Privacy Policy
Last Modified: May 19, 2026
About this policy
GrowInsight is a reporting and insight platform for allied health practices. It is operated by GROW INSIGHT SOLUTIONS PTY LTD (ABN 89679269508) (“GrowInsight“, “we“, “us“, “our“). This Privacy Policy explains, in plain English, what information we collect, why we collect it, where it is stored, who we share it with, how long we keep it, and the choices and rights you have.
It applies to everyone who interacts with us: visitors to our marketing website at growinsight.io, users of the GrowInsight web application at app.growinsight.io, and the practices whose practice-management data is processed by GrowInsight on behalf of our customers.
We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
If after reading this you still have questions, we want to hear them. Contact details are at the bottom of this page.
What you should know about GrowInsight before reading the rest
Two things shape almost every privacy decision we make, and it’s easier to read the rest of this policy with both in mind.
GrowInsight is designed to minimise the client information it holds. GrowInsight is built to answer questions like “how is the practice performing?” and “how is each practitioner tracking against capacity?”. To answer those questions we only need to know that a client attended an appointment, not who that client is. Our database stores the PMS’s internal client identifier (a number or string that only has meaning inside your PMS) and the appointment, invoice, and service information attached to it. Our database does not store client names, contact details, dates of birth, Medicare numbers, NDIS numbers, session notes, diagnoses, treatment plans, or any other clinical information. This is a deliberate product constraint, not just a policy commitment.
There is one transient exception. If you use Zanda, the data export you upload to GrowInsight (a zip file produced by Zanda’s data-export screen) may contain client-identifying fields that Zanda chose to include in the export. That file sits in encrypted Amazon S3 storage in the Sydney region for up to 7 days while we process it. We do not extract or persist client-identifying fields from that file; we only ingest the structured operational records we need. After 7 days the original file is automatically deleted. See “How long we keep your information” for the full picture.
Your practice’s operational data is hosted in Australia. We use Amazon Web Services in the Sydney region for application hosting, databases, file storage, and the delivery of transactional and report emails. Your practice’s operational data does not leave Australia in the ordinary course of running the service. The one exception is your account’s billing contact details, which are processed by Xero (our invoicing provider) and may be stored on servers outside Australia. See the sub-processors section below.
Who we are and how to contact us
| Entity | GROW INSIGHT SOLUTIONS PTY LTD |
| ABN | 89679269508 |
| Contact email | privacy@growinsight.io |
| General enquiries | hello@growinsight.io |
What information we collect
We collect different information depending on how you interact with us.
When you visit our marketing website (growinsight.io)
We collect basic technical information automatically through cookies and analytics tools, including your IP address, browser type and version, device type, the pages you visit, the time of your visit, and the website that referred you. If you fill in the “Connect With Us” form we also collect your name, email address, phone number, country, organisation name, and the practice-management system you currently use. We use this information to respond to your enquiry, understand how the site is being used, and improve it.
When you sign up for or use the GrowInsight app (app.growinsight.io)
To create an account and use the service we collect your name, work email address, and the practice (organisation) you are associated with. When a user is invited as a team member we also collect the role they have been assigned (full access, administrative access, or practitioner). When you log in we record session and authentication information including the one-time password sent to verify your identity, the time of login, and the device and browser used.
If you contact us for support we keep a record of the conversation, including any screenshots or files you send us.
When we read data from your practice-management system
To produce the dashboards and Insight Emails, GrowInsight ingests operational data from your PMS. For Halaxy customers we connect directly to the Halaxy API and refresh data overnight. For Zanda customers, you export a zip file from Zanda’s data-export screen and upload it to GrowInsight; we typically process the file within 5 to 10 minutes.
We treat the PMS data flow in three layers:
- Temporary uploads. The raw zip file you upload from Zanda may contain client-identifying fields. It is stored in encrypted Amazon S3 in the Sydney region while we process it and is automatically deleted within 7 days of upload. We do not extract or persist client-identifying fields from this file.
- Transient processing. During ingestion, our processing pipeline reads the raw payload (whether from a zip upload or the Halaxy API), filters out fields we do not need, and writes only the structured operational records into our database. Identifying fields are discarded at this step and are not written to the database or to our application logs.
- Persistent storage. What ends up in our database is what we keep. That is limited to the items listed below.
