Privacy Policy
Last updated: 24 September 2026
1. About this policy
Radly Pty Ltd (ABN 93 698 488 407) ("we", "us", "our") operates the website radly.com.au and related services. This Privacy Policy explains how we collect, use, disclose, and protect your personal information in accordance with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
By using Radly, you consent to the collection and use of your information as described in this policy. This policy should be read alongside our Terms of Service.
2. Information we collect
We may collect the following types of personal information:
Account information: When you create an account, we collect your name, email address, phone number, and account type (patient, clinic, practitioner, or corporate). If you sign in with Google, we receive your name, email, and profile photo from Google.
Phone verification: During account creation, we may verify your phone number via a one-time SMS code. We collect and store your phone number for booking communications.
Clinic and practitioner information: If you register as a clinic or practitioner, we collect your practice name, address, phone number, specialties, qualifications, AHPRA number, photos, operating hours, billing information (bulk billing, health funds accepted), and other professional details you provide.
Corporate account information: If you manage clinics as a corporate group, we collect your name, email, role, and corporate group affiliation. Corporate users have access to booking requests and patient contact details for clinics within their group.
Booking request information: When you submit a booking request (whether as a registered user or as a guest), we collect the details you provide including your full name, email address, phone number, preferred scan type, preferred date and time, and any notes you include.
Guest booking data: If you submit a booking request without creating an account, we collect the same information listed above. Your data is stored in the same manner as registered user bookings and is shared with the selected imaging clinic so they can organise your appointment. Guest bookings are not linked to a Radly account at the time of booking; if you later create an account using the same verified email address or SMS-verified mobile number, your guest bookings are linked to that account so you can track them. We also collect your IP address for rate-limiting and spam-prevention purposes; IP addresses are not shared with clinics and are not retained beyond the rate-limiting window.
Uploaded referral documents: When you upload a physical referral letter (as an image or PDF) during the booking process, the file is stored securely in Firebase Storage (Google Cloud Platform). Uploaded referral documents may contain sensitive health information including your name, date of birth, Medicare number, referring doctor details, and clinical notes. These files are encrypted at rest and in transit, and access is restricted to your account and the imaging clinic you select. The referral document is also attached directly to the booking notification email sent to the clinic, allowing them to process your referral immediately. If you book without a referral attached, we send you a secure, single-use upload link by SMS and email; referrals uploaded through that link are handled in exactly the same way, and the link expires after 7 days or once your referral has been received.
Google Business data: When a clinic claims or registers their profile on Radly, we retrieve publicly available information from Google Maps and Google Business Profile, including Google reviews and ratings, business operating hours, address, phone number, and website. This data is used to enrich clinic profiles and provide patients with accurate information.
Usage information: We automatically collect information about how you use our website, including pages visited, search queries, browser type, device type, IP address, and referring URLs. We use cookies and similar technologies for this purpose.
Location information: With your permission, we may collect your approximate location to show nearby imaging clinics. You can decline or revoke location access at any time through your browser settings.
3. How we use your information
We use your personal information to:
- Provide and improve the Radly platform and services
- Create and manage your account
- Verify your identity and phone number for booking security
- Process and transmit booking requests to imaging clinics, including sending your details and referral documents to the clinic via email
- Send you booking confirmations, appointment reminders, and relevant notifications via email and SMS
- Show you imaging clinics and services relevant to your location and search
- Enable clinics, corporate groups, and practitioners to receive and respond to patient enquiries
- Analyse usage patterns to improve our website and services
- Comply with legal obligations
- Protect against fraud and misuse of the platform
We will not use your personal information for direct marketing without your consent. We will never sell your personal information to third parties.
4. How we share your information
We may share your personal information with:
- Imaging clinics: When you submit a booking request, your name, email, phone number, scan type, preferred date/time, notes, and any uploaded referral documents are shared with the selected clinic so they can respond to your request. Referral documents are attached directly to the email notification sent to the clinic. The clinic is an independent third party - once your information is shared, the clinic is independently responsible for the security and handling of that information under applicable privacy laws.
