This Data Processing Addendum (“Addendum”) forms part of the agreement between Wondertree Studios Pty Ltd (ACN 699 886 498, ABN 82 699 886 498) of Level 10, 387 George Street, Sydney NSW 2000, Australia (“Wondertree”, “we”, “us”, “our”) and the organisation subscribing to OneForce Care (“Customer”, “you”, “your”), and applies whenever we handle personal information contained in Customer Data on your behalf.
It exists because you are accountable to your participants and workers for their information, and you should be able to point to something specific when you are asked how your software provider handles it. Our Privacy Policy explains our practices in plain terms; this Addendum makes the same commitments contractual.
1. How this Addendum works
1.1 This Addendum applies automatically to every subscription to OneForce Care. You do not need to sign a separate document for it to bind us. If your procurement process needs an executed counterpart, email hello@oneforce.com.au and we will sign one, at no charge.
1.2 This Addendum forms part of the Terms of Service (the “Terms”). Capitalised terms not defined here have the meaning given in the Terms.
1.3 If there is a conflict between this Addendum and the rest of the Agreement in relation to our handling of personal information contained in Customer Data, this Addendum prevails, including over the Early Access Terms. Our data-protection commitments do not weaken because your account is in early access.
1.4 If we substantially change this Addendum in a way that reduces a commitment we make to you, we will give you at least 30 days’ notice by email to your account contact, and you may terminate the affected part of your subscription without penalty before the change takes effect.
2. Definitions
- “APPs” means the Australian Privacy Principles in Schedule 1 to the Privacy Act.
- “Customer Personal Information” means personal information contained in Customer Data that we handle on your behalf, including Participant Data and Worker Data.
- “Eligible Data Breach” has the meaning given in Part IIIC of the Privacy Act.
- “Personal information”, “sensitive information” and “health information” have the meanings given in the Privacy Act.
- “Privacy Act” means the Privacy Act 1988 (Cth).
- “Security Incident” means unauthorised access to, unauthorised disclosure of, or loss of Customer Personal Information held by us or a Subprocessor.
- “Subprocessor” means a service provider we engage that handles Customer Personal Information in helping us deliver the Service.
3. Roles and scope of processing
3.1 You are the organisation accountable for Customer Personal Information. You decide what is collected, from whom, why it is recorded, how long it is kept in your workspace, and who inside your organisation may see it. You are responsible for having a lawful basis and any consents required, and for giving collection notices to your participants and workers.
3.2 We handle Customer Personal Information solely as your service provider, on your instructions, to deliver the Service. We do not determine the purposes for which it is collected and we do not use it for our own purposes, except as set out in clause 4.3.
3.3 Annex A describes the subject matter, duration, nature and purpose of our processing, the types of personal information involved, and the categories of individuals it concerns.
3.4 We remain independently responsible under the Privacy Act for information we collect for our own purposes, such as your account and billing contacts. That handling is governed by our Privacy Policy, not by this Addendum.
4. Our processing instructions
4.1 Documented instructions. We will handle Customer Personal Information only on your documented instructions. Your instructions are:
- (a) your use of the features of the Service and the configuration choices you make in it;
- (b) this Addendum, the Terms and our Privacy Policy;
- (c) any written instruction you give us, including a support request asking us to act on a record; and
- (d) anything else we agree in writing.
4.2 When we will tell you an instruction is a problem. If we believe an instruction you give us would breach the Privacy Act or another Australian law, we will tell you promptly and may pause that instruction until it is resolved. We will not simply carry it out and leave you exposed.
4.3 The limited exceptions. We may handle Customer Personal Information outside your instructions only where:
- (a) it is necessary to secure, maintain, troubleshoot or operate the Service, including investigating misuse and preventing fraud;
- (b) it is required by Australian law, in which case we will tell you before we act unless the law prohibits us from doing so; or
- (c) it has been genuinely de-identified or aggregated so that no individual, and no Provider, can reasonably be identified, in which case it is no longer personal information.
4.4 What we will never do. We will not sell Customer Personal Information, use it for advertising, use it to train or benchmark models or products for other customers, or disclose it to a third party other than as this Addendum permits.
4.5 Government and law-enforcement requests. If we receive a request from a regulator, court or law-enforcement body for Customer Personal Information, we will, unless legally prohibited, notify you promptly, give you the opportunity to respond to the request yourself, and disclose only what we are legally required to disclose.
5. Your obligations
5.1 You warrant that you have the authority, lawful basis and consents needed for us to handle the Customer Personal Information you put into the Service, including sensitive and health information.
5.2 You are responsible for the accuracy and relevance of what you record, for the permissions you configure, for deactivating access when someone leaves your organisation, and for the lawfulness of features you enable that record information about your workers, including the on-site clock-in check and travel capture.
