AusChildSupport

Legal Information

Privacy Policy

Australian Child Support Calculator

auschildsupport.com.au

Version 2.4 | Effective Date: 27 July 2026 | Last Updated: 5 August 2026

Calculator-only use can stay anonymous

Using the free calculator does not require an account, a name, or direct personal contact details.

Firm contact requests require explicit consent

We only disclose Contact Request details to a Client Firm when you submit a firm-owned Contact Request and give clear consent.

Rights requests go to one inbox

Access, correction, withdrawal, and complaint requests are handled via privacy@auschildsupport.com.au.

At a glance

This policy explains how ChildSupport Direct collects, uses, discloses, stores, and protects personal information across the free calculator and firm-owned Contact Requests.

The document is organised as a readable legal reference: start with the quick facts, use the section navigation to jump to a topic, and contact us if you want to access, correct, or delete information we hold about you.

Business name
ChildSupport Direct
ABN
27 925 351 253
Service
Australian Child Support Calculator

1. About This Policy and Our Services

This Privacy Policy explains how ChildSupport Direct (trading as Australian Child Support Calculator) collects, uses, discloses, stores, and protects your personal information across all of our services:

  • Free Calculator Tool — an online child support estimator that does not require you to create an account or submit personal information.
  • Firm Contact Requests — optional firm-owned request forms, where available, that let you ask a named Client Firm to contact you. AusChildSupport does not match, screen, assign, or chase consumer legal matters from the Platform Site.

We apply the commitments in this policy across the services described above. Where the Privacy Act 1988 (Cth) and the APPs apply, they govern that handling; we offer the stated privacy contact processes in any event.

2. How Firm Contact Requests Work

When a firm-owned page offers a Contact Request and you choose to submit it, the following steps occur:

Step 1
Firm-Owned RequestYou choose a Contact Request on a named Client Firm page or branded calculator experience. Whether reached through an AusChildSupport-hosted firm subdomain or an approved exact custom hostname, the page and request remain operated by AusChildSupport for that named firm. The Platform Site contact page is for support, not legal advice intake.
Step 2
Form and ConsentThe form explains which firm will receive your details and what information will be shared. Pre-ticked consent boxes are not used.
Step 3
Secure Firm DisclosureAfter submission, the selected Client Firm can access the request details through authenticated firm admin access and audited export-token workflows.
Step 4
Direct Firm Follow-UpThe Client Firm decides whether and how to contact you. From that point, their privacy policy governs how they handle their copy of your information.
Important: We only disclose Contact Request details to the selected Client Firm after explicit, informed consent. You may withdraw consent before disclosure by emailing privacy@auschildsupport.com.au.

No platform matching: AusChildSupport does not route Platform Site visitors into a lawyer-matching queue. If a firm does not respond to a Contact Request, contact that firm directly.

3. Information We Collect

We collect personal information directly from you when you use the calculator, submit a firm-owned Contact Request, or contact support. We only collect information that is reasonably necessary for the purposes described in this policy (APP 3).

3.1 Firm Contact Requests

CategoryInformation CollectedPurpose
Contact DetailsOptional first name and verified email address for an ordinary Contact Request. The verified email is the only contact destination collected in that request.Email verification; selected firm follow-up after consent
Financial InformationGross or approximate income and employment status used by the calculator, if providedChild support calculation. Raw financial information is not included in an ordinary Contact Request.
Family & Child DetailsNumber of children, care arrangements, and relationship status used by the calculatorChild support calculation. Raw calculator inputs are not included in an ordinary Contact Request.
Child-related Review FactorsOptional selected factors and structured follow-up choices about a child's care, location, schooling, costs, medical or disability support needs, or financial resourcesIncluded only when you submit a Firm Contact Request, to provide intake context to the named Client Firm. Medical or disability information requires separate consent.
Consent RecordConsent timestamp, IP address at time of consentVerification and audit trail as required by APP 3

3.1A Conflict-Check Details Handoff

This optional capability is not enabled by default. If it is enabled for a particular Client Firm after the required agreement, legal/privacy review, approved firm privacy-policy URL, operational approval, and tenant activation, the collection notice shown before submission will identify that firm, the two names collected, and the short retention period. After an eligible Contact Request is already complete, you may then be offered the separate optional handoff. It collects only your full legal name and the other party's full legal name so that the named Client Firm performs its own conflict check. AusChildSupport does not perform or record the conflict check.

