Privacy Policy
Version: 1.0 (February 2026)
Company: Learnity Pty Ltd (ABN 76 689 268 031) trading as LearnAble Technologies
Contact: info@hellolearnable.com.au | LearnAble Technologies, Level 1, 1-5 Link Road, 136 Epsom Rd, Zetland NSW 2017
1. Purpose
Learnity Pty Ltd, trading as LearnAble Technologies (“LearnAble”, “we”, “our”, or “us”), is committed to protecting the privacy and confidentiality of everyone who engages with our services. We understand that many LearnAble users are National Disability Insurance Scheme (“NDIS”) participants, including people who may be considered vulnerable or who have a guardian or legal representative acting on their behalf.
We are committed to complying with:
The Privacy Act 1988 (Cth) (“Privacy Act”) and the Australian Privacy Principles (“APPs”) (together, “Privacy Laws”);
The NDIS Act 2013 (Cth), NDIS Code of Conduct, and NDIS Practice Standards (together, “NDIS Framework”); and
Relevant state and territory privacy, health records, and guardianship laws,
(together, “Applicable Law”).
This Privacy Policy explains how we collect, use, store and share personal information, including sensitive information, in accordance with the Privacy Laws. It should be read together with LearnAble’s Terms & Conditions, (hellolearnable.com.au/terms); Safety & Safeguards Policy (hellolearnable.com.au/safety); and Ethical AI & Responsible Data Use Policy (hellolearnable.com.au/ethics), which together outline how we deliver our services safely, ethically, and in compliance with Applicable Law.
2. Scope
This policy applies to personal information that we collect in connection with our products and services, including via:
Our LearnAble mobile app and any related platforms;
Our website (including forms, portals and online support tools);
Our social media platforms;
Email, phone and other communications with us; and
Documents or information provided to us by you or by third parties, in any form.
It applies to:
NDIS participants using our LearnAble app or website;
Guardians (including parents), nominees, and other authorised representatives;
Our employees, contractors, and service providers;
Visitors to our website or the LearnAble app; and
Support coordinators, allied health practitioners, and other providers who interact with Us.
3. Key Definitions
For this policy:
Personal Information – Any information or opinion about an identified individual or an individual who is reasonably identifiable, whether the information or opinion is true or not, and whether the information or opinion is recorded in a material form or not, including your name, address, and contact details. Personal Information includes Sensitive Information.
Sensitive Information – Any information about your health, disability, racial or ethnic origin, cultural background, criminal history, and certain other categories as defined in the Privacy Act, including medical history, treatment, or care, and NDIS plan information.
Authorised Representative – has the meaning given in LearnAble's Terms & Conditions. In general terms, this means a person who has legal authority to act on your behalf, such as an appointed guardian, parent, primary carer, or plan nominee. A plan manager is not an Authorised Representative unless they also hold legal decision-making authority for you.
Participant – An NDIS participant engaging with the Services.
Services - The LearnAble mobile app, web platform, AI tools, website and related features provided by Us.
4. Information We Collect
We only collect Personal Information that is either provided voluntarily by a Participant, or that we reasonably need to provide our services or to meet our legal and compliance obligations. Because we provide services in a health and disability context, some of this information is Sensitive Information.
We may collect the following types of Personal Information:
Identity and contact details: name, date of birth, address, phone number and email address;
Account details: username and password, profile information, preference and settings;
NDIS information: NDIS number, plan details including start and end dates, funding management details whether self managed or plan managed, other provider details, and NDIS goals;
Interaction information: usage data from our LearnAble platform (including audio, transcripts, and chat logs);
Payment information: bank account, credit card, debit card and other payment-related information; and
Technical and usage data: device type, operating system and browser type, IP address, general location information, cookie data and preferences.
We may also collect similar Personal Information about your Authorised Representative, support coordinators, therapists, and other providers, such as their name, role, organisation and contact details.
We may also collect and hold the following types of Sensitive Information:
Health and disability information: such as therapy notes or medical reports, assessments and recommendations provided by allied health or medical professionals, disability-related information, support needs, diagnosis and medical history where relevant to your supports, information about behaviours of concern or risk factors where necessary to keep you and others safe;
NDIS-related information: health or disability status, NDIS plan details and goals, therapy or service outcomes, progress notes and support documentation;
Cultural and background information: language preferences, information regarding your cultural background or Aboriginal or Torres Strait Islander status (if relevant); and
Criminal history information (if relevant).
