Last updated: April 2026
Figments (“we”, “us”, “our”) is a clinical practice management platform for Australian allied health practices. This Privacy Policy explains how we collect, hold, use, and disclose personal information (including health information) in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
Health information is sensitive information under the Privacy Act and is afforded the highest level of protection. We treat all client data accordingly.
Figments is operated by Figments Tech Pty Ltd (ABN 91 697 631 780). For privacy enquiries, contact us at privacy@figments.com.au.
Figments acts as a data processor on behalf of the allied health practice (the “Organisation”) that subscribes to our platform. The Organisation is the primary data controller responsible for how client health information is collected and used within their practice.
Client health information (collected by practices using Figments):
Clinician and practice information:
Cookies:
IP addresses:
Analytics:
We do not use client health information to train AI models. We do not sell personal information to third parties.
Figments's Voice AI feature transcribes session recordings and generates draft clinical notes using Google Cloud Vertex AI. This feature:
We store data in Australia wherever possible:
Some data may be processed by third-party services outside Australia (see Section 8). Where this occurs, we take reasonable steps to ensure those providers maintain equivalent privacy protections under APP 8.
We engage the following sub-processors to deliver the platform:
| Provider | Purpose | Location |
|---|---|---|
| Firebase Auth (Google Cloud) | Authentication & identity | Global (Google Cloud) |
| Google Cloud Vertex AI | Voice AI transcription & note generation | Australia |
| Stripe | Subscription billing | USA |
| Resend | Email delivery — appointment reminders, clinical letters, and clinician-composed messages (may include health information where sent by the practice) | USA |
| Twilio | SMS delivery — appointment reminders and clinician-composed messages (may include health information where sent by the practice) | USA |
| Daily.co | Telehealth video conferencing (session data processed in transit only, not stored) | USA |
| Xero | Accounting integration (client names, invoices) | Australia/USA |
| Google Cloud | File & recording storage | Australia |
| Neon | Database | Australia |
| Vercel | Application hosting | Australia |
Some personal information (including health information) is disclosed to service providers located outside Australia, as listed in Section 8. This occurs when:
Before disclosing personal information to overseas recipients, we take reasonable steps under APP 8.1 to ensure those recipients do not breach the Australian Privacy Principles. All overseas providers listed above have entered into Data Processing Agreements (DPAs) with us and are bound by equivalent privacy obligations.
By using Figments (as a practice) or by having your health information stored in Figments (as a client of a practice), you acknowledge that your information may be processed by overseas sub-processors as described in this policy.
We do not disclose personal information to third parties except:
We take reasonable steps to protect personal information from misuse, loss, unauthorised access, modification, or disclosure. Security measures include:
Clinical records are retained for a minimum of 7 years from the date of last service (or until a minor client turns 25, whichever is later), in accordance with state-based health records legislation. Organisations may request earlier deletion subject to applicable legal obligations.
SMS and email message records are retained for the same period as clinical records (7 years). Message content is encrypted at rest within the database. Organisations may request earlier deletion subject to applicable legal obligations.
Pending guardian user records with no active links are automatically removed after 30 days.
Individuals have the right to access personal information we hold about them and to request correction of inaccurate information. Requests should be directed to the practice that holds your clinical records in the first instance. Platform-level access requests can be directed to privacy@figments.com.au.
We will respond to access requests within 30 days. A reasonable fee may apply for complex requests.
In the event of an eligible data breach under the Notifiable Data Breaches (NDB) scheme, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) as required by Part IIIC of the Privacy Act.
If you believe we have breached your privacy, please contact us at privacy@figments.com.au. We will respond within 30 days. If you are not satisfied with our response, you may lodge a complaint with the OAIC at www.oaic.gov.au.
We may update this policy from time to time. The current version will always be available at figments.com.au/privacy. Material changes will be communicated to practice administrators by email.