Skipping this optional handoff does not affect the Contact Request you already submitted. The firm may ask you for the names later. Do not provide a case narrative, documents, dates of birth, addresses, case numbers, or other information through this handoff.

For access, correction, deletion, or a privacy complaint about the platform copy, email privacy@auschildsupport.com.au. Platform access ends exactly 14 days after submission and the encrypted copy is deleted during the following daily retention run, within 24 hours. The firm handles its received copy under its own privacy policy.

3.2 Support and Professional Enquiries

The support or professional-enquiry form may collect your name and email address, the selected request category, and any firm or business name, website, role, area of interest, planned traffic source, or message that the form asks for and you choose to provide. The application sends the submission through our email-delivery path. Please do not include documents, detailed case narratives or sensitive information unless we ask for it.

3.3 Technical and Usage Data

CategoryInformation CollectedPurpose
Technical DataIP address, browser type and version, device type, operating systemSecurity, analytics, cross-border disclosure compliance
Usage DataPages visited, calculator interactions, session duration, referring URLService improvement; aggregated analytics only
CookiesSee Section 9 for a full cookie tableSite functionality; analytics (with consent)

3.4 Administrator Accounts (Law Firm Users)

If you register as a law firm user of our platform, we collect your name, work email address, and a one-way password hash. We do not store passwords in plain text or in reversibly encrypted form. This information is used solely to authenticate your account and manage your access to firm platform features.

3.5 Sensitive Information

Sensitive Information — Separate Consent Required

Sensitive information under the Privacy Act includes health information and criminal-record information, among other listed categories. Family-violence information is not automatically a separate statutory category, but it may reveal sensitive information and we handle it as high-risk safety information. For a Contact Request, we require separate explicit consent for medical or disability information and family-violence safety information.

Sensitive information is disclosed to a Client Firm only where you voluntarily include it in a firm-owned Contact Request and give explicit consent for that disclosure.

Recommendation: If your matter involves sensitive circumstances, we suggest describing them in general terms only (e.g., “safety concerns”) until you are in direct contact with a lawyer you have chosen to engage.

3.6 Calculator-Only Use — Anonymity

You may use the child support calculator without providing any personal information. Calculator inputs and results are used only to display your estimate in-browser and are NOT stored or retained after your session ends. If you choose not to submit a Contact Request or support form, no direct contact details are collected.

3.7 Unsolicited Information

If we receive personal information we did not request (for example, if someone emails us unsolicited sensitive details), we will assess whether we could have collected it under APP 3. If not, we will destroy or de-identify it as soon as practicable, unless we are required by law to retain it.

4. Why We Collect This Information

We collect personal information for the following purposes where it is reasonably necessary for one or more of our functions or activities. Where the APPs apply, APP 3.2 applies to personal information other than sensitive information and APP 3.3 applies to sensitive information.

  • Providing child support estimate calculations.
  • Facilitating firm-owned Contact Requests where you explicitly submit one to a selected Client Firm.
  • Transferring optional Conflict-Check Details to the named Client Firm after a Contact Request is complete, where you separately acknowledge that purpose.
  • Processing and verifying payments via Stripe.
  • Communicating with you about your inquiry or purchase.
  • Meeting legal, regulatory, tax, and reporting obligations.
  • Improving calculator accuracy and website performance using aggregated, de-identified data only.

What happens if I don’t provide information? Use of the calculator requires no personal information. However, if you submit a firm-owned Contact Request or support form, we need enough contact information to process that request. If you do not provide optional Conflict-Check Details, the completed Contact Request is unchanged and the Client Firm may request the names directly later.

5. How We Use and Disclose Your Information

5.1 Consent for Firm Contact Requests

We will NOT share your personal information with a Client Firm without your explicit, informed consent. Consent is obtained as follows:

  • On a firm-owned page or branded calculator, you may be offered the option to ask that firm to contact you.
  • A consent form will be displayed, clearly explaining what information will be shared, which firm will receive it, and for what purpose.
  • You must tick a consent checkbox with language that clearly authorises disclosure to the named Client Firm for follow-up about your request.
  • Pre-ticked checkboxes are not used. Consent must be an affirmative act.
  • Your consent timestamp and IP address are recorded as an audit trail.
  • You may withdraw consent before your information is shared with the selected Client Firm by emailing privacy@auschildsupport.com.au.

