Privacy policy
Last updated
Yumee is in build and is not yet taking real patient calls. This describes how the system is designed and built to handle information, so that it is on the record before the first clinic goes live rather than after.
Who this covers
Yumee answers phone calls for allied-health clinics and books appointments into the clinic's practice management system. Two different groups of people appear in this policy: the clinic staff who use Yumee, and the patients who ring the clinic and reach it.
For patient information, the clinic decides what is collected and why — we handle it on the clinic's instructions. For clinic staff accounts and for this website, we make those decisions ourselves.
Which law applies to you
Yumee is built for allied-health clinics in Australia, New Zealand and the United Kingdom. Which privacy law governs a clinic's patient information depends on where that clinic is, so this policy names all three rather than describing one and leaving you to guess whether it is yours.
In Australia: the Privacy Act 1988 and the Australian Privacy Principles, overseen by the Office of the Australian Information Commissioner. Health information is sensitive information, the most tightly held category the Act defines.
In New Zealand: the Privacy Act 2020 and the Information Privacy Principles, with the Health Information Privacy Code 2020 sitting over health information specifically, overseen by the Office of the Privacy Commissioner.
In the United Kingdom: the UK GDPR and the Data Protection Act 2018. Health data is special category data under Article 9, which needs a lawful basis of its own beyond the one that covers ordinary personal data. The regulator is the Information Commissioner's Office.
Where the three differ, we build to the strictest of them rather than to the one that happens to apply — a system that handles a Sydney clinic's calls one way and a Manchester clinic's another is a system with two chances to get it wrong.
What we collect
From a patient calling the clinic: the phone number the call came from, what was said during the call, and the appointment that resulted. We also keep a mapping of the patients in the clinic's practice management system — name, date of birth and phone number — so that a caller can be matched to their existing record instead of a duplicate being created.
From clinic staff: name, work email, and the settings for the clinic and its phone numbers.
From this website: the email address you give the waitlist form, which form sent it, and the site you arrived from — the origin only, never the full address, because a full address can carry identifying details in it. We also use product analytics on the site and in the dashboard.
We treat everything a patient says on a call as health information, whether or not it obviously is — sensitive information in Australia, special category data in the United Kingdom, and covered by the Health Information Privacy Code in New Zealand.
What we do not collect
Calls are not recorded. That is stronger than a setting that happens to be off: there is nowhere in our database to put a recording, and an automated test fails the build if a column for one is ever added. If that ever changes, callers will be told at the start of the call and will be able to decline and still be served.
Patient information never reaches our logs, our error reports or our analytics. Logs identify a call by a reference and the clinic it belongs to, never by who rang. This is enforced in the code and in our review process, not left to memory.
Analytics is never used to decide what a clinic is billed or anything about a patient's care.
How long we keep it
The transcript of a call is deleted after the clinic's retention window, which defaults to 30 days and can be set anywhere between 1 and 365. The same nightly job erases the caller's phone number from the call record for the same window. After that, a call is a duration, an outcome and a reference — it identifies nobody.
The call record itself, without the phone number, is kept indefinitely: it is what the clinic's dashboard and its bill are calculated from.
One exception, stated plainly because it is the part most easily glossed over. The mapping of patients in the clinic's practice management system — name, date of birth and phone number — is kept for as long as the clinic uses Yumee, and is not covered by the retention window above. It exists so a returning caller is matched to their existing record. We are actively reviewing whether it should expire too.
Waitlist addresses are kept until you ask us to remove them, or until the waitlist is retired.
Where it is stored
Records at rest — the database and sign-in — are hosted in Sydney, Australia.
For an Australian clinic that is a point in our favour, and we say so. For a clinic in New Zealand or the United Kingdom it reads the other way round: records leave the country at rest, not only while a call is running, so the basis for that transfer is the thing that matters rather than the address. The data processing agreement sets out what we do about it, per market.
The call path crosses a border in every market, and we would rather say so than imply otherwise. The voice service that answers the call runs in the United States and Canada, and our background job service runs in Singapore. Call audio and the transcript therefore leave the country the clinic is in while a call is in progress, wherever that country is.
The full list of companies that process information on our behalf, what each one can see, and where it runs, is on the subprocessors page. It is one list, and that page is the copy we keep current.
Being told you are speaking to an AI
Yumee says so at the start of every call: "Just so you know, I'm an AI assistant, not a person."
It is not a setting a clinic can switch off: the greeting a clinic writes is assembled with the disclosure built into it, so an agent carries it by construction rather than by a box someone remembers to tick. The automated check that will confirm it before any clinic takes real patient calls is still being built, and no clinic is taking them yet.
Security
Every clinic's data is isolated at the database level, and that isolation is covered by tests that run before any change ships. Credentials for a clinic's practice management system are encrypted before they are stored, with the key held outside the database entirely, so a database backup does not contain anything that could be used to reach the clinic's own system.
We are not certified against SOC 2, ISO 27001 or HIPAA, and we do not claim to be.
Access, correction and complaints
If you are a patient of a clinic that uses Yumee, ask the clinic first — they hold the relationship and the record. If you would rather come to us directly, email hello@getyumee.com and we will work with the clinic to answer you.
Clinic staff can ask for a copy of their information, ask us to correct it, or ask us to delete an account, at hello@getyumee.com.
If you think we have mishandled your information and our answer does not resolve it, you can complain to the regulator where you are: in Australia the Office of the Australian Information Commissioner at oaic.gov.au, in New Zealand the Office of the Privacy Commissioner at privacy.org.nz, and in the United Kingdom the Information Commissioner's Office at ico.org.uk.
Changes
When this changes materially we will update the date at the top and tell clinic customers by email. The version history lives in our public repository, so a change is visible rather than silent.