5.3 You must not put into the Service categories of information the Service is not designed to hold, and you must not enter a real person’s identifying details purely for testing or demonstration. Our Acceptable Use Policy sets this out in full.
6. Confidentiality and our personnel
6.1 We will ensure that every person we authorise to access Customer Personal Information is bound by written confidentiality obligations that survive the end of their engagement.
6.2 We will limit access to production systems containing Customer Personal Information to personnel who need it to build, support, secure or operate the Service, granted on a need-to-know basis, reviewed when a person’s role changes, and removed promptly when their engagement ends.
6.3 Before we grant a person that access, we will ensure they have been briefed on their obligations and on the sensitivity of the information the Service holds, and have completed background verification appropriate to their role, which for roles with standing access to participant records includes a national police check.
6.4 We are not an NDIS provider and do not deliver NDIS supports, so the NDIS Code of Conduct does not bind us of its own force. We require personnel with access to participant information to act consistently with its principles about privacy, dignity, respect and the prompt reporting of concerns.
7. Security measures
7.1 We will implement and maintain technical and organisational measures appropriate to the sensitivity of Customer Personal Information, designed to protect it from misuse, interference, loss, and unauthorised access, modification or disclosure, consistent with APP 11. Annex B summarises the measures in place, and our Security page describes them in detail and is kept current.
7.2 We may change our security measures over time, provided the overall level of protection is not reduced.
7.3 On request, we will assist you with your own security obligations in relation to Customer Personal Information, including by answering a reasonable security questionnaire, explaining a control, and giving you the information you need for a risk assessment of the Service. We will do this at no charge once in any 12-month period.
8. Data breach notification and assistance
8.1 Detection and assessment. We maintain processes to detect, assess and respond to Security Incidents, and we keep an internal record of each suspected or confirmed incident, our assessment of it, and the steps taken. Where we suspect an Eligible Data Breach may have occurred, we will carry out a reasonable and expeditious assessment and complete it within 30 days of becoming aware of the grounds for suspicion, as section 26WH of the Privacy Act requires. Containment does not wait for the assessment.
8.2 Notifying you. We will notify you of a Security Incident affecting your Customer Personal Information without undue delay and, in any event, within 72 hours of confirming an Eligible Data Breach affecting your data. If we do not have the full picture within that time, we will tell you what we know and update you as the investigation progresses.
8.3 What the notice contains. Our notice will include, to the extent known at the time: what happened and when; how it was discovered; the categories of personal information and the approximate number of individuals affected; whether your participants, your workers, or both are affected; the likely consequences; the containment and remediation steps taken or planned; and a named contact at Wondertree for follow-up.
8.4 Notifying individuals. We will consult you before notifying your participants or workers about an incident affecting your Customer Personal Information, and we will not notify them unilaterally except where the law requires us to, or where a delay would create a serious risk to a person’s safety. Where we must notify without your agreement, we will tell you before we do so.
8.5 Helping you meet your own obligations. We will give you the information and assistance you reasonably need to meet your own obligations under the Notifiable Data Breaches scheme and, where applicable, to the NDIS Quality and Safeguards Commission. That includes the facts of the incident, the categories and volume of data affected, relevant log and audit extracts where we can provide them without compromising the security of other customers, and reasonable co-operation with your investigation and your communications to affected individuals.
8.6 Our own notifications. Where an Eligible Data Breach requires us to notify the OAIC or affected individuals in our own right, we will do so as the Privacy Act requires. Notifying in our own right does not remove our obligations to you under this clause 8.
8.7 No admission. Notifying you under this clause is not an admission of fault or liability.
9. Subprocessors
9.1 Your general authorisation. You authorise us to engage Subprocessors to help deliver the Service. Annex C lists the categories of Subprocessor we use today, what each does, and where it handles data. We keep a current list naming the specific provider behind each category, and we will give it to you on request so you can run your own APP 8 assessment.
9.2 Flow-down. Before a Subprocessor handles Customer Personal Information, we will put in place written terms imposing obligations at least as protective as those in this Addendum, limited to what that Subprocessor needs for its function, and prohibiting it from using the information for its own purposes.
9.3 Our responsibility. We remain responsible to you for the acts and omissions of each Subprocessor in connection with Customer Personal Information as if they were our own.
9.4 Change notice. We will give you at least 30 days’ notice before we add a new Subprocessor, or replace an existing one, that will handle Customer Personal Information. Notice will be by email to your account contact and by updating our Privacy Policy and Annex C.
9.5 Your right to object. You may object to a new or replacement Subprocessor on reasonable data-protection grounds within the notice period. We will work with you in good faith to resolve the objection, which may include offering a configuration that avoids the Subprocessor for your workspace. If we cannot resolve it, you may terminate the affected part of your subscription without penalty, and you will not pay fees for any period after termination.
