Skip to content

Privacy

Privacy policy

How Clinic X collects, uses, stores and protects personal information. Last updated 30 September 2026.

1. About this policy

This policy explains how Pixel8 Digital Pty Ltd (ABN 99 617 217 839) (“Clinic X”, “we”, “us”) handles personal information when you use the Clinic X website at clinicx.com.au, the Clinic X web app, and the Clinic X apps for iPhone, iPad and Android (together, the “service”).

We handle personal information in line with the Privacy Act 1988 (Cth), including the Australian Privacy Principles, and the Notifiable Data Breaches scheme.

2. Our role and your practice’s role

Clinic X is practice-management software for general practices and medical centres. Each practice that uses Clinic X (an “organisation”) decides who is added to it, what their role is, and what is recorded about the practice’s work.

Most of the information in the service is entered by a practice and its staff, and we hold and process it on the practice’s behalf so that we can provide the service. If you are a staff member, your practice is usually the best first contact for questions about the information it keeps about you, and some requests (for example, removing you from the practice) are made by the practice.

Clinic X is not a clinical records system. It is not designed to hold patient records or clinical notes, and we ask practices not to enter them.

3. What we collect

Your account and profile. Your name, work email address, phone number, role, position title, the centres you work at, qualifications and a profile photo if you add one. If your practice chooses to record them, your date of birth (used for team birthdays) and home address.

Work you do in the service. Tasks and checklists, messages and announcements, team-feed posts, comments, photos and videos, policy acknowledgements, cleaning records, complaints, incidents, quality-improvement activities, contracts, certificates and documents you upload, and the history of changes to them.

Limited patient information. Complaint and incident forms ask only for a patient’s initials and, if known, date of birth, together with a description of what happened. Staff should not enter patients’ full names, contact details or clinical notes.

Your organisation. The practice’s name, legal name and ABN, its centres, addresses, phone numbers, opening hours, logo, and staff working patterns.

Sign-in and technical information. Records of sign-in codes being sent and used, your signed-in sessions and the name and type of each device, the push-notification token for your phone, and technical logs (such as IP addresses and the time of each request) kept by our hosting provider for security and reliability.

What we don’t collect. We don’t use advertising or third-party analytics, we don’t track you across other apps or websites, and the apps don’t access your location or contacts. The camera, photo library and microphone are used only when you choose to add a photo or video. Face ID, fingerprint and your app PIN stay on your device and are never sent to us.

4. How we collect it

  • From you, when you sign in, complete your profile or use the service.
  • From your practice, when a manager registers you, assigns you work or records information about the practice.
  • From your colleagues, when they mention or assign you in tasks, messages, complaints or incidents.
  • Automatically, from your device and browser when you use the service (see section 11).

5. How we use it

  • To provide the service: show you and your colleagues the information your roles allow, and keep a record of work, policies and cases.
  • To sign you in securely, keep your account safe and detect misuse.
  • To send you emails and notifications the service needs, such as sign-in codes, invitations, task and message alerts, and reminders.
  • To respond to support requests and to requests about your information.
  • To keep the service running, fix problems and make it better. Where we look at how the service performs, we use the least information we need.
  • To meet our legal obligations.

We don’t sell personal information, and we don’t use it for advertising.

6. Who we share it with

Within your organisation. People in your practice see information according to their role and the centres they work at. For example, managers see complaints and incidents for their centres; everyone in the organisation sees the team feed.

Our service providers, who process information for us under their own security and confidentiality obligations and only to provide their service:

  • Cloudflare: hosting, database and file storage. The database and uploaded files are stored in Cloudflare’s Oceania region; requests pass through Cloudflare’s global network.
  • Amazon Web Services: sign-in (one-time codes) and email delivery, in the Sydney region.
  • Expo, Apple and Google: delivery of push notifications to the mobile apps.
  • GitHub: encrypted-in-transit storage of database backup copies made before each update to the service.

When the law requires it, for example in response to a court order, or where needed to lessen a serious threat to someone’s life, health or safety.

If our business changes hands, to a buyer who agrees to protect the information in line with this policy.

7. Overseas disclosure

Our main data stores are in Australia and Oceania, but some service providers handle information overseas: Cloudflare’s global network may process requests in other countries, push notifications are delivered through Expo, Apple and Google (mainly in the United States), and database backup copies are stored by GitHub in the United States. We choose providers with strong security practices and take reasonable steps to ensure they handle the information consistently with the Australian Privacy Principles.

8. How we protect it

  • All connections use encryption in transit (HTTPS).
  • Every record belongs to one organisation, and only that organisation’s staff can see it, within the limits of their role and centres.
  • There are no passwords to leak: you sign in with a one-time code sent to your work email.
  • Sessions end after 30 days without use, and after 90 days at most. You can see your signed-in devices and sign any of them out from your profile in the app.
  • The mobile apps lock themselves when in the background and need Face ID, fingerprint or your PIN to reopen.

If a data breach is likely to cause serious harm, we will notify the affected practices, the people involved and the Office of the Australian Information Commissioner as the Notifiable Data Breaches scheme requires.

9. How long we keep it

We keep an organisation’s information for as long as it uses Clinic X, because policies, complaints, incidents and similar records are kept as a history the practice relies on. When someone leaves a practice, their account is deactivated at the practice’s request; the records they took part in stay with the practice.

When an organisation stops using Clinic X or asks us to delete its account, we delete its information within 90 days, except where the law requires us to keep it. Backup copies are deleted automatically within 90 days of being made. Sign-in codes expire within minutes.

10. Access, correction and deletion

You can view and update much of your own profile in the app. To ask for a copy of the personal information we hold about you, to have it corrected, or to have your account deleted, contact your practice or email us at privacy@clinicx.com.au. We will confirm who you are, respond within 30 days, and tell you if there is a lawful reason we can’t do what you ask (for example, a record the practice must keep).

A practice owner can ask us to delete the whole organisation and everything in it.

11. Cookies and data on your device

The website uses only the cookies it needs to work: a secure, HttpOnly cookie that keeps you signed in, and a short-lived cookie used while you create a new organisation. We don’t use advertising or analytics cookies.

The mobile apps keep your session in your device’s secure storage, along with a protected copy of your app PIN, and may keep copies of documents you open. Signing out removes them from the device.

12. Children

Clinic X is a workplace service for adults. It isn’t intended for anyone under 18, and we don’t knowingly collect their information except as limited patient details in complaints and incidents recorded by a practice.

13. Questions and complaints

If you have a question about privacy, or think we have mishandled your personal information, contact our privacy officer at privacy@clinicx.com.au. We will acknowledge your complaint within 7 days and aim to resolve it within 30 days.

If you’re not satisfied with our response, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au or on 1300 363 992.

14. Changes to this policy

We may update this policy as the service changes. We will show the date of the latest version at the top of this page and let practice owners know about significant changes before they take effect.