Privacy Policy
Last updated 11 August 2026
SILWise is a web tool that helps NDIS Supported Independent Living (SIL) and Specialist Disability Accommodation (SDA) providers work out how much rent and board each participant should contribute.
This policy explains what personal information we collect, why we collect it, who we share it with, where it is stored, and how you can access, correct or delete it. It covers both the information we hold about you as a customer and the participant records you enter into the tool.
1. Who we are, and how this policy works
SILWise is an Australian small business. Our annual turnover is under $3 million, so we may fall within the small business exemption in the Privacy Act 1988 (Cth). We do not rely on it.
We have chosen to handle personal information in accordance with the Australian Privacy Principles, and this policy is written to meet Australian Privacy Principle 1. We do that for a straightforward reason: our customers are NDIS providers who are bound by the Privacy Act, and they cannot meet their obligations to the people they support if we do not meet ours.
This policy applies to our website, our help site, and the SILWise application. Our Terms of Service govern your use of the service itself.
2. Two different kinds of information
This is the most important thing to understand about SILWise, so we have put it first.
Information about you
If you sign up, we hold your email address, your name if you provide it, and records of your subscription. You are our customer, you gave us this information directly, and this policy governs how we handle it.
Information about participants
When you use SILWise you enter details about the NDIS participants your organisation supports — their name, the house they live in, which Centrelink payments they receive and what they are charged for. Those participants are not our customers. They did not sign up and they have no account.
For that information, your organisation decides what goes in, what it is used for, and how long it is kept. We hold and process it on your organisation’s instructions, solely in order to provide the service. We do not use it for our own purposes, we do not sell it, and we do not use it to train artificial intelligence models.
Because we act on your organisation’s behalf, your organisation is responsible for having a lawful basis to collect and enter participant information — including any consent required — and for telling participants how their information is handled, as Australian Privacy Principle 5 requires. Our Terms of Service set this out.
Where a participant has a guardian, an NDIS-appointed nominee, a plan nominee or another formal substitute decision-maker, or is supported to decide by a family member or support coordinator, it is your organisation’s job to make sure consent comes from the right person under whatever arrangement applies. We have no way to check that, and we do not.
If you are a participant, or a family member, guardian or supporter of one, and you want to know what information is held about you: contact the provider that supports you first. They control the record and can show you, correct it or remove it. You can also email us at tomt@agentmail.to and we will help you reach the right organisation.
3. What information we collect
About you and your organisation
- your email address, which is required to create an account
- your name, which is optional and added in account settings
- a securely hashed version of your password — we never store the password itself and cannot see it
- your organisation’s name, and the role you hold in it (owner, admin or member)
- your subscription plan and status, and the identifiers Stripe uses for your customer and subscription records
- an activity log of significant actions — for example signing in, inviting a member or saving a calculation — recorded against your user ID with a timestamp
- the content of any correspondence you send us
We do not collect your date of birth, your postal address or your ABN. We only collect a phone number if you give us one through the enquiry form on our website.
About participants, entered by you
- the participant’s name
- the house they live in, including its address if your organisation chooses to record one
- which Disability Support Pension rate applies to them, and which supplements and allowances they receive — pension supplement, energy supplement, Commonwealth Rent Assistance, youth disability supplement, pharmaceutical allowance, utilities allowance and telephone allowance
- whether they are under 21, because different Centrelink rates apply
- their living arrangement where it changes the rate — for example single, partnered, illness-separated, or living in the family home
- which meals and consumables they are charged for, and the amounts
We do not ask for and do not store a participant’s date of birth, NDIS number, Centrelink Customer Reference Number, diagnosis, or any description of their disability or support needs.
Because every participant record includes a Disability Support Pension rate, the fact that a person receives that pension is recorded. Combined with their name and the address of the house they live in, that is sensitive information under the Privacy Act. Section 6 explains how we treat it.
Saved calculations and PDFs
When you save a calculation, SILWise stores a permanent snapshot of the figures used, including participant names and the payment amounts that applied on that date. This is deliberate: a saved calculation must not change when Centrelink rates are indexed later, so that you can always show what you charged and why. PDFs generated from a calculation contain the same information, plus the name and email address of the staff member who created them.
Collected automatically
- standard web server logs, including IP address, browser type and the pages requested
- technical error reports and diagnostic data when something goes wrong
We use no analytics, advertising or tracking tools of any kind. There are no third-party trackers on our website or in the application.
From our website enquiry form
If you submit the enquiry form on our website, we collect your name, organisation, email address, phone number, the number of houses you run, and your message.
4. How we collect information
Wherever we can, we collect personal information directly from you: when you create an account, when you enter data into the application, when you complete a form, and when you contact us.
