This is an info Alert.
Conpago
  • Product
  • Solutions
  • Help & Trust
  • Pricing
Book a Demo
[ Legal ]

Legal Documentation

[ Last updated · 1 July 2026 ]

Conpago Privacy Policy

The short version

  • Conpago builds the portal your provider uses to keep clients, residents, families and staff connected. Most of the information in it is held by us on your provider's behalf.
  • We mostly hold names, contact details and the messages, photos and notes shared through the portal. We are not a medical records system, and there are no fields for charts, diagnoses, allergies or medications.
  • We do not sell personal information, and we do not use the information we hold for providers for our own marketing.
  • Our AI summary feature runs on Australian-hosted infrastructure, is designed around human control, and the content is not used to train AI models.
  • The fastest way to see or correct information about you is usually through your provider. You can also contact us at any time using the details at the end of this policy.

1. Who we are and what this policy covers

Conpago Pty Ltd (ACN 616 088 218) and its related entities, including Conpago Trading Co Pty Ltd (ACN 658 846 916) (we, us, our), build a portal that retirement living, aged care, disability and community organisations (providers) use to engage with the people they serve. We do not deliver care, and we are not a clinical or medical records system.

This policy explains how we handle personal information under the Privacy Act 1988 (Cth) (Privacy Act) and the Australian Privacy Principles (APPs). Where state or territory health records laws apply to information in our platform, we handle that information consistently with them as well.

2. The two kinds of information we handle

It helps to separate two things this policy covers.

Information we hold for providers (platform information). When a provider uses Conpago, their staff, clients and families put information into the portal. The provider decides what is collected and why, under its own privacy policy and consents. We hold and process that information on the provider's behalf so the portal works, and we do not use it for our own purposes. Sections 3 and 4 cover this.

Information we collect for ourselves (our own information). Like any business, we also collect some information directly, mainly about the people we deal with at provider organisations, visitors to our website, and anyone who contacts us. Section 5 covers this.

We have obligations under the Privacy Act for both kinds, and the rest of this policy, including security, breaches, access and complaints, applies to both.

3. Platform information

What it includes.

  • Profile and contact details for clients, residents, families and staff, such as names, ages or dates of birth, addresses, phone numbers, email addresses and preferred language. For most people, this is the bulk of what we hold. Profile photos are optional: there is no default photo, and one is only added if the person chooses to upload it.
  • Content shared through the portal, such as messages, news and newsletters, event details and RSVPs, surveys and feedback, and any photos or other media shared through these features.
  • Plain text notes written by provider staff about the people they support. The platform is not designed to hold structured clinical records, and by design there are no fields for charts, diagnoses, allergies or medications. Because notes are free text, a staff member may still include health or other sensitive details in one, so we treat all notes with the same care as if they did.
  • Account and usage records, such as logins and activity within the portal.

Where it comes from. Providers and their staff enter most of it. Clients and family members add some themselves through the portal. We rely on the provider having the authority and consents needed for information to be recorded and shared in the portal, including anything a family member records about someone else.

What we do with it. We use platform information only to provide, support, secure and improve the portal for the provider. In practice that means storing it, delivering messages and updates to the right people, fixing problems and keeping the service reliable. Our staff access it only when needed for support or operations, under access controls.

What we do not do with it. We do not sell it. We do not use it for our own advertising or marketing. We do not use it to train AI models.

Sensitive information. We do not ask anyone for sensitive information such as health details, ethnicity or religion, and the platform has no fields designed to collect it. Where it appears in free text notes or messages, we hold it for the provider and handle it only as described in this section, or as the law otherwise permits.

4. AI features

Providers can select to utilise optional features that uses artificial intelligence to help their staff draft summaries of the notes and updates they have already recorded, for example a weekly update for a resident's family. The feature is a tool for provider staff. It is designed around human control, with provider staff owning the editing and publication of each summary, and it does not make decisions about anyone.

AI processing takes place on Australian-hosted infrastructure, and the content is not used to train AI models. We keep a record of each prompt and its output in line with our storage policy, so we can support providers with any questions about a summary.

