Privacy Policy

SSapp’s adherence to New Zealand’s Health Information Privacy Code 2020 and Privacy Act 2020

Effective date: 2 April 2026

Who we are and how SSapp fits

SSapp is a clinical tool used by audiologists to turn shorthand into structured notes (Magic Notes), generate referral letters (Referral Letters), and ask point‑of‑care clinical questions (Chat to Me). SSapp is designed to be ephemeral by default and to minimise personally identifiable information in processing. When SSapp is used by a clinic, the clinic remains the New Zealand “health agency” and data controller; SSapp and its infrastructure providers act as data processors under the clinic’s instructions.

Jump to: New ZealandAustralia

Responsibility and allocation of roles

Clinics and clinicians are responsible for what they enter into SSapp and for meeting their obligations under New Zealand’s Health Information Privacy Code 2020 and Privacy Act 2020. SSapp provides privacy‑protective defaults and guidance, but the clinic must ensure that unnecessary personally identifying information is omitted from prompts and drafts, and that final outputs are reviewed and filed correctly in the PMS/EHR. SSapp cannot accept liability for any disclosure or misuse arising from identifiers or patient details supplied by a clinic or clinician, or for failures to follow clinic policy and best practice.

What information we process

SSapp processes health information as defined in New Zealand’s Health Information Privacy Code 2020 (for example, clinical observations, assessment notes, referral details). Inputs originate from a clinician and relate to a specific patient encounter; SSapp does not collect information directly from patients. Magic Notes and Referral Letters operate solely on the clinician’s text; Chat to Me operates on clinician queries plus a small rolling context to improve immediate relevance.

Purposes and limits on use

We process health information only to provide the features the clinician invokes: creating structured notes, generating referral letters, and answering clinical questions. These purposes are directly related to documentation and care delivery, consistent with HIPC Rule 1 and Rule 10 and Privacy Act IPP 1 and IPP 10. We do not use health information for model training or marketing; OpenAI API data‑use for training is explicitly disabled on our keys.

Collection and transparency

Information is collected from the clinician user and relates to their patient (HIPC Rule 2 and Rule 3/3A; IPP 2 and IPP 3). Clinics remain responsible for informing patients that overseas processors may be used to deliver SSapp’s functions, and that patients have rights of access and correction. SSapp does not provide a privacy notice template; clinics must maintain their own notices and consent processes.

Accuracy and clinician verification

Clinicians must review and verify AI‑generated content before it is saved to the patient record or disclosed (HIPC Rule 8; IPP 8). SSapp presents draft outputs and requires human confirmation for clinical notes and referral letters. This helps ensure information is accurate, up‑to‑date, complete, relevant, and not misleading before use or disclosure.

Storage, security, and confidentiality

SSapp applies encryption in transit and at rest, strict access controls, and environment isolation proportionate to health information sensitivity (HIPC Rule 5; IPP 5). We minimise operational logs and avoid logging payload bodies that could contain health information. SSapp does not record audio and does not include any audio capture features.

Retention and deletion

SSapp is not a system of record. Magic Notes and Referral Letters are ephemeral in‑app; drafts exist only during the session unless the clinician exports them to the clinic’s PMS/EHR, where standard clinical retention periods apply (HIPC Rule 9; IPP 9). Chat to Me maintains a short rolling working memory across recent conversations to make the tool more helpful in context; the memory is session‑scoped and is wiped on exit. Certain providers may retain operational anti‑abuse telemetry briefly (for example, OpenAI’s 30‑day retention) and then delete it.

Overseas disclosures and comparable safeguards

SSapp uses reputable processors that provide safeguards comparable to New Zealand law through recognised frameworks and contractual terms (HIPC Rule 12; IPP 12). Cloudflare relies on Data Privacy Framework certifications and SCCs/CBPR for cross‑border transfers. Railway is certified under the Data Privacy Framework and uses SCCs where applicable. Supabase offers region selection and SCCs for EU/UK transfers. OpenAI offers GDPR‑aligned contractual safeguards with model‑training disabled. Chroma Cloud hosts a vector database for general audiology knowledge; it stores no patient content for embeddings and relies on SCCs for cross‑border transfers.

Data minimisation and scope of embeddings

SSapp encourages clinicians to remove direct identifiers unless necessary for the task at hand. Embeddings used by Chat to Me are limited to New Zealand‑relevant audiology sources such as NZAS best practice guidelines, manufacturer product information, funding information, and general medical audiology and technical hearing aid/test information. Embeddings do not include patient notes or patient‑specific content.

