Privacy Policy
A clear overview of how BondiByte Robotics may handle information across the public website, customer workspaces, support processes, and platform operations.
Overview
This Privacy Policy explains how BondiByte Robotics may handle information in connection with the BondiByte website, SaaS platform, customer workspaces, support processes, and billing or subscription activities where applicable.
BondiByte is provided by BondiByte Robotics Pty Ltd (ACN 699 516 231), a company registered in Queensland, Australia, which is responsible for the information described in this policy.
BondiByte is designed for NDIS provider operations. Information may include account, organisation, workspace, operational, document, audit, support, usage, and billing information.
This Privacy Policy was last updated on 17 June 2026.
Information we may collect
The information handled by BondiByte depends on how a customer, user, auditor, or website visitor interacts with the website and platform.
- Account and contact information, such as name, role, email, organisation, and login-related identifiers.
- Organisation and workspace information, such as workspace settings, sites, teams, roles, and operational configuration.
- Staff and client operational records entered by customers.
- Documents, files, and audit evidence uploaded or released by customers.
- Usage, logs, device, security, support, and troubleshooting information.
- Billing, plan, subscription, invoice, order, and payment-related information where applicable.
- Sensitive information, including health, disability, or care-related information about participants, and staff clearances or checks, where customers enter it into their workspace.
How information is used
BondiByte Robotics may use information to provide, secure, support, maintain, improve, and administer the website and platform.
Information may also be used to support customer onboarding, workspace operation, notifications, email workflows, audit evidence workflows, automation capacity controls, subscription administration, support enquiries, and security monitoring.
Customer workspace information
Customer workspace information is entered, uploaded, configured, or managed by the customer and its authorised users. This may include staff, clients, sites, rosters, service agreements, documents, incidents, reports, timesheets, invoice drafts, audit evidence, and automation settings.
Customers are responsible for deciding what information is entered into their workspace, who can access it, and how it is reviewed, approved, published, exported, or shared.
For customer workspace information, the customer is the organisation responsible for that information under the Privacy Act 1988 (Cth). BondiByte Robotics handles it on the customer's behalf and on their instructions, applying role-aware access and permission checks.
Staff, client, auditor, and user information
BondiByte may handle information about staff, clients, auditors, customer users, platform users, and other people when that information is provided by a customer, entered into the platform, used for access control, or needed for support.
Staff Portal and Auditor Portal access are designed for separate access surfaces, with customer-controlled staff records and scoped auditor access supporting the relevant workflow.
Sensitive and health information
Because BondiByte supports NDIS provider operations, customer workspaces may contain sensitive information as defined by the Privacy Act 1988 (Cth), including health, disability, and care-related information about participants, and information such as staff clearances and checks.
Customers decide what sensitive information is entered into their workspace and are responsible for collecting and handling it lawfully, including obtaining any consent required under the Australian Privacy Principles. BondiByte Robotics handles this information on the customer's behalf, applies access controls, and does not use customer workspace information for its own unrelated purposes.
Customers may store government-related identifiers such as NDIS numbers in their records. BondiByte Robotics does not adopt those identifiers as its own.
Automation and decision support
BondiByte includes automation and smart features that prepare drafts, suggestions, reminders, and scheduled actions to support provider operations. These features are decision-support tools designed to be reviewed and acted on by the customer's authorised people.
BondiByte Robotics does not use these features to make decisions that produce legal or similarly significant effects about an individual without human involvement. Customers review automated features and their outputs when needed, and decide what to act on, consistent with the BondiByte Terms and Conditions.
Service providers and hosting
BondiByte Robotics may use trusted service providers to operate the website and platform, including providers for hosting, storage, email delivery, monitoring, support, analytics, security, payment processing, or other operational needs.
Service provider use may change over time as the platform develops. BondiByte Robotics expects service providers to support the secure and reliable operation of the service.
Where information is stored and overseas disclosure
BondiByte is built for Australian NDIS providers, and customer workspace information is primarily stored and processed in Australia.
Some service providers may process limited information outside Australia, for example, payment processing or email delivery, which can involve recipients in other countries, including the United States. Where information is disclosed to an overseas recipient, BondiByte Robotics takes reasonable steps, consistent with Australian Privacy Principle 8, to require that recipient to handle the information in a way consistent with the Australian Privacy Principles.
Security measures
BondiByte is designed to support role-aware access, separated access surfaces, controlled file access patterns, platform-managed email, and permission checks.
No online service can prevent every possible security event. Customers also play an important role by managing user access, protecting credentials, reviewing role assignments, and handling uploaded information responsibly.
Data breaches
BondiByte Robotics maintains processes to assess and respond to data security incidents. If an eligible data breach occurs that is likely to result in serious harm, BondiByte Robotics will respond consistently with the Notifiable Data Breaches scheme under the Privacy Act 1988 (Cth), including notifying the Office of the Australian Information Commissioner and affected individuals where required.
Where a breach involves customer workspace information, BondiByte Robotics will work with the affected customer, who may also have its own notification obligations.
Retention
BondiByte Robotics may retain information for as long as needed to provide the service, support customer workspaces, meet operational and billing needs, resolve disputes, maintain audit and security records, comply with legal obligations, and support legitimate business purposes.
Retention periods may vary depending on the type of information, customer agreement, configuration, legal requirements, and operational needs.
Cookies and website analytics
The public BondiByte website stores a small amount of first-party information in the visitor's own browser to remember how they found the site, for example a campaign name or referring website, so that enquiries can be understood in context. This is limited to marketing-channel details, is kept for around 90 days, and never includes form contents, names, contact details, or any NDIS participant or client information. Visitors can clear it at any time through their browser settings.
The public website uses Google Analytics 4 to measure aggregate traffic and page usage, such as which pages are viewed and how visitors generally move through the site. This does not include the contents of any form you submit, your name, or your contact details, and it is not used for advertising personalisation. You can disable this in your browser using its privacy settings or an extension that blocks analytics scripts.
The signed-in platform uses cookies and similar technologies that are necessary to authenticate users and keep workspaces secure.
Access, correction, and enquiries
Customers can manage many records directly inside their workspace. People seeking access to or correction of information should usually contact the organisation that controls the relevant workspace information.
Privacy questions for BondiByte Robotics can be sent through the public contact page. BondiByte Robotics may need to verify the request and coordinate with the relevant customer where the information belongs to a customer workspace.
Contact BondiByte RoboticsPrivacy complaints
If you believe BondiByte Robotics has handled personal information in a way that is inconsistent with the Australian Privacy Principles, you can make a complaint through the public contact page. Please include enough detail for BondiByte Robotics to identify and investigate the issue.
BondiByte Robotics will acknowledge the complaint, investigate it, and respond within a reasonable time. If you are not satisfied with the response, you can escalate the complaint to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
Where a complaint concerns information held in a customer workspace, BondiByte Robotics may need to coordinate with the relevant customer.
Raise a privacy complaintChanges to this policy
BondiByte Robotics may update this Privacy Policy as the website, platform, service providers, support model, billing processes, or legal requirements change.
The latest version published on the website should be read together with any applicable customer agreement or order terms.
Contact
For privacy enquiries, contact BondiByte Robotics through the public contact page.
Send a privacy enquiry