Plain language summary: When you use RoCSYNK to manage NDIS participant information, you decide what data is collected and why — you are the "data controller". We process that data on your behalf to run the service. This Addendum explains how we protect it, who helps us process it, how we notify you of any breach, and how you get your data back or have it deleted.
1. Scope and Roles
This Data Processing Addendum ("Addendum") forms part of the agreement between Royal Care AU Pty Ltd (ABN 76 684 189 320), trading as Royal Care Tech ("we", "us", "our"), and the customer ("you") for use of RoCSYNK (the "Service"). It applies to Personal Information — including sensitive NDIS participant and health information — that we process on your behalf.
- You are the data controller: you determine what participant information is entered and the purposes for which it is used.
- We are the data processor: we process that information only to provide and support the Service, on your documented instructions.
- Both parties comply with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth).
2. Our Obligations
- Process Personal Information only to provide the Service and on your instructions
- Keep Personal Information confidential and ensure our staff are bound by confidentiality
- Apply appropriate technical and organisational security measures (encryption in transit and at rest, access controls, per-customer data isolation)
- Not use participant or health information for marketing or any commercial purpose
- Assist you in responding to requests from individuals exercising their privacy rights
3. Sub-processors
We use trusted sub-processors to deliver the Service. Each is bound to protect data consistent with this Addendum:
- Base44 — application hosting and database infrastructure
- Stripe — subscription payment processing (billing data only; no participant health data)
We will give you reasonable notice before adding or replacing a sub-processor, so you can object on reasonable grounds.
4. Data Location
Personal Information is primarily stored in Australia. Where any processing occurs outside Australia via a sub-processor, we take reasonable steps to ensure it is handled consistent with the Australian Privacy Principles (APP 8).
5. Data Breach Notification
If we become aware of an eligible data breach affecting Personal Information we process for you, we will notify you without undue delay and provide the information you need to meet your obligations under the Notifiable Data Breaches (NDB) scheme. We will cooperate with you to investigate and remediate.
6. Return and Deletion of Data
- You can export your data from the Service at any time (CSV and report formats).
- After your subscription ends, your data is retained for 90 days so you can export or reactivate.
- After 90 days, your data is permanently deleted, unless we are required by law to retain it.
7. Participant Access Requests (APP 12)
Where an NDIS participant (or their authorised representative) asks you for the information held about them, the Service lets you export that participant's records to fulfil the request. We will assist you where reasonably required.
8. Contact
Royal Care AU Pty Ltd (ABN 76 684 189 320), trading as Royal Care Tech
Data & privacy matters: hello@royalcaregroup.com.au
See also our Privacy Policy and Terms of Service.