Privacy Policy
Last updated: 5 September 2026
Parkway is operating software for NDIS support providers. It is operated by Parkways Software Pty Ltd (ACN 697 911 890) (“we”, “us”). An ABN will be added here when ABR shows it as Active. This policy explains how we collect, use, disclose and hold personal information through the website at parkways.com.au, the worker, family and coordinator apps, and related services (the “Service”).
We handle personal information under the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) in Schedule 1. Disability support is a health service for the Act (ss 6FA, 6FB), so APP duties apply to health and participant information held in the Service.
Parcare Support Service Pty Ltd (ABN 94 666 356 430, NDIS 4050161227), trading as Parcare Lifestyle, is a related NDIS provider and a customer of the Service. Parcare remains responsible for its own participant, worker and NDIS records. Parkways Software processes that information to run the platform (APP 6). The two companies are not the same legal person.
1. What we collect
1.1 From provider organisations + admin staff
- Name, email, phone, role, employer organisation
- Authentication credentials (hashed; we never see your password)
- Audit log of actions taken in the platform (super-admin viewable only)
1.2 From support workers
- Identity, contact, and emergency contact
- Compliance documents (Blue Card, NDIS Worker Screening, First Aid, CPR, driver's licence, insurance)
- Tax File Number, super fund details, bank account details (payroll)
- Self-declared skills, cultural background (optional), availability
- Geo-location at clock-in/clock-out (Electronic Visit Verification)
- Photo for Worker ID badge (optional)
1.3 From NDIS participants (entered by your provider)
- Identity, contact, NDIS number, plan funding, supports + goals
- Care plan, behaviour support plan, risk assessment
- Medications and clinical observations
- Shift completion notes
- Incidents and feedback
1.4 Automatic technical data
- Browser/device user agent, IP address (request logs only)
- App crash reports and performance metrics
- Web Push subscription endpoints (so we can notify your device)
2. How we use it
- To run your provider organisation's operations (rostering, billing, compliance, payroll)
- To deliver notifications you've opted into (shift invites, credential reminders)
- To produce audit-ready records for the NDIS Quality and Safeguards Commission
- To improve the Service (aggregated, de-identified usage analytics)
We do not sell personal information. We do not use participant or worker data for advertising.
3. Where it's stored and overseas disclosure (APP 8)
Personal information is stored in databases hosted in Sydney, Australia (Supabase, region ap-southeast-2). Files (photos, certificates, signed PDFs) are stored in the same region.
Some sub-processors process information outside Australia (APP 1.4 / APP 8): Anthropic in the United States (AI features), OpenAI in the United States (voice-note transcription), DocuSeal in the United States (e-sign), Resend in the European Union (email). We share only what the feature needs. You consent to that disclosure by using those features.
4. Sub-processors we use
- Supabase: primary database + authentication + storage (AU)
- Vercel: application hosting (AU edge, US for some functions)
- Anthropic: AI text generation (US). Inputs and outputs are not used to train models.
- OpenAI: Whisper transcription when you dictate a voice note (US)
- Sentry: application error and performance monitoring
- Xero: accounting sync when a provider connects their Xero organisation
- Stripe: card billing for Parkway subscriptions
- Resend: transactional email delivery (EU)
- DocuSeal: eSignature for contracts and consent forms (US)
- Twilio: SMS delivery for shift invites (AU)
5. AI features
When you use AI-augmented features (note clean-up, goal-alignment scan, worker chatbot), the relevant data is sent to Anthropic's Claude API for processing. Anthropic does not train its models on the data sent through their API. We do not send AI providers data unrelated to the feature you're using (e.g. the chatbot only sees your own profile + the policy library + your own next shift, not other workers' data).
6. Worker app permissions
The worker app may request these device permissions:
- Location: only at clock-in / clock-out, to confirm you arrived at the participant's address. Location is not tracked between shifts.
- Notifications: to alert you about shift invites, credential renewals, and on-call updates.
- Microphone: when you use the voice-note feature to dictate a completion note. Audio is sent to OpenAI Whisper for transcription; it is not processed only on-device. The transcript is then stored with the note.
- Camera + Photos: when you upload an ID photo or credential scan.
You can revoke any of these in your device settings at any time.
7. Push notifications
We send push notifications via the Web Push standard (or Apple Push Notification service when using the iOS app). You can disable these by revoking notification permission in your browser or device settings.
8. Eligible data breaches (Privacy Act Part IIIC)
If we suspect an eligible data breach, we assess it as soon as practicable and in any case within 30 days (s 26WH). If we have reasonable grounds to believe an eligible data breach has occurred, we prepare a statement for the Australian Information Commissioner (s 26WK) and notify individuals at risk (s 26WL) as soon as practicable. Remedial action that prevents serious harm can take an incident outside the NDB scheme (s 26WF).
NDIS reportable incidents (NDIS Act s 73Z) are a separate duty of the registered provider. A platform security incident is not automatically a Commission reportable. Practice Standards information management (s 12) still applies to how records are kept.
9. How long we keep it
- Active worker + participant records: kept for the duration of engagement + 7 years after (NDIS audit retention requirement)
- Shift notes + clinical records: 7 years (NDIS standard)
- Audit logs: 7 years
- Web Push subscriptions: deleted when you unsubscribe or after 90 days of inactivity
10. Your rights
You can ask us to:
- Access the personal information we hold about you
- Correct anything that's inaccurate
- Delete your data, except where NDIS law requires us to keep it
- Receive a copy of your data
Requests go to hello@parkways.com.au. We respond within 30 days. You can also make an anonymous complaint or speak-up report at /speak-up without giving your name.
11. Security (APP 11)
- All data in transit is TLS-encrypted
- Data at rest is encrypted by Supabase (AES-256)
- Row-level security restricts every query to the requesting org
- Service-role keys are scoped to specific server-side functions only
- Two-factor authentication (TOTP) is optional for most sign-in. A fresh authenticator check is required before money movement (for example bank transfers).
12. Children
The platform is for adult workers and NDIS providers. Information about NDIS participants who are minors is entered by their support provider under their professional and legal duty of care.
13. Automated decisions
From 10 December 2026, APP 1 requires disclosure of kinds of personal information used in substantially automated decisions that have a legal or similarly significant effect. Parkway AI features (form prefill, note quality, incident classification suggestions) assist staff. They do not by themselves make a legally significant decision. This section will be updated if that changes.
14. Changes to this policy
We'll post material changes here with a new “Last updated” date and email registered users at least 7 days before they take effect.
15. Contact
Parkways Software Pty Ltd
ACN 697 911 890
Unit 5/5-7 Cairns Street, Loganholme QLD 4129
Email: hello@parkways.com.au
If you're not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au. For NDIS supports, you can also use /speak-up or complain to the NDIS Quality and Safeguards Commission.
