Privacy Policy
How ClientForms collects, uses, stores, and protects your personal and health information.
1. Who We Are
ClientForms is a clinical assessment platform operated from Australia. We provide digital assessment forms for healthcare professionals including psychologists, counsellors, and dermatologists. Our platform enables clinicians to send standardised assessment instruments to their patients, collect responses securely, and view scored results.
We also provide registration forms and service agreements to Australian practices that are not clinical, including NDIS plan managers. Those practices use the platform to register participants and to have a service agreement read and signed, not to send clinical assessments. Where this policy says “patient”, read “participant” for those practices.
ClientForms is operated from Australia and complies with Australian and New Zealand privacy law. Clinicians in other jurisdictions are responsible for ensuring their use of the platform meets their local regulatory requirements. This policy explains how we handle data and the specific frameworks we comply with.
2. Information We Collect
Clinician Account Information
- Name and email address
- Practice name and URL slug
- Country of operation
- Payment information (processed by Stripe — we do not store card details)
Patient and Participant Information
- Name (or initials/pseudonym — patients may use pseudonyms)
- Email address (optional, for sending assessment links)
- Date of birth (for age-appropriate assessments)
- Phone number (optional)
- Postal and residential address, where the practice asks for it
Patients and participants do not create an account and do not log in. They reach their forms through a private link, so no authentication details are collected from them and none of their information is held by our authentication provider.
Representatives and Other Contacts
A registration form may be completed by someone other than the person it is about: a plan nominee, correspondence nominee, child representative, attorney, appointed guardian, or someone helping informally. Where that happens we collect, about that person:
- Their name, and the role or relationship they hold
- Their email address and phone number, so the practice can reach them
- The details of any alternative contact or support coordinator the participant names
NDIS Information (Australian plan-management practices)
- NDIS participant number
- Plan start date and plan reassessment date
- Whether another plan manager is currently engaged, and when their service ends
The NDIS participant number is a government related identifier. We do not use it to identify you in our own systems: your record carries an identifier of our own, and the NDIS number is stored against it only so the practice can transact with the NDIA on your behalf. It is never used as a login, never placed in a web address, file name or email subject, and never used to link you across practices.
Agreements, Consents and Registrations
- The answers given on a registration form
- Signed consent forms and signed service agreements, including the wording as it stood when it was signed
- The name and, where given, the capacity of the person who signed, and the date and time of signing
Health Assessment Data
- Responses to standardised clinical assessments (e.g., PHQ-9, GAD-7, DASS-21, PASI)
- Calculated scores and severity classifications
- Assessment completion timestamps
Health assessment data is classified as sensitive information under both Australian and New Zealand privacy law and receives heightened protection.
Technical Information
- IP address and browser type (for security and analytics)
- Pages visited and interaction patterns (via Vercel Analytics — privacy-preserving, no personal data)
- Cookies necessary for authentication and preferences
3. How We Use Your Information
We use your information only for purposes directly related to providing and improving our clinical assessment service:
- Service delivery: Rendering assessment forms, calculating scores, displaying results to clinicians
- Account management: Authentication, billing, subscription management
- Communication: Service notifications, support responses, product updates (you can opt out of non-essential communications)
- Security: Fraud prevention, breach detection, access logging
- Improvement: Aggregated, de-identified analytics to improve the platform (we never use identifiable health data for analytics)
We do not: sell your data, use patient health data for marketing, share identifiable patient data with third parties for their own purposes, or use health data for automated decision-making.
5. Cross-Border Data Transfers
For Australian and New Zealand practices, everything a patient or participant gives us is stored in Sydney, Australia on Supabase infrastructure. That means their personal details, their health assessment responses, the answers on their registration form, their NDIS information, the details of anyone acting on their behalf, and their signed consents and service agreements. The equivalent data for US practices is stored in US-region data centres (see below). Some ancillary data is processed overseas:
- Clinician authentication data (email, name) is processed by Clerk in the United States. This covers the practice's own login only. Patients and participants do not log in, so none of their information reaches Clerk.
- Payment data is processed by Stripe globally — we never store card details
- Application code runs on Vercel's global edge network — but clinical data is fetched from the regional database (Sydney for AU/NZ practices, US-East for US practices) at runtime
For Australian Clinicians
Under APP 8 of the Privacy Act 1988, we take reasonable steps to ensure overseas recipients of personal information comply with the Australian Privacy Principles. Our service providers are contractually bound to protect your data to a comparable standard.
