Privacy policy

How aurii handles personal and clinical information.

Privacy policy v2.4 · in effect Updated Privacy Act 1988 (Cth)

This policy states how aurii handles personal and clinical information as at 12 October 2026. It is written to the Australian Privacy Principles in the Privacy Act 1988 (Cth). Privacy enquiries go to privacy@aurii.com.au.

Who we are

In this policy, “aurii”, “we”, “us” and “our” mean Aurii Pty Ltd (ABN 52 697 638 538), which operates the aurii platform.

“You” means the people whose personal information aurii handles: the clinicians and practice staff who use it, and the patients whose clinical information passes through it.

The platform is built, hosted and secured by Black Shard Pty Ltd (ABN 66 696 910 773) under contract to Aurii Pty Ltd.

This policy covers this website, the aurii applications for iPhone, iPad and Android, and the web application at app.aurii.com.au.

What we collect

aurii collects five groups of information.

  • Accounts Account and practice information Names, work emails, provider numbers, specialty, practice or hospital affiliation and role, supplied by you or by the organisation that created your account.
  • Clinical Clinical information you create The consult audio, the transcript, the note, letters and discharge summary drafted from it, and the patient identifiers and billing items attached to them.
  • Documents Clinical documents you capture Photographs and scans of hospital labels, chart front pages, admission summaries, referrals, medication charts, and pathology and imaging reports, together with the text read from them.
  • Operational Operational and device information Sign-in events, the device and app version in use, the action taken on each record, and the diagnostic logs needed to keep the service available.
  • Events Event registration details When you register for an aurii event such as a launch dinner: your name, specialty or role, mobile number, email, practice name and address, the hospitals you work at, and any dietary or accessibility requirements you give. Dietary and accessibility requirements can be health information, and the registration form collects them only with your consent. Your name and those requirements may be given to the venue for seating and catering.

aurii does not buy personal information from data brokers and is not advertising-funded.

The clinical application carries no third-party advertising and no advertising tracking.

Clinical information

Patient health information means the consult audio, the transcript, the documents drafted from them, and the clinical documents you photograph or upload.

Each session recording carries a purge date, 30 days after the session by default. A daily sweep deletes the recording and clears the reference to it.

How we use it

aurii uses that information for five purposes.

  • Provide To provide the service To transcribe the consult, draft the note, letters and discharge summary, and capture billing items for a clinician to review and sign.
  • Deliver To deliver correspondence To send a signed letter to its chosen recipient and record the delivery acknowledgement against it.
  • Protect To authenticate and account for access To authenticate users, prevent misuse, and maintain the record of who did what and when.
  • Support To support and maintain To diagnose faults and keep the service available.
  • Events To run aurii events To arrange your place at an event you registered for and to contact you about it.

Clinical information is not used for marketing.

aurii does not sell personal information or health information.

Your content is not used to train models.

Where the data is held

Consult audio, transcripts, scanned document images, drafted documents and the audit log are stored and backed up inside Australia, on Microsoft Azure.

Encrypted database backups are held for 35 days.

The hosting arrangement

Encryption and keys

Clinical information is encrypted on every hop in transit, and encrypted at rest with AES-256.

Dictation audio, the clinical documents clinicians photograph or upload, and the rendered note and letter PDFs are held in object storage encrypted under a customer-managed key held by aurii in Azure Key Vault in Australia.

The database, which holds note and letter text, transcripts and the audit log, is encrypted under keys managed by the platform, and its encrypted backups inherit those keys. A separate key for each class of data is planned and not yet in effect.

Three value types carry a second layer of encryption applied before the value reaches the database: Medicare numbers, Individual Healthcare Identifiers and multi-factor authentication secrets. Each value is encrypted under its own data key, which is wrapped by a key held in Azure Key Vault in Australia, and is stamped with the key version it was written under.

Note text, letter text and transcripts rely on the platform encryption at rest described above. No clinical content is held under per-record application keys.

Each practice's workspace is isolated from every other workspace.

Access control, monitoring and the rest of the security controls.

Sub-processors

Each provider sits in the path of aurii's data, is engaged under contract, and is used only to run the service.

