EsyTech Pty Ltd

Australian health software. Developer of ESYRIS.

Privacy Policy

Version 1.0 · Effective 23 August 2026 · EsyTech Pty Ltd, ABN 23 692 043 646

About this policy

EsyTech Pty Ltd (ABN 23 692 043 646) builds and operates ESYRIS, a hosted radiology information system for Australian diagnostic imaging practices. In this policy, we, us and our mean EsyTech Pty Ltd.

This policy explains how we handle personal information, including health information. It is our privacy policy for the purposes of Australian Privacy Principle 1 under the Privacy Act 1988 (Cth), and it also covers our obligations under the Healthcare Identifiers Act 2010 (Cth) and the My Health Records Act 2012 (Cth).

Current status of ESYRIS

ESYRIS is in development. It is not yet in clinical use, and it does not yet hold information about any patient.

We are publishing this policy now so that practices considering ESYRIS, and the people they care for, can see how information will be handled before any of it is entrusted to us. We will review this policy before the first practice goes live, and again whenever what we do with information changes.

Our two roles — please read this first

We handle personal information in two distinct capacities, and the difference matters for your rights.

1. Information we collect for ourselves. People who contact us, visit our website, work for a practice we deal with, apply to work with us, or represent a supplier. We are the entity responsible for this information and you deal with us directly about it.

2. Information we hold on behalf of a practice. When a diagnostic imaging practice uses ESYRIS, the practice remains the health service provider responsible for its patients’ records. We hold and process that information as the practice’s service provider, under contract and on the practice’s instructions. If you are a patient, your practice is your first point of contact — it is the practice’s record, and the practice controls access to it, corrections to it, and how long it is kept. We will always help a practice respond to you, and you can also contact us directly if you prefer.

What we collect and hold

Information we collect for ourselves

Our website is a plain information page. It does not use cookies, analytics, tracking pixels or advertising technology, and it does not collect information about visitors.

Information we hold on behalf of practices

Once ESYRIS is in clinical use, the information a practice will hold in it includes:

How we collect information

We collect information we hold for ourselves directly from you — when you contact us, when your practice nominates you as a user, or when we deal with you as a supplier or applicant.

Information about patients is not collected by us from patients. It is entered by the practice, received from a referring practitioner, or obtained from a government service at the practice’s direction — for example, verifying a Medicare number with Services Australia, or looking up an IHI through the Healthcare Identifiers Service to make sure the right record is attached to the right person.

Why we collect, hold, use and disclose information

We use information we hold for ourselves to answer enquiries, provide and support ESYRIS, manage our contracts and accounts, meet our obligations to Services Australia and the Australian Digital Health Agency, and run our business.

We use information held on behalf of a practice only to provide the ESYRIS service to that practice, and only for the purposes the practice has engaged us for: registering and scheduling patients, producing and distributing reports, verifying eligibility and claiming with Medicare and DVA, matching records using healthcare identifiers, uploading diagnostic imaging reports to My Health Record where the practice has chosen to do so, and supporting, securing and maintaining the system.

We do not sell personal information. We do not use it for marketing. We do not use patient information for our own purposes, and we do not use it to train machine-learning models.

Healthcare identifiers

Healthcare identifiers — IHIs, HPI-Is and HPI-Os — are specially protected. We collect, use and disclose them only as permitted by the Healthcare Identifiers Act 2010 and its regulations: to identify the right individual or provider, to communicate or manage health information about that individual, and for the associated claiming and record-keeping purposes. We do not use a healthcare identifier as a general account or reference number, and we do not disclose one except as that Act allows.

My Health Record

Where a practice uses ESYRIS to interact with the My Health Record system, we do so as a contracted service provider to that practice and are bound by the My Health Records Act 2012. We act only on the practice’s instructions and only within the access the practice holds. We keep records of relevant exceptions for at least two years, as that Act requires. Any decision to upload a report to a My Health Record, and any patient’s decision not to have one uploaded, rests with the patient and the practice — not with us.

Who we disclose information to

We do not disclose personal information to anyone else without your consent, or the practice’s, unless the law requires it.

Overseas disclosure

We do not disclose personal information to overseas recipients.

ESYRIS is designed and required to operate wholly within Australia. It is hosted in Australia, in the Sydney region of Amazon Web Services (Asia Pacific (Sydney), ap-southeast-2). We require every contractor engaged on ESYRIS to perform development, testing, support and operational work within Australia.

If that position ever changes, we will amend this policy and notify affected practices before the change takes effect.

How we store and protect information

ESYRIS is built to hold health information safely, and the protections are engineering controls rather than promises:

We work to the Australian Government Information Security Manual and to the security requirements of Services Australia and the Australian Digital Health Agency, and our compliance with those requirements is assessed as part of the certification we must complete before ESYRIS may transact with either agency.

How long we keep information

Information held for a practice is kept for as long as the practice requires and as long as the law requires. Health records in Victoria must generally be kept for at least seven years from the last occasion of service, or until a person who was a child at the time turns 25 — whichever is later — and ESYRIS is built to support that. Our transaction journal is retained for at least seven years. My Health Record exception records are kept for at least two years. Information we hold for ourselves is kept only as long as we need it, and then destroyed or de-identified.

When a practice stops using ESYRIS, we return its records to it in a usable form and then destroy our copies, other than anything we are required to retain by law.

Data breaches

If a data breach occurs that is likely to result in serious harm, we will notify the affected individuals and the Office of the Australian Information Commissioner as the Notifiable Data Breaches scheme requires, and we will notify the affected practice and the relevant government agency within the timeframes we are contractually required to meet. We maintain an incident response plan for this purpose and test it.

Anonymity and pseudonymity

You can contact us with a general enquiry without identifying yourself. We cannot provide the ESYRIS service, verify a Medicare entitlement, submit a claim or look up a healthcare identifier anonymously or under a pseudonym — the law and the government systems involved require a correctly identified person.

Accessing and correcting your information

If you are a patient: contact the practice that cared for you. It holds your record and it decides on access and correction. We will support the practice in responding to you, and if you contact us directly we will help you reach the right practice.

For information we hold about you for ourselves: write to us at the address below. We will respond within 30 days. There is no charge for making a request; if giving access involves substantial work we may charge a reasonable cost, and we will tell you before we do. If we cannot give you access or make a correction, we will tell you why in writing and how to have that decision reviewed.

Complaints

If you think we have mishandled your personal information, please tell us first. Write to our Privacy Officer at the address below, describing what happened. We will acknowledge your complaint within five business days and respond within 30 days.

If you are not satisfied with our response, or you would rather not deal with us, you can complain to the Office of the Australian Information Commissioner, which also handles complaints about healthcare identifiers and My Health Record:

Changes to this policy

We will update this policy when what we do with information changes, and in any case we review it at least annually. The version and date below always show the current edition. Where a change materially affects information we hold for a practice, we will notify that practice before the change takes effect.

How to contact us

Privacy Officer Dr Piyush Siwach, Director
Email admin@esytech.com.au
Post The Privacy Officer, EsyTech Pty Ltd, 76 Park Street, Moonee Ponds VIC 3039, Australia
Entity EsyTech Pty Ltd, ABN 23 692 043 646, ACN 692 043 646