Privacy
Effective 15 September 2026 · Version 1.8
This Privacy Policy explains how True North Analytics ("we", "us", "our") handles personal information when you, your organisation, or your end-users use Accorda (the "Service"). True North Analytics operates as a sole trader from New South Wales, Australia (ABN 24 726 502 584).
This policy covers what we do as the operator of the Service. If you are an end-user accessing Accorda at the invitation of an organisation that has subscribed to the Service (your "Customer Organisation"), that organisation is the data controller for your personal information, and a separate notice applies inside the Service describing what they collect from you. This policy describes our role as their data processor.
True North Analytics is a sole-trader business operating Accorda from New South Wales, Australia. We hold an Australian Business Number (ABN 24 726 502 584). We are bound by the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles ("APPs").
For all privacy enquiries, contact us at privacy@accorda.com.au.
This policy covers:
It does not cover:
When you visit pages such as our marketing site or this policy, we may collect:
The funding planner is a free tool on our public website. The plan you build in it is held in your own browser, and the words you type into it — the plan label, the description of each support, anything you write about a person — are never sent to us. How large that plan is, we do record: the usage log described further down this section sets out exactly what that means. When you ask the tool for a download, it asks for your email address first, and we create a record of that request.
That record holds:
We keep the email address so that we can answer you and, if you consented, send you occasional updates about Accorda, and the name of the file so that we know which tool the request came from. The request details and the timestamp are kept as evidence of when and where the consent was given: this form is open to the public internet and anyone can post to it, so without them we could not tell a genuine request from a forged one, or show that an address on our list asked to be there. They are not used to build a profile of you or to follow you across other websites. Section 10.1 states how long the record is kept.
The pages of the tool carry the same page-view measurement as the rest of our website (see Section 5). They do not carry the Meta Pixel: it is kept off this tool deliberately, so opening one of its pages is not reported to Meta and no advertising cookie is set while you use it. Nothing you type into the tool forms part of either.
Page views are not all we record about the planner. The tool also keeps a usage log of its own, whether or not you ever ask for a download. It is written each time the tool reaches one of a handful of moments, and it holds no identifier that joins an entry to your export record, to your email address, or to any other visit — no account, no session token, and no marker kept in your browser to recognise you by. Each entry does carry the date and time it was written, as your export record does, and we do not match one against the other.
Each entry in that log holds:
Whether the plan has funding blocks in it, and whether supports have been allocated against them, are read off the plan open in your browser rather than off a button you press: a plan you saved on an earlier visit and had restored registers both of those steps without you doing anything to it. We use this to see how many people open the planner and how far through it they get, which is how we judge whether the tool is worth keeping and improving. What it records about a plan is its size and nothing else: no participant name, no plan name, no description of a support, and none of the other words you type into the tool. Those stay in your browser — the log has no field that could hold them, and the tool has no way to send them.
When an authorised representative of an organisation signs up for Accorda, we collect:
When end-users from a Customer Organisation use Accorda, the Service collects information *on behalf of the Customer Organisation* (who is the data controller). This typically includes:
We process this information solely on the instructions of the Customer Organisation, under our standard Data Processing Agreement.
We do not knowingly collect "sensitive information" as defined by the Privacy Act (such as health information, racial or ethnic origin, political opinions, religious beliefs, sexual orientation, or biometric data). End-users and administrators must not enter sensitive information into free-text fields in the Service. Customer Organisations are responsible for instructing their personnel accordingly.
Incident records and incident attachments may naturally include references to or information about your clients, patients, service recipients, or other vulnerable individuals. Incident records in regulated sectors (such as healthcare, aged care, NDIS, childcare, and other community services) commonly document events involving vulnerable people, and may therefore contain health information or information about safeguarding concerns. When recording incidents, the Customer Organisation must ensure: (1) that it has a documented lawful basis for collecting and recording the incident information under Australian privacy law and any other applicable law, (2) that consent has been obtained where required by law, and (3) that any attachments to incidents (such as photographs) do not contain identifiable information about such individuals unless absolutely necessary and lawfully authorised. Accorda is designed to support compliance management and incident tracking, but is not a specialised system for medical records, safeguarding case management, or the secure handling of sensitive incident media; if your incident records or attachments frequently contain sensitive information about vulnerable individuals, consider whether a more specialised system is appropriate.
