Privacy

Privacy Policy

Effective 15 September 2026 · Version 1.8

This Privacy Policy explains how True North Analytics ("we", "us", "our") handles personal information when you, your organisation, or your end-users use Accorda (the "Service"). True North Analytics operates as a sole trader from New South Wales, Australia (ABN 24 726 502 584).

This policy covers what we do as the operator of the Service. If you are an end-user accessing Accorda at the invitation of an organisation that has subscribed to the Service (your "Customer Organisation"), that organisation is the data controller for your personal information, and a separate notice applies inside the Service describing what they collect from you. This policy describes our role as their data processor.

1. Who we are

True North Analytics is a sole-trader business operating Accorda from New South Wales, Australia. We hold an Australian Business Number (ABN 24 726 502 584). We are bound by the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles ("APPs").

For all privacy enquiries, contact us at privacy@accorda.com.au.

2. What this policy covers

This policy covers:

  • Personal information we collect when you visit our public marketing pages
  • Personal information we collect when an organisation signs up for Accorda
  • How we handle personal information processed on behalf of Customer Organisations
  • Your rights and how to exercise them

It does not cover:

  • The information practices of any third party we do not control (including Customer Organisations themselves; see their own privacy notices)
  • Information you choose to upload into Accorda as part of compliance documentation (Customer Organisations are responsible for the lawful basis for that processing — see Section 7)

3. Personal information we collect

3.1 From visitors to our public website

When you visit pages such as our marketing site or this policy, we may collect:

  • Standard server logs (IP address, user-agent, page accessed, timestamp), retained for up to 30 days for security and operational purposes
  • Cookies set by analytics, advertising, or session-management tools, where used (see Section 5)

3.2 When you use the funding planner

The funding planner is a free tool on our public website. The plan you build in it is held in your own browser, and the words you type into it — the plan label, the description of each support, anything you write about a person — are never sent to us. How large that plan is, we do record: the usage log described further down this section sets out exactly what that means. When you ask the tool for a download, it asks for your email address first, and we create a record of that request.

That record holds:

  • The email address you enter
  • Your answer to the marketing consent question, recorded as you gave it — a record that you left the box unticked is not the same as no record at all
  • Which file you asked for (the spreadsheet or the image)
  • The IP address the request reached us from, the user-agent your browser sent, and the address of the page it was sent from (the referrer)
  • The date and time the record was created

We keep the email address so that we can answer you and, if you consented, send you occasional updates about Accorda, and the name of the file so that we know which tool the request came from. The request details and the timestamp are kept as evidence of when and where the consent was given: this form is open to the public internet and anyone can post to it, so without them we could not tell a genuine request from a forged one, or show that an address on our list asked to be there. They are not used to build a profile of you or to follow you across other websites. Section 10.1 states how long the record is kept.

The pages of the tool carry the same page-view measurement as the rest of our website (see Section 5). They do not carry the Meta Pixel: it is kept off this tool deliberately, so opening one of its pages is not reported to Meta and no advertising cookie is set while you use it. Nothing you type into the tool forms part of either.

Page views are not all we record about the planner. The tool also keeps a usage log of its own, whether or not you ever ask for a download. It is written each time the tool reaches one of a handful of moments, and it holds no identifier that joins an entry to your export record, to your email address, or to any other visit — no account, no session token, and no marker kept in your browser to recognise you by. Each entry does carry the date and time it was written, as your export record does, and we do not match one against the other.

Each entry in that log holds:

  • Which step of the tool the visit reached — that the planner was opened, that funding blocks were generated, that supports were allocated against them, that a download was asked for, or that an email address was given
  • How large the plan open in your browser was at that moment: the total it budgets and the total it commits, both in dollars, how many funding blocks it runs to, and how many disciplines it covers
  • Any campaign tags carried in the link that brought you to the tool (the utm_source, utm_medium, utm_campaign and utm_content values a marketing link adds to a web address)
  • The address of the page you came from (the referrer), reduced to the site and page — anything after the question mark is dropped before the entry is written
  • Whether you are on a phone, a tablet or a desktop, recorded as one of those three words and nothing more specific
  • The date and time the entry was written

Whether the plan has funding blocks in it, and whether supports have been allocated against them, are read off the plan open in your browser rather than off a button you press: a plan you saved on an earlier visit and had restored registers both of those steps without you doing anything to it. We use this to see how many people open the planner and how far through it they get, which is how we judge whether the tool is worth keeping and improving. What it records about a plan is its size and nothing else: no participant name, no plan name, no description of a support, and none of the other words you type into the tool. Those stay in your browser — the log has no field that could hold them, and the tool has no way to send them.

