Skip to main content

Heidi II is here. Learn more.

HeidiHeidi
  • Pricing
Log inGet Heidi free
alt
alt

Resources

  • Explainers

  • FAQs

  • Progress Notes

  • Podcast

  • AI Tools

Why Heidi

  • Impact

  • Awards and Recognition

  • Evaluating Heidi

  • Patient Experience

Compliance

  • Trust Center

  • GDPR

  • HIPAA

  • AU/NZ

  • UK

  • Canada

Support

  • Help Centre

  • Heidi Guides

  • System Status

  • System Requirements

  • Contact Us

Legal

  • Privacy Policy

  • Terms of Service

  • Usage Policy

  • UKGDPR Policy

  • Accessibility

imxYAA

© 2026 Heidi. All rights reserved.

Heidi Desktop goes where the browser can’t.

Dictate anywhere on your screen, capture telehealth audio straight from the call,
and skip the second login.

Download for macOSDownload for Windows
  1. Home
  2. legal

Privacy Policy

Heidi Team

29 September 2026•

Table of Contents

1. About this Policy

2. Get in touch

3. Definitions

4. About the Platform

5. What information do we collect?

6. How do we collect your information?

7. How do we use your information?

8. AI, model training and automated decisions

9. Sponsored content and advertising

10. Marketing communications and opting out

11. Where your information is stored and how it moves

12. Who do we share your information with?

13. Cookies and similar technologies

14. How do we protect your information?

15. How long do we keep your information?

16. Your rights

17. Employees, contractors and job applicants

18. Changes to this Policy

19. Our related companies

20. Region-specific terms

Restore eye contact with your patients

It's like your very own junior resident.
Get Heidi free

This Policy replaces all previous versions of our privacy policy, including versions previously published for particular regions. It does not amend any agreement governing our handling of information or expand any permission under that agreement.

1. About this Policy

Heidi Health Trading Pty Ltd (ABN 84 649 783 871) and its related companies listed in section 19 (“Heidi”, “we”, “us” or “our”) provide AI tools designed for use in healthcare settings. This Privacy Policy explains how we collect, use, disclose and protect your information when you use the Heidi platform (the “Platform”), visit our websites and their child pages (the “Site”), or apply for a role with us.

We act in two different roles, and it matters which one applies to you.

When we act for a Practitioner or healthcare organisation. Where we handle clinical or other information on behalf of a Practitioner or healthcare organisation (such as a clinic, hospital, health service or employer), that Practitioner or organisation decides what information we receive and how we may use it, and we handle that information as its service provider, on its instructions. The applicable agreement — including any data processing agreement or business associate agreement — governs our handling of that information and prevails over this Policy to the extent of any inconsistency. This role can apply whether the account is an organisation account, an individual or self-serve subscription, or a free account. If you are a patient of a Practitioner or organisation that uses Heidi, they are responsible for the clinical records about you: their own privacy notice applies to those records, and you should contact them to access or correct them. We will help them respond to you.

When we act in our own right. We are directly responsible for information we handle for our own purposes, including account registration, subscription administration and billing information about individual and self-serve subscribers and users of our free offering; information about Patients who hold their own account with us through a patient-facing app; information about visitors to our Site and people we market to; and information about people who apply to work with us. For that information, this Policy is the main description of how we handle it. An individual, self-serve or free account does not by itself determine our role for the clinical or other information handled through that account.

No agreement reduces the rights you have under Privacy Laws (see section 16).

2. Get in touch

You can contact us at any time about the way we handle and safeguard your information — to ask questions, update your information or your account, change your preferences, exercise any of your rights, opt out of marketing, or raise a concern or complaint.

2.1. General support: support@heidihealth.com

2.2. Privacy Officer and compliance team: compliance@heidihealth.com. Our Privacy Officer is Yassin Omar.

2.3. Data Protection Officer (where required by Privacy Laws): Yassin Omar, compliance@heidihealth.com

Region-specific contacts and regulators are listed in section 20.

3. Definitions

3.1. You means you, the reader of this Policy, whether you are a Practitioner, a Patient or another individual we deal with.

