Privacy Policy
Last updated: 23 August 2026
AI Core CRM Pty Ltd (ABN 77 670 376 879), trading as Effica, respects personal information and handles it under applicable Australian privacy law. This policy explains what we handle, why we use it, who may receive it, where it may be processed, and how to ask questions or make a privacy request.
Who this policy applies to
This policy covers Effica's website, web platform, mobile apps, sales and support interactions. An NDIS provider normally decides why and how information in its Effica workspace is used. Effica processes that workspace information to provide the service and follow the provider's authorised instructions. Effica separately manages information needed for its own accounts, security, billing, sales, support, and legal obligations.
Effica is independent provider-management software for provider operations. It is not the NDIA or the NDIS Quality and Safeguards Commission, is not NDIS approved or endorsed by either agency, and is not a participant-provider marketplace. Effica may process claim and billing records for a provider, but does not hold or process NDIS plan funds as an intermediary. The customer provider remains responsible for its participant relationships, services, authorisations, regulatory and claim decisions, and submissions.
If a provider manages your record, contact that provider first where practical. We will assist the provider and will respond directly where Effica is responsible for the request.
Participant information consent
A provider can use Effica to explain and record how a participant's information will be collected, stored, used, and shared. The signed form shows each purpose separately, who made the decision, the date, and the retained consent evidence.
Optional purposes are not bundled into the general acknowledgement. They include photo and media use, information sharing where a separate choice is needed, and AI-assisted record processing. A participant or authorised decision-maker may decline an optional purpose without affecting supports and may later withdraw or update it through the provider.
Effica users can review the current choices and signed evidence in the participant profile under Records & compliance, and during referral or intake. The provider remains responsible for explaining the purposes in an accessible way and confirming that the person giving consent has authority to do so.
Information we handle
Accounts and provider administration
Names, contact details, organisation and role details, login and authentication records, permissions, support requests, subscription and billing details, and security or audit events.
Participant and family information
Identity and contact details, NDIS and plan information, support needs, health or disability information, goals, preferences, schedules, service records, notes, incidents, complaints, consents, messages, documents, photos, audio, signatures, and family, nominee, guardian, or other representative details supplied to a provider.
Worker and workforce information
Identity and contact details, employment and role information, availability, qualifications, screening and training records, rosters, timesheets, payroll-related details, shift evidence, messages, and location used for enabled shift workflows.
Technical and usage information
Device, browser, IP address, time zone, session, diagnostic, performance, security, navigation, and feature-use information. Effica may use sanitised route and performance data to monitor website and application reliability. On Effica's public marketing domains, optional Storylane analytics may also receive page, referrer, marketing-cookie, form-attribution, and interactive-demo engagement information after a visitor allows analytics.
Integrations and enquiries
Information exchanged through integrations a provider enables, including Xero or Employment Hero payroll records and encrypted connection credentials while connected. Contact and demo forms use HubSpot, interactive-demo lead attribution may use Storylane after the visitor's analytics choice, and provider subscription checkout and payments use Stripe. Effica does not receive full payment-card details entered directly into Stripe Checkout.
How we collect and use information
We receive information from providers, authorised users, participants and representatives, devices, connected services, and people who contact us. We use it to:
- provide, secure, support, and improve Effica;
- manage participants, workers, rosters, records, billing, compliance workflows, and authorised communications;
- operate customer-selected integrations and AI-enabled workflows;
- administer accounts, subscriptions, service notices, and support;
- detect misuse, investigate incidents, keep audit evidence, and meet legal obligations; and
- respond to enquiries and send marketing that recipients can opt out of.
We do not sell personal information, use tenant operational records for third-party advertising, or use mobile-app information for cross-app tracking. Effica does not currently load a third-party advertising pixel on its public pages. Essential storage, hosting logs, and sanitised performance measurement remain in use. Optional Storylane analytics is disabled until the visitor chooses to allow analytics.
Marketing analytics and privacy choices
Storylane analytics is limited to Effica's public marketing domains and is not loaded on the authenticated application or development application domains. If allowed, it helps Effica connect interactive-demo engagement with known sales enquiries in HubSpot. It does not receive participant, worker, NDIS, clinical, roster, payroll, bank, document, care-note, or incident records.
Visitors can select Essential only or Allow analytics. The choice is stored in the browser and can be changed later using the Privacy choices button. Withdrawing analytics triggers a clean reload so the Storylane tracker is no longer active.
Mobile permissions and location
With device permission, the mobile app may use the camera, photo library, microphone, notifications, and location for role-based workflows. Participant and family portals do not use location for ordinary schedules, messages, or support access.
Support-worker location is used for shift attendance, geofence, arrival clock-in, map, or worker-safety workflows. Background location is off by default and is limited to provider-enabled, worker-consented active-shift tracking or arrival detection. Active tracking stops at clock-out. Arrival detection watches the boundary around the next rostered location rather than recording movement, and stops at arrival, clock-in, sign-out, or when the worker turns it off.
