Torvi Privacy Policy
From 3 October 2026, Torvi is provided by Torvi Technology Pty Ltd (ABN 17 702 923 528), which took over from Skilled Health Professionals Pty Ltd.
1. Who we are
Torvi is a workforce management platform for aged care, disability support, and workforce agencies, operated by Torvi Technology Pty Ltd, ABN 17 702 923 528 ("Torvi", "we", "us"). Torvi is a software provider — we are not an NDIS provider, an aged care provider, or a healthcare provider ourselves. Our customers ("Organisations") are the aged care and disability support businesses who use Torvi to manage their own staff, rostering, timesheets, and (where relevant) participant/client records.
This policy explains how we collect, use, store, and protect personal information in connection with the Torvi platform, in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
2. Two roles: Torvi as processor, Organisations as controller
It's important to understand the relationship between Torvi and the information in the system:
- Organisations (our customers) collect and control the personal information of their own staff and, where applicable, the people they support (participants/clients). Organisations are responsible for ensuring they have a proper legal basis to collect and enter that information into Torvi, and for meeting their own obligations under the Privacy Act, the NDIS Practice Standards, and Aged Care Quality Standards.
- Torvi acts as the technology platform and, for personal information entered by Organisations, generally acts as a data processor on the Organisation's behalf — we store and process it as instructed by the Organisation, and do not use it for our own independent purposes beyond providing and improving the service (see Section 5).
- Separately, Torvi also collects information directly from Organisations and their authorised users for our own purposes (e.g. account administration, billing) — this policy also covers that information as the primary collector.
If you are a participant, client, or staff member of one of our customer Organisations and have a question about your own information, please contact that Organisation directly in the first instance, as they control that data.
3. Information we collect
Depending on how Torvi is used, the platform may hold:
Account and billing information (collected directly by Torvi):
- Organisation name, ABN, contact details
- Names, email addresses, and login credentials of authorised users
- Billing and subscription information (payment card details are collected and stored directly by our payment processor, Stripe — see Section 7; Torvi does not store full card numbers)
Staff information (entered by Organisations):
- Names, contact details, addresses
- Employment details (occupation, employment type, pay/rate information)
- Rostering, shift, and timesheet records
- Compliance documents (e.g. police checks, certifications, working with children checks) and their expiry dates
- Messages sent within the platform
- Photographs and files uploaded to the platform — profile photos, scans or photographs of compliance documents, photographs attached to incident reports, odometer photographs supporting a mileage claim, and files attached to messages. These may be taken with the device camera or chosen from the device's existing photos, in both cases only at the moment the person chooses to attach one. Torvi does not read the device's photo library other than the specific item a person selects, and does not access the camera at any other time.
- Location information recorded at clock-in and clock-out — where an Organisation's staff clock on and off using Torvi, the platform records the device's reported position at those two moments, together with how accurate that reading was. This is captured only at the moment of clocking on and clocking off. Torvi does not track location continuously, in the background, or at any other time, and does not record where a staff member is between shifts or outside working hours. The Torvi mobile apps do not collect location at all — see Section 4b. Where a position cannot be obtained — because the app does not ask for it, because the staff member declines a web browser's permission request, or because the device has no signal — the reason is recorded instead, and clocking on or off is never prevented.
Participant/client information (entered by Organisations, where applicable — this may include sensitive and health information):
- Names and contact details
- Care plans, clinical notes, medication records, incident reports
- Consent records
- NDIS or aged care funding information
Sensitive and health information of this kind is subject to heightened protection requirements under the Privacy Act, and access within Torvi is restricted based on the roles the Organisation assigns to its own staff.
4. How we collect information
We collect information:
- Directly from Organisations and their staff when they sign up, enter data, or use the platform
- Automatically through use of the platform (e.g. login activity, system logs, for security and troubleshooting purposes)
- From the device a staff member uses to clock on and off, where that device provides a location and the person permits it — which, on the Torvi mobile apps, it does not, because the apps do not ask for location access
- From the camera or stored photographs of a device, at the moment somebody chooses to attach a photograph or a document to a record
- From our payment processor (Stripe) regarding subscription and payment status (not full payment card details)
4a. Location information, specifically
Location information relates to identifiable individuals and their physical movements, so it is worth setting out separately what is and is not done with it.
- It is recorded only at the two moments a staff member clocks on and clocks off. There is no continuous or background tracking.
- It is stored against the timesheet for that shift, and is deleted with that timesheet.
- It is visible to the staff member themselves, and to those people within their own Organisation whose role already permits them to view that timesheet. Torvi does not share it with other Organisations.
