Privacy Policy

Effective: 2026-05-18 · Last updated: 2026-05-18

Important — please read before signing up. Drive Ready Assessments handles health information about identified individuals, which is sensitive information under the Australian Privacy Act 1988. This policy describes what we collect, how we use it, where it is stored, who else can access it, and what rights you have. We aim to meet the 13 Australian Privacy Principles (APP 1–13). If a section is unclear, please email privacy@drivereadyassessments.com before creating an account or entering any client data.

1. Who we are

“Drive Ready Assessments” (the Platform, we, us, or our) is operated by Rizan Mohamed, an Australian sole trader, as a software-as-a-service tool that helps Occupational Therapists (“Clinicians”) conduct two driving-readiness assessments: OT-DRivER (17-item screening, formerly ASD-DRivE) and OT-DORA-2 Battery (the 8-section off-road battery published by Caroline Unsworth et al.).

For everything you do on the Platform, the Platform is the data processor; the Clinician using their account is the controller of the client information they enter. Joint-controller arrangements between the Platform and a Clinician’s practice may apply where the Platform analyses aggregated, de-identified clinical data for product improvement or independent research (see §6).

2. What we collect

2.1 From Clinicians

  • Name, email, mobile, practice name + address, AHPRA registration number (or equivalent regulator number for non-AU clinicians).
  • Verification documents you upload during onboarding (regulator certificate, government photo ID where requested). These are reviewed by an administrator, stored encrypted, and deleted within 30 days of a verification decision unless retained for fraud-prevention reasons.
  • A hashed password (we never see the plaintext). Authentication tokens are stored as one-way SHA-256 hashes; raw tokens never enter our database.
  • Activity logs: which assessments you start, complete, or cancel, when, from which IP address and device type. Used for security monitoring + abuse prevention; retained 12 months by default.

2.2 About Clients (entered by their Clinician)

  • The Platform does not request or collect client-identifying information such as full name, date of birth, age, gender, contact details or address. A client is recorded only by a first name (or an alternate non-identifying label) chosen by the Clinician, together with an internal “client code”. The link between that label and the client’s identity is held by the Clinician in their own clinic records, outside the Platform.
  • Clinical data: primary diagnosis, secondary diagnoses, diagnosis details as relevant to the assessment.
  • Per-assessment data: scores on each of the 17 OT-DRivER items, scores on each of the 8 OT-DORA-2 Battery sections, clinician notes and recommendations, the final outcome category, and the date of assessment.
  • The client label is stored encrypted at rest using AES-256-GCM, hosted in Australia (AWS Sydney, ap-southeast-2 region).
  • We never collect a client’s payment information. Stripe handles all card transactions (between the Platform and the Clinician) and we receive only a tokenised customer reference + the last four digits.

2.3 About Researchers

Researchers using the Platform’s research dashboard see only de-identified records — pseudonymous participant codes, age brackets, diagnoses, state, and scores. Researchers cannot view names, full dates of birth, exact ages, addresses, or any other directly identifying information.

2.4 Automatically collected

  • Standard web logs: IP address, browser user-agent, referring URL, timestamp of each request. Used for security monitoring + debugging; retained 90 days.
  • Crash and performance telemetry from the mobile app (TestFlight and Google Play Internal Testing): non-identifying device model, operating system version, app version, crash stack trace. Not combined with PII.
  • We do not use analytics SDKs (Google Analytics, Firebase Analytics, Meta Pixel, etc.) and we do not place third-party tracking cookies.

3. Why we collect it — purposes (APP 3, APP 5)

  • To allow Clinicians to record, score, and report on driving-readiness assessments for their clients.
  • To verify a Clinician’s identity and regulatory standing before activating their account (anti-fraud, professional accountability).
  • To produce printable reports (PDF) that Clinicians can share with their clients, treating teams, and licensing authorities.
  • To bill Clinicians for assessments they complete (via Stripe tokenised checkout).
  • To enable independent academic research on driving-readiness outcomes — but only using the de-identified dataset, and only for clients whose consent record explicitly opts in to research participation. Clinicians cannot override this on a client’s behalf.
  • To investigate suspected abuse, fraud, or breach of the Terms of Service.
  • To comply with Australian law, including the Notifiable Data Breaches scheme administered by the Office of the Australian Information Commissioner (OAIC).

We do not use any personal information for direct marketing. We do not sell, rent, or share any personal information with advertisers, data brokers, or third-party marketers (APP 7).

4. Where the information is stored

  • Primary database: PostgreSQL on Amazon Web Services (AWS) RDS, Sydney (ap-southeast-2) region. Encrypted at rest using AES-256.
  • Application server: AWS App Runner, Sydney (ap-southeast-2) region. TLS 1.2+ for all in-transit traffic.
  • Mobile app distribution: Apple TestFlight (Apple, USA — for beta-testing only) and Google Play Internal Testing (Google, USA — for beta-testing only). No client data is transmitted via these channels; the apps only carry compiled code.
  • Transactional email: sent through a third-party email-delivery provider (subject to its own privacy policy). Only Clinician email addresses, the email subject, and the email body are transmitted; no client identifying data.
  • Payments: Stripe, Inc. (USA / Ireland). We never receive raw card numbers; Stripe’s privacy policy applies: stripe.com/privacy.
  • Backups: daily encrypted snapshots of the database, stored in the same AWS Sydney region.