Disclosure and sharing

SSapp discloses information only to deliver the services requested by the clinician or as required by law (HIPC Rule 11; IPP 11). Typical recipients are the clinic’s own systems (for example, PMS/EHR) and the nominated recipient of a referral letter under the clinic’s authority. We do not sell personal information or permit processors to use it for their own marketing.

Unique identifiers

SSapp does not assign unique identifiers to patients (HIPC Rule 13; IPP 13). If a clinic includes an NHI or other identifier in an input or template, it is used solely for the documentation or referral purpose and is not repurposed.

Cookies and authentication

We do not use analytics or marketing cookies in the clinical app. SSapp uses a strictly necessary JWT access token (access_token) to authenticate the request; in SSR contexts (for example, SvelteKit using Supabase helpers) this JWT may be stored in secure, HTTP‑only, same‑site cookies so the server can call Supabase with the correct identity. No other cookies are set by SSapp.

Your rights of access and correction

Patients have the right to request access to and correction of their health information held by the clinic (HIPC Rule 6 and Rule 7; IPP 6 and IPP 7). Because SSapp is a processor, clinics should direct requests through their privacy officer, who can retrieve any transient SSapp artefacts if still available and applicable. SSapp assists clinics to respond promptly to valid requests.

Notifiable privacy breaches

If a privacy breach occurs that is likely to cause serious harm, the clinic (as controller) will notify the Office of the Privacy Commissioner and affected individuals as soon as practicable (Privacy Act 2020, Part 6). SSapp maintains an incident response plan, supports clinics in assessment and containment, and cooperates with breach notifications.

Subprocessors and transfer mechanisms

Our primary processors today are Cloudflare (edge/security/CDN), Railway (application hosting), Supabase (authentication, customer account and subscription data), OpenAI (inference with training disabled), Chroma Cloud (vector store of audiology knowledge only), and Stripe (payments processing; credit card data handled by Stripe, not by SSapp). All are engaged under contractual terms that include confidentiality, security obligations, and recognised cross‑border safeguards such as the Data Privacy Framework and/or Standard Contractual Clauses. Stripe’s privacy policy: https://stripe.com/privacy

Record retention and clinical records

SSapp is not a system of record. Clinicians export finalised notes and letters to the clinic’s PMS/EHR, where the clinic’s standard clinical retention periods apply. SSapp’s ephemeral design avoids unnecessary duplication and long‑term storage outside the clinic’s records.

Children and sensitive contexts

SSapp is a professional tool for clinicians and is not directed to children. Clinics should avoid entering superfluous sensitive details not necessary for clinical documentation or referral.

Updates to this privacy subsection

We may update this subsection to reflect changes in law, processors, or technical safeguards. Material changes will be highlighted in‑app or on our website, and the effective date will be updated.

Who to contact

For questions or to exercise rights of access or correction, please contact your clinic’s privacy officer in the first instance. If you need to contact SSapp about privacy or security, email support@shockinglysimple.app and we will coordinate with your clinic to support your request.

Summary of how SSapp meets New Zealand’s Health Information Privacy Code 2020 and Privacy Act 2020

We collect only what is necessary for clinical documentation and referral, from the clinician, for lawful and related purposes. We require clinician verification of accuracy before use or disclosure, minimise storage, and delete transient data according to short retention windows. We disclose overseas only to vetted processors with comparable safeguards and contractually limit processing to your instructions. We assist clinics with patient rights requests and notifiable breach obligations, and we maintain robust technical and organisational controls proportionate to the sensitivity of health information.

