This policy applies to Allied Orbit and its related entities and operations in New Zealand, Australia, the Philippines, and South Africa (together, "Allied Orbit", "we", "us", "our").
Allied Orbit is a diagnostic-led healthcare operational advisory. We design, build and operate Human-AI blended workforce functions for healthcare practices across Australia and New Zealand, combining governed AI, automation and specialist remote professionals. Because our work touches patient and practice information, confidentiality and data security are fundamental to how we operate, not an afterthought. This policy explains what information we collect, why, how we protect it, where it is processed, and the rights you have in relation to it.
We design and audit our privacy and security controls against the following instruments:
Where we handle patient information on behalf of a practice, the practice remains the health agency (NZ) or APP entity (AU) for that information. We act as a governed service provider under formal data handling agreements, and in some circumstances we are ourselves directly subject to the Australian Privacy Act as an organisation holding health information in the course of providing a health service. We accept that accountability expressly.
The information we hold falls into four groups.
Enquiry and diagnostic information. When you complete a contact form, Friction Triage, Remote Monitoring Triage or newsletter signup, we collect your name, role, practice or organisation name, work email, phone number, practice location, approximate caseload or clinician numbers, practice management software, and the operational pressures you choose to describe.
Client operational information. During a Sprint, Audit or managed engagement we may collect and hold workflow documentation, SOPs, governance protocols, rosters, billing and performance data, and system configuration details needed to design and deliver the engagement.
Patient and health information. Where a managed function requires it (for example, remote monitoring coordination, transcription, billing or patient communication), our specialists process patient identifiable and clinical information inside your systems, under your governance protocol and our data handling agreement. We collect the minimum necessary for the agreed function.
Technical and usage information. When you visit our website we collect standard technical data such as IP address, device and browser type, pages visited and interaction patterns, through cookies and analytics tools described in section 11.
We collect information directly from you when you submit forms, correspond with us, or engage us; from your practice's systems where you have granted governed access for an agreed function; and automatically through website technologies. We do not collect personal information from third parties except where you have authorised it (for example, a referee during recruitment vetting) or where it is necessary to deliver a contracted service and lawful to do so.
We use information only for the purposes for which it was collected: responding to enquiries and delivering triage briefs; scoping, proposing and delivering diagnostic and managed engagements; operating managed functions under contract, including triage, documentation, communication and escalation; billing and account management; meeting legal, regulatory and professional obligations; improving our services and website; and, with consent, sending insights and updates you can unsubscribe from at any time. We do not sell personal information. We do not disclose it to outside parties except as described in this policy or as required by law.
Health information is treated with the highest level of protection under both the APPs and the Health Information Privacy Code. In practice this means patient identifiable information is accessed only by named, vetted team members whose role requires it; access is role-based, logged and auditable; health information is processed within your systems or within ANZ-hosted environments wherever practicable; and personal health information is not retained on individual workstations, with working copies securely destroyed once the work is delivered. We do not use patient information for any purpose other than the contracted function, and we never use it to train AI models except as described in section 7.4.
Our controls operate in five layers. The same model applies whether work is performed by in-house advisors, remote specialists or AI systems under Human-in-the-Loop oversight.
Every employee and contractor signs a non-disclosure and confidentiality agreement before any system access is granted. All team members complete background vetting (criminal record, education, reference and system capability checks), privacy and security induction training covering Australian and New Zealand health privacy requirements, and client-specific training in the governance protocol of each practice they serve. Access is reviewed regularly and revoked immediately on role change or exit. Any deliberate or grossly negligent breach results in dismissal and may carry personal liability.
All team members work from hardened, monitored workstations, including secure cloud-based Microsoft Azure virtual desktops, with multi-factor authentication enforced across all systems. Workstations run current endpoint protection with locked-down application and browser configurations, and smart activity monitoring software that records work session activity for security audit and quality assurance. Access to client systems is role-based and least-privilege: team members see only the information their function requires, including limited visibility of protected health information where full access is not needed. All connections use encrypted, authenticated channels, and remote access to client environments is enforced through secure methods agreed with each practice's IT requirements.
