Privacy Policy
Last updated: 13 July 2026
​
1. About CliniScribe and this policy
​
The AI Dev Australia Pty Ltd (ABN 62 678 241 800), trading as CliniScribe AI (CliniScribe, we, us or our), provides software that assists healthcare and allied-health organisations and practitioners with clinical documentation, transcription, workflow and related services (Services).
​
This Privacy Policy explains, in general terms, how we collect, hold, use, disclose and protect personal information. It applies to our websites, applications, support services and related business activities.
​
This policy does not replace the privacy notice, consent process or legal obligations of a healthcare provider or other organisation using the Services (Customer). More specific terms may also apply under a customer agreement, data processing agreement or Business Associate Agreement (BAA). Where those terms provide additional protections for Customer Data, those terms will apply alongside this policy.
​
2. Our role when handling information
​
CliniScribe may handle personal information in different capacities depending on the context.
​
-
For information used to operate our own business—such as account, billing, sales, website, support and business-contact information—CliniScribe generally determines why and how the information is processed.
-
For patient and clinical information submitted to the Services by or on behalf of a Customer (Customer Data), the Customer generally determines why the information is collected and how it is used. CliniScribe processes that information to provide the Services and follow the Customer’s lawful instructions.
-
Where European or United Kingdom data protection law applies, the Customer will generally be the controller and CliniScribe the processor for Customer Data.
-
Where the United States Health Insurance Portability and Accountability Act (HIPAA) applies, CliniScribe may act as a business associate or subcontractor business associate under an executed BAA.
Customers are responsible for ensuring that they have an appropriate legal basis, authority, privacy notice and any required patient consent for information they submit to the Services.
​
3. Personal information we may collect and hold
​
The kinds of personal information we may collect and hold depend on how a person or organisation interacts with us. They may include:
​
-
account and business information, such as names, professional roles, organisations, work contact details, login details, preferences and subscription information;
-
patient and clinical information submitted to or generated through the Services, including identifiers, appointment information, consultation audio or dictation, transcripts, notes, medical history, symptoms, assessments, diagnoses, treatment information, care plans, referrals, reports and correspondence;
-
billing and transaction information, such as billing contacts, invoices, payment status and limited payment information supplied by a payment provider;
-
technical, device and usage information, such as IP address, browser and device type, operating system, authentication events, feature usage, application activity, integration events, audit logs and security information;
-
communications and support information, including enquiries, demonstrations, feedback, support requests, complaints and incident reports;
-
marketing preferences and information about interactions with our communications; and
-
other information that a person, Customer or authorised integration provides to us in connection with the Services.
​
Customer Data may include sensitive information, including health information. We expect Customers to submit only information that is reasonably necessary for their authorised use of the Services.
​
4. How we collect and hold personal information
​
We may collect personal information:
​
-
directly from a person when they create an account, request a demonstration, communicate with us, subscribe, complete a form or use the Services;
-
from a Customer, authorised user, healthcare practitioner, patient representative or connected system;
-
through consultation audio, dictation, typed content, uploaded files, templates and information generated through use of the Services;
-
automatically through cookies, logs, authentication systems, security tools and similar technologies; and
-
from service providers, professional advisers, business partners and publicly available sources where permitted by law.
​
We hold personal information electronically in systems operated by us and by service providers engaged to support the Services. We use access controls and other safeguards appropriate to the nature and sensitivity of the information.
​
A person may deal with us anonymously or using a pseudonym where this is lawful and practicable. Identification will generally be required to create or administer an account, provide secure access, process payments, deliver support or respond to a request concerning personal or clinical information.
