Legal
Privacy Policy
Elite Allied Health Pty Ltd (ACN 645 070 579, ABN 29 645 070 579) trading as Clinic Chimp
Version au-1.0 ยท Effective 4 September 2026
1. About this policy
Elite Allied Health Pty Ltd (ACN 645 070 579, ABN 29 645 070 579) trading as Clinic Chimp ("Clinic Chimp", "we", "us", "our") operates Clinic Chimp. This policy explains how we collect, hold, use and disclose personal information in connection with the service and how you can access, correct or complain about our handling of it.
Clinic Chimp is used by allied health practices and handles patient health information on their behalf. A subscribing practice remains responsible for its relationship with its patients and its own privacy obligations. We are separately responsible for the personal information we handle under the Privacy Act 1988 (Cth) and the Australian Privacy Principles.
2. Personal information we collect and hold
Depending on how the service is used, we may collect and hold:
- account and user information, including names, email addresses, roles, invitations, authentication identifiers and account preferences
- practice information, including business name, discipline, location, team structure, settings, report recipients and practice-management system credentials
- synced patient and practice records, including practice-management system identifiers, patient dates of birth, first and last seen dates, appointment dates, times, types and statuses, practitioners, locations, invoices, payments, services and products
- rebooking-audit information, including patient and case information retrieved from the connected practice-management system when the feature is used, recorded contact outcomes, and the exact text and result of treatment-note write attempts
- content users create in Clinic Chimp, including goals, coaching questions and messages, action points, feedback, deletion reasons and support communications
- billing information, including Stripe customer and subscription identifiers, plan and subscription status and limited payment-method summaries; full card details are supplied directly to Stripe and are not received or stored by us
- technical and operational information, including session and security data, sync and error logs, email delivery records, unsubscribe preferences and timestamps of actions
We do not store patient names as part of the ordinary synced patient record. A patient name may be retrieved from the connected practice-management system when an authorised user opens a rebooking workflow. The service may also handle health information contained in appointment types, treatment-note text or other content supplied by a practice or user.
3. How we collect information
We collect information directly from users when they create an account, configure the service, invite team members, enter content, contact support or use a feature. We collect practice and patient information from the practice-management system a subscribing practice chooses to connect and authorises us to access. We also receive operational information automatically from the service and from providers that help us run it.
People may contact us without identifying themselves where practical. An identifiable account and practice connection are necessary to provide the subscribed service, control access and protect patient information.
4. Why we handle personal information
We collect, hold, use and disclose personal information where reasonably necessary to:
- create and secure accounts, authenticate users and enforce role-based access
- connect to the practice-management system selected by a practice and sync the records needed to provide the service
- calculate and display analytics, dashboards, goals, reports, rebooking audits and coaching features
- send reports, account messages, invitations, security and sync notices, and support or feedback communications
- administer trials, subscriptions, billing, tax and accounting records
- provide support, investigate errors, protect against misuse and maintain the security, availability and integrity of the service
- comply with law, respond to lawful requests, resolve disputes and establish or defend legal claims
- improve the service and, where described in our Terms and Conditions, produce de-identified and aggregated benchmarking; a practice may email us to opt out of benchmarking
We do not sell personal information and do not use Customer Data for advertising. Clinic Chimp provides analytics to authorised practice users; it is not designed to make clinical decisions or decisions that determine a patient's access to healthcare.
5. Who we disclose information to
We may disclose relevant information to:
- authorised users of the subscribing practice, according to their role and the access selected by the practice
- Supabase for database, authentication and related infrastructure services
- Vercel for application hosting, delivery and operational services
- Resend for email delivery and delivery records
- Stripe for checkout, subscription and payment processing
- the practice-management provider selected by the practice, including Nookal, when reading authorised records or when a user directs the service to write a treatment note
- our professional advisers, insurers, contractors or a purchaser of the business where reasonably necessary and subject to appropriate confidentiality obligations
- regulators, courts, law-enforcement bodies or other recipients where required or authorised by law
Scheduled email reports contain practice and practitioner metrics and may contain user-created goals or action points, depending on the report settings. We do not intentionally include synced patient records in those reports. Bug reports, feature requests and support communications are sent as entered, so users should not include patient information unless it is necessary and authorised.
