Privacy Policy

Last updated: 19 January 2025

This Privacy Policy describes how NoteMate (ABN 33 659 424 629) ("NoteMate", "we", "us", or "our") collects, uses, and handles your information when you use our clinical documentation platform ("Service").

1. Zero-Knowledge Architecture

1.1 Core Principles

Our software architecture ensures that:

  1. The application cannot access or decrypt your sensitive clinical content

  2. Clinical documentation is stored locally on your device

  3. We cannot access, view, or retrieve your clinical content

  4. You maintain complete control over your sensitive information

  5. Content is temporarily transmitted for processing (transcription and generation)

1.2 Data Categories

We handle different types of data with specific protections:

  1. Content Data (Local Storage):

    • Clinical documentation on your device

    • Generated transcripts and documents

    • Audio recordings before processing

    • Generated clinical content

  2. Operational Data (Minimal Storage):

    • Authentication data managed by Clerk

    • Usage metrics and quotas

    • Payment information via Stripe

    • Application monitoring data

    • Template storage and management

  3. Processing Data (Temporary):

    • Audio recordings during transcription

    • Text during document generation

    • Transmitted securely and immediately discarded

2. Data Processing and Partners

2.1 Third-Party Services

We use the following third-party services with strict data processing agreements:

  1. Clerk (United States)

    • Purpose: Authentication and user management

    • Data Handling:

      • User authentication

      • Session management

      • Security monitoring

      • User profiles

    • Security Measures:

      • SOC 2 Type 2 certified

      • Enterprise-grade encryption

      • MFA support

      • Fraud prevention

  2. OpenAI (United States)

    • Purpose: Audio transcription and text processing

    • Data Handling:

      • Temporary audio transcription

      • Real-time text processing

      • No data retention

      • No training or model fine-tuning

    • Security Measures:

      • SOC 2 Type 2 certified

      • Data encrypted in transit

      • Strict access controls

      • Regular security audits

  3. Redis (United States)

    • Purpose: Database operations and usage tracking

    • Data Handling:

      • Rate limiting data

      • Usage quotas

      • Application metrics

      • No user content storage

    • Security Measures:

      • Australian data center

      • SOC 2 Type 2 certified

      • Network isolation

      • Encryption at rest

  4. Stripe (United States)

    • Purpose: Payment processing

    • Data Handling:

      • Payment information only

      • PCI DSS Level 1 certified

      • No access to clinical data

    • Security Measures:

      • Encryption for all data in-transit

      • Fraud detection

      • Regular assessments

      • Compliance monitoring

2.2 Data Processing Principles

All data processing follows these principles:

  1. Temporary and immediate processing only

  2. Subject to strict data processing agreements

  3. Compliant with Australian privacy laws

  4. Limited to essential operations

  5. Regular security and compliance audits

3. Security Measures

3.1 Technical Security

We protect your data through:

  1. Encryption for all data in transit

  2. Zero-knowledge architecture preventing data access

  3. Secure authentication using Clerk

  4. Multi-factor authentication options

  5. Regular security assessments and penetration testing

3.2 Operational Security

Our operational security includes:

  1. Regular security audits

  2. Access control and monitoring

  3. Incident response procedures

  4. Security patch management

4. Data Protection Obligations

4.1 Our Commitments

We commit to:

  1. Protecting your privacy and data security

  2. Processing data only as necessary

  3. Maintaining appropriate security measures

  4. Promptly responding to security incidents

  5. Regular compliance reviews

4.2 Your Responsibilities

You are responsible for:

  1. Maintaining local device security

  2. Protecting access credentials

  3. Obtaining patient consent

  4. Following professional privacy obligations

  5. Reporting security concerns promptly

5. Healthcare Use Requirements

5.1 Patient Consent

When using NoteMate in healthcare settings, you must:

  1. Obtain explicit patient consent before recording

  2. Document consent in medical records

  3. Inform patients about:

    • The purpose of recording

    • Temporary processing details

    • Local device storage

    • Security measures in place

  4. Follow local healthcare privacy regulations

5.2 Professional Obligations

You must maintain:

  1. Appropriate clinical records

  2. Patient privacy protocols

  3. Professional standards compliance

  4. Organisational policy compliance

6. Your Privacy Rights

6.1 Legal Rights

Under Australian privacy law, you have the right to:

  1. Access your personal information

  2. Correct your personal information

  3. Request account deletion

  4. Withdraw processing consent

  5. Lodge privacy complaints

  6. Receive data breach notifications

6.2 Exercise of Rights

To exercise these rights:

  1. Email us at contact@notemate.io

  2. Provide necessary identification

  3. Specify your request clearly

  4. Allow up to seven (7) days for response

7. Data Incidents

7.1 Our Response

In case of a data incident, we will:

  1. Investigate immediately

  2. Notify affected users

  3. Implement containment measures

  4. Conduct root cause analysis

  5. Take preventive actions

7.2 Notification Process

We will notify you of incidents:

  1. Within required timeframes

  2. With incident details

  3. With recommended actions

  4. Through secure channels

8. Jurisdiction and Governing Law

8.1 Governing Law

This Privacy Policy is governed by the laws of Victoria, Australia.

8.2 Jurisdiction

Any privacy disputes will be subject to the exclusive jurisdiction of the courts of Victoria, Australia.

9. Changes to Policy

9.1 Updates

We may update this Privacy Policy by:

  1. Posting changes on our website

  2. Notifying you via email

  3. Providing in-app notifications

  4. Requiring acknowledgment if necessary

9.2 Effect

Changes will be effective upon posting, with continued use constituting acceptance.

Contact

For privacy-related inquiries, please email contact@notemate.io.

Privacy complaints may also be directed to:

Office of the Victorian Information Commissioner
PO Box 24274
Melbourne VIC 3001