Privacy Policy.
Otro is a health service provider under the Privacy Act 1988 (Cth), so the small-business exemption does not apply to us. Your health information is sensitive information and carries a higher level of protection.
1. About this policy
This policy explains how Otro Pty Ltd (ABN to be confirmed · ACN to be confirmed) ("Otro", "we", "us") handles your personal information, including your health information.
Otro is a health service provider for the purposes of the Privacy Act 1988 (Cth). This matters: health service providers are covered by the Act regardless of turnover, so the small-business exemption does not apply to us. We are bound by the Australian Privacy Principles (APPs) and by the additional protections the Act gives to health information.
This policy applies to our website, our patient and practitioner accounts, and the second opinion service. It should be read alongside our Terms of Service.
Your health information is "sensitive information" under the Act. It carries a higher level of protection than ordinary personal information, and we generally cannot collect it without your consent.
2. What we collect
2.1 Information you give us
When you create an account: your name, email address, phone number, date of birth, and a password (which we store only as a cryptographic hash — we never see or store your actual password).
When you submit a case: your health information, including —
- the medical documents you upload: referral letters, imaging and scan reports, pathology results, specialist letters, GP notes and summaries, medication lists, surgical and procedure reports, hospital discharge summaries, and clinical photographs;
- your own description of your situation and the specific questions you want answered;
- links or access details you provide to investigations held elsewhere.
When you contact us: the content of your enquiry and your contact details.
When you pay: your payment is processed by Stripe. Otro does not collect or store your full card number. We retain a payment reference, the amount, and the outcome.
2.2 Records your reviewing specialist obtains
When you submit a case you give a separate authorisation to the reviewing specialist(s) matched to your case, allowing them to seek the investigations and records relevant to your case — including from your healthcare providers and, where the specialist is themselves authorised under the My Health Records Act 2012 (Cth), through My Health Record. This is explained at B5 of our Terms of Service.
Otro does not access those records itself. We do not access My Health Record, and we do not request records from your healthcare providers. The specialist does that in their own professional capacity, under their own registration and their own legal and professional obligations. Our role is to record your authorisation and pass it to them.
What we do hold is:
- Links you supply to investigations, stored with your case so the specialist can use them. We treat these like credentials — they are not displayed in full and we do not follow them; and
- Any material the specialist adds to your case record on the platform. Specialists are required, under their agreement with us, to file the materials they obtained and relied on. Once it is in your case record, it is held by us and handled under this policy, including the retention terms at section 8.
For practitioners: we verify AHPRA registration against the national public register, and collect fellowship, specialty, hospital appointment and indemnity insurance details.
2.3 Information collected automatically
When you use the website we collect limited technical information: IP address, browser and device type, pages requested, and timestamps. We use IP addresses for security and abuse prevention (rate limiting) and for aggregate analytics.
Cookies. We use cookies that are strictly necessary for the service to work — principally to keep you securely logged in. We do not use analytics cookies, marketing cookies or third-party tracking on this website.
2.4 What we do not collect
We do not collect Medicare numbers, Individual Healthcare Identifiers, tax file numbers, or government identity document numbers as part of case submission. Please do not send them to us unless we specifically ask.
3. Why we collect it, and what we use it for
We collect and use your information to:
| Purpose | What this involves |
|---|---|
| Provide the service | Triage your case, match it to a suitable independent specialist, enable them to prepare your report, and deliver it to you |
| Quality assurance | Chief Medical Officer review of every report for structure, clarity and completeness before release |
| Verify independence | Run per-case conflict-of-interest checks between you and the reviewing specialist |
| Billing | Authorise and charge the fee, issue invoices, handle refunds |
| Communicate | Send transactional emails about your case status, and respond to your enquiries |
| Security and integrity | Authenticate you, prevent unauthorised access, rate-limit abuse, maintain audit logs |
| Legal and regulatory | Meet record-keeping, health, tax and consumer law obligations, and respond to lawful requests |
| Improve the service | Understand aggregate usage patterns. We do not use your health information for product development or marketing |
We do not sell your personal information. We do not use your health information for marketing, and we do not disclose it to advertisers or data brokers.
4. Who we share it with
4.1 Reviewing specialists
The specialist matched to your case receives the documentation and information necessary to prepare your opinion. Specialists are bound by professional confidentiality obligations, by AHPRA's requirements, and by their agreement with us.
4.2 Our clinical team
Otro's clinical coordination staff and Chief Medical Officer access case information to triage, match, quality-review and deliver reports. Access is role-based, logged, and limited to what each role requires.
4.3 Service providers
We use third-party providers to run the platform. Each is engaged under contract, is limited to processing information for our purposes, and is required to protect it.
| Provider | What it does | Information involved | Location |
|---|---|---|---|
| Supabase | Database, file storage, authentication | Account details, case data, uploaded documents, reports | Australia (Sydney) |
| Vercel | Website and application hosting | Request data, technical logs | Region to be confirmed |
| Stripe | Payment processing | Name, email, card details (collected directly by Stripe), payment records | Global, incl. United States |
| Resend | Transactional email delivery | Name, email address, notification content | Region to be confirmed |
| Upstash | Rate limiting and abuse prevention | IP addresses, request counts | Region to be confirmed |
| Anthropic / AWS Bedrock | AI-assisted drafting support (see section 5) | De-identified clinical free text; where enabled, document content | See section 5 |
4.4 Others
We may disclose information where required or authorised by law, to respond to a lawful request from a court, regulator or law enforcement, to our professional advisers under confidentiality, or to a purchaser as part of a sale or restructure of the business (on notice to you).
