Privacy Policy

Last updated: 23 September 2026  ·  Version: 2026-09  ·  Governing law: New Zealand

The things that matter most

Your session audio is never stored by Vocara. Audio is streamed to our transcription provider (AssemblyAI, in the US) to create a live transcript. Vocara never writes your session audio to disk; AssemblyAI processes it under its own privacy terms.
Your patient data is encrypted. Patient records and clinical notes are stored on secure servers in Australia and encrypted field-by-field, so they cannot be read from the database without keys held separately in AWS KMS.
🇳🇿
NZ law applies. Vocara operates under the New Zealand Privacy Act 2020 and the Health Information Privacy Code 2020. You have the right to request deletion of your account data at any time.
ACC work means sending information to ACC. When you lodge an ACC45, upload a document to a claim or invoice ACC from Vocara, the patient's details and the document itself go to ACC. That is what the tool is for. It happens only when you take that action, and every call is recorded in your account. The same is true of a note you push to Cliniko or Nookal, and of any document you email.

1. Who we are

Vocara is an AI-assisted clinical documentation tool built for New Zealand allied health practitioners. Vocara is operated by Vocara Limited (NZBN 9429053850393), a company registered in New Zealand, with its registered office at 12 Ridings Road, Auckland 1050, New Zealand. Vocara Limited was founded by Lachlan Kennedy. In this policy, "Vocara", "we", "us" and "our" refer to Vocara Limited. This Privacy Policy explains how we collect, use, and protect information in connection with your use of Vocara.

For privacy enquiries, contact: lachlan@vocara.co.nz

2. What information we collect

Account information: Your name, discipline, practice name, ACC provider number, and email address when you sign up.

Patient records and clinical notes: To provide the service, Vocara stores the patient records you create (such as name, date of birth, NHI number, contact details, and ACC claim details) and the clinical notes generated and signed from your sessions. This clinical information is encrypted at the field level before it is stored (see How your data is protected in section 5 below).

Session metadata: Timestamps, session duration, ACC claim codes, and note generation activity, used to operate the service and for billing.

Usage data: Basic app usage logs (page views, feature usage) to help us improve the product. These logs contain no patient or clinical information.

Session audio is streamed to our transcription provider, AssemblyAI (United States), to produce a live text transcript in real time. Vocara does not store your session audio; AssemblyAI processes it under its own privacy and security terms. Only the resulting text transcript is used to generate your note.

The patient's name is sent to AssemblyAI. Vocara sends the patient's name to AssemblyAI as a vocabulary hint, so their name is spelled correctly in the transcript. It is sent alongside the audio for that session.

The patient's name and up to three prior signed notes are sent to Anthropic. When a note is generated, Vocara sends the session transcript, the patient's name, and up to three of that patient's prior signed notes to Anthropic (United States) so the new note follows on from their treatment so far. Nothing sent to Anthropic is used to train AI models.

Documents you produce are stored. Every clinical document Vocara produces, including session notes, rehab plans, referral letters, ACC32 requests, discharge summaries and the patient and employer copies of ACC forms, is saved to your account with its full content, so it can be found again, reissued and audited. Document content is encrypted at the field level like the rest of your clinical data.

ACC submission receipts. Every call Vocara makes to ACC on your behalf writes a receipt in your account recording what was sent, what ACC said back, and whether it succeeded. Receipts are encrypted and are deleted with your account.

2a. What Vocara sends to ACC and to Health New Zealand

Vocara is built for ACC work, and ACC work means sending information to ACC. None of the following happens on its own: each is an action you take, on a claim the patient has made.

Health New Zealand (Te Whatu Ora). Vocara can look up a patient's NHI against Health New Zealand's National Health Index service. When you use it, we send either the NHI number you are checking, or the name, date of birth and gender you are searching on, along with an identifier for the person making the request, which Health New Zealand requires. This connection is enabled only where Health New Zealand's approval is in place; where it is not enabled, the lookup returns test data and nothing leaves Vocara. Every NHI lookup is recorded in an access log that stores a one-way hash of the identifier, never the identifier itself.

Vocara cannot lodge anything to ACC under its own identity. Every submission goes out under your practice's own ACC certificate, vendor ID and provider number, which you supply in Settings.

Outside ACC and the National Health Index, we do not disclose your information or your patients' information to any government agency unless the law requires it.

2b. What Vocara sends to your practice management system

A practice-system connection exists only if you create it, using your own practice's credentials, and you can remove it in Settings at any time.

Information sent to a practice management system is going to your own practice's system, under your own account with that provider, and is then held under that provider's terms rather than ours.

2c. What Vocara sends by email

Email is sent through Resend (United States). Three of these carry clinical content, and all three are actions you take:

Service email (sign-up, password reset, account notices) carries only your email address and name.

3. How we use your information

We do not sell your information to third parties. We do not use your clinical content to train AI models.

4. Who can access your information

You: You have full access to all information in your account.

Vocara operator: Vocara Limited may access account metadata when required to operate or troubleshoot the service. Patient clinical content is encrypted field by field and is not readable from the database itself; the keys that would unwrap it are held separately in AWS KMS. We do not decrypt or read your patients' clinical content as part of support.

Role clarification: You are the data controller for your patients' health information. Vocara acts as a data processor on your behalf, processing data only as directed by your use of the service and in accordance with this policy.

