Terms of Service
Longstead Terms of Service Version: 0.2 · Effective date: 6 August 2026
These Terms of Service (Terms) are an agreement between CLOUD RESEARCH AND DEVELOPMENT XENTER PTY LTD (ABN 52 677 458 187) (we, us, our) and the organisation that subscribes to the service (you, your, the Customer). By signing an order form, accepting an invitation to the service, or using the service, you agree to these Terms on behalf of your organisation and warrant that you have authority to do so.
Longstead is a business-to-business service. It is offered only to organisations, not to individual consumers.
1. What the Service is
1.1 Longstead (the Service) is a software-as-a-service platform that helps Australian disability-sector providers organise the records, registers, credentials, evidence documents and self-assessments relevant to NDIS provider registration and audit preparation. The first offering is SIL Registration & Audit Readiness.
1.2 The Service includes tools such as incident and complaint registers, worker credential tracking, an evidence vault, self-assessment workbenches, readiness summaries and scores, and audit-pack exports. The specific features available to you are those described in your order form or the current published feature list.
1.3 We may improve, add to or modify features of the Service over time. We will not materially reduce the core functionality you are paying for during a subscription period without notice under clause 17.
2. What the Service is not — important disclaimers
Please read this clause carefully. It defines the boundary of what you are buying.
2.1 Not advice. The Service provides information-management and organisation tools. It does not provide legal advice, compliance advice, registration advice, auditing services or any other professional advice. Content in the Service (including checklists, requirement descriptions, citations to NDIS rules, and gap or deadline prompts) is general information prepared in good faith and may be incomplete, out of date, or inapplicable to your circumstances.
2.2 The readiness score is a self-assessment aid. Any readiness score, gap list, verdict or similar output is generated from the information you enter, against general criteria. It is not a prediction, assurance or guarantee of the outcome of any NDIS registration application, certification audit, mid-term audit, verification audit or any other regulatory process. A "ready" indication does not mean you will pass an audit; an identified gap does not necessarily mean you will fail one.
2.3 You remain responsible. You are solely responsible for your compliance with the National Disability Insurance Scheme Act 2013 (Cth), the NDIS (Provider Registration and Practice Standards) Rules, the NDIS Practice Standards, the NDIS Code of Conduct, the NDIS Pricing Arrangements / Pricing Schedule, and all other laws and regulatory obligations that apply to you. Nothing in the Service transfers, reduces or discharges any of those obligations. You should obtain your own legal, compliance or audit advice where appropriate.
2.4 No regulator affiliation. We are not an approved quality auditor under the NDIS (Approved Quality Auditors Scheme) Guidelines. We are not affiliated with, endorsed by, or acting for the NDIS Quality and Safeguards Commission, the National Disability Insurance Agency (NDIA), or any other government body. Use of the Service does not constitute engagement of an auditor and does not satisfy any requirement to engage one.
2.5 Timeliness of regulatory content. NDIS rules, price limits, item codes and deadlines change. We use reasonable efforts to keep regulatory reference content current, but you must verify any regulatory requirement against the official source before relying on it.
3. Your account and users
3.1 Provisioning. Accounts are currently provisioned by us on invitation. You must provide accurate organisation details and keep them up to date.
3.2 Users. You may authorise your personnel (employees, contractors and advisers acting for you) as users. You are responsible for the acts and omissions of your users as if they were your own, for keeping your user list current, and for promptly deactivating users who leave your organisation or no longer need access.
3.3 Credentials. You and your users must keep login credentials confidential, must not share individual accounts, and must notify us promptly at security@longstead.com.au if you suspect unauthorised access.
4. Subscription, fees and invoicing
4.1 Subscription. The Service is supplied on a month-to-month subscription. The current standard price is approximately $299 per month (excluding GST) per provider organisation, or as otherwise set out in your order form. Prices are in Australian dollars.
4.2 Invoicing. We bill by manual invoice (no card-on-file, no direct debit unless separately agreed). Invoices are issued monthly in advance and are payable within 14 days of the invoice date. GST will be added where applicable and invoices will be valid tax invoices.
4.3 No auto-renewal traps. There is no lock-in contract, no minimum term beyond the current month, and no cancellation fee. Your subscription simply continues month to month until you cancel under clause 6 or these Terms are otherwise terminated.
4.4 Price changes. We may change subscription prices by giving you at least 30 days' written notice. A price change takes effect from your next monthly period after the notice period ends. If you do not accept the change, you may cancel before it takes effect.
4.5 Late payment. If an invoice remains unpaid 14 days after its due date, we may suspend the Service under clause 7 after giving you at least 7 days' written warning. We do not charge interest on late payments in this version of these Terms, but we may recover reasonable costs of collecting significantly overdue amounts.
