Legal · Privacy · Australia
Privacy Policy
Novada Tech runs the desk for Australian healthcare businesses. We answer calls and enquiries, make and change bookings, coordinate rosters and maintain records, and we do that work inside the systems our clients already run. That means we come into contact with health information about their participants, clients and residents, which Australian privacy law treats as sensitive information and protects more strictly than ordinary personal information.
This policy explains what we collect, why we collect it, who we disclose it to, how long we keep it and what you can do about it. It is written for two different readers: someone using this website, and someone whose information we handle because their care provider engaged us. Section 02 explains which one you are.
- Last updated
- 27 August 2026
- Applies to
- novadatech.com.au and our desk services
- Governing law
- Privacy Act 1988 (Cth)
About this policy
This policy sets out how Novada Tech handles personal information, including health information. It applies to this website, to enquiries and bookings made through it, and to the services we provide to Australian care providers.
It describes our practices. It is not legal advice, and it does not replace the privacy policy of the care provider that holds your record. Where we handle information on behalf of a client, that client's own policy and consent arrangements govern the record itself, and this policy explains our part in it.
This policy is not a collection notice. Where the Privacy Act 1988 (Cth) requires us to tell you specific things at the moment we collect your information, we do that separately, at that moment.
Who we are, and the two roles we play
Novada Tech is an Australian owned and operated business. Our coordinators are onshore in Australia. We do not offshore the desk work.
- Legal entity and ABN: Novada Tech Pty Ltd (ABN 90 665 134 921)
- Registered and postal address: Suite 23, 220 Collins Street, Melbourne VIC 3000
- Privacy contact: support@novadatech.com.au · +61 485 000 813
Role one: information we hold in our own right
This covers people who visit this website, people who make an enquiry or a booking with us, our business clients and the people who work for them, our suppliers, and our own workers and job applicants. We decide how that information is handled, and this policy governs it.
Role two: information we handle for a client
This is the larger part of what we do, and it works differently. We work inside the client's own systems, using access the client grants us, under the client's instructions and the terms of our service agreement. For care providers that means the care management platform they already run, such as ShiftCare, FlowLogic, Brevity or Carelink. For care providers it means platforms such as ShiftCare, FlowLogic, Brevity or Carelink. Nothing migrates to a Novada system. The client keeps the system of record.
In that role the care provider is generally the organisation with the primary relationship to the participant or participant, and the organisation that holds the record. We handle that information as a service provider, for the client's purposes, and not for our own.
If you are a participant, client or resident
Your record belongs to your care provider, not to Novada. Requests to see it, correct it or complain about it should go to them first, because they hold it and they can act on it. If you contact us instead, we will pass your request on to them promptly and tell you we have done so.
What we do not do
Novada does not provide clinical services of any kind. No triage, no clinical advice, no assessment, no diagnosis and no treatment decision. Anything clinical is escalated to the client's own team under an escalation protocol agreed with that client in writing. That boundary is a term of our service agreements.
We do not access the My Health Record system, and we do not collect, use or handle Individual Healthcare Identifiers. If that ever changes we will update this policy before the change takes effect, because the Healthcare Identifiers Act 2010 (Cth) and the My Health Records Act 2012 (Cth) would then also apply to us.
The laws that apply to us
The primary law is the Privacy Act 1988 (Cth) and the thirteen Australian Privacy Principles in Schedule 1 to that Act, which cover open and transparent management (APP 1), anonymity (APP 2), collection (APPs 3 to 5), use and disclosure (APP 6), direct marketing (APP 7), cross border disclosure (APP 8), identifiers and quality (APPs 9 and 10), security (APP 11) and access and correction (APPs 12 and 13).
The small business exemption, and why we do not use it
Section 6D of the Privacy Act 1988 (Cth) exempts many businesses with an annual turnover of $3 million or less. Two things about that exemption matter here.
- It does not apply to health service providers. Section 6D(4)(b) removes the exemption from an entity that provides a health service to another individual and holds health information other than in an employee record. Turnover is irrelevant. Our care provider clients are covered by the Privacy Act whatever their size.
