Programmio
Privacy policyTerms of service

Privacy Policy

Last updated: 26 July 2026


1. About this policy

This policy explains how we collect, hold, use, disclose and protect personal information.

Programmio ("Programmio", "we", "us", "our") is an Australian business, ABN 42 634 229 204. We provide software that sports clubs, schools and similar organisations use to manage their members, sessions, equipment, safety and compliance obligations.

This policy applies to:

  • the Programmio website at programmio.com.au
  • the club application provided to each organisation at their own address in the form organisation.programmio.com.au
  • any related email, notification and support channels we operate

We handle personal information in a way that is consistent with the Australian Privacy Principles (APPs) in the Privacy Act 1988 (Cth).

2. Our role, and your club's role

There are two different relationships to understand.

When you deal with us directly. If you visit our website, enquire about the platform, or are the person who administers a club's account and pays for it, we collect and hold your information for our own purposes as a business.

When you use a club's application. If you are a member, parent, coach, volunteer or official using an organisation's Programmio site, the information in that site belongs to and is controlled by that organisation. The organisation decides who is added, what is recorded, who can see it and how long it is kept. We hold and process that information on the organisation's instructions so we can provide the service to them.

If you want your record in a club's site changed or removed, contact the club first. We will also act on requests made to us directly, but in most cases we will need to refer you to the organisation, because they control the record. We will tell you if we do that.

Each organisation is responsible for its own privacy practices and may have its own privacy policy.

3. What personal information we collect

3.1 Website visitors and prospective customers

  • Name, email address, phone number, organisation name and any message you send us through an enquiry or contact form
  • Technical information described in section 9

3.2 Organisation administrators and billing contacts

  • Name, email address, mobile number, role within the organisation
  • Account credentials. We never see or store your password in readable form.
  • Billing records. We invoice organisations and are paid by bank transfer. We do not collect or store credit card or payment card details.
  • Records of support requests and correspondence with us

3.3 Members and other users of a club's application

The organisation decides what is recorded. It includes:

  • Name and email address
  • Mobile number
  • Birth month and birth year. We do not collect full date of birth.
  • Membership status, squad and session participation, and role within the organisation
  • Attendance, availability and responses to sessions, including any note or estimated arrival time you provide
  • Qualifications, accreditations, checks and their expiry dates
  • Incident reports, risk assessments and risk reports, described in section 4
  • Equipment, maintenance and damage records, where these name the person who reported, inspected or repaired an item
  • Feedback you submit to your organisation or to us
  • Records of actions taken in the application, including who performed an action and whether it was performed on behalf of another person
  • Messages and notifications sent to you through the application
  • Files or documents uploaded by or about you
  • Where a school chooses to use one, a student number issued by that school

We do not collect emergency contact details, medical records, dietary requirements, disability or access needs, or parent and guardian details.

3.4 Information about people who are not members

An incident, a piece of equipment damage or a safety report may involve someone who is not a member of the organisation, including a member of the public. Where that happens, the organisation may record that person's name and their role in what occurred.

If you are named in a record of this kind and want to know what is held about you, or want it corrected, contact the organisation. Section 18 explains how, and we will help you reach the right person.

3.5 Information we do not want

We do not ask for, and ask that you do not provide, information that is not needed for the organisation to run its activities. If we receive personal information we did not solicit and could not have collected lawfully, we will destroy or de-identify it where the law permits.

4. Sensitive information, incidents and safeguarding

Some categories of information are treated as "sensitive information" under the Privacy Act 1988, including health information, racial or ethnic origin, religious beliefs, sexual orientation and criminal record.

Programmio is not a medical system. Organisations are asked not to record medical conditions, treatment details, medications, diagnoses, medical certificates or clinical notes in the platform. Where an organisation can add its own questions to the incident report form, that instruction appears on the screen where those questions are created.

Incidents are the exception, and we treat them accordingly. When an incident occurs, an organisation records what happened, where and when, who was involved and in what capacity, and what was done about it. Where a person was injured, that record describes the injury and a photograph may be attached. Information describing a person's injury is health information under the Act.

The platform is built around that fact rather than around a hope that it will not happen:

  • Incidents involving injury or safeguarding are treated as sensitive by default. The person reporting can also raise the sensitivity of any report, and an administrator can adjust it when the report is triaged.
  • Access to a sensitive report is restricted to those in the organisation whose role requires it. It is not visible to the general membership.
  • Photographs attached to an incident have their own visibility controls, separate from the report itself.
  • Sensitive reports are used only for the organisation's incident management, safety, insurance and child safety obligations, and are not disclosed outside the organisation except as described in section 11.

Safeguarding. The platform allows an organisation to record a safeguarding concern. Where children are involved, these are the most sensitive records the platform holds, and they carry the tightest access restrictions in the system. They exist so that an organisation can meet its child safety obligations, and for no other purpose. We do not access them, analyse them, or use them for any purpose of our own.

Organisations should be aware that their obligations to retain records relating to child safety are their own, are set by the child safety framework that applies to them, and can run for decades. Those obligations continue after an organisation stops using Programmio, and section 17 explains what that means in practice.

Gender is recorded where an organisation's activities require it, for example where sessions, grades, groups or events are separated by gender, or where a governing body's rules require it for eligibility. It is used for eligibility, grouping and reporting, and is visible to organisation administrators and to those with a coaching or instructing role.

5. Children and young people

Some organisations using Programmio are schools or clubs with members under 18.

  • Where a member is under 18, we expect the organisation to have obtained consent from a parent or guardian before creating a record, and to have given that parent or guardian a copy of the organisation's own privacy notice.
  • We do not knowingly collect personal information directly from a child except through their organisation's account.
  • We do not use children's personal information for marketing, profiling or advertising. We do not sell personal information to anyone. We do not use it to train artificial intelligence models.
  • Incident and safeguarding records involving a person under 18 are subject to the access restrictions described in section 4.
  • Parents and guardians who want to see, correct or remove a child's record should contact the organisation in the first instance. Section 18 explains how, and we will help you reach the right person.

6. How we collect personal information

We collect information:

  • directly from you, when you sign up, complete your profile, respond to a session, report an incident, upload a document or contact us
  • from your organisation, when an administrator adds you, imports a member list, records an action on your behalf, or updates your record
  • from another member, where they name you in an incident report, a session record or a maintenance record
  • automatically, through your use of the website and application, as described in section 9

Where we collect information from someone other than you, we rely on the organisation to have told you that it is doing so.

7. Why we collect, hold and use personal information

We use personal information to:

  • create and administer accounts and control who can see what
  • provide the features the organisation has asked for, including session and group management, attendance, communications, equipment and maintenance records, incident and risk reporting, document distribution and compliance tracking
  • send you notifications, including email and web push notifications, about sessions, cancellations, broadcasts and compliance obligations that apply to you
  • verify your identity and keep the service secure, including preventing unauthorised access
  • keep records of actions taken in the system so that organisations can meet their own governance, safety and accountability obligations
  • diagnose faults, monitor performance and improve the service
  • invoice organisations and manage our commercial relationship with them
  • respond to enquiries and provide support
  • comply with our legal obligations

We do not use personal information for any other purpose unless you would reasonably expect it, you have consented, or the law requires or permits it.

8. Anonymity and pseudonymity

You can browse our public website without telling us who you are.

You cannot use a club's application anonymously or under a pseudonym. The application exists to identify members to their organisation, to record who attended what and who did what, and to allow organisations to meet safety and governance obligations. Identification is a necessary part of the service.

9. Automatically collected information and cookies

When you use the website or application we automatically collect:

  • IP address, browser type and version, operating system and device type
  • pages visited, features used, dates and times of access
  • error and diagnostic information when something goes wrong

We use cookies and similar browser storage only for purposes that are strictly necessary to provide the service: keeping you signed in, remembering your preferences, and keeping the service secure. We do not use advertising cookies, tracking cookies or third party analytics.

Push notifications. If you enable push notifications, your browser creates a subscription that we store so we can send you messages. Delivering a push notification requires us to send it through the push service operated by your browser or device vendor, which may be located overseas. You can turn push notifications off at any time in your browser or device settings, or in the application.

10. Automated decision making

We do not use automated decision making. No decision affecting your rights or interests is made by the platform without a person in your organisation making it.

Some features apply rules and raise alerts, for example flagging that a qualification has expired, that a compliance obligation is due, or that a proposed group or equipment booking conflicts with a rule set by the organisation or its governing body. These features alert and inform. They do not block, decide or select. A person in your organisation always makes the decision and can proceed regardless of the alert.

We do not use artificial intelligence to make decisions about individuals, and we do not use personal information held in the platform to train artificial intelligence models.

11. Who we disclose personal information to

Within your organisation. Your information is visible to people in your organisation according to the roles and permissions the organisation has set, and subject to the additional restrictions on sensitive records described in section 4. Different organisations using Programmio cannot see each other's information.

Our service providers. We use the following providers to run the platform:

ProviderPurposeWhere data is held
SupabaseDatabase, authentication, file storageStored in Sydney, Australia. Supabase Inc is based in the United States and its personnel may access data from outside Australia for support and maintenance.
VercelApplication hosting and content deliveryOur application code executes in Sydney, Australia. Static files such as images, stylesheets and scripts are served from Vercel's global network, which includes locations outside Australia. Static files contain no personal information. Vercel Inc is based in the United States.
ResendSending transactional and notification emailsUnited States
Browser and device push servicesDelivering push notificationsOperated by the vendor of your browser or device, typically outside Australia

Others. We may also disclose personal information:

  • to our professional advisers, where they are bound by confidentiality
  • where you have consented
  • where required or authorised by law, including to a court, tribunal or regulator
  • to lessen or prevent a serious threat to a person's life, health or safety, or to public health or safety
  • to a buyer or successor if the business is sold or transferred, in which case we will take reasonable steps to ensure the buyer handles the information consistently with this policy

We do not sell personal information, and we do not disclose it to third parties for their own marketing.

12. Overseas disclosure

Personal information in the platform is stored in Australia, and all of our application code, including request routing, executes in Australia.

Some of the providers listed in section 11 are based overseas or operate infrastructure overseas, which means personal information may be accessed from, transmitted through or processed in countries including the United States.

Before disclosing personal information to an overseas recipient we take reasonable steps to ensure the recipient handles it consistently with the Australian Privacy Principles, including through our contracts with those providers.

13. Direct marketing

We may send marketing communications to organisation administrators and to people who have enquired about the platform, about our services, features and pricing.

We do not send marketing to members of an organisation's application. Messages you receive there come from your organisation, not from us.

Every marketing message from us includes a way to unsubscribe. You can also opt out at any time by contacting us at programmio@outlook.com. Operational messages, such as invoices, security alerts and service interruptions, are not marketing and will continue.

14. Government related identifiers

We do not adopt a government related identifier, such as a driver licence, Medicare or tax file number, as our own identifier for you, and we do not use or disclose one except where the law permits.

Where a school chooses to record a student number, that number is issued by the school and is used only within that school's own site.

15. How we keep personal information secure

We take reasonable steps to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure. These include:

  • encryption of data in transit and at rest
  • authentication and role based access control, enforced at the database level so that each organisation's data is separated from every other organisation's data
  • additional access restrictions on sensitive records, as described in section 4
  • restricting our own access to what is needed to operate and support the service
  • automated daily backups and monitoring
  • keeping our software and dependencies up to date

No system can be completely secure. If you believe your account has been compromised, contact us immediately at programmio@outlook.com.

16. Data breaches

If we become aware of unauthorised access to, or disclosure or loss of, personal information, we will assess it promptly, take steps to contain and remediate it, and notify the affected organisation without undue delay so that the organisation can meet any obligations it has to its own members.

17. How long we keep information

While an organisation's account is active

We keep personal information for as long as we need it to provide the service.

When a member is removed or archived by their organisation, their record is retained so that historical attendance, incident, compliance and accountability records remain accurate and complete.

When an organisation stops paying or chooses to leave

Your data belongs to your organisation, and exporting it is your organisation's responsibility. The application provides exports of the member register, the equipment and asset register and incident history, available to organisation administrators at any time, including throughout the period below. We do not perform exports on an organisation's behalf.

The process is:

StageWhat happens
Payment missedWe notify the organisation's administrators. Nothing changes in the application.
30 days afterThe application may be moved to read only. Members can still sign in and read everything, and administrators can still run every export. Nothing new can be recorded.
A further 60 days after thatThe application may be removed and access ends.
After removalThe organisation's data may be permanently deleted.

An organisation that gives us notice that it is leaving follows the same path from the date of that notice.

A warning we will repeat at each stage. Records relating to incidents, injuries and child safety are usually subject to retention obligations that are far longer than any of the periods above, and those obligations belong to your organisation, not to us. Once we delete, the copy is gone. Export before you leave.

We may retain information beyond these periods where the law requires it, or where it is relevant to a dispute or claim that is on foot.

Other records

We keep invoicing and business records for at least seven years, as required by Australian tax law.

We may keep de-identified information indefinitely for analysis and service improvement. De-identified information is not personal information.

Backups

Our database is backed up daily. Deleted information persists in those backups for up to seven days after deletion, after which the backup containing it is no longer retained.

18. Accessing and correcting your information

You can view and update much of your own information in the application at any time.

You may also ask us for access to the personal information we hold about you, or ask us to correct it if it is inaccurate, out of date, incomplete, irrelevant or misleading. Write to programmio@outlook.com.

We will:

  • respond within 30 days
  • ask you to verify your identity before releasing information
  • not charge for making a request, though we may charge a reasonable cost for providing access where the request is substantial
  • tell you in writing, with reasons, if we refuse access or correction, and explain how to complain

Where the information is held in an organisation's application, we will normally refer your request to that organisation, because they control the record. We will tell you when we do that and who to contact.

19. Complaints

If you think we have mishandled your personal information, contact us first at programmio@outlook.com. Set out what happened and what you would like us to do.

We will acknowledge your complaint within 5 business days and give you a written response within 30 days.

If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner:

  • Online: oaic.gov.au
  • Phone: 1300 363 992
  • Post: GPO Box 5218, Sydney NSW 2001

20. Changes to this policy

We may update this policy from time to time. The current version is always published at programmio.com.au/privacy and shows the date it was last updated. That date is how you tell which version applies.

Where a change materially affects how we handle personal information, we will tell you before it takes effect, by some or all of: publishing the updated policy, adding a notice in the application, and emailing your organisation's administrators.

21. Contact us

Privacy enquiries: programmio@outlook.com Business: Programmio, ABN 42 634 229 204


Back to programmio.com.au
© 2026 Programmio. All rights reserved.