Trust
Privacy, security and Australian safeguards
Refera protects referral information with controls that practices can inspect, test and include in their own security review. This page explains those controls and links to the supporting detail.
- Real-data build designed for Australian residency
- Draft-first - nothing sent without human approval
- Controls verified before live use
Six promises
Six commitments you can verify
Each commitment maps to an enforced control or a control that must be proven before activation. Before any real referrals flow, the practice and Refera must execute a lawyer-reviewed data processing agreement.
Australian data residency
The licensed portal, API and pooled tenant store run in AWS Sydney, protected by explicit runtime and release-identity region denies; account-wide coverage is verified before live capture begins. The browser reaches portal.refera.au directly through an AWS load balancer to Refera's ECS/Fargate service. Real-referral Bedrock processing is not active and must pass published regional verification before use.
No clinical triage
Refera is administrative process-state software. Urgency is only ever the referrer's own words, quoted and attributed; attachments are noted, never interpreted. The extraction schema has no field a clinical judgement could occupy.
Draft-first, always
Nothing leaves Refera without a named staff member approving it. That approval step is also the error firewall: an extraction mistake cannot reach a GP or a record, because a person reviews every draft first.
No independent patient contact
No patient account or patient-facing Refera portal exists. Cancellation Fill can prepare generic appointment copy for an eligible record, but Refera never auto-sends or acts independently. Named practice staff approve and copy the draft, use their normal channel, then separately attest the offer and booking.
Export freedom
The authenticated workspace exports structured settings, referral records and available sealed events as tenant-scoped JSON, free at any time. Versioned, Object-Locked source-archive storage is deployed in AWS Sydney. Complete source retention, authenticated readback, restore, export and tenant-isolation proof must be proven before live capture begins.
Sealed audit trail
Every event is hash-chained and production writes use a server-held HMAC key. The current JSON export carries event content and chain heads but is not independently verifiable without a tenant-safe artifact; that artifact and any write-once anchor are not claimed as deployed.
Privacy Act 1988
The Australian Privacy Principles, mapped to controls
Health information is sensitive information under the Privacy Act 1988 (Cth). Refera's controls are designed to support practices' obligations under the Australian Privacy Principles and applicable state health-record laws. The table separates controls operating now from safeguards that must pass before real referral data can flow; a lawyer-reviewed data processing agreement is also required.
| Principle | Refera's control |
|---|---|
| APP 1 - open and transparent management | Published privacy policy, a privacy impact assessment before launch naming every processor, and a nominated privacy contact. |
| APP 2 - anonymity and pseudonymity | Patients deal with their practice, never with Refera. Identifiers remain available only where the referral workflow requires them; Refera does not claim a separate token vault. |
| APP 3 - collection | Only what arrives in the referral the practice already receives, only on the practice's instruction - no enrichment, no other sources. |
| APP 4 - unsolicited information | The locally tested HealthLink adapter holds and pages a synthetic message demonstrably addressed to another organisation before any downstream delivery or extraction; no live HealthLink receiver is enabled. Other real-data channels remain blocked until equivalent handling and a retention schedule are proven. No automated destruction is claimed today. |
| APP 5 - notification | The practice's collection notice names Refera; template wording ships in the onboarding pack. |
| APP 6 - use and disclosure | One purpose only: the contracted service. No secondary use, no sale, no training AI on patient data, ever. |
| APP 7 - direct marketing | None. Patient information is never used for marketing. Cancellation Fill is a practice-controlled appointment administration workflow for explicit eligible records, with generic drafts, no automatic send and no independent Refera contact. |
| APP 8 - cross-border disclosure | Licensed referral processing is pinned to AWS Sydney and verified in CloudTrail. Public website, onboarding and optional voice support contain business information only. Web voice names AI, recording and provider processing before any session or microphone request. |
| APP 9 - government identifiers | Medicare and provider numbers are data on the referral, never Refera's own identifiers. |
| APP 10 - quality | The workspace shows extracted fields beside a verbatim source excerpt and attachment metadata. Before live capture begins, source-document retention, authenticated retrieval, restore/readback and complete export must be proven end to end. |
| APP 11 - security | Encrypted pooled DynamoDB storage, tenant-partitioned access, server-held seal keys, no patient data in logs, and detection on before real data. |
| APP 11.2 - destruction | An authenticated owner can record an assisted closure request. Refera confirms export, deletion scope and applicable legal, security and backup retention before any removal; no browser action promises immediate deletion. |
| APP 12 - access | Access requests go to the practice. Authenticated structured export is free at any time. Object-Locked source-archive storage is deployed in AWS Sydney; complete authenticated retrieval, restore and export are verified before live capture begins. |
| APP 13 - correction | Corrections are sealed as new events with the prior value preserved in append-only history, never quietly rewritten. |
Beyond the APPs
State law, My Health Record and breaches
Three questions practices ask early, answered in a sentence each - and in full in the compliance guide.
