Legal
Privacy Policy
Effective date: 1 April 2026 · Version 1.0
This Privacy Policy explains how REDROCK SYSTEMS PTY LTD (ABN 53 696 760 433) (“RedRock Systems”, “we”, “us”, or “our”) collects, uses, discloses, and protects personal information in accordance with the Privacy Act 1988(Cth) and the Australian Privacy Principles (APPs) contained in Schedule 1 of that Act. This policy applies to all services, websites, and products operated by RedRock Systems, including CoordHub, RedRock PM, Trim, RedRock AML, Solace, PolicyReady, and Growth Advisory (collectively, the “Services”).
Open and Transparent Management of Personal Information
We are committed to managing personal information openly and transparently. This policy is publicly available on our website at redrocksystems.com.au/privacy. A copy is also available on request by contacting us at hello@redrocksystems.com.au.
We only collect personal information that is reasonably necessary for one or more of our functions or activities. Where it is lawful and practicable to do so, individuals may deal with us anonymously or by pseudonym.
Our Privacy Officer can be contacted at: hello@redrocksystems.com.au or by writing to REDROCK SYSTEMS PTY LTD, Australia.
Collection of Solicited Personal Information
We collect personal information that is reasonably necessary to provide our Services, respond to enquiries, process payments, and comply with our legal obligations.
Information you provide directly
- Identity information: full name, job title, organisation name
- Contact information: email address, phone number, postal or business address
- Account credentials: username and hashed password
- Payment information: billing name, billing address, and card details (processed directly by Stripe — we do not store raw card numbers)
- Profile and configuration data entered into the Services
- Communications you send to us including support requests and enquiries
Information collected automatically
- Usage and interaction data: pages visited, features used, session duration, click paths
- Technical data: IP address, browser type and version, operating system, device type
- Performance data: page load times, Core Web Vitals metrics (collected via Vercel Speed Insights in aggregated, non-identifiable form)
- Error and diagnostic logs
Information collected from third parties
- Payment and fraud-risk signals from Stripe
- Identity verification data (name, date of birth, document type) from identity verification providers used in the RedRock AML and Growth Advisory services, with your prior express consent
Sensitive information
Certain of our Services involve sensitive information as defined in the Privacy Act, including health information (in CoordHub, for NDIS support coordination purposes) and biometric information or government identifiers (in RedRock AML and Growth Advisory, for AML/CTF and KYC purposes). We only collect sensitive information with your express consent or where otherwise permitted by law. See the “Sensitive Information” section below for further detail.
Notification of Collection
At or before the time we collect personal information, or as soon as practicable afterwards, we will take reasonable steps to notify you (or ensure you are aware) of the following:
- Our identity and contact details
- The fact and circumstances of collection
- Whether the collection is required or authorised by law
- The purposes for which we collect the information
- The consequences if the information is not collected
- Other entities or categories of entities to whom we usually disclose the information
- That this Privacy Policy contains information about how to access, correct, or complain about handling of the information
Notification is provided through collection notices displayed on our sign-up forms, account creation flows, and product onboarding screens. Where personal information is collected from a third party, we take reasonable steps to ensure you are notified.
Use and Disclosure of Personal Information
We only use or disclose personal information for the primary purpose for which it was collected, or for a secondary purpose that you would reasonably expect, or where you have consented, or where otherwise permitted by the Privacy Act.
Primary purposes
- Providing, operating, and improving the Services
- Creating and managing your account
- Processing payments and managing billing
- Providing customer support and responding to enquiries
- Sending transactional communications (account notices, receipts, security alerts)
- Complying with legal and regulatory obligations
Secondary purposes
- Analysing aggregated usage patterns to improve product features
- Detecting and preventing fraud, security incidents, and abuse
- Conducting audits, investigations, and resolving disputes
- Sending product updates or marketing communications (only with consent — see APP 7)
Sub-processors and service providers
We disclose personal information to the following categories of third-party service providers who process data on our behalf:
- Supabase Inc — database hosting and authentication, data stored in Sydney (AWS ap-southeast-2)
- Stripe Inc — payment processing and fraud detection (United States and global)
- Resend Inc — transactional email delivery (United States)
- Vercel Inc — web hosting, edge network, and serverless functions (global edge network)
These providers are contractually bound to process personal information only on our instructions and in accordance with applicable privacy laws.
