Policies
Operational, security and governance policies covering participants, providers, support workers and the ShiftLink platform. Our Privacy Policy is published separately.
1. Purpose
This Privacy Policy explains how Care2All Australia Pty Ltd trading as ShiftLink collects, uses, stores and discloses personal information.
It is intended to assist compliance with the Privacy Act 1988 (Cth), the Australian Privacy Principles and other applicable laws.
2. Scope
This Policy applies to personal information collected through the ShiftLink website, software platform, mobile applications and related services.
3. Definitions
Personal Information has the meaning given in the Privacy Act 1988 (Cth).
Sensitive Information includes health and other information afforded additional protection under applicable law.
4. Collection of Information
ShiftLink may collect personal, business and technical information necessary to provide its products and services.
5. Information We Collect
Information may include identity, contact, billing, employment, usage, device and support information.
6. Sensitive Information
Sensitive information will only be collected where authorised by law or with appropriate consent.
7. Purpose of Collection
Information is collected to provide services, manage accounts, improve the Platform, comply with legal obligations and communicate with users.
8. Lawful Basis
ShiftLink collects and processes information in accordance with applicable Australian privacy laws and contractual obligations.
9. Data Quality
Reasonable steps are taken to ensure personal information is accurate, complete and up to date.
10. User Responsibilities
Users should promptly notify ShiftLink of changes to their personal information to maintain accurate records.
11. Use of Personal Information
- Personal information is used only for the purposes for which it was collected or as otherwise permitted by law.
12. Disclosure of Information
- Personal information may be disclosed to service providers, regulators or other parties where authorised, required by law or with consent.
13. Overseas Disclosure
- Where information is disclosed overseas, ShiftLink will take reasonable steps to ensure appropriate privacy protections are maintained.
14. Data Security
- ShiftLink implements reasonable administrative, physical and technical safeguards to protect personal information from misuse, loss and unauthorised access.
15. Data Retention
- Personal information is retained only for as long as necessary to fulfil legal, regulatory and business requirements.
16. Access and Correction
- Individuals may request access to or correction of their personal information in accordance with applicable Australian privacy laws.
17. Marketing Communications
- Marketing communications will only be sent where permitted by law and users may opt out at any time.
18. Cookies and Analytics
- ShiftLink may use cookies and analytics technologies to improve website functionality, security and user experience.
19. Data Breaches
- Eligible data breaches will be managed in accordance with the Notifiable Data Breaches scheme and applicable legal obligations.
20. Complaints
- Privacy complaints may be submitted to ShiftLink and will be investigated and handled in accordance with internal complaint procedures.
21. Changes to this Policy
- ShiftLink may amend this Privacy Policy from time to time. Updated versions become effective upon publication unless otherwise stated.
22. Governing Law
- This Privacy Policy is governed by the laws of the Commonwealth of Australia and the applicable State or Territory.
23. Contact Details
- Questions regarding this Privacy Policy or personal information handling practices should be directed to Care2All Australia Pty Ltd using the official ShiftLink contact details.
24. Severability
- If any provision of this Policy is found invalid or unenforceable, the remaining provisions continue in full force and effect.
25. Review
- This Policy will be reviewed periodically to ensure ongoing compliance with legal, regulatory and operational requirements.
Version Control
- Version: 1.0
- Effective Date: __________________
- Approved By: __________________
- Next Review Date: __________________
Acknowledgement
- Users acknowledge that they have read and understood this Privacy Policy and consent to the collection, use and disclosure of personal information as described, where applicable.
Schedule A – Privacy Rights
- This Schedule summarises individual rights relating to access, correction, complaints and privacy enquiries under applicable Australian privacy legislation.
Schedule B – Definitions
- Defines key terms including Personal Information, Sensitive Information, Processing, Disclosure, Data Breach and APPs.
1. Purpose
This Cookie Policy explains how ShiftLink uses cookies and similar technologies across its website and platform.
2. Scope
This Policy applies to all visitors and users accessing ShiftLink websites, applications and online services.
3. Definitions
Cookies are small text files stored on a user's device to support functionality, analytics and security.
4. Consent
Where required by law, ShiftLink will obtain consent before placing non-essential cookies on a user's device.
5. Types of Cookies
ShiftLink may use essential, functional, performance, analytics and preference cookies.
