Privacy Policy
Last updated: September 2026
1. Introduction
Octavise ("we", "our", or "us") operates the Octavise analytics dashboard platform accessible at octavise.com.au. This Privacy Policy explains how we collect, use, store, and protect information when you use our services. By using Octavise, you agree to the terms of this Privacy Policy.
2. Information We Collect
We collect the following types of information: Account information: When you register for Octavise, we collect your email address and the credentials necessary to create and manage your account. Practice management data: With your explicit authorisation, Octavise connects to your practice management system (such as Nookal or Cliniko) and accesses selected practice management records required to produce aggregated, anonymised business metrics including appointment counts, revenue totals, patient counts, cancellation rates, and practitioner performance summaries. Advertising platform data: With your explicit authorisation, Octavise connects to your advertising accounts (such as Meta Ads and Google Ads) and retrieves campaign performance metrics including ad spend, impressions, clicks, conversions, and cost per result. Lead form data: With your explicit authorisation, Octavise receives lead form submissions from your connected advertising and website platforms (such as Meta Lead Ads). A submitted lead's contact details (email address and phone number) are converted at the moment of receipt into one-way cryptographic fingerprints (SHA-256 hashes of the standardised values); Octavise stores the fingerprints, the campaign and ad the lead came from, the submission time, and the last three digits of the phone number as a reference. Octavise does not store, display, or log a lead's readable email address or phone number. The fingerprints are used solely to match leads and enquiries to bookings recorded in your practice management system, so that your dashboard can report which advertising produces actual appointments. We do not store patient names, email addresses, phone numbers, full dates of birth, addresses, clinical notes, or individual clinical records in the Octavise dashboard. Practice management data is processed to produce aggregated business metrics, and where patient continuity is required for reporting, Octavise uses pseudonymised or hashed identifiers rather than direct patient identifiers. Where Octavise processes contact details from lead forms or matches leads to bookings, it does so using one-way hashed identifiers as described above; readable contact details are not retained. Hashed identifiers may still constitute personal information under the Privacy Act 1988, and this policy applies to them accordingly.
3. How We Use Your Information
We use the information we collect to: • Provide and operate the Octavise dashboard service • Display aggregated business performance metrics in your dashboard • Generate insights and analysis based on your aggregated data • Maintain and improve the platform • Communicate with you about your account and our services • Comply with legal obligations We do not sell your data to third parties. We do not use your data for advertising purposes.
4. Data Storage and Security
Your data is stored in Australia using Supabase's Sydney region (ap-southeast-2) infrastructure. We implement the following security measures: • Row Level Security (RLS) at the database level ensures each client's data is completely isolated and inaccessible to other clients • All data is encrypted at rest and in transit using HTTPS/TLS • API credentials and secrets are stored in encrypted environment variables and never exposed to the browser • Access to your dashboard requires authenticated login • We maintain read-only access to connected systems - we never modify, delete, or write data back to your practice management system or advertising accounts
5. Third-Party Services
Octavise integrates with the following third-party services to provide its functionality: • Nookal and Cliniko: Practice management systems. We access these services using API credentials you provide. We use selected practice management records only where required to produce aggregated dashboard metrics. • Meta: We access your advertising data using OAuth 2.0 authorisation. We retrieve campaign performance metrics, and — where you connect your Facebook Page for lead capture — lead form submissions, which are processed as described in Section 2 (Lead form data). Connecting a Page subscribes Octavise to that Page's lead notifications; Octavise makes no other changes to your Page and does not post, message, or manage content. • Google Ads: We access your advertising data using OAuth 2.0 authorisation for the Google Ads API. Octavise only uses this access to retrieve campaign performance metrics. • Supabase: Our database provider. Data is stored in Australia (Sydney region). • Vercel: Our hosting provider. Application code is served from Vercel's infrastructure. • Google Analytics, Meta Pixel and Microsoft Clarity: Website analytics on our public pages only. These record page visits, referring source, and — in the case of Microsoft Clarity — anonymised recordings of how visitors move through those pages, so that we can understand which pages are useful and where people get stuck. These website analytics tools are deliberately restricted. They do not run on the Octavise dashboard, your account settings, or any administration screen. No practice management data, patient information, or clinic performance data is ever sent to them. Text entered into form fields is masked before any recording is stored. Each third-party service is governed by their own privacy policy and terms of service.
6. Google Ads API Data
Octavise uses the Google Ads API to retrieve campaign performance data on behalf of authorised customers. Specifically: • We request the Google Ads API OAuth scope and use it only for reporting reads • We retrieve advertising performance metrics including campaign spend, impressions, clicks, conversions, click-through rate (CTR), cost per click (CPC), and other reporting metrics made available through the Google Ads API • We use Google Ads API data solely to provide reporting, analytics, attribution reporting, business intelligence, performance monitoring, and performance insights to the authorised customer • Octavise does not request, access, store, or process customer list data, remarketing audience data, or personally identifiable information from Google Ads accounts. Octavise only uses Google Ads reporting data needed to provide dashboard analytics • We do not create, modify, pause, resume, delete, or otherwise manage campaigns, ad groups, advertisements, keywords, budgets, bidding strategies, or any other advertising assets • We do not use Google Ads API data for advertising, remarketing, profiling, or marketing activities • We do not sell Google Ads API data or share Google Ads API data with third parties except where required to provide the Octavise service or where required by law • We do not use Google Ads API data to train artificial intelligence or machine learning models • Google Ads API data is stored only within the authorised customer's client-isolated environment and is not accessible to other Octavise customers • Customers may revoke Octavise's access to Google Ads at any time through their Google account permissions or by contacting Octavise.
7. Data Retention
We use different retention periods depending on the type of information, reflecting how long each type remains necessary for the purpose it was collected for. Aggregated snapshot data (dashboard metrics such as appointment counts, revenue totals, and campaign performance) is retained for as long as your account is active, to enable historical trend analysis in your dashboard. Hashed lead fingerprints and other matching identifiers (described in Section 2, used to match a lead to a booking) are retained for 120 days from the date the lead was received — covering our 90-day attribution window plus a 30-day allowance for bookings that are recorded in your practice management system after some delay — and are then permanently cleared, whether or not a match was found. Where a lead never results in a matched booking, we keep only de-identified, aggregate information about it (such as the campaign, advertisement, and date it came from) for as long as your account is active, so that advertising performance reporting remains accurate; no fingerprint or other identifying detail is kept for that lead beyond the 120-day period. Verified records confirming that a specific booking resulted from a specific lead are retained for as long as your account is active, so your dashboard can continue reporting historical advertising performance over time. If you close your account, within 90 days we will de-identify these verified records — retaining only aggregate, campaign-level totals — and delete or de-identify hashed matching identifiers and other personal account information, unless we are required to retain it for legal or regulatory purposes. You may request erasure of your data, or of an individual patient's attribution record, at any time by contacting us at https://octavise.com.au/contact.
8. Your Rights
Under the Australian Privacy Act 1988 and the Australian Privacy Principles, you have the right to: • Access the personal information we hold about you • Request correction of inaccurate or incomplete information • Request deletion of your personal information • Lodge a complaint with the Office of the Australian Information Commissioner (OAIC) if you believe we have breached the Privacy Act To exercise any of these rights, please contact us at https://octavise.com.au/contact.
9. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page with a revised date. Your continued use of Octavise after any changes constitutes your acceptance of the updated policy.
10. Contact Us
Contact: https://octavise.com.au/contact Website: https://octavise.com.au