1. Who We Are
This Privacy Policy applies to Royal Care AU Pty Ltd (ABN 76 684 189 320), trading as Royal Care Tech ("we", "us", "our"). We operate the SYNK ecosystem of software products, mobile applications, consulting services, and this website (collectively, "Services").
Our registered office is in Victoria, Australia. We provide Services to customers across Australia and internationally.
Privacy Contact: hello@royalcaregroup.com.au
2. Scope of This Policy
This policy applies to all personal information collected through:
- Our website at royalcaregroup.com.au and any subdomains
- SYNK mobile applications distributed via Google Play Store, Apple App Store, or direct download
- SYNK SaaS platforms and web applications
- Consulting engagements, training, and support services
- Email, phone, and other direct communications with us
3. Information We Collect
3.1 Information You Provide
- Account information — name, email address, phone number, business name, role
- Contact form submissions — name, email, inquiry type, message content
- Payment information — billing details processed securely through third-party payment processors (we do not store credit card numbers)
- Service data — information you enter into SYNK products including notes, invoices, shift records, calendar entries, and business data
- Communications — emails, support tickets, and feedback you send us
3.2 Information Collected Automatically
- Device information — browser type, operating system, device model, screen resolution
- Usage data — pages visited, features used, session duration, click patterns
- Network information — IP address, approximate location (city/region level), internet service provider
- Cookies and similar technologies — see Section 10 (Cookie Policy)
3.3 Mobile App Permissions
Certain SYNK mobile apps request device permissions to function. These are only used for the stated purpose:
- Call log access (CallSYNK) — to automatically log calls to your calendar. Call content is never recorded or stored.
- SMS access (TextSYNK) — to sync SMS metadata to your calendar. Message content is processed locally and not transmitted to our servers unless you explicitly enable cloud sync.
- Calendar access (CallSYNK, TextSYNK, ChargeSYNK) — to create and manage calendar entries on your behalf.
- Location (ShiftSYNK) — for GPS-verified clock in/out. Location is only captured at clock-in and clock-out events, not continuously tracked.
You can revoke any permission at any time through your device settings. Revoking a permission may limit the functionality of the relevant app.
3.4 Sensitive Information
Some SYNK products may process sensitive information as defined under the Australian Privacy Act 1988, including:
- Health information — clinical notes, support plans, incident reports, and care records entered by NDIS providers and support workers
- Disability information — NDIS participant details managed through our platforms
We treat all sensitive information with the highest level of protection. We only collect sensitive information with your explicit consent, where it is directly related to the Services you use, and where it is reasonably necessary for our functions.
4. How We Use Your Information
We use personal information for the following purposes:
- Service delivery — to provide, maintain, and improve our products and Services
- Account management — to create and manage your user account and subscriptions
- Communication — to respond to your inquiries, provide support, and send service-related notices
- Billing — to process payments and manage subscriptions
- Product improvement — to analyse usage patterns and improve user experience (using aggregated, de-identified data where possible)
- Security — to detect, prevent, and address fraud, abuse, and security issues
- Legal compliance — to comply with applicable laws, regulations, and legal processes
- Marketing — to send product updates and promotional communications (only with your opt-in consent, and you can unsubscribe at any time)
We will not use your personal information for purposes materially different from those described above without notifying you and, where required, obtaining your consent.
5. Legal Basis for Processing
Under Australian law and applicable international privacy frameworks, we process personal information based on:
- Consent — you have given clear consent for us to process your personal information for a specific purpose
- Contract performance — processing is necessary to fulfil our contractual obligations to you
- Legitimate interests — processing is necessary for our legitimate business interests, provided these do not override your rights
- Legal obligation — processing is necessary to comply with the law
6. Who We Share Your Information With
We do not sell, rent, or trade your personal information.
We may share information with:
- Service providers — trusted third parties who assist in operating our Services (cloud hosting, payment processing, analytics, email delivery). These providers are contractually bound to protect your data and use it only for the purposes we specify.
- Professional advisors — lawyers, accountants, and auditors where necessary for business operations
- Law enforcement — where required by law, court order, or government regulation
- Business transfers — in connection with a merger, acquisition, or sale of assets (you will be notified of any change in ownership or use of your personal information)
We will never share NDIS participant health information or sensitive data with third parties for marketing or commercial purposes.
