Privacy Policy

Effective date: 23 May 2026
Last updated: 23 May 2026

Digital Rabbit Pty Ltd (“Digital Rabbit”, “we”, “us”, “our”) respects your privacy and is committed to handling your personal information in accordance with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (“APPs”).

This Privacy Policy explains how we collect, use, store, disclose, and protect personal information when you interact with our website, our Rostero web platform, and our Rostero mobile applications.

1. About Digital Rabbit Pty Ltd

Digital Rabbit Pty Ltd
ACN: 698238201
ABN: 43698238201
Registered office: Unit 1005, 6 Joseph Road, Footscray VIC 3011, Australia
Privacy contact: privacy@digitalrabbit.com.au

2. Products and services covered by this policy

This Privacy Policy applies to:

  • The digitalrabbit.com.au website
  • Rostero — our web-based customer relationship management (CRM) platform designed for organisations that deliver services under the National Disability Insurance Scheme (NDIS)
  • The Rostero mobile app for iOS and Android, which is a companion app used by support workers employed by NDIS provider organisations that subscribe to our CRM
3. Types of personal information we collect

The personal information we collect depends on how you interact with us.

3.1 Visitors to our website
  • Technical information (IP address, browser type, device type, operating system)
  • Pages visited, time spent, referral source
  • Information you voluntarily submit through contact forms (e.g., name, email, message)
3.2 NDIS provider organisations subscribing to our CRM
  • Business name, registered address, ABN/ACN
  • Primary contact details (name, email, phone)
  • Billing and payment information
  • Configuration data your organisation uploads into the platform, including employee rosters and operational records
3.3 Support workers using the Rostero mobile app
  • Email address and password (passwords are hashed and never stored in plain text)
  • Name and employment details provided by your employer
  • Shift assignments, scheduled times, and location information for shifts
  • Push notification tokens (Apple Push Notification service and Firebase Cloud Messaging)
  • Device information (device model, operating system version, app version)
  • Diagnostic data (crash logs, error reports, performance telemetry)
  • Files or notes you create, upload, or view through the app
3.4 Information provided by your employer

If you are a support worker, your employing NDIS provider may upload information about you into our platform (such as employment status, qualifications, and shift assignments). In relation to that information, we act as a service provider to your employer. For questions or requests about that information, please contact your employer in the first instance.

4. How we collect personal information

We collect personal information:

  • Directly from you when you sign up, sign in, or use our services
  • From your employer (for support workers using the mobile app)
  • Automatically from your device or browser when you interact with our services
  • From third-party service providers we engage to operate our platform
5. How we use personal information

We use personal information for the following purposes:

  • To provide, maintain, secure, and improve our products and services
  • To authenticate users and protect accounts from unauthorised access
  • To deliver shift notifications, reminders, and other operational communications
  • To respond to support requests and customer enquiries
  • To detect, prevent, and investigate fraud, abuse, and security incidents
  • To comply with our legal and regulatory obligations
  • To improve our products through analysis of aggregated and de-identified data

We do not sell personal information.

6. Legal bases for handling personal information

We handle personal information where:

  • We have a contract with you (or your employer on your behalf) to provide the services
  • You have given consent
  • We have a legitimate interest in operating and improving our services
  • We are required or permitted by Australian law
7. Disclosure of personal information
7.1 Your employer (for support workers)

If you are a support worker, information about your activity in the Rostero mobile app — such as shift status, completion, attendance records, notes, and uploaded files — is visible to your employing NDIS provider organisation, which is our customer.

7.2 Service providers

We engage trusted third-party service providers to help operate our platform. These may include:

  • Cloud hosting and database services (e.g., Google Cloud Platform, Amazon Web Services)
  • Push notification delivery (Apple Push Notification service, Firebase Cloud Messaging)
  • Authentication services (e.g., Firebase Authentication)
  • Diagnostic and crash reporting (e.g., Firebase Crashlytics)
  • Email delivery (e.g., SendGrid, Postmark)
  • Payment processing (for NDIS provider organisations paying for the CRM subscription — handled outside the mobile app)

These providers are contractually required to handle personal information in accordance with our instructions and with applicable privacy laws, and to use it only for the purposes we authorise.

