Privacy Policy
Longstead Privacy Policy Version: 0.2 · Effective date: 6 August 2026
This Privacy Policy explains how CLOUD RESEARCH AND DEVELOPMENT XENTER PTY LTD (ABN 52 677 458 187) (we, us, our) collects, holds, uses and discloses personal information in connection with Longstead (the Service), a compliance and audit-readiness software platform for Australian disability-sector (NDIS) providers.
We take the handling of personal information — especially health and other sensitive information about people with disability — extremely seriously. The Service exists to help providers keep compliant records; handling those records carefully is the core of what we do.
In one paragraph: we host compliance records for NDIS providers, in Australia only, and use them only to run the Service. Providers own and control the records they enter, including records about their workers and participants. We never sell personal information, never use it for advertising, and never use it to train AI models. Some records are kept in tamper-proof storage for legally required retention periods. The rest of this policy is the detail.
1. Who this policy covers, and our role
1.1 The Service is a business-to-business product. Our customers are provider organisations (Customers), not individuals. This policy covers:
- Customer personnel — people at a Customer who hold user accounts (administrators, staff, advisers);
- Workers — a Customer's employees and contractors whose details (such as screening checks and credentials) the Customer records in the Service;
- NDIS participants — people to whom a Customer provides supports, whose details the Customer records in the Service (including consent records, incident records and evidence documents);
- Website visitors and business contacts — people who visit our website, contact us, or deal with us in sales and support.
1.2 Two roles. We handle personal information in two distinct capacities:
- For our own purposes (as the organisation with the direct relationship): account data for Customer personnel, billing and business contact details, website and support interactions. We decide how this information is handled, within this policy.
- As a service provider to the Customer: personal information about workers and participants is collected by the Customer, entered into the Service by the Customer, and handled by us only on the Customer's behalf and at its direction, to provide the Service. The Customer controls what is entered, who at the Customer can see it, and when it is corrected or deleted (subject to the retention rules in section 10).
If you are a worker or participant and have questions about information a provider holds about you in the Service, your first point of contact is that provider — see section 11.
2. The Privacy Act applies to us
We are bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). We do not rely on the small business exemption: because the Service holds health information about individuals (see section 4), the Privacy Act applies to us regardless of our annual turnover, and we treat ourselves as an APP entity in full. Where state or territory health-records laws also apply to information in the Service (for example the Health Records Act 2001 (Vic) for information handled in Victoria), we aim to meet the stricter standard.
3. What we collect
Information we collect for our own purposes:
- Account data — name, work email address, role and organisation of each user; authentication data (we use a managed identity service; we do not see your password); user activity within the Service (see audit logging, section 8).
- Billing and business contact data — organisation name, ABN, contact names, email addresses, phone numbers, billing address, invoice and payment records. We invoice manually and do not collect or store payment card details.
- Support and communications — the content of emails and support requests you send us.
- Enquiry and registration-check data — when a readiness assessment is requested, we collect the organisation's ABN and provider name and check them against our extract of the publicly available NDIS Commission provider register, so that the assessment starts from the organisation's actual registration position. The ABN, the check outcome and the date of the register extract are stored with the enquiry. See section 5.5.
- Website data — limited technical information described in section 13 (Cookies and analytics).
Information Customers enter into the Service (handled on the Customer's behalf):
- Worker records — names, roles, and compliance credentials such as NDIS worker screening check outcomes, qualifications, training records and expiry dates.
- Participant records — names and identifiers, consent records, and records in which participants appear, such as incident records (which may describe injuries or health events), complaint records, and self-assessment or evidence material.
- Evidence documents — files the Customer uploads as compliance evidence (policies, certificates, registers, reports), which may contain personal information about any of the above people.
We collect personal information only when it is reasonably necessary for our functions — providing the Service — and we ask Customers to enter only what they need for their compliance purposes.
4. Sensitive information, including health information
4.1 Records in the Service can include sensitive information as defined in the Privacy Act — most significantly health information about NDIS participants (for example, an incident record describing an injury, or evidence documents referencing a participant's disability or health needs), and worker screening information.
4.2 Our commitments for sensitive information:
- it is collected only as directed by the Customer, for the Customer's compliance and record-keeping purposes — we never solicit it for our own purposes;
- it is never sold;
- it is never used for marketing of any kind, to anyone;
- it is never used to train artificial-intelligence or machine-learning models;
- access within our company is restricted to personnel who need it to operate and support the Service, and access is logged (section 8);
- it is stored only in Australia (section 7).
4.3 Consent. The Customer is responsible for obtaining any consents required to collect and record this information (our terms of service require this of Customers). The Service includes features for Customers to record participant consent; those features record the Customer's consent process — they do not substitute for it.
