Privacy Policy
How we handle personal and health information.
Last updated 29 June 2026 · version 2026-06-29.draft-1
This Privacy Policy explains how MedHound handles personal information, including health information, in connection with the Service. [DRAFT: to be reviewed against the Australian Privacy Principles (APPs) and the Privacy Act 1988 (Cth).]
1. What we handle
On a clinic's behalf we process patient identifiers (name, date of birth, gender), appointment details, and the imaging-study metadata retrieved from the clinic's radiology-provider portals (for example study date, modality, and accession number).
We process the radiology-portal credentials the clinic supplies, stored encrypted, solely to perform lookups the clinic requests or schedules.
2. Why we handle it
Solely to provide the Service: to retrieve and display prior imaging for the clinic's patients, and to operate, secure, and support the platform.
3. Where it is stored (data residency)
Patient and clinic data is stored in Australia. [DRAFT: production is hosted in DigitalOcean's Sydney region; confirm and list all sub-processors and their locations before finalising.]
4. Who can access it
Access is restricted to the clinic's own users (scoped so one practice can never see another's data) and to a small number of authorised MedHound personnel for support and operation of the Service. Access to patient data is logged.
5. Retention and deletion
Deleting a patient removes them from the clinic's lists; recovery and final-deletion timeframes are [DRAFT: to be specified]. Technical failure diagnostics are scrubbed of identifying information and retained only for a limited period.
6. Your rights / contact
[DRAFT] Access, correction, and complaint processes to be specified. Contact: [DRAFT: insert contact / privacy officer].