For New Zealand Clinicians
Under IPP 12 of the Privacy Act 2020, overseas disclosure of personal information requires adequate safeguards. Our cloud infrastructure providers (Supabase, Vercel) act as our agents under Section 11 of the Privacy Act 2020, meaning data held by them is legally considered to be held by us. Australia is generally considered to provide comparable privacy safeguards under IPP 12(1)(c). We maintain contractual safeguards consistent with the OPC's model contract clauses.
For US Clinicians
US clinician data is stored on US-based servers. Authentication and payment processing are also US-based. ClientForms is operated from Australia, so administrative and support access to those systems happens from Australia — our Business Associate Agreement states this openly. For details on our HIPAA compliance, see our HIPAA Compliance page.
6. Data Security
- Encryption: AES-256 encryption at rest, TLS 1.2+ in transit
- Access controls: Role-based access enforced at the database level
- Authentication: Multi-factor authentication available for all accounts
- Monitoring: 24/7 security monitoring, DDoS protection, real-time threat detection
- Backups: Automatic daily backups of all databases
- Data isolation: Each practice's data is logically isolated at the database level
For more detail, see our Security & Privacy page.
7. Data Retention
| Data Type | Australia | New Zealand | United States |
|---|---|---|---|
| Adult health records | 7 years (recommended) | 10 years (mandatory) | 6+ years (state law) |
| Children's health records | Until patient turns 25 | Until patient turns 25 | Per state law |
| Registration form answers | Kept with the practice's record of that person, for as long as the practice holds it | ||
| Signed consents and service agreements | Kept for as long as the practice holds the record, so both sides can see what was agreed and when | ||
| NDIS plan documents attached by a participant | Kept while the practice manages the plan, then 5 years from the end of that relationship (Australian Taxation Office record-keeping requirements). Abandoned upload attempts are removed within 7 days | Not offered | |
| Identifiers collected on a form (Medicare, DVA, NDIS participant number) | Removed from the form record by an automatic monthly job once it is more than 60 days old, so in practice within about 90 days | No automatic removal. Retained per the record retention period for that country | |
| Clinician account data | Duration of account + 12 months after closure | ||
| Payment records | 7 years (tax compliance) | ||
The applicable retention period depends on the country selected during account setup. Data is retained for at least the applicable period and securely disposed of when it is deleted, including from backups.
One thing worth stating plainly, because the row above could be read the wrong way. Removing an identifier from the form record does not always remove it from the practice. Where a practice needs an identifier to keep doing its job, it is also held against that person's record, and it stays there while the practice holds the record. An NDIS plan manager, for example, needs the participant number to claim from the NDIA for the life of the plan. What the monthly job removes is the copy sitting in the submitted form.
8. Your Rights
You have the right to:
- Access: Request a copy of the personal information we hold about you
- Correction: Request that inaccurate information be corrected
- Deletion: Request deletion of your data (subject to legal retention requirements)
- Complaint: Lodge a complaint with the relevant privacy regulator (see Section 14)
To exercise any of these rights, contact us at privacy@clientforms.app. We will respond within 20 working days (NZ), 30 days (AU), or 30 days (US).
9. Australia — Privacy Act 1988
ClientForms complies with the 13 Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth). Key commitments:
Open and transparent management
This policy documents our personal information handling practices.
Anonymity and pseudonymity
Patients may use initials or pseudonyms when completing assessments.
Collection of personal information
We collect only information that is reasonably necessary for clinical assessment services.
Use and disclosure
Personal information is used only for the purpose it was collected — delivering clinical assessment services.
Direct marketing
We do not use patient health data for marketing purposes.
Cross-border disclosure
Data is stored in Australia. Where data is processed overseas (authentication, payments), we ensure comparable protection.
Security
We take reasonable steps to protect personal information with encryption, access controls, and monitoring.
Access
You may request access to your personal information at any time.
Correction
You may request correction of inaccurate personal information.
For the full list of 13 APPs and how we meet each one, see our Security & Privacy page. You may also contact the OAIC (opens in new tab) to make a privacy complaint.
10. New Zealand — Privacy Act 2020
ClientForms complies with the 13 Information Privacy Principles (IPPs) under the New Zealand Privacy Act 2020. Where health information is processed, the Health Information Privacy Code 2020 (HIPC) applies, with HIPC Rules replacing the IPPs.
Purpose of collection
We collect personal information only for purposes directly connected to our assessment platform service.
Source of information
Personal information is collected directly from clinicians and patients, not from third parties.
Collection from the individual
When we collect information, we inform individuals of the purpose, intended recipients, and their rights.
Storage and security
We take reasonable steps to protect personal information against loss, unauthorised access, and misuse.
Access to personal information
Individuals may request access to their personal information held by us.
