Skip to main content

Your data stays yours. Full stop.

MySDAmanager holds the most sensitive information in the sector: participant records, NDIS numbers, plans, and the compliance evidence your registration depends on. Here is exactly how that information is protected, and why any SDA provider can trust us with it.

MySDAmanager is a product of MMZ Studios Pty Ltd (ABN 19 698 690 596), an independent Australian software company.

We build one thing: the software. Your operational data belongs to you, is isolated from every other customer, and is never shared with any other organisation.

How we protect your data

Six commitments that govern how MySDAmanager handles the information you trust us with.

Complete isolation between providers

MySDAmanager is a multi-tenant platform, and every organisation's data is isolated at the database row level. What you enter can never be seen by another provider on the platform, regardless of circumstance. One customer can never access another customer's data.

Built by someone who does this work

MySDAmanager began with a founder who hit these pain points every day and built the software to solve them, believing it could help many others in the same position. That first-hand experience is why privacy sits at the core of the platform: your information is handled only by the MySDAmanager team, never by another organisation, and is treated exactly like every other customer's, kept separate and never shared.

We use your data only to serve you

Your records, templates, and processes are used for one purpose: delivering the service to you. We never sell your data, and we never use your identifiable participant information for anything other than running your account.

Export or delete, on your terms

Your data belongs to you. You can export it at any time. On written request we will securely delete it and confirm in writing. We are upfront about two limits: encrypted backups are purged on a short rolling cycle after deletion, and audit and incident records are kept for up to 7 years where NDIS record-keeping rules require it.

Confidentiality that does not expire

Protection of your technical, security, personal, and participant information does not lapse over time. It is reinforced by our ongoing obligations under the Australian Privacy Act.

We prove it before you share anything

You should never have to hand over real participant data just to evaluate software. During evaluation we work with de-identified or demonstration data only, and we are glad to sign a mutual NDA and data-handling agreement before any real information changes hands.

Encrypted at the field level

Sensitive fields, including NDIS numbers, dates of birth, and bank details, are encrypted with AES-256 so they are protected even at rest.

Questions about ownership or data privacy?

We are happy to walk through our data-isolation architecture and the safeguards that protect your operational privacy.