Privacy Policy
01The short version
Consulta holds the minimum needed to run bookings: account details for clinics and doctors, booking records, and the consult documents the parties choose to exchange. Consult documents are visible only to the booking's clinic, its doctor, and Consulta operations, never to other clinics, other doctors, or anyone else. We treat consult documents as sensitive health information and handle them under the Australian Privacy Principles and the applicable state health-records laws.
02What we collect
Clinics and doctors: name, email, contact details, and for doctors the credentials needed for verification (AHPRA registration, indemnity certificates, identity verification via a hosted provider, Consulta never stores identity media itself).
About patients: bookings carry an opaque reference chosen by the clinic; optionally, the patient's name, date of birth and contact details, supplied by the clinic so the booked doctor can identify the patient in the doctor's own clinical records and so we can send that booking's confirmation message; and any consult documents (questionnaires, notes, scripts) the clinic or doctor attaches. Every patient field is optional and the booking works without them; we never require patient details or clinical information. Whatever the clinic supplies is visible only to that booking's clinic, its booked doctor, and Consulta operations.
03Health information and consent
Consult documents may contain health information, which is sensitive information. Consulta processes it as an intermediary so the clinic and its booked doctor can run the consult: it is encrypted in transit and at rest, access is enforced per booking at the database layer, files are served through short-lived signed links, and it is never used for any secondary purpose, not analytics, not model training, not marketing.
Because this information reaches us from the clinic rather than the patient, the clinic must obtain the patient's specific, informed consent before supplying any patient details or attaching any document, covering both sharing with the booked doctor and Consulta's handling of it, and must be able to evidence that consent. The clinic confirms this at the point of booking. Consulta relies on that consent and on the clinic's warranty of it.
04Appointment confirmations
When a clinic supplies patient contact details, Consulta sends a single appointment confirmation on the clinic's behalf. The message is sent in the clinic's name and identifies that it is sent on the clinic's behalf through its scheduling provider, with contact details for follow-up, as required by the Spam Act. Beyond that one message, patient contact details are visible to the booked doctor as part of the booking record and are never used for marketing or any other purpose.
05Use and disclosure
We use the data above to run bookings, payments, payouts, verification and support. We do not sell data and we do not use consult documents for any purpose other than delivering that booking. Service providers (hosting in Australia, and a licensed payment processor once live payments are enabled) process data on our behalf under contract. We disclose information only when the law requires it.
06Retention and destruction
We keep data only as long as we need it. Patient details on a booking (name, date of birth, contact) are retained only while the booking's purpose requires them, including any review or dispute of that consult, and are then deleted or de-identified. Consult documents are retained only for as long as the booking's purpose requires and are then deleted or de-identified; a clinic may request removal of patient details or consult documents from a booking at any time. Booking and payment records are kept as long as needed for the account relationship and our legal obligations, then deleted. Data is hosted in Australia (Sydney region).
07Data breaches
We maintain a data-breach response process. If a breach involving personal or health information is likely to cause serious harm, we will assess it promptly and notify the affected individuals and the Office of the Australian Information Commissioner as the Notifiable Data Breaches scheme requires.
08Access, correction and complaints
Account holders can access and correct their information from their portal, or ask us at the address below. Patients wishing to access or correct information held about them should contact their clinic, which holds the primary relationship; we will support the clinic in responding. Privacy questions or complaints: privacy@consulta.dev. If you're not satisfied with our response, you can complain to the Office of the Australian Information Commissioner (OAIC).