Skip to content
OneForce Care
Legal & trust

Acceptable Use Policy

What's expected, and what's off-limits, when using the platform.

Last updated · 26 August 2026

This Acceptable Use Policy (“AUP”) sets out how the OneForce Care web platform and Worker App (the “Service”, operated by Wondertree Studios Pty Ltd, ACN 699 886 498, ABN 82 699 886 498, of Level 10, 387 George Street, Sydney NSW 2000, Australia, “Wondertree”, “we”, “us”, “our”) may and may not be used. It forms part of our Terms of Service and uses the defined terms set out there, including “Customer” (“you”, “your”), “Authorised User”, “Customer Data”, “Participant Data” and “Worker Data”. We may update this AUP as the Service evolves, in line with Section 22 of the Terms.

The goal is simple: keep the Service safe, lawful and reliable for everyone, especially the participants and workers whose information it holds.

This policy applies to you and to every Authorised User you give access to, on the web platform and in the Worker App. You are responsible for making sure your people know what is in it.

1. Lawful use

You and your Authorised Users must not use the Service to:

  • (a) breach any law, regulation, industry code, or third party’s rights, including intellectual property, privacy, or confidentiality rights;
  • (b) collect, store, or share information you have no right to collect, hold, or disclose, including where you lack the consent or lawful basis required under the Privacy Act 1988 (Cth);
  • (c) harass, threaten, defame, discriminate against, or otherwise harm any person, including a participant or worker whose record is held in the Service;
  • (d) impersonate any person or organisation, or misrepresent your affiliation with one;
  • (e) do anything inconsistent with the NDIS Code of Conduct in relation to a participant whose record you hold; or
  • (f) engage in any activity that would expose Wondertree, other customers, or their participants or workers to legal liability.

2. Use of real participant and worker data

The Service is built to hold real, sensitive information about people receiving and delivering disability support. Because of that:

  • (a) you must only enter real participant or worker personal information into the Service where you have the lawful basis and consent needed to do so, and only for the purpose of managing that person’s care, employment, or engagement through your organisation;
  • (b) you must not enter a real person’s identifying details (name, date of birth, NDIS number, health information, or similar) purely for testing, demonstration, or training purposes; use fictitious or clearly marked test records for that instead;
  • (c) you must not repurpose participant or worker information collected through the Service for a use that person has not consented to, such as marketing unrelated to their support, or sharing it with a third party outside the scope of their care or employment;
  • (d) you must keep participant and worker information in the Service accurate and current, and correct or remove it promptly once you become aware it is wrong; and
  • (e) you must not use the Service to hold categories of information it is not designed for, such as payment card numbers or credentials for unrelated systems.

3. Unauthorised access, scraping and security testing

You must not, and must not attempt to:

  • (a) access, or attempt to access, any account, record, or area of the Service you are not authorised to access, including another provider’s workspace or another Authorised User’s account;
  • (b) probe, scan, penetration-test, or otherwise test the security of the Service without our prior written permission (see our Security page for responsible reporting);
  • (c) circumvent or attempt to circumvent any security or access control;
  • (d) introduce malware, ransomware, or other harmful code, or otherwise interfere with, degrade, or disrupt the integrity, security, or performance of the Service or the systems of any other customer;
  • (e) scrape, crawl, or bulk-extract data from the Service other than through export or reporting features we provide for that purpose; or
  • (f) reverse engineer, decompile, or disassemble any part of the Service except to the extent an applicable law gives you the right to do so despite this restriction.

4. Respecting participant and worker privacy

Because the Service holds sensitive care and employment information, each of your Authorised Users must:

  • (a) only access participant and worker records they are authorised to access for their role, and not browse records out of curiosity or for a purpose unrelated to their work;
  • (b) keep their login credentials and multi-factor authentication method confidential, and never share an account between two individuals;
  • (c) take reasonable care when exporting, downloading, printing, or sharing information from the Service, including participant notes, incident reports, and documents, so it is not disclosed to anyone who should not see it;
  • (d) treat an export as what it is, a copy of sensitive information now outside the platform’s access controls, and store or dispose of it accordingly; and
  • (e) report a suspected privacy or security incident involving the Service promptly, to you as their employer or engager, and, where it may involve the platform itself, to us at hello@oneforce.com.au.