The data we persist in our database includes:
- The PMS’s internal client identifier (a number or string that only has meaning inside your PMS). We do not store client names or contact details.
- Appointment records: date, time, duration, status (completed, cancelled, etc.), the practitioner the appointment was with, and which calendar it sat in.
- Invoice and payment records: amounts invoiced, amounts received, service items, and Medicare or other funding codes attached to the service item.
- Practitioner profile information needed to attribute appointments and revenue correctly (name and role within the practice).
- Referrer information as it appears in the PMS.
- Client type as recorded in the PMS (e.g. private, NDIS, Medicare, DVA) without any identifying client information.
We do not persist session notes, treatment plans, diagnoses, assessment results, correspondence, or any other clinical or directly identifying client information. If your PMS would otherwise include any of that data in an export, we discard it during ingestion.
How we use information
We use the information we collect to:
- Provide the GrowInsight service, including generating dashboards, calculating metrics, and producing the AI-generated weekly and monthly Insight Emails.
- Authenticate users and keep accounts secure.
- Send transactional emails such as registration confirmations, login one-time passwords, billing notifications, and the weekly or monthly Insight Email. Some of these emails include the recipient’s first name. They never include the names of your clients.
- Respond to enquiries and provide customer support.
- Investigate, prevent, and respond to security incidents, fraud, misuse, or breaches of our Terms of Service.
- Comply with our legal obligations.
- Where you have opted in, send you product news and marketing communications. You can opt out of these at any time using the unsubscribe link in the email.
- Create aggregated and de-identified information that we use to operate, support, and improve the Service. See “Industry benchmarking” below for the specific direction we are exploring.
We do not sell your personal information. We do not use your data to train external AI models, and we do not use one customer’s practice data to influence another customer’s individual experience.
Industry benchmarking
We may combine and de-identify operational data across customer practices to produce industry benchmarks (for example, the average utilisation rate across psychology practices in Australia, or the average client retention figure across practices of a similar size). These benchmarks help our customers understand how their practice compares to the broader industry, and help us improve the Service.
We are not producing or publishing benchmarks today. We are likely to do so once we have enough customer practices on the Service for the benchmarks to be both useful and genuinely de-identified. We are flagging it now so that you understand, when you agree to this Privacy Policy, the full set of ways your data may be used.
When we do produce benchmarks, the following will apply:
- Benchmarks will use aggregated and de-identified data only. No individual practice, practitioner, or client will be identifiable in any benchmark we publish or share.
- Benchmarks will never include information that could identify a client (and as described above, we never hold client names or contact details to begin with).
- We will apply minimum-sample-size thresholds so that small cohorts cannot be reverse-engineered to a single practice.
- We will not sell raw practice data to third parties.
We will update this Privacy Policy if and when we change the way benchmarks are produced or shared.
How we use AI to generate insights
Parts of the Service use a large-language model to generate narrative content. This currently includes the weekly and monthly Insight Emails, and will soon include AI-generated reports and interpretations accessible inside the GrowInsight app. We run these models on Amazon Bedrock in the Sydney region, which means AI inference happens entirely inside the Australian AWS environment. Your data is not sent to OpenAI, Anthropic’s direct API, Google Gemini, or any other AI provider that would process it outside Australia.
What we send to the model is the structured operational payload produced by our analysis layer (metrics, comparisons, trends, calendar context) together with the prompt template. We do not send your clients’ personal information because, as described above, we do not hold that information in the first place. We do not use your data to train external AI models.
AI-generated outputs are designed to surface patterns and prompt useful conversations. They are not perfect. They can occasionally misinterpret trends or suggest a Recommended Action that does not apply to your circumstances. Treat the outputs as one input into your decision-making, not as a substitute for your own judgement or qualified professional advice. The Terms of Service set out the disclaimers that apply to all GrowInsight outputs.
Who we share information with
We only share information with a small number of trusted service providers and only to the extent needed to run GrowInsight. Our current sub-processors are:
Australian-region providers (process your practice’s operational data inside Australia):
- Amazon Web Services (AWS), Sydney region — application hosting, databases, and file storage. Files you upload (such as Zanda export zips) are stored temporarily in AWS S3 and automatically deleted within 7 days of upload.
