Rostrel
Legal

Privacy Policy.

Rostrel is practice-management software for Australian NDIS providers. The records our customers keep in Rostrel are about real people — participants, their supports, and the workers who deliver them — so we treat privacy as a core part of the product, not a legal afterthought.

This policy is issued by Rostrel Pty Ltd (“Rostrel”, “we”, “us”). It explains how we handle personal information in accordance with the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs), the Notifiable Data Breaches scheme, and the Privacy (Tax File Number) Rule 2015. Last updated: 3 July 2026.

The short version: your primary records live in a database in Sydney, Australia. We never sell personal information, we never use participant or worker records for advertising, and the provider you deal with — not Rostrel — decides what goes into their records and who they are shared with.

Who this policy covers

This policy applies to three groups of people:

For the third group, an important distinction: the provider controls those records. They decide what is collected, why, and who sees it — Rostrel stores and processes the records on the provider’s behalf and on their instructions. If you are a participant or worker with a question about a record a provider holds about you, your provider is the right first contact, and we will help them respond.

What we collect

Through this website: if you contact us or book a demo we collect what you give us — typically your name, email, organisation and message. Our hosting provider keeps standard server logs (IP address, pages requested, browser type) for security and performance. We do not run advertising trackers on this site.

Through the Rostrel platform, providers enter and we store:

Tax file numbers are collected for one purpose only — payroll — and are handled in line with the Privacy (Tax File Number) Rule 2015: encrypted in storage, never displayed where they are not needed, and never used or disclosed for any other purpose.

How we use personal information

Some Rostrel features use AI models to assist coordinators (for example, summarising or checking roster and billing data). Inputs to those features are processed by our AI provider solely to generate the response, and are not used to train their models. We never sell personal information and never use participant or worker records for marketing or advertising.

Where data lives, and who helps us run the service

Primary records — the database holding participant, worker and operational data — are stored in Sydney, Australia. Like almost all modern software, we use a small number of specialist service providers to run parts of the service. Some of them process limited data overseas (mainly in the United States), and where they do, APP 8 applies: we take reasonable steps, including contractual safeguards, to ensure they handle it consistently with Australian privacy law.

Beyond these processors, we disclose personal information only when the provider directs it (for example, submitting claims to the NDIA through PRODA, or invoicing a plan manager), or where the law requires it.

How we protect it

If a data breach happens: we follow the Notifiable Data Breaches scheme. We will contain and assess the incident, notify the affected provider promptly, and where a breach is likely to result in serious harm, notify the Office of the Australian Information Commissioner (OAIC) and affected individuals as the scheme requires.

Retention and deletion

We keep personal information for as long as the provider’s subscription is active, because the provider needs it to run their service and to meet their own NDIS record-keeping obligations. When a subscription ends, the provider can export their data, after which we delete it from live systems; residual copies in encrypted backups age out on a fixed cycle.

Website enquiries are kept only as long as needed to deal with them.

Access, correction and complaints

Under APPs 12 and 13 you can ask for access to the personal information held about you, and ask for it to be corrected. If your information is held in a provider’s Rostrel records, contact that provider first — they control the record, and we will assist them to respond. For anything we hold directly (for example, a website enquiry), contact us at hello@rostrel.com.au and we will respond within 30 days.

If you believe we have mishandled your personal information, please tell us first so we can put it right. If you are not satisfied with our response, you can complain to the OAIC at oaic.gov.au or on 1300 363 992.

Cookies, marketing and overseas visitors

The Rostrel application uses essential cookies only — the ones needed to keep you signed in securely. This website does not use advertising or cross-site tracking cookies.

We only send marketing email in line with the Spam Act 2003 — with your consent or an existing relationship, always with a working unsubscribe, which we honour promptly.

Rostrel is built for Australian providers. If you access it from the UK or the European Union, you may have additional rights under the UK/EU GDPR (including access, erasure and portability) — contact us and we will honour them.

Changes and contact

When we change this policy we will post the new version here with an updated date, and tell our customers about any material change. Questions about privacy at Rostrel: hello@rostrel.com.au.

Rostrel Pty Ltd · Australia · See also our Terms of Service.