Housing Match

Specialist Disability Accommodation Provider Portal

Privacy Policy

Privacy Policy

How Housing Match collects, uses, discloses and protects personal and sensitive information, in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles.

Version  v1.3Effective  15 August 2026Classification  Customer Assurance Pack

Version

v1.3

Next review

15 November 2026

Document owner

Housing Match

Effective date

15 August 2026

Change history

VersionDateChange
v1.017 July 2026Initial comprehensive version prepared for the Customer Assurance Pack. Supersedes the interim Privacy Policy published July 2026.
v1.118 July 2026Updated to reflect the implemented Australian document storage architecture (AWS S3, Sydney region ap-southeast-2, SSE-S3 encryption, short-lived presigned links) and the completed automated regression testing. Added Australian document storage callout and data-residency amendments to Sections 5, 11 and 14.
v1.214 August 2026Reconciled Privacy Policy with current Housing Match data retention, privacy and governance controls; removed obsolete pre-publication wording; referenced the published Data Retention & Deletion Schedule.
v1.315 August 2026Added transparency information about automated matching, compatibility scoring and AI-assisted decision support, and clarified how personal information is used by these functions. New Section 10A addresses the automated decision-making transparency provisions commencing 10 December 2026.
1

Introduction

Housing Match is a technology platform that connects people with disability, housing providers, support coordinators, allied health professionals and health services to improve housing outcomes. To do this, we hold information about participants — including their disability, support needs, clinical reports and housing preferences — and information about providers — including their properties, residents, applications and financials.

We are committed to protecting the privacy of that information. This Privacy Policy explains, in plain English, what information we collect, why we collect it, how we use it, who we share it with, how we keep it secure, and how you can exercise your rights. It has been written to align with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

It describes only controls and features that Housing Match has actually implemented. Where a feature is planned but not yet built, we say so.

2

Scope

This Privacy Policy applies to:

  • All users of the Housing Match platform — participants, providers, support coordinators, specialist support coordinators, allied health professionals, family members, guardians, nominees and platform administrators.
  • All personal and sensitive information handled by Housing Match in the course of operating the platform.
  • The Housing Match website and platform available at housingmatch.com.au.

This policy does not apply to:

  • Third-party websites that Housing Match links to — those sites have their own privacy policies.
  • Services provided by other organisations — for example, a provider's own support services, a support coordinator's own practice, or a hospital's own clinical services. Each of those organisations is responsible for their own privacy practices.

Housing Match is a facilitating platform

Housing Match is not a disability support service, support coordination service, clinical service provider, tenancy advice service or housing allocation authority. We do not make placement decisions or provide professional advice. We are a facilitating technology platform only.
3

Definitions

The following terms have the meanings set out below in this Privacy Policy:

APPAustralian Privacy Principles, set out in Schedule 1 of the Privacy Act 1988 (Cth).
ConsentYour voluntary, informed and specific agreement to the collection, use or disclosure of your information. On Housing Match, consent is recorded as an event in a permanent, append-only ledger.
Consent ledgerThe platform's immutable record of every consent grant, withdrawal, amendment and reconfirmation — including who consented, on whose authority, and when.
De-identified dataInformation from which identifying details (such as name, NDIS number, contact details and date of birth) have been removed so that you cannot reasonably be identified.
Health informationInformation about your health, disability, or health services received. Health information is a type of sensitive information under the Privacy Act.
NDISNational Disability Insurance Scheme, established under the National Disability Insurance Scheme Act 2013 (Cth).
Overseas AI processingProcessing of information by an artificial intelligence provider located outside Australia. Housing Match uses overseas AI providers for compatibility assessment (de-identified data) and document extraction (raw documents, consent-gated).
ParticipantA person with disability who uses Housing Match to find suitable housing and supports, or whose profile is managed on their behalf by an authorised representative.
Personal informationInformation or an opinion about an identified or reasonably identifiable individual, as defined in the Privacy Act 1988 (Cth).
ProviderAn organisation that uses Housing Match to manage properties, vacancies, residents, applications and related information — for example, an SDA provider, SIL provider, or community housing provider.
Sensitive informationA category of personal information defined in the Privacy Act that includes health information, genetic information, and information about a person's racial or ethnic origin, political opinions, or sexual orientation. Sensitive information is given heightened protection.
Support coordinatorA professional who assists a participant to understand and implement their NDIS plan, and who may manage a participant's profile on Housing Match on their behalf.
We / us / ourHousing Match, the operator of the platform available at housingmatch.com.au.
You / yourThe individual or organisation whose information is handled under this Privacy Policy, whether you are a participant, provider, support coordinator, allied health professional, family member, guardian, or platform administrator.
4

