Privacy Policy
How we handle personal information, including the compliance records and health information held on the platform.
HCPA Pty Ltd operates Dallo. We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles, and this policy explains how. A copy of the Australian Privacy Principles is available from the Office of the Australian Information Commissioner at oaic.gov.au.
Who this policy covers
It applies to people who use the platform, the providers who subscribe to it, our own staff and contractors, visitors to this website, and anyone whose personal information is processed through the service. It covers this website, the Dallo platform, onboarding, and everything we do around them.
Dallo is not a clinical system and we do not set out to collect patient or participant clinical records. Where such information reaches us, it is because a client has uploaded it as part of their own compliance evidence.
What we collect
- Who you are
- Names, job titles, email addresses, phone numbers, postal addresses, and the credentials you use to sign in.
- What your organisation holds
- The policies, procedures, incident and complaint records, training records, worker screening checks and accreditation evidence you create or upload while using Dallo.
- Sensitive information
- Some compliance records contain health information, such as worker immunisation status, or information about a disability. Health information is sensitive information under the Privacy Act and we handle it accordingly.
- How you use the platform
- IP address, browser and device information, sign-in times, pages visited and actions taken, which we use to keep the service secure and working.
- What you tell us
- Support requests, enquiry forms, feedback and other correspondence.
How we collect it
Most of it comes directly from you: when you register, when you use the platform, when you send an enquiry, and when you contact support. Some of it is generated as you work, such as sign-in times and the record of who approved a document. Some arrives through the services you connect to Dallo. Where it is necessary and the law allows it, we may also collect from public sources, such as a regulator's public register.
Why we collect it, and what we do with it
- Running the platform and giving you the service you signed up for.
- Checking your documents and records against the standards that apply to your registration, and telling you where there is a gap.
- Preparing the evidence an audit asks for.
- Keeping accounts, data and the service itself secure.
- Answering support requests and managing your account.
- Improving the product, including the checks it runs.
- Telling you about changes that affect you, such as a standard that has moved.
- Meeting our own legal obligations, and preventing fraud and misuse.
Automated processing and AI
Dallo uses automated processing, including artificial intelligence, to read your documents and records against the standards that apply to you, to draft documents from your answers, and to flag gaps and changes. Your information is used to do your work. It is not used to train models for anyone else.
What the platform produces is a draft and a prompt to act, not professional advice and not a decision. A person in your organisation approves anything that becomes your policy, your submission or your published page.
Who we disclose it to
- Our own staff and contractors, where they need it to do their job.
- The cloud hosting, infrastructure and security providers that run the platform for us.
- Professional advisers such as lawyers, accountants and auditors.
- A regulator, court or government agency, where the law requires or authorises it.
- Anyone else you ask us to share it with.
We do not sell personal information. Your compliance records are not shared with your competitors or with our other clients.
Overseas disclosure
Your information is stored in Australia. Some of the providers we rely on, such as infrastructure and security services, may process information overseas. Where that happens we require them to handle it consistently with Australian privacy law and to meet appropriate security standards.
How we keep it secure
- Encryption in transit and at rest
- Role based access control, so a person sees only their own organisation's records
- Multi-factor authentication
- Audit logging of access and changes
- Secure cloud hosting
- Vulnerability management and security monitoring
No system can be guaranteed secure, and we do not claim otherwise. If a breach happens that is likely to cause you serious harm, we will tell you and the Office of the Australian Information Commissioner, as the Notifiable Data Breaches scheme requires.
How long we keep it
We keep personal information for as long as we need it to provide the service, to meet our legal obligations, and to resolve disputes. Client records are generally kept for at least seven years after the relationship ends, and some compliance records are kept longer where a health or aged care regulation requires it. When we no longer need information, we destroy it securely or de-identify it.
Your rights
Getting a copy
You can ask us to confirm what personal information we hold about you, what we use it for, and to give you a copy of it.
Correcting it
If something we hold is wrong, incomplete or out of date, ask us and we will correct it. If we decide not to, we will tell you why in writing.
Deleting it
You can ask us to delete or de-identify your information. We will consider the request against what the law requires us to keep, what our agreement with your organisation requires, and what we may need as evidence. Some records we are obliged to retain, and we will say so.
How to ask
Email [email protected] with your name, how to reach you, and what you are asking for. We may need to verify who you are first, which protects your information as much as it does ours. We aim to respond within 30 days. There is no charge to make a request, though we may charge for the reasonable cost of copying a large amount of material.
Cookies and analytics
This website uses cookies that are necessary for it to work, such as keeping you signed in and remembering your preferences. Where they are enabled, we also use analytics cookies to understand how the site is used, and advertising cookies so we can measure our own marketing. You can control or block cookies through your browser settings, though blocking the necessary ones will stop parts of the site working.
Marketing
If we send you marketing, every message carries a way to unsubscribe, and you can also just tell us. Messages about your account, your security and the operation of the service are not marketing and will continue.
Children
Dallo is a business platform. We do not knowingly collect personal information from children.
Changes to this policy
We update this policy as our practices or the law change. The date at the top shows when it last changed. Where a change is significant, we will tell account holders directly.
Contact us, or complain
If you have a question about this policy, or you think we have mishandled your personal information, contact us first at [email protected]. We will investigate and come back to you.
If you are not satisfied with our response, you can take it to the Office of the Australian Information Commissioner at oaic.gov.au or on 1300 363 992.