Privacy Policy
- 1. About This Policy
- 2. Who We Are
- 3. Information We Collect
- 4. How We Collect Information
- 5. How We Use Your Information
- 6. Health Information
- 7. Disclosure to Third Parties
- 8. Overseas Disclosure
- 9. Data Residency
- 10. Security
- 11. Retention and Deletion
- 12. Access and Correction
- 13. Complaints
- 14. Cookies and Tracking
- 15. Children's Privacy
- 16. Changes to This Policy
- 17. Contact Us
Important: Maree-CareFlow is a self-hosted software product. When your practice uses Maree-CareFlow, your client health records and practice data are stored on infrastructure that you control - not on Maree-CareFlow's servers, unless your practice subscribes to Managed Hosting (see the paragraph below, and Section 6A). This policy covers how we handle information about you as a customer (practice owner, administrator, or subscriber) rather than the health records of the participants your practice serves.
One exception, and it is an important one: we also sell an optional Managed Hosting subscription, under which we run your instance for you on Australian infrastructure at yourpractice.maree-careflow.com.au. If your practice is on that subscription, the sentence above does not describe you: your records sit on infrastructure we operate, and we hold them on your behalf. Wherever this policy says your data stays on your own server, read it as describing the self-hosted product. Section 6A sets out what is different, and the terms that govern it are in the Managed Hosting agreement we provide before that subscription starts.
1. About This Policy
Maree-CareFlow (ABN 21 498 105 915) ("Maree-CareFlow", "we", "our", or "us") is committed to protecting personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) contained in Schedule 1 of that Act.
This Privacy Policy explains how we collect, hold, use, and disclose personal information about:
- Visitors to our marketing website (maree-careflow.com.au);
- Prospective and current customers (practices, organisations, and their authorised representatives); and
- Individuals who contact us for support, sales enquiries, or general information.
This policy does not govern the health records or participant data managed by practices that use the Maree-CareFlow software. That data is held on the practice's own infrastructure and is subject to the practice's own privacy obligations under the Privacy Act 1988, applicable state health records legislation, and the NDIS Act.
2. Who We Are
Maree-CareFlow (ABN 21 498 105 915) is an Australian business, operated as a sole trader, that develops and distributes Maree-CareFlow - a self-hosted practice management platform for Australian allied health and NDIS providers.
We are bound by the Australian Privacy Principles and, where applicable, the Health Records Act 2001 (Vic) and equivalent state health records legislation.
3. Information We Collect
3.1 Information You Provide
We collect personal information that you voluntarily provide, including:
- Contact details: name, email address, phone number, practice name, practice address;
- Account information: subscription tier, billing details (processed by our payment provider - we do not store card numbers);
- Licence information: organisation name, licence key details, deployment method;
- Support enquiries: messages you send via our contact forms or email;
- Demo and enquiry requests: information you provide when booking a demonstration, requesting a beta licence key, or asking for help getting started.
3.2 Information Collected Automatically
A self-hosted install sends us three kinds of operational data, and this is the complete list. First, during the public beta, one registration - practice name, business contact email and the install's random id - unless the install disables it with MCF_BETA_REGISTER=false. Second, for a licensed install, a daily entitlement check carrying the install id and its licence token. Third, once, at the end of the beta, a claim for the thank-you entitlement, carrying the install id and the date that install joined the beta. None of the three includes participant, client or clinical data. (This paragraph said "two kinds ... and nothing else" until 24 September 2026; the third message existed and the sentence did not describe it. The absolute is the part that was wrong, so it has been replaced with the list.) All three go only to the address in MCF_VENDOR_RENEWAL_URL, which ships empty - an install that sets nothing transmits nothing. This paragraph describes a self-hosted install. A Managed Hosting instance runs on our infrastructure, so it is not a question of what it sends us - see Section 6A.
When you visit our website, our web server may collect:
- IP address;
- Browser type and version;
- Pages visited and time of visit;
- Referring URL.