7. Data Storage and Security
We implement industry-standard security measures to protect your personal information, including:
- Encryption of data in transit (TLS/SSL) and at rest
- Access controls and authentication requirements
- Regular security assessments and monitoring
- Secure cloud infrastructure with reputable providers
- Employee access limited to those who require it for their role
Our primary data storage is located in Australia. Where data is processed or stored outside Australia (e.g., through cloud service providers), we ensure that adequate data protection measures are in place in accordance with Australian Privacy Principle 8 (cross-border disclosure).
While we take reasonable steps to protect your information, no method of electronic transmission or storage is 100% secure. We encourage you to use strong passwords and protect your account credentials.
8. Data Retention
We retain personal information for as long as necessary to:
- Provide our Services to you
- Comply with legal and regulatory obligations
- Resolve disputes and enforce our agreements
- Maintain business records as required by Australian tax and corporate law
When your account is closed or data is no longer needed, we will securely delete or de-identify your personal information within a reasonable timeframe, unless retention is required by law.
You may request deletion of your data at any time (see Section 9).
9. Your Rights
9.1 Under Australian Privacy Law
Under the Privacy Act 1988 and the Australian Privacy Principles, you have the right to:
- Access — request a copy of the personal information we hold about you
- Correction — request correction of inaccurate, incomplete, or outdated information
- Complaint — lodge a complaint with us or with the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au
- Opt-out — unsubscribe from marketing communications at any time
- Anonymity — where practicable, interact with us without identifying yourself
9.2 Under GDPR (EU/UK Users)
If you are located in the European Union or United Kingdom, you also have the right to:
- Erasure — request deletion of your personal data ("right to be forgotten")
- Data portability — receive your data in a structured, machine-readable format
- Restrict processing — request that we limit how we use your data
- Object to processing — object to processing based on legitimate interests
- Withdraw consent — withdraw previously given consent at any time
- Supervisory authority — lodge a complaint with your local data protection authority
9.3 Under CCPA (California Users)
If you are a California resident, you have the right to:
- Know — request disclosure of the categories and specific pieces of personal information we have collected
- Delete — request deletion of your personal information
- Non-discrimination — we will not discriminate against you for exercising your rights
- Opt-out of sale — we do not sell personal information. If this changes, we will provide a "Do Not Sell My Personal Information" option.
To exercise any of these rights, contact us at hello@royalcaregroup.com.au. We will respond within 30 days (or sooner where required by law).
10. Cookies and Tracking Technologies
Our website and products may use cookies and similar technologies to:
- Essential cookies — required for the website and products to function (authentication, security, preferences)
- Analytics cookies — to understand how visitors use our website and improve the experience
- Functional cookies — to remember your preferences and settings
We do not use advertising or behavioural tracking cookies. We do not build advertising profiles from your data.
You can control cookies through your browser settings. Disabling certain cookies may affect website functionality. For more information, see our Cookie Policy.
11. Children's Privacy
Our Services are designed for business use and are not directed at individuals under the age of 16. We do not knowingly collect personal information from children under 16. If we become aware that we have collected information from a child under 16, we will take steps to delete it promptly.
Where NDIS participants under 16 are supported through our platform, their data is managed by their authorised representatives (parents, guardians, or support coordinators) and is subject to the full protections of this policy.
12. Data Breach Response
In compliance with the Notifiable Data Breaches (NDB) scheme under the Privacy Act 1988, if we become aware of a data breach that is likely to result in serious harm, we will:
- Promptly assess the breach and take steps to contain it
- Notify affected individuals as soon as practicable
- Notify the Office of the Australian Information Commissioner (OAIC)
- Provide clear information about what happened, what data was affected, and what steps you can take
We maintain a data breach response plan and conduct regular reviews to ensure we can respond quickly and effectively.
13. International Data Transfers
Where your personal information is transferred outside Australia (for example, to cloud service providers in other countries), we take reasonable steps to ensure that the recipient handles your information in a manner consistent with the Australian Privacy Principles.
For EU/UK users, transfers outside the EEA are protected by appropriate safeguards including Standard Contractual Clauses or adequacy decisions where applicable.
14. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will:
- Update the "Last updated" date at the top of this page
- Notify registered users by email for significant changes
- Post a notice on our website
We encourage you to review this policy periodically. Continued use of our Services after changes constitutes acceptance of the revised policy.
15. Contact Us
If you have questions about this Privacy Policy, wish to exercise your rights, or want to make a complaint, contact us at:
Royal Care AU Pty Ltd (ABN 76 684 189 320), trading as Royal Care Tech
Email: hello@royalcaregroup.com.au
SMS: 0485 024 444
If you are not satisfied with our response, you may contact:
Office of the Australian Information Commissioner (OAIC)
Website: www.oaic.gov.au
Phone: 1300 363 992