Privacy Policy
Version 2026-06-13 · Last updated 13 June 2026
This policy explains how Fair Enough (operated by Devoted Abilities) handles personal information. We take privacy seriously: much of the information passing through Fair Enough relates to people with disability and is especially sensitive. We handle it in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
1. Who we are
Fair Enough is a digital signature platform operated by Devoted Abilities. We handle two broad kinds of information: information about the staff who use the platform, and the agreement information our customers send through it. This policy covers both.
2. The information we collect
Account information: the name, email address, organisation details and login/security data of the staff who use Fair Enough.
Agreement information: the documents, signer names, email addresses, signatures, and related details our customers send for signing. We process this on our customers' behalf, on their instructions.
Technical and security information: for security and to evidence the signing process, we record limited technical details such as timestamps, IP address and device/browser information at key events (for example, when an account is created or an agreement is signed).
Billing information: subscription and payment details. Card details are handled by our payment processor (see clause 6); we do not store full card numbers.
3. How we collect it
We collect information directly from the staff who use Fair Enough, from our customers when they create and send agreements, and automatically through the normal operation of the platform (such as the technical details above). Where we collect information about a signer, we generally do so from the customer who is sending them the agreement.
4. Sensitive information
Agreements may contain information about a person's disability, health or NDIS supports. This is "sensitive information" under the Privacy Act and the APPs and attracts extra protection. We handle it only to provide the platform, and we rely on our customers to have the consents and authority needed to send it to us.
5. How and why we use information
We use personal information to:
- provide, secure, maintain and improve the platform;
- send agreements and service-related emails (such as signing requests, reminders and confirmations);
- keep an audit trail of signing activity;
- manage subscriptions and billing; and
- meet our legal obligations.
We do not sell personal information, and we do not use it for unrelated marketing.
6. Service providers we use
We use a small number of trusted providers to run the platform, and we share information with them only as needed to provide the service:
- Google Cloud / Firebase: hosting, database and file storage;
- Stripe: subscription payments and card processing;
- An email delivery provider: to send agreement and service emails;
- Error-monitoring tooling: to detect and fix faults in the platform.
These providers are bound to handle information securely and only for the purposes we engage them for. We do not otherwise disclose personal information except with consent or where required or authorised by law.
7. Where your information is stored
Platform data is hosted in Australia (Google Cloud's australia-southeast1 region). Some of our service providers may process limited data overseas as part of their global operations; where that occurs, we take reasonable steps to ensure it is handled consistently with the APPs.
8. Controller and processor roles
For the agreement and signer information our customers send, the customer (the organisation sending the agreement) decides what is collected and why, so they are responsible for that information as its controller. Fair Enough acts as their processor, handling that information on their instructions to provide the service. If you are a signer or participant, the organisation that sent you the agreement is your first point of contact about your information.
9. Security
We protect information with measures including encryption in transit, access controls, and role- and token-based permissions. No system is perfectly secure, but we take steps appropriate to the sensitivity of the data. If a data breach likely to cause serious harm occurs, we will respond in line with the Notifiable Data Breaches scheme.
10. How long we keep it
We keep signed agreements and audit records for as long as needed to provide the service to our customers and to meet legal obligations. Account information is kept while an account is active and for a reasonable period afterwards. We then delete or de-identify information we no longer need.
11. Access, correction and your rights
You can access and correct your account information through your account or by contacting us. Signers and participants can ask the organisation that sent their agreement (the controller) to access or correct their information; we will assist that organisation as their processor. We will respond to requests within a reasonable time and as required by the APPs.
12. Cookies and analytics
We use only the cookies and local storage needed to keep you signed in and to make the platform work. We do not use third-party advertising trackers.
13. Complaints
To make a privacy enquiry or complaint, email hello@devotedabilities.com.au. We will acknowledge and investigate your complaint and respond within a reasonable time. If you are not satisfied with our response, you can contact the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
14. Changes to this policy
We may update this policy from time to time. The version and effective date are shown at the top of this page. If we make a material change, we will take reasonable steps to let you know.