- Entity
- Clinical Imaging Australia Pty Ltd
- ABN
- 58 606 095 934
- ACN
- 606 095 934
- Registered office
- Australia
- Privacy contact
- woodrow@clinicalimaging.com.au
- Version
- 1.0
- Effective date
- 8 September 2026
- Next review
- September 2027
1. About this policy
Clinical Imaging Australia Pty Ltd (CIA, we, us, our) provides standardised clinical photography systems, software and supporting services to medical, dental and aesthetic practices. Our work brings us into contact with photographs of patients and with limited patient identifying information.
This policy explains how we handle personal information, including health information and other sensitive information, and how we meet our obligations under the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
It applies to all CIA personnel, contractors and service providers, and to all CIA products and services, including the Clinical Imaging System and the LRToolbar plugin, Consult, Capture and Connect, our hosted and integration services, and our website.
2. Our role and where data is held
The practice collects the patient information, obtains patient consent for clinical photography, and controls the clinical record. CIA does not determine what is collected or why.
However, CIA also hosts that information. Cloud storage is supplied by CIA as part of our service plans, and clinical images are held in Microsoft 365 tenancies that CIA provisions and administers. Client-supplied storage is permitted only by exception, at CIA’s discretion and in consultation with the practice’s IT provider.
This means CIA holds health information and sensitive information about patients, and has its own obligations under the Privacy Act in respect of that information — obligations that exist independently of, and in addition to, the practice’s obligations. We accept those obligations.
Each practice has its own dedicated Microsoft 365 tenant. Practices do not share a tenant, and imagery is not pooled, combined, or accessible across practices. Separation is at the tenant boundary, not at folder or permission level within a shared environment.
We hold patient information solely to deliver the storage, imaging, analysis, support and integration services the practice has engaged us to provide. We do not use it for our own purposes.
3. What information we collect
3.1 Practice and client information
- •Names, job titles, business email addresses and phone numbers of practice staff and practitioners
- •Practice name, business address, ABN and billing details
- •Records of installation, training, support requests and system configuration
- •Records of correspondence with us
3.2 Patient information
When installing, supporting or integrating our systems we may access, and in some cases briefly handle:
- •Clinical photographs and video of patients. These are both health information and sensitive information under the Privacy Act.
- •Patient given and family name, date of birth, sex or gender, and the practice management system patient identifier, used to match an imaging series to the correct patient record
- •The treating practitioner and appointment associated with an imaging session
We do not require and do not seek clinical notes, diagnoses, medications, pathology results, correspondence, Medicare numbers or billing information.
3.3 Website information
We collect information through the following systems:
- •Jotform — onboarding and installation forms completed by practice staff
- •Xero and Stripe — client details, invoicing and payment information
- •Our website and online store, hosted on Squarespace — enquiry and order details
We do not store complete payment card numbers. Card payments are processed by Stripe under its own security controls.
4. How we collect information
We collect practice and client information directly from you — when you enquire, place an order, book an installation, attend training or contact support.
We access patient information only through systems the practice has authorised us to access, in the course of providing our services. Where our software connects to a practice management system, we retrieve only the fields necessary to match an imaging series to the correct patient record.
We rely on the practice to have obtained the patient consent required for clinical photography and for the practice’s own use of those images.
5. How we use and disclose information
We use practice and client information to deliver and support our products and services, respond to enquiries, arrange installation and training, invoice and administer our contracts, and communicate about products, updates and service matters.
We use patient information only to install, configure, support, troubleshoot and integrate the systems we provide, and to deliver the image analysis features a practice has chosen to enable.
We do not sell personal information. We do not use patient images in marketing, case studies, training material or product demonstrations unless the practice and the patient have given specific written consent for that use.
5.1 Service providers
We disclose information to third parties who provide services to us, on terms requiring them to protect it and use it only for the purpose we engaged them:
- •Microsoft — cloud storage and identity services, Australian region
- •Curity — our managed IT provider, which holds administrative access to our Microsoft 365 environment
- •Adobe — Lightroom Classic, licensed by the practice and used in the capture workflow
- •AI analysis providers — used to deliver skin analysis, mole mapping and facial measurement features. These providers do not use images supplied by CIA to train their models.
- •Jotform — onboarding and installation form capture
- •Xero and Stripe — invoicing and payment processing
- •Squarespace — website and online store hosting
- •Software development and client support contractors engaged by CIA, under confidentiality terms and with access limited to what their role requires
5.2 Other disclosures
We may also disclose personal information where required or authorised by law, to respond to a subpoena or lawful request, to establish or defend a legal claim, or where you have consented.
6. Overseas disclosure
All clinical imagery is stored at rest in Australian Microsoft datacentres. It is not stored overseas. However, personal information may be accessed from, or transmitted outside, Australia in the following circumstances.
6.1 Access from overseas by CIA and our IT provider
Access to client systems is ordinarily from within Australia. In addition:
- •CIA team members and our managed IT provider may access client systems while working or travelling outside Australia
- •Our client-experience support team member, based in Manila, Philippines, may be granted access on request in order to resolve a specific support issue
In each case the information is accessed remotely and is not copied to or stored in the overseas location. The same authentication, multi-factor authentication and conditional access controls apply regardless of where the person is working from.
6.2 Transmission to AI analysis providers
Where a practice enables the skin analysis, mole mapping or facial measurement features, the clinical photograph is transmitted to a third-party AI provider for processing and the results are returned to the clinician. We do not send patient names, dates of birth, contact details, Medicare numbers or practice management system identifiers to these providers.
These providers do not use images supplied by CIA to train their models.
