Legal
Complete legal and compliance suite
Consolidated legal, compliance, and regulatory agreements applicable to the CareLedger website and mobile applications.
Last updated 11 February 2026
This document consolidates all legal, compliance, and regulatory agreements applicable to the CareLedger website and mobile applications (Android and iOS). CareLedger is a secure documentation platform designed for care providers, including NDIS organisations. It does not provide medical, legal, or compliance advice.
1. End-user license agreement
1.1 License grant
CareLedger Pty Ltd (ABN: 44 280 421 1850) grants you a limited, non-exclusive, non-transferable, revocable licence to install and use the CareLedger mobile applications on compatible devices for authorised organisational purposes.
1.2 Scope of license
- Use is limited to authorised users within subscribing organisations.
- The app may only be used in accordance with your subscription plan.
- No sublicensing, resale, redistribution, or commercial exploitation is permitted.
1.3 Prohibited uses
You must not:
- Reverse engineer, decompile, or attempt to extract source code.
- Use the Services for unlawful, fraudulent, or harmful purposes.
- Share login credentials or bypass authentication systems.
- Access or extract data outside permitted exports.
- Attempt to compromise system integrity or security.
1.4 Updates and modifications
CareLedger may update or modify the Services to improve performance, security, or compliance. Continued use constitutes acceptance of updates.
1.5 Suspension and termination
Access may be suspended or terminated if you breach these terms, compromise security, or misuse the platform.
1.6 Service disclaimer
CareLedger provides a documentation and record-management platform only. We implement reasonable security safeguards but do not guarantee uninterrupted or error-free operation. CareLedger is not responsible for incorrect data entered by users.
1.7 Governing law
This agreement is governed by the laws of Tasmania, Australia.
2. Cookie and tracking policy
2.1 Purpose of cookies
Cookies and similar technologies are used to:
- Maintain secure user sessions
- Remember user preferences
- Improve system functionality
- Monitor platform performance and security
2.2 Cookie categories used
- Essential cookies (required for login and secure access)
- Functional cookies (store preferences)
- Analytics tools for system performance monitoring
2.3 No advertising cookies
CareLedger does not use advertising cookies, behavioural tracking technologies, or targeted advertising systems. We do not use personal or health data for advertising or profiling purposes.
2.4 Third-party services
We may use trusted third-party service providers (such as hosting, performance monitoring, and payment processors) solely for operating the platform. These providers are contractually required to maintain data protection standards.
3. NDIS client data consent framework
3.1 Purpose
CareLedger is used by organisations to document care services. Organisations are responsible for obtaining lawful consent before uploading sensitive client information.
3.2 Consent statement template
I, [Client Name], consent to the collection, storage, and processing of my personal and sensitive information within CareLedger by [Organisation Name] for care documentation and compliance purposes.
3.3 Revocation and deletion
Consent may be withdrawn at any time. Upon lawful request, data will be deleted or anonymised unless retention is required under applicable legislation.
3.4 Authorised adult entry
CareLedger is not intended for direct use by children. Sensitive information relating to children or vulnerable persons is entered only by authorised adults under lawful care arrangements.
4. Data processing agreement
4.1 Parties
CareLedger Pty Ltd (Processor) and [Organisation Name] (Controller).
4.2 Purpose
CareLedger processes Personal and Sensitive Information solely to provide secure documentation services.
4.3 Processor obligations
CareLedger will:
- Process data only under documented instructions
- Maintain confidentiality
- Implement technical and organisational safeguards
- Restrict access through role-based permissions
- Assist with access, correction, and deletion requests
- Notify the Controller without undue delay of any confirmed data breach
4.4 Sub-processors
We may engage trusted sub-processors (e.g. secure hosting providers) subject to equivalent data protection obligations. Sub-processors are not permitted to use Personal or Sensitive Information for advertising, marketing, or profiling.
4.5 International transfers
Where data is transferred outside Australia, appropriate contractual safeguards are applied.
4.6 Termination
Upon termination of services, data will be returned or securely deleted in accordance with legal obligations.
5. Health and sensitive data safeguards
CareLedger may store health and disability-related information entered by authorised users. Health and sensitive information is:
- Collected solely for care documentation and compliance
- Encrypted in transit and at rest where applicable
- Accessible only to authorised organisational users
- Never sold or rented
- Never used for advertising or behavioural profiling
- Never shared with third parties for advertising or analytics
6. Data deletion and user rights
Users and organisations may:
- Access their personal information
- Correct inaccurate records
- Request deletion of personal or sensitive information
Deletion requests may be submitted to support@careledger.com.au. Upon verification, data will be deleted or anonymised unless legally required to retain it.
7. Limitation of liability
CareLedger provides a secure documentation platform but does not provide medical, clinical, legal, or NDIS compliance advice. Users are responsible for ensuring their use of the platform complies with applicable laws and organisational policies. CareLedger is not liable for indirect or consequential damages arising from misuse of the platform.
8. Contact
CareLedger Pty Ltd
Email: support@careledger.com.au
Website: www.careledger.com.au