Privacy Policy

Last updated: May 2026

1. Who We Are

This policy applies to Refract Clinical Pty Ltd(ABN: 33 696 886 352), registered in New South Wales, Australia (“we”, “us”, “our”). We are the data controller for personal information collected through the Refract Clinical platform.

We are bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). Because we handle health information, we take particular care to comply with APP 6 (use and disclosure) and APP 11 (security).

2. Information We Collect

We collect the following categories of personal information:

  • Account information: Name, email address, professional role, specialty, department, years of practice, professional registration details and qualifications
  • Feedback data: Self-assessment responses, colleague feedback (anonymised before delivery), supervisor notes, debrief records, and action plans
  • Usage data: Log data, IP addresses, session information (used for security and error monitoring only)
  • Payment data:Transaction records (card details are processed and stored by Stripe — we do not store card numbers)

Feedback provided by colleagues is collected under a confidentiality undertaking. Individual responses are anonymised before being presented to the subject physician. We collect personal information directly from you when you register, complete interviews, or contact us. We may also receive information from the coordinator or organisation that invited you to the platform.

3. How We Use Your Information

We use personal information to:

  • Provide and operate the feedback platform
  • Generate anonymised feedback reports and debrief sessions
  • Conduct AI-assisted structured interviews and synthesise feedback
  • Send service-related emails (invitations, reminders, reports)
  • Process payments
  • Investigate and resolve security incidents
  • Comply with legal obligations, including mandatory reporting obligations

We do not use your information for advertising, sell it to third parties, or use it to make automated decisions that have legal or similarly significant effects on you without human review.

4. Cookies

We use only strictly necessary cookies required to operate the platform. These are: a session cookie (next-auth.session-token) to keep you logged in, a CSRF token cookie (next-auth.csrf-token) to protect against cross-site request forgery, and a callback URL cookie (next-auth.callback-url) to redirect you correctly after login.

We do not use analytics, advertising, or tracking cookies, and no third-party cookies are set by this website. These cookies do not identify you to any third party. They are required for the platform to function; users who do not wish to accept them should not use the platform.

5. Disclosure of Information

We disclose personal information only:

  • To coordinators and supervisors in the course of a feedback cycle, within the limits set by the platform
  • To third-party service providers who process data on our behalf (see section 6)
  • Where required by law, a court order, or mandatory reporting obligations under the Health Practitioner Regulation National Law
  • In anonymised, aggregated form for research and platform improvement purposes (see section 8)

We do not disclose individual feedback responses to the subject physician or any other party in an identifiable form. We do not sell, rent, or share personal information with any third party for marketing or advertising purposes.

6. Third-Party Service Providers

We disclose personal information only to the following service providers who assist in operating the platform. Each provider is engaged under contractual terms that restrict use of your data to the services they perform for us and prohibit use for their own purposes.

  • Supabase / AWS — database hosting (AWS infrastructure, Oceania region, Sydney, Australia)
  • Fly.io — application hosting (Sydney, Australia)
  • Resend — transactional email delivery (United States)
  • Stripe — payment processing (United States)
  • Anthropic — AI interview and synthesis processing (United States); data is not used to train AI models

Your personal data (database) is stored in Sydney, Australia. Some providers process data overseas (United States) for email delivery, payment processing, and AI interview processing. By using the platform you consent to these transfers under APP 8.1. We take reasonable steps to ensure overseas recipients handle your information consistently with the Australian Privacy Principles, including selecting providers with recognised security certifications and data processing agreements.

7. AI Processing

We use Anthropic’s AI API to conduct structured interviews, synthesise feedback, and generate personalised improvement recommendations. Your personal information is processed by Anthropic solely to provide these services and is not used to train AI models.

AI processing is integral to the platform. By registering and using the Service, you consent to this processing as described in this Privacy Policy. You may withdraw consent at any time by closing your account; however, as AI processing is core to the Service, we are unable to provide a meaningful alternative without it.

8. Research and Service Improvement

We may use data collected through the platform for research purposes, including to improve the quality of feedback generated and to evaluate the efficacy of longitudinal serial feedback as a professional development tool. Any data used for research or disclosed for research purposes will be de-identified and aggregated prior to use, such that no individual can reasonably be identified from it. Once de-identified, this information is no longer personal information under the Privacy Act 1988 (Cth) and may be used or published without further notice to you.

We will not use your identifiable personal information for research purposes without your separate, explicit consent.

9. Data Security

Personal information is stored in Supabase (PostgreSQL), hosted on AWS infrastructure in Sydney, Australia, with AES-256 encryption at rest and TLS 1.2+ encryption in transit. Database connections are certificate-verified. Access within the platform is governed by role-based controls (administrator, coordinator, supervisor, provider) enforced at the API layer and re-verified against the database on each request. Passwords are hashed with bcrypt (cost factor 12) and never stored in plaintext. Administrative actions are recorded in an audit log.

No method of electronic transmission or storage is 100% secure. We will notify you and the Office of the Australian Information Commissioner (OAIC) of eligible data breaches in accordance with the Notifiable Data Breaches scheme.

10. Data Retention

We retain your account and feedback data for as long as your account is active and for a period of 7 years after account closure, consistent with professional record-keeping obligations in the healthcare sector. You may request earlier deletion subject to any legal hold obligations.

11. Your Rights

Under the Australian Privacy Principles you have the right to:

  • Access the personal information we hold about you
  • Request correction of inaccurate information
  • Request deletion of your data (subject to retention obligations)
  • Lodge a complaint with the OAIC if you believe we have mishandled your information

To exercise these rights, contact us at privacy@refractclinical.com. We will respond within 30 days.

12. Changes to This Policy

We may update this policy from time to time. We will notify registered users by email before material changes take effect. The current version is always available at refractclinical.com/privacy.

13. Contact & Complaints

Privacy enquiries and complaints: privacy@refractclinical.com
Refract Clinical Pty Ltd, Level 1, 63-73 Ann Street, Surry Hills NSW 2010, Australia

If we are unable to resolve your complaint, you may contact the Office of the Australian Information Commissioner at oaic.gov.au.