Information we collect

Housing Match collects the following categories of information:

CategoryExamples
Account informationName, email address, phone number, date of birth, gender, role, contact preferences, and login credentials.
Profile informationHousing preferences, location preferences, accessibility needs, household preferences, support needs, interests and hobbies.
NDIS & funding informationNDIS plan details, funding type, support needs level, SDA eligibility and design categories (where voluntarily provided).
Health & disability informationDisability type, diagnoses, mobility, communication, behaviour, clinical and health support needs (where voluntarily provided or supplied by an authorised representative).
DocumentsNDIS plans, Functional Capacity Assessments, Occupational Therapy reports, Behaviour Support Plans, medical and hospital reports, risk assessments, hospital discharge summaries and other supporting documents uploaded at your discretion.
CommunicationsMessages, applications, notes and enquiries sent within the Housing Match platform.
Provider informationProperties, residents, vacancies, applications, financials, inspections and compliance records entered by provider organisations.
Usage & audit dataRecords of actions taken on the platform (documents accessed, consent changes, profile updates, AI processing) retained in the immutable audit log.

NDIS participant numbers

NDIS participant numbers are collected only where you or your authorised representative choose to provide them (for example, for SDA enrolment or NDIS funding verification). They are stored on the participant or resident record and access is restricted by role-based permissions. NDIS numbers are excluded from all AI processing — they are removed by the de-identification layer before compatibility and match prompts are built, and they are excluded from AI document extraction. They are not required for the core matching and application features.
5

Sensitive information

Under the Privacy Act, sensitive information includes health information and information about a person's disability. Sensitive information is given heightened protection. Housing Match collects sensitive information only where:

  • You voluntarily provide it — for example, by uploading a clinical document or entering disability information into your profile.
  • It is provided by an authorised representative acting on your behalf — such as a guardian, nominee, support coordinator or allied health professional — with appropriate authority.

Sensitive information held by Housing Match may include:

  • Disability type, diagnoses and support needs.
  • Clinical reports (OT reports, Functional Capacity Assessments, Behaviour Support Plans, medical and hospital reports).
  • Hospital discharge summaries and risk assessments.
  • NDIS plan details and funding information.

Heightened handling

Sensitive information is stored in private storage — never as permanent public web links. Uploaded participant documents are stored in AWS S3 in the Sydney region (ap-southeast-2) and remain in Australia, encrypted at rest using AWS server-side encryption (SSE-S3). Access requires authentication, the correct role, and the participant's consent, and is provided only through short-lived presigned links that expire after approximately five minutes. Every access is recorded in the immutable audit log with the stated purpose.
6

How information is collected

Housing Match collects information in three ways:

MethodWhat this means
Directly from youWhen you register, complete your profile, upload documents, send messages, or submit an application. You decide what information to provide.
From an authorised representativeWhere a support coordinator, allied health professional, guardian, nominee or family member creates or manages a profile on your behalf, with your consent or under their legal authority.
AutomaticallyWhen you use the platform, we record usage data and audit entries — such as pages viewed, documents accessed, and actions taken — to operate the platform securely and maintain the audit trail.

