Skip to main content
Back to home

Privacy Policy

Last updated: 28 June 2026

1. Introduction

This Privacy Policy explains how MMZ Studios Pty Ltd (ACN 698 690 596 / ABN 19 698 690 596), an Australian proprietary company trading as MySDAmanager ("we", "us", or "our") collects, uses, stores, and discloses personal information through the MySDAmanager platform ("Service"), accessible at https://mysdamanager.com.

We are committed to protecting the privacy and confidentiality of personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). Given that our Service handles information relating to NDIS participants, including people with disability, we take particular care to ensure the security and appropriate handling of sensitive and personal information.

This policy applies to all users of the Service, including organisation administrators, property managers, staff members, and any person whose personal information is stored within the Service.

2. What We Collect

We collect different types of information depending on how you use the Service.

2.1 Organisation Details

  • Organisation name, ABN, and contact details
  • Branding preferences (logo, colours) for white-label configuration
  • Subscription plan and billing history

2.2 User Accounts

  • Full names, email addresses, and assigned roles
  • Account login handled by our authentication provider (Clerk); MySDAmanager does not store or have access to your password
  • Multi-factor authentication (MFA) configuration
  • Session tokens and login timestamps

2.3 SDA Property and Participant Data

  • Property addresses, dwelling details, and SDA design categories
  • Participant names, NDIS numbers, dates of birth, and emergency contacts
  • NDIS plan details including funding amounts, plan dates, and support requirements
  • Support coordinator, SIL provider, and occupational therapist details
  • Owner and investor information, including bank account details for payment distribution
  • Maintenance requests, inspection records, incident reports, and complaints
  • Photographs attached to inspections, incidents, and maintenance records
  • Compliance certifications and uploaded documents

2.4 Payment Information

  • SDA payment records, invoices, and MTA claims
  • Reasonable Rent Contribution (RRC) calculations
  • Subscription billing information (processed and stored by Stripe -- we never store full credit card numbers)

2.5 Usage Analytics and Error Logs

  • Audit logs of actions performed within the Service (who did what and when)
  • Error and crash reports sent to our error monitoring service (personally identifiable information is scrubbed before transmission)
  • Device information for push notification delivery
  • Browser type, operating system, and general location derived from IP address

3. How We Use Your Information

We use the information we collect for the following purposes:

  • Providing the Service -- storing and displaying property, participant, and operational data as directed by you
  • Authentication and security -- verifying user identity, managing sessions, and enforcing access controls
  • Billing and subscription management -- processing payments, issuing invoices, and managing plan entitlements via Stripe
  • Notifications -- sending email and SMS alerts for maintenance, document expiries, compliance deadlines, and other Service-related events
  • Compliance support -- generating audit logs, compliance reports, and incident records to assist with NDIS regulatory requirements
  • AI document analysis -- analysing uploaded documents (such as NDIS plans and compliance certificates) using AI to extract key information, when you choose to use this feature
  • Product improvement -- analysing aggregated and anonymised usage patterns to improve the Service
  • Customer support -- responding to enquiries, troubleshooting issues, and providing technical assistance
  • Legal compliance -- meeting our obligations under Australian law, including the Privacy Act and NDIS legislation

We will not use personal information for purposes other than those described in this policy without your consent, unless required or authorised by law (APP 6).

4. NDIS Data Handling

The Service is specifically designed for managing NDIS SDA participant information, which may include sensitive information as defined under the Privacy Act. We apply heightened protections to this data.

4.1 Sensitive Information (APP 3)

NDIS participant data may include health information, disability information, and other sensitive information. We only collect such information where it is reasonably necessary for the provision of SDA management services and where you have obtained appropriate consent from participants or their authorised representatives.

4.2 Data Minimisation

We encourage organisations to collect only the minimum amount of participant information necessary for SDA management purposes. The Service is designed to collect data fields that are relevant to NDIS SDA operations and compliance.

4.3 Your Responsibilities

As the organisation using the Service, you are the primary holder of participant personal information and bear responsibility for:

  • Obtaining informed consent from participants (or their authorised representatives) before entering personal information into the Service
  • Ensuring the accuracy of participant data
  • Providing participants with access to their information upon request
  • Complying with the NDIS Code of Conduct regarding participant information
  • Notifying the NDIS Quality and Safeguards Commission of reportable incidents in accordance with required timeframes

4.4 Incident Data

Incident reports and complaints records may contain particularly sensitive information. The Service provides secure storage, audit trails, and chain-of-custody tracking for this data to support NDIS compliance obligations. Incident data is subject to the same security controls as all other data within the Service, with additional audit logging for regulatory compliance.

