Government Approved Provider. Learn about NDIS & Aged Care funding.
CareLinc Logo
Back to CareLinc Home
Privacy GovernanceVersion 1.0.0Effective Date: September 10, 2026

CareLinc Privacy Policy

CareLinc is committed to respecting your privacy and protecting personal, health, and sensitive information in accordance with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth).

1. About CareLinc & Scope

CareLinc ("we", "us", or "our") provides a web-based care-management software platform designed for Australian care providers, NDIS registered and non-registered support services, aged care organisations, support workers, care coordinators, and clients/participants.

This Privacy Policy describes how we collect, hold, use, disclose, and safeguard personal information and sensitive health information when you access or use the CareLinc website, web application, custom admin views, client portals, worker portals, or e-commerce shop.

Legal Entity Notice: CareLinc Pty Ltd [REQUIRES BUSINESS CONFIRMATION] (ABN: [REQUIRES BUSINESS CONFIRMATION]).

2. Personal Information We Collect

We collect personal information that is reasonably necessary to provide care-management software functionality, process subscriptions, facilitate workforce rostering, and deliver e-commerce store products.

A. User & Account Credentials

Full name, email address, contact phone number, encrypted password hash, system role assignment (e.g. Super Admin, Provider Admin, Staff, Care Coordinator, Roster Manager, Care Worker, Client, Family Member, Supplier), and module access permissions.

B. Client & Participant Records

Name, date of birth, gender, home residential address, telephone, email, emergency contact details, primary language, interpreter requirements, cultural/diversity preferences, and authorized representative details (relationship, power of attorney notes).

C. Workforce & Employment Information

Care worker profile details, primary job title, employment classification (full-time, part-time, casual, contractor), department, skills, compliance certifications, office location, bank account details (BSB and account number), Tax File Number (TFN), and superannuation details [REQUIRES BUSINESS CONFIRMATION].

D. Operational & Service Delivery Information

Shift rosters, scheduled appointments, service requests, shift attendance timestamps, daily instructions, care team assignments, activity logs, and system audit trails.

E. Financial & E-Commerce Information

Quotes, invoices, service agreement funding types (NDIS, Aged Care, Private), billing addresses, e-commerce shop product orders, and delivery addresses.

3. Sensitive & Health Information

Because CareLinc operates as a care-management platform, the system processes sensitive information (including health and disability information) as defined under the Privacy Act 1988 (Cth).

Handling Sensitive Health Records

Sensitive information is collected and processed only with express consent, or where entered by authorized customer organisations and care workers in accordance with relevant care contracts and legal requirements.

Verified sensitive data modules in CareLinc include:

  • Medical History & Health Summaries: Clinical medical history, health summaries, recorded allergies, and emergency medical protocols.
  • Functional Ability Assessments: Standardized Barthel Index ADL scores (feeding, bathing, grooming, dressing, bowel, bladder, toilet, transfers, mobility, stairs) and Lawton IADL scores.
  • Individualized Support Plans & Care Plans: Operational goals, support needs, assistive technology needs, daily morning/afternoon/evening routines, and emergency disaster plans.
  • Progress Notes & Clinical Records: Care worker progress notes, shift logs, clinical observations, medication administration records, and incident reports.
  • Risks & Alerts: Identified participant risks (e.g. falls risk, medication risk), likelihood, consequences, and risk mitigation strategies.

4. How We Collect Information

We collect personal information through several channels:

  • Directly from You: When you register an account, complete online inquiry/intake forms, place an e-commerce shop order, or subscribe to newsletter updates.
  • From Customer Care Provider Organisations: When care coordinators, administrators, or support workers input participant details, care plans, rosters, or progress notes into the platform.
  • From Authorised Representatives: When family members, legal guardians, or holders of Power of Attorney provide details on behalf of a participant.
  • Automated System Logging: Web server logs, audit logs, authentication session trackers, and error diagnostics collected when accessing the platform.

5. How We Hold & Protect Data

We implement technical and organizational security controls designed to safeguard personal and sensitive information against unauthorized access, modification, disclosure, or misuse.