Where possible, we encourage you to avoid sharing Personal Information, including Sensitive Information unless it is essential to your use of or interaction with the Services.
5. How We Collect Information
We may collect Personal Information in the following ways:
Directly from Participants, guardians or nominees when:
an account is created with us, including through our LearnAble app;
details, settings, goals or preferences are entered or updated;
documents, audio, text or other content are uploaded or inputted, for example by a Participant inputting information into our LearnAble app; or
the Participant communicates with us by phone, email, via our LearnAble App or through our website;
From the Participant’s Authorised Representative;
From service providers and professionals who support a Participant, such as authorised NDIS providers, healthcare professionals, therapists or support coordinators; or
Automatically when the Participant uses LearnAble’s app, website forms, or other communications through technical and analytics tools that collect device and usage information and cookies and similar technologies on our website.
We collect Sensitive Information only where it is voluntarily provided to us by a Participant, or where it is reasonably necessary for our functions and activities. We deploy additional safeguards for Participants under guardianship or supported decision-making arrangements.
6. How We Use Your Information
We use and disclose Personal Information only for purposes that are reasonably necessary for our functions and activities, or as otherwise permitted or required by Applicable Law.
We use your Personal Information to:
Deliver our Services, including creating and managing your account, enabling the use of our LearnAble App, recording and sharing NDIS plan details, supports and goals, and storing and making available therapy notes, reports, session information and other health and disability information;
Personalise your experience and tailor assistance, including helping track progress towards your goals;
Communicate with you, your Authorised Representative, and relevant providers, including facilitating communication between parties, sending alerts and updates, and responding to your queries, feedback or complaints;
Comply with NDIS and other legal obligations as required by Applicable Law;
Improve LearnAble through research and service evaluation, training, and conducting audits and quality assurances (using de-identified data wherever possible); and
Protecting you and your rights, our rights, and the safety of others, including managing and investigating incidents, abuse or misuse of our Services, and responding to and managing complaints and disputes.
We do our best to limit the disclosure of your Personal Information to only what is necessary for these and related purposes. We will not share your Personal Information with third parties for marketing purposes without your explicit consent.
7. Disclosure of Personal Information
We may disclose your Personal Information to third parties only when reasonably necessary for the purposes set out in this Privacy Policy, or as otherwise permitted or required by Applicable Law. We may disclose your Personal Information to:
Government agencies and regulators, including the NDIS Quality and Safeguards Commission and the National Disability Insurance Agency (“NDIA”) (where required by Applicable Law);
Health and allied-health professionals, support workers and service providers involved in your care and support. Personal Information will only be shared to aid in your care and support, mitigate risks, and to meet your needs;
You and your Authorised Representative;
Authorised service providers (for example, IT or cloud-storage providers, our accountants and our lawyers) who comply with Privacy Laws and only for purposes related to our provision of the Services; and
Organisations involved in account transition or closure, where you request (or consent to) the transfer of your Personal Information, for example, providing a secure export of your records to you, your Authorised Representative, or a new provider before your LearnAble account is closed.
In limited circumstances, we may be required to disclose Personal information to protect you or others from serious harm, to manage serious threats to health or safety, or to comply with legal obligations. We will only transfer data containing your Personal Information outside of Australia securely, to the extent any of the above recipients are located outside of Australia and for the purposes set out above. In the case where a third party has their own privacy policy, we encourage you to read it to understand how your information is handled under their privacy policy. Once you leave our LearnAble app or website environment, or are redirected to a third-party site, this Privacy Policy no longer applies.
8. Mandatory Reporting and Disclosures
Because LearnAble operates within the NDIS Framework, there are limited circumstances where we must disclose Personal Information to protect your safety, rights and wellbeing, and / or to comply with Applicable Law.
These circumstances include (but are not limited to):
Child protection matters, where we are required to report concerns about the safety or wellbeing of a child or young person to the relevant state or territory authority;
Incidents of violence, exploitation, neglect or abuse, and sexual misconduct, including suspected incidents;
Criminal conduct or threats to the life, health or safety of a person, where disclosure is necessary to prevent or lessen a serious risk;
Reportable Incidents under the NDIS (Incident Management and Reportable Incidents) Rules 2018, which require us to notify the NDIS Commission about serious incidents affecting Participants; and
Mental health crises, including content or behaviour indicating suicidal ideation, risk of self-harm, or risk of harm to another person. In such cases, LearnAble may, in its absolute discretion, contact the most appropriate person(s), which may include Your Authorised Representative, Your nominated emergency contact, Your support network, or relevant authorities (such as emergency services or the NDIS Quality and Safeguards Commission). This safety monitoring is a mandatory condition of using the Services and operates independently of any other consent provided or withdrawn by the Participant.
