Cardiac Helth
  • Home
  • Product
  • How It Works
  • Mobile App
  • Contact
Login

Privacy Policy

Who we are

Cardiac Health Pty Ltd (“Cardiac Health”, “we”, “us”, “our”) provides a cardiac imaging and reporting platform used by clinicians, cardiology practices and hospitals, together with this website and our mobile app.

We are bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles. This policy explains what personal information we collect, why we collect it, who we share it with, how we protect it, and how you can access it, correct it or make a complaint.

This policy applies to our website, our platform and our mobile app. It does not apply to third-party websites we link to, which have their own privacy policies.

The information we collect

The information we collect depends on how you interact with us.

If you browse our website, we collect your IP address, browser type and version, device and operating system, the pages you view, the time and duration of your visit, and the website that referred you to us.

If you contact us or request a demo, we collect the details you provide — typically your name, email address, phone number, organisation, role, and anything you write in a message field.

If you hold an account on our platform, we collect your name, work email address, phone number, professional role, employer or practice, your login credentials, your user permissions, and a record of your activity, including the reports you create, edit, assign or finalise, and the date and time of each action.

If you use our mobile app, we collect the app version in use, so that we can support it and prompt you to update.

Clinical information. Our platform stores and displays cardiac imaging studies and related clinical records, which may include patient names and identifiers, dates of birth, sex, referring clinician details, imaging data, measurements, clinical findings and diagnostic reports.

If your organisation is a customer, we hold contact details for authorised and billing contacts, along with invoice and payment records. We do not accept card payments and we do not hold payment card details at all; customers are invoiced and pay by bank transfer.

Health information

Health information is “sensitive information” under the Privacy Act and is given a higher level of protection than other personal information. We handle it accordingly.

Where a healthcare provider uses our platform, that provider holds the relationship with the patient and decides what patient information is entered into the platform and for what purpose. Cardiac Health handles that information on the provider’s behalf, under our agreement with them, and only for the purposes described in this policy.

If you are a patient and you want to know what information is held about you, or you want it corrected, please contact your treating clinician or healthcare provider first, as they hold the record. They can raise the request with us on your behalf. You may also contact us directly and we will work with your provider to respond.

We do not collect health information without consent, except where the Privacy Act permits it — for example, where the collection is required or authorised by Australian law, or where it is necessary to lessen or prevent a serious threat to a person’s life, health or safety.

How we collect information

We collect information:

  • directly from you, when you complete a form, email or call us, create an account, or use our platform or app;
  • from your employer or the healthcare organisation that holds the account, when it sets up or manages its users;
  • from healthcare providers and connected clinical systems, when imaging studies, worklists or reports are transferred into the platform;
  • from connected imaging devices, where your organisation has configured an integration; and
  • automatically, through cookies and similar technologies on our website and app.

Where it is lawful and practicable, you can deal with us anonymously or under a pseudonym — for example, when making a general enquiry. This is not possible for platform accounts, because we must be able to identify who has accessed a clinical record.

Why we collect your information

We use personal information to:

  • provide, operate, maintain and support our platform, website and mobile app;
  • create and manage user accounts, and verify identity and permissions;
  • store, display and transmit imaging studies and reports between authorised clinicians;
  • maintain audit records of who accessed or changed a clinical record;
  • respond to your enquiries, demo requests and support requests;
  • investigate and resolve technical faults, security incidents and misuse of our services;
  • send you service messages, including maintenance notices, security alerts and changes that affect you;
  • send you marketing communications, where you have consented or where we are otherwise permitted to under the Spam Act 2003 (Cth);
  • meet our legal, regulatory and clinical governance obligations; and
  • invoice our customers and manage our commercial relationships.

We do not sell personal information, and we do not disclose it to third parties for their own marketing purposes.

Cookies

Cookies are small text files placed on your device when you visit a website. This section applies mainly to this website, which uses cookies to keep the site working, to remember your preferences, and where you submit a form.

  • Essential cookies keep the site working and help protect against automated and fraudulent form submissions. Our website will not work properly without them.
  • Preference cookies remember choices such as your display settings.

We do not currently use third-party advertising cookies, and we do not use cookies to track you across other websites. If we introduce analytics or other non-essential cookies, we will update this policy first.

Our clinical platform does not rely on cookies to keep you signed in. Instead, it stores a session token and a small amount of related information in your browser’s local storage on the device you sign in from. That information is needed for the platform to work, is cleared when you sign out, and is not readable by other websites.

You can block or delete cookies, and clear local storage, through your browser settings. If you do, parts of our website and platform will not work and you will need to sign in again.

Embedded content from other websites

Pages on our website may include embedded content such as videos, maps or forms hosted by other providers. Embedded content behaves as though you had visited that provider’s website directly: the provider may collect data about you, set its own cookies, and monitor your interaction with that content, including if you have an account and are signed in with them.

We do not control these providers, and we recommend you review the privacy policy of any third party whose content is embedded on our pages.

