Australian care providers handle some of the most sensitive information there is, and many are required, or simply prefer, to keep it onshore. This page explains, specifically, where OneForce Care stores and processes data, and where it does not. It is published by Wondertree Studios Pty Ltd (ACN 699 886 498, ABN 82 699 886 498) of Level 10, 387 George Street, Sydney NSW 2000, Australia.
We have written it so a provider can use it directly in its own privacy impact assessment or APP 8 analysis, rather than having to ask us follow-up questions. If something you need is missing, tell us and we will add it.
1. Your data stays in Sydney, Australia
The platform’s application hosting, database, document storage, electronic signing and backups all run in Sydney, Australia:
- Application hosting runs with our cloud hosting provider, in its Sydney, Australia region.
- Database and authentication run with our database provider, in its Sydney, Australia region.
- Document storage (signed service agreements, consent forms, worker compliance documents, incident evidence and other uploaded files) is held with our cloud storage provider, in its Sydney, Australia region.
- Automated backups of the database are stored in Australia, in the same region as the live database.
- Electronic signatures are handled by a signing workflow that runs on infrastructure we operate in Australia. Documents sent for signature, and the signatory details attached to them, stay in Australia.
- Transactional email (account invites, signing invitations and reminders, scheduled report emails and security notifications) is sent from our email provider’s Sydney, Australia infrastructure. See section 4 for what happens after a message leaves us.
This means Provider Data, including Participant and Worker records, service agreements, progress notes, incident reports, documents, invoices, claims and payroll figures, is stored and processed in Australia, at rest and in transit.
2. What never leaves Australia
To be concrete about the part providers most often ask about, none of the following is sent overseas by the Service:
- the platform database, in whole or in part;
- participant records, including diagnosis, support needs, goals, risks, plan and funding details, and government identifiers such as NDIS numbers;
- worker records, including screening and clearance details, classifications and pay figures;
- progress notes, shift notes and incident reports;
- documents you upload or the platform generates, including signed service agreements and consents;
- invoices, claims and payment records; or
- database backups.
The exceptions in section 3 are narrow, function-specific, and do not carry any of the above. The one thing that can carry your own words offshore is an announcement you write to your team, because it reaches phones exactly as you typed it; see section 4.
3. The named exceptions
A small number of specific, limited functions involve processing outside Australia. We name each one, and say exactly what is sent, so a provider can assess it against its own obligations:
| Function | What is sent | Why |
|---|---|---|
| Push notifications to the Worker App | The device’s push token and the notification content, for example “Shift starts in 30 minutes” | Delivering a notification to a phone requires a push delivery service located outside Australia, which passes the message on to the device’s own notification network |
| Address autocomplete | The characters typed into an address field, and the address selected | Suggesting real addresses as you type |
| Geocoding | A shift’s starting address, as text | Converting the address to coordinates so the platform can check whether a worker is on site at clock-in, where a provider has enabled that check. No participant or worker name is sent |
| Route distance and maps | The start and end coordinates of a recorded travel leg | Measuring the distance and drawing the map shown when travel is reviewed. No participant or worker name is sent |
| Accounting integration (Xero) | Invoice data (participant or recipient name, NDIS support item numbers and amounts) and timesheet data (worker name, hours and pay items) | Applies only where a provider chooses to connect its own Xero organisation. Data goes to that provider’s own Xero organisation, hosted on Xero’s infrastructure, in whichever region Xero uses for it |
| Website enquiries | Name, work email, phone, organisation and message content submitted through our contact or demo forms | Recording and responding to sales enquiries. This never involves platform data |
| In-product help and issue reports | The reporter’s name and email, their provider, the category and details they write, and any file they attach | Tracking a reported issue through to resolution. Attachments sometimes include screenshots of the product, so we treat these reports as capable of containing personal information |
Two things we send offshore carry no personal information at all: ABN verification goes to the Australian Business Register, which is Australian, and award rate reference data is fetched from published sources without sending anything about you.
Each of these carries only the specific, limited data listed. The platform’s database, document storage and backups are not routed through any of them.
4. Email is a special case, and we will not pretend otherwise
We send transactional email from Australian infrastructure. Once a message leaves us it travels to the recipient’s own mail server, which we do not control and which may be located anywhere in the world. If your worker’s email address is on an overseas mail provider, the content of the notification we send them will be stored there.
That is inherent to email rather than a hosting choice we make, and it applies to every system that emails anyone. We mention it because a residency claim that ignores it is not honest, and because it is worth remembering when deciding what a notification should say. The notifications the platform writes itself carry the minimum needed to prompt an action in the app. An announcement you write to your own team is the exception: its title and message are delivered as a push notification exactly as you typed them, so whatever you put in one goes through the push delivery service with it.
5. How we assess overseas processing
Where a service provider could process personal information outside Australia, we assess it and put appropriate protections in place, consistent with APP 8 (cross-border disclosure of personal information) under the Privacy Act 1988 (Cth). Specifically, we:
- limit what is sent to each provider to the minimum needed for its function, which is why the geocoding and mapping rows above carry no names;
- prefer a provider that can process in Australia, and use one where a viable option exists, which is why hosting, storage, signing and email sending are all onshore;
- rely on the provider’s own contractual terms, published security practices and data-protection commitments in satisfying ourselves that it handles personal information in a manner consistent with the APPs; and
- record each of these flows publicly, here and in our Privacy Policy, rather than describing our subprocessors only in general terms.
We keep a current list naming the specific provider behind each category, and we will give it to a provider on request so it can carry out its own assessment.
6. If any of this changes
Residency is only a commitment if changing it is visible. Before we add or replace a subprocessor that will handle personal information, we give providers at least 30 days’ notice, by email to the account contact and by updating this page and our Privacy Policy, and a provider can object on reasonable data-protection grounds and terminate without penalty if we cannot resolve the objection. Clause 9 of our Data Processing Addendum sets that out as a binding term, and clause 10.4 commits us not to move a category of data offshore that is currently handled in Australia without following that process first.
7. Why this matters
Keeping participant and worker records onshore helps providers meet their own privacy and NDIS Practice Standards obligations, supports continuity of care, and keeps sensitive health-adjacent information within Australian jurisdiction, where Australian law and the OAIC apply to it directly. It also makes an audit conversation shorter: the answer to “where is participant data held?” is a place, not a diagram.
8. Evidence for your own assessment
If you are completing a privacy impact assessment, a supplier questionnaire, or an internal risk review, we will give you, at no charge: the current subprocessor list naming each provider, a description of the security measures in place (see Security), written answers to a reasonable security questionnaire, and a signed counterpart of our Data Processing Addendum if your process needs one. Ask at hello@oneforce.com.au.
9. Contact
Questions about data residency? Email hello@oneforce.com.au.