Contents
Privacy Policy
1.Introduction & Scope
Welcome to Avand Health, a product of Avand Solutions Pty Ltd (ABN 96 687 039 416; ACN 687 039 416), a proprietary company registered in New South Wales, Australia (“Company,” “we,” “our,” or “us”). We are committed to handling your personal information in accordance with the 13 Australian Privacy Principles (APPs) set out in the Privacy Act 1988 (Cth).
This Privacy Policy describes how we collect, use, disclose, and protect personal information when you access or use our AI-powered clinical documentation services. Our security architecture is informed by AS/NZS ISO 27799:2011 (Health informatics — information security management in health) and NIST SP 800-66 Rev 2 as architectural reference standards.
This policy applies to all practitioners, their staff, and patients whose information is processed through our platform.
2.Information We Collect
a. Practitioner Information
- Contact details: name, email address, phone number
- Professional credentials: qualifications, profession registration number (e.g., AHPRA / Psychology Board / AASW / PACFA registration number), practice name and address
- Payment information: billing details for subscription services (processed by our payment provider)
- Account credentials and access logs
b. Health & Clinical Data
For practitioners using our AI-assisted documentation tools, we process:
- Voice recordings of therapy sessions (see §4)
- AI-generated transcripts of sessions
- AI-generated clinical note drafts (requiring practitioner review and approval before use)
- Recording-consent status, as recorded by the treating practitioner
- Sensitive identifiers encrypted at the application layer: Medicare number, Medical Record Number (MRN), and similar identifiers
Voice recordings are sensitive information — specifically health information — under the Privacy Act 1988 (Cth), and may contain biometric characteristics. Their collection requires explicit consent under APP 3.3 (see §4).
c. Device, Usage & Cookies
- Device information: device type, operating system, browser type, IP address
- Usage data: access timestamps, feature usage metrics to improve platform functionality
- Cookies and similar technologies: we use essential cookies needed to operate and secure the platform, and analytics cookies that help us understand usage. Essential cookies are required for the service to function; you can control or disable non-essential cookies through your browser settings.
We do not use clinical content for analytics, advertising, or tracking. Any analytics is limited to non-clinical usage data.
3.How We Collect Your Information
- Directly from you: when you register, configure your account, or interact with our services
- During session recording: voice and audio data captured through our platform, on the instruction of the treating practitioner, who is responsible for obtaining and documenting the patient’s consent (see §4)
- From third parties: professional registration verification services, as necessary to confirm practitioner credentials
- Automatically: device and usage data collected through platform logs
4.AI Processing, Voice Recordings & Consent
Voice Recordings — Sensitive Health Information
Voice recordings of clinical sessions are sensitive information — and specifically health information — under the Privacy Act 1988 (Cth), and may contain biometric characteristics. We treat them as sensitive information whose collection requires explicit, informed consent under APP 3.3. We collect voice recordings on the instruction of the treating practitioner, who is responsible for obtaining and documenting the patient’s explicit, informed consent before the recording begins, consistent with OAIC’s guidance on privacy and AI products (October 2024).
Patient consent must be:
- Obtained before any recording commences
- Recorded by the practitioner as part of the clinical file
- Freely given, specific, informed, and unambiguous
AI Processing — No Model Training on Customer Data
We do not use customer clinical content — including voice recordings, transcripts, or AI-generated note drafts — to train, fine-tune, or improve any AI model.
Our AI providers (Microsoft Azure OpenAI Service, Azure AI Speech) are contractually bound under the Microsoft Data Protection Addendum and Microsoft Product Terms not to use Avand customer data for model training or improvement purposes.
AI Outputs Are Drafts Only
All AI-generated content (transcripts, note drafts, summaries) is a draft requiring review, editing, and approval by the treating practitioner before it becomes part of any patient record. The practitioner is responsible for the accuracy and clinical appropriateness of all finalised documentation.
5.How We Use Your Information
We use your personal information to:
- Provide services: enable access to and use of our AI transcription and clinical documentation tools
- Improve platform functionality: analyse aggregated, non-clinical usage metrics to enhance the service
- Communicate: send service updates, support messages, and billing information
- Marketing: with your consent, send information about new features or relevant resources
- Comply with legal obligations: respond to lawful requests from regulators and courts
You can withdraw marketing consent at any time. Every marketing email includes an unsubscribe link, and we action unsubscribe requests within 5 business days, consistent with the Spam Act 2003 (Cth). Withdrawing marketing consent does not affect service or transactional communications.
Clinical data is used only for the purpose for which it was collected (APP 6). We do not use clinical content for secondary purposes, including AI model training or product improvement.
