1. About this policy
This policy explains how audito (ABN 95 164 685 849) (we, us) collects, uses, stores and discloses personal information in connection with audito, our website and free tools. We are bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
Its purpose is to tell you, in plain English, what we do with personal information, why, and what choices and rights you have.
2. Who this policy covers
This policy applies to personal information about:
- visitors to our website and people who use our free tools or subscribe to our emails;
- account holders and Team Members who log in to audito;
- workers who use staff sign-off or staff mock audit links, and auditors who use auditor access links; and
- workers whose details a provider chooses to record in audito, such as names and emails on the Team screen and screening, training and induction dates on the Staff records screen.
We do not collect participant information. audito is not designed to hold information about NDIS participants, and providers must not enter it (clause 6). When providers record details about their workers, they remain responsible for that information. We handle it on their behalf, to provide the service to them, and in line with this policy and our terms.
This policy does not cover third-party websites we link to, which have their own policies.
3. Definitions
- Personal information: information or an opinion about an identified individual, or an individual who is reasonably identifiable, as defined in the Privacy Act.
- Sensitive information: a category of personal information that includes health and disability information, criminal records and some other details, as defined in the Privacy Act.
- Provider: an organisation with an account in audito.
- Team Member: a person a provider invites to log in to its account.
- Participant: a person receiving supports from a provider, including NDIS participants.
- Free tools: the tools on our public website that anyone can use without an account.
- Automation Software: software features of the service that use artificial intelligence (a machine-learning model operated by a third-party provider) to generate text, such as answers, drafts and summaries, as defined in our terms.
- Assisted Output: text produced by Automation Software.
4. What we collect
- Account details: your name, email, phone, organisation, role and login details (passwords are stored hashed, never in plain text).
- Organisation information: your set-up answers, registration groups, services, roles and key personnel, logo and documents.
- Records you keep in the service: for example evidence checklist ticks and notes, corrective actions, compliance calendar notes, your team list (names, roles and emails), staff record dates (such as screening, training and induction dates) and sign-off records. These are about your organisation and workers, not participants.
- Sign-off and auditor activity: the name a worker enters when signing off, mock audit results, and a log of what an auditor views or downloads through an access link.
- Billing information: plan, invoices and payment status. Card details are handled by Stripe, not us.
- Website and free tools: your email and the results or details you choose to submit (for example a readiness score, or the organisation details you enter in the policy generator). Logos uploaded to the free policy generator are deleted within an hour.
- Communications: messages, enquiries, service requests and questions you send us (including policies you email us for a policy gap check), and questions you send to Ask audito.
- Technical information: IP address, browser and device type, pages visited and security logs.
5. Sensitive and health information
We do not ask for sensitive information about you to provide the service. We only collect sensitive information with consent, or where the law otherwise allows it.
audito is built for organisation-level compliance work, not for participant, clinical or health records. We do not collect health information about participants or workers, and the service is not designed to hold it. Please:
- enter only what you need for the purpose;
- make sure you have given the notices and obtained the consents your own privacy obligations require; and
- never enter health information in Automation Software, notes, documents or uploads.
Remove participant names and health information from anything you send us, including policies you email for a gap check, contact forms and questions to us.
6. Participant and worker information
Do not enter participant information. Providers must not upload or enter information about participants, including names, NDIS numbers or health information, anywhere in audito. Keep participant records and evidence in your own systems. If we find participant information in an account, we may delete it or ask the provider to remove it.
Providers may record worker details (name, role and email) on the Team screen, staff record dates on the Staff records screen and sign-off records. Staff records hold dates and short notes only, not clearance or licence numbers, certificates or health information. For that information, we act on the provider's behalf and only use it to provide the service to that provider. The provider decides what is recorded and is responsible for having the consent or other authority to collect it, store it in audito and share it, for example with their auditor.
If you are a participant or worker who thinks a provider has recorded your information in audito, please contact that provider first, as they control those records. We will help them respond.
