Effective 17 August 2026 · Version 1.0
The short version
Patient records stay in your practice management system. We do not copy them, we do not sell anything, we do not train models on your patients, and nothing reaches a patient without one of your staff approving it.
- We do not build a second database of your patients. Your records stay where they are.
- We access your systems through named user accounts that you create, see and can revoke at any time.
- No automation contacts a patient, books an appointment or changes a record without a staff member approving it first.
- Every automated action is recorded, so you can see what happened and who approved it.
- We never sell, rent or share clinic or patient information with anyone for marketing.
- When an engagement ends, our access ends with it.
The detail behind each of those six statements follows, including the parts that are less flattering to us.
What is Plexara's role, legally?
Your clinic remains the organisation responsible for your patients' health information. We work inside your systems on your instruction. We do not become the custodian of your records.
This distinction matters, and it is worth being precise about it. Under the Privacy Act 1988, private sector health service providers are covered regardless of turnover — there is no small business threshold for a clinic. Your obligations to your patients do not transfer to a supplier, and no contract with us can move them. What we can do is work in a way that makes those obligations easier to meet rather than harder.
As for Plexara itself: we are a small Australian business, and depending on turnover a business our size may sit outside parts of the Privacy Act. We do not rely on that. We hold ourselves to the thirteen Australian Privacy Principles regardless of whether the Act compels us to, and we will put that in writing in an engagement agreement. A supplier who points at a turnover threshold as a reason to do less is not a supplier a clinic should let near its patient records.
What information do we collect and hold?
Very little from website visitors, ordinary business contact details from people who enquire, and — during an engagement — the minimum patient information a specific workflow needs in order to run.
| Who | What we hold | Why |
|---|---|---|
| Website visitors | Nothing. No cookies, no analytics, no tracking pixels, and no third-party requests of any kind. | — |
| People who enquire | Name, email address, clinic name, practice management system, and whatever you write in the message. | To answer you, and to keep a record of what was discussed. |
| Clinic staff during an engagement | Names, work email addresses, roles, and system permissions. | To build the workflow and to know who approves what. |
| Patients | Only the fields a specific workflow requires — typically a name, a mobile number, an appointment time, an appointment type and a practitioner. | To perform the task the clinic has asked for, and nothing else. |
We do not collect patient information from any source other than your own systems, and we do not enrich it with anything from elsewhere.
What do we actually touch inside a clinic?
A defined, written list of fields, agreed before anything is built, read through your own system under a named account.
Three practical commitments sit behind that:
- Named accounts, not shared logins. We ask you to create a user in your practice management system for each Plexara person who needs one, with the narrowest permission set that works. You can see that account in your own admin screen, you can see what it did, and you can switch it off without asking us.
- Minimum fields, written down. Before a build starts, we list exactly which fields the workflow reads and writes. If a field is not on the list, the automation does not have it. Clinical notes are almost never on the list.
- No bulk export. We do not take copies of your patient database for development, testing or any other reason. Test environments use invented data.
Automated decision-making
Nothing we build makes a decision about a patient on its own. Software narrows options and drafts messages; a staff member decides.
From 10 December 2026, organisations covered by the Privacy Act must set out in their privacy policy how they use computer programs to make, or to help make, decisions that significantly affect people. The requirement comes from the Privacy and Other Legislation Amendment Act 2024, and it captures ordinary rule-based automation just as much as it captures artificial intelligence — a scoring formula counts.
Most Australian clinics have not yet written this section. We have written ours early, in the same three parts the law asks for, partly because we should and partly so you can see what one looks like.
The kinds of personal information used
Name, contact details, appointment date, time, type and status, practitioner, waitlist preferences and availability, referral source and date, and funding plan dates and utilisation. Clinical notes are not used unless a clinic specifically asks for a workflow that requires them, and we would want a good reason.
