Privacy Policy

Effective: 22 June 2026 · Last reviewed: 22 June 2026

Boucher Advisory Group Pty Ltd (ABN 36 685 315 477) (“we”, “us”, “our”) operates the Indicator Pro platform (“Indicator Pro” or the “Service”), which provides aged-care providers with AI-assisted analysis of de-identified clinical progress notes.

We take privacy seriously, especially the health information that flows through the Service. This policy explains what we collect, why, and what choices you have. It is written to comply with the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs), the Notifiable Data Breaches scheme, and (where applicable) state-based health-records legislation.

1. Who this policy applies to

  • Provider organisations (our customers — e.g. residential aged-care or home-care operators).
  • Provider staff (registered nurses, care managers, administrators) who log in to the Service.
  • Care recipients (residents, home-care clients) whose progress notes are uploaded.
  • Visitors to our marketing website.

If you are a care recipient, your provider — not us — is the entity that has primary responsibility for your personal information under the Privacy Act. We process the information on the provider’s behalf as a service provider. The provider’s own privacy policy applies first; ours describes how we handle it once it reaches us.

2. The kinds of personal information we collect

2.1 Information about provider staff users

When a member of provider staff signs up or is invited:

  • Full name
  • Work email address
  • Role within the organisation
  • Authentication identifiers (managed via Clerk — see § 6)
  • Activity logs: which features were used, when, from which IP

2.2 Information about care recipients (sensitive — health information)

Provider staff upload progress notes, which can contain:

  • Care recipient name (referred to as a “client identifier”)
  • Note text (free-text clinical observations)
  • Outcome / Action / Comment fields
  • Date of the care event

We treat all of the above as sensitive informationunder s.6 of the Privacy Act because it concerns a person’s health.

2.3 Information we infer

The categoriser AI generates classifications, confidence scores, and a prompt-version stamp for each note. These derived rows are stored against the original note.

2.4 Information we do not collect

We do not ask for or deliberately collect:

  • Banking, credit-card, or financial information about care recipients.
  • Government identifiers (Medicare numbers, tax file numbers, immigration status).
  • Real-time location data, device identifiers, or biometrics.

Progress notes are free text, so a government identifier could appear in a note even though we never request one. Where that happens, the note is stored in Australia and the identifier is redacted before the note is sent to any AI processor (see § 4).

3. How we collect personal information

  • Directly from provider staff when they sign up, invite colleagues, or upload files.
  • From the provider’s own systems when they upload CSV / Excel / PDF exports of progress notes.
  • From browser metadata — IP address, session timestamps — used only to operate the Service securely.

We do not buy or rent personal information from third parties.

4. How we use personal information

4.1 Primary purposes

  • Categorise and analyse progress notes to produce clinical-indicator dashboards and board-pack reports.
  • Authenticate staff and authorise access to the correct provider’s data.
  • Operate, maintain, and improve the Service.

4.2 De-identification before AI processing

Before any progress-note text is sent to an AI processor, we run an automated de-identification pass that replaces:

  • The care recipient’s name (and common honorific + surname variants)
  • Any other care recipient name from the same upload batch
  • Phone numbers (mobile, landline, +61 forms)
  • Email addresses
  • Medicare card numbers
  • Dates of birth
  • Street addresses with an Australian postcode

These tokens are replaced with placeholders such as [CLIENT], [PHONE], [EMAIL] so the clinical content remains intact for analysis but the personal identifiers do not leave Australia.

Our de-identification targets care-recipient identifiers — each name is expanded to its honorific, surname, and common shortened or nickname forms so abbreviated references are caught — together with the contact details and government numbers most likely to identify a person. As with any automated de-identification, it reduces rather than wholly eliminates the chance that an identifier remains in free text, which is why all note content stays within the secured Australian environment described in this policy.

4.3 We do not use personal information for AI model training

We run AI inference through AWS Bedrock, which does not store the inputs or outputs of our requests and does not use them to train any model. Your data is not used to train any AI model.

4.4 Automated processing and human oversight

Indicator Pro uses AI to read each progress note and assign it to clinical-indicator categories with a confidence score. This is automated processing, but it is designed to keep a human in control:

  • The output is aggregate clinical-indicator reporting for a provider’s management and board. It is not a decision about any individual’s care, treatment, funding, or entitlements.
  • Classifications are designed to be reviewed by a registered nurse, who can correct any of them. Corrections are recorded as new entries — the original AI classification is never overwritten — so the review history is fully auditable.
  • No decision that legally or significantly affects an individual is made solely by automated means.

If you have questions about how the automated categorisation works, you can contact us using the details in section 13.

5. Sensitive information and consent

The Privacy Act requires express consent before collecting sensitive information, with limited exceptions including the provision of a health service. We rely on the provider’s consent and lawful basis for collecting progress notes from their care recipients. The provider warrants under our Data Processing Agreement that they have obtained any necessary consent before uploading notes to Indicator Pro.