  • Cloud Microsoft Azure · Australia Hosting, storage, encrypted backups, Key Vault, speech-to-text, and the text recognition applied to photographed and uploaded clinical documents. Australia East is the primary region; Australia Southeast holds the geo-redundant backups.
  • Drafting Enterprise AI provider Turns the consult transcript into the draft note, letters and discharge summary, and receives each photographed or uploaded clinical document attached to the encounter, as an image or as a whole PDF, on each note generation. It is engaged under commercial terms and a data processing agreement, and your content is not used to train models.
  • Messaging Medical Objects · Australia Carries signed correspondence to the recipient's clinical software as HL7 v2 over mutual TLS, and returns the delivery acknowledgement.
  • Fax Notifyre · outbound clinical fax Carries the rendered PDF of a signed letter, discharge summary or order to the fax line the clinician addressed it to, and returns the delivery receipt.
  • SMS Twilio Carries a short text message giving a recipient a notice and either a secure link or a one-time code, used for handover access codes, secure-portal share codes, patient order links and prescription tokens. The recipient's mobile number, including a patient's, is disclosed to it. No clinical content is carried in the message body.
  • Mail Microsoft 365 · Australian tenant Carries account and notification email, and any letter a clinician addresses to a plain email recipient, from no-reply@aurii.com.au through aurii's own Microsoft 365 tenant. Delivery failure notices return on the same path.
  • Sign-in Apple, Google and Microsoft · application sign in Where a clinician signs in to the aurii application with an Apple, Google or Microsoft account, that provider authenticates the sign-in and returns the account identifier and email address aurii matches to the user.
  • Push Apple and the browser vendors' push services Deliver a notification to the aurii iOS app, or to a browser on which a clinician has allowed notifications, through the device or browser vendor's push service.
  • Edge Cloudflare Sits in front of the aurii website and the aurii application as the network edge, terminates the encrypted connection there and passes the request through.
  • Payments Stripe Processes subscription payments on an Australian account, charged in Australian dollars. Card details are entered with Stripe and never held by aurii. No clinical information is disclosed to Stripe.
  • Analytics (website) Google Analytics and Cloudflare Web Analytics Measure use of this marketing website. Neither runs in the aurii application and neither receives clinical information.
  • Advertising (website) LinkedIn Measures whether a visitor who arrived from an aurii advertisement on LinkedIn went on to start a trial. It runs on this marketing website for a visit that arrived on a LinkedIn link or carrying a LinkedIn channel tag, and for a later visit from the same browser while the 30-day channel cookie lasts. It never runs in the aurii application and receives no clinical information.
  • Error reporting (website) GlitchTip · Australia aurii's own error tracker, run by Black Shard Pty Ltd on its own server in Australia. It receives a report when a script on this marketing website fails in a visitor's browser. It receives no clinical information, no form contents and no IP address.
  • Analytics (application) Black Shard Analytics · Australia aurii's own page-view measurement, run by Black Shard Pty Ltd on its own servers in the Azure Australia East region. It runs on this marketing website and inside the aurii application, where every address is rewritten to a route template before a measurement is sent, so no record identifier and no clinical information reaches it. The iOS app presents that same application, so it runs there too. Nothing in this flow leaves Australia.

The drafting provider's legal name, its ultimate parent and its contractual terms are supplied in writing on request to hello@aurii.com.au, before any agreement is signed.

aurii discloses clinical information beyond these providers only where a clinician directs it, for example a letter signed and sent to a general practitioner, or where Australian law requires it.

This list is current at the version date above.

Named accounts at Aurii Pty Ltd and Black Shard Pty Ltd hold fleet-wide access to production for support and administration.

What that access shows, what it is recorded against and what it cannot do.

Website analytics

This marketing website uses three analytics services. Two are third parties. The third is aurii's own and stays in Australia. It also runs LinkedIn's advertising tag for a visit that came in on a LinkedIn link or a LinkedIn channel tag.

Google Analytics 4 records page views, clicks on telephone and email links, and whether a form was submitted. It sets analytics cookies. Advertising storage, advertising user data and advertising personalisation are denied on every page load, so no advertising or cross-site signal is sent.

Cloudflare Web Analytics records page views without cookies and without cross-site tracking.

Black Shard Analytics is run by Black Shard Pty Ltd, which builds and hosts aurii, on its own servers in the Azure Australia East region. It records page views without cookies and without a cross-site identifier, and that data does not leave Australia.

Black Shard Analytics is the one of the three that also runs inside the aurii application at app.aurii.com.au. There it records which screen was opened, together with the browser, the operating system, the device class, the screen size, the language and the country that every web request already carries, and the domain a visit arrived from where there is one. It does not record the IP address, and region and city are not stored. Before any measurement is sent, the address is rewritten to a route template, so a patient, encounter, letter, message or any other record identifier is replaced by a placeholder and never reaches the collector. Query strings, page titles and free text are dropped in the same step, no clinical information is recorded, and no session recording is loaded. Google Analytics and Cloudflare Web Analytics do not run in the application at all.

