Privacy Policy, Disclaimer & Guarantee Terms
Last updated: 24 July 2026 · Version 1.1
This page sets out how A.C.N. 694 240 152 Pty Ltd (ACN 694 240 152) ("Cenaris", "we", "us") collects, uses and protects personal information under the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), describes the nature and limits of the Cenaris platform, and sets out the Terms and Conditions of the Cenaris Audit Money-Back Guarantee.
1. Purpose and scope
This Privacy Policy explains how A.C.N. 694 240 152 Pty Ltd (ACN 694 240 152) ("Cenaris", "we", "us") handles personal information. Cenaris provides compliance and audit-readiness software for NDIS providers and other regulated organisations. Cenaris handles personal information in accordance with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth).
This Policy applies to:
- personal information that Cenaris collects to operate its business and provide the platform; and
- compliance evidence that customers upload to the platform.
Cenaris is responsible for the personal information in the first category. Customers control the content of the compliance evidence they upload, as set out in section 4 and in the customer's Terms.
2. Information Cenaris collects
Cenaris collects:
- contact and account details, including name, work email, telephone number, organisation, and role;
- information provided in enquiries, communications, or product demonstrations; and
- technical and analytics information, including IP address, browser type, and pages visited, when the website is used.
Cenaris does not seek health information or other sensitive information through its website or marketing.
3. How Cenaris collects personal information
Cenaris collects personal information directly from the individual, from use of its website, and from use of the platform. Where practicable, Cenaris collects personal information directly from the individual concerned.
4. Compliance evidence uploaded to the platform
The platform is designed to hold organisational compliance evidence, including policies, procedures, governance records, registers, training records, and system-level incident and audit documentation.
The platform is not a clinical record system and is not designed to receive personal information about identifiable individuals, including named staff or NDIS participants.
The customer determines the content of its uploads. The customer is responsible for ensuring that personal information about identifiable individuals is not included, and for holding the rights necessary to upload the material it provides. Where personal information is uploaded despite these controls, Cenaris handles it in accordance with this Policy and the customer's Terms.
5. Purposes of use
Cenaris uses personal information to:
- respond to enquiries and provide requested services;
- establish and operate customer accounts and the platform;
- send service communications and, where requested, product updates;
- comply with legal obligations; and
- maintain and improve the security and performance of its systems.
6. Service providers and AI features
Cenaris engages service providers to operate its business, including cloud hosting, email, analytics, and AI providers. These providers are subject to confidentiality and data-handling obligations no less protective than this Policy and the customer's Terms, and may use personal information only to provide services to Cenaris. Cenaris does not sell or rent personal information.
The platform uses AI to assist in classifying and mapping uploaded compliance evidence. AI outputs are indicative only and are intended to support, not replace, the customer's review. AI features are provided by third-party providers that may process content outside Australia. Those providers process content only to generate the AI outputs, do not retain content beyond the period required to return a result, and do not use content to train their models.
A current list of Cenaris service providers is available at cenaris.com.au/sub-processors. Details of the AI providers are available on request. Cenaris will notify customers of material changes to this list by email or by updating that page.
7. Location of information and overseas processing
Information uploaded to the platform is stored in Australia, in the Sydney region. When AI features are used, the relevant content is transmitted to AI providers located outside Australia for the purpose of generating the AI outputs. As the platform is intended to hold organisational compliance evidence and not personal information about identifiable individuals, this processing is not intended to involve such personal information.
Personal information that Cenaris holds to operate its business and customer accounts, including contact and account details, may be handled by service providers located outside Australia, including for cloud hosting, email, and analytics. Where this occurs, Cenaris takes reasonable steps to ensure those providers protect the information and use it only to provide services to Cenaris, consistent with Australian Privacy Principle 8. Cenaris does not otherwise transfer personal information outside Australia without notice.
8. Security
Cenaris takes reasonable technical and organisational steps to protect personal information, appropriate to its size and the sensitivity of the information. These steps include encryption in transit and at rest, role-based access controls, regular security assessments, incident response procedures, and logging of account activity. If a data breach affecting a customer's information occurs, Cenaris will notify the customer without undue delay and assist with the response, in accordance with the customer's Terms.
