Privacy Policy

Last updated: 15 June 2026 · UpHealth Services Pty Ltd (ABN 19 676 532 960)

GPConsent (“we”, “us”) is operated by UpHealth Services Pty Ltd. We handle personal and health information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

What we collect. Practice and user account details; and, on behalf of your practice, patient/resident information needed to capture Medicare Assignment of Benefit consent (name, Medicare number, provider details, MBS items, signature and consent metadata).

How we use it. Solely to provide the consent-capture, retention and billing-export service to your practice. We do not sell personal information or use it for advertising.

Where it’s stored (APP 8). All data is hosted in Australia (Supabase, Sydney ap-southeast-2). Each practice’s data is isolated by database Row-Level Security.

Security (APP 11). Data is encrypted in transit and at rest, access is role-based, and consent actions are recorded in an audit log. Consents are retained for the mandatory two years.

Your practice is the controller. For patient information captured in GPConsent, your practice is responsible as the treating provider; we act as the processor on your instructions.

Access, correction & complaints. Contact hello@gpconsent.com.au to access or correct information, or to raise a privacy concern. Unresolved concerns can be referred to the OAIC.

This summary is provided for transparency and is not legal advice. Practices should confirm their own privacy and breach-response obligations with their adviser.