- The definition of a health service is broad. Section 6FB defines a health service to include an activity performed in relation to an individual that is intended to assess, record, maintain or improve that individual's health. The line between a clinical service and an administrative service performed on a health record is not always obvious.
For those reasons we do not rely on the small business exemption. We handle health information to the standard the Australian Privacy Principles set, regardless of whether a court would find the exemption available to us, and our service agreements require the same thing.
Removing the small business exemption generally is a proposed second tranche reform that the Australian Government has agreed to in principle. As at the date of this policy it has not been legislated and no commencement date has been set, so the exemption remains part of the Act.
Amendments in force
The Privacy and Other Legislation Amendment Act 2024 (Cth) received assent on 10 December 2024 and commenced most of its provisions on that day. Three consequences are relevant to this policy:
- APP 11.3 now states expressly that the reasonable steps required to secure personal information include technical and organisational measures.
- A statutory cause of action for serious invasions of privacy, in Schedule 2 to the Privacy Act, commenced on 10 June 2025. It allows an individual to sue for intrusion upon seclusion or misuse of information, and it applies more widely than the Australian Privacy Principles do.
- New transparency obligations about automated decision making, in APPs 1.7 to 1.9, commence on 10 December 2026. See section 17.
State and territory health records law
State and territory health privacy legislation can apply in addition to the Commonwealth Act, not instead of it, so a single record can be covered by both. The laws most likely to be relevant to our clients are:
- Health Records and Information Privacy Act 2002 (NSW), which sets fifteen Health Privacy Principles and applies to private sector persons in New South Wales who are health service providers or who collect, hold or use health information.
- Health Records Act 2001 (Vic), which sets eleven Health Privacy Principles and applies to organisations that handle health information in Victoria.
- Health Records (Privacy and Access) Act 1997 (ACT), which covers health records in the Australian Capital Territory.
Sector rules our clients pass on to us
Our care provider clients are subject to obligations we support but do not hold ourselves, including the National Disability Insurance Scheme Act 2013 (Cth) together with the NDIS Code of Conduct and the NDIS Practice Standards, and the Aged Care Act 2024 (Cth), which commenced on 1 November 2025 and restricts the use and disclosure of protected information. Where a client passes such a requirement to us in our service agreement, we work to it.
Electronic and telephone marketing is separately governed by the Spam Act 2003 (Cth) and the Do Not Call Register Act 2006 (Cth). See section 11.
The information we collect
a. Website visitors
When you open a page on novadatech.com.au, the tools in section 08 collect your IP address and the approximate location it suggests, your device type, browser and operating system, the pages you view and how long you spend on them, the page or advertisement that sent you, and cookie and advertising identifiers.
b. Enquiries and bookings
If you contact us or book a review, we collect your name, email address, phone number, business name and role, the type of care service you run, the workload you described,
c. Clients, suppliers and their people
For the businesses we work with, we collect contact details and roles, the system access arrangements the client sets up, and contract and billing information.
d. Information we handle for a client, inside the client's systems
For the Operations Partner, working inside a provider's care management platform, this can include: participant, client and resident names and contact details; service, shift and rostering details; call-off and availability records; notes and escalations recorded during after-hours calls; intake administration records; and the statutory records we maintain on the client's behalf. Some of this is health information.
For the Workforce Partner, this can include candidate and worker names and contact details; work history, qualifications and referee details; onboarding, induction and training records; and screening and credential records. Screening records can include criminal record information, which is also sensitive information under the Privacy Act.
Where a client engages a worker from the pool, we hold the worker's screening and credential verification and the record of the engagement itself. The service agreement for that engagement is between the client and the worker; we do not employ those workers and we do not run their payroll, so we do not hold their pay records.
The employee records exemption in section 7B(3) of the Privacy Act 1988 (Cth) concerns an organisation's own current and former employees. We do not treat worker records we handle for a client as exempt employee records.
e. Telephone calls
We answer calls for our clients, so we receive whatever the caller tells us and record the outcome in the client's system.
