← Back
The Shift Stack

Privacy Policy

Last updated: [DATE]

Draft for review. Placeholder wording to be reviewed and finalised by a qualified advisor against the Australian Privacy Act and the Australian Privacy Principles before public launch. Not legal advice.

Our two roles

For your account and billing information, we are the data controller. For the patient information your clinic enters or connects, your clinic is the controller and we act as a data processor on your instructions. A Data Processing Agreement is available to clinics.

What we collect

How we use it

To provide the Service, process payments, keep it secure, and support you. We do not sell your data, and we do not use patient data for advertising.

AI-assisted features

When you use the letter-writer or Cliniko auto-drafting, the relevant clinical text is sent to our AI provider (Anthropic) to generate a draft. The AI provider does not train on this data. We are finalising a zero-retention arrangement so inputs and outputs are not retained after a request is served. Every output is draft-only and reviewed by a clinician before use. We recommend your patient intake consent covers AI-assisted preparation of correspondence.

Where your data lives and who processes it

Each clinic's data is isolated from every other clinic.

Security

Data is encrypted in transit and at rest by our infrastructure providers, access is scoped per clinic, and integration keys are encrypted and only decrypted server-side. No system is perfectly secure, but we take reasonable steps to protect your data.

Retention

We keep clinic content while your account is active and for a reasonable period afterwards, then delete or de-identify it. You can request export or deletion at any time (subject to your own record-keeping obligations).

Patient rights

Patients should direct access, correction or deletion requests to their clinic (the controller). We will assist the clinic in responding.

Contact

Privacy questions: support@shiftspinalhealth.com.au.