- Corporate group administrators: If the clinic you select is part of a corporate imaging group, your booking request details may also be visible to authorised corporate administrators who manage that clinic.
- Practitioners: When a practitioner submits a referral, the referral details are shared with the patient and the selected clinic.
- Service providers: We use the following third-party service providers who may process your data on our behalf:
- Google Cloud Platform / Firebase - authentication, database (Firestore), phone-number verification (Firebase Auth), and file storage (Firebase Storage) for uploaded referral documents. Our primary Firestore database and referral-file storage are hosted in Google Cloud's Australian region (australia-southeast1, Sydney). Firebase Authentication processes authentication records — including your email address, phone number, display name and password hashes (not plaintext passwords) — exclusively in Google's United States data centres. Google does not offer an Australian region for Firebase Authentication.
- Vercel - website hosting and serverless API functions. Function execution is configured for Vercel's Sydney region. Vercel may also keep platform logs and cached copies of public pages on its global infrastructure.
- Microsoft Azure OpenAI Service - reads referral images when you choose to use Ron, our optional referral reader. Hosted as a regional deployment in Microsoft's Australia East region (New South Wales), so the image is processed in Australia. Microsoft's published terms state that prompts and completions are not used to train generative AI foundation models without permission (see section 5A).
- Resend - transactional email delivery. Emails we send — including booking notifications to clinics — are processed and stored by Resend in the United States. Current clinic emails can include the patient's name, contact details, date of birth and other booking information, and may attach the referral document. Where a referral is attached to an email, that attachment is also handled by Resend and by the recipient's email system. Resend's published retention for standard plans is 30 days for email content and logs. A secure-link delivery option exists in our systems but is not universally active; many clinic emails, including IDX booking emails, still attach the referral file.
- Twilio - SMS delivery for booking notifications, reminders, upload links and phone verification. Your mobile number and the text of the SMS are processed in Twilio's default United States region (US1). We have not configured a non-US Twilio region. We have not verified a specific Twilio retention period for these messages.
- Google Maps / Places API - clinic location data and reviews.
- Google Calendar - if a clinic connects Google Calendar, we write the patient's name, email, phone number and visit reason into an event on that clinic's Google account. Where that account stores data is controlled by the clinic and Google, not by Radly.
- Firebase Cloud Messaging - device push notifications that include the scan type and clinic name. Google operates this service on its global infrastructure.
- Radly support mailbox (support@radly.com.au) - some signup details and, when a founder notification setting is on, guest-booking summaries are also emailed to this address. Those messages go through Resend. We have not verified where the mailbox itself is hosted.
- PostHog - website usage analytics and session replay (pages visited, clicks, device type, approximate location), hosted in PostHog's EU region (Frankfurt, Germany). Session replay masks form inputs, so names, dates of birth, Medicare numbers and referral text you type are not recorded in the replay. Masking does not stop custom events. When a booking is saved, our code sends PostHog a
booking_submittedevent that can include the clinic name, scan type, clinic ID and appointment ID, unless an analytics guard blocks the session (for example an internal-tester flag or a private path). We have not separately verified production PostHog payloads in this review; the wording matches that code path. - Google Analytics / Google Ads - website traffic and conversion measurement, processed by Google and may be stored outside Australia. A successful booking can send Google Analytics the clinic name and scan type, and can send Google Ads a conversion that includes a value and the appointment ID. Internal-tester and research sessions are excluded from those Google events.
- Legal requirements: We may disclose information if required by law, regulation, legal process, or government request.
