Last updated: 20 August 2026
1. About this Privacy Policy
This Privacy Policy explains how personal information is collected, used, stored, disclosed and retained when you use SW Ally — our website at swally.com.au, our web application and our mobile app.
We aim to handle personal information responsibly and in accordance with applicable Australian privacy laws, including the Australian Privacy Principles (APPs) in the Privacy Act 1988 (Cth). Where a particular obligation does not apply to us as a matter of law, we still aim to meet the standard it sets, because SW Ally holds information about people with disability and we think that information deserves careful handling regardless of which obligations are technically enlivened.
This policy applies from the date above. It does not form part of any contract, and it does not replace the Terms of Service.
2. Who we are
SW Ally is operated by Edge Tech Digital (ABN 22 320 747 179), an Australian business.
In this policy, “SW Ally”, “we”, “us” and “our” mean Edge Tech Digital operating the SW Ally platform. “You” means the person using SW Ally.
SW Ally is a platform for independent disability support workers and support coordinators in Australia. SW Ally is not an advertising platform. We do not sell personal information, and we do not use the information in SW Ally to target advertising.
Privacy contact: support@swally.com.au
3. Information we collect
Depending on how you use SW Ally, we may collect and hold:
- Identity and contact information — name, email address, mobile and other contact details.
- Account and authentication information — your role, sign-in credentials (passwords are stored only as a one-way hash, never in readable form), authentication tokens, and sign-in activity.
- Support worker profile information — the professional and business details you choose to save, which may include business name, ABN, business address and the payment details used on your invoices.
- Participant-related information — see section 4.
- Shift notes and handover information.
- Incident records.
- Invoices and invoice information.
- Documents you upload to the service.
- Worker compliance documents where you choose to store them.
- Calendar entries and events.
- Tasks.
- Messages and other communications sent through the platform.
- Device and push-notification information — see section 11.
- Limited crash and error diagnostic information — see section 12.
- Technical and audit information — including the IP address of the request recorded against significant events in our audit log (see section 8).
We do not collect or store your payment card number. Card details are entered directly with our payment processor and do not reach our systems.
4. Participant and disability-support information
SW Ally exists to help support workers and support coordinators keep records about the people they support. That means the platform holds detailed information about NDIS participants, most of whom are not our users and do not have an account with us.
Participant information entered by a worker or coordinator may include a participant’s name, contact details, date of birth, address, NDIS number, plan dates and plan-management details, plan manager or self-managed billing contacts, shift notes describing the support provided, handover notes, important information such as preferences and communication needs, incident reports, calendar events, documents, messages and invoices.
This information is entered by the worker or coordinator, not by us. They remain the provider of supports and the keeper of the record. They are responsible for having the consent or lawful authority they need to record and share a participant’s information. Our role is to hold that information securely, enforce the access rules we publish, and handle it as described in this policy.
SW Ally accounts are currently provided to support workers and support coordinators. Participant information may be recorded in SW Ally by authorised users, but participants do not currently have their own SW Ally login. Participants have rights in relation to information about them whether or not they hold an account — see section 17.
5. How information is collected
We collect personal information:
- Directly from you — when you create an account, complete your profile, write a note or handover, report an incident, raise an invoice, upload a document, send a message, or contact us for support.
- From the workers and coordinators who use SW Ally — participant information is entered by them in the course of delivering or coordinating supports.
- From other users you are connected to — for example when a coordinator assigns you to a participant, or a colleague records a handover on a participant you both support.
- Automatically, through your use of the service — authentication events, audit records of significant actions, device and push-notification information, and limited crash and error diagnostics.
Where it is reasonable and practicable, we collect personal information directly from the individual concerned. In this product that is often not possible, because a support worker records information about a participant in order to do their job.
