Longstead

Privacy Policy

Longstead Privacy Policy Version: 0.2 · Effective date: 6 August 2026

This Privacy Policy explains how CLOUD RESEARCH AND DEVELOPMENT XENTER PTY LTD (ABN 52 677 458 187) (we, us, our) collects, holds, uses and discloses personal information in connection with Longstead (the Service), a compliance and audit-readiness software platform for Australian disability-sector (NDIS) providers.

We take the handling of personal information — especially health and other sensitive information about people with disability — extremely seriously. The Service exists to help providers keep compliant records; handling those records carefully is the core of what we do.

In one paragraph: we host compliance records for NDIS providers, in Australia only, and use them only to run the Service. Providers own and control the records they enter, including records about their workers and participants. We never sell personal information, never use it for advertising, and never use it to train AI models. Some records are kept in tamper-proof storage for legally required retention periods. The rest of this policy is the detail.

1. Who this policy covers, and our role

1.1 The Service is a business-to-business product. Our customers are provider organisations (Customers), not individuals. This policy covers:

1.2 Two roles. We handle personal information in two distinct capacities:

If you are a worker or participant and have questions about information a provider holds about you in the Service, your first point of contact is that provider — see section 11.

2. The Privacy Act applies to us

We are bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). We do not rely on the small business exemption: because the Service holds health information about individuals (see section 4), the Privacy Act applies to us regardless of our annual turnover, and we treat ourselves as an APP entity in full. Where state or territory health-records laws also apply to information in the Service (for example the Health Records Act 2001 (Vic) for information handled in Victoria), we aim to meet the stricter standard.

3. What we collect

Information we collect for our own purposes:

Information Customers enter into the Service (handled on the Customer's behalf):

We collect personal information only when it is reasonably necessary for our functions — providing the Service — and we ask Customers to enter only what they need for their compliance purposes.

4. Sensitive information, including health information

4.1 Records in the Service can include sensitive information as defined in the Privacy Act — most significantly health information about NDIS participants (for example, an incident record describing an injury, or evidence documents referencing a participant's disability or health needs), and worker screening information.

4.2 Our commitments for sensitive information:

4.3 Consent. The Customer is responsible for obtaining any consents required to collect and record this information (our terms of service require this of Customers). The Service includes features for Customers to record participant consent; those features record the Customer's consent process — they do not substitute for it.

5. How we collect, and related APP matters

5.1 How we collect. We collect personal information: directly from you (when your organisation is set up, when you use the Service, or when you contact us); from your organisation (when it creates your user account or enters records about you); and automatically through your use of the Service (authentication events and the audit log described in section 8). We do not buy personal information from data brokers or collect it from social media.

5.2 Anonymity and pseudonymity (APP 2). You may browse our public website and make general enquiries anonymously or under a pseudonym. Anonymity is not practicable for the Service itself: user accounts must identify real individuals (this is itself a compliance feature — the audit trail must show who did what), and compliance records necessarily identify the people they are about.

5.3 Unsolicited information (APP 4). If we receive personal information we did not solicit (for example, in an email sent to the wrong address) and we could not have collected it under APP 3, we will destroy or de-identify it as soon as practicable, if it is lawful and reasonable to do so.

5.4 Government identifiers (APP 9). We do not adopt, use or disclose government-related identifiers (such as Medicare or NDIS participant numbers) as our own identifiers for individuals. Where a Customer records such an identifier in the Service, it is held as part of the Customer's records only.

5.5 Register checks. We maintain a copy of the NDIS Commission's public provider register to power our register tools and to check the details given when a readiness assessment is requested. Four things follow from that:

6. Why we use personal information

We use personal information only to:

We do not use personal information held in the Service to profile individuals, for advertising, or for any purpose unrelated to providing the Service. We will only send marketing material to business contacts who would reasonably expect it or have opted in, and every such message includes an unsubscribe option.

7. Where information is stored, and cross-border disclosure

7.1 Australia only. All Customer Data and personal information held in the Service is stored and processed in the AWS Asia Pacific (Sydney) region (ap-southeast-2), including backups (and any in-country disaster-recovery replication, which also remains within Australia].

7.2 No overseas disclosure (APP 8). We do not disclose personal information to overseas recipients. Currently, none. If that ever changes, we will update this policy first and, for information handled on a Customer's behalf, obtain the Customer's agreement first.

7.3 CDN caveat. Static, non-personal website assets (application code, stylesheets, images that contain no personal information) may be delivered through a global content delivery network for performance. No personal information or Customer Data is served or cached through the CDN.