We do not record telephone calls. If a client chooses to record calls on their own service, that recording is the client's own arrangement. The client is responsible for it, including for meeting the notification and consent obligations that apply under the Telecommunications (Interception and Access) Act 1979 (Cth) and the surveillance and listening devices legislation of the relevant State or Territory.
f. Our own people
We collect the information we need to recruit, employ or engage our coordinators and to meet our obligations as an employer.
Health information and other sensitive information
Section 6FA of the Privacy Act 1988 (Cth) defines health information broadly. It includes information or an opinion about an individual's health or disability, information about a health service provided or to be provided to them, and other personal information collected in the course of providing a health service. A roster record that names a participant and the support they are receiving is health information.
Health information is sensitive information under section 6(1) of that Act, and sensitive information carries a higher bar. Under APP 3.3, an organisation must not collect sensitive information unless the individual consents and the collection is reasonably necessary for one or more of the organisation's functions or activities, unless an exception in the Act applies. Under APP 7.4, sensitive information may only be used or disclosed for direct marketing with the individual's consent.
How that works in practice for us
- Where we collect or record health information, we do so on behalf of and at the direction of the client, inside the client's system, for the purpose the client engaged us for. The consent framework covering that record is the client's, obtained under the client's own privacy arrangements.
- We use it only for that purpose, and for directly related purposes the individual would reasonably expect, consistent with APP 6.
- We do not sell personal information or health information, and we do not use health information we handle for a client for our own marketing or business development.
- We do not configure the analytics and advertising tools described in section 08 to receive health information, and health information from a client's system is not sent to them.
The clinical boundary
Nothing we do is a clinical act. We do not triage, assess, diagnose, advise or treat. If a call raises anything clinical, it goes to the client's own team under the escalation protocol agreed with that client.
How we collect it
Under APP 3.6, an organisation must collect personal information about an individual only from that individual, unless the individual consents to collection from someone else or it is unreasonable or impracticable to collect it directly. We collect information:
- Directly from you, when you call us, email us, use the booking widget or the chat widget on this website, or speak to one of our coordinators.
- Automatically from your device, through the cookies, tags and pixels described in section 08.
- From our client, or from the client's system, where we are working on that client's behalf under access the client has granted us.
- From a third party at a client's direction, for example a referrer or another provider, where the client's own arrangements allow it.
Where we collect a participant's information, we are collecting it for the client, into the client's record, and the client is responsible for the collection notice that goes with it.
How we use it, and who we disclose it to
We use personal information to:
- answer calls, messages and enquiries for our clients and for ourselves;
- administer rosters, coordinate call-offs and after-hours cover, process intake administration and maintain the statutory records a client is required to keep;
- source and screen candidates against a client's criteria for the client's own workforce, administer onboarding, and maintain induction, training, screening and credential records;
- verify screening and credentials for workers in the pool, make availability visible to a client, and record the evidence of an engagement a client enters into directly with a worker;
- produce the monthly report we give each client, covering what came in, what we did, what was escalated and what was recorded, measured against the baseline taken at onboarding;
- respond to your enquiry, prepare for a review call and follow up with you;
- operate, secure, measure and improve this website;
- invoice, keep our own business records and meet our legal and tax obligations; and
- handle complaints, disputes and insurance matters.
Who we disclose it to
- The client, for anything we handle on their behalf. This is the main disclosure, and in most cases the information never leaves the client's own system.
- Our coordinators and staff, limited to the people assigned to that client, under written confidentiality obligations.
- Technology suppliers that run this website, our customer relationship management and booking platform, and the analytics and advertising tools in sections 08 and 09. Beyond those, we work inside the systems our clients already run. The only system we supply is a telephone number that a client forwards their after-hours line to, so that calls reach our coordinators. If an engagement ever requires an additional tool, we tell the client before it is introduced.
- Professional advisers, such as our accountants and lawyers, where they need it.
- Anyone we are required or authorised by law to disclose to, including a court, tribunal or regulator, or where disclosure is necessary to lessen or prevent a serious threat to life, health or safety.
We do not sell personal information, and we do not disclose it to third parties for their own independent marketing purposes.