5.2 What Client Firms Receive

StageInformation Disclosed
Submitted Contact RequestThe verified email address, optional first name, Result Summary, selected Review Factors and Complexity Indicators, permitted structured Complexity Details, consent and Safe Contact records, firm-source attribution, and minimum operational metadata collected through the firm-owned form.
Conflict-Check Details HandoffYour full legal name and the other party's full legal name, only when you separately choose the optional post-submission handoff. The named Client Firm receives the names to perform its own conflict check. AusChildSupport does not perform or record the conflict check.
Platform Support RequestNot disclosed to Client Firms. Support and professional-enquiry submissions are sent to AusChildSupport through its email-delivery path for the selected support, privacy, correction, accessibility, or professional-enquiry purpose.

5.3 Client Firm Obligations — Data Sharing Agreement

Before a Client Firm can access Contact Request details, it must accept the current Data Sharing Agreement. Under this agreement, firms are contractually required to:

  • Handle your information in accordance with the Australian Privacy Principles.
  • Use your information only for the purpose of responding to your Contact Request.
  • Not sell, resell, reroute, broker, or otherwise pass your Contact Request data to another business as a lead.
  • Not use your information for unrelated marketing without your separate consent.
  • Not use Contact Request data for model training, profiling, or unrelated product development.
  • Delete your information if you do not proceed to engage their services.
Important limitation: Once we disclose information to a Client Firm, the firm holds a separate copy and is responsible for that copy under its applicable privacy, professional and record-keeping obligations. We cannot monitor or audit its day-to-day practices. If you have concerns about how a lawyer or firm has handled your information, contact: (a) the firm directly; (b) the Law Society in your state or territory; or (c) the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au.

5.4 Use of Information for Service Improvement

We may use aggregated, de-identified data to improve our calculator and services. This data cannot be linked back to any individual. We do not use identifiable personal information or Contact Request payloads for service improvement, model training, profiling, or unrelated marketing.

6. Third-Party Service Providers

This register identifies providers that may handle information for currently supported AusChildSupport services. A provider is listed only for the feature and data categories described below; listing does not mean every provider is used for every visitor or Client Firm. We do not sell personal information to data brokers or unrelated third parties for commercial purposes. Firm Contact Request data is not sold, resold, rerouted, brokered, or used as a paid lead resale product.

We may also disclose information to professional advisers, insurers, government agencies, regulators, courts, or law enforcement where reasonably necessary or legally required.

6.1 Product Feature Data Flows

FeatureData FlowProviders Involved
Free calculatorCalculator inputs and results are processed in your browser to display an estimate. If you do not submit a Contact Request, email a result summary, or use analytics cookies, these inputs are not intentionally stored by us.Vercel hosting; Google Analytics and Microsoft Clarity only after analytics consent.
Firm Contact RequestsThe verified email address, optional first name, Result Summary, selected Review Factors and Complexity Indicators, permitted structured Complexity Details, consent and Safe Contact records, firm-source attribution, and minimum operational metadata are stored in the application database, rate limited, and available to authorised firm users through authenticated in-app access. Firm notification emails contain no Contact Request details. The data is retained under the Contact Request retention rule.Vercel hosting, Neon/PostgreSQL-compatible database, Upstash Redis, Resend, selected Client Firm, and Vercel Domains API where a firm uses a custom domain.
Conflict-Check Details HandoffThis optional capability is not enabled by default. If it is enabled for a particular Client Firm after the required agreement, legal/privacy review, approved firm privacy-policy URL, operational approval, and tenant activation, you may separately and optionally provide your full legal name and the other party's full legal name after an eligible Contact Request is complete. The named firm uses the names for its own conflict check. AusChildSupport stores only an encrypted copy for the short handoff period and does not perform or record the conflict check.Vercel hosting, Neon/PostgreSQL-compatible database, Resend for a neutral firm notification, and the named Client Firm.
Result summary emailThe result summary PDF is generated on the server from the submitted calculator data and emailed to the address you provide. Download-only summaries are returned directly to the browser.Vercel hosting, Upstash Redis for email rate limiting, and Resend for email delivery.
Client Firm administrationFirm profile, tenant configuration, custom-domain status, admin account data, MFA data, audit activity, Contact Request lifecycle records, exports, and subscription identifiers are stored for platform administration and security.Vercel hosting, Neon/PostgreSQL-compatible database, Upstash Redis, Stripe, Resend, and Vercel Domains API.
Analytics and product improvementWith analytics consent, usage events, pages visited, device/browser data, pseudonymous identifiers, and interaction/session replay data are sent to analytics providers. We also use aggregated or de-identified operational metrics.Google Analytics and Microsoft Clarity. Vercel Analytics is not implemented in the current production codebase.

