KareShift
← Back to Home

Privacy Policy

Last updated: 14 August 2026

1. Introduction

Aventaryk Pty Ltd (ABN 86 628 196 921) ("we", "us", "our") is committed to protecting the privacy of your personal information. This Privacy Policy explains how we collect, use, store, and disclose personal information in accordance with:

  • The Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) — for Australian users
  • Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and Ontario's Personal Health Information Protection Act (PHIPA) — for Canadian users
  • The New Zealand Privacy Act 2020 and Information Privacy Principles (IPPs) — for New Zealand users
  • The UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 — for UK-based users

By using the Service, you acknowledge the collection, use, and disclosure of personal information as described in this Privacy Policy. You also acknowledge that certain service metadata — including transactional email content — may be disclosed to overseas recipients (including in the United States) as described in Section 11.

We collect, use, and disclose personal information where reasonably necessary for our functions and activities, to provide the Service, comply with legal obligations, and otherwise as permitted by applicable law.

1.1 Scope Across Organisations, Sectors, and Jurisdictions

This Privacy Policy applies to all Organisations you create or manage within the Service, regardless of:

  • The number of Organisations under your account
  • The country or jurisdiction in which each Organisation operates (including Australia, Canada, New Zealand, and the United Kingdom)
  • The sector of care the Organisation operates in (including NDIS, Residential Aged Care, disability support, long-term care, or any other sector supported by the Service)

Each Organisation's data is stored in the region assigned to its country (see Section 4.1). Where an Organisation operates in a jurisdiction with its own privacy legislation, the Organisation remains responsible for ensuring its collection and use of personal information complies with applicable local privacy laws. We will handle data for all Organisations in accordance with this Privacy Policy and, where required, take reasonable steps to support compliance with applicable local privacy legislation.

UK organisations may request a Data Processing Agreement (DPA) under Article 28 UK GDPR by contacting privacy@kareshift.com.

Canadian organisations handling personal health information under Ontario's PHIPA may contact privacy@kareshift.com to discuss PHIPA-specific custodian obligations and any available privacy addenda.

2. Information We Collect

2.0 Sensitive and Special Category Information

Applicable frameworks: AU — APP 3.3 | CA — PHIPA | NZ — Health Information Privacy Code 2020 | GB — UK GDPR Art. 9

The Service may store sensitive or special category information, including:

  • Health and disability information (participant/resident/client disability type, support needs, progress notes, clinical observations)
  • Location data (GPS coordinates collected only when a worker actively performs a clock-in or clock-out action — not biometric data; KareShift does not perform continuous or background location tracking)

We only collect sensitive information where:

  • You have provided explicit consent by entering the data into the Service on behalf of your participants, residents, or clients; or
  • The collection is required or authorised by law (e.g., NDIS record-keeping obligations, LTCHA documentation requirements); or
  • Collection is necessary to prevent a serious threat to life, health, or safety.

We apply additional safeguards to sensitive information, including encryption at rest and in transit, strict access controls, and audit logging of relevant access and security events.

For UK organisations: GPS location data collected during worker clock-in/out is processed on the basis of Art. 6(1)(b) (performance of the employment contract between the worker and the Organisation) and Art. 6(1)(f) (legitimate interests in care delivery verification). KareShift does not perform continuous location tracking — coordinates are captured only at the point of clock-in or clock-out. The Organisation is responsible for ensuring workers are informed of location data collection as required by the ICO's guidance on employee monitoring.

2.1 Account Information

When you create an account, we collect:

  • Full name
  • Email address
  • Phone number (optional)
  • Organisation name
  • Province, state, or region (depending on your Organisation's country)
  • Password (stored in hashed form — we cannot see your password)

2.2 Organisation Data

When you use the Service, you may enter data about your organisation, including:

  • Support worker / carer / PSW details (name, email, phone, address, employment details, compliance documents)
  • Participant / client details (name, contact information, NDIS number or NHI number, disability type, funding information including Whaikaha or MoH funding details)
  • Resident details (name, contact information, medical history, medications, allergies, dietary needs, mobility, cognitive status, next of kin, GP details, Medicare number or NHI number)
  • Canadian client/resident identifiers: Ontario Health Card Number (OHIP), Passport Program service codes and funding amounts, Developmental Services Ontario (DSO) referral identifiers, and provincial ministry funding information (Canadian organisations). We do not collect Social Insurance Numbers (SIN) or passport numbers.
  • Facility and room information (wings, floors, bed counts, occupancy)
  • Shift and timesheet records
  • Leave records
  • Progress notes and incident reports
  • Clinical observations (vitals, skin integrity, falls risk assessments)
  • Care plans (ADL tasks, frequencies, priorities)
  • AN-ACC funding classifications (AU aged care)
  • Restrictive practice event records
  • Messages, attachments, and communication records
  • NHS Number, CQC registration details, and NHS CHC or local authority funding information (UK organisations)
  • interRAI assessment data and Whaikaha service booking information (NZ organisations)

