DRAFT FOR LEGAL REVIEW. This policy reflects the current River Aftercare product and intended launch operations but has not yet received final legal approval.
Last updated .
1. Who River Aftercare is
River Aftercare is operated by [FULL LEGAL NAME], an Australian sole trader trading as River Aftercare, ABN 32 671 297 130, based in Tweed Heads South, New South Wales, Australia.
River Aftercare is an Australian B2B publishing platform for healthcare practices. It helps clinics publish clinic-branded aftercare guidance on the web. The first vertical is dental, with planned applicability to other clinic types such as cosmetic and aesthetic clinics, physiotherapy, chiropractic and allied health.
2. Scope
This Privacy Policy explains how we handle personal information in connection with:
- the public River Aftercare marketing website;
- clinic enquiries submitted through the Contact form;
- clinic and staff accounts;
- practice configuration, branding and published aftercare content; and
- readers of public clinic-branded aftercare pages.
This policy is written to a high Australian privacy standard. It does not state whether River Aftercare is an APP entity under the Privacy Act 1988 (Cth). That status has not been determined in this document.
3. Personal information we collect
Depending on how you interact with us, we may collect:
- marketing enquiry details: name, work email, clinic or practice name, optional phone number, and any message you choose to send;
- clinic staff account details: name (if provided), email address, password stored as a one-way hash, clinic membership and role, and session data needed to stay signed in;
- practice configuration such as display name, contact details, emergency instructions, colours, presentation settings, logos (where logo upload is enabled), and aftercare guides or other clinic-published content; and
- technical information generated by hosting or application systems, which may include IP address, user agent, requested URL, HTTP status and timestamp.
We collect only what is reasonably needed for the relevant interaction. We do not collect a category of information merely because the underlying software could do so.
4. Information the current product is not designed to collect
River Aftercare is not currently designed for users to enter identifiable patient health records or personalised patient information.
Clinics and other users must not submit through the current product:
- patient names attached to clinical data;
- dates of birth;
- Medicare numbers;
- medical record numbers;
- diagnoses;
- clinical histories;
- treatment records; or
- other identifiable patient health information,
unless River Aftercare later introduces functionality explicitly designed for that purpose and updates its privacy, security and contractual arrangements.
Some forms include free-text fields (for example an enquiry message or clinic-authored guide copy). Those fields are intended for business contact details and generic aftercare instructions, not for patient records. Please do not enter identifiable patient information into them.
5. How information is collected
We collect information:
- directly from you when you submit the Contact form, create or use a staff account, or configure a clinic;
- from authorised clinic users who enter practice details, branding and aftercare content; and
- automatically, to the extent hosting or application systems generate technical logs when the service is used.
The Contact form includes a hidden field used only to reduce automated spam. That field is not intended to collect personal information from people filling in the form.
6. How we use information
We use personal information to:
- respond to clinic enquiries and operate an assisted onboarding or commercial relationship;
- create and administer clinic and staff accounts;
- host, display and maintain clinic-branded aftercare pages;
- provide support, security, troubleshooting and service communications;
- meet legal, accounting and dispute-related obligations; and
- improve the reliability and operation of the service.
We do not sell personal information.
7. Public aftercare guides
Public aftercare pages are published by the clinic on a clinic hostname. They present clinic-branded procedure guidance. The URL identifies a clinic and a procedure or guide (for example a tooth-extraction page). It does not identify a named patient.
Generic public guides do not require a patient account and are not designed to collect reader personal information. Anyone with the link can open the page, in the same way they can open a public practice webpage.
8. Clinic and staff account information
Staff accounts are for clinic personnel and, where relevant, platform operators. We store the account name (if provided), email address, a hashed password, clinic membership and role, and session records needed to authenticate the user.
Platform operators who administer clinics can see clinic identity and configuration. They do not receive a patient health record through the current product, because the current product is not designed to hold one.
9. Practice configuration and branding
A clinic may store operational and branding information used to present its aftercare pages, including practice display name, colours, radius and theme settings, instruction terminology, clinic contact details, emergency instructions, logos where upload is enabled, and the aftercare guides the clinic creates or adapts.
That information is clinic operational data. It is shown on the clinic’s patient pages under the clinic’s brand.
10. Technical and log information
The systems that host the service may record technical information commonly generated by web applications, such as IP address, user agent, requested URL, HTTP status and timestamp. This information is used to operate, secure and diagnose the service.
11. Cookies and local browser storage
Staff authentication uses a host-only session cookie on the staff hostname. The cookie is HttpOnly, uses SameSite=Lax, and is marked Secure in production. It is used to keep an authorised user signed in. It is not an advertising tracker.
Appearance preferences (Light, Dark or System) may be stored in the browser’s localStorage on the marketing site, the staff portal, and public aftercare pages where a clinic enables a patient theme control. These preferences stay on the device and are not advertising cookies.
