Your information

Privacy policy

How Signal Health and Longevity GP collect, use, protect and provide access to your personal health information.

Signal Health is operated by Longevity Practice Pty Ltd (ACN 690005700). Medical services are provided by Dr Colin Coward through Longevity GP (ABN 44690005700), and exercise physiology services are provided by O2 Active.

This policy explains how information is handled across our clinical practice, website and secure portal. We follow the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs), applicable health-record obligations and professional duties. Effective 7 September 2026.

1. Who is responsible

Longevity Practice Pty Ltd operates the Signal Health service and is the APP entity responsible for the personal information used to administer Signal Health, including the portal. “Signal Health” is the service name; it is not a separate company or privacy entity.

Dr Colin Coward, through Longevity GP, is responsible for the medical services he provides, his clinical decisions and the medical records created as part of that care.

O2 Active is our current contracted clinical provider for exercise physiology. O2 Active is responsible for information it collects directly and the exercise-physiology records it creates under its own professional and privacy obligations. Relevant information may be shared between the Signal Health team and O2 Active to coordinate your care.

2. Information we collect

We collect only information reasonably required to provide, coordinate and administer health services. Depending on how you use Signal Health, this may include:

  • identity and contact details, date of birth, address, Medicare information and emergency or usual-care contacts;
  • medical, medication, allergy, family-history, lifestyle, questionnaire and appointment information;
  • pathology, imaging, genetic, epigenetic, exercise, body-composition and other investigation results;
  • consultation notes, diagnoses, referrals, care plans, tasks, reports and clinical correspondence;
  • wearable screenshots, photographs or PDFs that you or a clinician choose to upload;
  • portal account, authentication, device, IP-address, access, security and audit information; and
  • payment status, package and receipt information. Full card details are handled by Stripe and are not stored in the Signal Health portal.

We usually collect information from you. With your consent or where otherwise permitted, we may also receive it from your treating practitioners, O2 Active, pathology or imaging providers, hospitals, Medicare, My Health Record and other services involved in your care.

The portal’s clinical-processing workflow is designed to minimise the use of direct identifiers. Clinical results and uploaded material are associated with a six-digit patient reference. The portal nevertheless holds limited identifying and account information needed to create the patient file, control access, contact the patient and connect the reference with the correct clinical record. Uploaded results, reports, exercise programs and wearable material must be de-identified before clinical extraction or summarisation.

3. How we use information

We use information to assess and provide care; coordinate appointments, referrals, investigations and follow-up; communicate with you and your care team; prepare clinical records and reports; operate and secure the portal; process payments; meet professional, Medicare, tax and legal obligations; and investigate complaints or security events.

We do not sell patient information or use it for third-party advertising. We do not make clinical decisions solely through automated processing. AI-generated material is treated as assistance or a draft and does not replace professional judgment.

4. Clinical records, PracSuite and Heidi

PracSuite is the principal practice-management and clinical-record system. Final clinical notes, correspondence and other material that form part of the medical record are maintained there. PracSuite states that its client data is stored in Australia, encrypted in transit and at rest, and protected by role-based access and mandatory two-factor authentication.

Heidi is a clinical documentation support tool, not the authoritative medical record. It may be used to collate information and prepare transcripts, summaries or draft notes. All Heidi output used in care is critically reviewed and edited by Dr Colin Coward before it is accepted or transferred into the clinical record. You may ask that Heidi not be used for your consultation.

Heidi states that Australian customer data can be localised in Australia and is not used to train its AI models. Its published policy also permits some de-identified or aggregated information to be used for platform functionality and improvement. Any use is subject to our contract with Heidi and applicable privacy law.

5. Portal access, security and audit logs

The Signal Health portal separates direct identifiers from the clinical content used for automated processing wherever practicable. Clinical datasets and uploads use a six-digit patient reference. A restricted patient-directory and authentication layer contains the limited identity and contact details needed to establish the account, manage access and match the reference to the correct patient file.

Identified booking and onboarding details, including contact, Medicare and intake information, are placed in a separate restricted New Bookings queue. Authorised staff use that queue only to establish or update the PracSuite record. Internal notification emails contain no patient details. Queue access and transfer are audited. Signatures, medication attachments and on-demand booking PDF downloads are available only to Dr Colin Coward's verified staff account.

Because authorised practice staff can reconnect the patient reference with the correct person, this information is more precisely described as pseudonymised, rather than anonymous, and remains personal and health information under privacy law. We protect it to the same standard as directly identified health information and do not rely on pseudonymisation alone as a security control.

Portal database records, authentication data and private uploaded files are held in the Signal Health Supabase project. Access is protected through individual accounts, two-factor authentication, row-level database security, role-based staff permissions, short-lived signed file links and inactivity timeouts.

Patients can access their own portal record. Doctors and authorised staff can access information required for their role and the care they provide. Exercise physiologists have more limited permissions for medical material and reports.

The portal records session starts and selected clinical, administrative and security events, including important additions, approvals, changes and deletions. These logs support accountability, security investigation and care coordination. They are not advertising analytics and should not be understood as a recording of every keystroke or every screen view.

6. Clinical and technology providers

O2 Active is currently the only contracted clinical provider. We may also disclose relevant information to a pathology, imaging, specialist or other provider chosen for your care where you consent, would reasonably expect the disclosure, or the disclosure is otherwise permitted by law.