6.2 Subprocessor and Provider Register

Register last reviewed: 1 August 2026. The register is maintained from typed application data, but repository source does not establish deployed provider configuration, contractual role, processing region, or provider retention. Location entries are bounded descriptions from the register and are not an Australia-only residency promise.

ProviderPurposeData CategoriesLocationRetention DependencyOverseas Disclosure
Vercel hosting and serverless functionsWebsite hosting, API routes, server-side rendering, runtime logs, cron-style retention endpoints, and deployment infrastructure.IP address, headers, request metadata, submitted form payloads while processing, authentication/session cookies, operational logs, and generated responses.Vercel processing regions and infrastructure locations configured by Vercel; not verified as Australia-only.Vercel account, log, deployment, and security retention settings, plus our application retention rules for data saved to the database or storage.Yes.
Neon / PostgreSQL-compatible database selected by DATABASE_URLPrimary application database for tenants, admins, Contact Requests, audit records, video orders, script cache records, billing identifiers, and retention state.Contact Request data, encrypted payloads, contact HMACs, calculator results, firm/admin account data, hashed passwords, MFA records, audit activity, Stripe identifiers, video order metadata, delivery token hashes, and render identifiers.Depends on the configured DATABASE_URL provider and project region. The current code does not verify Australia-only storage.Our database retention jobs and legal/tax retention rules, plus provider backup, replication, and disaster-recovery policies.May occur.
Upstash RedisRate limiting for Contact Requests, result summary email delivery, contact verification, authentication, and global abuse prevention.IP-derived rate-limit identifiers, rate-limit keys, counters, reset times, and request timing metadata.Depends on the configured Upstash database region; not verified as Australia-only.Upstash key expiry and account configuration.May occur.
ResendTransactional email delivery for verification codes, Contact Request notifications/reminders, support and professional inquiries, result summary PDFs, and operational notices.Recipient email address, names or firm names where relevant, message content, verification codes, Contact Request notification context, result summary PDF attachments, and delivery metadata.Resend and its email infrastructure processing locations; not verified as Australia-only.Resend message, event, suppression, and log retention policies, plus our email and database retention rules.Yes.
StripeCheckout, payment processing, refunds, billing webhooks, firm subscription identifiers, and billing portal sessions.Checkout session IDs, payment intent IDs, customer/subscription IDs, product and price metadata, billing contact details provided to Stripe, webhook metadata, and refund information. We do not store full card numbers or CVV codes.Stripe global processing locations; not verified as Australia-only.Stripe financial, fraud, tax, and compliance retention policies, plus our 7-year payment metadata retention rule.Yes.
Vercel BlobStorage and delivery of Client Firm brand assets.Client Firm brand image files, object paths, access metadata, and storage metadata.Vercel Blob storage and processing locations; not verified as Australia-only.Client Firm asset retention and provider backup/deletion settings.May occur.
Vercel Domains APIAdding, verifying, checking, and removing custom domains for Client Firm tenant sites.Custom domain names, verification records, project/team identifiers, domain status, and related operational metadata.Vercel processing locations; not verified as Australia-only.Vercel account/domain records and our tenant configuration retention.Yes.
Google AnalyticsConsent-gated website analytics and event measurement.Pseudonymous analytics identifiers, IP-derived location, device/browser data, page views, referrers, events, and usage data.Google processing locations; not verified as Australia-only.Google Analytics property retention settings and Google analytics retention policies.Yes.
Microsoft ClarityConsent-gated heatmaps, session replay, interaction analytics, and internal admin session tagging.Pseudonymous identifiers, IP-derived location, browser/device data, page and interaction data, session replay data, and internal admin tags such as sam-admin, internal_user=true, and environment.Microsoft processing locations; not verified as Australia-only.Microsoft Clarity retention settings and Microsoft product/service retention policies.Yes.
Client FirmsResponding to firm-owned Contact Requests after explicit consent.The verified email address, optional first name, Result Summary, selected Review Factors and Complexity Indicators, permitted structured Complexity Details, consent and Safe Contact records, firm-source attribution, and minimum operational metadata shared with the selected firm.Depends on the selected firm and its own systems, suppliers, and privacy policy.The Client Firm data sharing agreement and that firm's legal, professional, and privacy obligations.May occur.
Backups, logs, and disaster recovery for listed providersService continuity, security investigation, restoration, and compliance.Copies or logs of the same categories processed by the relevant hosting, database, storage, email, payment, and analytics providers.Depends on each provider. We do not claim backups are stored only in Australia.Each provider backup/log retention policy and our deletion workflows where deletion APIs or account settings permit.May occur.
Explicitly non-production or non-personal providersGoogle Gemini is not present in package.json, .env.example, or active production code; Vercel Analytics is not implemented; licensed font files are bundled locally and do not make Google Fonts a production recipient; local libraries such as React PDF, Jest, and Playwright run in our build, test, or server environment and are not separate production recipients of user personal information.No active production disclosure of user personal information identified from the current code and configuration.Not applicable unless a future feature or deployment configuration enables the provider.Not applicable for current production data flows.No current production disclosure identified.

