This Acceptable Use Policy sets out the rules for using the Rise platform, the riseos.care website and every related service we provide (together, the Platform). It applies to every person and organisation that uses the Platform, including every Authorised User, and it forms part of our Terms of Service. Words defined in the Terms of Service have the same meaning here.
The Platform holds the records that care providers are assessed on, and information about the people they support. The rules below exist to protect those people, the providers, the auditors who rely on the records, and the integrity of the Platform itself. If you are unsure whether something is allowed, ask us at dev@riseos.care before you do it.
1Purpose and scope
This Policy describes conduct that is not permitted on the Platform, sets out the responsibilities that come with an account, and explains how we respond to misuse. It is not an exhaustive list. Conduct that is not listed here may still breach the Terms of Service or the law, and we may treat it in the same way.
An organisation that holds an account is responsible for ensuring that its Authorised Users comply with this Policy, and is responsible for their conduct on the Platform as if it were the organisation's own.
2Your responsibilities
When you use the Platform you must:
- use it only for the lawful business purposes it is provided for: managing, evidencing, reviewing and auditing compliance in the care sector;
- keep your credentials private, use multi-factor authentication where it is available, and never let another person use your account;
- give us accurate registration information and keep it current;
- apply the Platform's access controls so that Personal Information, and in particular health information about participants, is visible only to the people who need it;
- remove access for people who leave your organisation or no longer need it, promptly;
- comply with every law that applies to you, including the Privacy Act 1988 (Cth), the NDIS Act 2013 (Cth), and any state, territory or foreign law that governs the information you handle; and
- tell us at dev@riseos.care as soon as you become aware of a security incident, a vulnerability, or a breach of this Policy.
3Prohibited conduct
You must not, and must not allow or help anyone else to:
- use the Platform in breach of any law, regulation, professional obligation or court order, or to plan or carry out an unlawful act;
- upload, store, generate or share material that is defamatory, harassing, discriminatory, obscene, or that incites violence or hatred;
- upload, store, generate or share material that infringes another person's intellectual property, privacy or other rights;
- impersonate any person or organisation, misrepresent your affiliation, role or authority, or misrepresent the status of any provider, auditor, registration or certification;
- access, or attempt to access, an account, data or part of the Platform that you are not authorised to access, or exceed the access you have been granted;
- probe, scan or test the Platform for vulnerabilities, or attempt to breach or circumvent any security or authentication measure, except as permitted by clause 8;
- introduce malware, or any code or material that is designed to interfere with the Platform or with any system, device or data;
- interfere with the operation of the Platform, or with any other customer's use of it, including by overloading it, sending unsolicited communications through it, or using it to send spam in breach of the Spam Act 2003 (Cth) or an equivalent law;
- use bots, scrapers, crawlers or other automated means to access the Platform or extract data from it, other than through an interface we provide for that purpose and within the limits we set;
- copy, reproduce, republish, sell, rent, sublicense or otherwise distribute the Rise Materials, or any substantial part of them, outside your organisation;
- reverse engineer, decompile, disassemble or otherwise attempt to derive the source code, models, prompts, mappings or underlying structure of the Platform, except to the extent the law expressly permits despite this clause;
- use the Platform, its Output or the Rise Materials to build, train, benchmark or improve a product or service that competes with the Platform;
- circumvent any usage limit, plan restriction or billing mechanism, or share a single account between organisations; or
- remove, obscure or alter any proprietary notice, audit trail, timestamp or record of access on the Platform.
4Data you upload
You may upload only data that you have the right to upload, and that you have collected and are entitled to disclose in accordance with the Privacy Act 1988 (Cth), the Australian Privacy Principles, any applicable health records law and, where it applies, the GDPR. That includes having the consents, notices and authority needed to place Personal Information about participants, workers and others on the Platform and to share it with anyone you give access to.
Upload only the Personal Information you need for the purpose you are using the Platform for. Do not use the Platform as a general document store for material unrelated to compliance, and do not upload more participant information than a policy, record or piece of evidence requires.
You must not upload:
- full payment card numbers, card verification codes, bank account credentials, passwords, or government identifiers such as tax file numbers, except where the Platform provides a specific, protected field for that item;
- Personal Information about a person who has asked you not to hold it, where the law requires you to honour that request;
- material that you are prohibited from disclosing by a court order, a confidentiality obligation, or a law; or
- material that you know or ought to know is false, fabricated or misleading, as described in clause 5.
You are responsible for keeping your own copies of Customer Data to the extent you need them. The Platform's export tools exist so that you can do so at any time.
5Evidence integrity
The Platform holds the policies, records and evidence that regulators and auditors rely on to decide whether a provider is safe to deliver care. The integrity of that material is the point of the Platform. This clause applies to every user and is enforced strictly.
You must not:
- create, upload or alter a record so that it represents something that did not happen, or did not happen at the time or in the way the record states;
- backdate a policy, review, training record, incident report, consent or any other record, or alter timestamps, version histories or audit trails;
- present a draft, template or AI-generated document as a policy or procedure that has been reviewed, approved or implemented when it has not been;
- present Output, or a score, status or report produced by the Platform, as a certification, registration or a statement of compliance from any regulator, auditor or from Rise;
- submit, or cause to be submitted, to the NDIS Quality and Safeguards Commission, an approved quality auditor, or any other regulator or auditor, information from the Platform that you know or ought to know is false or misleading; or
- conceal from an auditor a record that the scope of the audit requires you to disclose, or manipulate the sharing controls to present an incomplete or misleading picture of your compliance.