Cookies, analytics and advertising tracking
This website loads four tracking tools, and only these four:
- Google Tag Manager, a container that loads the Google tags below.
- Google Analytics, which measures how the website is used, managed through that container.
- Google Ads conversion tracking, which tells us which advertisement produced an enquiry or a booking, also managed through that container.
- The Meta pixel, which measures the performance of advertising on Facebook and Instagram and can be used to build advertising audiences.
Between them these tools collect the website visitor information listed in section 04, set cookies and similar identifiers in your browser, and share that information with Google and Meta, who process it on their own infrastructure. See section 10 for where that infrastructure is.
These tools load when a page opens, and this website does not currently present a cookie consent banner. If you do not want this collection, you can:
- block or delete cookies, or use private browsing, through your browser settings;
- install the Google Analytics opt-out browser add-on from tools.google.com/dlpage/gaoptout;
- adjust the advertising settings in your Google account and your Meta account; or
- use a browser or extension that blocks tracking scripts.
Blocking cookies and scripts may stop parts of this website working, including the booking widget. The privacy policies of the two providers are at policies.google.com/privacy and facebook.com/privacy/policy.
The Office of the Australian Information Commissioner published guidance on tracking pixels and privacy obligations in November 2024. It makes clear that responsibility for a pixel sits with the organisation that deploys it, not with the provider whose code is being used. We treat that responsibility as ours.
Third party tools embedded in this website
The booking widget
Our booking calendar is embedded from link.novadatech.com, which is our customer relationship management and booking platform. The calendar is an iframe served from that domain, so anything you enter into it goes to that platform and then into our customer records. The widget sets its own cookies and receives the campaign parameters we attach to the embed address, which is how we know which page produced a booking.
The booking embed also writes a short value to your browser's session storage recording which page you booked from, so the confirmation page can greet you correctly. It is cleared when you close the tab.
The chat widget
On some pages of this website, but not all of them, we load a chat widget from widgets.leadconnectorhq.com, which is part of the same platform. Where it appears, anything you type into it, including your name and contact details, goes into that platform and becomes an enquiry record.
Links to other sites
This website links to sites we do not run. We are not responsible for their content or their privacy practices, and this policy does not apply to them.
Sending information overseas
APP 8 and section 16C of the Privacy Act 1988 (Cth) govern disclosure of personal information to an overseas recipient. Before we disclose, we must take reasonable steps to ensure the recipient does not breach the Australian Privacy Principles, and if the recipient then mishandles the information we can be held accountable for that act as though we had done it ourselves. Reasonable steps is an obligation to act carefully, not a guarantee about what an overseas company will do.
The overseas processing that applies to us is:
- Google and Meta. The website tracking described in section 08 sends information to Google and to Meta, who process and store it on infrastructure outside Australia, including in the United States.
- Our customer relationship management and booking platform. Enquiries, bookings and chat messages made through this website are stored in that platform. Enquiry and booking records submitted through this website are held in our customer relationship management and booking platform, which stores that data in Australia.
The desk service itself is delivered onshore. Our coordinators are in Australia, and participant and participant records stay in the client's own system. We do not export a client's records overseas as part of delivering the service, and we do not send health information to the tracking tools in section 08.
Marketing, email and SMS
Our own marketing
We may send you information about our services if you gave us your details or you would reasonably expect to hear from us, and every message carries a way to stop. Under APP 7.4, sensitive information, including health information, may only be used for direct marketing with consent. To opt out of our marketing, use the unsubscribe link in any email, reply STOP to any SMS, or email support@novadatech.com.au.
Commercial electronic messages are governed by the Spam Act 2003 (Cth), which requires consent, accurate identification of the sender with contact details that stay current for at least thirty days, and a functional unsubscribe facility that works for at least thirty days after the message is sent. Opt-outs must be actioned within five working days, and we action them sooner where we can. Telemarketing calls are governed by the Do Not Call Register Act 2006 (Cth). Under APP 7.8, APP 7 does not apply to the extent that those Acts apply.
Messages we send on a client's behalf
When we contact a client's workers, candidates, participants or their nominated contacts, we do so as the client, not as Novada. Those are the client's messages, sent from the client's system, under the client's own consent records and instructions, and opt-outs are recorded in the client's system.
