Privacy & Data Handling Policy

Effective date: 8 September 2026

This Policy explains how No Sick Days Pty Ltd (ABN 35 697 254 452) ("NSD", "we", "us") collects, holds, uses, discloses and protects personal information — including personal information handled on behalf of our healthcare-practice clients — in the course of providing Aiden, our AI voice receptionist and appointment-booking platform. This Policy applies to callers, patients, and practice staff, and to any integration between NSD and third-party practice management systems, including Best Practice (Bp Premier).

1. About No Sick Days and Aiden

NSD provides an AI voice agent ("Aiden") that answers inbound calls for small and medium healthcare and allied-health practices, qualifies the caller's request, and books, reschedules or cancels appointments on the practice's behalf. NSD acts as a service provider (data processor) to each practice client; the practice itself remains the primary point of contact for, and controller of, its patients' personal information. Where NSD integrates with a practice's existing practice management software, NSD only accesses the data objects necessary to check availability and create, amend or cancel appointments, as agreed with the practice and, where applicable, the software vendor.

2. Legislative Framework

  • Privacy Act 1988 (Cth) and the 13 Australian Privacy Principles (APPs)
  • The Notifiable Data Breaches (NDB) scheme under Part IIIC of the Privacy Act
  • Where applicable, relevant state and territory health records legislation governing the practice client's own patient records

NSD does not hold itself out as a covered entity for the My Health Records Act 2012 (Cth) and does not connect to the My Health Record system as part of the current Aiden product.

3. Information We Collect

The categories of personal information collected through Aiden are limited to what is required to identify a caller and manage their appointment:

  • Caller identification: name, phone number, and business name (if calling on behalf of a business), provided verbally during the call.
  • Appointment details: requested service, preferred day/time, confirmed booking time.
  • Contact details: email address and mobile number, for confirmations and reminders.
  • Call metadata: duration, timestamp, outcome, and cost, generated automatically by the telephony platform.
  • Call recordings and transcripts: generated automatically for quality, dispute-resolution and service-improvement purposes.
  • Health information (limited): the stated reason for an appointment, only where the caller volunteers it (e.g. "a check-up"), not solicited beyond what is needed to book correctly.

NSD does not request Medicare numbers, health identifiers, clinical history, or Medicare/DVA information through Aiden.

4. How We Use Your Information

  • Verifying the caller and matching them to an existing patient/contact record, where one exists
  • Checking appointment availability and creating, amending or cancelling bookings on the practice's behalf
  • Sending appointment confirmations and reminders by email or SMS
  • Quality assurance, dispute resolution and improving Aiden's conversational accuracy
  • Billing the practice client for NSD's services
  • Meeting NSD's own legal and regulatory obligations

NSD does not use caller personal information for direct marketing to callers, and does not sell or trade personal information to third parties.

5. Sensitive and Health Information

Where a caller volunteers health-related information (for example, the general reason for an appointment), NSD treats this as sensitive information under APP 3 and limits its use strictly to completing the booking. NSD relies on the practice's own patient consent arrangements and its status as a service provider acting on the practice's instructions. Each practice client remains responsible for ensuring its own patients are aware that call handling is performed by an AI voice agent on the practice's behalf.

6. Disclosure and Overseas Recipients

To provide the Aiden service, personal information is disclosed to a limited number of sub-processors who provide telephony, speech-recognition, language-model and hosting infrastructure, each governed by a service agreement:

ProviderPurposeLocation
TwilioTelephony (call routing, audio streaming)United States
Deepgram / AssemblyAIReal-time speech-to-textUnited States
GroqLanguage model inferenceUnited States
Inworld AIText-to-speech voice synthesisUnited States
SupabasePrimary application databaseSingapore
Cloudflare (R2)Private storage of call recordingsGlobal CDN (private bucket)
StripeBilling of practice clientsUnited States / global
DigitalOceanApplication hostingSydney, Australia

Consistent with APP 8, NSD takes reasonable steps to ensure overseas recipients handle personal information in a manner consistent with the APPs. NSD does not disclose personal information to any party for that party's own marketing purposes.

7. Data Storage, Security and Access Controls

  • All application secrets and credentials are managed through a dedicated secrets manager rather than stored in code or configuration files
  • Data in transit is encrypted (TLS) between the caller's phone network, our telephony provider, and our backend
  • Call recordings are stored in a private, non-public storage bucket, not directly accessible over the public internet
  • Access to production systems is restricted to authorised NSD personnel only
  • Application-level audit logging records access to sensitive operations within the platform

8. Data Retention and Deletion

Personal information, call recordings and transcripts are retained only for as long as necessary to provide the service, meet legal and accounting obligations, and resolve any disputes, after which they are automatically deleted. A practice client may request earlier deletion of its callers' data at any time, and an individual may request deletion of their own personal information subject to legal record-keeping obligations.

9. Data Breach Response

NSD maintains a documented data breach response process consistent with the Notifiable Data Breaches (NDB) scheme:

  • Identification and containment: suspected breaches are contained immediately — revoking compromised credentials, isolating affected systems, and halting unauthorised access.
  • Assessment: assessed within 30 days to determine whether it is an "eligible data breach" likely to result in serious harm.
  • Notification: where eligible, the OAIC and affected individuals are notified as soon as practicable; affected practice clients are notified promptly regardless of eligibility threshold.
  • Remediation: root cause investigated and corrective measures implemented to prevent recurrence.
  • Review: procedures reviewed periodically and after any actual incident.

10. Your Rights

You may request access to, or correction of, personal information we hold about you by contacting us below, or by contacting the relevant practice directly. We will respond within a reasonable period, consistent with APPs 12 and 13. Complaints not resolved to your satisfaction may be referred to the OAIC (oaic.gov.au).

11. Division of Responsibility with Practice Clients

NSD acts as a service provider to each practice client. The practice remains responsible for its own patients' consent, its own privacy notices, and compliance with any health-records legislation specific to its jurisdiction and profession. NSD is responsible for handling the personal information it processes on the practice's behalf in accordance with this Policy and its service agreement with the practice.

12. Changes to This Policy

This Policy is reviewed periodically and updated as our product, sub-processors, or obligations change. The current version and effective date appear at the top of this page.

13. Contact Us

No Sick Days Pty Ltd

Attention: Hayden Reed

Email: hayden@nosickdays.com.au

Registered address: 37/120 Victoria Road, Gladesville, NSW, 2111

© 2026 No Sick Days Pty Ltd. All rights reserved.