Information about participants is necessarily collected indirectly — you enter it, they do not. We do not obtain participant information from Centrelink, Services Australia, the NDIA, the NDIS Quality and Safeguards Commission or any other third party. The Centrelink rates the tool applies are published payment rates, not information about any individual.
You cannot hold a SILWise account anonymously or under a pseudonym. Australian Privacy Principle 2 asks us to allow that where it is lawful and practicable, and here it is neither: the whole point of the access controls in section 9 is to keep one organisation’s records away from another’s, and we cannot do that without knowing who holds the account. You can read our public website without telling us anything.
5. Why we collect information and what we use it for
Your information
- to create your account and keep it secure
- to provide the service and support you
- to take payment and manage your subscription
- to send service emails — password resets, billing notices and important service changes
- to maintain an activity log so your organisation can see who did what inside its account
- to detect, investigate and prevent misuse or security incidents
- to meet our legal obligations
Participant information
For one purpose only: to calculate and present rent and board contributions, and to produce the statements and PDFs you ask for.
We will not use or disclose personal information for any other purpose unless you would reasonably expect it, you have consented to it, or we are required or authorised by law. We do not sell personal information, and we do not use your data or participant data to train machine learning or artificial intelligence models.
Today we do not use your data or participant data in de-identified or aggregated form either. We may do so in future — for example to show you how your house running costs compare with other providers. If we do, three things will always hold: the data will be aggregated and stripped of anything that identifies a person or an organisation, no individual participant record will ever be visible to another customer, and we will update this policy and tell account owners before it starts rather than afterwards.
6. Sensitive information
Under the Privacy Act, health information — which includes information about a person’s disability — is sensitive information and attracts additional protection.
We treat participant records in SILWise as sensitive information. In practice:
- we collect it only because you enter it, and only for the calculation purpose described in section 5
- we disclose it only to the service providers listed in section 7, and only so far as they need it to host or transmit it
- it is confined to your organisation by access rules enforced in the database itself, so no other customer can reach it
- we never use it for marketing, profiling or product analytics
- we do not send it outside Australia
Your organisation is responsible for having participant consent, or another lawful basis, before entering this information into SILWise. We rely on that.
The people this information is about
These records describe people with disability who did not choose this software and in many cases will never know it exists. That is worth saying plainly, because it is the reason for most of the choices elsewhere in this policy: no analytics, no tracking, no AI training, no marketing use, storage in Australia, and no participant record leaving the country.
Other laws that may apply to you
The Commonwealth Privacy Act is not the only law about health information. New South Wales, Victoria and the Australian Capital Territory each have their own health records legislation, and depending on where your organisation operates you may be covered by it as well. We handle participant records to the standard set out in this policy whichever applies — but your own obligations are yours to check, and in some states they are stricter than the Commonwealth rules.
8. Where your information is stored, and overseas disclosure
Your account records, your participant records and your generated PDFs are stored in a Supabase database in Sydney, Australia (AWS ap-southeast-2). The application code that reads and writes them runs in Vercel’s Sydney region. Backups are held in the same region.
Participant information does not leave Australia. It is stored in Sydney, processed in Sydney, and is not disclosed to any of the overseas recipients listed below.
Australian Privacy Principle 8 requires us to tell you about overseas recipients. Some information is disclosed outside Australia:
- Stripe, in the United States, receives your billing details when you subscribe
- Resend, in the United States, transmits our account emails
- Sentry, in the United States, receives technical error reports
- Google, in the United States, receives enquiry form submissions from our website
- Vercel is a United States company. Although our application functions run in Sydney, Vercel’s global network and support staff may handle request logs outside Australia
Before disclosing personal information overseas we take reasonable steps to ensure the recipient handles it in a way consistent with the Australian Privacy Principles, through the terms of our agreements with them. We cannot, however, guarantee that an overseas recipient will never be compelled to disclose information under the laws of its own country.
9. How we keep information secure
- Separation between customers. Access rules are enforced in the database itself, not only in the application. Every query runs as a restricted role that can only reach rows belonging to your organisation. We maintain an automated test suite whose specific job is to prove one organisation cannot read another’s data.
- Encryption. All traffic to and from SILWise uses HTTPS. Data is encrypted at rest by our hosting providers.
- Passwords. Stored only as a bcrypt hash. We cannot read your password. Password reset links are single-use, expire after 60 minutes and are rate-limited.
- Sessions. Logins use a signed, HTTP-only, secure cookie that scripts on the page cannot read. Sessions expire after 24 hours.
- Payments. Card details are entered on Stripe’s own pages and never reach our servers. We never see or store a card number.
- Documents. Generated PDFs are held in a private storage area and are only reachable through a time-limited link issued after we have checked your membership of the organisation.
- Roles. Owners, admins and members have different permissions. Only owners can invite or remove members.