6.3 Material Subprocessor Changes

Before adding a provider that will process Client Firm personal information, or materially changing a listed provider's purpose or processing location, we complete privacy, security, contractual, location, retention, and data-flow review. The provider does not receive production data until that review is approved and this register is updated.

We notify affected Client Firms through their nominated operational or privacy contact at least 30 days before the new provider begins processing. The notice identifies the provider, purpose, data categories, expected processing locations, intended effective date, and a contact path for reasonable objections. If an urgent security, availability, or legal requirement makes advance notice impracticable, we notify affected Client Firms as soon as reasonably practicable and record the reason for the exception. Contractual details are set out in our Terms of Service.

7. Data Retention

We retain personal information only for as long as reasonably necessary for the purpose for which it was collected, or as required by law (APP 11.2).

Data TypeRetention PeriodJustification
Contact Request data (optional name, verified email address, and case details)180 days unless deleted earlier or subject to a documented legal holdFirm follow-up, dispute resolution, audit, and legal or regulatory obligations under the Privacy Act 1988.
Conflict-Check Details Handoff namesAccess ends exactly 14 days after submission; the encrypted copy is deleted during the following daily retention run, within 24 hoursShort, purpose-limited transfer to the named Client Firm. A Contact Request legal hold does not extend this period. The firm handles its received copy under its own privacy policy.
Calculator inputs and resultsNot retained — session onlyUsed only to display results in-browser. Not required for any ongoing purpose.
Billing metadata (Stripe IDs)7 yearsAustralian tax and financial reporting obligations under the Income Tax Assessment Act 1997.
Analytics dataProvider default retention periods; then aggregated/de-identified where availableAggregated data cannot identify individuals and is retained for trend analysis.
Admin account dataDuration of account + 12 months after closureSecurity audit trail and dispute resolution.
Provider backups and logsDepends on the hosting, database, storage, email, payment, analytics, and security provider involvedBackups and logs are governed by each provider’s retention and deletion settings. We do not claim backups are Australia-only or deleted on the same schedule as active application records.

When personal information is no longer required, it is securely deleted using industry-standard deletion methods or permanently de-identified so that it can no longer be linked to an individual.

8. Data Security

We take reasonable steps to protect personal information from misuse, interference, loss, unauthorised access, modification, and disclosure (APP 11).

Security measures include:

  • Encryption of browser-to-service traffic in transit using HTTPS/TLS.
  • Role-based access controls and least-privilege principles — staff access personal data only when necessary.
  • One-way hashed storage of administrator passwords; plain-text passwords are never stored.
  • Application-level encryption for selected sensitive fields, including Contact Request payloads and MFA secrets, with Contact Request envelopes currently using AES-256-GCM.
  • Separate application-level encryption and purpose binding for Conflict-Check Details, with names revealed only through an audited, non-cacheable firm portal action.
  • Tenant-scoped HMAC lookup for Contact Request deduplication, authenticated firm admin access, short-lived export tokens, and audit trails for Contact Request access and export activity.
  • Provider-managed database, storage, backup, logging, and infrastructure security controls for records and files that are not separately encrypted by the application.
  • Regular security reviews and vulnerability assessments.
  • Formal incident response procedures including escalation, containment, and notification processes.

Not every database field is separately encrypted by application code. Where this policy refers to encrypted Contact Request payloads, MFA secrets, token hashes, password hashes, or contact HMACs, it refers to those specific implementation controls rather than blanket application-level encryption of every database column.

