Privacy Policy
How we collect, use, store, and protect your personal information under Australian privacy law.
1. About this Privacy Policy
This Privacy Policy explains how New Era Medical Pty Ltd (ABN 89 682 028 708) ("we", "us", "our") collects, holds, uses, and discloses personal information in connection with the GPguide service ("Service").
We are bound by the Australian Privacy Principles (APPs) contained in the Privacy Act 1988 (Cth) and any applicable registered APP code. This policy is provided in compliance with APP 1 (open and transparent management of personal information).
By using the Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our practices, please do not use the Service.
2. What personal information we collect
We collect only the personal information reasonably necessary to provide and support the Service (APP 3). The categories of personal information we may collect include:
- Name, email address, and professional role (e.g. general practitioner, registrar)
- Authentication credentials (stored in hashed form)
- Practice or organisation name (if provided)
- Subscription plan, billing cycle, and payment history
- We use Stripe as our payment processor — we do not store full credit card numbers on our systems
- Messages you send to support@gpguide.com.au
- Feedback, feature requests, and bug reports
- IP address, browser type, device type, and operating system
- Pages visited, features used, session duration, and referral source
- Error logs and performance data needed to maintain reliability and security
What we do NOT collect
GPguide is designed for non-identifying clinical inputs. We do not collect patient health information, and we do not store the text you enter into GPguide drafting fields or the draft outputs generated. Do not enter patient identifying information into GPguide.
3. How we collect personal information
We collect personal information:
- Directly from you — when you create an account, subscribe, contact support, or interact with the Service
- Automatically — through cookies, analytics tools, and server logs when you use the Service
- From third-party service providers — for example, payment confirmation from Stripe, or authentication data from identity providers
Where practicable, we collect personal information directly from you (APP 3.5). If we receive unsolicited personal information, we will assess whether we could have collected it under APP 3 and, if not, destroy or de-identify it as soon as practicable (APP 4).
4. Why we collect, hold, use and disclose personal information
We collect, hold, use and disclose your personal information only for purposes that are reasonably necessary for, or directly related to, our functions and activities (APP 6). These purposes include:
- Providing, maintaining, and improving the Service
- Processing payments and managing subscriptions
- Responding to support enquiries and communications
- Sending service-related notifications (e.g. billing confirmations, service updates)
- Analysing usage patterns to improve performance and user experience
- Detecting, preventing, and addressing security incidents, fraud, or technical issues
- Complying with legal obligations (including the Notifiable Data Breaches scheme)
We will not use or disclose your personal information for direct marketing unless you have consented, or it is within your reasonable expectation and we provide a simple opt-out mechanism (APP 7).
5. Disclosure of personal information
We may disclose personal information to the following categories of recipients, solely for the purposes described in Section 4:
- Infrastructure and hosting providers — e.g. Supabase (for database and authentication), Vercel or similar (for hosting)
- Payment processors — Stripe, for processing subscription payments
- Analytics providers — to understand usage patterns (data is aggregated/anonymised where possible)
- Professional advisers — accountants, lawyers, or auditors, where necessary
- Government or regulatory bodies — where required by law or a court/tribunal order
We require all third-party service providers to handle personal information in accordance with applicable privacy laws. We do not sell personal information to any third party.
6. Related companies
GPguide is operated by New Era Medical Pty Ltd (ABN 89 682 028 708). At the date of this Privacy Policy, we do not have related companies to which we regularly disclose personal information.
If this changes (for example, through an acquisition, restructure, or establishment of related entities), we will update this section and notify affected users. Any disclosure to a related company will be made in accordance with the APPs and this Privacy Policy.
7. Overseas disclosure
GPguide is hosted in Australia. Some of our third-party service providers (e.g. Stripe, analytics tools) may store or process data in overseas locations, including the United States (APP 8).
Before disclosing personal information to an overseas recipient, we take reasonable steps to ensure that the recipient does not breach the APPs in relation to that information. Where we cannot ensure compliance, we will either:
- Obtain your consent to the overseas disclosure, or
- Ensure that a prescribed exception under APP 8.2 applies
8. Data hosting and storage location
The GPguide service and your account data are hosted in Australia. We rely on infrastructure providers (including Supabase) that describe encryption in transit (TLS) and at rest (AES-256) as part of their security posture. We implement application-level controls appropriate to the nature of our service.