9.6 Emergency changes. If we must replace a Subprocessor urgently, for example because of a security or continuity problem, we will make the change and notify you as soon as we reasonably can, with the reason. Your objection right under clause 9.5 still applies afterwards.
10. Cross-border processing
10.1 Customer Personal Information is stored and processed in Australia by default. The platform’s application hosting, database, authentication, document storage, electronic signing and transactional email sending all take place in Australia.
10.2 A small number of specific functions involve handling limited personal information outside Australia. They are named in Annex C, in our Privacy Policy and on our Data residency page, and are limited to push-notification delivery, address autocomplete, geocoding, route distance measurement, an accounting integration you choose to connect, and our enquiry and issue-tracking system.
10.3 For each of those flows we send only the minimum information needed, and we take reasonable steps consistent with APP 8 to satisfy ourselves that the recipient handles personal information in a manner consistent with the APPs. The platform’s database, document storage and backups are not routed through any of them.
10.4 We will not move a category of Customer Personal Information offshore that is currently handled in Australia without first following the Subprocessor change process in clause 9.
11. Assistance with individual rights and regulatory obligations
11.1 The Service gives you direct control of your own records, so most access and correction requests are ones you can action yourself, immediately, without involving us. That is deliberate.
11.2 If an individual contacts us directly about a record we hold on your behalf, we will not respond to the substance of their request. We will confirm that we hold information as your service provider, refer the individual to you, and tell you about the request without undue delay.
11.3 Where you cannot action a request through the Service, we will provide reasonable assistance to help you meet your obligations under APPs 12 and 13, and to help you respond to an OAIC enquiry or complaint that concerns information we hold on your behalf. Reasonable assistance is provided at no charge; where a request requires substantial engineering work, we will quote for it first and proceed only with your approval.
11.4 We will also give you reasonable assistance with a privacy impact assessment or risk assessment you carry out in relation to the Service.
12. Audit and information rights
12.1 Information first. On written request, and no more than once in any 12-month period unless we have suffered a Security Incident affecting your data, we will give you the information you reasonably need to verify our compliance with this Addendum. That includes our current Subprocessor list, a description of our security measures, our data flow and residency position, and written answers to a reasonable security questionnaire.
12.2 Audit. If the information we provide does not reasonably satisfy you, you may audit our compliance with this Addendum, on the following basis:
- (a) at least 30 days’ written notice, at a mutually agreed time during business hours, and no more than once in any 12-month period unless required by a regulator or following a Security Incident affecting your data;
- (b) conducted remotely wherever that is sufficient, and by you or an independent auditor you appoint who is not a competitor of ours and who signs a confidentiality undertaking;
- (c) limited in scope to our handling of your Customer Personal Information, and conducted so it does not disrupt the Service, compromise the security of other customers’ data, or require us to disclose another customer’s information; and
- (d) at your cost, including our reasonable costs of supporting the audit, which we will estimate before the audit starts.
12.3 We will address any material non-compliance an audit identifies within a reasonable period, and will tell you what we have done.
12.4 We will co-operate with the OAIC or another regulator in relation to Customer Personal Information, and will tell you if a regulator approaches us about your data unless we are legally prohibited from doing so.
13. Return and deletion of Customer Data
13.1 While you are a customer. You can export your own data at any time, at no charge, in the formats set out in Section 11 of the Terms. If the self-service tools do not cover something, we will produce a complete export, tabular records as machine-readable CSV and stored documents as their original files, within 10 Business Days of your written request, at no charge, once during your subscription term and once on exit.
13.2 On termination. We will make Customer Data available for export for 30 days after termination or expiry. After that period we will delete or de-identify it, except where we are required to retain something to meet our own legal obligations, in which case we will tell you what and why, and continue to protect it under this Addendum for as long as we hold it.
13.3 Backups. Residual copies of deleted Customer Data in encrypted backups are purged within 35 days of deletion from live systems. Until they are purged they remain subject to the same access controls and confidentiality obligations as live data.
13.4 Certification. On written request after deletion, we will certify to you in writing that your Customer Data has been deleted or de-identified in accordance with this clause, and identify anything retained and the legal basis for retaining it.
13.5 Your record-keeping is not ours. Deletion under this clause is the whole point of an exit process, and it is not compatible with treating the Service as your statutory archive. NDIS and other record-keeping obligations, commonly at least 7 years, are yours to meet from your own copies. Export before you go.
14. Liability, term and general
14.1 This Addendum takes effect when your subscription starts and continues for as long as we hold Customer Personal Information on your behalf. Clauses 6, 8, 12, 13 and this clause 14 survive termination for as long as they are capable of applying.
14.2 Each party’s liability under this Addendum is subject to the limitations and exclusions in Section 18 of the Terms.
14.3 This Addendum is governed by the laws of New South Wales, Australia, and disputes about it follow Section 21 of the Terms.
