Privacy Policy.
Rostrel is practice-management software for Australian NDIS providers. The records our customers keep in Rostrel are about real people — participants, their supports, and the workers who deliver them — so we treat privacy as a core part of the product, not a legal afterthought.
This policy is issued by Rostrel Pty Ltd (“Rostrel”, “we”, “us”). It explains how we handle personal information in accordance with the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs), the Notifiable Data Breaches scheme, and the Privacy (Tax File Number) Rule 2015. Last updated: 3 July 2026.
The short version: your primary records live in a database in Sydney, Australia. We never sell personal information, we never use participant or worker records for advertising, and the provider you deal with — not Rostrel — decides what goes into their records and who they are shared with.
Who this policy covers
This policy applies to three groups of people:
- —Visitors to rostrel.com.au — people browsing this website or contacting us about the product.
- —Our customers — NDIS providers and their staff who hold Rostrel accounts.
- —People whose information our customers store in Rostrel — NDIS participants and support workers whose records a provider keeps in the platform.
For the third group, an important distinction: the provider controls those records. They decide what is collected, why, and who sees it — Rostrel stores and processes the records on the provider’s behalf and on their instructions. If you are a participant or worker with a question about a record a provider holds about you, your provider is the right first contact, and we will help them respond.
What we collect
Through this website: if you contact us or book a demo we collect what you give us — typically your name, email, organisation and message. Our hosting provider keeps standard server logs (IP address, pages requested, browser type) for security and performance. We do not run advertising trackers on this site.
Through the Rostrel platform, providers enter and we store:
- —Worker records — contact details, qualifications and screening-check details (e.g. NDIS Worker Screening, WWCC, first aid), availability and leave, and payroll details including bank account and tax file number.
- —Participant records — contact details, NDIS number, plan and funding information, service agreements, rosters, case notes and care plans. Case notes and care plans can include health information, which is sensitive information under the Privacy Act and is handled accordingly.
- —Operational data — shifts, timesheets, claims and invoices, messages and notifications, and (where a provider uses the clock-in feature) shift check-in and check-out times, which may include location at the moment of clocking.
Tax file numbers are collected for one purpose only — payroll — and are handled in line with the Privacy (Tax File Number) Rule 2015: encrypted in storage, never displayed where they are not needed, and never used or disclosed for any other purpose.
How we use personal information
- —To provide, operate and support the Rostrel service — rostering, case notes, claiming, payroll and the rest of the product.
- —To bill our customers and manage their accounts.
- —To keep the service secure — access control, audit trails and investigating suspicious activity.
- —To improve the product, using aggregated or de-identified information wherever possible.
- —To meet our legal obligations.
Some Rostrel features use AI models to assist coordinators (for example, summarising or checking roster and billing data). Inputs to those features are processed by our AI provider solely to generate the response, and are not used to train their models. We never sell personal information and never use participant or worker records for marketing or advertising.
Where data lives, and who helps us run the service
Primary records — the database holding participant, worker and operational data — are stored in Sydney, Australia. Like almost all modern software, we use a small number of specialist service providers to run parts of the service. Some of them process limited data overseas (mainly in the United States), and where they do, APP 8 applies: we take reasonable steps, including contractual safeguards, to ensure they handle it consistently with Australian privacy law.
- —Supabase — primary database and file storage (Sydney, Australia).
- —Vercel — application hosting and content delivery (global, US-headquartered).
- —Anthropic — AI features (US). Inputs are not used to train models.
- —Xero — payroll and invoicing, only where a provider connects their own Xero organisation.
- —Google — email and calendar integrations, only where a provider connects them.
- —Twilio — SMS notifications, e.g. shift reminders (US).
- —Resend — transactional email delivery (US).
- —Sentry — error monitoring. Identifying details such as NDIS numbers, tax file numbers and phone numbers are scrubbed before error reports leave the platform.
Beyond these processors, we disclose personal information only when the provider directs it (for example, submitting claims to the NDIA through PRODA, or invoicing a plan manager), or where the law requires it.
How we protect it
- —Encryption in transit (TLS) and at rest, with an additional layer of application-level encryption on the most sensitive fields — tax file numbers and bank details.
- —Role-based access: support workers see only their own shifts, notes and records; coordinators and administrators see only what their role requires. Access rules are enforced in the database itself (row-level security), not just in the interface.
- —Tenant isolation: each provider’s data is segregated and inaccessible to any other provider.
- —Audit trails on key records, including a deletion-protected log of roster and record changes.
If a data breach happens: we follow the Notifiable Data Breaches scheme. We will contain and assess the incident, notify the affected provider promptly, and where a breach is likely to result in serious harm, notify the Office of the Australian Information Commissioner (OAIC) and affected individuals as the scheme requires.
Retention and deletion
We keep personal information for as long as the provider’s subscription is active, because the provider needs it to run their service and to meet their own NDIS record-keeping obligations. When a subscription ends, the provider can export their data, after which we delete it from live systems; residual copies in encrypted backups age out on a fixed cycle.
Website enquiries are kept only as long as needed to deal with them.
Access, correction and complaints
Under APPs 12 and 13 you can ask for access to the personal information held about you, and ask for it to be corrected. If your information is held in a provider’s Rostrel records, contact that provider first — they control the record, and we will assist them to respond. For anything we hold directly (for example, a website enquiry), contact us at hello@rostrel.com.au and we will respond within 30 days.
If you believe we have mishandled your personal information, please tell us first so we can put it right. If you are not satisfied with our response, you can complain to the OAIC at oaic.gov.au or on 1300 363 992.
Cookies, marketing and overseas visitors
The Rostrel application uses essential cookies only — the ones needed to keep you signed in securely. This website does not use advertising or cross-site tracking cookies.
We only send marketing email in line with the Spam Act 2003 — with your consent or an existing relationship, always with a working unsubscribe, which we honour promptly.
Rostrel is built for Australian providers. If you access it from the UK or the European Union, you may have additional rights under the UK/EU GDPR (including access, erasure and portability) — contact us and we will honour them.
Changes and contact
When we change this policy we will post the new version here with an updated date, and tell our customers about any material change. Questions about privacy at Rostrel: hello@rostrel.com.au.
Rostrel Pty Ltd · Australia · See also our Terms of Service.