Language

Privacy Policy

Last updated: 29 July 2026

1. About this policy

Radly Pty Ltd (ABN 93 698 488 407) ("we", "us", "our") operates the website radly.com.au and related services. This Privacy Policy explains how we collect, use, disclose, and protect your personal information in accordance with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

By using Radly, you consent to the collection and use of your information as described in this policy. This policy should be read alongside our Terms of Service.

2. Information we collect

We may collect the following types of personal information:

Account information: When you create an account, we collect your name, email address, phone number, and account type (patient, clinic, practitioner, or corporate). If you sign in with Google, we receive your name, email, and profile photo from Google.

Phone verification: During account creation, we may verify your phone number via a one-time SMS code. We collect and store your phone number for booking communications.

Clinic and practitioner information: If you register as a clinic or practitioner, we collect your practice name, address, phone number, specialties, qualifications, AHPRA number, photos, operating hours, billing information (bulk billing, health funds accepted), and other professional details you provide.

Corporate account information: If you manage clinics as a corporate group, we collect your name, email, role, and corporate group affiliation. Corporate users have access to booking requests and patient contact details for clinics within their group.

Booking request information: When you submit a booking request (whether as a registered user or as a guest), we collect the details you provide including your full name, email address, phone number, preferred scan type, preferred date and time, and any notes you include.

Guest booking data: If you submit a booking request without creating an account, we collect the same information listed above. Your data is stored in the same manner as registered user bookings and is shared with the selected imaging clinic so they can organise your appointment. Guest bookings are not linked to a Radly account at the time of booking; if you later create an account using the same verified email address or SMS-verified mobile number, your guest bookings are linked to that account so you can track them. We also collect your IP address for rate-limiting and spam-prevention purposes; IP addresses are not shared with clinics and are not retained beyond the rate-limiting window.

Uploaded referral documents: When you upload a physical referral letter (as an image or PDF) during the booking process, the file is stored securely in Firebase Storage (Google Cloud Platform). Uploaded referral documents may contain sensitive health information including your name, date of birth, Medicare number, referring doctor details, and clinical notes. These files are encrypted at rest and in transit, and access is restricted to your account and the imaging clinic you select. The referral document is also attached directly to the booking notification email sent to the clinic, allowing them to process your referral immediately. If you book without a referral attached, we send you a secure, single-use upload link by SMS and email; referrals uploaded through that link are handled in exactly the same way, and the link expires after 7 days or once your referral has been received.

Google Business data: When a clinic claims or registers their profile on Radly, we retrieve publicly available information from Google Maps and Google Business Profile, including Google reviews and ratings, business operating hours, address, phone number, and website. This data is used to enrich clinic profiles and provide patients with accurate information.

Usage information: We automatically collect information about how you use our website, including pages visited, search queries, browser type, device type, IP address, and referring URLs. We use cookies and similar technologies for this purpose.

Location information: With your permission, we may collect your approximate location to show nearby imaging clinics. You can decline or revoke location access at any time through your browser settings.

3. How we use your information

We use your personal information to:

  • Provide and improve the Radly platform and services
  • Create and manage your account
  • Verify your identity and phone number for booking security
  • Process and transmit booking requests to imaging clinics, including sending your details and referral documents to the clinic via email
  • Send you booking confirmations, appointment reminders, and relevant notifications via email and SMS
  • Show you imaging clinics and services relevant to your location and search
  • Enable clinics, corporate groups, and practitioners to receive and respond to patient enquiries
  • Analyse usage patterns to improve our website and services
  • Comply with legal obligations
  • Protect against fraud and misuse of the platform

We will not use your personal information for direct marketing without your consent. We will never sell your personal information to third parties.

4. How we share your information

We may share your personal information with:

  • Imaging clinics: When you submit a booking request, your name, email, phone number, scan type, preferred date/time, notes, and any uploaded referral documents are shared with the selected clinic so they can respond to your request. Referral documents are attached directly to the email notification sent to the clinic. The clinic is an independent third party - once your information is shared, the clinic is independently responsible for the security and handling of that information under applicable privacy laws.
  • Corporate group administrators: If the clinic you select is part of a corporate imaging group, your booking request details may also be visible to authorised corporate administrators who manage that clinic.
  • Practitioners: When a practitioner submits a referral, the referral details are shared with the patient and the selected clinic.
  • Service providers: We use the following third-party service providers who may process your data on our behalf:
    • Google Cloud Platform / Firebase - authentication, database (Firestore), phone number verification (Firebase Auth), and secure file storage (Firebase Storage) for uploaded referral documents. Data may be stored in Australia and the United States.
    • Vercel - website hosting and serverless API functions.
    • Resend - transactional email delivery, including booking notification emails with referral attachments sent to clinics.
    • Google Maps / Places API - clinic location data and reviews.
    • OpenAI - AI-powered referral analysis (Radly AI feature). When you use the AI Referral Analysis feature, your uploaded referral image is sent to OpenAI for processing on servers located in the United States. The whole image is transmitted, so any personal details visible on the referral (such as your name, date of birth, or Medicare number) are included in what OpenAI receives. The image is used solely to interpret the scan type and clinical details on your referral. Radly does not extract or store patient-identifying information from the analysis, and our instructions to the AI expressly prohibit it from extracting or returning patient-identifying details. OpenAI processes this data under their data processing terms and does not use API inputs to train their models. OpenAI may retain API inputs for up to 30 days for safety and abuse monitoring purposes, after which they are deleted. Radly does not permanently store the referral image after analysis - it is discarded from our servers immediately after the result is returned to you.
    These providers are bound by their own privacy obligations and data processing agreements. Radly does not sell your data to any third party.
  • Legal requirements: We may disclose information if required by law, regulation, legal process, or government request.