Important: The Organisation remains responsible for determining the purposes and lawful basis for the collection and use of participant, resident, worker, and client information. KareShift acts as a service provider and processes personal information only to provide the Service and in accordance with the Organisation's instructions. The Organisation is responsible for obtaining appropriate consents before entering sensitive information (including health, disability, and clinical data) into the Service.

2.3 Information We Receive From Others

We may receive personal information from Organisations, administrators, integrations, or other authorised users of the Service (for example, when an administrator invites a worker or imports records via CSV).

2.4 Automatically Collected Information

  • IP address
  • Browser type and version
  • Device type
  • Pages visited and features used
  • GPS coordinates (collected only when a worker actively performs a clock-in or clock-out action)

3. How We Use Your Information

We use your information to:

  • Provide, maintain, and improve the Service
  • Process your subscription and payments
  • Send transactional emails (shift notifications, approval alerts, compliance reminders)
  • Provide customer support
  • Detect and prevent fraud or security issues
  • Comply with legal obligations

We do not use your information to:

  • Sell or rent your data to third parties
  • Send unsolicited marketing emails — we will only send marketing communications where we have your consent. For Canadian recipients, we comply with Canada's Anti-Spam Legislation (CASL) and will only send commercial electronic messages (CEMs) where we have your express or implied consent as defined by CASL. You may withdraw consent at any time via the unsubscribe link in any such email or by contacting hello@kareshift.com. Transactional emails (shift notifications, compliance reminders, billing receipts) are not commercial electronic messages and are sent without separate CASL consent.
  • Build advertising profiles
  • Share participant, resident, or worker data with anyone outside your organisation

4. Data Storage and Security

4.1 Where We Store Data

Organisation CountryData RegionAWS Region
AustraliaSydney, Australiaap-southeast-2
CanadaSydney, Australiaap-southeast-2
New ZealandSydney, Australiaap-southeast-2
United KingdomSydney, Australiaap-southeast-2

Data residency note: All customer data is currently stored in AWS Sydney (ap-southeast-2), Australia. This applies to all countries including Canada, New Zealand, and the United Kingdom. We are a small independent software company and do not yet operate regional infrastructure outside Australia. We take reasonable technical and organisational steps to protect data stored in this region.

For New Zealand organisations: your data is stored in Australia by an Australian entity. KareShift handles New Zealand personal information in accordance with the New Zealand Privacy Act 2020 and the Australian Privacy Act 1988. We consider Australia to provide comparable privacy protections for the purposes of Information Privacy Principle 12 of the NZ Privacy Act 2020.

For Canadian organisations: your data is stored in Australia by an Australian entity. KareShift handles Canadian personal information in accordance with PIPEDA and, for Ontario health information, PHIPA. All data is encrypted at rest (AES-256) and in transit (TLS 1.2+). We use contractual safeguards with our hosting provider (Amazon Web Services) to ensure Canadian personal information receives a comparable level of protection as required by PIPEDA Principle 7. Details of these safeguards are available on request by contacting privacy@kareshift.com. We plan to review Canadian regional infrastructure options as our Canadian customer base grows.

For UK organisations: Australia does not hold a UK adequacy decision under UK GDPR Article 45. We transfer UK personal data to Australia on the basis of the UK International Data Transfer Agreement (UK IDTA) or equivalent Standard Contractual Clauses (SCCs) as approved by the ICO, which provide appropriate safeguards for the transfer. We will make a copy of the applicable transfer mechanism available on request — contact privacy@kareshift.com. We also offer a Data Processing Agreement (Art. 28 UK GDPR) on request. We plan to provision a UK-region infrastructure option as our UK customer base grows.

Care-related operational data is stored in the region assigned to your organisation's country. See Section 11 for details on service metadata that may be processed outside your region.

