Data handling summary
Version 2026-06-05.b. Effective 5 June 2026.
A plain-language summary of where Practice Binder data is stored, who can access it, how it is protected, and what happens when an account ends. This page is the auditor-facing artefact: print it or save it as a PDF and the result fits in your compliance binder.
Full legal detail is in the privacy policy and terms of service.
1. What this covers
This summary covers personal information held in Practice Binder accounts: account details (name, email, hashed password, practice name), the records you enter (incidents, behaviour support plans, complaints, restrictive practice entries, registers), file attachments uploaded against those records, and billing metadata when paid plans are enabled. During the beta you must only upload synthetic or de-identified files.
2. Where the data lives
| Provider | Purpose | Storage region | Country of incorporation |
|---|---|---|---|
| Vercel Inc. | Application hosting | Sydney (syd1) | United States |
| Neon Inc. | Postgres database | Sydney (ap-southeast-2) | United States |
| Vercel Inc. (Vercel Blob) | File attachment storage | Sydney (syd1) | United States |
| Stripe Payments Australia Pty Ltd | Payment processing (paid plans only) | Australia / United States | Australia / United States |
Data storage is pinned to Australian regions wherever the provider supports it. The current sub-processor list is published on the privacy policy and is versioned; we publish changes before any new processor handles personal information.
3. Cross-border disclosure (APP 8)
Data is stored onshore. However, several providers are incorporated overseas, primarily in the United States, and their staff or systems may access data from overseas for support, maintenance, backups, or security purposes. Before disclosing personal information to an overseas provider we take reasonable steps to ensure the provider handles it consistently with the Australian Privacy Principles, principally through the data protection terms in our agreements with them.
4. Who can access it
Access to production data is limited to people who need it to operate the Service. During the beta this is a small operator team (one or two people) acting on customer support requests, incident response, or system maintenance. Access is via credentialed accounts on each processor, not shared logins.
5. How we protect it
- TLS for data in transit.
- Processor-native encryption at rest (Vercel, Neon, Stripe).
- Passwords stored only as salted bcrypt hashes, never in plain text.
- Storage pinned to Australian regions as listed above.
We do not hold ISO 27001, SOC 2, or IRAP certification today. A security maturity roadmap is planned before the Service stores real participant data outside the beta.
6. Backups and retention
The production database uses Neon point-in-time recovery with a 7-day window. Beta data may be purged at the end of the beta period. Account data is retained for as long as the account is active or as needed to provide the Service.
7. Breach notification
If we confirm a security incident that affects your data, we will notify you within 72 hours of confirmation, by email to the contact address on your account. We assess every confirmed incident against the Notifiable Data Breaches scheme in the Privacy Act 1988 (Cth) and notify the Office of the Australian Information Commissioner (OAIC) where the scheme requires it.
8. Termination, return, and deletion
You can export a complete copy of your account at any time, yourself, from the Data export page in the app. It is a single download with every register in open formats (CSV and JSON) plus your original attached files, so you are never locked in. On termination of your account we delete production data within 30 days of confirmed termination. Backups containing the data expire on the recovery window described in section 6 and are not retained beyond it.
We may retain limited records (for example, billing records) where Australian law requires it. Those records are kept only for the period the law requires and are not used for any other purpose.
9. State health-privacy overlay
The federal Privacy Act 1988 (Cth) and Australian Privacy Principles apply nationally. In New South Wales, the Health Records and Information Privacy Act 2002 and the Health Privacy Principles also apply to health information; the Australian Capital Territory has equivalent obligations under the Health Records (Privacy and Access) Act 1997. We handle health information consistently with these obligations regardless of where your practice is located.
10. Contact
| Data requests, privacy questions, breach notifications | hello@practicebinder.com.au |
|---|---|
| Security disclosure | /.well-known/security.txt |
| Entity | Practice Binder Pty Ltd (ACN 698 705 387) |
| Registered office | 56 Epsom Rd, Kensington VIC 3031 |