5. How We Protect Your Data

We take reasonable steps to protect personal information from misuse, interference, loss, unauthorised access, modification, and disclosure (APP 11). Our security measures include:

5.1 Encryption

  • Encryption in transit: All data transmitted between your browser and our servers is encrypted using TLS (HTTPS)
  • Field-level encryption at rest: NDIS participant personally identifiable information (PII) -- including NDIS numbers, dates of birth, emergency contacts, and bank account numbers -- is encrypted using AES-256-GCM before it is written to the database. This means the stored data is unreadable without your organisation's encryption keys

5.2 Authentication and Access Control

  • Authentication: User authentication, including password storage and verification, is handled by our identity provider (Clerk); MySDAmanager does not store user passwords
  • Multi-factor authentication (MFA): MFA is provided through our authentication provider (Clerk) for administrator accounts
  • Role-based access control (RBAC): Granular permissions based on user roles (administrator, property manager, staff, SIL provider). Each role only has access to the functions and data it needs
  • Row-level tenant isolation: Every database record is tagged with an organisation ID. Queries are scoped so that one organisation can never access another organisation's data
  • Session management: Server-side sessions with 24-hour access tokens and 30-day refresh tokens, with automatic expiry
  • Inactivity lock: Automatic screen lock after a period of inactivity to protect unattended devices

5.3 Audit and Integrity

  • Immutable audit logging: A comprehensive, tamper-resistant audit trail records all data access and modifications. Each log entry is linked to the previous entry using a SHA-256 hash chain, and integrity is verified automatically every day
  • Content Security Policy (CSP): Strict CSP headers prevent cross-site scripting and code injection attacks
  • Webhook signature verification: Outbound webhooks are signed with HMAC-SHA256, allowing recipients to verify that payloads have not been tampered with

5.4 Data Breach Response

In the event of an eligible data breach as defined under Part IIIC of the Privacy Act (Notifiable Data Breaches scheme), we will:

  • Conduct an assessment as soon as practicable, and no later than 30 days, to determine whether the breach is likely to result in serious harm
  • Notify the Office of the Australian Information Commissioner (OAIC) and affected individuals as soon as practicable after we confirm an eligible data breach has occurred, in accordance with Part IIIC of the Privacy Act
  • Notify affected organisations so they may fulfil their own notification obligations to participants
  • Take reasonable steps to contain the breach and mitigate harm

6. Where Your Data Is Stored

Australian data residency (Sydney)

Your core records, including organisations, properties, NDIS participants, plans, payments, maintenance, incidents, documents and uploaded files, are stored in a PostgreSQL database and object storage hosted by Supabase in the Sydney, Australia region (ap-southeast-2). The application itself also runs in the Sydney region.

A limited number of specialised third-party processors operate in the United States (payment processing, outbound and inbound email, SMS, AI document analysis, error monitoring, and optional calendar sync). Only the data those specific functions require is sent to them. See Section 7 for the full list and Section 8 for cross-border details.

In addition, all NDIS participant personally identifiable information (PII) is encrypted using AES-256-GCM field-level encryption before it is written to the database, so sensitive fields are unreadable without your organisation's encryption keys.

6.1 Infrastructure Summary

  • Database and backend: Supabase (managed PostgreSQL) hosted in Sydney, Australia (AWS ap-southeast-2)
  • File storage: Uploaded documents and images are stored in Supabase Storage in Sydney, Australia, with per-organisation access controls
  • Application hosting: Vercel, with the application's server functions pinned to the Sydney region (syd1); static assets may be served from a global edge network

6.2 What This Means in Practice

Your participants' records reside in Australia. On top of that residency, the sensitive fields that identify NDIS participants (NDIS numbers, dates of birth, emergency contact details, and bank account numbers) are encrypted with AES-256-GCM before storage. Even if someone gained direct access to the database, these fields would appear as unreadable ciphertext. Decryption can only occur within our secure backend using keys that are not stored alongside the data.

7. Third-Party Services

We do not sell personal information. We do not sell, rent, or trade personal information to third parties for marketing or any other purpose.

