CORA Workforce
Privacy Policy
Last updated 21 August 2026.
This policy explains what personal information CORA Workforce collects, why we collect it, who we share it with, where it is stored, and how you can see it, correct it or have it deleted. It is written to be read, not to be survived.
The short version
We collect the least we can: who you are, which training you have done, and the credentials your employer has to keep on file. Your data is stored in Australia. We do not sell it and we never will. Four overseas services help us run CORA, and the Custom Course Builder is the one that sends document content outside Australia, which is set out in full below, including what it strips out first and what it does not.
If you are an independent support worker using CORA as your own back office, we also hold what you record about the people you support. That is the most sensitive thing we hold, so it has a section of its own: section 3a says what it is, who put it there, how long it stays and how to have it deleted. The AI that helps you write a note or a report runs in Australia.
1. Who we are
CORA Workforce provides online training and workforce capability reporting to Australian NDIS and disability service providers, and directly to individual support workers.
In this policy, “CORA”, “we” and “us” mean CORA Workforce. “You” means whoever is reading it: a provider, a support worker, or someone whose information a provider has given us.
Registered entity name and ABN: CORA Workforce Pty Ltd, ACN 701 110 152, ABN 91 701 110 152. Contact details are in section 13.
2. Whose data, and whose decision
CORA holds information in two different roles, and the difference decides who you should talk to.
When your employer is in charge
If your provider enrolled you, they decide what training you are assigned, what credentials they record about you, and whether your account stays open. We hold that information on their behalf. If you want your record changed or removed, start with your employer. We will help them do it, and we will act on a direct request from you as well.
When we are in charge
If you bought an individual membership yourself, or you signed up on our website, we decide how that information is handled and you deal with us directly.
When an independent support worker is in charge
Some of our members are independent support workers who use CORA to run their own work. If one of them supports you, we hold their records about you on their behalf. They decide what goes in, and we never collect any of it from you. Section 3a sets out what those records are. Start with your support worker if you want something changed, and come to us as well if you would rather: we will act on a request from you directly.
3. What we collect
| Who | What we hold |
|---|---|
| Provider administrators | Name, work email, password (stored only as a cryptographic hash, never as text), your role, your organisation, and a log of sign-ins. |
| Support workers | Name, email, team, which courses are assigned and due, completion dates, quiz scores and attempts, certificates, and any credentials your employer records: the licence or clearance name, issuer, issue and expiry dates, and the document itself if they upload one. |
| Individual members | Name, email, your subscription and payment status, and your own training record. You may optionally tell us your employer’s name. If you use CORA as your own back office, also your business details, your rates, your shifts, your invoices and your travel records. |
| People an individual member supports | Their profile and contact details, and the shift notes, incident reports, risk notes, progress reports, service agreements, consents, shifts and invoices the member writes about them. The member enters all of it. Section 3a sets it out in full, and it is the most sensitive information CORA holds. |
| People named in an uploaded document | Whatever the provider’s document contains. See section 5, which is the most important part of this policy. |
| Website and free-trial visitors | Name and email if you start a free course, whether you agreed to hear from us, and a one-way hash of your IP address and browser to stop automated abuse. Those hashes are erased on a schedule and cannot be turned back into an address. |
| Referrals | If a member refers a colleague, the contact details they give us, the wording of the consent they confirmed, and the date. |
The employer name an individual member gives us is used to understand who our members work for. It is not permission to contact that employer, and we do not.
3a. If your support worker uses CORA
Some of our members are independent support workers who use CORA as the back office for their own business. This section is about the people they support. Those people are not our customers and most of them will never have heard of us, so this says exactly what is held, who put it there, and how to get it out.
The member enters all of it, and the member decides what goes in. CORA provides the forms. We do not collect any of it from you, we never ask you for it, and we do not use it to run CORA or to sell anything to anybody.
What a member can record about you
- Who you are: your name, the name you prefer, phone, email and address.
- Your nominee or main contact: their name, their relationship to you, phone and email.
- Your NDIS number and date of birth. These two are asked for only when a service agreement or an invoice needs them. They are not on the ordinary profile form.
- What matters to you: your goals, your likes, your dislikes, and how you like to be supported.
- Whether a restrictive practice is in place, and the member’s own description of it.
- Shift notes: what the worker did on a shift, in their own words, under their own headings.
- Incident reports: what happened, when and where, what was done, who was told, and how serious the worker judged it to be.
- Risk notes, progress reports, and a record of every report that was emailed, including the exact text that was sent and who it went to.
- Service agreements and consent forms, and the signature on them.
- Shifts, services and invoices for the support provided.
