Skip to main content

Privacy

CareLedger privacy policy and health module compliance

How CareLedger collects, uses, and protects information across our web and mobile platforms.

Last updated 11 February 2026

CareLedger Pty Ltd (ABN: 44 280 421 1850) ("CareLedger", "we", "us", "our") operates the CareLedger mobile applications (Android and iOS), web platform, and related services (collectively, the "Services"). CareLedger is a secure digital documentation and record-management platform designed for healthcare and disability service providers, including NDIS-registered organisations.

This Privacy Policy is prepared in accordance with the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs), Google Play Developer Program Policies, the Google Play Health Apps Policy, and applicable Sensitive Data and User Data policies.

CareLedger provides digital tools that enable authorised staff within registered organisations to record and manage service-related documentation. The platform allows users to document daily support activities, personal care, continence support, visitor information, incident reports, rest charts, and other organisational records for compliance and auditing purposes. CareLedger also includes medication administration recording functionality, enabling authorised staff to log medication administration events, record PRN usage, track medication quantities, and document witnessing requirements.

CareLedger does not provide healthcare services, medical advice, clinical decision support, diagnosis, prescribing guidance, or medication recommendations. All clinical decisions, medication administration, and service delivery remain the responsibility of qualified healthcare professionals and registered care organisations using the platform.

1. Acceptance

By using the CareLedger Services you agree to this Privacy Policy. If you do not agree, you must not use the Services.

2. Information we collect

2.1 Account information

We collect basic account details such as your name, email address, phone number, organisation name, and user role when you register or use the Services.

2.2 Care and documentation data

Authorised organisations may enter care-related information into the platform, including participant details, support notes, care logs, incident reports, medication records, visitor records, health observations, and activity or nutrition entries. This information is entered and controlled by the registered care organisation.

2.3 Technical data

We may automatically collect limited technical information such as device details, IP address, app version, log data, and usage analytics to maintain security and improve the Services.

3. How we use and store information

We use the information we collect to operate and maintain the CareLedger Services, enable secure digital documentation, improve platform functionality, provide customer support, prevent misuse, and comply with applicable legal obligations. CareLedger does not sell personal information.

Information is securely stored using encrypted data transmission and protected cloud-based infrastructure with access controls and authentication safeguards. We take reasonable steps to ensure that personal and organisational data is stored securely and protected from unauthorised access, disclosure, or loss in accordance with applicable privacy laws.

4. How the CareLedger AI Assistant handles your data

We designed the assistant around the assumption that AI in a clinical setting is dangerous if unbounded. The constraints below are technical, not promises.

4.1 What the assistant can see

When you ask the assistant a question, the model receives:

  • your prompt text;
  • the list of tools it is allowed to call (read-only data fetchers and UI component selectors, never write paths);
  • whatever fields each tool explicitly chooses to return.

It does not see your full database, free-text chart notes that have not been requested by a tool, or any participant identifier that is not strictly required for the requested card.

4.2 What the assistant can do

  • Render a verified card from your live record (read-only).
  • Draft a message for you to review and send (draft-only).
  • Summarise a shift, a chart series, or a roster (read-only).

4.3 What the assistant cannot do

  • Sign a MAR cell, give a medication, or hold or refuse a dose.
  • Perform dose calculations, sliding-scale insulin math, or PRN authorisation.
  • Trigger or silence a clinical alarm.
  • Run an allergy or interaction check as a decision (it can surface the result of our rules engine, never the decision).
  • Write to any chart, audit log, or billing record.
  • Execute generated code in your browser.

This list extends, and does not contradict, the existing CareLedger clinical-scope disclaimer in the preamble of this policy.

4.4 Where the AI calls happen

All AI calls are processed in our Australian region. Inference runs in-region under a written Data Processing Agreement that prohibits training on your prompts. We log the prompt, the tool calls made, the data each tool returned, and the card the user actually saw, and retain those logs for the same period as your clinical audit log. Participant records never leave the Sydney and Melbourne ISO 27001 region.

4.5 Your right to opt out

The assistant is a per-tenant feature flag, a per-role permission, and a per-participant opt-out. A participant or their guardian can ask the registered care organisation to switch AI summaries about them off. The request and the change are recorded in the audit log. Service is unaffected; the assistant simply skips that participant.

4.6 What happens if the assistant is wrong

Every rendered card carries a banner: “This is the assistant’s read of your record. Confirm in the MAR before acting.” The fixed clinical workflow is the source of truth. The assistant is a navigator, not a decision-maker. If a card looks wrong, the audit log lets you reproduce the exact prompt, tool calls, and data the model saw.

