Privacy Policy

Last updated: August 2026

1. Overview

This privacy policy explains how Axior Labs Pty Ltd (ABN 91 949 773 596), which operates the NDIScompliant project at ndiscompliant.com.au, collects, uses, and protects personal information through ndiscompliant.com.au. We comply with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth).

2. Information We Collect

We may collect the following types of personal information:

2a. The "Notes Never Stored" Commitment

We make this commitment explicitly: NDISCompliant does not log, save, or retain the text content of any note you process through the Notes Rewriter tool. Our server logs capture only metadata such as request timestamps, response duration, token counts, and IP addresses — never the content of your notes. The "Private" engine processes notes entirely on our Australian server infrastructure; the "Premium" engine sends notes to Anthropic (US-based) for processing, after which Anthropic also discards the request per their data-handling policy. We strongly recommend redacting participant names before submitting notes — the in-tool "Anonymize names" button is provided for this purpose.

3. How We Use Your Information

We use personal information for the following purposes:

We do not sell, rent, or share your personal information with third parties for marketing purposes.

4. Third-Party Services

We use the following third-party services to operate NDISCompliant:

Meta (Facebook) Pixel and Conversions API — measures which advertisements lead to a purchase. Sets cookies. We send Meta a one-way cryptographic hash of a purchaser's email address so a sale can be matched to an advertisement; we do not send the address itself. See Meta's privacy policy. Google Analytics 4 — measures how pages are used. Sets cookies. See Google's privacy policy. Microsoft Clarity — records anonymised session replays and heatmaps so we can see where the site is confusing or broken. Text you type is masked before it leaves your browser, so form fields, email addresses and payment details are never recorded. Sets cookies. See Microsoft's privacy statement.

5. Data Storage and Security

6. Your Rights

Under the Australian Privacy Principles, you have the right to:

To exercise any of these rights, email hq [at] ndiscompliant.com.au.

7. Cookies

We use essential cookies for site functionality, and advertising cookies set by the Meta pixel described in section 4 — including _fbp, and _fbc when you arrive from an advertisement. These let us measure which advertisements lead to a purchase. We also send Meta a record of completed purchases from our own server, using the same identifiers together with a one-way hash of your email address; Meta cannot read the email address from that hash.

We do not sell your information, and we do not use these cookies to build a profile of you for anyone else. You can block them in your browser settings or with the advertising controls in your Meta account, and the site will still work.

8. Children's Privacy

Our products are designed for NDIS service providers, which are businesses and organisations. We do not knowingly collect personal information from children under the age of 18.

9. Changes to This Policy

We may update this privacy policy from time to time. The current version is always available at ndiscompliant.com.au/privacy.

Overseas disclosure

Some of the services we rely on to run NDISCompliant are operated outside Australia, so personal information you give us may be stored or processed overseas. Specifically:

We take reasonable steps to ensure overseas recipients handle your information consistently with the Australian Privacy Principles, but we cannot control their operations and they may be subject to the laws of the country they operate in.

Accessing and correcting your information

You may ask us what personal information we hold about you, and ask us to correct it if it is wrong. Email [email protected] from the address your account uses and we will respond within 30 days. There is no charge.

You can also ask us to delete your account and the personal information attached to it. Some records — a receipt, for example — we may need to keep to meet our own legal obligations, and we will tell you plainly if that applies.

10. Complaints

If you believe we have breached the Australian Privacy Principles, please contact us at hq [at] ndiscompliant.com.au. We will investigate your complaint and respond within 30 days.

If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.

11. Contact

For privacy-related enquiries, email hq [at] ndiscompliant.com.au.