Last updated: 18 June 2026
My Care CRM Pty Ltd (ACN 667 597 659) is committed to protecting your privacy and handling your personal information in accordance with Australian privacy laws and the NDIS Practice Standards.
This privacy statement provides information about the Personal Information that we collect, how that information is stored and the ways in which we use that Personal Information.
Your privacy is important to us. We comply with the Privacy Act 1988 (Privacy Act) when we handle Personal Information. The Privacy Act contains 13 Australian Privacy Principles (APPs) which provide the rules for how we must handle your Personal Information, including how you can request access to, and correction of, that information. Detailed information on the Privacy Act and the APPs can be found on the website of the Office of the Australian Information Commissioner (OAIC).
As the provider of a software service for NDIS supporters and participants, we also comply with the NDIS Practice Standards. Your Personal Information will be handled in line with the NDIS Practice Standards, a copy of which can be found on the NDIS Commission website.
By accessing and using our Software and Website, you agree to the terms of this Privacy Policy along with our Terms and Conditions, a copy of which can be found at End User License Agreement.
We will only use or disclose Personal Information we hold about you in accordance with this Privacy Policy or as otherwise notified to you.
In this Privacy Policy:
When you use the Website, your Personal Information is collected and held by us and may be disclosed to third parties in accordance with clause 6 of this Privacy Policy.
Your Personal Information that is collected via the Software and Website must be collected and held in accordance with this Privacy Policy.
At or before the time (or, if that is not practicable, as soon as practicable after) we collect Personal Information, we will take steps to ensure that you are aware of:
When you enquire about our services or when you become a client of ours, a record is made which includes your Personal Information.
The type of Personal Information that we collect will vary depending on the circumstances of collection and the kind of service that you request from us, but will typically include:
We do not ordinarily collect any information about you except where you provide it to us, or it is provided to us with your consent. In general, we do not use or disclose Personal Information collected about you other than for:
Your Personal Information may be used by us to:
We may exchange your information with other entities forming part of the same corporate group as us. We and our related entities may use this information for any of the purposes mentioned in clause 5.
We may also disclose Personal Information about you, as appropriate, to:
From time to time we may send your information overseas, including to overseas service providers or other third parties who operate or hold data outside Australia. Where we do this, we make sure that appropriate data handling and security arrangements are in place. Please note that Australian law may not apply to some of these entities. Please note that we never share Participant data to ensure that we comply with the NDIS participant privacy requirements.
We maintain security practices aligned with the ISO 27001:2022 framework to help ensure the confidentiality, integrity, and availability of information assets, particularly NDIS participant data. We take reasonable steps to protect your Personal Information from misuse, interference and loss and from unauthorised access, modification or disclosure.
We store your information in our Software, paper-based files or other electronic record keeping methods in secure databases. Personal Information may be collected in paper-based documents and converted to electronic form for use or storage (with the original paper-based documents either archived or securely destroyed). We take reasonable steps to protect your Personal Information from misuse, interference and loss and from unauthorised access, modification or disclosure.
We maintain physical security over paper and electronic data stores, such as through locks and security systems at our premises. We also maintain computer and network security, for example, we use firewalls (security measures for the internet) and other security systems such as user identifiers and passwords to control access to our computer systems.
Our Website does not necessarily use encryption or other technologies to ensure the secure transmission of information via the internet. Users of our websites such as yourself are encouraged to exercise care in sending Personal Information via the internet.
When your account with us is active, we take steps to destroy or de-identify information that we no longer require as and when necessary. If your account is terminated or suspended for non-payment, we manage your information in accordance with the lifecycle and export periods defined in our End User Licence Agreement. Upon expiration of the final export period, unless you have elected to transition to a paid archive arrangement, we will permanently destroy or de-identify your information, unless we are otherwise required by law to continue storing it.
Electronic signature and audit-trail retention. Where you or your clients use DocuCare to electronically sign documents, we generate and securely store cryptographic seals and audit trails (including IP addresses, timestamps and authentication logs). This data is inextricably linked to the executed document to preserve its legal integrity, tamper-evidence and compliance with the Electronic Transactions Act 1999 (Cth) and the NDIS Practice Standards. It is held within Australia and retained alongside the signed document for as long as the document is stored on the Platform, subject to the same security protocols and Australian data-sovereignty requirements as all other NDIS participant data we hold.
If at any time you do not wish to receive further marketing information, you may ask us not to send you any further information about services and not to disclose your information to other organisations for that purpose. You may do this by contacting us at [email protected].
If you provide us Personal Information about another person, you represent that you are authorised to do so and you agree to inform that person who we are, that we will use and disclose their Personal Information and that they may access any Personal Information we hold about them. You should also refer them to this Privacy Policy which applies to their Personal Information.
We take all reasonable precautions to ensure that the Personal Information we collect, use and disclose is accurate, complete and up-to-date.
If you believe that Personal Information that we hold about you is inaccurate, incomplete or out of date, please contact us at [email protected] and we will take all reasonable steps to correct the information.
You have a right to access your Personal Information, subject to some exceptions allowed by law. If you would like to do so, please let us know by contacting us at [email protected]. You may be required to put your request in writing for security reasons. We may also charge a fee for giving you access to your Personal Information and will try to deal with your request within a reasonable time.
We maintain security practices aligned with the ISO 27001:2022 framework to ensure the confidentiality, integrity, and availability of all information assets, particularly NDIS participant data.
We maintain strict procedures and standards and take all reasonable steps to prevent unauthorised access to, or unauthorised modification or disclosure of, your Personal Information and to protect it from misuse or loss.
We prioritise Australian-based providers, however some employee data may be securely processed by overseas providers. Please note that we securely store NDIS participant data in Australia and do not share or store this data with overseas entities, to ensure that we comply with the NDIS participant privacy requirements.
However, we do not guarantee that information sent over the internet is secure. We encourage users to exercise caution when sharing their Personal Information over the internet.
We may use cookies on our Website and Software. A cookie is an industry standard and is a small text file that our Website or Software may place on your device(s). Usually, cookies are used as a means for software applications to remember your preferences. As such, cookies are designed to improve your experience of the applications.
Cookies may collect and store Personal Information about you. We extend the same privacy protection to your Personal Information, whether gathered via cookies or from other sources. You can adjust your device settings to disable cookies or to warn you when cookies are being used, however this may affect the availability and functionality of the services offered through the Website or Software.
This statement sets out our current Privacy Policy. It replaces any other Privacy Policy which we have previously issued.
We may amend this Privacy Policy at any time. Our current Privacy Policy is available from our website or by contacting [email protected].
If you have any questions regarding this Privacy Policy please contact us at [email protected].