6. Essential Cookies
Essential cookies enable core website functionality such as authentication, security and session management.
7. Functional Cookies
Functional cookies remember user preferences to improve the user experience.
8. Analytics Cookies
Analytics cookies help understand website usage and improve platform performance.
9. Third-Party Cookies
Approved third-party providers may place cookies when integrated services are used.
10. Cookie Management
Users may manage or disable cookies through browser settings, noting that some functionality may be affected.
11. Browser Controls
- Users can configure browser settings to accept, reject or delete cookies at any time.
12. Do Not Track
- Where technically feasible, ShiftLink will consider browser privacy preferences, although Do Not Track signals may not always be supported.
13. Advertising Technologies
- Where used, advertising technologies help deliver relevant content and measure campaign effectiveness.
14. Analytics Providers
- ShiftLink may use trusted analytics providers to understand platform usage and improve services.
15. Security Technologies
- Cookies and similar technologies may be used to detect fraud, maintain account security and protect system integrity.
16. Retention
- Cookies are retained for varying periods depending on their purpose and configuration.
17. Updates to Preferences
- Users may update cookie preferences at any time through available consent management tools where provided.
18. Impact of Disabling Cookies
- Disabling certain cookies may affect website functionality, authentication and personalised settings.
19. Related Policies
- This Policy should be read together with the Privacy Policy and other applicable ShiftLink policies.
20. Compliance
- ShiftLink manages cookies in accordance with applicable Australian privacy and consumer protection laws.
21. Changes to this Policy
- ShiftLink may update this Cookie Policy from time to time. Changes take effect upon publication unless otherwise stated.
22. Governing Law
- This Cookie Policy is governed by the laws of the Commonwealth of Australia and the applicable State or Territory.
23. Contact Information
- Questions regarding this Cookie Policy should be directed to Care2All Australia Pty Ltd using the official ShiftLink contact details.
24. Version Control
- Version: 1.0
- Effective Date: __________________
- Approved By: __________________
- Next Review Date: __________________
25. Review
- This Policy will be reviewed periodically to ensure it remains accurate, effective and legally compliant.
Acknowledgement
- By continuing to use the ShiftLink website or platform, users acknowledge this Cookie Policy and applicable cookie preferences.
Schedule A – Cookie Categories
- Summary of essential, functional, analytics, performance and third-party cookies used by ShiftLink.
Schedule B – User Rights
- Overview of user choices regarding consent, browser settings and privacy rights relating to cookies.
1. Purpose
This Refund Policy sets out the principles governing refunds for ShiftLink software subscriptions and related services.
It supports compliance with Australian Consumer Law and applicable contractual obligations.
2. Scope
This Policy applies to customers purchasing ShiftLink subscriptions, implementation services and related offerings unless otherwise agreed in writing.
3. Definitions
Customer means the person or organisation purchasing ShiftLink products or services.
Refund means the repayment of amounts paid where required by law or approved under this Policy.
4. Australian Consumer Law
Nothing in this Policy excludes, restricts or modifies any rights or remedies available under the Australian Consumer Law.
5. Eligibility
Refund requests will be assessed based on applicable law, contractual terms and the circumstances of each request.
6. Subscription Fees
Subscription fees are generally non-refundable except where required by law or expressly stated in an applicable agreement.
7. Implementation Services
Fees for completed implementation, onboarding or consulting services are generally non-refundable unless otherwise agreed or required by law.
8. Free Trials
Where a free trial is offered, customers may cancel before the trial ends to avoid subscription charges in accordance with the applicable terms.
9. Request Process
Refund requests should be submitted through approved ShiftLink support channels with sufficient supporting information.
10. Assessment
Each refund request will be reviewed fairly, consistently and within a reasonable timeframe.
11. Decision Outcomes
- Customers will be advised of the outcome of refund requests together with the reasons for the decision where appropriate.
12. Approved Refunds
- Approved refunds will be processed using the original payment method where reasonably practicable unless otherwise agreed.
13. Partial Refunds
- Partial refunds may be provided where appropriate under applicable agreements or Australian Consumer Law.
14. Cancellation
- Subscription cancellations are governed by the applicable Subscription Agreement, Terms and Conditions and this Policy.
15. Chargebacks
- Customers should contact ShiftLink before initiating a payment chargeback to allow an opportunity to resolve the issue.
