Privacy Policy

This explains what personal information PF Platform holds, why we hold it, where it is stored, and how you or an NDIS participant can see it, correct it or have it deleted. It covers both the people who use this platform and the participants whose information providers record in it.

Last updated: 2026-08-06

Who we are

PF Platform is operated by Global Buildtech Australia Pty Ltd (ABN 54 672 395 685), the entity responsible for the personal information described in this policy.

We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. As a provider operating in the NDIS market we are also subject to the NDIS Quality and Safeguards Commission's requirements.

Post: 76-84 Brunswick Street, Fortitude Valley QLD 4006. Email: dennis@corporateaisolutions.com or +61 402 612 471.

Whose information this policy covers

Two different groups of people appear in this system, and the distinction matters.

Platform users are the staff of participating providers, rental agencies, plan managers and property owners who log in and do the work. They give us their information directly.

NDIS participants generally do not use this platform. Their information reaches us because a provider records it here in the course of managing accommodation and claims. If you are a participant, you can still exercise every right set out below, and you do not need to go through your provider to do it.

What we collect

From platform users: name, work email, phone, the organisation you act for, role and permissions, authentication data, and a record of the actions you take in the system (an audit log, which we keep deliberately — see Security).

About NDIS participants we hold the information required to manage an SDA tenancy and claim it correctly:

  • NDIS participant number
  • Name and date of birth
  • Contact details, where supplied
  • Plan management type, plan status and plan start and end dates
  • The SDA design category funded under the plan, and the dwelling and occupancy the participant is enrolled in
  • Claims, payments and reconciliation records arising from that occupancy

Sensitive information

Some of what we hold is sensitive information as defined in section 6 of the Privacy Act. A participant's NDIS number, funded SDA design category and occupancy together describe that person's disability support needs.

We collect it only because it is reasonably necessary to manage accommodation and to lodge and reconcile SDA claims accurately, and only from providers who have the participant's consent or another lawful basis to disclose it to us. We do not use it for marketing, we do not sell it, and we do not use it to train AI models.

How we use it

To run accounts and control who can see what; to calculate SDA pricing; to prepare, lodge and reconcile claims with the NDIA and plan managers; to manage properties, tenancies and occupancies; to produce statements for owners and clients; and to contact you about the service.

We use AI to read documents you upload — onboarding paperwork, property and participant records — and turn them into structured fields, so that a person is checking extracted data rather than retyping it. AI does not decide claim amounts, eligibility or pricing; those follow the NDIA published rules and are reviewable by the people using the system.

Who we share it with, and where it goes

Only the parties and providers needed to run the service:

  • The NDIA and, where applicable, a participant's plan manager — to lodge and reconcile claims
  • Rental agencies and property owners — limited to what they need for the tenancy and their own statements
  • Supabase — database, authentication and file storage
  • Vercel — application hosting
  • Anthropic — the AI that extracts fields from uploaded documents
  • Google Workspace — document handling
  • Xero — accounting and reconciliation
  • ElevenLabs — where the voice assistant is used
  • Resend — transactional and notification email

Your information is stored outside Australia

We are stating this plainly because it is the kind of thing people assume the other way. Our database — including participant records — is hosted in Supabase's ap-south-1 region in Mumbai, India. It is not stored in Australia.

The providers listed above also process data overseas, including in the United States. We take reasonable steps under APP 8 to ensure overseas recipients handle your information consistently with the Australian Privacy Principles, but we cannot control an overseas recipient's handling to the same degree as our own.

If Australian data residency is a condition of your organisation using this platform, or of a participant consenting to their information being recorded here, tell us before you proceed rather than after.

How long we keep it

Claims, payment and reconciliation records are kept for at least seven years, because NDIS and taxation record-keeping obligations require it. Participant records are kept for as long as the occupancy is current and for that same period afterwards.

User accounts are kept while they are active. When an account is closed we delete or de-identify the personal information attached to it, except where a record must be retained under the obligations above. Audit logs are retained deliberately, because their value depends on not being editable after the fact.

Your rights

You can ask us for a copy of the personal information we hold about you, ask us to correct it if it is wrong, ask us to delete it, or ask how a particular piece of information reached us. Participants can make any of these requests directly.

Write to dennis@corporateaisolutions.com or +61 402 612 471 and we will respond within 30 days. We may need to verify your identity first, which for a participant usually means confirming details already on the record.

If you are not satisfied with our response you can complain to the Office of the Australian Information Commissioner at oaic.gov.au or on 1300 363 992. Concerns about the conduct of an NDIS provider can also go to the NDIS Quality and Safeguards Commission on 1800 035 544.

Security

Access is restricted by role, so a rental agency or owner sees only their own records, enforced at the database with row-level security rather than only in the interface. Data is encrypted in transit and at rest. Actions that change records are written to an audit log.

If a data breach occurs that is likely to result in serious harm, we will notify affected people and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme.

Changes and contact

We will update this policy when what we do changes. The date at the top of the page tells you which version you are reading.

Privacy enquiries and complaints: dennis@corporateaisolutions.com or +61 402 612 471, or by post to 76-84 Brunswick Street, Fortitude Valley QLD 4006.

Report a problem