We do not purchase personal information from data brokers. We only accept information from third parties where appropriate consent or authority is in place.

7

Purpose of collection

We collect and use information for the following purposes:

  • To match participants with suitable housing and supports through the platform.
  • To generate AI compatibility assessments and plain-language match explanations (decision-support only).
  • To allow AI document extraction to pre-fill participant profiles from uploaded clinical documents (only with separate consent to overseas AI processing).
  • To process housing applications and manage placement workflows.
  • To facilitate communication between participants, providers, support coordinators and health services.
  • To maintain the security of the platform and detect fraud or unauthorised access.
  • To comply with our legal and regulatory obligations under Australian law.
  • To send service notifications where you have consented to receive them.
  • To operate and improve the platform.

We do not use your information for a purpose that is incompatible with the purpose for which it was collected, unless you consent or we are required by law.

8

Consent

Consent is central to how Housing Match operates. On our platform, consent is not a single on/off toggle — it is an event. Every consent grant, withdrawal, amendment and reconfirmation creates a new permanent record in an append-only consent ledger. The full history of who consented to what, when, and on whose authority is preserved and visible to the participant at any time.

Housing Match records the following types of consent separately, so each can be controlled independently:

Consent typeWhat it controls
Share with providersWhether your profile is visible to provider organisations for matching and applications.
Share with support coordinatorsWhether your information is shared with your support coordinator.
Share with allied healthWhether relevant health information is shared with allied health professionals.
Share with family / guardianWhether information is shared with a nominated family member or guardian.
Share with Housing Match adminWhether platform administrators can access your information for support and platform management.
MatchingWhether your profile appears in provider matching results.
Overseas AI processingWhether your documents may be sent to an overseas AI provider for document extraction (separate, explicit consent).
Direct provider contactWhether your direct contact details may be shown to a provider.
Marketing communicationsWhether you receive marketing or promotional communications.
Usage analyticsWhether your usage data contributes to platform analytics.
Research participationWhether your information may be used for research purposes.

Consent may be given on the following authority bases:

  • Self — the participant consents for themselves.
  • Guardian — a legally appointed guardian consents on the participant's behalf.
  • Nominee — an NDIS-appointed nominee consents on the participant's behalf.
  • Administrator — a legally appointed administrator consents on the participant's behalf.
  • Parent of a minor — a parent consents for a participant under 18.
  • Support coordinator (as agent) — a support coordinator consents on the participant's behalf, acting as their agent.
  • Other — another recognised authority, recorded with the relevant reference.

Every consent event is also recorded with a consent basis (how consent was obtained):

  • Written — a signed written consent.
  • Verbal — a verbal consent, noted on the record.
  • Guardian / Substitute Decision Maker — consent given under a formal guardianship or substitute decision-maker arrangement.
  • Digital Acceptance — consent given through the platform's digital acceptance flow (for example, selecting accept in the consent panel).

Each consent event records the event type that occurred — Consent Granted, Consent Updated, Consent Reconfirmed, Consent Withdrawn, Consent Expired, Provider Access Granted, Provider Access Revoked, or Identity Verified — together with the actor, their role and organisation, the legal document version in effect at the time, and the IP address of the request.

Withdrawing consent

You can withdraw any consent at any time. Withdrawal is recorded in the same permanent ledger as the original grant. Withdrawing consent does not affect the lawfulness of processing that occurred before the withdrawal. Once withdrawn, the relevant sharing or processing stops.
9

Legal basis for collection, use and disclosure

Housing Match collects, uses and discloses information on the following legal bases:

BasisHow it applies
Consent (APP 3, APP 6)The primary basis for collecting and using participant sensitive information and for sharing information with third parties.
Performance of a contractWhere necessary to provide the Housing Match service you have requested — for example, processing an application you have submitted.
Legitimate interestsWhere necessary for the platform's secure operation, fraud prevention, and the safety of participants and providers.
Legal obligationWhere required by or permitted under Australian law, including compliance with the Privacy Act, the NDIS Act 2013 (Cth), and the Notifiable Data Breaches scheme.
10

