Legal

Privacy Policy

Last updated 14 May 2026 · Placeholder pending Termly setup

1. Who we are

Solodesk (“we”, “us”) is the provider of the Solodesk software product described at solodesk.com.au. We operate under Australian Privacy Principles set out in the Privacy Act 1988 (Cth).

2. What we collect

  • Account details — your email address and a hashed password.
  • Pack content you create — provider details (name, ABN, contact), participant details (name, NDIS number, contact details), service agreement terms, support categories, and goals you enter.
  • Operational data — shifts you log, invoices you generate, and PDFs you download from the app.
  • Usage data — anonymised diagnostics about how the app is used (pages visited, errors). This does not include the contents of your pack.

3. How we use your information

We use what you provide to deliver the product: generate compliance documents, store your shifts and invoices, send transactional emails (trial warnings, password resets, receipts), and respond to support requests. We do not sell your data.

4. Where your data is stored

Application data is stored in Australia where practical. Authentication and session storage may use providers operating in or outside Australia (current providers documented below). When you cancel your account, your data is held for 30 days then permanently deleted.

5. Subprocessors

We use the following providers to operate Solodesk. Each is bound by their own privacy obligations.
  • Vercel — application hosting (US/AU edge regions)
  • Railway — application database (region selectable, AU available)
  • Stripe — payment processing (does not receive pack content)
  • Resend — transactional email
  • Anthropic (added when AI progress notes launch) — AI processing of shift descriptions you choose to convert. Only the text you submit for note generation is sent.

6. Your rights

You can access, correct, or delete your data at any time by signing in and using the app, or by emailing privacy@solodesk.com.au. You can complain to the Office of the Australian Information Commissioner (oaic.gov.au) if you believe we have breached the Australian Privacy Principles.

7. Sensitive information

Information about NDIS participants is sensitive. We protect it with industry-standard encryption-at-rest, encryption-in-transit, and strict access controls. We do not share participant information with anyone other than the subprocessors above strictly to operate the product.

8. Changes to this policy

We may update this Privacy Policy. Material changes will be notified at least 14 days in advance. Continued use after the effective date constitutes acceptance.

Placeholder notice

Replace with a Termly-generated Privacy Policy before opening paid signups. The Anthropic subprocessor section must be expanded and the explicit consent flow wired up before Layer 4 (AI progress notes) ships.