Last Updated: 8 March 2026
Webnity Care ("we", "us", "our") operates the Webnity Care software platform, including the web application
at webnitycare.com.au and the Webnity Care mobile application available on iOS (Apple App
Store) and Android (Google Play Store). This Privacy Policy explains how we collect, use, disclose, and
protect personal information in accordance with the Australian Privacy Act 1988 (Cth)
and the Australian Privacy Principles (APPs).
By using our platform, website, or mobile application, you consent to the practices described in this
Privacy Policy.
1. Information We Collect
1.1 Information You Provide Directly
We collect personal information that you voluntarily provide when you:
- Register for an account (name, email address, phone number, business name)
- Complete your staff profile (date of birth, address, gender, emergency contacts, qualifications,
compliance documents)
- Submit forms through our platform (incident reports, shift notes, leave requests, hazard reports,
house safety assessments)
- Contact us via email, phone, or the contact form on our website
- Book a demo or request information about our services
- Subscribe to communications or newsletters
1.2 Information Collected Automatically
When you use our platform or mobile app, we may automatically collect:
- Device Information: Device type, operating system, unique device identifiers,
browser type and version
- Location Data: GPS location data when you clock in/out of shifts (used for
geofenced attendance verification). Location is collected only when the app is in use and you
actively perform a clock-in or clock-out action
- Usage Data: Pages visited, features used, time spent, interaction patterns
- Log Data: IP address, access times, error logs, and referring URLs
- Push Notification Tokens: Firebase Cloud Messaging (FCM) device tokens for
delivering push notifications
1.3 Information from Third Parties
We may receive personal information from:
- Your employer or care provider organisation that uses Webnity Care
- NDIS and aged care regulatory bodies (for compliance verification purposes)
1.4 Sensitive Information
In the course of providing our services, we may collect sensitive information including:
- Health and medical information (for participant/client care management)
- Working with Children Check and police clearance status
- Professional qualifications and certifications
- Disability and care-related information about participants
We only collect sensitive information with your explicit consent or where required or authorised by law
(including the NDIS Act 2013).
2. How We Use Your Information
We use the personal information we collect to:
- Provide, operate, and maintain our platform and mobile application
- Process staff rostering, shift management, and attendance tracking
- Verify clock-in/out attendance using geolocation
- Manage compliance documentation and send expiry alerts
- Process billing, invoicing, and NDIS claims
- Facilitate in-app communication between team members
- Send push notifications for shift reminders, updates, and important alerts
- Send transactional emails (shift confirmations, password resets, onboarding instructions)
- Provide customer support and respond to enquiries
- Improve our platform, develop new features, and enhance user experience
- Comply with legal obligations, including NDIS and aged care regulatory requirements
- Protect the security and integrity of our platform
3. How We Share Your Information
We do not sell, rent, or trade your personal information. We may share your information with:
| Recipient |
Purpose |
| Your Employer/Organisation |
To facilitate rostering, compliance, and care management within your organisation |
| Amazon Web Services (AWS) |
Cloud hosting and infrastructure, email delivery (AWS SES) |
| Google Firebase |
Push notification delivery (FCM), crash reporting |
| NDIS/Government Agencies |
Where required for regulatory compliance, audits, or legal obligations |
| Professional Advisors |
Legal, accounting, or consulting services as necessary |
| Law Enforcement |
When required by law, court order, or to protect safety |
4. Data Storage and Security
4.1 Storage Location
Your data is stored on secure servers located in Australia. We use industry-standard
hosting providers with appropriate security certifications.
4.2 Security Measures
We implement a range of security measures to protect your personal information:
- SSL/TLS encryption for all data transmitted between your device and our servers
- Multi-Factor Authentication (MFA) including authenticator app and email OTP
- Role-based access controls limiting data access to authorised personnel
- Encrypted password storage using industry-standard hashing algorithms
- Regular security audits and vulnerability assessments
- Automated session management and token-based authentication
- Secure API endpoints with rate limiting and input validation
4.3 Data Breach Response
In the event of a data breach that is likely to result in serious harm, we will notify the Office
of the Australian Information Commissioner (OAIC) and affected individuals in accordance
with the Notifiable Data Breaches (NDB) scheme under the Privacy Act 1988.
5. Location Data and Permissions
Our mobile application requests location permissions for the following purpose:
- Geofenced Clock In/Out: When support workers clock in or out of a shift, we verify
their location is within the designated service area. This ensures accurate attendance records and
compliance with care delivery requirements.
Important:
- Location data is collected only when you actively perform a clock-in or clock-out
action
- We do not track your location continuously or in the background
- Location data is stored securely and is accessible only to your employer/organisation's
administrators
- You may deny location permissions, however you will be unable to use the geofenced clock-in/out
feature
6. Push Notifications
We use Firebase Cloud Messaging (FCM) to deliver push notifications including:
- Shift reminders and schedule updates
- New shift assignments and changes
- In-app chat messages
- Compliance document expiry alerts
- Important system announcements
You can manage notification preferences in your device settings. Opting out of push notifications may
affect your ability to receive timely shift updates.
7. Cookies and Tracking
Our website and web application use cookies and similar technologies to:
- Maintain your login session and preferences
- Analyse website traffic and usage patterns
- Improve our platform performance and user experience
You can control cookies through your browser settings. Disabling cookies may affect the functionality of
our platform.
8. Your Rights and Choices
Under the Australian Privacy Act 1988, you have the right to:
- Access: Request access to the personal information we hold about you
- Correction: Request correction of inaccurate or outdated personal information
- Complaint: Lodge a complaint if you believe we have breached the Australian Privacy
Principles
- Opt-Out: Opt out of receiving marketing communications at any time
- Delete: Request deletion of your personal information, subject to our legal
obligations and legitimate business needs
To exercise any of these rights, please contact us using the details in Section 13 below.
9. Data Retention
We retain personal information for as long as necessary to:
- Fulfil the purposes for which it was collected
- Comply with legal, regulatory, and contractual obligations
- Resolve disputes and enforce our agreements
NDIS and aged care regulatory requirements may require us to retain certain records for a minimum of
seven (7) years after the last service delivery date. When personal information is no
longer required, we will securely destroy or de-identify it.
10. Childrens Privacy
Our platform is designed for use by care providers, support workers, and administrators who are 18 years
of age or older. We do not knowingly collect personal information from children under the age of 18
without parental or guardian consent. If we become aware that we have collected information from a child
under 18 without appropriate consent, we will take steps to delete that information promptly.
Where our platform is used to manage care for participants under 18, this information is collected and
managed by the care provider organisation in their capacity as the data controller, in accordance with
applicable laws.
11. International Data Transfers
We primarily store and process data within Australia. In some cases, data may be processed by third-party
service providers located overseas (e.g., cloud infrastructure providers). Where this occurs, we ensure
that appropriate safeguards are in place in accordance with APP 8 of the Australian Privacy Principles.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or
legal requirements. We will notify you of material changes by:
- Posting the updated policy on our website with a revised "Last Updated" date
- Sending an in-app notification or email for significant changes
We encourage you to review this policy periodically.
13. Contact Us
If you have questions about this Privacy Policy, wish to exercise your privacy rights, or want to make a
complaint, please contact us:
If you are not satisfied with our response, you may lodge a complaint with the Office of the
Australian Information Commissioner (OAIC) at www.oaic.gov.au or by calling 1300 363 992.