Privacy Policy
Last updated: 11 August 2026
ClinicIQ Solutions is committed to protecting your personal information and respecting your privacy. This Privacy Policy outlines how we collect, use, disclose, and protect your personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
By using our website and services, you consent to the collection, use, and disclosure of your personal information as described in this policy.
1. Information We Collect
Personal Information
We may collect the following types of personal information:
- Name and contact details: Full name, email address, phone number, postal address
- Business information: Company name, business address, ABN/ACN, job title
- Communication information: Messages, inquiries, support requests, chat transcripts
- Technical information: IP address, device information, browser type, usage data
- Service-related information: Service requirements, project details, feedback
Sensitive Information
We may only collect sensitive information with your explicit consent or where required by law. This may include:
- Health information (only when relevant to healthcare automation solutions)
- Professional registration details (for healthcare professionals)
Automatically Collected Information
When you visit our website, we automatically collect:
- IP address and geolocation data
- Browser type, operating system, and device information
- Pages visited, time spent, and click patterns
- Cookies and similar tracking technologies
2. How We Use Your Information
We use your personal information for the following purposes in accordance with APP 3:
- Service delivery: Providing automation solutions, websites, and consulting services
- Communication: Responding to inquiries, sending service updates, and providing support
- Marketing: Sending newsletters, promotional materials (with your consent)
- Improvement: Analyzing usage patterns to enhance our services and website
- Legal compliance: Meeting legal obligations and protecting our rights
- Research: Conducting market research and service improvement studies
We will only use your personal information for the primary purpose of collection unless you consent to another use or the secondary use is otherwise permitted under law.
3. Information Disclosure
Third-Party Service Providers
We may disclose your information to trusted third-party service providers who assist us in operating our business:
- Web hosting and IT services: Netlify (United States - cloudflare.net), Amazon Web Services (AWS)
- Email services: Outbound notifications via our mail server (SMTP). Enquiry and chat summaries are delivered to our administrator mailbox (including a Google Gmail account) for review and follow-up
- Payment processors: Stripe (United States), PayPal (for payment processing only)
- Analytics services: Google Analytics (Google LLC - United States)
- Chat services: Custom AI chatbot — your messages are relayed through Netlify, processed by OpenAI (API-based - United States), and stored on our own server (n8n automation platform at johnsaenz.au)
Important: Some of these providers are located outside Australia. See Section 6 for international data transfer details.
Third-Party Privacy Rights
You also have the right to contact these third-party providers directly regarding their privacy practices:
- Google Analytics: https://policies.google.com/privacy
- Netlify: https://www.netlify.com/privacy/
- Stripe: https://stripe.com/privacy
- PayPal: https://www.paypal.com/au/webapps/mpp/ua/privacy-full
- OpenAI (API): https://openai.com/policies/privacy-policy
Legal Requirements
We may disclose your personal information where required or authorized by law, including:
- To comply with legal obligations and court orders
- To protect our rights, property, or safety
- To protect the rights, property, or safety of our customers or the public
- In emergency situations where disclosure is necessary
No Sale of Personal Information
We do not sell, rent, or trade your personal information to third parties for marketing purposes.
Chatbot and AI Assistant
Our website chat widget is an automated assistant. This section explains exactly how your chat details are handled:
- What we collect: Before chatting we ask for your name, email address and (optionally) phone number. Your chat messages are also collected.
- How it is processed: Your message is sent through our website host (Netlify) to our automation server (n8n, hosted by us at johnsaenz.au), which uses OpenAI's API (United States) to generate replies. See Section 6 for international transfer safeguards.
- How it is stored: When a chat enquiry is completed, your name, contact details and answers are recorded in our internal enquiry database on our own server.
- Review and follow-up: A summary of your enquiry is emailed to our administrator mailbox so we can respond to you. You will also receive an automatic confirmation email.
- Retention: Chat enquiry records are retained for up to 24 months, and are deleted earlier on request (see Section 5 for how to request deletion).
- Please don't share patient details: The chat is for general and workflow questions only. Please do not enter patient-identifiable information or sensitive health information.