6.3 Our accountability
Under APP 8 CIA remains accountable for personal information disclosed overseas. We take reasonable steps to ensure overseas recipients handle it consistently with the Australian Privacy Principles, including through contractual terms restricting use, retention and onward disclosure.
7. Storage and security
Our security controls are documented in the CIA OneDrive Data Storage & Security Policy (version 1.2, 13 October 2025), prepared with our managed IT provider. In summary:
- •Data residency — Microsoft 365 tenants are provisioned in the Australian geographic region, and core OneDrive and SharePoint data is stored at rest in Australian Microsoft datacentres
- •Encryption in transit — TLS over HTTPS for all traffic between capture devices, Lightroom, OneDrive and authenticated users
- •Encryption at rest — AES 256-bit, BitLocker disk-level plus per-file encryption with unique per-file keys stored separately from content; FIPS 140-2 compliant
- •Identity and access — Microsoft Entra ID with multi-factor authentication, role-based access control, conditional access policies and least-privilege configuration
- •Segregation — logical tenant isolation within Microsoft 365, with protection against cross-tenant exposure
- •Redundancy — replicated storage across multiple Australian datacentre facilities
- •Assurance — the underlying platform is aligned to ISO 27001, ISO 27018, SOC 1 and SOC 2, and IRAP
Access to clinical images is restricted to personnel who need it to perform their role. Administrative access to our Microsoft 365 environment is limited to the Director and our managed IT provider.
7.1 Remote support access
Delivering support requires remote access to the computers running our software in the practice. That access is used only to diagnose and resolve issues with image capture, camera reliability and tethering.
Support is delivered using TeamViewer. Under our Terms & Conditions, practices provide CIA with TeamViewer access to the computers running Adobe Lightroom and the Clinical Imaging Toolbar, together with credentials for those machines, and agree that CIA may request they be powered on during business hours. Access is used only for support purposes.
7.2 Image file format
Images are stored in open, non-proprietary file formats and are encrypted at rest within the SharePoint and OneDrive tenancy. The formats are not locked to CIA software, so a practice can retrieve and use its imagery without any CIA product.
8. Retention and destruction
Because CIA hosts the storage, we retain clinical images for as long as the practice maintains its service plan with us. The practice remains responsible for setting a retention period consistent with its obligations under State and Territory health records legislation, and we act on the practice’s instructions to retain or delete.
We do not delete a practice’s imagery without express written instruction from that practice via an offboarding form signed by the client.
8.1 End of service
When a practice ends its service plan, the closure of its tenancy is confirmed in a signed agreement. We hand over the practice’s complete image library, and we delete CIA’s copy 30 days after handover. Images are stored in open, non-proprietary formats, so they remain usable without CIA software.
We can provide written confirmation once deletion is complete on request.
We also retain limited operational records — diagnostic data, support attachments and configuration backups — only as long as needed for the purpose collected, or as required by law, and then destroy or de-identify them.
9. Access and correction
Patients seeking access to, or correction of, their clinical images or health record should contact the practice that treated them. The practice holds the record and is the appropriate point of contact.
If you are a practice client and want to access or correct the personal information we hold about you, contact us at woodrow@clinicalimaging.com.au. We will respond within 30 days. We may ask you to verify your identity. If we refuse access or correction we will give you written reasons and tell you how to complain.
Because the images are held in storage we administer, we will act promptly on a practice’s request to retrieve, correct, export or delete a patient’s images, and we will not charge for assisting with a patient access request.
10. Data breach response
Because CIA hosts patient imagery, a breach of our environment is a breach of information we hold, and our obligations under the Notifiable Data Breaches scheme apply directly. If we suspect a breach we will contain it, assess whether it is likely to result in serious harm, and where it is, notify affected individuals and the Office of the Australian Information Commissioner as soon as practicable. We will notify every affected practice without delay so each can meet its own obligations, and we will notify integration partners as our agreements with them require.
10.1 How we respond
We maintain a documented Data Breach Response Plan. It sets out four stages:
- •Contain — the suspected breach is reported to the Director immediately. Affected accounts and access are suspended, credentials rotated, and the affected tenancy isolated to stop the incident spreading.
- •Assess — within 30 days, and in practice far sooner, we establish what information was involved, whose information it was, who accessed it, and whether serious harm is likely. Clinical photographs are sensitive information, so the threshold for serious harm is low and we assess on that basis.
- •Notify — where serious harm is likely we notify the OAIC and affected individuals as soon as practicable. Because the practice holds the patient relationship, patient notification is made by the practice with our support, unless the practice is unable or unwilling to do so.
- •Review — after every incident, including near misses, we identify the cause, fix it, and update our controls and this plan.
10.2 Who we tell, and when
- •The affected practice — immediately on confirming a breach affecting its data, and before any external notification
- •Other practices — where the same root cause could affect them
- •Integration partners — within the timeframe our agreement with them requires
- •The OAIC and affected individuals — as soon as practicable where serious harm is likely
We will not delay notifying a practice while we complete our own assessment. A practice cannot meet its obligations if it does not know.
11. Complaints
If you believe we have mishandled your personal information, contact us at woodrow@clinicalimaging.com.au. We will acknowledge your complaint within 5 business days and respond within 30 days.
If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner at oaic.gov.au, by phone on 1300 363 992, or by writing to GPO Box 5218, Sydney NSW 2001.
12. Changes to this policy
We review this policy at least annually and update it when our practices change. The current version is always available at clinicalimaging.com.au. Material changes will be notified to practice clients.
13. Contact
Privacy enquiries: woodrow@clinicalimaging.com.au
Clinical Imaging Australia Pty Ltd, Australia