Australia privacy supplement
About this document
| Field | Value |
|---|---|
| Version | 1.0 |
| Effective date | 1 August 2026 |
| Publication date | 1 August 2026 |
| Last reviewed | 18 July 2026 |
| Status | Approved public document |
Version history
| Version | Effective date | Change summary | How this version applies |
|---|---|---|---|
1.0 | 1 August 2026 | Initial public version | Applies with the core Privacy Notice; consent is requested separately where required |
1. Scope and applicability
This supplement is intended for people in Australia who use Alessia or whose personal information Alessia handles. An individual professional normally controls personal information they choose for their professional User Content and Alessia handles it under the Individual Customer Terms. Institution-controlled portfolio information remains subject primarily to the Institution's privacy notice and Alessia's processing agreement with it. Alessia remains responsible for processing it determines for its own purposes.
This contractual role allocation does not remove any direct responsibility that Australian privacy law places on Alessia or another entity.
Alessia complies with the Australian Privacy Principles as an APP entity for personal information it handles in Australia and does not rely on the small-business exemption to reduce the protections described in this supplement. Alessia does not ask users for sensitive information for a standard account and collects it only with consent where a specific feature explains the purpose (APP 3.3). If Alessia receives unsolicited personal information it could not have collected itself, it assesses it under APP 4 and destroys or de-identifies it where lawful and reasonable. Additional federal, state or territory requirements may apply, particularly where an Institution controls health or education information. Nothing in this supplement limits any mandatory rights under applicable Australian law.
2. Collection and use
The core Privacy Notice describes the kinds of information Alessia handles, how it is collected, the purposes of use, usual disclosures and retention. Portfolio fields are optional unless expressly stated. Users must not submit identifiable patient information.
Alessia does not ask users to provide information about their own health, disability, ethnicity or other sensitive matters as part of an account or portfolio. Do not include that information in free text or attachments.
At or before collection, Alessia will provide any APP 5 information reasonably required for the feature, including its identity/contact details, the purpose and consequences of non-collection, usual recipients, complaint route and likely overseas disclosures.
3. Overseas processing and APP 8
Alessia uses providers for hosting, identity, analytics, email, notifications, subscription/payment administration and optional AI processing. The authoritative providers, recipient countries, roles and safeguards appear in the Subprocessor List.
Before disclosing personal information to an overseas recipient, Alessia will assess APP 8 and take reasonable steps to ensure the recipient does not breach the APPs where required. Contractual safeguards are important but do not necessarily remove Alessia's potential accountability under section 16C for an overseas recipient's act or practice.
Institution region selection applies to primary hosting only and does not mean that every support function or provider remains in that region.
4. Optional AI and automated decisions
Alessia's AI-assisted features produce transcripts, summaries and competency suggestions for human review. Alessia does not use AI to make decisions about a person's training progression, employment, professional registration, credentials or access to significant services. Users and Institutions remain responsible for those decisions.
The anonymous AI-improvement purpose described in the core Privacy Notice applies only after a documented assessment establishes that information is no longer personal information in the relevant context. The deidentification operation remains subject to the Australian Privacy Principles, including applicable requirements for a secondary use and sensitive information. Where there is doubt, Alessia continues to treat the information as personal information and does not use it for model development.
From 10 December 2026, Australian law requires additional privacy-policy information where a computer program makes, or performs a substantial and direct step towards, a decision that could significantly affect someone's rights or interests. Where that requirement applies, we will describe the kinds of personal information used and the relevant kinds of decisions before using the arrangement.
5. Quality, access and correction
Users should keep their account details accurate. Alessia does not verify that user-entered portfolio content is clinically complete or accurate.
Subject to applicable exceptions, an individual may ask to access or correct personal information held by Alessia. Use in-app tools or email privacy@alessiahq.com. Alessia may verify identity, explain a decision within its own responsibility and provide the applicable review route. Where an individual professional or Institution controls the relevant User Content, Alessia will direct or assist the request to that controller. This does not limit a direct Australian right against Alessia where one applies.
6. Security, retention and eligible data breaches
Alessia uses technical and organisational safeguards described in the Privacy Notice and security materials. No system is completely secure. Retention and deletion follow the published Retention Schedule and any Institution agreement.
Alessia will assess suspected incidents under the Notifiable Data Breaches scheme where it applies. If an eligible data breach is established, Alessia or the responsible Institution will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) as required.
7. Complaints
To make an Australian privacy complaint, email privacy@alessiahq.com with the subject “Data Protection Complaint”. The privacy complaints page explains the process. Include enough detail to investigate, but do not send patient information or unnecessary portfolio evidence by ordinary email.
Alessia will acknowledge, investigate and respond within a reasonable period. If the response is not satisfactory, a person may be able to complain to the OAIC. If an individual professional or Institution controls the relevant User Content, that controller's complaint route will normally apply first, while Alessia remains responsible for its own handling.
Privacy contact/person responsible in Australia: Privacy Officer, privacy@alessiahq.com, Alessia International Ltd, 27 Old Gloucester Street, London, WC1N 3AX, United Kingdom.
