI Assistance Modules (Care Plan Suggestions & Summaries) | Advisory AI modules used to assist care coordinators with care plan drafting, lead summarization, and task drafting. | Text prompts provided by staff (e.g. goals, assessment text snippets). Sensitive client PII should be anonymized by staff prior to input. | Global AI API Infrastructure [REQUIRES BUSINESS CONFIRMATION] (Possible [REQUIRES BUSINESS CONFIRMATION]) |
10. Overseas Disclosure
Core database records and document attachments are stored primarily in Australian data centers where available [REQUIRES BUSINESS CONFIRMATION]. However, certain subprocessors (such as email delivery via Resend, marketing management via Beehiiv, or crash diagnostics via Sentry) process data in servers located in the United States.
Before disclosing personal information to an overseas recipient, we take reasonable steps under APP 8 to ensure the recipient does not breach the Australian Privacy Principles.
11. Data Retention & Deletion
CareLinc retains personal information only for as long as reasonably necessary for the purposes for which it is held, and as required by applicable Australian legal, statutory, health record, and accounting obligations.
When personal information is no longer required, we take reasonable steps to securely destroy or permanently de-identify the information. Specific retention periods for health and financial records are governed by State and Commonwealth legislation [REQUIRES BUSINESS CONFIRMATION].
12. Access and Correction Rights
Under APPs 12 and 13, you have the right to request access to the personal information we hold about you and to request corrections if you believe the information is inaccurate, out-of-date, incomplete, irrelevant, or misleading.
To request access or correction, please submit a written request to our Privacy Officer at privacy@carelinc.com.au. We will respond within a reasonable period (normally within 30 days).
13. Privacy Complaints & OAIC
If you have a concern or complaint about how CareLinc has handled your personal information, please contact our Privacy Officer in writing:
CareLinc Privacy Officer
Email: privacy@carelinc.com.au
Address: 60 Martin Place, Sydney NSW 2000, Australia
If you are not satisfied with our response, you may escalate your complaint to the Office of the Australian Information Commissioner (OAIC):
Website: www.oaic.gov.au | Phone: 1300 363 992
14. Security Incidents & Data Breaches
CareLinc maintains a Security Incident & Data Breach response procedure under the Australian Notifiable Data Breaches (NDB) scheme. In the event of an eligible data breach involving personal information likely to result in serious harm, we will notify affected individuals and the OAIC as required by law.
16. AI-Assisted Features
CareLinc includes optional AI copilot and advisory features (e.g. care plan goal drafting suggestions, lead summary drafting). Prompts submitted to AI modules are processed strictly to generate advisory text suggestions. AI suggestions are non-binding drafts and must be reviewed and verified by qualified care coordinators before incorporation into care plans.
17. NDIS, Disability & Aged Care
CareLinc software is designed with operational safeguards tailored to NDIS Quality and Safeguards Commission guidelines and Aged Care Quality Standards, supporting client dignity, choice, control, and privacy protection.
18. Changes & Contact Details
We may update this Privacy Policy from time to time to reflect changes in our software, legal obligations, or business practices. Updated versions will be published on this page with an updated "Effective Date".
Privacy Contact Information
For privacy inquiries, access requests, or privacy complaints:
privacy@carelinc.com.au
60 Martin Place, Sydney NSW 2000, Australia
Notice: This Privacy Policy has been drafted based on CareLinc's current verified application architecture and Australian privacy regulations. It should be reviewed and approved by qualified Australian legal counsel prior to final production publication.