16. Fraud Prevention
- Refund requests may be verified to prevent fraud, abuse or unauthorised payment activity.
17. Records
- Records of refund requests, supporting evidence, decisions and payments must be retained in accordance with applicable recordkeeping requirements.
18. Exceptions
- Any exception to this Policy requires approval from an authorised representative unless otherwise required by law.
19. Monitoring
- Refund trends may be monitored to identify systemic issues and improve products, services and customer experience.
20. Compliance
- Failure to comply with this Policy may result in contractual remedies or other lawful action where applicable.
21. Policy Review
- This Policy will be reviewed periodically and updated to reflect legislative, commercial and operational changes.
22. Governing Law
- This Policy is governed by the laws of the Commonwealth of Australia and the applicable State or Territory.
23. Non-Compliance
- Failure to comply with this Policy may result in contractual remedies, disciplinary action or other lawful measures where applicable.
24. Version Control
- Version: 1.0
- Effective Date: __________________
- Approved By: __________________
- Next Review Date: __________________
25. Approval
- This Refund Policy is approved by Care2All Australia Pty Ltd and applies to all ShiftLink products and services unless otherwise agreed in writing.
Acknowledgement
- Care2All Australia Pty Ltd is committed to fair, transparent and legally compliant refund practices.
Schedule A – Refund Assessment Process
- Summary of refund request submission, assessment, approval, rejection and payment procedures.
Schedule B – Refund Eligibility Guide
- Summary of common refund scenarios, exclusions and Australian Consumer Law considerations.
Schedule C – Related Policies
- References to the SaaS Terms and Conditions, Master Subscription Agreement, Billing Policy, Payment Terms and Complaints Policy.
1. Purpose
This Billing Policy establishes the principles governing billing practices for ShiftLink subscriptions, implementation services and related offerings.
It supports transparent billing and compliance with Australian Consumer Law and applicable contractual obligations.
2. Scope
This Policy applies to all customers purchasing ShiftLink products or services unless otherwise agreed in writing.
3. Definitions
Billing Cycle means the recurring period for invoicing subscription fees.
Invoice means a document requesting payment for products or services supplied.
4. Billing Cycles
Subscription fees will be billed according to the billing cycle specified in the applicable agreement or order.
5. Invoicing
Invoices will include sufficient information to identify the products, services, applicable taxes and payment due dates.
6. Pricing
Applicable pricing is set out in the customer's order, subscription agreement or other written agreement.
7. Taxes
Prices may be exclusive of applicable taxes unless expressly stated otherwise. Taxes will be applied in accordance with applicable law.
8. Billing Information
Customers are responsible for providing and maintaining accurate billing and contact information.
9. Billing Disputes
Customers should notify ShiftLink promptly of any billing concerns or disputed charges for investigation.
10. Payment Due Dates
Payments are due by the date specified on the applicable invoice unless otherwise agreed in writing.
11. Accepted Payment Methods
- Payments may be made using approved payment methods specified by ShiftLink from time to time.
12. Automatic Renewal Billing
- Recurring subscriptions may be billed automatically in accordance with the applicable subscription agreement unless cancelled in accordance with the agreed terms.
13. Failed Payments
- If a payment fails, ShiftLink may retry the transaction or request an alternative payment method before taking further action.
14. Overdue Accounts
- Overdue invoices may be subject to service restrictions, reminders or other contractual remedies where permitted by law.
15. Credits and Adjustments
- Billing credits or invoice adjustments may be applied where appropriate and in accordance with applicable agreements.
16. Billing Errors
- Verified billing errors will be corrected as soon as reasonably practicable following investigation.
17. Recordkeeping
- Billing records, invoices and payment information will be retained in accordance with applicable legal and organisational requirements.
18. Confidentiality
- Billing information will be handled in accordance with the Privacy Policy and applicable data protection obligations.
19. Monitoring
- Billing processes may be reviewed periodically to improve accuracy, efficiency and compliance.
20. Compliance
- Failure to comply with this Policy may result in contractual remedies or other lawful action where applicable.
21. Policy Review
- This Policy will be reviewed periodically and updated to reflect legislative, operational and commercial changes.
22. Governing Law
- This Policy is governed by the laws of the Commonwealth of Australia and the applicable State or Territory.
23. Non-Compliance
- Failure to comply with this Policy may result in contractual remedies, suspension of services or other lawful action where applicable.