- Amazon SES (Simple Email Service), Sydney region — delivery of transactional emails and Insight Emails. Some emails include the recipient’s first name; none contain your clients’ personal information.
- Amazon Bedrock, Sydney region — large-language-model inference used to generate the AI-driven sections of the weekly and monthly Insight Emails. Inference runs entirely in the Australian region. See “How we use AI to generate insights” above.
Providers that may process data outside Australia (receive limited information only):
- Xero — invoicing and accounts receivable. Xero processes only your account’s billing contact details (organisation name, contact name, contact email, and invoice records). Your practice’s operational data is not shared with Xero. Xero may store billing information on servers outside Australia.
- Google Analytics 4 (Google LLC) — anonymous usage analytics on both our marketing website (growinsight.io) and the GrowInsight app. Receives pseudonymous identifiers and event data (page views, click events); does not receive your clients’ personal information or your practice’s underlying metric data. May process data outside Australia.
- Microsoft Clarity (Microsoft Corporation) — session-level usage analytics that helps us understand how the app is used and where users get stuck. Receives only account and user identifiers, page views, and interaction events; does not receive your clients’ personal information or your practice’s underlying metric data. May process data outside Australia.
- Pendo (Pendo.io Inc.) — in-app product analytics and onboarding tours. Receives only account and user identifiers and feature-usage events; does not receive your clients’ personal information or your practice’s underlying metric data. May process data outside Australia.
- Statsig (Statsig Inc.) — feature-flagging and experimentation platform that controls which features are enabled for which accounts and users. Receives only account and user identifiers; does not receive your clients’ personal information or your practice’s underlying metric data. May process data outside Australia.
We may also disclose information where we are required or permitted to do so by law, including in response to a lawful request from a government agency, a court order, or to enforce our Terms of Service, protect our rights, or protect the safety of our users.
If our business is ever sold, merged, or transferred, customer information may be part of that transaction. We will tell you in advance if this affects how your information is handled.
We will update this policy if our sub-processors change in a way that materially affects how your information is handled.
Where your information is stored
Your practice’s operational data, account information, AI inference for Insight Emails, and emails sent through Amazon SES are stored and processed in the Australian (Sydney) AWS region. This data does not leave Australia in the ordinary course of running the service.
Two narrow categories of metadata may be processed outside Australia. The first is your account’s billing contact information, which is processed by Xero and may be stored on servers outside Australia. The second is product-usage and feature-gating metadata (account and user identifiers, page views, click events, and feature-flag assignments) processed by Google Analytics 4, Microsoft Clarity, Pendo, and Statsig. None of these tools receive your practice’s operational data, the metric values shown on your dashboards, or any client information.
How we protect your information
We take a layered approach to keeping your data safe.
- Encryption in transit. All connections to GrowInsight (website, app, API) use TLS encryption. Data moving between you and our servers, and between our servers and our sub-processors, is encrypted while in transit.
- Encryption at rest. Customer data, including PMS data, is stored encrypted at rest in AWS.
- Access control. Internal access to production systems and customer data is restricted to staff who need it to operate or support the service. Administrative access is protected by multi-factor authentication.
- Tenant separation. Each practice’s data is logically segregated. A user from one practice cannot view, query, or otherwise access another practice’s data.
- Backups. Our primary database (AWS Aurora) is backed up daily. Backups are encrypted and retained for 7 days, after which they are automatically discarded.
- Logging hygiene. Our application and infrastructure logs are stored in AWS CloudWatch in the Sydney region. Logs are configured to exclude full PMS API payloads and any client-identifying fields. Email addresses appearing in logs are masked.
- The client-IDs-only design. As described above, the most sensitive personal information your practice holds (your clients’ identities and clinical records) never enters our database. This is the single biggest reduction in privacy risk we can offer, and it is built into the product rather than relying on policy.
No system is perfectly secure, and we don’t claim otherwise. If you believe your account has been compromised or you notice anything unusual, please email security@growinsight.io and we will investigate promptly.
Notifiable data breaches
If GrowInsight experiences a data breach that is likely to result in serious harm to any individual whose personal information we hold, we will notify the affected individuals and the Office of the Australian Information Commissioner (OAIC) as required under the Notifiable Data Breaches scheme in the Privacy Act 1988 (Cth). We will tell affected individuals what happened, what information was involved, what we are doing about it, and what they can do to protect themselves.
