01 · Scope
About this Privacy Policy
This Privacy Policy applies to https://notly.ai, related Notly.ai webpages, product enquiries, demos, support communications, and the Notly.ai software platform, including ambient AI clinical documentation, note generation, referral letter support, discharge summary support, coding prompts, team workflows, and related services.
In this Privacy Policy, Notly.ai, we, us, and our refer to the Notly.ai service operated by isim.ai Pty Ltd, unless another legal entity is specified in a signed agreement.
This Privacy Policy explains the kinds of personal information we collect and hold, how we collect and hold it, why we use and disclose it, how individuals may request access or correction, and how privacy questions or complaints may be made.
Clinical data caution: Notly.ai is designed for clinician-controlled documentation workflows. Do not submit patient information through public website forms, demo forms, chat widgets, or general email.
02 · Our role
Visitors, customers, authorised users, and patients
This Privacy Policy applies to people who visit the Website, request information, subscribe to updates, contact us, create an account, use the platform, or otherwise interact with Notly.ai.
Where a healthcare practice, hospital, clinic, company, government body, or other organisation subscribes to Notly.ai, that organisation is usually responsible for deciding what clinical information is collected and entered into Notly.ai, who may access it, and how it is used in its clinical workflow.
Notly.ai may act as a service provider, contractor, processor, or similar operational role for customer clinical data. Where this applies, we process that information to provide the service and in accordance with our agreement with the customer, applicable law, and this Privacy Policy.
Patients should direct requests about their clinical record, care, consent, or correction of clinical content to their healthcare provider.
03 · Information we collect
The kinds of information we may collect
We may collect and hold personal information that is reasonably necessary for our functions and services, including:
- Contact information: name, email address, phone number, organisation, role, specialty, practice details, and enquiry details.
- Account information: login details, user profile details, permissions, authentication information, workspace details, and account settings.
- Billing and subscription information: plan details, invoices, payment status, billing contact details, and transaction records. Card or bank details may be processed by a third-party payment provider and may not be stored directly by Notly.ai.
- Support and communications: emails, form submissions, chat messages, feedback, product requests, troubleshooting information, and support history.
- Usage and device information: IP address, browser type, operating system, device identifiers, approximate location, access times, pages viewed, features used, audit logs, diagnostics, and performance data.
- Integration information: information required to connect Notly.ai to authorised third-party systems, such as practice management systems, document systems, communication tools, or other customer-approved integrations.
04 · Clinical information
Patient, health, audio, transcript, and clinical note data
When customers or authorised users use Notly.ai for clinical documentation, they may submit or generate information that includes patient names, demographic details, consultation audio, transcripts, clinical histories, examination findings, diagnoses, medications, allergies, investigation results, procedures, referrals, discharge summaries, billing or coding prompts, and other health information.
This type of information may be sensitive information, health information, confidential information, or protected clinical information under applicable laws, professional obligations, and customer policies.
Customers and authorised users are responsible for ensuring they have appropriate authority, consent, notice, and lawful basis to record, upload, disclose, process, or use patient information in Notly.ai.
Notly.ai uses clinical information to provide the documentation service, generate and format draft outputs, support authorised workflows, maintain security, troubleshoot issues, meet contractual and legal obligations, and perform other actions requested or authorised by the customer.
Clinician control: Notly.ai may assist with drafting and structuring documentation. The treating clinician or authorised healthcare professional remains responsible for reviewing, editing, verifying, approving, and using clinical documentation.
05 · Use
How we use personal information
We may use personal information to:
- provide, operate, maintain, and improve the Website and platform;
- create, authenticate, secure, and manage accounts and workspaces;
- process clinical documentation workflows requested by customers and authorised users;
- respond to enquiries, provide support, troubleshoot issues, and send service communications;
- process subscriptions, billing, renewals, plan changes, and customer administration;
- monitor performance, reliability, security, fraud prevention, misuse, and unauthorised access;
- develop, test, evaluate, and improve features, templates, workflows, accuracy, usability, and service quality;
- send product updates, educational content, marketing communications, or event information where permitted by law, with opt-out options where required;
- comply with laws, court orders, regulatory obligations, professional obligations, and contractual commitments;
- protect the rights, safety, property, and legitimate interests of Notly.ai, customers, clinicians, patients, and others.
06 · AI
AI processing and model improvement
Notly.ai uses AI and automation to help transform authorised inputs into draft clinical documentation, summaries, letters, coding prompts, templates, and workflow outputs.
We may process prompts, transcripts, notes, edits, feedback, metadata, and usage data to provide, secure, debug, evaluate, and improve the service. Where clinical information is involved, this processing is subject to the applicable customer agreement, privacy obligations, and any relevant data processing terms.
Notly.ai does not use identifiable patient information from the platform to train public or general-purpose AI models unless this is expressly authorised by the relevant customer and permitted by applicable law.
We may use aggregated, de-identified, or anonymised information to understand service performance, improve workflows, monitor quality, and develop features, provided the information is handled so that individuals are not reasonably identifiable.