Other disclosures
We may disclose personal information to regulators, law enforcement, or courts where required by law; to professional advisers (lawyers, accountants, auditors) under obligations of confidentiality; and in the event of a business restructure, merger, or acquisition, subject to appropriate confidentiality obligations.
Direct Marketing
We will only use or disclose personal information for direct marketing purposes if we have your consent, or where the information was collected in the course of a commercial relationship and the marketing relates to our similar goods and services.
Every marketing communication we send will include a clear and easy mechanism to opt-out (unsubscribe). You may also opt out at any time by emailing hello@redrocksystems.com.au with the subject line “Unsubscribe”. We will action opt-out requests within five (5) business days. We do not sell personal information to third parties for marketing purposes.
Cross-Border Disclosure of Personal Information
Some of our service providers are located overseas and may receive personal information from us. We take reasonable steps to ensure that overseas recipients handle personal information in a manner consistent with the APPs before any disclosure.
Countries or regions to which personal information may be disclosed include:
- United States — Stripe (payment processing), Resend (email delivery)
- Global edge network — Vercel (hosting and content delivery; data may transit multiple regions)
- Australia (Sydney) — Supabase (primary database storage at AWS ap-southeast-2)
Where personal information is disclosed to overseas entities, we rely on contractual arrangements (including standard contractual clauses or data processing agreements) to ensure an adequate level of protection. By accepting this policy and using our Services, you acknowledge and consent to these cross-border disclosures as described.
Adoption, Use, or Disclosure of Government-Related Identifiers
Some of our Services handle government-related identifiers, including:
- NDIS participant numbers — collected and stored in CoordHub solely for the purpose of providing NDIS support coordination services as required under the NDIS Act 2013 and the NDIS (Registered Providers and Approved Quality Auditors) Rules
- Tax File Numbers (TFNs) — may be collected in RedRock PM in the context of accounting practice management, handled strictly in accordance with the Tax File Number Guidelines issued by the Privacy Commissioner
- Other business identifiers (ABN, ACN) — used for business identification only, not for individual tracking
We do not adopt government-related identifiers as our own identifiers for individuals, and we do not disclose them except as required to deliver the specific service for which they were collected or as required by law.
Quality of Personal Information
We take reasonable steps to ensure that personal information we collect, use, or disclose is accurate, up to date, and complete. These steps include:
- Allowing users to review and update their account information at any time within the platform
- Validating data formats at the point of collection (e.g., email addresses, phone numbers)
- Conducting periodic reviews of data held where operationally appropriate
- Acting promptly on notifications from individuals that their information is inaccurate or out of date
If you believe information we hold about you is inaccurate, incomplete, or outdated, please contact us and we will take reasonable steps to correct it (see APP 13 below).
Security of Personal Information
We take reasonable steps to protect personal information from misuse, interference, loss, unauthorised access, modification, or disclosure. Our security measures include:
Technical controls
- Encryption in transit: TLS 1.2 or higher for all data in transit across all Services
- Encryption at rest: AES-256 encryption applied to all data stored in Supabase (AWS ap-southeast-2)
- Row-level security (RLS): database policies enforced at the storage layer to ensure tenant data isolation — no customer can access another customer's data
- Authentication: secure session management, hashed passwords (bcrypt), optional multi-factor authentication
- Access controls: principle of least privilege applied to all internal system access
- Audit logging: access and modification events logged for security review
Organisational controls
- Access to production systems restricted to authorised personnel only
- Third-party providers vetted for security practices and bound by data processing agreements
- Regular review of access permissions
Notifiable Data Breaches
We comply with the Notifiable Data Breaches (NDB) scheme under Part IIIC of the Privacy Act. In the event of an eligible data breach — one that is likely to result in serious harm to any individual whose information is involved — we will notify the Office of the Australian Information Commissioner (OAIC) and affected individuals as soon as practicable.
Destruction and de-identification
When personal information is no longer needed for any purpose for which it may be used or disclosed, and we are not required by law to retain it, we will take reasonable steps to destroy it or ensure it is de-identified.