How long we keep your information
Raw uploaded files. Files you upload to GrowInsight (for example, a Zanda export zip) are stored temporarily in encrypted AWS S3 storage and are automatically deleted within 7 days of upload, regardless of whether you remain a customer. We keep only the structured records that have been ingested into our database.
Active subscriptions. While your subscription is active we keep your account and the ingested data so that GrowInsight can do its job and so that you have continuous historical comparisons.
After cancellation. If you cancel your subscription, we currently retain your account and ingested data unless you ask us to delete it. There are two reasons for this. First, if you decide to return later, your historical data is intact and you don’t need to re-import months or years of activity. Second, the operational data you’ve contributed may, once we have enough customers, be used in aggregated and de-identified form to produce industry benchmarks (see “Industry benchmarking” above). You can request deletion of your data at any time by emailing privacy@growinsight.io. We will action verified deletion requests within 30 days, except where we are required to retain certain records for legal, accounting, or tax purposes. We are working on automated deletion of long-inactive cancelled accounts and will update this policy when that capability is live.
Marketing-site enquiries. We keep marketing-website enquiry information for as long as needed to respond to the enquiry and for a reasonable period afterwards for follow-up.
Billing records. We retain invoicing and payment records (held in Xero) for the period required by Australian tax and accounting law, currently a minimum of 5 years.
Cookies, analytics, and similar technologies
Our marketing website uses cookies and similar technologies for three purposes:
- Strictly necessary cookies that make the site work (e.g. remembering you’ve dismissed a banner, processing a form submission).
- Analytics cookies that help us understand which pages are visited and where visitors come from, so we can improve the site.
- Marketing cookies placed by third parties such as LinkedIn or Google when we run advertising campaigns, used to measure the effectiveness of those campaigns.
You can control cookies through your browser settings. Disabling cookies may affect how parts of the website function.
The GrowInsight app itself uses only the cookies and local storage needed to keep you logged in and to remember your in-app preferences. The app does not run third-party advertising or interest-based-advertising trackers.
Your rights and choices
Under the Australian Privacy Principles you have a right to:
- Access the personal information we hold about you.
- Correct any personal information we hold about you that is inaccurate, out of date, incomplete, irrelevant, or misleading.
- Ask us to delete personal information we hold about you, subject to any legal or operational reasons we may need to retain it.
- Withdraw consent to receive marketing communications.
- Complain to us or to the OAIC if you believe we’ve mishandled your personal information.
To exercise any of these rights, email privacy@growinsight.io. We will verify your identity and respond within a reasonable time, generally within 30 days.
Children
GrowInsight is not intended for use by anyone under 18. We do not knowingly collect personal information from children. If you believe a child has submitted personal information to us, please contact privacy@growinsight.io and we will delete it.
Changes to this policy
We may update this Privacy Policy from time to time. If we make a material change we will tell active customers by email and post a notice in the app for a reasonable period. The “Last updated” date at the top of the policy will always tell you when it last changed.
Making a complaint
If you believe we have handled your personal information in a way that breaches the Privacy Act 1988 (Cth) or the Australian Privacy Principles, please contact us first at privacy@growinsight.io. We take complaints seriously and will work with you to resolve them.
If you are not satisfied with how we have handled your complaint, you can contact the Office of the Australian Information Commissioner:
- Website: www.oaic.gov.au
- Phone: 1300 363 992
- Post: GPO Box 5288, Sydney NSW 2001
Contact us
For any privacy-related question, request, or complaint:
Email: privacy@growinsight.io
Privacy Policy
LAST MODIFIED: 01/8/2024
GROW INSIGHT SOLUTIONS PTY LTD takes your privacy very seriously. This Privacy Policy explains how Grow Insight collects, uses, and discloses information, and your choices for managing your information preferences.
This Privacy Policy describes Grow Insight’s data practices associated with our website (growinsight.io) and Grow Insight services (“Services”), and the choices that Grow Insight provides in connection with our collection and use of your information. This Privacy Policy is intended for website publisher customers (“Publishers”), website merchant customers (“Merchants”) and individual users of websites and apps. For Publishers and Merchants, this Policy explains how Grow Insight may collect, use and disclose information associated with your company and with your company’s websites and apps that use Grow Insight Services. For individual website and app users, this Privacy Policy explains how Grow Insight may collect, use, and disclose information when you visit our website or when you use any website or app that uses Grow Insight Services.
