The questions people ask before they trust us with a file.
Where the data lives, who can reach it, whether it trains anything, what the mapping is built on, and who decides. A family handing over a decade of medical history deserves better than a confident paragraph that says nothing.
Ownership and control
Who owns the information a participant puts into BellaAssist?
The participant's information stays theirs to control. We hold it to run the service, and we are accountable for it under the Privacy Act, but we do not treat it as an asset of the business. A participant can ask us for a copy of what we hold, ask us to correct it, ask us to delete it, withdraw consent to optional research sharing, or revoke a delegation they have given someone else. Those are not favours; they are requests we are required to answer, and we normally respond within 30 calendar days.
What happens to the file if someone stops using BellaAssist?
They can export it before they go. The handover pack is a downloadable file that opens in any browser with no account at the other end, which is deliberate: leaving should not cost a person their own history. After that, retention runs by record type and lifecycle, and when information is no longer required we take reasonable steps to delete or de-identify it. Legal holds, backup cycles and open privacy requests can extend that, and we will say so if they apply.
Can a provider or coordinator see a participant's file without permission?
No. Access runs on explicit delegation, and the audit trail records who acted and when. Delegation can be revoked by the participant. Administrators at Bella Sláinte cannot impersonate a customer or browse participant, coordinator, document or submission content; their access covers account operations such as invitations, suspension and security recovery.
Australian residency
Where is the data actually held?
In Australia. Google Cloud hosts the BellaAssist application, database and documents in Australian regions. Account and application records sit on Australian servers, and participant documents use Australian dual-region storage across Sydney and Melbourne.
Where do the AI requests run?
Also in Australia. Approved AI requests are processed through AWS Bedrock and Google Vertex AI in Australian regions. We name the providers rather than saying “secure cloud infrastructure”, because the question behind this question is usually whether anything crosses a border, and the honest answer should be checkable.
Does anything leave the country?
Some operational services that support the business can hold correspondence and case details, including Google Workspace, Jira and Slack, and each receives only what it needs for its function rather than the full product dataset. Account emails are sent through Postmark, which may process the recipient address and the message in the United States. Where personal information is likely to be disclosed overseas we take the steps required by Australian Privacy Principle 8. We would rather state that plainly than imply a hermetic seal we do not have.
AI and training
Do you train AI models on participant data?
No. We do not use customer or participant content to train AI model parameters. If that were ever to change it would require the purpose, legal authority, notice, purpose-specific opt-in, a privacy assessment and approved safeguards first, which is a deliberately high bar and is written into the policy rather than left to intention.
Does the AI make decisions about funding?
It does not, and it cannot. BellaAssist analyses documents, drafts submission content and assesses readiness against the criteria. A person reviews everything, and nothing is submitted without someone approving it. Funding decisions rest with the NDIA and depend on the individual plan. What we do is put auditable evidence in front of the people who decide, mapped against what they are required to consider.
The privacy law changes in December. Does that affect BellaAssist?
The Privacy and Other Legislation Amendment Act 2024 commences on 10 December 2026. From then, an organisation using personal information in automated decisions that significantly affect a person must disclose that in its privacy policy. Whether the obligation reaches a tool that drafts text a person then verifies is genuinely arguable. A tool that scores or triages is squarely in scope, and our readiness evaluation produces a score, so we are treating ourselves as in scope rather than arguing our way out of it. The OAIC consulted on guidance in mid 2026 and has not yet published it. When it does, our policy will be updated to match and the version number will change.
Is it a problem that a submission was AI-assisted?
The evidence is what gets assessed, and the evidence is the participant's own reports and their own words. We publish an evidence memo covering what the research actually shows about AI in allied health practice, including the findings that cut against the case for a tool like ours. One of those findings is why we removed a claim from this site: no study has yet tested whether people perform better unassisted after using an AI tool, so we do not claim BellaAssist leaves someone with a durable skill.
The ontology
What does “ontology mapping” mean here?
It is the crosswalk between how a person describes their life and how the scheme is required to assess it. Eight ICAN domains sit at the centre: Health and Wellness, Social and Community Participation, Home and Living, Learning and Education, Work and Employment, Relationships, Choice and Control, and Daily Living. Each domain maps to the NDIS support categories it can draw funding from, to the plan review questions that elicit it, and to the evidence types that substantiate it.
What is it mapped against?
The baseline framework is the NDIS Act 2013 as amended in 2024, with the ICAN structure over it. The compliance layer runs 208 controls across 8 domains, and a readiness evaluation reports which of them a submission satisfies and which it does not, with the gap named rather than scored away. WHODAS 2.0 scores are extracted by a deterministic parser. Other gold-standard instruments, including Vineland and PEDI-CAT, are recognised when they appear in a report and cited from the document text; they are not run through a dedicated score parser.
Why does the mapping matter to a participant?
Because it is the difference between a file that is thorough and a file that is legible. Most people have plenty of evidence. What they do not have is that evidence expressed against the criteria the decision will be made under, which is why a strong file can still come back with a smaller plan.
Security and assurance
Where do you sit on ISO 27001?
We build and operate in line with the ISO 27001 standard, and formal certification is in progress. The controls are running today: access control, multi-factor authentication where required, encryption, audit logging, restricted service routes and incident response. We will describe ourselves as certified once the certificate is issued.
What gets masked?
NDIS numbers, Medicare numbers, phone numbers and email addresses. We name those four rather than claiming to redact all personal information, because the broader claim would not be true and the narrower one is testable.
Who is accountable, and what if we disagree with you?
David Haberlah, our CTO and Chief Data and AI Officer, is the Privacy Officer, at privacy@bellaassist.au. Access, correction, deletion, consent-withdrawal and delegation requests normally receive a response within 30 calendar days. Privacy complaints are acknowledged within two business days and we aim to give a written outcome within 21 calendar days. If more time is needed we explain why and give a revised date. If our answer is unsatisfactory, the Office of the Australian Information Commissioner takes complaints at oaic.gov.au or 1300 363 992.
Ask us something that is not here
Every answer here is drawn from the published Privacy Policy and from how the product is actually built, and where we are not there yet it says so. If a question is not covered, it is more useful to us as a question than as a doubt. Governance and security questions go to privacy@bellaassist.au. Anything else reaches us at hello@bellaassist.au, and we answer within five working days.