Important: withdrawing consent stops future processing that relies on that consent. It does not automatically erase an uploaded record when the record must be retained for safety, incident management, a complaint, a legal obligation or a legal hold. Every request receives a documented review.
1. Scope
This policy applies to client-support information processed in ptNexus services operated by PTCorp Pty Ltd (ABN 59 143 430 700), including client profiles, intakes, case notes, support sessions, recordings, transcripts, reports, identity references, documents, face photographs, consent records, access records and audit events.
It applies to production information, metadata, exports and recoverable copies controlled by PTCorp. It does not replace a tenant organisation’s legal, funding, clinical, safeguarding or records-management obligations. Where another applicable requirement requires a longer period, the longer period applies.
This policy does not authorise facial recognition. A face photograph may be collected for a stated support or verification purpose, but ptNexus does not create biometric templates or perform face matching, recognition or identification.
2. Responsibilities
Tenant organisation
The organisation delivering support ordinarily decides why client information is collected and used. It must identify its lawful purposes, confirm the people authorised to act, apply any sector-specific schedule and decide requests involving its client records.
Powered by PTCorp
PTCorp operates the platform and processes information for the tenant under the service agreement. We apply platform safeguards, enforce the approved workflow, assist with searches and deletion, record actions, and verify provider-side deletion where it is within our control.
Individual or authorised representative
A client, guardian, nominee or other authorised representative may request access, correction, restriction or deletion. We must verify identity and authority before disclosing or deleting client information.
3. Retention principles
- Collect and retain only information needed for a stated service, safety, legal, contractual or accountability purpose.
- Apply the shortest approved period that is consistent with the tenant’s obligations.
- Keep raw recordings and identity evidence for less time than the reviewed service record wherever possible.
- Stop new consent-based processing after valid consent withdrawal.
- Do not delete information while a complaint, incident, investigation, access request, safeguarding matter or legal hold requires it.
- Destroy or de-identify personal information when it is no longer needed and no exception requires retention.
- Record who approved a disposal, the scope, checks performed, provider results and completion date without preserving the deleted content.
4. Default retention schedule
The tenant may approve a shorter period where lawful or a longer period where required. The period is calculated from the trigger below unless a hold applies.
| Information | Default period and trigger | Disposal outcome |
|---|---|---|
| Raw audio recordings | 90 days after upload, or 30 days after the transcript or summary is reviewed and accepted, whichever occurs first. | Delete the audio object. Retain only an approved transcript, summary or case note when still required. |
| Unaccepted local recording | Immediately when consent is withdrawn before upload or the user cancels capture. | Discard locally; do not upload. |
| Client documents and face photographs | 30 days after the stated collection purpose is completed, unless the item is necessary evidence for an active service, complaint, incident, investigation or other required record. | Delete the object and sensitive metadata; retain only minimum verification or disposal evidence. |
| Client profiles, intakes, reviewed case notes, support records, transcripts and reports | 7 years after the client’s last service or the record’s closure, unless the tenant’s applicable law or approved schedule requires a different period. | Delete or irreversibly de-identify. Preserve only information subject to an approved exception. |
| NDIS complaint records | 7 years from the date the complaint record is made, where the NDIS complaints rules apply. | Delete or de-identify after the statutory period and hold review. |
| NDIS reportable incident records | 7 years from the relevant notification date, where the NDIS incident rules apply. | Delete or de-identify after the statutory period and hold review. |
| Anonymous, unlinked intakes | 12 months after last activity. The returned anonymous access credential expires after 30 days. | Delete or de-identify unless linked to a client record or retained for a safety or legal reason. |
| One-use linking credentials | Usable for no more than 24 hours. Expired or used token digests may be retained for 90 days for abuse and replay investigation. | Delete the digest and associated temporary access record. |
| Consent, access and disposal audit events | 7 years from the event. | Delete or de-identify while preserving no raw note, recording, document or access credential. |
| De-identified operational statistics | While reasonably required for service assurance and improvement, provided re-identification risk remains appropriately controlled. | Review at least annually and delete when no longer useful or sufficiently de-identified. |
5. Access, correction, consent withdrawal and deletion requests
Send requests to privacy@poweredbyptcorp.com.au. If your services are delivered by a ptNexus tenant, you may also contact that organisation directly. We will:
- acknowledge the request as soon as practicable;
- verify the requester’s identity and authority using proportionate information;
- identify the tenant and records in scope;
- ask the tenant to assess service, safety, recordkeeping and legal requirements;
- normally provide a decision within 30 calendar days, or explain why more time is reasonably needed;
- explain any refusal or partial refusal and available complaint options; and
- after approval, complete and verify deletion without requiring the person to submit another request.
Where consent is withdrawn, new processing under that consent scope stops. If an uploaded item cannot yet be deleted, access is restricted and the reason and review date are recorded.
6. Legal holds and required retention
A hold may apply to a complaint, reportable incident, safeguarding matter, anticipated or current legal proceeding, regulator request, audit, insurance matter, access request or investigation. A hold:
- must identify its authority, scope, owner and review date;
- must be limited to information reasonably required;
- prevents scheduled deletion only for the affected material;
- does not permit unrelated use or wider access; and
- must be lifted promptly when the reason ends, after which the normal schedule resumes.
7. Secure deletion and de-identification
An approved deletion covers the primary database record, private object storage, generated derivatives, searchable indexes, exports controlled by the tenant or PTCorp, and recoverable copies within our control. Sensitive client storage is configured without public access, object versioning or provider soft delete so an approved object deletion does not intentionally leave an ordinary recovery copy.
Backups that cannot be safely edited record-by-record are isolated from ordinary use, expire under the provider’s controlled backup cycle, and are subject to re-deletion if restored. Completion is not claimed until the deletion workflow records provider results or confirms that remaining material has been put beyond use pending expiry.
De-identification is used only when the remaining information is no longer about an identifiable or reasonably identifiable person, taking account of other data reasonably available. Replacing a name with an internal identifier is not, by itself, sufficient.
8. Other service providers
Cloud hosting, authentication, communications, payment and approved verification providers may retain information under their own legal obligations and published policies. PTCorp and tenants must not claim to have deleted provider-controlled information that they cannot delete. We will send an authorised request where the contract permits, record the response and tell the requester about any material exception.
9. Security, assurance and policy changes
Sensitive client capture remains unavailable for a tenant until dedicated Australian-region storage, encryption, least-privilege access, audit logging, this policy version and a live upload/download/delete test have been approved. Publication of this page alone does not prove that a tenant has passed that gate.
We review this policy at least annually and after a material legal, provider or platform change. Each release receives a version and effective date. A tenant must acknowledge a newer version before secure client-storage provisioning or revalidation can continue; prior acceptances remain available for audit.
10. Contact and complaints
Email privacy@poweredbyptcorp.com.au or write to PTCorp Pty Ltd, 8/5 Smiths Road, Goodna QLD 4300. You may also complain to the tenant organisation that provides your service. If a privacy concern is not resolved, you may contact the Office of the Australian Information Commissioner. NDIS participants may also contact the NDIS Quality and Safeguards Commission about the quality or safety of NDIS supports.
Authoritative references
- OAIC — APP 11: Security, destruction and de-identification
- OAIC — APP 12: Access to personal information
- NDIS Complaints Management and Resolution Rules 2018
- NDIS Incident Management and Reportable Incidents Rules 2018
This policy describes PTCorp’s operational commitments. It is not a complete statement of every law that may apply to a tenant or an individual record.