Draft — pending legal review
This policy is a draft. It was written by our own team, and it has not yet been reviewed by a lawyer. We are publishing it in this state deliberately, because an accurate draft is more use to you than nothing at all while we get it reviewed. Everything in it is our honest description of what our systems actually do, checked against the code and the servers on 23 August 2026. If something here turns out to be wrong, we will correct it and say so. Please tell us at info@leadingwithkindness.com.au.
Privacy Policy
Leading with Kindness Services Pty Ltd · ABN 90 684 056 148 · Last updated 23 August 2026
This policy explains what personal information we collect about you, why we hold it, who else sees it, and — the part most policies leave out — which countries it is held in. You can ask us for a copy in another format, or have it read to you, at no cost.
1. Who we are
Leading with Kindness Services Pty Ltd (ABN 90 684 056 148) is a Queensland company. We deliver NDIS and related supports, and we also build and run CareOS, the portal you are using. Those are the same company, not two.
We treat ourselves as bound by the Australian Privacy Principles in the Privacy Act 1988 (Cth), on the basis that we provide a health service and hold health information (s 6D(4)(b)), so the small-business exemption does not apply to us.
Which organisation this policy is about. CareOS is used by other disability and aged-care providers as well as by us, and several of them are separate companies with their own ABNs. If you are a participant, family member, worker or applicant of one of those providers, they are the organisation that collects and holds your information and decides what happens to it — this policy is not theirs and does not speak for them; ask them for their own. What this policy does tell you, and what applies whichever provider you deal with, is where in the world the information is held and which suppliers can reach it, because we run the platform all of them sit on and we chose those suppliers. In that role we hold their records on their behalf.
2. What we collect and hold
If you are a participant or a person we support: your name, date of birth, contact details and home address; your NDIS number, plan dates, funding and plan manager or support coordinator; your disability, diagnosis and communication needs; your goals, risk assessments, behaviour support plans and any restrictive practice records; your medications, including strength, form, route and prescribing doctor; progress notes written by workers after each shift; incident records; appointments; invoices and budget use; and any files uploaded about you, such as reports, plans and service agreements.
If you are a worker or an applicant: your name, date of birth, contact details and home address; your right-to-work, NDIS Worker Screening, Working with Children (Blue Card), AHPRA registration and other check details and expiry dates, and copies of those certificates; qualifications, skills, languages and availability; your emergency contact; your shifts, timesheets and payslips; and, where we pay you, your tax file number, bank BSB and account, and superannuation fund and member number.
If you are a family member, guardian, nominee or emergency contact: your name, relationship and contact details, and any notes of your involvement in a participant's supports.
Everyone who signs in: your email address, a scrambled version of your password (we never hold the password itself), your session, and an audit record of significant actions you take in the portal.
3. How we collect it
Mostly from you directly — through our onboarding forms, in conversation, or as you use the portal. We also collect it from support workers as they record what happened on a shift; from your plan manager, support coordinator or the NDIA; and, where you have agreed to it, from family members, guardians and treating health professionals. Where it is reasonable and practicable, we collect it from you rather than from someone else.
4. Why we collect, hold and use it
To plan and deliver your supports and keep them safe; to roster and pay workers; to invoice the NDIS, your plan manager or you; to keep the clinical and incident record that the NDIS Practice Standards require; to report incidents and restrictive practices where the law requires; to handle complaints and feedback; to check that workers hold current screening and registration; to meet our obligations under tax, work health and safety and employment law; and to establish or defend a legal claim if one is ever made.
Some features of the portal use artificial intelligence to draft text for a person to review — for example drafting a progress note, summarising a participant's recent notes, or flagging that something in a note might be an incident. No AI output becomes part of your record until a person reads it and approves it. Section 5 sets out what leaves our systems when those features are used, and this is not theoretical: our own usage log recorded 23 such calls as at 23 August 2026.
5. Where your information is held, and who else touches it
None of our infrastructure is in Australia today. Your records are held in Tokyo, Japan. That was a decision about speed, made when the system was built, and not a considered judgement about your records. We have decided in principle to move it to Australia and are preparing that migration; it has not happened yet, and we will tell you before it does.
