← Back to home

Privacy Policy

GP Platform Innovations Pty Ltd (ABN 17 700 992 936 · ACN 700 992 936) · Effective 13 August 2026 · Version 1.1

1. Who we are

GP Platform Innovations Pty Ltd (“we”, “us”, “our”) is an Australian company based in Victoria. We develop MediLabel, a Windows desktop application that enables general practices to print patient identification labels for pathology specimens.

We are committed to protecting privacy in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). Because our software is used in connection with health services, we hold ourselves to the standards applicable to health-related information even where our own handling of personal information is minimal.

2. The key point: patient data stays at the practice

MediLabel is installed on computers within a medical practice and operates entirely within that practice's environment. When a clinician prints a label, MediLabel reads a minimal set of patient demographic details — given name, surname, and date of birth — from the practice's clinical software at the moment of printing, formats them onto a label, and sends the label to a locally connected printer.

We do not collect, receive, store, or transmit patient information to our company. MediLabel reads three demographic fields, for one patient at a time, at the moment a label is printed — and discards them immediately after printing.

Specifically, MediLabel:

The medical practice remains the custodian of its patients' information at all times. Practices are responsible for their own obligations under the Privacy Act and their own privacy policies with respect to patient data.

3. Personal information we do collect

We collect limited personal information about our customers and website visitors (not patients), namely:

CategoryExamplesSource
Business contact detailsName, role, practice name, email, phoneYou, when you enquire, purchase, or request support
Licensing detailsPractice name, licence key, installation countGenerated when you purchase
Support informationCorrespondence, screenshots you choose to sendYou, during support
Website analyticsPages visited, approximate location, device typeOur website (aggregate, low-identifiability)
Payment detailsProcessed by our payment provider; we do not store full card numbersPayment processor

We collect this information directly from you wherever practicable (APP 3), and only what is reasonably necessary to provide and support MediLabel.

When contacting support: please do not include patient information in emails or screenshots. If patient details are inadvertently received, we will delete them promptly and will not use them for any purpose.

4. Why we collect it

We use customer information to provide, license, and support MediLabel; process payments and maintain business records; notify you of updates, security patches, and material changes; improve our products; and comply with legal obligations.

We do not sell personal information. We do not use it for direct marketing without your consent, and you can opt out at any time via info@medilabel.com.au.

5. Disclosure

We may disclose customer information to: service providers who help us operate (e.g. email, payment processing, cloud hosting for our business systems), under appropriate confidentiality arrangements; professional advisers (accountants, lawyers) where required; and government or regulatory bodies where required by law.

Some of our business service providers (e.g. email infrastructure) may process data outside Australia. Where this occurs, we take reasonable steps to ensure comparable privacy protections apply (APP 8). Patient information is not affected — it never leaves the practice.

6. Data quality and security

We take reasonable steps to keep customer information accurate, up to date, and secure, including encryption of data in transit (TLS) for all our business systems; multi-factor authentication on our administrative accounts; access limited to personnel who need it; and secure deletion of information that is no longer required.

For the security measures inside the MediLabel application itself, our Security Posture Statement is available on request via info@medilabel.com.au.

7. Data breach response

We maintain a data breach response process consistent with the Notifiable Data Breaches (NDB) scheme. If a breach of personal information we hold is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) as required.

Because patient information is processed only within the practice's own environment and is not held by us, a breach of patient data through MediLabel's own systems is structurally improbable; nonetheless, we will cooperate fully with practices in the event of any security incident involving our software.

8. Access and correction

You may request access to, or correction of, the personal information we hold about you by emailing info@medilabel.com.au. We will respond within a reasonable period (typically 30 days). We do not charge for making a request.

9. Complaints

If you have a privacy concern or complaint, contact us at info@medilabel.com.au. We will acknowledge your complaint promptly and aim to resolve it within 30 days. If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (OAIC) — www.oaic.gov.au · 1300 363 992.

10. MediLabel Connector browser extension

The MediLabel Connector browser extension (for Chrome and Edge) exists for a single purpose: at the user's request, it reads the patient name and date of birth displayed on the currently open clinical software page and delivers them to the MediLabel application running on the same computer (via the local address 127.0.0.1) so a pathology specimen label can be printed.

The extension does not collect, store, or transmit any data over the internet. It contains no analytics or tracking, contacts no external servers, and patient details never leave the computer on which the label is printed.

11. Changes to this policy

We may update this policy from time to time. The current version will always be available on this page, with the effective date shown at the top.