State health-records law
Victoria, NSW and the ACT each add health-record privacy requirements. Refera's controls are designed to support those obligations; the applicable jurisdiction and the lawyer-reviewed agreement are confirmed with each practice before real referrals flow.
My Health Record
Refera does not connect to, read from or write to the My Health Record system, holds no My Health Record data, and has no registered role under the My Health Records Act 2012. The front door is the practice's own - a national repository is not part of it.
If a breach ever happens
A written plan under the Notifiable Data Breaches scheme: contain and escalate immediately, assess within the statutory ceiling, and notify the OAIC and individuals as the Privacy Act requires. Affected practices receive an initial notice on the counsel-approved clock in the executed DPA; no fixed public timing is active until that allocation is agreed.
Sub-processors
Current sub-processors
This public register identifies current and planned providers. Before real referrals flow, the executed lawyer-reviewed data processing agreement must name the permitted scope and the process for any change.
| Sub-processor | Location and scope | What it sees |
|---|---|---|
| Amazon Web Services | Designed for Sydney (ap-southeast-2), region-pinned by policy before real data | All platform infrastructure - compute, database, storage, keys, logs. AWS publishes ISO/IEC 27001, 27017, 27018 and 27701 coverage for its in-scope services; those certifications belong to AWS, not Refera. |
| Amazon Bedrock (within AWS) | Planned Sydney endpoint using direct single-region invocation, unless an exact AU-only inference profile is later evidenced and activated | After activation only, raw referral text and a required image may be processed synchronously by a pinned Bedrock model. Exact retention, provider access and destination regions must be evidenced before activation. No real referral data is sent today. |
| Cloudflare | Global edge network | Public website, docs, status, analytics, business-only onboarding/authentication relays, dedicated business billing API and private automated release checks. Billing requests may contain practice identity, plan, cycle, subscription and invoice context, but no referral or patient material. Cloudflare holds a DNS-only record for the licensed referral API; it does not proxy that traffic, which terminates at the AWS load balancer. |
| Stripe | Global payment platform | Business identity, subscription, invoice and payment information. No referral or patient material. |
| Resend | Transactional email delivery | Account, agreement and sign-in email plus authorised Refera post-guard voice follow-up email. Voice email contains only fixed generic intent and limited call metadata, never raw transcript, free-text summary or caller name. No referral content. |
| Attio (retired) | Former business CRM; no new events | Historical business-only contact and lifecycle records may remain until provider-confirmed export, closure and deletion evidence is complete. No assistant or voice transcript, referral or patient material was permitted. Refera does not treat cancellation of the paid plan as deletion evidence. |
| OpenRouter | Public/support model gateway | Bounded product-request category, trusted Refera documentation extracts and bounded support-state enums/counts only. No visitor-authored question or history, contact or practice identity, arbitrary page context, referral or patient material. It is not used to summarise or persist conversations. |
| Slack | Business follow-up and operational notifications | Explicit business contact and practice metadata for requested follow-up, business signup and billing state, bounded voice intent, and platform or release-health alerts. Cloudflare D1 holds the durable business-event and delivery-state record. Assistant questions and replies, raw voice audio and transcript, free-text provider summaries, referral and patient material are prohibited. |
| ElevenLabs | Provider-operated AI voice infrastructure | Business sales and support audio is temporarily saved by ElevenLabs after explicit disclosure and consent so the privacy-filtered summary and required notifications can complete. Refera targets deletion of the provider conversation within four hours after required delivery and verifies absence. Provider retention is capped at one day as a fail-safe; under the provider's policy, deleted data may remain in backups for up to 30 days. Refera does not copy or retain raw audio or transcript. ElevenLabs publishes ISO/IEC 27001 and SOC 2 Type II assurance; those provider assurances belong to ElevenLabs, not Refera. No patient, referral or clinical information. |
| Twilio | Retained fallback telephone carrier | Business call audio and routing metadata for sales and product support only. This is not a patient or referral line. |
| Telnyx | Candidate customer-visible business telephone carrier | Business call audio and routing metadata for sales and product support only. Use begins only after Refera verifies and publishes the active line. This is not a patient or referral line. |
| Browser push providers | Apple, Google, Mozilla or Microsoft delivery infrastructure | An optional browser subscription endpoint, delivery timing and an encrypted generic count-only payload. No patient, referrer, referral, practice or clinical content. |
Updates and rollback
Kept current without interrupting the practice
Refera is cloud-managed, so updates happen centrally. Every release must preserve the no-triage boundary, the data wall and the practice's working day.
Security fixes first
Validated security fixes are patched the same day where possible. Interface improvements are grouped so practices are not interrupted by constant churn.
Every release is verified
Product, security, accessibility, desktop and mobile checks must pass before release. Live health checks then confirm the site, documentation, sign-in and workspace are responding correctly.
Rollback is built in
Public and documentation surfaces use versioned edge deployments; the licensed portal and API use health-checked ECS task revisions and can return to the previous proven revision.
Security roadmap
Built to a published bar
Security at Refera is engineering, not badges: a public roadmap of controls, each one landing before the data that needs it.