Role-Based Access Control (RBAC)

Access to participant records, health summaries, and staff details is strictly restricted based on user system roles and account type permissions.

Data Encryption in Transit

All web communications, API requests, and user logins are encrypted in transit using industry-standard TLS (HTTPS) protocols.

Secure Database Storage

Application data is stored in relational PostgreSQL database infrastructure managed with isolated user credentials and password hashing.

Audit Trails & System Logging

Key administrative actions, data edits, and shift notes generate audit logs to maintain transparency and operational accountability.

* Note: While we enforce stringent access controls, no internet-based software platform can guarantee 100% security against all potential security risks.

6. Purposes for Using Information

We use personal information for the following primary purposes:

  • Providing care-management software functionality, including care plan drafting, functional assessment scoring, rostering, and progress note logging.
  • Facilitating workforce scheduling, carer availability tracking, and shift assignment.
  • Processing e-commerce store orders, managing invoices, quotes, and billing.
  • Communicating transactional service notifications, shift reminders, and password reset links via email or SMS.
  • Improving application performance, monitoring system stability via Sentry, and troubleshooting technical errors.
  • Complying with applicable Australian legal, regulatory, health, and reporting obligations.

7. Disclosure of Personal Information

We disclose personal information only in limited circumstances:

  • To Customer Care Provider Organisations: Support workers, care coordinators, and administrators within the organization managing your care.
  • To Verified Subprocessors & Service Providers: Third-party technology infrastructure providers assisting with hosting, database storage, email delivery, SMS, and analytics (see Section 9).
  • To Emergency Services & Health Professionals: Where necessary to prevent or lessen a serious and imminent threat to life, health, or safety.
  • As Required by Law: Where mandated by Australian court orders, statutory bodies, or law enforcement authorities.

8. Care Providers vs Platform Operator

CareLinc operates primarily as a SaaS technology provider. Where a care provider organisation (such as an NDIS service provider or aged care provider) uses CareLinc to manage participant care, that organisation remains responsible for ensuring appropriate participant notices, authorisations, and consents are obtained under Australian privacy law.

9. Third-Party Subprocessors

We engage verified third-party technology subprocessors to deliver core application infrastructure. Each service provider is bound by confidentiality and data protection obligations:

ProviderPurposeData HandledLocation / Overseas
Amazon Web Services (AWS S3)Cloud Object Storage for uploaded attachments, care documents, media, and compliance evidence.Uploaded document files, media assets, attachments.Asia Pacific (Sydney, Australia) region [REQUIRES BUSINESS CONFIRMATION] (No (if Sydney region confirmed) [REQUIRES BUSINESS CONFIRMATION])
PostgreSQL Database InfrastructurePrimary relational database for core application records, user credentials, client profiles, care plans, shift logs, and billing data.All application data tables.Australia / Cloud Database Infrastructure [REQUIRES BUSINESS CONFIRMATION] (Pending host region confirmation [REQUIRES BUSINESS CONFIRMATION])
ResendTransactional email delivery service (e.g. welcome emails, password resets, system alerts).Recipient email address, name, email message body contents.United States [REQUIRES BUSINESS CONFIRMATION] (Yes (United States) [REQUIRES BUSINESS CONFIRMATION])
ClickSendSMS transactional messaging service for shift notifications, emergency alerts, and verification codes.Recipient mobile phone number, SMS message content.Australia [REQUIRES BUSINESS CONFIRMATION] (No [REQUIRES BUSINESS CONFIRMATION])
Zoho CRMCustomer Relationship Management integration for managing business inquiries, leads, and organizational accounts.Lead contact details, organization details, communications.Australia / Global Data Centers [REQUIRES BUSINESS CONFIRMATION] (Possible depending on Zoho data center region [REQUIRES BUSINESS CONFIRMATION])
BeehiivNewsletter and marketing update subscription service.Subscriber email address, subscription status.United States [REQUIRES BUSINESS CONFIRMATION] (Yes (United States) [REQUIRES BUSINESS CONFIRMATION])
SentryApplication error tracking, crash monitoring, and performance diagnostics.Error stack traces, browser metadata, IP address (scrubbed), page URLs.United States [REQUIRES BUSINESS CONFIRMATION] (Yes (United States) [REQUIRES BUSINESS CONFIRMATION])
AI Assistance Modules (Care Plan Suggestions & Summaries)Advisory AI modules used to assist care coordinators with care plan drafting, lead summarization, and task drafting.Text prompts provided by staff (e.g. goals, assessment text snippets). Sensitive client PII should be anonymized by staff prior to input.Global AI API Infrastructure [REQUIRES BUSINESS CONFIRMATION] (Possible [REQUIRES BUSINESS CONFIRMATION])