If you are a care recipient and would like to know whether your information is being processed by us, contact your provider first. If they direct you to us, we will work with them to respond within 30 days.

6. Disclosure to third parties (sub-processors)

We engage the following sub-processors. The list below, with location and purpose, is current as at 22 June 2026 and is updated whenever a sub-processor is added or changed.

Sub-processorPurposeRegionTouches PHI?
Amazon Web Services — Bedrock + EC2 + S3AI inference, compute, storageap-southeast-2 (Sydney)Yes — de-identified only
Anthropic (via AWS Bedrock)Claude AI modelSydney via Bedrock au.* profileYes — de-identified only
SupabaseManaged Postgres databaseap-southeast-2 (Sydney)Yes
VercelApplication hosting (functions in Sydney syd1)Sydney runtime; build pipeline US-EastNo PHI in build pipeline
ClerkAuthentication / user managementUnited StatesNo PHI — only staff identifiers
InngestWorkflow orchestrationUnited StatesNo — engineered so PHI never leaves AU
SentryError monitoringUnited StatesNo — note text redacted before logs ship

We bind every sub-processor by contract to:

  • Process the data only for the purpose we engage them for.
  • Implement security measures appropriate to the sensitivity.
  • Notify us of any security incident within 24 hours of discovery.

6.1 Business transfers

If our business, or assets that include personal information, is sold, merged, or reorganised, that information may be disclosed to the acquiring or successor entity. We will require the successor to handle it under this policy or a materially equivalent one, and we will notify affected customer organisations.

7. Cross-border disclosure (APP 8)

All progress-note text and care-recipient health information is processed within Australia. Specifically:

  • Progress notes are stored in Sydney (ap-southeast-2).
  • AI inference runs on the AWS Bedrock au.* inference profile, which keeps inference traffic within Australia.
  • Application functions execute in Vercel’s Sydney region (syd1).
  • Workflow orchestration metadata sent to Inngest (United States) does not include note content; it consists of internal record IDs only.

Authentication identifiers (Clerk) for provider staff are stored in the United States. We disclose this in our customer agreements. By signing up, provider staff consent under APP 8.2(b) to this overseas storage of their own user-account information; care-recipient health information is never sent to those services.

If a sub-processor adds an Australian region (Clerk has indicated this is on their roadmap), we will migrate as part of our normal vendor review.

8. How long we keep personal information

CategoryRetention
Progress notes + classificationsFor the lifetime of the customer’s account; deleted within 30 days of contract termination.
Audit logs of AI calls (ai_call_log)7 years to support clinical-decision review. Hashed payloads only; no PHI text.
Staff authentication identifiersLifetime of the user’s account; 30 days after deactivation.
Marketing-site analyticsUp to 26 months (Google Analytics 4 default), where website analytics are enabled.
Backups (Supabase)7 days, encrypted at rest.

We delete or de-identify personal information when the retention period ends, except where we are required by law to retain it (e.g. tax records, Aged Care Quality and Safety Commission audits).

9. Your rights

You can ask us to:

  • Access the personal information we hold about you.
  • Correct anything that is inaccurate.
  • Complain if you think we have breached the APPs.
  • Erase your account and any personal information not subject to a legal retention obligation.

Email our Privacy Officer at Info@boucheradvisorygroup.com.au. We will respond within 30 days.

If you are unhappy with our response, you can complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au or 1300 363 992.

10. How we keep personal information secure

  • All data is encrypted in transit (TLS 1.2+) and at rest (AES-256, AWS-managed keys).
  • Access to production data requires authenticated sign-in with multi-factor authentication and is limited to the small number of authorised Boucher Advisory Group operators.
  • Strict tenant isolation ensures each provider organisation can access only its own data.
  • AI processing is logged so that any classification can be audited, and progress-note text is kept out of our operational and error-monitoring logs.
  • Credentials are held in an encrypted secrets store, never in source code, and we conduct a security review of changes before they ship.

A more detailed security overview is available to prospective and current customers on request.

Under the Notifiable Data Breaches scheme, if we suspect a breach likely to result in serious harm we assess it within 30 days and, where the scheme requires it, notify the affected individuals and the OAIC as soon as practicable.

11. Children

Indicator Pro is a B2B service for aged-care providers. We do not knowingly market to or collect information from anyone under 18.

12. Changes to this policy

We will post a new effective date at the top of this document when we change it. Material changes will be notified by email to the primary contact at each customer organisation.

13. Contact

Privacy Officer: Jordy Fung

Privacy queries: Info@boucheradvisorygroup.com.au

Postal: Boucher Advisory Group Pty Ltd, 20 Ullora Rd, Nelson Bay NSW 2315

Office of the Australian Information Commissioner: oaic.gov.au / 1300 363 992