Correction of information
Individuals may request correction of personal information that is inaccurate, incomplete, or misleading.
Use of information
Information is used only for the purpose it was collected, unless an exception applies.
Disclosure of information
We disclose personal information only where authorised by the individual or required by law.
Disclosure outside New Zealand
Cross-border transfers are governed by IPP 12. Our cloud providers act as agents under Section 11, and Australia provides comparable safeguards.
Health Information Privacy Code 2020
The HIPC applies 13 health-specific Rules that replace the IPPs when health information is involved. Key differences include stricter rules on collection purposes, additional grounds for disclosure to health or disability services, and a mandatory 10-year retention period for health data under the Health (Retention of Health Information) Regulations 1996.
Notifiable Privacy Breaches
Under Sections 112–118 of the Privacy Act 2020, if we become aware of a privacy breach that poses a risk of serious harm, we must notify the Office of the Privacy Commissioner (OPC) and affected individuals as soon as practicable. Health data breaches are virtually always notifiable due to the sensitivity of the information. You may contact the OPC (opens in new tab) to make a privacy complaint.
11. United States — HIPAA
ClientForms complies with the Health Insurance Portability and Accountability Act (HIPAA) for US-based clinicians. Patient data is stored on US-based servers, on infrastructure that is physically separate from our Australian and New Zealand systems.
Privacy Rule
We collect and use only the minimum necessary protected health information (PHI) for clinical assessment services.
Security Rule
We implement administrative safeguards (access management, workforce policies), physical safeguards (facility access controls via our cloud provider), and technical safeguards (AES-256 encryption, role-based access controls, audit logging).
Breach Notification Rule
We are your business associate, so our duty runs to you, not to your patients. We notify your practice in writing within 15 days of discovering a breach, with the affected individuals identified, so you can meet your own 60-day deadline to notify them and the HHS Office for Civil Rights. We do not contact your patients.
Business Associate Agreement
We provide a BAA to every US account, on every plan. Our infrastructure provider also maintains a BAA with us.
Data retention
HIPAA requires us to keep compliance documentation for at least 6 years (45 CFR § 164.530(j)). How long medical records themselves are kept is governed by state law.
For full details on our HIPAA compliance, see our HIPAA Compliance page. You may also contact the HHS Office for Civil Rights (opens in new tab) to file a HIPAA complaint.
12. Canada — PIPEDA
For Canadian clinicians, ClientForms handles personal information in line with the Personal Information Protection and Electronic Documents Act (PIPEDA). Canadian account and patient data is stored in the United States on the same infrastructure that serves our US clinicians.
Cross-border processing
PIPEDA permits transferring personal information to a processor in another country, provided comparable protection is in place and the arrangement is transparent. We disclose the US storage location at signup and here.
Fair Information Principles
We handle personal information according to PIPEDA’s ten Fair Information Principles (accountability, consent, limiting collection and use, safeguards, and individual access among them).
Safeguards
Data is protected by AES-256 encryption at rest and TLS 1.2+ in transit, with role-based access controls and audit logging.
Breach notification
We report breaches posing a real risk of significant harm to the Office of the Privacy Commissioner of Canada (OPC) and to affected individuals as soon as feasible.
Provincial health-privacy law
Provincial rules (for example PHIPA in Ontario, or Quebec’s Law 25) may add requirements. ClientForms is intended for private-practice clinicians; it is not designed for BC/NS public-sector bodies that require data residency within Canada.
You may contact the Office of the Privacy Commissioner of Canada (opens in new tab) to raise a privacy concern.
14. Children's Information
Some assessments (such as child ADHD assessments) involve children's health data. This data is always provided by a parent, guardian, or treating clinician — never directly by the child. Children's health records are subject to extended retention periods (until the patient turns 25) in accordance with applicable health records legislation.
15. Contact & Complaints
For privacy enquiries, access requests, or complaints:
Privacy Officer
Email: privacy@clientforms.app
Australian Privacy Regulator
Office of the Australian Information Commissioner (OAIC)
www.oaic.gov.au (opens in new tab)
New Zealand Privacy Regulator
Office of the Privacy Commissioner (OPC)
www.privacy.org.nz (opens in new tab)
US Privacy Regulator
HHS Office for Civil Rights (OCR)
www.hhs.gov/ocr (opens in new tab)
16. Changes to This Policy
We may update this privacy policy from time to time. Material changes will be communicated via email to registered clinicians. The “Last updated” date at the top of this page reflects the most recent revision. Continued use of our service after changes constitutes acceptance of the updated policy.
Have questions about our privacy practices?