If you want a client's messages to stop
Reply as the message tells you, or contact the provider directly, because the consent record lives with them. You can also tell us at support@novadatech.com.au and we will pass it on to them and record it in their system.
How we protect information
APP 11 requires us to take reasonable steps to protect personal information from misuse, interference and loss and from unauthorised access, modification or disclosure. Since 10 December 2024, APP 11.3 states expressly that those reasonable steps include technical and organisational measures.
The measures we rely on are:
- working inside the client's own system, using credentials the client issues and permissions the client sets, so the record stays in the client's system of record rather than being copied into ours;
- limiting access to the coordinators assigned to that client;
- written confidentiality obligations on everyone who works for us, and onshore Australian staffing;
- access controls and authentication on the systems we use, and encryption in transit on this website; and
- returning or revoking system access at the end of an engagement.
What we are not claiming
We hold no security certification or accreditation, and this policy does not claim one. We do not describe our controls as bank grade, military grade or fully compliant, because those phrases mean nothing and promise everything. No system connected to the internet can be made completely secure, and we cannot guarantee absolute security.
How long we keep information
APP 11.2 requires us to take reasonable steps to destroy or de-identify personal information once we no longer need it for any purpose for which it may be used or disclosed, and we are not required by law or a court order to keep it.
- Our own record of the work. We keep our own operational log of what we did and when: what came in, what we did about it, who did it, what we escalated and to whom, and what we reported to the client. That log is our record, not a copy of theirs, and it is what our monthly reports and any audit response are built from. For care provider clients, the onboarding, induction, training and compliance records we maintain are kept to a seven year statutory retention standard. For all other engagements we keep the log for as long as we need it to answer for the work, and no longer than our limitation period obligations require.
- Records inside a client's system. These are kept by the client, under the client's own retention obligations, which can be long. For example, section 25 of the Health Records and Information Privacy Act 2002 (NSW) generally requires a health service provider to keep health information for seven years from the last occasion a health service was provided to an adult, and where it was collected while the individual was under eighteen, until that person turns twenty-five. Health Privacy Principle 4 under the Health Records Act 2001 (Vic) sets a comparable standard.
- Website enquiries and bookings. Records of enquiries and bookings made through this website are held in our customer relationship management and booking platform and are automatically deleted once they are more than 12 months old.
- Copies of a client's participant, client or resident records. We do not keep them. That work is carried out inside the client's own systems and those records stay there, under the client's own retention rules. Where our own log necessarily names a participant or a participant, for example to record that a call was returned or a booking was made, we hold that entry as part of our record of the work we did. It is not a copy of the client's file, and we do not assemble one.
- Business records. Contracts, invoices and accounting records are kept for as long as our tax, corporate and limitation period obligations require.
Data breaches
The Notifiable Data Breaches scheme in Part IIIC of the Privacy Act 1988 (Cth) applies to us. An eligible data breach occurs where there is unauthorised access to, unauthorised disclosure of, or loss of personal information, that is likely to result in serious harm to one or more individuals, and the harm has not been prevented by remedial action.
Our pathway is:
- contain the breach and assess it. Where we suspect an eligible data breach, we take all reasonable steps to complete that assessment within thirty days of becoming aware of the grounds for suspicion, and faster wherever we can, because the risk of harm grows with time;
- where we have reasonable grounds to believe an eligible data breach has occurred, notify the Office of the Australian Information Commissioner and the affected individuals as soon as practicable, with what happened, the kinds of information involved and what those individuals should do; and
- where the breach concerns information we handle for a client, notify that client without delay so they can meet their own obligations, and agree with them who notifies the individuals so nobody is told twice and nobody is missed.
The sensitivity of the information affected is one of the factors in whether serious harm is likely. Health information is among the most sensitive kinds of personal information there is, and we treat any incident involving it accordingly.
Accessing and correcting your information
Under APP 12 you may ask for access to the personal information we hold about you, and under APP 13 you may ask us to correct it if it is inaccurate, out of date, incomplete, irrelevant or misleading. We respond within a reasonable period, which the Office of the Australian Information Commissioner considers should generally not exceed thirty days.