3.2. Privacy Laws means all privacy and data protection laws that apply to us when we handle your information, including applicable health information laws.

3.3. Personal Information means information or an opinion about an identified individual, or an individual who is reasonably identifiable, and includes any equivalent concept under Privacy Laws (such as “personal data”).

3.4. Health Information means any information that falls within: (a) “protected health information” as defined in HIPAA (United States); (b) “health information” as defined in the Privacy Act 1988 (Cth) (Australia); (c) “data concerning health” as defined in the EU GDPR and UK GDPR; (d) “health information” as defined in the New Zealand Health Information Privacy Code 2020; (e) “personal health information” or any equivalent category under applicable Canadian federal, provincial or territorial privacy and health privacy laws (including PIPEDA); and (f) any equivalent category under any other applicable Privacy Laws — in each case including such information collected or generated through a Practitioner’s use of the Platform.

3.5. De-identified Information means information that has been processed to remove or transform anything that identifies you, your organisation or any other individual, so that it cannot reasonably be used to identify anyone. Section 8 describes how we create and use De-identified Information, including our commitment not to re-identify it.

3.6. Content means the data and content you provide to the Platform and the outputs the Platform generates for you.

3.7. Users means anyone who accesses or uses the Site, the Platform or our services, including Practitioners and Patients.

3.8. Practitioners means medical practitioners, their clinics and other health professionals who use the Platform.

3.9. Patients means individuals who receive or seek healthcare from a Practitioner and whose information we handle in connection with our services. Patients may also hold their own account with us through a patient-facing app, in which case we deal with those Patients directly.

4. About the Platform

The Platform is designed for use by Practitioners. It also includes features and functions directed towards Patients. The Platform includes documentation, research, communication, and assistive products and features. Some of these products and features can, at your direction, work with other accounts and systems you connect, prepare and carry out tasks you ask for, and remember your preferences to improve how they work for you. The features available to you depend on your subscription, your organisation’s configuration and your location. Where a Patient holds their own account with us through a patient-facing app, we deal with that Patient directly and handle their information in our own right, not only on behalf of a Practitioner.

5. What information do we collect?

We collect the information described below to provide, secure and improve the Platform and our services. Some of this information is necessary for the Platform to work — if you choose not to provide it, some features may not be available to you.

CategoryDetails
Personal InformationYour name, address, age or date of birth, gender, contact number and email address.
Professional and verification informationWhere you are a Practitioner: your qualifications, registrations, training and educational background, specialty, organisation and practice type, and information we use to verify your status as a health professional, including professional registration numbers and, in the United States, your National Provider Identifier (NPI) checked against public registries such as NPPES.
Payment and claim informationPayment information you provide so you can pay for services, which may include credit card information, bank account details and health scheme card and claim details.
Health InformationWe collect Health Information about Practitioners and Patients when Practitioners or Patients access or use our products, including information arising from the use of those products and their authorised integrations, such as a connection to an electronic medical record (EMR). Section 8 explains how Health Information may be used.
Queries and other inputs and outputsWhen you use our search, knowledge and assistant features (including Heidi Evidence and Ask Heidi), whether on the Platform or on our Site, we collect the queries, prompts and other content you enter, any material you upload or attach, and the outputs generated in response. We may store these so you can return to them. Where the applicable Product Terms (https://www.heidihealth.com/legal/product-terms) or in-product notice state that a feature is not designed to process Health Information about Patients, Practitioners should not enter patient-identifiable information into that feature. Where such information is entered, we handle it in accordance with applicable health information laws, the applicable agreement and this Policy.
Information from accounts and systems you connectWhen you connect another account or system (such as email, calendar, file storage, a clinical record or a practice management system), we collect information from it as needed to provide the features you have asked for. This may include message and document content and calendar details.
Information about tasks you ask us to carry outWhen you ask a feature to prepare or carry out a task, we collect the instruction, the information needed to complete it, records of the steps taken and the result. Where you configure the Platform to operate on your device or screen, this may include screen captures and information visible on screen at the time.
Access credentialsWhere necessary to connect to a system you have authorised, we handle access tokens or credentials for that system.
Preferences and memoryInformation about how you work, including preferences you tell us and patterns in the edits you make, used to tailor outputs to you. You can view, change or turn this off.
Device informationYour device ID, device type, geo-location information, computer and connection information, statistics on page views, traffic to and from our sites, IP address and standard web log information.
Advertising and measurement informationOnline identifiers and device information (such as IP address, device and browser type, cookie and advertising identifiers) and information about the pages you view on our Site and the actions you take there, including how you arrived. We collect this through cookies, pixels, tags, SDKs and similar technologies, some operated by third parties. See section 13.
Information collected by cookiesSee section 13 for the categories of cookies and similar technologies we use and the choices you have.
Additional information you provideInformation you provide through customer surveys, directly through our Site, or indirectly through your use of the Platform.
Recruitment informationPersonal Information you provide when you apply for a job or position with us, such as your name, contact details, work history and relevant records checks.

