How Capsl collects, uses and protects your information
This Privacy Policy explains how Capsl (operated by Luke Newman, ABN registered, trading as Capsl) collects, uses, stores and discloses personal information in accordance with the Australian Privacy Act 1988 and the Australian Privacy Principles (APPs).
This policy applies to information collected through the capsl.au website and through our software platform provided to institutional clients.
Website visitors: When you contact us through our website, we may collect your name and email address. We may also collect standard web analytics data (pages visited, browser type, approximate location) through analytics tools.
Client organisations: In the course of providing our software platform to hospital pharmacy clients, Capsl processes patient information on behalf of the client organisation. At minimum, this includes patient initials, Medical Record Number (MRN), admission and discharge dates, and medication name, form and quantity (for example, Metformin 500mg Tablets x30), linked to prescription and delivery records. Extended patient demographics (full name, date of birth, sex, and gender) are optional and only stored where enabled by the client organisation. Where extended data is disabled, only initials, MRN and prescription records are retained. This data is provided by the client and processed solely to deliver the contracted service.
We use information collected through our website to:
Patient data processed through our platform is used solely to provide the prescription tracking and ward stock delivery management service to the client organisation. We do not use patient data for any other purpose.
All data is stored in Microsoft Azure data centres located in Australia (Australia East — Sydney). Data is never stored or processed outside Australia.
Patient data is encrypted at rest and all data in transit is protected by TLS encryption. Access to the platform is controlled via Okta identity management with multi-factor authentication enforced.
We do not sell, rent or share personal information with third parties for marketing purposes. We may disclose information where required by law, or to service providers who assist us in operating the platform (such as our cloud hosting provider, Microsoft Azure), subject to appropriate data processing agreements.
Website enquiry data is retained for as long as necessary to respond to and follow up on enquiries. Patient data processed through the platform on behalf of client organisations is retained for the duration of the client agreement. Upon termination, clients have a 30-day window to export their data, after which it is securely deleted from our systems. Written confirmation of deletion is available on request.
Audit logs are retained for seven years in line with Australian health records legislation.
Under the Australian Privacy Act, you have the right to access personal information we hold about you and to request corrections where information is inaccurate. To make such a request, contact us at the details below.
Patients whose information is processed through our platform should direct privacy enquiries to the hospital or health service that provided their information to Capsl, as the data controller.
Capsl complies with the Notifiable Data Breaches (NDB) scheme under the Privacy Act. In the event of an eligible data breach, we will notify affected organisations and the Office of the Australian Information Commissioner (OAIC) as required by law.
For privacy enquiries, requests for access or correction, or questions about this policy, please contact:
Luke Newman
Founder, Capsl
hello@capsl.au
capsl.au
We may update this policy from time to time. The current version will always be available at capsl.au/privacy. Material changes will be communicated to active clients directly.