4.2 Security Measures

  • Data is encrypted at rest using AES-256 or equivalent industry-standard encryption technologies
  • All data in transit is encrypted (TLS 1.2+)
  • Passwords are hashed using bcrypt (never stored in plain text)
  • Access to production systems is restricted and logged
  • Regular automated backups with point-in-time recovery
  • Infrastructure is provisioned and managed using modern security and automation practices

While we implement reasonable security safeguards, no method of electronic transmission or storage is completely secure and we cannot guarantee absolute security.

5. Data Retention

We retain your data for the following periods:

Data TypeRetention PeriodReason
Participant & worker records (AU)Up to 7 years (or longer where required by law)NDIS record-keeping requirements; ATO requirements
Timesheets & payroll data (AU)Up to 7 yearsATO requirements; Fair Work Act
Health & care records (CA — Ontario LTC)Up to 10 years from last entry (or longer where required by law)Ontario Long-Term Care Homes Act (LTCHA); PHIPA retention requirements (s.13)
Worker & payroll records (CA)Up to 3 years (or longer where required by provincial law)Ontario Employment Standards Act, 2000 (ESA s.15); federal payroll record requirements
Health & clinical records (NZ)Up to 10 years from last entry (or until age 26 for minors, whichever is later)Health Information Privacy Code 2020, Rule 9
Care records & staff records (GB)Up to 8 years after last contact / 6 years after staff departureCQC/NHS Records Management Code of Practice
Audit logsUp to 7 years (or longer where required by law)Regulatory audit compliance
Account informationDuration of account + 30 daysService provision
Notification history90 daysOperational reference

After your subscription ends, your data remains in read-only mode for 30 days to allow you to export your records. After the read-only period, your account is suspended. Following account closure, we may retain archived records for the applicable period set out above where required to support legal, regulatory, audit, security, or record-keeping obligations. The Organisation remains responsible for maintaining its own copies of records required under applicable legislation. We strongly recommend exporting all data before or during the 30-day read-only period.

6. Third-Party Services

We use the following third-party services to operate KareShift:

ServicePurposeData Shared
Amazon Web Services (AWS)Infrastructure & hostingCustomer and operational data stored within the Service (encrypted, within your region)
StripePayment processingBilling email, payment method (we never see full card numbers)
AWS SES (ap-southeast-2)Transactional email (secondary)Email addresses, notification content. Processed in Sydney, Australia.
Resend (via resend.com)Transactional email (primary)Recipient email address, sender address, email subject and body content. Processed in the United States.

We do not share your organisation's participant, resident, or worker data with any third party for any purpose other than providing the Service.

We may engage carefully selected subprocessors and service providers to support the Service. A current list of subprocessors is available on request by contacting privacy@kareshift.com.

6A. Disclosure Required by Law

We may disclose personal information where required by law, court order, warrant, regulator request, or lawful request from a government authority. Where legally permitted, we will notify the affected Organisation before making such a disclosure.

7. Your Rights

Under the Australian Privacy Principles, you have the right to:

  • Access — Request a copy of the personal information we hold about you
  • Correction — Request correction of inaccurate or incomplete information
  • Export — Export supported categories of your organisation's data using the export tools made available through the Service
  • Deletion — Request deletion of your account and personal data (subject to legal, regulatory, audit, security, and record-keeping obligations)
  • Complaint — Lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au if you believe we have breached the APPs

To exercise any of these rights, contact privacy@kareshift.com. We will respond within 30 days.

7.1 Additional Rights for UK Users

If your Organisation is based in the United Kingdom, you have additional rights under the UK GDPR and Data Protection Act 2018:

  • Right of access — Request a copy of the personal data we process about you
  • Right to rectification — Request correction of inaccurate or incomplete personal data
  • Right to erasure — Request deletion of your personal data (subject to legal retention requirements)
  • Right to data portability — Receive your personal data in a structured, commonly used, machine-readable format
  • Right to restrict processing — Request that we limit how we use your data in certain circumstances
  • Right to object — Object to processing based on legitimate interests

To exercise these rights, contact privacy@kareshift.com. We will respond within one month as required by Article 12 UK GDPR. If you are not satisfied with our response, you may lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.

