Privacy Policy
Last updated: 2 August 2026
1. Who we are
Ndisvault is operated by Zeeshan Khan (ABN: [YOUR_ABN_HERE]) and is built for Australian NDIS providers. Our service helps providers prepare for NDIS audits by tracking document readiness, generating compliant policies, and sharing a read-only vault with auditors. This policy explains how we collect, use, disclose, and protect your information when you use our website and services.
2. Information we collect
We collect information you provide directly to us and information collected automatically through your use of the service.
- Account & business information: name, email address, password (stored as a hash), business name, ABN, state, services delivered, staff count, and audit track.
- Documents & policy data: files you upload (PDF/DOCX), AI-generated policy text, document status, analysis results, and expiry dates.
- Worker data: names, screening expiry dates, police check dates, WWC check dates, infection control training expiry, and employment contract status.
- Usage & analytics: pages visited, feature usage, device type, IP address, and approximate location.
- Payment information: handled securely by our payment processor (Whop). We do not store full credit card numbers on our servers.
3. How we use your information
- To provide and maintain the Ndisvault service, including document storage, AI policy generation, and readiness scoring.
- To send service-related notifications, such as expiry alerts, readiness updates, and account confirmations.
- To process payments and manage your subscription plan.
- To improve our service, fix bugs, and develop new features.
- To share documents with your auditor when you generate a read-only link.
- To comply with legal obligations and protect the rights and safety of Ndisvault, our users, and the public.
4. AI processing & third-party services
We use Anthropic's Claude API to analyse uploaded documents and generate compliant policies. Document text and your wizard answers are sent to Anthropic for processing. Anthropic does not use this data to train its models. We also use Supabase for database and authentication, Resend for transactional emails, and Whop for payments. Each provider has their own privacy policy, and we only share the minimum data necessary for the service to function.
5. Data storage & security
Your data is stored on Supabase infrastructure (primary region: Australia / Asia-Pacific where available). Files are stored in Supabase Storage with access restricted to your account. We use TLS/SSL in transit and apply role-based access controls. While we take reasonable steps to protect your data, no method of transmission or storage is 100% secure. You are responsible for maintaining the confidentiality of your account credentials.
6. Your rights
- Access & correction: you can update your business and worker details at any time from Settings.
- Deletion: you can request deletion of your account and all associated data by contacting support@ndisvault.com.au.
- Data portability: you can download all generated documents and policy PDFs from your vault at any time.
- Opt-out of marketing: we do not send marketing emails by default. Service emails (expiry alerts, receipts) can be disabled by deleting your account.
7. Retention
We retain your account and document data for as long as your account is active or as needed to provide services. If you cancel your plan, your documents remain accessible in read-only mode. You may request full deletion at any time.
8. Contact
For privacy enquiries or data requests, email support@ndisvault.com.au or visit our Contact page.