Privacy Policy
Last updated: 1 September 2026
Blue Merino handles some of the most sensitive information there is: your patients’ health information. We treat it the way we’d want our own handled.
This Privacy Policy explains what personal information Blue Merino collects and holds, why we need it, how we protect it, who we may disclose it to, and the rights you and your patients have in relation to it.
Blue Merino is operated by Blue Merino, ABN 96 697 506 684, in Australia. We comply with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), together with other privacy and health-information laws that apply to us.
Who we are
Blue Merino is a clinical-documentation platform designed for allied-health practitioners.
It connects with your practice-management system, listens to or transcribes consultations when you choose to use that functionality, and helps create clinical notes, patient briefings, letters, referrals, reports and other clinical documents.
When this policy refers to Blue Merino, we, us or our, it means Blue Merino.
You can contact us about privacy at:
privacy@bluemerino.com.au
Geelong West VIC 3218
Your clinic’s role and Blue Merino’s role
When Blue Merino processes patient information on behalf of a practitioner or clinic, the clinic remains responsible for the patient’s clinical record and for determining how that information is collected and used in providing healthcare.
Blue Merino acts as a service provider to the clinic. We process patient information to provide the Blue Merino service and do not independently use that information for unrelated purposes.
Practitioners remain responsible for obtaining any consent required from their patients, reviewing Blue Merino’s output, and deciding what is added to a patient’s clinical record or communicated to another person.
What information we collect
The information we collect depends on how you use Blue Merino.
Practitioner and account information
We may collect:
- your name
- email address
- telephone number
- clinic or organisation
- account and login information
- practitioner preferences and settings
- information you provide when contacting support
Passwords are stored using secure hashing. We do not store your password in plain text.
Clinic information
We may collect information about your clinic, practitioners, practice-management setup, templates and workflows where this is needed to configure and provide Blue Merino.
Patient and clinical information
When a clinic connects Blue Merino to a practice-management system such as Cliniko, Blue Merino may process information contained in patient records that is needed to provide the requested service.
Depending on how the clinic uses Blue Merino, this may include:
- patient names and contact or demographic information
- appointment information
- health information
- presenting complaints and symptoms
- medical, treatment and clinical history
- previous clinical notes
- correspondence and referrals
- practitioner observations
- treatment information
- other information contained in the patient’s clinical record
Health information is sensitive information under Australian privacy law and receives additional protection.
Consultation audio and dictation
If a practitioner chooses to record a consultation or use Blue Merino’s dictation functionality, Blue Merino processes the audio necessary to transcribe the spoken content.
Audio is used for transcription and is then deleted automatically, unless your clinic has chosen to retain it for a short recovery period of up to seven days. It is not retained as part of the patient’s ongoing Blue Merino clinical record.
Notes, letters and other documents
We process transcripts and relevant clinical context to generate material requested by the practitioner, which may include:
- clinical notes
- patient briefings
- referral letters
- reports
- treatment plans
- correspondence
- other clinical documentation
Documents and attachments
If a practitioner uploads or makes available an attachment for Blue Merino to process, we may process the information contained in that document to provide the requested functionality.
Billing information
We collect information necessary to administer subscriptions and payments.
Payment transactions are processed by our payment provider, Stripe. Blue Merino does not store full credit-card numbers.
Technical and usage information
We collect limited technical information needed to operate, secure and troubleshoot Blue Merino. This may include:
- IP address
- browser and device information
- login and authentication events
- application errors
- security events
- system and audit logs
We do not use patient health information for advertising.
How we collect information
We may collect personal information:
- directly from practitioners when they create an account, use Blue Merino or contact us
- from a clinic or organisation that creates or manages an account for a practitioner
- from a connected practice-management system, such as Cliniko, at the direction of the clinic
- through consultation audio, dictation, documents or other content provided through Blue Merino
- automatically through the technical operation and security of the service
- from service providers involved in payments or account administration
In many cases, patient information is collected indirectly because a practitioner or clinic provides it to Blue Merino or authorises Blue Merino to retrieve it from their practice-management system.
Why we collect and use information
We collect, hold, use and disclose personal information only where it is reasonably necessary to provide, operate, secure or support Blue Merino, or where otherwise permitted or required by law.
We may use information to:
- provide access to Blue Merino
- connect with a clinic’s practice-management system
- prepare patient and appointment briefings
- transcribe consultations and dictation
- generate clinical notes, letters, referrals, reports and other documents
- adapt generated documentation to a practitioner’s preferred templates and writing style
- return approved documentation to the appropriate patient record
- administer accounts, subscriptions and payments
- provide technical and customer support
- diagnose faults and maintain reliability
- prevent unauthorised access and protect the security of Blue Merino
- comply with applicable legal obligations
We do not sell patient, practitioner or clinic information.
We do not use patient information for advertising.