9. Retention
Cenaris retains personal information for as long as it is required for the purposes in this Policy and for the term of the customer's subscription. After a subscription ends, Cenaris makes the customer's data available for export for 30 days and then deletes it, except where retention is required by law, including records the customer must keep as an NDIS provider. Analysis outputs and related metadata may be retained to support audit history. Activity logs are retained for at least 90 days.
10. Cookies and analytics
Cenaris uses a limited number of cookies for website functionality and for privacy-respecting analytics. Non-essential cookies may be refused through the banner displayed on first visit or through browser settings. Essential cookies are required for the website and platform to operate.
11. Access and correction
An individual may request access to the personal information Cenaris holds about them and may request correction of information that is inaccurate or out of date. Requests should be directed to info@cenaris.com.au. Cenaris will respond within 30 days.
12. Complaints
A complaint about Cenaris's handling of personal information should be directed to info@cenaris.com.au in the first instance. A complaint may also be made to the Office of the Australian Information Commissioner at oaic.gov.au.
13. Changes to this Policy
Cenaris may update this Policy from time to time. Cenaris will notify account holders of material changes by email or by notice on its website. The "last updated" date identifies the current version.
14. Contact
A.C.N. 694 240 152 Pty Ltd (ACN 694 240 152)
Email: info@cenaris.com.au
Address: Level 4, 114 William St, Melbourne VIC 3000
Disclaimer
Decision-Support Platform, Cenaris Pty Ltd
No Audit or Certification Services
Cenaris is not an auditor, certifying body, or regulatory authority. The Cenaris platform does not conduct audits, accreditation assessments, certification reviews, or formal compliance determinations under the NDIS Practice Standards, Aged Care Quality Standards, ISO standards, or any other regulatory or accreditation framework.
Any outputs, insights, gap analyses, readiness indicators, or reports generated by Cenaris are informational only and must not be represented to third parties (including auditors, regulators, or funders) as audit findings or certification outcomes.
No Guarantee of Compliance
Use of the Cenaris platform does not guarantee compliance, registration, accreditation, audit outcomes, or regulatory approval. Compliance obligations remain the sole responsibility of the organisation using the platform. Regulatory bodies, auditors, and commissioners may interpret legislation, standards, and evidence requirements differently, and those interpretations may change over time.
Cenaris makes no representations or warranties that use of the platform will:
- achieve or maintain compliance,
- prevent regulatory action,
- result in successful audit or registration outcomes, or
- identify all compliance gaps, risks, or deficiencies.
Not a Replacement for Governance or Professional Advice
Cenaris does not replace organisational governance, management oversight, internal quality systems, or professional judgement. The platform is not a substitute for:
- board or executive governance,
- internal audits,
- risk management frameworks,
- legal advice,
- compliance consulting,
- clinical governance, or
- external accreditation or certification audits.
Users must continue to exercise independent judgement and, where appropriate, seek advice from qualified professionals (including auditors, legal advisers, compliance specialists, and clinical or governance experts).
Decision-Support Tool Only
Cenaris is a decision-support platform designed to assist organisations by:
- organising and analysing uploaded documentation,
- mapping evidence against selected standards,
- highlighting potential gaps or areas requiring review, and
- supporting internal compliance planning and quality improvement activities.
All decisions, actions, interpretations, and reliance on platform outputs remain the responsibility of the user.
User Responsibility
By using Cenaris, you acknowledge and agree that:
- you remain fully responsible for compliance with all applicable laws, regulations, and standards;
- Cenaris outputs are one input into your broader governance and compliance processes; and
- Cenaris is used at your own risk, to the maximum extent permitted by law.
Cenaris Audit Money-Back Guarantee Terms and Conditions
Cenaris Pty Ltd
1. About the Guarantee
Cenaris offers eligible customers an Audit Money-Back Guarantee: pass your audit, or receive up to 12 months of your Cenaris subscription fees back.
The Guarantee is intended to provide additional confidence in Cenaris as a compliance management and audit-readiness platform. It does not mean that Cenaris acts as an auditor, certifier, legal adviser or compliance consultant, and it does not guarantee the conduct, decisions or professional judgement of an auditor or regulatory body.
The Guarantee is subject to all eligibility requirements, conditions, exclusions and claim procedures contained in these Terms.
