Privacy Policy

Last updated: 5 August 2026 · V2

QIPify is owned and operated by Naetiq Pty Ltd trading as QIPify. In this Privacy Policy, "QIPify", "we", "us" and "our" refers to Naetiq Pty Ltd trading as QIPify.

You can contact us about privacy matters at hello@qipify.com.

This Privacy Policy explains how we collect, use, store, disclose and protect personal information when customers, users and visitors access QIPify, use our website, create an account, subscribe to our services, upload content, communicate with us or otherwise interact with our platform.

QIPify is a quality improvement planning platform for education and care services, including OSHC services, early childhood services, schools, P&Cs, approved providers, consultants and related organisations. QIPify is designed for staff and provider users. It is not designed for family or parent accounts.

By using QIPify, you agree to the handling of personal information in the way described in this Privacy Policy.

1. Scope of this Privacy Policy

This Privacy Policy applies to all QIPify customers, account owners, administrators, service users, staff users, invited users, website visitors and people who communicate with us.

It applies to personal information collected through the QIPify website, the QIPify platform, account registration, customer onboarding, billing processes, support requests, product communications, transactional emails, uploaded content, QIP Smart Upload and other related services.

This Privacy Policy should be read together with our Terms and Conditions and any other policies or notices we provide.

2. What personal information we collect

The types of personal information we collect depend on how a person uses QIPify.

We may collect names, email addresses, business addresses, organisation names, service names, service information, role or position information, account details, login details, subscription status, support communications and information provided when a customer or user contacts us.

We may collect technical and security information such as IP addresses, device information, browser information, session information, authentication records, audit logs and timestamps. We may record IP addresses and timestamps as evidence of account activity, login activity, security events and acceptance of our Terms and Conditions.

We may collect service information entered into QIPify, including QIP information, self-assessment information, improvement goals, actions, tasks, comments, due dates, service details, uploaded documents, evidence files, images, screenshots, PDFs, policies, meeting notes and related materials uploaded or stored by customers and users.

We may collect billing-related information such as plan selection, subscription status, Stripe customer identifiers, invoice metadata, payment status and billing contact information. Payments are handled by Stripe. We do not store full credit card numbers or complete payment card details on our own systems.

We may collect communications information when you email us, request support, provide feedback, respond to surveys, subscribe to updates, or otherwise communicate with QIPify.

If QIPify later provides blog updates, newsletters, product news or marketing communications, we may collect information about whether users subscribe, unsubscribe, open or interact with those communications.

3. Uploaded content and evidence

QIPify allows customers and authorised users to upload, store and manage evidence and QIP-related materials for the purpose of using the advertised QIPify service.

Uploaded content may include documents, images, screenshots, PDFs, policies, procedures, reflections, meeting notes, planning documents, evidence items and other materials that customers choose to store in QIPify.

The customer is responsible for the content it uploads to QIPify. This includes ensuring that uploaded content is lawful, accurate, appropriate, authorised, de-identified where required, and consistent with the customer's own privacy, confidentiality, child safety, record-keeping and regulatory obligations.

QIPify does not routinely review or approve all uploaded content. We may not know whether a customer or user has uploaded identifiable, sensitive, confidential or unauthorised information. Customers and users are responsible for checking content before uploading, storing, sharing, exporting or publishing it through QIPify.

If we become aware that uploaded content may breach this Privacy Policy, our Terms and Conditions, applicable law, privacy requirements, child safety expectations or another person's rights, we may remove, restrict, disable access to, delete or require the customer to remove that content.

4. Child and family information

QIPify is not designed to store identifiable child or family information.

Although quality improvement planning documents may be reviewed, shared or made available to authorised stakeholders, QIPify is not a child portfolio system, family communication platform, enrolment record system, incident management system, medical record system, child protection record system or long-term archive for identifiable child or family records.

Customers and users must not upload content that identifies, or could reasonably identify, a child, family member, parent, guardian or other individual connected with a child, unless QIPify has expressly authorised that use in writing.