6. Why we collect and use information
We use personal information to:
- provide the service — participant records, notes, handovers, incidents, documents, calendar, tasks, messaging and invoicing;
- authenticate you and keep accounts and records secure;
- send service communications such as verification messages, password resets, incident notifications, invoice delivery and important service notices;
- deliver push notifications you have enabled;
- provide support when you contact us;
- take payment and manage subscriptions;
- detect, investigate and prevent fraud, misuse and security incidents;
- maintain audit records so that access to participant information can be reviewed;
- diagnose crashes and errors so we can fix them;
- meet our legal, safeguarding and record-keeping obligations.
We also look at aggregated and de-identified usage information — how often features are used, where errors occur — to improve SW Ally. We do not use participant health information, shift notes, incident reports or message contents to train machine learning systems, and we do not use them for advertising.
7. Sensitive information
Much of what SW Ally holds is sensitive information under the Privacy Act 1988 (Cth) — in particular health information and information about a person’s disability.
Sensitive information about a participant is collected only because a worker or coordinator enters it in order to deliver or coordinate that participant’s supports. We do not collect it for any other purpose. We do not use it to build profiles, to target advertising, or to train machine learning systems.
The obligation to obtain a participant’s consent, or to have other lawful authority, to record and share their information sits with the worker or coordinator as the provider of supports. This is set out in our Terms of Service.
8. How information is stored and protected
We take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access, modification or disclosure. Those steps include:
- encryption in transit (HTTPS/TLS) and encryption at rest;
- passwords stored using a one-way hash — we cannot read your password;
- role-based access enforced in the backend, so permissions cannot be bypassed by manipulating the interface;
- relationship-based access — a worker sees a participant’s record because they are assigned to that participant, and removing the assignment ends the access;
- audit logging of significant events — including sign-in, issuing a device access token, assigning a worker to a participant, opening the emergency screen, and incident and document actions;
- expiring access tokens on mobile devices, and the ability to sign out other devices from your account settings;
- restricted staff access, with access to participant records logged and reviewable.
Technical information recorded with audited actions. For security, investigation and audit purposes, SW Ally may record technical information such as the IP address associated with certain audited actions. This is used to answer who, when and from where if a participant’s information is accessed inappropriately. It is not shown anywhere in the product, it is not shown to your coordinator, and it is not used in any report or metric. It is not GPS or precise device location, and it is not used to track a support worker’s whereabouts or working hours.
No system is perfectly secure, and we do not claim otherwise. We do not currently hold any independent security certification, and nothing in this policy should be read as claiming one.
Data breaches. If a breach occurs that is likely to result in serious harm, we will notify the affected individuals and the Office of the Australian Information Commissioner in line with the Notifiable Data Breaches scheme. Where a breach affects a participant’s information, we will also notify the worker or coordinator responsible for that record and, where appropriate, the participant or their nominee.
9. Service providers and third parties
We use a small number of service providers to run SW Ally. Each is engaged to provide a service to us, and is expected to protect the information and use it only for that purpose.
- Application hosting, database and document storage — SW Ally’s core application, database and participant document storage are hosted in Australia, in the Sydney (
ap-southeast-2) region. - Transactional email — used to deliver verification messages, invoices, notifications and service notices. Handles the recipient’s email address and the contents of the message.
- Payment processing — handles your name, email address and card details, which you enter directly with the processor. We receive confirmation and subscription status, not your card number.
- Mobile push notification delivery — handles a device push token, a short headline and internal record identifiers. See section 11.
- Error and crash diagnostics — where configured, receives the limited technical information described in section 12.
- Marketing website hosting — the public swally.com.au website is hosted separately from the application and holds no participant data.
We keep a current list of the providers we use and will name each one on request. Contact support@swally.com.au.
We do not sell personal information, and we do not disclose participant information to third parties for their own marketing or commercial purposes.
10. Overseas processing and storage
SW Ally’s core application, database and participant document storage are hosted in Australia. Some service providers used to deliver functions such as email, push notifications, billing or diagnostics may process limited information in other locations.
Where that happens, the information involved is limited to what that provider needs to perform its function — for example an email address and message contents for email delivery; a device token and a short headline for push notifications; your name, email address and payment details for billing; and the technical diagnostic information described in section 12.