24. Version Control
- Version: 1.0
- Effective Date: __________________
- Approved By: __________________
- Next Review Date: __________________
25. Approval
- This Billing Policy is approved by Care2All Australia Pty Ltd and applies to all ShiftLink billing activities unless otherwise agreed in writing.
Acknowledgement
- Care2All Australia Pty Ltd is committed to transparent, accurate and compliant billing practices.
Schedule A – Billing Process
- Summary of invoice generation, payment collection, reconciliation and account management procedures.
Schedule B – Billing Dispute Resolution
- Summary of billing enquiry, investigation, dispute resolution and adjustment procedures.
Schedule C – Related Policies
- References to the Payment Terms, Refund Policy, SaaS Terms and Conditions, Master Subscription Agreement and Complaints Policy.
1. Purpose
This Complaints Policy establishes the framework for receiving, managing and resolving complaints relating to ShiftLink products, services and operations.
It supports fair, transparent and timely complaint handling in accordance with applicable Australian laws and NDIS expectations where relevant.
2. Scope
This Policy applies to complaints made by customers, participants, providers, support workers, employees, contractors and other stakeholders.
3. Definitions
Complaint means an expression of dissatisfaction regarding a product, service, decision or conduct where a response or resolution is expected.
Complainant means the individual or organisation making the complaint.
4. Guiding Principles
Complaints will be managed fairly, impartially, respectfully, confidentially and without retaliation.
5. Lodging a Complaint
Complaints may be submitted through approved communication channels including email, online forms, telephone or other designated methods.
6. Complaint Acknowledgement
Complaints should be acknowledged within a reasonable timeframe and assigned for assessment.
7. Assessment
Each complaint will be assessed according to its nature, urgency, complexity and potential impact.
8. Investigation
Where appropriate, complaints will be investigated objectively using relevant information and evidence.
9. Communication
Complainants will be kept reasonably informed about the progress and outcome of their complaint where appropriate.
10. Resolution
Reasonable efforts will be made to resolve complaints promptly and implement appropriate corrective actions where required.
11. Escalation
- Complaints that cannot be resolved at the initial level may be escalated to appropriate management for further review.
12. Timeframes
- Complaints should be managed and resolved within reasonable timeframes, taking into account their complexity and applicable legal obligations.
13. Recordkeeping
- Accurate records of complaints, investigations, decisions and corrective actions must be maintained.
14. Confidentiality
- Complaint information must be handled confidentially and disclosed only where authorised or legally required.
15. Corrective Actions
- Where systemic issues are identified, appropriate corrective and preventive actions should be implemented.
16. External Review
- Where applicable, complainants may seek review through external dispute resolution bodies or relevant regulatory authorities.
17. Accessibility
- Reasonable assistance should be provided to enable all individuals to lodge and participate in the complaints process.
18. Staff Responsibilities
- Employees and contractors must cooperate with complaint investigations and comply with this Policy.
19. Monitoring and Reporting
- Complaint trends may be analysed to improve products, services and organisational performance.
20. Compliance
- Failure to comply with this Policy may result in disciplinary action, contractual remedies or other lawful measures.
21. Policy Review
- This Policy will be reviewed periodically and updated to reflect legislative, operational and organisational changes.
22. Governing Law
- This Policy is governed by the laws of the Commonwealth of Australia and the applicable State or Territory.
23. Non-Compliance
- Failure to comply with this Policy may result in disciplinary action, contractual remedies or other lawful action.
24. Version Control
- Version: 1.0
- Effective Date: __________________
- Approved By: __________________
- Next Review Date: __________________
25. Approval
- This Complaints Policy is approved by Care2All Australia Pty Ltd and applies to all ShiftLink personnel and relevant stakeholders.
Acknowledgement
- Care2All Australia Pty Ltd is committed to maintaining an accessible, fair and transparent complaints management process.
Schedule A – Complaint Handling Process
- Summary of complaint receipt, assessment, investigation, resolution and closure procedures.
Schedule B – Escalation Framework
- Summary of internal escalation pathways, external review options and response responsibilities.
Schedule C – Related Policies
- References to the Privacy Policy, Accessibility Statement, Information Security Policy, Refund Policy and other applicable ShiftLink governance documents.
1. Purpose
This Information Security Policy establishes the framework for protecting ShiftLink information assets.
