Legal

Data Processing Addendum

For clinic and healthcare clients · Last updated: 14 June 2026

This addendum applies where Visiably (ABN 52 462 944 537) processes personal information — including patient contact details — on behalf of a clinic, practice, or healthcare client ("the Client"). It forms part of, and is governed by, the Visiably Terms of Service.

1. Roles

The Client is responsible for the patient personal information it provides and determines the purpose for which it is used. Visiably acts only on the Client's behalf and on the Client's instructions, solely to deliver the agreed services (for example, sending review requests after appointments).

2. Scope of data

Visiably will only collect and process the minimum information needed to deliver the service. For clinic clients this is limited to:

Visiably does not require, and asks that the Client does not provide, any clinical or health information — including diagnoses, treatment details, conditions, or the reason for an appointment. The Client agrees not to share sensitive information as defined under the Australian Privacy Principles (APPs) beyond what is strictly listed above.

3. Client warranties

The Client confirms that:

4. Purpose limitation

Visiably will use the patient information only to deliver the agreed services. It will not use it for any other purpose, will not sell or rent it, and will not disclose it to any third party except trusted sub-processors strictly necessary to deliver the service (such as email or SMS delivery providers), each bound by equivalent obligations.

5. Security

Visiably takes reasonable technical and organisational steps to protect patient information from misuse, loss, and unauthorised access, including limiting access to information, using reputable service providers, and transmitting data over secure channels. No method of storage or transmission is perfectly secure, but Visiably commits to handling patient information with care proportionate to its sensitivity.

6. Messaging standards

Every message Visiably sends on the Client's behalf is sent under the Client's name, is professional in tone, and includes a clear and functional unsubscribe or opt-out mechanism. Patients who unsubscribe are suppressed from future messages, and patients contacted recently are not contacted again within the configured window.

7. Data breach

If Visiably becomes aware of a data breach affecting the Client's patient information, it will notify the Client without undue delay and cooperate in good faith with any assessment or response required under the Notifiable Data Breaches scheme.

8. Retention and deletion

Visiably retains patient information only for as long as needed to deliver the services. On termination of the engagement, or on the Client's written request, Visiably will delete or return the patient information it holds within a reasonable period, except where retention is required by law.

9. Sub-processors

Visiably may use third-party providers (for example, email and SMS delivery, and integration with the Client's practice management software) to deliver the services. These providers only receive the information needed to perform their function. Some may store data overseas; where that occurs, Visiably takes reasonable steps to ensure handling consistent with the APPs.

10. Liability and precedence

This addendum sits within the Visiably Terms of Service. Where this addendum and the Terms conflict on the handling of patient information, this addendum prevails. Nothing in this addendum limits rights or obligations that cannot be excluded under the Australian Consumer Law or the Privacy Act.

Contact

Questions about how Visiably handles patient information? Email hello@visiably.com.au.

Note: This addendum is provided as a general template and does not constitute legal advice. Because it concerns patient and health-adjacent information, we strongly recommend having it reviewed by a qualified Australian privacy lawyer before relying on it.