We use this information for security monitoring, service improvement, and aggregate analytics. We do not use third-party advertising trackers.
3.3 Information We Do Not Collect
We do not collect or store:
- Health records or clinical notes created within your Maree-CareFlow installation - on a self-hosted install these remain on your server and we never receive them. On a Managed Hosting subscription they are on a server we operate, so we hold them on your behalf; see Section 6A;
- NDIS participant identifiers or funding information stored in your system;
- Payment card numbers (payments are processed by our PCI-DSS-compliant payment provider);
- Sensitive information about your clients or participants.
4. How We Collect Information
We collect personal information:
- Directly from you when you submit an enquiry, register for a trial, purchase a licence, or contact us;
- Through your use of our website (server logs and basic analytics);
- From our payment provider when you complete a subscription transaction;
- Via email correspondence.
Where it is lawful and practicable to do so, we will collect information directly from the individual concerned.
5. How We Use Your Information
We use personal information to:
- Provide, administer, and support your Maree-CareFlow licence and subscription;
- Respond to support requests, enquiries, and feedback;
- Send service-related communications (licence expiry reminders, security notices, release announcements);
- Process payments and issue invoices;
- Improve our product and website;
- Comply with legal obligations;
- Prevent fraud and misuse of our services.
We will not use your personal information for direct marketing unless you have consented. You may opt out of marketing communications at any time by following the unsubscribe link in any marketing email or contacting us directly.
6. Health Information
Maree-CareFlow is a self-hosted application. All health records, clinical notes, NDIS participant plans, and related sensitive health information managed within your Maree-CareFlow installation are stored on servers under your control - not on Maree-CareFlow's infrastructure - unless your practice subscribes to Managed Hosting, in which case that server is one we operate for you. Section 6A says what changes, and what does not.
As the operator of that infrastructure, your practice is the entity responsible for those health records under:
- The Privacy Act 1988 (Cth) - Australian Privacy Principles (health information as sensitive information under APP 3);
- The Health Records Act 2001 (Vic), Health Records and Information Privacy Act 2002 (NSW), and equivalent state legislation;
- NDIS Quality and Safeguards Commission privacy and information management requirements;
- AHPRA ethical and confidentiality obligations.
Maree-CareFlow provides the software tools and technical safeguards (access controls, audit logging, data retention enforcement) that help you meet these obligations, but the primary legal responsibility for participant health data lies with your practice.
6A. If we host your instance (Managed Hosting)
Managed Hosting is an optional paid subscription, separate from your software licence. Most practices do not use it: they install Maree-CareFlow on their own cPanel account, VPS or server, and everything above applies to them unchanged. This section is for the practices that do, and it is written to be read before you subscribe rather than after.
6A.1 What we hold, and in what capacity
If we host your instance, we operate the server your Maree-CareFlow installation runs on. That means we hold your practice data and your participants' health information - the database, the uploaded documents, the clinical record and the backups - on your behalf. Your practice remains the entity that decides what goes into that record and who may see it. We are an APP entity in our own right in respect of the information we hold for you, and we are responsible for the security of the infrastructure it sits on.
This is the one situation in which Maree-CareFlow holds participant health information. On every other deployment we do not, and nothing in the software sends it to us.
6A.2 Where it is, and who else is on the machine
Managed Hosting runs on Australian infrastructure. The provider and region are named in your Managed Hosting agreement rather than here, so that the agreement and the reality cannot drift apart.
It is shared hosting, and we would rather be plain about what that means: your instance may run on a server that also runs other practices' instances, and in some configurations more than one practice may share a database. The software separates practices inside the application and, for the tables that hold participant records, at the database level as well. If your practice requires a dedicated machine or a dedicated database, that is available and is not the $69/month shared plan - ask us before you subscribe rather than assuming.