The email sign-up blocks on this site report whether a submission was accepted. The email address is not sent to any analytics service.

This site also records which channel a visitor arrived on. Where a link into the site carries a campaign tag, that tag is reduced to lower case with runs of anything that is not a letter or digit collapsed and a 64-character bound, then stored in a first-party cookie for 30 days and added to the link out to app.aurii.com.au, so that an account can be counted against the channel that produced it. aurii's own tagged links carry a channel word such as linkedin or qr. The cookie is read by this site to decide whether to run the LinkedIn advertising tag. No third party reads it and it carries no clinical information.

The LinkedIn Insight Tag runs on this website for a visit that arrived on a LinkedIn link or carrying a LinkedIn channel tag, for example by clicking an aurii advertisement there, and for a later visit from the same browser while the 30-day channel cookie lasts. It records the pages viewed and whether the visitor then followed a link to start a trial. On such a visit LinkedIn writes first-party cookies on aurii.com.au: li_adsId, a random identifier kept for 180 days with a matching browser-storage entry of the same name, and, where LinkedIn's click identifier is on the landing address, li_fat_id and li_giant. LinkedIn handles that information under its own privacy policy. The tag does not load when the browser sends a Global Privacy Control or Do Not Track signal, and it never runs in the aurii application.

All four can be blocked in the browser, and the site works without them.

This website also reports its own script failures. When a script on the site fails in a visitor's browser, the page sends a report to aurii's error tracker, GlitchTip, which Black Shard Pty Ltd hosts on its own server in Australia. A report carries whether the fault was an error or a rejected promise, its error class, the page path, the file, line and column in this site's own code, the browser family, and whether the device is a phone, tablet or computer. It never carries the error message, the stack, form contents, a query string, a cookie or an identifier, and no clinical information is recorded. The report is passed on by this website's own server, so the visitor's IP address does not reach GlitchTip. Faults raised by browser extensions and by other sites' scripts are discarded. Reports are kept for 90 days.

Every cookie this site and the aurii application set.

Retention and deletion

Every document and every action is written to an append-only, hash-chained audit log. The application database role holds no UPDATE or DELETE permission on it.

Clinical records are held under the record-keeping obligation that applies to the practice: seven years from the last entry for an adult, and until the age of 25 for a person under 18. That obligation sits with the practice, and aurii runs no job that deletes records once it expires.

Where a practice or hospital holds the agreement, that agreement governs retention. Where there is no organisation agreement and no other person holds an active membership, closing the account closes the workspace with it, and records already signed stay under the obligation above until the workspace is archived and purged.

Deleting an account revokes the password, passkeys, authenticator enrolment, backup codes and every active session in the same step, and removes the profile from live systems within 30 days.

A workspace purge is run by the platform operator, not automatically. The workspace is archived, the purge is scheduled with a seven-day grace period written to the audit chain, and the hard delete is then run from a gated command line. The tenant row survives as an audit tombstone.

Data breaches

aurii is bound by the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act 1988 (Cth).

A suspected exposure of patient identifiers is escalated to a director of aurii within 30 minutes of being found. aurii contains the breach and assesses whether it is an eligible data breach, and completes that assessment within 30 days.

Where a breach is likely to result in serious harm to any person, aurii notifies the Office of the Australian Information Commissioner and the affected individuals as soon as practicable, with a description of the breach, the kinds of information involved and the steps recommended in response.

Where aurii holds the information for a practice or hospital, aurii tells that organisation without undue delay, so it can meet its own obligations, and works with it on the assessment and any notification.

Report a suspected breach to privacy@aurii.com.au.

How a security incident is handled.

Your rights

The Australian Privacy Principles give you the following rights over your personal information.

  • Access Ask what personal information aurii holds about you and request a copy.
  • Correction Ask aurii to correct information that is inaccurate, out of date or incomplete.
  • Complaint Raise a privacy concern at privacy@aurii.com.au. If the response does not resolve it, the Office of the Australian Information Commissioner takes complaints at oaic.gov.au and on 1300 363 992.

aurii holds patient information for the practices and clinicians who use it. A patient request usually runs through the treating clinician or the organisation that controls the record, and aurii helps that organisation respond.

aurii's handling of personal information is mapped to each Australian Privacy Principle.

