At Covered, privacy is not a feature — it is the foundation of our service. Covered processes deeply sensitive personal information: children's details, educator credentials, medical records, court orders, and incident reports. We take that responsibility seriously.
Covered complies with all 13 Australian Privacy Principles (APPs) as set out in the Privacy Act 1988 (Cth). Key highlights:
| Principle | How we comply |
|---|---|
| APP 1 — Transparency | This policy is publicly available. Organisations are required to share it with educators and families during enrolment. |
| APP 2 — Pseudonymity | External API calls use deterministic pseudonyms (e.g. “Educator 1”, “Service A”) rather than real identifiers. |
| APP 3 — Collection | Data collection is limited to fields necessary for childcare management and regulatory compliance. |
| APP 6 — Use & Disclosure | Data is used only for its primary purpose. Data is never sold or shared for marketing. We may share de-identified, aggregated statistical data with government health bodies or regulatory partners where this serves a clear public benefit. No personally identifiable information is included in any such sharing. |
| APP 8 — Security | TLS 1.3 in transit, AES-256-GCM field-level encryption at rest for critical PII, row-level security for multi-tenancy. |
| APP 10 — Access | Educators and families can view and correct their own data via self-service dashboards. |
| APP 12 — Subject Access | Individuals can request their data via privacy@coveredapp.com.au. Response within 30 days. |
Covered shares limited data with the following providers:
| Provider | Data shared |
|---|---|
| Anthropic (Claude API) | PII-redacted compliance data only (pseudonymised) |
| Stripe | Billing data (organisation name, email, payment method) |
| Resend | Email notifications (recipient email + sanitised content) |
| Twilio | SMS notifications (recipient phone + sanitised content) |
| Supabase | Database infrastructure (data residency within Australia) |
As an individual whose data is stored in Covered, you have the right to:
For privacy inquiries, data access requests, or complaints:
Email: privacy@coveredapp.com.au
Company: Callixo Pty Ltd · Australia
If you are unsatisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au.