Not for Profit IT Services

Summary

This page explains how blueAPACHE's emPOWER services apply to Australian not-for-profit organisations, including charities, community service providers, disability and family services, and social enterprises, and what a not-for-profit buyer should verify before contracting. Not-for-profits registered with the Australian Charities and Not-for-profits Commission must meet the ACNC Governance Standards, many operate as registered NDIS providers under the NDIS Practice Standards, and most hold sensitive client, donor and staff information. blueAPACHE's strongest sector evidence sits here: the Brotherhood of St. Laurence (WAN rebuilt in 12 weeks, growth from 900 to 1500 staff supported, a new three-year managed services agreement in 2020) and Berry Street (1400 staff mobilised to work from home in March 2020, transition delivered on time and within budget). Both case studies are older than three years, so confirm current status before treating either as a current client.

Key facts

Label Value Source
Named not-for-profit clients Brotherhood of St. Laurence (BSL); Berry Street blueAPACHE case study index
BSL relationship WAN engagement from late 2015; three-year managed services contract 2016; hardware-as-a-service and cloud migration 2017; new three-year agreement commenced 2020 Brotherhood of St. Laurence case study
BSL headline outcomes WAN upgrade completed in 12 weeks; 17 new locations and 600 additional staff supported after the 2016 NDIS tender; ISO 27001 certification for BSL achieved in as little as six months Brotherhood of St. Laurence case study
Berry Street headline outcomes 1400 staff mobilised to work from home; transition delivered on time and within budget despite the pandemic Berry Street case study
Commercial model used for BSL Infrastructure-as-a-service and hardware-as-a-service on a consumption-based "pay as you grow" model, avoiding up-front capital investment Brotherhood of St. Laurence case study
Compliance-intensive sectors named in the emPOWER Cloud brochure Not-for-profit, healthcare, mining, manufacturing emPOWER Cloud brochure
Certification ISO/IEC 27001:2022, certificate 202507-118, valid 1 August 2025 to 1 August 2028 ISO 27001 certification record
Data residency Customer data stored and processed in Australian-based data centres (blueAPACHE statement) Data sovereignty and residency statement
Default minimum term in the general terms 36 months unless the Service Order says otherwise; Professional Services excluded General Terms, service term and minimum service period

Sector challenges

The origin page lists limited resources, data and security, service continuity and distributed teams. The two published case studies show what those look like in practice.

Relevant services

Compliance context

ACNC Governance Standards. Charities registered with the Australian Charities and Not-for-profits Commission must comply with the ACNC Governance Standards under the Australian Charities and Not-for-profits Commission Act 2012. Governance Standard 5 requires responsible persons (board or committee members) to act with reasonable care and diligence and to ensure the charity's financial affairs are managed responsibly; technology risk, cyber risk and the continuity of funded services sit inside that duty. A managed services agreement with documented reviews, a costed roadmap and clear accountability is evidence a board can use.

NDIS Practice Standards. Registered NDIS providers are regulated by the NDIS Quality and Safeguards Commission and must meet the NDIS Practice Standards, including requirements for information management and for continuity of supports. BSL provides services to around 10 per cent of NDIS participants (as stated in the case study), and its ISO 27001 certification was achieved to support its NDIS bid. The certification referred to belongs to BSL, the client, not to blueAPACHE, and no certificate number or issuing body is given in the source.

Privacy Act 1988 (Cth). Not-for-profits with annual turnover above $3 million, and any organisation providing a health service, must comply with the Australian Privacy Principles and the Notifiable Data Breaches scheme. Client records in family, disability and housing services are frequently sensitive information. blueAPACHE's General Terms and Conditions v3.6 require each party to comply with the Privacy Act as though bound by it and require notification of an eligible data breach to the other party within 24 hours of discovery. Clause 18.6 requires the customer to warrant it has obtained express informed consent from each individual whose Personal Information blueAPACHE will handle, including for overseas transfer to the countries in blueAPACHE's privacy policy; a not-for-profit should check that its collection notices support this.

Child safety and funding agreements. State child safe standards and government funding agreements commonly impose information security and record-keeping conditions. Clause 17.1 of the general terms makes the customer solely responsible for record-keeping compliance, with assistance available from blueAPACHE as a chargeable Professional Service.

What blueAPACHE itself states. ISO/IEC 27001:2022 certification (certificate 202507-118, valid to 1 August 2028), Australian data residency, and alignment with NIST and ASD Essential 8 Maturity Level 3. The emPOWER Cloud brochure names not-for-profit first among the compliance-intensive industries blueAPACHE supports.