7.4 Service providers. We use Amazon Web Services (Australian region) as our hosting provider. The current list of subprocessors is published at https://longstead.com.au/subprocessors/ and available on request. (Email delivery, error monitoring — with residency status; currently none handling Customer Data.] Our service providers may only handle personal information to provide services to us, under contractual obligations consistent with this policy.

8. How we protect information

Security measures include:

No system is perfectly secure, but we design for the sensitivity of this data and continue to invest in security as the Service grows.

9. Data breaches (Notifiable Data Breaches scheme)

We comply with the Notifiable Data Breaches (NDB) scheme under Part IIIC of the Privacy Act. If we become aware of a suspected eligible data breach we will promptly investigate and contain it, and assess it (within 30 days as required]. If an eligible data breach has occurred, we will notify the Office of the Australian Information Commissioner (OAIC) and affected individuals as required.

For personal information we hold on a Customer's behalf, we will notify the affected Customer without undue delay after becoming aware of a breach affecting its data, and cooperate with the Customer so that individuals are notified appropriately (usually by the Customer, which holds the relationship with its workers and participants) and double-notification is avoided.

You can report a suspected security issue to us at security@longstead.com.au.

10. How long we keep information

10.1 Account and billing data — kept for the life of the Customer relationship and then as needed for legal, accounting and tax purposes (generally up to 7 years for financial records).

10.2 Customer Data, including worker and participant records — kept while the Customer's subscription is active. When a subscription ends, the Customer has an export window, after which we delete or de-identify Customer Data, except as described in 10.3.

10.3 Compliance-record retention. The Service stores records that NDIS legislation and related rules require providers to retain for extended periods — up to 7 years, and in some cases longer. Evidence documents and audit records are held in write-once storage and cannot be altered or deleted before their retention period ends, by design. Where a deletion request (from a Customer, or from an individual via a Customer) applies to such a record, we will honour it subject to the legally required retention period: the record is restricted from ordinary use where practicable, retained solely for record-integrity and legal purposes, and deleted when the period ends.

10.4 Residual copies in encrypted backups are removed in the ordinary backup rotation cycle after deletion.

10.5 Enquiry data, including registration checks — kept while the enquiry is live and then for up to 2 years, so that a returning enquirer is not asked the same questions twice and so we can show why an assessment did or did not proceed. The ABN and register-check outcome recorded with an enquiry (section 5.5) are kept on this schedule and deleted with it. An enquirer may ask us to delete their enquiry sooner — see section 11.

11. Access and correction (APPs 12 and 13)

11.1 Your own dealings with us (Customer personnel, business contacts, website visitors): you may request access to, or correction of, personal information we hold about you by contacting us (section 15). We will respond within a reasonable period (normally within 30 days), and if we refuse a request we will tell you why and how to complain.

11.2 Worker and participant records: these are the Customer's records, which we hold on the Customer's behalf. If you are a worker or participant, please direct access or correction requests to the provider organisation that holds your records — it controls them and is best placed to respond. If you contact us directly about such a record, we will (with your basic details and where we can identify the relevant Customer) refer your request to that Customer and support it in responding. We do not access or alter a Customer's records except at its direction or as required by law.

11.3 Corrections vs. audit history. The Service keeps prior versions of records for audit integrity. Correcting a record updates the current version; the audit trail of what was previously recorded is preserved, as compliance-record rules require. Where a correction is made, the corrected version is the one presented for ordinary use.

12. Disclosure

We disclose personal information only:

We do not disclose personal information to anyone for their marketing. If our business is reorganised or sold, personal information may be transferred to the successor entity subject to this policy and the residency commitment in section 7.

13. Cookies and analytics

Our applications use only what is needed to run:

We do not use third-party advertising trackers, social-media pixels, or cross-site tracking of any kind. You can clear cookies in your browser; session cookies are required for the Service to function.

14. Complaints

If you believe we have breached the Privacy Act or mishandled your personal information, please contact us first (section 15) with the details. We will acknowledge your complaint within 7 days, investigate, and respond within 30 days. If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner:

If your complaint concerns how an NDIS provider (our Customer) has collected or used your information, the OAIC and, for NDIS-specific conduct, the NDIS Quality and Safeguards Commission may both be relevant avenues.

15. Contact us

Privacy Officer CLOUD RESEARCH AND DEVELOPMENT XENTER PTY LTD (ABN 52 677 458 187) Registered address to be published before launch Email: privacy@longstead.com.au

16. Changes to this policy

We may update this policy from time to time. Material changes will be notified to Customers by email at least 30 days before they take effect, and the current version will always be available at https://longstead.com.au/privacy/, with its effective date. Changes will never reduce the commitments in sections 4 (sensitive information) and 7 (Australian residency) for existing data without the affected Customers' agreement.