6. Australia and overseas processing
Our primary Supabase database, which holds core synced practice and patient data, is configured in Sydney, Australia. Our Vercel application functions are also configured to run in Sydney. The service nevertheless uses global delivery networks and providers whose support, security, operational systems, logs, subprocessors or backup arrangements may process or hold some information outside Australia.
Likely overseas locations include the United States for email-service metadata, logs and API records, payment processing and some infrastructure-provider operations, as well as other countries in which our providers or their subprocessors operate. The exact location can depend on the provider, service function and configuration and may change over time. Information processed overseas may include account and recipient email addresses, practice and practitioner metrics, user-entered coaching or feedback content, technical logs, billing contact details and, where it passes through hosting or delivery systems, Customer Data containing health information. Not all personal information remains exclusively in Australia.
Australian privacy law, including Australian Privacy Principle 8, may apply when personal information is disclosed overseas. Our providers publish privacy, data-processing and subprocessor information about their handling. Contact us if you need more detail about a particular information flow before using the service.
7. How we hold and protect information
We use technical and organisational safeguards appropriate to the information we handle. These include encrypted connections, encryption at rest provided by our database provider, server-side handling of integration credentials, role-based access and database row-level controls that separate practices and restrict practitioner access. We limit access to people and providers that need it to operate, secure or support the service.
No online service can guarantee absolute security. Practices and users must protect their credentials, use individual accounts, assign roles carefully and notify us promptly if they suspect unauthorised access.
8. Retention and deletion
We retain personal information only while reasonably needed for the purposes described in this policy, including providing reactivation or export, support, security, dispute resolution and compliance with legal, tax and accounting obligations. Cancelling a subscription does not by itself delete the account or its data. When personal information is no longer needed or permitted to be retained, we take reasonable steps to destroy it or de-identify it.
When a practice administrator uses Delete account, access and billing end immediately and the account and its data are marked for deletion. The data remains recoverable for 90 days. After that recovery window, it becomes eligible for permanent removal through our secure operational deletion process; it does not necessarily disappear automatically on that exact day. Contact support during the window to ask about restoration. Restoration after the window is not guaranteed.
We may retain limited deletion audit, transaction, security or legal records where reasonably necessary. Copies created by an infrastructure provider, including backup or disaster-recovery copies where available, may remain temporarily under that provider's normal overwrite or deletion cycle and are not used for ordinary business purposes.
9. Access and correction
You may ask to access personal information we hold about you or ask us to correct it by emailing reports@clinicchimp.com. We may need to verify your identity and authority. We will respond within the time required by law and will explain any lawful reason for refusing access or correction.
If your request concerns a patient record held for a subscribing practice, contacting that practice first will often be the quickest way to resolve it because the practice controls the source record. You may still contact us directly, and we will assist the practice or respond as required by law.
10. Privacy questions and complaints
Send privacy questions, access or correction requests, and complaints to reports@clinicchimp.com. Please describe the issue and the outcome you seek. We will acknowledge and investigate a complaint, may ask for further information, and aim to provide a response within 30 days.
If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner at oaic.gov.au. You may also have a right to complain to a state or territory health-privacy regulator, depending on the circumstances.
11. Changes to this policy
This policy is version au-1.0, effective 4 September 2026. We may update it when our information handling, providers or legal obligations change. The current version will be published on this page, and we will give account contacts reasonable notice of a material change where appropriate.
12. Contact
Elite Allied Health Pty Ltd (ACN 645 070 579, ABN 29 645 070 579) trading as Clinic Chimp
Privacy contact: Clinic Chimp Privacy Contact
Email: reports@clinicchimp.com