5. Sensitive and health information
Radly may collect limited sensitive health information in the course of facilitating bookings and referrals. This includes:
- The type of imaging scan requested (e.g. MRI, CT, X-ray, ultrasound)
- Notes you provide about your condition or reason for the scan
- Clinical notes or reason for referral provided by referring practitioners
- Uploaded referral documents that may contain health details, Medicare numbers, and clinical information written by your doctor
We follow a principle of data minimisation. We only collect information that is necessary to facilitate your booking or referral:
- We do not collect full medical histories or clinical records beyond what you or your doctor provide in the booking request or referral
- We do not access, analyse, interpret, or use the clinical content of uploaded referral documents for any purpose other than transmitting them to your selected clinic, except where you choose to use Ron to read a referral for clinic matching (see section 5A)
- We do not use referral documents or clinical notes for advertising. We may send the clinic name and scan type to analytics tools, and an appointment ID to Google Ads, as described in sections 4 and 9
- Uploaded referral files are stored in user-scoped paths. Your signed-in account can read its own files under Firebase Storage rules. Clinic staff, corporate admins and Radly operators can open a file through Radly's authenticated download service after we check their link to that booking. Some files can also be opened with a signed or tokenised URL that does not require a Radly login — including older records that still store a Firebase download URL, and Aperture staff uploads that receive a long-lived signed URL. The selected clinic also currently receives a copy as an email attachment (see section 6)
Collection and handling of sensitive health information is done with your explicit consent, provided when you submit a booking request and agree to the consent checkbox on the booking form. Where a referring practitioner submits a digital referral on your behalf, the practitioner must confirm at the time of submission that they have obtained your consent to share your personal and health information with Radly and the selected clinic.
5A. Ron — optional referral reading
Ron is Radly's optional referral reader. If you choose to use Ron, you upload a photo or scan of your imaging referral so Ron can identify the scan type and help you find matching clinics. This is separate from attaching a referral to a booking for a clinic.
- What is read: the referral image you upload. Anything visible on that image (including names or Medicare numbers) may be included in what Ron reads. You can cover personal details before photographing if you prefer — Ron only needs the scan details.
- Where it is processed: in Australia. Ron runs on Microsoft's Azure OpenAI service in the Australia East region (New South Wales), using a regional deployment so the image is processed in that Australian region. Microsoft's published terms for Azure OpenAI / Foundry Models sold by Azure state that prompts and completions are not used to train generative AI foundation models without the customer's permission (retrieved 23 September 2026). If Microsoft's automated safety systems flag a request, a sample may be held in Microsoft's abuse-monitoring store in the same Azure geography for review. We have not confirmed a modified-abuse-monitoring exemption for Radly, and Microsoft's current public documentation does not state a fixed retention period for those flagged samples. Radly does not permanently store the referral image after Ron has finished reading it.
- What we keep: scan-outcome metadata linked to your account (your account identifier, whether the read succeeded, scan type/modality, and a confidence score). We do not extract or save your name, date of birth, or Medicare number from the image. This metadata is linkable to your account and is deleted when you delete your Radly account. You may also ask us to delete it earlier.
- Not medical advice: Ron's reading is to help you find relevant clinics. Your imaging clinic verifies your referral and confirms the correct scan at your appointment.
Using Ron is optional. You can always search and book without it, and attach your referral directly to a clinic booking instead.
6. Data storage and security
Our primary application database and referral-file storage are hosted in Sydney, Australia (Google Cloud region australia-southeast1). Some personal and health information is also processed or stored overseas through supporting services, including authentication and email delivery. Where referral documents are attached to emails, those attachments are also handled by our email provider and recipients' email systems.
Firebase Authentication processes sign-in records in the United States. Resend processes and stores the content of emails we send in the United States. Twilio processes SMS in its default United States region. Our website and API functions run on Vercel in Sydney; Vercel may also keep platform logs and cached copies of public pages on its global infrastructure. Website usage analytics are processed separately by PostHog (European Union) and Google Analytics (see sections 4 and 9). Those tools do not receive form contents or referral files; they can receive clinic name, scan type and appointment ID on a saved booking.