Access to Personal Information
You have the right to request access to personal information we hold about you. To make an access request:
- Email us at hello@redrocksystems.com.au with the subject line "Privacy Access Request"
- Include sufficient information to identify yourself and describe the information you are seeking
- We will respond within 30 days of receiving a valid request
We may decline to give access in circumstances permitted under the Privacy Act, including where providing access would pose a serious threat to health or safety, have an unreasonable impact on others' privacy, or where the request is frivolous. If we decline, we will give you written reasons and notify you of available complaint mechanisms.
We will not charge a fee for making an access request, but may charge a reasonable fee for providing access where the retrieval is complex or time-consuming.
Correction of Personal Information
If you believe personal information we hold about you is inaccurate, out of date, incomplete, irrelevant, or misleading, you may request that we correct it. To make a correction request:
- Email us at hello@redrocksystems.com.au with the subject line "Privacy Correction Request"
- Describe the information you believe is incorrect and what the correct information should be
- We will respond within 30 days and take reasonable steps to correct the information
If we decline to correct information, we will give you written reasons. You may request that we attach a statement of the correction sought to the information, which we will do if it is reasonable to do so.
Sensitive Information
Sensitive information as defined in the Privacy Act receives a higher standard of protection. We collect sensitive information only with express consent or where required or authorised by law.
Health information (CoordHub)
CoordHub is used by NDIS support coordinators to manage participant support plans. Health and disability-related information may be entered into CoordHub by our customers (NDIS registered providers). This information is processed on behalf of the customer and is subject to the customer's own obligations under the NDIS Act 2013, the Privacy Act, and the NDIS Practice Standards. We act as a data processor, not a data controller, for this information.
Biometric and identity verification information (RedRock AML)
RedRock AML and Growth Advisory collect identity verification data including facial biometric matches and identity document images to satisfy customer identification obligations under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (AML/CTF Act). This data is collected only with express consent and is processed by integrated identity verification providers. Biometric data is not stored beyond the period required for AML/CTF record-keeping obligations.
Data Retention
We retain personal information only for as long as it is needed for the purpose for which it was collected, or as required by law. Our general retention periods are:
- Account and profile data: retained while your account is active, plus a 30-day recovery period following account closure, then deleted
- Billing and transaction records: retained for 7 years from the date of the transaction (compliance with Australian tax law)
- AML/CTF records (RedRock AML, Growth Advisory): retained for 7 years from the date the relevant transaction or business relationship ends, as required by Part 10 of the AML/CTF Act 2006
- NDIS participant records (CoordHub): retained in accordance with the NDIS Act 2013 and applicable NDIS rules; customers are responsible for their own retention obligations
- Support communications: retained for 3 years from the date of the last interaction
- Audit and security logs: retained for 12 months, then archived or deleted
Cookies and Analytics
We use a minimal number of cookies and do not use third-party tracking or advertising cookies.
Essential cookies
We use session and authentication cookies that are strictly necessary to operate the Services. These cookies expire at the end of your session or after a short fixed period. They cannot be disabled without preventing you from using the Services.
Analytics
We use Vercel Analytics and Vercel Speed Insights to understand how visitors use our website. These tools are privacy-focused: they do not set third-party cookies, do not use fingerprinting, do not track individuals across sites, and do not collect personally identifiable information. All analytics data is aggregated.
Privacy Complaints
If you believe we have interfered with your privacy or breached the Australian Privacy Principles, you may make a complaint to us. We take all privacy complaints seriously.
Step 1 — Contact us
Email your complaint to hello@redrocksystems.com.au with the subject line “Privacy Complaint”. Please include as much detail as possible about the nature of your complaint. We will acknowledge receipt within 5 business days and provide a substantive response within 30 days.
Step 2 — Office of the Australian Information Commissioner (OAIC)
If you are not satisfied with our response, or if we fail to respond within a reasonable time, you may lodge a complaint with the OAIC:
- Website: www.oaic.gov.au
- Phone: 1300 363 992
- Post: GPO Box 5218, Sydney NSW 2001
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. The updated policy will be published on our website with the revised effective date.
For material changes — those that significantly affect how we handle your personal information — we will provide at least 30 days' notice before the changes take effect, via a notice on our website and, where we hold your email address, by direct notification.
Your continued use of our Services after the effective date of any changes constitutes acceptance of the updated policy.
REDROCK SYSTEMS PTY LTD · ABN 53 696 760 433 · ACN 696 760 433 · Australia · hello@redrocksystems.com.au