Data breach assessment and notification:If we have reasonable grounds to suspect an eligible data breach, we will take reasonable and expeditious steps to assess it and take all reasonable steps to complete the assessment within 30 days under section 26WH. If there are reasonable grounds to believe an eligible data breach has occurred, the entity responsible for notification will give the required statement to the OAIC and notify affected individuals as soon as practicable under sections 26WK and 26WL. For information jointly held with a Client Firm, we coordinate the response incident by incident. One entity's notification can satisfy the same breach under section 26WM, but if no entity notifies, each may be found to have breached. Our agreement cannot delay a legally required notification.

8A. Enterprise Security Commitments

Security commitments for Client Firms, procurement teams, and enterprise reviewers are maintained separately from this consumer Privacy Policy. The current public security commitments are available at auschildsupport.com.au/security.

The security page describes the implemented controls, the limits of application-level encryption, incident response expectations, vendor dependency boundaries, and the procurement material we can provide under an appropriate business review process.

9. Cookies and Tracking Technologies

We use cookies and similar technologies on our website. When you first visit, a cookie consent banner will be displayed and analytics cookies will only be set if you actively consent.

CategoryCookie Name(s)PurposeProviderLifespan / Consent
Strictly Necessary__session, csrf_tokenAuthentication, security, form submissionInternalSession — No consent required
Analytics_ga, _ga_*, _clck, _clsk, CLID, ANONCHK, MR, MUID, SMUsage measurement, performance analysis, heatmaps, and session replay. Includes collection of IP address and browser or interaction data.Google Analytics, Microsoft ClarityUp to 2 years — Consent required

Microsoft Clarity is loaded only after analytics consent. Internal admin sessions may be identified in Clarity with the custom ID sam-admin and tagged with internal_user=true plus the current application environment.

You may withdraw analytics consent at any time using or by adjusting your browser settings. Withdrawing analytics consent does not affect your ability to use the calculator, Platform Support, or firm Contact Requests where available.

10. Your Rights

You may ask us to provide access to or correct personal information we hold about you. Where the Australian Privacy Principles apply, APPs 12 and 13 govern those requests; we offer the contact process below in any event.

RightHow to Exercise It
Access your Contact Request dataEmail privacy@auschildsupport.com.au to request access. Using “Access Request” as the subject helps us route the message but is not mandatory. Include the verified email address used for the Contact Request. Our privacy contact handles the request manually and verifies identity through the originally verified contact channel. We aim to complete verified Contact Request privacy requests within 10 business days.
Correct inaccurate Contact Request dataEmail privacy@auschildsupport.com.au to request correction. Using “Correction Request” as the subject helps us route the message but is not mandatory. After identity verification, we can correct the identifiable platform copy held by AusChildSupport. A routine update by Client Firm staff in firm admin is an operational update, not a verified privacy correction. A Client Firm holds a separate copy; contact it directly if that copy also requires correction.
Delete your Contact Request dataEmail privacy@auschildsupport.com.au. Identifiable Contact Requests expire 180 days after submission unless deleted earlier or blocked by a documented legal hold. Deletion removes contact details, contact lookup HMACs, Result Summary data, selected Complexity Indicators, structured Complexity Details, and request-linked sensitive activity data from active stores; only sanitized audit metadata and de-identified aggregate counts may remain.
Withdraw consentYou may withdraw consent for firm follow-up by emailing privacy@auschildsupport.com.au. Withdrawal cannot undo disclosures already made to the assigned firm.
Opt out of marketingWe do not use Contact Request or support information for unrelated direct marketing, and we do not send commercial electronic messages without your separate opt-in. If we send one, it will identify the sender, provide current contact details, and include a functional unsubscribe method as required by the Spam Act. Unsubscribing does not stop transactional messages needed to complete a request you made.

There is no charge to make an access request or to request or receive a correction. If providing access would involve a reasonable, non-excessive charge, we will tell you beforehand. If we refuse a request where the law requires reasons, we will provide written reasons and complaint options.

11. Cross-Border Disclosure of Personal Information

Overseas handling

Some service providers may process or store personal information outside Australia, including in the United States. Where Australian privacy law applies, we do not rely on your use of the service as consent that removes our APP 8 responsibilities. We use the APP 8.1 reasonable-steps framework where it applies, and section 16C may make us accountable for an overseas recipient's conduct. Likely countries and provider-specific details are described below where practicable and supported.

