Privacy and data requests
Request access, correction, or deletion
Use this page to ask for access to or correction of personal information held in Effica. You may also ask about deletion, export, restriction, or objection where that option is available. If an NDIS provider manages your account, we may need to coordinate with that provider.
Send a privacy request
Email your name, account email, provider organisation, and the request you want us to assess. Please do not include clinical records, identity documents, or other sensitive attachments in your first email. We may need to verify your identity before taking action.
Email info@effica.com.auRequests in the mobile app
Participants and family or guardian contacts can open Profile and choose Delete my account. This revokes their app access and login; it does not automatically delete operational records the provider must retain. Support workers can open More and choose Privacy/data requests to start a request without administrator access. Contact the provider or Effica about access, correction, or deletion of retained records.
Provider-managed accounts
The provider that created or manages an account normally controls the operational records in its workspace. We may direct the request to that provider, ask for its input, or require confirmation before changing records it is legally responsible for. We will still respond directly where Effica controls the relevant information. Coordination with the provider does not limit any obligation that applies to Effica for information it holds.
Staff offboarding
Provider administrators should archive, terminate, or offboard a worker through Workforce or Team Management in the authenticated web app. A privacy request is not a substitute for operational offboarding. Access can be suspended while audit, care, incident, rostering, billing, and employment records are retained where required.
What may be deleted
Personal information may be deleted or de-identified where permitted by law and the provider's obligations. Some financial, employment, safeguarding, incident, care, consent, audit, security, or dispute records may need to be retained. We will explain the applicable reason if information cannot be deleted outright.
How the request is handled
We identify the relevant workspace and privacy role, verify identity in a proportionate way, coordinate with the provider where needed, and respond within a reasonable period under applicable Australian privacy law and the governing customer agreement.