It supports compliance with Australian legal, regulatory and contractual obligations.
2. Scope
This Policy applies to all employees, contractors, authorised users, systems, networks and information processed by ShiftLink.
3. Definitions
Information Asset includes data, systems, software, hardware and documentation.
Confidential Information means information requiring protection against unauthorised disclosure.
4. Information Security Objectives
ShiftLink will protect the confidentiality, integrity and availability of information assets.
5. Governance
Management is responsible for implementing, maintaining and reviewing the information security program.
6. Roles and Responsibilities
All personnel must comply with security policies, report incidents and protect information under their control.
7. Risk Management
Security risks will be identified, assessed, treated and monitored through an ongoing risk management process.
8. Information Classification
Information must be classified according to its sensitivity, business value and legal requirements.
9. Access Control
Access to systems and information will be granted on the basis of least privilege and business need.
10. Authentication
Strong authentication controls, including multi-factor authentication where appropriate, must be implemented.
11. Password Management
- Passwords must comply with approved complexity, rotation and storage requirements.
12. Encryption
- Sensitive information must be protected using appropriate encryption technologies during storage and transmission.
13. Network Security
- Networks must be protected using appropriate firewalls, monitoring, segmentation and intrusion detection controls.
14. Endpoint Security
- All authorised devices must implement approved security controls including anti-malware, patching and device management.
15. Vulnerability Management
- Security vulnerabilities must be identified, assessed, prioritised and remediated in a timely manner.
16. Security Monitoring
- Security events and logs will be monitored to detect, investigate and respond to potential threats.
17. Incident Reporting
- Personnel must promptly report suspected or actual information security incidents using approved procedures.
18. Third-Party Security
- Suppliers and service providers must maintain appropriate security measures consistent with contractual obligations.
19. Business Continuity
- Security controls must support business continuity and disaster recovery planning.
20. Security Awareness
- Personnel will receive regular information security awareness and training appropriate to their roles.
21. Compliance and Audits
- Compliance with this Policy will be verified through periodic internal reviews, risk assessments and security audits.
22. Policy Exceptions
- Any exception to this Policy must be formally approved, documented and periodically reviewed.
23. Policy Review
- This Policy will be reviewed regularly and updated to reflect legal, regulatory, technological and operational changes.
24. Governing Law
- This Policy is governed by the laws of the Commonwealth of Australia and the applicable State or Territory.
25. Version Control
- Version: 1.0
- Effective Date: __________________
- Approved By: __________________
- Next Review Date: __________________
Acknowledgement
- All personnel acknowledge their responsibility to comply with this Information Security Policy and related security procedures.
Schedule A – Information Classification
- Summary of information classification levels, handling requirements and access controls.
Schedule B – Security Controls
- Summary of administrative, physical and technical safeguards implemented to protect ShiftLink information assets.
Schedule C – Incident Contacts
- Details of internal reporting channels and security escalation procedures.
1. Purpose
This Accessibility Statement explains ShiftLink's commitment to providing an accessible digital platform for all users.
It supports continuous improvement and alignment with applicable Australian accessibility expectations.
2. Scope
This Statement applies to the ShiftLink website, web application, mobile applications and associated digital services.
3. Commitment
Care2All Australia Pty Ltd is committed to improving accessibility for participants, providers, support workers and all users.
4. Accessibility Standards
ShiftLink aims to progressively align its digital services with recognised accessibility standards, including WCAG where reasonably practicable.
5. Accessible Design
Accessibility considerations are incorporated into product design, development, testing and maintenance processes.
6. Supported Features
The Platform seeks to support keyboard navigation, appropriate colour contrast, scalable text, meaningful headings and alternative text where applicable.
7. Assistive Technologies
Reasonable efforts are made to support commonly used assistive technologies and modern browsers.
8. Continuous Improvement
Accessibility issues identified through testing or user feedback are prioritised for remediation where appropriate.
9. User Feedback
Users are encouraged to report accessibility barriers or suggest improvements through approved support channels.
10. Alternative Assistance
Where practical, alternative methods of accessing information or services will be offered if accessibility barriers are identified.
11. Accessibility Requests
- Users may request reasonable assistance or accessible formats where practicable.
12. Accessibility Testing
- Accessibility testing may be conducted using automated tools, manual reviews and user testing where appropriate.