Customers and users must not upload children's faces, children's names, family names, parent or guardian details, home addresses, phone numbers, email addresses, dates of birth, enrolment records, medical information, allergy information, behavioural information, custody information, child protection information, incident records, medication records, sign-in sheets, attendance records, room lists, bag tags, name tags, screenshots showing child or family details, or any other information that could reasonably identify a child or family.

Customers and users must also be careful with images that may indirectly identify a child or family, such as images showing school uniforms, service locations, classroom displays, lockers, whiteboards, artwork with names, birthday charts, excursion lists or other contextual details.

Where a customer wants to evidence practice involving children or families, the customer should use de-identified evidence wherever possible. This may include cropped or blurred images, anonymised quotes, general descriptions of practice, service-level reflections, policy excerpts, meeting summaries, de-identified survey themes, aggregated feedback and examples of environments or resources that do not identify children or families.

If a customer or user uploads identifiable child or family information contrary to this Privacy Policy, the customer remains responsible for that upload and any resulting privacy, confidentiality, child safety or legal consequences. QIPify may take reasonable action if we become aware of the issue, but we do not accept responsibility for reviewing every upload or detecting every instance of identifiable information.

5. How we collect personal information

We collect personal information directly from customers and users when they create an account, accept an invitation, sign in, use QIPify, upload content, enter service information, use QIP Smart Upload, request support, subscribe, make a payment, communicate with us or interact with our website.

We may also collect information automatically through the platform, such as IP addresses, login events, timestamps, audit logs, browser information, security events, session data, cookies, local storage and similar technologies.

We may receive limited personal information from third-party providers where necessary to operate QIPify, such as Stripe for payment and subscription information, Supabase for authentication and account information, Resend for email delivery information, Google APIs for address lookup functions, and security or infrastructure providers used to operate and protect QIPify.

6. Why we collect and use personal information

We collect and use personal information to provide, operate, secure and improve QIPify.

This includes creating and managing accounts, authenticating users, providing access to services, managing service information, storing customer content, supporting QIP workflows, enabling collaboration, processing subscriptions, handling billing, sending transactional emails, providing customer support, maintaining security, keeping audit logs, recording acceptance of Terms and Conditions, preventing misuse, improving product performance, troubleshooting issues, complying with legal obligations and communicating with customers and users.

We may use contact details to send transactional and service-related emails, including account invitations, email verification, password reset emails, security notices, trial notices, billing notices, payment notices, subscription updates, service updates and support communications.

In the future, we may use contact details to send product updates, blog updates, newsletters or QIPify news. Users will be able to unsubscribe from marketing communications. Unsubscribing from marketing communications will not stop essential transactional, billing, security or account-related emails.

7. QIP Smart Upload and AI processing

QIPify may include a QIP Smart Upload feature that uses artificial intelligence to assist with processing or interpreting uploaded QIP-related content.

QIP Smart Upload uses OpenAI to provide the AI feature. Content submitted to QIP Smart Upload may be processed by OpenAI in the United States for the purpose of providing the AI functionality.

Customers and users must not upload or enter identifiable child information, family information, sensitive information, confidential information or unnecessary personal information into QIP Smart Upload.

AI outputs may be inaccurate, incomplete, outdated or unsuitable for a customer's circumstances. Customers and users must review, verify and edit any AI-assisted output before using, sharing or relying on it.

QIP Smart Upload is intended to support administrative quality improvement workflows. It is not legal advice, regulatory advice, compliance advice, child safety advice or professional consultancy advice.

We may apply usage limits, fair use controls, security checks or access restrictions to AI features where needed to protect QIPify, customers, users, third-party providers or the integrity of the service.

8. Cookies, local storage and similar technologies

QIPify may use cookies, local storage, session storage and similar technologies to operate the website and platform.

These technologies may be used for login sessions, authentication, security, user preferences, remembering settings, improving platform performance, preventing fraud, maintaining service functionality and understanding how the platform is used.

Users may be able to control some cookies through their browser settings. If cookies or local storage are disabled, some parts of QIPify may not function properly.