AI processing

Housing Match uses artificial intelligence (AI) for four purposes that involve participant or property information:

Most of these AI functions use de-identified data — no names, NDIS numbers, contact details or dates of birth leave Australia for these functions. Only document extraction, an optional opt-in feature, processes the original identifiable document, and only when the participant has given separate, explicit consent to overseas AI processing. Participants and their support coordinators can also choose to enter profile information manually instead of using AI document extraction.

AI useHow it worksDe-identification
Compatibility assessmentAnalyses participant and property data to score how well a participant matches a property and its existing residents.De-identified: name, NDIS number, contact details and date of birth are removed before processing. If de-identification verification fails, the AI call is blocked.
Match explanationGenerates a plain-language explanation of why a participant and property are a strong or moderate match, using the already-computed compatibility scores.De-identified: the same de-identification layer is applied before the prompt is built.
Document extractionReads uploaded clinical documents to pre-fill participant profile fields.Not de-identified at the document level — the raw, identifiable document is sent to the AI provider. This requires separate, explicit consent to overseas AI processing.
Executive & compliance reportingGenerates narrative summaries and recommendations for provider executive and compliance reports.Provider-level and aggregated operational data; these reports are not used to transmit individual participant clinical records.

AI is also used for an in-app assistant that answers user questions, and for internal business-development and knowledge-base tooling. These tools do not process participant clinical information.

The following protections apply to AI processing:

  • NDIS participant numbers are never captured by AI extraction — they are excluded from all AI prompts.
  • A dedicated de-identification layer removes names, NDIS numbers, contact details and dates of birth before compatibility and match-explanation prompts are built. If verification detects a prohibited identifier still present, the AI call is blocked.
  • Compatibility assessments and match explanations use de-identified data only.
  • Every AI action is recorded in the audit log with a flag indicating whether the data was de-identified.
  • Overseas AI document extraction requires separate, explicit consent that can be withdrawn at any time.
  • AI is a decision-support tool only. It does not independently make placement, funding or tenancy decisions. Where a Housing Match output informs such a decision, the relevant participant, provider or authorised professional considers the information before the decision is made.
  • Participants and their support coordinators can see and challenge AI-generated profile data.

An honest limitation

AI document extraction may not capture every clinical nuance in a document. Extracted data should always be verified against the source document by a qualified professional. Compatibility scores are recommendations, not guarantees.
10A

Automated decision-making and AI-assisted matching

From 10 December 2026, the Australian Privacy Principles (APP 1.7, APP 1.8 and APP 1.9) include requirements relating to computer programs that make decisions, or do things substantially and directly related to making decisions, about an individual where those decisions could reasonably be expected to significantly affect the individual's rights or interests. APP 1.9 assists with the interpretation of these provisions, including what constitutes making a decision and what may be a significant effect.

This section explains, in plain English, how Housing Match uses automated processing, automated matching and scoring, and AI-assisted decision support. Housing Match does not use solely automated decision-making for final housing, placement, funding or eligibility decisions.

What Housing Match does not do

Housing Match does not use computer programs to independently make final decisions about housing placement, provider acceptance, funding or support eligibility. Automated outputs do not independently determine these outcomes. Where a Housing Match output informs such a decision, the relevant participant, provider or authorised professional considers the information before the decision is made.