​
5. Why we collect, use and disclose personal information
​
We may collect, hold, use and disclose personal information to:
-
provide, configure, secure, maintain and support the Services;
-
capture or transcribe consultation audio or dictation where enabled by the Customer;
-
generate draft clinical notes, letters, reports, care plans and other documentation requested by authorised users;
-
operate integrations and exchange information with systems selected or authorised by a Customer;
-
authenticate users, administer accounts, manage subscriptions and process payments;
-
respond to enquiries, provide demonstrations, troubleshoot issues and deliver customer support;
-
monitor performance, investigate incidents, prevent fraud or misuse and protect the confidentiality, integrity and availability of information;
-
perform business administration, quality assurance, auditing and service improvement using information permitted by law and contract;
-
send service, security, billing and policy communications;
-
send marketing communications where permitted by law, subject to applicable consent and unsubscribe requirements;
-
comply with legal, regulatory, contractual, insurance and professional obligations; and
-
establish, exercise or defend legal claims and manage actual or proposed corporate transactions.
​
We do not sell Customer Data or use patient or clinical Customer Data for targeted advertising.
​
6. AI-assisted processing
​
The Services use artificial intelligence and machine-learning technologies to support transcription and the generation of draft documentation and related outputs.
​
When a Customer enables these features, relevant audio, text and other Customer Data may be processed by CliniScribe and approved service providers solely to provide, secure and support the Services in accordance with the applicable agreement.
​
CliniScribe does not use Customer Data to train general-purpose artificial intelligence models and does not authorise its AI service providers to use Customer Data for that purpose.
​
AI-generated outputs are drafts intended to assist authorised healthcare professionals. The treating practitioner or Customer remains responsible for reviewing, correcting, approving and appropriately using an output before it is relied upon, communicated or added to a clinical record. CliniScribe does not make final clinical or treatment decisions about patients.
​
7. Service providers and other disclosures
​
We may disclose personal information to organisations that assist us to operate the Services or our business, including providers of:
​
-
cloud hosting, data storage, backup and computing infrastructure;
-
AI-assisted processing and transcription infrastructure;
-
authentication, security, monitoring, logging and incident response;
-
payment processing and subscription management;
-
communications, customer support, analytics and business administration;
-
practice-management and other integrations selected by Customers; and
-
legal, accounting, insurance, audit and professional services.
​
We may also disclose personal information to a Customer and its authorised users, regulators, courts, law-enforcement bodies or government agencies where required or authorised by law, and to parties involved in a proposed or completed merger, financing, restructure or sale of all or part of our business, subject to appropriate safeguards.
​
We require service providers that handle Customer Data to be subject to appropriate privacy, security and confidentiality obligations. Where HIPAA applies, required BAAs or equivalent arrangements will be put in place before a service provider creates, receives, maintains or transmits protected health information on our behalf.
​
A current customer-facing subprocessor list, including processing purposes and available location information, may be provided through our compliance materials or on request.
​
8. Storage and overseas processing
​
Personal information may be stored or processed in Australia and in other countries where CliniScribe or its service providers operate. Depending on the Services and configuration used, overseas recipients may be located in the United States and other jurisdictions.
​
The countries and providers involved may change as the Services develop. Where practicable, current information about material subprocessors and processing locations is made available through our compliance materials, contractual documentation or on request.
​
When personal information is disclosed overseas, we take steps appropriate to the circumstances to assess the recipient and protect the information through contractual, technical and organisational safeguards. Where European or United Kingdom data protection law applies, we use an applicable transfer mechanism where required.
Customers with specific data-residency requirements should contact us before submitting Customer Data.
​
9. Security
​
We use administrative, technical and physical safeguards designed to protect personal information against misuse, interference, loss and unauthorised access, modification or disclosure.
​
Depending on the relevant system and risk, these safeguards include encryption in transit and at rest, access controls, authentication, audit logging, system monitoring, backup and recovery measures, workforce confidentiality requirements, security training, vulnerability management, supplier controls and incident-response procedures.
No system can be guaranteed to be completely secure. Customers and users are responsible for protecting their credentials and devices, managing authorised users and notifying us promptly of suspected unauthorised access.
​
10. Retention and deletion
​
We retain personal information only for as long as reasonably necessary for the purposes for which it was collected, to provide and support the Services, follow Customer instructions, comply with legal and contractual obligations, resolve disputes and maintain appropriate business, audit and security records.