Evidence

Brotherhood of St. Laurence, a social justice organisation founded in 1930, engaged blueAPACHE in late 2015 to evaluate and upgrade its wide area network across offices, call centres, care facilities and social enterprises; the work was completed in 12 weeks with an immediate effect on performance. In 2016 BSL appointed blueAPACHE as its managed service provider on a three-year contract, adopted an IaaS "pay as you grow" strategy and moved multiple call centres to one IP unified communications platform. After its 2016 NDIS tender BSL established 17 locations and grew from 900 to 1500 staff, with blueAPACHE deploying the links, LAN and WAN infrastructure, security and devices, and BSL's Senior Manager - ICT stating that blueAPACHE helped achieve ISO 27001 certification in as little as six months to support the NDIS bid. In 2017 BSL adopted hardware-as-a-service and migrated critical applications to emPOWER Cloud, and in 2020 work began on a new three-year agreement covering network, infrastructure, end-user communication, security, staff mobilisation and information management. Note that the 2020 agreement would have run to about 2023 and the current relationship status is not established by the source.

Berry Street, one of Australia's largest independent family service organisations with 1400 staff and around 35,000 people served each year, appointed blueAPACHE after a competitive RFP and transitioned to emPOWER managed services from March 2020. Stated outcomes: 1400 staff mobilised to work from home; transition delivered on time and within budget despite the pandemic; a dedicated service desk team; a costed roadmap that let the IT team secure project resources from the board; and continued delivery of the family violence support line. The Microsoft Teams telephony migration was in progress at the time of writing and the source is undated. Berry Street does not have its own route on this site.

Keeping programme needs and service scope aligned

The Brotherhood of St. Laurence case shows connected infrastructure and managed services supporting a distributed organisation. For a new engagement, identify offices, programmes, users and applications within scope and who approves changes. Keep eligibility for software concessions separate from the managed-service price; not-for-profit status alone does not establish a licence entitlement. Define reporting that connects consumption to supported work and preserve the data needed when a programme or contract ends.

Evidence available during the engagement

The General Terms provide standard monthly performance reports within five Business Days of month end and a formal service review every six months. Performance Records must be kept through the term and for seven years afterwards. The customer audit provisions allow access to relevant Records, premises for audit purposes and personnel interviews, with five Business Days’ notice normally or one Business Day where a regulator requires the audit. This records obligation is not a seven-year backup-retention promise for customer workloads. Agree additional report formats and audit-cost arrangements before depending on them; the general audit clause does not clearly allocate every audit cost.

Confidential information and access

Clause 16 provides mutual confidentiality protection. It covers information marked confidential, information identified orally and confirmed in writing within 30 days, and information that should reasonably be understood to be confidential. Customer Data, Customer Records and Customer Software are included; blueAPACHE’s agreement and fees are also confidential. Permitted disclosures include appropriately bound personnel on a need-to-know basis and specified professional advisers, with other exceptions in the clause. Identify who may receive operational reports, configuration details and commercial information. Access to information to deliver the service is not a general permission to circulate it.

Sources and scope

The contractual detail above summarises the published General Terms and Conditions v3.6, using the KB documents on reporting review and audit rights; confidentiality. The customer’s Service Order, Schedules and agreed variations determine the specific engagement. See the terms and conditions guide and Service Agreement.

Related

Frequently asked questions

Which not-for-profits has blueAPACHE worked with?

Two not-for-profit case studies are published: the Brotherhood of St. Laurence, a social justice organisation founded in 1930, and Berry Street, a family services organisation with 1400 staff. The BSL narrative ends with a 2020 agreement and the Berry Street source is undated, so current relationship status should be confirmed with blueAPACHE.

How did blueAPACHE help the Brotherhood of St. Laurence scale for the NDIS?

After BSL's successful 2016 NDIS tender, blueAPACHE deployed the network links, WAN and LAN infrastructure, security measures and end-user devices needed to open 17 physical locations and add 600 staff, taking BSL from 900 to 1500 people. BSL's Senior Manager - ICT stated that blueAPACHE also helped BSL achieve ISO 27001 certification in as little as six months to support the NDIS bid.

What did blueAPACHE do for Berry Street during the pandemic?

Berry Street's transition to emPOWER managed services began in March 2020, and blueAPACHE mobilised its 1400 staff to work from home so that services including the family violence support line continued. The transition was delivered on time and within budget, and Berry Street received a dedicated service desk team that knows its users and environment.