3.3 When you sign up your organisation

When an authorised representative of an organisation signs up for Accorda, we collect:

  • Their name, email address, and role
  • Organisation name and (if provided) ABN
  • Billing details necessary to process payment (handled by Stripe — we do not store card numbers ourselves)

3.4 When end-users use the Service

When end-users from a Customer Organisation use Accorda, the Service collects information *on behalf of the Customer Organisation* (who is the data controller). This typically includes:

  • Email address and full name
  • Role assigned by their administrator
  • Records of policy sign-offs, including timestamp, declaration text, IP address, and user-agent
  • Audit log entries describing administrative actions
  • Incident records, including: incident title, date of occurrence, type, severity, status, assigned owner, service context (brief description of who or what was affected), triage notes, and AI-generated provenance metadata describing how the incident was identified and categorised
  • External reporting details for incidents (such as the authority or regulator the incident was reported to, reference numbers, dates, and notes about the report)
  • Optional attachments to incident records (such as photographs, documents, or other files uploaded by authorised users)

We process this information solely on the instructions of the Customer Organisation, under our standard Data Processing Agreement.

3.5 Sensitive information

We do not knowingly collect "sensitive information" as defined by the Privacy Act (such as health information, racial or ethnic origin, political opinions, religious beliefs, sexual orientation, or biometric data). End-users and administrators must not enter sensitive information into free-text fields in the Service. Customer Organisations are responsible for instructing their personnel accordingly.

Incident records and incident attachments may naturally include references to or information about your clients, patients, service recipients, or other vulnerable individuals. Incident records in regulated sectors (such as healthcare, aged care, NDIS, childcare, and other community services) commonly document events involving vulnerable people, and may therefore contain health information or information about safeguarding concerns. When recording incidents, the Customer Organisation must ensure: (1) that it has a documented lawful basis for collecting and recording the incident information under Australian privacy law and any other applicable law, (2) that consent has been obtained where required by law, and (3) that any attachments to incidents (such as photographs) do not contain identifiable information about such individuals unless absolutely necessary and lawfully authorised. Accorda is designed to support compliance management and incident tracking, but is not a specialised system for medical records, safeguarding case management, or the secure handling of sensitive incident media; if your incident records or attachments frequently contain sensitive information about vulnerable individuals, consider whether a more specialised system is appropriate.

3.6 When you take the compliance readiness check

The compliance readiness check is a free tool on our public website. It asks you about how your organisation manages compliance, scores your answers on our server, and shows you a report. Three things are recorded about each check and kept together: a record of the session, a row for every answer, and a step-by-step log of how the visit moved through the tool. Where you give us an email address, it sits on the session record, and whatever is held against that record is joined to it.

The session record holds:

  • A random session token, kept in your browser so you can leave the check and come back to it. The same token is the address of your report page, and links a retake to the earlier attempt you took it from
  • The sector you chose and, where your sector is not listed, whatever you type in its place, up to 200 characters
  • Your team size and your role, as you picked them from the options we offer
  • Your email address, if you give us one, with when you gave it and whether you gave it up front or after seeing your report
  • When you started the check, whether you finished it, and when
  • Your overall score, the band it falls in, your score in each compliance domain, and the domains flagged as priority gaps
  • Whether you clicked through to a trial or asked for a demo at the end, and when you did
  • Whether we emailed you the report, and when
  • The campaign tags carried in the link that brought you to the check (the utm_source, utm_medium, utm_campaign and utm_content values a marketing link adds to a web address)
  • The address of the page that linked you to us (the referrer), as your browser reports it and with nothing trimmed off it at our end, up to 500 characters
  • Whether you are on a mobile, a tablet or a desktop, recorded as one of those three words and nothing more specific
  • The user-agent your browser sent with the request, up to 500 characters — the same technical string Section 3.1 describes for our server logs

We use this to see how many people start the check, how far they get, and which parts of compliance they find hardest, so that we can judge whether the tool is worth running and what to build next. Where a sector we do not yet cover is typed in, we read it to decide what to build. The campaign tags, the referrer, the device and the user-agent sit on the same row as the email address where one is given, so this is a record of your visit with your address on it rather than a count, and we can read it that way. What it does not hold is an IP address: none of the three tables the check writes to has a column for one. The standard server logs described in Section 3.1 cover the pages of the check as they cover the rest of this website, and those do record an IP address.