14.4 Nothing in this Addendum limits either party’s obligations under the Privacy Act or any other law, or an individual’s rights under them.
Annex A: Details of processing
Subject matter. Our provision of the OneForce Care platform and Worker App to you.
Duration. For the term of your subscription, plus the export and deletion periods in clause 13.
Nature and purpose of processing. Collection, recording, organisation, storage, retrieval, use, transmission, backup, and deletion of Customer Personal Information, for the purpose of operating scheduling and rostering, participant and worker records, compliance tracking, shift delivery including clock-in, travel capture and progress notes, incident recording, task management, document storage and electronic signing, payroll figure generation, invoicing, NDIS claim preparation, payment reconciliation, reporting, and the notifications and support that go with them.
Types of personal information. Identity and contact details; dates of birth; addresses; government-related identifiers including NDIS numbers and, where recorded, Medicare and Centrelink reference numbers; employment, engagement and award classification details; pay figures and timesheet records; compliance and screening records including worker screening and Working with Children Check details; availability and leave; shift, roster and attendance records; location readings taken at clock-in and travel routes where those features are enabled; health-adjacent support information including diagnosis, support needs, risks, preferences and goals; progress and shift notes; incident records including information about alleged conduct; plan, funding and budget details; financial records including invoices, claims and payments; documents uploaded or generated, including signed agreements and consents; account, login and audit records; device push-notification tokens; and support and issue reports.
Sensitive information. Yes. Participant records routinely contain health information and other sensitive information within the meaning of the Privacy Act, and incident records can contain information about alleged conduct.
Categories of individuals. Participants and their nominees, guardians, plan managers, support coordinators and emergency contacts; workers, including support workers, coordinators and administrative staff; your own account holders and administrators; directory contacts you record; and people named in referrals, incidents or notes.
Annex B: Security measures
The measures below are current at the date of this page. Our Security page describes each in more detail and is the authoritative, maintained version.
- Isolation between customers. Each provider workspace’s data is separated from every other workspace’s, enforced at more than one layer rather than by application code alone.
- Access control. Role-based permissions with independent read, create, edit and delete rights per area of the product, configured by you.
- Authentication. Password sign-in with passwords stored only in salted, hashed form, plus multi-factor authentication using standard authenticator apps, which you can require per role in your workspace.
- Encryption. TLS/HTTPS for all traffic in transit; encryption at rest for the database, backups and stored documents.
- Audit logging. An append-only record of significant actions, recording the acting user, the workspace, the action, the affected record and the timestamp, readable and exportable by you.
- Least-privilege operational access. Production access limited to personnel who need it, under confidentiality obligations and the personnel controls in clause 6.
- Credential handling. Integration credentials held server-side only, never exposed to a browser session, and revocable by you at any time by disconnecting the integration.
- Rate limiting and abuse controls on sensitive actions such as sign-in, account creation and invitations.
- Backups. Regular automated backups, retained in Australia, under the same access controls as live data.
- Patching and dependency management. We keep the platform’s dependencies and underlying infrastructure current and monitor for known vulnerabilities in the components we rely on.
- Vulnerability reporting. A published responsible-disclosure channel, described on our Security page.
We do not currently hold ISO 27001, SOC 2 or an equivalent third-party security certification, and we say so rather than implying otherwise.
Annex C: Subprocessor categories
| Category | Function | Where it handles data |
|---|---|---|
| Cloud database and authentication provider | Hosts the platform database and user authentication | Sydney, Australia |
| Cloud hosting and document storage provider | Application hosting; storage of uploaded and generated documents | Sydney, Australia |
| Electronic-signature service | The signing workflow for agreements, consents and other documents | Australia |
| Transactional email provider | Delivery of invitations, signing requests, report emails and security notices | Sydney, Australia |
| Mobile push-notification relay | Delivery of push notifications to the Worker App | Outside Australia |
| Address-lookup service | Address autocomplete during data entry | Outside Australia |
| Geocoding service | Converting a shift’s starting address to coordinates for the on-site clock-in check | Outside Australia |
| Mapping and route-distance service | Measuring and displaying a recorded travel leg | Outside Australia |
| Australian Business Register | ABN verification at sign-up | Australia |
| Xero | Accounting and payroll integration, only where you connect your own organisation | Xero’s own infrastructure |
| Enquiry and issue-tracking system | Website enquiries and in-product help and issue reports | Outside Australia |
The current list naming the specific provider behind each category is available on request from hello@oneforce.com.au.
Contact
Questions about this Addendum, a security questionnaire to complete, or a counterpart to sign? Email hello@oneforce.com.au, or write to Wondertree Studios Pty Ltd, Level 10, 387 George Street, Sydney NSW 2000, Australia.