ClinicProCapturePrivacy policy

For ClinicPro Capture only

Privacy policy

Applies to ClinicPro Capture, the clinical photo capture product. Other ClinicPro products have their own privacy documentation.

Effective date: 4 August 2026.

01Who we are

ClinicPro Capture is a product of NexWave Solutions Limited (NZBN 9429052227875), a New Zealand company and an official Medtech ALEX integration partner. It is built by Dr Ryo Eguchi, a practising GP in Auckland.

Our privacy officer is Dr Ryo Eguchi. For anything in this policy: ryo@clinicpro.co.nz.

The short version:Capture moves a clinical photo from a phone browser into the patient’s Medtech Evolution record. One copy ends up in Medtech. We keep none. No clinical image or patient identifier is ever stored on our servers, and every hop the image takes stays within New Zealand and Australia.

02Our role: agent of your practice

When a practice uses Capture, we act as an agent of that practice under section 11 of the Privacy Act 2020. In plain terms: the practice remains the agency that holds the health information, exactly as if a staff member had scanned the photo in themselves. Capture is the courier, not a second record-holder. The practice’s obligations under the Health Information Privacy Code 2020 (HIPC) continue to sit with the practice; our job is to handle the information on the practice’s behalf without keeping any of it.

Capture is designed to meet the Health Information Privacy Code 2020, the Privacy Act 2020, and HISO 10029 (the Health Information Security Framework, the NZ health sector’s security standard).

03Patient health information: what passes through, what we keep

What passes through: the clinical photo itself, any annotation or body-map detail added to it, and the patient identification details returned by Medtech when a staff member looks a patient up by NHI to confirm they have the right record.

What we keep: none of it. Specifically:

  • No server-side copy of any clinical image, ever. Images are processed in transit (resized and formatted) and pass straight through to Medtech. Nothing is written to any ClinicPro database or file store.
  • No patient data in any server-side database. Patient identifiers never appear in URLs; sessions are handled with server-side tokens.
  • On the phone, nothing persists. During the capture workflow the image is held only in the browser’s temporary session storage, and it is cleared immediately once the upload commits. Photos taken through Capture never touch the camera roll, iCloud, Google Photos, or any messaging app. If a staff member instead uploads an existing photo from the phone’s gallery rather than taking it in Capture, that original gallery photo was created outside Capture and remains on the device, Capture cannot and does not delete it. Practices should prefer in-Capture capture for clinical images.

Where a photo travels, every hop within New Zealand or Australia:

Where a photo travels
HopWhere it runsNote
Phone browserThe consult roomPhoto taken in the browser; nothing saved to the device
ClinicPro CaptureVercel, SydneyResizes and formats the image in transit
ALEX proxyAWS Lightsail, SydneyStatic IP, allow-listed by Medtech
Medtech ALEX APIMedtech’s gatewayThe official Medtech integration channel
Your Medtech databaseYour practiceThe patient’s Inbox Scan; the only stored copy

04Metadata stripping

Every photo has its embedded metadata (EXIF, including any GPS location) stripped automatically before it reaches the patient record. This happens in the image-processing pipeline itself, both on the phone during compression and on the server during format conversion, so a photo can never carry the location of a patient’s home or the practice into the record or anywhere else.

05Audit records

Every commit is logged so the practice has a complete audit trail: which user, which facility, which practitioner, when, how many images, and the Medtech document ID created. The patient’s NHI and internal patient ID appear in that log only as HMAC-SHA256 hashes, a one-way cryptographic fingerprint. The hash lets us verify “this log entry relates to that patient” if the practice ever needs to reconcile an audit question, but it cannot be reversed to reveal the NHI, and ClinicPro cannot identify any patient from its own records.

Audit records are retained for 10 years, matching the retention period for clinical records under the Health (Retention of Health Information) Regulations 1996, and then deleted.