Automated functions that use personal information

Housing Match uses the following automated functions that use personal information and are substantially and directly related to housing decisions:

  • Compatibility scoring — Housing Match automatically compares relevant housing needs and preferences with property and household information to help identify potentially suitable housing options. Compatibility scores and rankings support housing discovery but do not determine whether a participant will be accepted for a property.
  • Mandatory requirement filtering — Housing Match may automatically remove a property from your matching results where verified property information conflicts with a mandatory housing requirement you have selected, such as wheelchair accessibility or a household gender requirement. This filtering helps avoid displaying properties that do not meet requirements you have identified as mandatory. It does not reject you from a provider, determine your eligibility for housing or support, or make a final placement decision. You can update these requirements in your profile.
  • AI Compatibility Assessment — Housing Match uses AI-assisted analysis of de-identified information about a participant, property and household to produce a compatibility assessment for human consideration. Identifying information such as names, contact details, NDIS participant numbers and dates of birth is removed before external AI processing. The assessment may identify compatibility considerations, risks and areas requiring further review, but does not determine whether a participant is accepted for housing.
  • Housing Match Finder — Housing Match automatically compares the housing requirements provided in a Finder request with available properties and may notify the requester when potentially matching properties become available. The requester decides whether to explore a property or request an introduction. Contact information is not shared with a provider through the Finder introduction process without the requester's consent.
  • Match explanations — Housing Match may use AI-assisted analysis to provide a plain-language explanation of an existing compatibility result. The explanation does not create or change the underlying compatibility score and does not determine eligibility or acceptance.

Kinds of personal information used

The personal information used by these automated functions may include:

  • Housing and location preferences;
  • Accessibility requirements;
  • Household preferences;
  • Disability-related information (such as disability type and support needs);
  • Support needs;
  • Mobility requirements;
  • SDA eligibility and design requirements;
  • Funding type, where used for matching; and
  • Relevant risk and support information.

Not all personal information collected by Housing Match is used by these functions. Information used internally for automated matching (such as preferences and requirements) is kept within Housing Match. For functions that use external AI processing — the AI Compatibility Assessment and match explanations — identifying information (names, contact details, NDIS participant numbers and dates of birth) is removed before information is sent for external AI processing. If de-identification verification fails, the AI call is blocked.

The role of human decision-making

Housing Match is a facilitating technology platform. We do not make placement, funding or tenancy decisions. Automated outputs do not independently determine a final housing placement, provider acceptance, funding or support eligibility decision. Where a Housing Match output informs such a decision, the relevant participant, provider or authorised professional considers the information before the decision is made. Providers and support coordinators can override or disregard any score, ranking or recommendation. Applications are never automatically approved or refused — all application status changes are made manually by providers or administrators.

Questioning automated results and raising concerns

If you believe that personal information used in matching is inaccurate, out of date or misleading, that a matching result or compatibility score is wrong or unfair, that you have been filtered from a housing opportunity in error, or you wish to question an automated result or request human review, you can:

  • Correct your personal information through your profile or Account Settings (see Section 15);
  • Contact Housing Match using the details in Section 19; or
  • Make a complaint under Section 16.

We will respond within 30 days. If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au or on 1300 363 992.

11

Overseas disclosure

Some information handled by Housing Match is processed outside Australia. We are transparent about this, in line with APP 8.

Housing Match's primary application, database and backups are hosted on the Base44 managed cloud platform. Uploaded participant documents are stored separately in AWS S3 in the Sydney region (ap-southeast-2) and remain in Australia — Base44 stores only document metadata and audit information, never the file contents. The following overseas processing also occurs:

Not every AI function transmits identifiable information overseas. Routine compatibility assessment and match explanation send de-identified data only — no names, NDIS numbers, contact details or dates of birth leave Australia for these functions. Only the optional document extraction feature transmits an identifiable document overseas, and only when the participant has given separate, explicit consent. The table below sets out what is sent for each function.