- Where an administrator clocks a staff member on or off on their behalf, no location is recorded, because the administrator's device is not where the work happened.
- The Torvi mobile apps do not collect it at all. They request no location permission, so clocking on from the app records the reason in place of a position. Everything described here therefore applies to using Torvi in a web browser that has been given permission. See Section 4b.
Workplace positions, and what leaves the platform. So that the platform can tell whether somebody is near their workplace, each Location and Participant may have a position recorded against it. This can be set in three ways: found automatically from the address that has already been entered, placed by an administrator dragging a pin on a map, or captured by an administrator standing at the site. Where it is found automatically, the address is sent to Geoscape Australia, an Australian address data provider, and nothing else about the person is sent with it. Where a map is displayed, the coordinates being looked at are sent to Stadia Maps in order to return the map imagery; no address and no personal information is sent. A Participant's address is information about where somebody lives, so an Organisation that would rather it were not sent anywhere can leave the position unset or place it by hand, and the platform works the same way.
Organisations are responsible for telling their own staff. An Organisation using this feature is conducting a form of workplace monitoring of its own employees. Several Australian jurisdictions regulate this specifically — including the Workplace Surveillance Act 2005 (NSW) and the Workplace Privacy Act 2011 (ACT), which require written notice to employees before tracking surveillance begins, and prescribe how much notice must be given. Meeting those obligations is the Organisation's responsibility, not Torvi's. Organisations should obtain their own advice on what applies to them.
4b. The Torvi mobile apps, specifically
Torvi is also available as an app for iOS and Android. The apps are the same service in a different wrapper: they show the same screens, talk to the same servers, and are governed by everything else in this policy. This section sets out what the apps ask of the device itself.
Permissions the apps request. Two, and only when you use the feature that needs them:
- Camera — to photograph a compliance document, an incident, an odometer reading, or a profile picture, at the moment you choose to add one.
- Photos — to attach a picture you have already taken. On iOS this uses the system picker, which passes Torvi only the item you select; the app cannot browse the rest of your library.
- Notifications — to send you a push notification about a new shift, a timesheet decision, or a message. The app asks once, after you first sign in, and works normally if you decline. What a notification says is deliberately limited: it can name you, a shift's date, time and location, and who sent you a message, and it never names a participant or says anything about their care.
Permissions the apps do not request, and information they do not collect. The apps do not ask for, and cannot obtain:
- Location. The apps request no location permission of any kind, so clocking on and off from the app records no position — the reason is stored in its place, exactly as it is for a device that has no signal. Location capture described in Section 4a happens only in a web browser that has been given permission. If this ever changes, the app will ask you first and this policy will be updated before it does.
- Contacts, calendars, the microphone, health data, or files other than a photograph or document you choose to attach.
- Any advertising identifier. The apps contain no advertising, analytics, or tracking software of any kind, and no third-party software development kits that collect information about you. The apps include Google's Firebase Cloud Messaging library, which delivers notifications to the device and collects no information about you.
Nothing is collected in the background. While the app is closed it does nothing except receive notifications sent to it.
What the apps keep on the device. After you sign in, the app stores your session token and the display name and permissions belonging to it, so you are not asked to sign in again every time you open it. This stays on the device, is not readable by other apps, and is removed when you sign out. Documents you open from the app are fetched over a signed link and displayed in the device's own secure in-app browser.
5. How we use information
We use information to:
- Provide, operate, and maintain the Torvi platform
- Process subscription payments and manage billing
- Communicate with Organisations about their account, service updates, or support requests
- Investigate and respond to security incidents
- Allow Organisations to verify attendance and to calculate travel between visits for mileage purposes. Any distance shown is a straight-line distance between two recorded positions, offered as a starting point for a person to check and correct — Torvi does not file a mileage or reimbursement claim on anybody's behalf
- Meet our own legal obligations
- Improve and develop the platform (using aggregated or de-identified data wherever reasonably possible)
We do not sell personal information, and we do not use the personal information Organisations enter about their staff or participants for our own marketing purposes.
6. Disclosure of information
We may disclose information to:
- Service providers who help us run Torvi, listed in Section 7 below, under contractual obligations to protect it
- Law enforcement or regulators, where required by law
- A new owner, if Torvi is sold or transferred as part of a business transaction, subject to the new owner continuing to protect the information in line with this policy
We do not disclose participant or staff information to any other Organisation using Torvi — each Organisation's data is kept separate and isolated from every other Organisation on the platform.