4.6 Disputed invoices. If you genuinely dispute an invoice, tell us in writing before the due date, pay any undisputed portion, and we will work with you in good faith to resolve the dispute before taking any suspension action in respect of the disputed amount.
5. Trials and pilots
If we agree to a free or discounted trial, pilot or design-partner arrangement, these Terms apply, modified by the written terms of that arrangement. Trial use is provided "as available" and may be limited or ended by either party on written notice.
6. Cancellation and termination
6.1 Cancel any time. You may cancel your subscription at any time by written notice to billing@longstead.com.au. Cancellation takes effect at the end of the monthly period in which we receive your notice (or a later date you nominate). We do not refund the current month, but you will not be charged for any period after cancellation takes effect.
6.2 Termination by us for convenience. We may terminate these Terms and your subscription for convenience on at least 60 days' written notice (for example, if we discontinue the Service). If we do, we will refund any amount you have prepaid for a period after the termination date.
6.3 Termination for cause. Either party may terminate immediately by written notice if the other party (a) materially breaches these Terms and, if the breach is capable of remedy, fails to remedy it within 14 days of written notice; or (b) becomes insolvent, enters administration or liquidation, or ceases business.
6.4 Effect of termination. On termination or expiry: your right to access the Service ends; clauses that by their nature survive (including clauses 2, 8, 9, 12, 14 and 15) continue; and data export and deletion are handled under clause 9.
7. Suspension
7.1 We may suspend some or all of the Service, on written notice where practicable, if: (a) an invoice remains unpaid after the process in clause 4.5; (b) we reasonably believe your use breaches clause 13 (Acceptable use) or poses a security risk to the Service or other customers; or (c) suspension is required by law.
7.2 We will limit any suspension to what is reasonably necessary and will restore the Service promptly once the cause is resolved. Suspension does not relieve you of the obligation to pay amounts properly due for periods before suspension.
7.3 During a suspension for non-payment we will not delete your Customer Data, and the retention and export rights in clause 9 continue to apply.
8. Customer Data
8.1 Definition. Customer Data means all data, documents and records that you or your users enter into or upload to the Service, including information about your organisation, your workers (such as screening and credential records), and NDIS participants (such as participant details, consent records, incident and complaint records, and evidence documents).
8.2 You own it. As between the parties, you own all right, title and interest in Customer Data. You grant us a non-exclusive licence to host, copy, process, transmit, back up and display Customer Data solely to provide and support the Service, to comply with law, and as otherwise permitted by these Terms and our Privacy Policy.
8.3 We do not exploit it. We will not sell Customer Data, use it for advertising or marketing to any person, or use personal information within Customer Data to train artificial-intelligence or machine-learning models. We may use aggregated, de-identified usage and operational data (from which neither your organisation nor any individual can reasonably be re-identified) to operate, secure and improve the Service.
8.4 Your warranties about Customer Data. You warrant that:
- (a) you have the right to enter Customer Data into the Service and to allow us to process it as described in these Terms;
- (b) you have obtained, and will maintain, all consents, notices and other authorities required under the Privacy Act 1988 (Cth) and any other applicable law for the personal information you enter — including personal information about your workers (for example screening check outcomes and credentials) and sensitive information, including health information, about NDIS participants;
- (c) where the Service records a participant's consent (participant consent records are a feature of the Service), the underlying consent was genuinely and lawfully obtained by you — the Service records your consent process, it does not obtain consent for you; and
- (d) Customer Data does not infringe any third party's rights and is not unlawful.
8.5 Accuracy. The Service's outputs depend on Customer Data. You are responsible for the accuracy and completeness of what you enter.
8.6 Privacy roles. In respect of personal information within Customer Data, you are the collecting organisation with the primary relationship with the individuals concerned; we handle that information as your service provider, as described in our Privacy Policy. Each party must comply with the Privacy Act 1988 (Cth) in respect of its own obligations.
9. Records retention, immutable evidence, export and deletion
9.1 Why this clause is unusual. The Service is designed for compliance-record keeping. Some records you store in it (for example evidence documents, incident records and audit trails) are of a kind that NDIS legislation and related rules require providers to retain for long periods — up to 7 years, and in some cases longer, depending on the record and jurisdiction. To support this, evidence documents and audit events are stored in write-once (immutable) storage: once created, they cannot be altered, and deletion is restricted, by design.
9.2 Export on exit. At any time during your subscription, and for 30 days after cancellation or termination, you may export your Customer Data, including evidence documents and register/audit-pack exports, in the formats the Service provides (structured JSON and original uploaded file formats, or other machine-readable formats we make available). We will provide reasonable assistance with export at no additional charge for standard exports.