Publishers and Merchants and other clients may also have their own policies that govern how they collect, use, and share data. These policies may differ from Grow Insight’s policies described in this Privacy Policy. Please consult the privacy policies of the websites you visit and apps you use to become familiar with their privacy practices and to learn about any choices that these companies may offer with respect to their information practices. In addition, any website containing our Services may contain links to websites or content operated and maintained by third parties, over which we have no control. We encourage you to review the privacy policy of a third-party website before disclosing any information to the website.
1. Information Collection and Use
Grow Insight collects data in a variety of ways – including through the use of log files, pixel tags, cookies, and/or similar technologies. Examples of the types of data that we collect are:
- Browser information (e.g. URL, browser type, ‘click through’ data);
- Device-type information (e.g. screen dimensions, device brand and model);
- Information about your activities on our website and Services.
- Name
- Phone Number
- Email Address
- Organisation Name
- Practice Management System
We may combine information that does not directly identify an individual with data collected from other sources and disclose the combined information to participating publishers, advertisers and ad networks so that they can determine whether to bid on ad inventory and in order to improve the relevance of the advertising presented to users. We also use the information we collect to host, operate, maintain, secure, and further develop and improve our Services, such as to keep track of advertising delivery and to measure the effectiveness of advertising delivered through our Services, and investigate compliance with Grow Insight’s policies and terms and conditions. Some of the third parties that we work with may contribute additional data to us directly, which we may combine with our own in order to help us provide a better service. We do not collect any information that could be used to directly identify an individual.
Grow Insight does not engage in activities that require parental notice or consent under the Children’s Online Privacy Protection Act (COPPA). If you believe that Grow Insight has inadvertently collected information from a child under 13 that is subject to parental notice and consent under COPPA, please contact Grow Insight using the contact information below to request deletion of the information.
2. Cookies and Other Similar Technologies.
We use cookies (a small file containing a string of characters that uniquely identifies your Web browser), Web beacons (an electronic file placed within a Web site that monitors usage), pixels, tags, and similar technologies to operate and improve our website and Services, including for interest-based advertising as described below. Some of our Service Providers (defined below) may also use such technologies in connection with the services they perform on our behalf.
3. Information Sharing
We will disclose contact and billing information to third parties only as described in this Privacy Policy:
- with your express permission;
- with our affiliates, which include entities controlling, controlled by, or under common control with Grow Insight;
- where we contract with third parties to provide certain services, such as advertising, analytics, data management services, web hosting, and web development (“Service Providers”). We ask Service Providers to confirm that their privacy and security practices are consistent with ours, we provide our Service Providers with only the information necessary for them to perform the services we request, and Service Providers are prohibited from using such information for purposes other than as specified by Grow Insight;
- in the event that Grow Insight is merged, sold, or in the event of a transfer of some or all of our assets (including in bankruptcy), or in the event of another corporate change, we may disclose or transfer information in connection with such transaction; and
- where we believe it is necessary to protect Grow Insight or our users; to enforce our terms or the legal rights of Grow Insight or others; or to comply with a request from governmental authorities, legal process, or other legal obligations.
We may also share and disclose other information that we collect, including aggregate information, as we consider necessary to develop and provide our Services, including in the ways described above. The information that we share in this way would not be considered to personally identify an individual.
Grow Insight may also be required to disclose information in response to lawful requests by public authorities, including to meet national security or law enforcement requirements.
4. Interest-Based Advertising and Opting Out
Grow Insight adheres to the Digital Advertising Alliance (DAA) Self-Regulatory Principles in the US and to the European Digital Advertising Alliance (EDAA) Principles in the EU and the IAB Europe OBA Framework.
The Grow Insight Ad Exchange uses cookies, Web beacons, pixels, tags, and similar technologies to give Publishers the possibility to offer, and Ad Exchange advertisers the ability to show, targeted ads on the device on which you are viewing this policy or a different device. These ads are more likely to be relevant to you because they are based on inferences drawn from location data, web viewing data collected across non-affiliated sites over time, and/or application use data collected across non-affiliated apps over time. This is called “interest-based advertising.” In addition, certain third parties may collect data on the Grow Insight website and combine this data with information collected from other websites over time for purposes that include interest-based advertising.