Uploaded referral documents are stored in Firebase Storage in Sydney, which provides encryption at rest using AES-256 and encryption in transit using TLS. Each uploaded file is stored under a user-scoped path. Firebase Security Rules let the uploading patient's signed-in account read that path. Clinic staff, corporate admins and Radly operators can open the file through an authenticated server-side download after we check their connection to the booking. That is not the only way a file can be opened: older records may still store a Firebase download URL with an access token, and Aperture staff uploads are issued a long-lived signed URL. Anyone who has one of those links can fetch the file without signing into Radly. Storage in Sydney does not mean the file stays only in Australia: a copy may still be emailed overseas, as described below.
Referral documents sent to clinics are, in the current live configuration, attached directly to the booking notification email via Resend. Email transmissions use TLS encryption where supported by the receiving mail server. A secure download link exists in our systems but is not universally active, and IDX clinic emails still attach the file.
We implement the following security measures across the platform:
- HTTPS/TLS encryption for all data in transit
- AES-256 encryption at rest for all stored data (Google Cloud)
- User-scoped storage paths with Firebase Security Rules for uploaded documents
- File type validation (images and PDF only) and size limits on all uploads
- Phone number verification via SMS when you create a Radly account
- Role-based access control (patients, clinics, practitioners, corporate admins, platform admins)
- Secure authentication with email and phone verification
- No plaintext storage of passwords (Firebase Authentication stores password hashes)
- Audit logging of referral-document downloads and key corporate account actions
However, no method of internet transmission or electronic storage is 100% secure. We cannot guarantee absolute security. Radly is not liable for unauthorised access resulting from vulnerabilities in third-party infrastructure that are outside our reasonable control.
7. Data breach notification
In the event of a data breach that is likely to result in serious harm, we will comply with the Notifiable Data Breaches (NDB) scheme under the Privacy Act 1988. This means we will:
- Take immediate steps to contain the breach and reduce harm
- Assess whether the breach is likely to result in serious harm
- Notify affected individuals as soon as practicable
- Notify the Office of the Australian Information Commissioner (OAIC) if required
8. Data retention
We keep each category of personal information only while it is needed for the purpose we collected it, then we delete or de-identify it, unless a law requires us to keep it longer. Asking us to delete something is an extra right, not the reason we keep it. The periods below are purpose-based. They are not a 30-day or 12-month clock.
- Account and login records: Needed to run your account. We delete them from our live systems when you close the account. Google's documentation states that remaining Firebase Authentication records are then removed from its live and backup systems within 180 days.
- Booking records: Needed to send the request to the clinic and to operate that booking. While a booking is still being processed, we keep the details the clinic needs. After it has concluded (for example confirmed, completed or cancelled) we no longer need identifiable guest details for that purpose — those records are to be de-identified. If you have an account, we keep your booking history so you can track it, and we de-identify it when you delete the account (that path already runs). Automated de-identification of concluded guest bookings is not yet running, so those identifiable guest records still sit in live storage. That is a gap against this rule, not a decision to keep them indefinitely.
- Referral files — guest bookings: Needed only to deliver that booking. After the booking has concluded we no longer need the file in Radly storage. A deletion job for concluded guest files is written but not switched on, so those files still remain. That is a gap against this rule. You may also ask us to delete a file earlier.
- Referral files — account holders: Needed so you can reuse them for later bookings while your account is active. We delete them from live storage when you delete your account or ask us to delete a file.
- Ron scan-outcome metadata: Needed to operate the optional referral reader. We keep the account-linked outcome record described in section 5A. These records are deleted when you delete your Radly account. You may also ask us to delete them earlier.
- Digital referrals created by practitioners: Deleting your Radly account does not delete or alter referrals held in the practitioner portal. These may include your identifying details, clinical notes and practitioner-uploaded documents. Contact support@radly.com.au about access, correction or deletion requests for these records so we can assess the request with the practitioner and applicable retention requirements. These records currently have no automatic expiry; we are reviewing the applicable retention periods. This is not a policy of keeping them indefinitely.
