Privacy Policy

Last updated: July 2026

Rivea is an account-based referral platform operated by [TO BE CONFIRMED: legal entity name and ABN] (“Rivea”, “we”, “us”) for NDIS support coordination organisations and allied-health providers. Our launch network focuses on Melbourne's south-east. We handle personal and sensitive information in accordance with the privacy laws that apply to us: the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), and the Health Records Act 2001 (Vic), whose Health Privacy Principles can apply to health information handled by organisations in Victoria. We also work to the expectations that apply to organisations working alongside NDIS participants.

This policy is written to be read. If anything in it is unclear, contact us and we will explain it.

The short version

  • Referral information lives behind accounts and signed-in sessions. There are no links that open participant information without signing in.
  • Contacted providers see structured triage only. Full details reach the selected provider only after a separate, explicit confirmation of disclosure authority and the exact information approved.
  • Emails never contain participant information. A referral is only ever referenced by its code (for example RIV-2K7Q3M).
  • Provider contact, response, selection, disclosure and revocation decisions produce audit evidence.
  • We do not sell personal information, and we never use referral information for marketing.

1. What we collect

Account and organisation information

  • Workspace users: name, work email address, phone number, job title, and sign-in credentials.
  • Organisations: organisation name, ABN, suburb, and — for providers — services offered, service areas, capacity and wait-time information.

Referral information

Referral information is entered by support coordinators, with the participant's consent (see section 2). A referral record can include the participant's full name, date of birth, NDIS number, contact details, location, service needs, goals, support needs relevant to safe delivery, plan status, coordinator notes, and any documents the coordinator attaches. Holding this information on the record is what lets us share only the right slice of it at each stage — see section 3.

Platform activity

We record how the platform is used: sign-ins and sessions, actions taken on referrals, disclosure stage changes, messages sent in referral threads, and document views and downloads. This is a deliberate feature — it is what makes access to sensitive information accountable.

2. Consent and authority

A referral may only be submitted where the coordinator has the authority to make it. At intake we record the basis of that authority — the participant themselves, a plan nominee, a guardian, or a supported decision-making arrangement — together with the consent wording shown and the time it was confirmed. When a provider is selected, the record also captures how the choice was directed by the participant. Selection does not disclose full details by itself. The coordinator separately records who confirmed disclosure authority, when and how it was confirmed, and the exact fields and documents approved. If consent is withdrawn, the coordinator withdraws the referral and every contacted provider's access ends (see section 6).

3. Who sees what, and when — staged disclosure

Referral information is not shared with providers all at once. Every contacted provider receives the same structured triage allowlist. Full access is a separate recorded decision for the selected provider:

TriageEvery provider a referral is sent to

Shared: Service and controlled referral purpose; general area only (the first part of the postcode and the region — never an exact address or full postcode); age group; urgency band; delivery preference; and controlled support-need flags relevant to safe service delivery.

Withheld: Names, free text, date of birth, NDIS number, contact details, exact location, filenames, document metadata and document bytes are not shared.

FullThe one provider selected for the referral

Shared: Full name, date of birth, NDIS number, participant contact details, intake information, approved documents, and the coordinator's contact details. Contact details are exchanged in both directions so intake can begin.

Withheld: This stage is reached only after the participant's choice and a separate disclosure-authority confirmation record who confirmed it, when, how, and the exact fields and documents approved. Providers who are not selected never reach it, and their access to the referral ends.

Before full disclosure, the coordinator reviews the exact fields and documents to be shared and confirms their authority. Rivea then creates an immutable disclosure snapshot. The selected provider's full view is generated from that snapshot rather than the mutable referral.

4. Documents

Documents attached to a referral are private by default. Each document is visible to the selected provider only. Sharing and revoking a document is recorded, and document access events are kept as audit evidence. Structured referral information comes first; we do not ask for full NDIS plans by default.

5. Referrals belong to organisations

A referral belongs to the coordinator organisation that created it, not to an individual login. The current release enables one owner for each workspace; team membership and invitations remain disabled. Organisations are strictly separated from one another.

6. When access ends

  • Withdrawal or cancellation: if a referral is withdrawn, every contacted provider's access to it is revoked.
  • Non-selection: when a provider is selected, the providers who were not selected lose access. Rivea queues outcome notifications and tracks delivery separately so a failed email never masquerades as a delivered message.
  • Account and organisation controls: we can suspend accounts and organisations, and terminate active sessions, where that is needed to protect participant information.

