Privacy policy

Last updated: 24 August 2026

This policy explains how [LEGAL ENTITY NAME] (“we”, “us”, “FocusMD”) handles personal information, including health information, when you use the FocusMD service. FocusMD is a clinical documentation assistant used by medical practices, so the information we process is frequently sensitive.

1. Who this policy applies to

There are two groups whose information we handle:

  • Users — doctors, clinic administrators and other staff who hold a FocusMD account.
  • Patients — people whose consultations are recorded and documented by Users. We collect patient information on behalf of, and at the direction of, the medical practice. The practice is the patient's health service provider and controls what is recorded.

2. What we collect

  • Account data: name, email address, role, clinic affiliation, hashed password.
  • Consultation data: audio of the consultation (processed, not retained), the generated transcript, draft and approved clinical notes, suggested coding, and consent status.
  • Usage data: audit records of actions taken in the system (who created, edited, approved or exported a note, and when), and service logs.

3. Health information and consent

Consultation recordings and notes are health information under the Australian Privacy Act 1988. The practice using FocusMD is responsible for ensuring the patient is informed of, and consents to, the recording. FocusMD requires recording consent to be explicitly confirmed by the treating clinician before each session begins, and stores that confirmation with the consultation record.

4. How we use information

  • To generate transcripts and draft clinical notes for review by the treating clinician.
  • To operate, secure and support the service, including audit logging and abuse prevention.
  • To communicate with clinic administrators about their accounts.

We do not sell personal information. We do not use consultation content to train machine-learning models.

5. Speech processing and subprocessors

Audio is transcribed and notes are drafted using OpenAI's API. OpenAI processes this data under API terms that prohibit using customer data to train or improve their models. Other subprocessors include our hosting and database providers ([LIST HOSTING/DATABASE PROVIDERS AND REGIONS]). A current list of subprocessors is available on request.

6. Data storage and security

  • Data is encrypted in transit (TLS) and at rest.
  • Access is role-based and scoped: doctors can only access their own consultations.
  • Every action on a consultation is recorded in an immutable audit trail.

7. Retention

  • Audio: processed and not retained after the session is finalised.
  • Transcripts: automatically purged after the clinic's configured retention period (default 90 days).
  • Approved notes and audit records: retained until the clinic deletes them or the account is closed.
  • Account data: deleted within [30] days of account closure.

8. Your rights and access

Users may access and correct their account data through the service or by contacting us. Patients should direct requests about their health information to the treating practice, which can export the relevant records from FocusMD. You may complain to the Office of the Australian Information Commissioner (oaic.gov.au) if you believe we have breached the Australian Privacy Principles.

9. Contact

Privacy enquiries: hello@focusmd.org · Postal: [POSTAL ADDRESS]