We do not use personal information to make automated decisions that have legal or similarly significant effects on people. If that ever changes, we will update this policy first and meet our obligations under the Privacy Act. Our Responsible Use of AI page sets out our approach in full.

5. Our own information

We collect a modest amount of information for our own business:

  • Business contact details for the people we work with at providers and partners, such as names, roles, work email addresses and phone numbers, used for account management, billing and support.
  • Enquiries, feedback and support requests, including the correspondence itself.
  • Website information such as IP address, device type and pages visited, collected partly through cookies (see section 9).

People who use the portal as clients, residents or family members have no billing relationship with us. Providers pay for the service.

We use this information to run our business: managing accounts, billing providers, answering enquiries, improving our products and meeting our legal obligations. We may send marketing about our products to the organisations we work with, and every marketing message includes a way to unsubscribe.

We do not market to clients, residents or families through the portal, and in more than seven years of operating we never have. We may occasionally contact portal users directly where there is a genuine business need, such as important service information, and if any such message were ever promotional, it would include a simple way to opt out.

6. Security

We protect personal information with measures that include encryption in transit and at rest, multi-factor authentication, role-based access controls, logging and monitoring, staff training and regular reviews of our security practices. Our platform runs on AWS and Google Cloud infrastructure in Australia, and we are certified against ISO/IEC 27001:2022, a certification we have held since 2024. Our Data Governance Framework describes these practices in more detail.

No system is perfectly secure, and we cannot promise a breach will never happen. We work to make one unlikely, and to respond quickly and openly if it does.

7. Data breaches

If we have reasonable grounds to believe an eligible data breach has occurred, meaning a breach likely to result in serious harm, we will notify the affected people and the Office of the Australian Information Commissioner (OAIC) under the Notifiable Data Breaches scheme. Where a breach involves platform information, we will work with the affected provider so the right people are told quickly and clearly.

8. Who we share information with

We share personal information only where needed to run the service and our business, with:

  • The provider connected to you, and the people, companies and systems that provider authorises. This may include third parties associated with the provider connected to you, which they require us to integrate with to operate their business.
  • Service providers who help us operate, such as cloud hosting, email and SMS delivery, support and analytics tools. They may only use the information to deliver their services to us.
  • Our related entities where reasonably required to run the business, and our professional advisers such as lawyers, accountants and auditors.
  • A buyer or potential buyer if we sell or restructure part of the business, under confidentiality protections.
  • Government agencies, regulators, courts and others where the law requires or authorises it.

We do not sell personal information.

9. Cookies and website analytics

The website itself doesn't need cookies to function. We use analytics which set first-party cookies to help us understand how the site is used. We don't run advertising or retargeting trackers.

10. Overseas disclosure

Our platform runs on AWS and Google Cloud infrastructure in Australia, and production data is stored here. Some of the tools we use to run our business, including our email and SMS delivery, customer support and analytics systems, store limited information in the United States. Before personal information goes overseas, we take reasonable steps to ensure the recipient handles it consistently with the APPs, or we rely on another basis permitted under the Privacy Act.

11. How long we keep information

Platform information belongs with the provider's service. We keep it while the provider uses Conpago and handle it in line with our agreement with them. When a provider leaves, we work with them on the return and deletion of their data. The practical arrangements depend on the nature and scale of the engagement and the information involved, and we engage actively with each departing provider to meet reasonable expectations. Once those arrangements are settled, the data is deleted from our production systems, and backup copies expire on our normal backup cycle.

We keep our own business records only as long as we need them or the law requires, and then take reasonable steps to destroy or de-identify them.

12. Access, correction and anonymity

You can ask to see the personal information we hold about you, and ask us to correct anything that is wrong, out of date or incomplete.

For platform information, your provider is usually the fastest path, because they record and manage it day to day. You can also come to us directly using the details in section 15, and we will help you or pass your request to the right place. We respond within a reasonable time. If the law allows us to refuse a request and we do, we will tell you why and what you can do about it.

Where it is lawful and practical, you can deal with us anonymously or under a pseudonym. For most of the portal that is not practical, because accounts and the services they support depend on knowing who you are.