​
Retention periods for Customer Data may vary according to the type of information, account configuration, Customer instructions, contractual requirements and applicable law. The Services may provide Customers or authorised users with controls to delete certain information or configure retention settings.
​
When information is deleted from active systems, limited copies may remain temporarily in protected backups, logs or disaster-recovery systems until they are overwritten or deleted under applicable retention procedures. Such information is not used for ordinary service processing.
​
We may retain limited account, billing, security, audit, dispute and legal records after account closure where reasonably necessary or required by law. Where deletion is not possible or appropriate, we may restrict further use of the information.
​
11. Security incidents and data breaches
​
CliniScribe maintains procedures for identifying, reporting, containing, investigating, assessing, mitigating and remediating suspected security incidents and data breaches.
​
Where an incident involves Customer Data, we will notify the affected Customer without unreasonable delay and within the period required by the applicable agreement or law, and provide material updates as further information becomes available.
​
We will make notifications to affected individuals, regulators or other parties where CliniScribe is legally responsible for doing so. Where the Customer has the primary relationship with affected individuals, notification responsibilities may be coordinated or allocated under the applicable agreement and law.
​
12. Access, correction and privacy rights
​
A person may request access to personal information that CliniScribe holds about them for its own business purposes and may ask us to correct information that is inaccurate, out of date, incomplete, irrelevant or misleading. We may need to verify identity before acting on a request, and legal exceptions may apply.
​
Where a request concerns patient or clinical information submitted by a Customer, the request should ordinarily be directed to the relevant healthcare provider or organisation. CliniScribe will assist the Customer with access, correction, amendment, restriction, portability or other requests where required by law and the applicable agreement.
​
Depending on the law that applies, an individual may have additional rights, including rights to object, request deletion or restriction, withdraw consent or complain to a regulator. These rights are subject to legal conditions and exceptions.
​
HIPAA rights concerning protected health information are generally exercised through the relevant covered healthcare provider or health plan. CliniScribe supports HIPAA-regulated Customers as required by the applicable BAA.
​
13. Direct marketing
​
We may send information about CliniScribe products, services and events where permitted by law. Recipients can unsubscribe using the link in a marketing communication or by contacting us. We may continue to send service, security, billing and legal communications where necessary.
​
14. Cookies and similar technologies
​
Our websites and applications may use cookies and similar technologies for essential functions, authentication, security, preferences, performance and analytics. Where required by law, we seek consent before using non-essential cookies.
​
Browser settings may be used to block or delete cookies, but doing so may affect the operation of some features.
​
15. Children and representatives
​
CliniScribe accounts are intended for healthcare organisations, practitioners and other authorised adult users, not for children to create independently.
​
The Services may process information about children or individuals who require a representative when that information is submitted by an authorised Customer as part of healthcare delivery. The Customer is responsible for obtaining any authority, consent or other lawful basis required for that processing and for managing the rights of parents, guardians or personal representatives.
​
16. Privacy enquiries and complaints
​
A person who has a privacy enquiry, wishes to request access or correction, or believes CliniScribe has not handled personal information appropriately may contact our Privacy Officer using the details below.
​
Please provide enough information for us to understand and assess the matter. We will acknowledge and investigate privacy complaints and respond within a reasonable period. If the matter concerns Customer Data, we may need to coordinate with the relevant Customer.
​
If a person is not satisfied with our response, they may be entitled to complain to the Office of the Australian Information Commissioner or another competent privacy or data-protection regulator.
​
17. Changes to this policy
​
We may update this Privacy Policy to reflect changes to our Services, information-handling practices, providers or legal obligations.
​
The current version will be published on our website with the date of the latest update. Where a change is material, we will take reasonable steps to bring it to the attention of affected Customers or users.
​
18. Contact us
​​
Privacy Officer
CliniScribe AI
The AI Dev Australia Pty Ltd
ABN 62 678 241 800
​
Email: hello@cliniscribe.ai
​