7.1A Lawful Basis for Processing UK Personal Data (UK GDPR Art. 6 / Art. 9)

Under the UK GDPR, we must have a lawful basis for processing personal data. The following table summarises the basis we rely on for each processing activity:

Processing ActivityArt. 6 BasisArt. 9 Basis (if health/special category data)
Providing the Service (account, shifts, timesheets)Art. 6(1)(b) — performance of contract—
Storing health & clinical data entered by the OrganisationArt. 6(1)(b) + Art. 6(1)(c) — contract + legal obligationArt. 9(2)(h) — health/social care; Art. 9(2)(a) — consent via Organisation
GPS location data (worker clock-in/out)Art. 6(1)(b) — performance of contract (worker/Organisation); Art. 6(1)(f) — legitimate interests (care delivery verification)—
Transactional email notificationsArt. 6(1)(b) — contract—
Security logging, fraud preventionArt. 6(1)(f) — legitimate interests—
Legal retention after cancellationArt. 6(1)(c) — legal obligation—

7.2 Additional Rights for NZ Users

If your Organisation is based in New Zealand, you have rights under the New Zealand Privacy Act 2020, including:

  • Access (IPP 6) — Request a copy of personal information we hold about you
  • Correction (IPP 7) — Request correction of personal information that is inaccurate, out of date, incomplete, irrelevant, or misleading
  • Complaint — Lodge a complaint with the New Zealand Office of the Privacy Commissioner at www.privacy.org.nz

To exercise these rights, contact privacy@kareshift.com. We will respond within 20 working days as required by the NZ Privacy Act 2020.

7.3 Additional Rights for Canadian Users

If your Organisation is based in Canada, you have rights under the Personal Information Protection and Electronic Documents Act (PIPEDA), including:

  • Access — Request a copy of the personal information we hold about you (Principle 9)
  • Correction — Request correction of inaccurate personal information (Principle 9)
  • Withdrawal of consent — Withdraw consent to collection or use of your personal information, subject to legal or contractual restrictions (Principle 3)
  • Complaint — Lodge a complaint with the Office of the Privacy Commissioner of Canada at www.priv.gc.ca

For Ontario organisations handling personal health information under the Personal Health Information Protection Act (PHIPA): we act as a health information custodian's agent when storing and processing health records entered by your organisation. Your organisation (the custodian) retains primary responsibility for compliance with PHIPA obligations. Contact privacy@kareshift.com to discuss PHIPA-specific requirements.

To exercise privacy rights, contact privacy@kareshift.com. We will respond within 30 days as required by PIPEDA. For complex or voluminous requests, we may extend this by a further 30 days with written notice to you explaining the reason for the delay.

Where we process personal information on behalf of an Organisation, requests relating to participant, resident, or worker records should generally be directed to that Organisation in the first instance.

8. Cookies and Analytics

We use minimal cookies required for the Service to function:

  • Session cookies — to keep you logged in
  • localStorage values — to remember your cookie preferences (stored in browser localStorage, not transmitted to our servers — see our Cookie Policy for details)

For full details on our cookie usage, see our Cookie Policy.

We do not use third-party advertising cookies or tracking pixels. If we use analytics, we use privacy-friendly tools that do not track individual users across websites.

For Canadian users: our use of cookies that collect personal information (such as IP addresses or device identifiers) is governed by PIPEDA Principle 3 (consent) as well as CASL where applicable. See our Cookie Policy for details on what is collected and how consent is obtained.

9. Data Breach Notification

If we become aware of a suspected security incident or eligible data breach, we will investigate and assess the nature and scope of the incident and notify affected parties as required by law.

Australia: We will notify the OAIC and affected individuals as soon as practicable after becoming aware that there are reasonable grounds to believe an eligible data breach has occurred, in accordance with the Notifiable Data Breaches (NDB) scheme under the Privacy Act 1988.

Canada (federal — PIPEDA): We will notify the Office of the Privacy Commissioner of Canada and affected individuals as soon as feasible after becoming aware that a breach of security safeguards involving personal information has occurred that poses a real risk of significant harm, as required by PIPEDA (S.C. 2000, c. 5, s. 10.1). We will also maintain a record of all breaches of security safeguards as required by the Breach of Security Safeguards Regulations.

Canada (Ontario — PHIPA): For Ontario organisations handling personal health information, we will also notify the Information and Privacy Commissioner of Ontario (IPC) as required by section 12 of PHIPA where there are reasonable grounds to believe that personal health information has been stolen, lost, or accessed without authority. See www.ipc.on.ca.

New Zealand: We will notify the New Zealand Privacy Commissioner and affected individuals as soon as practicable after becoming aware that a notifiable privacy breach has occurred, as required by section 113 of the New Zealand Privacy Act 2020.