6. How do we collect your information?

We collect your information directly from you when you register, communicate with us, or interact with our Site, Platform, services, content and advertising. We also collect information about you from others, including:

6.1. Your organisation — where you use the Platform under an organisation’s agreement with us, your organisation may give us information needed to set up and manage your access.

6.2. Authorised integrations — where you (or your clinic) have authorised a connection between the Platform and a third-party system you use (such as an EMR or practice management system), we may collect information through that integration, including Health Information provided by or on behalf of the Practitioner. We handle this information as a service provider acting on the Practitioner’s (or clinic’s) behalf and in accordance with the applicable agreement and this Policy.

6.3. Practitioner verification sources — third-party and public sources (such as registration bodies and, in the United States, the NPPES registry) we use to verify your status as a qualified health professional.

6.4. Content and evidence partners — evidence source partners and content licensors whose medical literature databases and APIs are integrated into the Platform (such as clinical guideline providers and journal databases).

6.5. Recruitment sources — recruitment consultants, previous employers, referees and background-check agencies, when you apply for a role with us.

7. How do we use your information?

We use your information to deliver and improve our products and services. We build data protection into our systems and business practices from the outset, including encryption, strict access controls, continuous threat monitoring and regular privacy impact assessments.

PurposeDetails
Access and servicesTo enable you to access and use our Site, Platform and other services.
Platform functionality and improvementTo design, provide, manage, secure and improve our Site, Platform and other services, including performing analytics. Where we use information to develop, test and improve our models, products and services, we do so as described in section 8, using De-identified Information or aggregated information.
Practitioner-facing productsTo generate clinical notes, letters, summaries and related documentation on behalf of Practitioners for their review and approval, and to facilitate access to curated medical literature, clinical guidelines and evidence-based resources.
Patient-facing productsTo create and secure your Patient account, deliver the clinical summaries and other content your Practitioner shares with you, provide the in-app features you request, and share your information with family members, carers or others you nominate, where you ask us to.
Carrying out tasks at your directionTo prepare, check and carry out tasks you ask for, including drafting and sending correspondence, creating and updating records in systems you have connected, and completing multi-step tasks you have configured. Practitioners remain responsible for reviewing and approving outputs and actions where approval is required.
Safety and integrityTo keep the Platform safe and prevent misuse: we use automated systems to screen queries, inputs and activity for fraud, abuse or unsafe use, and we may decline, limit or review flagged activity. Sections 8 and 20 describe the rights you have in relation to automated processing.
Verification and eligibilityTo verify your status as a health professional and determine your eligibility for particular features or offerings.
Support and contactTo send you service, support and administrative messages, reminders, technical notices, updates, security alerts and information you request, and to contact you when we need to tell you something important about the Platform, our services or your information.
MarketingTo send you marketing and promotional messages and other information that may interest you (see section 10), and to show sponsored content as described in section 9.
LawTo comply with laws, and to assist government or law enforcement agencies where required and authorised.
EmploymentTo consider your employment application.

If we intend to use Personal Information we have already collected in a way that is materially different from what this Policy describes, we will notify you first and, where required, seek your consent (see section 18).

8. AI, model training and automated decisions

8.1. AI in the Platform

The Platform uses artificial intelligence to generate outputs such as transcripts, notes, summaries and answers. Outputs are drafts and decision support. Qualified Practitioners remain responsible for reviewing and approving outputs before they are relied on. Where the law requires it, we tell you when you are interacting with an AI system.

