Discuss a reportContact
Clearview Data & Automation

Privacy Policy

Last updated:

This policy explains how Clearview Data & Automation handles personal information when you use our website, contact us or engage our services. It is written for individuals, medical practices, clinicians and healthcare organisations.

Our approach is informed by the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs) and the Notifiable Data Breaches scheme. We will meet the obligations that apply to our activities. This policy describes our approach; it is not legal advice or a certification of compliance.

Please do not submit patient-identifiable information or sensitive clinical details through the public contact form. Describe your reporting needs in general terms. If patient information is needed for an agreed service, we will arrange an appropriate transfer method separately.

Information we collect

We collect information you provide directly, and limited information generated when you use the website. Depending on your interaction, this may include:

  • Your name, email address, optional phone number and practice or organisation name.
  • Enquiry details, correspondence and support requests.
  • Basic website analytics, such as page visits, browser and device information, approximate location and selected interactions.
  • Business contact, customer account and service administration information where applicable to a contracted service.
  • Health or patient information only where specifically required for an authorised service, as described below.

Hosting and website delivery providers may also process IP addresses and technical request or security logs. You can browse without providing contact details. If you choose not to provide information needed for an enquiry or service, we may be unable to respond or deliver that service.

How information is used

We use relevant information to:

  • Respond to enquiries and discuss your requirements.
  • Provide contracted reporting, data and automation services.
  • Administer customer relationships and accounts, deliver services and provide support.
  • Protect systems, investigate misuse and help prevent fraud.
  • Understand website use and improve our website and services.
  • Meet applicable legal obligations and agreed customer requirements.

Patient information is not used for marketing or website analytics.

Health and patient information

Patient and clinical information is highly sensitive. We only access or process it where the healthcare organisation has authorised the work, the information is necessary for the agreed service, and appropriate access controls are in place. Any consent or other lawful authority required for that handling must also be established.

We use the minimum information necessary for the task, with de-identified or aggregated information where it can meet the requirement. Access is limited to authorised people who need it for that service.

Engaging Clearview does not automatically give us access to your practice management system (PMS), clinical systems or patient records. The scope, access permissions, transfer method and handling requirements are agreed separately. The website’s reporting examples use synthetic data.

Security

We take reasonable steps to protect personal information from misuse, loss and unauthorised access, modification or disclosure. The website’s safeguards include:

  • Encryption in transit: HTTPS/TLS protects connections to the public website. The website’s connection to its email delivery service also requires TLS.
  • Restricted access: the deployment configuration separates publishing access from administration and limits the application’s permissions, following least-privilege principles.
  • Credential handling: email credentials are held in private server configuration, outside public website files, and are not sent to visitors’ browsers.
  • Abuse prevention and logging: contact submissions are validated and rate-limited. Application delivery-failure logs do not include enquiry contents or credentials.

Contact enquiries are delivered to our business mailbox; the website does not keep them in an application database. Operational logging and the ability to roll back website releases support fault investigation and recovery.

For healthcare services, storage and database encryption at rest, hosting locations, access auditing, backups and recovery arrangements must be confirmed for the agreed environment before sensitive data is provided. No system or transfer method can be guaranteed completely secure.

Third parties and analytics

Some website and business service providers may process information outside Australia; healthcare-data arrangements are agreed separately.

We use providers where needed to operate the website and deliver services. These include cloud hosting and website delivery providers, Cloudflare for website delivery and protection, Google Workspace for business email, and Google Analytics for basic website measurement. Providers may process information relevant to their role; disclosure may also occur where required or authorised by law.

Google Analytics uses cookies and processes website usage and browser/device information. Our website sends a limited set of page and interaction events. Analytics must not receive patient information, contact-form message contents or other sensitive clinical data. Our event handling excludes form values, patient rows and URL query strings, and disables advertising signals and ad personalisation.

You can block or delete analytics cookies through your browser settings or use a tracking blocker. The website’s core functions do not depend on analytics. See Google’s privacy policy for its handling of information.

Any provider involved in processing patient information for a contracted service must be considered separately as part of the authorised service arrangements. Using Google Analytics on this website does not authorise sending patient data to Google.

Retention and deletion

We retain personal information only for as long as reasonably necessary for the purpose it was collected, applicable legal obligations or agreed customer requirements. When it is no longer needed, we take reasonable steps to securely delete it or de-identify it where appropriate, including arranging deletion with relevant providers.

Retention and deletion requirements for healthcare data, including any backup copies, are agreed for the service. Legal retention duties may limit when information can be deleted.

Access and correction

You can request access to, or correction of, personal information we hold about you by emailing [email protected]. Tell us what you are seeking without including sensitive clinical details. We may need to verify your identity and authority using an appropriate method.

We will respond within a reasonable time. If we cannot provide access or make a correction, we will explain the reason, subject to applicable law, and how you can complain. For patient records held on behalf of a healthcare organisation, we will work with that organisation; you can also contact your healthcare provider directly.

Data breaches

We will investigate suspected breaches, take steps to contain them and assess the information and people affected. Where a healthcare organisation is involved, we will coordinate the response with it.

We will comply with applicable notification obligations, including under the Notifiable Data Breaches scheme. Where an eligible breach is likely to result in serious harm and the scheme requires notification, this includes notifying affected individuals and the Office of the Australian Information Commissioner (OAIC). Contact us promptly if you suspect a privacy or security issue.

Privacy questions and complaints

Email [email protected] with your privacy question or complaint. Please explain your concern and how we can contact you, without sending patient records or sensitive clinical material.

We will acknowledge your complaint, investigate it and aim to respond within 30 days. If more time is needed, we will explain why and keep you informed. If you are not satisfied with our response, or do not receive one within 30 days, you can contact the OAIC about making a privacy complaint, where it has jurisdiction.

Updates to this policy

We may update this policy as our services, information-handling practices or legal requirements change. The current version will be published on this page with a revised “Last updated” date.

Back to the main website