9.3 Deletion after exit. After the export window ends, we will delete or irreversibly de-identify Customer Data within 90 days, except:
- (a) records subject to an immutable-retention hold under clause 9.1, which we will retain in write-once storage for the applicable retention period and then delete;
- (b) data we are required by law to retain (which we retain only for as long as required); and
- (c) residual copies in encrypted backups, which are deleted in the ordinary backup rotation cycle.
Data retained under (a) or (b) remains subject to clauses 8.2, 8.3 and our Privacy Policy, is held only for record-integrity and legal purposes, and is not used for any other purpose.
9.4 Individual deletion requests. If you ask us to delete particular records (for example following a request from an individual), we will honour the request subject to the retention obligations in clause 9.1/9.3. Where a record cannot yet be deleted because of a legally required retention period, we will tell you, restrict the record from ordinary use where technically practicable, and delete it when the retention period ends.
9.5 Your retention obligations are yours. Clause 9 describes how we handle retention within the Service. It does not transfer your statutory record-keeping obligations to us. You should keep your own view of which records you are required to retain and for how long.
10. Data residency and subprocessors
10.1 Australian hosting. All Customer Data is hosted and processed in
Australia, in the AWS Asia Pacific (Sydney) region (ap-southeast-2),
including backups (and any in-country disaster-recovery replication, which
also remains within Australia]. We will not store Customer Data outside
Australia.
10.2 CDN for static assets only. Static, non-personal web assets (such as application code, stylesheets and images that contain no Customer Data) may be served through a global content delivery network. No Customer Data or personal information is served or cached through the CDN.
10.3 Subprocessors. We use Amazon Web Services as our hosting subprocessor. We will maintain a current list of subprocessors at https://longstead.com.au/subprocessors/ and on request and will give you at least 30 days' notice before adding a subprocessor that will handle Customer Data. Any such subprocessor must meet the residency commitment in clause 10.1 and security obligations no less protective than ours.
11. Availability, support and maintenance
11.1 Reasonable efforts, no SLA. We aim for high availability and will use reasonable efforts to keep the Service available, but we do not offer a contractual service-level agreement (uptime guarantee or service credits) in this version of the Service.
11.2 Maintenance. We may perform scheduled maintenance, and will use reasonable efforts to schedule maintenance likely to cause noticeable interruption outside Australian Eastern business hours and to give advance notice of it. Emergency maintenance (for example, urgent security patching) may occur without notice.
11.3 Support. Support is provided by hello@longstead.com.au during (Australian Eastern business hours], on a reasonable-efforts basis.
11.4 Backups. We maintain backups and point-in-time recovery for the Service's data stores. Backups are for disaster recovery of the Service as a whole; clause 9.2 (export) is the mechanism for your own copies.
12. Intellectual property and feedback
12.1 We (and our licensors) own the Service, its software, design, templates, requirement content and documentation. These Terms give you a right to use the Service, not ownership of it.
12.2 Outputs generated for you from your Customer Data (for example an exported audit pack) may be used by you for your business purposes, including providing them to auditors and regulators.
12.3 If you give us feedback or suggestions, we may use them without restriction or obligation, provided we never disclose your confidential information or Customer Data in doing so.
13. Acceptable use
You must not, and must ensure your users do not:
- (a) use the Service other than for your own organisation's compliance-management purposes, or resell or provide the Service to third parties (advisers acting for you are fine);
- (b) upload malicious code, or attempt to probe, scan, or breach the Service's security or authentication, or access another customer's data;
- (c) use the Service to store or transmit material that is unlawful, or personal information you have no right to hold;
- (d) interfere with the integrity or performance of the Service, including by unreasonable automated load;
- (e) copy, modify, reverse engineer or create derivative works of the Service except as permitted by law that cannot be excluded;
- (f) falsify records. The Service's audit trail is designed to be accurate; entering records you know to be false may also breach NDIS law, and we have no liability for the content of records you create; or
- (g) use the Service in a way that causes us to breach any law.
14. Security responsibilities
14.1 Ours. We will implement and maintain reasonable technical and organisational security measures appropriate to the sensitivity of Customer Data, including encryption in transit and at rest, tenant isolation, access controls, and audit logging, as further described in our Privacy Policy and security documentation.
14.2 Yours. You are responsible for: your users' credential hygiene and device security; promptly managing user access (especially removing departed staff); the accuracy of data entered; your own network and endpoints; and telling us promptly about any suspected compromise of your accounts.
14.3 Incidents. Each party will notify the other without undue delay of any security incident it becomes aware of that affects the other party's data or access, and will reasonably cooperate in response. Data-breach obligations under the Privacy Act are addressed in our Privacy Policy.