Where third-party AI providers help deliver a feature, we may share relevant Content you submit or authorise the Platform to access for processing on our behalf. Privacy Laws, the applicable agreement (including any data processing agreement or business associate agreement), and the model-training restrictions below apply. Providers may not use that Content for their own purposes. Sections 11 and 12 explain these arrangements; providers’ roles and locations are listed at https://trust.heidihealth.com/subprocessors.

8.2. Model training

Organisation customers. Where you use Heidi under an organisation’s agreement with us, that agreement governs how we handle the organisation’s data. No customer data (including outputs) is used as an input to train, fine-tune or otherwise improve any AI model, whether operated by Heidi or by any third party. Any creation or use of De-identified Information derived from that data is subject to the permissions and restrictions in the applicable agreement; this Policy does not expand those permissions or displace those restrictions.

Paid individual plans and complimentary access. We do not use Content from paid individual plans, or De-identified Information derived from that Content, to train, fine-tune or otherwise improve any AI model, whether operated by Heidi or a third party. Temporary or complimentary access to a feature, including a trial or preview, does not by itself change your plan or the permissions that govern the use of your information.

Health Information. We do not use Health Information as an input to train, develop or improve any AI model, whether operated by Heidi or a third party. We may process Health Information to provide, operate, secure, support, test and evaluate the Platform only as permitted by the applicable agreement and Privacy Laws. Testing and evaluating the Platform in this way does not involve using Health Information to train, fine-tune or adjust any AI model.

De-identified Information. We may create and use De-identified Information only as permitted by the agreement governing your use of the Platform, subject to the restrictions above. For users on a free plan, the applicable Terms of Service (https://www.heidihealth.com/legal/terms-of-service) describe when De-identified Information from their Content may be used to develop, train, test and improve our models, products and services, including for research, quality assurance and safety testing. Before any such use, information that identifies you, your organisation or any Patient is removed. We commit not to attempt to re-identify De-identified Information, and we require anyone we share it with to make the same commitment. The free-plan permission applies only to Content from free-plan use on or after the date that permission validly takes effect for you under the applicable Terms of Service. Publication of this Policy does not itself authorise a new use or override a stricter restriction in your applicable agreement.

Safety. Content you submit as feedback, and content flagged by our safety systems, may be reviewed by our team and used to improve the safety of the Platform. This does not permit model training or other use prohibited by your applicable agreement or plan.

8.3. Automated decisions

We do not make decisions based solely on automated processing that produce legal or similarly significant effects on you. Clinical documentation is always subject to Practitioner review and approval. Computer programs do assist us in making some decisions — including detecting misuse of the Platform, verifying Practitioner credentials, determining eligibility for features or sponsored content, and summarising job applications. The kinds of Personal Information used in these programs are account, professional and verification, usage and device information. Where an automated outcome significantly affects you, a human reviews it. Where the law gives you the right, you can ask us to review an automated outcome or express your point of view (see sections 16 and 20).

9. Sponsored content and advertising

We may show clearly labelled sponsored content to users of our free offering in the United States. Here is how it works:

9.1. Selection happens inside Heidi. Sponsored content is selected within our Platform using topic segments derived from how our free offering is used, in de-identified, segment-level form. We do not use third-party advertising networks to select sponsored content in the Platform.

9.2. Your information does not go to sponsors. We never provide sponsors or advertising platforms with your identity, your queries, your notes or transcripts, or any Health Information. Sponsors receive only aggregate, de-identified reporting — for example, the total number of views of their content by specialty.

9.3. Verification. We use professional and verification information (such as NPI status and specialty) to determine eligibility for our free offering and for sponsored content.

9.4. Limits. We do not use consumer health data to select sponsored content for you without your consent where the law requires consent, we do not use sensitive information to target advertising where the law prohibits it, and we do not direct targeted advertising at anyone we know to be a minor.

Your choices in relation to advertising, cookies and similar technologies are described in section 13 and, for United States residents, in section 20 (including the “Your Privacy Choices” link in the footer of our Site).