Who we share your information with

We disclose personal information only where it is necessary, and only to:

  • your own organisation — administrators at your practice or hospital can see account details and audit records for users in their organisation;
  • authorised clinicians — imaging studies and reports are shared with the clinicians and referrers your organisation has authorised to receive them;
  • our service providers — including cloud hosting, email delivery, bot and abuse protection on our sign-in and contact forms, monitoring and customer support providers, who may access personal information only to perform services for us, under written terms consistent with this policy, and not for their own purposes;
  • connected clinical systems — where your organisation has configured an integration, we transmit worklists and finalised reports to practice management, clinical information and EHR/EMR systems;
  • our professional advisers, such as our lawyers, auditors and insurers;
  • regulators, courts and law enforcement, where we are required or authorised by law to disclose; and
  • a purchaser, if we sell or transfer all or part of our business, on the condition that the purchaser handles the information consistently with this policy.

Where your information is stored

Personal information and clinical data are held on secure servers operated by our cloud hosting providers.

Some of our service providers may store or process information outside Australia. Before disclosing personal information overseas, we take reasonable steps to ensure the recipient handles it in a way consistent with the Australian Privacy Principles, including through contractual protections.

If you would like to know where information relating to you or your organisation is stored, contact us and we will tell you.

How we protect your information

We take reasonable steps to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure. These steps include:

  • encryption of data in transit between your browser or device and our services, using HTTPS;
  • hosting within a private, firewalled network, with encryption at rest applied where our hosting provider supports it;
  • role-based access controls, so that users can see only what their role requires;
  • account authentication, including emailed verification codes for sign-in where we have enabled them;
  • audit logging of changes to clinical records — including who created, edited, reassigned, finalised or deleted a report, and when — and, in our referrer portal, logging of each report a referrer opens, downloads or views images for;
  • network security controls and ongoing monitoring;
  • confidentiality obligations and privacy training for our staff; and
  • documented backup, business continuity and incident response procedures.

No system can be guaranteed completely secure. If you believe your account has been compromised, contact us immediately.

How long we keep your information

We keep personal information only for as long as we need it for the purposes described in this policy, or for as long as the law requires us to keep it.

Clinical records and imaging studies are retained for the period agreed with the relevant healthcare organisation and in line with the health records retention laws applying in the relevant state or territory. Because these laws generally require health records to be kept for many years, we do not delete clinical data simply because it is old.

When a subscription ends, we make the organisation’s data available for export, and we then withdraw access to it and remove it on the organisation’s written instruction, subject to any retention period the organisation is itself required by law to observe. Removal is carried out as a manual, requested process, and copies may persist in our backups until those backups expire on their normal cycle.

Financial records are retained for at least seven years, as required by Australian tax law.

When we no longer need information and are not required to retain it, we destroy it. Where we retain information for statistical or service-improvement purposes, we do so in aggregate form that does not identify an individual.

Accessing and correcting your information

You may ask us for access to the personal information we hold about you, and you may ask us to correct it if it is inaccurate, out of date, incomplete, irrelevant or misleading.

To make a request, contact us using the details at the end of this policy. We will need to verify your identity, and we will respond within 30 days. If we refuse access or a correction, we will explain why in writing and tell you how to complain.

We do not charge for making a request. We may charge a reasonable fee to cover the cost of retrieving and supplying extensive information, and we will tell you before we do.

If you are a patient, requests for your clinical records are usually best directed to your treating clinician or healthcare provider, who holds the record.

Data breaches

We maintain a data breach response plan. If we become aware of a data breach that is likely to result in serious harm, we will contain and assess it, and notify affected individuals and the Office of the Australian Information Commissioner as required under the Notifiable Data Breaches scheme.

Where a breach affects information we hold on behalf of a healthcare organisation, we will notify that organisation without undue delay and support it in meeting its own notification obligations.

Marketing

If you have opted in, we may send you emails about our products, features and events. Every marketing email contains an unsubscribe link, and we act on unsubscribe requests promptly. You can also opt out at any time by contacting us.

We will continue to send you service messages — such as security alerts, outage notices and changes to our terms — regardless of your marketing preferences, because they are necessary to the service.

Making a complaint

If you believe we have breached the Australian Privacy Principles or mishandled your personal information, please tell us first so that we can put it right. Contact us using the details below, setting out what happened and what you would like us to do. We will acknowledge your complaint promptly and aim to resolve it within 30 days. If we need longer, we will tell you why and keep you informed.

If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner:

  • Website: oaic.gov.au
  • Phone: 1300 363 992
  • Post: GPO Box 5218, Sydney NSW 2001

Changes to this policy

We may update this policy from time to time to reflect changes to our services, our systems or the law. The current version is always available on this page, and the effective date at the top shows when it last changed. If a change materially affects how we handle your personal information, we will notify you directly or through our platform before it takes effect.

Contact us

For any privacy question, request or complaint, contact our Privacy Officer through the Contact page on this website, or by writing to Cardiac Health Pty Ltd, marked for the attention of the Privacy Officer.

Cardiac Helth

Find precision,
feel better.

Product

  • Platform Overview
  • Features
  • Mobile App

Resources

  • FAQs
  • Contact Us

Legal

  • Privacy Policy

© 2026 Cardiac Health Pty Ltd. All rights reserved.