Every answer is stored as its own row: which question it was, which of the four options you chose, the score that option carries, the compliance domain it belongs to, and the date and time you answered. Going back and changing an answer overwrites the earlier one rather than adding to it.

The step log is written as you go, and records:

  • That the landing page was opened
  • That the questionnaire was opened and started
  • That a question was shown and answered
  • That the email step was taken or skipped
  • That the check was completed
  • That the report was viewed
  • That a domain was opened out in the report
  • That a retake was begun
  • That a follow-up was clicked
  • That a sector we do not yet cover was named

Each entry carries the date and time it was written, and some carry a little more detail beside them: our pages add the campaign tags on the arriving link, the device and the referring page, which domain was opened out, or whether the email step came before the questions or after the report. Two of these entries, the landing page being opened and the questionnaire being opened, are written without a session and stand on their own. The first of them is written as the landing page loads, and so whether or not you go on to start the check. The rest are held against the session they were sent with, and so against the email address on it where you have given one. We use the log to see where people leave the check.

The pages of the check carry the same page-view measurement as the rest of our website, and its landing page and its questionnaire carry the Meta Pixel as well: Section 5 sets out both, and Section 6.1 sets out what Meta receives. Section 10.2 states how long the records described here are kept.

4. How we use personal information

4.1 As the operator of the Service

We use personal information to:

  • Provide, maintain, and improve the Service
  • Authenticate users and protect against unauthorised access
  • Communicate with administrators about their account, billing, and material changes to the Service
  • Investigate and respond to security incidents
  • Comply with legal obligations
  • Defend our legal rights

4.2 As a processor on behalf of Customer Organisations

We use end-user personal information only to operate the Service on the Customer Organisation's instructions. We do not use it for our own purposes, do not analyse it for advertising or product development beyond the operation of the Service, and do not sell or rent it.

4.3 What we do not do

We do not:

  • Sell or rent personal information to anyone
  • Use personal information for advertising or marketing to third parties, beyond the advertising measurement described in Section 5
  • Train artificial intelligence models on Customer Organisation content
  • Use end-user content for our own business purposes beyond the operation of the Service

5. Cookies and similar technologies

Accorda uses cookies that are strictly necessary for the operation of the Service, including session cookies issued during sign-in.

Our public website also carries the Meta Pixel, an advertising tag supplied by Meta Platforms (see Section 6.1). It runs on our public marketing pages, and only on the pages we have specifically opted in to it: a page of this website carries the pixel where we have added it and nowhere else. Anywhere we have not opted in carries no pixel at all — the funding planner, which Section 3.2 covers, and our sign-in pages among them. The compliance readiness check is the other way about: its landing page and its questionnaire are opted in and do carry the pixel, and Section 3.6 sets out what the check itself records. The personal link that opens a completed compliance readiness check report is not opted in: that link is itself the key to the report, so the pixel is kept off it deliberately and opening one sends nothing to Meta. It is not strictly necessary: it sets Meta's own cookies in your browser, and it reports to Meta each page of ours that you open, along with the two actions we count as conversions — asking to see the live demo, and starting a trial. Meta can match what it receives against a browser or an account it already knows, so this is cross-site tracking for advertising, and Meta uses what it receives for its own purposes as well as ours. Those pages also carry forms asking for your name, email address and phone number, and while a Meta setting called Automatic Advanced Matching is switched on — a switch in Meta's Events Manager, not in our code — a hashed copy of what you type into them is sent to Meta as well. Section 6.1 sets out what Meta receives and what it is not given.

We do measure page views. Vercel Analytics, provided by our application host (see Section 6.1), is enabled on the pages this website serves — our marketing pages and the free tools among them — and reports which pages are visited.

Page views are not the only thing we record. The compliance readiness check on this site keeps its own log of how a visit reaches and moves through it, which Section 3.6 sets out in full: that its landing page was opened, which is recorded as that page loads whether or not you go on to start the check, together with any campaign tags carried in the link that brought you to it and the address of the page that linked you to us, and, once an assessment has been started, the steps taken through it against the session they belong to. We use that log to see where people leave the questionnaire. The funding planner keeps a usage log of its own on the same footing, which Section 3.2 sets out in full. This section is an account of the cookies and tags this website carries and of our page-view measurement, and not of everything the site records: what each of the two free tools records about a visit is set out in Sections 3.2 and 3.6, and how long each is kept in Sections 10.1 and 10.2.

