Suppora
Legal

Privacy Policy

Last updated 25 September 2026

Suppora Pty Ltd (“Suppora”, “we”) provides software to Australian NDIS providers. We handle personal information in line with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). This policy explains what we collect, why, and the choices you have.

1. Who is responsible for what

When a provider (our customer) uses Suppora to record information about participants, staff and contacts, that provider controls the information and decides how it is used. We process it on the provider's behalf, under our agreement with them. Questions about a participant record should go to the provider first; we will help them respond. For information about visitors to this website and our own customers' account contacts, Suppora is responsible.

2. Information we collect

  • Account details: name, work email, phone, organisation and role.
  • Customer content: records a provider enters, which may include health and other sensitive information about NDIS participants.
  • Usage and device data: log-ins, pages used, IP address, browser type — used for security and support.
  • Enquiries: what you send us through forms, email or calls.

3. How we use it

To provide, secure and support the service; to bill customers; to answer enquiries; to meet legal obligations; and, for account contacts who have not opted out, to send product updates. We do not sell personal information, and we do not use customer content to train third-party AI models or for advertising.

4. Storage, security and residency

Customer content is hosted in Australia. Access is limited by role, logged, and encrypted in transit and at rest. Our current hosting regions and subprocessors are listed on the security page.

5. Disclosure

We share information only with subprocessors who help us run the service (under written confidentiality and security terms), with a customer's own authorised users, or where required by law — for example a lawful request from the NDIS Quality and Safeguards Commission or a court.

6. Retention

Customer content is kept for the life of the subscription and then returned or deleted as agreed with the customer, subject to record-keeping periods that apply to NDIS providers. Website and enquiry data is kept only as long as needed for the purpose it was collected.

7. Access, correction and complaints

You can ask to access or correct personal information we hold about you, or make a privacy complaint, by emailing [email protected]. We aim to respond within 30 days. If you are not satisfied, you can contact the Office of the Australian Information Commissioner (oaic.gov.au).

8. Data breaches

We notify affected customers promptly of any eligible data breach and support them with their obligations under the Notifiable Data Breaches scheme.

9. Changes to this policy

We will post updates here and tell customers of material changes before they take effect.