The table below lists every organisation that receives personal information from this product as it stands today, what they get, and where they are. Where we could not establish a country, it says so — we would rather tell you we do not know than name a country we have not checked.
| Who | What they receive | Where they are |
|---|---|---|
| Supabase (running on Amazon Web Services) | The database itself and the files you upload — every participant record, progress note, incident, medication entry, roster, invoice and identity or screening document, plus the daily backups. | Tokyo, Japan (AWS ap-northeast-1). Confirmed with Supabase directly on 23 August 2026. |
| Vercel | The application servers. Every page you load and every action you take passes through their memory, so anything you can see on screen passes through here. | Tokyo, Japan (Vercel hnd1), set in our own configuration. |
| Resend | Outbound email. This includes incident notification emails, which carry the incident description, the immediate action taken, follow-up, witnesses and the participant’s name, with the incident PDF attached; invoice emails naming the participant; and payslip emails naming the worker. | The United States. Resend states that all account data, email metadata, logs and API records are held in the United States whichever sending region is chosen. |
| Anthropic (Claude) | Only where a staff member uses an AI feature. Depending on the feature this can include a participant’s name, NDIS number, disability or diagnosis, communication needs, medications with strength, form, route and prescriber, incident narrative, and the full text of progress notes. | Not established. We asked the question and could not answer it from our own systems, and we are pursuing it with Anthropic. We cannot tell you this stays in Australia. |
| Groq | Only where a worker dictates a note or an incident by voice: the raw audio recording, which is a support worker speaking aloud about a named person. | The United States. Groq states all customer data is retained in Google Cloud Platform buckets in the United States, that it does not retain inference data by default, and that reliability and abuse logs are kept for up to 30 days. |
| OpenStreetMap (Nominatim) | A participant’s home address, to turn it into map coordinates. Before it is sent we cut it back to the postal address alone: anything after a semicolon or a new line, anything in brackets, any email address or phone number typed into the field, and the unit or apartment number, are all removed. The coordinates are stored in our own database and re-used, so a map being drawn sends nothing. The address itself is sent again each time it is saved, and each time an address that did not resolve is retried — we are changing that so each distinct address is sent once, and this page will say so when it is. This is a free public service; we have no account and no contract with it. | Not established. It is a public endpoint served from more than one country and we cannot name a single one honestly. |
| CareCircle | Only where a participant links a CareCircle account: we send the eight-character consent code and nothing else, and receive that participant’s care snapshot back. | The United States (AWS us-east-1). Confirmed directly on 23 August 2026. |
| Open-Meteo | The weather badge on the schedule board. Coordinates only, rounded to about one kilometre, or the state capital when we have no coordinates. No address and no name is sent. | Not established. Public endpoint, no contract. |
| Google (Fonts) | Every page of this portal loads its typefaces from Google. That request carries your device’s IP address, your browser identification and the address of the page you are on — for every user, on every page, including participants and family members. It carries no record content. | Not established. Content-delivery network, served from whichever country is nearest. |
| Microsoft | Only where a staff member previews a Word, Excel or PowerPoint file from the organisation resource library: we hand Microsoft a link that works for five minutes and Microsoft’s servers fetch the file to render it. This affects organisation resource files, not the participant record. | Not established. |
We also share information with people involved in your supports in the ordinary way: your plan manager, your support coordinator, the workers rostered to you, treating health professionals you have agreed we can talk to, and your nominated family members or guardian. We give information to the NDIS Quality and Safeguards Commission, the NDIA, the Office of the Health Ombudsman, police or child safety authorities where the law requires it or where someone is at risk of harm. Our accountant and auditor may see financial records. Our source code is hosted with GitHub; that is the software, not the care record.
Some optional connections — accounting software, messaging, customer-relationship tools — can be switched on by an organisation using CareOS. As at 23 August 2026 no organisation has any of them switched on, and we checked rather than assumed. If that changes for your organisation, this policy will be updated before it does.
6. Overseas — whether, and which countries
Yes. We are likely to disclose your personal information, including health information, to recipients outside Australia. That is not a possibility we are flagging for completeness; it is how the system runs every day.
The countries we can name are:
- Japan — the database, the uploaded files and the backups (Supabase on AWS in Tokyo), and the application servers that process every request (Vercel in Tokyo). This is everything.
- United States — email (Resend), voice transcription where a worker dictates (Groq), and the CareCircle service where a participant has linked one.
For three recipients we cannot honestly name a country: Anthropic, whose processing location we have asked about and do not yet know; and OpenStreetMap, Open-Meteo, Google Fonts and the Microsoft document viewer, which are public services delivered from whichever country is nearest to the person making the request. We are not able to specify those countries, and we are not going to guess.
We do not rely on the “prescribed country” exception in Australian Privacy Principle 8.3: we have not established that any country or binding scheme has been prescribed for that purpose, so we do not treat any of these recipients as covered by it. We take responsibility for them under s 16C of the Privacy Act 1988 (Cth) as though their handling of your information were our own.