United Kingdom: We will notify the Information Commissioner's Office (ICO) within 72 hours of becoming aware of a personal data breach where feasible, as required by Article 33 UK GDPR. Where a breach is likely to result in high risk to the rights and freedoms of affected individuals, we will also notify those individuals without undue delay (Article 34 UK GDPR).

In all cases, we will provide details of the breach, the data affected, and steps we are taking to mitigate harm.

10. Children's Privacy

The Service is intended for use by care providers and their authorised staff, not by children directly. We do not knowingly collect personal information directly from children. If you become aware that a child has provided us with personal information directly (not via an authorised care provider), please contact us and we will take steps to address it.

Participant and resident records may include information about minors receiving care services. This data is entered and managed by the care provider (you) in your capacity as their service provider, and is subject to the same security and privacy protections as all other data.

11. International Data Transfers

All customer data is stored in AWS Sydney (ap-southeast-2), Australia. If you are based outside Australia, your data is transferred to and stored in Australia.

New Zealand organisations: We are an Australian entity storing data in Australia. We handle New Zealand personal information in accordance with both the New Zealand Privacy Act 2020 and the Australian Privacy Act 1988. We consider this arrangement to provide comparable safeguards for the purposes of Information Privacy Principle 12 of the NZ Privacy Act 2020.

Canadian organisations: We are an Australian entity storing data in Australia. We handle Canadian personal information in accordance with PIPEDA and, for Ontario health data, PHIPA. We use contractual safeguards with our infrastructure provider (AWS) to ensure Canadian personal information receives a comparable level of protection as required by PIPEDA Principle 7 (Accountability for Transfers for Processing). Details are available by contacting privacy@kareshift.com. We do not yet operate infrastructure within Canada — this will be reviewed as our Canadian customer base grows.

UK organisations: Australia does not hold a UK adequacy decision under UK GDPR Article 45. We transfer UK personal data to Australia on the basis of the UK International Data Transfer Agreement (UK IDTA) or equivalent Standard Contractual Clauses (SCCs) as approved by the ICO, which provide appropriate safeguards for the transfer. We will make a copy of the applicable transfer mechanism available on request — contact privacy@kareshift.com. We also offer a Data Processing Agreement (Art. 28 UK GDPR) on request.

Cross-border operational data: Certain service metadata may be processed outside Australia by our service providers:

  • Email delivery (primary) — processed by Resend, Inc. (United States). Email content includes recipient address, subject, and message body. No participant care data is included beyond what is necessary for the notification (e.g., shift time, worker name).
  • Email delivery (secondary) — AWS SES (processed in ap-southeast-2, Sydney, Australia)
  • Payment processing — Stripe (may process payment metadata outside Australia)

We take reasonable steps to ensure that overseas recipients of personal information comply with the APPs (as required by APP 8.1), including through contractual obligations and selecting providers with robust privacy and security practices.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes via email or in-app notification at least 14 days before they take effect. The "Last updated" date at the top of this page indicates when the policy was last revised.

12A. Business Transfers

In the event of a merger, acquisition, restructuring, or sale of all or substantially all assets, personal information may be transferred as part of that transaction subject to applicable privacy laws. Where required by law, or where reasonably practicable, we will notify you of any such transfer.

13. Complaints and Contact

If you believe we have breached the Privacy Act or the APPs, please contact our Privacy Officer first. We will acknowledge receipt of your complaint as soon as reasonably practicable and aim to provide a substantive response within 30 days.

If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au.

For Canadian privacy enquiries (PIPEDA), you may also contact the Office of the Privacy Commissioner of Canada at www.priv.gc.ca.

For UK privacy enquiries (UK GDPR), you may also contact the Information Commissioner's Office (ICO) at ico.org.uk.

Aventaryk Pty Ltd
ABN: 86 628 196 921
NSW, Australia

Privacy Officer (designated under PIPEDA Principle 1 and APP 1): privacy@kareshift.com
General enquiries: hello@kareshift.com

Product

Features Pricing Product Tour Blog

Company

Aventaryk hello@kareshift.com

Legal

Privacy Policy Terms of Service Cookie Policy

Region

🇦🇺 Australia 🇨🇦 Canada 🇳🇿 New Zealand 🇬🇧 United Kingdom

© 2026 Aventaryk Pty Ltd. All rights reserved. Built for care providers worldwide 🌏

Compliance tools assist organisations but do not replace independent compliance verification. Award calculations and funding information are provided as operational assistance only.

We use cookies to improve your experience. Cookie Policy