6.Data Security
We implement security measures that are reasonable in the circumstances (APP 11.1), informed by AS/NZS ISO 27799:2011 and NIST SP 800-66 Rev 2:
- Australian data residency: all clinical data hosted in Microsoft Azure Australia East (Sydney)
- Geo-redundant storage: geo-redundant storage (GRS) for blob data across Australia East and Australia Southeast; database backups are retained in-region
- Encryption in transit: TLS 1.2+ enforced for all data in transit
- Encryption at rest: Microsoft-managed encryption at rest on all storage services
- Application-layer encryption: sensitive identifiers (Medicare number, MRN) encrypted using AES-256-GCM envelope encryption; key encryption keys stored in Azure Key Vault (software-protected)
- Identity & access: practitioner sign-in is provided by Clerk (JWT-based authentication); service-to-service access within our Azure environment uses Entra ID managed identities; no password-based database authentication; shared-key access disabled on storage
- Role-based access control: organization-scoped roles limit access to the minimum necessary
- Blob access: storage blobs are not publicly accessible
Avand does not currently hold external compliance certifications (SOC 2, ISO 27001, HIPAA audit). SOC 2 and HIPAA-aligned controls are on our roadmap.
7.Named Sub-Processors
We take reasonable steps before disclosing personal information to overseas entities (APP 8.1). The following sub-processors may process personal information on our behalf:
| Sub-processor | Purpose | Country of processing |
|---|---|---|
| Microsoft Azure | Cloud infrastructure; clinical data hosting; AI processing (OpenAI Service, AI Speech) | Australia East (Sydney); Australia Southeast (Melbourne) for geo-redundant storage |
| Clerk Inc. | Authentication and identity management | United States |
| Stripe Inc. | Payment processing and subscription management | Australia / United States / Ireland (depending on payment flow) |
We will provide at least 30 days’ notice of material changes to this sub-processor list. Last updated: 14 May 2026.
Each sub-processor is bound by data protection obligations consistent with the APPs. Clinical data (voice recordings, transcripts, note drafts) remains in Microsoft Azure Australia East and does not leave Australia.
8.Overseas Disclosure (APP 8)
Under APP 8, we take reasonable steps before disclosing personal information to overseas recipients. Our approach:
- Clinical data stays in Australia: all voice recordings, transcripts, and note drafts remain in Microsoft Azure Australia East (Sydney)
- Identity data (Clerk — US): practitioner authentication information is processed by Clerk Inc. in the United States. We have in place contractual obligations consistent with APP 8.1 accountability requirements
- Payment data (Stripe): payment information is processed by Stripe Inc. across their global infrastructure. Stripe is bound by our data processing agreement
- Microsoft corporate parent: as the ultimate parent of Azure, Microsoft Corp. (US) is subject to our Microsoft Data Protection Addendum which includes APP 8 accountability obligations
By using our services, you acknowledge that some personal information (non-clinical) may be processed by overseas sub-processors as listed in §7, and that we have taken reasonable steps to ensure those recipients handle the information in a manner consistent with the APPs.
9.Data Sharing & Third Parties
We may share personal information with:
- Sub-processors listed in §7, for the purposes described
- Professional indemnity insurers or legal advisers, where necessary to respond to a complaint or legal proceeding
- Regulators and law enforcement, where required by law
- Successor entities, in the event of a merger, acquisition, or sale of business assets, with prior notice to affected users
We do not sell personal information to third parties. We do not share clinical data for advertising, analytics-for-hire, or AI model training by any third party.
10.Data Retention & Deletion
Clinical Records
Clinical records are retained for 7 years from the date of last contact for adult clients. For clients who were under 18 at the time of service, records are retained until the client turns 25, or for 7 years from last contact, whichever is later — consistent with the Psychology Board of Australia Guidelines on record-keeping (issued under s 39 of the Health Practitioner Regulation National Law). Practitioners may have additional obligations under their own profession’s guidelines.
Account Data
Practitioner account data is retained after cancellation and is destroyed in accordance with the deletion process described under Backups & Deleted Data below. Billing and transaction records are retained for the period required by Australian tax and corporate record-keeping law.
Voice Recordings
Consistent with APP 11.2, we do not retain voice recordings for longer than necessary for the purpose for which they were collected. Once the AI transcript and note draft have been generated, the recording is no longer required by us, and the practitioner may delete it. Where a practitioner deletes a voice recording in the platform, the underlying audio file is destroyed. Deletion requests can also be submitted to [email protected].
We act as a processor of clinical data on the practitioner’s instructions. Where we retain clinical records (see “Clinical Records” above), we do so on behalf of, and as directed by, the treating practitioner, who holds clinical custodianship of those records and remains responsible for the statutory retention obligations described in this section. Acting as a processor does not diminish our own obligations as an APP entity under the Privacy Act 1988 (Cth) in respect of personal information we hold.
Security Audit Logs
Security and access audit logs are retained in our active log analytics tier for no longer than necessary for security and compliance purposes, consistent with APP 11.2. Extended retention is on our security roadmap.
Deletion
Practitioners maintain control over patient record deletion within the platform, subject to their professional obligations to retain records for the minimum statutory period.
Backups & Deleted Data
When a record is deleted in the platform it is flagged as deleted and removed from active views, and remains in encrypted storage. Automated permanent destruction is being implemented; until then, permanent destruction is performed on written request to [email protected], subject to the retention obligations described above.