6. Disclosure of personal information

6.1 Subprocessors

We use the following subprocessors to deliver the Service. Except where the entry says otherwise, each is bound by contractual and (where applicable) statutory obligations to handle personal information only for the purposes of operating Accorda:

  • Supabase — database hosting, authentication, and file storage. Data is hosted in the Asia Pacific (Sydney) region.
  • Vercel — application hosting. Edge processing may occur in regions outside Australia for performance reasons; primary processing is in the Sydney region.
  • Stripe — payment processing for subscriptions.
  • Anthropic — AI inference for assistant and policy-analysis features. Customer content sent to Anthropic for these features is processed under Anthropic's terms, which prohibit use of customer data for training without consent.
  • Resend — transactional email delivery (sign-off reminders, account notifications).
  • Sentry — error monitoring. Sentry receives stack traces and limited request metadata; sensitive request bodies are scrubbed before transmission.
  • Meta Platforms — advertising measurement through the Meta Pixel on our public marketing pages (see Section 5). Meta receives the pages of ours you open, the conversion events listed in Section 5, and the technical details any web request carries, including your IP address. While a Meta setting called Automatic Advanced Matching is switched on, it also receives a hashed form of the contact details you type into forms on those pages — the name, work email address and phone number on the demo form, and the email address on the compliance readiness check, which Section 3.6 covers — so that it can match them to a person it already knows; hashing changes the form of those details, not the fact that they are sent. That setting lives in Meta's own Events Manager rather than in this website's code, so it can be turned on or off without any change to the pages you see. Meta is the exception to the paragraph above: it is an advertising business and uses what the pixel sends for its own purposes as well as for ours, under its own terms, and it processes it outside Australia. It is not given Customer Data, end-user content from inside the Service, or what you type into the free tools, beyond the contact details named above for as long as that setting is on.

We may add or replace subprocessors from time to time. Material changes are notified to administrators by email and reflected here.

6.2 Other disclosures

We may disclose personal information where:

  • Required by law, court order, or valid regulatory request in any jurisdiction in which we operate
  • Necessary to investigate or respond to a security incident
  • Necessary to protect the rights, property, or safety of any person
  • A successor entity acquires our business; in that case the acquirer assumes the same obligations under this policy

We do not disclose end-user personal information to other Customer Organisations.

7. Customer-uploaded content

Customer Organisations may upload documents and other content to Accorda (their "Customer Data"). The Customer Organisation is solely responsible for the lawful basis for collecting and uploading any personal information contained in Customer Data, including the personal information of their own employees, contractors, clients, patients, participants, and other third parties. We process Customer Data only on the Customer Organisation's instructions.

Customer Organisations should not upload personal information of their own end-customers, clients, or service recipients (such as patient records, client case files, or participant data) into Accorda except where strictly necessary for compliance documentation purposes and where they have a lawful basis to do so. See our Acceptable Use Policy for further detail.

8. International data transfers

The Service is operated from Australia, and primary processing of Customer Data occurs in the Sydney region. Some subprocessors — including Stripe, Anthropic, Sentry, Meta Platforms, and Vercel's edge network — may process certain personal information outside Australia. Except where the entry in Section 6.1 says otherwise, we rely for those transfers on the protections offered by those providers' privacy programmes, which include contractual and (where applicable) statutory safeguards. Meta is that exception: what the Meta Pixel sends is handled outside Australia by an advertising business under its own terms, and not under an agreement binding it to the operation of Accorda.

If you use the Service, you agree that your personal information may be processed in those locations. That agreement does not carry the Meta Pixel's transfer: the pixel is on our public marketing pages, so it sends what Section 6.1 describes to Meta when one of those pages is opened by anyone at all — including a reader who has never used the Service and has therefore agreed to nothing. You can limit what reaches Meta from your own browser: most browsers carry privacy settings that block third-party cookies and known tracking scripts, and a browser extension that blocks advertising tags will stop the pixel loading at all. If you hold a Meta account, the ad preferences and off-Meta activity sections of that account's settings govern what Meta may do with what it receives.

