NDISCompliant is now ProviderQMS — same team, same documents, same prices. What changes for you

Privacy Policy

Last updated: August 2026

1. Overview

This privacy policy explains how Wani Meridian Pty Ltd Pty Ltd (ABN 97 701 307 020), which operates the ProviderQMS project at providerqms.com.au, collects, uses, and protects personal information through providerqms.com.au. We comply with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth).

2. Information We Collect

We may collect the following types of personal information:

2a. The "Notes Never Stored" Commitment

We make this commitment explicitly: ProviderQMS does not log, save, or retain the text content of any note you process through the Notes Rewriter tool. Our server logs capture only metadata such as request timestamps, response duration, token counts, and IP addresses — never the content of your notes. The "Private" engine processes notes entirely on our Australian server infrastructure; the "Premium" engine sends notes to Anthropic (US-based) for processing, after which Anthropic also discards the request per their data-handling policy. We strongly recommend redacting participant names before submitting notes — the in-tool "Anonymize names" button is provided for this purpose.

3. How We Use Your Information

We use personal information for the following purposes:

We do not sell, rent, or share your personal information with third parties for marketing purposes.

4. Third-Party Services

We use the following third-party services to operate ProviderQMS:

Meta (Facebook) Pixel and Conversions API — measures which advertisements lead to a purchase. Sets cookies. We send Meta your email address in an encrypted (hashed) form, together with an identifier we generate ourselves (nc_xid, described in section 7), so that Meta can match a purchase to its own advertising records. We do not send the readable address. See Meta's privacy policy. Google Analytics 4 — measures how pages are used. Sets cookies. See Google's privacy policy. Microsoft Clarity — records anonymised session replays and heatmaps so we can see where the site is confusing or broken. Text you type is masked before it leaves your browser, so form fields, email addresses and payment details are never recorded. Sets cookies. See Microsoft's privacy statement.

5. Data Storage and Security

6. Your Rights

Under the Australian Privacy Principles, you have the right to:

To exercise any of these rights, email hq [at] providerqms.com.au.

7. Cookies

We use essential cookies for site functionality, and advertising cookies set by the Meta pixel described in section 4 — including _fbp, and _fbc when you arrive from an advertisement. These let us measure which advertisements lead to a purchase.

We also store our own advertising measurement identifier, nc_xid, in your browser. It is a randomly generated string that we create; it contains no information about you, is not derived from anything you have told us, and is not used to identify you to anyone other than Meta for advertising measurement. It lasts up to 13 months, and is shared with Meta so that a purchase can be recognised as coming from the same browser that saw an advertisement. Clearing your browser storage removes it, and a new one is generated on your next visit.

We send Meta a record of completed purchases from our own server, using these identifiers together with your email address in an encrypted (hashed) form, so that Meta can match your purchase to its own advertising records. We do not send Meta the readable address.

We do not sell your information, and we do not use these cookies to build a profile of you for anyone else. You can block them in your browser settings or with the advertising controls in your Meta account, and the site will still work.

8. Children's Privacy

Our products are designed for NDIS service providers, which are businesses and organisations. We do not knowingly collect personal information from children under the age of 18.

9. Changes to This Policy

We may update this privacy policy from time to time. The current version is always available at providerqms.com.au/privacy.

Overseas disclosure

Some of the services we rely on to run ProviderQMS are operated outside Australia, so personal information you give us may be stored or processed overseas. Specifically:

We take reasonable steps to ensure overseas recipients handle your information consistently with the Australian Privacy Principles, but we cannot control their operations and they may be subject to the laws of the country they operate in.

Accessing and correcting your information

You may ask us what personal information we hold about you, and ask us to correct it if it is wrong. Email hq@ndiscompliant.com.au from the address your account uses and we will respond within 30 days. There is no charge.

You can also ask us to delete your account and the personal information attached to it. Some records — a receipt, for example — we may need to keep to meet our own legal obligations, and we will tell you plainly if that applies.

10. Complaints

If you believe we have breached the Australian Privacy Principles, please contact us at hq [at] providerqms.com.au. We will investigate your complaint and respond within 30 days.

If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.

11. Contact

For privacy-related enquiries, email hq [at] providerqms.com.au.