Accounts must not be shared, because doing so undermines security, accountability and the reliability of activity records.

5. Recording work honestly

The Service is the record of what was delivered, to whom, by whom and when, and money and compliance both flow from it. You and your Authorised Users must not:

  • (a) record a clock-in, clock-out, break, travel leg or shift note for work that was not actually performed as recorded;
  • (b) ask, encourage or require a worker to clock in or out on someone else’s behalf, or to record a time other than the real one;
  • (c) record travel that did not occur, or inflate a distance beyond what was actually travelled;
  • (d) alter or delete a progress note, incident record or consent record to misrepresent what happened, as distinct from correcting a genuine error and saying so;
  • (e) generate or lodge a claim for a support that was not delivered, or that is not claimable in the circumstances; or
  • (f) use the Service to construct a record after the fact that is presented as contemporaneous.

Correcting a genuine mistake is expected and supported. Manufacturing a record is not, and we will treat it as a serious breach of this AUP.

6. Monitoring your workers lawfully

Some optional features record attendance, activity, travel or work-related location information. Where you enable these features, you must:

  • (a) have a lawful basis to collect that information, and comply with any workplace surveillance or industrial-instrument obligations that apply to you;
  • (b) give workers any notice, information or consultation required before collection begins;
  • (c) use the information only for the purpose you collected it, such as verifying attendance or reimbursing travel, and not for an unrelated purpose; and
  • (d) not use it to monitor a worker outside their working time.

You are responsible for understanding the features you enable and accurately explaining their operation and use to affected workers.

7. Fair use of communication and document features

You must not use communication or document features to:

  • (a) send content unrelated to the purpose the feature is provided for, including marketing, promotional, or unsolicited commercial content;
  • (b) send messages to a person who has not consented to being contacted by you through the Service, or who is not a genuine participant, worker, representative or Authorised User connected to your organisation;
  • (c) send an unreasonable volume of invitations, reminders, or signing requests, whether to genuine recipients or otherwise; or
  • (d) send a document for signature to a person you know is not authorised to sign it, or pressure a signatory into signing a document they have not been given a fair opportunity to read.

We may throttle, delay or block outgoing communications where we reasonably believe this clause is being breached.

8. Automated access

You may only use programmatic or automated access that we expressly provide or authorise, and only for its intended purpose and within reasonable usage limits.

You must not run scripts, bots, scraping tools or other automated processes against the Service without our written permission. You must not use the Service or extracted data to develop an unrelated data product, or disclose participant or worker information to a third-party tool unless you are authorised and have met your own privacy and security obligations.

9. Fair use of the Service

You must not place an unreasonable load on the Service, resell or sublicense access without our written authorisation, or provide access to a person who is not an Authorised User engaged by your organisation.

Uploads are for records that belong in the Service. Do not use document storage as general file hosting, and do not upload files unrelated to a participant, worker, incident or agreement.

10. Content standards

Content you put into the Service must be lawful and appropriate to a professional care record. Do not enter defamatory, discriminatory, abusive or gratuitous content. Individuals may have rights to access information about themselves.

11. Reporting misuse

If you become aware of a breach of this AUP, whether by one of your own Authorised Users or by anyone else, please tell us at hello@oneforce.com.au. If you discover a security vulnerability rather than misuse, please report it in line with the responsible disclosure process on our Security page.

12. Consequences of breach

Where we reasonably believe this AUP has been breached, we may, as described in Section 20 (Suspension and termination) of the Terms:

  • (a) investigate the use in question;
  • (b) warn you and require the offending conduct to stop;
  • (c) restrict, suspend, or terminate access for the Authorised User or account involved;
  • (d) remove or disable access to offending content; and
  • (e) notify an authority where required or authorised by law.

Where a breach threatens the security of the Service, the integrity of another customer’s data, or the safety of personal information, we may act immediately and without prior notice.

Where reasonably practicable and lawful, we will tell you why access was suspended and what must be addressed before we consider restoration. We may keep access restricted or terminate under Section 20.3 of the Terms where the risk or breach warrants it. Subject to identity, authority, security, legal and contractual restrictions, suspension alone does not permanently remove an applicable exit-export right under Section 11 of the Terms.

13. Contact

Questions about acceptable use, or a report of misuse? Email hello@oneforce.com.au.

Questions about this page? Contact us at hello@oneforce.com.au.