- AI limitations: Chat replies are automated and may be reviewed by us. They are not professional or clinical advice.
4. Data Security
Our Security Commitment: We take reasonable steps to protect your personal information from misuse, interference, loss, unauthorized access, modification, or disclosure in accordance with Australian Privacy Principle 11 (APP 11):
- Technical measures: SSL encryption, secure servers, firewalls, and regular security updates
- Organisational measures: Staff training, access controls, privacy policies, and confidentiality agreements
- Physical security: Secure office premises and document storage where applicable
Security Limitations: While we implement industry-standard security measures, please be aware that:
- No method of transmission over the internet is 100% secure
- We cannot guarantee absolute security of your information
- Security breaches may occur despite our best efforts
Third-Party Services: We use reputable third-party service providers (e.g., hosting providers, email services). While we carefully vet these providers and require appropriate security measures, we cannot be held responsible for:
- Security breaches of third-party providers outside our direct control
- Data loss or corruption in third-party systems
- Unauthorized access to data stored with third-party providers
Your Responsibilities: You also play a role in security by maintaining the confidentiality of your login credentials and notifying us immediately of any unauthorized access to your account.
5. Your Privacy Rights
Access and Correction
You have the right to request access to and correction of your personal information held by us (APP 12). To make a request:
- Email: admin@cliniciq.com.au
- Address: Wollongong NSW 2500
Data Deletion
You have the right to request deletion of your personal information. To make a request:
- Submit a written request to admin@cliniciq.com.au with "Data Deletion Request" in the subject line
- Include your full name, email address, and specify the data you want deleted
- We will acknowledge your request within 5 business days
- We will process and complete your request within 30 days
Retention Exceptions: We may retain certain information where required by law, including:
- Tax records (minimum 5 years under Australian tax law)
- Records relating to actual or pending legal proceedings
- Information required for our ongoing business operations
Data Breach Notification
We comply with the Notifiable Data Breaches (NDB) scheme. In the event of an eligible data breach:
- We will assess the breach promptly to determine if it is likely to result in serious harm
- If serious harm is likely, we will notify affected individuals as soon as practicable (and within 30 days)
- We will notify the Office of the Australian Information Commissioner (OAIC)
- Notifications will include: description of the breach, kind of information concerned, recommendations on steps to take
Examples of serious harm: Serious physical, psychological, emotional, financial, or reputational harm.
Complaints
If you believe we have breached the Australian Privacy Principles, you can:
- Contact our Privacy Officer at admin@cliniciq.com.au
- Make a complaint to the Office of the Australian Information Commissioner (OAIC)
Opt-Out
You can opt out of receiving marketing communications by:
- Clicking the unsubscribe link in our emails
- Contacting us directly at admin@cliniciq.com.au
6. International Data Transfers
Australian-First Approach: ClinicIQ Solutions prioritizes keeping your personal information within Australia whenever possible. However, to provide our comprehensive automation and website services, your personal information may occasionally need to be transferred to and stored on servers located outside Australia.
Third-Party Service Dependencies: Some essential services we use (such as cloud hosting providers, analytics platforms, or communication tools) may operate outside Australia. These transfers are necessary for service delivery but are carefully managed.
Our Protection Commitments: When international transfers occur, we implement the following safeguards:
- Compliance: All transfers comply with Australian Privacy Principle 8 (APP 8)
- Contractual Safeguards: We require overseas recipients to provide protection substantially similar to the Australian Privacy Principles
- Security Measures: We maintain appropriate security measures regardless of where data is stored
- Transparency: We will inform you when international transfers are required for specific services
Important Notice: While we take every reasonable step to protect your information internationally, including implementing robust contractual and technical safeguards, we cannot be held responsible for:
- Actions of foreign governments or legal requirements in other jurisdictions
- Security breaches of third-party international service providers outside our direct control
- Changes to international laws or regulations that affect data protection
- Interception or access to data during international transmission
Your Choice: If you have concerns about international data transfers, please contact us to discuss alternative service arrangements where available.
