Compliance & Legal
Privacy questions to ask a session-note software provider
Start with the information the product will handle. For session documentation, that may include sensitive health information, so the privacy conversation needs to be specific.
Follow the information
Ask where recordings, transcripts and notes are processed and stored. Find out who can access them, how retention works and what a deletion request means. Read the provider’s privacy policy alongside its service terms.
Use authoritative guidance
The OAIC recommends due diligence before adopting commercial intelligent tools and advises against entering personal information, particularly sensitive information, into publicly available generative tools. Its guidance covers both information submitted to a system and personal information generated by it. Read the guidance in the context of your practice and seek advice where needed.
Check Avand’s published position
Avand hosts clinical data in Azure Australia East. Blob data is geo-redundant within Australia and database backups stay in-region. Avand does not currently hold external compliance certifications. The Privacy Policy gives the full details.
Ask what deletion means in practice
Ask the vendor to distinguish removal from active views, permanent deletion and expiry from backups. Request the applicable retention periods and any exceptions in writing. Also ask which subprocessors handle clinical information and which handle account or payment information. “Australian hosting” is not a complete answer about every data flow; compare the detailed policy with your intended use.
Put it into practice
Use these prompts to guide your next step.
- Map recordings, transcripts, notes and account data.
- Ask about model training and access controls.
- Read retention, deletion and subprocessor terms.
- Record unresolved questions before deciding.