06Practice staff account information

To run the service, we hold a small amount of personal information about practice staff who use Capture, and for this information NexWave Solutions Limited is the agency under the Privacy Act 2020:

  • Name and work email address (used to sign in and to keep the audit trail per-person)
  • The practitioner and facility they are linked to
  • Sign-in and security records
  • Billing and subscription contact details for the practice

We use this only to operate Capture, support the practice, and bill the subscription. We do not sell personal information, use it for advertising, or use any information passing through Capture to train AI models.

Sign-in is handled by Clerk and billing by Stripe, both specialist providers based in the United States. Staff account and billing data may therefore transit or be processed in the US under those providers’ own security and privacy terms. This is separate from clinical image data, which never leaves New Zealand or Australia (see section 03).

Staff can request access to or correction of their account information at ryo@clinicpro.co.nz.

07Security

  • All data is encrypted in transit over HTTPS (TLS).
  • The connection into Medtech runs only through the ALEX API, Medtech’s official integration channel, from a static IP address that Medtech has allow-listed.
  • No clinical data at rest on ClinicPro infrastructure means the highest-value target simply is not there to attack.
  • Capture is designed against HISO 10029, the NZ health sector security framework.

08Retention

Retention periods
InformationRetention
Clinical imagesNot retained. Pass through only; the sole stored copy is in the practice’s Medtech record.
Patient identifiersNot retained in identifiable form; hashed values only, inside audit records.
Audit records10 years.
Staff account informationFor the life of the practice’s subscription, then deleted within 90 days.

09Access, correction, and patient rights

Under the Privacy Act 2020 and HIPC rules 6 and 7, people have the right to access and correct their information.

  • Patients:your photo and record live in your practice’s Medtech system, and your practice is the agency that holds them. Please direct access or correction requests to your practice, as you would for any part of your medical record. ClinicPro holds no information that can identify you, so we could not action such a request even in principle; if one reaches us, we will point you to your practice and help the practice with anything technical.
  • Practice staff: contact ryo@clinicpro.co.nz for your account information.

10What the practice remains responsible for

Because the practice is the agency, some HIPC duties stay at the practice and cannot be transferred to us: telling patients how their information is handled when it is collected (HIPC rule 3, and from 1 May 2026 rule 3A where information is collected indirectly), clinical record-keeping and retention under the Health (Retention of Health Information) Regulations 1996, and having its own privacy officer. Capture is designed so that using it changes nothing about these duties: a photo committed through Capture is, legally and practically, a photo in the practice’s record.

11If something goes wrong: privacy breaches

We maintain a defined notification chain with our infrastructure providers:

  1. AWS notifies ClinicPro within 24 hours of a breach on their infrastructure (an AWS NZ Notifiable Data Breach Addendum is in place).
  2. ClinicPro notifies the affected practice within 24 hours of becoming aware of any breach involving the practice’s information.
  3. The practice, as the agency, assesses serious harm and notifies the Office of the Privacy Commissioner within 72 hours where the Privacy Act 2020 threshold is met. We support the practice through that assessment with full technical detail.

12Complaints

If you believe we have handled personal information incorrectly, contact our privacy officer first: ryo@clinicpro.co.nz. We aim to acknowledge within 2 working days.

If you are not satisfied with our response, you can complain to the Office of the Privacy Commissioner: privacy.org.nz or 0800 803 909.

13Data Processing Agreement

A Data Processing Agreement (a contract setting out exactly how we handle the practice’s information as its agent) is available to any practice on request: ryo@clinicpro.co.nz.

14Analytics and cookies

The Capture website (not the clinical capture workflow itself) uses Vercel Analytics and PostHog to understand how visitors use our marketing pages, page views and navigation only. PostHog is US-hosted. Neither tool sees or has anything to do with clinical images or patient information, which never reach these pages at all.

Our booking page uses Calendly, a US-hosted scheduling provider, to let a practice book an Launcher icon setup session. Calendly receives only what you enter on that form, a name, an email address, and your practice details, so we can confirm the appointment. It is not used anywhere in the clinical capture workflow and never sees patient information.

15Changes to this policy

If we change this policy materially, we will post the updated version here with a new effective date and notify subscribed practices by email. Earlier versions are available on request.

See also the operational brief for cost, onboarding, and exit terms, or the Capture product page for the interactive demo.