7. Overseas disclosure and sub-processors
Some of the service providers we use to run Torvi are located overseas, or store data on servers located overseas. This means personal information may be transferred outside Australia. Under Australian Privacy Principle 8, we take reasonable steps to ensure these providers protect information consistently with the APPs.
Our current infrastructure providers include:
| Provider | Purpose | Location |
|---|---|---|
| Render | Application hosting | Oregon, USA |
| Cloudflare | Network protection and traffic delivery for all requests to Torvi. Every request passes through Cloudflare, which decrypts and re-encrypts it in transit as part of protecting the service | Cloudflare global network — the nearest location to the person making the request |
| Cloudflare R2 | Storage of uploaded files and documents | Cloudflare global network (automatic placement) |
| Neon | Database hosting | Ohio, USA (AWS us-east-2) |
| Stripe | Payment processing | Primarily US-based, PCI-DSS compliant |
| Resend | Account emails we send you directly (signup confirmation, password setup) | United States (stored in the US regardless of sending region) |
| Google Firebase Cloud Messaging (FCM) | Delivering push notifications to the Torvi mobile apps. Receives a device token, the notification's title and body, and — for shift, timesheet and message notifications only — a link containing the record's identifier so the app can open the right screen. A notification never identifies a participant, directly or indirectly: notification text never contains a participant's name, care or medical details, or the content of a message, and notifications about a participant's plans or calendar carry no link or identifier at all | United States (Google global infrastructure) |
| Google Fonts | Typefaces used by the Torvi interface | United States — receives your IP address and browser details when a page loads |
| Geoscape Australia | Converting a Location's or Participant's address into map coordinates, so the platform can check whether a staff member is near their workplace when they clock on. Sent only when an address is saved or changed, and only the address itself — never a person's name, or any indication of who the address belongs to | Australia |
| Stadia Maps | Map imagery shown when an administrator sets or adjusts a workplace position. Receives the map coordinates being viewed, and the browser's IP address, in order to return the map tiles. No address and no personal information is sent | European Union and United States |
Google Fonts receives only what any web request reveals — an IP address, browser and device details, and the address of the page being viewed. No account details, staff records, or participant information are sent to it.
Services your Organisation connects itself
Email and SMS sent from your Organisation — staff invitations, shift notifications, reminders — are sent through accounts your Organisation connects, not through ours. An Administrator enters your own Resend (email) and Twilio (SMS) credentials in Settings, and messages are then sent from your own account, under your own agreement with that provider, and appear to your staff as coming from you.
This means two things. Message content and recipient details go to your provider account, and the applicable data location is the one set on that account — for Resend this is the United States, and for Twilio it is the United States (region US1) unless your account was created in another region. It also means we store the credentials you enter so that we can send on your behalf; they are held against your Organisation and are not visible to any other Organisation.
If your Organisation has not connected an email or SMS provider, those messages are not sent, and Torvi records that they could not be delivered rather than sending them by another route.
8. Data security
We take reasonable technical and organisational steps to protect personal information from misuse, loss, and unauthorised access, including:
- Encrypted connections (HTTPS) for all data in transit
- Access controls so staff only see information relevant to their role
- Regular security review of the platform
- Multi-factor authentication available for user accounts
No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
9. Data breach notification
In the event of a data breach that is likely to result in serious harm, we will comply with our obligations under the Notifiable Data Breaches (NDB) scheme in the Privacy Act, including notifying the Office of the Australian Information Commissioner (OAIC) and affected individuals (via the relevant Organisation, where applicable) as required.
10. Access and correction
Individuals may request access to, or correction of, personal information held about them. If you are a staff member or participant of an Organisation using Torvi, please contact that Organisation directly, as they control that information. If your request relates to information Torvi holds directly about you as an Organisation's authorised user (e.g. your own login account), contact us using the details in Section 13.
11. Data retention
We retain personal information for as long as necessary to provide the service, and afterwards as required by law. This includes retention periods relevant to aged care and disability support record-keeping obligations (which may require retention for a number of years), and Fair Work Act record-keeping requirements for employment records. When information is no longer required, we take reasonable steps to destroy or de-identify it, subject to Organisations' own instructions and any legal retention obligations.
12. Complaints
If you believe we have breached the Privacy Act or this policy, you can contact us using the details below. We will investigate and respond within a reasonable time. If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
13. Contact us
Torvi Technology Pty Ltd ABN 17 702 923 528 Email: hello@torvi.com.au
14. Changes to this policy
We may update this policy from time to time. We will notify Organisations of material changes and update the "Last updated" date above.