7. How we collect it
Mostly directly from you or your Team Members when you sign up, answer questions, upload files, use the free tools or contact us. Some technical information is collected automatically when you use the website. If someone gives us information about you (for example an employer inviting you as a Team Member), we handle it under this policy.
You can browse the website and use most free tools without telling us who you are, or using a pseudonym. To keep a result, start a trial or contact us, we need your email. No law requires you to give us personal information, but if you do not, we may not be able to provide the service, reply to you or send you a result.
8. How we use it
- To provide the service: tailor and generate your documents, run the preparation tools, store your records and send the emails the service relies on (such as reminders, alerts and sign-off links).
- To handle billing, verify accounts, prevent fraud and keep the service secure.
- To respond to enquiries and provide support, including services you request such as Done with you.
- To send rule-change notes and occasional product emails if you subscribe or have an account. Every marketing email has an unsubscribe link.
- When you submit a free tool result with your email, to send you the result and pre-fill your trial sign-up with the details you entered.
- To improve the service, using aggregated or de-identified information where we can.
- To meet legal obligations.
We do not use your organisation's records to market to anyone.
9. Automation Software and automated processing
Automation Software includes Ask audito, assisted drafting and summaries of regulatory changes. When you use it, the text you submit and the context needed to answer it are sent to the third-party provider that operates it (listed in the table below) to generate the response.
- We configure this processing for providing the service to you, not for advertising or for building profiles of individuals.
- Assisted Output can be wrong or incomplete. It is not legal or professional advice, and you should review it before relying on it (see the Automation Software clause in our terms).
- We do not use Automation Software or other automated processing to make decisions that have a legal or similarly significant effect on an individual.
- Do not enter participant names, NDIS numbers or health information into Automation Software. Messages that look like they contain an NDIS or Medicare number are refused before they are sent.
You can use the rest of the service without Automation Software.
10. Decisions made by computer programs
As at the date of this policy, we do not use computer programs, including Automation Software, to make decisions that could reasonably be expected to significantly affect the rights or interests of an individual. Billing and access changes follow the choices you make and the payment status our payment provider reports. If this changes, we will update this policy before we start, as the Privacy Act requires from 10 December 2026.
11. Who we share it with
We do not sell, rent or trade personal information. We share it only with:
- service providers who help us run the service (listed below), under contractual confidentiality and security obligations;
- people you choose to share with, such as Team Members, your auditor through an auditor access link, or workers through sign-off links;
- our professional advisers and insurers, under confidentiality;
- a buyer or successor of our business, who must handle it under this policy; and
- government or law enforcement bodies where the law requires or permits it.
| Service provider | Purpose | Information | Location |
|---|---|---|---|
| Supabase (database and file storage) | Stores your account, Answers, records and uploaded files | All account data and files | Australia (Sydney) |
| Vercel (application hosting) | Runs the website and app and handles each request | Data in transit while a request is processed; technical logs | Global network; requests may be processed outside Australia, including in the United States |
| Stripe (payments) | Takes card payments and manages subscriptions and invoices | Name, email, organisation, billing details. We never see or store full card numbers. | Australia and other countries, including the United States |
| Postmark (email delivery) | Sends account, billing, reminder and rule-change emails | Email address, name and the email content | United States |
| Anthropic (provider that operates the model behind Automation Software) | Generates Ask audito answers, assisted drafting and summaries | The text you submit to Automation Software and relevant context, such as the question being answered | United States |
We may change providers from time to time and will update this list.
12. Overseas disclosure
Your account data and files are stored in Australia (Sydney). Some service providers in the table above may process limited information outside Australia, mainly in the United States, to send emails, process payments, run Automation Software or handle web requests. The countries are listed in the table.
We take reasonable steps under APP 8 to ensure they handle it consistently with the APPs, including choosing reputable providers and relying on their contractual privacy and security commitments.
13. Storage and security
- Account data and files are stored in Australia (Sydney), encrypted at rest by our storage provider, and sent over encrypted (HTTPS) connections.