10. Marketing communications and opting out

We may send you direct marketing communications and information about our services or products, by email or other channels, in accordance with Privacy Laws. You can opt out at any time using the unsubscribe facility in the relevant message or by contacting us (see section 2). We may also market our services generally, including via social media, advertising through our Site and other digital or non-digital platforms.

Without your consent, we will not:

10.1 use your Health Information to send you marketing communications, or to decide what marketing or advertising you see; or

10.2 disclose your Health Information, or the content of your consultations, notes, transcripts or queries, to any third party for that party’s own marketing purposes.

11. Where your information is stored and how it moves

We store your information in regional hosting environments. Depending on your region, information is currently stored in Australia, the United States, the United Kingdom, the European Union (Germany and Ireland), Canada or Switzerland; where we support additional regions, we list the applicable locations in our Trust Centre. We keep a current description of our hosting locations in our Trust Centre at trust.heidihealth.com and update it as our hosting footprint changes.

Some functionality relies on service providers and subprocessors that may process information in a different region — for example, third-party services that support particular features. The current list of our subprocessors, including their roles and locations, is available in our Trust Centre.

Where information moves across borders, we ensure that:

11.1. data processing agreements are in place, contractually binding the provider to applicable data protection standards and restricting any unauthorised use or disclosure of your Personal Information; and

11.2. applicable cross-border transfer requirements are met, including reliance on a recognised transfer mechanism — such as standard contractual clauses (including the UK Addendum or International Data Transfer Agreement, where applicable) or an adequacy decision.

Region-specific storage and transfer terms are set out in section 20.

12. Who do we share your information with?

Subject to Privacy Laws and the applicable agreement, we may share your Personal Information with the following recipients:

12.1. our employees and related companies;

12.2. third-party suppliers, service providers and subprocessors (including providers for the operation of our Platform, Site and business — see our Trust Centre for the current subprocessor list);

12.3. professional advisers, dealers and agents;

12.4. payment systems operators (for example, merchants receiving card payments);

12.5. advertising, retargeting, analytics and measurement providers, in relation to your use of our Site and our marketing channels only (see section 13);

12.6. sponsors of sponsored content — aggregate, de-identified reporting only, as described in section 9;

12.7. providers of systems and accounts you have connected, where we send information at your direction;

12.8. people you nominate to receive your information, including family members and carers, other specific third parties you authorise, and other parties involved in the delivery of healthcare services;

12.9. anyone to whom our assets or businesses (or any part of them) are transferred; and

12.10. other persons, including government agencies, regulatory bodies and law enforcement agencies, as required, authorised or permitted by law.

Where you ask us to share your information with someone you nominate, we share it as you direct. Once they have received your information, we cannot control how they use it or who else they share it with.

13. Cookies and similar technologies

We use cookies and similar technologies, including pixels, tags and SDKs, in three categories: essential (needed to operate the Site and keep it secure), analytics, and advertising.

We use essential technologies at all times. For analytics and advertising technologies, we ask for your consent before using them where the law requires consent, and we give you the ability to opt out where the law gives you that right instead. You can set and change your choices at any time using our cookie preferences tool, and doing so will not affect your access to the Platform.

Some of these technologies are operated by third parties, including social media and advertising platforms, and may share information with them. In some places, using advertising technologies in this way is treated as “sharing”, “selling” or “targeted advertising” under Privacy Laws.

A current list of the cookies and similar technologies we use, who operates them, what they are used for and how long they last is available in our cookie preferences tool on our Site. Where these technologies involve transfers of information outside your region, we rely on a recognised transfer mechanism as described in section 11.

We do not deploy third-party advertising or analytics technologies within the clinical areas of the Platform, and we do not transmit Health Information, consultation content, notes, transcripts or queries to advertising or analytics providers.

14. How do we protect your information?

We hold Personal Information in electronic databases, our Site and our Platform. Our systems are built with physical, technical and organisational safeguards designed to protect your information from misuse, interference and loss, and from unauthorised access, modification or disclosure. These include encryption of data in transit and at rest, strict access controls, secure storage and handling practices, continuous monitoring, independent security testing, and regular training for our staff on keeping your information safe.

