Skip to main content

Legal

Privacy Policy

Effective date: 23 September 2026  ·  Version 1.2

This Privacy Policy explains how REDROCK SYSTEMS PTY LTD (ABN 53 696 760 433) (“RedRock Systems”, “we”, “us”, or “our”) collects, uses, discloses, and protects personal information in accordance with the Privacy Act 1988(Cth) and the Australian Privacy Principles (APPs) contained in Schedule 1 of that Act. This policy applies to all services, websites, and products operated by RedRock Systems, including CoordHub and RedRock PM, and any other product we make generally available (collectively, the “Services”).

On this page
APP 1

Open and Transparent Management of Personal Information

We are committed to managing personal information openly and transparently. This policy is publicly available on our website at redrocksystems.com.au/privacy. A copy is also available on request by contacting us at hello@redrocksystems.com.au.

We only collect personal information that is reasonably necessary for one or more of our functions or activities. Where it is lawful and practicable to do so, individuals may deal with us anonymously or by pseudonym.

Our Privacy Officer can be contacted at: hello@redrocksystems.com.au or by writing to REDROCK SYSTEMS PTY LTD, Australia.

APP 3

Collection of Solicited Personal Information

We collect personal information that is reasonably necessary to provide our Services, respond to enquiries, process payments, and comply with our legal obligations.

Information you provide directly

  • Identity information: full name, job title, organisation name
  • Contact information: email address, phone number, postal or business address
  • Account credentials: username and hashed password
  • Payment information: billing name, billing address, and card details (processed directly by Stripe; we do not store raw card numbers)
  • Profile and configuration data entered into the Services
  • Communications you send to us including support requests and enquiries

Information collected automatically

  • Usage and interaction data: pages visited, features used, session duration, click paths
  • Technical data: IP address, browser type and version, operating system, device type
  • Performance data: page load times, Core Web Vitals metrics (collected via Vercel Speed Insights in aggregated, non-identifiable form)
  • Error and diagnostic logs

Information collected from third parties

  • Payment and fraud-risk signals from Stripe
  • A session reference and a pass/fail verification result from identity verification providers used in RedRock PM's optional AML/CTF and KYC feature, with your prior express consent

Sensitive information

Certain of our Services involve sensitive information as defined in the Privacy Act, including health information (in CoordHub, for NDIS support coordination purposes) and government identifiers such as Tax File Numbers (in RedRock PM). Where a firm enables RedRock PM's optional identity verification feature, biometric information is captured and held by the identity verification provider, not by RedRock PM. We only collect sensitive information with your express consent or where otherwise permitted by law. See the “Sensitive Information” section below for further detail.

APP 5

Notification of Collection

At or before the time we collect personal information, or as soon as practicable afterwards, we will take reasonable steps to notify you (or ensure you are aware) of the following:

  • Our identity and contact details
  • The fact and circumstances of collection
  • Whether the collection is required or authorised by law
  • The purposes for which we collect the information
  • The consequences if the information is not collected
  • Other entities or categories of entities to whom we usually disclose the information
  • That this Privacy Policy contains information about how to access, correct, or complain about handling of the information

Notification is provided through collection notices displayed on our sign-up forms, account creation flows, and product onboarding screens. Where personal information is collected from a third party, we take reasonable steps to ensure you are notified.

APP 6

Use and Disclosure of Personal Information

We only use or disclose personal information for the primary purpose for which it was collected, or for a secondary purpose that you would reasonably expect, or where you have consented, or where otherwise permitted by the Privacy Act.

