Legal

Privacy policy

Last updated: 7 August 2026

In plain English

We collect what a rostering system needs and nothing more: your account details, your rosters and timesheets, a worker's location at the moment they clock in or out, and the participant records your organisation enters. Everything is stored in Australia. Your organisation owns and controls participant data — we process it on your behalf, we never sell it, and you can export or delete it at any time.

Please note: Nexrosta is a demonstration application. This document is a template and must be reviewed by qualified legal counsel before any production use.

1. Who this policy covers

Nexrosta is rostering software for Australian NDIS providers. This policy explains what personal information we handle when an organisation uses Nexrosta, why we handle it, and the rights people have over it. We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles.

2. What we collect

We collect only what the product needs to work:

  • Account information — name, email address, phone number and role, for each person your organisation invites.
  • Roster and timesheet data — shifts, availability, leave, clock-in and clock-out events, and the timesheets derived from them.
  • Clock-in location — a single location reading, with its accuracy radius, captured only at the moment a worker clocks in or out. Nexrosta does not track location continuously, in the background, or between clock events.
  • Participant records — plans, case notes, incident reports, medication records and documents that your organisation chooses to enter. What is recorded, and about whom, is your organisation's decision.

3. Why we collect it

Each category has one purpose: to run rosters, produce accurate timesheets and claims, and hold the evidence a provider needs at audit. Clock-in location exists so a manager can confirm a shift happened where it was rostered — an out-of-range reading is flagged for human review, never used to automatically reject a shift or withhold pay. We do not use your data to profile people, to advertise, or for any purpose unrelated to running the service.

4. Where data is stored

All customer data is hosted in Australia. We do not move it offshore for processing or backup.

5. Who controls participant data

Your organisation is the controller of the participant records it enters. Nexrosta processes that data on your organisation's behalf and on its instructions — we do not decide what is collected, who may see it, or how long it is kept. If you are a participant, family member or worker with a question about records a provider holds about you, direct it to that provider first; we will assist them in answering it.

6. Access, correction and deletion

Your organisation can export everything it holds in Nexrosta at any time — CSV, NDIA, Xero, MYOB and QuickBooks formats are available in every tier, including the free one. Account holders can correct their own details in the app. When an organisation closes its account, its data is deleted after a wind-down period that allows a final export; the append-only audit log is included in that export so the record survives the account.

7. What we never do

We do not sell personal information. We do not share it with advertisers. We do not use participant records for any purpose other than providing the service to your organisation. Cookies are limited to sign-in and preferences — see the cookie policy.

8. Privacy requests and complaints

For access requests, corrections, deletion requests or complaints about how we have handled personal information, email privacy@nexrosta.com.au. If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner.

Privacy policy · Nexrosta