Privacy policy
How Pillar Health Systems collects, uses, stores and discloses personal information, in line with the Privacy Act 1988 (Cth) and the Australian Privacy Principles.
Information we collect
- Clinic account details: names, business contact details and billing information
- Patient interaction data processed on behalf of a clinic: call recordings, transcripts, messages and booking details
- Technical data: log records, device information and usage metrics for our own service
How we use it
Patient information is processed solely to deliver the service to the clinic that collected it. We act as a service provider to the clinic, which remains the holder of the patient relationship and the primary responsible entity.
Storage and security
- Data is stored and processed in Australia
- Encrypted in transit and at rest, with least-privilege internal access
- Patient data is not used to train third-party foundation models
- Access is logged and auditable
Retention and deletion
Interaction data is retained for the period agreed with the clinic and deleted on request or at the end of the agreement, other than records we are legally required to keep.
Access, correction and complaints
Patients should contact their clinic in the first instance. Clinics and individuals may contact us directly to request access, correction or deletion, or to make a privacy complaint; unresolved complaints may be escalated to the Office of the Australian Information Commissioner.
Privacy questions
Contact us for a copy of our data-handling documentation or to complete a vendor privacy assessment.