13. Third-Party Content
- Some third-party content or services may not fully meet accessibility requirements and are subject to the providers' own accessibility practices.
14. Known Limitations
- Known accessibility limitations will be documented and addressed through ongoing improvement activities where reasonably practicable.
15. Staff Awareness
- Relevant personnel should receive appropriate training and guidance on accessibility principles and inclusive design.
16. Procurement
- Accessibility considerations should be included when evaluating new software, services and technology solutions.
17. Regulatory Compliance
- ShiftLink will consider applicable Australian legal obligations and recognised accessibility guidance when developing and maintaining its services.
18. Monitoring
- Accessibility performance may be monitored through reviews, audits and user feedback.
19. Statement Updates
- This Statement may be updated to reflect changes in technology, legislation or organisational practices.
20. Contact
- Users experiencing accessibility difficulties are encouraged to contact ShiftLink support for assistance and feedback.
21. Policy Review
- This Statement will be reviewed periodically and updated to reflect legislative, technological and organisational changes.
22. Governing Law
- This Statement is governed by the laws of the Commonwealth of Australia and the applicable State or Territory.
23. Non-Compliance
- Accessibility issues identified through audits, feedback or testing will be addressed through appropriate corrective actions where reasonably practicable.
24. Version Control
- Version: 1.0
- Effective Date: __________________
- Approved By: __________________
- Next Review Date: __________________
25. Approval
- This Accessibility Statement is approved by Care2All Australia Pty Ltd and applies to all ShiftLink digital services.
Acknowledgement
- ShiftLink is committed to ongoing accessibility improvements and welcomes feedback from all users.
Schedule A – Accessibility Features
- Summary of supported accessibility features, assistive technology compatibility and inclusive design practices.
Schedule B – Accessibility Feedback Process
- Procedures for reporting accessibility barriers, requesting assistance and tracking remediation activities.
Schedule C – Related Policies
- References to the Privacy Policy, Information Security Policy, Acceptable Use Policy and other applicable ShiftLink documents.
1. Purpose
This Third-Party Services Policy establishes the principles governing the selection, use, monitoring and management of third-party products and services supporting ShiftLink.
The objective is to ensure third-party services are used securely, reliably and in compliance with legal and contractual obligations.
2. Scope
This Policy applies to all third-party vendors, suppliers, cloud service providers, software providers, consultants and outsourced service providers engaged by ShiftLink.
3. Definitions
Third-Party Service means any product or service supplied by an external organisation or individual.
Vendor means a third party providing products or services to ShiftLink.
4. Policy Objectives
Promote secure and compliant use of third-party services.
Manage operational, security and privacy risks.
Support business continuity and service quality.
5. Vendor Selection
Third-party providers shall be evaluated based on business needs, security, privacy, reliability, compliance and commercial suitability.
6. Due Diligence
Appropriate due diligence shall be completed before engaging significant third-party service providers.
7. Contractual Requirements
Third-party agreements should clearly define responsibilities, service levels, confidentiality obligations and applicable legal requirements.
8. Risk Assessment
Risks associated with third-party services shall be identified, assessed and managed throughout the vendor relationship.
9. Security Requirements
Third-party providers shall implement appropriate security controls to protect information and services.
10. Privacy Requirements
Where personal information is processed, third-party providers must comply with applicable privacy obligations and contractual requirements.
11. Ongoing Monitoring
- Third-party service providers shall be monitored periodically to ensure continued compliance with contractual, security and operational requirements.
12. Performance Management
- Vendor performance shall be evaluated against agreed service levels, quality standards and business expectations.
13. Incident Management
- Security, privacy or operational incidents involving third-party providers shall be managed in accordance with applicable incident response procedures.
14. Business Continuity
- Critical third-party providers should maintain appropriate business continuity and disaster recovery capabilities.
15. Access Management
- Third-party access to systems, networks and information shall be restricted to authorised purposes and reviewed regularly.
16. Data Handling
- Third-party providers shall process, store and dispose of information in accordance with contractual obligations and applicable privacy laws.
17. Compliance Reviews
- Periodic compliance reviews or audits may be conducted where appropriate to verify contractual and regulatory compliance.
18. Contract Changes
- Material changes to third-party services or agreements shall be assessed for operational, security and legal impacts before implementation.
19. Termination
- Termination of third-party arrangements shall include secure return, transfer or destruction of organisational information where applicable.