5. How we collect, and related APP matters
5.1 How we collect. We collect personal information: directly from you (when your organisation is set up, when you use the Service, or when you contact us); from your organisation (when it creates your user account or enters records about you); and automatically through your use of the Service (authentication events and the audit log described in section 8). We do not buy personal information from data brokers or collect it from social media.
5.2 Anonymity and pseudonymity (APP 2). You may browse our public website and make general enquiries anonymously or under a pseudonym. Anonymity is not practicable for the Service itself: user accounts must identify real individuals (this is itself a compliance feature — the audit trail must show who did what), and compliance records necessarily identify the people they are about.
5.3 Unsolicited information (APP 4). If we receive personal information we did not solicit (for example, in an email sent to the wrong address) and we could not have collected it under APP 3, we will destroy or de-identify it as soon as practicable, if it is lawful and reasonable to do so.
5.4 Government identifiers (APP 9). We do not adopt, use or disclose government-related identifiers (such as Medicare or NDIS participant numbers) as our own identifiers for individuals. Where a Customer records such an identifier in the Service, it is held as part of the Customer's records only.
5.5 Register checks. We maintain a copy of the NDIS Commission's public provider register to power our register tools and to check the details given when a readiness assessment is requested. Four things follow from that:
- An ABN identifies a business, but for a sole trader an ABN is personal information under the Privacy Act, and we handle it as such — the same security, access, retention and correction rules apply to it as to any other personal information we hold.
- The register extract is public-source data, refreshed nightly. It can lag the Commission's own record by a day or more, and the Commission's register is the authoritative one. Corrections to a register entry should be directed to the Commission.
- A check result is used only to prepare the assessment and to decide whether we can proceed with one. We do not publish per-provider results from this process, and a check result is never a statement by us that any provider is or is not compliant.
- The ABN and the check outcome are retained on the same schedule as the rest of the enquiry (section 10.5).
6. Why we use personal information
We use personal information only to:
- provide, operate, secure and support the Service (including authentication, tenant isolation, backups and audit logging);
- administer accounts and billing, and communicate with Customers about the Service (service notices, support, invoices, changes to terms);
- comply with our legal obligations, and establish or defend legal claims;
- improve the Service using aggregated, de-identified data from which neither an organisation nor an individual can reasonably be re-identified.
We do not use personal information held in the Service to profile individuals, for advertising, or for any purpose unrelated to providing the Service. We will only send marketing material to business contacts who would reasonably expect it or have opted in, and every such message includes an unsubscribe option.
7. Where information is stored, and cross-border disclosure
7.1 Australia only. All Customer Data and personal information held in the
Service is stored and processed in the AWS Asia Pacific (Sydney) region
(ap-southeast-2), including backups (and any in-country disaster-recovery
replication, which also remains within Australia].
7.2 No overseas disclosure (APP 8). We do not disclose personal information to overseas recipients. Currently, none. If that ever changes, we will update this policy first and, for information handled on a Customer's behalf, obtain the Customer's agreement first.
7.3 CDN caveat. Static, non-personal website assets (application code, stylesheets, images that contain no personal information) may be delivered through a global content delivery network for performance. No personal information or Customer Data is served or cached through the CDN.
7.4 Service providers. We use Amazon Web Services (Australian region) as our hosting provider. The current list of subprocessors is published at https://longstead.com.au/subprocessors/ and available on request. (Email delivery, error monitoring — with residency status; currently none handling Customer Data.] Our service providers may only handle personal information to provide services to us, under contractual obligations consistent with this policy.
8. How we protect information
Security measures include:
- Encryption in transit (TLS) and at rest;
- Tenant isolation — the Service is architected so each Customer's data is logically isolated, with isolation enforced in the data-access layer and verified by automated tests;
- Access controls — role-based access for Customer users; strictly limited, need-based administrative access for our personnel;
- Audit logging — the Service keeps a tamper-evident audit trail of changes to records, and logs access to sensitive records;
- Immutable evidence storage — evidence documents and audit events are kept in write-once storage so they cannot be silently altered;
- Backups and recovery — point-in-time recovery and backups, retained within Australia;
- organisational measures including least-privilege access and security review of changes.
No system is perfectly secure, but we design for the sensitivity of this data and continue to invest in security as the Service grows.
9. Data breaches (Notifiable Data Breaches scheme)
We comply with the Notifiable Data Breaches (NDB) scheme under Part IIIC of the Privacy Act. If we become aware of a suspected eligible data breach we will promptly investigate and contain it, and assess it (within 30 days as required]. If an eligible data breach has occurred, we will notify the Office of the Australian Information Commissioner (OAIC) and affected individuals as required.