13. Children and young people

Some providers, particularly in disability and community services, may support people under 18. Where that happens, we hold the young person's information for the provider in the same way as anyone else's, with the same protections, and parents and guardians can view and manage it through the provider.

14. Government identifiers

We do not use government related identifiers, such as Medicare or My Aged Care numbers, as our own identifier for anyone, and the platform has no fields that ask for them. If one is recorded in a free text note, we take a range of precautions to try and exclude them. However we cannot guarantee it and in that case we will continue to hold it for the provider and only use or disclose it as the Privacy Act permits.

15. Questions, requests and complaints

Contact our Privacy Officer:

  • Email: [email protected]
  • Post: Privacy Officer, Conpago Pty Ltd, 2/35 Amelia St, Fortitude Valley QLD 4006

We will acknowledge your complaint and do our best to respond within 30 days. If we need more time, we will tell you why.

If you are not satisfied with our response, you can contact the Office of the Australian Information Commissioner:

  • Website: www.oaic.gov.au
  • Phone: 1300 363 992
  • Email: [email protected]
  • Post: GPO Box 5288, Sydney NSW 2001

16. Changes to this policy

We review this policy regularly and update it when our practices or the law change. The current version is always available on our website, and where a change is significant we will take reasonable steps to let you know.

[ Last updated · 1 July 2026 ]

Conpago Data Governance Framework

1. Purpose and scope

This framework is a public statement of how Conpago Pty Ltd (ACN 616 088 218) and its related entities, including Conpago Trading Co Pty Ltd (ACN 658 846 916) (Conpago, we, us, our), govern, secure and manage data across our platform.

It covers our web platform and mobile apps, our integrations with provider systems, our AI features, and our support and operations. It applies to everyone who works for us.

It should be read with our Privacy Policy, which explains how we handle personal information, our Responsible Use of AI page, and the agreement each provider holds with us, which governs the commercial relationship.

2. Whose data it is

The organisations that use Conpago (providers) own and control the information their staff, clients and families enter into the platform. We hold and process that information to deliver the service, under our agreement with the provider and on their instructions. When a provider leaves, their data goes with them (see section 9).

The provider is also the originator of platform information, whether their team entered it directly or it arrived through an integration with their other systems. Because of that, changes and corrections are best raised with the provider, so they are made at the source and flow through correctly rather than being overwritten by the next update. Our role is to hold and process the information faithfully for them.

The other side of the same coin is the platform itself: the software, its design, features, workflows and improvements are Conpago's intellectual property. That changes nothing about the data. The information in the platform remains the provider's, and the agreement with each provider sets out the detail.

Australian privacy law does not use the European terms controller and processor, but the practical split is the same, and our Privacy Policy is structured around it: information we hold for providers, and the smaller amount of information we collect for our own business.

3. How we govern data

Accountability sits with named people, not a shared inbox:

  • Executive ownership of security and privacy sits with a member of our executive team, supported by a committee of senior leaders that keeps executive and managerial attention on how our controls operate.
  • A Privacy Officer handles privacy questions, requests and complaints.
  • Every information asset in our register has a named owner responsible for its classification, access and review.

We run an information security management system (ISMS) certified against ISO/IEC 27001:2022, a certification we have held since 2024. Certificates and further detail are available to providers on request. The ISMS includes a risk register, a policy suite covering areas such as access control, acceptable use, incident response and supplier management, and a cycle of internal reviews and external surveillance audits.

4. Data classification

We classify data so it is handled according to its sensitivity. Platform information that identifies clients, residents or families, including free text notes, sits in our highest tier and gets the strictest handling: tightest access, strongest protections, most careful disposal. Configuration, business and public information sit in lower tiers with handling rules to match.

5. Where data lives

Our platform runs on AWS and Google Cloud infrastructure in Australia. Production data is stored in Sydney, and our backup database is held separately in Victoria, so backups are geographically separated while remaining in Australia.

Some of the tools we use to run our business, including our email and SMS delivery, customer support and analytics systems, store limited information in the United States. Suppliers are assessed and contracted as described in section 10, overseas disclosure is covered in our Privacy Policy, and a list of our subprocessors is available to providers on request.