- Travel records for trips connected to your support: the date, the distance, any tolls, and any note the worker wrote about the trip.
Some of that is health information about somebody who is not our customer. A description of a restrictive practice is. So is anything a shift note or an incident report says about a person’s health, behaviour or disability. We treat all of it as sensitive whether or not the law compels us to, and section 4 applies to every line of it.
Where it lives, and who can see it
In Australia, in the database and the private storage described in section 8. Only that one member can see it. No other member, no provider, and no employer, and that stays true even if the member has told us where they work.
CORA does not send any of it overseas by itself. The writing help in section 5b is processed in Australia. If a member chooses to email a progress report, a service agreement or an invoice to somebody, that message and its attachment travel through Resend, our email provider in the United States, the same way every other email CORA sends does. That is the member’s decision, made one message at a time.
How long it is kept
While the member’s account is open. Nothing here is deleted on a timer. A member can archive a participant, which takes them off the working list, and archiving erases nothing, because the notes and reports already written are about that person and are the member’s own records of work they did.
How to have it deleted
Ask us. Email privacy@coraworkforce.com.au and tell us who you are. You can ask us directly, whether you are the person being supported, their nominee or their guardian, and you do not have to go through the worker, though we will usually need to tell them because the records are theirs. We will delete what we can, tell you plainly if any of it has to stay and why, and confirm when it is done. A support worker can be required to keep their own service records for a period, so that is the kind of thing we would tell you rather than quietly leave in.
If a member closes their account and asks us to delete their records, we do the same thing. If they close it and do not ask, we keep the records until they tell us otherwise, because they may need to produce them later.
If you would rather not be in CORA at all, tell your support worker, or tell us. None of this is a condition of receiving support from them.
4. Sensitive and health information
Some of what we hold is sensitive information under Australian privacy law, and some of it is health information about a person who is not our customer and has never heard of us. That happens in three ways.
- A provider records a worker credential such as an NDIS Worker Screening Check.
- A provider uploads a document that names a participant, most often a behaviour support plan or a mealtime management plan.
- An independent support worker records the people they support: their profile, their shift notes, their incidents and their reports. This is the largest of the three by a distance, it is health and disability information about a named person, and it is set out in full in section 3a.
We treat this information as sensitive whether or not the law compels us to. We do not use it for anything except the purpose it was given for, we never use it for marketing, and we never sell it.
5. The Custom Course Builder, in full
This is the only part of CORA that sends your content outside Australia, so it is set out step by step rather than summarised.
When a provider uploads a document, CORA reads the text out of it and sends that text to Anthropic, an artificial intelligence provider in the United States, which turns it into course screens. Then:
- Structured identifiers are removed before it is sent. Email addresses, phone numbers, NDIS and Medicare numbers, labelled dates of birth and street addresses are stripped out of the copy that leaves Australia. Names written in ordinary sentences are not detected and are not removed. If a plan says “Michael needs his drink thickened”, that sentence is sent as it stands. We say so plainly rather than implying the document is anonymised, because it is not.
- If the file is a scan or a photograph, the page image is sent instead of the text. A PDF with no readable text layer cannot be read on our servers, so the picture of the page goes to Anthropic to be transcribed, and everything else in this section applies to it in the same way. Ordinary PDFs, Word and OpenDocument files and text files are read here, and no image is sent.
- The file itself is never stored. We keep the extracted text, the file name and a checksum. We do not keep the document.
- The extracted text is deleted when the course is published, automatically. After that the course exists and its source text does not.
- Anthropic does not use it to train their models. Under their commercial terms, content sent through their API is excluded from model training. They may hold it briefly for safety and abuse monitoring.
- The person uploading has to confirm they are allowed to. Before any document is read, they tick an acknowledgement that they have authority to upload it and that CORA will process its text. It is never pre-ticked.
- Only that provider can ever see it. Courses and their source text are separated at the database level, so one provider cannot reach another’s.
If you are an NDIS participant and a provider has built a course from your plan: you can ask us what we hold about you and ask us to delete it, using the contact details in section 13. You do not have to go through the provider, though we will usually need to tell them, because the course belongs to them.
Providers: a document naming a participant is that participant’s information as well as your record. Uploading it is a disclosure you are making, so please satisfy yourself that you have the authority to make it before you do.
5a. Reading a certificate
When an admin uploads a worker’s certificate, licence or clearance, CORA sends the file to Anthropic once, to read the dates and the name printed on it, so nobody has to type them in. This is the only other thing CORA sends outside Australia.
- It is a picture of an identity document, so it usually carries a full name and often a licence or certificate number. We are saying so plainly rather than describing it as “a file”.