Decisions made solely by a computer program
None. This is a design rule, not an aspiration. No workflow we build contacts a patient, offers an appointment, books, cancels, reschedules, discharges, submits a claim or alters a record without a staff member reviewing and approving that specific action. If a clinic asked us to remove the approval step, we would decline.
Things done by a computer program that are substantially and directly related to a decision
This is where our automations do sit, and it is the part worth reading closely:
- Ranking and shortlisting. Producing an ordered list of waitlist patients who could suit a slot, based on appointment type, practitioner and stated availability.
- Drafting. Preparing the text of an SMS or email offer for a staff member to approve or edit.
- Flagging and prompting. Identifying that a funding plan is nearing its end date, that a report is due, that a referral has not been actioned, or that a patient has stopped attending partway through a plan of care.
- Sequencing. Once a staff member has approved an offer, sending it to approved recipients in order and stopping when someone accepts.
- Assembling. Gathering information the clinic already holds into a draft document for a clinician to review, correct and sign.
In each case the program narrows, orders or drafts. A person decides. Clinical judgement — whether a particular patient is appropriate for a particular appointment, what a participant needs next, whether a report is accurate — stays with your clinicians, and we will not build anything that quietly takes it from them.
Do we use AI?
Only where it earns its place, only with the clinic told in advance which service is being used and where it runs, and never in a way that lets a vendor train on your patients.
Many clinic workflows need no AI at all, and we will say so when that is the case rather than adding it for the sake of it. Where a workflow genuinely benefits from a language model — summarising a referral document, drafting text a human will edit — these rules apply:
- We name the service and tell you which country it processes data in, before it is built, in writing.
- We configure it so your data is not retained for or used in model training, and we tell you if a vendor cannot offer that — in which case we do not use it.
- Identifying detail is stripped or minimised wherever the task still works without it.
- Generated text is a draft. A person reads it and approves it. It is never sent or saved on its own.
If you would rather no AI component be used at all, say so and we will build without one or tell you the workflow is not viable.
Who else is involved?
A small number of ordinary business services, listed here in full. None of them receive patient information.
| Service | What it handles | Where |
|---|---|---|
| Vercel | Hosting for this website. Static pages only. | United States / global edge network |
| Formspree | Delivers the enquiry form on this site to our inbox. | United States |
| Google Workspace | Our email and documents, including enquiry correspondence. | Google LLC, multiple regions |
That list is complete, and it is shorter than it was. Typefaces and the animation library used to be loaded from Google Fonts, cdnjs and jsDelivr, which meant your browser handed your IP address to three companies you had never heard of in order to render a page. Those files now come from this domain. Browsing this site contacts nobody but us.
Patient information is not sent to any of the above. During an engagement, patient information stays inside the systems your clinic already runs and already has its own agreements with — your practice management system, your SMS provider, your email. We do not introduce a new destination for your patient data without telling you what it is and getting your agreement first.
Does anything go overseas?
The business services listed above are overseas. Patient information from an engagement is not sent overseas unless a clinic has specifically agreed to a component that requires it.
If a workflow would require patient information to be handled outside Australia, we tell you which service, which country, and why, before it is built — and if you would rather not, we design around it or tell you the workflow cannot be done that way. Most can be built entirely within services you already use.
How is it all protected?
Least privilege, multi-factor authentication everywhere, no shared logins, no copies of your data, and access that ends when the work does.
- Multi-factor authentication on every account that can reach a clinic system or our email. No exceptions.
- Least privilege. Each account gets the narrowest permissions that let the work happen, and no more.
- No shared credentials. Every person has their own account, so every action has a name against it.
- Credentials in a password manager — never in email, chat or a document. We will never ask you to send a password by email, and you should refuse if anyone does.
- Encrypted devices with full-disk encryption and automatic screen lock.
- Encryption in transit. Anything we build communicates over encrypted connections.
- Audit logging. Automated actions are recorded — what ran, when, on what, and who approved it — and the log is visible to you.