7. Cookies and Tracking Technologies
This is a static informational website. We do not operate user accounts, process payments, or run a shopping cart, so we have no need for the session, authentication, or checkout cookies commonly found on transactional sites.
Analytics Cookies (Google Analytics)
We use Google Analytics (GA4) to understand which pages are most useful to clinic staff. GA collects anonymous usage data including pages visited, time spent on the site, and approximate geographic region (derived from IP address). It sets cookies (such as _ga and _ga_*) on your browser to do this.
Our consent model: GA loads by default so we retain usage data, and you can opt out at any time. We do not use marketing or advertising cookies, and we do not share GA data with any advertising network.
Cookie banner: On your first visit you will see a cookie banner offering:
- Accept all — keeps analytics running
- Decline — disables Google Analytics immediately and removes its cookies
- Manage preferences — review and adjust your choice
Your preference is stored in your browser's local storage for 12 months, after which you will be asked again. You can change your cookie preferences at any time by:
- Clicking the "Cookie Settings" link in the website footer, or
- Adjusting your browser settings to block or delete cookies.
Note: Declining only affects Google Analytics. It does not affect our ability to operate the website.
8. Children's Privacy
Our services are not directed to children under 18. We do not knowingly collect personal information from children under 18. If we become aware that we have collected such information, we will take steps to delete it promptly.
9. Data Retention
We retain your personal information only as long as necessary for the purposes of collection or as required by law. Retention periods vary based on:
- Legal and regulatory requirements
- Business needs and service agreements
- Your ongoing relationship with us
Chatbot enquiries: records of completed chat enquiries (your name, contact details and answers) are retained for up to 24 months and deleted earlier on request.
10. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. We will:
- Post the updated policy on our website
- Update the "Last updated" date
- Provide at least 30 days' notice for material changes that significantly affect your privacy rights
- Notify you by email or prominent website notice for material changes
Your continued use of our services after the effective date of any change indicates your acceptance of the updated policy. If you do not agree to the changes, you may terminate your use of our services.
11. Australian Jurisdiction and Limitations
Australian-Focused Services: This Privacy Policy is designed for use in Australia and complies with Australian privacy laws. Our services are primarily intended for Australian clients and are governed by Australian law.
Jurisdiction: This Privacy Policy is governed by the laws of New South Wales, Australia. Any disputes relating to privacy matters will be resolved according to Australian law.
International Considerations: If you are accessing our services from outside Australia, please be aware that:
- Your data may be subject to different legal requirements in your jurisdiction
- Australian privacy laws may not apply to the same extent in your country
- International data transfers may be required, with the associated risks outlined in Section 6
- We cannot guarantee compliance with all international privacy laws
Limitations of Control: While ClinicIQ Solutions takes every reasonable precaution to protect your data and comply with Australian privacy standards, we must acknowledge that certain factors remain outside our control:
- International legal requirements that may compel disclosure of data
- Third-party service provider actions and policies
- Government surveillance or data requests in foreign jurisdictions
- Technical limitations in cross-border data security
- Changes in international laws or geopolitical situations
Your Acceptance: By using our services, you acknowledge that:
- You understand these limitations and accept the associated risks
- You understand that while we do our utmost to protect your data, some factors are beyond our control
- You agree that our liability is limited as outlined in our Terms of Service
- You acknowledge that our services are designed and primarily intended for use within Australia
12. Contact Information
If you have any questions about this Privacy Policy or our privacy practices, please contact us:
JOHN SAENZ
ABN: 55 882 511 758
Email: admin@cliniciq.com.au
Address: Wollongong NSW 2500, Australia
Privacy Officer: Please address privacy concerns to the attention of "Privacy Officer" in any correspondence.
Legal References
This Privacy Policy complies with:
- Privacy Act 1988 (Cth)
- Australian Privacy Principles (APPs)
- Notifiable Data Breaches (NDB) scheme - View NDB Guidelines
- Spam Act 2003 (Cth) (for electronic marketing)
- General Data Protection Regulation (GDPR) (where applicable to EU residents)
Key Resources: