Legal
Privacy Policy
Last updated 14 May 2026 · Placeholder pending Termly setup
1. Who we are
Solodesk (“we”, “us”) is the provider of the Solodesk software product described at solodesk.com.au. We operate under Australian Privacy Principles set out in the Privacy Act 1988 (Cth).
2. What we collect
- Account details — your email address and a hashed password.
- Pack content you create — provider details (name, ABN, contact), participant details (name, NDIS number, contact details), service agreement terms, support categories, and goals you enter.
- Operational data — shifts you log, invoices you generate, and PDFs you download from the app.
- Usage data — anonymised diagnostics about how the app is used (pages visited, errors). This does not include the contents of your pack.
3. How we use your information
We use what you provide to deliver the product: generate compliance documents, store your shifts and invoices, send transactional emails (trial warnings, password resets, receipts), and respond to support requests. We do not sell your data.
4. Where your data is stored
Application data is stored in Australia where practical. Authentication and session storage may use providers operating in or outside Australia (current providers documented below). When you cancel your account, your data is held for 30 days then permanently deleted.
5. Subprocessors
We use the following providers to operate Solodesk. Each is bound by their own privacy obligations.
- Vercel — application hosting (US/AU edge regions)
- Railway — application database (region selectable, AU available)
- Stripe — payment processing (does not receive pack content)
- Resend — transactional email
- Anthropic (added when AI progress notes launch) — AI processing of shift descriptions you choose to convert. Only the text you submit for note generation is sent.
6. Your rights
You can access, correct, or delete your data at any time by signing in and using the app, or by emailing privacy@solodesk.com.au. You can complain to the Office of the Australian Information Commissioner (oaic.gov.au) if you believe we have breached the Australian Privacy Principles.
7. Sensitive information
Information about NDIS participants is sensitive. We protect it with industry-standard encryption-at-rest, encryption-in-transit, and strict access controls. We do not share participant information with anyone other than the subprocessors above strictly to operate the product.
8. Changes to this policy
We may update this Privacy Policy. Material changes will be notified at least 14 days in advance. Continued use after the effective date constitutes acceptance.
Placeholder notice
Replace with a Termly-generated Privacy Policy before opening paid signups. The Anthropic subprocessor section must be expanded and the explicit consent flow wired up before Layer 4 (AI progress notes) ships.