Trust · Australia

Australian Privacy Act: programme in progress.

Every health service provider in Australia is covered by the Privacy Act and the Australian Privacy Principles, whatever its size, and by the Notifiable Data Breaches (NDB) scheme. Our server is in the United States, which is a cross-border disclosure under APP 8. The product has the safeguards below. The contracts, local hosting and the NDB workflow are still open.

Status as of 24 September 2026MedAppz Australia
An illustration of a clinic team reviewing a shared, secured workspace

Where we stand, as of 24 September 2026

This covers the Privacy Act 1988 and the Notifiable Data Breaches scheme. MedAppz does not claim compliance with it or any certification under it. This is a programme in progress, and this table is where it stands. Records are stored on one server: Boston, United States · Hostinger VPS. Using it is a cross-border disclosure under APP 8.

ItemStatusNote
Contract covering APP 8 cross-border disclosureNot startedThe server is in the US. No Australian contract terms are published yet.
Australian hosting regionNot startedThere is one server, in the US. No Australian region is set up.
Sub-processor agreementsNot startedWe hold no signed agreement with any sub-processor yet: not the host, not the AI or speech vendors, not the SMS, email or WhatsApp providers.
NDB scheme: 30-day assessment and notice to the OAICNot startedThe breach register tracks Indian deadlines only. The NDB assessment clock is not built.
My Health Record connectionNot startedNot connected.
Audit trail, emergency access, access reviews, backupsIn placeListed below, each with the module that does it.

In place in the product today

Each of these runs in the product now. The line under each one names the part of the law it relates to. That is a pointer for your own review, not a claim that the clause is met.

An audit trail that cannot be editedRecord opens, searches and exports are written once: who, when, from where, under which permission. The log is append-only by database trigger and hash-chained day by day; the chain is re-verified nightly.Audit schema and AuditLens · Security of personal information — APP 11
One clinic cannot read another’s rowsRow-level security on every tenant table, bound to the transaction. The account the application runs as cannot switch it off.Database row-level security · Security of personal information — APP 11
Emergency access that expires and is reviewedBreak-glass access needs a written reason, lasts at most four hours (a database constraint), and lands on a review queue.BreakGlass · Security of personal information — APP 11
Consent records, by notice versionMessages are gated on the consent notice the patient accepted, by version, at the moment of sending. Withdrawal cancels what is queued.ConsentVault and the consent service · Use or disclosure — APP 6
Access reviews with two-person revocationThe Security Centre runs dated access-review campaigns over privileged grants (full patient data, money, platform, emergency access). A challenge raises a two-person approval; a campaign cannot close with unread items.Security Centre · Open and transparent management — APP 1
Strong sign-in and short sessionsArgon2id password hashing, lockout after five failures, optional or organisation-required app-based two-factor, 15-minute access tokens with rotating refresh tokens, and a five-minute idle-out on shared devices.Identity
Encryption in transit, and sealed credentialsTLS on every connection, with certificates renewed automatically. Keys and passwords a clinic gives us are sealed with AES-256-GCM, bound to the organisation, and never shown back.TLS and the secrets envelope
Nightly verified backups, with a rehearsed restoreThe database and files are dumped every night and each dump is checked before the run counts as a success. A full restore was rehearsed on 3 September 2026.ops/backup.sh
Exports are whitelisted and recordedOnly listed views can be exported, each needs its permission, and each export is recorded with its row count and data classes.Exports · Use or disclosure — APP 6
AI you can switch off, or send redactedOne setting per organisation: off, redacted (the default) or full. Redacted strips the name, date of birth, hospital number, phone and email before the request leaves our server. A named person accepts every draft.AI governance

What you would need to do

  • Keep your own APP privacy policy, and tell patients their records may be held in the United States.
  • Take reasonable steps under APP 8 before disclosing to an overseas recipient, which starts with a contract we have not yet signed.
  • Have your own data breach response plan for the NDB scheme.
  • Do not move real patient records in until the contract is in place.
This page describes our product. It is not legal advice; take your own advice on how the law applies to your practice.

Sub-processors and where they are

Every outside service the product can send data to, where it processes it, and whether an agreement is signed. The list is generated from the register the product itself reads, the same one the Trust Centre shows.

ServiceLocationAgreement
HostingerThe rented server the database, the application and the uploaded files run onOne rented regionNone signed yet
S3-compatible object storageWhere uploaded files and documents live when object storage is switched onThe bucket region the deployment configuredNone signed yet
AnthropicAI drafting and answeringUnited StatesNone signed yet
OpenAIAI drafting and answeringUnited StatesNone signed yet
Google (Gemini)AI drafting and answeringUnited StatesNone signed yet
NVIDIA NIMAI drafting and answeringUnited StatesNone signed yet
The configured speech-to-text serviceTurning a consultation recording into a transcriptWherever SPEECH_API_BASE_URL points — api.openai.com (United States) unless changedNone signed yet
The clinic’s own Jitsi serverCarrying the live audio and video of a video visitWherever the clinic hosts itNone signed yet
ResendSending emailUnited States / European UnionNone signed yet
MSG91Sending SMSIndiaNone signed yet
Meta (WhatsApp Business)Sending WhatsApp messages through the official APIMeta’s global networkNone signed yet
The clinic’s paired WhatsApp numberSending WhatsApp messages from the clinic’s own handset sessionMeta’s global network, through the clinic’s own numberNone signed yet
Google (Firebase Cloud Messaging)Delivering push notifications to a phoneGoogle’s global networkNone signed yet
RazorpayTaking a payment online, and holding a standing UPI Autopay or e-mandate authorisationIndiaNone signed yet
PhonePeTaking a payment onlineIndiaNone signed yet
StripeTaking a payment onlineUnited StatesNone signed yet
Pine LabsTaking a card payment on the counter terminalIndiaNone signed yet
Google SheetsReceiving a scheduled exportGoogle’s global networkNone signed yet
Google Business Profile and MetaReading reviews and publishing the clinic’s repliesGoogle and Meta’s global networksNone signed yet
The clinic’s own mail serverThe mailbox MedAppz proxies rather than copiesWherever the clinic’s mail is hostedNone signed yet
The hospital’s own GST Suvidha ProviderRegistering the hospital’s own patient invoices with the Invoice Registration PortalIndiaNone signed yet
The clinic’s own Tally serverReceiving the accounting export, and answering which vouchers it tookWherever the clinic runs TallyNone signed yet
A database the clinic bringsA destination the clinic asked the product to write toWherever the clinic hosts itNone signed yet

Send us your Privacy Act questions

Your security questionnaire is longer than this page. Leave a number and we will answer it line by line, including where the answer is “not yet”.

We use your name, phone number and clinic name for one thing: to answer this enquiry about MedAppz. It is stored on our own server, in the single region our trust centre names, and it is not sold or passed to anyone else.

Email us

You can withdraw either at any time: write to hello@medappz.com, or tell whoever calls you, and we will delete what you gave us.