Privacy and the APPs
Who this page is for: whoever owns privacy at the practice - and their adviser.
Health information is “sensitive information” under the Privacy Act 1988 (Cth). Refera is designed to handle it solely as the practice’s contracted administrative service provider. Before real data, Australian privacy counsel must determine whether Refera is already an APP entity and whether a Privacy Act section 6EA opt-in registration is required. Any required registration is a launch gate. The controls below apply as product safeguards regardless; they do not claim that counsel has completed the coverage determination.
The current public privacy notice covers the public website, account setup, business support, billing, practice branding and the not-yet-enabled referral service. It does not replace the practice’s own patient collection notice or the executed data processing agreement required before real referral data can flow.
Privacy requests and complaints
Section titled “Privacy requests and complaints”Email [email protected] with the subject Privacy request or Privacy complaint. Do not put patient or referral details in an ordinary email. For a complaint, state what happened and the outcome you are seeking. Refera acknowledges it, investigates the facts and responds with an outcome or next steps; the notice does not promise a fixed response time. If it remains unresolved after Refera has had an opportunity to address it, make a privacy complaint to the OAIC.
Website and telephone voice
Section titled “Website and telephone voice”The text assistant classifies and retrieves against a question inside Refera’s edge function. OpenRouter receives only a bounded product-request category, trusted documentation extracts and their titles - never the visitor’s question, conversation history, email address, practice name or arbitrary page context. Patient-shaped turns are also refused before any model call. Conversation text is not written to the D1 business CRM, Slack, Cloudflare logs or a summary model. When a visitor explicitly asks for follow-up, only their business contact fields and a bounded request category are retained; the UI warns them not to include patient, referral or clinical information. A privacy-shaped enquiry is accepted for safe UI handling but sent to no CRM, outbox, Slack or task sink.
The optional Email me the walkthrough form is narrower again: one work-email field and a non-text bot trap. Unknown fields are refused. Refera first records a metadata-only product information request in the metadata-only D1 business CRM, then sends the product walkthrough link as one requested transactional email. It does not create an account or newsletter subscription, and there is no name, message, patient or referral field.
Refera offers optional AI-assisted product and setup support. Before browser voice starts, the person sees that the call is recorded, names the voice provider and consents to processing. The browser asks for microphone access only after that consent.
The voice provider temporarily saves audio so Refera can prepare the requested privacy-filtered business summary. Refera keeps that summary and limited delivery records. It does not keep a copy of the raw audio or transcript. Refera targets deletion within four hours after delivery; provider retention is capped at one day, and deleted data may remain in provider backups for up to 30 days under its policy. The limited delivery records do not retain caller number, organisation, caller name, raw transcript or raw audio. A customer-visible phone number is shown only after Refera verifies and publishes the active line; otherwise email and chat remain. Browser voice and any published practice line are for product, setup and pricing questions only. For a person, use the contact form or email [email protected].
Provider certifications apply to those providers, not Refera. AWS publishes certification coverage for ISO/IEC 27001, 27017, 27018 and 27701 across its in-scope services. ElevenLabs publishes ISO/IEC 27001 certification and an AICPA Type II system-and-organisation-controls report. Refera does not claim any of those provider assurances as its own.
| Principle | Refera’s control |
|---|---|
| APP 1 - open and transparent management | Published public privacy notice; counsel determination of Refera’s APP-entity coverage and any required section 6EA registration; a privacy impact assessment before real-data launch naming every processor; and a nominated privacy contact. |
| APP 2 - anonymity and pseudonymity | Patients deal with their practice, never with Refera. Identifiers remain available only where the referral workflow requires them; Refera does not claim a separate token vault. |
| APP 3 - collection | Only what arrives in the referral the practice already receives, only on the practice’s instruction - no enrichment, no other sources. |
| APP 4 - unsolicited information | The locally tested HealthLink adapter holds and pages a synthetic message demonstrably addressed to another organisation before any downstream delivery or extraction; no live HealthLink receiver is enabled. Other real-data channels remain blocked until equivalent handling and a retention schedule are proven. No automated destruction is claimed today. |
| APP 5 - notification | The practice’s collection notice names Refera; template wording ships in the onboarding pack. |
| APP 6 - use and disclosure | One purpose only: the contracted service. No secondary use, no sale, no training AI on patient data, ever. |
| APP 7 - direct marketing | Patient information is never used for marketing. Refera never auto-sends or independently contacts a patient; named practice staff may use an approved generic booking draft through the practice’s verified channel for the contracted administrative purpose. |
| APP 8 - cross-border disclosure | Referral and patient processing stays in AWS Sydney and is verified in CloudTrail before any patient data flows. Public website, onboarding, payments, optional voice and support requests contain business or generic information only. Their presently identified likely overseas recipient countries are the United States, United Kingdom, Ireland, Netherlands and Singapore. The voice clickwrap names provider processing before any web session. |
| APP 9 - government identifiers | Medicare and provider numbers are data on the referral, never Refera’s own identifiers. |
| APP 10 - quality | The connected console shows extracted fields beside the verbatim source excerpt and attachment metadata. Patient-data capture also requires source-document retention, authenticated retrieval, restore/readback and complete export to be proven end to end. |
| APP 11 - security | Encrypted pooled DynamoDB storage, tenant-partitioned access, server-held seal keys, no patient data in logs, and detection on before real data. No per-practice key or token-vault claim. |
| APP 11.2 - destruction | Current account closure revokes access and preserves records; it does not delete or de-identify them. A reviewed primary-record deletion or de-identification process plus backup-retention evidence must be deployed and evidenced before live capture begins. Refera does not claim instant cryptographic erasure. |
| APP 12 - access | Access requests go to the practice. Authenticated structured export is free at any time. Object-Locked source-archive storage is deployed in AWS Sydney; complete source retention, authenticated retrieval and export must be proven end to end before live capture begins. |
| APP 13 - correction | Corrections are sealed as new events with the prior value preserved in append-only history, never quietly rewritten. |
Related
Section titled “Related”- Public privacy notice - the public collection, use, disclosure, retention and contact notice.
- Data residency - APP 8 in depth.
- Sub-processors - who else ever touches anything.
- Breaches and state law - beyond the APPs.
Did this answer your question?
Thanks - that helps us make these docs better.
Refera tracks referral admin only. It does not triage patients.
Examples are fictional and contain no patient information. Practice staff approve every external action. Refera never auto-sends or independently contacts patients.
Refera homeStart account setupOpen ReferaPrivacyTerms
[email protected]AI-assisted product and setup support. For a person, use the contact form or email.