01The short version
Consulta is operated by Consulta Health Pty Ltd (ACN 700 965 466). Consulta holds the minimum needed to run bookings: account details for clinics and doctors, booking records, and the consult documents the parties choose to exchange. Consult documents are visible only to the booking's clinic, its doctor, and the Consulta team, never to other clinics, other doctors, or anyone else. We treat consult documents as sensitive health information and handle them under the Australian Privacy Principles and the applicable state health-records laws.
02What we collect
Clinics and practitioners: name, email, contact details, and for practitioners the credentials needed for verification (AHPRA registration, indemnity certificates and identity evidence, reviewed through Consulta's credentialing process). A hosted identity-verification integration is planned, and Consulta minimises what identity media it retains.
About patients: patient information reaches Consulta through two channels. When a clinic makes a booking for its patient, it may carry only an opaque reference, or the clinic may supply the patient's name, date of birth and contact details so the practitioner can identify the patient and the booking's messages can send. In that channel patient fields are optional. When a patient books directly through a clinic's booking page or website widget, the patient supplies their own name, email and mobile number, which that channel requires because the practitioner telephones the patient and confirmations must be able to reach them. Patients may also answer a pre-consult questionnaire and share documents through their secure appointment link or patient portal. Whatever is supplied is visible only to that booking's clinic, its booked practitioner, and the Consulta team.
03Health information and consent
Consult documents may contain health information, which is sensitive information. Consulta processes it as an intermediary so the clinic and its booked doctor can run the consult: it is encrypted in transit and at rest, access is enforced per booking at the database layer, files are served through short-lived signed links, and it is never used for any secondary purpose, not analytics, not model training, not marketing.
Where a patient supplies information directly, Consulta collects it with notice at the point of collection. Where a clinic supplies patient information, Consulta handles it in accordance with this policy and the parties' agreement. The clinic remains responsible for its own authority to collect and disclose that information, and confirms that authority at the point of booking.
04Appointment communications
Where a booking carries patient contact details, Consulta sends the transactional messages that booking needs, on the clinic's behalf and in the clinic's name: the appointment confirmation, appointment reminders (email and SMS), a link to the pre-consult questionnaire where one applies, follow-up and rebooking invitations where the clinic or practitioner initiates them, and a scheduled-review invitation where the clinic has set one. Every message identifies who it is sent for and how to follow up, as the Spam Act requires. Patient contact details are visible to the booked practitioner as part of the booking record and are never used for marketing or any purpose beyond running the booking.
05Use and disclosure
We use the data above to run bookings, payments, payouts, verification and support. We do not sell data and we do not use consult documents for any purpose other than delivering that booking. Service providers process data on our behalf under contract and only to deliver the service: database and file hosting (Supabase on AWS, Sydney region), payment processing (Stripe), transactional email delivery (Resend) and SMS delivery (ClickSend). Records are hosted in Australia. Message delivery providers may process the communications they carry (such as an email address and message content) on infrastructure outside Australia. Beyond the operational sharing this policy describes, we disclose information only when the law requires it.
06Retention and destruction
We keep data only as long as we need it. Patient details on a booking (name, date of birth, contact) are retained only while the booking's purpose requires them, including any review or dispute of that consult, and are then deleted or de-identified. Consult documents are retained only for as long as the booking's purpose requires and are then deleted or de-identified. A clinic may request removal of patient details or consult documents from a booking, subject to any record-retention obligation that applies to that record. Booking and payment records are kept as long as needed for the account relationship and our legal obligations, then deleted. Data is hosted in Australia (Sydney region).
07Data breaches
We maintain a data-breach response process. If a breach involving personal or health information is likely to cause serious harm, we will assess it promptly and notify the affected individuals and the Office of the Australian Information Commissioner as the Notifiable Data Breaches scheme requires.
08Access, correction and complaints
Account holders can access and correct their information from their portal, or ask us at the address below. Patients wishing to access or correct information held about them should contact their clinic, which holds the primary relationship. We will support the clinic in responding. Privacy questions or complaints: admin@consultahealth.com.au. If you're not satisfied with our response, you can complain to the Office of the Australian Information Commissioner (OAIC).