Appendix A: Definitions and abbreviations

  • Audiologists means MNZAS full members using SSapp in clinical practice.
  • The clinic means the clinic that the user works in while using SSapp; the clinic is the health agency and data controller.
  • New Zealand Health Information Privacy Code 2020 (HIPC) is the code issued under section 32 of the New Zealand Privacy Act 2020 that modifies the IPPs for health information.
  • New Zealand Privacy Act 2020 is the statute governing personal information in New Zealand, including IPPs, notifiable breaches, and codes of practice.
  • PMS means Practice Management System.
  • EHR means Electronic Health Record.
  • Chat to Me is SSapp’s clinical Q&A feature.
  • Magic Notes is SSapp’s note generation feature.
  • Referral Letters is SSapp’s referral generation feature.
  • RAG means Retrieval‑Augmented Generation, a technique for answering questions using a curated knowledge base; in SSapp this feature is presented as Chat to Me.
  • OpenAI retention policy refers to OpenAI’s 30‑day anti‑abuse operational retention for API requests and responses, with model training disabled on SSapp API keys.
  • DPA means Data Processing Addendum.
  • SCCs means Standard Contractual Clauses.
  • DPF means Data Privacy Framework.
  • CBPR means Global Cross‑Border Privacy Rules.
  • MNZAS means New Zealand Audiological Society (full membership).
  • NHI means National Health Index number.
  • JWT means JSON Web Token.
  • SSR means server‑side rendering.

SSapp’s adherence to Australia’s Privacy Act 1988 and Australian Privacy Principles (APPs)

Effective date: 2 April 2026

Who we are and how SSapp fits (Australia)

SSapp provides Magic Notes, Referral Letters, and Chat to Me to support clinicians. SSapp is designed to minimise identifiable data and to process ephemerally. When used by a clinic, the clinic remains the data controller; SSapp and its infrastructure providers act as processors under the clinic’s instructions. To the extent SSapp carries on business in Australia, the Privacy Act 1988 (Cth) and the APPs apply.

Responsibility and allocation of roles (APP 1)

The clinic is responsible for lawful collection, notices, and consents; for omitting unnecessary identifiers from prompts; and for verifying and filing outputs in the PMS/EHR. SSapp provides privacy‑protective defaults, purpose‑limited processing, and security aligned with APP 1 and clinic instructions.

What information we process

SSapp processes clinician‑entered health information related to a patient encounter (for example, shorthand notes, referral details, clinical observations). SSapp does not collect information directly from patients. Magic Notes/Referral Letters operate on clinician text; Chat to Me operates on clinician queries plus short rolling session context.

Purposes and limits on use (APP 6)

Processing is limited to providing the requested features: structured notes, referral letters, and clinical Q&A. We do not use clinical inputs for model training or marketing; OpenAI training is disabled on our API keys. Disclosures occur only as needed to deliver the Service or as required by law.

Collection and transparency (APP 3 and APP 5)

Information is provided by the clinician and relates to their patient. The clinic remains responsible for informing patients of overseas processing and their rights. SSapp does not provide patient‑facing notices; clinics maintain their own privacy notices and consent processes.

Accuracy and clinician verification (APP 10)

Clinicians must review and verify AI‑generated content before use or disclosure. SSapp presents drafts for human confirmation to help ensure information is accurate, up‑to‑date, complete, relevant, and not misleading.

Storage, security, and confidentiality (APP 11)

We apply encryption in transit and at rest, access controls, and environment isolation. Operational logs are minimised and avoid payload bodies. SSapp does not record audio and includes no audio capture features. We take reasonable steps to destroy or de‑identify information that is no longer needed for Service delivery, subject to legal obligations.

Retention and deletion

SSapp is not a system of record. Drafts are session‑scoped and ephemeral unless exported by the clinician to the PMS/EHR. Chat to Me uses a short rolling memory within the session and wipes on exit. Certain providers may retain brief operational anti‑abuse telemetry (for example, OpenAI’s 30‑day retention).

Overseas disclosures and comparable safeguards (APP 8 and s 16C)

We use subprocessors with recognised cross‑border safeguards (for example, DPF/SCCs/CBPR). We take reasonable steps to help ensure overseas recipients protect personal information in a way substantially similar to the APPs. Where APP 8.1 applies, the clinic acknowledges overseas disclosures may occur to deliver SSapp.

Data minimisation and scope of embeddings

Clinicians should remove direct identifiers unless necessary for the task. Embeddings are limited to audiology knowledge sources (for example, NZAS guidance, manufacturer and funding information, general medical audiology and technical materials) and exclude patient notes or patient‑specific content.

Disclosure and sharing (APP 6)

Disclosures are limited to Service delivery or legal requirements. Typical recipients are the clinic’s own systems (for example, PMS/EHR) and the nominated recipient of a referral letter under the clinic’s authority. We do not sell personal information or allow processors to market to you using it.

Unique identifiers (APP 9)

SSapp does not adopt government identifiers as our own. If a clinic includes an identifier such as an IHI/Medicare number in an input or template, it is used only for documentation or referral purposes and not repurposed.