There is no charge for making an access request, and no charge for a correction. We may charge for the reasonable cost of giving access, and any such charge will not be excessive. We may need to verify your identity first, and if we refuse a request we will tell you why in writing and how to complain.
Which organisation to ask
If the information is in a participant, client or resident record held in a provider's system, ask that provider. They hold the record and they can act on it. Equivalent access and correction rights exist under Health Privacy Principles 6 and 7 of the Health Records and Information Privacy Act 2002 (NSW) and under Part 5 and Health Privacy Principle 6 of the Health Records Act 2001 (Vic).
If the information is something Novada holds in its own right, such as an enquiry you made through this website, email support@novadatech.com.au and tell us what you are looking for.
Dealing with us anonymously
APP 2 gives you the option of dealing with us anonymously or under a pseudonym where that is lawful and practicable. You can read this website without telling us who you are, subject to the tracking described in section 08, and you can ask us a general question by phone without giving your name.
We cannot coordinate a shift or update a record in a provider's system anonymously, because the provider's record has to identify the person it belongs to.
Automated decision making
From 10 December 2026, APPs 1.7 to 1.9 of the Privacy Act 1988 (Cth), inserted by the Privacy and Other Legislation Amendment Act 2024 (Cth), require an organisation to state in its privacy policy whether it uses a computer program to make, or to do a thing substantially and directly related to making, a decision that could reasonably be expected to significantly affect an individual's rights or interests, where personal information about that individual is used in the operation of the program. If it does, the policy must set out the kinds of personal information and the kinds of decisions involved. The obligation is a transparency measure.
We do not use automated decision making. Our coordinators work inside our clients' own systems, and where an automated feature exists in one of those systems it is configured and controlled by the client rather than by us. If we ever introduce a system of our own that makes, or substantially contributes to, a decision significantly affecting an individual, we will update this policy before it is used.
Complaints
Step one: tell us
If you think we have mishandled your personal information, contact us first. Email support@novadatech.com.au with the subject line Privacy complaint, or call +61 485 000 813. We will acknowledge your complaint, investigate it and give you a written response, and we aim to do that within thirty days. Complaints are handled by Ade Eni, Privacy Officer.
Step two: escalate
If you are not satisfied with our response, or we do not respond, you can take it further. These offices generally expect you to have complained to the organisation first and given it about thirty days to respond.
- Office of the Australian Information Commissioner for complaints under the Privacy Act 1988 (Cth). oaic.gov.au · 1300 363 992 · online complaint form at webform.oaic.gov.au · GPO Box 5288, Sydney NSW 2001.
- Privacy Commissioner, Information and Privacy Commission NSW for health information complaints under the Health Records and Information Privacy Act 2002 (NSW). 1800 472 679 · ipcinfo@ipc.nsw.gov.au · ipc.nsw.gov.au.
- Health Complaints Commissioner, Victoria for health information complaints under the Health Records Act 2001 (Vic). 1300 582 113 · hcc.vic.gov.au.
If your complaint is about a record held by your care care provider rather than by us, raise it with them first. They hold the record.
Changes to this policy
We review this policy from time to time and will update it when our practices, our services or the law change. The current version is always published on this page with the date it took effect, shown at the top and repeated below. Where a change is significant, we will say so on this page.
This version took effect on 27 August 2026. It replaces all earlier versions.
How to contact us
For anything in this policy, including access, correction and complaints:
- Phone
- +61 485 000 813
- Privacy Officer
- Ade Eni, Privacy Officer
- Postal address
- Suite 23, 220 Collins Street, Melbourne VIC 3000
- Entity and ABN
- Novada Tech Pty Ltd (ABN 90 665 134 921)
- Effective
- 27 August 2026
You can read the Australian Privacy Principles and the Commissioner's guidance at oaic.gov.au, and the legislation named throughout this policy at legislation.gov.au and on the relevant State legislation registers.
Real people, onshore · Australian owned · Nothing clinical, ever