We do not provide patient information to third parties for their own marketing purposes.
If you choose not to provide information
You are not required to provide personal information to us.
However, some information is necessary for Blue Merino to provide particular features. For example, without access to relevant consultation or patient information, Blue Merino cannot generate the associated clinical documentation.
Patient consent
Practitioners and clinics are responsible for telling patients when Blue Merino is being used and for obtaining any consent required before a consultation is recorded or patient information is processed through Blue Merino.
Patients should be given enough information to understand the role Blue Merino will play in the consultation and how their information will be handled.
A patient who does not want Blue Merino used during their consultation should tell their practitioner. The practitioner remains responsible for providing an alternative way of documenting the consultation where appropriate.
A patient may withdraw their consent to the use of Blue Merino during a consultation by telling their practitioner.
How consultation audio is handled
When recording is used, consultation audio is transmitted over an encrypted connection to Blue Merino’s transcription infrastructure in Australia.
Transcription is performed on infrastructure located in Australia.
The resulting transcript is then used to prepare the documentation requested by the practitioner.
By default, consultation audio is deleted automatically once the transcript has been produced. A clinic owner may choose to retain audio for up to seven days so that a consultation can be re-transcribed if there is a problem with the transcript. Retained audio is stored encrypted in Australia and is deleted at the end of that period.
Blue Merino does not use consultation audio for advertising, profiling or AI-model training.
How AI processing works
Blue Merino uses artificial intelligence to help transform consultation information and relevant clinical context into useful clinical documentation.
Patient background information retrieved from your practice-management system is de-identified before it is used for AI processing — age, sex and visit history are included; names, dates of birth and contact details are not. Text carried forward from earlier notes and uploaded documents is filtered to remove identifying details where it can be detected automatically. Consultation transcripts are processed as spoken, so they may contain identifying information mentioned during the consultation.
AI processing for Australian Blue Merino customers takes place through AWS Bedrock in Sydney.
Information submitted for AI processing is used only to generate the requested output. Under our arrangements with the relevant service providers, patient information submitted through Blue Merino is not used to train their general-purpose AI models.
Blue Merino does not sell patient information or make it available to AI providers for their own independent purposes.
We don’t train AI models on your patients’ information
Patient information, consultation audio, transcripts, clinical notes and other patient records processed through Blue Merino are not used to train general-purpose AI models.
Blue Merino adapts to the way you work, based on what you tell it. When you set up your account, you can provide examples of your own writing so that generated documentation reads in your voice. You can also give standing instructions — how you want a section structured, terminology you prefer, and things you always want included or left out — and Blue Merino follows them. Anything Blue Merino holds about your preferences is stored against your account within your clinic and used only for your own documentation. It is never pooled across clinics or applied to another practitioner.
Where we use aggregated or de-identified information to understand how Blue Merino is performing, we take steps to ensure that it does not identify an individual patient.
Clinical decisions stay with the practitioner
Blue Merino assists with clinical documentation. It does not replace the practitioner’s professional judgement.
Practitioners review Blue Merino’s generated material and remain responsible for the final clinical record before it is published to a patient’s file or communicated to another person.
Blue Merino may use information available to it to help the practitioner prepare more useful documentation. For example, it may:
- carry relevant information forward from earlier patient records
- identify apparent inconsistencies for the practitioner to review
- highlight information that may warrant the practitioner’s attention
- suggest a document such as a letter or referral based on the clinical record
These are prompts for practitioner review. Blue Merino does not independently diagnose, prescribe, initiate treatment or communicate with another healthcare provider without practitioner action.
Where available, practitioners can use verbal-only mode if they want generated documentation to rely only on what was said during the consultation rather than information in earlier records.
Practice-management systems
Blue Merino connects with practice-management systems such as Cliniko at the direction of the practitioner or clinic.
The clinic provides the credentials or API authorisation required for that connection.
Cliniko API credentials stored by Blue Merino are encrypted at rest.
Through the connection, Blue Merino may retrieve information required to provide its features and return approved documentation to the patient’s clinical record.
The clinic controls the connection and can revoke Blue Merino’s access at any time through Settings → Cliniko → Remove key, which deletes the stored encrypted credential from Blue Merino. We recommend also revoking the key from the Cliniko end. Removing the key stops any further access but does not retrospectively remove anything already written to the clinic’s Cliniko record.
Practice-management providers operate under their own privacy policies and terms.
Australian data storage and overseas disclosure
Blue Merino has been designed to keep patient and clinical information within Australian infrastructure. For Australian customers:
- application data is stored in Australia
- clinical information is stored in Australia
- consultation transcription occurs in Australia
- AI processing occurs in Australia through AWS Bedrock
- audit logs and error-monitoring data are held in Australia
- email delivery is handled through Australian-hosted infrastructure
- support and monitoring access is limited to authorised Blue Merino staff through a separate admin role, with access recorded in the audit log
Patient records, clinical notes, consultation audio, transcripts, AI processing and patient-related email delivery remain within Australian infrastructure.