Mobile alerts use Expo and Apple or Google push services. Effica sends only a device push token, a generic alert, an opaque notification ID, and delivery metadata. Push payloads do not include names, care details, locations, links, or record types. Notification details load inside Effica only after authentication and tenant checks.
Sharing and sub-processors
Information may be available to the provider that controls the workspace, authorised users within that workspace, Effica personnel who need it for their role, and suppliers used to deliver the service. It may also be shared with customer-selected integrations, professional advisers, regulators, law-enforcement bodies, or other recipients where authorised or required by law.
Our Sub-processors page identifies the main platform suppliers, purposes, and processing boundaries. We assess suppliers and use contractual, access-control, minimisation, and security safeguards appropriate to the service. Supplier certifications apply to the supplier's scope and are not certifications inherited by Effica or its customers.
Australian storage and overseas processing
Effica's core operational records are hosted in Australia. The primary database, authentication, file storage, and dynamic application compute are configured in Sydney.
This is not a claim that every activity remains in Australia. The United States is the main disclosed overseas location. Email, push notifications, maps, support, payments, website enquiries, background processing, and AI services may also use global Apple, Google, support, or delivery networks. Public and static content may be delivered globally. The current providers and the most specific processing boundaries they publish are linked from our Sub-processors page. Customer-selected integrations may use the locations stated in their own terms.
Where overseas processing is used, it is limited to what is needed for the stated service. Effica applies data minimisation, contractual protections, access controls, and security safeguards appropriate to the information and risk.
Resend may process a recipient address, generic or service-message content, links or codes, and delivery metadata in the United States. Effica minimises email content and provides protected records through Effica-controlled secure access.
AI processing and data minimisation
AI help is optional. Staff choose when to use it. Help that uses a named participant's record stays off until a recorded yes, and can be turned off if that yes is withdrawn. We keep a history of those decisions.
When an authorised user starts an AI-enabled workflow, Effica may send only information relevant to the request to OpenAI, which is listed on our Sub-processors page. That help is processed outside Australia, in the United States. We use OpenAI under a written contract. Effica has not opted customer data into provider model training. We are working toward OpenAI Zero Data Retention.
Login, quota, permissions, and governed tools stay in front of every request. We send only what the task needs. Authorised people remain responsible for reviewing outputs and approving actions.
Automation and decisions
A provider may configure rule-based automation to approve eligible administrative leave requests or timesheets, or assign eligible workers to shifts. Those programs may use role, availability, qualifications, roster, leave, shift, clock, and timesheet information together with rules chosen by the provider. The provider controls the configuration and remains responsible for reviewing outcomes and managing exceptions.
Generative AI may substantially assist with summaries, extraction, completeness checks, drafting, roster suggestions, and operational alerts using the records relevant to that task. AI output is review material and does not independently make clinical, legal, regulatory, funding, or participant-access decisions. Authorised people remain responsible for those decisions and for approving operational changes proposed by Effie.
This section is also intended to support the automated-decision transparency requirements commencing on 10 December 2026.
Security and data-breach response
Effica uses tenant and role access controls, row-level security, encrypted transport, infrastructure encryption at rest, application-level protection for selected high-risk records, audit trails, monitoring, backups, and incident-response procedures. See our Security summary for a plain-English overview.
If we suspect an eligible data breach, we will contain and assess it promptly, take reasonable steps to complete the assessment within the period required by Australian law, and notify affected parties and the OAIC as soon as practicable where notification is required. We will also notify affected customers without undue delay in line with applicable law and any signed agreement.
Retention, access, correction, and deletion
We retain information while needed to provide and secure the service, follow a provider's instructions, resolve disputes, and meet legal, financial, safeguarding, audit, and NDIS record-keeping obligations. When information is no longer required, it is deleted or de-identified through applicable retention and backup processes.
You may ask to access or correct personal information. You may also request deletion, export, restriction, or objection where that option is available. Some records cannot be deleted immediately where a provider or Effica must retain them. Start at our Privacy and Data Requests page. We may verify identity and coordinate with the provider that controls the record. Coordination with the provider does not limit any obligation that applies to Effica for information it holds.
Questions and complaints
Email info@effica.com.au with your concern and enough information for us to identify the relevant provider or service. Please do not attach clinical records, identity documents, or other sensitive material in your first email. We will investigate and respond within a reasonable period.
If you are not satisfied with our response, or have not received a response after 30 days, you may complain to the Office of the Australian Information Commissioner.
AI Core CRM Pty Ltd, ABN 77 670 376 879
Unit 2, 59 Pennington Terrace, North Adelaide SA 5006, Australia
Policy changes
We may update this policy when our services or legal obligations change. The current version and effective date will remain available here. Contract terms are maintained separately in our Terms and Conditions.