DATA PROCESSING AGREEMENT
Last updated: 23 April 2026.
Your practice is data controller; RecallQ Pty Ltd is data processor for all patient personal information processed through the service.
We process patient data only on your documented instructions and for the purposes described in the Privacy Policy. We do not sell, rent, or disclose patient data.
Supabase (Sydney), Anthropic (USA), ClickSend (AU), Resend (USA), Stripe (AU), Sentry (EU). We notify you 30 days in advance of any change.
AES-256 at rest, TLS 1.3 in transit, RBAC, audit logs, annual penetration testing.
24-hour notification on confirmation of an eligible breach.
30-day export window on cancellation; permanent deletion within 60 days.
Written audit requests handled with current security summary; on-site audits by arrangement.