Skip to content
OneForce Care
Legal & trust

Privacy Policy

How we collect, use, disclose and protect personal information.

Last updated · 26 August 2026

OneForce Care is operated by Wondertree Studios Pty Ltd (ACN 699 886 498, ABN 82 699 886 498) of Level 10, 387 George Street, Sydney NSW 2000, Australia (“Wondertree”, “we”, “us”, “our”).

This policy explains how we collect, hold, use and disclose personal information through our website, web platform and Worker App (together, the “Service”). Where the Privacy Act 1988 (Cth) applies, we comply with it and the Australian Privacy Principles (APPs).

1. Scope and responsibilities

This policy covers information about website visitors, enquirers, Provider personnel, workers, participants, care recipients and their representatives.

A disability, aged-care or NDIS support organisation subscribing to the Service is a “Provider”. A Provider decides what participant, worker and operational information to record in its workspace (“Provider Data”) and is responsible for its collection notices, authority, consents, permissions and use. We handle Provider Data on the Provider’s instructions as set out in our Data Processing Addendum.

We are responsible for information we collect for our own business purposes, such as account, billing, enquiry, support and website information.

Participants and workers should usually direct questions about a Provider’s records to that Provider first. We will assist as described in section 11.

2. The kinds of information we collect and hold

The kinds of information we may handle are:

  • Business and account information, including contact, organisation, subscription, billing and account-administration details.
  • Provider Data, including participant, worker, representative and operational records entered or generated through the Service. Provider Data may include health information and other sensitive information.
  • Enquiry and support information, including communications and material supplied when requesting help.
  • Security and technical information, including account activity, device or browser information, network identifiers and records used to operate, secure and troubleshoot the Service.

The information held about a person depends on their relationship with us and the Provider’s use of the Service. No single record necessarily contains every kind listed above.

3. How we collect information

We collect personal information:

  • directly from a person who contacts us, creates or uses an account, or uses the Service;
  • from Providers and their authorised users;
  • automatically through operation and security of the Service; and
  • from a service a Provider chooses to connect, including Xero.

If we receive unsolicited personal information that we could not lawfully retain, we will delete or de-identify it where lawful and reasonable.

Where practical, we provide or link to a collection notice when information is collected directly. If required information is not provided, we or the Provider may be unable to respond or provide the relevant function.

You may browse our public website without identifying yourself. Identified information is generally required for account-based and care-management functions.

4. Why we handle information

We collect, hold, use and disclose personal information where reasonably necessary to:

  • provide, administer, support and improve the Service;
  • enable Providers to manage their operations using the Service;
  • provide features and integrations selected by a Provider;
  • manage accounts, subscriptions, billing, enquiries and customer relationships;
  • authenticate users, administer permissions, maintain records of activity and protect the Service;
  • investigate misuse, resolve disputes and enforce our agreements;
  • comply with legal and regulatory obligations; and
  • respond to access, correction, complaint and other lawful requests.

We may use de-identified or aggregated information to understand and improve the Service. We do not sell personal information or use Provider Data for advertising or an unrelated commercial data product.

5. Automated functions

The Service uses configured rules and calculations to support operational checks, calculations, alerts and access controls. The Provider selects relevant settings, reviews outputs and remains responsible for decisions made using them. The Service is not intended to make independent clinical or care decisions.

6. Who we disclose information to

We disclose personal information only where reasonably necessary for the purposes above, on a Provider’s instructions, with consent, or as required or authorised by law. Recipients may include:

  • service providers that support hosting, security, communications, administration and Service functionality;
  • services a Provider chooses to connect, including Xero;
  • professional advisers and insurers who are subject to confidentiality obligations;
  • regulators, courts, law-enforcement bodies and other recipients where required or authorised by law; and
  • a prospective or actual buyer or successor in connection with a corporate transaction, subject to appropriate confidentiality protections.

We limit disclosures to information reasonably required for the relevant purpose. Providers may request further due-diligence information, subject to confidentiality, security and third-party restrictions.

7. Data location

Primary Provider Data storage is maintained in Australia.

Our Data residency page provides the public summary. Providers may request additional information for their own assessment, subject to confidentiality, security and third-party restrictions.

8. Direct marketing, cookies and analytics

We may use business contact details to communicate about OneForce Care where permitted by law. Marketing messages include a way to opt out, and we honour valid unsubscribe requests. We do not use participant or worker information for direct marketing or disclose it for another organisation’s marketing.

Our website uses essential technologies and limited measurement to operate the site and understand engagement. The signed-in Service uses essential and functional device or browser storage. Further information and available controls are in our Cookie Policy.

9. Security

We use technical and organisational safeguards appropriate to the information we handle, including access controls, encryption, logging and continuity measures.

No method of storage or transmission is completely secure. We review our safeguards as the Service, risks and available technology change. Our Security page provides a high-level overview, and additional assurance information may be available to Providers subject to appropriate restrictions.

10. Retention and deletion

We retain personal information for as long as reasonably required for the relevant purpose, Provider instructions, contractual commitments, security or dispute management, and legal obligations. Retention periods vary by record and context.

Provider Data is generally held while the relevant subscription is active and is returned, deleted or de-identified after termination in accordance with the Terms of Service and Data Processing Addendum. Deleted information may remain temporarily in backups until those backups expire.

Providers are responsible for determining and meeting their own NDIS, employment, tax, incident and other record-keeping obligations. OneForce Care is not a substitute for a Provider’s independent retention process.

11. Access and correction

You may ask to access personal information we hold about you or ask us to correct information that is inaccurate, out of date, incomplete, irrelevant or misleading. We may need to verify your identity and authority before acting. Access may be refused or limited where permitted or required by law, including to protect another person’s privacy, security, confidentiality or legal privilege.

Participants and workers should normally contact the Provider responsible for their record first, because that Provider controls the record and can usually action the request directly. If you cannot identify or resolve the matter with the Provider, contact us and we will provide reasonable assistance, subject to legal and security requirements.

We do not charge for making a request. Where permitted by law, we may charge reasonable costs of providing access after giving notice.

We do not adopt a government-related identifier in Provider Data as our own identifier. We use or disclose it only on the Provider’s instructions, with authority or consent, or where required or permitted by law.

13. Data incidents

We maintain processes to identify, assess, contain and respond to data incidents. Where an incident affects Provider Data, we notify and assist the affected Provider in accordance with our Data Processing Addendum. Where the Notifiable Data Breaches scheme applies to us, we assess and notify eligible data breaches as required by the Privacy Act.

14. Complaints

If you are concerned about how we have handled personal information, contact us using section 16 and provide enough information for us to investigate. We will investigate and respond within a reasonable period.

If a complaint concerns Provider Data, we may need to involve the relevant Provider. If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner where it has jurisdiction, or another body with jurisdiction over the matter.

15. Changes to this policy

We may update this policy as our practices, the Service or applicable law changes. The updated date shown on this page identifies the current version. We will take reasonable steps to notify active Providers before a material change that significantly affects how we handle Provider Data, unless an earlier change is required for legal, security or continuity reasons.

16. Contact us

Privacy questions, requests and complaints can be sent to hello@oneforce.com.au, or by post to:

Wondertree Studios Pty Ltd, ACN 699 886 498 / ABN 82 699 886 498, Level 10, 387 George Street, Sydney NSW 2000, Australia

Questions about this page? Contact us at hello@oneforce.com.au.