5. Sensitive and health information

Radly may collect limited sensitive health information in the course of facilitating bookings and referrals. This includes:

  • The type of imaging scan requested (e.g. MRI, CT, X-ray, ultrasound)
  • Notes you provide about your condition or reason for the scan
  • Clinical notes or reason for referral provided by referring practitioners
  • Uploaded referral documents that may contain health details, Medicare numbers, and clinical information written by your doctor

We follow a principle of data minimisation. We only collect information that is necessary to facilitate your booking or referral:

  • We do not collect full medical histories or clinical records beyond what you or your doctor provide in the booking request or referral
  • We do not access, analyse, interpret, or use the clinical content of uploaded referral documents for any purpose other than transmitting them to your selected clinic - except when you explicitly choose to use the Radly AI Referral Analysis feature, in which case your referral image is sent to our AI provider for interpretation (see section 5A below)
  • We do not use health information for advertising, profiling, or any purpose unrelated to facilitating your booking
  • Uploaded referral files are stored in user-scoped, authentication-gated storage paths - only your authenticated account can access the stored file directly, and the selected clinic receives it through Radly's secure, access-controlled delivery (see section 6)

Collection and handling of sensitive health information is done with your explicit consent, provided when you submit a booking request and agree to the consent checkbox on the booking form. Where a referring practitioner submits a digital referral on your behalf, the practitioner must confirm at the time of submission that they have obtained your consent to share your personal and health information with Radly and the selected clinic.

5A. Radly AI Referral Analysis

Radly offers an optional AI-powered feature that allows you to upload a photo of your doctor's referral for automated interpretation. This feature is entirely opt-in - it is only activated when you explicitly choose to use it and provide active consent before your image is sent for analysis.

What happens when you use Radly AI:

  • You upload or photograph your referral and are shown a consent screen before any processing occurs
  • After you confirm consent, your referral image is sent to OpenAI (our AI provider) for processing
  • The AI attempts to identify the scan type, body region, and clinical details from your referral
  • A structured result is returned to you with identified imaging modalities so you can search for clinics

Data handling:

  • Your referral image is transmitted in full, so any personal details written on the referral (such as your name, date of birth, Medicare number, or referring doctor details) are included in what is sent to OpenAI. If you prefer, you can cover these details before photographing your referral - Radly AI only needs the scan request details
  • OpenAI processes the image on servers located in the United States. This is a cross-border disclosure of your personal information under APP 8 (see section 6), and you consent to it when you confirm the consent checkbox before analysis
  • Radly does not permanently store the referral image after analysis - it is discarded from our servers immediately after the AI result is returned to you
  • Radly does not extract or store patient-identifying information (such as your name, date of birth, or Medicare number) from the referral analysis, and our instructions to the AI expressly prohibit it from extracting or returning these details
  • OpenAI processes the image under their API data usage policy and does not use API inputs to train their models. OpenAI may retain API inputs for up to 30 days for safety and abuse monitoring purposes, after which they are deleted
  • Access to Radly AI requires a signed-in Radly account, and usage is rate-limited to prevent misuse
  • The AI result (scan type, modality, summary) is displayed to you but is not permanently stored in your Radly account

Limitations and disclaimers:

  • Radly AI is an assistive tool - it may not always accurately interpret your referral
  • The AI result is not a medical diagnosisand does not replace your doctor's advice
  • Your imaging clinic will verify your referral at your appointment and confirm the correct scan
  • Radly does not make medical decisions for you - the choice of clinic and scan is always yours
  • If the uploaded image does not appear to be a medical referral, or if the AI cannot confidently interpret the referral, you will be notified and encouraged to try again with a clearer image or search for clinics directly

Consent:

Before your referral image is sent to our AI provider, you will be asked to actively confirm your consent via a checkbox. You may withdraw consent at any time by not proceeding with the analysis or by contacting us at support@radly.com.au. Withdrawal of consent does not affect processing that has already occurred.

6. Data storage and security

Your data is stored on servers operated by Google Firebase (Google Cloud Platform) and Vercel. These services may store data in Australia and overseas (including the United States). If you use the Radly AI Referral Analysis feature, your referral image is also processed by OpenAI on servers located in the United States (see section 5A). By using Radly, you consent to the transfer of your data to these services in accordance with APP 8 (cross-border disclosure of personal information).