2. Relationship with Other Terms
These Terms apply in addition to:
- the Cenaris Subscription Terms;
- the Cenaris Privacy Policy;
- any order form or service agreement entered into with the customer; and
- any other applicable Cenaris terms.
Where there is an inconsistency concerning the Audit Money-Back Guarantee, these Terms will apply to the extent of that inconsistency.
3. Definitions
In these Terms:
Audit means an independent audit conducted by an appropriately approved or accredited auditor against a compliance framework that is actively supported by the customer's Cenaris subscription.
Audit Date means the first day on which the auditor formally begins reviewing the customer's evidence, systems or operations for the relevant Audit.
Audit Evidence Snapshot means the evidence, mappings, analysis results, confidence ratings, gap status and other relevant account information recorded in Cenaris immediately before the Audit Date.
Confidence Rating means the evidence confidence score displayed by Cenaris for a particular piece of evidence at the time the Audit Evidence Snapshot is created.
Eligible Subscription Fees means the subscription fees actually paid to Cenaris for the period between the customer's subscription commencement date and the Audit Date, capped at 12 months.
Eligible Subscription Fees:
- include GST where GST was paid;
- take account of any discounts, credits, promotional periods or reduced pricing;
- do not include implementation fees, consulting fees, training fees, custom development fees, third-party fees or other non-subscription charges;
- do not include fees that were refunded, credited, waived, disputed or subject to chargeback; and
- do not include subscription periods occurring after the Audit Date.
Evidence Gap means a requirement for which no evidence has been mapped, evidence has not been analysed, or the platform identifies that the available evidence does not adequately address the requirement.
Failed Audit means a final written audit outcome in which the customer does not obtain, maintain or successfully complete the relevant certification, registration, verification or audit approval because of one or more unresolved non-conformities.
A customer will not be considered to have failed an Audit where:
- the auditor identifies only observations, recommendations or opportunities for improvement;
- the auditor requests clarification or additional evidence;
- a non-conformity is corrected and accepted within the ordinary audit or corrective-action period;
- the customer receives a provisional, conditional or otherwise successful audit outcome; or
- the finding does not prevent the customer from obtaining or maintaining the relevant certification, registration or approval.
Final Audit Report means the written final report issued by the auditor after the customer has had any ordinary opportunity provided by the auditor to correct factual errors, submit previously available information or respond to draft findings.
Operational Non-Conformity means a non-conformity arising from what the customer, its personnel, contractors or representatives did or failed to do in practice, rather than from a technical failure of the Cenaris platform.
Platform-Caused Non-Conformity means a non-conformity caused solely and directly by a material error or malfunction in the Cenaris platform that:
- existed before the Audit Date;
- was not reasonably apparent to the customer;
- caused Cenaris to incorrectly represent that a requirement had been adequately addressed;
- occurred despite the customer satisfying all conditions of the Guarantee; and
- directly resulted in the customer not passing the Audit.
Qualifying Audit Failure means a final Audit outcome in which the customer does not pass the Audit because of a Platform-Caused Non-Conformity.
4. Eligible Customers
The Guarantee is available only where:
- the customer holds an active, paid Cenaris subscription that expressly includes the Guarantee;
- the customer's subscription account is not overdue, suspended or in breach of the Cenaris Subscription Terms;
- the Audit relates to an organisation and compliance framework recorded in the customer's Cenaris account;
- the customer has used Cenaris for at least 60 consecutive days before the Audit Date, unless Cenaris agrees otherwise in writing;
- the Audit Date occurs within the first 12 months after the customer's initial paid subscription commenced;
- the Audit is conducted by an independent and appropriately approved or accredited auditor;
- the customer has disclosed the scheduled Audit Date to Cenaris before the Audit begins;
- the customer has complied with all requirements in section 5; and
- no exclusion in these Terms applies.
The Guarantee applies only to the first eligible Audit conducted during the Guarantee period unless Cenaris agrees otherwise in writing.
Free trials, demonstration accounts, complimentary subscriptions and unpaid accounts are not eligible.
5. Audit-Readiness Requirements
To qualify for the Guarantee, the customer must satisfy all of the following requirements immediately before the Audit Date.
5.1 Complete evidence mapping
The customer must have evidence mapped to 100% of the requirements within the scope of the Audit.
There must be no unmapped requirements or identified Evidence Gaps.