07 · Disclosure
When we may share information
We do not sell patient clinical information. We may disclose personal information where reasonably necessary to provide and operate Notly.ai, including to:
- authorised users within the relevant customer workspace or organisation;
- service providers who support hosting, storage, security, analytics, payment processing, communications, customer support, AI processing, monitoring, and business operations;
- customer-approved third-party integrations and systems;
- professional advisers, auditors, insurers, legal advisers, and compliance advisers;
- regulators, courts, law enforcement, government agencies, or other parties where required or permitted by law;
- a successor or prospective successor in connection with a merger, acquisition, financing, restructuring, sale of assets, or similar business transaction, subject to appropriate confidentiality protections;
- other parties with consent or as directed by the relevant customer or authorised user.
We require service providers who handle personal information for us to use it only for authorised purposes and to apply reasonable privacy, confidentiality, and security protections.
08 · Cookies
Cookies, analytics, and online activity
We may use cookies, pixels, local storage, web beacons, logs, analytics tools, and similar technologies to operate the Website and platform, remember preferences, maintain sessions, secure accounts, measure traffic, understand usage, improve performance, and support marketing where permitted.
The information collected may include IP address, device and browser information, pages viewed, referrer URLs, time spent, feature use, click activity, and approximate location.
You can usually configure your browser to reject or delete cookies. Some parts of the Website or platform may not work properly if cookies or similar technologies are disabled.
Third-party analytics, advertising, support, or embedded content providers may also collect information under their own privacy policies. You should review those policies where applicable.
09 · Security
How we protect information
We take reasonable technical, organisational, and contractual measures designed to protect personal information from misuse, interference, loss, unauthorised access, modification, or disclosure.
These measures may include access controls, authentication controls, encryption, audit logging, monitoring, segmentation, staff confidentiality obligations, vendor due diligence, secure development practices, backup processes, and incident response procedures.
No method of transmission or storage is completely secure. You should use secure networks, protect passwords and devices, apply appropriate access controls in your organisation, and contact us promptly if you suspect unauthorised access or misuse.
Email caution: Ordinary email and public website forms may not be appropriate for highly sensitive information.
10 · Retention
Retention, deletion, and de-identification
We retain personal information for as long as reasonably ncessary to provide the service, maintain accounts, meet contractual obligations, comply with legal and regulatory requirements, resolve disputes, enforce agreements, maintain security, and support legitimate business purposes.
Clinical information may be retained, exported, deleted, or controlled according to the customer agreement, workspace settings, retention configurations, applicable health record obligations, and instructions from the relevant customer.
Where personal information is no longer needed for a permitted purpose, we will take reasonable steps to delete, destroy, de-identify, or anonymise it, unless retention is required or permitted by law, contract, backup integrity, audit requirements, or dispute preservation obligations.
11 · Access and choices
Access, correction, communications, and complaints
You may request access to personal information we hold about you, ask us to correct inaccurate information, or raise a privacy question or complaint by contacting us at support@notly.ai.
We may need to verify your identity before responding. In some cases, we may be unable to provide access or correction where the law permits or requires refusal, where another person’s privacy would be affected, or where the relevant information is controlled by a customer healthcare organisation.
You may unsubscribe from marketing emails by using the unsubscribe link or contacting us. You cannot opt out of essential service, security, transactional, legal, or account-related communications.
If your request relates to a patient record, consultation note, clinical documentation output, or care episode controlled by a healthcare provider, we may direct you to the relevant provider.
Notly cannot access generated notes after they are created, except where limited technical access is necessary for security, compliance, support, or service operation.
Notly cannot retrieve deleted notes once they have been removed from the user’s account.
12 · Overseas disclosure
Storage, hosting, and overseas recipients
Notly.ai may use cloud hosting, infrastructure, AI processing, analytics, support, security, and business service providers located in Australia.
As Notly.ai expands into other countries, we intend to support local data residency so that customer data is processed and stored in the country or region where the service is provided, where technically and legally available.
Personal information is stored, accessed, or processed inside the country where it is collected. The countries may include Australia, the United States, United Kingdom and other locations where our approved service providers operate.
13 · Children
Children and minors
The public Website is not directed to children. We do not knowingly collect personal information directly from children through the public Website without appropriate consent.
Clinical information about children or minors may be processed through the platform only where submitted by an authorised healthcare provider or customer in connection with their clinical workflow and applicable consent, notice, and legal obligations.
If you believe a child has provided personal information to Notly.ai through the public Website without appropriate consent, please contact us so we can review and take appropriate steps.
14 · Policy updates
Changes to this Privacy Policy
We may update this Privacy Policy from time to time. The updated version will be posted on the Website with a new effective date.
Where required by law or contract, we may provide additional notice of material changes. Continued use of the Website or platform after an updated Privacy Policy is posted means the updated policy applies from its effective date.
15 · Contact
Contact Notly.ai about privacy
For privacy questions, access or correction requests, data handling questions, or privacy complaints, contact Notly.ai using the details below.