Where personal information is disclosed to an overseas recipient, we take reasonable steps to ensure it is handled consistently with the Australian Privacy Principles. If you would like to know which providers we currently use and where they process information, contact support@swally.com.au.
11. Push notifications
If you use the SW Ally mobile app and allow notifications, your device is issued a push token, which we store so we can send notifications to that device. We also record when the token was last registered, so a device you no longer use can be retired.
Push notifications are deliberately minimal. A notification carries a short headline and internal record identifiers — for example the identifier of the notification and of the participant it relates to. A participant’s name and the contents of a note, handover, incident or message are not placed in a push notification, because a notification preview can be read on a locked phone left on a table.
You can turn notifications off in your device settings at any time, and you can control which categories you receive in the app’s notification settings.
12. Crash and error diagnostics
We may collect limited technical error and crash diagnostic information to help identify and fix problems with the SW Ally mobile application.
Our diagnostic configuration is designed to minimise personal information, and does not intentionally send participant records, authentication tokens, document contents or raw error messages. Diagnostic collection may be disabled where the service is not configured.
A diagnostic event may include the error class, a coarse error code, sanitised stack information, the screen name where the failure happened, the app version and build, the platform and environment, and an anonymous event identifier.
We have deliberately turned off the features of our diagnostics tooling that most often capture personal information. In particular, we do not enable:
- session replay or screen recording;
- screenshots;
- capture of the on-screen view hierarchy;
- capture of network request or response bodies;
- breadcrumb trails of your activity in the app;
- the tooling’s default collection of personally identifying information;
- native crash, app-hang and low-level device crash capture.
We will not claim these safeguards make it impossible for personal information to appear. Minimising and sanitising diagnostic data substantially reduces the risk, but an unexpected failure can produce output that no filter anticipated. We treat crash diagnostics as potentially containing personal information and handle them accordingly. If you believe diagnostic data has captured something it should not have, please tell us at support@swally.com.au.
13. Cookies and website technologies
The SW Ally application uses cookies that are necessary for the service to work — keeping you signed in, and protecting the security of your session. These cannot be turned off while you continue to use the service.
The public swally.com.au website does not use advertising, analytics or tracking cookies. Ordinary browsing of the public website does not require you to accept cookies. Our hosting platform may set a cookie where one is genuinely needed, for example for security or page caching, and signing in to the application sets the session cookies described above.
The website loads fonts from Google’s font service. That means your browser makes a request to Google in order to display the page, and Google receives your IP address as part of that request.
Most browsers let you block or delete cookies. If you block cookies that SW Ally needs to keep you signed in, parts of the service will not work.
14. Disclosure of information
We disclose personal information only in the following circumstances.
- To the people you share with inside the service. SW Ally is a shared workspace by design. When a coordinator assigns a worker to a participant, that worker can see that participant’s record according to the permissions we publish. When you send an invoice or a Request for Service, we deliver it to the address you specify. These are your disclosures, made through our software.
- To the service providers described in section 9, so they can provide their service to us.
- Where required or authorised by law — for example a court order, subpoena, or a lawful request from a regulator such as the NDIS Quality and Safeguards Commission, or from police.
- To lessen or prevent a serious threat to the life, health or safety of any individual, where we reasonably believe that is necessary. In a disability support context this matters: if we become aware of an immediate safeguarding risk, we will act on it.
- If the business is sold or transferred — information may transfer to the buyer. We will take reasonable steps to notify account holders, and would expect the buyer to be bound by this policy or one no less protective.
We do not sell personal information, and we do not disclose it for advertising.
15. Account deletion and retention
You can delete your SW Ally account from the app or website. Deleting your account turns off access, revokes active credentials and removes or replaces live account and profile information.
You can start this at app.swally.com.au/close-account, or by contacting us.