6. Security controls

Core controls include:

  • Encryption of data in transit and at rest.
  • Multi-factor authentication and role-based access, granted on a least-privilege basis and reviewed regularly.
  • A software development life cycle that moves changes through separate environments. Production and non-production are fully separated, and production data is never used in development or testing.
  • Logging and monitoring across the platform, with alerts for unusual activity.
  • Secure development practices, including code review and dependency management.

7. Availability, backups and continuity

We maintain a dedicated backup and restore policy for critical data as part of our certified ISMS, reviewed and acted on in line with our ISO 27001 standards. Backups run automatically and restores are tested. As set out in section 5, production data is stored in Sydney and the backup database is held separately in Victoria.

We maintain business continuity and disaster recovery plans. Providers are told about planned maintenance in advance and about significant unplanned outages as they happen.

8. Collecting less by design

The platform is built to hold what an engagement portal needs and not more. There are no fields for charts, diagnoses, allergies or medications, and no fields that ask for government identifiers. Notes are free text, so we treat every note as if it could contain sensitive information. We do not use platform information for advertising, we do not sell it, and we do not use it to train AI models.

9. Retention, return and deletion

We keep platform information while a provider uses Conpago and handle it under our agreement with them. When a provider offboards, we work with them on the return and deletion of their data. The practical arrangements depend on the nature and scale of the engagement and the information involved, and we engage actively with each departing provider to meet reasonable expectations. Once those arrangements are settled, the data is deleted from our production systems, and backup copies expire on our normal backup cycle.

Our own business records are kept only as long as needed or legally required, then destroyed or de-identified.

10. Suppliers and third parties

We keep a register of our suppliers and the systems they touch. Before we engage a supplier that will handle personal information, we assess their security and privacy posture, and our contracts require confidentiality and appropriate handling. Supplier arrangements and the asset register are reviewed regularly as part of our ISMS cycle.

11. AI governance

AI features in Conpago are optional tools for provider staff. Today that means AI-assisted summaries, which are live. Processing takes place on Australian-hosted infrastructure, content is not used to train AI models, and the workflow places editing and publication in the hands of provider staff. AI suppliers go through the same assessment as any other supplier, AI features sit inside our certified ISMS, and we document each feature for providers before they enable it. We are also working towards ISO/IEC 42001, the international standard for AI management systems, with our certification audit scheduled for late 2026. Our full approach, including what we will not do with AI, is set out in our Responsible Use of AI page.

12. Incidents and breaches

We maintain an incident response process covering detection, containment, assessment, notification and review. If an incident affects a provider's data, we notify that provider without undue delay. What that looks like in practice depends on the nature of the incident and the progress of our investigation, which may draw on legal and cybersecurity advisers, and we engage with affected providers openly and in good faith throughout.

Where an eligible data breach occurs under the Notifiable Data Breaches scheme, we notify affected individuals and the Office of the Australian Information Commissioner as the Privacy Act requires, working with the provider so the right people are told quickly and clearly. Every significant incident ends with a review and corrective actions.

13. Assurance and testing

  • Penetration testing undertaken in line with our ISO 27001 policies and standards, which are externally audited, with findings tracked to closure.
  • Ongoing vulnerability management and patching.
  • Internal audits and external ISO 27001 surveillance audits.
  • Support for provider due diligence, including security questionnaires and reviews.

14. Our people

Everyone at Conpago works under confidentiality obligations and completes regular security and privacy training. Access to platform information is limited to the people who need it to support or operate the service.

15. What providers are responsible for

Conpago is one part of the picture. Providers using the platform are responsible for:

  • Managing their own users, roles and permissions, and removing access when staff leave.
  • Obtaining the consents and authorities needed for the information their staff, clients and families put into the portal.
  • What goes into free text notes, and training their staff accordingly.
  • Their own records, retention and regulatory obligations as care organisations.
  • Telling us promptly if they suspect an account compromise or data incident.
  • Identifying and escalating inappropriate and antisocial behaviour amongst their client base that they may require additional technical support from Conpago to resolve

16. Requests, review and contact

Access, correction, export and deletion requests are covered in our Privacy Policy, and for platform information the provider is usually the fastest path. This framework is reviewed as part of our ISMS cycle and whenever our practices or the law change materially.