The compliance readiness check is a free tool on our public website. It asks you about how your organisation manages compliance, scores your answers on our server, and shows you a report. Three things are recorded about each check and kept together: a record of the session, a row for every answer, and a step-by-step log of how the visit moved through the tool. Where you give us an email address, it sits on the session record, and whatever is held against that record is joined to it.
The session record holds:
We use this to see how many people start the check, how far they get, and which parts of compliance they find hardest, so that we can judge whether the tool is worth running and what to build next. Where a sector we do not yet cover is typed in, we read it to decide what to build. The campaign tags, the referrer, the device and the user-agent sit on the same row as the email address where one is given, so this is a record of your visit with your address on it rather than a count, and we can read it that way. What it does not hold is an IP address: none of the three tables the check writes to has a column for one. The standard server logs described in Section 3.1 cover the pages of the check as they cover the rest of this website, and those do record an IP address.
Every answer is stored as its own row: which question it was, which of the four options you chose, the score that option carries, the compliance domain it belongs to, and the date and time you answered. Going back and changing an answer overwrites the earlier one rather than adding to it.
The step log is written as you go, and records:
Each entry carries the date and time it was written, and some carry a little more detail beside them: our pages add the campaign tags on the arriving link, the device and the referring page, which domain was opened out, or whether the email step came before the questions or after the report. Two of these entries, the landing page being opened and the questionnaire being opened, are written without a session and stand on their own. The first of them is written as the landing page loads, and so whether or not you go on to start the check. The rest are held against the session they were sent with, and so against the email address on it where you have given one. We use the log to see where people leave the check.
The pages of the check carry the same page-view measurement as the rest of our website, and its landing page and its questionnaire carry the Meta Pixel as well: Section 5 sets out both, and Section 6.1 sets out what Meta receives. Section 10.2 states how long the records described here are kept.
We use personal information to:
We use end-user personal information only to operate the Service on the Customer Organisation's instructions. We do not use it for our own purposes, do not analyse it for advertising or product development beyond the operation of the Service, and do not sell or rent it.
We do not:
Accorda uses cookies that are strictly necessary for the operation of the Service, including session cookies issued during sign-in.
Our public website also carries the Meta Pixel, an advertising tag supplied by Meta Platforms (see Section 6.1). It runs on our public marketing pages, and only on the pages we have specifically opted in to it: a page of this website carries the pixel where we have added it and nowhere else. Anywhere we have not opted in carries no pixel at all — the funding planner, which Section 3.2 covers, and our sign-in pages among them. The compliance readiness check is the other way about: its landing page and its questionnaire are opted in and do carry the pixel, and Section 3.6 sets out what the check itself records. The personal link that opens a completed compliance readiness check report is not opted in: that link is itself the key to the report, so the pixel is kept off it deliberately and opening one sends nothing to Meta. It is not strictly necessary: it sets Meta's own cookies in your browser, and it reports to Meta each page of ours that you open, along with the two actions we count as conversions — asking to see the live demo, and starting a trial. Meta can match what it receives against a browser or an account it already knows, so this is cross-site tracking for advertising, and Meta uses what it receives for its own purposes as well as ours. Those pages also carry forms asking for your name, email address and phone number, and while a Meta setting called Automatic Advanced Matching is switched on — a switch in Meta's Events Manager, not in our code — a hashed copy of what you type into them is sent to Meta as well. Section 6.1 sets out what Meta receives and what it is not given.
We do measure page views. Vercel Analytics, provided by our application host (see Section 6.1), is enabled on the pages this website serves — our marketing pages and the free tools among them — and reports which pages are visited.
Page views are not the only thing we record. The compliance readiness check on this site keeps its own log of how a visit reaches and moves through it, which Section 3.6 sets out in full: that its landing page was opened, which is recorded as that page loads whether or not you go on to start the check, together with any campaign tags carried in the link that brought you to it and the address of the page that linked you to us, and, once an assessment has been started, the steps taken through it against the session they belong to. We use that log to see where people leave the questionnaire. The funding planner keeps a usage log of its own on the same footing, which Section 3.2 sets out in full. This section is an account of the cookies and tags this website carries and of our page-view measurement, and not of everything the site records: what each of the two free tools records about a visit is set out in Sections 3.2 and 3.6, and how long each is kept in Sections 10.1 and 10.2.
We use the following subprocessors to deliver the Service. Except where the entry says otherwise, each is bound by contractual and (where applicable) statutory obligations to handle personal information only for the purposes of operating Accorda:
We may add or replace subprocessors from time to time. Material changes are notified to administrators by email and reflected here.