7. What we have not been able to establish
These are open questions with our suppliers, not answers we are keeping from you. We will update this policy when we have them.
- Which country Anthropic processes AI requests in.
- How long Resend keeps the body and attachments of an email, as distinct from the account records it says are held in the United States.
- Whether the sending of a participant's address to OpenStreetMap can be reduced to a suburb and postcode without breaking the map. We think it can, and we are working on it.
8. How we protect it
Access to the portal requires a password. Every record belongs to one organisation and the database refuses to return another organisation's records, enforced in the database itself rather than only in the application. What each person can see depends on their role. Significant actions are written to an audit trail. Connections are encrypted in transit, and uploaded identity papers and reports sit in private storage that can only be opened through a signed link that expires.
We will not overstate this. We are a small provider, our infrastructure is offshore as described above, and we are not claiming any security certification here. The people who run the platform hold administrative access that can reach records across organisations; that is how the system is repaired and supported, and it is kept to as few people as possible. If we have a data breach that is likely to cause you serious harm, we are required to tell you and the Office of the Australian Information Commissioner, and we will.
9. How long we keep it
CareOS does not delete anything automatically. That is deliberate, because several kinds of record must be kept by law for years, and because a record destroyed early cannot be recovered for a person who later needs it. The floors we work to are:
| Minimum | Record | Required by |
|---|---|---|
| 7 years | Incident records, from the day the record is made | NDIS (Incident Management and Reportable Incidents) Rules 2018 (Cth) ss 12(4), 25(2) |
| 7 years | Restrictive practice records, from the day the record is made | NDIS (Restrictive Practices and Behaviour Support) Rules 2018 (Cth) s 15(3) |
| 7 years | Complaints records, from the day the record is made | NDIS (Complaints Management and Resolution) Rules 2018 (Cth) s 10(3) |
| 7 years | Worker screening records, from the date the record is made | NDIS (Practice Standards—Worker Screening) Rules 2018 (Cth) ss 20, 21 |
| 7 years | Employee records | Fair Work Act 2009 (Cth) s 535(1) |
| 7 years | Company financial records, after the transactions they cover are completed | Corporations Act 2001 (Cth) s 286(2) |
| 3 years | All of the above, again, if we ever cease to be a registered NDIS provider — counted from the day we cease | National Disability Insurance Scheme Act 2013 (Cth) s 73R |
Beyond those floors, Australian Privacy Principle 11.2 requires us to destroy or de-identify personal information once we no longer need it for any purpose we are permitted to use it for and no law requires us to keep it. Where a claim could still be brought — and for claims arising from abuse of a person when they were a child, Queensland law sets no time limit at all (Limitation of Actions Act 1974 (Qld) s 11A) — we may need to keep a record for a long time. If you want to know what we hold about you and why, ask us and we will tell you.
10. Getting a copy, and getting it corrected
You can ask for a copy of the personal information we hold about you, and you can ask us to correct anything that is wrong, out of date or misleading. Email info@leadingwithkindness.com.au and tell us what you need. It costs nothing to ask. We aim to respond within 30 days. If we cannot give you access, or we do not agree that something is wrong, we will tell you why in writing and note your view on the record.
You can also ask us not to be identified, or to use a pseudonym, when you deal with us. For most support delivery that is not practical — we cannot claim NDIS funding or keep a safe clinical record for an anonymous person — but for a general enquiry it usually is, and you are entitled to ask.
11. If you are unhappy with how we handled your information
Tell us first, at info@leadingwithkindness.com.au. We will acknowledge your complaint, look into it, and write back to you with what we found and what we are doing about it. Tell us if you want someone to help you make the complaint, or if you would rather make it another way.
If you are not satisfied with our answer, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au. Complaints about the quality or safety of NDIS supports can go to the NDIS Quality and Safeguards Commission on 1800 035 544. You do not have to come to us first, and using our complaints process does not stop you going to them.
12. Changes to this policy
We will update this page when what we do changes — in particular if we move our servers to Australia, if we add or remove an AI or email supplier, or if an organisation switches on one of the optional connections in section 5. The date at the top is the date of the current version.
13. Contact us
Leading with Kindness Services Pty Ltd, ABN 90 684 056 148 — info@leadingwithkindness.com.au. If you need this policy in Easy Read, in another language, or read aloud, ask us and we will arrange it.
Draft, again, because it matters: this policy has not been reviewed by a lawyer. It is published so that you can see where your information actually goes while that review is arranged, and so that you can tell us if we have any of it wrong.