Primary purposes

  • Providing, operating, and improving the Services
  • Creating and managing your account
  • Processing payments and managing billing
  • Providing customer support and responding to enquiries
  • Sending transactional communications (account notices, receipts, security alerts)
  • Complying with legal and regulatory obligations

Secondary purposes

  • Analysing aggregated usage patterns to improve product features
  • Detecting and preventing fraud, security incidents, and abuse
  • Conducting audits, investigations, and resolving disputes
  • Sending product updates or marketing communications (only with consent; see APP 7)

Sub-processors and service providers

We disclose personal information to the following categories of third-party service providers who process data on our behalf:

  • Supabase Inc: database hosting and authentication, data stored in Sydney (AWS ap-southeast-2)
  • Stripe Inc: payment processing and fraud detection (United States and global)
  • Resend Inc: transactional email delivery. For this website, Resend processes mail from infrastructure in Tokyo, Japan (ap-northeast-1). Client-facing emails go through the firm's own Microsoft 365 account when the firm has connected one; otherwise, and for system emails such as reminders, invitations and billing notices, they go through Resend. The processing region for CoordHub's and RedRock PM's own use of Resend is not stated here
  • Vercel Inc: serverless functions and application hosting for CoordHub, RedRock PM and this website, pinned to Sydney, Australia; static asset caching runs on a global edge network for all Services
  • Microsoft 365: receives this website's enquiries in RedRock's own mailbox. RedRock PM also uses a firm's connected Microsoft 365 account to deliver client-facing email where that firm has connected one; its processing region follows that firm's tenant
  • Xero: this is the customer's or firm's own connected Xero account, not a RedRock Systems sub-processor. CoordHub and RedRock PM integrate with it when a provider or firm connects their own account, and RedRock does not control where Xero processes that data
  • AWS KMS: per-organisation envelope encryption key management for RedRock PM, Sydney, Australia (ap-southeast-2)
  • Sentry: application error monitoring for CoordHub and RedRock PM. For RedRock PM, it is configured not to send default personal data, with a filter that redacts tax file numbers, email addresses, phone numbers and ABNs from error reports; the processing region is not stated here
  • PostHog: product analytics for CoordHub (United States)
  • Annature: e-signing for RedRock PM documents (Australia)
  • Anthropic: AI-assisted processing of materials you provide during a workflow review or custom development engagement, used only under the written Discovery Agreement for that engagement and with your consent (United States)
  • Inngest: background job and workflow orchestration for CoordHub and RedRock PM; the processing region is not stated here
  • Upstash Redis: rate limiting for RedRock PM; the processing region is not stated here
  • Google Maps: address geocoding for CoordHub's provider directory; the processing region is not stated here

Each of these providers is engaged under its own standard terms of service, or its data processing agreement or standard contractual clauses where it offers them, and is instructed to process personal information only as we direct.

Other disclosures

We may disclose personal information to regulators, law enforcement, or courts where required by law; to professional advisers (lawyers, accountants, auditors) under obligations of confidentiality; and in the event of a business restructure, merger, or acquisition, subject to appropriate confidentiality obligations.

APP 7

Direct Marketing

We will only use or disclose personal information for direct marketing purposes if we have your consent, or where the information was collected in the course of a commercial relationship and the marketing relates to our similar goods and services.

Every marketing communication we send will include a clear and easy mechanism to opt-out (unsubscribe). You may also opt out at any time by emailing hello@redrocksystems.com.au with the subject line “Unsubscribe”. We will action opt-out requests within five (5) business days. We do not sell personal information to third parties for marketing purposes.

APP 8

Cross-Border Disclosure of Personal Information

Some of our service providers are located overseas and may receive personal information from us. We take reasonable steps to ensure that overseas recipients handle personal information in a manner consistent with the APPs before any disclosure.

Countries or regions to which personal information may be disclosed include:

  • United States: Stripe (payment processing)
  • Japan (Tokyo): Resend (email delivery for this website; other products' Resend regions are not stated here)
  • United States: PostHog (product analytics for CoordHub)
  • United States: Anthropic (AI-assisted processing for workflow review and custom development work, under each engagement's written Discovery Agreement and your consent)
  • Not stated here: Sentry (application error monitoring; the processing region is not confirmed)
  • Not stated here: Inngest (background job processing for CoordHub and RedRock PM)
  • Not stated here: Upstash Redis (rate limiting for RedRock PM)
  • Not stated here: Google Maps (address geocoding for CoordHub's provider directory)
  • Australia (Sydney): Supabase (primary database storage for CoordHub and RedRock PM at AWS ap-southeast-2); Vercel serverless functions for CoordHub, RedRock PM and this website (application logic, pinned to the Sydney region)
  • Global edge network: Vercel static asset caching (HTML, CSS, JS, and images only; contains no personal information)

Where personal information is disclosed to overseas entities, we rely on each provider's own standard terms of service, or its data processing agreement or standard contractual clauses where it offers them. By accepting this policy and using our Services, you acknowledge and consent to these cross-border disclosures as described.