We may disclose personal information where:
We do not disclose end-user personal information to other Customer Organisations.
Customer Organisations may upload documents and other content to Accorda (their "Customer Data"). The Customer Organisation is solely responsible for the lawful basis for collecting and uploading any personal information contained in Customer Data, including the personal information of their own employees, contractors, clients, patients, participants, and other third parties. We process Customer Data only on the Customer Organisation's instructions.
Customer Organisations should not upload personal information of their own end-customers, clients, or service recipients (such as patient records, client case files, or participant data) into Accorda except where strictly necessary for compliance documentation purposes and where they have a lawful basis to do so. See our Acceptable Use Policy for further detail.
The Service is operated from Australia, and primary processing of Customer Data occurs in the Sydney region. Some subprocessors — including Stripe, Anthropic, Sentry, Meta Platforms, and Vercel's edge network — may process certain personal information outside Australia. Except where the entry in Section 6.1 says otherwise, we rely for those transfers on the protections offered by those providers' privacy programmes, which include contractual and (where applicable) statutory safeguards. Meta is that exception: what the Meta Pixel sends is handled outside Australia by an advertising business under its own terms, and not under an agreement binding it to the operation of Accorda.
If you use the Service, you agree that your personal information may be processed in those locations. That agreement does not carry the Meta Pixel's transfer: the pixel is on our public marketing pages, so it sends what Section 6.1 describes to Meta when one of those pages is opened by anyone at all — including a reader who has never used the Service and has therefore agreed to nothing. You can limit what reaches Meta from your own browser: most browsers carry privacy settings that block third-party cookies and known tracking scripts, and a browser extension that blocks advertising tags will stop the pixel loading at all. If you hold a Meta account, the ad preferences and off-Meta activity sections of that account's settings govern what Meta may do with what it receives.
We implement reasonable technical and organisational measures to protect personal information, including:
For incident attachments specifically, additional measures include: private, non-public file storage accessible only to authorised users within the same organisation; tenant-scoped access control enforced at the storage layer; automatic removal of image metadata (EXIF data including GPS, timestamps, camera information) to prevent unintended disclosure of location or device information; validation of file type and content to prevent malicious uploads; and audit logging of all attachment access and downloads.
No system can be guaranteed entirely secure. We will notify affected individuals and the Office of the Australian Information Commissioner ("OAIC") of any eligible data breach in accordance with the Notifiable Data Breaches scheme under the Privacy Act.
When a Customer Organisation's subscription ends, Customer Data (including incident records and any remaining attachments) is retained in accordance with the data export and deletion provisions of our Data Processing Agreement (typically a 30-day grace period for export, followed by deletion).
A record created when someone exports a plan from the funding planner (Section 3.2) — the email address, the consent answer, which file was asked for, the request details kept as evidence of that consent, and the date and time — is deleted 24 months after it was created.
We delete it sooner on request. If you ask us to remove your address, or withdraw your consent to marketing, we delete the whole record rather than keeping the evidence behind it, unless we still need it to meet a legal obligation.
The record of a readiness check (Section 3.6) — the session record, the answers stored against it, and the entries of the step log — is deleted 24 months after the check was started. The two kinds of entry written without a session are deleted 24 months after each was written.
That deadline is ours to keep rather than the database’s. Nothing in the tables that hold these records removes a row on a schedule, so the deadline is met by a clear-out we run, and a record a little past it may still be there until the next one.
We delete sooner on request. If you ask us to remove your readiness check record, we delete the session record, and the answers and step entries held against it go with it, unless we still need them to meet a legal obligation.
If you are an individual whose personal information we hold (whether as administrator, end-user, or otherwise), you have the right to:
For end-user information processed on behalf of a Customer Organisation, please direct such requests to that organisation in the first instance, as they are the data controller. We will assist them in responding under our Data Processing Agreement.
To exercise any of these rights, contact us at privacy@accorda.com.au. We will respond within 30 days.
Accorda is a workplace-compliance platform and is not directed at children. We do not knowingly collect personal information from individuals under 16. If you become aware that a child has provided personal information through the Service, contact us and we will delete it.
We may update this policy from time to time. When we make material changes, we will:
Continued use of the Service after the effective date of an updated policy constitutes acceptance of the changes.
For all privacy enquiries, including to exercise your rights, contact:
True North Analytics ABN 24 726 502 584 Email: info@accorda.com.au
Postal correspondence is not currently accepted; please use email.