ProxiBlue Voice Booking Agent — Privacy Policy
Version 1.0 — Effective 26 July 2026
This Privacy Policy explains how ProxiBlue collects, holds, uses, and discloses personal information when you use the ProxiBlue voice-AI booking agent (the Service), and when your patients or callers interact with the Service on your behalf.
ProxiBlue is committed to handling personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). This policy should be read together with our Terms of Service.
1. Definitions
- ProxiBlue / we / us / our — ProxiBlue (ABN 30 550 620 048), the operator of the Service.
- Client / you / your — the clinic or business entity that subscribes to the Service.
- Caller / patient — an individual who telephones a Client and interacts with the Service.
- Service — the ProxiBlue voice-AI booking agent, including inbound call handling, the AI conversation layer, call recordings and transcripts, integrations with your practice management system, and the client dashboard.
- AI — the large-language-model based conversational system that speaks with your callers.
- Third-Party Services — the external systems on which the Service depends (voice/telephony, transcription, practice management, payments, and cloud hosting providers).
- Patient Data — patient records, appointments, call recordings, transcripts, and any other data flowing through the Service on your behalf.
2. Our role — who is responsible for what
2.1 You are the APP entity for Patient Data. When the Service handles calls for your clinic, you remain the entity responsible under the Privacy Act for the personal and health information of your patients. You control why the information is collected and how it is used in your practice.
2.2 We are your service provider. ProxiBlue processes Patient Data as your service provider, on your instructions, solely to deliver the Service. We do not use Patient Data for our own independent purposes except as permitted in clause 5 (operating and improving the Service) and clause 8 of the Terms of Service.
2.3 We are the controlling entity for account data. For information about you and your staff as Client account holders, and about visitors to our website, ProxiBlue is the entity responsible under the Privacy Act.
2.4 Patient requests. Because you are the APP entity for Patient Data, patients exercising privacy rights over their information should contact your clinic directly. Where a patient contacts us, we will refer the request to you within a reasonable time (see clause 11).
3. Information we collect
3.1 Client and account information
Names, business name, email addresses, phone numbers, billing details, practice details (practitioners, appointment types, business hours), login credentials, and support correspondence.
3.2 Patient and caller information (processed on your behalf)
- Caller name, date of birth, phone number, email, and other contact details;
- appointment requests, bookings, reschedules, and cancellations;
- voice recordings of calls and their transcripts;
- SMS and email content exchanged with the caller;
- health-related information the caller volunteers during a call (for example, the reason for an appointment).
3.3 Health and sensitive information
The Service may incidentally collect health information as part of a booking conversation. We treat all such information as sensitive information and process it only on your instructions as your service provider. We do not use it for any secondary purpose.
3.4 Automatically collected information
Website analytics, cookies, device and browser data, IP addresses, system and access logs, and AI performance metrics used to operate and improve the Service.
4. How the AI handles calls
4.1 Call recording notice. Calls are recorded. You are responsible for ensuring your greeting and privacy notices comply with the call-recording law of your State or Territory (see Terms of Service clause 4.4).
4.2 Not for emergencies. The AI cannot triage medical emergencies. It is configured to direct callers with an emergency to contact emergency services (000 in Australia). You must maintain your own emergency guidance for patients.
4.3 Human alternative. A caller who does not wish to interact with the AI may request to be handled by your staff. You are responsible for providing an alternative contact pathway for callers who object to AI processing.
4.4 AI limitations and verification. The AI can mishear, misinterpret, or produce inaccurate output. To reduce this risk, the ProxiBlue system automatically verifies each AI call multiple times to confirm the captured information is correct, so that mistakes are mostly eliminated. Information captured by the AI should nonetheless be treated as requiring verification. See Terms of Service clause 3 for the full acknowledgement of AI limitations.
5. How we use personal information
We use personal information to:
- provide, operate, maintain, and support the Service;
- answer calls, capture booking details, and update your connected practice management system;
- authenticate account holders and secure the Service;
- process billing and payments;
- investigate and resolve technical faults;
- improve the accuracy and reliability of the Service, including by evaluating AI performance on real transcripts, and in de-identified and aggregated form for benchmarking and product development;
- comply with legal obligations, court orders, and regulatory requests.
We do not sell personal information. We do not use Patient Data for marketing, profiling, or any purpose unrelated to delivering the Service.
6. Disclosure and third-party providers
6.1 Sub-processors. We disclose personal information to the Third-Party Services required to run the Service:
- voice AI, call handling, transcription, and recording (Retell AI);
- telephony / SIP carriage (Telnyx);
- practice management system integration (Cliniko);
- payment processing (Pin Payments);
- cloud hosting and infrastructure (DigitalOcean).