5.2 Evidence analysis
Every piece of evidence relied upon for the Audit must have been successfully analysed through Cenaris.
Evidence that has not been analysed will be treated as having a Confidence Rating of 0%.
5.3 Minimum confidence rating
Every piece of evidence relied upon for the Audit must have a Confidence Rating of at least 80%.
An average confidence rating of 80% is not sufficient. Each individual piece of evidence must meet the minimum threshold.
5.4 Current and accurate evidence
All mapped evidence must:
- be authentic, accurate and complete;
- relate to the customer's organisation;
- apply to the sites, services, registration groups and activities within the Audit scope;
- be current as at the Audit Date;
- have been properly approved where approval is required;
- reflect the customer's actual operating practices;
- be available to the auditor in its original or complete form; and
- not be misleading, altered, fabricated or presented out of context.
5.5 Correct account configuration
The customer is responsible for ensuring that its Cenaris account accurately records:
- its legal entity;
- organisational structure;
- operating locations;
- services and registration groups;
- applicable compliance modules;
- Audit scope;
- personnel and responsible roles; and
- any other information used by Cenaris to determine applicable requirements.
5.6 Resolution of platform warnings
Before the Audit Date, the customer must have reviewed and appropriately addressed all warnings, gaps, expired evidence notifications, low-confidence results, review reminders and corrective actions displayed by Cenaris.
5.7 Evidence snapshot
The customer must create or permit Cenaris to create an Audit Evidence Snapshot before the Audit begins.
Evidence added, replaced, remapped, reanalysed or materially changed after the Audit Date will not be considered when determining eligibility unless the evidence existed and was properly maintained before the Audit Date and was omitted because of a verified Cenaris platform malfunction.
5.8 Reasonable reliance
The customer must use Cenaris reasonably and in accordance with:
- platform instructions;
- onboarding materials;
- displayed warnings;
- implementation guidance;
- the applicable subscription terms; and
- reasonable compliance management practices.
The customer must not rely solely on a Confidence Rating where the platform has identified a qualification, limitation, warning or need for human review.
6. What the Guarantee Covers
The Guarantee covers a Qualifying Audit Failure caused solely and directly by a Platform-Caused Non-Conformity.
Examples may include:
- Cenaris incorrectly showing that a mandatory Audit requirement had been mapped when no mapping existed;
- a verified technical malfunction causing properly uploaded and analysed evidence to be unavailable during the Audit;
- Cenaris applying the wrong requirement set despite the customer correctly configuring its organisation and Audit scope; or
- a material platform analysis error that incorrectly assigned a Confidence Rating of at least 80% to evidence that plainly did not address the mapped requirement.
The existence of a platform error does not automatically qualify for a refund. The customer must demonstrate that the error directly caused the Qualifying Audit Failure.
7. What the Guarantee Does Not Cover
The Guarantee does not cover non-conformities, findings or Audit outcomes caused or contributed to by matters outside the reasonable control or responsibility of the Cenaris platform.
This includes the following.
7.1 Operational practices
The Guarantee does not cover Operational Non-Conformities, including:
- policies or procedures not being followed in practice;
- inconsistent implementation between sites or workers;
- missing operational records;
- services being delivered contrary to documented procedures;
- inadequate supervision or oversight;
- failure to complete required reviews;
- failure to implement corrective actions;
- inadequate incident, complaint or risk management practices;
- inadequate participant consultation or consent;
- failure to comply with reporting deadlines; or
- conduct occurring after evidence was uploaded or analysed.
7.2 Staffing and workforce matters
The Guarantee does not cover:
- worker screening failures;
- expired or missing licences, registrations or checks;
- inadequate qualifications or competencies;
- incomplete inductions;
- overdue training;
- inadequate staffing levels;
- employee, contractor or volunteer conduct;
- inadequate supervision;
- personnel files that are inaccurate or incomplete; or
- failure by personnel to understand or follow organisational requirements.
7.3 Evidence quality and accuracy
The Guarantee does not cover:
- false, inaccurate, misleading, incomplete or outdated evidence;
- evidence uploaded to the wrong requirement;
- documents that do not reflect actual practices;
- missing attachments, schedules, registers, records or approvals;
- evidence changed after it was analysed;
- evidence that applies to a different entity, site, service or period;
- information omitted from Cenaris by the customer;
- inaccessible, corrupted or password-protected files where the issue was not caused by Cenaris; or
- the customer's failure to provide mapped evidence to the auditor.