Cookies and authentication

SSapp does not use analytics or marketing cookies in the clinical app. A necessary JWT may be stored in secure, HTTP‑only, same‑site cookies in SSR contexts to authenticate server calls to Supabase. No other cookies are set by SSapp.

Your rights of access and correction (APP 12 and APP 13)

Patients can request access to and correction of their information via the clinic. SSapp, acting as a processor, assists clinics with valid requests and with timely responses.

Notifiable Data Breaches (Part IIIC)

We promptly assess suspected incidents and aim to complete assessments within 30 days. We notify the clinic without undue delay and cooperate on containment. Where SSapp is the APP entity primarily responsible, we prepare the required statement and notify OAIC and affected individuals; otherwise the clinic is the default notifier and SSapp assists.

Subprocessors and transfer mechanisms

Our primary processors include Cloudflare (edge/security/CDN), Railway (application hosting), Supabase (authentication, customer account and subscription data), OpenAI (inference with training disabled), Chroma Cloud (vector store of audiology knowledge only), and Stripe (payments processing). All are engaged under confidentiality and security obligations and rely on recognised cross‑border safeguards such as the Data Privacy Framework and/or Standard Contractual Clauses. Stripe’s privacy policy: https://stripe.com/privacy

Record retention and clinical records

SSapp is not a clinical record. Clinicians export final outputs to the PMS/EHR, where standard retention applies. Ephemeral processing avoids long‑term storage outside clinic systems.

Children and sensitive contexts

SSapp is for professional clinical use and is not directed to children. Avoid entering superfluous sensitive details not necessary for documentation or referral.

Updates to this privacy subsection

We may update this subsection to reflect changes in law, processors, or safeguards. Material changes will be highlighted in‑app or on our website, and the effective date will be updated.

Who to contact

Questions or requests should be directed to the clinic’s privacy officer. To contact SSapp about privacy or security, email support@shockinglysimple.app; we will coordinate with the clinic to support your request. For Australia, guidance is also available from the Office of the Australian Information Commissioner (OAIC).

Summary of how SSapp meets Australia’s Privacy Act 1988 and APPs

We limit collection and use to documentation and referral, rely on clinician inputs, and apply purpose limitation and security aligned with APPs. We minimise storage, de‑identify or destroy information when no longer needed, assist clinics with rights requests and NDB obligations, and implement cross‑border safeguards for overseas disclosures.

Appendix B: Australian definitions and abbreviations

  • Privacy Act 1988 (Cth) — Australia’s federal privacy statute governing personal information.
  • APPs — Australian Privacy Principles set out in Schedule 1 of the Privacy Act.
  • APP entity — an agency or organisation regulated by the Privacy Act.
  • Personal information — information or an opinion about an identified individual, or an individual who is reasonably identifiable.
  • Sensitive information — a subset of personal information including health information, biometric data, etc.
  • Health information — as defined in s 6FA (for example, health status, wishes about future care, or health services provided).
  • OAIC — Office of the Australian Information Commissioner.
  • NDB — Notifiable Data Breaches scheme (Part IIIC of the Privacy Act).
  • Eligible data breach statement — the statement required under s 26WK for NDB notifications.
  • Australian link — extra‑territorial application of the Privacy Act under s 5B to entities carrying on business in Australia.
  • Cross‑border disclosure — disclosure to an overseas recipient regulated by APP 8 and s 16C.
  • Government related identifier — an identifier assigned by a government body; restrictions on adoption/use under APP 9.
  • Reasonable steps — measures required under various APPs (for example, APP 1, APP 8, APP 11) proportionate to risk and context.
  • De‑identified — information no longer about an identifiable or reasonably identifiable individual.
  • DPA — Data Processing Addendum (contractual data protection terms with customers or vendors).
  • SCCs — Standard Contractual Clauses for international data transfers.
  • DPF — Data Privacy Framework (EU/UK/Swiss‑US transfer mechanism).
  • CBPR — Global Cross‑Border Privacy Rules system.
  • Subprocessor — a third‑party processor engaged by SSapp to process personal information on behalf of clinics.
  • ACL — Australian Consumer Law (non‑excludable consumer guarantees).
  • Clinic — the health agency/data controller that instructs SSapp’s processing.
  • SSapp — the processor providing Magic Notes, Referral Letters, and Chat to Me.