No system is completely secure. These measures reduce risk; they cannot eliminate it. If you believe your account has been compromised, contact us immediately at tomt@agentmail.to.
10. How long we keep information
We do not automatically delete your organisation’s records. That is a deliberate choice. NDIS providers have record-keeping obligations — including binding seven-year retention periods under the NDIS Rules for certain records — and it is not our place to decide when your records should be destroyed. You control that.
- While your account is open — we keep your account details, your organisation’s records and your saved calculations.
- Deleting inside the application — deleting a house, a participant or a calculation removes it from view but retains the underlying record, so that historical calculations remain intact and auditable. Tell us if you want something removed permanently.
- Closing your user account — your access ends and you are removed from the organisation. We retain a minimal record, including your email address in a scrambled form and your password hash, so that activity history stays intact and the account cannot be silently re-created. Your organisation’s records are unaffected. If you want those remaining details erased, ask us and we will do it.
- When your organisation stops using SILWise — we keep your data so that you can return or request a copy. We will not delete it unless you ask. If you ask, we will delete it within 30 days and confirm in writing.
- Unsaved drafts are cleared automatically after 30 days.
- Password reset tokens expire after 60 minutes.
- Website enquiries are kept in our email for as long as we need them to respond and to keep a record of the conversation.
If you would prefer that we hold nothing at all once you leave, tell us and we will delete everything.
11. Accessing, correcting and deleting information
We take reasonable steps to keep the personal information we hold accurate, up to date and complete. Almost all of it comes from you, so the most useful step we can take is making it easy for you to fix — which is why nearly everything is editable in the application.
You can view and change most of your own information inside the application: your name and email address under account settings, and your organisation’s houses, participants and cost centres in the application itself.
For anything else, email tomt@agentmail.to. You can ask us to:
- give you a copy of the personal information we hold about you
- correct anything that is wrong, incomplete or out of date
- permanently delete your personal information, or your organisation’s data
- export your organisation’s data
We will respond within 30 days. We do not charge for making a request. We may charge a reasonable cost for supplying a large volume of information, and we will tell you what it will cost before we do any work.
If we refuse a request, we will tell you why in writing and explain how you can complain.
Requests about a participant
If a participant, or someone acting on their behalf, asks us for the information held about them, we will direct them to the provider that entered it, because that organisation controls the record. We will let you know when this happens so that you can respond.
12. If something goes wrong — data breaches
If we become aware of unauthorised access to, or unauthorised disclosure or loss of, personal information held in SILWise, we will:
- act immediately to contain it
- assess whether it is likely to result in serious harm
- notify every affected customer organisation within 72 hours of becoming aware of it, whether or not the Notifiable Data Breaches scheme legally requires us to
We commit to 72 hours because you may have your own obligation to notify the Office of the Australian Information Commissioner and the people affected, and you cannot meet it if we are slow to tell you. Our notice will explain what happened, what information was involved, what we have done about it, and what we recommend you do.
Where the Notifiable Data Breaches scheme applies, we will also notify the Office of the Australian Information Commissioner.
14. How the calculation works
SILWise applies published Centrelink and NDIS rates to the information you enter and produces a suggested rent and board contribution.
This is a calculation, not a decision. SILWise does not make any decision about a participant. Your organisation reviews the figures and decides what to charge. No part of the process is automated decision-making about an individual.
We record which version of the Centrelink rates was used for every saved calculation, so that you can always see exactly what a figure was based on and reproduce it later.
15. Marketing emails
We send you service emails — password resets, billing notices and important changes to the service — because you hold an account. You cannot opt out of these while your account is open, because you need them to use the service safely.
Any marketing or product-update email we send will identify us clearly and include a working unsubscribe link, as the Spam Act 2003 (Cth) requires. Unsubscribing takes effect within five business days.
16. Making a complaint
If you think we have mishandled personal information, please tell us first. Email tomt@agentmail.to with the details. We will acknowledge your complaint within 5 business days and give you a written response within 30 days.
If you are not satisfied with our response, or we do not respond in time, you can complain to the Office of the Australian Information Commissioner:
- Online: oaic.gov.au/privacy/privacy-complaints
- Phone: 1300 363 992
- Post: GPO Box 5218, Sydney NSW 2001
17. Changes to this policy
We may update this policy from time to time. The “last updated” date at the top of the page always shows the current version.
If we make a change that materially affects how we handle your personal information, we will email account owners at least 30 days before it takes effect. That is the same notice period our Terms of Service give for a material change to the terms themselves, so a change that touches both runs to one deadline rather than two.
18. How to contact us
Privacy questions, access and correction requests, and complaints: tomt@agentmail.to
General support and billing: tomt@agentmail.to
ABN 59 676 182 096
