Privacy
The profile you give (professions, how the practice is registered for the NDIS, whether it works with children, whether it engages other workers) is read in your browser and is not sent to us unless you choose to save a register. The list never asks for a participant's name, a client record, a document or a practitioner's registration number. The clinician roster asks for a label you choose for each person (use a role or initials if you prefer), the profession and the dates you record; never paste a registration number or health details. Every saved text field is capped and any email address in it is removed before it is stored. That is data minimisation, not de-identification: whatever else you type in a field is kept as you typed it, so leave it out. Your email address is stored for sign-in. We do not sell data, run advertising, or share your register with anyone. Transactional email (sign-in links, receipts) is the only email a saved account receives. Payment details are handled by our payment processor and never touch our systems. You can delete a saved register or your account at any time; closing your account deletes everything saved under it.
Where it is kept and who can see it. Pages are served by Cloudflare. Saved work and your account are stored in a Supabase database in Sydney, Australia (AWS ap-southeast-2), encrypted at rest and reached only over encrypted connections. Payments are processed by Stripe, and sign-in links and receipts are sent through SendGrid; those four are the only services that handle your data for us. Saved work is kept until you delete it or close your account. Our support staff open a saved record only to answer a request from you.
Sign-in security, the audit log and deleting your data. Two-step sign-in is optional unless the owner of a Team account requires it for everyone on it; the authenticator key is stored encrypted and recovery codes only as one-way hashes. The account keeps an audit log of sign-ins and sign-outs, two-step sign-in changes and refused codes, opening, saving, deleting and exporting saved work, teammate invitations and role changes, security settings and plan changes. Each entry holds who, when, the kind of action and which saved record, with a one-way hash of the network address and the browser family; it never holds what you pasted or saved. On Team the owner and editors of the account can read and export it; on Solo you can read your own. Entries are deleted automatically after two years. You can delete a saved record, or your whole account and everything saved under it, yourself from the account page; deleting an account cancels an active subscription, and Stripe keeps its own record of past payments.
Emailing a result to yourself. Where a result offers to be emailed to you, your browser sends only the summary shown on the page: the counts and the names of the instruments with their counts. Your profile and anything you typed are never sent. We store your email address, that summary, when you asked, and whether you ticked the box for a note when the tool adds something new (no more than once a month), with the words of that box. Without the tick you get the one email and nothing else, and your address goes on no mailing list. Every email carries a link that stops them at once; an address that uses it is kept on a do-not-send list so we never write to it again. A request without the tick is deleted after 30 days; with it, it is kept until you unsubscribe and deleted 30 days after that. The email is sent through SendGrid from support@theartofservice.com.
Worksheet downloads are counted (the page and the campaign tags of the link you arrived by, with an anonymous browser cookie), so we can see which worksheets are used; nothing in a worksheet is personal.
Questions or deletion requests: support@theartofservice.com.
Allied Health NDIS Audit Checklist is operated by The Art of Service Pty Ltd, GPO Box 2673, Brisbane QLD 4001, Australia.