Heidi maintains ISO/IEC 27001:2022, ISO/IEC 42001 and Cyber Essentials Plus certifications and a SOC 2 Type II attestation. Current certificates, the SOC 2 report and related security documentation are available via our Trust Centre at trust.heidihealth.com.

15. How long do we keep your information?

We keep Personal Information only as long as needed for the purposes described in this Policy, as configured by you or your organisation, or as required by law. Retention is also subject to the applicable agreement.

These retention criteria also apply to information from connected systems, task instructions and action records, screen captures, access tokens or credentials, and preferences and memory. The period for which we keep that information depends on the purpose for which it is held and any applicable contractual requirements and retention settings. Disconnecting a system or turning off a feature does not by itself mean that all previously collected information has been deleted; applicable retention settings and deletion instructions continue to apply. Current retention practices:

InformationRetention
Clinical session data (transcripts, notes) — organisation customersAs configured or instructed by your organisation. Where auto-deletion is enabled, sessions and transcripts are deleted after the configured period (between 1 and 90 days); otherwise they are retained until deleted.
Clinical session data — individual subscribersAs configured by you, or until you delete it.
Other patient information held in the PlatformAs configured (between 30 and 365 days) or until deleted.
AudioAudio is used to create your transcript and is deleted as soon as processing is complete, unless you enable a feature that saves recordings.
Queries and assistant chats (e.g. Evidence, Ask Heidi)Retained so you can return to them, subject to the applicable agreement, available retention settings and deletion requests. A separate chat, or information copied into it, may remain after its source session is deleted; chat retention and deletion apply to those copies.
Account informationFor the life of your account and up to 12 months after closure.
Security and audit logsAt least 12 months.
Recruitment informationUp to 24 months after the recruitment process ends, unless you ask us to keep your application on file.
Marketing informationUntil you opt out or ask us to delete it.

Deletion from active systems and deletion from backups may occur at different times. Backup and archival copies remain protected and are deleted under the applicable backup retention schedule and any period required by your agreement or Privacy Laws; they are not retained for ordinary ongoing use. Where a backup is restored, applicable deletion instructions continue to apply. We may retain information for longer only where permitted by the applicable agreement and Privacy Laws, including where required by law or necessary to resolve disputes or enforce our agreements.

16. Your rights

You have rights in relation to your Personal Information. Depending on where you live (see section 20), these include the right to:

16.1. Access — request a copy of your information, including, where the law provides, information about how automated systems have been used;

16.2. Correct — ask us to correct or update your information;

16.3. Delete — ask us to delete your account and the information held in it, subject to information we are required or permitted by law to keep;

16.4. Port — receive certain information in a structured, commonly used, machine-readable format, or have it transmitted to another organisation;

16.5. Restrict or object — restrict or object to certain processing, including direct marketing;

16.6. Withdraw consent — withdraw consent at any time, where processing is based on consent;

16.7. Opt out — opt out of any “sale” or “sharing” of Personal Information or targeted advertising, where those rights apply (see sections 13 and 20); and

16.8. Complain — raise a concern or complaint with us, and with your privacy regulator.

To exercise any right, contact us at compliance@heidihealth.com (or use the mechanisms described in section 20). Please include your name and contact details and describe your request. We may need to verify your identity to protect your information. We aim to respond within 30 days or any shorter period your local law requires; if we cannot fulfil your request, we will explain why. You may authorise an agent to act for you where the law allows. We will never discriminate against you for exercising your rights.

If you are not satisfied with our response, you may lodge a complaint with your data protection authority — the relevant regulators are listed in section 20. If you contacted us first, we will acknowledge your complaint promptly and keep you informed of its progress.

Where we hold information as a service provider for your healthcare organisation, we may refer your request to that organisation and will help it respond to you.

17. Employees, contractors and job applicants

If you are a current or former employee or contractor, we handle your Personal Information in accordance with our Employee Privacy Notice, available from our People team or on request from compliance@heidihealth.com. If you are applying for a role with us, this Policy applies to you; if you are applying in California, the applicant notice provided to you during the application process also applies.

