Privacy policy

This policy is for Australian healthcare clinics using or considering Bilby, including owners, practitioners and authorised staff.

Published 14 September 2026.

Who we are

Bilby is operated by Bilby Labs Pty Ltd (ABN 98 699 098 354), Victoria, Australia. Contact us at legal@bilby.health or write to 1/493 Riversdale Road, Camberwell VIC 3124.

This policy explains how we handle your account and enquiry information, and the patient information your clinic manages through Bilby. References to “your clinic” include sole-practitioner practices. Patients interact with Bilby through your clinic’s bookings and forms. This is not patient-facing guidance, and it does not limit applicable individual privacy rights.

Information we handle

We handle practice and user contact details, account and authentication information, billing information and support enquiries. On behalf of practices, we store and process patient information such as contact details, appointments, clinical records, documents, form responses, healthcare identifiers, invoices and claiming information. The information involved depends on the features a practice uses.

We collect information from your clinic and its authorised users, through enabled integrations, and when patients use your clinic’s bookings and forms. Operational logs can also contain personal information. If you enquire through our website, we collect your name, email address, practice name, practitioner count and current software. Please do not include patient information in website enquiries.

The public marketing website uses Plausible Analytics. Your clinic decides what information it collects for patient care and is responsible for its own patient-facing privacy notices and any required consent. This policy explains how Bilby handles that information in providing services to your clinic.

Why we handle information

We use information to provide and maintain Bilby, authenticate users, manage bookings and forms, deliver communications, support payments and claims, respond to enquiries, investigate faults and protect the service. We also handle information where needed to meet applicable legal obligations.

Practices enable optional integrations, including ScriptPad, HICAPS and Xero. See the service provider register for name, purpose and location.

Access for support and debugging

There are no overseas contractors. Developer access to sensitive information, including patient records, is limited to what is necessary for a practice’s support request or for investigating and addressing a fault. An authorised developer may decide that access is necessary for debugging without obtaining separate advance approval from the practice. We minimise interaction with patient information.

Service providers and overseas processing

Our core clinical database, uploaded files and backups are hosted on AWS in Sydney. No cross-region backup copying is configured. Some connected services may process information outside Australia.

The service provider register lists each provider by name, purpose and location.

Storage, retention and deletion

Clinical information is encrypted in transit and at rest. Access controls and activity history support protection of practice records. No system can eliminate every security risk. The security page describes Sydney hosting, encryption, backups and export in more detail.

When trial access ends or a paid subscription ends, the practice can continue viewing and exporting its records in read-only mode indefinitely, unless its owner initiates deletion. Ending access does not itself delete records.

The practice owner can schedule deletion, with a cancellable 30-day grace period before a live-data purge. Protected backup copies are not immediately erased. Automated backups are retained for up to 35 days, monthly snapshots for 395 days and yearly snapshots for 2,555 days. There is no individual patient hard-delete function.

Victorian clinics that provide a health service are health service providers under the Health Records Act 2001 (Vic). They must retain health information for the period in Health Privacy Principle 4.2: the later of more than 7 years after the last occasion a health service was provided to that individual by the clinic, or until the individual turns 25 if the information was collected while they were a child. Bilby Labs Pty Ltd hosts that information as an organisation that holds health information. It is not a health service provider merely because it provides this software. While we host records for your clinic, we do so for that authorised purpose. If the practice owner completes deletion, we take reasonable steps to destroy or permanently de-identify live data we no longer need (Health Privacy Principle 4.5), subject to protected backups expiring over their stated periods and to any legal hold. Other Australian jurisdictions have their own retention rules. Your clinic remains responsible for meeting the rules that apply to it.

Security incidents

If we become aware of unauthorised access, disclosure or loss affecting your practice’s information, we will notify your nominated contact without undue delay, provide available information about the incident and protective steps, and give material updates as the investigation progresses.

If the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act 1988 (Cth) applies to us, we will assess a suspected eligible data breach and, where required, notify the Office of the Australian Information Commissioner and affected individuals. That statutory duty is separate from our commitment to notify your nominated practice contact. We will cooperate with your clinic on notifications your clinic must make, without limiting either party’s obligations.

Access, correction and privacy complaints

Contact legal@bilby.health for access to or correction of your account information, assistance with a privacy request received by your clinic, or a concern about Bilby’s handling of information. We may need to verify your identity and authority before providing information or acting on a request.

Your clinic manages patient requests relating to its clinical records. Where a patient contacts Bilby directly, we will coordinate with your clinic as appropriate while meeting our own legal obligations. Patient rights are not limited by this policy’s focus on clinics.

Where your clinic uses features that involve healthcare identifiers, those identifiers are also regulated by the Healthcare Identifiers Act 2010 (Cth). Your clinic remains responsible for using identifiers lawfully. We handle them only as needed to provide the enabled features.

Where applicable, an individual dissatisfied with our response may complain to the Office of the Australian Information Commissioner at oaic.gov.au. Other health privacy complaint bodies may also be relevant.

Changes

We will publish the current version and its publication date on this page.