At Covered, privacy is not a feature. It is the foundation of our service. Today (Stage 1, Tasmania trial), Covered processes educator credentials, qualification records, NQF/NQS policy documents, and document uploads (PDFs/images) provided by services. Future Stage 2 + Stage 3 expansions will introduce billing, SMS notifications, child management, parent portals, medication records, incident reports, and ACECQA integrations. Those data flows are described in the Stage 2/3 section below and are NOT processed today.
Covered complies with all 13 Australian Privacy Principles (APPs) as set out in the Privacy Act 1988 (Cth). Key highlights:
| Principle | How we comply |
|---|---|
| APP 1 — Transparency | This policy is publicly available. Organisations are required to share it with educators and families during enrolment. |
| APP 2 — Pseudonymity | External API calls use deterministic pseudonyms (e.g. “Educator 1”, “Service A”) rather than real identifiers. |
| APP 3 — Collection | Data collection is limited to fields necessary for childcare management and regulatory compliance. |
| APP 6 — Use & Disclosure | Data is used only for its primary purpose. Data is never sold or shared for marketing. We may share de-identified, aggregated statistical data with government health bodies or regulatory partners where this serves a clear public benefit. No personally identifiable information is included in any such sharing. |
| APP 8 — Security | TLS 1.3 in transit, AES-256-GCM field-level encryption at rest for critical PII, row-level security for multi-tenancy. |
| APP 10 — Access | Educators and families can view and correct their own data via self-service dashboards. |
| APP 12 — Subject Access | Individuals can request their data via privacy@coveredapp.com.au. Response within 30 days. |
Covered shares limited data with the following providers:
| Provider | Data shared |
|---|---|
| Anthropic (Claude API) | Prompt text and REDACTED document text only. Documents are OCR-read (AWS Textract) and PII-redacted (AWS Comprehend) inside Australia BEFORE any text reaches Anthropic. Document files themselves are never sent. Standard commercial terms: no training on our data; inputs/outputs auto-deleted within ~30 days (content flagged for trust-and-safety review or under legal hold may be retained up to 2 years). See §3.5 of the Security Assessment Brief. |
| Amazon Web Services (Sydney region) | Application hosting (ECS), document storage (S3, encrypted), document OCR + PII redaction (Textract + Comprehend), malware scanning (GuardDuty), compliance alert emails (SES), and operational logs/traces (CloudWatch + X-Ray). All in the Sydney (ap-southeast-2) region. |
| Supabase | Database + auth infrastructure (Sydney region; data residency within Australia for storage at rest). |
| Vercel (Sydney edge) | Web page rendering only. No customer records are stored by Vercel. |
| Stage 2: NOT ACTIVE TODAY | Stripe (billing data, when paid plans launch), Twilio (SMS, when notifications expand to SMS). Both require a documented cross-border decision before activation. |
| Stage 3: NOT ACTIVE TODAY | NQAITS / ACECQA APIs (regulator integrations, when child + parent management ships in 2027). |
As an individual whose data is stored in Covered, you have the right to:
For privacy inquiries, data access requests, or complaints:
Email: privacy@coveredapp.com.au
Company: Callixo Pty Ltd · Australia
If you are unsatisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au.