Confidential information is encrypted in transit and at rest using strong, industry standard encryption (including AES-256 at rest and TLS 1.2 or higher in transit, with perfect forward secrecy on our cloud platforms). Access to our document and workflow platforms occurs over HTTPS-encrypted tunnels with controlled, supervised and tracked permissions. We prioritise ANZ data residency, hosting with government-approved providers in regional data centres (for example AWS Sydney or Auckland) to maintain data sovereignty, minimise offshore risk and align with guidance from bodies such as the Australian Digital Health Agency and New Zealand's Ministry of Health. Where a client requires data to remain in a specific region or within their own dedicated tenancy, we configure isolated environments to meet that requirement.
Privacy and security controls are reviewed as part of our quarterly governance cycle for managed clients and through internal audits of access logs, activity records and incident registers. Compliance monitoring is embedded in managed delivery, and clients receive governance reporting that evidences the controls in operation, not just asserts them.
Our advisory team is based in New Zealand (Auckland) and Australia (Sydney and Gold Coast). Our specialist remote and HITL team members are located in the Philippines, South Africa and, from time to time, India. Where personal information is disclosed to team members outside New Zealand or Australia, we do so in compliance with IPP 12 and APP 8: the receiving team member is bound by contractual privacy and security obligations substantially similar to those under ANZ law; access occurs through the hardened, monitored, role-based environment described in section 7; data hosting remains in ANZ regions wherever practicable; and we remain accountable for the conduct of our workforce regardless of location. If you are a client, your data handling agreement specifies exactly which roles access which systems and from where.
We retain personal information only for as long as it is needed for the purpose for which it was collected, to meet legal and contractual obligations, or to resolve disputes. Working copies of patient information are securely destroyed when the relevant work is delivered, and personal information that is no longer required is securely deleted or de-identified. Clients may request access to, or deletion of, information we hold on their behalf at any time, subject to legal retention requirements.
We maintain a documented breach response procedure and all staff are trained in it. If a privacy breach occurs that has caused, or is likely to cause, serious harm, we will notify affected individuals and the New Zealand Office of the Privacy Commissioner or, for Australian matters, the Office of the Australian Information Commissioner and affected individuals under the Notifiable Data Breaches scheme, as required by law. Where a breach affects client data, we notify the affected client without undue delay and support their own notification obligations.
Our website uses cookies and similar technologies for site functionality and to understand how visitors use the site, including analytics and session recording tools such as Microsoft Clarity. These tools collect interaction data such as pages visited, clicks and scroll patterns, and device information. You can control or disable cookies through your browser settings; doing so may affect site functionality. We do not use website analytics data to identify individual patients, and no patient information is entered into our website forms.
If you subscribe to our insights or provide your details through a form, we may send you relevant content and updates. Every commercial electronic message includes a functional unsubscribe option, and we honour unsubscribe requests promptly, in compliance with the NZ Unsolicited Electronic Messages Act 2007 and the Australian Spam Act 2003.
We disclose personal information to third parties only where necessary to deliver our services (for example, cloud hosting, secure form and workflow platform providers, and professional advisers), where required by law, court order or lawful enforcement request, or with your consent. All third party providers that process information on our behalf are bound by contractual confidentiality and security obligations, and we take reasonable steps to ensure they meet the standards described in this policy. A list of material subprocessors is available on request.
You may request confirmation of whether we hold personal information about you, access to that information, and correction of it, under IPPs 6 and 7 (NZ) and APPs 12 and 13 (AU). Requests can be made to our Privacy Officer (section 17). We will respond within a reasonable period and, where we refuse a request on grounds permitted by law, we will tell you why and how you can complain. Where we hold information on behalf of a client practice, we may refer your request to that practice, which is the health agency or APP entity for that information.
Complaints or concerns about our handling of personal information are treated with the highest priority and investigated promptly. Contact our Privacy Officer in the first instance (section 17) and we will acknowledge and investigate your complaint and advise the outcome. If you are not satisfied, you may complain to the Office of the Privacy Commissioner (New Zealand) at privacy.org.nz or the Office of the Australian Information Commissioner at oaic.gov.au.
We may amend this policy from time to time to reflect changes in law, technology or our operations. The current version is always published on our website with its effective date. Material changes will be highlighted on this page, and for managed clients notified directly where the change affects their engagement.
Privacy Officer, Allied Orbit
Email: support@alliedorbit.com
New Zealand: +64 9 886 2887 | Australia: +61 2 8259 0322 or 1300 859 174
Stay ahead with industry insights, cutting-edge developments, and practical operational tips – delivered straight to your inbox. Join our community of forward-thinkers today!