RecipientWhat is sent overseasDe-identified?
Overseas AI provider — compatibility assessment (such as OpenAI, Google or Anthropic models)De-identified participant and property data for compatibility scoring.Yes — names, NDIS numbers, contact details and dates of birth are removed before processing.
Overseas AI provider — match explanation (such as OpenAI, Google or Anthropic models)De-identified participant and property data, plus already-computed compatibility scores.Yes — the same de-identification layer is applied.
Overseas AI provider — document extraction (such as OpenAI, Google or Anthropic models)Raw clinical documents uploaded for AI-assisted profile extraction.No — the raw, identifiable document is sent. Requires separate consent.
Google Analytics 4 (website measurement)Page views and platform events (see Section 13). IP addresses are anonymised.No personal names or health information are sent. Event parameters may include internal pseudonymous identifiers (for example, a property ID).
Email service (Resend)Email addresses and email content for transactional platform emails to registered users.N/A — limited to information necessary to deliver the email.

The platform's AI integration supports models from multiple overseas providers — including OpenAI (GPT), Google (Gemini) and Anthropic (Claude). The specific model used for a given task may be selected automatically by the platform integration. Where information is sent overseas, Housing Match takes reasonable steps to ensure the overseas recipient handles it in accordance with the APPs. For AI document extraction, this includes obtaining your separate, explicit consent before any raw document is processed overseas, and recording the processing in the audit log. You can choose not to use AI document processing — you may enter profile information manually or have your support coordinator or allied health professional enter it on your behalf.

12

Cookies

Housing Match uses cookies and similar technologies to keep you signed in and to measure how the platform is used. We do not use third-party advertising cookies or cross-site tracking cookies, and we do not sell information derived from cookies to any third party.

Specifically, Housing Match uses:

Cookie typePurposeThird party?
Authentication and session tokensKeep you signed in securely while using the platform.No — set by Housing Match.
Essential functionalityRemember your preferences within the platform (such as your selected view).No — set by Housing Match.
Google Analytics 4 measurement cookiesFirst-party website measurement — page views and platform events (see Section 13).Yes — set by Google on the housingmatch.com.au domain; IP addresses are anonymised.

Managing cookies:

  • You can control or delete cookies through your browser settings. Most browsers allow you to refuse third-party cookies and to delete existing cookies.
  • Blocking Google Analytics cookies will not stop you from using the platform, but it will prevent your activity from being counted in our website measurement.
  • Our Google Analytics configuration does not enable advertising features, demographic reporting, Google Signals, or User ID linking.
13

Analytics

Housing Match uses two analytics systems to understand how the platform is used and to improve it:

SystemWhat it collectsWhere it is stored
Internal analytics (first-party)Page views, page categories, time on page, device type, referrer, and platform events — linked to a visitor identifier stored in your browser.Housing Match's own database (PageView, VisitorSession and AnalyticsEvent records). Not shared with any third party.
Google Analytics 4 (third-party)Page views and custom events such as property views, searches, applications submitted, messages sent, and AI assessments generated.Stored by Google. IP addresses are anonymised (anonymize_ip is enabled).

For Google Analytics 4 specifically:

  • IP addresses are anonymised at the network edge before being used by Google.
  • User ID linking is not enabled — GA4 is not connected to your Housing Match account identity.
  • Advertising features, demographic reporting and Google Signals are not enabled.
  • Event parameters may include internal pseudonymous identifiers (such as a property ID or participant ID), but never names, contact details or health information.
  • Google Analytics retention is governed by Google's default GA4 settings; configuring a defined retention period is on our security roadmap.

We do not sell analytics data. You can control whether your usage contributes to our internal analytics through the 'Usage analytics' consent type. Controlling Google Analytics cookies is covered in Section 12.