APP 9

Adoption, Use, or Disclosure of Government-Related Identifiers

Some of our Services handle government-related identifiers, including:

  • NDIS participant numbers: collected and stored in CoordHub solely for the purpose of providing NDIS support coordination services as required under the NDIS Act 2013 and the NDIS (Registered Providers and Approved Quality Auditors) Rules
  • Tax File Numbers (TFNs): may be collected in RedRock PM in the context of accounting practice management, handled strictly in accordance with the Tax File Number Guidelines issued by the Privacy Commissioner
  • Other business identifiers (ABN, ACN): used for business identification only, not for individual tracking

We do not adopt government-related identifiers as our own identifiers for individuals, and we do not disclose them except as required to deliver the specific service for which they were collected or as required by law.

APP 10

Quality of Personal Information

We take reasonable steps to ensure that personal information we collect, use, or disclose is accurate, up to date, and complete. These steps include:

  • Allowing users to review and update their account information at any time within the platform
  • Validating data formats at the point of collection (e.g., email addresses, phone numbers)
  • Conducting periodic reviews of data held where operationally appropriate
  • Acting promptly on notifications from individuals that their information is inaccurate or out of date

If you believe information we hold about you is inaccurate, incomplete, or outdated, please contact us and we will take reasonable steps to correct it (see APP 13 below).

APP 11

Security of Personal Information

We take reasonable steps to protect personal information from misuse, interference, loss, unauthorised access, modification, or disclosure. Our security measures include:

Technical controls

  • Encryption in transit: TLS 1.2 or higher for all data in transit across all Services
  • Encryption at rest: AES-256 encryption applied to all data stored in Supabase (AWS ap-southeast-2)
  • Row-level security (RLS): database policies enforced at the storage layer to ensure tenant data isolation. No customer can access another customer's data
  • Authentication: secure session management, hashed passwords (bcrypt), optional multi-factor authentication
  • Access controls: principle of least privilege applied to all internal system access
  • Audit logging: access and modification events logged for security review

Organisational controls

  • Access to production systems restricted to authorised personnel only
  • Third-party providers vetted for security practices, and engaged under each provider's own standard terms of service, or its data processing agreement or standard contractual clauses where it offers them
  • Regular review of access permissions

Notifiable Data Breaches

If a data breach is likely to result in serious harm, we will notify the people affected and the Office of the Australian Information Commissioner (OAIC), as soon as practicable.

Destruction and de-identification

When personal information is no longer needed for any purpose for which it may be used or disclosed, and we are not required by law to retain it, we will take reasonable steps to destroy it or ensure it is de-identified.

APP 12

Access to Personal Information

You have the right to request access to personal information we hold about you. To make an access request:

  • Email us at hello@redrocksystems.com.au with the subject line "Privacy Access Request"
  • Include sufficient information to identify yourself and describe the information you are seeking
  • We will respond within 30 days of receiving a valid request

We may decline to give access in circumstances permitted under the Privacy Act, including where providing access would pose a serious threat to health or safety, have an unreasonable impact on others' privacy, or where the request is frivolous. If we decline, we will give you written reasons and notify you of available complaint mechanisms.

We will not charge a fee for making an access request, but may charge a reasonable fee for providing access where the retrieval is complex or time-consuming.

APP 13

Correction of Personal Information

If you believe personal information we hold about you is inaccurate, out of date, incomplete, irrelevant, or misleading, you may request that we correct it. To make a correction request:

  • Email us at hello@redrocksystems.com.au with the subject line "Privacy Correction Request"
  • Describe the information you believe is incorrect and what the correct information should be
  • We will respond within 30 days and take reasonable steps to correct the information

If we decline to correct information, we will give you written reasons. You may request that we attach a statement of the correction sought to the information, which we will do if it is reasonable to do so.