For personal information we hold on a Customer's behalf, we will notify the affected Customer without undue delay after becoming aware of a breach affecting its data, and cooperate with the Customer so that individuals are notified appropriately (usually by the Customer, which holds the relationship with its workers and participants) and double-notification is avoided.
You can report a suspected security issue to us at security@longstead.com.au.
10. How long we keep information
10.1 Account and billing data — kept for the life of the Customer relationship and then as needed for legal, accounting and tax purposes (generally up to 7 years for financial records).
10.2 Customer Data, including worker and participant records — kept while the Customer's subscription is active. When a subscription ends, the Customer has an export window, after which we delete or de-identify Customer Data, except as described in 10.3.
10.3 Compliance-record retention. The Service stores records that NDIS legislation and related rules require providers to retain for extended periods — up to 7 years, and in some cases longer. Evidence documents and audit records are held in write-once storage and cannot be altered or deleted before their retention period ends, by design. Where a deletion request (from a Customer, or from an individual via a Customer) applies to such a record, we will honour it subject to the legally required retention period: the record is restricted from ordinary use where practicable, retained solely for record-integrity and legal purposes, and deleted when the period ends.
10.4 Residual copies in encrypted backups are removed in the ordinary backup rotation cycle after deletion.
10.5 Enquiry data, including registration checks — kept while the enquiry is live and then for up to 2 years, so that a returning enquirer is not asked the same questions twice and so we can show why an assessment did or did not proceed. The ABN and register-check outcome recorded with an enquiry (section 5.5) are kept on this schedule and deleted with it. An enquirer may ask us to delete their enquiry sooner — see section 11.
11. Access and correction (APPs 12 and 13)
11.1 Your own dealings with us (Customer personnel, business contacts, website visitors): you may request access to, or correction of, personal information we hold about you by contacting us (section 15). We will respond within a reasonable period (normally within 30 days), and if we refuse a request we will tell you why and how to complain.
11.2 Worker and participant records: these are the Customer's records, which we hold on the Customer's behalf. If you are a worker or participant, please direct access or correction requests to the provider organisation that holds your records — it controls them and is best placed to respond. If you contact us directly about such a record, we will (with your basic details and where we can identify the relevant Customer) refer your request to that Customer and support it in responding. We do not access or alter a Customer's records except at its direction or as required by law.
11.3 Corrections vs. audit history. The Service keeps prior versions of records for audit integrity. Correcting a record updates the current version; the audit trail of what was previously recorded is preserved, as compliance-record rules require. Where a correction is made, the corrected version is the one presented for ordinary use.
12. Disclosure
We disclose personal information only:
- to our service providers listed in section 7.4, to provide the Service;
- to the relevant Customer (that is, back to the organisation whose records they are, and its authorised users);
- where required or authorised by law — for example to a court, or a regulator with compulsory powers. Where lawful, we will notify the affected Customer before disclosing its data in response to a compulsory request, and will disclose the minimum required;
- with consent, or as otherwise permitted by the Privacy Act.
We do not disclose personal information to anyone for their marketing. If our business is reorganised or sold, personal information may be transferred to the successor entity subject to this policy and the residency commitment in section 7.
13. Cookies and analytics
Our applications use only what is needed to run:
- Session/authentication cookies or tokens — required to keep you signed in;
- Minimal first-party analytics — page-view level, no cross-site tracking, hosted in Australia / none at present — confirm final state].
We do not use third-party advertising trackers, social-media pixels, or cross-site tracking of any kind. You can clear cookies in your browser; session cookies are required for the Service to function.
14. Complaints
If you believe we have breached the Privacy Act or mishandled your personal information, please contact us first (section 15) with the details. We will acknowledge your complaint within 7 days, investigate, and respond within 30 days. If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner:
- Web: oaic.gov.au
- Phone: 1300 363 992
- Post: GPO Box 5288, Sydney NSW 2001
If your complaint concerns how an NDIS provider (our Customer) has collected or used your information, the OAIC and, for NDIS-specific conduct, the NDIS Quality and Safeguards Commission may both be relevant avenues.
15. Contact us
Privacy Officer CLOUD RESEARCH AND DEVELOPMENT XENTER PTY LTD (ABN 52 677 458 187) Registered address to be published before launch Email: privacy@longstead.com.au
16. Changes to this policy
We may update this policy from time to time. Material changes will be notified to Customers by email at least 30 days before they take effect, and the current version will always be available at https://longstead.com.au/privacy/, with its effective date. Changes will never reduce the commitments in sections 4 (sensitive information) and 7 (Australian residency) for existing data without the affected Customers' agreement.