Privacy Policy

Last updated: 15 July 2026

Important: This policy is a plain-English summary of how AspireOS handles personal and health information under the Australian Privacy Act 1988 and the Australian Privacy Principles (APPs). Health information carries extra protection under Australian law, and we handle it accordingly. This summary is provided for transparency and is not legal advice.

1. Who we are

AspireOS is practice-management software operated by AspireOS Pty Ltd (ACN 700 311 780) (“we”, “us”, “AspireOS”). We are an APP entity and are bound by the Australian Privacy Act 1988 (Cth) and, where applicable, state health-records legislation (for example the Health Records Act 2001 (Vic) or the Health Records and Information Privacy Act 2002 (NSW)).

When your practice uses AspireOS to manage its patients, your practice is the entity that decides how patient information is handled and is responsible for its own privacy obligations to its patients. AspireOS processes that information on your practice’s behalf and protects it as described below.

2. What information we collect

  • Account & practice details — names, emails, roles, practice name and contact details.
  • Patient personal information — names, dates of birth, contact details, addresses, funding details (NDIS, Medicare, DVA, etc.), and appointment history that your team enters.
  • Health information — clinical notes, assessments, treatment plans, incidents and related records (see section 3).
  • Payment information — processed by our payment provider (Stripe). We do not store full card numbers; Stripe handles card data under PCI-DSS.
  • Usage & technical data — log data, device/browser information and audit records needed to run and secure the service.

3. Health information (sensitive information)

Health information is “sensitive information” and receives higher protection under the Privacy Act. We only collect it where your practice has a lawful basis and, where required, the patient’s consent. Your practitioners are responsible for obtaining appropriate consent from patients for the collection and use of their health information. AspireOS supports this with features such as explicit, recorded consent capture before any telehealth session is recorded, and full audit trails of what was collected, by whom and when.

4. How we use information

  • To provide the service — scheduling, records, invoicing, communications, the patient portal and related features.
  • To secure the service, prevent misuse and maintain audit trails.
  • To provide support and to communicate about the service.
  • To meet legal obligations.

We do not sell personal information, and we do not use patient health information for advertising.

5. Disclosure & third-party providers

We disclose information only as needed to run the service, to our sub-processors under contract, and where required by law:

  • Hosting & database — Contabo Australia Pty Ltd, Sydney.
  • Payments — Stripe and/or Tyro Health (card processing), when you connect one.
  • Messaging — your chosen SMS/email provider, when configured.
  • AI assistant (optional) — if you enable a third-party AI model provider for the “AspireAi” assistant, some content you send to the assistant may be processed by that provider. Without an AI provider configured, AspireAi runs on a built-in engine and no data leaves AspireOS.
  • Health-fund / Medicare claiming (optional) — Tyro Health or HICAPS, when you connect them.

6. Overseas disclosure (APP 8)

We aim to keep patient data hosted in Australia. Some optional third-party providers may process limited data outside Australia (for example, an overseas AI-model provider if you enable one, or Stripe for payments). Where this occurs we take reasonable steps to ensure the recipient handles the information consistently with the APPs. You can contact us at admin@aspireos.io to confirm which providers apply to your account before enabling overseas processing of health information.

7. Security & storage

We protect information with encryption in transit (HTTPS) and at rest, per-practice data isolation, role-based access controls, audit logging and least-privilege administration. See our Security & Compliance page for details. No system is perfectly secure, but we take reasonable steps proportionate to the sensitivity of the data.

8. Data breaches

We maintain a data-breach response process. If an eligible data breach occurs that is likely to result in serious harm, we will comply with the Notifiable Data Breaches (NDB) scheme, including notifying the Office of the Australian Information Commissioner (OAIC) and affected individuals as required, and will support your practice in meeting its own obligations.

9. Access, correction & your rights (APP 12 & 13)

Individuals can request access to, and correction of, their personal information. Patients should contact the practice that treats them. For account holders, contact us at admin@aspireos.io. We will respond within a reasonable time and may need to verify identity first.

10. Retention & deletion

We keep information for as long as needed to provide the service and to meet legal and professional record-keeping obligations (health records generally must be kept for a minimum period set by law — often 7 years for adults, and until age 25 for children, though this varies by state and profession). When no longer required, information is securely deleted or de-identified.

11. Complaints & contact

To make a privacy complaint, contact us first at admin@aspireos.io. We will acknowledge your complaint and respond within a reasonable time. If you are not satisfied, you can contact the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au or 1300 363 992.

12. Cookies & similar technologies

We use strictly necessary cookies and similar technologies to keep you signed in, secure the service, remember preferences and understand basic, aggregated usage so we can keep the service reliable. We do not use advertising or cross-site tracking cookies, and we do not use patient health information for analytics or marketing. You can control cookies through your browser, though some features may not work without them.

13. Children’s & third-party information

AspireOS is intended for use by practices and their authorised staff, not by patients or children directly. Where your practice enters information about a child or another individual (for example a patient, guardian or emergency contact), your practice is responsible for having the authority and any consent needed to do so. If you believe information has been provided to us without proper authority, contact us at admin@aspireos.io.

14. Changes to this policy

We may update this policy from time to time to reflect changes to the service, our providers or the law. We will post the updated policy here and change the “last updated” date above; where changes are significant we will take reasonable steps to notify you. Your continued use of the service after an update means you accept the revised policy.