Uploaded referral documentsare stored in Firebase Storage (Google Cloud Storage), which provides encryption at rest using AES-256 and encryption in transit using TLS. Each uploaded file is stored under a user-scoped path that is access-controlled by Firebase Security Rules - only the uploading patient's authenticated account can access the file directly. Authorised clinic staff access referral documents through Radly's authenticated, server-side download service, which verifies their identity and their connection to the booking before releasing the file.

Referral documents sent to clinics are attached directly to the booking notification email via our email provider (Resend). Email transmissions use TLS encryption where supported by the receiving mail server.

We implement the following security measures across the platform:

  • HTTPS/TLS encryption for all data in transit
  • AES-256 encryption at rest for all stored data (Google Cloud)
  • User-scoped storage paths with Firebase Security Rules for uploaded documents
  • File type validation (images and PDF only) and size limits on all uploads
  • Phone number verification via SMS when you create a Radly account
  • Role-based access control (patients, clinics, practitioners, corporate admins, platform admins)
  • Secure authentication with email and phone verification
  • Automatic session expiry
  • No plaintext storage of sensitive credentials
  • Audit logging of administrative and corporate actions

However, no method of internet transmission or electronic storage is 100% secure. We cannot guarantee absolute security. Radly is not liable for unauthorised access resulting from vulnerabilities in third-party infrastructure that are outside our reasonable control.

7. Data breach notification

In the event of a data breach that is likely to result in serious harm, we will comply with the Notifiable Data Breaches (NDB) scheme under the Privacy Act 1988. This means we will:

  • Take immediate steps to contain the breach and reduce harm
  • Assess whether the breach is likely to result in serious harm
  • Notify affected individuals as soon as practicable
  • Notify the Office of the Australian Information Commissioner (OAIC) if required

8. Data retention

We retain your personal information for the following periods:

  • Account information: Retained for as long as your account is active. You may request deletion at any time.
  • Booking request data: Retained for operational and compliance purposes. Personal identifiers are removed from booking records when you delete your account, and you may request deletion of your booking data at any time.
  • Referral documents - guest bookings: Automatically and permanently deleted from our storage systems approximately 30 days after your booking concludes (is confirmed, completed, or cancelled). Referrals attached to bookings that are still awaiting a clinic response are kept so the clinic can process your request.
  • Referral documents - account holders: Retained while your account is active so you can reuse them for future bookings. You may request deletion of individual referral documents at any time, and all of your referral documents are permanently deleted when you delete your account.
  • Digital referrals (GP-submitted): Retained while relevant for booking purposes; patient details are anonymised when the patient deletes their Radly account.
  • Phone verification data: Your verified phone number is retained with your account for as long as your account is active.
  • Reviews: Retained for as long as your account is active or until you request deletion.
  • Corporate and clinic data: Clinic profiles and corporate account data are retained for as long as the account is active. Deactivated clinic profiles may be retained in an unpublished state.
  • Usage and analytics data: Retained in anonymised or aggregated form indefinitely for service improvement.

You may request early deletion of your data at any time by contacting us at support@radly.com.au. Please note that once referral documents and booking details have been shared with an imaging clinic (via email attachment or other means), Radly cannot control or delete copies held by the clinic.

9. Cookies and tracking

We use cookies and similar technologies to remember your preferences, analyse how our website is used, and improve your experience. You can manage cookie settings through your browser. Disabling cookies may affect the functionality of our website.

10. Your rights

Under the Australian Privacy Principles, you have the right to:

  • Access the personal information we hold about you
  • Request correction of inaccurate or outdated information
  • Request deletion of your account and personal data (subject to legal retention requirements)
  • Request deletion of uploaded referral documents at any time
  • Withdraw consent for location tracking, SMS communications, or marketing communications
  • Request a copy of all personal data we hold about you in a portable format
  • Lodge a complaint if you believe your privacy has been breached

To exercise any of these rights, contact us at support@radly.com.au. We will respond to your request within 30 days.

11. Automated decision-making

Radly does not use automated decision-making or profiling that produces legal or similarly significant effects on individuals. Clinic search results are based on location, services, and user preferences - not on automated health assessments or clinical profiling.

12. Children's privacy

Radly is not intended for use by children under 16. We do not knowingly collect personal information from children under 16. Booking requests for minors should be submitted by a parent or legal guardian.

If you believe a child under 16 has provided us with personal information without parental consent, please contact us and we will delete it promptly.

13. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email or a prominent notice on the platform. Changes will be posted on this page with an updated "last updated" date. Your continued use of Radly after changes are posted constitutes acceptance of the updated policy.

14. Contact us and complaints

If you have any questions about this Privacy Policy, how we handle your personal information, or wish to make a privacy complaint, please contact us:

Privacy Officer
Email: support@radly.com.au

Website: radly.com.au

We will acknowledge your complaint within 5 business days and aim to resolve it within 30 days.

If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au or call 1300 363 992.