9. Google address features

QIPify may use Google APIs, such as address autocomplete or address lookup features, to help customers enter business or service address information.

When a user interacts with an address lookup feature, the information typed into the address field may be sent to Google so that Google can return address suggestions or related functionality.

Google may handle that information in accordance with its own terms and privacy practices.

10. Disclosure of personal information

We may disclose personal information where reasonably necessary to provide, operate, secure, support and improve QIPify.

This may include disclosure to our technology, hosting, database, authentication, storage, payment, email, security, AI, infrastructure and support providers.

Our current providers may include Supabase for database, authentication and storage, Stripe for payments and subscription processing, Resend for email delivery, Aikido for security monitoring and runtime protection, Cloudflare Turnstile for bot detection and abuse prevention, OpenAI for QIP Smart Upload AI processing, Replit for hosting and deployment, and Google APIs for address features.

QIPify does not use Cloudflare as its DNS provider. Our providers may change where reasonably necessary to operate, secure, maintain or improve QIPify.

We may also disclose information to professional advisers, insurers, contractors, consultants, regulators, law enforcement agencies, courts, government authorities or other parties where required or permitted by law, where necessary to protect our rights, where necessary to respond to security incidents, or where necessary to enforce our Terms and Conditions.

We do not sell personal information.

11. Overseas disclosure and storage

QIPify's primary customer workspace data is hosted in Australia using Supabase infrastructure located in Sydney.

QIP Smart Upload uses OpenAI and may process relevant content in the United States for the purpose of providing the AI feature.

Some limited account, billing, email, support, security, infrastructure, analytics or technical metadata may be processed by third-party providers outside Australia where this is necessary to provide, secure, maintain or support QIPify.

Where we disclose personal information to overseas recipients, we take reasonable steps to use reputable providers and manage privacy and security risks in accordance with applicable privacy laws.

Customers and users must not submit identifiable child information, family information or unnecessary sensitive information to QIP Smart Upload or any other feature that is not designed to handle that information.

12. Security of personal information

We take reasonable steps to protect personal information and customer data from misuse, interference, loss, unauthorised access, unauthorised modification and unauthorised disclosure.

These steps may include access controls, authentication, role-based permissions, secure hosting, private storage, signed access links, encryption in transit, audit logging, security monitoring, vulnerability scanning, firewall protections, runtime protection, vendor security controls and internal security processes.

No internet-based service, software platform, hosting provider, payment provider, email provider, AI provider or storage system can be guaranteed to be completely secure. Customers and users are responsible for using QIPify securely and for managing access within their own organisation.

Customers are responsible for inviting the right users, assigning appropriate roles, removing users who no longer need access, keeping account details accurate, training staff in safe information handling, reviewing uploads before sharing, and ensuring their own privacy and child safety obligations are met.

Users must keep login details confidential and notify QIPify promptly if they suspect unauthorised access, account compromise, incorrect access permissions or a data security issue involving QIPify.

13. Data retention

We retain personal information and customer data for as long as reasonably necessary to provide QIPify, maintain customer accounts, support active subscriptions, comply with legal obligations, resolve disputes, keep business records, manage billing, maintain security, prevent fraud and enforce our Terms and Conditions.

For active customer accounts, we generally retain customer data while the account remains active.

After cancellation, expiry or inactivity, we may retain customer data for up to 12 months unless the account becomes active again, the customer signs in, the customer requests deletion, or we are required or permitted to retain information for legal, billing, audit, fraud prevention, security or dispute management purposes.

Customers may export QIP content using QIPify's export functions and may download individual data or files where platform functionality allows.

If deletion is requested and processed, the deleted data will no longer be available for restoration through normal customer access. Some residual information may remain in backups, logs or records for a limited period where required for security, technical, billing, legal or compliance purposes. Backup data is not used for ordinary business purposes and is overwritten or deleted in accordance with normal backup cycles.

We may retain limited records such as invoices, subscription records, payment metadata, audit logs, security logs, support records and legal records for longer where necessary for legitimate business, tax, accounting, security, legal or compliance reasons.