7.4 Auditor judgement and interpretation
The Guarantee does not cover:
- a reasonable difference of professional opinion between Cenaris guidance and an auditor;
- an auditor imposing an interpretation not reasonably apparent from the published framework;
- an auditor requesting evidence beyond the stated Audit requirements;
- subjective findings concerning organisational culture, effectiveness, quality or implementation;
- an auditor changing or expanding the Audit scope;
- inconsistent decisions between auditors;
- a customer's disagreement with an auditor's professional judgement; or
- findings that do not cause the customer to fail the Audit.
7.5 Changes outside Cenaris
The Guarantee does not cover failures caused by:
- legislative, regulatory or standards changes occurring after Cenaris last updated the applicable framework;
- unpublished regulatory expectations;
- emergency regulatory directions;
- changes to the Audit scope after the Audit Evidence Snapshot;
- third-party systems, integrations or service providers;
- internet, network, hardware or customer system failures;
- cyber incidents not caused by Cenaris;
- force majeure events; or
- circumstances beyond Cenaris' reasonable control.
7.6 Customer conduct
The Guarantee will not apply where the customer:
- provides false or misleading information to Cenaris or the auditor;
- conceals relevant information;
- interferes with the Audit;
- refuses to provide evidence reasonably requested by the auditor;
- fails to respond to draft findings;
- fails to use an available opportunity to correct a factual misunderstanding;
- fails to follow reasonable remediation guidance;
- manipulates evidence, mappings or confidence results;
- attempts to obtain a refund dishonestly or fraudulently;
- breaches the Cenaris Subscription Terms; or
- was aware of the relevant compliance problem before the Audit and did not take reasonable steps to address it.
8. Audit Outcomes That Do Not Qualify
A refund will not be available merely because the auditor:
- raises an observation;
- identifies an opportunity for improvement;
- makes a recommendation;
- requests additional evidence;
- requires a minor clarification;
- records a finding that does not prevent the customer from passing;
- requires a corrective action that is completed within the ordinary Audit process; or
- schedules a surveillance, follow-up or verification activity without determining that the customer failed the Audit.
The customer must have experienced a Qualifying Audit Failure.
9. Claim Process
To make a claim, the customer must submit a written claim to info@cenaris.com.au within 30 calendar days after receiving the Final Audit Report.
The claim must include:
- the customer's legal name and Cenaris account details;
- the Audit framework and scope;
- the auditor's name and accreditation details;
- the Audit Date;
- the complete Final Audit Report;
- any draft findings and customer responses;
- the specific non-conformity alleged to have been caused by Cenaris;
- an explanation of how the platform error directly caused the Qualifying Audit Failure;
- relevant screenshots, exports, correspondence and supporting records;
- permission for Cenaris to inspect the relevant Audit Evidence Snapshot, platform records and audit logs;
- written auditor notes, findings or correspondence that clearly identify the relevant non-conformity as arising from inadequate, missing or deficient documentation, rather than from the customer's conduct, service delivery, implementation, staffing, operational practices or any other matter outside Cenaris' reasonable control; and
- any other information reasonably required to assess the claim.
Claims submitted outside the 30-day claim period may be declined unless the customer demonstrates that exceptional circumstances prevented the claim from being submitted on time.
10. Assessment of Claims
Cenaris will assess each claim reasonably, objectively and in good faith.
Cenaris may:
- review relevant platform logs, evidence records and account activity;
- request further information from the customer;
- request clarification from the auditor, with the customer's authorisation;
- obtain an independent compliance or technical opinion;
- consider whether the customer met all eligibility conditions;
- consider whether another matter caused or contributed to the Audit outcome; and
- offer to correct a platform problem or support a prompt reassessment where this is reasonably available.
The customer must reasonably cooperate with the assessment process.
A claim will not be approved unless the auditor's written findings reasonably demonstrate that the relevant non-conformity was documentation-based and was not caused or materially contributed to by behavioural, operational, staffing, implementation or service-delivery factors outside Cenaris' reasonable control.