These disclosures will be in accordance with Applicable Law, and we will only disclose Personal Information to the extent necessary for us to protect your safety and to comply with Applicable Law.
Where appropriate, safe and practicable, and where doing so is legally permissible and does not conflict with any legal or ethical obligations, we will:
notify you that a report has been made; and
keep you informed of progress and outcomes.
We are required to comply with mandatory reporting requirements irrespective of a Participant’s consent. These disclosures occur because they are necessary to comply with Applicable Law, and / or to protect the safety and rights of Participants.
9. AI and Automated Tools
LearnAble may use AI and automated tools to support or enhance our Services, including to handle and process decisions. These tools are governed by our Ethical AI & Responsible Data Use Policy (hellolearnable.com.au/ethics) and are designed to support, not replace, human care and decision-making.
Where AI tools rely on your data, we will use the minimum amount of Personal Information necessary and, wherever practicable, we will use de-identified or aggregated data.
You consent to LearnAble using anonymised or aggregated data generated through your use of our Services for the purposes of training, evaluating and improving our AI models.
Such use will not include Personal Information including Sensitive Information without your explicit consent, and we will not sell, transfer or licence to third parties any Personal Information for the purposes of training AI models owned by third parties.
Section 9A - How We Share Your Data with Other Services
To make LearnAble work, we share some information with two trusted technology companies. Here is what we share, who we share it with, and why.
OpenAI - Generating AI Responses
We use OpenAI to power LearnAble's AI conversations.
To help the AI understand and support you, we send OpenAI the following information:
Your chat messages
Your profile and contact details
Your diagnosis and disability information
Your preferences and communication settings
Summaries and/or excerpts of any documents your carer has shared with us
Before sending, we remove information that directly identifies you, such as your name and NDIS number. However, your diagnosis information is included so the AI can respond in a way that suits your needs.
OpenAI is based in the United States. They do not use your data to train their AI. We have a formal agreement with OpenAI to keep your information safe. You can read their privacy policy at openai.com/policies/privacy-policy.
Google - Reading Responses Aloud
We use Google's text-to-speech service to read AI responses aloud if you use voice output.
Google only receives the text of the AI's responses - not your messages, your voice, or any personal information about you.
Google is based in the United States. You can read their privacy policy at cloud.google.com/terms/cloud-privacy-notice.
Data Processed Overseas
Both OpenAI and Google process data in the United States. We have assessed both companies as meeting the privacy standards required under Australian law and have agreements in place to protect your information.
Your Consent
We will ask for your permission before any of this data sharing begins. You can withdraw your consent at any time by contacting us at support@hellolearnable.com.au. If you withdraw consent, some LearnAble features may not be available to you.
10. Guardianship and Decision-Making Capacity
Where a Participant has an Authorised Representative:
We will confirm the person’s authority prior to granting them access to the Participant’s Personal Information;
Consent will be sought and recorded from the authorised person before any information is collected, used, or shared with the Authorised Representative; and
Authorised Representatives may, within the scope of their authority:
Request access to, or correction of, a Participant’s Personal Information on their behalf; or
Make complaints or enquiries about privacy matters.
11. Cookies and Analytics
We use cookies and other tracking tools to improve our app, website function and your user experience. You can manage these features including disabling these functions in your browser or account settings, though in such cases, some features may not work properly. By using our website or our app, you consent to our and our service providers’ use of these technologies for these purposes.
12. Data Security and Retention
We are committed to protecting Personal Information from misuse, interference, loss and unauthorised access, including through:
Technical safeguards, such as encryption of data during transfer and storage; Secure authentication and access controls; and
Administrative safeguards within our organisation, such as confidentiality obligations, privacy training, and policies and procedures for handling health and disability information.
While we take reasonable steps to reduce risk, we cannot guarantee absolute protection against unauthorised access, cyberattacks, or data loss. In such an event, please refer to our data breach response contained in Section 13 below.
