1. About this policy
This Privacy Policy explains how VoxVersa collects, holds, uses and discloses personal information when you visit our website, create an account, use the VoxVersa clinical documentation service, contact support or interact with us in another way.
We handle personal information in accordance with applicable Australian privacy law, including the Privacy Act 1988 (Cth) and the Australian Privacy Principles where they apply. A customer agreement or data processing agreement may add stricter requirements for a particular health service deployment.
2. Our role and your organisation's role
For patient and clinical information entered into a workspace, the healthcare provider or organisation usually decides why and how that information is handled. VoxVersa processes that information to provide the service on the customer's instructions. The customer remains responsible for its clinical records, privacy notices, authority to collect information and patient consent obligations.
VoxVersa separately decides how to handle account, billing, website, security and direct support information needed to operate our business. If your organisation provides your account, its privacy policy also applies to its handling of your information.
3. Information we collect
Depending on how you use VoxVersa, we may collect:
- Account and identity information, such as your name, email address, authentication identifiers, profession, role and organisation.
- Clinical content, such as recordings, transcripts, patient details, consultation context, templates, generated documents, corrections and consent records supplied by you or your organisation.
- Workspace and workflow information, including team membership, assignments, approvals, audit events, retention settings and document delivery status.
- Integration information, including identifiers and records exchanged with practice-management, identity, EHR or document systems that you choose to connect.
- Billing information, such as plan, credit, transaction and invoice details. Payment card details are collected and handled by our payment provider rather than stored by VoxVersa.
- Technical and usage information, including IP address, browser and device details, timestamps, diagnostic events, service activity and security logs.
- Communications, including support requests, feedback and the information you choose to include in them.
- Marketing attribution, such as campaign parameters, referral source and advertising identifiers when those features are enabled.
We collect information directly from you, from your organisation and authorised users, from connected systems at your direction, and automatically when you use our website or service. Clinical information may relate to patients who do not use VoxVersa themselves.
4. How we use information
We use personal information to:
- provide transcription, document generation, review, storage, collaboration and integration features;
- create and secure accounts, enforce workspace permissions and maintain audit trails;
- process payments, administer plans and report usage;
- respond to support requests and, with appropriate authority, investigate service problems;
- maintain, monitor and improve the reliability, accessibility and security of the service;
- communicate service, security, billing and policy updates;
- prevent fraud, abuse and unlawful activity, and comply with legal obligations; and
- measure marketing performance where tracking is enabled.
We do not sell clinical content. We do not use customer recordings, transcripts or generated clinical documents to train VoxVersa's general-purpose AI models. We may use aggregated or de-identified operational information where permitted, but not to recreate or identify a patient or customer's clinical content.
5. Automated processing and clinical review
VoxVersa uses automated speech recognition and generative AI to transcribe recordings, extract information and prepare draft documents. These systems may make errors. They do not diagnose, prescribe, determine treatment, decide a person's eligibility for care or replace professional judgement.
An authorised healthcare professional must review and approve clinical outputs before relying on them or adding them to a health record. Users can correct transcripts and documents, and organisation administrators can configure review and governance controls.
6. When we disclose information
We disclose information only where reasonably necessary, including to:
- authorised members of the customer's workspace, according to their assigned access and responsibilities;
- cloud hosting, database, storage, authentication, speech recognition, AI, document-processing, email, analytics and support providers that help us deliver the service;
- payment providers for purchases, subscriptions, fraud prevention and invoices;
- practice-management, EHR and other systems when an authorised user requests or configures an exchange;
- professional advisers, insurers, auditors or a prospective purchaser under confidentiality obligations; and
- regulators, courts, law-enforcement bodies or other parties where required or authorised by law, or where necessary to protect people, rights or the security of the service.
Customer transcriptionists, documentation officers and reviewers may access recordings and drafts when the customer gives them that workspace access. VoxVersa personnel do not access clinical content as a matter of routine; access is restricted to authorised support, security or operational purposes and is logged where the service supports it.
7. Australian clinical data and overseas services
VoxVersa stores production clinical content in Australia. Speech recognition and AI document generation for production clinical workloads are also configured to run in Australia. We do not send recordings, transcripts, patient details or generated clinical documents overseas for processing.
Some providers supporting non-clinical functions may operate overseas or allow authorised access from overseas. These functions can include identity sign-in, payments, communications, support and website analytics. We limit the information shared with those providers to what is reasonably necessary and do not intentionally provide them with clinical content. We assess those services and use contractual, technical and organisational safeguards appropriate to the information involved.
If a customer-specific deployment has a different or stricter boundary, that boundary will be stated in the applicable order form or customer agreement.
8. Retention and deletion
We keep information only for as long as needed for the purposes described in this policy, the customer's configured retention policy, our agreement with the customer and applicable law. Different information has different retention periods.
- Recordings are deleted according to the policy pinned to the work when it was captured, such as after processing, finalisation, delivery or a set period.
- Short-lived browser recovery fragments expire automatically and are scheduled for secure deletion.
- Transcripts, documents, templates and patient context remain until deleted or until the workspace or contract retention rule applies.
- Account, billing, security and audit records may be retained longer where reasonably required for legal, financial, fraud-prevention, safety or accountability purposes.
- Backups and deletion queues may take a limited additional period to cycle out securely.
Workspace administrators may be able to choose retention settings. An organisation may also be legally required to retain clinical records even after a person's account access ends.
9. Security
We use administrative, technical and physical safeguards designed for the sensitivity of the information we handle. These include access controls, workspace isolation, encryption in transit, protected storage, least-privilege service access, audit and deletion controls, and monitoring for misuse or failures.
No online service can guarantee absolute security. You must protect your credentials, devices and connected systems, use appropriate access roles, and notify us promptly if you suspect unauthorised access. We assess and notify eligible data breaches as required by applicable law and our customer agreements.
11. Access, correction and complaints
You may ask to access or correct personal information VoxVersa holds about you. You may also ask questions, request deletion where applicable, or make a privacy complaint. We may need to verify your identity and authority before acting. If the information is controlled by your healthcare provider or employer, we may refer the request to that organisation.
Contact us at support@vox-versa.com. Please do not include patient or clinical information in an ordinary email. We will investigate and respond within a reasonable period. If you are not satisfied, you may contact the Office of the Australian Information Commissioner.
12. Children and patient information
VoxVersa accounts are intended for adults acting in a professional or organisational capacity. Clinical content may concern children or other people who do not hold an account. The healthcare provider is responsible for having a lawful basis and any required consent or authority to record and process that information.
13. Changes and contact
We may update this policy when our services, providers or legal obligations change. We will publish the updated version here, change the date above and give additional notice where a change is material or required by law.
Privacy questions can be sent to support@vox-versa.com.