Acceptable Use Policy
Version: 1.1 · Effective: 11 August 2026
This policy forms part of the OpsFlow Terms of Service. It applies to you and to everyone who uses the platform under your account.
Its purpose is narrow: to keep the platform lawful, secure and available for everyone, and to protect our carrier and provider relationships. We enforce it proportionately — we will almost always contact you before taking action.
1. General conduct
You must not use the platform to:
- break any law, or help anyone else break any law;
- store or transmit material you have no right to store or transmit;
- harass, threaten, defame or abuse any person;
- store or transmit malware, or anything designed to disrupt or damage software, hardware or data;
- gain unauthorised access to any system, account or data — including another provider’s tenant;
- probe, scan or test the security of the platform without our prior written consent (see clause 6);
- interfere with the platform’s operation, or place an unreasonable load on it;
- circumvent access controls, usage limits, rate limits or billing measurement;
- scrape or bulk-extract data other than through the export features we provide; or
- resell or provide the platform to a third party as a service, unless your Order Form says you may.
2. Communications — SMS, voice and email ⚠️
This is the section most likely to get you or us into trouble. Please read it.
2.1 You are the sender
When you send a message or make a call through OpsFlow, you are the sender at law, not us. The legal obligations sit with you. We provide the tool.
2.2 Consent — the Spam Act 2003 (Cth)
You must not send a commercial electronic message (SMS or email) unless:
(a) you have the recipient’s express or inferred consent; (b) the message clearly identifies you and includes accurate contact details; and (c) the message includes a functional unsubscribe facility that is honoured within 5 business days.
Operational messages to participants and workers about services you are actually providing are generally not “commercial electronic messages”, but marketing and re-engagement messages are. If you are unsure which category a message falls into, treat it as commercial.
2.3 Telemarketing — Do Not Call Register Act 2006 (Cth)
If you make marketing calls, you must wash your lists against the Do Not Call Register and observe permitted calling hours.
2.4 ⚠️ ACMA SMS Sender ID Register — in force from 1 July 2026
From 1 July 2026, sender IDs used in SMS to Australian recipients must be approved on the ACMA SMS Sender ID Register.
You must:
- only use a sender ID you are entitled to use;
- ensure any alphanumeric sender ID you use is registered; and
- tell us promptly if your registration status changes.
Messages using an unregistered sender ID may be blocked by carriers, and using a sender ID you are not entitled to use may be unlawful.
2.5 ⚠️ Call recording consent
Recording a telephone conversation is regulated by the Telecommunications (Interception and Access) Act 1979 (Cth) and by State and Territory surveillance devices legislation. The rules differ between States.
Before you enable call recording you must:
(a) notify all parties that the call is being or may be recorded, at the start of the call; (b) obtain any consent required in the relevant jurisdiction; (c) have a lawful basis under APP 3.3 to collect what is likely to be sensitive information when a participant is on the call; and (d) tell your own staff that calls may be recorded.
We provide the recording controls and the ability to pause recording. We do not and cannot verify that you have consent. If you have not taken advice on recording in your State, take it before turning recording on.
2.6 Prohibited communications use
You must not use the communications features to:
- send unsolicited bulk marketing;
- spoof, forge or misrepresent the origin of a call or message;
- send content that is misleading, deceptive, or that impersonates another organisation;
- conduct auto-dialling, robocalling or predictive dialling campaigns;
- send messages to numbers obtained from a purchased or scraped list;
- send premium-rate, gambling, adult, or high-risk financial promotional content;
- use numbers or sender IDs in a way that damages number reputation or triggers carrier filtering; or
- rely on the platform for emergency calls — the platform must not be used to contact emergency services.
2.7 Fair use
Communications volumes should be consistent with the operational needs of a disability service provider. Sudden, very large volume increases may trigger a review. We will contact you first unless the pattern indicates fraud or a compromised account.
2.8 Visibility of communications on business lines
Communications sent and received through the platform on your organisation’s business phone lines and mailboxes — including calls, call recordings, voicemail, SMS and email — form part of your organisation’s business records. They are stored against the relevant participant or contact record and are visible to your organisation’s authorised administrators and managers for oversight, quality and record-keeping purposes, including the record-keeping expected of NDIS providers.
(a) If you are an administrator: you must tell your staff, in writing and before they use the communications features, that communications on business lines are visible to administrators — and you must comply with any workplace surveillance or monitoring notice requirements that apply in your State or Territory.
(b) If you are a staff member: business lines are provided for your organisation’s work. They are not private, and must not be used for personal communications you intend to be private. Your acceptance of this policy records that you have been notified.
3. Data you put into the platform
3.1 You must have a lawful basis for every record you create, and have given the notices and obtained the consents required by the Australian Privacy Principles.
3.2 You must not upload:
- personal information you have no lawful reason to hold;
- payment card numbers, or other cardholder data, into free-text fields, notes or documents;
- credentials or API keys belonging to you or anyone else; or
- material subject to a suppression order or legal restriction on storage.
3.3 You are responsible for choosing appropriate retention and recording settings for your organisation.
4. Accounts and access
4.1 One login per person. Shared logins are not permitted — they defeat the audit trail your NDIS auditor will ask about.
4.2 Remove access for departed staff promptly.
4.3 Do not share links intended for a specific external person (such as a support worker task link) with anyone else.
4.4 Report suspected compromise to security@opsflow.net.au as soon as you become aware of it.
5. What we will do if this policy is breached
We take a graduated approach:
| Situation | What we do |
|---|---|
| Minor or likely accidental breach | Contact you, explain, ask you to fix it |
| Breach not fixed after notice | Restrict the affected feature, with notice |
| Serious breach — unlawful conduct, security risk, fraud, carrier risk | Suspend the affected feature or account immediately, then tell you why and work with you to restore it |
| Repeated serious breach | Terminate under clause 19.4 of the Terms |
We will always tell you what happened and what you need to do. We will not suspend an account over a billing dispute or a disagreement about interpretation of this policy.
6. Security research
We welcome responsible disclosure. If you believe you have found a vulnerability:
- email security@opsflow.net.au with enough detail to reproduce it;
- do not access, modify or delete data belonging to anyone else;
- do not run automated scanning against production without asking first; and
- give us a reasonable period to fix it before disclosing publicly.
We will acknowledge within 3 business days and will not pursue action against researchers who follow this process in good faith.
7. Changes
We may update this policy in accordance with clause 21 of the Terms of Service.