Privacy Policy
Effective 20 August 2026 · Version 1.7
This Privacy Policy explains how True North Analytics ("we", "us", "our") handles personal information when you, your organisation, or your end-users use Accorda (the "Service"). True North Analytics operates as a sole trader from New South Wales, Australia (ABN 24 726 502 584).
This policy covers what we do as the operator of the Service. If you are an end-user accessing Accorda at the invitation of an organisation that has subscribed to the Service (your "Customer Organisation"), that organisation is the data controller for your personal information, and a separate notice applies inside the Service describing what they collect from you. This policy describes our role as their data processor.
True North Analytics is a sole-trader business operating Accorda from New South Wales, Australia. We hold an Australian Business Number (ABN 24 726 502 584). We are bound by the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles ("APPs").
For all privacy enquiries, contact us at privacy@accorda.com.au.
This policy covers:
It does not cover:
When you visit pages such as our marketing site or this policy, we may collect:
When an authorised representative of an organisation signs up for Accorda, we collect:
When end-users from a Customer Organisation use Accorda, the Service collects information *on behalf of the Customer Organisation* (who is the data controller). This typically includes:
We process this information solely on the instructions of the Customer Organisation, under our standard Data Processing Agreement.
We (True North Analytics) do not collect "sensitive information" as defined by the Privacy Act (such as health information, racial or ethnic origin, political opinions, religious beliefs, sexual orientation, or biometric data) for our own purposes. Except where a feature is specifically designed to record it (see below), end-users and administrators must not enter sensitive information into free-text fields in the Service, and Customer Organisations are responsible for instructing their personnel accordingly.
Some features are designed to record information that may be, or may border on, sensitive information. In particular, the worker screening and credentials features let a Customer Organisation record the status of background checks and clearances for its workers, contractors, and volunteers — such as national police checks, Working with Children Checks, and NDIS Worker Screening — together with the outcome of those checks and any certificates the organisation uploads. Information about an individual's criminal-history record checks is sensitive information under the Privacy Act. Similarly, complaint records may contain allegations or other sensitive details about the people involved. Where a Customer Organisation uses these features, it does so as the data controller and is responsible for ensuring it has a documented lawful basis for collecting and recording the information, for obtaining any consent required by law, and for recording only what is necessary for the compliance purpose (for example, the fact and status of a clearance rather than the underlying criminal-history detail). We process this information only on the Customer Organisation's instructions and do not use it for any purpose of our own.
Incident records and incident attachments may naturally include references to or information about your clients, patients, service recipients, or other vulnerable individuals. Incident records in regulated sectors (such as healthcare, aged care, NDIS, childcare, and other community services) commonly document events involving vulnerable people, and may therefore contain health information or information about safeguarding concerns. When recording incidents, the Customer Organisation must ensure: (1) that it has a documented lawful basis for collecting and recording the incident information under Australian privacy law and any other applicable law, (2) that consent has been obtained where required by law, and (3) that any attachments to incidents (such as photographs) do not contain identifiable information about such individuals unless absolutely necessary and lawfully authorised. Accorda is designed to support compliance management and incident tracking, but is not a specialised system for medical records, safeguarding case management, or the secure handling of sensitive incident media; if your incident records or attachments frequently contain sensitive information about vulnerable individuals, consider whether a more specialised system is appropriate.
We use personal information to:
We use end-user personal information only to operate the Service on the Customer Organisation's instructions. We do not use it for our own purposes, do not analyse it for advertising or product development beyond the operation of the Service, and do not sell or rent it.
The one limited exception is the trial and demo follow-up retention described in Section 10. That exception applies only to the business-contact and high-level usage information of a trial or demo account, and never to end-user content processed on behalf of a paying Customer Organisation.
We do not:
Accorda uses cookies that are strictly necessary for the operation of the Service, including session cookies issued during sign-in. We do not use third-party advertising cookies or cross-site tracking.
We use Vercel Analytics to understand aggregate usage of the Service, such as which pages are visited. Vercel Analytics is designed to be privacy-friendly: it does not set tracking cookies, does not track you across other websites, and does not build advertising profiles. It collects aggregated page-view data rather than identifying individual visitors.
We use the following subprocessors to deliver the Service. Each is bound by contractual and (where applicable) statutory obligations to handle personal information only for the purposes of operating Accorda:
We may add or replace subprocessors from time to time. Material changes are notified to administrators by email and reflected here.
We may disclose personal information where:
We do not disclose end-user personal information to other Customer Organisations.
Customer Organisations may upload documents and other content to Accorda (their "Customer Data"). The Customer Organisation is solely responsible for the lawful basis for collecting and uploading any personal information contained in Customer Data, including the personal information of their own employees, contractors, clients, patients, participants, and other third parties. We process Customer Data only on the Customer Organisation's instructions.