Disclosure AreaHow Location Is DeterminedWhat This Means
Application hosting, logs, and server-side processingVercel processing locations and runtime configuration.Requests may be processed outside Australia. See Section 6.2 for provider-level detail.
Application databaseThe configured DATABASE_URL provider and database project region.The current implementation uses a PostgreSQL-compatible database connection and does not verify Australia-only storage.
Payments, email, analytics, AI, voice, rendering, storage, and domain servicesEach provider’s infrastructure, account settings, and subprocessor network.Overseas disclosure may occur as described in Section 6.2, including the United States and other provider processing locations.
Backups, support access, security logs, and disaster recoveryEach provider’s backup, log, support, and failover architecture.We do not promise that backup, log, support, or disaster-recovery copies remain only in Australia.

We prefer Australian regions where practical, but we do not claim Australia-only data residency unless we have verified the full chain of production dependencies, backups, logs, support access, and failover paths for the relevant service.

12. International Users

This policy does not state that the GDPR or UK GDPR applies generally to the service. Whether another privacy law applies depends on the circumstances. If you believe another privacy law gives you rights concerning our handling of your information, contact privacy@auschildsupport.com.au so we can consider your request.

13. Children’s Privacy

Our service is intended for adults (parents and guardians aged 18 and over). We do not knowingly collect personal information directly from children under 18.

When you use our calculator, you may provide information about your children, such as age bands and care arrangements, to generate a child support Estimate. Those calculator inputs are not sent with an ordinary Contact Request.

An adult may also choose optional Review Factors about a child, including care, location, schooling, costs, medical or disability support needs, or financial resources. If the adult submits a Firm Contact Request, AusChildSupport collects the selected factors and structured follow-up choices and shares them with the named Client Firm for intake review. The adult can continue without sharing these factors, and medical or disability information requires separate consent.

Review Factors do not ask for a child's name, contact details, address, date of birth, school name, documents or free-text narrative.

If you become aware that a child has submitted personal information to us without appropriate consent, please contact us immediately at privacy@auschildsupport.com.au and we will take steps to delete that information.

14. Complaints and Contact

If you have a privacy concern or complaint, please contact us first and we will endeavour to resolve it promptly:

Email: privacy@auschildsupport.com.au (subject: “Privacy Complaint”)

Complaints about AusChildSupport's platform handling or platform copy should be directed to us. Complaints about a Client Firm's separately held copy or its legal services should be directed to that firm and, where applicable, the relevant professional body.

Our complaint handling process:

  • We will acknowledge your complaint within 7 business days.
  • We will investigate and respond with a written decision within 30 days.
  • If more time is needed, we will notify you and explain why.

If we have not responded within 30 days, or you are dissatisfied with our response, you may lodge a written complaint with the OAIC using its online privacy complaint form:

BodyContact Details
Office of the Australian Information Commissioner (OAIC)OAIC online privacy complaint form | 1300 363 992 | oaicintake@oaic.gov.au
Law Society (lawyer complaints)Contact the Law Society in your state or territory. Links at lawcouncil.au

15. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will:

  • Update the “Last Updated” date at the top of this policy.
  • Post a notice on our website homepage for at least 30 days.
  • Email users who have submitted inquiries if the changes affect how we handle their information.

The current version of this policy is always available at auschildsupport.com.au/privacy-policy. We encourage you to review it periodically.

16. Glossary of Key Terms

TermDefinition
Personal informationInformation that identifies you or makes you reasonably identifiable — including your name, email address, IP address, and phone number where a feature explicitly collects one.
Sensitive informationA statutory subset of personal information that includes health information and criminal-record information, among other listed categories. Family-violence information is not automatically a separate statutory category, but it may reveal sensitive information and is handled by us as high-risk safety information.
Explicit consentA clear, affirmative, and informed agreement. Cannot be inferred from silence or pre-ticked boxes.
Authenticated Contact Request accessAuthorised Client Firm users access Contact Requests through authenticated firm admin accounts and audited export-token workflows, subject to their role permissions and firm scope.
Firm Contact RequestAn optional firm-owned request path where a user asks a named Client Firm to contact them. It is not platform lawyer matching or referral intake.
De-identificationThe irreversible removal of identifying information so that the data can no longer be linked to an individual.
APPAustralian Privacy Principle — one of 13 principles in Schedule 1 of the Privacy Act 1988 (Cth) that governs the handling of personal information.
OAICOffice of the Australian Information Commissioner — the federal regulator for privacy. See www.oaic.gov.au.