14. Access, correction and deletion requests

Users may contact us at hello@qipify.com to request access to, correction of, or deletion of their personal information.

We may need to verify the identity and authority of the person making the request before responding.

Where a request relates to information controlled by a customer, such as workspace content, service data, uploaded evidence, QIP records, staff-created content or organisation records, we may refer the request to the relevant customer account owner or require the request to be managed by the customer.

We may refuse or limit a request where permitted by law, including where access would affect another person's privacy, reveal confidential information, compromise security, be frivolous or vexatious, relate to anticipated or existing legal proceedings, or where we are required or permitted to retain the information.

If personal information is inaccurate, incomplete, out of date, irrelevant or misleading, we will take reasonable steps to correct it where appropriate.

15. Privacy complaints

If you have a concern about how QIPify has handled personal information, you can contact us at hello@qipify.com.

Please include enough information for us to understand the issue, identify the relevant account or information, and respond appropriately.

We will review privacy complaints and aim to respond within a reasonable time. We may ask for further information, verify identity, investigate the issue, consult relevant customer account owners or service providers, and take appropriate steps if we identify an error or privacy issue.

16. Security incidents and data breaches

No online platform, database, hosting service, email service or storage system can be guaranteed to be completely secure.

If we become aware of a suspected or actual security incident involving personal information, we will assess whether action is required under applicable law.

Depending on the circumstances, we may investigate the incident, restrict or revoke access, work with relevant service providers or advisers, attempt to contain or remediate the issue, and preserve relevant records or logs.

Where notification is required by applicable law, we will notify affected customers, individuals, regulators or other relevant parties in the manner and timeframe required by that law.

Where notification is not legally required, we may determine whether notification is appropriate based on the available information, likely harm, security considerations and legal obligations. We do not guarantee notification within a particular timeframe.

Information about an incident may be delayed or limited where reasonably necessary to investigate or contain the incident, protect system security, protect another person's information, comply with law or follow directions from law enforcement, insurers, advisers or service providers.

Customers must promptly report suspected unauthorised access, accidental disclosure, inappropriate uploads, incorrect sharing, compromised credentials, incorrect permissions or other suspected incidents involving their QIPify account.

Customers remain responsible for notification and response obligations that apply to information they collected, controlled, uploaded or disclosed.

17. Customer backups

QIPify may maintain platform-level backups and recovery processes for internal operational and business continuity purposes. These processes are not a dedicated customer backup, archival, disaster recovery or statutory record-retention service.

Customers must maintain independent copies of information they are required to retain or could not reasonably recreate if lost. Customers must not rely on QIPify as the sole repository or permanent archive for important information.

We do not guarantee that a particular file, record, version, deletion, amendment or recent change can be recovered or restored.

18. Customer responsibilities

Customers are responsible for how they and their authorised users collect, use, upload, store, disclose, export and share information through QIPify.

Customers are responsible for ensuring they have all necessary notices, consents, authorities, permissions and legal bases before entering information into QIPify or uploading content.

Customers must ensure their users comply with the QIPify Terms and Conditions, this Privacy Policy, internal policies, privacy obligations, confidentiality obligations, child safety obligations and any applicable laws or regulatory requirements.

Customers must not use QIPify as a substitute for their own privacy management systems, child safety processes, record-keeping obligations, regulatory compliance processes or professional judgement.

19. Changes to this Privacy Policy

We may update this Privacy Policy from time to time.

The updated version will be posted on QIPify.com or made available through the QIPify platform.

Where changes are material, we will take reasonable steps to notify customers or users, such as through email, in-platform notice or website notice.

Continued use of QIPify after an updated Privacy Policy takes effect means the customer or user accepts the updated Privacy Policy.

20. Contact us

For privacy questions, access requests, correction requests, deletion requests, complaints or data breach concerns:

Naetiq Pty Ltd trading as QIPify
ABN: 698366657  |  ACN: 35698366657
Website: QIPify.com
Email: hello@qipify.com
Address: 888 Brunswick Street, New Farm, Australia