Sensitive Information

Sensitive information as defined in the Privacy Act receives a higher standard of protection. We collect sensitive information only with express consent or where required or authorised by law.

Health information (CoordHub)

CoordHub is used by NDIS support coordinators to manage participant support plans. Health and disability-related information may be entered into CoordHub by our customers (NDIS registered providers). This information is processed on behalf of the customer and is subject to the customer's own obligations under the NDIS Act 2013, the Privacy Act, and the NDIS Practice Standards. We act as a data processor, not a data controller, for this information.

Biometric and identity verification information (RedRock PM)

RedRock PM includes an optional identity verification (KYC) feature, built on a third-party provider, to support customer identification obligations under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (AML/CTF Act). As at the effective date of this policy, this feature is in pre-production and is not enabled for any customer.

When a firm uses this feature, the identity verification provider, not RedRock PM, captures identity document images and performs facial biometric checks directly, only with the individual's express consent. That biometric information is held by the identity verification provider, not by RedRock PM. For checks run through the provider, RedRock PM does not store document images or biometric data. We store only the document's metadata (document type, issuing authority, and relevant dates: document numbers are stored encrypted), the provider's session reference, and the pass/fail result of the check.

RedRock PM also offers an optional manual document upload path, where a customer can upload identity documents directly rather than using the provider's capture flow. Documents uploaded this way are stored in our own infrastructure (Supabase Storage, Sydney), not with the identity verification provider.

Once the verification result is received, RedRock PM asks the identity verification provider to delete that session, including the document images and biometric data it captured, and records whether the deletion succeeded.

Data Retention

We retain personal information only for as long as it is needed for the purpose for which it was collected, or as required by law. Our general retention periods are:

  • Account and profile data: retained while your account is active, plus a 30-day recovery period following account closure, then deleted
  • Billing and transaction records: retained for 7 years from the date of the transaction (compliance with Australian tax law)
  • AML/CTF records (RedRock PM): retained for 7 years from the date the relevant transaction or business relationship ends, as required by Part 10 of the AML/CTF Act 2006
  • NDIS participant records (CoordHub): retained in accordance with the NDIS Act 2013 and applicable NDIS rules; customers are responsible for their own retention obligations
  • Support communications: retained for 3 years from the date of the last interaction
  • Audit and security logs: retained for 12 months, then archived or deleted

Cookies and Analytics

We use a minimal number of cookies and do not use third-party tracking or advertising cookies.

Essential cookies

We use session and authentication cookies that are strictly necessary to operate the Services. These cookies expire at the end of your session or after a short fixed period. They cannot be disabled without preventing you from using the Services.

Analytics

We use Vercel Analytics and Vercel Speed Insights to understand how visitors use our website. These tools are privacy-focused: they do not set third-party cookies, do not use fingerprinting, do not track individuals across sites, and do not collect personally identifiable information. All analytics data is aggregated.

Privacy Complaints

If you believe we have interfered with your privacy or breached the Australian Privacy Principles, you may make a complaint to us. We take all privacy complaints seriously.

Step 1: Contact us

Email your complaint to hello@redrocksystems.com.au with the subject line “Privacy Complaint”. Please include as much detail as possible about the nature of your complaint. We will acknowledge receipt within 5 business days and provide a substantive response within 30 days.

Step 2: Office of the Australian Information Commissioner (OAIC)

If you are not satisfied with our response, or if we fail to respond within a reasonable time, you may lodge a complaint with the OAIC:

  • Website: www.oaic.gov.au
  • Phone: 1300 363 992
  • Post: GPO Box 5288, Sydney NSW 2001

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. The updated policy will be published on our website with the revised effective date.

For material changes (those that significantly affect how we handle your personal information), we will provide at least 30 days' notice before the changes take effect, via a notice on our website and, where we hold your email address, by direct notification.

Your continued use of our Services after the effective date of any changes constitutes acceptance of the updated policy.

REDROCK SYSTEMS PTY LTD  ·  ABN 53 696 760 433  ·  ACN 696 760 433  ·  Australia  ·  hello@redrocksystems.com.au