5. Opting Out for Cookie-Based Services
If you would like to learn more about this type of advertising, or would prefer to opt out of website interest-based advertising enabled by Grow Insight’s Ad Exchange, European Union residents may opt-out of this form of advertising by companies participating in the EDAA at www.youronlinechoices.com and all other users may visit www.aboutads.info/choices to opt out of this form of advertising by companies participating in the DAA self-regulatory program. Please note that in order for your opt-out choice to be effective using this tool, you must ensure that your browser is set to accept third-party cookies such as the Grow Insight opt-out cookie. Some browsers block third-party cookies by default, and you may need to change your browser settings to accept third-party cookies before opting out.
6. Opting Out for Certain Non-Cookie Services (in applicable countries)
To help identify your browser and/or possible relationships between different browsers and devices, Grow Insight or our partners may use the local storage or cache in your browser. Using the browser cache or local storage helps Grow Insight or our partners deliver interest-based advertising to a browser without the use of third-party cookies. We are using local storage only for application processing, not for any tracking processes. To opt out of Grow Insight’s use of local storage or the browser cache to provide its services, please (1) use any tools provided by your browser to clear local storage and the browser cache, and (2) turn on any “Do Not Track” header setting offered by your browser. As long as the two steps are completed and maintained on a browser, Grow Insight will not use local storage or the cache on that browser to identify and sync browsers and devices. If you also want to opt out of Grow Insight’s use of third-party cookies for interest-based advertising as enabled by Grow Insight’s Ad Exchange, please see instructions above.
7. Opting Out for Mobile Application Data
To opt out of Grow Insight’s collection, use, and transfer of data for interest-based advertising on mobile apps, you may download the DAA’s AppChoices application from the Android or iOS app store on your mobile device. The Privacy Policy Generator played a role in the creation of our document. Users outside the United States may not have access to this application; instead, you can use “Limit Ad Tracking” in your iOS settings or “Opt out of interest-based ads” in your Android settings to limit Grow Insight’s collection of data for interest-based advertising.
8. Opting Out for Location Data
You may opt out of our collection, use, and transfer of precise location data by using the location services controls in your mobile device’s settings.
9. Effect of Opting Out
If you use a different device or browser, or erase cookies from your browser, you will need to renew your opt-out choice.
If you opt out of Grow Insight’s practices, you may continue to receive interest-based advertising through other companies. Third-party advertisers and ad networks that participate in the Grow Insight Ad Exchange may also use their own cookies and other ad service technologies to display and track their ads. We do not control and are not responsible for such third-party advertisers and ad networks’ information practices or their use of cookies and other ad service technologies. To learn more about the practices of these companies, please read their privacy policies.
Even if you opt-out, Grow Insight may continue to collect data for other purposes. You still will receive advertising from the Grow Insight Ad Exchange when you visit websites of a Publisher who uses our Services – but such advertisements will not be targeted to you.
10. Reviewing and Updating Information
Grow Insight takes reasonable steps to ensure that information is accurate, complete, current, and reliable for its intended use. For contact or billing information submitted through our website, you may review, correct, update, or change your information, request that we deactivate your account, or remove your information from our direct marketing efforts, at any time by emailing us privacy@growinsight.io.
11. International Information Transfers
Please be aware that the information we collect, including contact and billing information, may be transferred to and maintained on servers or databases located outside your state, province, country, or other jurisdiction, where the privacy laws may not be as protective as those in your location. If you are located outside of the United States, please be advised that we process and store information in the United States and your consent to this Privacy Policy or use of Grow Insight Services represents your agreement to this processing.
12. Security
Information that we collect is stored using procedures and practices reasonably designed to help protect information from unauthorised access, destruction, use, modification, or disclosure.
13. Policy Updates
From time to time, we may change this Privacy Policy. If we decide to change this Privacy Policy, in whole or in part, we will inform you by posting the revised Privacy Policy on the Grow Insight website. Those changes will go into effect on the effective date disclosed in the revised Privacy Policy.
14. Contact Us
If you have any questions or concerns regarding this Grow Insight Privacy Policy, please contact us by emailing us at privacy@growinsight.io.