5. Cross-border disclosure (APP 8)

Day-to-day clinical data lives on Australian soil (AWS Sydney, ap-southeast-2). The following third parties handle data outside Australia:

  • Apple Inc. (USA) — for distributing the mobile app to TestFlight beta testers. Receives only your TestFlight email address and crash diagnostics.
  • Google LLC (USA) — for distributing the mobile app to Google Play testers. Receives only your Google email address (if you opt-in as a tester) and crash diagnostics.
  • Stripe (USA / Ireland) — for processing Clinician payments. Receives Clinician card details directly; we do not.
  • Amazon Web Services (Sydney primary, global edge) — primary data residency is Australia. Edge requests (DNS, static assets) may transit AWS’s global network.

By creating a Drive Ready Assessments account you consent to this cross-border disclosure for the specific purposes listed above.

6. De-identified data and research

With explicit client consent (captured per-assessment via the Consent Record form), a de-identified copy of the assessment data may be written to a separate research dataset. That dataset contains only: a pseudonymous participant code (one-way SHA-256 hash, salted), age bracket, gender (if provided), primary diagnosis, state, assessment date, scores, and a per-record source hash.

It does not contain: names, full dates of birth, exact ages, addresses, AHPRA numbers, clinician identities, or any free-text notes that a clinician entered.

Researchers using the Platform’s research dashboard see only this de-identified dataset. The Platform’s technical architecture enforces this separation at the database query layer — the researcher application code cannot access the encrypted PII tables.

7. Your rights (APP 12, APP 13)

You can ask us, at any time, to:

  • Tell you what personal information we hold about you (Clinician accounts: log in to Settings → Account; clients should contact their Clinician first).
  • Correct any inaccurate information.
  • Permanently delete your account and the associated records (subject to retention obligations described in §8).
  • Withdraw consent to participation in the research dataset. If a client withdraws consent, their de-identified records will be removed from the research dataset within 30 days.
  • Export your records in a portable format (JSON or CSV).

Send these requests to privacy@drivereadyassessments.com from the email address on the account. We respond within 30 days. If you are dissatisfied, you may complain to the Office of the Australian Information Commissioner (OAIC).

8. Retention and deletion

  • Active accounts: records kept while the account is active and for 7 years after the last assessment (consistent with AHPRA/Australian Health Practitioner Regulation guidance on clinical record retention).
  • Cancelled or unverified Clinician accounts: deleted within 90 days of cancellation, except where a client’s record must be retained under (a) above.
  • Verification documents uploaded during onboarding: deleted within 30 days of a verification decision.
  • Web access logs: 90 days.
  • Activity (audit) logs: 12 months.
  • Database backups: 35 days, then automatically overwritten.
  • Research dataset: retained indefinitely in de-identified form unless the originating client withdraws consent.

9. Security

  • TLS 1.2+ for all browser ⇄ server traffic.
  • AES-256-GCM encryption at rest for identifying fields (name, date of birth, etc.) on Australian Azure infrastructure.
  • Bcrypt-hashed passwords (cost factor ≥ 10). Plaintext passwords are never logged or transmitted to any third party.
  • JWT RS256 access tokens with short expiry; refresh tokens stored as SHA-256 hashes.
  • Server-side input validation against XSS and SQL injection.
  • Server-side enforcement that Clinicians cannot access other Clinicians’ client records (database queries are scoped per Clinician).
  • Race-condition-safe credit ledger and consent linking (database-transaction-level atomicity).
  • Server-side identity verification gate: an account cannot perform assessments until an administrator has verified the regulator registration evidence.
  • Independent third-party security audit completed (commit history available on request).

10. Data breaches

If we become aware of an eligible data breach as defined by Part IIIC of the Privacy Act 1988 (loss, unauthorised access, or disclosure of personal information likely to result in serious harm), we will, as soon as practicable:

  • Contain the breach and assess the actual or suspected scope.
  • Notify the affected individuals directly (or via this Platform).
  • Notify the Office of the Australian Information Commissioner (OAIC) within 72 hours of becoming aware, with the information required by the Notifiable Data Breaches scheme.
  • Conduct a root-cause review and publish a post-mortem summary on this page within 60 days.

11. Cookies

We set only essential first-party cookies (session id, CSRF token). No third-party cookies. No tracking pixels. No analytics SDKs. We deliberately avoid them because the platform processes sensitive health information.

12. Children’s privacy

Drive Ready Assessments is intended for use by registered Occupational Therapists in their professional capacity. We do not market the platform to children. Clinicians may, in the course of their normal practice, assess clients who are minors; in that case the Clinician is responsible for obtaining consent from the minor and (where required) the minor’s parent or guardian under the laws of their jurisdiction. We will not knowingly process records for a child under 12 without explicit consent recorded in the Consent Record form.

13. Changes to this policy

We will post any material changes to this page at least 14 days before they take effect, update the “Last updated” date at the top, and notify active Clinicians by email. Continued use of the Platform after the effective date constitutes acceptance.

14. Contact

Privacy enquiries, access or correction requests, or complaints:
privacy@drivereadyassessments.com
Rizan Mohamed (Sole trader)
Drouin VIC 3818, Australia

External oversight: Office of the Australian Information Commissioner — www.oaic.gov.au · 1300 363 992.

Drafted in good faith but not lawyer-reviewed. This policy is a starting point for a clinical SaaS operating under the Australian Privacy Act 1988 and the Australian Privacy Principles. If you intend to operate at meaningful scale, retain a privacy lawyer to review it against your specific data flows, security controls, and any additional jurisdictions you operate in (e.g. UK GDPR, NZ Privacy Act 2020, EU GDPR, US state laws). Update the Last updated field and the version-history section any time you change material content.