Sub-processors: We use the following third-party services (sub-processors) to operate Vocara:

Service Purpose Data processed Location
Anthropic (Claude API)AI note generationSession text transcript, patient name, up to three prior signed notesUSA
AssemblyAIReal-time speech-to-text transcriptionSession audio (streamed live, not stored by Vocara), patient name as a vocabulary hintUSA
Google FirebaseAuthentication & databaseAccount data, session metadataAustralia / USA
ResendTransactional and clinical emailRecipient email address and name. Where you send one: the full text of a referral letter, the text of a patient session summary, or a clinical note as a PDF attachment, with the patient's name in the subject lineUSA
ACC (Accident Compensation Corporation)Lodging ACC45 claims, uploading clinical documents, invoicing, checking claim and treatment statusPatient name, date of birth, NHI number, contact details, ACC claim number, accident, injury and diagnosis details, the document PDF itself, treatment dates, service codes and amountsNew Zealand
Health New Zealand / Te Whatu Ora (National Health Index)Looking up or confirming a patient's NHI, where enabledNHI number, or the name, date of birth and gender being searched, plus an identifier for the person making the requestNew Zealand
Cliniko (only if you connect it)Practice management sync and note pushPatient demographics, appointments, cases, medical alerts, intake forms and attachments read from your account; the signed note's sections written into itYour Cliniko account's own region (Australia for NZ practices)
Nookal (only if you connect it)Practice management sync and note pushPatients and cases read from your account; the signed note written into it as a treatment noteAustralia
Gensolve (only if you connect it)Appointment lookup. Read only: no clinical note is sentAppointment and patient name data read from your accountNew Zealand or Australia, by your Gensolve region
Amazon Web Services (AWS KMS)Encryption key managementEncryption keys only, no patient or clinical contentAustralia
SentryError monitoringError logs (PII-scrubbed)EU

Offshore disclosure: Some sub-processors listed above are located outside New Zealand, and patient clinical content does leave New Zealand. It does so in these ways:

Information sent to ACC and to Health New Zealand stays in New Zealand. By using Vocara you acknowledge these transfers. Each is made on the basis of contractual commitments with the sub-processor to maintain equivalent privacy protections.

ACC, Health New Zealand and other agencies. Vocara sends information to ACC and, where enabled, to Health New Zealand's National Health Index, because that is what the tool does and because you ask it to. Section 2a sets out exactly what goes to each. Outside those two, we do not share your information or your patients' information with any government agency unless the law requires it.

5. Data storage and location

Vocara stores your account data, patient records, and clinical notes in Google Firestore, hosted in Australia. All data is encrypted in transit (TLS 1.2+) and at rest.

How your data is protected. On top of standard at-rest encryption, every patient record and clinical note is additionally protected with field-level AES-256 encryption. Each record is encrypted with its own key, and that key is itself locked ("wrapped") by a master key held in Amazon Web Services Key Management Service (AWS KMS), in Australia, kept separate from the database. The master key never leaves AWS KMS. In practice this means patient names, NHI numbers, and clinical content are unreadable to anyone, including Vocara staff, without access to both systems.

We recommend exporting signed notes as PDF for your own records, in line with your professional record-keeping obligations.

6. Your rights under the Privacy Act 2020

Under the New Zealand Privacy Act 2020, you have the right to:

To exercise these rights, contact us at lachlan@vocara.co.nz. We will respond within 20 working days as required by law.

7. Patient rights and the Health Information Privacy Code 2020

Vocara is a tool for practitioners - we do not hold a direct relationship with patients. Under the Health Information Privacy Code 2020, the treating practitioner is responsible for:

Patients seeking access to their clinical records should contact their treating practitioner directly, not Vocara.

8. Account deletion

You may request deletion of your account at any time by contacting lachlan@vocara.co.nz. Upon receiving your request, we will:

You can also delete your account yourself, from Settings in the app, in which case the deletion runs immediately rather than within 48 hours.

What deletion also destroys. Deleting your account destroys your ACC submission receipts, the record in Vocara of what was sent to ACC and what ACC said back. ACC holds its own record of every lodgement, and we keep a count of how many receipts were destroyed, but no content. It also destroys clinical records that a practice may be legally required to keep for ten years under the Health (Retention of Health Information) Regulations 1996. Vocara does not block a deletion you have asked for, so export what you need to keep before you delete. Our full position is in our retention policy, available on request.

Note: Vocara may keep a temporary local copy of an in-progress note in your browser for crash recovery. That local copy clears when you sign out, or you can clear it in your browser settings; it is separate from the encrypted records we delete from our servers.

9. Cookies and tracking

Vocara uses essential cookies only - for session management and authentication. We do not use advertising cookies or third-party tracking pixels.

We use anonymised analytics to understand how practitioners use the product. These analytics contain no personally identifiable or patient information.

10. GDPR - Rights for users in the European Economic Area

If you access Vocara from within the European Economic Area (EEA), the General Data Protection Regulation (GDPR) may apply to our processing of your personal data. In addition to the rights under the NZ Privacy Act 2020, you have the right to:

Our lawful basis for processing your account data is contract performance (to provide the Vocara service you signed up for). We process health-related data only as a data processor on your behalf, under your control.

To exercise any GDPR rights, contact lachlan@vocara.co.nz.

11. Changes to this policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or by a prominent notice in the app. The date at the top of this page reflects the most recent update.

Continued use of Vocara after changes are posted constitutes your acceptance of the updated policy.

Privacy enquiries

For any privacy concerns, requests, or complaints:
Email: lachlan@vocara.co.nz
Vocara Limited · NZBN 9429053850393 · 12 Ridings Road, Auckland 1050, New Zealand
Response time: Within 20 working days (NZ Privacy Act 2020 requirement)

If you are not satisfied with our response, you may complain to the NZ Privacy Commissioner at privacy.org.nz.