Privacy policy
Version 1.0 · Effective 28 August 2026
Who we are, and whether the Act applies
Gap Check is a sole trader business providing advisory services to NDIS provider organisations. We review organisation-level documentation against the NDIS Practice Standards and produce written gap analysis reports.
As a small business operator with an annual turnover under $3 million, Gap Check is generally not an APP entity bound by the Privacy Act 1988 (Cth). We nonetheless apply the Australian Privacy Principles as our working standard, because our clients are organisations with their own privacy obligations and they are entitled to know how we handle information.
We do not accept participant information
This is the most important clause on this page. We do not collect, request or accept participant names, dates of birth, NDIS numbers, contact details, case notes, care plans, support plans, assessments, behaviour support plans or restrictive practice authorisations containing identifying details, or any health information about any individual.
Our engagement terms require clients to de-identify documents before supply, and to send blank templates rather than completed participant records.
If identifying or health information reaches us in error, we delete it, tell you in writing, and record that we have done so. We do not retain it, copy it, or reproduce it in any deliverable.
We do not provide health services and we do not give clinical advice.
What we do hold
- Business contact details — name, role, business email, business phone
- Business information — ABN, registration groups, audit pathway and dates
- Organisation-level documents supplied for review, de-identified
- Correspondence with us, and billing records
Where we contact an organisation that has not dealt with us before, we hold a business contact address the organisation has published on its own website, together with the source web address and the date we recorded it. We hold that to send the message and handle any reply.
Client documents sometimes contain worker names or credential records. We ask clients to remove these before supply. Where they appear anyway we treat them as confidential, do not extract them, and delete them at the end of the engagement.
We do not sell personal information, and we do not disclose it for anyone else's marketing.
Storage, security and overseas processing
Information is stored electronically. We take reasonable steps to protect it, including device encryption, access controls on accounts, and limiting who can access client material — which, as a sole trader business, is one person.
Delivering the work uses third-party services for email, file storage, business software and AI-assisted document review. Some of those providers may store or process data outside Australia. We select providers that offer appropriate security, but by supplying information to us you acknowledge it may be handled by such services.
Only organisation-level documents are processed this way. Participant records are out of scope, are never accepted, and are therefore never supplied to any AI service.
How long we keep things
| Client documents supplied for review | Deleted at the end of the engagement, unless you ask us to retain them |
|---|---|
| Reports we produce | 7 years |
| Financial and tax records | 5 years minimum, as required by law |
| Record of how a business contact address was obtained | 6 years |
| Requests not to be contacted | Kept indefinitely, so we can honour them |
Anything identifying a participant is deleted on discovery, not on a schedule.
Marketing and opting out
Every message we send about our services identifies us, states where we obtained the address, and includes a way to opt out. Reply “unsubscribe” or “stop” to any message, or email hello@gapcheck.net. We action opt-outs immediately and keep a record so the address is not contacted again.
Access, correction and complaints
You can ask what personal information we hold about you, ask us to correct it, or ask us to delete it. Email hello@gapcheck.net. We respond within 30 days, at no charge.
If you are unhappy with how we have handled your information, tell us first and we will respond within 30 days. If you are not satisfied with our response you may contact the Office of the Australian Information Commissioner at oaic.gov.au or 1300 363 992.
This website
This site uses no analytics, no tracking and no cookies. It has no contact forms — the links on it open your own email client, and nothing is submitted to us until you choose to send a message.
Changes
We may update this policy. The current version and its effective date appear at the top of this page.