This Privacy Policy explains how Fresh Trading Pty Ltd (ACN 624 936 081) (referred to as “we”, “us”, “our”) handles Personal Information in connection with our provision of the Claro clinical platform (“Claro”) in the United States. It is the privacy policy that applies to Claro.
If you are a patient of a clinic that uses Claro: your clinic (or its affiliated professional entity) is the HIPAA covered entity responsible for your health information. Claro processes your protected health information (“PHI”) only on your clinic’s behalf, as a business associate, under a Business Associate Agreement with your clinic. Your clinic’s Notice of Privacy Practices — not this policy — describes how your health information is used and disclosed and how to exercise your HIPAA rights. This policy describes how Claro handles Personal Information that is not PHI, and gives you visibility into the platform that supports your clinic.
This policy applies to:
We comply with the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”) in our role as a business associate, with applicable state privacy and data breach notification laws, and — to the extent it applies to us — with the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA”).
The Personal Information we collect depends on your relationship with Claro.
When you visit our websites or interact with our marketing materials, we may collect:
When your organization subscribes to Claro, and when you become an Authorized User, we collect:
When a clinic uses Claro to deliver care, the clinic collects Patient health information and that information is processed through Claro. We act as the clinic’s business associate under HIPAA, and our use and disclosure of this information is governed by the Business Associate Agreement with the clinic, not by this policy. The categories processed include identifiers, clinical information, clinical media (including consultation audio recordings, AI-generated transcripts, and AI-generated draft notes), and interaction data.
The collection of this information is the responsibility of your clinic. Your clinic’s Notice of Privacy Practices explains why it is collected, how it is used and disclosed, and how to exercise your rights over it.
We may incidentally process Personal Information about individuals who are not Patients, Authorized Users, or visitors — for example, an emergency contact named in a Patient record, or a family member mentioned in a clinical note. Where this information is part of a Patient record it is treated as PHI under the Business Associate Agreement.
We collect and use Personal Information (other than PHI, which is used only as the Business Associate Agreement permits) to:
To provide the Claro platform to our customer clinics and their Authorized Users, including enabling secure login and authentication, delivering notifications by email and push, supporting customer service and incident response, and maintaining audit logs and security monitoring.
To provide the AI Features described in section 4. PHI processed by the AI Features is processed on the clinic’s behalf under the Business Associate Agreement. AI Features are intended to be used only where the relevant clinic has obtained any patient consent required (including any recording consent required by state law); obtaining and recording that consent is the clinic’s responsibility.
To bill and collect payments, manage accounts, respond to inquiries, deliver onboarding and training, and otherwise administer the Master Subscription Agreement we have with the clinic.
To respond to inquiries from prospective customers, send marketing communications (where permitted by law and subject to your right to opt out), and arrange demonstrations of Claro.
To respond to lawful requests by regulators, courts, and law-enforcement authorities, and to comply with our obligations under tax, employment, and other applicable laws.
To analyze the use of Claro, troubleshoot problems, prevent fraud and abuse, secure our infrastructure, and develop new features and improvements. Where clinical data is involved, we do so only on a de-identified basis in accordance with 45 CFR 164.514, or on aggregate usage metrics. We do not use Customer Data, Patient Data, Practitioner inputs, consultation audio, transcripts, or AI-generated clinical content to train, develop, fine-tune, or improve any artificial-intelligence or machine-learning model — whether a third party’s general-purpose model or one of our own. The only data we use for product analytics is aggregate usage metrics (such as counts, timings, and error rates) that contain no health information and no clinical content.
Claro includes AI Features that record audio of clinical consultations, transcribe the audio, and generate draft clinical notes. AI Features may also draft letters, investigation orders (including pathology and imaging request drafts), treatment-plan item drafts, summaries, and suggestions to support clinical workflow, and may extract structured information (such as treatment areas mentioned in the consultation) and suggest labels. All of these AI Features are processed through the same safeguards described in this section, and patient identifiers held in the record are not sent to the language-model provider.
Claro is a clinical documentation and workflow-support tool. It is intended to transcribe, summarize, structure, and draft documentation from information stated or provided by the practitioner, or otherwise present in the patient record, and (where a feature is designed to do so) to draw the practitioner’s attention to information recorded in the patient record or to matters the practitioner may wish to confirm. Claro is not designed or intended to generate, and must not be used to obtain, a diagnosis, differential diagnosis, or treatment recommendation that the practitioner has not independently formed. Every AI-generated output is a draft or decision-support prompt for the practitioner to review, verify, edit, accept, or reject; the practitioner exercises independent clinical judgment and is solely responsible for all clinical decisions. Claro is not intended to function as a medical device.
The third-party providers of these artificial-intelligence services (speech-to-text transcription and large-language-model text generation) are our AI Service Providers. They are engaged as subprocessors — and, where they handle PHI, as HIPAA subcontractors under written business associate agreements — and are identified in our Subprocessor List, which we update from time to time. Processing by the AI Service Providers for the US deployment occurs in the United States.
When AI Features are used:
No patient data, consultation audio, transcript, or generated clinical content is used to train, develop, or improve any AI model — whether a third party’s model or one of our own. We do not authorize any AI Service Provider to retain or use this information for any such purpose, and we do not use it for any such purpose ourselves.
The decision to use AI Features in any particular consultation, and any consent obtained from the Patient for their use (including any recording consent required by state law), is the responsibility of the clinic. We provide the clinic with template materials (a Patient Information Sheet and a Patient Consent Addendum) to help the clinic inform patients.