7.3 Legal and regulatory disclosures

We may disclose personal information where required or authorised by Australian law, court order, or regulatory request, or where reasonably necessary to protect the safety of any person or our legitimate interests.

7.4 Business transfers

If Digital Rabbit Pty Ltd is involved in a merger, acquisition, restructure, or sale of assets, personal information may be transferred as part of that transaction. We will notify affected individuals before personal information becomes subject to a different privacy policy.

8. Cross-border data transfers

Some of the service providers listed in section 7.2 are based outside Australia, including in the United States and the European Union. When personal information is transferred overseas, we take reasonable steps to ensure the recipient handles it consistently with the Australian Privacy Principles, including through contractual safeguards.

By using our services, you acknowledge that your personal information may be processed in jurisdictions other than Australia.

9. Data retention

We retain personal information only for as long as is reasonably necessary for the purposes set out in this policy:

  • Active accounts: for the duration of your account being active on our platform
  • Deactivated accounts: retained for 90 days after deactivation, then deleted or de-identified, unless we are required to retain it for legal reasons
  • Records required by law: retained as long as legally required (for example, taxation, employment, or contractual records)
  • Aggregated or de-identified data: may be retained indefinitely for analytics and product improvement

If you are a support worker and your employer terminates your access to the platform, your account is deactivated and your personal information is handled per the above schedule.

10. Your rights

Under the Australian Privacy Act and the APPs, you have the right to:

  • Access the personal information we hold about you
  • Correct personal information that is inaccurate, incomplete, or out of date
  • Request deletion of your personal information, subject to our legal and contractual obligations
  • Opt out of marketing communications at any time
  • Lodge a complaint about how we handle your personal information

To exercise any of these rights, please contact us at privacy@digitalrabbit.com.au. We will respond to your request within a reasonable period (generally within 30 days).

If you are a support worker, some of the information about you is provided and controlled by your employing NDIS provider organisation. For requests relating to that information, please contact your employer directly. We can help direct your request to the appropriate party if you are unsure.

11. Security

We take the security of personal information seriously and apply industry-standard safeguards, including:

  • Encrypted connections (TLS) for all data in transit
  • Encryption at rest for sensitive data stored in our database
  • Role-based access controls and authentication for our internal systems
  • Regular security reviews, software updates, and dependency monitoring
  • Logging and monitoring for unauthorised access attempts

No system can be guaranteed to be 100% secure. If we become aware of a data breach that is likely to result in serious harm to affected individuals, we will notify them and the Office of the Australian Information Commissioner (OAIC) in accordance with the Notifiable Data Breaches scheme.

12. Children’s privacy

Our services are intended for use by adults (18 years and over) employed in the NDIS workforce or operating NDIS provider organisations. We do not knowingly collect personal information from children under 18. If you believe a child has provided us with personal information, please contact us so we can delete it.

13. Cookies and similar technologies

Our website uses cookies and similar technologies to:

  • Remember your preferences and session state
  • Analyse website traffic and improve our content
  • Provide essential functionality (e.g., authentication)

You can control or disable cookies through your browser settings. Disabling cookies may affect the functionality of our website.

Our mobile app does not use cookies but may use device identifiers (such as advertising IDs or vendor identifiers) for security, diagnostic, and analytics purposes.

14. Third-party links

Our website and app may contain links to third-party websites and services. We are not responsible for the privacy practices of those third parties. We encourage you to review their privacy policies before providing them with personal information.

15. Changes to this Privacy Policy

We may update this Privacy Policy from time to time. The “Last updated” date at the top of this policy reflects the most recent version. If we make material changes, we will notify users by email or by prominent notice within our services prior to the changes taking effect.

16. Complaints

If you have a concern or complaint about how we handle your personal information, please first contact us at privacy@digitalrabbit.com.au. We will acknowledge your complaint within 7 days and aim to resolve it within 30 days.

If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC):

  • Website: oaic.gov.au
  • Phone: 1300 363 992
  • Mail: GPO Box 5288, Sydney NSW 2001
17. Contact us

For any privacy-related questions, requests, or concerns:

Email: privacy@digitalrabbit.com.au
Mail: Privacy Officer, Digital Rabbit Pty Ltd, Unit 1005, 6 Joseph Road, Footscray VIC 3011, Australia