Privacy Policy

Privacy Policy

Compliance Guardian AI

Effective date: 23 June 2026  Last updated: 23 June 2026

1. Who we are

Compliance Guardian AI (ABN 96 696 667 535) is an Australian consultancy that helps NDIS providers with compliance and AI projects, both for first-time registration and for ongoing audit-readiness. Our first productised tool, the Free Readiness Check, is launching in 2026. Alongside this we run consulting and AI project engagements with NDIS provider clients. We also use the trading name “CGAI”. Our website is complianceguardianai.com.au.

In this policy, “we,” “us,” and “our” mean Compliance Guardian AI. “You” means anyone interacting with our website or products.

2. Scope of this policy

This policy covers personal information we collect and handle through:

  • Our website at complianceguardianai.com.au
  • The Free Readiness Check, our 10-minute online compliance diagnostic for NDIS providers
  • Our consulting, advisory, and AI project engagements with NDIS provider clients (compliance reviews, audit-readiness preparation, governance support, and AI implementation work)
  • Any new product or service we launch in future, once this policy has been updated to cover it

Different surfaces collect different categories of information and have different security and storage arrangements. The section-specific detail below sets out the specifics.

3. What personal information we collect

3.1 Through our website

When you browse complianceguardianai.com.au we collect limited aggregate information for analytics purposes (the page you visited, your approximate location based on IP address, your device type). This information is not used to identify you individually.

When you use a contact form we collect the information you provide (typically name, email, organisation, and your message).

3.2 Through the Free Readiness Check

When you complete the Free Readiness Check we collect:

  • Your first name
  • Your email address
  • Your organisation name, if you provide it
  • Your phone number, if you provide it
  • A short free-text answer to a follow-up question, if you provide one
  • Your responses to the 22 assessment questions
  • The scores and readiness position computed from your responses
  • The date and time of your submission

We do not collect information about NDIS participants through the Free Readiness Check. The assessment is about your organisation’s compliance posture, not about the people you support.

3.3 Through our consulting, advisory, and AI project engagements

When you engage us for compliance, audit-readiness, governance, or AI project work, we collect:

  • Information about your organisation (name, ABN, registration status, scope of services, key personnel)
  • Information you provide as part of the engagement (policies, procedures, registers, training records, worker screening records, incident reports, technical documents, project briefs, and other materials relevant to the work)
  • Our correspondence with you during the engagement

Some material you share with us may incidentally contain personal information about your workers (for example, training certificates with worker names) or about NDIS participants (for example, incident reports, behaviour support plans, or care notes). We treat this information with heightened controls as set out in section 10.

3.4 Through billing

If you are a paying client we collect the billing information needed to invoice you (typically your organisation name, billing contact, billing address, and ABN). We do not store credit card numbers on our systems.

4. How we collect personal information

We collect personal information:

  • Directly from you when you submit a form, sign up for a product, or communicate with us
  • Automatically when you use our products (such as the timestamps of your submissions)
  • From third parties only where you have authorised it, or where the information is publicly available

We do not purchase contact lists or acquire personal information from data brokers.

5. Why we collect personal information

We use personal information for the following purposes:

  • To deliver the products and services you have requested
  • To send you the results of an assessment, including the PDF report
  • To communicate with you about your account, the products, or related matters
  • To respond to your enquiries and complaints
  • To improve our products and services
  • To comply with our legal and regulatory obligations
  • To send you marketing communications, where you have consented to receive them

You can unsubscribe from marketing communications at any time. Service communications (such as your assessment results or a billing notice) are not marketing and you cannot unsubscribe from them while you are using the relevant product.

6. Who we share personal information with

We use a small number of third-party service providers to operate our products. They handle personal information only on our instructions and only for the purposes set out below.

Service provider

Used for

Where data is processed

Base44

Hosting the Free Readiness Check

United States

Resend

Sending transactional emails from the Free Readiness Check (lead notifications and your PDF result)

United States

GoHighLevel (GHL)

Managing the marketing contact list and sending follow-up communications

United States

Fastmail

Hosting the contact@ mailbox and our internal email

United States and Netherlands

Amazon Web Services (AWS)

Storing documents and working files for our consulting, advisory, and AI project engagements

Australia (Sydney region, ap-southeast-2)

Google Analytics

Aggregate website analytics

United States and globally

We do not sell personal information. We do not share it with advertisers or marketers. We may share personal information with:

  • Professional advisors (lawyers, accountants, auditors) acting under a duty of confidentiality
  • Regulators or law enforcement where required by law (such as a valid subpoena or court order)
  • A buyer or successor in the event of a sale, merger, or restructure of our business, in which case we will require the recipient to honour this policy

7. Where your data is stored

The Free Readiness Check is hosted on Base44, a platform with infrastructure in the United States. The Free Readiness Check carries only lead information and your responses to the 22 assessment questions. It does not carry NDIS participant information. By using the Free Readiness Check you consent to your information being processed in the United States.

Documents and working files for our consulting, advisory, and AI project engagements are stored on Amazon Web Services in Sydney (ap-southeast-2). This includes any material that contains worker or NDIS participant information shared with us during the engagement. We do not transfer that material outside Australia.