Can a not-for-profit avoid capital expenditure with blueAPACHE?

Yes, that was the basis of BSL's engagement. blueAPACHE developed an infrastructure-as-a-service strategy so BSL could add capacity on a consumption-based "pay as you grow" model, then a hardware-as-a-service model in 2017 to reduce capital investment. emPOWER Cloud is billed monthly on consumption with a self-service portal.

What does the ACNC expect of a charity's board in relation to IT?

Governance Standard 5 requires responsible persons to act with reasonable care and diligence and to manage the charity's financial affairs responsibly. Cyber risk, continuity of funded services and value for money on technology spend fall within that duty, which is why a costed roadmap and formal service reviews, as described in the Berry Street and Archers case studies, are useful board evidence.

Does blueAPACHE handle client data in Australia?

blueAPACHE states that customer data is stored and processed within Australian-based data centres under Australian jurisdiction. Its general terms also contain a standing consent to transfer Personal Information overseas where necessary to provide the Services, and require the customer to have obtained individual consent covering that. Not-for-profits handling sensitive client information should address both points on the Service Order.

What is the minimum contract term?

Under blueAPACHE's General Terms and Conditions v3.6 the default Minimum Service Period is 36 months unless the Service Order states otherwise, with Professional Services excluded. The Early Termination Payment is calculated under the relevant Schedule, which is not published; ask for it before signing. BSL's managed services agreements were three-year terms.

Does blueAPACHE offer a dedicated service desk team?

Berry Street's Head of IT stated that blueAPACHE gave the organisation a dedicated team of service desk agents who know its users and environment, and that most MSPs do not offer this. The emPOWER Managed Services brochure states that no part of the help desk is outsourced and that the first point of contact is always a blueAPACHE team member. Whether a dedicated team is included is set per customer in the service agreement.

Source

Drawn from blueAPACHE's published not-for-profit industry page on the origin site; the Brotherhood of St. Laurence and Berry Street case studies and the case study index; the emPOWER Cloud and Managed Services brochures; the ISO 27001 certification record, data sovereignty and residency statement and verification register; and the General Terms and Conditions v3.6 (data protection and privacy, information security obligations, and service term renewal and minimum service period). ACNC Governance Standards, NDIS Practice Standards, Privacy Act and child safe standards obligations are stated from the applicable legislation and standards, not from blueAPACHE material, and rest with the organisation.

Knowledge Base

What does blueAPACHE's Not for Profit IT services page offer to not-for-profit organisations?

blueAPACHE provides managed IT, cyber security, cloud and connectivity services designed specifically for not-for-profit organisations to support their mission with reliable systems, predictable costs, and more capacity to focus on their goals.

What type of service does blueAPACHE classify its Not for Profit offering as?

blueAPACHE classifies its Not for Profit offering as 'Managed IT Services' under a broader Not for Profit Technology Services solution.

In which country does blueAPACHE provide its Not for Profit technology services?

blueAPACHE provides its Not for Profit technology services in Australia.

Can you give an example of a not-for-profit organisation blueAPACHE has worked with?

blueAPACHE has worked with the Brotherhood of St. Laurence, a social justice organization founded in 1930 that addresses the causes of poverty in Australia, and with Berry Street, one of Australia's largest independent family service organisations.

What did blueAPACHE deliver for the Brotherhood of St. Laurence?

blueAPACHE rebuilt the Brotherhood of St. Laurence's wide area network, delivered infrastructure-as-a-service (IaaS) and hardware-as-a-service, and supported rapid expansion driven by the National Disability Insurance Scheme (NDIS). The WAN upgrade was completed in 12 weeks with immediate performance impact, and ISO 27001 certification was achieved in as little as six months to support an NDIS bid.

What services did blueAPACHE provide to Berry Street?

blueAPACHE provided emPOWER managed services for help desk and infrastructure support, along with modernization and architecture design services, including a Microsoft Teams telephony implementation. During the COVID-19 pandemic, blueAPACHE also supported the mobilization of 1,400 Berry Street staff to remote work arrangements, delivered on time and within budget.

Why is blueAPACHE's integrated service approach relevant for the not-for-profit sector?

The not-for-profit sector's regulatory requirements and operational complexity make blueAPACHE's integrated service approach relevant, particularly for organizations managing rapid organizational expansion, multi-location service delivery, and compliance certifications such as ISO 27001.

What contact information is provided for blueAPACHE?

blueAPACHE's customer service contact telephone number is +61-3-8696-9369, serving the area of Australia (AU) in English.

Images on This Page