Cenaris will not unreasonably reject a claim solely because it is responsible for making the initial assessment. Where responsibility is genuinely disputed, Cenaris may refer the technical or compliance issue to an appropriately qualified independent reviewer.
11. Opportunity to Rectify
Where an alleged platform problem can reasonably be corrected before the auditor issues the Final Audit Report, the customer must allow Cenaris a reasonable opportunity to correct the problem.
Where the auditor permits corrective evidence, clarification or reassessment as part of the original Audit process, a refund will generally become payable only if:
- Cenaris is unable to correct the platform problem within the available reasonable timeframe; and
- the customer ultimately experiences a Qualifying Audit Failure.
This section does not require the customer to incur unreasonable additional Audit costs or accept an unreasonable delay.
12. Refund Amount
For an approved claim, Cenaris will refund the customer's Eligible Subscription Fees.
The maximum refund is the equivalent of 12 months of subscription fees.
Where the Audit occurs less than 12 months after the customer subscribed, the refund is limited to the subscription fees attributable to the period between:
- the commencement of the customer's paid subscription; and
- the Audit Date.
For example, where an eligible customer has been subscribed for four months before the Audit Date, the maximum refund is four months of subscription fees actually paid, not 12 months.
Where the customer paid annually in advance, the refund will be calculated on a pro-rata basis up to the Audit Date. The unused portion of an annual subscription will be dealt with under the applicable Subscription Terms and is not automatically part of the Guarantee refund.
Any refund will be returned to the original payment method where reasonably possible.
13. Effect of an Approved Refund
Unless otherwise agreed:
- an approved refund does not automatically terminate the customer's subscription;
- future subscription fees remain payable if the subscription continues;
- the Guarantee cannot be claimed more than once for the same customer, legal entity or Audit;
- the refund is limited to Eligible Subscription Fees; and
- the Guarantee does not reimburse auditor fees, consulting fees, remediation costs, lost revenue, penalties, legal expenses or other losses.
Nothing in this section limits any rights or remedies that cannot lawfully be excluded.
14. No Substitution for Professional Advice
Cenaris is a compliance management and audit-readiness technology platform.
Cenaris does not:
- conduct certification or registration audits;
- determine whether an organisation is legally compliant;
- provide legal advice;
- replace professional compliance advice;
- control the conduct or decisions of an auditor;
- supervise the customer's personnel; or
- verify that uploaded evidence is being followed in practice.
Confidence Ratings and AI-generated analysis are decision-support tools. They indicate the platform's assessment of the relationship between evidence and a requirement. They are not legal opinions, audit findings or certification decisions.
Customers remain responsible for their organisation's compliance, operations, personnel, evidence, representations and Audit preparation.
15. Australian Consumer Law
The Guarantee is provided in addition to any rights and remedies available under the Australian Consumer Law and any other applicable legislation.
Nothing in these Terms excludes, restricts or modifies any consumer guarantee, right, remedy or liability that cannot lawfully be excluded, restricted or modified.
Where Cenaris services come with statutory guarantees that cannot be excluded, the customer may be entitled to remedies independently of this voluntary Guarantee.
16. Changes to the Guarantee
Cenaris may amend these Terms from time to time.
Any material change will apply prospectively and will not reduce the Guarantee applicable to an eligible customer who subscribed while an earlier version was in effect, unless:
- the change is required by law;
- the change is reasonably necessary to prevent fraud or misuse; or
- the customer agrees to the change.
The version applying to a claim will generally be the version provided or made available when the customer commenced its eligible paid subscription.
17. Transfer and Resale
The Guarantee:
- applies only to the subscribing customer and legal entity;
- cannot be transferred, assigned, sold or exchanged;
- has no cash value except through an approved refund claim; and
- does not apply to resold, sublicensed or unauthorised access to Cenaris.
18. Governing Law
These Terms are governed by the laws of Victoria, Australia.
The parties submit to the courts of Victoria and any courts entitled to hear appeals from those courts, subject to any rights the customer may have under applicable consumer legislation to bring proceedings in another jurisdiction.
19. Contact
Questions and claims relating to the Audit Money-Back Guarantee may be submitted to:
A.C.N. 694 240 152 Pty Ltd (ACN 694 240 152)
Email: info@cenaris.com.au
Address: Level 4, 114 William St, Melbourne VIC 3000
Website: cenaris.com.au