15. Liability
15.1 Australian Consumer Law. Nothing in these Terms excludes, restricts or modifies any consumer guarantee, right or remedy under the Competition and Consumer Act 2010 (Cth) (including the Australian Consumer Law, ACL) or any other law that cannot lawfully be excluded, restricted or modified. To the extent the ACL applies to our supply and permits it, our liability for a failure to comply with a consumer guarantee is limited, at our option, to resupplying the services or paying the cost of having the services supplied again.
15.2 Cap. Subject to clauses 15.1 and 15.4, each party's total aggregate liability to the other arising out of or in connection with these Terms (whether in contract, tort including negligence, statute or otherwise) is limited to the total fees paid or payable by you in the 12 months before the event giving rise to the liability.
15.3 Excluded loss. Subject to clauses 15.1 and 15.4, neither party is liable to the other for loss of profits, loss of revenue, loss of anticipated savings, loss of goodwill, or indirect or consequential loss, however arising. For clarity, the following are direct losses and are not excluded by this clause (though they remain subject to the cap in 15.2): your reasonable costs of restoring or re-creating Customer Data lost due to our breach.
15.4 Uncapped matters. Nothing in these Terms limits or excludes liability for: (a) death or personal injury caused by negligence; (b) fraud or fraudulent misrepresentation; (c) your obligation to pay fees properly due; (d) a party's wilful misconduct; or or (e) your liability under clause 15.5 ( either party's breach of the other's intellectual-property rights — confirm scope with counsel].
15.5 Your indemnity (data and consents). You indemnify us against third-party claims, and reasonable costs of defending them, to the extent arising from (a) Customer Data breaching clause 8.4, or (b) your breach of privacy or NDIS law in connection with information you enter into the Service — except to the extent we caused the loss. (Note: an indemnity is appropriate for this customer base or whether warranty + cap is enough.]
15.6 Acknowledgement. You acknowledge that fees are set on the basis of this clause 15, and that the disclaimers in clause 2 mean regulatory outcomes (registration decisions, audit results, Commission or NDIA action) are outside our control and not something we assume liability for.
16. Confidentiality
Each party must keep the other's confidential information confidential, use it only for the purposes of these Terms, and disclose it only to personnel and advisers who need it and are bound to keep it confidential — except where disclosure is required by law or a regulator (in which case, where lawful, the disclosing party gives prompt notice). Customer Data is your confidential information. These obligations survive termination.
17. Changes to these Terms
17.1 We may update these Terms from time to time. For material changes we will give you at least 30 days' written notice (email is sufficient) before the change takes effect. Non-material changes (for example clarifications or changes required by law) may take effect on posting.
17.2 If a material change is detrimental to you and you do not accept it, you may cancel under clause 6.1 before the change takes effect; the prior Terms apply until your cancellation takes effect. Continued use of the Service after a change takes effect constitutes acceptance.
18. Notices
Notices under these Terms must be in writing and may be given by email — to us at legal@longstead.com.au, and to you at the billing or administrative email address on your account (you must keep it current). A notice sent by email is taken to be received on the business day it is sent (Australian Eastern time) if sent before 5 pm, otherwise the next business day.
19. General
19.1 Relationship. The parties are independent contractors. Nothing creates a partnership, joint venture, employment or agency relationship, and we are not your agent for any dealing with the NDIS Commission or the NDIA.
19.2 Assignment. Neither party may assign these Terms without the other's consent (not to be unreasonably withheld), except that we may assign to a related body corporate or in connection with a genuine corporate reorganisation or sale of the business, on notice to you.
19.3 Subcontracting. We may use subcontractors (including subprocessors under clause 10.3) but remain responsible for their performance.
19.4 Force majeure. Neither party is liable for delay or failure caused by events beyond its reasonable control (excluding your payment obligations for services already delivered), provided the affected party takes reasonable steps to mitigate.
19.5 Severability. If part of these Terms is unenforceable, it is severed to the minimum extent necessary and the rest remains in force.
19.6 Entire agreement. These Terms, your order form and our Privacy Policy are the entire agreement about the Service and supersede prior discussions. If there is an inconsistency, the order form prevails over these Terms.
19.7 No waiver. A failure to enforce a right is not a waiver of it.
20. Governing law
These Terms are governed by the laws of New South Wales (the State or Territory of the Company's registration — confirm]**, Australia. The parties submit to the non-exclusive jurisdiction of the courts of that State or Territory and the courts competent to hear appeals from them.
21. Contact
CLOUD RESEARCH AND DEVELOPMENT XENTER PTY LTD (ABN 52 677 458 187) Registered address to be published before launch Billing: billing@longstead.com.au · Support: hello@longstead.com.au · Legal notices: legal@longstead.com.au · Security: security@longstead.com.au