We do not currently operate a cookie-consent marketing stack, because we do not currently run marketing analytics or advertising pixels.
12. Analytics
River Aftercare does not currently use third-party behavioural advertising or advertising pixels on its public website or public aftercare guides.
We do not currently operate a marketing analytics product on those pages. If that changes, we will update this policy before any such processing begins.
13. Disclosure to service providers
We may disclose personal information to service providers who help us operate the service, strictly as needed for that purpose. Those providers may fall into categories such as:
- application hosting;
- database hosting;
- object or file storage for clinic logos and similar assets;
- DNS and network services;
- email delivery; and
- monitoring or security services.
We will name production service providers in this policy once those arrangements are finalised. Contact enquiries are delivered by email using the mail transport configured for the application. They are not stored as enquiry records in the application database.
14. Overseas processing
River Aftercare is operated from Australia and is aimed at Australian healthcare practices. Some service providers may process information outside Australia. We will update this Policy as our production service-provider arrangements are finalised.
15. Security
We take reasonable technical and organisational measures designed to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure.
Those measures currently include:
- storing staff passwords as one-way hashes rather than in usable form;
- access control based on authenticated sessions, clinic membership and role;
- clinic authorisation boundaries so staff act within their own clinic;
- host-only, HttpOnly session cookies with SameSite=Lax, marked Secure in production;
- separated hostnames for the public marketing site, staff portal and clinic patient pages; and
- HTTPS for production access once the service is deployed on a public hostname.
No method of transmission or storage is completely secure. We do not claim ISO, SOC, HIPAA or Privacy Act certification, encryption-at-rest guarantees, or a completed independent penetration-test status.
16. Data breach response
If we become aware of a suspected security incident affecting personal information, River Aftercare will investigate, take reasonable containment and remediation steps, and make any notifications required by applicable law, including under the Notifiable Data Breaches scheme where that scheme applies to River Aftercare in the relevant circumstances.
17. Retention and deletion
We keep personal information only for as long as reasonably needed for the purposes described in this policy, or as required by law. Our intended retention approach is:
- Contact and enquiry personal information: normally up to 12 months after the last meaningful interaction, unless needed longer for an active commercial relationship, a legal obligation or a dispute.
- Active clinic and staff account information: while the clinic has an active relationship with River Aftercare.
- Terminated clinic operational data: we aim to delete active clinic account and operational data after a 30-day exit period following the end of the subscription, unless it is still required.
- Security and application logs: we aim to retain them for about 90 days, unless a security incident, legal obligation or infrastructure requirement reasonably requires longer.
- Backups: where production architecture permits, we aim to rotate or overwrite backups so that deleted operational data is not retained in backups for longer than about 90 days after active deletion.
- Billing, accounting and tax records: retained for the period required by Australian law, which is commonly at least 5 years and may be longer in a particular circumstance.
These periods describe our intended operating practice. Exact backup and deletion timing depends on the production hosting and backup arrangements in place at the time.
18. Direct marketing and service communications
We distinguish operational messages from marketing messages.
- Operational or service messages include responses to an enquiry, account, billing, security and similar messages needed to provide or administer the service.
- Marketing or promotional messages are electronic messages sent to promote River Aftercare rather than to operate an existing account or complete a requested enquiry.
Commercial electronic marketing will comply with applicable Australian law and will include an unsubscribe mechanism where required.
19. Access and correction
You may request access to, or correction of, personal information we hold about you, where applicable. We may need to verify your identity before responding. Clinic administrators can also update much of their practice configuration in the staff portal.
Please do not include patient records in an access or correction request sent through the Contact form.
20. Privacy complaints
If you have a privacy complaint, contact us using the details in section 24, or through the Contact page on this website. We may ask for enough information to verify the request and investigate the complaint. We will acknowledge and investigate complaints and aim to respond within 30 days.
If you are not satisfied with our response, the Office of the Australian Information Commissioner (OAIC) may be available to assist where applicable.
21. Children
River Aftercare is a business platform and does not provide child accounts. Public aftercare guides can be viewed by anyone with the link, including children or parents and guardians. Generic guides are not designed to collect reader personal information.
22. Automated decision-making
River Aftercare does not currently use personal information to make automated decisions that could reasonably be expected to significantly affect an individual's rights or interests.
23. Changes to this policy
We may update this Privacy Policy from time to time, including when our product, service-provider arrangements or legal obligations change. The “Last updated” date on this page will change when we do. Material changes will be published on this page.
24. Contact
For privacy questions or requests, use the Contact page on this website or write to the privacy contact below. Please do not include patient or clinical records in that correspondence.
[FULL LEGAL NAME], an Australian sole trader trading as River Aftercare, ABN 32 671 297 130, based in Tweed Heads South, New South Wales, Australia. Privacy contact: [PRIVACY EMAIL].