Privacy Policy
Last updated 17 August 2026.
Before this page goes live, replace every highlighted placeholder and have this document reviewed by an Australian privacy lawyer.
Loopd handles health information about people with disability, which is sensitive information under the Privacy Act 1988. That raises the bar on what this page has to get right, and it is not a document to publish on a draft.
Who we are
Loopd is operated by [Legal entity name], ABN [ABN], of [Registered address] ("Loopd", "we", "us"). We are an APP entity and we handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles.
Loopd is software sold to disability, aged care, community health and in-home care providers. It removes rostering and coordination admin by working on top of the rostering system a provider already runs.
Two different relationships
It matters which one applies to you, because our obligations differ.
- If you are a provider using Loopd, we handle personal information on your behalf and under your instructions. You decide what goes in, who can see it, and how long it stays. You remain responsible for having a lawful basis to collect it and for the notices and consents your own clients rely on.
- If you are a client, family member, nominee or support worker of a provider using Loopd, the provider is the organisation accountable to you. We hold your information because they asked us to. Requests to access, correct or delete it should go to them first, and we will support them in answering you.
What we collect
From the provider and from the rostering system they connect:
- Client names, contact numbers, addresses and scheduled supports.
- Support worker and coordinator names, contact numbers and shift assignments.
- Service agreements, rostered times and related notes.
- Messages sent and received through Loopd, including the wording of change requests, and a record of when each was sent and what came back.
Some of this is sensitive information. Support schedules reveal that a person receives disability, aged care or health supports, and the wording of a request can reveal more. We treat it accordingly and collect it only because it is necessary to deliver the service the provider has engaged us for.
From visitors to this website: nothing beyond what your browser sends to load the page. This site sets no cookies and runs no analytics or tracking of any kind.
Why we hold it
To do the work the provider engaged us to do, and nothing else. That means sending rosters for confirmation, following up the ones that do not come back, applying a requested change and telling the people it affects, and keeping a record of what was sent and agreed so the provider can answer a family or an auditor later.
We do not sell personal information, and we do not use a provider's data to train machine learning models.
Who else touches it
We use a small number of service providers to run Loopd. Each receives only what it needs.
- The provider's rostering system (for our first customers, ShiftCare) so shifts can be read and updated in the system they already use.
- A messaging provider to deliver SMS to families and support workers.
- An AI provider (Anthropic) to read a change request written in a client's own words and work out which shift it refers to. The text of that request and the relevant shift details are sent for that purpose. It is not used to train their models.
- Hosting and infrastructure providers to run the application and store its data.
Some of these process data outside Australia. Where that happens we take reasonable steps to ensure the recipient handles the information consistently with the Australian Privacy Principles, but you should assume some processing occurs overseas. [Confirm the hosting region and each subprocessor's data location, then state them here.]
Keeping it safe
Access to a provider's data requires an account we create for a named person at that provider. Client-facing schedule links are individual to the client. Data is encrypted in transit. We keep the number of people with production access as small as the work allows.
No system is immune. If a data breach occurs that is likely to result in serious harm, we will notify the affected provider promptly and comply with the Notifiable Data Breaches scheme.
How long we keep it
For as long as the provider's account is active, plus the period they need the record for their own compliance obligations. On written request after an account closes we will delete or de-identify the data we hold, except where we are required to keep it by law. [Set the retention period you will commit to and state it here.]
Access, correction and complaints
You can ask for access to the personal information we hold about you, and ask us to correct it if it is wrong. If you are a client or family member of a provider, please ask them first, since they hold the relationship and the context.
Write to privacy@loopdau.com. We will acknowledge within 5 business days and respond within 30 days.
If you are not satisfied with how we have handled a privacy matter, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au or on 1300 363 992.
Changes
If we change this policy we will update the date at the top. If a change materially affects how we handle a provider's data, we will tell that provider directly rather than relying on this page.