20. Compliance
- Compliance with this Policy is mandatory for personnel responsible for procuring or managing third-party services.
21. Policy Review
- This Third-Party Services Policy will be reviewed periodically and updated to reflect legislative, operational, security and business changes.
22. Governing Law
- This Policy is governed by the laws of the Commonwealth of Australia and the applicable State or Territory.
23. Non-Compliance
- Failure to comply with this Policy may result in disciplinary action, contractual remedies or other lawful measures where applicable.
24. Version Control
- Version: 1.0
- Effective Date: __________________
- Approved By: __________________
- Next Review Date: __________________
25. Approval
- This Third-Party Services Policy is approved by Care2All Australia Pty Ltd and applies to all ShiftLink personnel responsible for procuring or managing third-party services.
Acknowledgement
- ShiftLink is committed to maintaining secure, compliant and reliable relationships with third-party service providers.
Schedule A – Vendor Risk Assessment
- Summary of vendor due diligence, risk classification and approval requirements.
Schedule B – Third-Party Monitoring
- Summary of performance reviews, security assessments, compliance monitoring and contract management procedures.
Schedule C – Related Documents
- References to the Information Security Policy, Privacy Policy, Data Processing Agreement, Business Continuity Policy and Incident Response Policy.
1. Purpose
This Modern Slavery Statement outlines ShiftLink's commitment to preventing modern slavery, forced labour, human trafficking and related practices within its operations and supply chain.
It supports alignment with the Modern Slavery Act 2018 (Cth) and ethical business practices.
2. Scope
This Statement applies to Care2All Australia Pty Ltd, its employees, contractors, suppliers, service providers and business partners.
3. Commitment
Care2All Australia Pty Ltd is committed to conducting business ethically and taking reasonable steps to identify and reduce modern slavery risks.
4. Governance
Management is responsible for overseeing implementation of this Statement and related compliance activities.
5. Risk Assessment
Potential modern slavery risks will be considered when engaging suppliers, contractors and strategic partners.
6. Supplier Expectations
Suppliers are expected to comply with applicable laws and maintain practices that prohibit modern slavery and exploitation.
7. Due Diligence
Reasonable due diligence processes may be applied when onboarding or reviewing suppliers and service providers.
8. Reporting Concerns
Employees and stakeholders are encouraged to report suspected modern slavery concerns through approved reporting channels.
9. Training and Awareness
Relevant personnel may receive training on recognising and responding to modern slavery risks.
10. Continuous Improvement
ShiftLink will periodically review its processes and controls to strengthen its response to modern slavery risks.
11. Supplier Screening
- Appropriate supplier screening and procurement processes should consider modern slavery risk factors where reasonably practicable.
12. Contractual Requirements
- Supplier agreements may include clauses requiring compliance with applicable modern slavery laws and ethical labour practices.
13. Monitoring
- Supplier relationships may be periodically reviewed to identify and manage potential modern slavery risks.
14. Remediation
- Where modern slavery concerns are identified, ShiftLink will consider appropriate corrective actions, remediation measures and contractual responses.
15. Whistleblower Protection
- Individuals reporting concerns in good faith should be protected from retaliation in accordance with applicable policies and law.
16. Recordkeeping
- Records relating to due diligence, supplier assessments and reported concerns should be maintained where appropriate.
17. Internal Responsibilities
- Management and relevant personnel are responsible for implementing this Statement within their areas of responsibility.
18. External Engagement
- ShiftLink may engage with suppliers and stakeholders to promote ethical sourcing and responsible business conduct.
19. Performance Review
- The effectiveness of modern slavery risk management measures may be reviewed periodically and improved where necessary.
20. Compliance
- Failure to comply with applicable legal or contractual obligations relating to modern slavery may result in corrective or contractual action.
21. Policy Review
- This Statement will be reviewed periodically and updated to reflect legislative, operational and supply chain developments.
22. Governing Law
- This Statement is governed by the laws of the Commonwealth of Australia and the applicable State or Territory.
23. Non-Compliance
- Failure to comply with this Statement or related contractual obligations may result in corrective action, contract review or termination where appropriate.
24. Version Control
- Version: 1.0
- Effective Date: __________________
- Approved By: __________________
- Next Review Date: __________________
25. Approval
- This Modern Slavery Statement is approved by Care2All Australia Pty Ltd and applies across its operations and, where relevant, its supply chain.
