My Care CRM
  • Features
    Participant Management Employee Management Employee App Scheduling & Rostering
  • Integrations
    Xero SIPcity
  • Ecosystem
    AcadeMy Care DocuCare
  • Pricing
  • Resources
    Blog Free Tools Support
  • Contact
Book a Demo
Features Participant Management Employee Management Employee App Scheduling & Rostering Integrations Xero SIPcity Ecosystem AcadeMy Care DocuCare Pricing Blog Free Tools Support Contact Book a Demo

Privacy Policy

Last updated: 18 June 2026

My Care CRM Pty Ltd (ACN 667 597 659) is committed to protecting your privacy and handling your personal information in accordance with Australian privacy laws and the NDIS Practice Standards.

1. Protecting your Privacy

This privacy statement provides information about the Personal Information that we collect, how that information is stored and the ways in which we use that Personal Information.

Your privacy is important to us. We comply with the Privacy Act 1988 (Privacy Act) when we handle Personal Information. The Privacy Act contains 13 Australian Privacy Principles (APPs) which provide the rules for how we must handle your Personal Information, including how you can request access to, and correction of, that information. Detailed information on the Privacy Act and the APPs can be found on the website of the Office of the Australian Information Commissioner (OAIC).

As the provider of a software service for NDIS supporters and participants, we also comply with the NDIS Practice Standards. Your Personal Information will be handled in line with the NDIS Practice Standards, a copy of which can be found on the NDIS Commission website.

By accessing and using our Software and Website, you agree to the terms of this Privacy Policy along with our Terms and Conditions, a copy of which can be found at End User License Agreement.

We will only use or disclose Personal Information we hold about you in accordance with this Privacy Policy or as otherwise notified to you.

2. Meaning of Words

In this Privacy Policy:

  • "App" means any of the My Care CRM applications provided by My Care CRM Pty Ltd (ACN 667 597 659) and as downloaded and accessed by you, including any amendments as made by us from time to time.
  • "Personal Information" is information about an individual that either directly identifies that individual or can be used to ascertain that individual's identity. It includes information and opinions obtained from the individual or from a third party.
  • "Software" means one or more of the My Care CRM software products provided by My Care CRM Pty Ltd (ACN 667 597 659) and as accessed and used by you via the Website or by downloading our App, including any amendments as made by us from time to time. These products include, but are not limited to, My Care CRM, DocuCare, CareWolf ai and AcadeMy Care.
  • "you" refers to any individual or entity which uses the Software and Website;
  • "we", "us" and "our" refers to My Care CRM Pty Ltd (ACN 667 597 659);
  • "Website" means https://mycarecrm.com.au or any website that we own or maintain to which these terms apply; and
  • the singular includes the plural and vice versa.

3. Your Personal Information

When you use the Website, your Personal Information is collected and held by us and may be disclosed to third parties in accordance with clause 6 of this Privacy Policy.

Your Personal Information that is collected via the Software and Website must be collected and held in accordance with this Privacy Policy.

At or before the time (or, if that is not practicable, as soon as practicable after) we collect Personal Information, we will take steps to ensure that you are aware of:

  • our identity and contact details;
  • the facts and circumstances of collection of your Personal Information;
  • the purposes for which the Personal Information is collected;
  • the fact that you are able to gain access to the Personal Information;
  • to whom we usually disclose Personal Information of the type collected;
  • information about our Privacy Policy;
  • any law that requires the particular Personal Information to be collected; and
  • the main consequences (if any) if all or part of the Personal Information that is not provided.

4. What Information is Collected About You

When you enquire about our services or when you become a client of ours, a record is made which includes your Personal Information.

The type of Personal Information that we collect will vary depending on the circumstances of collection and the kind of service that you request from us, but will typically include:

  • your name, e-mail and other contact details;
  • your profile image;
  • the reason for your request;
  • information about your employer or an organisation who you represent;
  • your professional details (including credentials and qualifications);
  • your location data, login credentials and activity logs;
  • electronic signature data, including cryptographic seals, digital signatures and consent records;
  • audit-trail data generated during the electronic signing process, which may include IP addresses (which may indicate approximate location), device and browser information, and timestamps;
  • one-time password (OTP) verification data and the email address or phone number used to authenticate signers;
  • information entered by signers directly into document fields during the electronic signing process, which may include personal details such as names, addresses, contact information, preferences, and any other data requested by the document template; and
  • any additional Personal Information you provide to us, or authorise us to collect, as part of your interaction with us.