- Nothing is kept from the reading. The image is not stored by that step and the text that comes back is not saved. It fills in the form on screen, and disappears if the admin closes it without saving.
- The certificate itself is only stored if they press save, in Sydney, in the private storage described in section 8. That is the same as it has always been.
- Anthropic does not use it to train their models, under the same commercial terms set out in section 5.
- CORA never works out an expiry date. It records only what is printed. If a certificate shows the date it was completed and no expiry, the expiry stays empty, because a renewal date we calculated would end up on a compliance record looking like something a person had read off the document.
A worker who would rather their certificate was not read this way can ask their employer to type the dates in instead. It saves typing and changes nothing about what is recorded.
5b. The writing help in a member’s own back office
An independent member has four places where CORA uses artificial intelligence on their own words. All four run in Australia, on Amazon Web Services, and none of them goes to the service in section 5.
- Tidy into note. The member types or dictates a shift note in their own words and CORA puts what they wrote under their own headings. Dictation is their phone’s own keyboard, on the device: CORA never receives audio and no recording is made anywhere.
- Draft a progress report. CORA writes a first draft from that member’s own shift notes for the period. They edit it, and they have to confirm they have reviewed it before it can be sent.
- One safeguarding question. After a note is saved, CORA reads it once and may ask a single question, such as whether they want to record an incident report. It never says an incident occurred, and the question is stored nowhere.
- Course suggestions. CORA suggests up to three of its own courses from the note. Only that member ever sees them, and they never appear in a report, an export or an email.
The same facts apply to all four.
- Names are swapped out first. Every name CORA holds for that member’s participants and their nominees is replaced with a tag before anything is sent, and put back afterwards. A name we do not hold, a nickname, or somebody mentioned in passing, is not detected and is not replaced. We say so plainly rather than calling it anonymised, because it is not.
- Then identifiers are stripped: email addresses, phone numbers, NDIS and Medicare numbers, dates of birth and addresses, the same list as section 5.
- What is never sent: a participant’s contact details, NDIS number, date of birth, address, goals, agreements, consents, or any note other than the one being worked on.
- Where it goes. Amazon Web Services, through their Bedrock service, in Australia. The model is Claude, running inside AWS. AWS states that what is sent is not stored, is not used to train models, and is not passed on to anyone else, including the maker of the model.
- What we record: that a call happened, how long the text was, how many identifiers were stripped, and nothing at all of what it said.
- A person reads it before it counts. A tidied note goes back into the boxes the member was already typing in, and the note exists when they press save. A report draft has to be reviewed and confirmed before it can be emailed to anybody.
- CORA never assesses anybody. None of these four says whether a worker did their job well, and none of them says anything about a participant’s health. They restructure, they draft and they ask.
Each of these says so on the screen where it happens, in one line, with this same detail a tap behind it.
6. Why we use it
- To give you an account and let you sign in.
- To deliver training and record what has been completed.
- To produce training registers, certificates and capability reporting for your employer.
- To tell you when training or a credential is coming due.
- To take payment and issue invoices.
- To keep the service secure and to investigate misuse.
- To give an independent member the records they need to run their own support work, and to produce those records for them.
- To meet our own legal obligations.
We do not use your data to make automated decisions about you. A capability report is a summary of what a worker answered. It is a prompt for a conversation, not a verdict, and CORA never asserts that a worker is competent. That judgement belongs to your organisation.
CORA does suggest training to an individual member from their own shift notes, described in section 5b. That is a prompt and not an assessment: it changes nothing about their account or their record, nobody else can see it, and they can dismiss any of it.
7. Who we share it with
We share personal information only with the services that make CORA work, and only as much as each one needs. We do not sell personal information, and we do not disclose it for anyone else’s marketing.