14

Data security

Housing Match protects information using a defence-in-depth approach — multiple layers of security so that no single failure exposes information. The following controls are implemented and verified today:

  • Secure login — every account requires email and password; every page is access-controlled.
  • Role-based permissions — six user roles, each seeing only relevant data; admin actions re-checked on the server.
  • Australian document storage — uploaded participant documents are stored in AWS S3 in the Sydney region (ap-southeast-2) and remain in Australia; Base44 stores only document metadata and audit information, never the file contents.
  • Encryption — documents are encrypted in transit using HTTPS/TLS and at rest using AWS server-side encryption (SSE-S3).
  • Secure upload and download — documents are uploaded and downloaded directly to AWS using short-lived presigned links that expire after approximately five minutes; documents never use public URLs.
  • Authorised document access — a fresh access check (identity, role, organisation and participant consent) occurs before each download link is issued; users can only access documents they are authorised to access and cannot provide or manipulate arbitrary storage keys; deleted documents cannot be downloaded.
  • Immutable audit logging — every sensitive action recorded in a permanent, append-only log, including secure upload link generation, upload confirmation, secure download link generation, deletion, failed access attempts, failed upload confirmation and administrative actions.
  • Consent history ledger — every consent event recorded permanently.
  • Organisation data separation — each provider sees only their own properties, residents, applications and financials, resolved through providerDataScope and platform record-level security.
  • Secure AI processing — de-identification for compatibility; consent-gated overseas processing for document extraction.
  • Encryption in transit — all data between your browser and the platform is encrypted using HTTPS/TLS.
  • Immutable agreement acceptance — legal document acceptance is version-locked and permanently recorded.

Backups and disaster recovery:

  • Application data, the database, document metadata and audit information are hosted on the Base44 managed cloud platform, which manages infrastructure backups.
  • Uploaded participant document files are stored separately in AWS S3 in the Sydney region (ap-southeast-2), encrypted at rest using AWS server-side encryption (SSE-S3).
  • Formal disaster-recovery testing, and published recovery time and recovery point objectives (RTO/RPO), have not yet been completed. These are on our security roadmap.

Australian document storage

Uploaded participant documents are stored in AWS S3 in the Sydney region (ap-southeast-2) and remain in Australia. Document files are encrypted at rest using AWS server-side encryption (SSE-S3) and in transit using HTTPS/TLS. Documents are uploaded and downloaded directly to AWS storage using short-lived presigned links that expire after approximately five minutes — documents never use public URLs. A fresh access check (identity, role, organisation and participant consent) occurs before each download link is issued. Storage keys are random and do not contain participant names, NDIS numbers, dates of birth or addresses. Presigned URLs are not stored in entities, logs or analytics. Housing Match records audit events for secure upload link generation, upload confirmation, secure download link generation, deletion, failed access attempts, failed upload confirmation and administrative actions. The Australian document storage pathway has passed end-to-end integration and automated regression testing and is progressing through a controlled administrator pilot before broader provider release.

What we do not claim

Housing Match has not completed ISO 27001, SOC 2, IRAP assessment or independent penetration testing. Backups, disaster recovery and infrastructure monitoring are managed by the hosting platform; independent evidence has not yet been provided. Required TOTP multi-factor authentication is implemented for platform and organisation administrators. These roadmap items are not presented as current functionality. See our Trust Centre for the current assurance position.
15

Access and correction

You have the right to:

  • Request access to the personal and sensitive information we hold about you.
  • Request correction of information that is inaccurate, out of date, incomplete, irrelevant or misleading.
  • Request deletion of your information, subject to legal retention requirements (see Section 17).
  • Withdraw consent at any time.
  • Obtain a copy of your information in a structured, commonly used format.

To make an access or correction request, contact us using the details in Section 19. We will respond within a reasonable period, and in any event within 30 days. If we refuse access or correction, we will tell you why and explain how you can complain.

16

Complaints

If you believe Housing Match has mishandled your information, or you are not satisfied with our response to a privacy enquiry, you may make a complaint. We take complaints seriously and will investigate and respond promptly.

To make a complaint:

  1. Contact Housing Match first using the details in Section 19. We will acknowledge your complaint and investigate.
  2. If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (OAIC). The OAIC can be contacted at www.oaic.gov.au or on 1300 363 992.
17

Data retention

We retain your information only for as long as necessary to provide Housing Match services, maintain the audit trail and consent ledger, resolve disputes, and comply with our legal obligations. Our Data Retention & Deletion Schedule sets out the retention period for each category of data and is available at housingmatch.com.au/data-retention-schedule.