We share personal information only with the following service providers, solely for the purpose of operating the Service:

ServicePurposeData ResidencyData Shared
SupabaseDatabase, backend and file storageAustralia (Sydney, ap-southeast-2)Encrypted PII, organisation data, uploaded files
ClerkAuthentication and user identityUnited StatesEmail, name, and login identifiers
StripePayment processingUnited StatesPayment details, billing email (PCI-DSS compliant)
ResendTransactional emailUnited StatesEmail addresses, notification content
PostmarkInbound emailUnited StatesInbound email content
SentryError monitoringUnited StatesError logs (PII is scrubbed before transmission)
Anthropic (Claude)AI analysis of uploaded plans and documentsUnited StatesDocument content (including participant details where you upload NDIS plans); encrypted in transit; governed by a data processing agreement with Anthropic and not used for model training
Voyage AIAI support-triage text embeddingsUnited StatesSupport ticket text
Google CalendarCalendar schedulingUnited StatesCalendar events (if you connect your calendar)
Microsoft Outlook CalendarCalendar scheduling (optional)United States / EUCalendar events (if you connect your calendar)
XeroAccounting sync (optional)AustraliaOwner/provider financial records and contact details
MYOBAccounting sync (optional)AustraliaOwner/provider financial records and contact details
Cloudflare TurnstileBot protection on public formsGlobalA verification token (no participant data)
Google Analytics, Google Ads, LinkedInMarketing-website analytics (public pages only)United StatesWebsite visitor activity (not participant data)
VercelApplication hosting and computeAustralia (Sydney, syd1) for server functions; global edge for static assetsStatic assets, server function requests

We may also disclose personal information where required or authorised by Australian law, including in response to a lawful request from a government authority or court order.

8. Cross-Border Data Transfer

In accordance with APP 8, we disclose to you that the primary store of your data, the database and file storage operated by Supabase, is located in Australia (Sydney, ap-southeast-2), and the application's server functions run in the same Australian region.

Some data is nonetheless transferred overseas to the specialised sub-processors listed in Section 7, each only for the function it performs: authentication (Clerk), payment processing (Stripe), outbound and inbound email (Resend, Postmark), AI analysis of uploaded documents (Anthropic) and AI support-triage embeddings (Voyage AI), error monitoring (Sentry), and optional calendar sync (Google, Microsoft) all operate in the United States. Accounting sync (Xero, MYOB) operates in Australia. Bot protection (Cloudflare Turnstile) and marketing-website analytics (Google, LinkedIn) may use servers in other jurisdictions but do not receive participant data.

We take reasonable steps to ensure that our overseas sub-processors handle personal information in a manner consistent with the Australian Privacy Principles. This includes:

  • Selecting sub-processors with robust security practices and certifications (such as SOC 2 compliance)
  • Entering into contractual arrangements that require sub-processors to protect personal information
  • Reviewing sub-processor security practices periodically
  • Encrypting sensitive PII fields before they reach any third-party infrastructure

By using the Service, you acknowledge and consent to the transfer of data to these overseas sub-processors for the purposes described in this policy. Your core participant and property records remain in Australia.

9. Data Retention

We retain personal information in accordance with the following schedule:

Data TypeRetention Period
Active account dataRetained for the duration of the active subscription
Cancelled account dataRetained for 90 days after cancellation, then permanently deleted
Audit logsRetained for 7 years (NDIS record-keeping requirement)
Incident and complaints recordsRetained for 7 years (NDIS record-keeping requirement)
Billing and transaction recordsRetained for 7 years (Australian tax law requirement)
Compliance documentationRetained for 7 years (NDIS record-keeping requirement)
Error monitoring logs (Sentry)Retained for 90 days, then automatically deleted
Backup dataRetained for 30 days on a rolling basis

When data is deleted, we use reasonable measures to ensure it is permanently removed from our active systems. Data in backups will be overwritten as part of the normal backup rotation cycle.

We will not retain personal information longer than is necessary for the purposes described in this policy, unless required by law (APP 11.2).

10. Your Rights

Under the Australian Privacy Principles, you have the following rights in relation to your personal information:

10.1 Access Your Data (APP 12)

You have the right to request access to the personal information we hold about you. Organisation administrators can access and export most data directly through the Service using the built-in data export feature (Settings > Data Export). For other access requests, please contact our Privacy Officer.

10.2 Correct Your Data (APP 13)

You have the right to request correction of personal information that is inaccurate, out of date, incomplete, irrelevant, or misleading. Organisation administrators can correct most data directly within the Service. For other correction requests, please contact our Privacy Officer.

10.3 Delete Your Data

You may request deletion of personal information that is no longer needed for the purposes for which it was collected. Please note that we may be required to retain certain records (such as audit logs and incident reports) for regulatory compliance purposes, even after a deletion request.