Copies may also persist in encrypted backups and, for blob data, in our geo-redundant storage replica (Australia East and Australia Southeast). Backup and replica copies are protected by the same security controls described in this Privacy Policy and are not used for any other purpose.
11.Your Rights (APP 12 & 13) & DSAR Process
Under APPs 12 and 13, individuals have the right to:
- Access personal information we hold about them (APP 12)
- Request correction of inaccurate, out-of-date, incomplete, irrelevant, or misleading information (APP 13)
How to Submit a Data Subject Access Request (DSAR)
Submit requests to our privacy team at [email protected].
We will acknowledge your request within 5 business days and respond within 30 days. If we cannot provide access to certain information (e.g., because it would reveal another person’s information), we will explain why.
Note: for patient records, requests should be directed to the treating practitioner in the first instance, as the practitioner holds clinical custodianship of those records.
12.Breach Notification
In the event of an eligible data breach under the Notifiable Data Breaches scheme (Privacy Act 1988 (Cth), Part IIIC), we will:
- Conduct an assessment within 30 days of becoming aware of a suspected breach (s 26WH)
- Notify the Office of the Australian Information Commissioner (OAIC) and affected individuals at likely risk of serious harm as soon as practicable after we confirm an eligible data breach (Privacy Act 1988 (Cth) ss 26WK, 26WL). Where the affected information is patient clinical data, we will coordinate notification with, or notify via, the treating practitioner as custodian of the clinical record
- Provide information about the kind of information affected, the steps affected individuals should take, and our contact details for further enquiries
To report a suspected security incident, contact [email protected] immediately.
13.Practitioner Obligations
Avand Health is a clinical documentation assistance tool. We are not a healthcare practitioner, a registered health professional, or a regulated healthcare provider.
Practitioners using our platform remain responsible for:
- Obtaining valid patient consent for recording and AI processing before each session (see §4)
- Reviewing and verifying all AI-generated content before it becomes part of a patient record
- Complying with their own profession’s record-keeping requirements (Psychology Board of Australia, AASW, AHPRA guidelines as applicable)
- Mandatory notification obligations to AHPRA, the relevant professional board, or other regulators — these obligations rest with the practitioner, not with Avand
- Ensuring patients are informed of how their information is processed, consistent with their consent obligations
- Where a patient is a minor, obtaining age-appropriate, parental, or Gillick-competent consent as required by the law of the relevant Australian state or territory. Avand processes minors’ clinical information only on the practitioner’s instruction and does not assess consent capacity
Reference: AHPRA “Meeting your professional obligations when using Artificial Intelligence in healthcare” (March 2024) — responsibility for AI-assisted clinical work sits with the registered practitioner.
14.Automated Decision-Making (APP 1.8)
From 10 December 2026, APPs 1.7–1.9 require an APP entity to disclose in its privacy policy where personal information is used by a computer program to make a decision, or to do a thing that is substantially and directly related to making a decision. We set that out below.
What personal information our automated systems use
- Voice recordings of clinical sessions and the transcripts generated from them
- Clinical content the practitioner records in the platform, including health information
- Sensitive identifiers, where the practitioner enters them (Medicare number, MRN)
Practitioner account, billing, device, and usage data is not used by these systems to produce clinical content.
What those systems produce
Our automated systems transcribe the session and draft clinical documentation from it. A draft may include session notes, mental state observations, suggested diagnostic impressions, risk-related content, symptom trends, formulations, medications mentioned during the session, and draft correspondence such as GP summaries and referrals.
These systems do not decide anything about a person
Every output is a draft. It has no effect until the treating practitioner reviews and confirms it, and only content the practitioner confirms enters the patient record. We do not use automated systems to decide a person’s access to a service, eligibility, treatment, or any other matter affecting their rights or entitlements. Consistent with §9(f) of our Terms of Service, Avand does not monitor patients, issue alerts, or escalate to any person or service.
How to find out more
Contact our Privacy Officer at [email protected]. If you are a patient, ask your treating practitioner in the first instance — they hold clinical custodianship of your record, and can tell you what was drafted and what they confirmed.
15.Policy Updates & Contact
Policy Updates
We may update this policy with 30 days’ notice for material changes. Continued use of the platform after the effective date constitutes acceptance of the updated policy. If you do not accept the changes, you may cancel your subscription.
Complaints
If you believe we have breached the Australian Privacy Principles, you can lodge a complaint by emailing [email protected]. We will acknowledge your complaint within 5 business days and aim to resolve it within 30 days. If you are not satisfied with our response, you may escalate to the OAIC (see below).
Contact — Privacy Officer
Our Privacy Officer is responsible for privacy enquiries, access requests, complaints, and breach reports, and can be contacted at:
Privacy Officer
[email protected]Written correspondence may be addressed to the Privacy Officer, Avand Solutions Pty Ltd, at our registered office in Sydney, NSW, Australia (full postal address available on request).
If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au.