18. Changes to this Policy

If we make a material change to this Policy, we will give you advance notice before it takes effect — through the Platform, by email, or by an alert — and we will publish the updated Policy on our Site. Where we begin using Personal Information we have already collected for a materially different purpose, we will notify you and, where the law requires it, seek your consent. A change to this Policy does not amend your governing agreement or create a new permission to use information contrary to that agreement. We encourage you to check our Site periodically so you are aware of the current version.

19. Our related companies

Heidi Health Trading Pty Ltd (ABN 84 649 783 871) is located at Level 30, 360 Elizabeth Street, Melbourne VIC 3000, Australia. You can contact us at hello@heidihealth.com, or at compliance@heidihealth.com for privacy and security matters. Our related companies include Oscer Enterprises Pty Limited (Australia), Heidi Health Ltd (United Kingdom), Heidi Health Canada Inc (Ontario, Canada) and Heidi Health Corp (Delaware, United States), together with any other related entities we establish from time to time.

We may disclose your Personal Information to our related companies, which may use it in accordance with this Policy. If you access the services of our related companies, you should also consider their privacy documentation where it differs from this Policy.

20. Region-specific terms

These terms apply to individuals located in the region named. Where they are inconsistent with sections 1 to 19 of this Policy, these region-specific terms prevail to the extent of the inconsistency.

20.1. Australia

The Privacy Act 1988 (Cth) and the Australian Privacy Principles apply to our handling of your information, together with applicable state and territory health records laws. We are likely to disclose Personal Information to overseas recipients — the countries where information is stored are listed in section 11, and the locations of our subprocessors are listed in our Trust Centre. We will not use or disclose your Health Information for direct marketing without your consent, and you can opt out of direct marketing at any time (see section 10). Section 8.3 describes the kinds of Personal Information used in, and the kinds of decisions made or substantially assisted by, computer programs. A statement of our health information management practices is available on request. If you are not satisfied with our response to a complaint, you may complain to the Office of the Australian Information Commissioner (oaic.gov.au).

20.2. New Zealand

The Privacy Act 2020 applies to our handling of your information, and the Health Information Privacy Code 2020 applies to Health Information. Information about New Zealand users is stored on servers located in Australia, held by providers acting as our agents under contracts requiring comparable safeguards. Where we collect your information from someone other than you (for example, from your Practitioner or a system you connect), this Policy is how we make the required information available to you. You may complain to the Office of the Privacy Commissioner (privacy.org.nz).

20.3. United States

HIPAA. Where we act as a business associate of a healthcare provider, our use and disclosure of protected health information is governed by our business associate agreement with that provider and by HIPAA; the provider’s Notice of Privacy Practices applies to your treatment records, and requests about them should go to your provider.

State privacy laws. If you live in California or another state with a comprehensive privacy law, you have rights to know, access, correct, delete and port your Personal Information; to opt out of “sale”, “sharing” and targeted advertising; to limit the use of sensitive personal information; and to appeal a refusal. Section 5 describes the categories of Personal Information we collect (including sensitive information such as Health Information), section 6 the sources, section 7 the purposes, section 12 the categories of recipients, and section 15 the retention criteria for each category. We honour opt-out preference signals, including Global Privacy Control, as a valid opt-out of sale/sharing. To exercise rights, use the “Your Privacy Choices” link in the footer of our Site or email compliance@heidihealth.com. We do not sell Personal Information for money. Our use of advertising cookies and similar technologies on our Site may be treated as a “sale”, “sharing” or “targeted advertising” under some state laws — you can opt out at any time using the “Your Privacy Choices” link, our cookie preferences tool, or an opt-out preference signal such as Global Privacy Control. We do not knowingly sell or share the Personal Information of consumers under 16. Where you have a right to appeal our decision on a privacy request, you may submit your appeal to compliance@heidihealth.com. We will review the appeal and respond within the period required by the applicable law. Section 9 explains sponsored content shown to users of our free offering in the United States; sections 10 and 13 explain the related marketing and privacy choices.

Consumer health data. If you are a Washington or Nevada resident, our Consumer Health Data Privacy Policy, at https://www.heidihealth.com/legal/consumer-health-data-privacy-notice, describes how we handle consumer health data and the rights you have.

