Privacy Policy
Built so we never see patient data.
Last updated 22 May 2026
What we collect, where it lives, and how to get any of it back. In plain English.
Four things we hold to.
-
No patient data.
Names, Medicare numbers, IHIs, dates of birth. We never collect any of it. Zero Data Persistence by design.
-
Australian hosting.
Microsoft Azure data centres in Australia. Your data doesn’t leave the country.
-
No selling. Ever.
We don’t sell your data. To anyone. For any reason.
-
Delete on request.
Email us. We action within 30 days. Same window for any other privacy request.
What we collect
We collect what we need to provide the service and run the website. Nothing more.
You can’t use the service anonymously or under a pseudonym. We need to know who you are to authenticate with Services Australia and bill your subscription.
Account information. When you sign up, we collect your organisation’s name, ABN, and the contact details of your authorised representative.
Usage data. Each time a request goes through the service, we record operational data (time, endpoint, success or failure) to give you usage reports and meter your plan.
Website data. When you visit rebateright.com.au, our hosting provider records standard request data (page, IP, time) for security. We don’t add cookies, cross-site tracking, or any identifiers. If you email, book a demo, or send a form, we receive what you send.
Government identifiers. We don’t treat Medicare numbers, IHIs, or provider numbers as your account identifier. They belong to Services Australia. We don’t store them or claim them as our own.
What we never collect:
- Any patient information: names, Medicare numbers, dates of birth, Individual Healthcare Identifiers (IHIs), or any identifying detail.
- Payment card or banking details. These are handled entirely by our payment processors.
- Any personal data beyond what is necessary to provide the service.
How we use it
We use what we collect for these purposes only:
- to manage your account and provide access to the service;
- to process and respond to your requests;
- to generate usage insights and reports visible to you through the application;
- to communicate with you about your account, including support, invoicing, and service updates;
- to meet our obligations under Australian law, including the Privacy Act 1988 and applicable healthcare regulations.
On AI. We don’t use your data, or any patient data, to train AI or machine-learning models. Our rules engine doesn’t use AI: it runs rule-by-rule against the published Medicare Benefits Schedule.
On selling. We never sell your data. We don’t share it with third parties except where required by law, or with the service providers acting on our behalf under strict confidentiality.
Where it lives
Storage. Your data lives in Microsoft Azure data centres located in Australia. It doesn’t leave the country.
Retention. We retain your account and usage data for as long as your account is active, plus a reasonable period thereafter for legal and record-keeping obligations. Ask us to delete it sooner and we will. See Your rights below.
Security. We encrypt data in transit and at rest and grant access on a need-to-have basis. The full architecture, the PRODA key model, access controls, the Essential Eight reference, lives on the Security page.
Your rights
Under the Australian Privacy Act 1988, you can:
- access the personal information we hold about you;
- correct anything inaccurate or out of date;
- request information about how your data has been used or disclosed;
- request deletion of your data. We’ll action this promptly. If we need to keep some data for legal obligations, we’ll explain why.
Email us at hello@rebateright.com.au to exercise any of these. We’ll action your request within 30 days.
If you believe we’ve fallen short of our obligations under the Privacy Act 1988, you can complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au or by calling 1300 363 992.
If something goes wrong
Notifiable Data Breaches. Under Australian law (the Notifiable Data Breaches scheme), we must notify you and the OAIC if a data breach is likely to result in serious harm. We’ll do so as soon as practicable, with a plain-English description of what happened, what data was affected, and what to do next.
Reporting a concern. If you suspect a breach involving your account, or have a privacy concern of any kind, email hello@rebateright.com.au. We’ll investigate and reply directly.
Reporting a vulnerability. Security researchers and integrators can disclose vulnerabilities directly to security@rebateright.com.au. More on our response approach: Security: Reporting a vulnerability.
Changes to this policy
If we make material changes to this policy, we’ll email you at least 14 days before they take effect. Continued use of the service after that date constitutes acceptance.
Contact
Questions or concerns about this policy or how we handle your data? Email us at hello@rebateright.com.au.