Last updated: May 2026
This policy applies to Refract Clinical Pty Ltd(ABN: 33 696 886 352), registered in New South Wales, Australia (“we”, “us”, “our”). We are the data controller for personal information collected through the Refract Clinical platform.
We are bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). Because we handle health information, we take particular care to comply with APP 6 (use and disclosure) and APP 11 (security).
We collect the following categories of personal information:
Feedback provided by colleagues is collected under a confidentiality undertaking. Individual responses are anonymised before being presented to the subject physician. We collect personal information directly from you when you register, complete interviews, or contact us. We may also receive information from the coordinator or organisation that invited you to the platform.
We use personal information to:
We do not use your information for advertising, sell it to third parties, or use it to make automated decisions that have legal or similarly significant effects on you without human review.
We use only strictly necessary cookies required to operate the platform. These are: a session cookie (next-auth.session-token) to keep you logged in, a CSRF token cookie (next-auth.csrf-token) to protect against cross-site request forgery, and a callback URL cookie (next-auth.callback-url) to redirect you correctly after login.
We do not use analytics, advertising, or tracking cookies, and no third-party cookies are set by this website. These cookies do not identify you to any third party. They are required for the platform to function; users who do not wish to accept them should not use the platform.
We disclose personal information only:
We do not disclose individual feedback responses to the subject physician or any other party in an identifiable form. We do not sell, rent, or share personal information with any third party for marketing or advertising purposes.
We disclose personal information only to the following service providers who assist in operating the platform. Each provider is engaged under contractual terms that restrict use of your data to the services they perform for us and prohibit use for their own purposes.
Your personal data (database) is stored in Sydney, Australia. Some providers process data overseas (United States) for email delivery, payment processing, and AI interview processing. By using the platform you consent to these transfers under APP 8.1. We take reasonable steps to ensure overseas recipients handle your information consistently with the Australian Privacy Principles, including selecting providers with recognised security certifications and data processing agreements.
We use Anthropic’s AI API to conduct structured interviews, synthesise feedback, and generate personalised improvement recommendations. Your personal information is processed by Anthropic solely to provide these services and is not used to train AI models.
AI processing is integral to the platform. By registering and using the Service, you consent to this processing as described in this Privacy Policy. You may withdraw consent at any time by closing your account; however, as AI processing is core to the Service, we are unable to provide a meaningful alternative without it.
We may use data collected through the platform for research purposes, including to improve the quality of feedback generated and to evaluate the efficacy of longitudinal serial feedback as a professional development tool. Any data used for research or disclosed for research purposes will be de-identified and aggregated prior to use, such that no individual can reasonably be identified from it. Once de-identified, this information is no longer personal information under the Privacy Act 1988 (Cth) and may be used or published without further notice to you.
We will not use your identifiable personal information for research purposes without your separate, explicit consent.
Personal information is stored in Supabase (PostgreSQL), hosted on AWS infrastructure in Sydney, Australia, with AES-256 encryption at rest and TLS 1.2+ encryption in transit. Database connections are certificate-verified. Access within the platform is governed by role-based controls (administrator, coordinator, supervisor, provider) enforced at the API layer and re-verified against the database on each request. Passwords are hashed with bcrypt (cost factor 12) and never stored in plaintext. Administrative actions are recorded in an audit log.
No method of electronic transmission or storage is 100% secure. We will notify you and the Office of the Australian Information Commissioner (OAIC) of eligible data breaches in accordance with the Notifiable Data Breaches scheme.
We retain your account and feedback data for as long as your account is active and for a period of 7 years after account closure, consistent with professional record-keeping obligations in the healthcare sector. You may request earlier deletion subject to any legal hold obligations.
Under the Australian Privacy Principles you have the right to:
To exercise these rights, contact us at privacy@refractclinical.com. We will respond within 30 days.
We may update this policy from time to time. We will notify registered users by email before material changes take effect. The current version is always available at refractclinical.com/privacy.
Privacy enquiries and complaints: privacy@refractclinical.com
Refract Clinical Pty Ltd, Level 1, 63-73 Ann Street, Surry Hills NSW 2010, Australia
If we are unable to resolve your complaint, you may contact the Office of the Australian Information Commissioner at oaic.gov.au.