20.4. Canada

PIPEDA and applicable provincial privacy and health privacy legislation apply to our handling of your information. Our Privacy Officer is Yassin Omar (yassin@heidihealth.com). Where we handle Patient information for a clinic or hospital, we do so as its service provider (for example, as an agent or electronic service provider under Ontario’s PHIPA, or an information manager under Alberta’s Health Information Act), on its instructions. Information about Canadian users is stored in Canada (AWS Canada Central, Montréal); our subprocessors and their locations are listed in our Trust Centre.

Québec. If you are in Québec, the Act respecting the protection of personal information in the private sector applies. The person in charge of the protection of personal information is Yassin Omar (yassin@heidihealth.com). Your information may be communicated outside Québec, including to the jurisdictions listed in section 11; before any such communication we assess the protection the information will receive. Technologies that allow you to be identified, located or profiled are activated only by your choice (see section 13). Section 8.3 describes automated processing; if a decision were ever based exclusively on automated processing, we would inform you and you may present observations to a member of our team. You also have rights to portability and to request de-indexation in accordance with the Act.

20.5. European Economic Area

The EU GDPR applies to our handling of your information. The controller for the processing described in this Policy (where we act in our own right) is Heidi Health Trading Pty Ltd. Our legal bases are: performance of a contract (providing the Platform and services you request); our legitimate interests (securing and improving our services, preventing misuse, verifying professional status, and marketing to business contacts — details of our balancing assessments are available on request); consent (where we ask for it, including for non-essential cookies — you may withdraw it at any time); and compliance with legal obligations. Where we process special category data (such as health data) in our own right, we rely on your explicit consent or on the provision of health care under the responsibility of a professional subject to secrecy obligations. Where we collect information about you from someone other than you, section 6 describes the sources. You may request information about the safeguards we rely on when your Personal Information is transferred outside the European Economic Area. You may lodge a complaint with the supervisory authority in your member state of residence, workplace or the place of an alleged infringement (edpb.europa.eu/about-edpb/about-edpb/members_en).

20.6. United Kingdom

The UK GDPR and the Data Protection Act 2018 apply to our handling of your information. The legal bases in section 20.5 apply equally under the UK GDPR. You may request information about the safeguards we rely on when your Personal Information is transferred outside the United Kingdom. We have a UK establishment, Heidi Health Ltd (registered in England and Wales, company number 15878893). If you make a privacy complaint to us, we will acknowledge it within 30 days and keep you informed of its progress. You may also complain to the Information Commissioner’s Office (ico.org.uk / 0303 123 1113).

20.7. Switzerland

The Swiss Federal Act on Data Protection applies to our handling of your information. Your Personal Information may be disclosed to recipients in the countries listed in section 11 and in the locations shown in our Trust Centre subprocessor list, protected by an adequacy decision of the Federal Council or by standard contractual clauses adapted for Switzerland. You may complain to the Federal Data Protection and Information Commissioner (edoeb.admin.ch).

20.8. Singapore

The Personal Data Protection Act 2012 applies to our handling of your information. Our Data Protection Officer is Yassin Omar, contactable at compliance@heidihealth.com. Where your information is transferred outside Singapore, we ensure the recipient is bound to provide a standard of protection comparable to the PDPA.

20.9. Hong Kong

The Personal Data (Privacy) Ordinance applies to our handling of your information. We will only use your Personal Information for direct marketing with your consent, which you may withdraw at any time free of charge; the kind

s of information used and the classes of services marketed are described in sections 5, 9 and 10. Requests for access to or correction of your information may be made to our Privacy Officer at compliance@heidihealth.com or by post to the address in section 19.

20.10. South Africa

The Protection of Personal Information Act (POPIA) applies to our handling of your information. Your information is transferred to and stored in the European Union, in compliance with POPIA. Our Information Officer is John Stanley Giles (john@michalsons.com).

20.11. Other regions

If you are in a region not listed above, we handle your information in accordance with this Policy and the Privacy Laws that apply to you, and you can exercise the rights in section 16 by contacting us. As we launch in new regions, we publish any additional region-specific terms or local-language notices required by local law.