Privacy

Privacy Policy

Patient data passes through us. None of it remains.

Last updated 7 September 2026

What we never store, what we keep, where it lives, who handles it, and how to see, correct or delete it.

Our commitments

Four things you can rely on.

  1. No patient data is ever stored.

    Names, Medicare numbers, IHIs and dates of birth pass through to Services Australia to answer your request. None of it remains with us.

  2. Your data stays in Australia.

    Microsoft Azure data centres in Australia. Nothing leaves the country.

  3. Never sold, never given away.

    We never sell your data, and we never give it to anyone for their own use.

  4. Yours to see, correct or delete.

    Email us. Every privacy request is actioned within 30 days.

What we never store

The patient details you send us pass through our service to Services Australia to answer your request. Once the response is returned, nothing is retained. We never store:

  • Any patient information: names, Medicare numbers, dates of birth, Individual Healthcare Identifiers (IHIs) or any other identifying detail.
  • Payment card or banking details. Our payment provider handles those entirely.
  • Any personal data beyond what we need to provide the service.

This is how the service is built, not a setting. No part of our infrastructure holds a patient record, so no patient record can be leaked, breached or subpoenaed.

What we keep

We keep what we need to provide the service and run the website, and nothing more. The service cannot be used anonymously, because we need to know who you are to authenticate with Services Australia and to invoice you.

Account information. Your organisation’s name, ABN, and the contact details of your authorised representative.

Usage data. A record of each request: when it was made, which endpoint it used and a short summary of the result. It never includes patient details. We use it for billing and for the usage reports in the application.

Website data. When you visit rebateright.com.au, our hosting provider records the page, your IP address and the time, for security and performance. We add no cookies, no cross-site tracking and no identifiers of our own. If you email us, book a demonstration or send a form, we receive what you send and use it only to reply.

Government identifiers. Medicare numbers, IHIs and provider numbers belong to Services Australia. We do not store them, and we do not use them as your account identifier. Your account is identified by a subscriber code we issue.

How we use it

We use the information we keep only to:

  • manage your account and give you access to the service;
  • process and respond to your requests;
  • generate the usage insights and reports you see in the application;
  • calculate what to invoice you;
  • communicate with you about your account, including support, invoicing and service updates;
  • meet our obligations under Australian law, including the Privacy Act 1988 (Cth) and applicable healthcare regulations.

No AI on your data. We do not use your data, or any patient data, to train AI or machine-learning models. Our eligibility engine is not AI. It applies the published Medicare Benefits Schedule rule by rule.

Never sold, never given away. No third party receives your data for its own purposes. The providers below handle it only to deliver the service to you, and beyond that we disclose it only where the law requires.

Where it lives

Storage. Microsoft Azure data centres in Australia. Your data does not leave the country.

Retention. We keep your account and usage data while your account is active, and for a reasonable period afterwards to meet our legal and record-keeping obligations. You may have it deleted sooner. See Your rights.

Security. We encrypt data in transit and at rest, and we give each person and system access only to what they need. The full picture, including the PRODA key model and access controls, is on the Security page.

Who handles it

Only the providers we need to run the service. What each one sees, and what it does not:

Services Australia. The Australian Government agency that administers Medicare. The patient details you submit pass through our service to Services Australia to answer your request. We keep no copy.

Microsoft Azure (Australia). Hosts the service and your account data: organisation details and the operational record of your requests. No patient data is held here, because we store none.

Cloudflare. Delivers the website. It sees your visits to rebateright.com.au: the page, your IP address and the time. Nothing from inside the application.

Payment provider. We send you an invoice, and you pay the provider directly. It handles your card or banking details, and we never see them. It receives no patient data, because we store none.

Your rights

Under the Privacy Act 1988, you may access the personal information we hold about you, and have it corrected if it is inaccurate or out of date.

Beyond the Act, we also give you the right to:

  • know how your data has been used or disclosed;
  • have your data deleted. If we must keep some of it to meet a legal obligation, we explain why.

Email hello@rebateright.com.au to exercise any of these. We action every request within 30 days.

If you believe we have not handled your personal information in line with the Privacy Act 1988, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au or by calling 1300 363 992.

If something goes wrong

Notifiable data breaches. Under the Notifiable Data Breaches scheme, we must notify you and the OAIC if a data breach is likely to result in serious harm. We do so as soon as practicable, with a plain-English account of what happened, what data was affected and what to do next.

Reporting a concern. If you suspect a breach involving your account, or have any privacy concern, email hello@rebateright.com.au. We investigate every concern and reply personally.

Reporting a vulnerability. Security researchers and integrators may write to security@rebateright.com.au. How we respond is on the Security page.

The documents and their versions

Three dated documents form your agreement with us:

Nothing else we publish adds to them, including this page.

A material change to this policy comes with 30 days’ notice to the email address on your account. If you continue to use the service after that date, you accept the updated policy. Dated revisions are listed in the revision history.

Contact

If you have questions about this policy or how we handle your data, email hello@rebateright.com.au.