7. Emails contain no participant information

Email is used to tell people that something is waiting for them — never to carry referral content. Notification emails identify a referral only by its reference code and link to the sign-in screen. The only email links that carry any authority are the normal account ones: email verification and password reset, and they only ever lead to an authentication screen. We follow the same rule ourselves: our team will never ask you to share participant information by email or phone.

8. How we use information

  • To identify providers that meet the current approval, service, area and capacity rules.
  • To let coordinators choose among eligible providers without ranking or automatic selection.
  • To notify workspace users that something needs their attention.
  • To administer provider workspace activation and record the dates of business identity (ABN) and registration checks when performed.
  • To operate, secure, audit and improve the service.

We do not sell or rent personal information, we do not share it for marketing, and we do not use referral information to build profiles of participants.

9. Who else receives information

Staged disclosure covers providers. A small set of other recipients can also receive information:

  • Rivea administrators receive organisation, account and provider-directory metadata needed to activate and secure the service. The administrator role does not receive participant or referral content.
  • Technology providers that run our hosting, database, file storage, email and security services. They process information to provide those services to us, not for their own purposes. The list of these providers — what each one does and where it processes information — will be published at [TO BE CONFIRMED: subprocessor register location, before launch].
  • Regulators, courts and law enforcement, where the law requires or permits it, and emergency services where someone's safety is at serious and immediate risk.
  • A successor organisation, if Rivea is restructured or its operations are transferred. A successor takes the information subject to this policy, and workspace users are notified first.

10. Storage, security and overseas processing

Information is encrypted in transit and at rest. Participant content stays with the coordinator and contacted provider workspaces; the administrator role is restricted to account, organisation and provider metadata. Sessions can be reviewed and terminated.

Where the infrastructure sits — hosting, database, file storage and backups — is [TO BE CONFIRMED: production hosting, database, file-storage and backup locations, and any overseas countries involved]. We do not claim that all information stays in Australia. Before launch we will assess any overseas processing against the cross-border disclosure rules that apply to us, and record the outcome in this policy.

11. Retention

We keep referral records for as long as they are needed to support the referral and to meet the record-keeping obligations that apply to the organisations involved. Where information is no longer required and we are not obliged to retain it, we delete or de-identify it. The schedule for each record type — including audit logs, withdrawn referrals and backups — is [TO BE CONFIRMED: retention and deletion schedule by record type, before launch]. You can ask us about retention of any specific record.

12. Your rights

Under the Australian Privacy Principles you may:

  • request access to the personal information we hold about you;
  • request correction of information that is inaccurate or out of date;
  • request deletion of your information, where we are not required to retain it;
  • withdraw consent for a referral (via your support coordinator, or directly with us); and
  • make a privacy complaint.

Participants can exercise these rights through their support coordinator or by contacting us directly at admin@rivea.app. We respond to access, correction and deletion requests within [TO BE CONFIRMED: response timeframe, before launch].

One limit worth stating plainly: deletion is not an absolute right. Record-keeping obligations can require us to keep a referral record even after a deletion request. Where that happens, we will tell you what we are keeping, why, and when it can be deleted.

13. Data breaches

If we suspect a data breach, we contain it, assess what happened, fix the cause and document it. Where the Notifiable Data Breaches scheme or another law requires it, we notify the people affected and the relevant regulator. A notification describes what happened, the information involved, and the practical steps you can take.

14. Complaints

If you believe we have mishandled personal information, contact admin@rivea.app. We acknowledge complaints promptly, investigate them, and respond within [TO BE CONFIRMED: complaint response target, before launch]. If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner at https://www.oaic.gov.au/privacy/privacy-complaints. For health information handled in Victoria, you can also complain to the Health Complaints Commissioner at https://hcc.vic.gov.au/make-complaint; both bodies will usually expect you to have raised the issue with us first. For concerns about NDIS supports and services more broadly, the NDIS Quality and Safeguards Commission is at https://www.ndiscommission.gov.au. Our contact page sets out the full pathway.

15. Changes to this policy

When this policy changes, we update the date at the top and, for material changes, notify workspace users in the product. Earlier versions are available on request.

16. Contact

Privacy enquiries: admin@rivea.app. General enquiries: admin@rivea.app. See also our contact and complaints page.