Email correspondence and our marketing tools (listed in section 6) sit on infrastructure outside Australia. We do not place NDIS participant information into our email or marketing systems.

8. How long we keep personal information

We keep personal information only as long as we need it for the purposes set out in this policy or as required by law.

Information

Retention period

Free Readiness Check submissions

24 months from submission, unless you ask us to delete sooner

Consulting, advisory, and AI project engagement records

Duration of the engagement plus 7 years, aligned with typical NDIS recordkeeping obligations

Marketing list

Until you unsubscribe

Billing records

7 years, as required by Australian tax law

Website contact form enquiries

12 months

After the retention period expires we delete personal information or de-identify it so it can no longer be linked to you.

9. How we keep personal information secure

We take reasonable steps to protect personal information from loss, misuse, unauthorised access, modification, and disclosure. Our controls include:

  • Encryption in transit (TLS 1.2 or higher) for all communication with our products and our website
  • Multi-factor authentication on administrative accounts
  • Role-based access with the principle of least privilege
  • Careful selection of third-party platforms with industry-standard security postures (see section 6 for our current subprocessors)
  • The Australian Cyber Security Centre’s Essential Eight as our engineering baseline
  • ISO/IEC 27001 as our long-term governance target

No system is perfectly secure. If we become aware of a data breach that is likely to result in serious harm to you, we will notify you and the Office of the Australian Information Commissioner in accordance with the Notifiable Data Breaches scheme.

10. Sensitive information and NDIS participant information

Personal information that relates to a person’s health, disability, or behaviour support needs is “sensitive information” under the Privacy Act and requires heightened handling. NDIS participant information falls into this category.

We collect and handle sensitive information only where:

  • It is provided to us as part of a consulting, advisory, or AI project engagement, and
  • The person it relates to (or their authorised decision-maker) has consented to its handling for the purpose of the engagement, and
  • The handling is reasonably necessary for the engagement

Sensitive information is stored on our Australian-hosted file storage (AWS Sydney, ap-southeast-2) as set out in section 7. It is held only as long as the engagement requires plus the 7-year recordkeeping period set out in section 8. Access is restricted to personnel who need it for the engagement. It is not used for marketing, product improvement, or analytics.

We do not collect sensitive information through the Free Readiness Check, the website, or any other surface.

11. AI and automated processing

We use automated processing in two specific ways.

The Free Readiness Check uses a deterministic scoring algorithm. Your responses are processed by a versioned scoring algorithm that produces a readiness position and a list of compliance gaps. The algorithm is rule-based, not a large language model, and the version of the algorithm used at the time of your submission is recorded with your result so the output remains reproducible.

In our consulting, advisory, and AI project work we may use AI tools to assist us. This includes drafting, summarising, evidence review, and supporting AI implementation projects with our clients. Where AI is used, a human reviews every output before it is shared with you. We do not feed your information into third-party AI providers for the purpose of training their models.

No automated process makes a decision about your NDIS registration outcome. Decisions about registration are made by the NDIS Quality and Safeguards Commission and your approved quality auditor. Our products and services are preparation tools, not regulatory decision-makers. The Free Readiness Check carries a prominent disclaimer to this effect on every output.

12. Cookies and website analytics

Our website uses cookies that are necessary for the site to function. We do not use advertising cookies. We use Google Analytics to understand aggregate website use, with IP anonymisation enabled so that this data is not used to identify you individually.

You can disable cookies in your browser settings, and you can opt out of Google Analytics tracking using the Google Analytics Opt-out Browser Add-on. Some parts of our website may not work correctly without cookies.

13. Your rights

Under the Privacy Act you have the right to:

  • Access the personal information we hold about you
  • Correct information that is inaccurate, out of date, incomplete, or misleading
  • Request deletion of your information, subject to any legal obligation we have to keep it
  • Withdraw consent to marketing communications at any time
  • Complain about how we have handled your personal information

To exercise any of these rights, email [email protected]. We will respond within 30 days, and usually much sooner.

14. Complaints

If you believe we have handled your personal information in a way that breaches the Privacy Act or this policy, please contact us first:

Email: [email protected] Response time: within 7 days for an acknowledgement, within 30 days for a substantive response

If your complaint is not resolved to your satisfaction, you can complain to:

The Office of the Australian Information Commissioner (OAIC) Website: www.oaic.gov.au Phone: 1300 363 992

15. Children

Our website and the Free Readiness Check are not directed at children under 18 and we do not knowingly collect personal information from children through these surfaces.

NDIS participants may be children. Where information about an NDIS participant is provided to us through a consulting, advisory, or AI project engagement, we handle it as sensitive information under section 10, and only with the consent of the appropriate decision-maker (the participant if they have capacity, otherwise their parent, guardian, or nominee).

16. Changes to this policy

We may update this policy from time to time to reflect changes to our products, our service providers, or applicable law. Material changes will be notified to current customers by email and posted on this page with an updated “Last updated” date. Previous versions of this policy are available on request.

17. Contact us

Compliance Guardian AI ABN: 96 696 667 535 Registered office: Banora Point NSW, Australia

Email: [email protected]

Website: complianceguardianai.com.au

©2026 Compliance Guardian AI. All Rights Reserved.