| Service | What it receives | Where |
|---|---|---|
| Vercel hosting and file storage | Everything the site serves, and the files you upload: credential documents, and any course package a provider or partner loads in, including video inside it. | Sydney, Australia. Company is United States based. |
| Neon database | The database itself. | Sydney, Australia. Company is United States based. |
| Anthropic AI: Custom Course Builder, and reading a certificate. Provider features only. | The text of a document a provider uploads, or a picture of the page when the file is a scan, and the image of a certificate when one is uploaded for a worker. Email addresses, phone numbers, NDIS and Medicare numbers, dates of birth and addresses are stripped out first. A person’s name written in a sentence is not. Nothing else about your account goes to Anthropic: no learner list, no email addresses, no training records. An individual member’s notes and reports do not come here at all: they go to the row below, in Australia. | United States. |
| Amazon Web Services AI: an individual member’s notes and reports (section 5b) | The text of one shift note, or the notes that feed one report, with the names CORA holds swapped for tags and structured identifiers stripped out first. No participant profile, no contact details, no NDIS number, no date of birth, no address, and no other note. AWS states that it is not stored, is not used to train models and is not passed on to anyone else. | Australia. Company is United States based. |
| Rustici SCORM Cloud course delivery | A learner reference, and their progress and score in a course. | United States. |
| Stripe payments | Billing name, email and subscription details. Card numbers go straight to Stripe, and CORA never receives or stores them. | United States and Australia. |
| Resend email delivery | The name and email address of the person being emailed, and the message. When an individual member chooses to email a progress report, a service agreement or an invoice, the attachment goes with it, and that attachment names the person it is about. | United States. |
We may also disclose information where the law requires it, or to protect someone’s safety. If CORA is ever sold or merged, personal information may transfer with it, and we will tell you before that happens.
8. Where your data lives
The database and uploaded documents are stored in Sydney. Uploaded credential documents are held in private storage and are served only after we check that the person asking is signed in and belongs to the organisation that owns the file. Every access is logged.
The overseas services in the table above are the exceptions, and it is worth being exact about which of them sees what you have written.
- Anthropic receives uploaded document content and certificate images, and nothing else. Sections 5 and 5a.
- Amazon Web Services receives an individual member’s note and report text, and it stays in Australia. Section 5b.
- Resend carries every email CORA sends, including any attachment a member chooses to send with one. Email leaves Australia because our email provider is overseas.
- Rustici SCORM Cloud receives a learner reference and their progress in a course. No participant information and no health information goes there.
9. Marketing, and what you actually agreed to
- A consent box is never pre-ticked.
- If you are a worker at a provider, we email you about your training: what is assigned, what is due, what has expired. That is the service, not marketing.
- We only send you CORA news and offers if you asked for them, and every one has an unsubscribe link that works.
- Telling us your employer’s name is not permission to contact them.
10. How long we keep it
- Uploaded document text: deleted when the course is published.
- Deleted learners and organisations: removed from view immediately and recoverable for 30 days, because most deletions are mistakes. The window is enforced by the database itself, not by code that could be bypassed.
- Free-trial visitors: the IP and browser hashes are erased on a schedule.
- Training records: kept while the provider has an account, because they are compliance records a provider may need to produce years later. When an account closes, we agree a deletion date with them.
- What an individual member records about the people they support: kept while their account is open, and never deleted on a timer. Archiving a participant takes them off the working list and erases nothing. Section 3a says how to have it deleted, and who can ask.
- Payment records: kept as long as tax and business records law requires.
Deleting a course does not delete the record that someone completed it. Somebody did that training, and erasing the evidence to tidy up a mistake would be the worse wrong.
11. How we protect it
- Encrypted in transit and at rest.
- Passwords are stored as one-way hashes. Nobody at CORA can read your password.
- Providers are separated at the database level, so one organisation cannot query another’s data even if the application is wrong.
- Access to uploaded documents is checked on every request and logged.
- Every time anything is sent to an AI service, whether it leaves Australia or not, we record that it happened: which organisation, which person, when, how large it was and how many identifiers were stripped. We do not record any of the content.Keeping a copy of the text in a log would be a second copy of a participant’s plan, or of somebody’s shift note, under a different deletion rule, which would quietly defeat the deletion promised in sections 3a and 5. The log answers who sent what and when, and it can answer that without holding a word of it.
- No security is perfect. If something goes wrong, section 12 says what we do.
12. Your rights, complaints and breaches
Seeing and correcting your information
Ask us and we will tell you what we hold about you, usually within 30 days and at no charge. If it is wrong, we will fix it. If we cannot give you something, we will tell you why in writing.
If something goes wrong
If there is a data breach likely to cause serious harm, we will notify the people affected and the Office of the Australian Information Commissioner, as the Notifiable Data Breaches scheme requires.
Complaints
Complain to us first, using the details below, and we will respond within 30 days. If you are not satisfied, you can take it to the Office of the Australian Information Commissioner at oaic.gov.au or 1300 363 992.
13. Contact us
Email privacy@coraworkforce.com.au. Please put “Privacy” in the subject line, and tell us who you are so we can find your record.
14. Changes to this policy
If we change how we handle personal information, we will update this page and change the date at the top. If the change is significant, such as adding a service that receives your data, we will tell account holders directly rather than quietly editing the page.
This policy covers the CORA Workforce platform at portal.coraworkforce.com.au and the CORA website.