5. How your Personal Information is Used

We do not ordinarily collect any information about you except where you provide it to us, or it is provided to us with your consent. In general, we do not use or disclose Personal Information collected about you other than for:

  • a purpose set out in this Privacy Policy;
  • a purpose you would reasonably expect;
  • a purpose required or permitted by law; or
  • a purpose otherwise disclosed to you or for which you have consented.

Your Personal Information may be used by us to:

  • verify your identity;
  • add you to our mailing list;
  • price and design products and services;
  • assist you to subscribe to products and services;
  • provide the products and services you require;
  • provide you access to the Software;
  • notify you of new or changed services;
  • arrange for the products and services you require to be provided by third party service providers;
  • manage our relationship with you;
  • responding to enquiries and complaints;
  • administer, improve and manage our products and services;
  • conduct appropriate checks for credit-worthiness and for fraud;
  • research and develop our products and services;
  • gain an understanding of your needs in order to provide you with a better service and products;
  • assist with the resolution of technical support issues or other issues relating to the Software and our services and products;
  • carry out marketing or training;
  • comply with the laws and regulations in applicable jurisdictions;
  • facilitate the electronic execution of documents via DocuCare and DocuCare Studio;
  • generate, maintain and verify tamper-evident audit trails and cryptographic seals for electronically signed documents;
  • authenticate the identity of individuals signing documents to support the legal integrity and non-repudiation of executed agreements; and
  • maintain and develop our systems and infrastructure.

6. Disclosures of Personal Information

We may exchange your information with other entities forming part of the same corporate group as us. We and our related entities may use this information for any of the purposes mentioned in clause 5.

We may also disclose Personal Information about you, as appropriate, to:

  • our volunteers, employees, assignees, agents, referred service providers, contractors and external advisers;
  • your agents, advisers, referees, executor, administrator, trustee, the beneficiary of any trust of which you are a trustee, your guardian, attorney or franchisor;
  • law enforcement, regulatory and government bodies;
  • anyone who introduces you to us;
  • yours and our auditors, insurers or prospective insurers and their underwriters;
  • any person we consider necessary to execute your instructions; and
  • other organisations (and their agents) with whom we have arrangements for the supply and marketing of our respective products and services, unless you 'opt out' of marketing (see below).

From time to time we may send your information overseas, including to overseas service providers or other third parties who operate or hold data outside Australia. Where we do this, we make sure that appropriate data handling and security arrangements are in place. Please note that Australian law may not apply to some of these entities. Please note that we never share Participant data to ensure that we comply with the NDIS participant privacy requirements.

7. How do we hold your Information

We maintain security practices aligned with the ISO 27001:2022 framework to help ensure the confidentiality, integrity, and availability of information assets, particularly NDIS participant data. We take reasonable steps to protect your Personal Information from misuse, interference and loss and from unauthorised access, modification or disclosure.

We store your information in our Software, paper-based files or other electronic record keeping methods in secure databases. Personal Information may be collected in paper-based documents and converted to electronic form for use or storage (with the original paper-based documents either archived or securely destroyed). We take reasonable steps to protect your Personal Information from misuse, interference and loss and from unauthorised access, modification or disclosure.

We maintain physical security over paper and electronic data stores, such as through locks and security systems at our premises. We also maintain computer and network security, for example, we use firewalls (security measures for the internet) and other security systems such as user identifiers and passwords to control access to our computer systems.

Our Website does not necessarily use encryption or other technologies to ensure the secure transmission of information via the internet. Users of our websites such as yourself are encouraged to exercise care in sending Personal Information via the internet.