We will not disclose your health information to your employer, insurer, or any other party without your express consent, except where required by law.
5. AI-assisted drafting, and how we protect you
We use artificial intelligence tools to assist specialists in preparing reports. It is important you understand the boundaries.
What AI does not do:
- It does not form clinical opinions, diagnoses or recommendations.
- It does not decide anything about your case — not whether it is accepted, who reviews it, or what the conclusion is.
- It does not replace the reviewing specialist. Every report is authored, reviewed and signed by a named human specialist, and every report passes Chief Medical Officer review before release.
What AI may do: assist with drafting and structuring report sections, and pre-populating a clinical summary from supplied documents, for a specialist to then verify, correct and take responsibility for.
Safeguards:
- AI features are disabled by default and enabled only deliberately.
- Where clinical free text is processed, identifying details are removed first.
- Content sent to an AI provider is not used by that provider to train their models.
- Every instance of cross-border processing is recorded in our audit log.
Cross-border processing (APP 8). Our default is to process information containing identifying details in Australia (AWS Bedrock, Sydney region). Where a workload is instead processed by Anthropic's first-party API, that processing occurs in the United States, and only material with identifying details removed is sent.
Where we send personal information overseas, we take reasonable steps to ensure the overseas recipient handles it in accordance with the Australian Privacy Principles, and we remain accountable to you for their handling of it under section 16C of the Privacy Act. We do not ask you to give up that protection.
Automated decision-making. Otro does not use automated decision-making to make decisions that significantly affect your rights or interests. Case acceptance, specialist matching, clinical conclusions and report content are all human decisions.
If we ever introduce computer programs that make, or do things substantially and directly related to making, decisions that significantly affect your rights or interests, we will describe here the kinds of decisions involved and the kinds of personal information they use, as the Privacy Act requires.
6. Where your information is stored
Case documents, reports and account data are stored in Australian data centres (Supabase, Sydney region).
Information is encrypted in transit (TLS) and at rest. Document downloads use short-lived signed URLs rather than public links.
The exceptions to Australian storage are the service providers listed at 4.3 that operate outside Australia, and the AI processing described at section 5.
7. How we protect it
- Encryption in transit and at rest.
- Role-based access control, enforced at the database level, so a user account can only reach its own data and staff roles only reach what their role requires.
- Audit logging of access to case data and of privileged actions.
- Rate limiting and abuse prevention on authentication and submission endpoints.
- Security testing — the platform has undergone security review with findings remediated.
- Staff and specialist obligations — confidentiality terms, and access limited to what is needed for the case.
No system is perfectly secure. If a data breach occurs that is likely to result in serious harm, we will notify you and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act.
8. How long we keep it
We retain case documentation, reports and associated records for 7 years from the date of last activity on the case. This is the period required of private health service providers under Australian health records legislation for adult patients, and it is one of the reasons our service is limited to patients aged 18 and over.
We retain account and billing records for the period required by tax and corporations law.
Your reviewing specialist keeps their own file. They hold it under their own professional record-keeping obligations. Their retention does not discharge ours, and ours does not discharge theirs — the two run in parallel.
You can ask us to delete your information earlier. We will do so unless we are required to retain it — for example, for the health record-keeping period above, to meet a legal obligation, or to resolve a dispute or claim. Where we cannot delete something, we will tell you why.
After the retention period, records are securely destroyed or de-identified, and we keep a record of what was destroyed, when and how.
9. Your rights
9.1 Access
You can ask for a copy of the personal information we hold about you. Much of it is available directly in your account. For anything else, contact our Privacy Officer. We will respond within 30 days. We do not charge for a request, though we may charge a reasonable fee for a substantial one — we will tell you first.
We may refuse access in the limited circumstances the Privacy Act allows. If we refuse, we will explain why and how to complain.
9.2 Correction
If information we hold is inaccurate, out of date or incomplete, tell us and we will correct it.
A note on reports: a delivered report is a clinical record of the specialist's opinion at a point in time. We will correct factual errors (for example, a wrong date of birth). We will not alter a clinical conclusion, but you can ask us to attach a statement of your disagreement to the record.
9.3 Withdrawing consent
You can withdraw your consent to us handling your health information at any time. This may mean we cannot complete a review in progress — see the Terms of Service for what that means for fees.
9.4 Anonymity
You can browse this website without identifying yourself and you can make a general enquiry anonymously or under a pseudonym. We cannot provide the second opinion service anonymously — a specialist cannot review records that cannot be attributed to a person.
10. Complaints
If you think we have mishandled your personal information, contact our Privacy Officer:
Privacy Officer — Otro Pty Ltd
Email: hello@otro.com.au (a dedicated privacy address is to be confirmed)
Post: Sydney NSW 2000, Australia
We will acknowledge your complaint within 2 business days and respond within 30 days.
If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner (OAIC):
- Online: oaic.gov.au
- Phone: 1300 363 992
- Post: GPO Box 5218, Sydney NSW 2001
You may also be able to complain to the health complaints body in your State or Territory. If your complaint concerns the professional conduct of a registered practitioner, you can contact AHPRA at ahpra.gov.au.
11. Changes to this policy
We may update this policy. The current version and its effective date are always published on this page. Where a change is material, we will take reasonable steps to notify account holders before it takes effect.
12. Contact us
Privacy Officer — Otro Pty Ltd (ABN to be confirmed · ACN to be confirmed)
Email: hello@otro.com.au (a dedicated privacy address is to be confirmed)
General enquiries: hello@otro.com.au
Post: Sydney NSW 2000, Australia
Effective . Version 1.0.