6A.3 Who on our side can reach your records
Operating a server for you means our staff can reach what is on it. Specifically:
- Our operators hold a
super_adminrole in the software, which is not limited to a single practice. It exists so that we can support, migrate and recover instances we host. - Our operators have administrative access to the underlying server, database and backups, which is inherent in running them.
- Every administrative action inside the application is written to the same immutable audit trail your own staff's actions are written to, and you can read it.
We access your clinical records only where it is necessary to operate, support or restore your instance, or where you ask us to, or where the law requires it. We do not use them for any other purpose, and we do not use them to train anything.
6A.4 Backups, and what happens if you leave
Backups are included in the Managed Hosting subscription and are encrypted. Retention, export on request, and what happens to your instance and its backups when the subscription ends are set out in the Managed Hosting agreement. We do not state a figure here, because the agreement is what governs it and a number on a web page that disagrees with the agreement would be worse than no number at all.
Your data is yours. The export tools in the software work on a hosted instance exactly as they do on a self-hosted one, and you can use them at any time without asking us.
6A.5 If we suffer a breach
If we become aware of unauthorised access to, or loss of, information we hold for you on Managed Hosting, we will tell you, and we will give you what you need to make your own assessment under the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act 1988 (Cth) - what happened, what was affected, and when. Where the breach is one we must assess and notify in our own right, we will do that too. Timeframes and the named contact on each side are set out in the Managed Hosting agreement.
This is separate from, and does not replace, your practice's own obligations for a breach that happens inside your own operations.
6A.6 What does not change
The software is the same build, installed the same way. Nothing about Managed Hosting changes what the application does, what it sends out, or the choices you make inside it - the AI provider, the telehealth server, the integrations you connect and the consent gates all behave exactly as described elsewhere in this policy. What changes is who owns the machine, and therefore who is responsible for it.
7. Disclosure to Third Parties
We do not sell, rent, or trade personal information. We may disclose personal information to:
- Payment processors: to process subscription payments (subject to their own privacy policies and PCI-DSS compliance);
- Cloud infrastructure providers: who host our marketing website and licence management systems (data processing agreements are in place);
- Legal and regulatory authorities: where required by law, court order, or applicable regulation;
- Professional advisers: including lawyers, accountants, and auditors, under strict confidentiality;
- Business successors: in the event of a merger, acquisition, or business transfer (you will be notified in advance).
All third parties to whom we disclose personal information are required to handle it in accordance with Australian privacy law or equivalent protections.
8. Overseas Disclosure
Our marketing website and licence management systems may be hosted on infrastructure located outside Australia. Where personal information is transferred or stored overseas, we take reasonable steps to ensure that overseas recipients handle it in accordance with standards at least equivalent to the Australian Privacy Principles (APP 8.1).
We will not disclose personal information to an overseas recipient unless we are satisfied that the recipient provides adequate privacy protections, or you have consented to the transfer, or disclosure is required or authorised by law.
9. Data Residency (Your Client Data)
Because Maree-CareFlow is self-hosted, you decide where your client data is stored. You can install Maree-CareFlow on:
- An Australian-based cPanel hosting account;
- An Australian-based VPS or cloud server (e.g. AWS Sydney, Azure Australia East);
- On-premises hardware within your practice.
On a self-hosted install, Maree-CareFlow does not transmit your clinical data to our servers. (On Managed Hosting our server is the server it runs on - see Section 6A.) It does not transmit it to any third-party service either, with one default you should know about: the built-in telehealth video feature runs through the public meet.jit.si server unless you point Maree-CareFlow at your own Jitsi instance. A telehealth consultation is health information, so if that matters to your practice - and under APP 8 it may - set TELEHEALTH_JITSI_SERVER to your own server before you use it. Every other route out to a third party is one you switch on yourself (for example, connecting a cloud AI provider, an accounting package, or secure messaging).
Enterprise customers can receive a written Australian data residency commitment on request - contact our enterprise team.