Key retention periods include:

  • Participant profiles and documents — retained for the duration of your engagement plus 7 years, or until consent is withdrawn (documents deleted within 30 days of withdrawal).
  • Applications and referrals — 3 years after resolution; unsuccessful applications are anonymised after 3 years.
  • Audit log entries — 7 years (anonymised; no sensitive health information retained).
  • Consent events — 7 years after withdrawal (retained as a legal record of consent history).
  • Communications and messages — 3 years.
  • Analytics and page views — 2 years (aggregated, de-identified).

When you request deletion of your information:

  • Clinical documents in private storage are deleted and signed access links are revoked; documents are deleted within 30 days of a deletion request or consent withdrawal.
  • Profile information is removed or de-identified.
  • Audit log entries and consent history records are retained for the legal retention period in anonymised form — they contain no sensitive health information, only pseudonyms, timestamps, field-name references and the stated purpose of each action.
  • We may retain minimal information (such as your email address) where required to comply with legal obligations or to prevent fraud.

Data Retention & Deletion Schedule

Our Data Retention & Deletion Schedule sets out the full retention period for each data type and the secure deletion procedures that apply when retention periods expire or consent is withdrawn. It is available at housingmatch.com.au/data-retention-schedule. Participants can request deletion of their data at any time through their dashboard or by contacting Housing Match support; requests are processed within 30 days.
18

Notifiable Data Breaches

Housing Match complies with the Notifiable Data Breaches (NDB) scheme under Part IIIC of the Privacy Act 1988 (Cth). If we experience a data breach that is likely to result in serious harm to one or more individuals, we will:

  1. Assess the breach as soon as we become aware of it, using the audit log to identify affected records and individuals.
  2. Contain the breach and take steps to limit its impact.
  3. Notify affected individuals as soon as practicable, where required, with information about the breach, the steps we have taken, and what you can do to protect yourself.
  4. Notify the Office of the Australian Information Commissioner (OAIC) where required by the NDB scheme.

Our data breach response procedures are further described in our Data Breach Response Plan. Formal incident response tabletop testing is planned as part of our security roadmap.

19

Contact details

For privacy enquiries, consent withdrawal, data access or correction requests, or complaints, please contact:

Housing Match

Email: hello@housingmatch.com.au

Web: housingmatch.com.au/contact

We will respond to privacy requests within 30 days. If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au or on 1300 363 992.

20

Version history

This Privacy Policy is version-controlled. The current version is published on the Housing Match Trust Centre. When this policy is updated, a new version is recorded with an effective date and a summary of changes.

VersionDateSummary of changes
v1.017 July 2026Initial comprehensive version prepared for the Customer Assurance Pack. Supersedes the interim Privacy Policy published July 2026.
v1.118 July 2026Updated to reflect the implemented Australian document storage architecture (AWS S3, Sydney region ap-southeast-2, SSE-S3 encryption, short-lived presigned links) and the completed automated regression testing. Added Australian document storage callout and data-residency amendments to Sections 5, 11 and 14.
v1.214 August 2026Reconciled Privacy Policy with current Housing Match data retention, privacy and governance controls; removed obsolete pre-publication wording; referenced the published Data Retention & Deletion Schedule.
v1.315 August 2026Added transparency information about automated matching, compatibility scoring and AI-assisted decision support, and clarified how personal information is used by these functions. New Section 10A addresses the automated decision-making transparency provisions commencing 10 December 2026.

Document owner: Founder, Housing Match. Next scheduled review: 15 November 2026, or earlier if there is a material change to platform functionality or applicable law.

Housing Match — Privacy Policy v1.3

This Privacy Policy describes only controls and features that Housing Match has implemented and verified. It does not constitute legal advice. © Housing Match 2026.