10. Overseas Disclosure

Core database records and document attachments are stored primarily in Australian data centers where available [REQUIRES BUSINESS CONFIRMATION]. However, certain subprocessors (such as email delivery via Resend, marketing management via Beehiiv, or crash diagnostics via Sentry) process data in servers located in the United States.

Before disclosing personal information to an overseas recipient, we take reasonable steps under APP 8 to ensure the recipient does not breach the Australian Privacy Principles.

11. Data Retention & Deletion

CareLinc retains personal information only for as long as reasonably necessary for the purposes for which it is held, and as required by applicable Australian legal, statutory, health record, and accounting obligations.

When personal information is no longer required, we take reasonable steps to securely destroy or permanently de-identify the information. Specific retention periods for health and financial records are governed by State and Commonwealth legislation [REQUIRES BUSINESS CONFIRMATION].

12. Access and Correction Rights

Under APPs 12 and 13, you have the right to request access to the personal information we hold about you and to request corrections if you believe the information is inaccurate, out-of-date, incomplete, irrelevant, or misleading.

To request access or correction, please submit a written request to our Privacy Officer at privacy@carelinc.com.au. We will respond within a reasonable period (normally within 30 days).

13. Privacy Complaints & OAIC

If you have a concern or complaint about how CareLinc has handled your personal information, please contact our Privacy Officer in writing:

CareLinc Privacy Officer

Email: privacy@carelinc.com.au

Address: 60 Martin Place, Sydney NSW 2000, Australia

If you are not satisfied with our response, you may escalate your complaint to the Office of the Australian Information Commissioner (OAIC):

Website: www.oaic.gov.au | Phone: 1300 363 992

14. Security Incidents & Data Breaches

CareLinc maintains a Security Incident & Data Breach response procedure under the Australian Notifiable Data Breaches (NDB) scheme. In the event of an eligible data breach involving personal information likely to result in serious harm, we will notify affected individuals and the OAIC as required by law.

15. Cookies, Tracking & Analytics

We use cookies and similar browser storage technologies to maintain secure user login sessions, remember user preferences, and analyze website traffic. Users can manage or disable non-essential cookies via our built-in Cookie Preference Banner.

16. AI-Assisted Features

CareLinc includes optional AI copilot and advisory features (e.g. care plan goal drafting suggestions, lead summary drafting). Prompts submitted to AI modules are processed strictly to generate advisory text suggestions. AI suggestions are non-binding drafts and must be reviewed and verified by qualified care coordinators before incorporation into care plans.

17. NDIS, Disability & Aged Care

CareLinc software is designed with operational safeguards tailored to NDIS Quality and Safeguards Commission guidelines and Aged Care Quality Standards, supporting client dignity, choice, control, and privacy protection.

18. Changes & Contact Details

We may update this Privacy Policy from time to time to reflect changes in our software, legal obligations, or business practices. Updated versions will be published on this page with an updated "Effective Date".

Privacy Contact Information

For privacy inquiries, access requests, or privacy complaints:

privacy@carelinc.com.au

60 Martin Place, Sydney NSW 2000, Australia

Notice: This Privacy Policy has been drafted based on CareLinc's current verified application architecture and Australian privacy regulations. It should be reviewed and approved by qualified Australian legal counsel prior to final production publication.