1. Scope and roles
Refera provides administrative process-state software to Australian practices. Refera performs no clinical triage and is not a patient-facing service. Practices decide how referral information is collected and used in their care and administration. Refera handles that information as the practice's contracted service provider and on the practice's instructions.
New accounts begin with an empty workspace. For supported direct connections, Refera uses a fixed connection email containing no patient information; assisted paths use a clearly labelled check coordinated with the practice or its IT provider. Real patient data remains technically blocked until the published connection and privacy checks are complete, including the data processing agreement and the practice collection-notice check.
Do not send patient information through public channels. The public assistant, product-overview request, enquiry form, voice service, telephone line and billing forms are for business, product and account matters only.
2. What we collect
| Context | Information handled |
|---|---|
| Public website | Technical request and security data needed to serve and protect the site, plus Cloudflare Web Analytics. The public assistant sends its model gateway a bounded request category and trusted Refera documentation, not the visitor's authored question or conversation history. |
| Enquiries and support | Business contact name, work email, practice, phone, ABN and a bounded request category when a person explicitly asks for follow-up. The optional product-overview form accepts only a work email and sends the requested overview as one transactional email; it records a business-only information request in Refera's Cloudflare D1 business CRM and does not create a newsletter subscription. Slack may receive the matching business follow-up card. Assistant conversation text and AI-generated summaries are not written to D1, Slack or the support handoff. |
| Account setup | Practice name, ABN, specialty, location, business contacts, systems, selected capture channels, plan preference and the signed acceptance record. The acceptance record includes the signer's name, role, email, timestamp, document fingerprint and signup reference. |
| Practice branding | An optional public practice website, confirmed colours and an optional small embedded raster logo. A brand lookup reads a bounded public homepage and eligible public logo to prepare a preview; page content is not retained or returned. Nothing is applied until an Owner or Admin confirms it. |
| Sign-in and security | Work email, passkey public credential material, authenticator and recovery verification records, session state and generic security events. Recovery proof permits restricted factor replacement only and does not open referral data. |
| Billing | Practice business identity, ABN, selected plan and cycle, subscription and invoice state, billing email and an optional business purchase-order reference. Card and bank details are entered into Stripe's hosted surface and do not touch Refera. Submitting an invoice request does not charge, create a Stripe invoice, start a subscription or unlock paid capture. Invoice-request fields must not contain patient or payment-card information. |
| Referral service | Once a practice is explicitly activated for real data, the referral information the practice instructs Refera to process, including identifiers, referral text and source documents needed for the contracted administrative workflow. Refera does not enrich it from unrelated sources or use it for marketing. |
| Device notifications | An optional browser push endpoint and generic count-only delivery state. Lock-screen copy contains no patient, referrer, referral, practice or clinical detail. |
| Voice and telephone | Business sales and support calls use encrypted transport and are processed by the voice provider after disclosure and consent. Refera keeps a privacy-filtered business summary and limited delivery metadata, but does not keep a copy of the raw audio or transcript. The provider retains call data for up to one day, with deleted data potentially remaining in backups for up to 30 days under its policy. |
3. How we use information
Refera uses information to:
- create, secure and support the practice account;
- provide the contracted referral-administration workflow on the practice's instructions;
- prepare and verify practice branding the practice explicitly chooses;
- operate subscription checkout, invoice requests, receipts and account administration;
- answer product questions and respond to requested business follow-up;
- send generic account, security, billing and device notifications; and
- protect, test, audit and improve the reliability of the service using fictional test data and bounded operational evidence.
Refera uses deterministic account, security, allowance, billing, connector and activation checks to allow, pause or refuse an account action. These checks do not make patient-care decisions, rank referrals or infer clinical urgency. A practice user can ask the Refera team to review an account-control outcome through the privacy or support contact below.
Refera does not sell patient information, use patient information for direct marketing, train AI models on patient information, independently contact a patient, or use referral information to rank clinical urgency, acuity, severity or diagnosis.
5. Where information is handled
The licensed portal and tenant data plane run in AWS Sydney and are protected by an AWS regional-deny policy. Any future real-referral AI processing must separately prove its exact Australian route before activation. The connected portal is served directly from AWS Sydney rather than proxied through Cloudflare.
Public website, payment, business email, CRM, support, browser push and optional voice providers operate overseas infrastructure. The countries in which recipients are currently likely to be located are the United States, United Kingdom, Ireland, Netherlands and Singapore. Those channels are restricted to the business-only or generic information described above and must not be used for patient, referral or clinical information. The live sub-processor register identifies each provider and its permitted scope. See Data residency for the testable technical boundary.
Provider certifications belong to the providers, not Refera. AWS infrastructure is independently ISO 27001 certified, and ElevenLabs states that it maintains SOC 2 certification. Refera does not claim either certification as its own.
6. Security
Refera uses encrypted transport and encrypted AWS storage, tenant-partitioned access, server-held seal keys, passkey-preferred access, email plus authenticator as the non-passkey live-access route, restricted recovery sessions, session revocation after factor changes, one-hour inactivity locking, privacy-safe logging and a sealed event history.
Authorised Refera services process referral content only to provide the features a practice has enabled. Current controls, provider responsibilities and independent assurance are published on the Trust page.
7. Retention, export and deletion
Refera keeps information for as long as needed to provide and secure the service, maintain required business and acceptance records, respond to a request, and meet any applicable legal, security and backup-retention obligations. Retention differs by record and provider; this notice does not promise one period for every category.
A practice can export its structured tenant data and available sealed history free while the account is open. Current account closure is authenticated and operator-assisted: it revokes access and preserves the records while Refera confirms the lawful export and retention position. A deletion or de-identification process is not deployed today and must be completed before live capture begins. Refera does not claim instant cryptographic erasure.
For optional web and telephone voice, ElevenLabs temporarily saves the business call so Refera can prepare the requested summary and follow-up. Refera targets deletion from ElevenLabs within four hours; provider retention is capped at one day, and deleted data may remain in provider backups for up to 30 days. Refera keeps the business summary and limited delivery records, but not a copy of the raw audio or transcript. This channel is for product and practice enquiries, not patient, referral or clinical information.
8. Access and correction
Practice users can review and correct their business profile in the authenticated workspace and can request access, correction, export or closure through Refera. Corrections to sealed referral history are recorded as new events rather than silently rewriting the prior record.
Patients should direct access or correction requests about their referral or health information to their practice. Refera assists the practice with the records it processes on the practice's instructions.
9. Contact, concerns and changes
Privacy requests and complaints
Email [email protected] with the subject Privacy request or Privacy complaint. Do not include patient or referral details in an ordinary email. Refera will verify the request and move sensitive follow-up to an appropriate channel.
For a complaint, explain what happened and the outcome you are seeking. Refera will acknowledge it, investigate the facts and respond with the outcome or next steps. This notice does not promise a fixed response time.
If the concern remains unresolved after Refera has had an opportunity to address it, you can make a privacy complaint to the Office of the Australian Information Commissioner.
Emba Consulting Pty Ltd (ABN 43 684 216 706), trading as Refera
Melbourne, Australia
Refera may update this notice when the service or its providers change. The effective date at the top changes with it. A change to this public notice does not silently change an accepted practice agreement; where re-acceptance is required, Refera presents the new agreement separately.