10. Security
We take reasonable steps to protect the personal information we hold from misuse, interference, loss, unauthorised access, modification, or disclosure. Our security measures include:
- Encrypted data transmission (HTTPS/TLS for all web communications);
- Access controls and authentication for our internal systems;
- Regular security reviews of our software;
- Staff training on data handling obligations.
If you become aware of a security vulnerability in Maree-CareFlow or suspect that your practice's installation has been compromised, please contact us immediately at security@maree-careflow.com.au.
11. Retention and Deletion
We retain personal information for as long as necessary to fulfil the purposes for which it was collected, or as required by law.
- Account and licence records: retained for the duration of the subscription plus 7 years (Australian tax law and regulatory compliance);
- Support correspondence: retained for 2 years after resolution;
- Website server logs: retained for 90 days, then automatically deleted;
- Marketing enquiry records: retained until you opt out or request deletion, or for a maximum of 3 years if no subscription is established.
You may request deletion of your personal information by contacting us (see Section 17). We will delete or de-identify your information unless we are legally required or permitted to retain it.
12. Access and Correction (APP 12 & APP 13)
Under APP 12, you have the right to request access to the personal information we hold about you. Under APP 13, you have the right to request correction of information that is inaccurate, out of date, incomplete, irrelevant, or misleading.
To make an access or correction request:
- Email us at privacy@maree-careflow.com.au; or
- Contact our privacy officer via the website contact form (see Section 17).
We will respond to access requests within 30 days. We will not charge a fee for making a request, but may charge a reasonable cost for providing access if the volume of information involved is large.
If we refuse an access or correction request, we will explain why in writing and advise you of your right to complain to the Office of the Australian Information Commissioner.
13. Complaints (APP 1)
If you believe we have handled your personal information in a manner inconsistent with the Australian Privacy Principles, you may lodge a complaint with us:
- Email: privacy@maree-careflow.com.au
- Contact form: our website contact form, addressed to the Privacy Officer (see Section 17)
We will acknowledge your complaint within 5 business days and aim to resolve it within 30 days. If you are not satisfied with our response, you may escalate to the Office of the Australian Information Commissioner (OAIC):
- Website: www.oaic.gov.au
- Phone: 1300 363 992
14. Cookies and Tracking
Our marketing website uses a small number of essential functional cookies and Google Analytics 4, a third-party analytics service provided by Google, to understand aggregate visitor traffic and improve the site. We do not use advertising cookies or cross-site advertising trackers, and we do not sell your personal information.
Cookies we use:
- Session cookies: used temporarily while you navigate the site - deleted when you close your browser;
- Preference cookies: remember display preferences (e.g. monthly/annual pricing toggle) - stored for 30 days;
- Analytics cookies (Google Analytics 4): Google sets first-party cookies such as
_gaand_gidto measure page visits and general usage patterns in aggregate. You can opt out using Google's Analytics Opt-out Browser Add-on.
You can disable cookies in your browser settings. Disabling cookies will not prevent you from viewing our marketing website.
15. Children's Privacy
Our marketing website and services are directed at allied health practice operators and administrators. We do not knowingly collect personal information from individuals under 18 years of age through our website. If you believe we have inadvertently collected information about a child, please contact us and we will promptly delete it.
Note: Maree-CareFlow software is used by practices that do work with children (e.g. paediatric OT, speech pathology). The privacy of those children's health records is the responsibility of the practice as the data controller on their own server.
16. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or business operations. When we make material changes, we will:
- Update the "Last updated" date at the top of this page;
- Notify active subscribers by email.
Your continued use of our website or services after the effective date of the updated policy constitutes acceptance of the changes.
17. Contact Us
Privacy Officer - Maree-CareFlow (ABN 21 498 105 915)
Email: privacy@maree-careflow.com.au
Security issues: security@maree-careflow.com.au
General enquiries: Contact form
We aim to acknowledge all privacy enquiries within 2 business days and to resolve complaints within 30 days.
If you are not satisfied with our response to a privacy complaint, you may contact the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au or by calling 1300 363 992.