10.4 Export Your Data

Active subscribers can export a complete copy of their organisation's data at any time through the Service (Settings > Data Export). The export includes all records across all tables in a standard JSON format. After account cancellation, data export is available for 90 days.

10.5 Close Your Account

You can cancel your subscription and close your account at any time. After cancellation, your data is retained for 90 days (in case you change your mind), after which it is permanently deleted. To close your account, contact us at privacy@mysdamanager.com.

10.6 Complain

If you believe we have breached the Australian Privacy Principles, you may lodge a complaint with us (see Section 15 below) or directly with the Office of the Australian Information Commissioner (OAIC):

Office of the Australian Information Commissioner

We will respond to access and correction requests within 30 days. If we refuse a request, we will provide written reasons and information about how you may complain about the refusal.

11. Cookies and Analytics

We use cookies and similar technologies in two categories: those strictly necessary to operate the Service, and optional marketing analytics on our public website only.

Strictly necessary (no consent required)

  • Session and authentication cookies — required to sign in and maintain your account (Clerk)
  • Preference cookies — store choices such as theme and language
  • Security cookies — bot protection on public forms (Cloudflare Turnstile, where enabled)

Marketing analytics (your choice, public pages only)

On public marketing pages (for example the homepage, pricing, and contact forms), we may load analytics and advertising tags from Google Analytics, Google Tag Manager, Google Ads, and LinkedIn Insight Tag to measure visits and campaign performance. These tools may set cookies or use similar identifiers. They are not loaded inside the authenticated app where participant and incident records are viewed.

When you first visit a public page, we ask for your permission before enabling marketing analytics. You may accept or reject analytics cookies using the banner at the bottom of the page. You can change your mind at any time: select Cookie settings in the footer of any public page and the banner will ask again. Rejecting analytics does not affect your ability to use the site or submit contact forms.

Product improvement inside the signed-in Service relies on first-party operational data (for example which features are used) and, where configured, error monitoring (Sentry). That is separate from the marketing tags above and is described in Section 7.

12. Children's Privacy

The Service is designed for use by SDA property providers and their staff. It is not directed at, or intended for direct use by, children under the age of 18.

However, we recognise that NDIS participant records stored within the Service may include information about minors who reside in SDA properties. Where participant data relates to a child:

  • Consent for data collection must be obtained from the child's parent, guardian, or authorised representative
  • Such data is handled with the same security protections and access controls as all participant data
  • We encourage organisations to apply the principle of data minimisation with particular care to information about minors

13. NDIS Compliance

MySDAmanager is designed to support compliance with the NDIS Practice Standards, including the requirements for record-keeping, incident management, complaints handling, and participant privacy. The Service provides tools such as audit trails, consent workflows, incident reporting timelines, and compliance certification tracking to help your organisation meet its obligations.

However, we do not make regulatory compliance guarantees. Compliance with NDIS Practice Standards, the NDIS Code of Conduct, and the NDIS Quality and Safeguards Commission requirements is ultimately the responsibility of each registered provider. The Service is a tool to assist with compliance, not a substitute for your own compliance processes, staff training, and professional advice.

If you have questions about how the Service supports specific NDIS compliance requirements, please contact us at support@mysdamanager.com.

14. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, the Service, or legal requirements. For material changes, we will provide at least 30 days' notice by:

  • Sending an email notification to organisation administrators
  • Displaying a prominent notice within the Service

Non-material changes (such as formatting corrections or clarifications that do not affect your rights) may be made without notice.

Your continued use of the Service after the notice period constitutes acceptance of the updated policy. If you do not agree with the changes, you should stop using the Service and contact us about account cancellation.

Previous versions of this policy are available upon request.

15. Contact and Complaints

If you have any questions about this Privacy Policy, wish to make an access or correction request, or want to lodge a privacy complaint, please contact our Privacy Officer:

Privacy Officer

MMZ Studios Pty Ltd (ACN 698 690 596)

Trading as MySDAmanager

Complaint Process

  1. Lodge your complaint in writing to our Privacy Officer at privacy@mysdamanager.com
  2. We will acknowledge your complaint within 7 business days
  3. We will investigate and respond within 30 days
  4. If you are not satisfied with our response, you may escalate your complaint to the OAIC (see Section 10.6 above)

16. Effective Date

This Privacy Policy is effective as of 1 February 2026.

This policy was last reviewed and updated on 25 May 2026. The May 2026 update reflects the migration of our primary database and file storage to Australian data residency (Supabase, Sydney ap-southeast-2), as described in Sections 6 and 8.