When your account with us is active, we take steps to destroy or de-identify information that we no longer require as and when necessary. If your account is terminated or suspended for non-payment, we manage your information in accordance with the lifecycle and export periods defined in our End User Licence Agreement. Upon expiration of the final export period, unless you have elected to transition to a paid archive arrangement, we will permanently destroy or de-identify your information, unless we are otherwise required by law to continue storing it.

Electronic signature and audit-trail retention. Where you or your clients use DocuCare to electronically sign documents, we generate and securely store cryptographic seals and audit trails (including IP addresses, timestamps and authentication logs). This data is inextricably linked to the executed document to preserve its legal integrity, tamper-evidence and compliance with the Electronic Transactions Act 1999 (Cth) and the NDIS Practice Standards. It is held within Australia and retained alongside the signed document for as long as the document is stored on the Platform, subject to the same security protocols and Australian data-sovereignty requirements as all other NDIS participant data we hold.

8. Marketing 'opt out'

If at any time you do not wish to receive further marketing information, you may ask us not to send you any further information about services and not to disclose your information to other organisations for that purpose. You may do this by contacting us at [email protected].

9. Personal Information about Third Parties

If you provide us Personal Information about another person, you represent that you are authorised to do so and you agree to inform that person who we are, that we will use and disclose their Personal Information and that they may access any Personal Information we hold about them. You should also refer them to this Privacy Policy which applies to their Personal Information.

10. Maintaining the Accuracy of your Information

We take all reasonable precautions to ensure that the Personal Information we collect, use and disclose is accurate, complete and up-to-date.

If you believe that Personal Information that we hold about you is inaccurate, incomplete or out of date, please contact us at [email protected] and we will take all reasonable steps to correct the information.

11. Accessing your Personal Information

You have a right to access your Personal Information, subject to some exceptions allowed by law. If you would like to do so, please let us know by contacting us at [email protected]. You may be required to put your request in writing for security reasons. We may also charge a fee for giving you access to your Personal Information and will try to deal with your request within a reasonable time.

12. Security and the Internet

We maintain security practices aligned with the ISO 27001:2022 framework to ensure the confidentiality, integrity, and availability of all information assets, particularly NDIS participant data.

We maintain strict procedures and standards and take all reasonable steps to prevent unauthorised access to, or unauthorised modification or disclosure of, your Personal Information and to protect it from misuse or loss.

We prioritise Australian-based providers, however some employee data may be securely processed by overseas providers. Please note that we securely store NDIS participant data in Australia and do not share or store this data with overseas entities, to ensure that we comply with the NDIS participant privacy requirements.

However, we do not guarantee that information sent over the internet is secure. We encourage users to exercise caution when sharing their Personal Information over the internet.

13. Cookies on our Website and Software

We may use cookies on our Website and Software. A cookie is an industry standard and is a small text file that our Website or Software may place on your device(s). Usually, cookies are used as a means for software applications to remember your preferences. As such, cookies are designed to improve your experience of the applications.

Cookies may collect and store Personal Information about you. We extend the same privacy protection to your Personal Information, whether gathered via cookies or from other sources. You can adjust your device settings to disable cookies or to warn you when cookies are being used, however this may affect the availability and functionality of the services offered through the Website or Software.

14. Changes to this Privacy Policy

This statement sets out our current Privacy Policy. It replaces any other Privacy Policy which we have previously issued.

We may amend this Privacy Policy at any time. Our current Privacy Policy is available from our website or by contacting [email protected].

15. Contacting us

If you have any questions regarding this Privacy Policy please contact us at [email protected].

My Care CRM

The complete NDIS provider platform. Australian owned and operated.

FB LI YT

Product

  • Features
  • Pricing
  • Security

Ecosystem

  • AcadeMy Care
  • DocuCare

Resources

  • Blog
  • Free Tools
  • Support

Legal

  • Privacy Policy
  • Terms of Service
  • Contact

Compare

  • Best NDIS Software Australia
  • Switch from ShiftCare
  • Switch from Nightingale
  • Switch from Care Master
  • NDIS Compliance Software

© 2026 My Care CRM Pty Ltd. All rights reserved.

Australian Owned & Operated