Blue Merino does not send or store patient or consultation information overseas as part of its normal service.
If our use of service providers changes in a way that involves overseas disclosure of patient or clinical information, we will update this Privacy Policy and take the steps required under Australian privacy law before making that change.
How we protect information
We use administrative, technical and organisational safeguards designed to protect personal and health information from misuse, interference, loss and unauthorised access, modification or disclosure.
These safeguards include:
- encryption of data in transit
- encryption of data at rest
- additional encryption of sensitive fields using AES-256-GCM
- separation and isolation of clinic data
- encrypted storage of practice-management API credentials
- authentication and access controls
- two-factor authentication using an authenticator app, with single-use backup codes — a clinic can require two-factor authentication for all of its users, backup codes are stored hashed and never in readable form, and the login session is regenerated after a two-factor check
- audit logging
- security monitoring
- restrictions on staff access to patient information
Access to sensitive information is limited to authorised people and systems that require it to provide, maintain or support Blue Merino.
No system can guarantee absolute security, but protecting clinical information is a fundamental part of how Blue Merino is designed and operated.
More information about our technical and organisational safeguards is available on our Security page.
How long we keep information
We keep personal information only for as long as it is required for the purpose for which it was collected, to provide Blue Merino, or to meet applicable legal and regulatory obligations.
Different types of information may have different retention periods.
Consultation audio: deleted automatically following successful transcription, or at the end of the clinic’s chosen retention period of up to seven days.
Transcripts and generated clinical information: retained as part of the clinical record for as long as the clinic remains a Blue Merino customer, with no fixed expiry.
Account and billing information: retained for as long as reasonably necessary to administer the account and meet applicable accounting and legal requirements.
Security and audit logs: retained for seven years to support security, accountability and investigation requirements.
When information is no longer required, we take reasonable steps to securely delete or de-identify it, unless we are required or permitted by law to retain it.
Accessing and correcting personal information
You may request access to personal information Blue Merino holds about you and ask us to correct information that is inaccurate, out of date, incomplete, irrelevant or misleading.
Practitioners and account holders can contact us at privacy@bluemerino.com.au.
We may need to verify your identity before providing access or making a change.
There may be circumstances in which Australian law allows us to refuse an access or correction request. If that occurs, we will explain the reason where required and tell you what further options are available.
If you are a patient
Your clinic controls your clinical record.
If you want to access or correct information in your patient record, you should ordinarily contact your treating practitioner or clinic directly.
If you contact Blue Merino about patient information that we process on behalf of a clinic, we may refer your request to that clinic and assist them as appropriate in responding to it.
Deleting information and closing an account
Practitioners or clinics may request deletion of information held in Blue Merino where that information is no longer required and we are not legally required or otherwise authorised to retain it.
When a Blue Merino account is closed, we keep your clinic’s records for 90 days. During that period you can sign back in at any time to read your records and take a full export of them. We email the account owner before the end of that period. Once the 90 days have passed, the information held in your Blue Merino account is permanently deleted.
Deleting information from Blue Merino does not necessarily delete information that has already been published to Cliniko or another practice-management system. The clinic controls its copy of the clinical record and is responsible for its applicable record-retention obligations.
Privacy complaints
If you believe Blue Merino has mishandled personal information or breached your privacy, please contact us at privacy@bluemerino.com.au.
Please provide enough information for us to understand and investigate your concern.
We will acknowledge your complaint, investigate it and respond within 30 days, or let you know if we reasonably need more time.
If your complaint relates to information controlled by your practitioner or clinic, we may work with that clinic to investigate and resolve it.
If you are not satisfied with our response, you may be entitled to make a complaint to the Office of the Australian Information Commissioner (OAIC).
Data breaches
Blue Merino maintains processes for identifying, assessing and responding to suspected data breaches.
If a breach involving personal information is likely to result in serious harm and the requirements of Australia’s Notifiable Data Breaches scheme are met, we will notify affected individuals and/or clinics and the Office of the Australian Information Commissioner as required by law.
Where patient information is processed by Blue Merino on behalf of a clinic, we will work with the clinic to investigate and respond appropriately.
Changes to this Privacy Policy
We may update this Privacy Policy as Blue Merino develops, our technology changes or legal requirements change.
The latest version will always be available on our website, with the date of the most recent update shown at the top.
If we make a material change affecting how we handle personal information, we will take reasonable steps to let affected customers know, such as through Blue Merino or by email.
Contact us
Questions, privacy requests or complaints are welcome.
Blue Merino
Email: privacy@bluemerino.com.au
Address: Geelong West VIC 3218
A real person on our team will respond.