9. Data security
We take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access, modification, or disclosure (APP 11). Our security measures include:
- Encryption in transit (TLS) and at rest (AES-256) via our infrastructure providers
- Role-based access controls and least-privilege administrative access
- Multi-factor authentication available for user accounts
- Rate limiting and monitoring to mitigate brute-force and abuse patterns
- Regular review of security configurations and access permissions
No security measure can guarantee absolute security. We take reasonable steps consistent with Australian privacy expectations and the nature of the information we hold.
10. Data retention and destruction
We retain personal information only for as long as it is needed to fulfil the purposes for which it was collected, or as required by law (APP 11.2). Specifically:
- Drafting inputs/outputs: We do not store the text you enter or the drafts generated
- Account information: Retained while your account is active, and for a reasonable period after closure to handle billing enquiries or legal obligations
- Billing records: Retained as required by Australian tax law (generally up to 5 years)
- Technical/security logs: Retained for a limited period to maintain service reliability, then destroyed or de-identified
When personal information is no longer needed, we take reasonable steps to destroy or de-identify it.
11. Your rights — access, correction and complaints
Under the Australian Privacy Principles, you have the right to:
You may request access to the personal information we hold about you. We will respond within a reasonable period (generally within 30 days). We may refuse access in limited circumstances permitted by law, and we will provide reasons if we do so.
If you believe personal information we hold about you is inaccurate, out-of-date, incomplete, irrelevant, or misleading, you may request that we correct it. We will take reasonable steps to correct the information and notify any third parties to whom we have previously disclosed it.
If you believe we have breached the APPs or handled your personal information inappropriately, you may lodge a complaint by emailing support@gpguide.com.au. We will:
- Acknowledge your complaint within 5 business days
- Investigate and respond within 30 days
- If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au
12. Notifiable Data Breaches
We comply with the Notifiable Data Breaches (NDB) scheme under Part IIIC of the Privacy Act 1988 (Cth).
If we become aware of a data breach that is likely to result in serious harm to any individual whose personal information is involved, we will:
- Take immediate steps to contain the breach and assess the risk of serious harm
- Notify affected individuals as soon as practicable, and in any event within 30 days of becoming aware of the breach (or sooner where required)
- Notify the OAIC as required by law
- Take reasonable steps to reduce the risk of harm
- Maintain a record of the breach and our response in accordance with our data breach response plan
We maintain an internal data breach response plan that is reviewed periodically to ensure compliance with the NDB scheme.
13. Cookies and analytics
We may use cookies and similar technologies (e.g. local storage, analytics scripts) to:
- Remember your authentication session
- Understand how the Service is used (e.g. pages visited, features accessed)
- Improve performance and user experience
You can control cookie preferences through your browser settings. Disabling cookies may affect certain features of the Service (e.g. staying logged in).
14. De-identified and aggregated data
We may de-identify and/or aggregate personal information (excluding health information, which we do not collect) for purposes including:
- Analysing usage patterns to improve the Service
- Developing new features or service offerings
- Identifying business trends
- Compiling aggregated statistics (e.g. number of users, feature popularity)
Once de-identified, this data is no longer personal information and we may use it for our own purposes. We will not publish aggregated data compiled using a sample size small enough to make underlying portions identifiable.
"De-identified" means information that has undergone a process of removing all personal identifiers so that there is no reasonable likelihood of re-identification.
15. Third-party links
The Service may contain links to third-party websites or services (e.g. MBS Online, RACGP resources, eTG). We are not responsible for the privacy practices or content of those third-party sites. We encourage you to review their privacy policies before providing any personal information.
16. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, the Service, or applicable law. The "Last updated" date at the top of this page indicates when the latest changes were made.
Where changes are material, we will take reasonable steps to notify you (for example, by email or a notice within the Service). Continued use of the Service after changes are published constitutes acceptance of the updated Privacy Policy.
For questions about this Privacy Policy, please contact us at support@gpguide.com.au.