We also use contracted technology providers to operate the service:

  • PracSuite (Smartsoft) for practice management and the principal clinical record;
  • Heidi Health for clinician-controlled documentation, collation and summarisation;
  • Supabase for portal database, authentication, private storage and server functions;
  • OpenAI API for privacy screening, transcription, extraction and draft summaries of selected portal content;
  • Netlify for delivery of the website and portal interface;
  • Resend for transactional email, ClickSend/Sinch for SMS and Stripe for payments; and
  • Coviu when you use the virtual waiting room.

Providers receive only the information reasonably necessary for their function and are subject to their own legal, security and contractual obligations. Provider lists and subprocessors can change; we review material changes and update this policy when appropriate.

7. Australian hosting and overseas processing

The portal’s primary Supabase database and private file storage are configured in the Sydney AWS region (ap-southeast-2). PracSuite states that its client data is stored in Australia. This does not mean that every service interaction occurs only in Australia.

Patients and staff are required to remove direct identifiers from clinical uploads before submission. Automated privacy screening necessarily examines the submitted material before it can confirm that requirement has been met. If the screen detects identifying content, the source is rejected and no clinical extraction or summarisation is performed. Content that passes screening is processed using the patient reference and without names, contact details or Medicare details.

Selected content is sent to the OpenAI API with response storage disabled for the request. OpenAI does not use API inputs or outputs to train models by default, but its standard service may retain content in abuse-monitoring logs for a limited period unless enhanced retention controls apply. We do not currently represent that OpenAI processing is confined to Australia.

Website delivery, payment, email and messaging providers may process account details, IP addresses, device or usage information, transaction data, message content and delivery metadata outside Australia. In particular, Resend states that email metadata, logs and API records are stored in the United States; Netlify operates internationally; Stripe may transfer payment information globally; and ClickSend/Sinch identifies support or monitoring access in Australia, North America, Europe and the Philippines.

Accordingly, personal information or metadata may be disclosed to or processed by recipients outside Australia. We use reputable providers, data-minimisation and contractual or technical safeguards, and we assess cross-border arrangements under APP 8. Contact us if you want further information about a particular provider or transfer.

8. Genetic information and wearable data

Genetic and epigenetic information is highly sensitive health information. We collect or arrange testing only where clinically relevant and with appropriate consent. Results are used for your care, stored with your clinical information, and disclosed only to the laboratory, relevant treating practitioners or others where authorised or required by law. We do not use identified genetic information for marketing or sell it.

Wearable uploads must be de-identified before submission. The portal re-encodes supported images to remove standard embedded metadata, stores the generated image privately, performs an automated privacy screen and uses AI to produce observations and searchable tags. The original HEIC or other source image is not uploaded. Automated wearable comments may be incomplete or wrong, are not a diagnosis and should be discussed with your care team.

A patient can delete a wearable upload from the portal. Deletion removes the portal record and private stored image, subject to provider backup cycles, security records and any copy that has already become part of the clinical record.

9. Retention and deletion

Clinical records are retained for the periods required by applicable law, professional standards and the continuing needs of safe care. Administrative, payment, security and audit information is retained only while reasonably necessary for its purpose or a legal obligation.

When information is no longer required, we take reasonable steps to delete it or de-identify it. Identified booking details remain in the restricted working queue until Dr Colin Coward confirms deletion after transfer to PracSuite. That deletion permanently removes the booking intake, signed consent, signature and medication attachment from the active Supabase database and private storage. A booking PDF can be downloaded by Dr Colin Coward before deletion for placement in the principal clinical record. Deletion from an active system may not immediately remove encrypted backups, provider delivery logs or information that a treating provider must retain. Those copies are handled under the relevant provider’s retention cycle and legal obligations.

You may request deletion, but health records cannot always lawfully or safely be erased on request. Requests are assessed individually. The portal also has a protected whole-file deletion process available to an authorised doctor; it requires two-factor authentication, password re-entry and confirmation, and removes patient-scoped portal records, private files and portal access while retaining only a non-patient-identifying security event.

10. De-identified analytics and research

Longevity Practice does not currently use patient records or portal health information for external research, commercial analytics, advertising or model training. We may use limited operational information to maintain security, troubleshoot the service and measure whether functions work correctly.

We may consider genuinely de-identified information for service evaluation, analytics or research in the future. Before doing so, we will assess re-identification risk, ethics and consent requirements, update this policy where appropriate, and obtain consent or other authority where required. Information is only treated as de-identified when there is no reasonable likelihood that an individual can be identified in the circumstances.

Technology providers may create operational, security, aggregated or de-identified information as described in their contracts and privacy terms. This is separate from Longevity Practice undertaking its own research.

11. Access, correction and complaints

You may request access to personal information we hold about you or ask us to correct information that is inaccurate, out of date, incomplete, irrelevant or misleading. Please make the request in writing. We aim to respond within 30 days and may charge only a reasonable administrative fee where permitted. Access may be limited where the law allows or requires it.

If you have a privacy concern or complaint, contact the Longevity Practice Privacy Officer:

Longevity Practice Privacy Officer

hello@signal-health.com.au
08 6275 2080

If you are not satisfied with our response, you may contact:

Office of the Australian Information Commissioner (OAIC)

1300 363 992
www.oaic.gov.au

Health and Disability Services Complaints Office (HaDSCO) WA

(08) 6551 7600
www.hadsco.wa.gov.au

12. Policy updates

We review this policy when our services, providers or legal obligations change. The current version and effective date will remain available on this website. If a change materially affects how we handle existing health information, we will provide additional notice or seek consent where required.