Claro uses automated processing to generate draft clinical documentation and suggestions, which a practitioner then reviews, edits, and approves. Claro does not make automated decisions that produce legal or similarly significant effects about a patient without a practitioner’s involvement: a licensed health care professional remains responsible for, and makes, the clinical decisions about a patient’s care.
We disclose Personal Information only as described in this policy (and, for PHI, only as the Business Associate Agreement permits) and only to the extent necessary for the purposes listed in section 3.
For Patient information, the customer clinic (or its affiliated professional entity) is the covered entity that controls the information. The clinic and its Authorized Users access Patient information in accordance with their roles and the clinic’s clinical workflows. Other clinics in the same network may have access to a Patient where the Patient is referred between them, in accordance with the clinic’s referral arrangements.
Authorized Users of a clinic see Personal Information of that clinic’s Patients in accordance with their assigned role and the clinic’s data isolation rules, consistent with the HIPAA minimum necessary standard. We do not allow Authorized Users to see Patient information held for other clinics outside the network and referral arrangements approved by the clinics.
We engage third-party service providers to support the delivery of Claro. We refer to these as Subprocessors; those that handle PHI are HIPAA subcontractors under written business associate agreements. They include providers of:
A list of our current Subprocessors is available on our legal pages. We update the list when our Subprocessors change.
We may disclose Personal Information to regulators (such as the U.S. Department of Health and Human Services and its Office for Civil Rights, state medical and nursing boards, state departments of health, the Drug Enforcement Administration, and state boards of pharmacy) and to courts and law-enforcement authorities where we are required or permitted to do so by applicable law, and — for PHI — only as permitted by the Business Associate Agreement and HIPAA.
We may disclose Personal Information to our professional advisers (lawyers, accountants, auditors, and consultants) and to our insurers and brokers, in each case for the purpose of obtaining advice or insurance and on terms that protect the confidentiality of the Personal Information.
If we sell, transfer, or restructure all or part of our business, we may disclose Personal Information to a buyer, transferee, or successor as part of that transaction, on terms that require the buyer to handle the Personal Information consistent with this policy (and, for PHI, with HIPAA).
We may disclose Personal Information for any other purpose where you have consented to that disclosure.
For the US deployment, Claro’s production infrastructure and its AI Service Providers process Personal Information in the United States. Our corporate group is headquartered in Australia; limited administrative and support access from Australia may occur under the same confidentiality and security controls described in section 7 (and, for PHI, under the Business Associate Agreement).
We take reasonable steps to protect Personal Information from misuse, interference, loss, unauthorized access, modification, or disclosure. Our technical and organizational security measures include:
A more detailed description of our technical and organizational measures is set out in the Business Associate Agreement and the Data Processing Agreement that we provide to customer clinics.
No security measure is perfect. If we become aware that Personal Information has been compromised, we will respond in accordance with the HIPAA Breach Notification Rule (for PHI, supporting the responsible covered entity) and applicable state data breach notification laws, and will notify affected individuals where required.
We retain Personal Information only for as long as is necessary for the purposes for which it was collected, and in accordance with the Master Subscription Agreement, the Business Associate Agreement, and applicable law.
In particular:
We may retain de-identified or aggregated information indefinitely.
If you are a Patient of a customer clinic, your rights over your health information (access, amendment, accounting of disclosures, restriction requests) arise under HIPAA and are exercised through your clinic. Please direct your request to your clinic in the first instance; we will assist your clinic to respond, as its business associate. If we receive your request directly, we will forward it to your clinic.
If you are an Authorized User, customer, or visitor, you can ask us to access, correct, or delete the Personal Information we hold about you at the contact details in section 12. We will respond within 30 days, or such other period as is reasonable in the circumstances. We may decline requests where retention is required by law (for example, audit records); if we decline, we will give you reasons in writing.
To the extent the CCPA applies to us, California residents have the right to: know the categories and specific pieces of personal information we have collected; delete personal information (subject to exceptions); correct inaccurate personal information; opt out of sale or sharing (we do not sell or share personal information); limit the use of sensitive personal information (we use it only for the purposes permitted by the CCPA regulations); and not be discriminated against for exercising these rights. Note that information processed as PHI under HIPAA, and medical information governed by California’s Confidentiality of Medical Information Act, is exempt from the CCPA — for that information, see section 9.1. You can exercise CCPA rights at the contact details in section 12, and you may use an authorized agent; we will verify your identity before acting on a request.
You can opt out of marketing communications at any time using the unsubscribe link in the communication or by contacting us. We will continue to send transactional and service messages (for example, sign-in links and security notices).
If you have a complaint about how we have handled your Personal Information, you can contact us at the details in section 12.
We will:
If your complaint concerns health information held by your clinic, you may also complain to your clinic, or to the U.S. Department of Health and Human Services, Office for Civil Rights (hhs.gov/ocr). California residents may also contact the California Privacy Protection Agency or the California Attorney General.
We use cookies and similar technologies on our websites for purposes including:
You can disable cookies in your browser, but some features of our websites may not function correctly without them.
We use a limited number of analytics services (for example, basic web analytics that do not combine with health information) to understand site usage. We do not use analytics services on the authenticated parts of Claro that contain Patient information, and we do not use advertising cookies or cross-context behavioral advertising on Claro.
You can contact us about this policy or about your Personal Information at:
Privacy Officer, Fresh Trading Pty Ltd (ACN 624 936 081) Email: [email protected]
For Patients, please contact your clinic in the first instance.
We may update this policy from time to time. The current version is always available on our legal pages. Material changes will be notified through Claro and (where you are a customer or Authorized User) by email to your nominated contact address.
The version date at the top of the policy will reflect the most recent update.