VoxDocs Privacy Policy

Effective Date: 1 January 2025
Last Updated: 7 August 2025

VoxDocs (a software product provided by Codestax Pty Ltd) lets clinicians capture consultation information on the road and securely deliver it to their own back-office team or an authorised Bureau for manual dictation, billing, and record keeping. We only collect what’s needed to run the service. We don’t sell personal information. ...

Effective Date: 1 January 2025
Last Updated: 7 August 2025

1. Who we are

Codestax Pty Ltd (“Codestax”, “we”, “us”, “our”) provides the VoxDocs software product and related services for healthcare professionals. In this policy, “VoxDocs” refers to our software and related services; “we/us/our” refers to Codestax Pty Ltd as the legal entity responsible for the Services. This policy explains how we collect, use, disclose, store, and protect personal information (including health information) when you use our website, platform, and mobile apps (the “Services”).

2. Our role (controller vs processor/operator)

For practitioner/admin account data (e.g., contact, login, subscription/billing), Codestax is the controller/responsible party. For patient/clinical data processed in VoxDocs on a practitioner’s documented instructions (e.g., consultation audio, transcripts, clinical notes), Codestax acts as a processor/operator and processes only on the practitioner’s instructions (GDPR Art. 28; POPIA operator obligations). We may act as controller for limited system data (security logs, fraud prevention, compliance).

3. Laws we comply with

4. Information we collect

5. How we collect information

6. Conduit function & processing instructions

VoxDocs acts as a conduit for clinical information under the practitioner’s documented instructions. For patient/clinical data, Codestax processes personal information only to capture, transcribe/summarise (if enabled), and deliver that information to the practitioner’s designated recipients (e.g., the practitioner’s internal back office and/or an authorised medical Bureau). The practitioner remains the controller/responsible party for such data.

7. Audio, notes, and retention

8. Sharing and disclosures

9. International data transfers

Data may be processed in Australia and in other locations of our subprocessors. For South African data (POPIA s72), we ensure adequate protection via contractual safeguards and technical/organisational measures, and assess recipient protections. For EU/UK transfers (GDPR/UK GDPR Chapter V), we use appropriate safeguards such as Standard Contractual Clauses (SCCs) and, where applicable, the UK IDTA/Addendum, plus supplementary measures where needed.

10. Security & breach notification

We apply administrative, technical, and physical security measures appropriate to the risks, including encryption in transit and at rest, role‑based and tenant‑scoped access, logging/monitoring, and staff confidentiality obligations. No system is 100% secure. If a notifiable breach occurs, we will notify you and regulators as required by law (Australia NDB, POPIA s22, GDPR/UK GDPR 72‑hour rule where applicable).

11. Your rights and choices

Depending on your location, you may have rights to access, rectify, erase, restrict or object to processing (including direct marketing), and data portability. If we process based on consent, you can withdraw consent at any time (this will not affect prior lawful processing). To exercise rights, contact support@voxdocs.com.au. We will verify identity and respond within required timeframes.

Marketing: You can opt out at any time (unsubscribe link or email us). Where POPIA s69 applies, we obtain consent before direct marketing and honour opt‑outs promptly.

12. Children and minors

The Services are for professional use. We process minors’ health information only under practitioner instructions. Retention for minors may be longer where required by law.

13. Cookies & remarketing

We use cookies for functionality and analytics and may use remarketing tools (e.g., Google Analytics/Ads). You can manage cookies in your browser settings; some features may not work if disabled.

14. How long we keep information

We keep personal information only as long as necessary for the purposes above, to comply with legal obligations, and to resolve disputes and enforce agreements. See Section 7 for clinical content retention options and dormant account deletion.

15. Changes to this policy

We may update this policy from time to time. We will post changes and, if material, notify you (email or in‑app). Your continued use after the effective date means you accept the changes.

16. Contact us

Codestax Pty Ltd – provider of the VoxDocs software product
Email: support@voxdocs.com.au
Postal: PO Box 274, Karrinyup, 6921, WA

If you are in Australia, you may contact the Office of the Australian Information Commissioner (OAIC). If you are in South Africa, you may contact the Information Regulator (South Africa). If you are in the EU/UK, you may contact your local supervisory authority.

Appendix A — GDPR/UK GDPR Disclosures