- Invented test data. Development and testing never use real patient records.
- Access removed at the end. When an engagement finishes, you disable our accounts and we confirm what has been removed in writing.
What we do not have
We are not certified to ISO 27001 or SOC 2, we have not commissioned an external penetration test, and we are two people rather than a security team.
You will find suppliers who imply otherwise at our size. We would rather you knew the position and judged it, because you are going to ask eventually and the answer will be the same then.
What that means practically: the controls above are real and we will demonstrate any of them on request, but they are the practices of a small firm, not an audited certification. If your clinic requires certified suppliers, we are not the right choice yet, and we will tell you that on the first call rather than after a proposal.
How long is anything kept?
Enquiries for two years. Engagement records for five. Patient information for as long as the workflow needs it, which is usually not at all.
- Enquiries that go nowhere — deleted within two years, or sooner if you ask.
- Engagement records — the scope, the design, the agreed measure, the correspondence — kept for five years for tax, insurance and professional records reasons.
- Patient information — not retained by us. Where a workflow needs to hold something briefly to do its job, such as which offers are outstanding, that is held in the clinic's own environment and cleared when the task completes.
- Your own records stay under your retention obligations, which for most Australian jurisdictions means at least seven years from the last entry for an adult, and until age 25 for a patient who was a child. Those obligations are yours and unaffected by anything we do.
How does someone see or correct their information?
Patients should go to their clinic. Anyone who has contacted us directly can email us.
If you are a patient of a clinic we work with, your records are held by that clinic, not by us. Your request for access or correction goes to them, and we will help them answer it if their systems make that awkward.
If you have contacted Plexara directly — an enquiry, an email, a call — write to hello@plexara.com.au and ask what we hold. We will respond within 30 days, and there is no charge.
If something goes wrong
We tell you within 24 hours of becoming aware, in writing, with what we know and what we do not yet know.
Australia's Notifiable Data Breaches scheme requires an organisation that suspects a breach likely to cause serious harm to assess it — taking all reasonable steps to finish within 30 days — and to notify affected individuals and the Information Commissioner as soon as practicable once it is confirmed. For a breach involving your patients, that obligation is your clinic's.
Which is exactly why our commitment is speed rather than reassurance:
- We notify you within 24 hours of becoming aware of any incident that might involve your systems or data, even before we know how serious it is.
- We tell you what we actually know, and say plainly what we do not.
- We help you run your assessment inside the statutory window — logs, timelines, scope, whatever you need.
- We will not delay telling you while we work out whether it reflects badly on us.
What we ask of clinics
Some things only you can do, and a workflow is only as safe as the environment it runs in.
This is a division of work, not a disclaimer. We are not trying to move risk onto you — we are telling you which controls sit on your side of the line so that neither of us assumes the other has them covered:
- Your own privacy policy and collection notices — telling patients how their information is handled, including any automated processing, is yours to publish. We will help you draft the automation section, and from 10 December 2026 that section is not optional for you.
- Consent for patient contact — whether a patient has agreed to be contacted by SMS or email, and for what.
- Who approves what — nominating which staff can approve which actions, and keeping that current as people join and leave.
- Your own accounts — multi-factor authentication for your staff, removing access for people who have left, and not sharing logins.
- Telling us when someone leaves — including us.
Where responsibility genuinely is shared, our engagement agreement says so specifically rather than in general terms.
Complaints
Email us first. If we do not resolve it, the Information Commissioner will hear it.
Write to hello@plexara.com.au with "Privacy complaint" in the subject line. We will acknowledge within five business days and respond substantively within 30 days.
If you are not satisfied, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au or on 1300 363 992. Victoria, New South Wales and the ACT also have their own health records regimes with their own complaint bodies, and a patient in those states may go to either.
Changes to this page
We date every version and keep the previous ones.
Substantive changes are dated at the top of this page. Where a change affects a clinic we are working with, we tell them directly rather than relying on them to notice.