What deleting your account does:
- your access to the service is turned off;
- authentication, session and device credentials are revoked, and you are signed out everywhere;
- stored push-token values are disabled or forgotten, so your devices stop receiving notifications;
- live account and profile information is removed or replaced;
- live worker bank, contact and profile information is cleared, where applicable;
- unused drafts and certain derived data are deleted.
Using the same email address again. The email address on a deleted account may later be used to create a new SW Ally account. That new account is a fresh start: it does not automatically receive the deleted account’s records.
Account deletion is not an erase-all of every record. Some records may be retained where necessary or appropriate for legal, safeguarding, financial, audit, NDIS record-keeping, dispute-resolution or similar obligations. Records that may be retained include:
- completed shift notes;
- submitted incident records;
- published handovers;
- issued and numbered invoices, and their PDFs;
- participant documents;
- worker compliance evidence, where retention remains required;
- audit and administrative records.
There is a further reason beyond our own obligations: participant records and invoices are frequently documents that you, or another worker or coordinator, are legally required to keep. Removing them on request could destroy someone else’s record.
Before you delete your account, export what you need. SW Ally can generate a progress report covering a date range, and your invoices can be exported. We do not charge for an export.
If you want to understand exactly what would be kept in your circumstances, or you want to ask a question about deletion or retention, contact support@swally.com.au and we will explain what we hold, what we can remove, what we cannot, and why.
16. Data retention
We retain personal information only for as long as reasonably necessary for the purposes for which it is held, and where retention is required or appropriate for legal, safeguarding, financial, audit, NDIS record-keeping, dispute-resolution or similar obligations. Different categories of records may be retained for different periods.
If you want to know how long a particular kind of record is kept, ask us at support@swally.com.au.
17. Access and correction
You can ask for a copy of the personal information we hold about you, and ask us to correct it if it is wrong. Email support@swally.com.au. We aim to respond within 30 days. We do not charge for reasonable requests.
If you are a participant — including if you do not have a SW Ally account — you have the same right in relation to information about you. Where that information sits in a record kept by your support worker or coordinator, we will usually direct you to them first, because they control that record and are best placed to explain it. If that does not work, contact us and we will help.
Much of a participant’s record can be exported as a progress report covering a date range. Ask your coordinator or support worker.
There are limited circumstances where we may not be able to give access or make a correction — for example where doing so would unreasonably affect another person’s privacy, such as identifying a worker who raised a safeguarding concern, or where a record must be preserved. If we cannot act on a request, we will tell you why in writing and explain how to complain.
18. Privacy complaints
If you think we have mishandled personal information, please tell us first. Email support@swally.com.au with the details. We will acknowledge your complaint and aim to respond substantively within 30 days.
If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner:
- oaic.gov.au
- 1300 363 992
- GPO Box 5288, Sydney NSW 2001
If your complaint concerns the conduct of an NDIS provider rather than our software, the NDIS Quality and Safeguards Commission (1800 035 544, ndiscommission.gov.au) is the right place to raise it.
19. Children and participant information
SW Ally accounts are for adults. You must be at least 18 to hold an account.
However, a participant supported through SW Ally may be a child or young person, and a worker or coordinator may record information about them in the same way as for any other participant. Where that happens, the information is subject to the same protections described in this policy, and the worker or coordinator remains responsible for having the consent or authority of the child’s parent, guardian or nominee.
Where a participant, nominee, parent or guardian wants access to information held about a child, section 17 applies. If you believe information about a child has been recorded in SW Ally without proper authority, contact support@swally.com.au.
20. Changes to this policy
We may update this policy. The date at the top of this page shows when it was last updated.
If a change is significant — particularly a change to who we share information with, or to what we use information for — we will take reasonable steps to notify account holders before it takes effect. We will not apply a materially broader use to information already collected without your consent.
21. Contact details
For privacy questions, access or correction requests, or questions about deletion and retention:
Edge Tech Digital
ABN 22 320 747 179
Email: support@swally.com.au
Privacy policy: https://swally.com.au/privacy