Questions go to our Privacy Officer:

  • Email: [email protected]
  • Post: Privacy Officer, Conpago Pty Ltd, 2/35 Amelia St, Fortitude Valley QLD 4006
[ Last updated · 1 July 2026 ]

Responsible Use of AI

About this page

Conpago builds a portal that retirement living, aged care, disability and community organisations (providers) use to engage with the people they serve. Some parts of our product use artificial intelligence. This page explains what those features do, the principles behind them, and the commitments we make. It should be read with our Privacy Policy, which covers personal information, and our Data Governance Framework, which covers how we secure and manage data.

What AI does in Conpago today

One AI feature is live: AI-assisted summaries. It helps provider staff turn the plain text notes and updates they have already recorded into a clear, readable draft, for example a weekly update for a resident's family.

The feature drafts. It does not decide. It does not assess, score or profile anyone, and it takes no action on its own.

When we add AI features, we document them for providers before they can be enabled.

People stay in control

Our AI summaries are designed around human control. The workflow places ownership of editing and publication with provider staff: a person shapes the draft, decides what it says, and decides whether it is shared. What families receive is their provider's communication.

Providers choose whether to turn AI features on for their organisation, and nothing is on by default. Whether a person or family receives summaries at all is managed between them and their provider.

How data is handled

  • AI processing takes place on Australian-hosted infrastructure.
  • Content processed by AI features is not used to train AI models.
  • We keep a record of each prompt and its output in line with our storage policy, so we can support providers with any questions about a summary.
  • Notes can contain sensitive information, and everything our Privacy Policy and Data Governance Framework say about protecting platform information applies to AI features too.

AI limitations

AI can make mistakes. That is one of the reasons the workflow keeps provider staff in control of editing and publication. Responsibility for a communication stays with the trained staff who know the person it is about, not with the software that helped draft it.

What we will not do

  • We will not use AI to make automated decisions that have legal or similarly significant effects on a person. Decisions about care sit with providers and their people.
  • We will not use AI to score, rank or profile the people our providers support.
  • We will not use platform information to train AI models.
  • We will not sell platform information or use it for advertising.

If our approach changes in a way that matters, we will update this page and our Privacy Policy first.

Governance

AI features sit inside the same ISO/IEC 27001:2022 certified management system as the rest of our platform, with executive ownership of security and privacy held by a member of our executive team and supported by a committee of senior leaders. AI suppliers go through the same assessment as any other supplier.

Going further than we have to

Independent certification is uncommon in our corner of the software industry. Many platforms serving aged care, disability and community organisations hold no information security certification at all. We have held ISO/IEC 27001 certification since 2024, and we are now applying the same discipline to AI.

We are working towards ISO/IEC 42001, the international standard for AI management systems. Our certification audit is scheduled for late 2026, and we are seeking formal certification before the year is out. In the meantime, we already operate in line with recognised guidance, including Australia's Voluntary AI Safety Standard.

Nobody requires us to do this. We think the people our providers support deserve it anyway, and independent scrutiny is what keeps a phrase like "responsible AI" honest.

Questions

Providers can raise questions through their Conpago contact or at [email protected]. If you use the portal as a client, resident or family member, your provider is the best first stop for questions about the updates you receive, and you can also contact us:

  • Email: [email protected]
  • Post: Privacy Officer, Conpago Pty Ltd, 2/35 Amelia St, Fortitude Valley QLD 4006
Conpago

The operating system for community and care.

Stay in the loop
One useful email a month on running better communities. No noise.

CaptureCommunicationReportingAutomations

DashboardAppWorkflow StudioAlloyAI

Retirement LivingCare

AboutTrust CentrePricingBook a DemoLegal

© 2026 Conpago Pty Ltd · All rights reserved
ISO/IEC 42001 (AI) Planned
ISO 27001 certified
Australian owned and operated