- Account access restrictions: After account deletion we retain a restricted record of the deleted account ID and a timestamp to prevent its old credentials accessing retained practitioner referrals. This record contains no name, email or clinical content. Its retention period is also under review.
- Phone verification data: Needed with your account while the account is active.
- Reviews: Needed while the review is published. We remove your name from the public review when you delete your account, or earlier if you ask.
- Corporate and clinic data: Needed while the clinic or corporate account is active. Deactivated clinic profiles may be kept unpublished.
- Analytics events: Clinic name, scan type and appointment ID sent to PostHog or Google are kept according to those providers' own periods. We have not verified those periods here.
You may request early deletion of your data at any time by contacting us at support@radly.com.au. Please note that once referral documents and booking details have been shared with an imaging clinic (via email attachment or other means), Radly cannot control or delete copies held by the clinic. Our email provider also keeps a copy of messages we send, including any attachments, for its own operational period (Resend's published period for standard plans is 30 days). Radly keeps backups and recovery copies of Radly's primary database and uploaded-file storage in Sydney, Australia. These currently include: automated daily and weekly database backups (kept for 14 days and 14 weeks respectively); a rolling database point-in-time recovery window (currently 7 days); prior versions of uploaded files (kept for 30 days after a file is replaced or deleted, plus a 7-day recovery window for deleted files); and occasional manual database exports made for maintenance or testing, which do not expire automatically and are kept until we delete them. When you delete data, it stops being available in the live system, but copies may remain in these backups for the periods described above — or, for manual exports, until we delete them. Practitioner records described above remain in the live practitioner portal. Closing your account does not revoke separate referral links issued by your practitioner; those links remain subject to their expiry or revocation. We use backups to restore service after data loss or corruption; restoring them for any other purpose is not part of our normal operations.
9. Cookies and tracking
We use cookies and similar technologies to remember your preferences, analyse how our website is used, and improve your experience. We use Google Analytics and PostHog for website analytics; the usage data they collect (pages visited, clicks, device type, IP address) may be processed outside Australia (PostHog in the European Union, Google in the United States). Session replays captured by PostHog mask everything you type into forms. Custom events can still include clinic name, scan type and appointment ID when a booking is saved (see section 4). You can manage cookie settings through your browser. Disabling cookies may affect the functionality of our website.
10. Your rights
Under the Australian Privacy Principles, you have the right to:
- Access the personal information we hold about you
- Request correction of inaccurate or outdated information
- Request deletion of your account and personal data (subject to legal retention requirements)
- Request deletion of uploaded referral documents at any time
- Withdraw consent for location tracking, SMS communications, or marketing communications
- Request a copy of all personal data we hold about you in a portable format
- Lodge a complaint if you believe your privacy has been breached
To exercise any of these rights, contact us at support@radly.com.au. We will respond to your request within 30 days.
11. Automated decision-making
Radly does not use automated decision-making or profiling that produces legal or similarly significant effects on individuals. Clinic search results are based on location, services, and user preferences - not on automated health assessments or clinical profiling.
12. Children's privacy
Radly is not intended for use by children under 16. We do not knowingly collect personal information from children under 16. Booking requests for minors should be submitted by a parent or legal guardian.
If you believe a child under 16 has provided us with personal information without parental consent, please contact us and we will delete it promptly.
13. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email or a prominent notice on the platform. Changes will be posted on this page with an updated "last updated" date. Your continued use of Radly after changes are posted constitutes acceptance of the updated policy.
14. Contact us and complaints
If you have any questions about this Privacy Policy, how we handle your personal information, or wish to make a privacy complaint, please contact us:
Privacy Officer
Email: support@radly.com.au
Website: radly.com.au
We will acknowledge your complaint within 5 business days and aim to resolve it within 30 days.
If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au or call 1300 363 992.