Privacy Policy

PurpleCare (ABN 60 201 663 251) · NDIS registered provider · Last updated 24 November 2026 · Version 2.0

  1. Information we collect
  2. Purpose and use
  3. Storage and location
  4. Access controls
  5. SMS consent
  6. Disclosure
  7. Retention periods
  8. Right to access, correction and deletion
  9. Data breach response
  10. Your rights as a participant
  11. Complaints
  12. Contact

PurpleCare is an Australian registered NDIS provider operating a care delivery platform serving participants, support workers and clinicians. This Privacy Policy explains what personal information we collect, how we use it, where it is stored, and your rights under the Australian Privacy Principles (APPs) in the Privacy Act 1988 (Cth), the NDIS Practice Standards, and the Notifiable Data Breaches scheme.

1. Information we collect

2. Purpose and use

We collect personal information only for purposes related to the delivery of NDIS-funded supports and the lawful operation of our business. Specifically:

3. Storage and location

All participant, worker and clinical records are stored in Supabase PostgreSQL hosted in the Australian region (ap-southeast-1, Sydney). Data does not leave Australia for primary storage. Backups are encrypted and held in Australian-region object storage. We use Australian-region compute for the application layer.

Data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Database backups are taken daily and retained for 30 days.

4. Access controls

5. SMS consent

By providing your phone number you consent to receive SMS notifications about shifts, invoices, and account updates from PurpleCare. Reply STOP to opt out at any time.

Standard message and data rates from your carrier may apply. Reply HELP for assistance, or contact support@purplecare.com.au. Opting out of SMS will not affect your access to care services but may delay operational notifications.

6. Disclosure

We disclose personal information only where necessary to deliver services — to assigned support workers and clinicians, to plan managers and the NDIA for billing, to SMS and email delivery providers (including Twilio Inc.), to our hosting (Supabase) and payments providers (Xero), and where required by Australian law.

We do not sell personal information. We do not use personal information for direct marketing without separate consent.

7. Retention periods

Per NDIS Practice Standards, ATO record-keeping rules and the Privacy Act 1988, we retain records for the following minimum periods:

Record typeMinimum retentionBasis
Participant clinical & service records7 years from last serviceNDIS Practice Standards
Worker employment records (incl. payroll)7 yearsFair Work Act / ATO
Incident reports7 yearsNDIS Quality & Safeguards Rules
Financial & tax records5 yearsATO
Consent recordsLife of relationship + 7 yearsAPP 11
Marketing contact recordsUntil you unsubscribeSpam Act 2003
Server logs & technical telemetry90 daysOperational

After the minimum retention period expires, records are securely destroyed unless we are required by law to retain them for longer (for example, ongoing legal proceedings).

8. Right to access, correction and deletion

You have the right to:

To exercise any of these rights, email our Privacy Officer at support@purplecare.com.au. We will respond within 30 days. Admin staff can flag your account for deletion immediately; full erasure occurs at the end of the regulatory retention period.

9. Data breach response

PurpleCare maintains a documented Data Breach Response Plan aligned with the OAIC Notifiable Data Breaches scheme:

  1. Contain: within 24 hours of detection, contain the breach (isolate affected systems, revoke credentials, take systems offline if required).
  2. Assess: within 72 hours, assess severity, scope, individuals affected and likelihood of serious harm.
  3. Notify OAIC and affected individuals: where the breach is likely to result in serious harm, we will notify the OAIC within 30 days of becoming aware (the statutory maximum) and notify affected participants as soon as practicable. We aim to notify within 72 hours where feasible.
  4. Remediate & review: implement permanent fix, update controls, conduct post-incident review.

The full Breach Response Plan is available to staff at /var/www/purplecareos/BREACH_RESPONSE_PLAN.md. Contact the Privacy Officer for a copy.

10. Your rights as a participant

As an NDIS participant, you have additional rights under the NDIS Code of Conduct and the NDIS Quality and Safeguarding Framework:

11. Complaints

If you are not satisfied with how we have handled your personal information, contact our Privacy Officer first. If your concern is not resolved, you may lodge a complaint with:

12. Contact

Privacy Officer, PurpleCare
Email: support@purplecare.com.au
ABN 60 201 663 251 · Queensland, Australia