Participant records are kept for at least seven (7) years after the last date of Service, or longer if required by Applicable Law. When Personal Information in our possession is no longer needed for the purpose for which it was collected, or for any legal, compliance or business purposes, we will take reasonable steps to ensure that such Personal Information is either securely destroyed or permanently de-identified. If this is not possible (for example, because your Personal Information has been stored in backup archives), we will securely store and isolate it from further processing until it can be deleted or anonymised.
13. Data Breach Response
If an actual or suspected data breach occurs,
We will promptly investigate the incident and take all reasonable steps to contain the actual or suspected breach;
If serious harm is likely, or where required by the Notifiable Data Breaches Scheme, we will notify affected individuals (and their Authorised Representatives, if applicable) and the Office of the Australian Information Commissioner (“OAIC”) in accordance with Privacy Laws and the NDIS Framework.
We will take all reasonable steps to reduce the risk of harm and to prevent future breaches.
14. Access and Correction
You (or your Authorised Representative) have the right to request:
Access to your Personal Information;
Deletion of your Personal Information; or
Corrections or amendments to any inaccurate, incomplete, misleading or outdated details. It is your responsibility to inform us of any updates to your Personal Information which are required for you to use our Services.
Requests must be made in writing to our Privacy Officer (see Section 16). We may ask you to provide verification information to confirm your identity, or your authority if acting on a Participant’s behalf. We will do our best to respond to requests for access or correction within thirty (30) days. Requests for deletion or de-identification of Personal Information may require up to sixty (60) days, as these requests involve additional verification steps to ensure data is removed or de-identified across all systems and any downstream recipients. If we are unable to meet the applicable timeline, we will update you with the soonest possible time within which we can action your request.
Please note that certain types of personal information access and correction requests may be exempt under Applicable Law, and there may be circumstances in which we are unable to provide such access, including where the information is legally privileged, would compromise the privacy or other legitimate rights of other persons, or where the information requested comprises proprietary business information.
15. Overseas Disclosure
All LearnAble data, including Personal Information, is stored within Australia unless otherwise stated. Some AI-related processing may be performed by trusted service providers located outside Australia. In such cases, we take reasonable steps to ensure that any overseas recipient handles Personal Information in accordance with privacy standards and protections at least equivalent to those contained in the Privacy Laws.
If we propose to use overseas storage or service providers for any other purposes (for example, through a secure cloud provider), we will update this Privacy Policy to identify the countries in which those providers are located, and will take reasonable steps to ensure that any overseas recipient upholds privacy standards and protections at least to equivalent those contained in the Privacy Laws.
16. Complaints
If you believe your privacy has been breached, please contact our Privacy Officer using the following details:
Attention: Privacy Officer, LearnAble Technologies, 1-5 Link Road, Zetland, NSW, 2017, Australia
Privacy complaints may require additional time due to the complexity of data investigations. We will acknowledge your complaint within seven (7) days. We aim to investigate and respond within thirty (30) days. If we are unable to meet this timeline, we will update you with the soonest possible time within which we can provide the information or make the correction. If unsatisfied with our response, or if the issue is not resolved, you may contact:
OAIC – www.oaic.gov.au; or
NDIS Quality and Safeguards Commission – www.ndiscommission.gov.au.
17. Review and Updates
This policy is reviewed from time to time to reflect changes in Applicable Law or to our business or practices.
Updates to this Privacy Policy may occur alongside updates to LearnAble’s Terms & Conditions, (hellolearnable.com.au/terms); Safety & Safeguards Policy (hellolearnable.com.au/safety); and Ethical AI & Responsible Data Use Policy (hellolearnable.com.au/ethics).
The latest versions of all policies are always available at www.hellolearnable.com.au. We encourage you to review this policy regularly to stay informed about how we manage your Personal Information.
18. Related Policies
This Privacy Policy operates alongside:
LearnAble Terms & Conditions (hellolearnable.com.au/terms) – governing the use of our products and services;
LearnAble Safety & Safeguards Policy (hellolearnable.com.au/safety) – outlining processes and categories by which we keep users safe; and
LearnAble Ethical AI & Responsible Data Use Policy (hellolearnable.com.au/ethics) – outlining how we design, train, and use AI responsibly.
Together, these documents reflect LearnAble’s commitment to ethical, transparent, and Participant-centred technology.
© 2026 Learnity Pty Ltd (trading as LearnAble Technologies). All rights reserved.