Acknowledgement
- Care2All Australia Pty Ltd is committed to ethical business practices and continuous improvement in identifying and addressing modern slavery risks.
Schedule A – Modern Slavery Risk Assessment
- Summary of risk assessment criteria, supplier evaluation considerations and due diligence processes.
Schedule B – Reporting and Remediation
- Procedures for reporting concerns, investigating allegations and implementing remediation measures.
Schedule C – Related Policies
- References to the Supplier Code of Conduct, Procurement Policy, Whistleblower Policy and other applicable ShiftLink governance documents.
1. Purpose
This Vulnerability Disclosure Policy establishes the framework for receiving, assessing and responding to reports of security vulnerabilities affecting ShiftLink systems, applications and services.
It encourages responsible disclosure and supports the timely remediation of identified security issues.
2. Scope
This Policy applies to all internet-facing services, software applications, APIs, infrastructure and supporting systems owned or operated by ShiftLink.
3. Definitions
Vulnerability means a weakness that could adversely affect the confidentiality, integrity or availability of information or systems.
Security Researcher means an individual or organisation reporting a suspected vulnerability in good faith.
4. Policy Objectives
Promote responsible vulnerability disclosure.
Protect customers and information assets.
Support timely investigation and remediation.
5. Responsible Disclosure
Security researchers are encouraged to report vulnerabilities promptly through approved reporting channels.
6. Good Faith Research
Good faith security research conducted in accordance with this Policy will be treated respectfully and professionally.
7. Reporting Requirements
Reports should include sufficient information to reproduce and assess the reported vulnerability.
8. Initial Assessment
Reported vulnerabilities will be triaged according to severity, exploitability and potential business impact.
9. Confidentiality
Reported vulnerabilities will be handled confidentially until appropriate remediation and disclosure decisions have been made.
10. Acknowledgement
ShiftLink will endeavour to acknowledge receipt of vulnerability reports within a reasonable timeframe.
11. Validation
- Reported vulnerabilities will be validated to determine authenticity, severity and potential impact.
12. Risk Classification
- Validated vulnerabilities shall be prioritised according to established risk assessment criteria and business impact.
13. Remediation
- Appropriate corrective actions shall be implemented within reasonable timeframes based on the assessed risk.
14. Communication
- Where appropriate, ShiftLink will communicate with the reporting party regarding the status of the investigation and remediation.
15. Coordinated Disclosure
- Public disclosure should occur only after remediation or in accordance with an agreed coordinated disclosure process.
16. Third-Party Vulnerabilities
- Vulnerabilities affecting third-party products or services shall be referred to the relevant vendor where appropriate.
17. Prohibited Activities
- This Policy does not authorise unlawful access, denial-of-service testing, social engineering or activities that disrupt services or compromise customer data.
18. Recordkeeping
- Vulnerability reports, investigations and remediation actions shall be documented and retained in accordance with organisational requirements.
19. Training and Awareness
- Relevant personnel shall receive training on vulnerability management and responsible disclosure practices.
20. Compliance
- Compliance with this Policy is mandatory for applicable personnel responsible for vulnerability management.
21. Policy Review
- This Vulnerability Disclosure Policy will be reviewed periodically and updated to reflect legislative, security, operational and technological changes.
22. Governing Law
- This Policy is governed by the laws of the Commonwealth of Australia and the applicable State or Territory.
23. Non-Compliance
- Failure to comply with this Policy may result in disciplinary action, contractual remedies or other lawful measures where applicable.
24. Version Control
- Version: 1.0
- Effective Date: __________________
- Approved By: __________________
- Next Review Date: __________________
25. Approval
- This Vulnerability Disclosure Policy is approved by Care2All Australia Pty Ltd and applies to all ShiftLink personnel, contractors and relevant service providers.
Acknowledgement
- ShiftLink appreciates responsible security research and cooperation in protecting its systems and customers.
Schedule A – Vulnerability Severity Ratings
- Summary of vulnerability classification criteria, priority levels and remediation objectives.
Schedule B – Disclosure Process
- Summary of reporting, assessment, communication, coordinated disclosure and remediation procedures.
Schedule C – Related Documents
- References to the Information Security Policy, Incident Response Policy, Data Breach Response Policy, Acceptable Use Policy and Service Level Agreement (SLA).