Each provider is bound by a data processing agreement (or equivalent) and may only use the information to perform services for us. Our voice provider, Retell AI, processes call data as our sub-processor under a data processing addendum and holds SOC 2 Type I and Type II, HIPAA, and GDPR compliance. A current list of sub-processors is available to Clients on written request to sales@proxiblue.com.au.
6.2 Legal disclosure. We may disclose information where required by law, court order, or a lawful request by a regulator or enforcement body.
6.3 Business transfers. If ProxiBlue is involved in a merger, acquisition, or asset sale, personal information may transfer to the successor entity under equivalent privacy protections.
7. Cross-border disclosure (APP 8)
Some Third-Party Services store or process data outside Australia — in particular, our voice provider (Retell AI) processes call recordings, transcripts, and associated data in the United States. Before disclosing personal information overseas, we take reasonable steps to ensure the recipient handles it consistently with the APPs, through contractual protections (such as a data processing addendum) or an applicable exception under APP 8. A summary of the countries in which data may be processed is available on request. ProxiBlue remains accountable to you under Australian law for information disclosed to its sub-processors.
8. Data security
8.1 We protect personal information with technical, organisational, and physical safeguards, including:
- encryption of data in transit and at rest;
- multi-factor authentication and role-based access controls;
- access restricted to personnel who require it to deliver the Service;
- logging and monitoring, and periodic security review;
- incident response procedures.
8.2 No system is perfectly secure. We cannot guarantee absolute security, but we take reasonable steps to protect information and to respond promptly to any incident.
9. Data retention
We retain personal information only as long as necessary for the purposes described in this policy or as required by law. Indicative retention periods:
| Data | Retention |
|---|---|
| Call recordings and transcripts | Stored by our voice provider (Retell AI) under a data-retention setting that automatically deletes recordings and transcripts after a configured number of days. Retell supports retention from 1 day up to 2 years; the Service is configured to 90 days. Recording download links delivered by webhook expire 10 minutes after each call. |
| Appointment and booking data | Held in your practice management system (Cliniko), which you control; retained by us only as needed to deliver the Service |
| Client account information | Duration of the account plus 90 days |
| Billing and payment records | 7 years for tax and audit compliance |
| Website analytics | 26 months |
PII minimisation. Retell AI supports automatic redaction of personal identifiers (names, addresses, dates of birth, phone numbers, PINs) from stored transcripts and recordings, and a metadata-only mode that stores no transcript or recording at all. The Service's configured storage level is redact PII.
On termination, we delete Patient Data (except records legally required to be retained) within the period stated in Terms of Service clause 8.5.
10. Data breaches
If we become aware of a data breach that is likely to result in serious harm, we will act in accordance with the Notifiable Data Breaches scheme under Part IIIC of the Privacy Act. Where the breach concerns Patient Data for which you are the APP entity, we will notify you without undue delay so that you can meet your own notification obligations to affected individuals and to the Office of the Australian Information Commissioner (OAIC).
11. Your privacy rights
11.1 Access (APP 12) and correction (APP 13). You may request access to, or correction of, the personal information we hold about you as an account holder. We will respond within a reasonable time (generally 30 days). We do not charge for making a request; a reasonable fee may apply to providing access where significant work is required, and we will tell you in advance.
11.2 Patient rights. Patients seeking access to, or correction of, their information should contact your clinic, as you are the APP entity for that information. We will support you in responding to such requests and will forward any request received directly by us to you within a reasonable time.
11.3 How to make a request. Email sales@proxiblue.com.au with the details of your request. We may need to verify your identity before acting.
12. Cookies and website analytics
Our website uses cookies and similar technologies for essential functionality and analytics. You can manage cookies through your browser settings. Disabling some cookies may affect website functionality.
13. Children's privacy
The Service and website are intended for use by clinics and their staff, not by children directly. The Service may process a minor patient's information where your clinic instructs it to as part of a booking; that information is handled under your clinic's own privacy obligations.
14. Complaints
14.1 Contact us first. If you have a privacy concern, contact us at sales@proxiblue.com.au. We will acknowledge your complaint promptly and aim to resolve it within a reasonable time (generally 30 days).
14.2 Escalation. If you are not satisfied with our response, you may complain to the OAIC at www.oaic.gov.au or 1300 363 992.
15. Changes to this policy
We may update this policy from time to time. The current version, with its effective date, is published on our website. Material changes will be notified to Clients by email or via the client dashboard.
16. Contact
Privacy enquiries: sales@proxiblue.com.au Entity: ProxiBlue ABN: 30 550 620 048 Effective date: 26 July 2026