Effective August 2026 · Last updated 2 August 2026.
Avilo Health Pty Ltd (ACN 698 695 019) ("Avilo", "we", "us") provides an AI-assisted patient-communications service for allied health clinics: answering calls, handling text messages, sending appointment reminders and confirmations, and running patient recall on behalf of the clinics that subscribe to us (each a "Clinic").
We handle health information, which is sensitive information under Australian privacy law. We treat it accordingly. We are bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles ("APPs"), and by applicable state and territory health records legislation including the Health Records and Information Privacy Act 2002 (NSW) and the Health Records Act 2001 (Vic).
This policy has three parts:
If you are a patient of a clinic that uses Avilo: your relationship is with your clinic, and your clinic's privacy policy applies alongside this one. Requests about your information should normally go to your clinic first, and we will assist them. Parts B and C are written for you.
To provide and administer the service; to support accounts; to bill; to answer enquiries; to improve the product; to send service notices; and, with consent or as permitted by law, marketing you can opt out of at any time. We do not sell personal information.
Some of the providers listed in B5, including our billing, email, demo-booking and enquiry-form providers, handle this information overseas. B5 explains where our providers are located and how we manage overseas disclosure.
Essential functionality only. This website does not run analytics, advertising or tracking cookies, and does not load fonts, scripts or images from third parties. Our web fonts are served from our own domain, so simply browsing the site sends nothing to anyone but us. If we introduce analytics in future, we will update this policy before doing so.
The booking calendar is the one exception, and it is opt-in. Our demo booking calendar is provided by Calendly. It does not load unless you click to load it. If you do, your browser connects to Calendly and Calendly may set its own cookies at that point. You can book by sending us an enquiry instead if you would rather not load it.
You can disable cookies in your browser; parts of the site may not work.
What we deliberately do not collect or hold:
Most patient information reaches us from the Clinic's PMS under an API connection the Clinic authorises, or from patients messaging or calling the Clinic's Avilo-managed number.
New patients. Where someone who is not yet a patient of the Clinic calls or messages, Avilo may create a patient record and book an appointment on the Clinic's behalf. In that case we collect your information, including a brief reason for your visit, directly from you, for the Clinic. We tell you at the start of the call that you are speaking with an AI assistant and that a written record is kept, and the booking confirmation links to the Clinic's privacy policy. You can ask for a person at any point and the assistant will transfer you or take a message.
We collect health information only where reasonably necessary to book or manage your appointment, and ask for no more than that. Please don't send clinical detail through this channel; anything clinical is passed to the Clinic's team rather than handled by the AI.
Only what is needed to run the service for the Clinic:
We never contact a Clinic's patients for any purpose of our own, and we do not use patient information for our own marketing.
Clinics can use Avilo to send appointment reminders and to check in with patients they haven't seen for a while.
We use the service providers below, each bound by contract to use information only to provide services to us:
| Provider | Purpose | Data location |
|---|---|---|
| Supabase | Primary database and authentication | Australia (Sydney) |
| Make.com | Custom workflow automation for clinics | United States |
| Fly.io | Application hosting | Australia (Sydney) |
| Twilio | SMS and voice carriage | United States |
| ElevenLabs | Real-time voice AI; transcripts only, no audio retained | United States |
| Anthropic | AI language processing | United States |
| Resend | Transactional email to Clinic staff | United States |
| Stripe | Billing (Clinic billing data only, no patient data) | United States |
| Calendly | Demo booking for website visitors, loaded only on request (no patient data) | United States |
| Formspree | Website enquiry form delivery (no patient data) | United States |
| Sentry | Error monitoring (patient content filtered before transmission) | United States |
Where the data sits. Our primary database and our application hosting are both in Australia. The remaining providers process information in the United States in the course of delivering their functions.
Overseas access, even to Australian-hosted data. Supabase and Fly.io are companies incorporated in the United States. Although the data they hold for us is stored in Australia, their personnel and support systems may be able to access it from outside Australia. We therefore treat every provider in this table as an overseas recipient rather than relying on the storage location alone. The countries in which recipients are likely to be located are Australia and the United States.
Before disclosing personal information overseas we take reasonable steps under APP 8.1 to ensure the recipient handles it consistently with the APPs. This includes binding contractual data-protection terms with each provider that limit it to acting on our instructions, prohibit use of the information for its own purposes, and require it to protect the information to a standard consistent with the APPs.
The table above is our current list of sub-processors. Clinics receive at least 30 days' notice before we add or replace a provider that handles patient information.
We may also disclose where required by law, or to our professional advisers under confidentiality.
Encryption in transit (TLS) and at rest; PMS credentials encrypted with AES-256-GCM; tenant isolation enforced at the database layer so a Clinic's data is only reachable within that Clinic's tenancy; role-based access for Clinic staff; multi-factor authentication for administrative access; access and audit logging.
Access by Avilo personnel. Avilo is a small team. Personnel with technical access can reach patient content when required to investigate a specific fault or support request. Such access is limited to what the issue requires, and is logged. We also review escalated conversations to improve how the service handles them; see Part C.
If a breach occurs that is likely to result in serious harm, we begin assessing immediately, notify affected Clinics without undue delay and in any case within 72 hours of becoming aware, and comply with the Notifiable Data Breaches scheme, including notification to the OAIC and to affected individuals where required, working with the affected Clinic.
We publish this section voluntarily, ahead of the APP 1 automated-decision transparency obligations that commence on 10 December 2026.
When a message or call arrives, software classifies it: what the patient appears to want, how urgent it seems, and how confident the system is. It then either handles the request (booking, rescheduling, cancelling, answering the Clinic's approved practice questions) or escalates to Clinic staff. It uses the content of your message or call and your contact and appointment details, the categories listed in B1.
Booking itself is not decided by AI: which appointment slots exist and can be booked is determined by ordinary programmed rules reading the Clinic's calendar.
The consequential automated decision is whether a human sees your message, and how quickly. We build conservatively around it:
Avilo is not an emergency service and never gives clinical advice. If you are experiencing a medical emergency, call 000. The assistant is designed to say so and stop.
We review escalated conversations to correct mistakes and tune the system for that Clinic.
Boundaries we hold to:
Tell your clinic, or contact us at privacy@avilo.com.au. A person will review what happened, and the full conversation is available to your clinic.
Privacy questions or complaints: privacy@avilo.com.au. We acknowledge within 7 days and respond within 30 days.
Not satisfied? Complain to the Office of the Australian Information Commissioner: oaic.gov.au, 1300 363 992.
Material changes are notified to Clinics by email at least 30 days before taking effect. The current version is always at avilo.com.au/privacy.
Avilo Health Pty Ltd (ACN 698 695 019) · Effective August 2026 · Last updated 2 August 2026. See also our Terms of Service.