Giving false or misleading information to the NDIS Quality and Safeguards Commission, or to an auditor acting for it, is an offence under the NDIS Act 2013 (Cth) and may also be an offence under the Criminal Code Act 1995 (Cth) and state law. Where we become aware of conduct of this kind, we may suspend or terminate access under clause 10 and may be required by law to report it.
6Using AI features
The Platform's AI features draft, summarise, map and analyse. They do not decide. Output from an AI feature can be wrong, incomplete or out of date, and it can reflect biases in the material it was trained on. You must have a suitably qualified person review AI Output before you adopt it as a policy, rely on it for a compliance decision, submit it to a regulator or auditor, or act on it in relation to a participant.
You must not use AI features to:
- generate a record of an event, assessment, review or consultation that did not take place;
- make a decision about an individual that has legal or similarly significant effects on them, such as a decision about their support, their employment or their access to a service, without meaningful review by a person;
- generate material that is unlawful, that infringes another person's rights, or that breaches clause 3;
- attempt to extract the prompts, system instructions, models or training data behind a feature, or to make a feature act outside the purpose it is provided for; or
- process Personal Information beyond what the purpose of the feature reasonably requires.
Where the Platform indicates that a document or section was generated or substantially drafted by an AI feature, you must not remove that indication before a qualified person has reviewed and approved the content.
7Auditors and consultants
If you access the Platform as an auditor, assessor or consultant, the material a provider shares with you is shared for the engagement it was shared for and for nothing else. You must:
- use the material only for that engagement, and only for as long as the engagement requires;
- keep it confidential, and not copy it outside the Platform except as your engagement and your professional obligations require;
- maintain the independence, objectivity and professional standards that your role and any accreditation you hold require, including the requirements of the NDIS (Approved Quality Auditors Scheme) Guidelines where they apply to you;
- not solicit the provider's workers or participants, or use the material to compete with the provider or with Rise; and
- record your findings honestly and only against evidence you have actually reviewed.
Rise is not a party to your engagement with a provider and does not supervise it. Nothing in this Policy reduces your obligations to the provider, to a regulator or to a professional body.
8Security testing and vulnerability reporting
You must not carry out penetration testing, vulnerability scanning, load testing, fuzzing or any other security testing against the Platform without our prior written agreement, which will set out the scope, timing and rules of engagement. Unauthorised access to, or impairment of, a computer system is an offence under Part 10.7 of the Criminal Code Act 1995 (Cth), and an agreed scope is what separates research from an offence.
If you discover a vulnerability in the Platform, we want to know. Report it to dev@riseos.care with enough detail for us to reproduce it. We ask that you do not access, alter or download Customer Data beyond the minimum needed to demonstrate the issue, that you do not disclose it publicly until we have had a reasonable opportunity to fix it, and that you act in good faith. We will acknowledge a report within two business days, keep you informed of our progress, and will not take legal action against a researcher who reports in good faith and within these guidelines.
9Respectful conduct
The Platform is used by people who work in care, and much of what it holds concerns people who receive care. Treat both with respect. Do not use messages, comments, findings, notes or any other feature of the Platform to harass, bully, intimidate, demean or discriminate against anyone, and do not record about a participant or worker anything that a reasonable person in their position would consider gratuitous, disrespectful or irrelevant to the purpose of the record.
10Monitoring and enforcement
We do not routinely read Customer Data. We may, however, review Customer Data and usage where we have a reasonable basis to believe this Policy or the Terms of Service have been breached, where a user reports misuse, where the law or a court or regulator requires it, or where it is necessary to protect the security of the Platform or the safety of a person. We keep logs of access and activity for security, support and audit purposes.
If we determine that this Policy has been breached, we may, depending on the seriousness of the breach and having regard to clause 16 of the Terms of Service:
- warn you and require that the conduct stop or that material be removed;
- remove or disable access to material;
- suspend one or more Authorised Users, or your whole account;
- terminate the Agreement under clause 6 of the Terms of Service; and
- where the law requires or permits it, report the conduct to a regulator, a professional body or law enforcement, and cooperate with any investigation.
Except where it would be unlawful, would compromise an investigation, or would risk harm to a person or to the security of the Platform, we will tell you what we have found and give you a reasonable opportunity to respond before we suspend or terminate.
11Reporting misuse
If you believe someone is using the Platform in breach of this Policy, or that material on the Platform infringes your rights, tell us at dev@riseos.care. Include the account, material or conduct concerned and why you believe it breaches this Policy. We will acknowledge your report within two business days and will tell you the outcome where we are able to.
12Changes to this Policy
We may update this Policy in accordance with clause 17 of the Terms of Service. Changes that materially affect your rights or obligations will be notified to your account holder at least 30 days before they take effect. The current version is always available at riseos.care/acceptable-use, with the date it was last updated.
Questions about this document go to dev@riseos.care. Read it alongside our Terms of Service.