Customer Organisations should not upload personal information of their own end-customers, clients, or service recipients (such as patient records, client case files, or participant data) into Accorda except where strictly necessary for compliance documentation purposes and where they have a lawful basis to do so. See our Acceptable Use Policy for further detail.
The Service is operated from Australia, and primary processing of Customer Data occurs in the Sydney region. Some subprocessors (such as Stripe, Anthropic, OpenAI, Voyage AI, Sentry, and Vercel's edge network) may process certain personal information outside Australia. Where this occurs, we rely on the protections offered by those providers' privacy programmes, which include contractual and (where applicable) statutory safeguards. By using the Service, you agree that your personal information may be processed in those locations.
The optional Dictate feature involves an overseas disclosure that we want to be explicit about, consistent with Australian Privacy Principle 8 (cross-border disclosure of personal information). When — and only when — a user actively chooses to dictate an incident description rather than type it, the short audio recording of their voice is sent to OpenAI in the United States for transcription. The feature is entirely optional, nothing is sent unless the user initiates a dictation, and a typed alternative is always available for every field Dictate can fill. The audio is transcribed and discarded — it is not stored by us — and under OpenAI's API terms it is not used for model training and is retained by OpenAI for no more than 30 days for abuse monitoring. We take reasonable steps to ensure this overseas recipient handles personal information consistently with the APPs, including through the contractual safeguards described in Section 6.1. Customer Organisations that prefer to avoid this transfer entirely can instruct their personnel to type incident reports instead of dictating them.
We implement reasonable technical and organisational measures to protect personal information, including:
For incident attachments specifically, additional measures include: private, non-public file storage accessible only to authorised users within the same organisation; tenant-scoped access control enforced at the storage layer; automatic removal of image metadata (EXIF data including GPS, timestamps, camera information) to prevent unintended disclosure of location or device information; validation of file type and content to prevent malicious uploads; and audit logging of all attachment access and downloads.
To operate, support, secure, troubleshoot, and maintain the Service, a small number of authorised personnel of True North Analytics (the platform operator) may access Customer Data across the Service, including through administrative tools. This access is granted on a least-privilege basis, is limited to what is necessary for those purposes, and is subject to confidentiality obligations. We do not use it to view Customer Data for any purpose other than operating and supporting the Service.
No system can be guaranteed entirely secure. We will notify affected individuals and the Office of the Australian Information Commissioner ("OAIC") of any eligible data breach in accordance with the Notifiable Data Breaches scheme under the Privacy Act.
When a Customer Organisation's subscription ends, Customer Data (including incident records and any remaining attachments) is retained in accordance with the data export and deletion provisions of our Data Processing Agreement (typically a 30-day grace period for export, followed by deletion).
Trial and demo accounts are treated differently from paid subscriptions. A trial runs for about 14 days. When a trial ends and is not continued, the account enters a short grace period of about 7 days, during which it is suspended but the data still exists and the account can be reactivated or continued. After that grace period, the trial or demo account and its Customer Data are deleted. This 7-day trial grace period is separate from, and shorter than, the 30-day export window that applies to paid subscriptions when they are cancelled.
When a trial or demo account is deleted, we keep a limited follow-up record so we can contact the business about its trial, seek feedback, and offer the opportunity to continue. This record contains business-contact details (an administrator's name and email address, and the business name and sector) and high-level usage information (counts such as the number of policies added, sign-offs, and users, the date of last activity, and key dates for the account). It does not include the documents, incident records, or other content held in the account, which are deleted with the account. We keep this follow-up record for no longer than 12 months from deletion, after which it is deleted. You can ask us not to contact you (opt out) at any time, and you can ask us to erase this record at any time. We do not sell this information, and we do not share it for anyone else's marketing. To opt out or request erasure, contact us at privacy@accorda.com.au.
If you are an individual whose personal information we hold (whether as administrator, end-user, or otherwise), you have the right to:
For end-user information processed on behalf of a Customer Organisation, please direct such requests to that organisation in the first instance, as they are the data controller. We will assist them in responding under our Data Processing Agreement.
To exercise any of these rights, contact us at privacy@accorda.com.au. We will respond within 30 days.
Accorda is a workplace-compliance platform and is not directed at children. We do not knowingly collect personal information from individuals under 16. If you become aware that a child has provided personal information through the Service, contact us and we will delete it.
We may update this policy from time to time. When we make material changes, we will:
Continued use of the Service after the effective date of an updated policy constitutes acceptance of the changes.
For all privacy enquiries, including to exercise your rights, contact:
True North Analytics ABN 24 726 502 584 Email: privacy@accorda.com.au
Postal correspondence is not currently accepted; please use email.