- Files are kept in private storage and never on public links. They are released only after permission checks.
- Passwords are hashed. Sign-in tokens are stored only in hashed form, and sign-in is rate limited.
- Team access is role-based, so each Team Member only sees what their role allows.
- Auditor access links need a passcode, expire automatically and are logged.
- Access by our staff is limited to what is needed for support and operations, our accounts with our hosting, database and payment providers are protected by multi-factor authentication, and actions in our owner console are logged.
No system is completely secure, and we cannot guarantee that information will never be accessed without authorisation. Please help by using a strong, unique password and removing Team Members who no longer need access.
14. Notifiable data breaches
If we become aware of a suspected data breach, we will act quickly to contain it and assess the risk of harm.
If a breach is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) as required by the Notifiable Data Breaches scheme. Where the breach involves records a provider keeps in audito, we will tell that provider without undue delay and work with them on any notifications.
15. How long we keep it
We keep your information while your account is active. After cancellation or closure we keep it for 90 days so you can return or export it, then delete it, except records we must keep by law (such as tax records for 5 years) or routine backups that are overwritten on their normal cycle.
Policy gap checks. Policies you email us for a gap check are kept with our email records so we can reply and answer follow-up questions. We read the documents you send to prepare your report and do not keep separate copies in audito; the report itself is kept in your account. Policies uploaded to the earlier gap check upload are kept in private storage. You can ask us to delete either at any time.
Website leads and enquiries. Emails and details from the free tools, the contact form and newsletter sign-ups are kept while they are useful for following up, and you can ask us to delete them at any time. When information is no longer needed, we delete or de-identify it.
16. Access and correction
You can see and update most of your information in the app. You can also ask us for access to, or correction of, personal information we hold about you by emailing ask@audito.com.au.
We may need to verify your identity before acting on a request. We will respond within 30 days, and there is no fee to make a request. We may refuse access where the law allows, in which case we will explain why and how you can complain.
If we correct information we have shared with others, we will tell them where reasonable.
17. Deleting your information
The account owner can ask us to delete the account in the app (Account > Delete my account) or by emailing ask@audito.com.au. We cancel any subscription and delete the account, answers and documents within 30 days, except records we must keep by law and copies in routine backups, which are overwritten on their normal cycle (clause 15).
You can also ask us to delete other personal information we hold about you, such as a free tool lead or newsletter subscription. We will do so within 30 days unless the law requires us to keep it, and we will tell you if that is the case.
19. Marketing communications
We send rule-change notes only to people who subscribe, and each one has a one-click unsubscribe link. Account holders can turn off free trial tips, reminders and digest emails in Account settings > Email notifications, or with the unsubscribe link in each of those emails. A free tool result is a one-off email you asked for: we do not add you to a mailing list. You can also opt out of any of these by emailing ask@audito.com.au.
Every email we send identifies us and how to contact us. Service emails that your account relies on (such as billing, security and sign-off notifications) are not marketing and are sent while your account is active.
20. Children's privacy
audito is for organisations and is not directed at children. Account holders and Team Members must be 18 or older, and we do not knowingly collect personal information from children.
Some NDIS participants are children. Like all participant information, information about them must not be entered in audito (clause 6).
21. Collection notices
Where we collect personal information, we show a short notice with a link to this policy: on the sign-up form, the contact form, the free tools that ask for your email and the rule-change notes sign-up. Each notice says what we collect it for. This policy gives the rest: who we share it with, overseas disclosure, and how to access, correct or complain.
22. Changes to this policy
We may update this policy. We will post the new version here with its date, and tell account holders about material changes by email or in the app.
23. Contact and complaints
If you have a question or a complaint about how we handle personal information, contact us at ask@audito.com.au. We will acknowledge it within 5 business days and aim to resolve it within 30 days.
If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner (OAIC): www.oaic.gov.au, phone 1300 363 992.
audito (ABN 95 164 685 849)
Email: ask@audito.com.au
Phone: 0488 863 626