For your account and billing information, we are the data controller. For the patient information your clinic enters or connects, your clinic is the controller and we act as a data processor on your instructions. A Data Processing Agreement is available to clinics.
To provide the Service, process payments, keep it secure, and support you. We do not sell your data, and we do not use patient data for advertising.
When you use the letter-writer or Cliniko auto-drafting, the relevant clinical text is sent to our AI provider (Anthropic) to generate a draft. The AI provider does not train on this data. We are finalising a zero-retention arrangement so inputs and outputs are not retained after a request is served. Every output is draft-only and reviewed by a clinician before use. We recommend your patient intake consent covers AI-assisted preparation of correspondence.
Each clinic's data is isolated from every other clinic.
Data is encrypted in transit and at rest by our infrastructure providers, access is scoped per clinic, and integration keys are encrypted and only decrypted server-side. No system is perfectly secure, but we take reasonable steps to protect your data.
We keep clinic content while your account is active and for a reasonable period afterwards, then delete or de-identify it. You can request export or deletion at any time (subject to your own record-keeping obligations).
Patients should direct access, correction or deletion requests to their clinic (the controller). We will assist the clinic in responding.
Privacy questions: support@shiftspinalhealth.com.au.