Privacy Policy
Last updated 4 October 2026
Corvale (“we”, “us”) respects your privacy. This policy explains how we handle personal information, including health information, in line with the Privacy Act 1988 (Cth) and the Australian Privacy Principles.
1. Who we are and our role
Corvale provides practice management, telehealth and e-prescribing software to healthcare clinics in Australia. We handle personal information in two ways:
- For our own business — about clinic staff, enquirers and visitors to our website. For this information, Corvale decides how it is handled.
- On behalf of clinics — patient records and other information a clinic stores in Corvale. The clinic is responsible for that information and its own privacy policy applies; we process it only to provide the service to the clinic. Patients should contact their clinic first about their records.
2. Information we collect
- Account details — name, email, phone, role, professional registration details (such as AHPRA and prescriber numbers) and sign-in records.
- Clinic details — business name, ABN, address, branding and billing contacts.
- Health information — appointments, consultation notes, questionnaire answers, prescriptions and documents entered by clinics and their patients.
- Payment information — handled by our payment provider (Stripe). We do not store full card numbers.
- Technical information — IP address, browser and device type, and activity logs used for security and audit.
- Enquiries — what you tell us when you contact us or enrol your clinic.
3. How we use information
We use personal information to:
- provide, maintain and support the Corvale platform;
- verify identity and secure accounts, including two-step sign-in;
- send service messages such as booking confirmations and reminders;
- process payments and keep business records;
- detect, investigate and prevent misuse, fraud and security incidents;
- meet our legal and regulatory obligations.
We do not sell personal information, and we do not use health information for advertising.
5. Storage and security
Clinic and patient data is stored in Australia, in Amazon Web Services’ Sydney region, with each clinic’s data kept separate. We use encryption in transit and at rest, role-based access, two-step sign-in and audit logging.
Some providers (for example email delivery) may process limited information outside Australia. Where this happens we take reasonable steps to make sure it is handled consistently with the Australian Privacy Principles.
6. How long we keep information
We keep information for as long as the clinic’s account is active and as required by law. Health records are retained in line with applicable health records legislation, which generally requires adult records to be kept for at least seven years. When information is no longer needed, we delete or de-identify it.
7. Access and correction
You can ask to access or correct personal information we hold about you by emailing support@corvale.health. If your request relates to a clinic’s patient records, we will refer it to that clinic. We will respond within 30 days and may need to verify your identity first.
8. Data breaches
If a data breach is likely to cause serious harm, we will act quickly to contain it, notify affected clinics, and notify affected individuals and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme.
10. Questions and complaints
Contact us at support@corvale.health with any privacy question or complaint. We aim to respond within 30 days.
If you are not satisfied with our response, you can contact the Office of the Australian Information Commissioner at oaic.gov.au or on 1300 363 992.
11. Changes to this policy
We may update this policy from time to time. The latest version will always be on this page, and we will tell clinics about significant changes.