Privacy Policy
Last updated: August 2026
1. Overview
This privacy policy explains how Axior Labs Pty Ltd (ABN 91 949 773 596), which operates the NDIScompliant project at ndiscompliant.com.au, collects, uses, and protects personal information through ndiscompliant.com.au. We comply with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth).
2. Information We Collect
We may collect the following types of personal information:
- Purchase information: your name, email address, and payment details. Payment is processed by Stripe — we do not store your credit card numbers.
- Usage data: anonymised page views and funnel events (such as which tool features you use) collected to improve the product. These tools set cookies and can identify a returning browser. See section 4 for exactly which ones and what each does.
- Contact information: your email address and any details you provide when you contact us at hq [at] ndiscompliant.com.au.
- Email captured at the Notes Rewriter: if you provide your email through the Notes Rewriter (e.g. to continue using the free tier beyond the free trial limit, or to join the Pro waitlist), we store your email address and the source of the submission. We do not store the contents of the notes you submit through the tool.
- Notes Rewriter tool inputs: the rough notes you submit are processed by AI in real time and are NEVER stored on our servers. They exist only in transit during the request and in your browser's local storage (which you control and can clear at any time).
2a. The "Notes Never Stored" Commitment
We make this commitment explicitly: NDISCompliant does not log, save, or retain the text content of any note you process through the Notes Rewriter tool. Our server logs capture only metadata such as request timestamps, response duration, token counts, and IP addresses — never the content of your notes. The "Private" engine processes notes entirely on our Australian server infrastructure; the "Premium" engine sends notes to Anthropic (US-based) for processing, after which Anthropic also discards the request per their data-handling policy. We strongly recommend redacting participant names before submitting notes — the in-tool "Anonymize names" button is provided for this purpose.
3. How We Use Your Information
We use personal information for the following purposes:
- To deliver purchased products, including download links and confirmation emails
- To process refund requests
- To respond to enquiries sent to hq [at] ndiscompliant.com.au
- To improve our website and products through anonymised usage analytics
- To send occasional product updates and NDIS-related tips to email addresses captured at the Notes Rewriter or Pro waitlist sign-up. Each such message includes a one-click unsubscribe link, and we honour unsubscribe requests immediately.
We do not sell, rent, or share your personal information with third parties for marketing purposes.
4. Third-Party Services
We use the following third-party services to operate NDISCompliant:
- Stripe (payment processing) — see Stripe's privacy policy
- Cloudflare (website security and content delivery) — see Cloudflare's privacy policy
- Anthropic (AI processing for the Notes Rewriter tool) — text submitted is processed via API and is subject to Anthropic's usage policy
Meta (Facebook) Pixel and Conversions API — measures which advertisements lead to a purchase. Sets cookies. We send Meta a one-way cryptographic hash of a purchaser's email address so a sale can be matched to an advertisement; we do not send the address itself. See Meta's privacy policy. Google Analytics 4 — measures how pages are used. Sets cookies. See Google's privacy policy. Microsoft Clarity — records anonymised session replays and heatmaps so we can see where the site is confusing or broken. Text you type is masked before it leaves your browser, so form fields, email addresses and payment details are never recorded. Sets cookies. See Microsoft's privacy statement.
5. Data Storage and Security
- Purchase records are stored securely on servers located in Australia
- We use HTTPS encryption for all data transmission
- Payment processing is handled entirely by Stripe, which is PCI-DSS compliant
- We retain purchase records for 7 years as required by Australian tax law
6. Your Rights
Under the Australian Privacy Principles, you have the right to:
- Request access to the personal information we hold about you
- Request correction of inaccurate or out-of-date information
- Request deletion of your personal information, subject to legal retention requirements
To exercise any of these rights, email hq [at] ndiscompliant.com.au.
7. Cookies
We use essential cookies for site functionality, and advertising cookies set by the Meta pixel described in section 4 — including _fbp, and _fbc when you arrive from an advertisement. These let us measure which advertisements lead to a purchase. We also send Meta a record of completed purchases from our own server, using the same identifiers together with a one-way hash of your email address; Meta cannot read the email address from that hash.
We do not sell your information, and we do not use these cookies to build a profile of you for anyone else. You can block them in your browser settings or with the advertising controls in your Meta account, and the site will still work.
8. Children's Privacy
Our products are designed for NDIS service providers, which are businesses and organisations. We do not knowingly collect personal information from children under the age of 18.
9. Changes to This Policy
We may update this privacy policy from time to time. The current version is always available at ndiscompliant.com.au/privacy.
Overseas disclosure
Some of the services we rely on to run NDISCompliant are operated outside Australia, so personal information you give us may be stored or processed overseas. Specifically:
- Stripe processes payments and is headquartered in the United States. Your card details go directly to Stripe and never reach our servers.
- Our transactional email provider is United States based, and handles the address we send your receipt, your sign-in code and your download links to.
- Your account and your documents are held in Australia, in Sydney.
We take reasonable steps to ensure overseas recipients handle your information consistently with the Australian Privacy Principles, but we cannot control their operations and they may be subject to the laws of the country they operate in.
Accessing and correcting your information
You may ask us what personal information we hold about you, and ask us to correct it if it is wrong. Email [email protected] from the address your account uses and we will respond within 30 days. There is no charge.
You can also ask us to delete your account and the personal information attached to it. Some records — a receipt, for example — we may need to keep to meet our own legal obligations, and we will tell you plainly if that applies.
10. Complaints
If you believe we have breached the Australian Privacy Principles, please contact us at hq [at] ndiscompliant.com.au. We will investigate your complaint and respond within 30 days.
If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
11. Contact
For privacy-related enquiries, email hq [at] ndiscompliant.com.au.