9. Security

We implement reasonable technical and organisational measures to protect personal information, including:

  • Encryption in transit (TLS) and at rest
  • Strict access controls, with multi-factor authentication required for administrative access
  • Tenant data segregation enforced at the database level
  • Regular security monitoring and logging
  • Incident response procedures (see our Incident Response Plan, available on request)

For incident attachments specifically, additional measures include: private, non-public file storage accessible only to authorised users within the same organisation; tenant-scoped access control enforced at the storage layer; automatic removal of image metadata (EXIF data including GPS, timestamps, camera information) to prevent unintended disclosure of location or device information; validation of file type and content to prevent malicious uploads; and audit logging of all attachment access and downloads.

No system can be guaranteed entirely secure. We will notify affected individuals and the Office of the Australian Information Commissioner ("OAIC") of any eligible data breach in accordance with the Notifiable Data Breaches scheme under the Privacy Act.

10. Data retention

  • Account information for active subscriptions is retained while the subscription is active.
  • End-user information and sign-off records processed on behalf of a Customer Organisation are retained for the period specified by that organisation, typically aligned with sector-specific retention requirements (commonly 7 years for healthcare, financial services, and similar regulated industries).
  • Incident records are retained for the period specified by the Customer Organisation, typically the same as sign-off records. Incident records are marked as closed or resolved at the Customer Organisation's direction; closed incidents and their associated data are retained but flagged as inactive.
  • Incident attachments are retained as part of the incident record, including after the incident is closed, so that the evidence trail remains intact. Attachments are removed only by deliberate action of an authorised user (using the remove-attachment control), or when the incident or the Customer Organisation's account is deleted. A Customer Organisation that requires attachments to be purged on incident closure, or after a set period, may request this.
  • Audit logs and compliance evidence are retained for the same period as sign-off records.
  • Server logs are retained for up to 30 days.
  • Email delivery logs are retained for up to 90 days.
  • Backups are retained for up to 7 days on a rolling basis.

When a Customer Organisation's subscription ends, Customer Data (including incident records and any remaining attachments) is retained in accordance with the data export and deletion provisions of our Data Processing Agreement (typically a 30-day grace period for export, followed by deletion).

10.1 Funding planner lead records

A record created when someone exports a plan from the funding planner (Section 3.2) — the email address, the consent answer, which file was asked for, the request details kept as evidence of that consent, and the date and time — is deleted 24 months after it was created.

We delete it sooner on request. If you ask us to remove your address, or withdraw your consent to marketing, we delete the whole record rather than keeping the evidence behind it, unless we still need it to meet a legal obligation.

10.2 Compliance readiness check records

The record of a readiness check (Section 3.6) — the session record, the answers stored against it, and the entries of the step log — is deleted 24 months after the check was started. The two kinds of entry written without a session are deleted 24 months after each was written.

That deadline is ours to keep rather than the database’s. Nothing in the tables that hold these records removes a row on a schedule, so the deadline is met by a clear-out we run, and a record a little past it may still be there until the next one.

We delete sooner on request. If you ask us to remove your readiness check record, we delete the session record, and the answers and step entries held against it go with it, unless we still need them to meet a legal obligation.

11. Your rights

If you are an individual whose personal information we hold (whether as administrator, end-user, or otherwise), you have the right to:

  • Access the personal information we hold about you
  • Request correction of inaccurate or out-of-date information
  • Request deletion of your personal information, subject to retention obligations and legitimate operational needs
  • Withdraw consent for non-essential processing
  • Lodge a complaint with the Office of the Australian Information Commissioner (www.oaic.gov.au) if you believe we have mishandled your personal information

For end-user information processed on behalf of a Customer Organisation, please direct such requests to that organisation in the first instance, as they are the data controller. We will assist them in responding under our Data Processing Agreement.

To exercise any of these rights, contact us at privacy@accorda.com.au. We will respond within 30 days.

12. Children

Accorda is a workplace-compliance platform and is not directed at children. We do not knowingly collect personal information from individuals under 16. If you become aware that a child has provided personal information through the Service, contact us and we will delete it.

13. Changes to this policy

We may update this policy from time to time. When we make material changes, we will:

  • Update the "Effective" date and "Version" at the top of this page
  • Notify Customer Organisation administrators by email
  • Where you are an end-user, request your fresh consent at next sign-in if the changes materially affect you

Continued use of the Service after the effective date of an updated policy constitutes acceptance of the changes.

14. How to contact us

For all privacy enquiries, including to exercise your rights, contact:

True North Analytics ABN 24 726 502 584 Email: info@accorda.com.au

Postal correspondence is not currently accepted; please use email.

Questions about this document? privacy@accorda.com.au