Changes to this policy

Version 2.4, in effect 12 October 2026, replaces version 2.3 of 8 October 2026. It adds the Data breaches section: the escalation of a suspected breach, the 30-day assessment under the Notifiable Data Breaches scheme, who is notified when serious harm is likely, and notice to the practice or hospital whose information is involved.

Version 2.3, in effect 8 October 2026, replaced version 2.2 of the same date. It corrects the LinkedIn advertising tag and the channel cookie. Version 2.2 and earlier said the tag ran only for a visit that arrived from LinkedIn and did not load for any other visit; it also runs for a later visit from the same browser while the 30-day channel cookie lasts, and for a visit carrying a LinkedIn channel tag. The first-party cookies the tag writes on this domain are now named. The channel cookie is described as it is stored rather than as one word from a fixed list, and the statement that it holds no identifier is removed.

Version 2.2, in effect 8 October 2026, replaced version 2.1 of the same date. It removes a statement that no SMS provider was engaged. A live check found the SMS channel armed and called from eight places in the application, so a recipient's mobile number, including a patient's, is disclosed to the SMS carrier. The carrier is now named in the sub-processor list, together with the sign-in, push and network edge providers, which the list had not named.

Version 2.1, in effect 8 October 2026, replaced version 2.0 of the same date. Privacy enquiries, access and correction requests and privacy complaints go to privacy@aurii.com.au. The sub-processor list names Notifyre, the carrier for outbound clinical fax. The drafting entry no longer puts a condition on the sending of a photographed or uploaded clinical document: each document attached to the encounter is sent on each note generation.

Version 2.0, in effect 8 October 2026, replaced version 1.9 of 7 October 2026. It corrects the encryption section. Version 1.9 and earlier said storage keys were managed by the platform and that customer-managed keys were not yet in effect. A live check of the production storage accounts found object storage already encrypted under a customer-managed key held by aurii in Azure Key Vault in Australia, so that wording understated a control that exists. The database stays under platform-managed keys, and a separate key for each class of data is still not in effect.

Version 1.9, in effect 7 October 2026, replaced version 1.8 of 6 October 2026. It adds the LinkedIn Insight Tag on this website: when it runs, what it records, and the Global Privacy Control and Do Not Track signals that stop it.

Version 1.8, in effect 6 October 2026, replaced version 1.7 of 29 September 2026. It states that the second layer of encryption covers three value types: Medicare numbers, Individual Healthcare Identifiers and multi-factor authentication secrets. Version 1.7 also listed prescriber authentication credentials, which aurii does not hold.

Version 1.7, in effect 29 September 2026, replaced version 1.6 of 21 September 2026. It adds event registration details to what aurii collects and why: the mobile number, and any dietary or accessibility requirements a guest gives, which can be health information and may be given to the venue for seating and catering.

Version 1.6, in effect 21 September 2026, replaced version 1.5 of 7 September 2026. It adds browser error reporting on this website: what a report carries, what it never carries, and GlitchTip, the self-hosted error tracker that receives it.

Version 1.5, in effect 7 September 2026, replaced version 1.4 of 6 September 2026. It states in full what the first-party analytics collector records inside the application: the screen, and the browser, operating system, device class, screen size, language and country each request carries, plus the referring domain where there is one. The previous wording said the screen and nothing else, which understated it.

Version 1.4, in effect 6 September 2026, replaced version 1.3 of 5 September 2026. It states where information is held and no longer states where any processing step runs, keeps the no-training commitment as a plain term under How we use it, and keeps the sub-processor list complete by function.

Version 1.3, in effect 5 September 2026, replaced version 1.2 of the same date. It names the third analytics service, Black Shard Analytics, which is first-party, held in Australia, and the only one that runs inside the aurii application, and it sets out the route-template rewrite that keeps record identifiers out of it.

Version 1.2, in effect 5 September 2026, replaced version 1.1 of 27 July 2026. It states the AI provider generically, adds the full sub-processor list, covers the clinical documents clinicians photograph or upload, and adds the website analytics clause.

Earlier versions are available on request at hello@aurii.com.au.

Contact

A privacy request should name the account email it relates to. A request about a specific patient record should name the practice or hospital that holds it.

Privacy enquiries privacy@aurii.com.au

The security controls behind this policy are on the security page. The Australian Privacy Principles mapping is on the compliance page.

Email us about privacy

This policy sits alongside the terms of service.