5. Health and sensitive information

CareLedger may process health-related and other sensitive information that is entered into the platform by authorised organisations. This information is used solely to provide secure documentation and record-keeping services.

CareLedger does not provide medical advice, diagnose conditions, prescribe medication, recommend treatment, or offer clinical decision support. All healthcare and clinical decisions remain the responsibility of qualified healthcare professionals and the registered care organisation using the platform.

6. Data security

CareLedger takes reasonable steps to protect personal and organisational information from loss, misuse, unauthorised access, disclosure, alteration, or destruction. We implement appropriate technical and organisational safeguards, including encrypted data transmission, secure cloud infrastructure, firewalls, authentication controls, and restricted access permissions.

Where you request access to personal information, we may require verification of identity to protect data security and prevent unauthorised disclosure.

To ensure the proper operation of the CareLedger platform and comply with applicable legal obligations, authorised CareLedger personnel or approved contractors may access information where necessary for support, maintenance, security, or compliance purposes. All authorised personnel are bound by strict confidentiality agreements and internal data protection policies.

If you suspect any misuse, loss, or unauthorised access to information within CareLedger, please notify us immediately so appropriate action can be taken.

7. Data sharing

We may share information only where necessary to operate the Services, including with authorised users within your organisation, secure cloud hosting and technology providers, or where required by law. We may also disclose information where necessary to protect rights, safety, or comply with legal obligations.

CareLedger does not sell, rent, or trade personal information.

8. Data retention

We retain information for the duration of your organisation's subscription and as required to comply with legal, regulatory, audit, and compliance obligations.

Organisations may request data export prior to account termination, subject to applicable laws and contractual terms.

9. Your rights

Under the Privacy Act 1988 (Cth) and the Australian Privacy Principles, you have the right to request access to the personal information we hold about you and to request correction of any information that is inaccurate, incomplete, or outdated.

Where legally permitted, you may also request deletion of your personal information.

CareLedger will respond to such requests within a reasonable timeframe. In some cases, we may need to verify your identity or may be unable to delete certain information where it is required for legal, regulatory, audit, or compliance purposes.

To make a request, please contact us at info@careledger.com.

10. Children's privacy

CareLedger is designed for use by authorised adult care providers and organisations. The Services are not intended for direct use by children.

We do not knowingly collect personal information directly from children. Any information relating to minors is entered and managed solely by authorised care organisations in accordance with their legal and professional obligations.

11. International transfers

CareLedger hosts and processes information within Australia.

If, in the future, data is transferred or hosted outside Australia, we will ensure that appropriate legal, contractual, and security safeguards are in place to protect personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles.

12. Changes to this privacy policy

We may update this Privacy Policy from time to time to reflect changes in our Services, legal or regulatory requirements, security practices, or business operations. Updates will be published on this website and take effect upon posting.

13. Health module compliance statements

CareLedger provides documentation tools only.

The platform records and stores information entered by authorised care organisations and does not provide healthcare services, medical advice, diagnosis, or treatment.

In healthcare services and management, CareLedger allows organisations to record daily support activities, personal care, continence support, visitor logs, and incident reports. It does not deliver healthcare services, assess medical conditions, or make care decisions.

In medication and treatment management, authorised staff can record medication administration, PRN usage, quantities, and witnessing details. CareLedger does not recommend medication, suggest dosage changes, provide prescribing advice, or calculate adjustments.

Across diseases and conditions, sleep, activity, and nutrition modules, CareLedger stores observational information entered by authorised staff. It does not diagnose conditions, interpret clinical data, generate treatment plans, or provide medical advice.

14. Chart customisation and organisational control

All charts, modules, and documentation templates within CareLedger are fully customisable by the subscribing organisation. Organisations may add, remove, or modify fields, adjust chart structures, create organisation-specific formats, configure charts to individual client needs, and tailor forms to meet internal policies and compliance requirements.

CareLedger does not determine what information must be recorded and does not enforce clinical standards or care protocols.

15. Cookies and website analytics

We may use cookies on our website to recognise returning visitors, remember preferences, and analyse website traffic. Most browsers automatically accept cookies, but you may choose to disable them through your browser settings.

16. Third-party websites and services

CareLedger may engage trusted third-party service providers to support the operation of our platform, including secure cloud hosting, analytics, security services, and payment processing. Third parties operate lawfully and maintain their own privacy policies and data protection standards.

17. Contact and privacy enquiries

You may contact CareLedger at any time to request access to the personal information we hold about you, request corrections, ask questions about this Privacy Policy, or lodge a privacy-related complaint.

Email support@careledger.com.au.

If you are not satisfied with our response, or if your complaint remains unresolved after 30 days, you may escalate the matter to the Office of the Australian Information Commissioner (OAIC).